From d59d995943e8c6490d2740ee13cc10ebfc30e592 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 10:51:19 +0900 Subject: [PATCH 001/250] docs: refresh live product gap baseline --- CHANGELOG.md | 10 ++--- README.md | 8 ++-- .../0107-browser-protocol-adapter-strategy.md | 8 ++-- docs/product-technical-gap-baseline.md | 43 +++++++++++++------ docs/traceability/mcp-authority-route.md | 20 ++++----- ...cumentation_active_pr_evidence_contract.py | 15 ++++--- ...test_gap_snapshot_inventory_consistency.py | 20 +++++---- tests/test_product_completion_gap_contract.py | 15 ++++--- tests/test_product_documentation_contract.py | 2 +- 9 files changed, 83 insertions(+), 58 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index f747adeae..fe543ea74 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,11 +4,11 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] -- Refreshed the product-gap queue to 126 open pull requests (54 ready, 72 draft) after #190, #188, #185, #192, #182, #184, #115, #181, #116, #117, #118, #183, #114, #127, #112, #109, #186, #110, #108, #111, #174, and #113 were merged into their immediate stacked prerequisites. PRs #147, #146, #145, #144, #143, #142, #141, #139, #136, #132, #129, and #128 moved to ready after exact-head checks and thread review; these are queue-consolidation results, not protected-main shipment. +- Refreshed the product-gap queue to 114 open pull requests (30 ready, 84 draft) on 2026-08-28; these are queue evidence, not protected-main shipment. ### Added -- Corrected the 2026-08-26 product-gap snapshot with current #229 presentation-identity evidence, stacked-only #205 integration evidence, current base/head pairs, the 126-PR queue count, explicit root-versus-child merge ordering, and the active GitHub counted-approval gate. -- Refreshed the product and technical gap baseline onto the 2026-08-26 live inventory: 126 open pull requests (54 ready, 72 draft), protected-main promotion of #168/#194/#196/#216/#151, a verified maintenance-loop record (supersession closure of #153, conflict reconciliations on #37/#149/#152/#173/#175, issue #212 option-(b) authorization on #43, Strix vuln-0001 homoglyph remediation on #124), provider-rerun outcome evidence, an organization review-pipeline congestion record, and refreshed merge-order queue guidance. Documentation evidence contracts were aligned to the same snapshot so the baseline, its dated markers, and the pinned exact-head rows cannot silently diverge. +- Corrected the 2026-08-28 product-gap snapshot with protected-main `542ca1e9`, 114 open pull requests (30 ready, 84 draft), 11 open issues, current exact base/head pairs for representative PRs, PR #170's merged `tools/list` contract, the active counted-approval gate, and the unchanged Phase 1 browser gap. +- Refreshed the product and technical gap baseline onto the 2026-08-28 live inventory; current queue and exact-head evidence are explicitly separated from the historical 2026-08-26 snapshot so stale delivery evidence cannot be promoted. - Added `originweave_core::release_acceptance`, a deterministic fail-closed benchmark release-decision contract that requires one authoritative result for every mandatory suite, bounds explicit buyer-visible limitations, rejects duplicate limitation claim identities, and rejects non-canonical surrounding whitespace rather than normalizing it into an alternate claim spelling. - Refreshed the product and technical gap baseline with the 2026-08-24 live inventory: 158 open pull requests (44 ready, 114 draft), refreshed exact base/head evidence for the #208–#222 release, enterprise-approval, BAP, and WARC/PROV chains, the governance issue additions #212 and #215, and a required-check provider-failure record for the fail-closed Strix re-dispatches on #208/#218/#220. @@ -20,7 +20,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Canonical HTTPS and loopback-origin boundary with case-normalized schemes and hosts, default-port normalization, IPv4/IPv6 handling, browser-special numeric-host rejection, and explicit malformed-input errors. - Typed browser actions, capabilities, risk classes, execution modes, robots decisions, secret-delivery contracts, immutable canonical action-intent digests, and intent-bound approval scopes. - Protected main now contains deterministic MCP `2026-07-28` stateless `tools/call` routing with bounded method/tool names, a single reviewed tool-to-action registry shared by routing and discovery metadata, and fail-closed policy binding that grants no ambient authority. The complete MCP adapter, transport serialization, discovery response handling, OAuth, browser I/O, and persistence remain planned. -- Active PR #170 adds conservative MCP `2026-07-28` `tools/list` discovery metadata derived from that protected-main catalog, with `resultType = complete`, zero freshness, private cache scope, no continuation cursor, per-request protocol/client-capability admission, and bounded protocol-version and method metadata validated before cross-field comparison. This remains active-PR evidence only and grants no browser, network, secret, approval, or Agent authority. +- Protected main now includes the conservative MCP `2026-07-28` `tools/list` discovery metadata merged through PR #170: `resultType = complete`, zero freshness, private cache scope, no continuation cursor, per-request protocol/client-capability admission, and bounded protocol-version and method metadata validated before cross-field comparison. This grants no browser, network, secret, approval, or Agent authority and does not complete the MCP adapter. - Deterministic fail-closed policy evaluation for untrusted instructions, origin grants, crawler restrictions, execution-mode and purpose consistency, approvals, and brokered secrets. - Fail-closed resolved-destination policy with IPv4/IPv6 special-purpose and reviewed cloud-platform endpoint classification, IPv4-mapped canonicalization, explicit class grants, non-empty origin-bound DNS snapshots capped at 256 resolver addresses, concrete connection pinning, DNS-set expansion detection, and per-hop redirect reauthorization. - Bounded resolution-freshness authority with trusted monotonic approval time, capped non-zero validity, half-open use windows, non-expanding revalidation, and credential-free authorization timestamps. @@ -102,4 +102,4 @@ All notable changes to OriginWeave are documented in this file. The format follo - The hourly product agent has no Git metadata or repository authority. A separate post-verification publisher opens one PR and cannot approve or merge it. - The unprivileged OpenCode user is restricted to loopback egress during model execution, preventing runner-wide allow-listed endpoints from becoming direct source-exfiltration channels. -[Unreleased]: https://github.com/ContextualWisdomLab/OriginWeave/compare/main...HEAD \ No newline at end of file +[Unreleased]: https://github.com/ContextualWisdomLab/OriginWeave/compare/main...HEAD diff --git a/README.md b/README.md index 0942976cf..85706a92c 100644 --- a/README.md +++ b/README.md @@ -4,7 +4,7 @@ OriginWeave is a Chromium-compatible, Rust-first control plane for governed AI agents on the web. It is designed to let an agent observe, extract, and act without turning untrusted page content into authority, exposing secrets to a model, connecting to an unapproved network destination, accepting an unauthenticated web service, or losing the evidence required to explain what happened. -> Project status: pre-alpha. The current protected repository contains independently reusable safety, resolved-destination, direct TCP peer-binding, authenticated TLS service-identity, and bounded MCP `2026-07-28` stateless `tools/call` routing/policy foundations. Chromium, WebDriver BiDi, CDP, complete MCP, HTTP, proxy, WARC, and persistent provenance adapters are planned but not yet shipped. Active PR #170 implements only conservative `tools/list` discovery metadata on top of the protected-main MCP catalog; it remains non-shipped active-PR evidence and does not make the complete MCP adapter available. +> Project status: pre-alpha. The current protected repository contains independently reusable safety, resolved-destination, direct TCP peer-binding, authenticated TLS service-identity, and bounded MCP `2026-07-28` stateless `tools/call`/`tools/list` routing and policy foundations. Chromium, WebDriver BiDi, CDP, complete MCP, HTTP, proxy, WARC, and persistent provenance adapters are planned but not yet shipped. The merged `tools/list` contract does not make the complete MCP adapter available. ## Why OriginWeave @@ -40,7 +40,7 @@ The repository is organized as independently consumable Rust crates: - `originweave-resource`: task-level RAM, VRAM, thread, and frame-time budgets with cumulative mitigation plans. - `originweave-evidence`: universally value-redacted network evidence and source-bound provenance records. -Protected main additionally contains an `originweave-core` MCP routing registry and `originweave-policy` binding for the MCP `2026-07-28` `tools/call` boundary. That shipped foundation validates and maps an explicit tool name to an existing typed action while preserving normal OriginWeave policy. Active PR #170 adds non-shipped conservative `tools/list` discovery metadata derived from the same reviewed catalog. Neither boundary implements transport parsing, OAuth, browser control, secret materialization, persistence, or ambient authority. +Protected main additionally contains an `originweave-core` MCP routing registry and `originweave-policy` binding for the MCP `2026-07-28` `tools/call` and `tools/list` boundaries, merged through PRs #168 and #170. Those shipped foundations validate explicit routing and conservative discovery metadata while preserving normal OriginWeave policy. Neither boundary implements transport parsing, OAuth, browser control, secret materialization, persistence, or ambient authority. See [ARCHITECTURE.md](ARCHITECTURE.md) and the [architecture decision records](docs/adr/) for binding design decisions. @@ -99,7 +99,7 @@ isolated Chromium session → redacted provenance bundle ``` -Subsequent work connects the live Chromium network service, adds explicit proxy and download policy, WARC/PROV persistence, completes the MCP and Browser Agent Protocol adapters beyond the protected-main `tools/call` foundation and active `tools/list` refinement, expands extension compatibility testing, adds GPU/RAM telemetry and prompt-injection benchmarks, and builds an accessible approval interface. See [docs/product-roadmap.md](docs/product-roadmap.md). +Subsequent work connects the live Chromium network service, adds explicit proxy and download policy, WARC/PROV persistence, completes the MCP and Browser Agent Protocol adapters beyond the protected-main `tools/call` and `tools/list` foundations, expands extension compatibility testing, adds GPU/RAM telemetry and prompt-injection benchmarks, and builds an accessible approval interface. See [docs/product-roadmap.md](docs/product-roadmap.md). ## Hourly product-development loop @@ -111,4 +111,4 @@ Read [AGENTS.md](AGENTS.md), [CONTRIBUTING.md](CONTRIBUTING.md), and [SECURITY.m ## License -Apache License 2.0. See [LICENSE](LICENSE). \ No newline at end of file +Apache License 2.0. See [LICENSE](LICENSE). diff --git a/docs/adr/0107-browser-protocol-adapter-strategy.md b/docs/adr/0107-browser-protocol-adapter-strategy.md index fb1bf2e17..8f77138a5 100644 --- a/docs/adr/0107-browser-protocol-adapter-strategy.md +++ b/docs/adr/0107-browser-protocol-adapter-strategy.md @@ -38,11 +38,11 @@ MCP version negotiation is independent of the OriginWeave Protocol version. As o The complete MCP adapter remains **Planned**. Protected main now contains the narrower bounded Rust `tools/call` routing/action-policy foundation merged through PR #168. That protected-main foundation validates the `2026-07-28` stateless `tools/call` routing envelope presented to this boundary, bounds and syntax-checks both untrusted method fields and both untrusted tool-name fields before cross-field correlation, derives one of the existing typed `ActionKind` values from a deterministic reviewed registry, exposes discovery metadata from that same registry, and requires the resulting action to pass the ordinary OriginWeave policy evaluator. The method boundary accepts only nonempty ASCII method names up to 64 bytes using the reviewed routing alphabet, while the tool-name boundary accepts only nonempty ASCII names up to 128 bytes using its narrower reviewed alphabet. The catalog and validated route grant no capability, approval, origin, secret, browser, persistence, or evidence authority by themselves. -Active PR #170 is a separate non-shipped refinement on top of that protected-main catalog. It adds one conservative typed `tools/list` request/result contract: both protocol-version fields are required and bounded before comparison, client-capability metadata must be present without becoming authority, both routing/body methods are syntax-bounded before correlation, only exact `tools/list` is admitted, and every caller-supplied cursor is rejected because the current fixed catalog issues none. The result is one complete page with zero freshness, private cache scope, and no continuation cursor. +The merged PR #170 is a protected-main refinement on top of that catalog. It adds one conservative typed `tools/list` request/result contract: both protocol-version fields are required and bounded before comparison, client-capability metadata must be present without becoming authority, both routing/body methods are syntax-bounded before correlation, only exact `tools/list` is admitted, and every caller-supplied cursor is rejected because the current fixed catalog issues none. The result is one complete page with zero freshness, private cache scope, and no continuation cursor. -Neither protected main nor PR #170 implements Streamable HTTP transport parsing, JSON-RPC/HTTP serialization, OAuth, browser I/O, WebMCP/BiDi/CDP translation, secret delivery, persistence, general pagination/subscription state, or a complete OriginWeave Protocol adapter. Those remain separate adapter/runtime work. Protected `main` may therefore describe only the bounded merged `tools/call` foundation as implemented; the full MCP adapter remains planned, and the `tools/list` refinement remains active-PR evidence until separately integrated. +Neither protected main nor PR #170 implements Streamable HTTP transport parsing, JSON-RPC/HTTP serialization, OAuth, browser I/O, WebMCP/BiDi/CDP translation, secret delivery, persistence, general pagination/subscription state, or a complete OriginWeave Protocol adapter. Those remain separate adapter/runtime work. Protected `main` may therefore describe only the bounded merged `tools/call` and `tools/list` foundations as implemented; the full MCP adapter remains planned. -The version boundary is explicit: the protected-main routing foundation and active discovery refinement accept only MCP `2026-07-28`; neither infers compatibility with later protocol generations. OriginWeave Protocol versioning remains independent and cannot be changed by MCP metadata. +The version boundary is explicit: the protected-main routing foundation and merged discovery refinement accept only MCP `2026-07-28`; neither infers compatibility with later protocol generations. OriginWeave Protocol versioning remains independent and cannot be changed by MCP metadata. ## Consequences @@ -60,7 +60,7 @@ Protocol validation occurs before messages influence policy. Tool/page-provided Require version-negotiation tests, schema/property tests, malformed-message tests, BiDi/CDP semantic parity tests for shared capabilities, WebMCP prompt-injection tests, MCP authority-separation and version-change tests, browser-version compatibility matrices, and end-to-end proof that unsupported capabilities fail without side effects. -For the protected-main `tools/call` foundation, acceptance includes deterministic method and tool-name bounds/syntax, exact header/body method and tool-name correlation only after both sides are bounded, explicit invalid-method/invalid-tool-name/unknown-tool rejection, one unambiguous tool-to-action registry, independent capability/risk expectations, route/action mismatch denial before ordinary policy evaluation, exact 100% owned-production coverage, and integrated review evidence from PR #168. For active PR #170, exact-current acceptance additionally requires bounded protocol metadata before cross-field comparison, required client-capabilities presence, bounded `tools/list` method correlation, rejection of unissued cursors, deterministic result/cache semantics, exact 100% owned-production coverage, and unchanged-head CI/security/review evidence. These checks do not substitute for complete transport or adapter conformance. +For the protected-main `tools/call` foundation, acceptance includes deterministic method and tool-name bounds/syntax, exact header/body method and tool-name correlation only after both sides are bounded, explicit invalid-method/invalid-tool-name/unknown-tool rejection, one unambiguous tool-to-action registry, independent capability/risk expectations, route/action mismatch denial before ordinary policy evaluation, exact 100% owned-production coverage, and integrated review evidence from PR #168. The merged PR #170 discovery contract additionally requires bounded protocol metadata before cross-field comparison, required client-capabilities presence, bounded `tools/list` method correlation, rejection of unissued cursors, deterministic result/cache semantics, exact 100% owned-production coverage, and current-head acceptance evidence recorded at merge. These checks do not substitute for complete transport or adapter conformance. ## Migration and rollback diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 8a702c75f..32185d617 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,11 +2,11 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, architecture decisions, or live GitHub state. It keeps buyer-visible gaps, current issues, active pull-request evidence, and commercial completion tracks in one discoverable place. Protected `main` is the implementation boundary: code in an open pull request is not shipped behavior. -## Observed snapshot: 2026-08-26 +## Observed snapshot: 2026-08-28 ### Protected-main truth -- Protected `main` is at `b05d5acca82b9d916ada2c8e82f59f92a89817e1` for this snapshot. Since the 2026-08-24 observation (`0841d2ab`), protected `main` absorbed #196 (dated gap baseline publication), #216 (RFC 3986 evidence-path syntax enforcement), #194 (branch-coverage nightly and toolchain tracking refresh), #168 (typed MCP stateless tool-routing foundations), and #151 (exact crash-root termination before crash credit). +- Protected `main` is at `542ca1e9c0a863595b8b6697790005d2471f5413` for this snapshot. Since the 2026-08-26 observation (`b05d5acca82b9d916ada2c8e82f59f92a89817e1`), protected `main` absorbed #161 (TLS trust-bundle identifier shape). PR #170's conservative `tools/list` discovery contract is also merged into protected `main`; the complete MCP adapter remains planned. - Phase 0 remains complete as a reusable safety-kernel foundation: typed policy contracts, destination classification, direct TCP peer verification, TLS service identity, evidence bounds, resource mitigation, document-node authority, and protected-main tests. - Phase 1 is **in progress**, not shipped. The first real Chromium vertical slice still needs the active WebDriver BiDi transport stack to reach protected `main`, then compose isolated Chromium launch, session/context identity, semantic observation, typed action authorization, native browser input, post-condition proof, evidence, cancellation, crash recovery, and profile/process teardown. - HTTP/1.1 bounds, downloads/MIME, proxy/PAC consumption, full browser-network integration, the sensitive-data broker runtime, durable WARC/PROV capture, persistent task/API surfaces, signed cross-platform distribution, enterprise administration, and release-grade buyer acceptance remain open. @@ -14,9 +14,28 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a ### Open pull requests -The live repository contained **126 open pull requests: 54 non-draft and 72 draft** when this snapshot re-paginated the complete open inventory. Compared with the prior **2026-08-24 158-PR snapshot**, the current inventory is 32 PRs smaller. Intervening queue consolidation includes #190, #188, #185, #192, #182, #184, #115, #181, #116, #117, #118, #183, #114, #127, #112, #109, #186, #110, #108, #111, #174, and #113 being merged into their immediate stacked prerequisites, while PRs #147, #146, #145, #144, #143, #142, #141, #139, #136, #132, #129, and #128 moved to ready after exact-head checks and thread review. Those transitions are queue consolidation, not protected-main delivery; protected `main` remains `b05d5acca82b9d916ada2c8e82f59f92a89817e1`, with 13 open issues and no releases or tags. The volume and stack depth remain themselves a product-delivery risk: review, exact-head checks, dependency order, and integration truth can drift faster than a buyer-visible vertical slice reaches protected `main`. +The live repository contained **114 open pull requests: 30 non-draft and 84 draft** when this snapshot re-paginated the complete open inventory. Compared with the prior **2026-08-26 126-PR snapshot**, the current inventory is 12 PRs smaller. These counts are queue evidence, not protected-main delivery; protected `main` remains `542ca1e9c0a863595b8b6697790005d2471f5413`, with 11 open issues and no releases or tags. The volume and stack depth remain themselves a product-delivery risk: review, exact-head checks, dependency order, and integration truth can drift faster than a buyer-visible vertical slice reaches protected `main`. -#### 2026-08-26 maintenance-loop record +#### 2026-08-28 maintenance-loop record + +This snapshot re-fetched the complete open-PR inventory, the protected `main` commit, the active required-workflow ruleset, collaborator permissions, and the exact base/head pair for each representative PR. The active ruleset still requires one counted approving review and resolved threads; the only repository collaborator is `seonghobae`, so review provisioning remains the merge blocker. PR #170 is merged and is not active-PR evidence. + +#### Current exact-head active PR evidence + +The following representative slices were re-fetched from GitHub for this snapshot. Their exact base/head pairs are recorded so later checks, reviews, and restacks cannot be confused with predecessor evidence: + +| PR | State | Exact base head | Exact head | +|---|---|---|---| +| #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `8c5fc6a92e8a19e9b304c84b3517d1ff8711d379` | +| #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fb868589d065c2cea0b9c8c0f5e655a89f42bee6` | +| #220 | Ready | `f658f329c83a106b68385e17cb714c4147c12f49` | `a2b0c5372dd6df803011933836c56136244dc8af` | +| #211 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `52a918577958a5701e1146c7eb8b62fe8f8ccd44` | +| #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | `72f112d52a60e7caa992a3f5ff7f16d5d9a4d047` | +| #124 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `028789d8bb6cc30b8e84b1ba7ed46556b26e75ea` | + +These rows are delivery evidence only. None has counted independent approval in the current collaborator inventory. + +#### Historical 2026-08-26 maintenance-loop record The interactive maintenance loop performed the following verified state changes on exact heads; none of them is protected-main behavior until merged: @@ -38,12 +57,12 @@ Representative active workstreams at this snapshot were: | Workstream | Representative active PR evidence | Delivery boundary | |---|---|---| | Product baseline | (merged: #196 on 2026-08-24) | Baseline publication reached protected `main`; this document is its successor snapshot | -| Presentation identity | #229 at `585a7d5545b13f18d76f79100ff4d47ac423e861` onto `b05d5acca82b9d916ada2c8e82f59f92a89817e1` | Ready/non-draft local privacy kernel; all observed exact-head checks except Strix passed, but the PR remains blocked and review-required, and no Chromium adapter or protected-main shipment is claimed | -| Enterprise approval authority | #220 | Ready/non-draft bounded maker-checker approval lifecycle on the exact `ApprovalScope`; all current-head checks green at snapshot, awaiting current-head review evidence | +| Presentation identity | #229 at `fb868589d065c2cea0b9c8c0f5e655a89f42bee6` onto `542ca1e9c0a863595b8b6697790005d2471f5413` | Ready/non-draft local privacy kernel; current required checks include a failed Strix run, and the PR remains blocked without counted approval; no protected-main shipment is claimed | +| Enterprise approval authority | #220 at `a2b0c5372dd6df803011933836c56136244dc8af` onto base `f658f329c83a106b68385e17cb714c4147c12f49` | Ready/non-draft bounded maker-checker approval lifecycle on the exact `ApprovalScope`; current checks are green except the latest failed Strix run, with changes requested and no counted approval | | Release artifact identity | #218 and #219 | Ready/non-draft fail-closed benchmark release decision and canonical release manifest binding; Strix provider-failure reruns completed green on both heads | | Schema-bound extraction and BAP lifecycle | #209 and #208 | Ready/non-draft schema-bound extraction contract and resumable task-lifecycle kernel; #209 Strix rerun green, #208 rerun re-dispatched after a further provider failure | | WebDriver BiDi transport | #188 through #205 | Active stack whose top #205 merged into its prerequisite branch, not protected `main`; it exercises framed `locateNodes` exchange over a bounded WebSocket opening path, but authenticated browser-process provenance, semantic task execution, and protected-main shipment remain unproven | -| MCP adapter | (#168 merged) and #170 | Typed MCP routing foundations are protected-main behavior since 2026-08-24; conservative `tools/list` cache metadata remains active-PR evidence with a Strix rerun in flight | +| MCP adapter | (#168 and #170 merged) | Typed MCP routing and conservative `tools/list` cache metadata are protected-main behavior; the complete MCP transport, OAuth, browser I/O, and persistence adapter remains planned | | Workflow-registry audit | #124 | Real Strix finding vuln-0001 (Unicode homoglyph path confusion, MEDIUM) remediated on head `30cc458b` with regression contract tests; fresh exact-head checks and review re-running | | Controlled Chromium and recovery | #65, #70-#73, #100, #105, #142-#152 and descendants | Real pinned-browser fixture, semantic location, resource, crash, and teardown evidence exists on active stacks; evidence does not transfer across heads or prerequisites | | Durable WARC/PROV evidence | #210, #217 | Bounded WARC resource records and PROV JSON-LD binding are draft active-PR foundations; durable ownership, replay, retention/deletion, and browser side-effect reconciliation remain open | @@ -51,9 +70,9 @@ Representative active workstreams at this snapshot were: | Sensitive-data and model route policy | #10 and its active policy stacks | Deterministic policy values exist, but trusted broker execution, retention/deletion, runtime isolation, and auditable product workflows remain open | | VPN/profile intent | #149 | Bounded WireGuard/IKEv2 profile authority reconciled with main (`54f96008`); it does not create a tunnel, route, DNS state, authenticated gateway, or connectivity proof | -PR #205 head `f427aa69151987d7e3369bd96d5739ea38d0f7ad` merged as `6c5ef5e2079d54c617183ecfa757e406f48f0aea` into stacked prerequisite branch `feat/webdriver-bidi-websocket-frame-transport` at base `c1bc7e78f3a9debf4f517fb6b5f11dd67be4ad92`. Its successful exact-head checks are stacked-branch integration evidence only; protected `main` remains `b05d5acca82b9d916ada2c8e82f59f92a89817e1`. +PR #205 head `f427aa69151987d7e3369bd96d5739ea38d0f7ad` merged as `6c5ef5e2079d54c617183ecfa757e406f48f0aea` into stacked prerequisite branch `feat/webdriver-bidi-websocket-frame-transport` at base `c1bc7e78f3a9debf4f517fb6b5f11dd67be4ad92`. Its successful exact-head checks are stacked-branch integration evidence only; the current protected `main` is `542ca1e9c0a863595b8b6697790005d2471f5413`. -#### Current exact-head active PR evidence +#### Historical exact-head active PR evidence: 2026-08-26 The following newest slices were re-fetched from GitHub for this snapshot. Their exact base/head pairs are recorded so later checks, reviews, and restacks cannot be confused with predecessor evidence: @@ -68,7 +87,7 @@ The following newest slices were re-fetched from GitHub for this snapshot. Their These rows are delivery evidence only. None has counted independent approval in the current collaborator inventory, and predecessor rows from earlier snapshots are retained below as regression anchors that must never be promoted to current-head evidence. -#### Regression-anchor exact-head evidence: superseded 2026-08-24 rows +#### Historical regression-anchor exact-head evidence: superseded 2026-08-24 rows The following rows were current on 2026-08-24 and are retained only as regression anchors; every listed head has since been superseded or merged and must never be promoted to current-head evidence: @@ -148,7 +167,7 @@ The hourly product-development loop is operational infrastructure, not proof tha | P1 | Buyers can install, update, verify, and roll back a supported product | **Not shipped** | #201; signed Windows/macOS/Linux/headless artifacts, Chromium revision manifest, updater security, patch SLA, SBOM, SLSA provenance, and recovery | | P1 | Enterprise teams can provision, approve, audit, operate, and recover the service | **Not shipped** | #202; Keyverse-compatible OIDC/SCIM, tenant isolation, policy/approval/evidence UI, SLO/incident controls, data residency, CSAP/SOC 2 evidence mapping, WCAG 2.2, Figma File ID, and Storybook | | P0 | A release has reproducible proof of usefulness, safety, evidence completeness, and recovery | **No product-wide release gate** | #203; deterministic, compatibility, adversarial, recovery, and enterprise suites with statistical reporting and an exact-artifact commercial acceptance gate | -| P0 | Valid changes reach protected `main` without authority improvisation or unbounded stack growth | **Blocked / high integration debt** | Shrink the 126-PR queue in dependency order, provision legitimate review authority, require exact-current evidence, and close duplicates/superseded branches | +| P0 | Valid changes reach protected `main` without authority improvisation or unbounded stack growth | **Blocked / high integration debt** | Shrink the 114-PR queue in dependency order, provision legitimate review authority, require exact-current evidence, and close duplicates/superseded branches | ## Commercial completion definition @@ -167,7 +186,7 @@ OriginWeave is not complete merely because every low-level primitive exists in s ## Next executable queue -1. Drain the merge gate in dependency order: for every ready root PR whose current head is check-green with resolved threads, obtain the current ruleset's counted `APPROVED` review from an eligible non-author collaborator; OpenCode approval or skip evidence does not substitute for that GitHub review. If no eligible approver exists, record the reviewer-provisioning gap and do not merge. Root candidates include #37, #40, #43, #45–#48, #51, #62–#65, #74, #82, #124, #149, #152, #156–#166, #170, #173, #175, #208, #209, #218, and #219 as their re-dispatched checks land. Treat dependent children separately: only after a predecessor reaches protected `main`, retarget and independently revalidate its immediate child; preserve orders such as #218 → #221 → #220 rather than treating #208–#220 as a flat merge range. +1. Drain the merge gate in dependency order: for every ready root PR whose current head is check-green with resolved threads, obtain the current ruleset's counted `APPROVED` review from an eligible non-author collaborator; OpenCode approval or skip evidence does not substitute for that GitHub review. If no eligible approver exists, record the reviewer-provisioning gap and do not merge. Root candidates include #37, #40, #43, #45–#48, #51, #62–#65, #74, #82, #124, #149, #152, #156–#166, #173, #175, #208, #209, #211, #218, #219, #229, and #237 as their current checks land. Treat dependent children separately: only after a predecessor reaches protected `main`, retarget and independently revalidate its immediate child; preserve orders such as #218 → #221 → #220 rather than treating #208–#220 as a flat merge range. 2. Keep the organization review pipeline healthy: monitor the central Actions backlog recorded above; if OpenCode reviews stop landing on OriginWeave heads while the queue is idle, repair `ContextualWisdomLab/.github` dispatch/concurrency configuration rather than weakening any gate. 3. Finish the #9/#28 browser-network and Chromium vertical slice, including the #181–#205 WebSocket opening path and framed BiDi command/response stack, then semantic observation, policy, action, post-condition, and recovery boundaries on protected `main`. 4. Finish #27 and #10 as separate security tracks; neither should be hidden inside the first browser PR. diff --git a/docs/traceability/mcp-authority-route.md b/docs/traceability/mcp-authority-route.md index 94f181ed4..71b3b527a 100644 --- a/docs/traceability/mcp-authority-route.md +++ b/docs/traceability/mcp-authority-route.md @@ -1,25 +1,25 @@ # MCP 2026-07-28 authority-route traceability - **`tools/call` capability maturity:** `IMPLEMENTED_ON_PROTECTED_MAIN` -- **`tools/list` capability maturity:** `IMPLEMENTED_ON_ACTIVE_PR` +- **`tools/list` capability maturity:** `IMPLEMENTED_ON_PROTECTED_MAIN` - **Protected-main owning work:** merged PR #168 `feat(mcp): bind stateless tool routing to typed actions` -- **Active follow-on:** PR #170 `feat(mcp): expose conservative tools list cache contract` +- **Discovery refinement:** merged PR #170 `feat(mcp): expose conservative tools list cache contract` - **Complete MCP adapter status:** `PLANNED` - **Governing decision:** ADR 0107 ## Scope -Protected main at `b05d5acca82b9d916ada2c8e82f59f92a89817e1` contains the bounded Rust control-plane foundation for MCP `2026-07-28` `tools/call` routing that merged through PR #168. It validates the represented stateless routing envelope, bounds and syntax-validates both attacker-controlled method fields and both attacker-controlled tool-name fields before correlation, maps only an explicit reviewed `originweave.*` catalog to existing typed `ActionKind` values, derives discovery metadata from the same catalog, and rejects route/action mismatch before ordinary deterministic policy evaluation. Methods are nonempty reviewed-ASCII routing tokens of at most 64 bytes; tool names are nonempty reviewed-ASCII identifiers of at most 128 bytes. Invalid method metadata is rejected distinctly from a bounded but unsupported MCP method. +Protected main at `542ca1e9c0a863595b8b6697790005d2471f5413` contains the bounded Rust control-plane foundation for MCP `2026-07-28` `tools/call` routing that merged through PR #168. It validates the represented stateless routing envelope, bounds and syntax-validates both attacker-controlled method fields and both attacker-controlled tool-name fields before correlation, maps only an explicit reviewed `originweave.*` catalog to existing typed `ActionKind` values, derives discovery metadata from the same catalog, and rejects route/action mismatch before ordinary deterministic policy evaluation. Methods are nonempty reviewed-ASCII routing tokens of at most 64 bytes; tool names are nonempty reviewed-ASCII identifiers of at most 128 bytes. Invalid method metadata is rejected distinctly from a bounded but unsupported MCP method. A successful `ValidatedMcpToolCall` proves routing integrity only. It grants no capability, origin, approval, secret, browser, tenant, persistence, network, or evidence authority. `originweave_policy::evaluate_mcp` still delegates to the ordinary policy evaluator after the route/action match. -Active PR #170 builds on that protected-main catalog with a conservative typed `tools/list` request/result boundary. Its current branch requires matching MCP protocol metadata, required client-capability presence, bounded and syntax-validated routing/body methods, exact `tools/list` routing, and no caller-supplied cursor because the fixed catalog issues none. Its result is one complete page with zero freshness, private cache scope, and no continuation cursor. This active-PR slice remains non-shipped until it reaches protected main and does not grant any OriginWeave action authority. +The merged PR #170 adds a conservative typed `tools/list` request/result boundary to that protected-main catalog. It requires matching MCP protocol metadata, required client-capability presence, bounded and syntax-validated routing/body methods, exact `tools/list` routing, and no caller-supplied cursor because the fixed catalog issues none. Its result is one complete page with zero freshness, private cache scope, and no continuation cursor. It does not grant any OriginWeave action authority. ## Product-status reconciliation -`docs/PRD.md` PRD-INT-004 and `docs/TRD.md` Section 12 intentionally remain **Planned** at the complete-adapter level. That status is not contradicted by the bounded `tools/call` foundation now on protected main or by active PR #170: both are reusable control-plane contracts below the complete product adapter. `README.md` and `CHANGELOG.md` distinguish protected-main routing from the active discovery refinement, and ADR 0107 records the protocol/version and authority boundary. +`docs/PRD.md` PRD-INT-004 and `docs/TRD.md` Section 12 intentionally remain **Planned** at the complete-adapter level. That status is not contradicted by the bounded `tools/call` and `tools/list` foundations now on protected main: both are reusable control-plane contracts below the complete product adapter. `README.md` and `CHANGELOG.md` distinguish protected-main routing/discovery from the still-planned complete adapter, and ADR 0107 records the protocol/version and authority boundary. -The following remain outside protected main and PR #170 and must not be inferred from either: +The following remain outside protected main and PR #170 and must not be inferred from either foundation: - Streamable HTTP transport parsing and header materialization; - JSON-RPC/HTTP response serialization of the typed discovery page; @@ -32,7 +32,7 @@ The following remain outside protected main and PR #170 and must not be inferred ## Version boundary -The protected-main routing foundation and active discovery refinement accept only protocol generation `2026-07-28`. MCP versioning is independent of the OriginWeave Protocol. A later MCP revision does not silently change OriginWeave action, risk, capability, approval, secret, origin, tenant, browser, or evidence semantics. +The protected-main routing foundation and merged discovery refinement accept only protocol generation `2026-07-28`. MCP versioning is independent of the OriginWeave Protocol. A later MCP revision does not silently change OriginWeave action, risk, capability, approval, secret, origin, tenant, browser, or evidence semantics. The reviewed primary source is: @@ -49,10 +49,10 @@ Protected-main PR #168 production/test surfaces include: - `crates/originweave-policy/src/lib.rs` — `evaluate_mcp` route/action guard before normal policy evaluation; and - `crates/originweave-policy/tests/mcp_route_binding.rs` — confused-deputy and policy-preservation evidence. -Active PR #170 additionally exercises its discovery contract in `crates/originweave-core/tests/mcp_tools_list_cache.rs`, including result/cache semantics, required protocol/client metadata, bounded protocol and method validation, routing correlation, cursor rejection, and public error contracts. +PR #170's merged discovery contract is exercised in `crates/originweave-core/tests/mcp_tools_list_cache.rs`, including result/cache semantics, required protocol/client metadata, bounded protocol and method validation, routing correlation, cursor rejection, and public error contracts. -Exact current-head CI/security/review evidence must be regenerated after every branch mutation. Protected-main evidence proves only the merged `tools/call` foundation; predecessor or protected-main results are not current-head proof for active PR #170. +Exact current-head CI/security/review evidence must be regenerated after every branch mutation. Protected-main evidence proves only the merged typed routing/discovery foundations, not the complete adapter. ## Promotion rule -The bounded `tools/call` routing foundation is already `IMPLEMENTED_ON_PROTECTED_MAIN`. The `tools/list` discovery refinement may change to `IMPLEMENTED_ON_PROTECTED_MAIN` only after PR #170 reaches protected `main` under live governance and exact-head acceptance. Neither promotion makes the complete MCP adapter implemented; each remaining transport/runtime boundary requires its own integrated evidence. +The bounded `tools/call` routing foundation and `tools/list` discovery refinement are `IMPLEMENTED_ON_PROTECTED_MAIN` through PRs #168 and #170. Neither makes the complete MCP adapter implemented; each remaining transport/runtime boundary requires its own integrated evidence. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index bc60535a2..bdcbaa8f5 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -37,12 +37,12 @@ def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> No """The baseline must preserve exact heads for the newest active product slices.""" for marker in ( "Current exact-head active PR evidence", - "| #220 | Ready | `b05d5acca82b9d916ada2c8e82f59f92a89817e1` | `e0740a6f3a41067a4460249378e0266815018a74` |", - "| #219 | Ready | `b05d5acca82b9d916ada2c8e82f59f92a89817e1` | `3e34a54ae279686a28309d59b8b3b9bfbd283a80` |", - "| #218 | Ready | `b05d5acca82b9d916ada2c8e82f59f92a89817e1` | `911ea33d8a5aca7673307bb6fdcad4b450f5c111` |", - "| #209 | Ready | `b05d5acca82b9d916ada2c8e82f59f92a89817e1` | `b35d739017aa5d361b605be48045be50b5a35f6f` |", - "| #208 | Ready | `b05d5acca82b9d916ada2c8e82f59f92a89817e1` | `e41d3be4c290c4e434aac33d777e511dfb94e03d` |", - "| #124 | Ready | `b05d5acca82b9d916ada2c8e82f59f92a89817e1` | `296ad25bb541023dbc869ae07ae1d853820f83a4` |", + "| #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `8c5fc6a92e8a19e9b304c84b3517d1ff8711d379` |", + "| #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fb868589d065c2cea0b9c8c0f5e655a89f42bee6` |", + "| #220 | Ready | `f658f329c83a106b68385e17cb714c4147c12f49` | `a2b0c5372dd6df803011933836c56136244dc8af` |", + "| #211 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `52a918577958a5701e1146c7eb8b62fe8f8ccd44` |", + "| #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | `72f112d52a60e7caa992a3f5ff7f16d5d9a4d047` |", + "| #124 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `028789d8bb6cc30b8e84b1ba7ed46556b26e75ea` |", ): with self.subTest(marker=marker): self.assertIn(marker, self.baseline) @@ -54,7 +54,8 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: changed = self.changelog.split("### Changed", 1)[1].split("### Security", 1)[0] self.assertIn(refresh, added) self.assertNotIn(refresh, changed) - self.assertIn("126 open pull requests (54 ready, 72 draft)", self.changelog) + self.assertIn("114 open pull requests (30 ready, 84 draft)", self.changelog) + self.assertNotIn("126 open pull requests (54 ready, 72 draft)", added) self.assertNotIn("128 open pull requests (54 ready, 74 draft)", added) self.assertNotIn("153 open pull requests (39 ready, 114 draft)", added) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 0daca1f85..a417a926d 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -20,21 +20,23 @@ def setUpClass(cls) -> None: cls.changelog = CHANGELOG.read_text(encoding="utf-8") def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: - """The current snapshot must use the exact 126/54/72 inventory observation.""" + """The current snapshot must use the exact 114/30/84 inventory observation.""" current = self.baseline.split("### Open pull requests", 1)[1].split( - "#### 2026-08-26 maintenance-loop record", 1 + "#### 2026-08-28 maintenance-loop record", 1 )[0] for marker in ( - "126 open pull requests", - "54 non-draft", - "72 draft", + "114 open pull requests", + "30 non-draft", + "84 draft", ): with self.subTest(marker=marker): self.assertIn(marker, current) for stale in ( "128 open pull requests", - "74 draft", + "126 open pull requests", + "54 non-draft", + "72 draft", "153 open pull requests", "114 draft", ): @@ -47,11 +49,11 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "126 open pull requests (54 ready, 72 draft)" + expected = "114 open pull requests (30 ready, 84 draft)" self.assertIn(expected, preamble) self.assertIn(expected, added) - self.assertNotIn("128 open pull requests (54 ready, 74 draft)", preamble) - self.assertNotIn("153 open pull requests (39 ready, 114 draft)", added) + self.assertNotIn("126 open pull requests (54 ready, 72 draft)", preamble) + self.assertNotIn("126 open pull requests (54 ready, 72 draft)", added) if __name__ == "__main__": diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 1c24fe674..4ce0aca5e 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -15,12 +15,15 @@ class ProductCompletionGapContractTests(unittest.TestCase): def test_baseline_records_current_inventory_and_completion_issues(self) -> None: """The dated baseline must not retain superseded queue counts or omit buyer tracks.""" text = BASELINE.read_text(encoding="utf-8") + current = text.split("## Observed snapshot: ", 1)[1].split( + "#### 2026-08-28 maintenance-loop record", 1 + )[0] for phrase in ( - "126 open pull requests", - "54 non-draft", - "72 draft", - "2026-08-24 158-PR snapshot", + "114 open pull requests", + "30 non-draft", + "84 draft", + "2026-08-26 126-PR snapshot", "#198", "#199", "#200", @@ -34,7 +37,7 @@ def test_baseline_records_current_inventory_and_completion_issues(self) -> None: "commercial acceptance gate", ): with self.subTest(phrase=phrase): - self.assertIn(phrase, text) + self.assertIn(phrase, current if "pull requests" in phrase or "draft" in phrase else text) for stale_phrase in ( "100 open pull requests", @@ -50,7 +53,7 @@ def test_baseline_records_current_inventory_and_completion_issues(self) -> None: "74 draft", ): with self.subTest(stale_phrase=stale_phrase): - self.assertNotIn(stale_phrase, text) + self.assertNotIn(stale_phrase, current) def test_active_github_approval_rule_is_not_documented_as_bypassable(self) -> None: """An active counted-approval rule must stop merge without an eligible approver.""" diff --git a/tests/test_product_documentation_contract.py b/tests/test_product_documentation_contract.py index f192aaa4d..5597b7caf 100644 --- a/tests/test_product_documentation_contract.py +++ b/tests/test_product_documentation_contract.py @@ -44,7 +44,7 @@ def test_product_technical_gap_baseline_records_live_delivery_state(self) -> Non self.assertTrue(baseline.is_file()) text = baseline.read_text(encoding="utf-8") for phrase in ( - "Observed snapshot: 2026-08-26", + "Observed snapshot: 2026-08-28", "Protected-main truth", "Open pull requests", "Open issues", From 8efb69ad0eaf068526067d73ca417a7ec9f0139e Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 11:15:59 +0900 Subject: [PATCH 002/250] docs: refresh live queue after PR publication --- CHANGELOG.md | 4 ++-- docs/product-technical-gap-baseline.md | 7 ++++--- .../test_documentation_active_pr_evidence_contract.py | 4 +++- tests/test_gap_snapshot_inventory_consistency.py | 11 +++++++---- tests/test_product_completion_gap_contract.py | 8 +++++--- 5 files changed, 21 insertions(+), 13 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index fe543ea74..ca1633898 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,10 +4,10 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] -- Refreshed the product-gap queue to 114 open pull requests (30 ready, 84 draft) on 2026-08-28; these are queue evidence, not protected-main shipment. +- Refreshed the product-gap queue to 115 open pull requests (31 ready, 84 draft) on 2026-08-28; these are queue evidence, not protected-main shipment. ### Added -- Corrected the 2026-08-28 product-gap snapshot with protected-main `542ca1e9`, 114 open pull requests (30 ready, 84 draft), 11 open issues, current exact base/head pairs for representative PRs, PR #170's merged `tools/list` contract, the active counted-approval gate, and the unchanged Phase 1 browser gap. +- Corrected the 2026-08-28 product-gap snapshot with protected-main `542ca1e9`, 115 open pull requests (31 ready, 84 draft), 11 open issues, current exact base/head pairs for representative PRs including #37, PR #170's merged `tools/list` contract, the active counted-approval gate, and the unchanged Phase 1 browser gap. - Refreshed the product and technical gap baseline onto the 2026-08-28 live inventory; current queue and exact-head evidence are explicitly separated from the historical 2026-08-26 snapshot so stale delivery evidence cannot be promoted. - Added `originweave_core::release_acceptance`, a deterministic fail-closed benchmark release-decision contract that requires one authoritative result for every mandatory suite, bounds explicit buyer-visible limitations, rejects duplicate limitation claim identities, and rejects non-canonical surrounding whitespace rather than normalizing it into an alternate claim spelling. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 32185d617..e079a29e6 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -14,7 +14,7 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a ### Open pull requests -The live repository contained **114 open pull requests: 30 non-draft and 84 draft** when this snapshot re-paginated the complete open inventory. Compared with the prior **2026-08-26 126-PR snapshot**, the current inventory is 12 PRs smaller. These counts are queue evidence, not protected-main delivery; protected `main` remains `542ca1e9c0a863595b8b6697790005d2471f5413`, with 11 open issues and no releases or tags. The volume and stack depth remain themselves a product-delivery risk: review, exact-head checks, dependency order, and integration truth can drift faster than a buyer-visible vertical slice reaches protected `main`. +The live repository contained **115 open pull requests: 31 non-draft and 84 draft** when this snapshot re-paginated the complete open inventory. Compared with the prior **2026-08-28 114-PR snapshot**, the current inventory is one PR larger. These counts are queue evidence, not protected-main delivery; protected `main` remains `542ca1e9c0a863595b8b6697790005d2471f5413`, with 11 open issues and no releases or tags. The volume and stack depth remain themselves a product-delivery risk: review, exact-head checks, dependency order, and integration truth can drift faster than a buyer-visible vertical slice reaches protected `main`. #### 2026-08-28 maintenance-loop record @@ -32,6 +32,7 @@ The following representative slices were re-fetched from GitHub for this snapsho | #211 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `52a918577958a5701e1146c7eb8b62fe8f8ccd44` | | #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | `72f112d52a60e7caa992a3f5ff7f16d5d9a4d047` | | #124 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `028789d8bb6cc30b8e84b1ba7ed46556b26e75ea` | +| #37 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `5423803d3fbd9d2d8e08bbd6dbf81ae6b2addefe` | These rows are delivery evidence only. None has counted independent approval in the current collaborator inventory. @@ -167,7 +168,7 @@ The hourly product-development loop is operational infrastructure, not proof tha | P1 | Buyers can install, update, verify, and roll back a supported product | **Not shipped** | #201; signed Windows/macOS/Linux/headless artifacts, Chromium revision manifest, updater security, patch SLA, SBOM, SLSA provenance, and recovery | | P1 | Enterprise teams can provision, approve, audit, operate, and recover the service | **Not shipped** | #202; Keyverse-compatible OIDC/SCIM, tenant isolation, policy/approval/evidence UI, SLO/incident controls, data residency, CSAP/SOC 2 evidence mapping, WCAG 2.2, Figma File ID, and Storybook | | P0 | A release has reproducible proof of usefulness, safety, evidence completeness, and recovery | **No product-wide release gate** | #203; deterministic, compatibility, adversarial, recovery, and enterprise suites with statistical reporting and an exact-artifact commercial acceptance gate | -| P0 | Valid changes reach protected `main` without authority improvisation or unbounded stack growth | **Blocked / high integration debt** | Shrink the 114-PR queue in dependency order, provision legitimate review authority, require exact-current evidence, and close duplicates/superseded branches | +| P0 | Valid changes reach protected `main` without authority improvisation or unbounded stack growth | **Blocked / high integration debt** | Shrink the 115-PR queue in dependency order, provision legitimate review authority, require exact-current evidence, and close duplicates/superseded branches | ## Commercial completion definition @@ -186,7 +187,7 @@ OriginWeave is not complete merely because every low-level primitive exists in s ## Next executable queue -1. Drain the merge gate in dependency order: for every ready root PR whose current head is check-green with resolved threads, obtain the current ruleset's counted `APPROVED` review from an eligible non-author collaborator; OpenCode approval or skip evidence does not substitute for that GitHub review. If no eligible approver exists, record the reviewer-provisioning gap and do not merge. Root candidates include #37, #40, #43, #45–#48, #51, #62–#65, #74, #82, #124, #149, #152, #156–#166, #173, #175, #208, #209, #211, #218, #219, #229, and #237 as their current checks land. Treat dependent children separately: only after a predecessor reaches protected `main`, retarget and independently revalidate its immediate child; preserve orders such as #218 → #221 → #220 rather than treating #208–#220 as a flat merge range. +1. Drain the merge gate in dependency order: for every ready root PR whose current head is check-green with resolved threads, obtain the current ruleset's counted `APPROVED` review from an eligible non-author collaborator; OpenCode approval or skip evidence does not substitute for that GitHub review. If no eligible approver exists, record the reviewer-provisioning gap and do not merge. Root candidates include #37, #40, #43, #45–#48, #51, #62–#65, #74, #82, #124, #149, #152, #156–#166, #173, #175, #208, #209, #211, #218, #219, #229, #237, and #238 as their current checks land. Treat dependent children separately: only after a predecessor reaches protected `main`, retarget and independently revalidate its immediate child; preserve orders such as #218 → #221 → #220 rather than treating #208–#220 as a flat merge range. 2. Keep the organization review pipeline healthy: monitor the central Actions backlog recorded above; if OpenCode reviews stop landing on OriginWeave heads while the queue is idle, repair `ContextualWisdomLab/.github` dispatch/concurrency configuration rather than weakening any gate. 3. Finish the #9/#28 browser-network and Chromium vertical slice, including the #181–#205 WebSocket opening path and framed BiDi command/response stack, then semantic observation, policy, action, post-condition, and recovery boundaries on protected `main`. 4. Finish #27 and #10 as separate security tracks; neither should be hidden inside the first browser PR. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index bdcbaa8f5..7d34e1351 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -43,6 +43,7 @@ def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> No "| #211 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `52a918577958a5701e1146c7eb8b62fe8f8ccd44` |", "| #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | `72f112d52a60e7caa992a3f5ff7f16d5d9a4d047` |", "| #124 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `028789d8bb6cc30b8e84b1ba7ed46556b26e75ea` |", + "| #37 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `5423803d3fbd9d2d8e08bbd6dbf81ae6b2addefe` |", ): with self.subTest(marker=marker): self.assertIn(marker, self.baseline) @@ -54,7 +55,8 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: changed = self.changelog.split("### Changed", 1)[1].split("### Security", 1)[0] self.assertIn(refresh, added) self.assertNotIn(refresh, changed) - self.assertIn("114 open pull requests (30 ready, 84 draft)", self.changelog) + self.assertIn("115 open pull requests (31 ready, 84 draft)", self.changelog) + self.assertNotIn("114 open pull requests (30 ready, 84 draft)", added) self.assertNotIn("126 open pull requests (54 ready, 72 draft)", added) self.assertNotIn("128 open pull requests (54 ready, 74 draft)", added) self.assertNotIn("153 open pull requests (39 ready, 114 draft)", added) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index a417a926d..d4816ca53 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -20,13 +20,13 @@ def setUpClass(cls) -> None: cls.changelog = CHANGELOG.read_text(encoding="utf-8") def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: - """The current snapshot must use the exact 114/30/84 inventory observation.""" + """The current snapshot must use the exact 115/31/84 inventory observation.""" current = self.baseline.split("### Open pull requests", 1)[1].split( "#### 2026-08-28 maintenance-loop record", 1 )[0] for marker in ( - "114 open pull requests", - "30 non-draft", + "115 open pull requests", + "31 non-draft", "84 draft", ): with self.subTest(marker=marker): @@ -37,6 +37,8 @@ def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: "126 open pull requests", "54 non-draft", "72 draft", + "114 open pull requests", + "30 non-draft", "153 open pull requests", "114 draft", ): @@ -49,10 +51,11 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "114 open pull requests (30 ready, 84 draft)" + expected = "115 open pull requests (31 ready, 84 draft)" self.assertIn(expected, preamble) self.assertIn(expected, added) self.assertNotIn("126 open pull requests (54 ready, 72 draft)", preamble) + self.assertNotIn("114 open pull requests (30 ready, 84 draft)", preamble) self.assertNotIn("126 open pull requests (54 ready, 72 draft)", added) diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 4ce0aca5e..720d2c295 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -20,10 +20,10 @@ def test_baseline_records_current_inventory_and_completion_issues(self) -> None: )[0] for phrase in ( - "114 open pull requests", - "30 non-draft", + "115 open pull requests", + "31 non-draft", "84 draft", - "2026-08-26 126-PR snapshot", + "2026-08-28 114-PR snapshot", "#198", "#199", "#200", @@ -51,6 +51,8 @@ def test_baseline_records_current_inventory_and_completion_issues(self) -> None: "prior 150-PR snapshot", "128 open pull requests", "74 draft", + "114 open pull requests", + "30 non-draft", ): with self.subTest(stale_phrase=stale_phrase): self.assertNotIn(stale_phrase, current) From b3b2c4994534529b971cd3751d17188a26b295b4 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 27 Aug 2026 19:22:10 -0700 Subject: [PATCH 003/250] test(docs): scope active snapshot evidence --- ...cumentation_active_pr_evidence_contract.py | 41 +++++++++++++------ 1 file changed, 29 insertions(+), 12 deletions(-) diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 7d34e1351..ea9e7b4b2 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -23,6 +23,16 @@ def active_pr_row(text: str, pr_number: int) -> str: return rows[0] +def bounded_section(text: str, start: str, end: str) -> str: + """Return one explicitly bounded documentation section, failing closed on drift.""" + if start not in text: + raise AssertionError(f"missing section start marker: {start}") + remainder = text.split(start, 1)[1] + if end not in remainder: + raise AssertionError(f"missing section end marker after {start}: {end}") + return remainder.split(end, 1)[0] + + class ActivePullRequestDocumentationContractTests(unittest.TestCase): """Keep volatile implementation evidence separate from protected-main truth.""" @@ -34,9 +44,13 @@ def setUpClass(cls) -> None: cls.changelog = CHANGELOG.read_text(encoding="utf-8") def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> None: - """The baseline must preserve exact heads for the newest active product slices.""" + """The current section must preserve exact heads for the newest active slices.""" + current = bounded_section( + self.baseline, + "#### Current exact-head active PR evidence", + "#### Historical 2026-08-26 maintenance-loop record", + ) for marker in ( - "Current exact-head active PR evidence", "| #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `8c5fc6a92e8a19e9b304c84b3517d1ff8711d379` |", "| #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fb868589d065c2cea0b9c8c0f5e655a89f42bee6` |", "| #220 | Ready | `f658f329c83a106b68385e17cb714c4147c12f49` | `a2b0c5372dd6df803011933836c56136244dc8af` |", @@ -46,20 +60,23 @@ def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> No "| #37 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `5423803d3fbd9d2d8e08bbd6dbf81ae6b2addefe` |", ): with self.subTest(marker=marker): - self.assertIn(marker, self.baseline) + self.assertIn(marker, current) def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: - """The changelog must classify and state the same baseline refresh.""" - refresh = "Refreshed the product and technical gap baseline with the current open-PR inventory" + """The current changelog refresh item must carry its own live queue evidence.""" added = self.changelog.split("### Added", 1)[1].split("### Changed", 1)[0] changed = self.changelog.split("### Changed", 1)[1].split("### Security", 1)[0] - self.assertIn(refresh, added) - self.assertNotIn(refresh, changed) - self.assertIn("115 open pull requests (31 ready, 84 draft)", self.changelog) - self.assertNotIn("114 open pull requests (30 ready, 84 draft)", added) - self.assertNotIn("126 open pull requests (54 ready, 72 draft)", added) - self.assertNotIn("128 open pull requests (54 ready, 74 draft)", added) - self.assertNotIn("153 open pull requests (39 ready, 114 draft)", added) + refresh_prefix = "- Corrected the 2026-08-28 product-gap snapshot" + refresh_lines = [line for line in added.splitlines() if line.startswith(refresh_prefix)] + self.assertEqual(1, len(refresh_lines)) + refresh_line = refresh_lines[0] + self.assertIn("115 open pull requests (31 ready, 84 draft)", refresh_line) + self.assertIn("11 open issues", refresh_line) + self.assertNotIn(refresh_prefix, changed) + self.assertNotIn("114 open pull requests (30 ready, 84 draft)", refresh_line) + self.assertNotIn("126 open pull requests (54 ready, 72 draft)", refresh_line) + self.assertNotIn("128 open pull requests (54 ready, 74 draft)", refresh_line) + self.assertNotIn("153 open pull requests (39 ready, 114 draft)", refresh_line) def test_dependency_stacks_are_explicit_and_non_shipped(self) -> None: """Current browser, network, sensitive and compatibility stacks stay active-only.""" From 9625854dbca9cc45a68dad4deeb16ecb487a67f3 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 27 Aug 2026 19:22:48 -0700 Subject: [PATCH 004/250] test(docs): fail closed on missing snapshot boundary --- tests/test_product_completion_gap_contract.py | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 720d2c295..852f068aa 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -15,9 +15,9 @@ class ProductCompletionGapContractTests(unittest.TestCase): def test_baseline_records_current_inventory_and_completion_issues(self) -> None: """The dated baseline must not retain superseded queue counts or omit buyer tracks.""" text = BASELINE.read_text(encoding="utf-8") - current = text.split("## Observed snapshot: ", 1)[1].split( - "#### 2026-08-28 maintenance-loop record", 1 - )[0] + end_marker = "#### 2026-08-28 maintenance-loop record" + self.assertIn(end_marker, text) + current = text.split("## Observed snapshot: ", 1)[1].split(end_marker, 1)[0] for phrase in ( "115 open pull requests", From 6e5c0af671c5b3435843bdbeab827baef8edabad Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 11:43:01 +0900 Subject: [PATCH 005/250] docs: reconcile gap snapshot counts --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 8 +++++--- tests/test_product_completion_gap_contract.py | 17 +++++++++++++++++ 3 files changed, 23 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index ca1633898..b6780a663 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Refreshed the product-gap queue to 115 open pull requests (31 ready, 84 draft) on 2026-08-28; these are queue evidence, not protected-main shipment. ### Added +- Clarified the 2026-08-28 gap snapshot's prior queue observation and separated open issues from governance signals. - Corrected the 2026-08-28 product-gap snapshot with protected-main `542ca1e9`, 115 open pull requests (31 ready, 84 draft), 11 open issues, current exact base/head pairs for representative PRs including #37, PR #170's merged `tools/list` contract, the active counted-approval gate, and the unchanged Phase 1 browser gap. - Refreshed the product and technical gap baseline onto the 2026-08-28 live inventory; current queue and exact-head evidence are explicitly separated from the historical 2026-08-26 snapshot so stale delivery evidence cannot be promoted. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e079a29e6..7cb461bf1 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -18,7 +18,7 @@ The live repository contained **115 open pull requests: 31 non-draft and 84 draf #### 2026-08-28 maintenance-loop record -This snapshot re-fetched the complete open-PR inventory, the protected `main` commit, the active required-workflow ruleset, collaborator permissions, and the exact base/head pair for each representative PR. The active ruleset still requires one counted approving review and resolved threads; the only repository collaborator is `seonghobae`, so review provisioning remains the merge blocker. PR #170 is merged and is not active-PR evidence. +This snapshot re-fetched the complete open-PR inventory, the protected `main` commit, the active required-workflow ruleset, collaborator permissions, and the exact base/head pair for each representative PR. Before PR #238 was published, the same maintenance loop observed 114 open pull requests (30 ready, 84 draft); the current re-paginated inventory is one PR larger. The active ruleset still requires one counted approving review and resolved threads; the only repository collaborator is `seonghobae`, so review provisioning remains the merge blocker. PR #170 is merged and is not active-PR evidence. #### Current exact-head active PR evidence @@ -131,9 +131,11 @@ The active `CWL Central required workflows` ruleset (re-fetched for this snapsho This gap does not authorize self-approval, stale-head merges, administrative bypass, or weaker checks. Because the current GitHub ruleset independently requires a counted approval, the solo-maintainer hold does not satisfy the live merge gate: an eligible non-author collaborator must submit a formal `APPROVED` review on the current head. Until that reviewer-provisioning gap is repaired, protected-main merges stop even when exact-head checks, security gates, complete coverage, rustdoc/Clippy, threads, and AI-review evidence are otherwise complete. Before any merge decision, re-fetch the exact ruleset, collaborators, PR head/base, reviews, unresolved threads, and required checks; do not assume this dated observation remains current. -### Open issues and operational signals +### Open issues and governance signals -| Issue | Current gap or signal | +This snapshot contains 11 open issues plus 2 governance signals, for the 13 rows below. Governance signals remain visible because they affect delivery authority but are not counted as product or operational issues. + +| Issue or signal | Current gap or signal | |---|---| | #28 | First real Chromium Agent Task vertical slice; highest immediate Phase 1 buyer-visible gap | | #27 | Complete Manifest V3 compatibility and extension-authority isolation matrix | diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 852f068aa..28fc9fb8e 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -65,6 +65,23 @@ def test_active_github_approval_rule_is_not_documented_as_bypassable(self) -> No self.assertIn("reviewer-provisioning gap", text) self.assertNotIn("owner-directed administrative merge", text) + def test_same_day_prior_inventory_is_bound_to_the_maintenance_record(self) -> None: + """A same-day comparison must retain its exact prior observation in the record.""" + text = BASELINE.read_text(encoding="utf-8") + record = text.split("#### 2026-08-28 maintenance-loop record", 1)[1].split( + "#### Current exact-head active PR evidence", 1 + )[0] + self.assertIn("114 open pull requests (30 ready, 84 draft)", record) + + def test_issue_table_distinguishes_open_issues_from_governance_signals(self) -> None: + """The table total must distinguish product issues from governance signals.""" + text = BASELINE.read_text(encoding="utf-8") + table = text.split("### Open issues and governance signals", 1)[1].split( + "## Buyer-visible and technical gap matrix", 1 + )[0] + self.assertIn("11 open issues plus 2 governance signals", table) + self.assertIn("Issue or signal", table) + def test_evidence_commands_reproduce_inventory_checks_and_review_state(self) -> None: """The evidence procedure must paginate the queue and inspect each exact PR head.""" text = BASELINE.read_text(encoding="utf-8") From 28648fcf276220317458efded210f60222a6165b Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 16:19:28 +0900 Subject: [PATCH 006/250] docs: refresh live gap baseline evidence --- CHANGELOG.md | 4 ++-- docs/product-technical-gap-baseline.md | 13 ++++++++----- ...st_documentation_active_pr_evidence_contract.py | 7 ++++--- tests/test_gap_snapshot_inventory_consistency.py | 14 +++++++------- tests/test_product_completion_gap_contract.py | 12 ++++++------ 5 files changed, 27 insertions(+), 23 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index b6780a663..b5542363e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,11 +4,11 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] -- Refreshed the product-gap queue to 115 open pull requests (31 ready, 84 draft) on 2026-08-28; these are queue evidence, not protected-main shipment. +- Refreshed the product-gap queue to 116 open pull requests (32 ready, 84 draft) on 2026-08-28; these are queue evidence, not protected-main shipment. ### Added - Clarified the 2026-08-28 gap snapshot's prior queue observation and separated open issues from governance signals. -- Corrected the 2026-08-28 product-gap snapshot with protected-main `542ca1e9`, 115 open pull requests (31 ready, 84 draft), 11 open issues, current exact base/head pairs for representative PRs including #37, PR #170's merged `tools/list` contract, the active counted-approval gate, and the unchanged Phase 1 browser gap. +- Corrected the 2026-08-28 product-gap snapshot with protected-main `542ca1e9`, 116 open pull requests (32 ready, 84 draft), 11 open issues, current exact base/head pairs for representative PRs including #37, #237, and #239, PR #170's merged `tools/list` contract, the active counted-approval gate, and the unchanged Phase 1 browser gap. - Refreshed the product and technical gap baseline onto the 2026-08-28 live inventory; current queue and exact-head evidence are explicitly separated from the historical 2026-08-26 snapshot so stale delivery evidence cannot be promoted. - Added `originweave_core::release_acceptance`, a deterministic fail-closed benchmark release-decision contract that requires one authoritative result for every mandatory suite, bounds explicit buyer-visible limitations, rejects duplicate limitation claim identities, and rejects non-canonical surrounding whitespace rather than normalizing it into an alternate claim spelling. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 7cb461bf1..83a8978d7 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -14,11 +14,13 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a ### Open pull requests -The live repository contained **115 open pull requests: 31 non-draft and 84 draft** when this snapshot re-paginated the complete open inventory. Compared with the prior **2026-08-28 114-PR snapshot**, the current inventory is one PR larger. These counts are queue evidence, not protected-main delivery; protected `main` remains `542ca1e9c0a863595b8b6697790005d2471f5413`, with 11 open issues and no releases or tags. The volume and stack depth remain themselves a product-delivery risk: review, exact-head checks, dependency order, and integration truth can drift faster than a buyer-visible vertical slice reaches protected `main`. +The live repository contained **116 open pull requests: 32 non-draft and 84 draft** when this snapshot re-paginated the complete open inventory. Compared with the prior **2026-08-28 115-PR snapshot**, the current inventory is one PR larger. These counts are queue evidence, not protected-main delivery; protected `main` remains `542ca1e9c0a863595b8b6697790005d2471f5413`, with 11 open issues and no releases or tags. The volume and stack depth remain themselves a product-delivery risk: review, exact-head checks, dependency order, and integration truth can drift faster than a buyer-visible vertical slice reaches protected `main`. #### 2026-08-28 maintenance-loop record -This snapshot re-fetched the complete open-PR inventory, the protected `main` commit, the active required-workflow ruleset, collaborator permissions, and the exact base/head pair for each representative PR. Before PR #238 was published, the same maintenance loop observed 114 open pull requests (30 ready, 84 draft); the current re-paginated inventory is one PR larger. The active ruleset still requires one counted approving review and resolved threads; the only repository collaborator is `seonghobae`, so review provisioning remains the merge blocker. PR #170 is merged and is not active-PR evidence. +This snapshot re-fetched the complete open-PR inventory, the protected `main` commit, the active required-workflow ruleset, collaborator permissions, and the exact base/head pair for each representative PR. Before PR #238 was published, the same maintenance loop observed 115 open pull requests (31 ready, 84 draft); the current re-paginated inventory is one PR larger. The active ruleset still requires one counted approving review and resolved threads; the only repository collaborator is `seonghobae`, so review provisioning remains the merge blocker. PR #170 is merged and is not active-PR evidence. + +The later exact-head recheck also recorded the WARC/PROV retention-lifecycle slice: #239 is Draft at `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` on #227 head `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0`, with its Rust contracts and production coverage checks successful, zero unresolved threads, and no counted approval. #237 is Draft at `21e9ad1e8da72c81f521152ea6739b088da230f7` on protected `main`; its deterministic contracts and coverage are successful, while exact-head `opencode-review` failed closed for the absent current-head verdict and `strix` remained in progress. Neither active branch is protected-main behavior. #### Current exact-head active PR evidence @@ -26,7 +28,8 @@ The following representative slices were re-fetched from GitHub for this snapsho | PR | State | Exact base head | Exact head | |---|---|---|---| -| #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `8c5fc6a92e8a19e9b304c84b3517d1ff8711d379` | +| #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `21e9ad1e8da72c81f521152ea6739b088da230f7` | +| #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` | | #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fb868589d065c2cea0b9c8c0f5e655a89f42bee6` | | #220 | Ready | `f658f329c83a106b68385e17cb714c4147c12f49` | `a2b0c5372dd6df803011933836c56136244dc8af` | | #211 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `52a918577958a5701e1146c7eb8b62fe8f8ccd44` | @@ -66,7 +69,7 @@ Representative active workstreams at this snapshot were: | MCP adapter | (#168 and #170 merged) | Typed MCP routing and conservative `tools/list` cache metadata are protected-main behavior; the complete MCP transport, OAuth, browser I/O, and persistence adapter remains planned | | Workflow-registry audit | #124 | Real Strix finding vuln-0001 (Unicode homoglyph path confusion, MEDIUM) remediated on head `30cc458b` with regression contract tests; fresh exact-head checks and review re-running | | Controlled Chromium and recovery | #65, #70-#73, #100, #105, #142-#152 and descendants | Real pinned-browser fixture, semantic location, resource, crash, and teardown evidence exists on active stacks; evidence does not transfer across heads or prerequisites | -| Durable WARC/PROV evidence | #210, #217 | Bounded WARC resource records and PROV JSON-LD binding are draft active-PR foundations; durable ownership, replay, retention/deletion, and browser side-effect reconciliation remain open | +| Durable WARC/PROV evidence | #210, #217, #239 | Bounded WARC resource records, PROV JSON-LD binding, and retention-lifecycle boundaries are draft active-PR foundations; durable ownership, replay, retention/deletion, and browser side-effect reconciliation remain open | | Manifest V3 and native messaging | #27, #43 governance remediation, and the extension/native-host stack including #154 and #169 | Compatibility and Agent-authority isolation remain incomplete until exact release artifacts and platform matrices are proven; #43's sandbox workflow mutation is now owner-authorized under issue #212 option (b) | | Sensitive-data and model route policy | #10 and its active policy stacks | Deterministic policy values exist, but trusted broker execution, retention/deletion, runtime isolation, and auditable product workflows remain open | | VPN/profile intent | #149 | Bounded WireGuard/IKEv2 profile authority reconciled with main (`54f96008`); it does not create a tunnel, route, DNS state, authenticated gateway, or connectivity proof | @@ -189,7 +192,7 @@ OriginWeave is not complete merely because every low-level primitive exists in s ## Next executable queue -1. Drain the merge gate in dependency order: for every ready root PR whose current head is check-green with resolved threads, obtain the current ruleset's counted `APPROVED` review from an eligible non-author collaborator; OpenCode approval or skip evidence does not substitute for that GitHub review. If no eligible approver exists, record the reviewer-provisioning gap and do not merge. Root candidates include #37, #40, #43, #45–#48, #51, #62–#65, #74, #82, #124, #149, #152, #156–#166, #173, #175, #208, #209, #211, #218, #219, #229, #237, and #238 as their current checks land. Treat dependent children separately: only after a predecessor reaches protected `main`, retarget and independently revalidate its immediate child; preserve orders such as #218 → #221 → #220 rather than treating #208–#220 as a flat merge range. +1. Drain the merge gate in dependency order: for every ready root PR whose current head is check-green with resolved threads, obtain the current ruleset's counted `APPROVED` review from an eligible non-author collaborator; OpenCode approval or skip evidence does not substitute for that GitHub review. If no eligible approver exists, record the reviewer-provisioning gap and do not merge. Root candidates include #37, #40, #43, #45–#48, #51, #62–#65, #74, #82, #124, #149, #152, #156–#166, #173, #175, #208, #209, #211, #218, #219, #229, #237, #238, and #239 as their current checks land. Treat dependent children separately: only after a predecessor reaches protected `main`, retarget and independently revalidate its immediate child; preserve orders such as #218 → #221 → #220 rather than treating #208–#220 as a flat merge range. 2. Keep the organization review pipeline healthy: monitor the central Actions backlog recorded above; if OpenCode reviews stop landing on OriginWeave heads while the queue is idle, repair `ContextualWisdomLab/.github` dispatch/concurrency configuration rather than weakening any gate. 3. Finish the #9/#28 browser-network and Chromium vertical slice, including the #181–#205 WebSocket opening path and framed BiDi command/response stack, then semantic observation, policy, action, post-condition, and recovery boundaries on protected `main`. 4. Finish #27 and #10 as separate security tracks; neither should be hidden inside the first browser PR. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index ea9e7b4b2..61fa04a2b 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -51,7 +51,8 @@ def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> No "#### Historical 2026-08-26 maintenance-loop record", ) for marker in ( - "| #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `8c5fc6a92e8a19e9b304c84b3517d1ff8711d379` |", + "| #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `21e9ad1e8da72c81f521152ea6739b088da230f7` |", + "| #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` |", "| #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fb868589d065c2cea0b9c8c0f5e655a89f42bee6` |", "| #220 | Ready | `f658f329c83a106b68385e17cb714c4147c12f49` | `a2b0c5372dd6df803011933836c56136244dc8af` |", "| #211 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `52a918577958a5701e1146c7eb8b62fe8f8ccd44` |", @@ -70,10 +71,10 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: refresh_lines = [line for line in added.splitlines() if line.startswith(refresh_prefix)] self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] - self.assertIn("115 open pull requests (31 ready, 84 draft)", refresh_line) + self.assertIn("116 open pull requests (32 ready, 84 draft)", refresh_line) self.assertIn("11 open issues", refresh_line) self.assertNotIn(refresh_prefix, changed) - self.assertNotIn("114 open pull requests (30 ready, 84 draft)", refresh_line) + self.assertNotIn("115 open pull requests (31 ready, 84 draft)", refresh_line) self.assertNotIn("126 open pull requests (54 ready, 72 draft)", refresh_line) self.assertNotIn("128 open pull requests (54 ready, 74 draft)", refresh_line) self.assertNotIn("153 open pull requests (39 ready, 114 draft)", refresh_line) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index d4816ca53..aa34e1e89 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -20,13 +20,13 @@ def setUpClass(cls) -> None: cls.changelog = CHANGELOG.read_text(encoding="utf-8") def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: - """The current snapshot must use the exact 115/31/84 inventory observation.""" + """The current snapshot must use the exact 116/32/84 inventory observation.""" current = self.baseline.split("### Open pull requests", 1)[1].split( "#### 2026-08-28 maintenance-loop record", 1 )[0] for marker in ( - "115 open pull requests", - "31 non-draft", + "116 open pull requests", + "32 non-draft", "84 draft", ): with self.subTest(marker=marker): @@ -37,8 +37,8 @@ def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: "126 open pull requests", "54 non-draft", "72 draft", - "114 open pull requests", - "30 non-draft", + "115 open pull requests", + "31 non-draft", "153 open pull requests", "114 draft", ): @@ -51,11 +51,11 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "115 open pull requests (31 ready, 84 draft)" + expected = "116 open pull requests (32 ready, 84 draft)" self.assertIn(expected, preamble) self.assertIn(expected, added) self.assertNotIn("126 open pull requests (54 ready, 72 draft)", preamble) - self.assertNotIn("114 open pull requests (30 ready, 84 draft)", preamble) + self.assertNotIn("115 open pull requests (31 ready, 84 draft)", preamble) self.assertNotIn("126 open pull requests (54 ready, 72 draft)", added) diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 28fc9fb8e..be471c30b 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -20,10 +20,10 @@ def test_baseline_records_current_inventory_and_completion_issues(self) -> None: current = text.split("## Observed snapshot: ", 1)[1].split(end_marker, 1)[0] for phrase in ( - "115 open pull requests", - "31 non-draft", + "116 open pull requests", + "32 non-draft", "84 draft", - "2026-08-28 114-PR snapshot", + "2026-08-28 115-PR snapshot", "#198", "#199", "#200", @@ -51,8 +51,8 @@ def test_baseline_records_current_inventory_and_completion_issues(self) -> None: "prior 150-PR snapshot", "128 open pull requests", "74 draft", - "114 open pull requests", - "30 non-draft", + "115 open pull requests", + "31 non-draft", ): with self.subTest(stale_phrase=stale_phrase): self.assertNotIn(stale_phrase, current) @@ -71,7 +71,7 @@ def test_same_day_prior_inventory_is_bound_to_the_maintenance_record(self) -> No record = text.split("#### 2026-08-28 maintenance-loop record", 1)[1].split( "#### Current exact-head active PR evidence", 1 )[0] - self.assertIn("114 open pull requests (30 ready, 84 draft)", record) + self.assertIn("115 open pull requests (31 ready, 84 draft)", record) def test_issue_table_distinguishes_open_issues_from_governance_signals(self) -> None: """The table total must distinguish product issues from governance signals.""" From d2241a29def56f4908b6f3bcd104b3e5c1521b43 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 16:31:38 +0900 Subject: [PATCH 007/250] fix(docs): close baseline review findings --- docs/product-technical-gap-baseline.md | 2 +- tests/test_product_completion_gap_contract.py | 9 +++++++-- 2 files changed, 8 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 83a8978d7..b3c3cf256 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -173,7 +173,7 @@ The hourly product-development loop is operational infrastructure, not proof tha | P1 | Buyers can install, update, verify, and roll back a supported product | **Not shipped** | #201; signed Windows/macOS/Linux/headless artifacts, Chromium revision manifest, updater security, patch SLA, SBOM, SLSA provenance, and recovery | | P1 | Enterprise teams can provision, approve, audit, operate, and recover the service | **Not shipped** | #202; Keyverse-compatible OIDC/SCIM, tenant isolation, policy/approval/evidence UI, SLO/incident controls, data residency, CSAP/SOC 2 evidence mapping, WCAG 2.2, Figma File ID, and Storybook | | P0 | A release has reproducible proof of usefulness, safety, evidence completeness, and recovery | **No product-wide release gate** | #203; deterministic, compatibility, adversarial, recovery, and enterprise suites with statistical reporting and an exact-artifact commercial acceptance gate | -| P0 | Valid changes reach protected `main` without authority improvisation or unbounded stack growth | **Blocked / high integration debt** | Shrink the 115-PR queue in dependency order, provision legitimate review authority, require exact-current evidence, and close duplicates/superseded branches | +| P0 | Valid changes reach protected `main` without authority improvisation or unbounded stack growth | **Blocked / high integration debt** | Shrink the 116-PR queue in dependency order, provision legitimate review authority, require exact-current evidence, and close duplicates/superseded branches | ## Commercial completion definition diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index be471c30b..d858549ee 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -30,6 +30,7 @@ def test_baseline_records_current_inventory_and_completion_issues(self) -> None: "#201", "#202", "#203", + "Shrink the 116-PR queue", "durable WARC/PROV replay", "stable BAP/MCP runtime API", "signed cross-platform Chromium distribution", @@ -68,16 +69,20 @@ def test_active_github_approval_rule_is_not_documented_as_bypassable(self) -> No def test_same_day_prior_inventory_is_bound_to_the_maintenance_record(self) -> None: """A same-day comparison must retain its exact prior observation in the record.""" text = BASELINE.read_text(encoding="utf-8") + record_end = "#### Current exact-head active PR evidence" + self.assertIn(record_end, text) record = text.split("#### 2026-08-28 maintenance-loop record", 1)[1].split( - "#### Current exact-head active PR evidence", 1 + record_end, 1 )[0] self.assertIn("115 open pull requests (31 ready, 84 draft)", record) def test_issue_table_distinguishes_open_issues_from_governance_signals(self) -> None: """The table total must distinguish product issues from governance signals.""" text = BASELINE.read_text(encoding="utf-8") + table_end = "## Buyer-visible and technical gap matrix" + self.assertIn(table_end, text) table = text.split("### Open issues and governance signals", 1)[1].split( - "## Buyer-visible and technical gap matrix", 1 + table_end, 1 )[0] self.assertIn("11 open issues plus 2 governance signals", table) self.assertIn("Issue or signal", table) From 0c694a0dcee86b2e29f2fc8f19b2a0c59abd8ba7 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 18:20:47 +0900 Subject: [PATCH 008/250] docs: record current Chromium evidence stack --- docs/product-technical-gap-baseline.md | 6 ++++++ tests/test_documentation_active_pr_evidence_contract.py | 4 ++++ 2 files changed, 10 insertions(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b3c3cf256..8f52c6e74 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -22,12 +22,18 @@ This snapshot re-fetched the complete open-PR inventory, the protected `main` co The later exact-head recheck also recorded the WARC/PROV retention-lifecycle slice: #239 is Draft at `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` on #227 head `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0`, with its Rust contracts and production coverage checks successful, zero unresolved threads, and no counted approval. #237 is Draft at `21e9ad1e8da72c81f521152ea6739b088da230f7` on protected `main`; its deterministic contracts and coverage are successful, while exact-head `opencode-review` failed closed for the absent current-head verdict and `strix` remained in progress. Neither active branch is protected-main behavior. +The controlled Chromium prerequisite stack was also re-fetched after its exact-head repairs: #70 is Ready at `51967a9f28a32e08e68b87b4f6cd46f1f1104ec7` on `93a85c1464ab73ed7386367dc78fbad9c4f2f107`, #71 is Ready at `54738f695b9d3508d96d1b95bede5a7dc4ceb3a8` on #70, #72 is Draft at `087f5527c68086dae2558c9f3ffd72191da1360d` on #71, and #73 is Draft at `be5509e970bde719908495c07210cc617e197791` on #72. #72's current Rust, pinned-Chrome, and production-coverage checks are successful; #73's new exact-head checks were queued at the end of this snapshot. These are active-stack evidence only, not protected-main behavior or merge authorization. + #### Current exact-head active PR evidence The following representative slices were re-fetched from GitHub for this snapshot. Their exact base/head pairs are recorded so later checks, reviews, and restacks cannot be confused with predecessor evidence: | PR | State | Exact base head | Exact head | |---|---|---|---| +| #73 | Draft | `087f5527c68086dae2558c9f3ffd72191da1360d` | `be5509e970bde719908495c07210cc617e197791` | +| #72 | Draft | `54738f695b9d3508d96d1b95bede5a7dc4ceb3a8` | `087f5527c68086dae2558c9f3ffd72191da1360d` | +| #71 | Ready | `51967a9f28a32e08e68b87b4f6cd46f1f1104ec7` | `54738f695b9d3508d96d1b95bede5a7dc4ceb3a8` | +| #70 | Ready | `93a85c1464ab73ed7386367dc78fbad9c4f2f107` | `51967a9f28a32e08e68b87b4f6cd46f1f1104ec7` | | #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `21e9ad1e8da72c81f521152ea6739b088da230f7` | | #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` | | #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fb868589d065c2cea0b9c8c0f5e655a89f42bee6` | diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 61fa04a2b..9425fb4d8 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -51,6 +51,10 @@ def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> No "#### Historical 2026-08-26 maintenance-loop record", ) for marker in ( + "| #73 | Draft | `087f5527c68086dae2558c9f3ffd72191da1360d` | `be5509e970bde719908495c07210cc617e197791` |", + "| #72 | Draft | `54738f695b9d3508d96d1b95bede5a7dc4ceb3a8` | `087f5527c68086dae2558c9f3ffd72191da1360d` |", + "| #71 | Ready | `51967a9f28a32e08e68b87b4f6cd46f1f1104ec7` | `54738f695b9d3508d96d1b95bede5a7dc4ceb3a8` |", + "| #70 | Ready | `93a85c1464ab73ed7386367dc78fbad9c4f2f107` | `51967a9f28a32e08e68b87b4f6cd46f1f1104ec7` |", "| #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `21e9ad1e8da72c81f521152ea6739b088da230f7` |", "| #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` |", "| #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fb868589d065c2cea0b9c8c0f5e655a89f42bee6` |", From a2b25ee719a6dfad49ab1efefed09d388ef907bf Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 21:23:12 +0900 Subject: [PATCH 009/250] docs: refresh exact active PR baseline --- CHANGELOG.md | 2 +- docs/product-technical-gap-baseline.md | 7 ++++--- tests/test_documentation_active_pr_evidence_contract.py | 5 +++-- 3 files changed, 8 insertions(+), 6 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index b5542363e..2277007cf 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -8,7 +8,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ### Added - Clarified the 2026-08-28 gap snapshot's prior queue observation and separated open issues from governance signals. -- Corrected the 2026-08-28 product-gap snapshot with protected-main `542ca1e9`, 116 open pull requests (32 ready, 84 draft), 11 open issues, current exact base/head pairs for representative PRs including #37, #237, and #239, PR #170's merged `tools/list` contract, the active counted-approval gate, and the unchanged Phase 1 browser gap. +- Corrected the 2026-08-28 product-gap snapshot with protected-main `542ca1e9`, 116 open pull requests (32 ready, 84 draft), 11 open issues, current exact base/head pairs for representative PRs including #70, #71, #152, #37, #237, and #239, PR #170's merged `tools/list` contract, the active counted-approval gate, and the unchanged Phase 1 browser gap. - Refreshed the product and technical gap baseline onto the 2026-08-28 live inventory; current queue and exact-head evidence are explicitly separated from the historical 2026-08-26 snapshot so stale delivery evidence cannot be promoted. - Added `originweave_core::release_acceptance`, a deterministic fail-closed benchmark release-decision contract that requires one authoritative result for every mandatory suite, bounds explicit buyer-visible limitations, rejects duplicate limitation claim identities, and rejects non-canonical surrounding whitespace rather than normalizing it into an alternate claim spelling. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 8f52c6e74..dec8481a4 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -22,7 +22,7 @@ This snapshot re-fetched the complete open-PR inventory, the protected `main` co The later exact-head recheck also recorded the WARC/PROV retention-lifecycle slice: #239 is Draft at `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` on #227 head `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0`, with its Rust contracts and production coverage checks successful, zero unresolved threads, and no counted approval. #237 is Draft at `21e9ad1e8da72c81f521152ea6739b088da230f7` on protected `main`; its deterministic contracts and coverage are successful, while exact-head `opencode-review` failed closed for the absent current-head verdict and `strix` remained in progress. Neither active branch is protected-main behavior. -The controlled Chromium prerequisite stack was also re-fetched after its exact-head repairs: #70 is Ready at `51967a9f28a32e08e68b87b4f6cd46f1f1104ec7` on `93a85c1464ab73ed7386367dc78fbad9c4f2f107`, #71 is Ready at `54738f695b9d3508d96d1b95bede5a7dc4ceb3a8` on #70, #72 is Draft at `087f5527c68086dae2558c9f3ffd72191da1360d` on #71, and #73 is Draft at `be5509e970bde719908495c07210cc617e197791` on #72. #72's current Rust, pinned-Chrome, and production-coverage checks are successful; #73's new exact-head checks were queued at the end of this snapshot. These are active-stack evidence only, not protected-main behavior or merge authorization. +The controlled Chromium prerequisite stack was also re-fetched after its exact-head repairs: #70 is Ready at `378240888b39218c97c1b5c514492bb0a0cf3aa2` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`, #71 is Ready at `f86ce504138e79d6e95141a441f60b40920e1fa6` on #70, #72 remains Draft at `087f5527c68086dae2558c9f3ffd72191da1360d` on its older #71 head `54738f695b9d3508d96d1b95bede5a7dc4ceb3a8`, and #73 remains Draft at `be5509e970bde719908495c07210cc617e197791` on #72. #70's Rust, coverage, pinned-Chrome, and ordinary security checks are successful but its exact-head `opencode-review` and `strix` checks failed closed; #71's Rust contracts, production coverage, and pinned-Chrome checks are successful, with no unresolved current thread, but neither has counted approval. #152 is Ready at `81407a0e5189a413d1be0963fea90a0c2f254ce1` on protected `main`; its source, coverage, and security checks are successful except exact-head `opencode-review`, which failed closed without a current-head verdict. These are active-stack evidence only, not protected-main behavior or merge authorization. #### Current exact-head active PR evidence @@ -32,13 +32,14 @@ The following representative slices were re-fetched from GitHub for this snapsho |---|---|---|---| | #73 | Draft | `087f5527c68086dae2558c9f3ffd72191da1360d` | `be5509e970bde719908495c07210cc617e197791` | | #72 | Draft | `54738f695b9d3508d96d1b95bede5a7dc4ceb3a8` | `087f5527c68086dae2558c9f3ffd72191da1360d` | -| #71 | Ready | `51967a9f28a32e08e68b87b4f6cd46f1f1104ec7` | `54738f695b9d3508d96d1b95bede5a7dc4ceb3a8` | -| #70 | Ready | `93a85c1464ab73ed7386367dc78fbad9c4f2f107` | `51967a9f28a32e08e68b87b4f6cd46f1f1104ec7` | +| #71 | Ready | `378240888b39218c97c1b5c514492bb0a0cf3aa2` | `f86ce504138e79d6e95141a441f60b40920e1fa6` | +| #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `378240888b39218c97c1b5c514492bb0a0cf3aa2` | | #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `21e9ad1e8da72c81f521152ea6739b088da230f7` | | #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` | | #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fb868589d065c2cea0b9c8c0f5e655a89f42bee6` | | #220 | Ready | `f658f329c83a106b68385e17cb714c4147c12f49` | `a2b0c5372dd6df803011933836c56136244dc8af` | | #211 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `52a918577958a5701e1146c7eb8b62fe8f8ccd44` | +| #152 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `81407a0e5189a413d1be0963fea90a0c2f254ce1` | | #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | `72f112d52a60e7caa992a3f5ff7f16d5d9a4d047` | | #124 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `028789d8bb6cc30b8e84b1ba7ed46556b26e75ea` | | #37 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `5423803d3fbd9d2d8e08bbd6dbf81ae6b2addefe` | diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 9425fb4d8..e32988788 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -53,8 +53,9 @@ def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> No for marker in ( "| #73 | Draft | `087f5527c68086dae2558c9f3ffd72191da1360d` | `be5509e970bde719908495c07210cc617e197791` |", "| #72 | Draft | `54738f695b9d3508d96d1b95bede5a7dc4ceb3a8` | `087f5527c68086dae2558c9f3ffd72191da1360d` |", - "| #71 | Ready | `51967a9f28a32e08e68b87b4f6cd46f1f1104ec7` | `54738f695b9d3508d96d1b95bede5a7dc4ceb3a8` |", - "| #70 | Ready | `93a85c1464ab73ed7386367dc78fbad9c4f2f107` | `51967a9f28a32e08e68b87b4f6cd46f1f1104ec7` |", + "| #71 | Ready | `378240888b39218c97c1b5c514492bb0a0cf3aa2` | `f86ce504138e79d6e95141a441f60b40920e1fa6` |", + "| #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `378240888b39218c97c1b5c514492bb0a0cf3aa2` |", + "| #152 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `81407a0e5189a413d1be0963fea90a0c2f254ce1` |", "| #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `21e9ad1e8da72c81f521152ea6739b088da230f7` |", "| #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` |", "| #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fb868589d065c2cea0b9c8c0f5e655a89f42bee6` |", From 9fc63fa298f9b9dd47715d343530c3bfdee7bbab Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 21:33:09 +0900 Subject: [PATCH 010/250] docs: track restacked browser evidence queue --- docs/product-technical-gap-baseline.md | 6 +++--- tests/test_documentation_active_pr_evidence_contract.py | 4 ++-- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index dec8481a4..caadaa17c 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -22,7 +22,7 @@ This snapshot re-fetched the complete open-PR inventory, the protected `main` co The later exact-head recheck also recorded the WARC/PROV retention-lifecycle slice: #239 is Draft at `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` on #227 head `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0`, with its Rust contracts and production coverage checks successful, zero unresolved threads, and no counted approval. #237 is Draft at `21e9ad1e8da72c81f521152ea6739b088da230f7` on protected `main`; its deterministic contracts and coverage are successful, while exact-head `opencode-review` failed closed for the absent current-head verdict and `strix` remained in progress. Neither active branch is protected-main behavior. -The controlled Chromium prerequisite stack was also re-fetched after its exact-head repairs: #70 is Ready at `378240888b39218c97c1b5c514492bb0a0cf3aa2` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`, #71 is Ready at `f86ce504138e79d6e95141a441f60b40920e1fa6` on #70, #72 remains Draft at `087f5527c68086dae2558c9f3ffd72191da1360d` on its older #71 head `54738f695b9d3508d96d1b95bede5a7dc4ceb3a8`, and #73 remains Draft at `be5509e970bde719908495c07210cc617e197791` on #72. #70's Rust, coverage, pinned-Chrome, and ordinary security checks are successful but its exact-head `opencode-review` and `strix` checks failed closed; #71's Rust contracts, production coverage, and pinned-Chrome checks are successful, with no unresolved current thread, but neither has counted approval. #152 is Ready at `81407a0e5189a413d1be0963fea90a0c2f254ce1` on protected `main`; its source, coverage, and security checks are successful except exact-head `opencode-review`, which failed closed without a current-head verdict. These are active-stack evidence only, not protected-main behavior or merge authorization. +The controlled Chromium prerequisite stack was also re-fetched after its exact-head repairs: #70 is Ready at `378240888b39218c97c1b5c514492bb0a0cf3aa2` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`, #71 is Ready at `f86ce504138e79d6e95141a441f60b40920e1fa6` on #70, #72 is Draft at `600d3975c02b68da1974a4c73069b966b39dce7` on #71, and #73 is Draft at `ce1b138509ab4f52cb0f80290f104358473c6ed3` on #72. #70's Rust, coverage, pinned-Chrome, and ordinary security checks are successful but its exact-head `opencode-review` and `strix` checks failed closed; #71's Rust contracts, production coverage, and pinned-Chrome checks are successful, with no unresolved current thread, but neither has counted approval. #72's and #73's exact-head native checks are queued or in progress after their non-destructive restacks; no predecessor results transfer. #152 is Ready at `81407a0e5189a413d1be0963fea90a0c2f254ce1` on protected `main`; its source, coverage, and security checks are successful except exact-head `opencode-review`, which failed closed without a current-head verdict. These are active-stack evidence only, not protected-main behavior or merge authorization. #### Current exact-head active PR evidence @@ -30,8 +30,8 @@ The following representative slices were re-fetched from GitHub for this snapsho | PR | State | Exact base head | Exact head | |---|---|---|---| -| #73 | Draft | `087f5527c68086dae2558c9f3ffd72191da1360d` | `be5509e970bde719908495c07210cc617e197791` | -| #72 | Draft | `54738f695b9d3508d96d1b95bede5a7dc4ceb3a8` | `087f5527c68086dae2558c9f3ffd72191da1360d` | +| #73 | Draft | `600d3975c02b68da1974a4c73069b966b39dce7` | `ce1b138509ab4f52cb0f80290f104358473c6ed3` | +| #72 | Draft | `f86ce504138e79d6e95141a441f60b40920e1fa6` | `600d3975c02b68da1974a4c73069b966b39dce7` | | #71 | Ready | `378240888b39218c97c1b5c514492bb0a0cf3aa2` | `f86ce504138e79d6e95141a441f60b40920e1fa6` | | #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `378240888b39218c97c1b5c514492bb0a0cf3aa2` | | #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `21e9ad1e8da72c81f521152ea6739b088da230f7` | diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index e32988788..ad1628993 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -51,8 +51,8 @@ def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> No "#### Historical 2026-08-26 maintenance-loop record", ) for marker in ( - "| #73 | Draft | `087f5527c68086dae2558c9f3ffd72191da1360d` | `be5509e970bde719908495c07210cc617e197791` |", - "| #72 | Draft | `54738f695b9d3508d96d1b95bede5a7dc4ceb3a8` | `087f5527c68086dae2558c9f3ffd72191da1360d` |", + "| #73 | Draft | `600d3975c02b68da1974a4c73069b966b39dce7` | `ce1b138509ab4f52cb0f80290f104358473c6ed3` |", + "| #72 | Draft | `f86ce504138e79d6e95141a441f60b40920e1fa6` | `600d3975c02b68da1974a4c73069b966b39dce7` |", "| #71 | Ready | `378240888b39218c97c1b5c514492bb0a0cf3aa2` | `f86ce504138e79d6e95141a441f60b40920e1fa6` |", "| #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `378240888b39218c97c1b5c514492bb0a0cf3aa2` |", "| #152 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `81407a0e5189a413d1be0963fea90a0c2f254ce1` |", From 685cf810c843e25b5a3b291cbb0374bed28d92a8 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 21:36:34 +0900 Subject: [PATCH 011/250] docs: record completed restack checks --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index caadaa17c..a4bdc52aa 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -22,7 +22,7 @@ This snapshot re-fetched the complete open-PR inventory, the protected `main` co The later exact-head recheck also recorded the WARC/PROV retention-lifecycle slice: #239 is Draft at `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` on #227 head `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0`, with its Rust contracts and production coverage checks successful, zero unresolved threads, and no counted approval. #237 is Draft at `21e9ad1e8da72c81f521152ea6739b088da230f7` on protected `main`; its deterministic contracts and coverage are successful, while exact-head `opencode-review` failed closed for the absent current-head verdict and `strix` remained in progress. Neither active branch is protected-main behavior. -The controlled Chromium prerequisite stack was also re-fetched after its exact-head repairs: #70 is Ready at `378240888b39218c97c1b5c514492bb0a0cf3aa2` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`, #71 is Ready at `f86ce504138e79d6e95141a441f60b40920e1fa6` on #70, #72 is Draft at `600d3975c02b68da1974a4c73069b966b39dce7` on #71, and #73 is Draft at `ce1b138509ab4f52cb0f80290f104358473c6ed3` on #72. #70's Rust, coverage, pinned-Chrome, and ordinary security checks are successful but its exact-head `opencode-review` and `strix` checks failed closed; #71's Rust contracts, production coverage, and pinned-Chrome checks are successful, with no unresolved current thread, but neither has counted approval. #72's and #73's exact-head native checks are queued or in progress after their non-destructive restacks; no predecessor results transfer. #152 is Ready at `81407a0e5189a413d1be0963fea90a0c2f254ce1` on protected `main`; its source, coverage, and security checks are successful except exact-head `opencode-review`, which failed closed without a current-head verdict. These are active-stack evidence only, not protected-main behavior or merge authorization. +The controlled Chromium prerequisite stack was also re-fetched after its exact-head repairs: #70 is Ready at `378240888b39218c97c1b5c514492bb0a0cf3aa2` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`, #71 is Ready at `f86ce504138e79d6e95141a441f60b40920e1fa6` on #70, #72 is Draft at `600d3975c02b68da1974a4c73069b966b39dce7` on #71, and #73 is Draft at `ce1b138509ab4f52cb0f80290f104358473c6ed3` on #72. #70's Rust, coverage, pinned-Chrome, and ordinary security checks are successful but its exact-head `opencode-review` and `strix` checks failed closed; #71's Rust contracts, production coverage, and pinned-Chrome checks are successful, with no unresolved current thread, but neither has counted approval. #72's and #73's exact-head Rust, coverage, and pinned-Chrome checks are successful after their non-destructive restacks; no predecessor results transfer and neither has counted approval. #152 is Ready at `81407a0e5189a413d1be0963fea90a0c2f254ce1` on protected `main`; its source, coverage, and security checks are successful except exact-head `opencode-review`, which failed closed without a current-head verdict. These are active-stack evidence only, not protected-main behavior or merge authorization. #### Current exact-head active PR evidence From f1d1afb5a83165da929cfd3260be077305a3c715 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 21:38:04 +0900 Subject: [PATCH 012/250] docs: record baseline PR exact head --- docs/product-technical-gap-baseline.md | 1 + tests/test_documentation_active_pr_evidence_contract.py | 1 + 2 files changed, 2 insertions(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index a4bdc52aa..f79028834 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -35,6 +35,7 @@ The following representative slices were re-fetched from GitHub for this snapsho | #71 | Ready | `378240888b39218c97c1b5c514492bb0a0cf3aa2` | `f86ce504138e79d6e95141a441f60b40920e1fa6` | | #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `378240888b39218c97c1b5c514492bb0a0cf3aa2` | | #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `21e9ad1e8da72c81f521152ea6739b088da230f7` | +| #238 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `685cf810c843e25b5a3b291cbb0374bed28d92a8` | | #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` | | #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fb868589d065c2cea0b9c8c0f5e655a89f42bee6` | | #220 | Ready | `f658f329c83a106b68385e17cb714c4147c12f49` | `a2b0c5372dd6df803011933836c56136244dc8af` | diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index ad1628993..f96def1cd 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -57,6 +57,7 @@ def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> No "| #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `378240888b39218c97c1b5c514492bb0a0cf3aa2` |", "| #152 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `81407a0e5189a413d1be0963fea90a0c2f254ce1` |", "| #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `21e9ad1e8da72c81f521152ea6739b088da230f7` |", + "| #238 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `685cf810c843e25b5a3b291cbb0374bed28d92a8` |", "| #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` |", "| #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fb868589d065c2cea0b9c8c0f5e655a89f42bee6` |", "| #220 | Ready | `f658f329c83a106b68385e17cb714c4147c12f49` | `a2b0c5372dd6df803011933836c56136244dc8af` |", From 0b2f278dc9f4a1392bc2f6a0424bd0c66b7e582c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 21:41:49 +0900 Subject: [PATCH 013/250] test: make baseline phrase scope explicit --- CHANGELOG.md | 1 + tests/test_product_completion_gap_contract.py | 13 ++++++++++++- 2 files changed, 13 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 2277007cf..92fe72b19 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -10,6 +10,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Clarified the 2026-08-28 gap snapshot's prior queue observation and separated open issues from governance signals. - Corrected the 2026-08-28 product-gap snapshot with protected-main `542ca1e9`, 116 open pull requests (32 ready, 84 draft), 11 open issues, current exact base/head pairs for representative PRs including #70, #71, #152, #37, #237, and #239, PR #170's merged `tools/list` contract, the active counted-approval gate, and the unchanged Phase 1 browser gap. - Refreshed the product and technical gap baseline onto the 2026-08-28 live inventory; current queue and exact-head evidence are explicitly separated from the historical 2026-08-26 snapshot so stale delivery evidence cannot be promoted. +- Hardened the product-completion documentation contract by classifying current-snapshot count markers explicitly instead of routing them by substring heuristics. - Added `originweave_core::release_acceptance`, a deterministic fail-closed benchmark release-decision contract that requires one authoritative result for every mandatory suite, bounds explicit buyer-visible limitations, rejects duplicate limitation claim identities, and rejects non-canonical surrounding whitespace rather than normalizing it into an alternate claim spelling. - Refreshed the product and technical gap baseline with the 2026-08-24 live inventory: 158 open pull requests (44 ready, 114 draft), refreshed exact base/head evidence for the #208–#222 release, enterprise-approval, BAP, and WARC/PROV chains, the governance issue additions #212 and #215, and a required-check provider-failure record for the fail-closed Strix re-dispatches on #208/#218/#220. diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index d858549ee..44df493fb 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -12,6 +12,12 @@ class ProductCompletionGapContractTests(unittest.TestCase): """Keep the exact repository snapshot and completion tracks reviewable.""" + def test_current_snapshot_checks_do_not_route_by_phrase_substrings(self) -> None: + """Current-snapshot assertions must not depend on count-word substrings.""" + source = pathlib.Path(__file__).read_text(encoding="utf-8") + brittle_condition = '"pull requests" in phrase or ' + '"draft" in phrase' + self.assertNotIn(brittle_condition, source) + def test_baseline_records_current_inventory_and_completion_issues(self) -> None: """The dated baseline must not retain superseded queue counts or omit buyer tracks.""" text = BASELINE.read_text(encoding="utf-8") @@ -24,6 +30,11 @@ def test_baseline_records_current_inventory_and_completion_issues(self) -> None: "32 non-draft", "84 draft", "2026-08-28 115-PR snapshot", + ): + with self.subTest(phrase=phrase): + self.assertIn(phrase, current) + + for phrase in ( "#198", "#199", "#200", @@ -38,7 +49,7 @@ def test_baseline_records_current_inventory_and_completion_issues(self) -> None: "commercial acceptance gate", ): with self.subTest(phrase=phrase): - self.assertIn(phrase, current if "pull requests" in phrase or "draft" in phrase else text) + self.assertIn(phrase, text) for stale_phrase in ( "100 open pull requests", From 48af1734099aacfd8f0a131818a032d72cd0d957 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 21:43:58 +0900 Subject: [PATCH 014/250] docs: correct full active stack SHAs --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 8 ++++---- tests/test_documentation_active_pr_evidence_contract.py | 6 +++--- 3 files changed, 8 insertions(+), 7 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 92fe72b19..8a9141a8c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -11,6 +11,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Corrected the 2026-08-28 product-gap snapshot with protected-main `542ca1e9`, 116 open pull requests (32 ready, 84 draft), 11 open issues, current exact base/head pairs for representative PRs including #70, #71, #152, #37, #237, and #239, PR #170's merged `tools/list` contract, the active counted-approval gate, and the unchanged Phase 1 browser gap. - Refreshed the product and technical gap baseline onto the 2026-08-28 live inventory; current queue and exact-head evidence are explicitly separated from the historical 2026-08-26 snapshot so stale delivery evidence cannot be promoted. - Hardened the product-completion documentation contract by classifying current-snapshot count markers explicitly instead of routing them by substring heuristics. +- Corrected the baseline's #72/#73 exact SHA evidence to full 40-character values and tracked PR #238's current head. - Added `originweave_core::release_acceptance`, a deterministic fail-closed benchmark release-decision contract that requires one authoritative result for every mandatory suite, bounds explicit buyer-visible limitations, rejects duplicate limitation claim identities, and rejects non-canonical surrounding whitespace rather than normalizing it into an alternate claim spelling. - Refreshed the product and technical gap baseline with the 2026-08-24 live inventory: 158 open pull requests (44 ready, 114 draft), refreshed exact base/head evidence for the #208–#222 release, enterprise-approval, BAP, and WARC/PROV chains, the governance issue additions #212 and #215, and a required-check provider-failure record for the fail-closed Strix re-dispatches on #208/#218/#220. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index f79028834..7e1d58227 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -22,7 +22,7 @@ This snapshot re-fetched the complete open-PR inventory, the protected `main` co The later exact-head recheck also recorded the WARC/PROV retention-lifecycle slice: #239 is Draft at `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` on #227 head `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0`, with its Rust contracts and production coverage checks successful, zero unresolved threads, and no counted approval. #237 is Draft at `21e9ad1e8da72c81f521152ea6739b088da230f7` on protected `main`; its deterministic contracts and coverage are successful, while exact-head `opencode-review` failed closed for the absent current-head verdict and `strix` remained in progress. Neither active branch is protected-main behavior. -The controlled Chromium prerequisite stack was also re-fetched after its exact-head repairs: #70 is Ready at `378240888b39218c97c1b5c514492bb0a0cf3aa2` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`, #71 is Ready at `f86ce504138e79d6e95141a441f60b40920e1fa6` on #70, #72 is Draft at `600d3975c02b68da1974a4c73069b966b39dce7` on #71, and #73 is Draft at `ce1b138509ab4f52cb0f80290f104358473c6ed3` on #72. #70's Rust, coverage, pinned-Chrome, and ordinary security checks are successful but its exact-head `opencode-review` and `strix` checks failed closed; #71's Rust contracts, production coverage, and pinned-Chrome checks are successful, with no unresolved current thread, but neither has counted approval. #72's and #73's exact-head Rust, coverage, and pinned-Chrome checks are successful after their non-destructive restacks; no predecessor results transfer and neither has counted approval. #152 is Ready at `81407a0e5189a413d1be0963fea90a0c2f254ce1` on protected `main`; its source, coverage, and security checks are successful except exact-head `opencode-review`, which failed closed without a current-head verdict. These are active-stack evidence only, not protected-main behavior or merge authorization. +The controlled Chromium prerequisite stack was also re-fetched after its exact-head repairs: #70 is Ready at `378240888b39218c97c1b5c514492bb0a0cf3aa2` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`, #71 is Ready at `f86ce504138e79d6e95141a441f60b40920e1fa6` on #70, #72 is Draft at `600d3975c02b68da1974a4c73069b966b39dce7b` on #71, and #73 is Draft at `ce1b138509ab4f52cb0f80290f104358473c6ed3` on #72. #70's Rust, coverage, pinned-Chrome, and ordinary security checks are successful but its exact-head `opencode-review` and `strix` checks failed closed; #71's Rust contracts, production coverage, and pinned-Chrome checks are successful, with no unresolved current thread, but neither has counted approval. #72's and #73's exact-head Rust, coverage, and pinned-Chrome checks are successful after their non-destructive restacks; no predecessor results transfer and neither has counted approval. #152 is Ready at `81407a0e5189a413d1be0963fea90a0c2f254ce1` on protected `main`; its source, coverage, and security checks are successful except exact-head `opencode-review`, which failed closed without a current-head verdict. These are active-stack evidence only, not protected-main behavior or merge authorization. #### Current exact-head active PR evidence @@ -30,12 +30,12 @@ The following representative slices were re-fetched from GitHub for this snapsho | PR | State | Exact base head | Exact head | |---|---|---|---| -| #73 | Draft | `600d3975c02b68da1974a4c73069b966b39dce7` | `ce1b138509ab4f52cb0f80290f104358473c6ed3` | -| #72 | Draft | `f86ce504138e79d6e95141a441f60b40920e1fa6` | `600d3975c02b68da1974a4c73069b966b39dce7` | +| #73 | Draft | `600d3975c02b68da1974a4c73069b966b39dce7b` | `ce1b138509ab4f52cb0f80290f104358473c6ed3` | +| #72 | Draft | `f86ce504138e79d6e95141a441f60b40920e1fa6` | `600d3975c02b68da1974a4c73069b966b39dce7b` | | #71 | Ready | `378240888b39218c97c1b5c514492bb0a0cf3aa2` | `f86ce504138e79d6e95141a441f60b40920e1fa6` | | #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `378240888b39218c97c1b5c514492bb0a0cf3aa2` | | #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `21e9ad1e8da72c81f521152ea6739b088da230f7` | -| #238 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `685cf810c843e25b5a3b291cbb0374bed28d92a8` | +| #238 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0b2f278dc9f4a1392bc2f6a0424bd0c66b7e582c` | | #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` | | #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fb868589d065c2cea0b9c8c0f5e655a89f42bee6` | | #220 | Ready | `f658f329c83a106b68385e17cb714c4147c12f49` | `a2b0c5372dd6df803011933836c56136244dc8af` | diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index f96def1cd..6399c5af6 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -51,13 +51,13 @@ def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> No "#### Historical 2026-08-26 maintenance-loop record", ) for marker in ( - "| #73 | Draft | `600d3975c02b68da1974a4c73069b966b39dce7` | `ce1b138509ab4f52cb0f80290f104358473c6ed3` |", - "| #72 | Draft | `f86ce504138e79d6e95141a441f60b40920e1fa6` | `600d3975c02b68da1974a4c73069b966b39dce7` |", + "| #73 | Draft | `600d3975c02b68da1974a4c73069b966b39dce7b` | `ce1b138509ab4f52cb0f80290f104358473c6ed3` |", + "| #72 | Draft | `f86ce504138e79d6e95141a441f60b40920e1fa6` | `600d3975c02b68da1974a4c73069b966b39dce7b` |", "| #71 | Ready | `378240888b39218c97c1b5c514492bb0a0cf3aa2` | `f86ce504138e79d6e95141a441f60b40920e1fa6` |", "| #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `378240888b39218c97c1b5c514492bb0a0cf3aa2` |", "| #152 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `81407a0e5189a413d1be0963fea90a0c2f254ce1` |", "| #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `21e9ad1e8da72c81f521152ea6739b088da230f7` |", - "| #238 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `685cf810c843e25b5a3b291cbb0374bed28d92a8` |", + "| #238 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0b2f278dc9f4a1392bc2f6a0424bd0c66b7e582c` |", "| #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` |", "| #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fb868589d065c2cea0b9c8c0f5e655a89f42bee6` |", "| #220 | Ready | `f658f329c83a106b68385e17cb714c4147c12f49` | `a2b0c5372dd6df803011933836c56136244dc8af` |", From b3a3eb61802d509b1605a3d189c631702cec4a5e Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 22:31:01 +0900 Subject: [PATCH 015/250] docs: track current WARC PR evidence --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 5 ++++- tests/test_documentation_active_pr_evidence_contract.py | 1 + 3 files changed, 6 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 8a9141a8c..f18776817 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -12,6 +12,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Refreshed the product and technical gap baseline onto the 2026-08-28 live inventory; current queue and exact-head evidence are explicitly separated from the historical 2026-08-26 snapshot so stale delivery evidence cannot be promoted. - Hardened the product-completion documentation contract by classifying current-snapshot count markers explicitly instead of routing them by substring heuristics. - Corrected the baseline's #72/#73 exact SHA evidence to full 40-character values and tracked PR #238's current head. +- Refreshed the baseline's #210 WARC row to exact Ready head `d83748a70bd1b16dbfec46007fe02989ba6ce188` and recorded its nested credential-query defense and current-head hosted-check regeneration. - Added `originweave_core::release_acceptance`, a deterministic fail-closed benchmark release-decision contract that requires one authoritative result for every mandatory suite, bounds explicit buyer-visible limitations, rejects duplicate limitation claim identities, and rejects non-canonical surrounding whitespace rather than normalizing it into an alternate claim spelling. - Refreshed the product and technical gap baseline with the 2026-08-24 live inventory: 158 open pull requests (44 ready, 114 draft), refreshed exact base/head evidence for the #208–#222 release, enterprise-approval, BAP, and WARC/PROV chains, the governance issue additions #212 and #215, and a required-check provider-failure record for the fail-closed Strix re-dispatches on #208/#218/#220. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 7e1d58227..1b1017508 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -22,6 +22,8 @@ This snapshot re-fetched the complete open-PR inventory, the protected `main` co The later exact-head recheck also recorded the WARC/PROV retention-lifecycle slice: #239 is Draft at `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` on #227 head `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0`, with its Rust contracts and production coverage checks successful, zero unresolved threads, and no counted approval. #237 is Draft at `21e9ad1e8da72c81f521152ea6739b088da230f7` on protected `main`; its deterministic contracts and coverage are successful, while exact-head `opencode-review` failed closed for the absent current-head verdict and `strix` remained in progress. Neither active branch is protected-main behavior. +The WARC resource-record slice #210 is now Ready at exact head `d83748a70bd1b16dbfec46007fe02989ba6ce188` directly on protected `main`; its latest forward-only repair rejects credential names found in raw and percent-encoded nested query-like values. Local evidence is green, while the current-head hosted CI, security, Noema, scheduler, and OpenCode workflows were still regenerating at the recheck; no predecessor status is promoted and no counted approval exists. + The controlled Chromium prerequisite stack was also re-fetched after its exact-head repairs: #70 is Ready at `378240888b39218c97c1b5c514492bb0a0cf3aa2` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`, #71 is Ready at `f86ce504138e79d6e95141a441f60b40920e1fa6` on #70, #72 is Draft at `600d3975c02b68da1974a4c73069b966b39dce7b` on #71, and #73 is Draft at `ce1b138509ab4f52cb0f80290f104358473c6ed3` on #72. #70's Rust, coverage, pinned-Chrome, and ordinary security checks are successful but its exact-head `opencode-review` and `strix` checks failed closed; #71's Rust contracts, production coverage, and pinned-Chrome checks are successful, with no unresolved current thread, but neither has counted approval. #72's and #73's exact-head Rust, coverage, and pinned-Chrome checks are successful after their non-destructive restacks; no predecessor results transfer and neither has counted approval. #152 is Ready at `81407a0e5189a413d1be0963fea90a0c2f254ce1` on protected `main`; its source, coverage, and security checks are successful except exact-head `opencode-review`, which failed closed without a current-head verdict. These are active-stack evidence only, not protected-main behavior or merge authorization. #### Current exact-head active PR evidence @@ -34,6 +36,7 @@ The following representative slices were re-fetched from GitHub for this snapsho | #72 | Draft | `f86ce504138e79d6e95141a441f60b40920e1fa6` | `600d3975c02b68da1974a4c73069b966b39dce7b` | | #71 | Ready | `378240888b39218c97c1b5c514492bb0a0cf3aa2` | `f86ce504138e79d6e95141a441f60b40920e1fa6` | | #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `378240888b39218c97c1b5c514492bb0a0cf3aa2` | +| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `d83748a70bd1b16dbfec46007fe02989ba6ce188` | | #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `21e9ad1e8da72c81f521152ea6739b088da230f7` | | #238 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0b2f278dc9f4a1392bc2f6a0424bd0c66b7e582c` | | #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` | @@ -77,7 +80,7 @@ Representative active workstreams at this snapshot were: | MCP adapter | (#168 and #170 merged) | Typed MCP routing and conservative `tools/list` cache metadata are protected-main behavior; the complete MCP transport, OAuth, browser I/O, and persistence adapter remains planned | | Workflow-registry audit | #124 | Real Strix finding vuln-0001 (Unicode homoglyph path confusion, MEDIUM) remediated on head `30cc458b` with regression contract tests; fresh exact-head checks and review re-running | | Controlled Chromium and recovery | #65, #70-#73, #100, #105, #142-#152 and descendants | Real pinned-browser fixture, semantic location, resource, crash, and teardown evidence exists on active stacks; evidence does not transfer across heads or prerequisites | -| Durable WARC/PROV evidence | #210, #217, #239 | Bounded WARC resource records, PROV JSON-LD binding, and retention-lifecycle boundaries are draft active-PR foundations; durable ownership, replay, retention/deletion, and browser side-effect reconciliation remain open | +| Durable WARC/PROV evidence | #210, #217, #239 | Bounded WARC resource records, PROV JSON-LD binding, and retention-lifecycle boundaries are active-PR foundations; durable ownership, replay, retention/deletion, and browser side-effect reconciliation remain open | | Manifest V3 and native messaging | #27, #43 governance remediation, and the extension/native-host stack including #154 and #169 | Compatibility and Agent-authority isolation remain incomplete until exact release artifacts and platform matrices are proven; #43's sandbox workflow mutation is now owner-authorized under issue #212 option (b) | | Sensitive-data and model route policy | #10 and its active policy stacks | Deterministic policy values exist, but trusted broker execution, retention/deletion, runtime isolation, and auditable product workflows remain open | | VPN/profile intent | #149 | Bounded WireGuard/IKEv2 profile authority reconciled with main (`54f96008`); it does not create a tunnel, route, DNS state, authenticated gateway, or connectivity proof | diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 6399c5af6..ea167ed44 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -56,6 +56,7 @@ def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> No "| #71 | Ready | `378240888b39218c97c1b5c514492bb0a0cf3aa2` | `f86ce504138e79d6e95141a441f60b40920e1fa6` |", "| #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `378240888b39218c97c1b5c514492bb0a0cf3aa2` |", "| #152 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `81407a0e5189a413d1be0963fea90a0c2f254ce1` |", + "| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `d83748a70bd1b16dbfec46007fe02989ba6ce188` |", "| #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `21e9ad1e8da72c81f521152ea6739b088da230f7` |", "| #238 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0b2f278dc9f4a1392bc2f6a0424bd0c66b7e582c` |", "| #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` |", From 92467cc67c5f2d9b76965b8ec2068066922c6781 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 22:35:46 +0900 Subject: [PATCH 016/250] docs: avoid self-referential PR head evidence --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 3 ++- tests/test_documentation_active_pr_evidence_contract.py | 3 ++- 3 files changed, 5 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index f18776817..1d80927f3 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -13,6 +13,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Hardened the product-completion documentation contract by classifying current-snapshot count markers explicitly instead of routing them by substring heuristics. - Corrected the baseline's #72/#73 exact SHA evidence to full 40-character values and tracked PR #238's current head. - Refreshed the baseline's #210 WARC row to exact Ready head `d83748a70bd1b16dbfec46007fe02989ba6ce188` and recorded its nested credential-query defense and current-head hosted-check regeneration. +- Removed the self-referential #238 exact-head row from the baseline; the live PR metadata and body remain authoritative because every documentation update necessarily creates a new branch head. - Added `originweave_core::release_acceptance`, a deterministic fail-closed benchmark release-decision contract that requires one authoritative result for every mandatory suite, bounds explicit buyer-visible limitations, rejects duplicate limitation claim identities, and rejects non-canonical surrounding whitespace rather than normalizing it into an alternate claim spelling. - Refreshed the product and technical gap baseline with the 2026-08-24 live inventory: 158 open pull requests (44 ready, 114 draft), refreshed exact base/head evidence for the #208–#222 release, enterprise-approval, BAP, and WARC/PROV chains, the governance issue additions #212 and #215, and a required-check provider-failure record for the fail-closed Strix re-dispatches on #208/#218/#220. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 1b1017508..aa34f0578 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -38,7 +38,6 @@ The following representative slices were re-fetched from GitHub for this snapsho | #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `378240888b39218c97c1b5c514492bb0a0cf3aa2` | | #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `d83748a70bd1b16dbfec46007fe02989ba6ce188` | | #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `21e9ad1e8da72c81f521152ea6739b088da230f7` | -| #238 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0b2f278dc9f4a1392bc2f6a0424bd0c66b7e582c` | | #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` | | #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fb868589d065c2cea0b9c8c0f5e655a89f42bee6` | | #220 | Ready | `f658f329c83a106b68385e17cb714c4147c12f49` | `a2b0c5372dd6df803011933836c56136244dc8af` | @@ -50,6 +49,8 @@ The following representative slices were re-fetched from GitHub for this snapsho These rows are delivery evidence only. None has counted independent approval in the current collaborator inventory. +The current documentation branch is PR #238 itself, so its self-referential exact-head row is intentionally omitted; GitHub PR metadata and the PR body are the authoritative current-head record for this change. + #### Historical 2026-08-26 maintenance-loop record The interactive maintenance loop performed the following verified state changes on exact heads; none of them is protected-main behavior until merged: diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index ea167ed44..bcbbb49bb 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -58,7 +58,6 @@ def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> No "| #152 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `81407a0e5189a413d1be0963fea90a0c2f254ce1` |", "| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `d83748a70bd1b16dbfec46007fe02989ba6ce188` |", "| #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `21e9ad1e8da72c81f521152ea6739b088da230f7` |", - "| #238 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0b2f278dc9f4a1392bc2f6a0424bd0c66b7e582c` |", "| #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` |", "| #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fb868589d065c2cea0b9c8c0f5e655a89f42bee6` |", "| #220 | Ready | `f658f329c83a106b68385e17cb714c4147c12f49` | `a2b0c5372dd6df803011933836c56136244dc8af` |", @@ -69,6 +68,8 @@ def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> No ): with self.subTest(marker=marker): self.assertIn(marker, current) + self.assertNotIn("| #238 |", current) + self.assertIn("PR #238 itself", current) def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: """The current changelog refresh item must carry its own live queue evidence.""" From 14def76eb1297dffe153f65910add6fe49b712b7 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 23:06:26 +0900 Subject: [PATCH 017/250] docs: record missing required workflow identities --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 6 ++++-- ...cumentation_active_pr_evidence_contract.py | 2 +- tests/test_product_completion_gap_contract.py | 21 +++++++++++++++++++ 4 files changed, 27 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 1d80927f3..a7f633691 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -13,6 +13,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Hardened the product-completion documentation contract by classifying current-snapshot count markers explicitly instead of routing them by substring heuristics. - Corrected the baseline's #72/#73 exact SHA evidence to full 40-character values and tracked PR #238's current head. - Refreshed the baseline's #210 WARC row to exact Ready head `d83748a70bd1b16dbfec46007fe02989ba6ce188` and recorded its nested credential-query defense and current-head hosted-check regeneration. +- Refreshed the baseline's #210 WARC row to exact Ready head `0341079331f9cea669eb9a5cc21842fd6027431e`, including encoded-control rejection, and recorded the active ruleset's missing required workflow identities with exact PR #70 404 evidence without weakening any gate. - Removed the self-referential #238 exact-head row from the baseline; the live PR metadata and body remain authoritative because every documentation update necessarily creates a new branch head. - Added `originweave_core::release_acceptance`, a deterministic fail-closed benchmark release-decision contract that requires one authoritative result for every mandatory suite, bounds explicit buyer-visible limitations, rejects duplicate limitation claim identities, and rejects non-canonical surrounding whitespace rather than normalizing it into an alternate claim spelling. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index aa34f0578..1edda3681 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -22,7 +22,9 @@ This snapshot re-fetched the complete open-PR inventory, the protected `main` co The later exact-head recheck also recorded the WARC/PROV retention-lifecycle slice: #239 is Draft at `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` on #227 head `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0`, with its Rust contracts and production coverage checks successful, zero unresolved threads, and no counted approval. #237 is Draft at `21e9ad1e8da72c81f521152ea6739b088da230f7` on protected `main`; its deterministic contracts and coverage are successful, while exact-head `opencode-review` failed closed for the absent current-head verdict and `strix` remained in progress. Neither active branch is protected-main behavior. -The WARC resource-record slice #210 is now Ready at exact head `d83748a70bd1b16dbfec46007fe02989ba6ce188` directly on protected `main`; its latest forward-only repair rejects credential names found in raw and percent-encoded nested query-like values. Local evidence is green, while the current-head hosted CI, security, Noema, scheduler, and OpenCode workflows were still regenerating at the recheck; no predecessor status is promoted and no counted approval exists. +The same exact-head recheck found a required workflow identities gap: the active ruleset names seven required workflow paths (`close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, and `noema-review`), but protected `main` and the current Actions workflow inventory exposed none of those paths. On PR #70 head `378240888b39218c97c1b5c514492bb0a0cf3aa2`, the exact current-head run lookup returned 404 for the `opencode-review` and `strix` workflow IDs `327727411` and `327727415`. This is unavailable or deleted workflow-identity evidence, not passing review or security evidence. It blocks affected PRs until the central workflow authority restores or deliberately rebinds the identities; it does not authorize bypass, self-approval, stale checks, or weaker gates. + +The WARC resource-record slice #210 is now Ready at exact head `0341079331f9cea669eb9a5cc21842fd6027431e`, based directly on protected `main`; its latest forward-only repair rejects raw and recursively percent-encoded nested credential names and percent-encoded ASCII controls. Local evidence is green, while the current-head hosted CI, security, Noema, scheduler, and OpenCode workflows were still regenerating at the recheck; no predecessor status is promoted and no counted approval exists. The controlled Chromium prerequisite stack was also re-fetched after its exact-head repairs: #70 is Ready at `378240888b39218c97c1b5c514492bb0a0cf3aa2` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`, #71 is Ready at `f86ce504138e79d6e95141a441f60b40920e1fa6` on #70, #72 is Draft at `600d3975c02b68da1974a4c73069b966b39dce7b` on #71, and #73 is Draft at `ce1b138509ab4f52cb0f80290f104358473c6ed3` on #72. #70's Rust, coverage, pinned-Chrome, and ordinary security checks are successful but its exact-head `opencode-review` and `strix` checks failed closed; #71's Rust contracts, production coverage, and pinned-Chrome checks are successful, with no unresolved current thread, but neither has counted approval. #72's and #73's exact-head Rust, coverage, and pinned-Chrome checks are successful after their non-destructive restacks; no predecessor results transfer and neither has counted approval. #152 is Ready at `81407a0e5189a413d1be0963fea90a0c2f254ce1` on protected `main`; its source, coverage, and security checks are successful except exact-head `opencode-review`, which failed closed without a current-head verdict. These are active-stack evidence only, not protected-main behavior or merge authorization. @@ -36,7 +38,7 @@ The following representative slices were re-fetched from GitHub for this snapsho | #72 | Draft | `f86ce504138e79d6e95141a441f60b40920e1fa6` | `600d3975c02b68da1974a4c73069b966b39dce7b` | | #71 | Ready | `378240888b39218c97c1b5c514492bb0a0cf3aa2` | `f86ce504138e79d6e95141a441f60b40920e1fa6` | | #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `378240888b39218c97c1b5c514492bb0a0cf3aa2` | -| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `d83748a70bd1b16dbfec46007fe02989ba6ce188` | +| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0341079331f9cea669eb9a5cc21842fd6027431e` | | #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `21e9ad1e8da72c81f521152ea6739b088da230f7` | | #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` | | #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fb868589d065c2cea0b9c8c0f5e655a89f42bee6` | diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index bcbbb49bb..fc977ac8d 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -56,7 +56,7 @@ def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> No "| #71 | Ready | `378240888b39218c97c1b5c514492bb0a0cf3aa2` | `f86ce504138e79d6e95141a441f60b40920e1fa6` |", "| #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `378240888b39218c97c1b5c514492bb0a0cf3aa2` |", "| #152 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `81407a0e5189a413d1be0963fea90a0c2f254ce1` |", - "| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `d83748a70bd1b16dbfec46007fe02989ba6ce188` |", + "| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0341079331f9cea669eb9a5cc21842fd6027431e` |", "| #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `21e9ad1e8da72c81f521152ea6739b088da230f7` |", "| #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` |", "| #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fb868589d065c2cea0b9c8c0f5e655a89f42bee6` |", diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 44df493fb..483155ebc 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -77,6 +77,27 @@ def test_active_github_approval_rule_is_not_documented_as_bypassable(self) -> No self.assertIn("reviewer-provisioning gap", text) self.assertNotIn("owner-directed administrative merge", text) + def test_baseline_records_missing_required_workflow_identities(self) -> None: + """The baseline must preserve the exact current required-workflow gap.""" + text = BASELINE.read_text(encoding="utf-8") + + for phrase in ( + "required workflow identities", + "close-empty-pr", + "opencode-review", + "pr-review-merge-scheduler", + "security-scan", + "strix", + "sast-semgrep", + "noema-review", + "run lookup returned 404", + "327727411", + "327727415", + "does not authorize bypass", + ): + with self.subTest(phrase=phrase): + self.assertIn(phrase, text) + def test_same_day_prior_inventory_is_bound_to_the_maintenance_record(self) -> None: """A same-day comparison must retain its exact prior observation in the record.""" text = BASELINE.read_text(encoding="utf-8") From 4b5fa6f3331f0cdf31bc004feb482eef2e47bb86 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 23:14:43 +0900 Subject: [PATCH 018/250] docs: correct central workflow failure evidence --- CHANGELOG.md | 2 +- docs/product-technical-gap-baseline.md | 2 +- tests/test_product_completion_gap_contract.py | 16 ++++++++++------ 3 files changed, 12 insertions(+), 8 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index a7f633691..bf3bc6e60 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -13,7 +13,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Hardened the product-completion documentation contract by classifying current-snapshot count markers explicitly instead of routing them by substring heuristics. - Corrected the baseline's #72/#73 exact SHA evidence to full 40-character values and tracked PR #238's current head. - Refreshed the baseline's #210 WARC row to exact Ready head `d83748a70bd1b16dbfec46007fe02989ba6ce188` and recorded its nested credential-query defense and current-head hosted-check regeneration. -- Refreshed the baseline's #210 WARC row to exact Ready head `0341079331f9cea669eb9a5cc21842fd6027431e`, including encoded-control rejection, and recorded the active ruleset's missing required workflow identities with exact PR #70 404 evidence without weakening any gate. +- Refreshed the baseline's #210 WARC row to exact Ready head `0341079331f9cea669eb9a5cc21842fd6027431e`, including encoded-control rejection, and corrected required-workflow provenance to the central `.github` repository with exact OpenCode/Strix failure evidence without weakening any gate. - Removed the self-referential #238 exact-head row from the baseline; the live PR metadata and body remain authoritative because every documentation update necessarily creates a new branch head. - Added `originweave_core::release_acceptance`, a deterministic fail-closed benchmark release-decision contract that requires one authoritative result for every mandatory suite, bounds explicit buyer-visible limitations, rejects duplicate limitation claim identities, and rejects non-canonical surrounding whitespace rather than normalizing it into an alternate claim spelling. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 1edda3681..43058a97e 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -22,7 +22,7 @@ This snapshot re-fetched the complete open-PR inventory, the protected `main` co The later exact-head recheck also recorded the WARC/PROV retention-lifecycle slice: #239 is Draft at `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` on #227 head `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0`, with its Rust contracts and production coverage checks successful, zero unresolved threads, and no counted approval. #237 is Draft at `21e9ad1e8da72c81f521152ea6739b088da230f7` on protected `main`; its deterministic contracts and coverage are successful, while exact-head `opencode-review` failed closed for the absent current-head verdict and `strix` remained in progress. Neither active branch is protected-main behavior. -The same exact-head recheck found a required workflow identities gap: the active ruleset names seven required workflow paths (`close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, and `noema-review`), but protected `main` and the current Actions workflow inventory exposed none of those paths. On PR #70 head `378240888b39218c97c1b5c514492bb0a0cf3aa2`, the exact current-head run lookup returned 404 for the `opencode-review` and `strix` workflow IDs `327727411` and `327727415`. This is unavailable or deleted workflow-identity evidence, not passing review or security evidence. It blocks affected PRs until the central workflow authority restores or deliberately rebinds the identities; it does not authorize bypass, self-approval, stale checks, or weaker gates. +The same exact-head recheck corrected workflow provenance: the active ruleset's seven required workflow entries (`close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, and `noema-review`) point to the central `.github` repository, repository ID `1274066402`, where all seven files exist on `main`; their absence from the OriginWeave tree did not prove missing workflow identities. On PR #210 head `0341079331f9cea669eb9a5cc21842fd6027431e`, run `33177641855` failed closed because no OpenCode current-head verdict existed, while run `33177641888` failed closed after three bounded attempts because the Strix provider/backend returned an internal server error and produced no vulnerability report. A `gh run view` workflow-endpoint 404 for the external workflow IDs is a lookup mismatch, not passing evidence or proof that the identities are absent. A bounded central scheduler dispatch was accepted as run `33178984025` with auto-merge and branch updates disabled; no result is transferred until the exact head is revalidated. These failures block affected PRs until current-head review and security evidence complete. This does not authorize bypass, self-approval, stale checks, or weaker gates. The WARC resource-record slice #210 is now Ready at exact head `0341079331f9cea669eb9a5cc21842fd6027431e`, based directly on protected `main`; its latest forward-only repair rejects raw and recursively percent-encoded nested credential names and percent-encoded ASCII controls. Local evidence is green, while the current-head hosted CI, security, Noema, scheduler, and OpenCode workflows were still regenerating at the recheck; no predecessor status is promoted and no counted approval exists. diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 483155ebc..d220b21fe 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -77,12 +77,13 @@ def test_active_github_approval_rule_is_not_documented_as_bypassable(self) -> No self.assertIn("reviewer-provisioning gap", text) self.assertNotIn("owner-directed administrative merge", text) - def test_baseline_records_missing_required_workflow_identities(self) -> None: - """The baseline must preserve the exact current required-workflow gap.""" + def test_baseline_records_central_required_workflow_failures(self) -> None: + """The baseline must preserve exact central workflow provenance and failures.""" text = BASELINE.read_text(encoding="utf-8") for phrase in ( - "required workflow identities", + "central `.github` repository", + "repository ID `1274066402`", "close-empty-pr", "opencode-review", "pr-review-merge-scheduler", @@ -90,9 +91,12 @@ def test_baseline_records_missing_required_workflow_identities(self) -> None: "strix", "sast-semgrep", "noema-review", - "run lookup returned 404", - "327727411", - "327727415", + "OpenCode current-head verdict", + "Strix provider/backend", + "internal server error", + "33177641855", + "33177641888", + "did not prove missing workflow identities", "does not authorize bypass", ): with self.subTest(phrase=phrase): From 9c877adbf1db560104b5733d6b414f5bdc0f2fa3 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 23:16:18 +0900 Subject: [PATCH 019/250] docs: bind workflow status to exact failures --- docs/product-technical-gap-baseline.md | 2 +- tests/test_product_completion_gap_contract.py | 5 +++++ 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 43058a97e..d8eefde4d 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -24,7 +24,7 @@ The later exact-head recheck also recorded the WARC/PROV retention-lifecycle sli The same exact-head recheck corrected workflow provenance: the active ruleset's seven required workflow entries (`close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, and `noema-review`) point to the central `.github` repository, repository ID `1274066402`, where all seven files exist on `main`; their absence from the OriginWeave tree did not prove missing workflow identities. On PR #210 head `0341079331f9cea669eb9a5cc21842fd6027431e`, run `33177641855` failed closed because no OpenCode current-head verdict existed, while run `33177641888` failed closed after three bounded attempts because the Strix provider/backend returned an internal server error and produced no vulnerability report. A `gh run view` workflow-endpoint 404 for the external workflow IDs is a lookup mismatch, not passing evidence or proof that the identities are absent. A bounded central scheduler dispatch was accepted as run `33178984025` with auto-merge and branch updates disabled; no result is transferred until the exact head is revalidated. These failures block affected PRs until current-head review and security evidence complete. This does not authorize bypass, self-approval, stale checks, or weaker gates. -The WARC resource-record slice #210 is now Ready at exact head `0341079331f9cea669eb9a5cc21842fd6027431e`, based directly on protected `main`; its latest forward-only repair rejects raw and recursively percent-encoded nested credential names and percent-encoded ASCII controls. Local evidence is green, while the current-head hosted CI, security, Noema, scheduler, and OpenCode workflows were still regenerating at the recheck; no predecessor status is promoted and no counted approval exists. +The WARC resource-record slice #210 is now Ready at exact head `0341079331f9cea669eb9a5cc21842fd6027431e`, based directly on protected `main`; its latest forward-only repair rejects raw and recursively percent-encoded nested credential names and percent-encoded ASCII controls. Local evidence is green, while the exact-head hosted failures are recorded above and the central scheduler re-dispatch is still pending; no predecessor status is promoted and no counted approval exists. The controlled Chromium prerequisite stack was also re-fetched after its exact-head repairs: #70 is Ready at `378240888b39218c97c1b5c514492bb0a0cf3aa2` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`, #71 is Ready at `f86ce504138e79d6e95141a441f60b40920e1fa6` on #70, #72 is Draft at `600d3975c02b68da1974a4c73069b966b39dce7b` on #71, and #73 is Draft at `ce1b138509ab4f52cb0f80290f104358473c6ed3` on #72. #70's Rust, coverage, pinned-Chrome, and ordinary security checks are successful but its exact-head `opencode-review` and `strix` checks failed closed; #71's Rust contracts, production coverage, and pinned-Chrome checks are successful, with no unresolved current thread, but neither has counted approval. #72's and #73's exact-head Rust, coverage, and pinned-Chrome checks are successful after their non-destructive restacks; no predecessor results transfer and neither has counted approval. #152 is Ready at `81407a0e5189a413d1be0963fea90a0c2f254ce1` on protected `main`; its source, coverage, and security checks are successful except exact-head `opencode-review`, which failed closed without a current-head verdict. These are active-stack evidence only, not protected-main behavior or merge authorization. diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index d220b21fe..237defd51 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -51,6 +51,11 @@ def test_baseline_records_current_inventory_and_completion_issues(self) -> None: with self.subTest(phrase=phrase): self.assertIn(phrase, text) + self.assertNotIn( + "current-head hosted CI, security, Noema, scheduler, and OpenCode workflows were still regenerating at the recheck", + text, + ) + for stale_phrase in ( "100 open pull requests", "22 non-draft", From a505b9fb8ea2a04d3d4a4193e458b232f7478a37 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 00:02:32 +0900 Subject: [PATCH 020/250] docs: record exact review-tool rerun evidence --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 4 +++- tests/test_product_completion_gap_contract.py | 6 ++++++ 3 files changed, 10 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index bf3bc6e60..a4ef2a326 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -14,6 +14,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Corrected the baseline's #72/#73 exact SHA evidence to full 40-character values and tracked PR #238's current head. - Refreshed the baseline's #210 WARC row to exact Ready head `d83748a70bd1b16dbfec46007fe02989ba6ce188` and recorded its nested credential-query defense and current-head hosted-check regeneration. - Refreshed the baseline's #210 WARC row to exact Ready head `0341079331f9cea669eb9a5cc21842fd6027431e`, including encoded-control rejection, and corrected required-workflow provenance to the central `.github` repository with exact OpenCode/Strix failure evidence without weakening any gate. +- Recorded the exact #238 OpenCode model-unavailable rerun (`33182772296`) and central scheduler dispatch (`33182749298`), and linked the central Rust coverage repair PR #1391 without promoting review-tool output to approval. - Removed the self-referential #238 exact-head row from the baseline; the live PR metadata and body remain authoritative because every documentation update necessarily creates a new branch head. - Added `originweave_core::release_acceptance`, a deterministic fail-closed benchmark release-decision contract that requires one authoritative result for every mandatory suite, bounds explicit buyer-visible limitations, rejects duplicate limitation claim identities, and rejects non-canonical surrounding whitespace rather than normalizing it into an alternate claim spelling. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index d8eefde4d..2f5e7169c 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -24,7 +24,9 @@ The later exact-head recheck also recorded the WARC/PROV retention-lifecycle sli The same exact-head recheck corrected workflow provenance: the active ruleset's seven required workflow entries (`close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, and `noema-review`) point to the central `.github` repository, repository ID `1274066402`, where all seven files exist on `main`; their absence from the OriginWeave tree did not prove missing workflow identities. On PR #210 head `0341079331f9cea669eb9a5cc21842fd6027431e`, run `33177641855` failed closed because no OpenCode current-head verdict existed, while run `33177641888` failed closed after three bounded attempts because the Strix provider/backend returned an internal server error and produced no vulnerability report. A `gh run view` workflow-endpoint 404 for the external workflow IDs is a lookup mismatch, not passing evidence or proof that the identities are absent. A bounded central scheduler dispatch was accepted as run `33178984025` with auto-merge and branch updates disabled; no result is transferred until the exact head is revalidated. These failures block affected PRs until current-head review and security evidence complete. This does not authorize bypass, self-approval, stale checks, or weaker gates. -The WARC resource-record slice #210 is now Ready at exact head `0341079331f9cea669eb9a5cc21842fd6027431e`, based directly on protected `main`; its latest forward-only repair rejects raw and recursively percent-encoded nested credential names and percent-encoded ASCII controls. Local evidence is green, while the exact-head hosted failures are recorded above and the central scheduler re-dispatch is still pending; no predecessor status is promoted and no counted approval exists. +The WARC resource-record slice #210 is now Ready at exact head `0341079331f9cea669eb9a5cc21842fd6027431e`, based directly on protected `main`; its latest forward-only repair rejects raw and recursively percent-encoded nested credential names and percent-encoded ASCII controls. Local evidence is green, while the exact-head hosted failures are recorded above; central repair PR #1391 is open at `e4ba6b599cd1e50d0139762885682607b731655d` and no predecessor status is promoted or counted approval exists. + +The documentation refresh PR #238 was rechecked at exact head `9c877adbf1db560104b5733d6b414f5bdc0f2fa3`: its coverage, security, Noema, and scheduler checks completed, but required OpenCode run `33179334415` failed closed without a current-head verdict. Targeted central scheduler run `33182749298` completed with auto-merge and branch updates disabled and dispatched OpenCode run `33182772296`; coverage evidence succeeded, but the review failed closed as `MODEL_OUTPUT_UNAVAILABLE` with the failure reason `model pool exhausted` and no current-head control block. Optional cross-repository status publication was denied with HTTP 403 due the unavailable target write credential. These are review-tool failures, not approval or shipping evidence. The controlled Chromium prerequisite stack was also re-fetched after its exact-head repairs: #70 is Ready at `378240888b39218c97c1b5c514492bb0a0cf3aa2` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`, #71 is Ready at `f86ce504138e79d6e95141a441f60b40920e1fa6` on #70, #72 is Draft at `600d3975c02b68da1974a4c73069b966b39dce7b` on #71, and #73 is Draft at `ce1b138509ab4f52cb0f80290f104358473c6ed3` on #72. #70's Rust, coverage, pinned-Chrome, and ordinary security checks are successful but its exact-head `opencode-review` and `strix` checks failed closed; #71's Rust contracts, production coverage, and pinned-Chrome checks are successful, with no unresolved current thread, but neither has counted approval. #72's and #73's exact-head Rust, coverage, and pinned-Chrome checks are successful after their non-destructive restacks; no predecessor results transfer and neither has counted approval. #152 is Ready at `81407a0e5189a413d1be0963fea90a0c2f254ce1` on protected `main`; its source, coverage, and security checks are successful except exact-head `opencode-review`, which failed closed without a current-head verdict. These are active-stack evidence only, not protected-main behavior or merge authorization. diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 237defd51..76b07fa03 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -101,6 +101,12 @@ def test_baseline_records_central_required_workflow_failures(self) -> None: "internal server error", "33177641855", "33177641888", + "33182772296", + "MODEL_OUTPUT_UNAVAILABLE", + "model pool exhausted", + "33182749298", + "#1391", + "e4ba6b599cd1e50d0139762885682607b731655d", "did not prove missing workflow identities", "does not authorize bypass", ): From 6a39bbef41ee8b478bf162d3c1dd1e02d91a5b3f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 00:19:06 +0900 Subject: [PATCH 021/250] docs: mark superseded WARC head historical --- CHANGELOG.md | 2 +- tests/test_product_completion_gap_contract.py | 7 +++++++ 2 files changed, 8 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index a4ef2a326..cfc764ab2 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -12,7 +12,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Refreshed the product and technical gap baseline onto the 2026-08-28 live inventory; current queue and exact-head evidence are explicitly separated from the historical 2026-08-26 snapshot so stale delivery evidence cannot be promoted. - Hardened the product-completion documentation contract by classifying current-snapshot count markers explicitly instead of routing them by substring heuristics. - Corrected the baseline's #72/#73 exact SHA evidence to full 40-character values and tracked PR #238's current head. -- Refreshed the baseline's #210 WARC row to exact Ready head `d83748a70bd1b16dbfec46007fe02989ba6ce188` and recorded its nested credential-query defense and current-head hosted-check regeneration. +- Historical predecessor: PR #210 Ready head `d83748a70bd1b16dbfec46007fe02989ba6ce188` was superseded by exact Ready head `0341079331f9cea669eb9a5cc21842fd6027431e`; the earlier entry recorded its nested credential-query defense and current-head hosted-check regeneration. - Refreshed the baseline's #210 WARC row to exact Ready head `0341079331f9cea669eb9a5cc21842fd6027431e`, including encoded-control rejection, and corrected required-workflow provenance to the central `.github` repository with exact OpenCode/Strix failure evidence without weakening any gate. - Recorded the exact #238 OpenCode model-unavailable rerun (`33182772296`) and central scheduler dispatch (`33182749298`), and linked the central Rust coverage repair PR #1391 without promoting review-tool output to approval. - Removed the self-referential #238 exact-head row from the baseline; the live PR metadata and body remain authoritative because every documentation update necessarily creates a new branch head. diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 76b07fa03..52183d1d9 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -82,6 +82,13 @@ def test_active_github_approval_rule_is_not_documented_as_bypassable(self) -> No self.assertIn("reviewer-provisioning gap", text) self.assertNotIn("owner-directed administrative merge", text) + def test_changelog_marks_superseded_warc_head_as_historical(self) -> None: + """A predecessor WARC head must not look like the current exact evidence.""" + text = (ROOT / "CHANGELOG.md").read_text(encoding="utf-8") + + self.assertIn("`d83748a70bd1b16dbfec46007fe02989ba6ce188` was superseded", text) + self.assertIn("0341079331f9cea669eb9a5cc21842fd6027431e", text) + def test_baseline_records_central_required_workflow_failures(self) -> None: """The baseline must preserve exact central workflow provenance and failures.""" text = BASELINE.read_text(encoding="utf-8") From 5181ef9eff472c0e8ca59b782bffc37d6df6b425 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 00:52:18 +0900 Subject: [PATCH 022/250] docs: refresh live delivery gap baseline --- CHANGELOG.md | 2 +- docs/product-technical-gap-baseline.md | 24 ++++++++++--------- tests/test_product_completion_gap_contract.py | 8 +++---- 3 files changed, 18 insertions(+), 16 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index cfc764ab2..a932b9a93 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,7 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] -- Refreshed the product-gap queue to 116 open pull requests (32 ready, 84 draft) on 2026-08-28; these are queue evidence, not protected-main shipment. +- Refreshed the product-gap queue to 111 open pull requests (27 ready, 84 draft) on 2026-08-28 after #71, #154, #233, #234, and #235 merged into unprotected feature parents; these are queue evidence, not protected-main shipment. ### Added - Clarified the 2026-08-28 gap snapshot's prior queue observation and separated open issues from governance signals. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 2f5e7169c..69828accb 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -14,21 +14,23 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a ### Open pull requests -The live repository contained **116 open pull requests: 32 non-draft and 84 draft** when this snapshot re-paginated the complete open inventory. Compared with the prior **2026-08-28 115-PR snapshot**, the current inventory is one PR larger. These counts are queue evidence, not protected-main delivery; protected `main` remains `542ca1e9c0a863595b8b6697790005d2471f5413`, with 11 open issues and no releases or tags. The volume and stack depth remain themselves a product-delivery risk: review, exact-head checks, dependency order, and integration truth can drift faster than a buyer-visible vertical slice reaches protected `main`. +The live repository contained **111 open pull requests: 27 non-draft and 84 draft** when this snapshot re-paginated the complete open inventory. Compared with the prior **2026-08-28 116-PR snapshot**, five stacked evidence PRs (#71, #154, #233, #234, and #235) were merged into their unprotected feature parents; none reached protected `main`. These counts are queue evidence, not protected-main delivery; protected `main` remains `542ca1e9c0a863595b8b6697790005d2471f5413`, with 11 open issues and no releases or tags. The volume and stack depth remain themselves a product-delivery risk: review, exact-head checks, dependency order, and integration truth can drift faster than a buyer-visible vertical slice reaches protected `main`. #### 2026-08-28 maintenance-loop record -This snapshot re-fetched the complete open-PR inventory, the protected `main` commit, the active required-workflow ruleset, collaborator permissions, and the exact base/head pair for each representative PR. Before PR #238 was published, the same maintenance loop observed 115 open pull requests (31 ready, 84 draft); the current re-paginated inventory is one PR larger. The active ruleset still requires one counted approving review and resolved threads; the only repository collaborator is `seonghobae`, so review provisioning remains the merge blocker. PR #170 is merged and is not active-PR evidence. +This snapshot re-fetched the complete open-PR inventory, the protected `main` commit, the active required-workflow ruleset, collaborator permissions, and the exact base/head pair for each representative PR. Before PR #238 was published, the same maintenance loop observed 115 open pull requests (31 ready, 84 draft); a later 116-PR recheck preceded five stack merges, leaving 111 open pull requests (27 ready, 84 draft). The active ruleset still requires one counted approving review and resolved threads; the only repository collaborator is `seonghobae`, so review provisioning remains the merge blocker for main-targeting PRs. PR #170 is merged and is not active-PR evidence. + +During this recheck, #71, #154, #233, #234, and #235 were merged only into their unprotected feature-parent branches after exact current-head checks and review-thread resolution. Their successful stack checks are not protected-main delivery, and their child branches retain independent evidence requirements. The later exact-head recheck also recorded the WARC/PROV retention-lifecycle slice: #239 is Draft at `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` on #227 head `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0`, with its Rust contracts and production coverage checks successful, zero unresolved threads, and no counted approval. #237 is Draft at `21e9ad1e8da72c81f521152ea6739b088da230f7` on protected `main`; its deterministic contracts and coverage are successful, while exact-head `opencode-review` failed closed for the absent current-head verdict and `strix` remained in progress. Neither active branch is protected-main behavior. The same exact-head recheck corrected workflow provenance: the active ruleset's seven required workflow entries (`close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, and `noema-review`) point to the central `.github` repository, repository ID `1274066402`, where all seven files exist on `main`; their absence from the OriginWeave tree did not prove missing workflow identities. On PR #210 head `0341079331f9cea669eb9a5cc21842fd6027431e`, run `33177641855` failed closed because no OpenCode current-head verdict existed, while run `33177641888` failed closed after three bounded attempts because the Strix provider/backend returned an internal server error and produced no vulnerability report. A `gh run view` workflow-endpoint 404 for the external workflow IDs is a lookup mismatch, not passing evidence or proof that the identities are absent. A bounded central scheduler dispatch was accepted as run `33178984025` with auto-merge and branch updates disabled; no result is transferred until the exact head is revalidated. These failures block affected PRs until current-head review and security evidence complete. This does not authorize bypass, self-approval, stale checks, or weaker gates. -The WARC resource-record slice #210 is now Ready at exact head `0341079331f9cea669eb9a5cc21842fd6027431e`, based directly on protected `main`; its latest forward-only repair rejects raw and recursively percent-encoded nested credential names and percent-encoded ASCII controls. Local evidence is green, while the exact-head hosted failures are recorded above; central repair PR #1391 is open at `e4ba6b599cd1e50d0139762885682607b731655d` and no predecessor status is promoted or counted approval exists. +The WARC resource-record slice #210 is now Ready at exact head `0341079331f9cea669eb9a5cc21842fd6027431e`, based directly on protected `main`; its latest forward-only repair rejects raw and recursively percent-encoded nested credential names and percent-encoded ASCII controls. Local evidence is green, while the exact-head hosted failures are recorded above; central repair PR #1391 was opened at historical head `e4ba6b599cd1e50d0139762885682607b731655d` and is now open at exact head `48ec8ce041c299d956a76ed7d52658920bb64cf8` on current central `main` `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Its branch-update merge is not approval or coverage evidence. -The documentation refresh PR #238 was rechecked at exact head `9c877adbf1db560104b5733d6b414f5bdc0f2fa3`: its coverage, security, Noema, and scheduler checks completed, but required OpenCode run `33179334415` failed closed without a current-head verdict. Targeted central scheduler run `33182749298` completed with auto-merge and branch updates disabled and dispatched OpenCode run `33182772296`; coverage evidence succeeded, but the review failed closed as `MODEL_OUTPUT_UNAVAILABLE` with the failure reason `model pool exhausted` and no current-head control block. Optional cross-repository status publication was denied with HTTP 403 due the unavailable target write credential. These are review-tool failures, not approval or shipping evidence. +The documentation refresh PR #238 is Ready at exact head `6a39bbef41ee8b478bf162d3c1dd1e02d91a5b3f` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`: current Rust, coverage, security, Noema, scheduler, and repository checks are successful, but required OpenCode run `33184553025` / job `98894986761` failed closed because no `APPROVED` or `CHANGES_REQUESTED` verdict existed on that exact head. Earlier targeted run `33182749298` dispatched OpenCode run `33182772296`, whose coverage evidence succeeded but review failed closed as `MODEL_OUTPUT_UNAVAILABLE` with `model pool exhausted`; optional cross-repository status publication was denied with HTTP 403. These are review-tool failures, not approval or shipping evidence, and the branch has not been merged. -The controlled Chromium prerequisite stack was also re-fetched after its exact-head repairs: #70 is Ready at `378240888b39218c97c1b5c514492bb0a0cf3aa2` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`, #71 is Ready at `f86ce504138e79d6e95141a441f60b40920e1fa6` on #70, #72 is Draft at `600d3975c02b68da1974a4c73069b966b39dce7b` on #71, and #73 is Draft at `ce1b138509ab4f52cb0f80290f104358473c6ed3` on #72. #70's Rust, coverage, pinned-Chrome, and ordinary security checks are successful but its exact-head `opencode-review` and `strix` checks failed closed; #71's Rust contracts, production coverage, and pinned-Chrome checks are successful, with no unresolved current thread, but neither has counted approval. #72's and #73's exact-head Rust, coverage, and pinned-Chrome checks are successful after their non-destructive restacks; no predecessor results transfer and neither has counted approval. #152 is Ready at `81407a0e5189a413d1be0963fea90a0c2f254ce1` on protected `main`; its source, coverage, and security checks are successful except exact-head `opencode-review`, which failed closed without a current-head verdict. These are active-stack evidence only, not protected-main behavior or merge authorization. +The controlled Chromium prerequisite stack was also re-fetched after its exact-head repairs: #70 is Ready at `441a8ce1d09c329c5c1168f4906d9a38fd0abc01` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`; #71 is merged into the unprotected #70 feature branch; #72 is Draft at `600d3975c02b68da1974a4c73069b966b39dce7b` on the retained #71 branch; and #73 is Draft at `ce1b138509ab4f52cb0f80290f104358473c6ed3` on #72. #70's Rust, coverage, pinned-Chrome, and ordinary security checks are successful while its exact-head OpenCode verdict remains failed closed and Strix is still running; #72 and #73 retain independent exact-head evidence requirements. #152 is Ready at `81407a0e5189a413d1be0963fea90a0c2f254ce1` on protected `main`; its source, coverage, and security checks are successful except exact-head `opencode-review`, which failed closed without a current-head verdict. These are active-stack evidence only, not protected-main behavior or merge authorization. #### Current exact-head active PR evidence @@ -38,12 +40,12 @@ The following representative slices were re-fetched from GitHub for this snapsho |---|---|---|---| | #73 | Draft | `600d3975c02b68da1974a4c73069b966b39dce7b` | `ce1b138509ab4f52cb0f80290f104358473c6ed3` | | #72 | Draft | `f86ce504138e79d6e95141a441f60b40920e1fa6` | `600d3975c02b68da1974a4c73069b966b39dce7b` | -| #71 | Ready | `378240888b39218c97c1b5c514492bb0a0cf3aa2` | `f86ce504138e79d6e95141a441f60b40920e1fa6` | -| #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `378240888b39218c97c1b5c514492bb0a0cf3aa2` | +| #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `441a8ce1d09c329c5c1168f4906d9a38fd0abc01` | +| #82 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `f5776f5f233ac0a7c05e3f4a2846436c23438043` | | #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0341079331f9cea669eb9a5cc21842fd6027431e` | | #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `21e9ad1e8da72c81f521152ea6739b088da230f7` | | #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` | -| #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fb868589d065c2cea0b9c8c0f5e655a89f42bee6` | +| #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0145ccba5901e301b41d4be674ca1ed23483ad37` | | #220 | Ready | `f658f329c83a106b68385e17cb714c4147c12f49` | `a2b0c5372dd6df803011933836c56136244dc8af` | | #211 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `52a918577958a5701e1146c7eb8b62fe8f8ccd44` | | #152 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `81407a0e5189a413d1be0963fea90a0c2f254ce1` | @@ -84,9 +86,9 @@ Representative active workstreams at this snapshot were: | WebDriver BiDi transport | #188 through #205 | Active stack whose top #205 merged into its prerequisite branch, not protected `main`; it exercises framed `locateNodes` exchange over a bounded WebSocket opening path, but authenticated browser-process provenance, semantic task execution, and protected-main shipment remain unproven | | MCP adapter | (#168 and #170 merged) | Typed MCP routing and conservative `tools/list` cache metadata are protected-main behavior; the complete MCP transport, OAuth, browser I/O, and persistence adapter remains planned | | Workflow-registry audit | #124 | Real Strix finding vuln-0001 (Unicode homoglyph path confusion, MEDIUM) remediated on head `30cc458b` with regression contract tests; fresh exact-head checks and review re-running | -| Controlled Chromium and recovery | #65, #70-#73, #100, #105, #142-#152 and descendants | Real pinned-browser fixture, semantic location, resource, crash, and teardown evidence exists on active stacks; evidence does not transfer across heads or prerequisites | +| Controlled Chromium and recovery | #65, #70, #72-#73, #100, #105, #142-#152 and descendants | Real pinned-browser fixture, semantic location, resource, crash, and teardown evidence exists on active stacks; #71 is merged only into the #70 feature branch, and evidence does not transfer across heads or prerequisites | | Durable WARC/PROV evidence | #210, #217, #239 | Bounded WARC resource records, PROV JSON-LD binding, and retention-lifecycle boundaries are active-PR foundations; durable ownership, replay, retention/deletion, and browser side-effect reconciliation remain open | -| Manifest V3 and native messaging | #27, #43 governance remediation, and the extension/native-host stack including #154 and #169 | Compatibility and Agent-authority isolation remain incomplete until exact release artifacts and platform matrices are proven; #43's sandbox workflow mutation is now owner-authorized under issue #212 option (b) | +| Manifest V3 and native messaging | #27, #43 governance remediation, and the extension/native-host stack including merged #154 and active #169 | Compatibility and Agent-authority isolation remain incomplete until exact release artifacts and platform matrices are proven; #43's sandbox workflow mutation is now owner-authorized under issue #212 option (b) | | Sensitive-data and model route policy | #10 and its active policy stacks | Deterministic policy values exist, but trusted broker execution, retention/deletion, runtime isolation, and auditable product workflows remain open | | VPN/profile intent | #149 | Bounded WireGuard/IKEv2 profile authority reconciled with main (`54f96008`); it does not create a tunnel, route, DNS state, authenticated gateway, or connectivity proof | @@ -189,7 +191,7 @@ The hourly product-development loop is operational infrastructure, not proof tha | P1 | Buyers can install, update, verify, and roll back a supported product | **Not shipped** | #201; signed Windows/macOS/Linux/headless artifacts, Chromium revision manifest, updater security, patch SLA, SBOM, SLSA provenance, and recovery | | P1 | Enterprise teams can provision, approve, audit, operate, and recover the service | **Not shipped** | #202; Keyverse-compatible OIDC/SCIM, tenant isolation, policy/approval/evidence UI, SLO/incident controls, data residency, CSAP/SOC 2 evidence mapping, WCAG 2.2, Figma File ID, and Storybook | | P0 | A release has reproducible proof of usefulness, safety, evidence completeness, and recovery | **No product-wide release gate** | #203; deterministic, compatibility, adversarial, recovery, and enterprise suites with statistical reporting and an exact-artifact commercial acceptance gate | -| P0 | Valid changes reach protected `main` without authority improvisation or unbounded stack growth | **Blocked / high integration debt** | Shrink the 116-PR queue in dependency order, provision legitimate review authority, require exact-current evidence, and close duplicates/superseded branches | +| P0 | Valid changes reach protected `main` without authority improvisation or unbounded stack growth | **Blocked / high integration debt** | Shrink the 111-PR queue in dependency order, provision legitimate review authority, require exact-current evidence, and close duplicates/superseded branches | ## Commercial completion definition diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 52183d1d9..3d3e9a0ae 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -26,10 +26,10 @@ def test_baseline_records_current_inventory_and_completion_issues(self) -> None: current = text.split("## Observed snapshot: ", 1)[1].split(end_marker, 1)[0] for phrase in ( - "116 open pull requests", - "32 non-draft", + "111 open pull requests", + "27 non-draft", "84 draft", - "2026-08-28 115-PR snapshot", + "2026-08-28 116-PR snapshot", ): with self.subTest(phrase=phrase): self.assertIn(phrase, current) @@ -41,7 +41,7 @@ def test_baseline_records_current_inventory_and_completion_issues(self) -> None: "#201", "#202", "#203", - "Shrink the 116-PR queue", + "Shrink the 111-PR queue", "durable WARC/PROV replay", "stable BAP/MCP runtime API", "signed cross-platform Chromium distribution", From 0c14e33c5c7ccff327a340642eaaf630cf951417 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 00:56:21 +0900 Subject: [PATCH 023/250] test: align live gap snapshot contracts --- CHANGELOG.md | 2 +- .../test_documentation_active_pr_evidence_contract.py | 8 ++++---- tests/test_gap_snapshot_inventory_consistency.py | 10 ++++++---- 3 files changed, 11 insertions(+), 9 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index a932b9a93..2afcca26e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -8,7 +8,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ### Added - Clarified the 2026-08-28 gap snapshot's prior queue observation and separated open issues from governance signals. -- Corrected the 2026-08-28 product-gap snapshot with protected-main `542ca1e9`, 116 open pull requests (32 ready, 84 draft), 11 open issues, current exact base/head pairs for representative PRs including #70, #71, #152, #37, #237, and #239, PR #170's merged `tools/list` contract, the active counted-approval gate, and the unchanged Phase 1 browser gap. +- Corrected the 2026-08-28 product-gap snapshot with protected-main `542ca1e9`, 111 open pull requests (27 ready, 84 draft), 11 open issues, current exact base/head pairs for representative PRs including #70, #82, #152, #37, #237, and #239, PR #170's merged `tools/list` contract, the active counted-approval gate, and the unchanged Phase 1 browser gap. - Refreshed the product and technical gap baseline onto the 2026-08-28 live inventory; current queue and exact-head evidence are explicitly separated from the historical 2026-08-26 snapshot so stale delivery evidence cannot be promoted. - Hardened the product-completion documentation contract by classifying current-snapshot count markers explicitly instead of routing them by substring heuristics. - Corrected the baseline's #72/#73 exact SHA evidence to full 40-character values and tracked PR #238's current head. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index fc977ac8d..5b6e0f314 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -53,13 +53,13 @@ def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> No for marker in ( "| #73 | Draft | `600d3975c02b68da1974a4c73069b966b39dce7b` | `ce1b138509ab4f52cb0f80290f104358473c6ed3` |", "| #72 | Draft | `f86ce504138e79d6e95141a441f60b40920e1fa6` | `600d3975c02b68da1974a4c73069b966b39dce7b` |", - "| #71 | Ready | `378240888b39218c97c1b5c514492bb0a0cf3aa2` | `f86ce504138e79d6e95141a441f60b40920e1fa6` |", - "| #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `378240888b39218c97c1b5c514492bb0a0cf3aa2` |", + "| #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `441a8ce1d09c329c5c1168f4906d9a38fd0abc01` |", + "| #82 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `f5776f5f233ac0a7c05e3f4a2846436c23438043` |", "| #152 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `81407a0e5189a413d1be0963fea90a0c2f254ce1` |", "| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0341079331f9cea669eb9a5cc21842fd6027431e` |", "| #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `21e9ad1e8da72c81f521152ea6739b088da230f7` |", "| #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` |", - "| #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fb868589d065c2cea0b9c8c0f5e655a89f42bee6` |", + "| #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0145ccba5901e301b41d4be674ca1ed23483ad37` |", "| #220 | Ready | `f658f329c83a106b68385e17cb714c4147c12f49` | `a2b0c5372dd6df803011933836c56136244dc8af` |", "| #211 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `52a918577958a5701e1146c7eb8b62fe8f8ccd44` |", "| #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | `72f112d52a60e7caa992a3f5ff7f16d5d9a4d047` |", @@ -79,7 +79,7 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: refresh_lines = [line for line in added.splitlines() if line.startswith(refresh_prefix)] self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] - self.assertIn("116 open pull requests (32 ready, 84 draft)", refresh_line) + self.assertIn("111 open pull requests (27 ready, 84 draft)", refresh_line) self.assertIn("11 open issues", refresh_line) self.assertNotIn(refresh_prefix, changed) self.assertNotIn("115 open pull requests (31 ready, 84 draft)", refresh_line) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index aa34e1e89..c5a6f69a8 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -20,13 +20,13 @@ def setUpClass(cls) -> None: cls.changelog = CHANGELOG.read_text(encoding="utf-8") def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: - """The current snapshot must use the exact 116/32/84 inventory observation.""" + """The current snapshot must use the exact 111/27/84 inventory observation.""" current = self.baseline.split("### Open pull requests", 1)[1].split( "#### 2026-08-28 maintenance-loop record", 1 )[0] for marker in ( - "116 open pull requests", - "32 non-draft", + "111 open pull requests", + "27 non-draft", "84 draft", ): with self.subTest(marker=marker): @@ -39,6 +39,8 @@ def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: "72 draft", "115 open pull requests", "31 non-draft", + "116 open pull requests", + "32 non-draft", "153 open pull requests", "114 draft", ): @@ -51,7 +53,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "116 open pull requests (32 ready, 84 draft)" + expected = "111 open pull requests (27 ready, 84 draft)" self.assertIn(expected, preamble) self.assertIn(expected, added) self.assertNotIn("126 open pull requests (54 ready, 72 draft)", preamble) From 08ea7600a689bdaf27506181663d78912d7cd701 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 01:14:04 +0900 Subject: [PATCH 024/250] docs: enforce MCP traceability evidence --- CHANGELOG.md | 5 ++-- docs/product-technical-gap-baseline.md | 28 +++++++++---------- docs/traceability/README.md | 4 +++ ...cumentation_active_pr_evidence_contract.py | 16 +++++------ tests/test_documentation_fitness_contract.py | 16 +++++++++++ ...test_gap_snapshot_inventory_consistency.py | 10 ++++--- tests/test_product_completion_gap_contract.py | 6 ++-- 7 files changed, 54 insertions(+), 31 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 2afcca26e..7d77a50e0 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,11 +4,12 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] -- Refreshed the product-gap queue to 111 open pull requests (27 ready, 84 draft) on 2026-08-28 after #71, #154, #233, #234, and #235 merged into unprotected feature parents; these are queue evidence, not protected-main shipment. +- Refreshed the product-gap queue to 110 open pull requests (26 ready, 84 draft) on 2026-08-28 after #53, #71, #154, #233, #234, and #235 merged into unprotected feature parents; these are queue evidence, not protected-main shipment. ### Added +- Added an enforcing traceability contract for the protected-main MCP `tools/list` maturity claim and indexed its executable evidence dossier. - Clarified the 2026-08-28 gap snapshot's prior queue observation and separated open issues from governance signals. -- Corrected the 2026-08-28 product-gap snapshot with protected-main `542ca1e9`, 111 open pull requests (27 ready, 84 draft), 11 open issues, current exact base/head pairs for representative PRs including #70, #82, #152, #37, #237, and #239, PR #170's merged `tools/list` contract, the active counted-approval gate, and the unchanged Phase 1 browser gap. +- Corrected the 2026-08-28 product-gap snapshot with protected-main `542ca1e9`, 110 open pull requests (26 ready, 84 draft), 11 open issues, current exact base/head pairs for representative PRs including #70, #82, #152, #37, #237, and #239, PR #170's merged `tools/list` contract, the active counted-approval gate, and the unchanged Phase 1 browser gap. - Refreshed the product and technical gap baseline onto the 2026-08-28 live inventory; current queue and exact-head evidence are explicitly separated from the historical 2026-08-26 snapshot so stale delivery evidence cannot be promoted. - Hardened the product-completion documentation contract by classifying current-snapshot count markers explicitly instead of routing them by substring heuristics. - Corrected the baseline's #72/#73 exact SHA evidence to full 40-character values and tracked PR #238's current head. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 69828accb..4beaa35ef 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -14,11 +14,11 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a ### Open pull requests -The live repository contained **111 open pull requests: 27 non-draft and 84 draft** when this snapshot re-paginated the complete open inventory. Compared with the prior **2026-08-28 116-PR snapshot**, five stacked evidence PRs (#71, #154, #233, #234, and #235) were merged into their unprotected feature parents; none reached protected `main`. These counts are queue evidence, not protected-main delivery; protected `main` remains `542ca1e9c0a863595b8b6697790005d2471f5413`, with 11 open issues and no releases or tags. The volume and stack depth remain themselves a product-delivery risk: review, exact-head checks, dependency order, and integration truth can drift faster than a buyer-visible vertical slice reaches protected `main`. +The live repository contained **110 open pull requests: 26 non-draft and 84 draft** when this snapshot re-paginated the complete open inventory. Compared with the prior **2026-08-28 111-PR snapshot**, stacked evidence PR #53 was merged into its unprotected feature parent; the preceding **2026-08-28 116-PR snapshot** had already recorded #71, #154, #233, #234, and #235 merging into their unprotected feature parents. None reached protected `main`. These counts are queue evidence, not protected-main delivery; protected `main` remains `542ca1e9c0a863595b8b6697790005d2471f5413`, with 11 open issues and no releases or tags. The volume and stack depth remain themselves a product-delivery risk: review, exact-head checks, dependency order, and integration truth can drift faster than a buyer-visible vertical slice reaches protected `main`. #### 2026-08-28 maintenance-loop record -This snapshot re-fetched the complete open-PR inventory, the protected `main` commit, the active required-workflow ruleset, collaborator permissions, and the exact base/head pair for each representative PR. Before PR #238 was published, the same maintenance loop observed 115 open pull requests (31 ready, 84 draft); a later 116-PR recheck preceded five stack merges, leaving 111 open pull requests (27 ready, 84 draft). The active ruleset still requires one counted approving review and resolved threads; the only repository collaborator is `seonghobae`, so review provisioning remains the merge blocker for main-targeting PRs. PR #170 is merged and is not active-PR evidence. +This snapshot re-fetched the complete open-PR inventory, the protected `main` commit, the active required-workflow ruleset, collaborator permissions, and the exact base/head pair for each representative PR. Before PR #238 was published, the same maintenance loop observed 115 open pull requests (31 ready, 84 draft); a later 116-PR recheck preceded five stack merges, leaving 111 open pull requests (27 ready, 84 draft), and the exact current recheck leaves 110 open pull requests (26 ready, 84 draft) after #53 merged. The active ruleset still requires one counted approving review and resolved threads; the only repository collaborator is `seonghobae`, so review provisioning remains the merge blocker for main-targeting PRs. PR #170 is merged and is not active-PR evidence. During this recheck, #71, #154, #233, #234, and #235 were merged only into their unprotected feature-parent branches after exact current-head checks and review-thread resolution. Their successful stack checks are not protected-main delivery, and their child branches retain independent evidence requirements. @@ -26,11 +26,11 @@ The later exact-head recheck also recorded the WARC/PROV retention-lifecycle sli The same exact-head recheck corrected workflow provenance: the active ruleset's seven required workflow entries (`close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, and `noema-review`) point to the central `.github` repository, repository ID `1274066402`, where all seven files exist on `main`; their absence from the OriginWeave tree did not prove missing workflow identities. On PR #210 head `0341079331f9cea669eb9a5cc21842fd6027431e`, run `33177641855` failed closed because no OpenCode current-head verdict existed, while run `33177641888` failed closed after three bounded attempts because the Strix provider/backend returned an internal server error and produced no vulnerability report. A `gh run view` workflow-endpoint 404 for the external workflow IDs is a lookup mismatch, not passing evidence or proof that the identities are absent. A bounded central scheduler dispatch was accepted as run `33178984025` with auto-merge and branch updates disabled; no result is transferred until the exact head is revalidated. These failures block affected PRs until current-head review and security evidence complete. This does not authorize bypass, self-approval, stale checks, or weaker gates. -The WARC resource-record slice #210 is now Ready at exact head `0341079331f9cea669eb9a5cc21842fd6027431e`, based directly on protected `main`; its latest forward-only repair rejects raw and recursively percent-encoded nested credential names and percent-encoded ASCII controls. Local evidence is green, while the exact-head hosted failures are recorded above; central repair PR #1391 was opened at historical head `e4ba6b599cd1e50d0139762885682607b731655d` and is now open at exact head `48ec8ce041c299d956a76ed7d52658920bb64cf8` on current central `main` `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Its branch-update merge is not approval or coverage evidence. +The WARC resource-record slice #210 is now Ready at exact head `bea65643109449d63d367a35b8d9bf327ee7cb2c`, based directly on protected `main`; its latest forward-only repair rejects raw and recursively percent-encoded nested credential names and percent-encoded ASCII controls. Local evidence is green, while the exact-head hosted failures are recorded above; central repair PR #1391 was opened at historical head `e4ba6b599cd1e50d0139762885682607b731655d` and is now open at exact head `36ac3aa71b2580685f84d416a81e42c39dee927c` on current central `main` `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Its branch-update merge and follow-up prompt hardening are not approval or coverage evidence. -The documentation refresh PR #238 is Ready at exact head `6a39bbef41ee8b478bf162d3c1dd1e02d91a5b3f` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`: current Rust, coverage, security, Noema, scheduler, and repository checks are successful, but required OpenCode run `33184553025` / job `98894986761` failed closed because no `APPROVED` or `CHANGES_REQUESTED` verdict existed on that exact head. Earlier targeted run `33182749298` dispatched OpenCode run `33182772296`, whose coverage evidence succeeded but review failed closed as `MODEL_OUTPUT_UNAVAILABLE` with `model pool exhausted`; optional cross-repository status publication was denied with HTTP 403. These are review-tool failures, not approval or shipping evidence, and the branch has not been merged. +The documentation refresh PR #238 is Ready at exact head `0c14e33c5c7ccff327a340642eaaf630cf951417` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`: local full-suite evidence is green, and current repository/security/coverage checks are regenerating for the exact head. Required OpenCode run `33187565535` / job `98904422126` was queued at this recheck, while the preceding exact-head run `33184553025` / job `98894986761` failed closed because no `APPROVED` or `CHANGES_REQUESTED` verdict existed. Earlier targeted run `33182749298` dispatched OpenCode run `33182772296`, whose coverage evidence succeeded but review failed closed as `MODEL_OUTPUT_UNAVAILABLE` with `model pool exhausted`; optional cross-repository status publication was denied with HTTP 403. A current Devin review opened one unresolved documentation-evidence thread requiring an enforcing `tools/list` traceability contract; this snapshot records the finding as active until the follow-up head is verified. These are review-tool/documentation findings, not approval or shipping evidence, and the branch has not been merged. -The controlled Chromium prerequisite stack was also re-fetched after its exact-head repairs: #70 is Ready at `441a8ce1d09c329c5c1168f4906d9a38fd0abc01` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`; #71 is merged into the unprotected #70 feature branch; #72 is Draft at `600d3975c02b68da1974a4c73069b966b39dce7b` on the retained #71 branch; and #73 is Draft at `ce1b138509ab4f52cb0f80290f104358473c6ed3` on #72. #70's Rust, coverage, pinned-Chrome, and ordinary security checks are successful while its exact-head OpenCode verdict remains failed closed and Strix is still running; #72 and #73 retain independent exact-head evidence requirements. #152 is Ready at `81407a0e5189a413d1be0963fea90a0c2f254ce1` on protected `main`; its source, coverage, and security checks are successful except exact-head `opencode-review`, which failed closed without a current-head verdict. These are active-stack evidence only, not protected-main behavior or merge authorization. +The controlled Chromium prerequisite stack was also re-fetched after its exact-head repairs: #70 is Ready at `441a8ce1d09c329c5c1168f4906d9a38fd0abc01` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`; #71 is merged into the unprotected #70 feature branch; #72 is Draft at `600d3975c02b68da1974a4c73069b966b39dce7b` on the retained #71 branch; and #73 is Draft at `ce1b138509ab4f52cb0f80290f104358473c6ed3` on #72. #70's Rust, coverage, pinned-Chrome, and ordinary security checks are successful, while exact-head OpenCode failed closed without a current verdict and exact-head Strix failed closed after three provider HTTP 500 attempts; all current Devin informational threads are resolved. #72 and #73 retain independent exact-head evidence requirements. #82 is Ready at `f5776f5f233ac0a7c05e3f4a2846436c23438043` on protected `main`; its Rust, coverage, Chrome, and ordinary security checks pass, exact-head OpenCode failed closed without a current verdict, and its current Devin informational thread is resolved. #152 is Ready at `81407a0e5189a413d1be0963fea90a0c2f254ce1` on protected `main`; its source, coverage, and security checks are successful except exact-head `opencode-review`, which failed closed without a current-head verdict. These are active-stack evidence only, not protected-main behavior or merge authorization. #### Current exact-head active PR evidence @@ -42,16 +42,16 @@ The following representative slices were re-fetched from GitHub for this snapsho | #72 | Draft | `f86ce504138e79d6e95141a441f60b40920e1fa6` | `600d3975c02b68da1974a4c73069b966b39dce7b` | | #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `441a8ce1d09c329c5c1168f4906d9a38fd0abc01` | | #82 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `f5776f5f233ac0a7c05e3f4a2846436c23438043` | -| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0341079331f9cea669eb9a5cc21842fd6027431e` | -| #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `21e9ad1e8da72c81f521152ea6739b088da230f7` | -| #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` | +| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `bea65643109449d63d367a35b8d9bf327ee7cb2c` | +| #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `2459af602e72fbfe1ce816919473a1075ec0c41f` | +| #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `e840ca299d29a15223c8b9bb1397002c4f41b4a3` | | #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0145ccba5901e301b41d4be674ca1ed23483ad37` | -| #220 | Ready | `f658f329c83a106b68385e17cb714c4147c12f49` | `a2b0c5372dd6df803011933836c56136244dc8af` | +| #220 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `b11db2be68f9b6d71aa4c4290b97a8b22097b353` | | #211 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `52a918577958a5701e1146c7eb8b62fe8f8ccd44` | | #152 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `81407a0e5189a413d1be0963fea90a0c2f254ce1` | -| #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | `72f112d52a60e7caa992a3f5ff7f16d5d9a4d047` | -| #124 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `028789d8bb6cc30b8e84b1ba7ed46556b26e75ea` | -| #37 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `5423803d3fbd9d2d8e08bbd6dbf81ae6b2addefe` | +| #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | `05e440948840afff1dc6e62cdb6fa52e03ebdaa9` | +| #124 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fdb88698ca20626a6643bc2ad7944fb968835700` | +| #37 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `5e3dfcbd7a4daea297782cb99635990368589232` | These rows are delivery evidence only. None has counted independent approval in the current collaborator inventory. @@ -80,7 +80,7 @@ Representative active workstreams at this snapshot were: |---|---|---| | Product baseline | (merged: #196 on 2026-08-24) | Baseline publication reached protected `main`; this document is its successor snapshot | | Presentation identity | #229 at `fb868589d065c2cea0b9c8c0f5e655a89f42bee6` onto `542ca1e9c0a863595b8b6697790005d2471f5413` | Ready/non-draft local privacy kernel; current required checks include a failed Strix run, and the PR remains blocked without counted approval; no protected-main shipment is claimed | -| Enterprise approval authority | #220 at `a2b0c5372dd6df803011933836c56136244dc8af` onto base `f658f329c83a106b68385e17cb714c4147c12f49` | Ready/non-draft bounded maker-checker approval lifecycle on the exact `ApprovalScope`; current checks are green except the latest failed Strix run, with changes requested and no counted approval | +| Enterprise approval authority | #220 at `b11db2be68f9b6d71aa4c4290b97a8b22097b353` onto protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413` | Ready/non-draft bounded maker-checker approval lifecycle on the exact `ApprovalScope`; current checks and review state require a fresh exact-head audit, with no counted approval | | Release artifact identity | #218 and #219 | Ready/non-draft fail-closed benchmark release decision and canonical release manifest binding; Strix provider-failure reruns completed green on both heads | | Schema-bound extraction and BAP lifecycle | #209 and #208 | Ready/non-draft schema-bound extraction contract and resumable task-lifecycle kernel; #209 Strix rerun green, #208 rerun re-dispatched after a further provider failure | | WebDriver BiDi transport | #188 through #205 | Active stack whose top #205 merged into its prerequisite branch, not protected `main`; it exercises framed `locateNodes` exchange over a bounded WebSocket opening path, but authenticated browser-process provenance, semantic task execution, and protected-main shipment remain unproven | @@ -191,7 +191,7 @@ The hourly product-development loop is operational infrastructure, not proof tha | P1 | Buyers can install, update, verify, and roll back a supported product | **Not shipped** | #201; signed Windows/macOS/Linux/headless artifacts, Chromium revision manifest, updater security, patch SLA, SBOM, SLSA provenance, and recovery | | P1 | Enterprise teams can provision, approve, audit, operate, and recover the service | **Not shipped** | #202; Keyverse-compatible OIDC/SCIM, tenant isolation, policy/approval/evidence UI, SLO/incident controls, data residency, CSAP/SOC 2 evidence mapping, WCAG 2.2, Figma File ID, and Storybook | | P0 | A release has reproducible proof of usefulness, safety, evidence completeness, and recovery | **No product-wide release gate** | #203; deterministic, compatibility, adversarial, recovery, and enterprise suites with statistical reporting and an exact-artifact commercial acceptance gate | -| P0 | Valid changes reach protected `main` without authority improvisation or unbounded stack growth | **Blocked / high integration debt** | Shrink the 111-PR queue in dependency order, provision legitimate review authority, require exact-current evidence, and close duplicates/superseded branches | +| P0 | Valid changes reach protected `main` without authority improvisation or unbounded stack growth | **Blocked / high integration debt** | Shrink the 110-PR queue in dependency order, provision legitimate review authority, require exact-current evidence, and close duplicates/superseded branches | ## Commercial completion definition diff --git a/docs/traceability/README.md b/docs/traceability/README.md index e30b9eda1..64e291640 100644 --- a/docs/traceability/README.md +++ b/docs/traceability/README.md @@ -30,6 +30,10 @@ Transient implementation evidence that materially tightens an existing authority These dossiers are evidence indexes, not substitute ADRs. A new ADR is required only when a durable architecture/trust/deployment decision changes. +### 1.2 Protected-main authority dossiers + +- [`mcp-authority-route.md`](mcp-authority-route.md) — protected-main MCP `tools/call` and `tools/list` routing/discovery foundations, with their exact merged PR lineage and executable test paths; the complete MCP adapter remains planned. + ## 2. Capability maturity vocabulary Capability maturity uses exactly one of these values: diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 5b6e0f314..a9c7c60fb 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -56,15 +56,15 @@ def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> No "| #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `441a8ce1d09c329c5c1168f4906d9a38fd0abc01` |", "| #82 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `f5776f5f233ac0a7c05e3f4a2846436c23438043` |", "| #152 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `81407a0e5189a413d1be0963fea90a0c2f254ce1` |", - "| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0341079331f9cea669eb9a5cc21842fd6027431e` |", - "| #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `21e9ad1e8da72c81f521152ea6739b088da230f7` |", - "| #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` |", + "| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `bea65643109449d63d367a35b8d9bf327ee7cb2c` |", + "| #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `2459af602e72fbfe1ce816919473a1075ec0c41f` |", + "| #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `e840ca299d29a15223c8b9bb1397002c4f41b4a3` |", "| #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0145ccba5901e301b41d4be674ca1ed23483ad37` |", - "| #220 | Ready | `f658f329c83a106b68385e17cb714c4147c12f49` | `a2b0c5372dd6df803011933836c56136244dc8af` |", + "| #220 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `b11db2be68f9b6d71aa4c4290b97a8b22097b353` |", "| #211 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `52a918577958a5701e1146c7eb8b62fe8f8ccd44` |", - "| #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | `72f112d52a60e7caa992a3f5ff7f16d5d9a4d047` |", - "| #124 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `028789d8bb6cc30b8e84b1ba7ed46556b26e75ea` |", - "| #37 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `5423803d3fbd9d2d8e08bbd6dbf81ae6b2addefe` |", + "| #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | `05e440948840afff1dc6e62cdb6fa52e03ebdaa9` |", + "| #124 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fdb88698ca20626a6643bc2ad7944fb968835700` |", + "| #37 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `5e3dfcbd7a4daea297782cb99635990368589232` |", ): with self.subTest(marker=marker): self.assertIn(marker, current) @@ -79,7 +79,7 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: refresh_lines = [line for line in added.splitlines() if line.startswith(refresh_prefix)] self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] - self.assertIn("111 open pull requests (27 ready, 84 draft)", refresh_line) + self.assertIn("110 open pull requests (26 ready, 84 draft)", refresh_line) self.assertIn("11 open issues", refresh_line) self.assertNotIn(refresh_prefix, changed) self.assertNotIn("115 open pull requests (31 ready, 84 draft)", refresh_line) diff --git a/tests/test_documentation_fitness_contract.py b/tests/test_documentation_fitness_contract.py index 33aefed22..b628d7cdf 100644 --- a/tests/test_documentation_fitness_contract.py +++ b/tests/test_documentation_fitness_contract.py @@ -9,6 +9,7 @@ DOCS_ROOT = REPOSITORY_ROOT / "docs" ADR_ROOT = DOCS_ROOT / "adr" UML_ROOT = DOCS_ROOT / "uml" +MCP_TRACEABILITY = DOCS_ROOT / "traceability" / "mcp-authority-route.md" ADR_STATUSES = {"Proposed", "Accepted", "Superseded", "Deprecated", "Rejected"} @@ -177,6 +178,21 @@ def test_current_replacement_lanes_are_not_promoted_to_protected_main(self) -> N self.assertIn("IMPLEMENTED_ON_PROTECTED_MAIN", traceability) self.assertIn("Active-PR behavior is never protected-main truth", traceability) + def test_protected_main_mcp_route_is_indexed_with_executable_evidence(self) -> None: + """A protected-main MCP maturity claim must be discoverable and test-backed.""" + index = (DOCS_ROOT / "traceability" / "README.md").read_text(encoding="utf-8") + route = MCP_TRACEABILITY.read_text(encoding="utf-8") + + self.assertIn( + "[`mcp-authority-route.md`](mcp-authority-route.md)", + index, + ) + self.assertIn("`tools/list`", route) + self.assertIn("crates/originweave-core/tests/mcp_tools_list_cache.rs", route) + self.assertTrue( + (REPOSITORY_ROOT / "crates/originweave-core/tests/mcp_tools_list_cache.rs").is_file() + ) + def test_semantic_observation_lane_stays_non_shipped_and_provenance_bound(self) -> None: """The semantic observation value object must stay active-only and distinct from browser I/O.""" appendix = (DOCS_ROOT / "evidence" / "2026-08-10-active-pr-maturity.md").read_text( diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index c5a6f69a8..4b713f45a 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -20,13 +20,13 @@ def setUpClass(cls) -> None: cls.changelog = CHANGELOG.read_text(encoding="utf-8") def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: - """The current snapshot must use the exact 111/27/84 inventory observation.""" + """The current snapshot must use the exact 110/26/84 inventory observation.""" current = self.baseline.split("### Open pull requests", 1)[1].split( "#### 2026-08-28 maintenance-loop record", 1 )[0] for marker in ( - "111 open pull requests", - "27 non-draft", + "110 open pull requests", + "26 non-draft", "84 draft", ): with self.subTest(marker=marker): @@ -41,6 +41,8 @@ def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: "31 non-draft", "116 open pull requests", "32 non-draft", + "111 open pull requests", + "27 non-draft", "153 open pull requests", "114 draft", ): @@ -53,7 +55,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "111 open pull requests (27 ready, 84 draft)" + expected = "110 open pull requests (26 ready, 84 draft)" self.assertIn(expected, preamble) self.assertIn(expected, added) self.assertNotIn("126 open pull requests (54 ready, 72 draft)", preamble) diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 3d3e9a0ae..42a428631 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -26,8 +26,8 @@ def test_baseline_records_current_inventory_and_completion_issues(self) -> None: current = text.split("## Observed snapshot: ", 1)[1].split(end_marker, 1)[0] for phrase in ( - "111 open pull requests", - "27 non-draft", + "110 open pull requests", + "26 non-draft", "84 draft", "2026-08-28 116-PR snapshot", ): @@ -41,7 +41,7 @@ def test_baseline_records_current_inventory_and_completion_issues(self) -> None: "#201", "#202", "#203", - "Shrink the 111-PR queue", + "Shrink the 110-PR queue", "durable WARC/PROV replay", "stable BAP/MCP runtime API", "signed cross-platform Chromium distribution", From 0cb11e1ad09444236a8ee89f882c6f9120f927d0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 01:16:16 +0900 Subject: [PATCH 025/250] docs: remove volatile self-head snapshot --- docs/product-technical-gap-baseline.md | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 4beaa35ef..321e95b9b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -22,13 +22,15 @@ This snapshot re-fetched the complete open-PR inventory, the protected `main` co During this recheck, #71, #154, #233, #234, and #235 were merged only into their unprotected feature-parent branches after exact current-head checks and review-thread resolution. Their successful stack checks are not protected-main delivery, and their child branches retain independent evidence requirements. -The later exact-head recheck also recorded the WARC/PROV retention-lifecycle slice: #239 is Draft at `365c4a6b9e6d0f088d2f8330834f54c7cb5fb491` on #227 head `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0`, with its Rust contracts and production coverage checks successful, zero unresolved threads, and no counted approval. #237 is Draft at `21e9ad1e8da72c81f521152ea6739b088da230f7` on protected `main`; its deterministic contracts and coverage are successful, while exact-head `opencode-review` failed closed for the absent current-head verdict and `strix` remained in progress. Neither active branch is protected-main behavior. +The sensitive-data child slice #53 was subsequently squash-merged into the unprotected #46 feature branch at merge commit `93c713a107df05385f745db4dca20091f21c4a3a` after exact-head Rust/coverage checks passed and current inline review threads were resolved. PR #46 remains an active main-targeting parent and still requires its own current-head evidence and legitimate approval. + +The later exact-head recheck also recorded the WARC/PROV retention-lifecycle slice: #239 is Draft at `e840ca299d29a15223c8b9bb1397002c4f41b4a3` on #227 head `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0`, and #237 is Draft at `2459af602e72fbfe1ce816919473a1075ec0c41f` on protected `main`; their current exact checks and reviews remain independently actionable evidence. Neither active branch is protected-main behavior. The same exact-head recheck corrected workflow provenance: the active ruleset's seven required workflow entries (`close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, and `noema-review`) point to the central `.github` repository, repository ID `1274066402`, where all seven files exist on `main`; their absence from the OriginWeave tree did not prove missing workflow identities. On PR #210 head `0341079331f9cea669eb9a5cc21842fd6027431e`, run `33177641855` failed closed because no OpenCode current-head verdict existed, while run `33177641888` failed closed after three bounded attempts because the Strix provider/backend returned an internal server error and produced no vulnerability report. A `gh run view` workflow-endpoint 404 for the external workflow IDs is a lookup mismatch, not passing evidence or proof that the identities are absent. A bounded central scheduler dispatch was accepted as run `33178984025` with auto-merge and branch updates disabled; no result is transferred until the exact head is revalidated. These failures block affected PRs until current-head review and security evidence complete. This does not authorize bypass, self-approval, stale checks, or weaker gates. The WARC resource-record slice #210 is now Ready at exact head `bea65643109449d63d367a35b8d9bf327ee7cb2c`, based directly on protected `main`; its latest forward-only repair rejects raw and recursively percent-encoded nested credential names and percent-encoded ASCII controls. Local evidence is green, while the exact-head hosted failures are recorded above; central repair PR #1391 was opened at historical head `e4ba6b599cd1e50d0139762885682607b731655d` and is now open at exact head `36ac3aa71b2580685f84d416a81e42c39dee927c` on current central `main` `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Its branch-update merge and follow-up prompt hardening are not approval or coverage evidence. -The documentation refresh PR #238 is Ready at exact head `0c14e33c5c7ccff327a340642eaaf630cf951417` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`: local full-suite evidence is green, and current repository/security/coverage checks are regenerating for the exact head. Required OpenCode run `33187565535` / job `98904422126` was queued at this recheck, while the preceding exact-head run `33184553025` / job `98894986761` failed closed because no `APPROVED` or `CHANGES_REQUESTED` verdict existed. Earlier targeted run `33182749298` dispatched OpenCode run `33182772296`, whose coverage evidence succeeded but review failed closed as `MODEL_OUTPUT_UNAVAILABLE` with `model pool exhausted`; optional cross-repository status publication was denied with HTTP 403. A current Devin review opened one unresolved documentation-evidence thread requiring an enforcing `tools/list` traceability contract; this snapshot records the finding as active until the follow-up head is verified. These are review-tool/documentation findings, not approval or shipping evidence, and the branch has not been merged. +The documentation refresh PR #238 remains Ready on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`; its live GitHub metadata and PR body are authoritative for the exact self-referential head, while local full-suite evidence is green and current repository/security/coverage checks regenerate after each documentation push. The preceding exact-head OpenCode run `33184553025` / job `98894986761` failed closed because no `APPROVED` or `CHANGES_REQUESTED` verdict existed; earlier targeted run `33182749298` dispatched OpenCode run `33182772296`, whose coverage evidence succeeded but review failed closed as `MODEL_OUTPUT_UNAVAILABLE` with `model pool exhausted`, and optional cross-repository status publication was denied with HTTP 403. The current Devin documentation-evidence finding requiring an enforcing `tools/list` traceability contract has been implemented and its review thread resolved; the follow-up exact-head hosted checks remain required. These are review-tool/documentation findings, not approval or shipping evidence, and the branch has not been merged. The controlled Chromium prerequisite stack was also re-fetched after its exact-head repairs: #70 is Ready at `441a8ce1d09c329c5c1168f4906d9a38fd0abc01` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`; #71 is merged into the unprotected #70 feature branch; #72 is Draft at `600d3975c02b68da1974a4c73069b966b39dce7b` on the retained #71 branch; and #73 is Draft at `ce1b138509ab4f52cb0f80290f104358473c6ed3` on #72. #70's Rust, coverage, pinned-Chrome, and ordinary security checks are successful, while exact-head OpenCode failed closed without a current verdict and exact-head Strix failed closed after three provider HTTP 500 attempts; all current Devin informational threads are resolved. #72 and #73 retain independent exact-head evidence requirements. #82 is Ready at `f5776f5f233ac0a7c05e3f4a2846436c23438043` on protected `main`; its Rust, coverage, Chrome, and ordinary security checks pass, exact-head OpenCode failed closed without a current verdict, and its current Devin informational thread is resolved. #152 is Ready at `81407a0e5189a413d1be0963fea90a0c2f254ce1` on protected `main`; its source, coverage, and security checks are successful except exact-head `opencode-review`, which failed closed without a current-head verdict. These are active-stack evidence only, not protected-main behavior or merge authorization. From e4266b568227d459c4ca1fa3e25b62d195fbd5d0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 01:30:53 +0900 Subject: [PATCH 026/250] docs: refresh live gap baseline for pr46 --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 9 +++++---- tests/test_documentation_active_pr_evidence_contract.py | 1 + tests/test_gap_snapshot_inventory_consistency.py | 2 +- tests/test_product_completion_gap_contract.py | 4 ++-- tests/test_product_documentation_contract.py | 2 +- 6 files changed, 11 insertions(+), 8 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 7d77a50e0..de68194c4 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Revalidated the product-gap queue at 110 open pull requests (26 ready, 84 draft) on 2026-08-29; refreshed protected-main `542ca1e9` and PR #46 exact-head evidence at `373113119446d99f578febd39efc19366e7736b1` after its ADR 0007 authority-boundary repair. Current hosted checks and independent approval remain required; no protected-main shipment is claimed. - Refreshed the product-gap queue to 110 open pull requests (26 ready, 84 draft) on 2026-08-28 after #53, #71, #154, #233, #234, and #235 merged into unprotected feature parents; these are queue evidence, not protected-main shipment. ### Added diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 321e95b9b..dd57ac29b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,7 +2,7 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, architecture decisions, or live GitHub state. It keeps buyer-visible gaps, current issues, active pull-request evidence, and commercial completion tracks in one discoverable place. Protected `main` is the implementation boundary: code in an open pull request is not shipped behavior. -## Observed snapshot: 2026-08-28 +## Observed snapshot: 2026-08-29 ### Protected-main truth @@ -14,15 +14,15 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a ### Open pull requests -The live repository contained **110 open pull requests: 26 non-draft and 84 draft** when this snapshot re-paginated the complete open inventory. Compared with the prior **2026-08-28 111-PR snapshot**, stacked evidence PR #53 was merged into its unprotected feature parent; the preceding **2026-08-28 116-PR snapshot** had already recorded #71, #154, #233, #234, and #235 merging into their unprotected feature parents. None reached protected `main`. These counts are queue evidence, not protected-main delivery; protected `main` remains `542ca1e9c0a863595b8b6697790005d2471f5413`, with 11 open issues and no releases or tags. The volume and stack depth remain themselves a product-delivery risk: review, exact-head checks, dependency order, and integration truth can drift faster than a buyer-visible vertical slice reaches protected `main`. +The live repository contained **110 open pull requests: 26 non-draft and 84 draft** when this snapshot re-paginated the complete open inventory. Compared with the prior **2026-08-28 111-PR snapshot**, stacked evidence PR #53 was merged into its unprotected feature parent; the preceding **2026-08-28 116-PR snapshot** had already recorded #71, #154, #233, #234, and #235 merging into their unprotected feature parents. The 2026-08-29 exact-head recheck changed no queue counts. None reached protected `main`. These counts are queue evidence, not protected-main delivery; protected `main` remains `542ca1e9c0a863595b8b6697790005d2471f5413`, with 11 open issues and no releases or tags. The volume and stack depth remain themselves a product-delivery risk: review, exact-head checks, dependency order, and integration truth can drift faster than a buyer-visible vertical slice reaches protected `main`. -#### 2026-08-28 maintenance-loop record +#### 2026-08-29 maintenance-loop record This snapshot re-fetched the complete open-PR inventory, the protected `main` commit, the active required-workflow ruleset, collaborator permissions, and the exact base/head pair for each representative PR. Before PR #238 was published, the same maintenance loop observed 115 open pull requests (31 ready, 84 draft); a later 116-PR recheck preceded five stack merges, leaving 111 open pull requests (27 ready, 84 draft), and the exact current recheck leaves 110 open pull requests (26 ready, 84 draft) after #53 merged. The active ruleset still requires one counted approving review and resolved threads; the only repository collaborator is `seonghobae`, so review provisioning remains the merge blocker for main-targeting PRs. PR #170 is merged and is not active-PR evidence. During this recheck, #71, #154, #233, #234, and #235 were merged only into their unprotected feature-parent branches after exact current-head checks and review-thread resolution. Their successful stack checks are not protected-main delivery, and their child branches retain independent evidence requirements. -The sensitive-data child slice #53 was subsequently squash-merged into the unprotected #46 feature branch at merge commit `93c713a107df05385f745db4dca20091f21c4a3a` after exact-head Rust/coverage checks passed and current inline review threads were resolved. PR #46 remains an active main-targeting parent and still requires its own current-head evidence and legitimate approval. +The sensitive-data child slice #53 was subsequently squash-merged into the unprotected #46 feature branch at merge commit `93c713a107df05385f745db4dca20091f21c4a3a` after exact-head Rust/coverage checks passed and current inline review threads were resolved. PR #46 remains an active main-targeting parent. Its current exact base/head pair is protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413` to `373113119446d99f578febd39efc19366e7736b1`; the head adds the ADR 0007 predicate-boundary clarification and regression contract, with local Python/Rust verification green. Current hosted security/review workflow runs are still pending or queued, and no qualifying non-author approval is present. The later exact-head recheck also recorded the WARC/PROV retention-lifecycle slice: #239 is Draft at `e840ca299d29a15223c8b9bb1397002c4f41b4a3` on #227 head `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0`, and #237 is Draft at `2459af602e72fbfe1ce816919473a1075ec0c41f` on protected `main`; their current exact checks and reviews remain independently actionable evidence. Neither active branch is protected-main behavior. @@ -42,6 +42,7 @@ The following representative slices were re-fetched from GitHub for this snapsho |---|---|---|---| | #73 | Draft | `600d3975c02b68da1974a4c73069b966b39dce7b` | `ce1b138509ab4f52cb0f80290f104358473c6ed3` | | #72 | Draft | `f86ce504138e79d6e95141a441f60b40920e1fa6` | `600d3975c02b68da1974a4c73069b966b39dce7b` | +| #46 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `373113119446d99f578febd39efc19366e7736b1` | | #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `441a8ce1d09c329c5c1168f4906d9a38fd0abc01` | | #82 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `f5776f5f233ac0a7c05e3f4a2846436c23438043` | | #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `bea65643109449d63d367a35b8d9bf327ee7cb2c` | diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index a9c7c60fb..e8405acd7 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -53,6 +53,7 @@ def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> No for marker in ( "| #73 | Draft | `600d3975c02b68da1974a4c73069b966b39dce7b` | `ce1b138509ab4f52cb0f80290f104358473c6ed3` |", "| #72 | Draft | `f86ce504138e79d6e95141a441f60b40920e1fa6` | `600d3975c02b68da1974a4c73069b966b39dce7b` |", + "| #46 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `373113119446d99f578febd39efc19366e7736b1` |", "| #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `441a8ce1d09c329c5c1168f4906d9a38fd0abc01` |", "| #82 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `f5776f5f233ac0a7c05e3f4a2846436c23438043` |", "| #152 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `81407a0e5189a413d1be0963fea90a0c2f254ce1` |", diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 4b713f45a..7b3a01870 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -22,7 +22,7 @@ def setUpClass(cls) -> None: def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: """The current snapshot must use the exact 110/26/84 inventory observation.""" current = self.baseline.split("### Open pull requests", 1)[1].split( - "#### 2026-08-28 maintenance-loop record", 1 + "#### 2026-08-29 maintenance-loop record", 1 )[0] for marker in ( "110 open pull requests", diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 42a428631..655213f2d 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -21,7 +21,7 @@ def test_current_snapshot_checks_do_not_route_by_phrase_substrings(self) -> None def test_baseline_records_current_inventory_and_completion_issues(self) -> None: """The dated baseline must not retain superseded queue counts or omit buyer tracks.""" text = BASELINE.read_text(encoding="utf-8") - end_marker = "#### 2026-08-28 maintenance-loop record" + end_marker = "#### 2026-08-29 maintenance-loop record" self.assertIn(end_marker, text) current = text.split("## Observed snapshot: ", 1)[1].split(end_marker, 1)[0] @@ -125,7 +125,7 @@ def test_same_day_prior_inventory_is_bound_to_the_maintenance_record(self) -> No text = BASELINE.read_text(encoding="utf-8") record_end = "#### Current exact-head active PR evidence" self.assertIn(record_end, text) - record = text.split("#### 2026-08-28 maintenance-loop record", 1)[1].split( + record = text.split("#### 2026-08-29 maintenance-loop record", 1)[1].split( record_end, 1 )[0] self.assertIn("115 open pull requests (31 ready, 84 draft)", record) diff --git a/tests/test_product_documentation_contract.py b/tests/test_product_documentation_contract.py index 5597b7caf..7919c69db 100644 --- a/tests/test_product_documentation_contract.py +++ b/tests/test_product_documentation_contract.py @@ -44,7 +44,7 @@ def test_product_technical_gap_baseline_records_live_delivery_state(self) -> Non self.assertTrue(baseline.is_file()) text = baseline.read_text(encoding="utf-8") for phrase in ( - "Observed snapshot: 2026-08-28", + "Observed snapshot: 2026-08-29", "Protected-main truth", "Open pull requests", "Open issues", From 2c81990a2b95d8cd0d93a70b3700f75ba2b0f425 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 01:38:25 +0900 Subject: [PATCH 027/250] docs: align current baseline changelog date --- CHANGELOG.md | 4 ++-- tests/test_documentation_active_pr_evidence_contract.py | 6 ++++-- 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index de68194c4..202652125 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,13 +4,13 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] -- Revalidated the product-gap queue at 110 open pull requests (26 ready, 84 draft) on 2026-08-29; refreshed protected-main `542ca1e9` and PR #46 exact-head evidence at `373113119446d99f578febd39efc19366e7736b1` after its ADR 0007 authority-boundary repair. Current hosted checks and independent approval remain required; no protected-main shipment is claimed. - Refreshed the product-gap queue to 110 open pull requests (26 ready, 84 draft) on 2026-08-28 after #53, #71, #154, #233, #234, and #235 merged into unprotected feature parents; these are queue evidence, not protected-main shipment. ### Added +- Revalidated the product-gap queue at 110 open pull requests (26 ready, 84 draft) and 11 open issues on 2026-08-29; refreshed protected-main `542ca1e9` and PR #46 exact-head evidence at `373113119446d99f578febd39efc19366e7736b1` after its ADR 0007 authority-boundary repair. Current hosted checks and independent approval remain required; no protected-main shipment is claimed. - Added an enforcing traceability contract for the protected-main MCP `tools/list` maturity claim and indexed its executable evidence dossier. - Clarified the 2026-08-28 gap snapshot's prior queue observation and separated open issues from governance signals. -- Corrected the 2026-08-28 product-gap snapshot with protected-main `542ca1e9`, 110 open pull requests (26 ready, 84 draft), 11 open issues, current exact base/head pairs for representative PRs including #70, #82, #152, #37, #237, and #239, PR #170's merged `tools/list` contract, the active counted-approval gate, and the unchanged Phase 1 browser gap. +- Historical 2026-08-28 product-gap snapshot: protected-main `542ca1e9`, 110 open pull requests (26 ready, 84 draft), 11 open issues, current exact base/head pairs for representative PRs including #70, #82, #152, #37, #237, and #239, PR #170's merged `tools/list` contract, the active counted-approval gate, and the unchanged Phase 1 browser gap. - Refreshed the product and technical gap baseline onto the 2026-08-28 live inventory; current queue and exact-head evidence are explicitly separated from the historical 2026-08-26 snapshot so stale delivery evidence cannot be promoted. - Hardened the product-completion documentation contract by classifying current-snapshot count markers explicitly instead of routing them by substring heuristics. - Corrected the baseline's #72/#73 exact SHA evidence to full 40-character values and tracked PR #238's current head. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index e8405acd7..93750701a 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -76,13 +76,15 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: """The current changelog refresh item must carry its own live queue evidence.""" added = self.changelog.split("### Added", 1)[1].split("### Changed", 1)[0] changed = self.changelog.split("### Changed", 1)[1].split("### Security", 1)[0] - refresh_prefix = "- Corrected the 2026-08-28 product-gap snapshot" + refresh_prefix = "- Revalidated the product-gap queue at" refresh_lines = [line for line in added.splitlines() if line.startswith(refresh_prefix)] self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] + self.assertIn("on 2026-08-29", refresh_line) self.assertIn("110 open pull requests (26 ready, 84 draft)", refresh_line) self.assertIn("11 open issues", refresh_line) - self.assertNotIn(refresh_prefix, changed) + self.assertNotIn("- Corrected the 2026-08-28 product-gap snapshot", added) + self.assertNotIn("- Revalidated the product-gap queue at", changed) self.assertNotIn("115 open pull requests (31 ready, 84 draft)", refresh_line) self.assertNotIn("126 open pull requests (54 ready, 72 draft)", refresh_line) self.assertNotIn("128 open pull requests (54 ready, 74 draft)", refresh_line) From b6f7dce1caaeceb129eab877fddb81fee8582eee Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 01:45:21 +0900 Subject: [PATCH 028/250] docs: bind warc gate failures to current head --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 2 +- .../test_documentation_active_pr_evidence_contract.py | 10 ++++++++++ 3 files changed, 12 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 202652125..cc2274999 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -8,6 +8,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ### Added - Revalidated the product-gap queue at 110 open pull requests (26 ready, 84 draft) and 11 open issues on 2026-08-29; refreshed protected-main `542ca1e9` and PR #46 exact-head evidence at `373113119446d99f578febd39efc19366e7736b1` after its ADR 0007 authority-boundary repair. Current hosted checks and independent approval remain required; no protected-main shipment is claimed. +- Recorded PR #210's current exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; no failure was promoted to passing evidence. - Added an enforcing traceability contract for the protected-main MCP `tools/list` maturity claim and indexed its executable evidence dossier. - Clarified the 2026-08-28 gap snapshot's prior queue observation and separated open issues from governance signals. - Historical 2026-08-28 product-gap snapshot: protected-main `542ca1e9`, 110 open pull requests (26 ready, 84 draft), 11 open issues, current exact base/head pairs for representative PRs including #70, #82, #152, #37, #237, and #239, PR #170's merged `tools/list` contract, the active counted-approval gate, and the unchanged Phase 1 browser gap. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index dd57ac29b..1ee9d483f 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -28,7 +28,7 @@ The later exact-head recheck also recorded the WARC/PROV retention-lifecycle sli The same exact-head recheck corrected workflow provenance: the active ruleset's seven required workflow entries (`close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, and `noema-review`) point to the central `.github` repository, repository ID `1274066402`, where all seven files exist on `main`; their absence from the OriginWeave tree did not prove missing workflow identities. On PR #210 head `0341079331f9cea669eb9a5cc21842fd6027431e`, run `33177641855` failed closed because no OpenCode current-head verdict existed, while run `33177641888` failed closed after three bounded attempts because the Strix provider/backend returned an internal server error and produced no vulnerability report. A `gh run view` workflow-endpoint 404 for the external workflow IDs is a lookup mismatch, not passing evidence or proof that the identities are absent. A bounded central scheduler dispatch was accepted as run `33178984025` with auto-merge and branch updates disabled; no result is transferred until the exact head is revalidated. These failures block affected PRs until current-head review and security evidence complete. This does not authorize bypass, self-approval, stale checks, or weaker gates. -The WARC resource-record slice #210 is now Ready at exact head `bea65643109449d63d367a35b8d9bf327ee7cb2c`, based directly on protected `main`; its latest forward-only repair rejects raw and recursively percent-encoded nested credential names and percent-encoded ASCII controls. Local evidence is green, while the exact-head hosted failures are recorded above; central repair PR #1391 was opened at historical head `e4ba6b599cd1e50d0139762885682607b731655d` and is now open at exact head `36ac3aa71b2580685f84d416a81e42c39dee927c` on current central `main` `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Its branch-update merge and follow-up prompt hardening are not approval or coverage evidence. +The WARC resource-record slice #210 is now Ready; PR #210 current exact head `bea65643109449d63d367a35b8d9bf327ee7cb2c` is based directly on protected `main`, and its latest forward-only repair rejects raw and recursively percent-encoded nested credential names and percent-encoded ASCII controls. Local evidence is green. On this current head, run `33183939299` / job `98894420986` failed closed because no OpenCode current-head verdict existed, and run `33183939193` / job `98892185954` failed closed after three provider HTTP 500 attempts without a vulnerability report. Central repair PR #1391 was opened at historical head `e4ba6b599cd1e50d0139762885682607b731655d` and is now open at exact head `36ac3aa71b2580685f84d416a81e42c39dee927c` on current central `main` `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Its branch-update merge and follow-up prompt hardening are not approval or coverage evidence. The documentation refresh PR #238 remains Ready on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`; its live GitHub metadata and PR body are authoritative for the exact self-referential head, while local full-suite evidence is green and current repository/security/coverage checks regenerate after each documentation push. The preceding exact-head OpenCode run `33184553025` / job `98894986761` failed closed because no `APPROVED` or `CHANGES_REQUESTED` verdict existed; earlier targeted run `33182749298` dispatched OpenCode run `33182772296`, whose coverage evidence succeeded but review failed closed as `MODEL_OUTPUT_UNAVAILABLE` with `model pool exhausted`, and optional cross-repository status publication was denied with HTTP 403. The current Devin documentation-evidence finding requiring an enforcing `tools/list` traceability contract has been implemented and its review thread resolved; the follow-up exact-head hosted checks remain required. These are review-tool/documentation findings, not approval or shipping evidence, and the branch has not been merged. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 93750701a..1e7907baf 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -90,6 +90,16 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertNotIn("128 open pull requests (54 ready, 74 draft)", refresh_line) self.assertNotIn("153 open pull requests (39 ready, 114 draft)", refresh_line) + def test_current_warc_provider_failures_are_bound_to_current_head(self) -> None: + """WARC provider failures must not rely only on a superseded head's runs.""" + for marker in ( + "PR #210 current exact head `bea65643109449d63d367a35b8d9bf327ee7cb2c`", + "run `33183939299` / job `98894420986` failed closed because no OpenCode current-head verdict existed", + "run `33183939193` / job `98892185954` failed closed after three provider HTTP 500 attempts", + ): + with self.subTest(marker=marker): + self.assertIn(marker, self.baseline) + def test_dependency_stacks_are_explicit_and_non_shipped(self) -> None: """Current browser, network, sensitive and compatibility stacks stay active-only.""" for pr_number in (52, 53, 54, 55, 56, 57, 58, 59, 60, 61, 62, 63, 64, 65, 66): From 5bd7991c71a7d542aa8779194033e64ab43a506f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 01:55:17 +0900 Subject: [PATCH 029/250] docs: record current WARC provider rerun --- CHANGELOG.md | 2 +- docs/product-technical-gap-baseline.md | 2 +- tests/test_documentation_active_pr_evidence_contract.py | 1 + 3 files changed, 3 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index cc2274999..c828d6ddc 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -8,7 +8,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ### Added - Revalidated the product-gap queue at 110 open pull requests (26 ready, 84 draft) and 11 open issues on 2026-08-29; refreshed protected-main `542ca1e9` and PR #46 exact-head evidence at `373113119446d99f578febd39efc19366e7736b1` after its ADR 0007 authority-boundary repair. Current hosted checks and independent approval remain required; no protected-main shipment is claimed. -- Recorded PR #210's current exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; no failure was promoted to passing evidence. +- Recorded PR #210's current exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence. - Added an enforcing traceability contract for the protected-main MCP `tools/list` maturity claim and indexed its executable evidence dossier. - Clarified the 2026-08-28 gap snapshot's prior queue observation and separated open issues from governance signals. - Historical 2026-08-28 product-gap snapshot: protected-main `542ca1e9`, 110 open pull requests (26 ready, 84 draft), 11 open issues, current exact base/head pairs for representative PRs including #70, #82, #152, #37, #237, and #239, PR #170's merged `tools/list` contract, the active counted-approval gate, and the unchanged Phase 1 browser gap. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 1ee9d483f..34b975cc9 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -28,7 +28,7 @@ The later exact-head recheck also recorded the WARC/PROV retention-lifecycle sli The same exact-head recheck corrected workflow provenance: the active ruleset's seven required workflow entries (`close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, and `noema-review`) point to the central `.github` repository, repository ID `1274066402`, where all seven files exist on `main`; their absence from the OriginWeave tree did not prove missing workflow identities. On PR #210 head `0341079331f9cea669eb9a5cc21842fd6027431e`, run `33177641855` failed closed because no OpenCode current-head verdict existed, while run `33177641888` failed closed after three bounded attempts because the Strix provider/backend returned an internal server error and produced no vulnerability report. A `gh run view` workflow-endpoint 404 for the external workflow IDs is a lookup mismatch, not passing evidence or proof that the identities are absent. A bounded central scheduler dispatch was accepted as run `33178984025` with auto-merge and branch updates disabled; no result is transferred until the exact head is revalidated. These failures block affected PRs until current-head review and security evidence complete. This does not authorize bypass, self-approval, stale checks, or weaker gates. -The WARC resource-record slice #210 is now Ready; PR #210 current exact head `bea65643109449d63d367a35b8d9bf327ee7cb2c` is based directly on protected `main`, and its latest forward-only repair rejects raw and recursively percent-encoded nested credential names and percent-encoded ASCII controls. Local evidence is green. On this current head, run `33183939299` / job `98894420986` failed closed because no OpenCode current-head verdict existed, and run `33183939193` / job `98892185954` failed closed after three provider HTTP 500 attempts without a vulnerability report. Central repair PR #1391 was opened at historical head `e4ba6b599cd1e50d0139762885682607b731655d` and is now open at exact head `36ac3aa71b2580685f84d416a81e42c39dee927c` on current central `main` `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Its branch-update merge and follow-up prompt hardening are not approval or coverage evidence. +The WARC resource-record slice #210 is now Ready; PR #210 current exact head `bea65643109449d63d367a35b8d9bf327ee7cb2c` is based directly on protected `main`, and its latest forward-only repair rejects raw and recursively percent-encoded nested credential names and percent-encoded ASCII controls. Local evidence is green. On this current head, run `33183939299` / job `98894420986` failed closed because no OpenCode current-head verdict existed, and run `33183939193` / job `98892185954` failed closed after three provider HTTP 500 attempts without a vulnerability report. The direct attempt-2 rerun `33172708455` / job `98915847518` also failed closed after three provider HTTP 500 attempts without a vulnerability report, confirming the provider/backend blocker rather than a source failure. Central repair PR #1391 was opened at historical head `e4ba6b599cd1e50d0139762885682607b731655d` and is now open at exact head `36ac3aa71b2580685f84d416a81e42c39dee927c` on current central `main` `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Its branch-update merge and follow-up prompt hardening are not approval or coverage evidence. The documentation refresh PR #238 remains Ready on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`; its live GitHub metadata and PR body are authoritative for the exact self-referential head, while local full-suite evidence is green and current repository/security/coverage checks regenerate after each documentation push. The preceding exact-head OpenCode run `33184553025` / job `98894986761` failed closed because no `APPROVED` or `CHANGES_REQUESTED` verdict existed; earlier targeted run `33182749298` dispatched OpenCode run `33182772296`, whose coverage evidence succeeded but review failed closed as `MODEL_OUTPUT_UNAVAILABLE` with `model pool exhausted`, and optional cross-repository status publication was denied with HTTP 403. The current Devin documentation-evidence finding requiring an enforcing `tools/list` traceability contract has been implemented and its review thread resolved; the follow-up exact-head hosted checks remain required. These are review-tool/documentation findings, not approval or shipping evidence, and the branch has not been merged. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 1e7907baf..f2593dd89 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -96,6 +96,7 @@ def test_current_warc_provider_failures_are_bound_to_current_head(self) -> None: "PR #210 current exact head `bea65643109449d63d367a35b8d9bf327ee7cb2c`", "run `33183939299` / job `98894420986` failed closed because no OpenCode current-head verdict existed", "run `33183939193` / job `98892185954` failed closed after three provider HTTP 500 attempts", + "attempt-2 rerun `33172708455` / job `98915847518` also failed closed after three provider HTTP 500 attempts", ): with self.subTest(marker=marker): self.assertIn(marker, self.baseline) From b04830d91fdaf168c601b748293a56cf2d215595 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 02:02:55 +0900 Subject: [PATCH 030/250] docs: record review dispatch authorization blockers --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 4 ++-- .../test_documentation_active_pr_evidence_contract.py | 11 +++++++++++ 3 files changed, 14 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index c828d6ddc..252078107 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -9,6 +9,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ### Added - Revalidated the product-gap queue at 110 open pull requests (26 ready, 84 draft) and 11 open issues on 2026-08-29; refreshed protected-main `542ca1e9` and PR #46 exact-head evidence at `373113119446d99f578febd39efc19366e7736b1` after its ADR 0007 authority-boundary repair. Current hosted checks and independent approval remain required; no protected-main shipment is claimed. - Recorded PR #210's current exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence. +- Recorded current-head OpenCode dispatch authorization failures for PR #46 (`33192478312` / `98921183278`) and PR #238 (`33192483900` / `98921203971`): the central validator rejected the maintainer actor because it was not the configured scheduler identity; no review verdict or approval was synthesized. - Added an enforcing traceability contract for the protected-main MCP `tools/list` maturity claim and indexed its executable evidence dossier. - Clarified the 2026-08-28 gap snapshot's prior queue observation and separated open issues from governance signals. - Historical 2026-08-28 product-gap snapshot: protected-main `542ca1e9`, 110 open pull requests (26 ready, 84 draft), 11 open issues, current exact base/head pairs for representative PRs including #70, #82, #152, #37, #237, and #239, PR #170's merged `tools/list` contract, the active counted-approval gate, and the unchanged Phase 1 browser gap. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 34b975cc9..b1833e63e 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -22,7 +22,7 @@ This snapshot re-fetched the complete open-PR inventory, the protected `main` co During this recheck, #71, #154, #233, #234, and #235 were merged only into their unprotected feature-parent branches after exact current-head checks and review-thread resolution. Their successful stack checks are not protected-main delivery, and their child branches retain independent evidence requirements. -The sensitive-data child slice #53 was subsequently squash-merged into the unprotected #46 feature branch at merge commit `93c713a107df05385f745db4dca20091f21c4a3a` after exact-head Rust/coverage checks passed and current inline review threads were resolved. PR #46 remains an active main-targeting parent. Its current exact base/head pair is protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413` to `373113119446d99f578febd39efc19366e7736b1`; the head adds the ADR 0007 predicate-boundary clarification and regression contract, with local Python/Rust verification green. Current hosted security/review workflow runs are still pending or queued, and no qualifying non-author approval is present. +The sensitive-data child slice #53 was subsequently squash-merged into the unprotected #46 feature branch at merge commit `93c713a107df05385f745db4dca20091f21c4a3` after exact-head Rust/coverage checks passed and current inline review threads were resolved. PR #46 remains an active main-targeting parent. Its current exact base/head pair is protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413` to `373113119446d99f578febd39efc19366e7736b1`; the head adds the ADR 0007 predicate-boundary clarification and regression contract, with local Python/Rust verification green. Current hosted evidence remains incomplete: automatic OpenCode run `33189822385` / job `98913006386` failed closed without a current-head verdict, and central Strix run `33190794267` / job `98915422837` failed closed after three provider HTTP 500 attempts without a vulnerability report. A direct central `opencode-review` dispatch run `33192478312` / job `98921183278` was rejected because repository_dispatch actor `seonghobae` did not match configured scheduler identity `github-actions[bot]`; no qualifying non-author approval is present. The later exact-head recheck also recorded the WARC/PROV retention-lifecycle slice: #239 is Draft at `e840ca299d29a15223c8b9bb1397002c4f41b4a3` on #227 head `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0`, and #237 is Draft at `2459af602e72fbfe1ce816919473a1075ec0c41f` on protected `main`; their current exact checks and reviews remain independently actionable evidence. Neither active branch is protected-main behavior. @@ -30,7 +30,7 @@ The same exact-head recheck corrected workflow provenance: the active ruleset's The WARC resource-record slice #210 is now Ready; PR #210 current exact head `bea65643109449d63d367a35b8d9bf327ee7cb2c` is based directly on protected `main`, and its latest forward-only repair rejects raw and recursively percent-encoded nested credential names and percent-encoded ASCII controls. Local evidence is green. On this current head, run `33183939299` / job `98894420986` failed closed because no OpenCode current-head verdict existed, and run `33183939193` / job `98892185954` failed closed after three provider HTTP 500 attempts without a vulnerability report. The direct attempt-2 rerun `33172708455` / job `98915847518` also failed closed after three provider HTTP 500 attempts without a vulnerability report, confirming the provider/backend blocker rather than a source failure. Central repair PR #1391 was opened at historical head `e4ba6b599cd1e50d0139762885682607b731655d` and is now open at exact head `36ac3aa71b2580685f84d416a81e42c39dee927c` on current central `main` `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Its branch-update merge and follow-up prompt hardening are not approval or coverage evidence. -The documentation refresh PR #238 remains Ready on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`; its live GitHub metadata and PR body are authoritative for the exact self-referential head, while local full-suite evidence is green and current repository/security/coverage checks regenerate after each documentation push. The preceding exact-head OpenCode run `33184553025` / job `98894986761` failed closed because no `APPROVED` or `CHANGES_REQUESTED` verdict existed; earlier targeted run `33182749298` dispatched OpenCode run `33182772296`, whose coverage evidence succeeded but review failed closed as `MODEL_OUTPUT_UNAVAILABLE` with `model pool exhausted`, and optional cross-repository status publication was denied with HTTP 403. The current Devin documentation-evidence finding requiring an enforcing `tools/list` traceability contract has been implemented and its review thread resolved; the follow-up exact-head hosted checks remain required. These are review-tool/documentation findings, not approval or shipping evidence, and the branch has not been merged. +The documentation refresh PR #238 remains Ready on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`; its live GitHub metadata and PR body are authoritative for the exact self-referential head, while local full-suite evidence is green and current repository/security/coverage checks regenerate after each documentation push. The preceding exact-head OpenCode run `33184553025` / job `98894986761` failed closed because no `APPROVED` or `CHANGES_REQUESTED` verdict existed; earlier targeted run `33182749298` dispatched OpenCode run `33182772296`, whose coverage evidence succeeded but review failed closed as `MODEL_OUTPUT_UNAVAILABLE` with `model pool exhausted`, and optional cross-repository status publication was denied with HTTP 403. On current head `5bd7991c71a7d542aa8779194033e64ab43a506f`, automatic OpenCode run `33192261383` / job `98920524559` failed closed without a current-head verdict, current Strix evidence was still running at the recheck, and central `opencode-review` dispatch run `33192483900` / job `98921203971` was rejected because repository_dispatch actor `seonghobae` did not match configured scheduler identity `github-actions[bot]`. The current Devin documentation-evidence finding requiring an enforcing `tools/list` traceability contract has been implemented and its review thread resolved; the follow-up exact-head hosted checks remain required. These are review-tool/documentation findings, not approval or shipping evidence, and the branch has not been merged. The controlled Chromium prerequisite stack was also re-fetched after its exact-head repairs: #70 is Ready at `441a8ce1d09c329c5c1168f4906d9a38fd0abc01` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`; #71 is merged into the unprotected #70 feature branch; #72 is Draft at `600d3975c02b68da1974a4c73069b966b39dce7b` on the retained #71 branch; and #73 is Draft at `ce1b138509ab4f52cb0f80290f104358473c6ed3` on #72. #70's Rust, coverage, pinned-Chrome, and ordinary security checks are successful, while exact-head OpenCode failed closed without a current verdict and exact-head Strix failed closed after three provider HTTP 500 attempts; all current Devin informational threads are resolved. #72 and #73 retain independent exact-head evidence requirements. #82 is Ready at `f5776f5f233ac0a7c05e3f4a2846436c23438043` on protected `main`; its Rust, coverage, Chrome, and ordinary security checks pass, exact-head OpenCode failed closed without a current verdict, and its current Devin informational thread is resolved. #152 is Ready at `81407a0e5189a413d1be0963fea90a0c2f254ce1` on protected `main`; its source, coverage, and security checks are successful except exact-head `opencode-review`, which failed closed without a current-head verdict. These are active-stack evidence only, not protected-main behavior or merge authorization. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index f2593dd89..27e87edfb 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -101,6 +101,17 @@ def test_current_warc_provider_failures_are_bound_to_current_head(self) -> None: with self.subTest(marker=marker): self.assertIn(marker, self.baseline) + def test_current_opencode_dispatch_failures_are_bound_to_current_heads(self) -> None: + """OpenCode dispatch authorization failures must remain explicit blockers.""" + for marker in ( + "A direct central `opencode-review` dispatch run `33192478312` / job `98921183278` was rejected", + "On current head `5bd7991c71a7d542aa8779194033e64ab43a506f`, automatic OpenCode run `33192261383` / job `98920524559` failed closed", + "central `opencode-review` dispatch run `33192483900` / job `98921203971` was rejected", + "repository_dispatch actor `seonghobae` did not match configured scheduler identity `github-actions[bot]`", + ): + with self.subTest(marker=marker): + self.assertIn(marker, self.baseline) + def test_dependency_stacks_are_explicit_and_non_shipped(self) -> None: """Current browser, network, sensitive and compatibility stacks stay active-only.""" for pr_number in (52, 53, 54, 55, 56, 57, 58, 59, 60, 61, 62, 63, 64, 65, 66): From ef2bd1fa7a5028801c10be5d3edc7b2d82a0594f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 02:06:04 +0900 Subject: [PATCH 031/250] docs: bound prior review dispatch observation --- CHANGELOG.md | 2 +- docs/product-technical-gap-baseline.md | 2 +- tests/test_documentation_active_pr_evidence_contract.py | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 252078107..2344e269d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -9,7 +9,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ### Added - Revalidated the product-gap queue at 110 open pull requests (26 ready, 84 draft) and 11 open issues on 2026-08-29; refreshed protected-main `542ca1e9` and PR #46 exact-head evidence at `373113119446d99f578febd39efc19366e7736b1` after its ADR 0007 authority-boundary repair. Current hosted checks and independent approval remain required; no protected-main shipment is claimed. - Recorded PR #210's current exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence. -- Recorded current-head OpenCode dispatch authorization failures for PR #46 (`33192478312` / `98921183278`) and PR #238 (`33192483900` / `98921203971`): the central validator rejected the maintainer actor because it was not the configured scheduler identity; no review verdict or approval was synthesized. +- Recorded the current-head OpenCode dispatch authorization failure for PR #46 (`33192478312` / `98921183278`) and the immediately preceding PR #238 head (`33192483900` / `98921203971`): the central validator rejected the maintainer actor because it was not the configured scheduler identity; no review verdict or approval was synthesized. - Added an enforcing traceability contract for the protected-main MCP `tools/list` maturity claim and indexed its executable evidence dossier. - Clarified the 2026-08-28 gap snapshot's prior queue observation and separated open issues from governance signals. - Historical 2026-08-28 product-gap snapshot: protected-main `542ca1e9`, 110 open pull requests (26 ready, 84 draft), 11 open issues, current exact base/head pairs for representative PRs including #70, #82, #152, #37, #237, and #239, PR #170's merged `tools/list` contract, the active counted-approval gate, and the unchanged Phase 1 browser gap. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b1833e63e..2e892b615 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -30,7 +30,7 @@ The same exact-head recheck corrected workflow provenance: the active ruleset's The WARC resource-record slice #210 is now Ready; PR #210 current exact head `bea65643109449d63d367a35b8d9bf327ee7cb2c` is based directly on protected `main`, and its latest forward-only repair rejects raw and recursively percent-encoded nested credential names and percent-encoded ASCII controls. Local evidence is green. On this current head, run `33183939299` / job `98894420986` failed closed because no OpenCode current-head verdict existed, and run `33183939193` / job `98892185954` failed closed after three provider HTTP 500 attempts without a vulnerability report. The direct attempt-2 rerun `33172708455` / job `98915847518` also failed closed after three provider HTTP 500 attempts without a vulnerability report, confirming the provider/backend blocker rather than a source failure. Central repair PR #1391 was opened at historical head `e4ba6b599cd1e50d0139762885682607b731655d` and is now open at exact head `36ac3aa71b2580685f84d416a81e42c39dee927c` on current central `main` `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Its branch-update merge and follow-up prompt hardening are not approval or coverage evidence. -The documentation refresh PR #238 remains Ready on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`; its live GitHub metadata and PR body are authoritative for the exact self-referential head, while local full-suite evidence is green and current repository/security/coverage checks regenerate after each documentation push. The preceding exact-head OpenCode run `33184553025` / job `98894986761` failed closed because no `APPROVED` or `CHANGES_REQUESTED` verdict existed; earlier targeted run `33182749298` dispatched OpenCode run `33182772296`, whose coverage evidence succeeded but review failed closed as `MODEL_OUTPUT_UNAVAILABLE` with `model pool exhausted`, and optional cross-repository status publication was denied with HTTP 403. On current head `5bd7991c71a7d542aa8779194033e64ab43a506f`, automatic OpenCode run `33192261383` / job `98920524559` failed closed without a current-head verdict, current Strix evidence was still running at the recheck, and central `opencode-review` dispatch run `33192483900` / job `98921203971` was rejected because repository_dispatch actor `seonghobae` did not match configured scheduler identity `github-actions[bot]`. The current Devin documentation-evidence finding requiring an enforcing `tools/list` traceability contract has been implemented and its review thread resolved; the follow-up exact-head hosted checks remain required. These are review-tool/documentation findings, not approval or shipping evidence, and the branch has not been merged. +The documentation refresh PR #238 remains Ready on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`; its live GitHub metadata and PR body are authoritative for the exact self-referential head, while local full-suite evidence is green and current repository/security/coverage checks regenerate after each documentation push. The preceding exact-head OpenCode run `33184553025` / job `98894986761` failed closed because no `APPROVED` or `CHANGES_REQUESTED` verdict existed; earlier targeted run `33182749298` dispatched OpenCode run `33182772296`, whose coverage evidence succeeded but review failed closed as `MODEL_OUTPUT_UNAVAILABLE` with `model pool exhausted`, and optional cross-repository status publication was denied with HTTP 403. On the immediately preceding PR #238 head `5bd7991c71a7d542aa8779194033e64ab43a506f` (before this baseline commit), automatic OpenCode run `33192261383` / job `98920524559` failed closed without a current-head verdict, current Strix evidence was still running at that recheck, and central `opencode-review` dispatch run `33192483900` / job `98921203971` was rejected because repository_dispatch actor `seonghobae` did not match configured scheduler identity `github-actions[bot]`. The current Devin documentation-evidence finding requiring an enforcing `tools/list` traceability contract has been implemented and its review thread resolved; the follow-up exact-head hosted checks remain required. These are review-tool/documentation findings, not approval or shipping evidence, and the branch has not been merged. The controlled Chromium prerequisite stack was also re-fetched after its exact-head repairs: #70 is Ready at `441a8ce1d09c329c5c1168f4906d9a38fd0abc01` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`; #71 is merged into the unprotected #70 feature branch; #72 is Draft at `600d3975c02b68da1974a4c73069b966b39dce7b` on the retained #71 branch; and #73 is Draft at `ce1b138509ab4f52cb0f80290f104358473c6ed3` on #72. #70's Rust, coverage, pinned-Chrome, and ordinary security checks are successful, while exact-head OpenCode failed closed without a current verdict and exact-head Strix failed closed after three provider HTTP 500 attempts; all current Devin informational threads are resolved. #72 and #73 retain independent exact-head evidence requirements. #82 is Ready at `f5776f5f233ac0a7c05e3f4a2846436c23438043` on protected `main`; its Rust, coverage, Chrome, and ordinary security checks pass, exact-head OpenCode failed closed without a current verdict, and its current Devin informational thread is resolved. #152 is Ready at `81407a0e5189a413d1be0963fea90a0c2f254ce1` on protected `main`; its source, coverage, and security checks are successful except exact-head `opencode-review`, which failed closed without a current-head verdict. These are active-stack evidence only, not protected-main behavior or merge authorization. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 27e87edfb..3cdf769e9 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -105,7 +105,7 @@ def test_current_opencode_dispatch_failures_are_bound_to_current_heads(self) -> """OpenCode dispatch authorization failures must remain explicit blockers.""" for marker in ( "A direct central `opencode-review` dispatch run `33192478312` / job `98921183278` was rejected", - "On current head `5bd7991c71a7d542aa8779194033e64ab43a506f`, automatic OpenCode run `33192261383` / job `98920524559` failed closed", + "On the immediately preceding PR #238 head `5bd7991c71a7d542aa8779194033e64ab43a506f` (before this baseline commit), automatic OpenCode run `33192261383` / job `98920524559` failed closed", "central `opencode-review` dispatch run `33192483900` / job `98921203971` was rejected", "repository_dispatch actor `seonghobae` did not match configured scheduler identity `github-actions[bot]`", ): From d0b0d1ed92f891f14646fc673b8e1c0d912586fd Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 02:15:11 +0900 Subject: [PATCH 032/250] docs: align current changelog snapshot date --- CHANGELOG.md | 4 ++-- tests/test_gap_snapshot_inventory_consistency.py | 2 ++ 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 2344e269d..ca80c563d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,7 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] -- Refreshed the product-gap queue to 110 open pull requests (26 ready, 84 draft) on 2026-08-28 after #53, #71, #154, #233, #234, and #235 merged into unprotected feature parents; these are queue evidence, not protected-main shipment. +- Refreshed the product-gap queue to 110 open pull requests (26 ready, 84 draft) on 2026-08-29 after #53, #71, #154, #233, #234, and #235 merged into unprotected feature parents; these are queue evidence, not protected-main shipment. ### Added - Revalidated the product-gap queue at 110 open pull requests (26 ready, 84 draft) and 11 open issues on 2026-08-29; refreshed protected-main `542ca1e9` and PR #46 exact-head evidence at `373113119446d99f578febd39efc19366e7736b1` after its ADR 0007 authority-boundary repair. Current hosted checks and independent approval remain required; no protected-main shipment is claimed. @@ -13,7 +13,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Added an enforcing traceability contract for the protected-main MCP `tools/list` maturity claim and indexed its executable evidence dossier. - Clarified the 2026-08-28 gap snapshot's prior queue observation and separated open issues from governance signals. - Historical 2026-08-28 product-gap snapshot: protected-main `542ca1e9`, 110 open pull requests (26 ready, 84 draft), 11 open issues, current exact base/head pairs for representative PRs including #70, #82, #152, #37, #237, and #239, PR #170's merged `tools/list` contract, the active counted-approval gate, and the unchanged Phase 1 browser gap. -- Refreshed the product and technical gap baseline onto the 2026-08-28 live inventory; current queue and exact-head evidence are explicitly separated from the historical 2026-08-26 snapshot so stale delivery evidence cannot be promoted. +- Historical 2026-08-28 baseline refresh: current queue and exact-head evidence were explicitly separated from the historical 2026-08-26 snapshot so stale delivery evidence cannot be promoted. - Hardened the product-completion documentation contract by classifying current-snapshot count markers explicitly instead of routing them by substring heuristics. - Corrected the baseline's #72/#73 exact SHA evidence to full 40-character values and tracked PR #238's current head. - Historical predecessor: PR #210 Ready head `d83748a70bd1b16dbfec46007fe02989ba6ce188` was superseded by exact Ready head `0341079331f9cea669eb9a5cc21842fd6027431e`; the earlier entry recorded its nested credential-query defense and current-head hosted-check regeneration. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 7b3a01870..f9dce6443 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -57,6 +57,8 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: expected = "110 open pull requests (26 ready, 84 draft)" self.assertIn(expected, preamble) + self.assertIn("on 2026-08-29", preamble) + self.assertNotIn("on 2026-08-28", preamble) self.assertIn(expected, added) self.assertNotIn("126 open pull requests (54 ready, 72 draft)", preamble) self.assertNotIn("115 open pull requests (31 ready, 84 draft)", preamble) From b6913404125976e24ddd7110221b51c6ad666674 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 02:46:13 +0900 Subject: [PATCH 033/250] docs: refresh gap baseline after WARC stack merge --- CHANGELOG.md | 7 ++-- docs/product-technical-gap-baseline.md | 17 ++++---- ...cumentation_active_pr_evidence_contract.py | 20 ++++----- ...test_gap_snapshot_inventory_consistency.py | 42 +++++++++++++++++-- 4 files changed, 61 insertions(+), 25 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index ca80c563d..8e575e8a1 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,11 +4,12 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] -- Refreshed the product-gap queue to 110 open pull requests (26 ready, 84 draft) on 2026-08-29 after #53, #71, #154, #233, #234, and #235 merged into unprotected feature parents; these are queue evidence, not protected-main shipment. +- Refreshed the product-gap queue to 109 open pull requests (25 ready, 84 draft) on 2026-08-29 after #53, #71, #154, #217, #233, #234, and #235 merged into unprotected feature parents; these are queue evidence, not protected-main shipment. ### Added -- Revalidated the product-gap queue at 110 open pull requests (26 ready, 84 draft) and 11 open issues on 2026-08-29; refreshed protected-main `542ca1e9` and PR #46 exact-head evidence at `373113119446d99f578febd39efc19366e7736b1` after its ADR 0007 authority-boundary repair. Current hosted checks and independent approval remain required; no protected-main shipment is claimed. -- Recorded PR #210's current exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence. +- Revalidated the product-gap queue at 109 open pull requests (25 ready, 84 draft) and 11 open issues on 2026-08-29; refreshed protected-main `542ca1e9`, PR #46 exact-head evidence at `373113119446d99f578febd39efc19366e7736b1`, and PR #210's post-stack-merge head at `66f360ccac5cec60c72222cc79d58e39f6f00088`. Current hosted checks and independent approval remain required; no protected-main shipment is claimed. +- Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. +- Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. - Recorded the current-head OpenCode dispatch authorization failure for PR #46 (`33192478312` / `98921183278`) and the immediately preceding PR #238 head (`33192483900` / `98921203971`): the central validator rejected the maintainer actor because it was not the configured scheduler identity; no review verdict or approval was synthesized. - Added an enforcing traceability contract for the protected-main MCP `tools/list` maturity claim and indexed its executable evidence dossier. - Clarified the 2026-08-28 gap snapshot's prior queue observation and separated open issues from governance signals. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 2e892b615..fedad82c9 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -14,23 +14,25 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a ### Open pull requests -The live repository contained **110 open pull requests: 26 non-draft and 84 draft** when this snapshot re-paginated the complete open inventory. Compared with the prior **2026-08-28 111-PR snapshot**, stacked evidence PR #53 was merged into its unprotected feature parent; the preceding **2026-08-28 116-PR snapshot** had already recorded #71, #154, #233, #234, and #235 merging into their unprotected feature parents. The 2026-08-29 exact-head recheck changed no queue counts. None reached protected `main`. These counts are queue evidence, not protected-main delivery; protected `main` remains `542ca1e9c0a863595b8b6697790005d2471f5413`, with 11 open issues and no releases or tags. The volume and stack depth remain themselves a product-delivery risk: review, exact-head checks, dependency order, and integration truth can drift faster than a buyer-visible vertical slice reaches protected `main`. +The live repository contained **109 open pull requests: 25 non-draft and 84 draft** when this snapshot re-paginated the complete open inventory. Compared with the prior **2026-08-28 111-PR snapshot**, stacked evidence PR #53 was merged into its unprotected feature parent; the preceding **2026-08-28 116-PR snapshot** had already recorded #71, #154, #233, #234, and #235 merging into their unprotected feature parents. PR #217 has since been squash-merged into the unprotected #210 feature parent; the current queue therefore contains no protected-main shipment. These counts are queue evidence, not protected-main delivery; protected `main` remains `542ca1e9c0a863595b8b6697790005d2471f5413`, with 11 open issues and no releases or tags. The volume and stack depth remain themselves a product-delivery risk: review, exact-head checks, dependency order, and integration truth can drift faster than a buyer-visible vertical slice reaches protected `main`. #### 2026-08-29 maintenance-loop record -This snapshot re-fetched the complete open-PR inventory, the protected `main` commit, the active required-workflow ruleset, collaborator permissions, and the exact base/head pair for each representative PR. Before PR #238 was published, the same maintenance loop observed 115 open pull requests (31 ready, 84 draft); a later 116-PR recheck preceded five stack merges, leaving 111 open pull requests (27 ready, 84 draft), and the exact current recheck leaves 110 open pull requests (26 ready, 84 draft) after #53 merged. The active ruleset still requires one counted approving review and resolved threads; the only repository collaborator is `seonghobae`, so review provisioning remains the merge blocker for main-targeting PRs. PR #170 is merged and is not active-PR evidence. +This snapshot re-fetched the complete open-PR inventory, the protected `main` commit, the active required-workflow ruleset, collaborator permissions, and the exact base/head pair for each representative PR. Before PR #238 was published, the same maintenance loop observed 115 open pull requests (31 ready, 84 draft); a later 116-PR recheck preceded five stack merges, leaving 111 open pull requests (27 ready, 84 draft), and subsequent child-stack merges left 109 open pull requests (25 ready, 84 draft). The active ruleset still requires one counted approving review and resolved threads; the only repository collaborator is `seonghobae`, so review provisioning remains the merge blocker for main-targeting PRs. PR #170 is merged and is not active-PR evidence. During this recheck, #71, #154, #233, #234, and #235 were merged only into their unprotected feature-parent branches after exact current-head checks and review-thread resolution. Their successful stack checks are not protected-main delivery, and their child branches retain independent evidence requirements. The sensitive-data child slice #53 was subsequently squash-merged into the unprotected #46 feature branch at merge commit `93c713a107df05385f745db4dca20091f21c4a3` after exact-head Rust/coverage checks passed and current inline review threads were resolved. PR #46 remains an active main-targeting parent. Its current exact base/head pair is protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413` to `373113119446d99f578febd39efc19366e7736b1`; the head adds the ADR 0007 predicate-boundary clarification and regression contract, with local Python/Rust verification green. Current hosted evidence remains incomplete: automatic OpenCode run `33189822385` / job `98913006386` failed closed without a current-head verdict, and central Strix run `33190794267` / job `98915422837` failed closed after three provider HTTP 500 attempts without a vulnerability report. A direct central `opencode-review` dispatch run `33192478312` / job `98921183278` was rejected because repository_dispatch actor `seonghobae` did not match configured scheduler identity `github-actions[bot]`; no qualifying non-author approval is present. +The WARC/PROV child slice #217 was squash-merged into the unprotected #210 feature branch at merge commit `66f360ccac5cec60c72222cc79d58e39f6f00088` from exact PR head `6b8a3fdeae52ad94b90086bbc9b42863b90c9614`. PR #210 consequently moved to that merge commit as its current exact head on protected `main`; its current Rust, coverage, and security checks are regenerating, with `opencode-review` still queued and `Production coverage`, `Rust contracts`, and `strix` still in progress at the recheck. This stack merge is not protected-main delivery or approval evidence. + The later exact-head recheck also recorded the WARC/PROV retention-lifecycle slice: #239 is Draft at `e840ca299d29a15223c8b9bb1397002c4f41b4a3` on #227 head `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0`, and #237 is Draft at `2459af602e72fbfe1ce816919473a1075ec0c41f` on protected `main`; their current exact checks and reviews remain independently actionable evidence. Neither active branch is protected-main behavior. The same exact-head recheck corrected workflow provenance: the active ruleset's seven required workflow entries (`close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, and `noema-review`) point to the central `.github` repository, repository ID `1274066402`, where all seven files exist on `main`; their absence from the OriginWeave tree did not prove missing workflow identities. On PR #210 head `0341079331f9cea669eb9a5cc21842fd6027431e`, run `33177641855` failed closed because no OpenCode current-head verdict existed, while run `33177641888` failed closed after three bounded attempts because the Strix provider/backend returned an internal server error and produced no vulnerability report. A `gh run view` workflow-endpoint 404 for the external workflow IDs is a lookup mismatch, not passing evidence or proof that the identities are absent. A bounded central scheduler dispatch was accepted as run `33178984025` with auto-merge and branch updates disabled; no result is transferred until the exact head is revalidated. These failures block affected PRs until current-head review and security evidence complete. This does not authorize bypass, self-approval, stale checks, or weaker gates. -The WARC resource-record slice #210 is now Ready; PR #210 current exact head `bea65643109449d63d367a35b8d9bf327ee7cb2c` is based directly on protected `main`, and its latest forward-only repair rejects raw and recursively percent-encoded nested credential names and percent-encoded ASCII controls. Local evidence is green. On this current head, run `33183939299` / job `98894420986` failed closed because no OpenCode current-head verdict existed, and run `33183939193` / job `98892185954` failed closed after three provider HTTP 500 attempts without a vulnerability report. The direct attempt-2 rerun `33172708455` / job `98915847518` also failed closed after three provider HTTP 500 attempts without a vulnerability report, confirming the provider/backend blocker rather than a source failure. Central repair PR #1391 was opened at historical head `e4ba6b599cd1e50d0139762885682607b731655d` and is now open at exact head `36ac3aa71b2580685f84d416a81e42c39dee927c` on current central `main` `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Its branch-update merge and follow-up prompt hardening are not approval or coverage evidence. +The WARC resource-record slice #210 is now Ready; PR #210 current exact head is `66f360ccac5cec60c72222cc79d58e39f6f00088` based directly on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`, after incorporating #217. Its prior exact head `bea65643109449d63d367a35b8d9bf327ee7cb2c` and its OpenCode/Strix provider failures remain historical evidence only. At the current head, `opencode-review` job `98931501473` is queued, `Production coverage` job `98931213826`, `Rust contracts` job `98931213574`, and `strix` job `98931205643` are in progress; completed security jobs are successful, but no current-head review verdict or counted approval exists. Central repair PR #1391 was opened at historical head `e4ba6b599cd1e50d0139762885682607b731655d` and is now open at exact head `36ac3aa71b2580685f84d416a81e42c39dee927c` on current central `main` `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Its branch-update merge and follow-up prompt hardening are not approval or coverage evidence. -The documentation refresh PR #238 remains Ready on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`; its live GitHub metadata and PR body are authoritative for the exact self-referential head, while local full-suite evidence is green and current repository/security/coverage checks regenerate after each documentation push. The preceding exact-head OpenCode run `33184553025` / job `98894986761` failed closed because no `APPROVED` or `CHANGES_REQUESTED` verdict existed; earlier targeted run `33182749298` dispatched OpenCode run `33182772296`, whose coverage evidence succeeded but review failed closed as `MODEL_OUTPUT_UNAVAILABLE` with `model pool exhausted`, and optional cross-repository status publication was denied with HTTP 403. On the immediately preceding PR #238 head `5bd7991c71a7d542aa8779194033e64ab43a506f` (before this baseline commit), automatic OpenCode run `33192261383` / job `98920524559` failed closed without a current-head verdict, current Strix evidence was still running at that recheck, and central `opencode-review` dispatch run `33192483900` / job `98921203971` was rejected because repository_dispatch actor `seonghobae` did not match configured scheduler identity `github-actions[bot]`. The current Devin documentation-evidence finding requiring an enforcing `tools/list` traceability contract has been implemented and its review thread resolved; the follow-up exact-head hosted checks remain required. These are review-tool/documentation findings, not approval or shipping evidence, and the branch has not been merged. +The documentation refresh PR #238 remains Ready on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`; its live GitHub metadata and PR body are authoritative for the exact self-referential head, while local full-suite evidence is green. PR #238 current exact head is `d0b0d1ed92f891f14646fc673b8e1c0d912586fd`: automatic OpenCode run `33193822920` / job `98926243116` failed closed without a current-head verdict, while current Strix run `33193822929` / job `98925769697` succeeded and the other current repository/security/coverage checks succeeded. Central dispatch run `33194506918` / job `98928580387` also failed closed at OpenCode after its validator, bootstrap, and coverage jobs succeeded. The preceding exact-head OpenCode run `33184553025` / job `98894986761` and earlier targeted run `33182749298` remain historical; targeted run `33182749298` dispatched OpenCode run `33182772296`, which failed closed as `MODEL_OUTPUT_UNAVAILABLE` with `model pool exhausted`, and optional cross-repository status publication was denied with HTTP 403. The current Devin documentation-evidence finding requiring an enforcing `tools/list` traceability contract has been implemented and its review thread resolved. No non-author counted approval exists, so these are review-tool/documentation findings, not approval or protected-main shipping evidence. The controlled Chromium prerequisite stack was also re-fetched after its exact-head repairs: #70 is Ready at `441a8ce1d09c329c5c1168f4906d9a38fd0abc01` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`; #71 is merged into the unprotected #70 feature branch; #72 is Draft at `600d3975c02b68da1974a4c73069b966b39dce7b` on the retained #71 branch; and #73 is Draft at `ce1b138509ab4f52cb0f80290f104358473c6ed3` on #72. #70's Rust, coverage, pinned-Chrome, and ordinary security checks are successful, while exact-head OpenCode failed closed without a current verdict and exact-head Strix failed closed after three provider HTTP 500 attempts; all current Devin informational threads are resolved. #72 and #73 retain independent exact-head evidence requirements. #82 is Ready at `f5776f5f233ac0a7c05e3f4a2846436c23438043` on protected `main`; its Rust, coverage, Chrome, and ordinary security checks pass, exact-head OpenCode failed closed without a current verdict, and its current Devin informational thread is resolved. #152 is Ready at `81407a0e5189a413d1be0963fea90a0c2f254ce1` on protected `main`; its source, coverage, and security checks are successful except exact-head `opencode-review`, which failed closed without a current-head verdict. These are active-stack evidence only, not protected-main behavior or merge authorization. @@ -45,7 +47,7 @@ The following representative slices were re-fetched from GitHub for this snapsho | #46 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `373113119446d99f578febd39efc19366e7736b1` | | #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `441a8ce1d09c329c5c1168f4906d9a38fd0abc01` | | #82 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `f5776f5f233ac0a7c05e3f4a2846436c23438043` | -| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `bea65643109449d63d367a35b8d9bf327ee7cb2c` | +| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `66f360ccac5cec60c72222cc79d58e39f6f00088` | | #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `2459af602e72fbfe1ce816919473a1075ec0c41f` | | #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `e840ca299d29a15223c8b9bb1397002c4f41b4a3` | | #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0145ccba5901e301b41d4be674ca1ed23483ad37` | @@ -123,7 +125,6 @@ The following rows were current on 2026-08-24 and are retained only as regressio | #220 | Ready | `0841d2ab3d8b5e60a03c0a8e818cf438e2716829` | `ed4cab16cf88c76ce1c145a22d0a274ef2d57263` | | #219 | Ready | `0841d2ab3d8b5e60a03c0a8e818cf438e2716829` | `8145d40f1b028a8f4dc7e7da47ac89bb9e5bb2c7` | | #218 | Ready | `0841d2ab3d8b5e60a03c0a8e818cf438e2716829` | `49e98fba6974219b3bb0336c822b12667f1e1c03` | -| #217 | Draft | `529d11a3571f6b1834b9baa49ef67eb08f043978` | `56fcfa56525e4f2e980e0ee05b6776d621bcddc5` | | #216 | Ready | `0841d2ab3d8b5e60a03c0a8e818cf438e2716829` | `75130851a0f7ce528a7a36382eb026ac7942a0aa` | | #214 | Draft | `40d642d5470a7753b8211907c190367f742f2f12` | `f79999681866ecf0e5fe17d895170f3f6cae7361` | | #211 | Draft | `85cc477688246900697f4cfb91c0c8f1f692934a` | `40d642d5470a7753b8211907c190367f742f2f12` | @@ -131,7 +132,7 @@ The following rows were current on 2026-08-24 and are retained only as regressio | #209 | Ready | `0841d2ab3d8b5e60a03c0a8e818cf438e2716829` | `c38b9665774d6b3754e572bed527737b5e179833` | | #208 | Ready | `0841d2ab3d8b5e60a03c0a8e818cf438e2716829` | `85cc477688246900697f4cfb91c0c8f1f692934a` | -The stack topology shows #209 → #210 → #217 → #222 (WARC/PROV chain), #208 → #211 → #214 (BAP chain), #218 → #221 → #220 (release/enterprise chain) at this snapshot. Every row above remains active-PR evidence; none is protected-main behavior. +The stack topology shows #209 → #210 → #217 → #222 (WARC/PROV chain, with #217 merged into #210's unprotected branch), #208 → #211 → #214 (BAP chain), and #218 → #221 → #220 (release/enterprise chain) at this snapshot. Every active row above remains PR evidence; none is protected-main behavior. ### Required-check provider failure record @@ -194,7 +195,7 @@ The hourly product-development loop is operational infrastructure, not proof tha | P1 | Buyers can install, update, verify, and roll back a supported product | **Not shipped** | #201; signed Windows/macOS/Linux/headless artifacts, Chromium revision manifest, updater security, patch SLA, SBOM, SLSA provenance, and recovery | | P1 | Enterprise teams can provision, approve, audit, operate, and recover the service | **Not shipped** | #202; Keyverse-compatible OIDC/SCIM, tenant isolation, policy/approval/evidence UI, SLO/incident controls, data residency, CSAP/SOC 2 evidence mapping, WCAG 2.2, Figma File ID, and Storybook | | P0 | A release has reproducible proof of usefulness, safety, evidence completeness, and recovery | **No product-wide release gate** | #203; deterministic, compatibility, adversarial, recovery, and enterprise suites with statistical reporting and an exact-artifact commercial acceptance gate | -| P0 | Valid changes reach protected `main` without authority improvisation or unbounded stack growth | **Blocked / high integration debt** | Shrink the 110-PR queue in dependency order, provision legitimate review authority, require exact-current evidence, and close duplicates/superseded branches | +| P0 | Valid changes reach protected `main` without authority improvisation or unbounded stack growth | **Blocked / high integration debt** | Shrink the 109-PR queue in dependency order, provision legitimate review authority, require exact-current evidence, and close duplicates/superseded branches | ## Commercial completion definition diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 3cdf769e9..e42df42e2 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -57,7 +57,7 @@ def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> No "| #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `441a8ce1d09c329c5c1168f4906d9a38fd0abc01` |", "| #82 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `f5776f5f233ac0a7c05e3f4a2846436c23438043` |", "| #152 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `81407a0e5189a413d1be0963fea90a0c2f254ce1` |", - "| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `bea65643109449d63d367a35b8d9bf327ee7cb2c` |", + "| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `66f360ccac5cec60c72222cc79d58e39f6f00088` |", "| #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `2459af602e72fbfe1ce816919473a1075ec0c41f` |", "| #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `e840ca299d29a15223c8b9bb1397002c4f41b4a3` |", "| #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0145ccba5901e301b41d4be674ca1ed23483ad37` |", @@ -81,7 +81,7 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] self.assertIn("on 2026-08-29", refresh_line) - self.assertIn("110 open pull requests (26 ready, 84 draft)", refresh_line) + self.assertIn("109 open pull requests (25 ready, 84 draft)", refresh_line) self.assertIn("11 open issues", refresh_line) self.assertNotIn("- Corrected the 2026-08-28 product-gap snapshot", added) self.assertNotIn("- Revalidated the product-gap queue at", changed) @@ -91,12 +91,12 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertNotIn("153 open pull requests (39 ready, 114 draft)", refresh_line) def test_current_warc_provider_failures_are_bound_to_current_head(self) -> None: - """WARC provider failures must not rely only on a superseded head's runs.""" + """WARC evidence must describe the current parent head after stack merge.""" for marker in ( - "PR #210 current exact head `bea65643109449d63d367a35b8d9bf327ee7cb2c`", - "run `33183939299` / job `98894420986` failed closed because no OpenCode current-head verdict existed", - "run `33183939193` / job `98892185954` failed closed after three provider HTTP 500 attempts", - "attempt-2 rerun `33172708455` / job `98915847518` also failed closed after three provider HTTP 500 attempts", + "PR #210 current exact head is `66f360ccac5cec60c72222cc79d58e39f6f00088`", + "`opencode-review` job `98931501473` is queued", + "`Production coverage` job `98931213826`, `Rust contracts` job `98931213574`, and `strix` job `98931205643` are in progress", + "Its prior exact head `bea65643109449d63d367a35b8d9bf327ee7cb2c` and its OpenCode/Strix provider failures remain historical evidence only", ): with self.subTest(marker=marker): self.assertIn(marker, self.baseline) @@ -105,9 +105,9 @@ def test_current_opencode_dispatch_failures_are_bound_to_current_heads(self) -> """OpenCode dispatch authorization failures must remain explicit blockers.""" for marker in ( "A direct central `opencode-review` dispatch run `33192478312` / job `98921183278` was rejected", - "On the immediately preceding PR #238 head `5bd7991c71a7d542aa8779194033e64ab43a506f` (before this baseline commit), automatic OpenCode run `33192261383` / job `98920524559` failed closed", - "central `opencode-review` dispatch run `33192483900` / job `98921203971` was rejected", - "repository_dispatch actor `seonghobae` did not match configured scheduler identity `github-actions[bot]`", + "PR #238 current exact head is `d0b0d1ed92f891f14646fc673b8e1c0d912586fd`", + "automatic OpenCode run `33193822920` / job `98926243116` failed closed without a current-head verdict", + "Central dispatch run `33194506918` / job `98928580387` also failed closed at OpenCode", ): with self.subTest(marker=marker): self.assertIn(marker, self.baseline) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index f9dce6443..fd6360573 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -20,13 +20,13 @@ def setUpClass(cls) -> None: cls.changelog = CHANGELOG.read_text(encoding="utf-8") def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: - """The current snapshot must use the exact 110/26/84 inventory observation.""" + """The current snapshot must use the exact 109/25/84 inventory observation.""" current = self.baseline.split("### Open pull requests", 1)[1].split( "#### 2026-08-29 maintenance-loop record", 1 )[0] for marker in ( - "110 open pull requests", - "26 non-draft", + "109 open pull requests", + "25 non-draft", "84 draft", ): with self.subTest(marker=marker): @@ -55,7 +55,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "110 open pull requests (26 ready, 84 draft)" + expected = "109 open pull requests (25 ready, 84 draft)" self.assertIn(expected, preamble) self.assertIn("on 2026-08-29", preamble) self.assertNotIn("on 2026-08-28", preamble) @@ -63,6 +63,40 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: self.assertNotIn("126 open pull requests (54 ready, 72 draft)", preamble) self.assertNotIn("115 open pull requests (31 ready, 84 draft)", preamble) self.assertNotIn("126 open pull requests (54 ready, 72 draft)", added) + self.assertNotIn("110 open pull requests (26 ready, 84 draft)", preamble) + + def test_current_snapshot_records_pr217_merge_and_pr210_revalidation(self) -> None: + """A stacked merge must update the live queue and parent exact-head evidence.""" + current = self.baseline.split("### Open pull requests", 1)[1].split( + "#### 2026-08-29 maintenance-loop record", 1 + )[0] + record = self.baseline.split( + "#### 2026-08-29 maintenance-loop record", 1 + )[1].split("#### Current exact-head active PR evidence", 1)[0] + self.assertIn("109 open pull requests", current) + self.assertIn("25 non-draft", current) + self.assertIn("#217 was squash-merged", record) + self.assertIn("66f360ccac5cec60c72222cc79d58e39f6f00088", record) + self.assertIn( + "| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | " + "`66f360ccac5cec60c72222cc79d58e39f6f00088` |", + self.baseline, + ) + self.assertNotIn("| #217 |", current) + + def test_current_documentation_head_records_security_and_review_state(self) -> None: + """The self-referential documentation PR must preserve current-head gate truth.""" + record = self.baseline.split( + "#### 2026-08-29 maintenance-loop record", 1 + )[1].split("#### Current exact-head active PR evidence", 1)[0] + for marker in ( + "PR #238 current exact head is `d0b0d1ed92f891f14646fc673b8e1c0d912586fd`", + "automatic OpenCode run `33193822920` / job `98926243116` failed closed", + "current Strix run `33193822929` / job `98925769697` succeeded", + "Central dispatch run `33194506918` / job `98928580387` also failed closed at OpenCode", + ): + with self.subTest(marker=marker): + self.assertIn(marker, record) if __name__ == "__main__": From 40c217e6b07027f41cc922c06baf7cad9fcf713e Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 02:47:43 +0900 Subject: [PATCH 034/250] test: align gap queue contract with live snapshot --- tests/test_product_completion_gap_contract.py | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 655213f2d..f570c6a33 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -26,8 +26,8 @@ def test_baseline_records_current_inventory_and_completion_issues(self) -> None: current = text.split("## Observed snapshot: ", 1)[1].split(end_marker, 1)[0] for phrase in ( - "110 open pull requests", - "26 non-draft", + "109 open pull requests", + "25 non-draft", "84 draft", "2026-08-28 116-PR snapshot", ): @@ -41,7 +41,7 @@ def test_baseline_records_current_inventory_and_completion_issues(self) -> None: "#201", "#202", "#203", - "Shrink the 110-PR queue", + "Shrink the 109-PR queue", "durable WARC/PROV replay", "stable BAP/MCP runtime API", "signed cross-platform Chromium distribution", From ea9bf083b3e394c1903e05d8a17f65145b32beb9 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 02:58:24 +0900 Subject: [PATCH 035/250] docs: refresh current WARC parent evidence --- CHANGELOG.md | 2 +- docs/product-technical-gap-baseline.md | 8 ++++---- ...st_documentation_active_pr_evidence_contract.py | 14 +++++++------- tests/test_gap_snapshot_inventory_consistency.py | 6 +++--- 4 files changed, 15 insertions(+), 15 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 8e575e8a1..31002be95 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,7 +7,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Refreshed the product-gap queue to 109 open pull requests (25 ready, 84 draft) on 2026-08-29 after #53, #71, #154, #217, #233, #234, and #235 merged into unprotected feature parents; these are queue evidence, not protected-main shipment. ### Added -- Revalidated the product-gap queue at 109 open pull requests (25 ready, 84 draft) and 11 open issues on 2026-08-29; refreshed protected-main `542ca1e9`, PR #46 exact-head evidence at `373113119446d99f578febd39efc19366e7736b1`, and PR #210's post-stack-merge head at `66f360ccac5cec60c72222cc79d58e39f6f00088`. Current hosted checks and independent approval remain required; no protected-main shipment is claimed. +- Revalidated the product-gap queue at 109 open pull requests (25 ready, 84 draft) and 11 open issues on 2026-08-29; refreshed protected-main `542ca1e9`, PR #46 exact-head evidence at `373113119446d99f578febd39efc19366e7736b1`, and PR #210's current post-stack-merge head at `5f59947f5e4b0d3bc0aa5b2d4c6722d3b7c43047`. Current hosted checks and independent approval remain required; no protected-main shipment is claimed. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. - Recorded the current-head OpenCode dispatch authorization failure for PR #46 (`33192478312` / `98921183278`) and the immediately preceding PR #238 head (`33192483900` / `98921203971`): the central validator rejected the maintainer actor because it was not the configured scheduler identity; no review verdict or approval was synthesized. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index fedad82c9..80841cd5d 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -24,15 +24,15 @@ During this recheck, #71, #154, #233, #234, and #235 were merged only into their The sensitive-data child slice #53 was subsequently squash-merged into the unprotected #46 feature branch at merge commit `93c713a107df05385f745db4dca20091f21c4a3` after exact-head Rust/coverage checks passed and current inline review threads were resolved. PR #46 remains an active main-targeting parent. Its current exact base/head pair is protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413` to `373113119446d99f578febd39efc19366e7736b1`; the head adds the ADR 0007 predicate-boundary clarification and regression contract, with local Python/Rust verification green. Current hosted evidence remains incomplete: automatic OpenCode run `33189822385` / job `98913006386` failed closed without a current-head verdict, and central Strix run `33190794267` / job `98915422837` failed closed after three provider HTTP 500 attempts without a vulnerability report. A direct central `opencode-review` dispatch run `33192478312` / job `98921183278` was rejected because repository_dispatch actor `seonghobae` did not match configured scheduler identity `github-actions[bot]`; no qualifying non-author approval is present. -The WARC/PROV child slice #217 was squash-merged into the unprotected #210 feature branch at merge commit `66f360ccac5cec60c72222cc79d58e39f6f00088` from exact PR head `6b8a3fdeae52ad94b90086bbc9b42863b90c9614`. PR #210 consequently moved to that merge commit as its current exact head on protected `main`; its current Rust, coverage, and security checks are regenerating, with `opencode-review` still queued and `Production coverage`, `Rust contracts`, and `strix` still in progress at the recheck. This stack merge is not protected-main delivery or approval evidence. +The WARC/PROV child slice #217 was squash-merged into the unprotected #210 feature branch at merge commit `66f360ccac5cec60c72222cc79d58e39f6f00088` from exact PR head `6b8a3fdeae52ad94b90086bbc9b42863b90c9614`. PR #210 subsequently advanced to current exact head `5f59947f5e4b0d3bc0aa5b2d4c6722d3b7c43047` after its merged-child attribution repair; this stack remains active-PR evidence and not protected-main delivery or approval evidence. The later exact-head recheck also recorded the WARC/PROV retention-lifecycle slice: #239 is Draft at `e840ca299d29a15223c8b9bb1397002c4f41b4a3` on #227 head `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0`, and #237 is Draft at `2459af602e72fbfe1ce816919473a1075ec0c41f` on protected `main`; their current exact checks and reviews remain independently actionable evidence. Neither active branch is protected-main behavior. The same exact-head recheck corrected workflow provenance: the active ruleset's seven required workflow entries (`close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, and `noema-review`) point to the central `.github` repository, repository ID `1274066402`, where all seven files exist on `main`; their absence from the OriginWeave tree did not prove missing workflow identities. On PR #210 head `0341079331f9cea669eb9a5cc21842fd6027431e`, run `33177641855` failed closed because no OpenCode current-head verdict existed, while run `33177641888` failed closed after three bounded attempts because the Strix provider/backend returned an internal server error and produced no vulnerability report. A `gh run view` workflow-endpoint 404 for the external workflow IDs is a lookup mismatch, not passing evidence or proof that the identities are absent. A bounded central scheduler dispatch was accepted as run `33178984025` with auto-merge and branch updates disabled; no result is transferred until the exact head is revalidated. These failures block affected PRs until current-head review and security evidence complete. This does not authorize bypass, self-approval, stale checks, or weaker gates. -The WARC resource-record slice #210 is now Ready; PR #210 current exact head is `66f360ccac5cec60c72222cc79d58e39f6f00088` based directly on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`, after incorporating #217. Its prior exact head `bea65643109449d63d367a35b8d9bf327ee7cb2c` and its OpenCode/Strix provider failures remain historical evidence only. At the current head, `opencode-review` job `98931501473` is queued, `Production coverage` job `98931213826`, `Rust contracts` job `98931213574`, and `strix` job `98931205643` are in progress; completed security jobs are successful, but no current-head review verdict or counted approval exists. Central repair PR #1391 was opened at historical head `e4ba6b599cd1e50d0139762885682607b731655d` and is now open at exact head `36ac3aa71b2580685f84d416a81e42c39dee927c` on current central `main` `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Its branch-update merge and follow-up prompt hardening are not approval or coverage evidence. +The WARC resource-record slice #210 is now Ready; PR #210 current exact head is `5f59947f5e4b0d3bc0aa5b2d4c6722d3b7c43047` based directly on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`, after incorporating #217 and correcting the merged-child attribution. Its prior stack merge head `66f360ccac5cec60c72222cc79d58e39f6f00088`, earlier exact head `bea65643109449d63d367a35b8d9bf327ee7cb2c`, and their OpenCode/Strix provider failures remain historical evidence only. At the current head, `coverage-evidence` job `98935786817` is queued, `Production coverage` job `98935658309` and `Rust contracts` job `98935657983` are in progress, and completed ordinary checks include `Semgrep OSS` job `98935840392` and `Trivy` job `98935809116`; no current-head review verdict or counted approval exists. Central repair PR #1391 was opened at historical head `e4ba6b599cd1e50d0139762885682607b731655d` and is now open at exact head `36ac3aa71b2580685f84d416a81e42c39dee927c` on current central `main` `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Its branch-update merge and follow-up prompt hardening are not approval or coverage evidence. -The documentation refresh PR #238 remains Ready on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`; its live GitHub metadata and PR body are authoritative for the exact self-referential head, while local full-suite evidence is green. PR #238 current exact head is `d0b0d1ed92f891f14646fc673b8e1c0d912586fd`: automatic OpenCode run `33193822920` / job `98926243116` failed closed without a current-head verdict, while current Strix run `33193822929` / job `98925769697` succeeded and the other current repository/security/coverage checks succeeded. Central dispatch run `33194506918` / job `98928580387` also failed closed at OpenCode after its validator, bootstrap, and coverage jobs succeeded. The preceding exact-head OpenCode run `33184553025` / job `98894986761` and earlier targeted run `33182749298` remain historical; targeted run `33182749298` dispatched OpenCode run `33182772296`, which failed closed as `MODEL_OUTPUT_UNAVAILABLE` with `model pool exhausted`, and optional cross-repository status publication was denied with HTTP 403. The current Devin documentation-evidence finding requiring an enforcing `tools/list` traceability contract has been implemented and its review thread resolved. No non-author counted approval exists, so these are review-tool/documentation findings, not approval or protected-main shipping evidence. +The documentation refresh PR #238 remains Ready on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`; its moving current head is intentionally authoritative in live GitHub metadata and the PR body rather than repeated in this self-referential baseline, while local full-suite evidence is green. The immediately preceding PR #238 head `d0b0d1ed92f891f14646fc673b8e1c0d912586fd` remains historical: automatic OpenCode run `33193822920` / job `98926243116` failed closed without a current-head verdict, current Strix run `33193822929` / job `98925769697` succeeded, and central dispatch run `33194506918` / job `98928580387` also failed closed at OpenCode after its validator, bootstrap, and coverage jobs succeeded. The preceding exact-head OpenCode run `33184553025` / job `98894986761` and earlier targeted run `33182749298` remain historical; targeted run `33182749298` dispatched OpenCode run `33182772296`, which failed closed as `MODEL_OUTPUT_UNAVAILABLE` with `model pool exhausted`, and optional cross-repository status publication was denied with HTTP 403. The current Devin documentation-evidence finding requiring an enforcing `tools/list` traceability contract has been implemented and its review thread resolved. No non-author counted approval exists, so these are review-tool/documentation findings, not approval or protected-main shipping evidence. The controlled Chromium prerequisite stack was also re-fetched after its exact-head repairs: #70 is Ready at `441a8ce1d09c329c5c1168f4906d9a38fd0abc01` on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`; #71 is merged into the unprotected #70 feature branch; #72 is Draft at `600d3975c02b68da1974a4c73069b966b39dce7b` on the retained #71 branch; and #73 is Draft at `ce1b138509ab4f52cb0f80290f104358473c6ed3` on #72. #70's Rust, coverage, pinned-Chrome, and ordinary security checks are successful, while exact-head OpenCode failed closed without a current verdict and exact-head Strix failed closed after three provider HTTP 500 attempts; all current Devin informational threads are resolved. #72 and #73 retain independent exact-head evidence requirements. #82 is Ready at `f5776f5f233ac0a7c05e3f4a2846436c23438043` on protected `main`; its Rust, coverage, Chrome, and ordinary security checks pass, exact-head OpenCode failed closed without a current verdict, and its current Devin informational thread is resolved. #152 is Ready at `81407a0e5189a413d1be0963fea90a0c2f254ce1` on protected `main`; its source, coverage, and security checks are successful except exact-head `opencode-review`, which failed closed without a current-head verdict. These are active-stack evidence only, not protected-main behavior or merge authorization. @@ -47,7 +47,7 @@ The following representative slices were re-fetched from GitHub for this snapsho | #46 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `373113119446d99f578febd39efc19366e7736b1` | | #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `441a8ce1d09c329c5c1168f4906d9a38fd0abc01` | | #82 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `f5776f5f233ac0a7c05e3f4a2846436c23438043` | -| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `66f360ccac5cec60c72222cc79d58e39f6f00088` | +| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `5f59947f5e4b0d3bc0aa5b2d4c6722d3b7c43047` | | #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `2459af602e72fbfe1ce816919473a1075ec0c41f` | | #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `e840ca299d29a15223c8b9bb1397002c4f41b4a3` | | #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0145ccba5901e301b41d4be674ca1ed23483ad37` | diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index e42df42e2..f75f6f096 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -57,7 +57,7 @@ def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> No "| #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `441a8ce1d09c329c5c1168f4906d9a38fd0abc01` |", "| #82 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `f5776f5f233ac0a7c05e3f4a2846436c23438043` |", "| #152 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `81407a0e5189a413d1be0963fea90a0c2f254ce1` |", - "| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `66f360ccac5cec60c72222cc79d58e39f6f00088` |", + "| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `5f59947f5e4b0d3bc0aa5b2d4c6722d3b7c43047` |", "| #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `2459af602e72fbfe1ce816919473a1075ec0c41f` |", "| #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `e840ca299d29a15223c8b9bb1397002c4f41b4a3` |", "| #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0145ccba5901e301b41d4be674ca1ed23483ad37` |", @@ -93,10 +93,10 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: def test_current_warc_provider_failures_are_bound_to_current_head(self) -> None: """WARC evidence must describe the current parent head after stack merge.""" for marker in ( - "PR #210 current exact head is `66f360ccac5cec60c72222cc79d58e39f6f00088`", - "`opencode-review` job `98931501473` is queued", - "`Production coverage` job `98931213826`, `Rust contracts` job `98931213574`, and `strix` job `98931205643` are in progress", - "Its prior exact head `bea65643109449d63d367a35b8d9bf327ee7cb2c` and its OpenCode/Strix provider failures remain historical evidence only", + "PR #210 current exact head is `5f59947f5e4b0d3bc0aa5b2d4c6722d3b7c43047`", + "`coverage-evidence` job `98935786817` is queued", + "`Production coverage` job `98935658309` and `Rust contracts` job `98935657983` are in progress", + "Its prior stack merge head `66f360ccac5cec60c72222cc79d58e39f6f00088`, earlier exact head `bea65643109449d63d367a35b8d9bf327ee7cb2c`, and their OpenCode/Strix provider failures remain historical evidence only", ): with self.subTest(marker=marker): self.assertIn(marker, self.baseline) @@ -105,9 +105,9 @@ def test_current_opencode_dispatch_failures_are_bound_to_current_heads(self) -> """OpenCode dispatch authorization failures must remain explicit blockers.""" for marker in ( "A direct central `opencode-review` dispatch run `33192478312` / job `98921183278` was rejected", - "PR #238 current exact head is `d0b0d1ed92f891f14646fc673b8e1c0d912586fd`", + "The immediately preceding PR #238 head `d0b0d1ed92f891f14646fc673b8e1c0d912586fd` remains historical", "automatic OpenCode run `33193822920` / job `98926243116` failed closed without a current-head verdict", - "Central dispatch run `33194506918` / job `98928580387` also failed closed at OpenCode", + "central dispatch run `33194506918` / job `98928580387` also failed closed at OpenCode", ): with self.subTest(marker=marker): self.assertIn(marker, self.baseline) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index fd6360573..6d24077d3 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -79,7 +79,7 @@ def test_current_snapshot_records_pr217_merge_and_pr210_revalidation(self) -> No self.assertIn("66f360ccac5cec60c72222cc79d58e39f6f00088", record) self.assertIn( "| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | " - "`66f360ccac5cec60c72222cc79d58e39f6f00088` |", + "`5f59947f5e4b0d3bc0aa5b2d4c6722d3b7c43047` |", self.baseline, ) self.assertNotIn("| #217 |", current) @@ -90,10 +90,10 @@ def test_current_documentation_head_records_security_and_review_state(self) -> N "#### 2026-08-29 maintenance-loop record", 1 )[1].split("#### Current exact-head active PR evidence", 1)[0] for marker in ( - "PR #238 current exact head is `d0b0d1ed92f891f14646fc673b8e1c0d912586fd`", + "The immediately preceding PR #238 head `d0b0d1ed92f891f14646fc673b8e1c0d912586fd` remains historical", "automatic OpenCode run `33193822920` / job `98926243116` failed closed", "current Strix run `33193822929` / job `98925769697` succeeded", - "Central dispatch run `33194506918` / job `98928580387` also failed closed at OpenCode", + "central dispatch run `33194506918` / job `98928580387` also failed closed at OpenCode", ): with self.subTest(marker=marker): self.assertIn(marker, record) From 693f91d0e546dfd48226bbb632236b902ab29ea0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 03:25:55 +0900 Subject: [PATCH 036/250] docs: refresh WARC current-head evidence --- CHANGELOG.md | 2 +- docs/product-technical-gap-baseline.md | 6 +++--- .../test_documentation_active_pr_evidence_contract.py | 10 +++++----- tests/test_gap_snapshot_inventory_consistency.py | 2 +- 4 files changed, 10 insertions(+), 10 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 31002be95..0985e4dae 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,7 +7,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Refreshed the product-gap queue to 109 open pull requests (25 ready, 84 draft) on 2026-08-29 after #53, #71, #154, #217, #233, #234, and #235 merged into unprotected feature parents; these are queue evidence, not protected-main shipment. ### Added -- Revalidated the product-gap queue at 109 open pull requests (25 ready, 84 draft) and 11 open issues on 2026-08-29; refreshed protected-main `542ca1e9`, PR #46 exact-head evidence at `373113119446d99f578febd39efc19366e7736b1`, and PR #210's current post-stack-merge head at `5f59947f5e4b0d3bc0aa5b2d4c6722d3b7c43047`. Current hosted checks and independent approval remain required; no protected-main shipment is claimed. +- Revalidated the product-gap queue at 109 open pull requests (25 ready, 84 draft) and 11 open issues on 2026-08-29; refreshed protected-main `542ca1e9`, PR #46 exact-head evidence at `373113119446d99f578febd39efc19366e7736b1`, and PR #210's current post-stack-merge head at `7946dce9a3dd074047d93fca299d48c7aef40e47`. Current hosted checks and independent approval remain required; no protected-main shipment is claimed. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. - Recorded the current-head OpenCode dispatch authorization failure for PR #46 (`33192478312` / `98921183278`) and the immediately preceding PR #238 head (`33192483900` / `98921203971`): the central validator rejected the maintainer actor because it was not the configured scheduler identity; no review verdict or approval was synthesized. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 80841cd5d..473b7cc54 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -24,13 +24,13 @@ During this recheck, #71, #154, #233, #234, and #235 were merged only into their The sensitive-data child slice #53 was subsequently squash-merged into the unprotected #46 feature branch at merge commit `93c713a107df05385f745db4dca20091f21c4a3` after exact-head Rust/coverage checks passed and current inline review threads were resolved. PR #46 remains an active main-targeting parent. Its current exact base/head pair is protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413` to `373113119446d99f578febd39efc19366e7736b1`; the head adds the ADR 0007 predicate-boundary clarification and regression contract, with local Python/Rust verification green. Current hosted evidence remains incomplete: automatic OpenCode run `33189822385` / job `98913006386` failed closed without a current-head verdict, and central Strix run `33190794267` / job `98915422837` failed closed after three provider HTTP 500 attempts without a vulnerability report. A direct central `opencode-review` dispatch run `33192478312` / job `98921183278` was rejected because repository_dispatch actor `seonghobae` did not match configured scheduler identity `github-actions[bot]`; no qualifying non-author approval is present. -The WARC/PROV child slice #217 was squash-merged into the unprotected #210 feature branch at merge commit `66f360ccac5cec60c72222cc79d58e39f6f00088` from exact PR head `6b8a3fdeae52ad94b90086bbc9b42863b90c9614`. PR #210 subsequently advanced to current exact head `5f59947f5e4b0d3bc0aa5b2d4c6722d3b7c43047` after its merged-child attribution repair; this stack remains active-PR evidence and not protected-main delivery or approval evidence. +The WARC/PROV child slice #217 was squash-merged into the unprotected #210 feature branch at merge commit `66f360ccac5cec60c72222cc79d58e39f6f00088` from exact PR head `6b8a3fdeae52ad94b90086bbc9b42863b90c9614`. PR #210 subsequently advanced to current exact head `7946dce9a3dd074047d93fca299d48c7aef40e47` after its merged-child attribution repair, recursively encoded-control repair, and exact coverage repair; this stack remains active-PR evidence and not protected-main delivery or approval evidence. The later exact-head recheck also recorded the WARC/PROV retention-lifecycle slice: #239 is Draft at `e840ca299d29a15223c8b9bb1397002c4f41b4a3` on #227 head `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0`, and #237 is Draft at `2459af602e72fbfe1ce816919473a1075ec0c41f` on protected `main`; their current exact checks and reviews remain independently actionable evidence. Neither active branch is protected-main behavior. The same exact-head recheck corrected workflow provenance: the active ruleset's seven required workflow entries (`close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, and `noema-review`) point to the central `.github` repository, repository ID `1274066402`, where all seven files exist on `main`; their absence from the OriginWeave tree did not prove missing workflow identities. On PR #210 head `0341079331f9cea669eb9a5cc21842fd6027431e`, run `33177641855` failed closed because no OpenCode current-head verdict existed, while run `33177641888` failed closed after three bounded attempts because the Strix provider/backend returned an internal server error and produced no vulnerability report. A `gh run view` workflow-endpoint 404 for the external workflow IDs is a lookup mismatch, not passing evidence or proof that the identities are absent. A bounded central scheduler dispatch was accepted as run `33178984025` with auto-merge and branch updates disabled; no result is transferred until the exact head is revalidated. These failures block affected PRs until current-head review and security evidence complete. This does not authorize bypass, self-approval, stale checks, or weaker gates. -The WARC resource-record slice #210 is now Ready; PR #210 current exact head is `5f59947f5e4b0d3bc0aa5b2d4c6722d3b7c43047` based directly on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`, after incorporating #217 and correcting the merged-child attribution. Its prior stack merge head `66f360ccac5cec60c72222cc79d58e39f6f00088`, earlier exact head `bea65643109449d63d367a35b8d9bf327ee7cb2c`, and their OpenCode/Strix provider failures remain historical evidence only. At the current head, `coverage-evidence` job `98935786817` is queued, `Production coverage` job `98935658309` and `Rust contracts` job `98935657983` are in progress, and completed ordinary checks include `Semgrep OSS` job `98935840392` and `Trivy` job `98935809116`; no current-head review verdict or counted approval exists. Central repair PR #1391 was opened at historical head `e4ba6b599cd1e50d0139762885682607b731655d` and is now open at exact head `36ac3aa71b2580685f84d416a81e42c39dee927c` on current central `main` `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Its branch-update merge and follow-up prompt hardening are not approval or coverage evidence. +The WARC resource-record slice #210 is now Ready; PR #210 current exact head is `7946dce9a3dd074047d93fca299d48c7aef40e47` based directly on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`, after incorporating #217, correcting the merged-child attribution, and closing the recursively encoded-query-control coverage gap. Its predecessor head `5f59947f5e4b0d3bc0aa5b2d4c6722d3b7c43047`, prior stack merge head `66f360ccac5cec60c72222cc79d58e39f6f00088`, earlier exact head `bea65643109449d63d367a35b8d9bf327ee7cb2c`, and their OpenCode/Strix provider failures remain historical evidence only. At the current head, `Rust contracts` job `98942518975` and `Production coverage` job `98942518680` succeeded, while `noema-review` job `98942513421` and `strix` job `98942803402` remain in progress; the current-head OpenCode verdict is still absent and no counted approval exists. Central repair PR #1391 was opened at historical head `e4ba6b599cd1e50d0139762885682607b731655d` and is now open at exact head `36ac3aa71b2580685f84d416a81e42c39dee927c` on current central `main` `e1b03eebc6dc5c85aed393e5928927c96376cf46`. Its branch-update merge and follow-up prompt hardening are not approval or coverage evidence. The documentation refresh PR #238 remains Ready on protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413`; its moving current head is intentionally authoritative in live GitHub metadata and the PR body rather than repeated in this self-referential baseline, while local full-suite evidence is green. The immediately preceding PR #238 head `d0b0d1ed92f891f14646fc673b8e1c0d912586fd` remains historical: automatic OpenCode run `33193822920` / job `98926243116` failed closed without a current-head verdict, current Strix run `33193822929` / job `98925769697` succeeded, and central dispatch run `33194506918` / job `98928580387` also failed closed at OpenCode after its validator, bootstrap, and coverage jobs succeeded. The preceding exact-head OpenCode run `33184553025` / job `98894986761` and earlier targeted run `33182749298` remain historical; targeted run `33182749298` dispatched OpenCode run `33182772296`, which failed closed as `MODEL_OUTPUT_UNAVAILABLE` with `model pool exhausted`, and optional cross-repository status publication was denied with HTTP 403. The current Devin documentation-evidence finding requiring an enforcing `tools/list` traceability contract has been implemented and its review thread resolved. No non-author counted approval exists, so these are review-tool/documentation findings, not approval or protected-main shipping evidence. @@ -47,7 +47,7 @@ The following representative slices were re-fetched from GitHub for this snapsho | #46 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `373113119446d99f578febd39efc19366e7736b1` | | #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `441a8ce1d09c329c5c1168f4906d9a38fd0abc01` | | #82 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `f5776f5f233ac0a7c05e3f4a2846436c23438043` | -| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `5f59947f5e4b0d3bc0aa5b2d4c6722d3b7c43047` | +| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `7946dce9a3dd074047d93fca299d48c7aef40e47` | | #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `2459af602e72fbfe1ce816919473a1075ec0c41f` | | #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `e840ca299d29a15223c8b9bb1397002c4f41b4a3` | | #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0145ccba5901e301b41d4be674ca1ed23483ad37` | diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index f75f6f096..9ab926183 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -57,7 +57,7 @@ def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> No "| #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `441a8ce1d09c329c5c1168f4906d9a38fd0abc01` |", "| #82 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `f5776f5f233ac0a7c05e3f4a2846436c23438043` |", "| #152 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `81407a0e5189a413d1be0963fea90a0c2f254ce1` |", - "| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `5f59947f5e4b0d3bc0aa5b2d4c6722d3b7c43047` |", + "| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `7946dce9a3dd074047d93fca299d48c7aef40e47` |", "| #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `2459af602e72fbfe1ce816919473a1075ec0c41f` |", "| #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `e840ca299d29a15223c8b9bb1397002c4f41b4a3` |", "| #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0145ccba5901e301b41d4be674ca1ed23483ad37` |", @@ -93,10 +93,10 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: def test_current_warc_provider_failures_are_bound_to_current_head(self) -> None: """WARC evidence must describe the current parent head after stack merge.""" for marker in ( - "PR #210 current exact head is `5f59947f5e4b0d3bc0aa5b2d4c6722d3b7c43047`", - "`coverage-evidence` job `98935786817` is queued", - "`Production coverage` job `98935658309` and `Rust contracts` job `98935657983` are in progress", - "Its prior stack merge head `66f360ccac5cec60c72222cc79d58e39f6f00088`, earlier exact head `bea65643109449d63d367a35b8d9bf327ee7cb2c`, and their OpenCode/Strix provider failures remain historical evidence only", + "PR #210 current exact head is `7946dce9a3dd074047d93fca299d48c7aef40e47`", + "`Rust contracts` job `98942518975` and `Production coverage` job `98942518680` succeeded", + "`noema-review` job `98942513421` and `strix` job `98942803402` remain in progress", + "Its predecessor head `5f59947f5e4b0d3bc0aa5b2d4c6722d3b7c43047`, prior stack merge head `66f360ccac5cec60c72222cc79d58e39f6f00088`, earlier exact head `bea65643109449d63d367a35b8d9bf327ee7cb2c`, and their OpenCode/Strix provider failures remain historical evidence only", ): with self.subTest(marker=marker): self.assertIn(marker, self.baseline) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 6d24077d3..52a8ab3a9 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -79,7 +79,7 @@ def test_current_snapshot_records_pr217_merge_and_pr210_revalidation(self) -> No self.assertIn("66f360ccac5cec60c72222cc79d58e39f6f00088", record) self.assertIn( "| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | " - "`5f59947f5e4b0d3bc0aa5b2d4c6722d3b7c43047` |", + "`7946dce9a3dd074047d93fca299d48c7aef40e47` |", self.baseline, ) self.assertNotIn("| #217 |", current) From 1e0e49d24e4b63e9509aa105cd8fb50e133e178c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 29 Aug 2026 03:48:30 +0900 Subject: [PATCH 037/250] docs: record browser interruption stack merge --- CHANGELOG.md | 5 +++-- docs/product-technical-gap-baseline.md | 7 +++++-- ...documentation_active_pr_evidence_contract.py | 2 +- .../test_gap_snapshot_inventory_consistency.py | 17 ++++++++++------- tests/test_product_completion_gap_contract.py | 4 ++-- 5 files changed, 21 insertions(+), 14 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 0985e4dae..cc5d6c747 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,10 +4,11 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] -- Refreshed the product-gap queue to 109 open pull requests (25 ready, 84 draft) on 2026-08-29 after #53, #71, #154, #217, #233, #234, and #235 merged into unprotected feature parents; these are queue evidence, not protected-main shipment. +- Refreshed the product-gap queue to 108 open pull requests (24 ready, 84 draft) on 2026-08-29 after #53, #67, #71, #154, #217, #233, #234, and #235 merged into unprotected feature parents; these are queue evidence, not protected-main shipment. ### Added -- Revalidated the product-gap queue at 109 open pull requests (25 ready, 84 draft) and 11 open issues on 2026-08-29; refreshed protected-main `542ca1e9`, PR #46 exact-head evidence at `373113119446d99f578febd39efc19366e7736b1`, and PR #210's current post-stack-merge head at `7946dce9a3dd074047d93fca299d48c7aef40e47`. Current hosted checks and independent approval remain required; no protected-main shipment is claimed. +- Revalidated the product-gap queue at 108 open pull requests (24 ready, 84 draft) and 11 open issues on 2026-08-29; refreshed protected-main `542ca1e9`, PR #46 exact-head evidence at `373113119446d99f578febd39efc19366e7736b1`, PR #64's post-stack-merge head at `5021d142583cb5a8e393248048bb824762a98056`, and PR #210's current post-stack-merge head at `7946dce9a3dd074047d93fca299d48c7aef40e47`. Current hosted checks and independent approval remain required; no protected-main shipment is claimed. +- Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. - Recorded the current-head OpenCode dispatch authorization failure for PR #46 (`33192478312` / `98921183278`) and the immediately preceding PR #238 head (`33192483900` / `98921203971`): the central validator rejected the maintainer actor because it was not the configured scheduler identity; no review verdict or approval was synthesized. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 473b7cc54..46d4acc36 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -14,11 +14,11 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a ### Open pull requests -The live repository contained **109 open pull requests: 25 non-draft and 84 draft** when this snapshot re-paginated the complete open inventory. Compared with the prior **2026-08-28 111-PR snapshot**, stacked evidence PR #53 was merged into its unprotected feature parent; the preceding **2026-08-28 116-PR snapshot** had already recorded #71, #154, #233, #234, and #235 merging into their unprotected feature parents. PR #217 has since been squash-merged into the unprotected #210 feature parent; the current queue therefore contains no protected-main shipment. These counts are queue evidence, not protected-main delivery; protected `main` remains `542ca1e9c0a863595b8b6697790005d2471f5413`, with 11 open issues and no releases or tags. The volume and stack depth remain themselves a product-delivery risk: review, exact-head checks, dependency order, and integration truth can drift faster than a buyer-visible vertical slice reaches protected `main`. +The live repository contained **108 open pull requests: 24 non-draft and 84 draft** when this snapshot re-paginated the complete open inventory. Compared with the prior **2026-08-28 111-PR snapshot**, stacked evidence PR #53 was merged into its unprotected feature parent; the preceding **2026-08-28 116-PR snapshot** had already recorded #71, #154, #233, #234, and #235 merging into their unprotected feature parents. PR #217 was squash-merged into the unprotected #210 feature parent, followed by PR #67 into the unprotected #64 feature parent; the current queue therefore contains no protected-main shipment. These counts are queue evidence, not protected-main delivery; protected `main` remains `542ca1e9c0a863595b8b6697790005d2471f5413`, with 11 open issues and no releases or tags. The volume and stack depth remain themselves a product-delivery risk: review, exact-head checks, dependency order, and integration truth can drift faster than a buyer-visible vertical slice reaches protected `main`. #### 2026-08-29 maintenance-loop record -This snapshot re-fetched the complete open-PR inventory, the protected `main` commit, the active required-workflow ruleset, collaborator permissions, and the exact base/head pair for each representative PR. Before PR #238 was published, the same maintenance loop observed 115 open pull requests (31 ready, 84 draft); a later 116-PR recheck preceded five stack merges, leaving 111 open pull requests (27 ready, 84 draft), and subsequent child-stack merges left 109 open pull requests (25 ready, 84 draft). The active ruleset still requires one counted approving review and resolved threads; the only repository collaborator is `seonghobae`, so review provisioning remains the merge blocker for main-targeting PRs. PR #170 is merged and is not active-PR evidence. +This snapshot re-fetched the complete open-PR inventory, the protected `main` commit, the active required-workflow ruleset, collaborator permissions, and the exact base/head pair for each representative PR. Before PR #238 was published, the same maintenance loop observed 115 open pull requests (31 ready, 84 draft); a later 116-PR recheck preceded five stack merges, leaving 111 open pull requests (27 ready, 84 draft), and subsequent child-stack merges left 108 open pull requests (24 ready, 84 draft). The active ruleset still requires one counted approving review and resolved threads; the only repository collaborator is `seonghobae`, so review provisioning remains the merge blocker for main-targeting PRs. PR #170 is merged and is not active-PR evidence. During this recheck, #71, #154, #233, #234, and #235 were merged only into their unprotected feature-parent branches after exact current-head checks and review-thread resolution. Their successful stack checks are not protected-main delivery, and their child branches retain independent evidence requirements. @@ -26,6 +26,8 @@ The sensitive-data child slice #53 was subsequently squash-merged into the unpro The WARC/PROV child slice #217 was squash-merged into the unprotected #210 feature branch at merge commit `66f360ccac5cec60c72222cc79d58e39f6f00088` from exact PR head `6b8a3fdeae52ad94b90086bbc9b42863b90c9614`. PR #210 subsequently advanced to current exact head `7946dce9a3dd074047d93fca299d48c7aef40e47` after its merged-child attribution repair, recursively encoded-control repair, and exact coverage repair; this stack remains active-PR evidence and not protected-main delivery or approval evidence. +The browser-task interruption child slice #67 was squash-merged into the unprotected #64 feature branch at merge commit `5021d142583cb5a8e393248048bb824762a98056` from exact PR head `25ab76e8279d4a904d04afeb264bac3e89f46b45`. PR #64 consequently advanced from `debc761aa59aee1509b7a260474fa33216453511` to current exact head `5021d142583cb5a8e393248048bb824762a98056`; its exact-head hosted checks were regenerating at this snapshot, with no unresolved inline review threads. This stack remains active-PR evidence and not protected-main delivery or approval evidence. + The later exact-head recheck also recorded the WARC/PROV retention-lifecycle slice: #239 is Draft at `e840ca299d29a15223c8b9bb1397002c4f41b4a3` on #227 head `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0`, and #237 is Draft at `2459af602e72fbfe1ce816919473a1075ec0c41f` on protected `main`; their current exact checks and reviews remain independently actionable evidence. Neither active branch is protected-main behavior. The same exact-head recheck corrected workflow provenance: the active ruleset's seven required workflow entries (`close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, and `noema-review`) point to the central `.github` repository, repository ID `1274066402`, where all seven files exist on `main`; their absence from the OriginWeave tree did not prove missing workflow identities. On PR #210 head `0341079331f9cea669eb9a5cc21842fd6027431e`, run `33177641855` failed closed because no OpenCode current-head verdict existed, while run `33177641888` failed closed after three bounded attempts because the Strix provider/backend returned an internal server error and produced no vulnerability report. A `gh run view` workflow-endpoint 404 for the external workflow IDs is a lookup mismatch, not passing evidence or proof that the identities are absent. A bounded central scheduler dispatch was accepted as run `33178984025` with auto-merge and branch updates disabled; no result is transferred until the exact head is revalidated. These failures block affected PRs until current-head review and security evidence complete. This does not authorize bypass, self-approval, stale checks, or weaker gates. @@ -48,6 +50,7 @@ The following representative slices were re-fetched from GitHub for this snapsho | #70 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `441a8ce1d09c329c5c1168f4906d9a38fd0abc01` | | #82 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `f5776f5f233ac0a7c05e3f4a2846436c23438043` | | #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `7946dce9a3dd074047d93fca299d48c7aef40e47` | +| #64 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `5021d142583cb5a8e393248048bb824762a98056` | | #237 | Draft | `542ca1e9c0a863595b8b6697790005d2471f5413` | `2459af602e72fbfe1ce816919473a1075ec0c41f` | | #239 | Draft | `e45cd6cdcdee73b5c16dc942e6c98cb7e745fae0` | `e840ca299d29a15223c8b9bb1397002c4f41b4a3` | | #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0145ccba5901e301b41d4be674ca1ed23483ad37` | diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 9ab926183..45a98da72 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -81,7 +81,7 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] self.assertIn("on 2026-08-29", refresh_line) - self.assertIn("109 open pull requests (25 ready, 84 draft)", refresh_line) + self.assertIn("108 open pull requests (24 ready, 84 draft)", refresh_line) self.assertIn("11 open issues", refresh_line) self.assertNotIn("- Corrected the 2026-08-28 product-gap snapshot", added) self.assertNotIn("- Revalidated the product-gap queue at", changed) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 52a8ab3a9..f797fff84 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -20,13 +20,13 @@ def setUpClass(cls) -> None: cls.changelog = CHANGELOG.read_text(encoding="utf-8") def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: - """The current snapshot must use the exact 109/25/84 inventory observation.""" + """The current snapshot must use the exact 108/24/84 inventory observation.""" current = self.baseline.split("### Open pull requests", 1)[1].split( "#### 2026-08-29 maintenance-loop record", 1 )[0] for marker in ( - "109 open pull requests", - "25 non-draft", + "108 open pull requests", + "24 non-draft", "84 draft", ): with self.subTest(marker=marker): @@ -55,7 +55,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "109 open pull requests (25 ready, 84 draft)" + expected = "108 open pull requests (24 ready, 84 draft)" self.assertIn(expected, preamble) self.assertIn("on 2026-08-29", preamble) self.assertNotIn("on 2026-08-28", preamble) @@ -65,7 +65,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: self.assertNotIn("126 open pull requests (54 ready, 72 draft)", added) self.assertNotIn("110 open pull requests (26 ready, 84 draft)", preamble) - def test_current_snapshot_records_pr217_merge_and_pr210_revalidation(self) -> None: + def test_current_snapshot_records_recent_stack_merges_and_revalidation(self) -> None: """A stacked merge must update the live queue and parent exact-head evidence.""" current = self.baseline.split("### Open pull requests", 1)[1].split( "#### 2026-08-29 maintenance-loop record", 1 @@ -73,10 +73,13 @@ def test_current_snapshot_records_pr217_merge_and_pr210_revalidation(self) -> No record = self.baseline.split( "#### 2026-08-29 maintenance-loop record", 1 )[1].split("#### Current exact-head active PR evidence", 1)[0] - self.assertIn("109 open pull requests", current) - self.assertIn("25 non-draft", current) + self.assertIn("108 open pull requests", current) + self.assertIn("24 non-draft", current) self.assertIn("#217 was squash-merged", record) self.assertIn("66f360ccac5cec60c72222cc79d58e39f6f00088", record) + self.assertIn("#67 was squash-merged", record) + self.assertIn("5021d142583cb5a8e393248048bb824762a98056", record) + self.assertIn("PR #64 consequently advanced", record) self.assertIn( "| #210 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | " "`7946dce9a3dd074047d93fca299d48c7aef40e47` |", diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index f570c6a33..03ed97127 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -26,8 +26,8 @@ def test_baseline_records_current_inventory_and_completion_issues(self) -> None: current = text.split("## Observed snapshot: ", 1)[1].split(end_marker, 1)[0] for phrase in ( - "109 open pull requests", - "25 non-draft", + "108 open pull requests", + "24 non-draft", "84 draft", "2026-08-28 116-PR snapshot", ): From 6c092ce47489818250e91474a40bb849b86583f2 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 01:40:04 +0900 Subject: [PATCH 038/250] test(docs): require distinct live delivery baseline --- ...test_gap_snapshot_inventory_consistency.py | 29 ++++++++++++++++--- 1 file changed, 25 insertions(+), 4 deletions(-) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index f797fff84..9283cab4d 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -19,8 +19,29 @@ def setUpClass(cls) -> None: cls.baseline = BASELINE.read_text(encoding="utf-8") cls.changelog = CHANGELOG.read_text(encoding="utf-8") + def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: + """A volatile live section must not rely on the historical dated inventory.""" + current = self.baseline.split("## Current live delivery state", 1)[1].split( + "## Observed snapshot: 2026-08-29", 1 + )[0] + for marker in ( + "141 open pull requests", + "26 Ready/non-draft", + "115 Draft", + "11 open non-PR issues", + "542ca1e9c0a863595b8b6697790005d2471f5413", + "18156473", + "1bdd8aec51b43cf9f87086411e693c812b5d3597", + "b3595ef5656ebdb5aa301d4d2f3e487f6a1f21c8", + ): + with self.subTest(marker=marker): + self.assertIn(marker, current) + self.assertIn("Strix run `33473689091` is cancelled before job creation", current) + self.assertIn("OpenCode run `33473689030` remains queued", current) + self.assertIn("active-PR evidence only", current) + def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: - """The current snapshot must use the exact 108/24/84 inventory observation.""" + """The dated 2026-08-29 snapshot must keep its exact historical inventory.""" current = self.baseline.split("### Open pull requests", 1)[1].split( "#### 2026-08-29 maintenance-loop record", 1 )[0] @@ -50,7 +71,7 @@ def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: self.assertNotIn(stale, current) def test_unreleased_changelog_uses_one_current_inventory(self) -> None: - """The Unreleased current snapshot must agree before and inside Added.""" + """The historical Unreleased entry remains internally self-consistent.""" unreleased = self.changelog.split("## [Unreleased]", 1)[1] preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] @@ -66,7 +87,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: self.assertNotIn("110 open pull requests (26 ready, 84 draft)", preamble) def test_current_snapshot_records_recent_stack_merges_and_revalidation(self) -> None: - """A stacked merge must update the live queue and parent exact-head evidence.""" + """A stacked merge must update the dated queue and parent exact-head evidence.""" current = self.baseline.split("### Open pull requests", 1)[1].split( "#### 2026-08-29 maintenance-loop record", 1 )[0] @@ -88,7 +109,7 @@ def test_current_snapshot_records_recent_stack_merges_and_revalidation(self) -> self.assertNotIn("| #217 |", current) def test_current_documentation_head_records_security_and_review_state(self) -> None: - """The self-referential documentation PR must preserve current-head gate truth.""" + """The dated self-referential record must preserve its historical gate truth.""" record = self.baseline.split( "#### 2026-08-29 maintenance-loop record", 1 )[1].split("#### Current exact-head active PR evidence", 1)[0] From 8b24f6396d3d31646837878b0c34f83042d89aa6 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 01:43:40 +0900 Subject: [PATCH 039/250] docs(gap): add current live delivery state --- docs/product-technical-gap-baseline.md | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 46d4acc36..bafed1312 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,6 +2,18 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, architecture decisions, or live GitHub state. It keeps buyer-visible gaps, current issues, active pull-request evidence, and commercial completion tracks in one discoverable place. Protected `main` is the implementation boundary: code in an open pull request is not shipped behavior. +## Current live delivery state + +This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. + +- Protected `main` remains `542ca1e9c0a863595b8b6697790005d2471f5413`. +- The complete open inventory is **141 open pull requests: 26 Ready/non-draft and 115 Draft; 11 open non-PR issues**. The increase from the prior 140-PR observation is real queue movement, not protected-main delivery; PR #274 is a new Ready documentation-only lane. +- Active organization ruleset `18156473` (`CWL Central required workflows`) remains the effective default-branch authority. It requires one approving review, resolved review threads, and the configured central required workflows. Auto-merge remains disabled, and protected-main `AGENTS.md` still forbids this scheduled writer from merging, tagging/publishing, mutating workflows/rulesets/secrets, weakening gates, or manufacturing approval. +- Issue #28 remains the P0 buyer-visible integration target. PR #271 is Draft at exact head `1bdd8aec51b43cf9f87086411e693c812b5d3597` on #270 head `480d411011120b40d88beec3942aee049541b71d`; native CI run `33518406193`, Rust contracts job `99891170594`, and production coverage job `99891170556` succeeded. This is active-PR evidence only: the pinned Chromium isolated profile → BiDi session/subscription → navigation/document epoch → semantic observation → admitted node → typed click/type → correlated result plus real post-condition → credential-safe provenance → teardown/crash-cleanup path is not yet protected-main truth. +- DDD ownership correction #272 is Draft at exact head `b3595ef5656ebdb5aa301d4d2f3e487f6a1f21c8` on protected `main`; its patch keeps MCP as an external adapter depending inward on stable core contracts and policy, and removes MCP protocol types from core/policy authority. Native CI, MV3, Security Scan, SAST Semgrep, Noema, scheduler, and close-empty evidence succeeded on this exact head. Required Strix run `33473689091` is cancelled before job creation, and a bounded leaf rerun attempt returned HTTP 403 (`This workflow run cannot be retried`); OpenCode run `33473689030` remains queued. Neither condition is converted to success. PR #273 remains the Draft Context Map/Ubiquitous Language child at `d75462b91fb3b3d2dbbaf01a153e3e0ca6b7a539` and cannot inherit parent evidence. +- The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #199 durable WARC/PROV plus tenant persistence/KMS/retention/replay, #200 stable BAP/MCP task lifecycle and contextual-orchestrator integration, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 durable enterprise identity/tenant/policy/approval/audit/SLO operations, and #203 exact-artifact commercial benchmark/recovery acceptance. Partial PRs remain partial evidence and are not described as shipped completion. +- Current evidence procedure remains fail-closed: paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. + ## Observed snapshot: 2026-08-29 ### Protected-main truth From 027abf5947139e33640b222c1184309d03676df0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 03:41:50 +0900 Subject: [PATCH 040/250] test(docs): require current Chromium stack evidence --- tests/test_gap_snapshot_inventory_consistency.py | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 9283cab4d..d32ea3cca 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -31,11 +31,12 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "11 open non-PR issues", "542ca1e9c0a863595b8b6697790005d2471f5413", "18156473", - "1bdd8aec51b43cf9f87086411e693c812b5d3597", + "48aeba93e659999c51e76c69e58ff0bdeb1af863", "b3595ef5656ebdb5aa301d4d2f3e487f6a1f21c8", ): with self.subTest(marker=marker): self.assertIn(marker, current) + self.assertIn("CI run `33544819779` is queued", current) self.assertIn("Strix run `33473689091` is cancelled before job creation", current) self.assertIn("OpenCode run `33473689030` remains queued", current) self.assertIn("active-PR evidence only", current) From 421e58b3b4631a18a4ac4978ef178cb075a3812d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 03:45:37 +0900 Subject: [PATCH 041/250] docs(gap): refresh current Chromium stack evidence --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index bafed1312..dac70f196 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -9,7 +9,7 @@ This volatile section is refreshed from live GitHub state and is authoritative o - Protected `main` remains `542ca1e9c0a863595b8b6697790005d2471f5413`. - The complete open inventory is **141 open pull requests: 26 Ready/non-draft and 115 Draft; 11 open non-PR issues**. The increase from the prior 140-PR observation is real queue movement, not protected-main delivery; PR #274 is a new Ready documentation-only lane. - Active organization ruleset `18156473` (`CWL Central required workflows`) remains the effective default-branch authority. It requires one approving review, resolved review threads, and the configured central required workflows. Auto-merge remains disabled, and protected-main `AGENTS.md` still forbids this scheduled writer from merging, tagging/publishing, mutating workflows/rulesets/secrets, weakening gates, or manufacturing approval. -- Issue #28 remains the P0 buyer-visible integration target. PR #271 is Draft at exact head `1bdd8aec51b43cf9f87086411e693c812b5d3597` on #270 head `480d411011120b40d88beec3942aee049541b71d`; native CI run `33518406193`, Rust contracts job `99891170594`, and production coverage job `99891170556` succeeded. This is active-PR evidence only: the pinned Chromium isolated profile → BiDi session/subscription → navigation/document epoch → semantic observation → admitted node → typed click/type → correlated result plus real post-condition → credential-safe provenance → teardown/crash-cleanup path is not yet protected-main truth. +- Issue #28 remains the P0 buyer-visible integration target. PR #271 is Draft at exact head `48aeba93e659999c51e76c69e58ff0bdeb1af863` on #270 head `480d411011120b40d88beec3942aee049541b71d`. Its predecessor exact head `58af9ed492ef4c4985be8b069006468b2c298c39` failed Rust contracts at canonical formatting; the same canonical branch was repaired from the exact rustfmt artifact without changing production semantics. Current CI run `33544819779` is queued, so Rust contracts and production coverage for `48aeba93e659999c51e76c69e58ff0bdeb1af863` are not yet passing evidence. This remains active-PR evidence only: the pinned Chromium isolated profile → BiDi session/subscription → navigation/document epoch → semantic observation → admitted node → typed click/type → correlated result plus real post-condition → credential-safe provenance → teardown/crash-cleanup path is not yet protected-main truth. - DDD ownership correction #272 is Draft at exact head `b3595ef5656ebdb5aa301d4d2f3e487f6a1f21c8` on protected `main`; its patch keeps MCP as an external adapter depending inward on stable core contracts and policy, and removes MCP protocol types from core/policy authority. Native CI, MV3, Security Scan, SAST Semgrep, Noema, scheduler, and close-empty evidence succeeded on this exact head. Required Strix run `33473689091` is cancelled before job creation, and a bounded leaf rerun attempt returned HTTP 403 (`This workflow run cannot be retried`); OpenCode run `33473689030` remains queued. Neither condition is converted to success. PR #273 remains the Draft Context Map/Ubiquitous Language child at `d75462b91fb3b3d2dbbaf01a153e3e0ca6b7a539` and cannot inherit parent evidence. - The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #199 durable WARC/PROV plus tenant persistence/KMS/retention/replay, #200 stable BAP/MCP task lifecycle and contextual-orchestrator integration, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 durable enterprise identity/tenant/policy/approval/audit/SLO operations, and #203 exact-artifact commercial benchmark/recovery acceptance. Partial PRs remain partial evidence and are not described as shipped completion. - Current evidence procedure remains fail-closed: paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. From 1103103dddf83dc0f3e81dfae56dcac2cd3b0f55 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 05:20:24 +0900 Subject: [PATCH 042/250] test(docs): require current OriginWeave delivery evidence --- tests/test_gap_snapshot_inventory_consistency.py | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index d32ea3cca..33e33bd4c 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -31,12 +31,18 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "11 open non-PR issues", "542ca1e9c0a863595b8b6697790005d2471f5413", "18156473", - "48aeba93e659999c51e76c69e58ff0bdeb1af863", + "61bd2e00d2c60f9d846d5a5d59c7329695d5a3ed", + "9ba972838e44c15a0a88148533bec787ffd87a47", + "f0dcf215f3f2477a18798ef302560fc43c74fac3", + "cf5fd422a329acbfa04ac0685d32a405942a7146", "b3595ef5656ebdb5aa301d4d2f3e487f6a1f21c8", ): with self.subTest(marker=marker): self.assertIn(marker, current) - self.assertIn("CI run `33544819779` is queued", current) + self.assertIn("CI run `33548339062` is **success**", current) + self.assertIn("CI run `33553936912` is queued", current) + self.assertIn("CI run `33554087393` is queued", current) + self.assertIn("CI run `33554207683` is queued", current) self.assertIn("Strix run `33473689091` is cancelled before job creation", current) self.assertIn("OpenCode run `33473689030` remains queued", current) self.assertIn("active-PR evidence only", current) From c077307f16275873856baa9109a69cb1308cc3cf Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 05:24:04 +0900 Subject: [PATCH 043/250] docs(gap): refresh live Chromium stack evidence --- docs/product-technical-gap-baseline.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index dac70f196..0301a5339 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -9,7 +9,8 @@ This volatile section is refreshed from live GitHub state and is authoritative o - Protected `main` remains `542ca1e9c0a863595b8b6697790005d2471f5413`. - The complete open inventory is **141 open pull requests: 26 Ready/non-draft and 115 Draft; 11 open non-PR issues**. The increase from the prior 140-PR observation is real queue movement, not protected-main delivery; PR #274 is a new Ready documentation-only lane. - Active organization ruleset `18156473` (`CWL Central required workflows`) remains the effective default-branch authority. It requires one approving review, resolved review threads, and the configured central required workflows. Auto-merge remains disabled, and protected-main `AGENTS.md` still forbids this scheduled writer from merging, tagging/publishing, mutating workflows/rulesets/secrets, weakening gates, or manufacturing approval. -- Issue #28 remains the P0 buyer-visible integration target. PR #271 is Draft at exact head `48aeba93e659999c51e76c69e58ff0bdeb1af863` on #270 head `480d411011120b40d88beec3942aee049541b71d`. Its predecessor exact head `58af9ed492ef4c4985be8b069006468b2c298c39` failed Rust contracts at canonical formatting; the same canonical branch was repaired from the exact rustfmt artifact without changing production semantics. Current CI run `33544819779` is queued, so Rust contracts and production coverage for `48aeba93e659999c51e76c69e58ff0bdeb1af863` are not yet passing evidence. This remains active-PR evidence only: the pinned Chromium isolated profile → BiDi session/subscription → navigation/document epoch → semantic observation → admitted node → typed click/type → correlated result plus real post-condition → credential-safe provenance → teardown/crash-cleanup path is not yet protected-main truth. +- Issue #28 remains the P0 buyer-visible integration target. PR #271 is Draft at exact head `61bd2e00d2c60f9d846d5a5d59c7329695d5a3ed` on exact #270 head `480d411011120b40d88beec3942aee049541b71d`. Exact CI run `33548339062` is **success**: Rust contracts job `99991309941` and Production coverage job `99991309610` both completed successfully on that unchanged head. This proves only that the current #271 slice satisfies its repository-native Rust/coverage contract; it does not transfer predecessor evidence or make the stacked Chromium Agent Task protected-main behavior. +- The active WebDriver BiDi dependency chain was repaired non-destructively after prerequisite heads moved. PR #251 now sits on current #250 at exact head `9ba972838e44c15a0a88148533bec787ffd87a47` and uses command-kind-bound `SessionEnd` correlation; its exact CI run `33553936912` is queued. PR #252 is restacked on that current #251 at `f0dcf215f3f2477a18798ef302560fc43c74fac3`, uses typed `SessionEnd` response correlation, and CI run `33554087393` is queued. PR #253 is restacked on current #252 at `cf5fd422a329acbfa04ac0685d32a405942a7146`; CI run `33554207683` is queued. Queued runs remain non-passing. PR #254 still carries its unique transport-closure delta on an older #253 snapshot and therefore remains a dependency-restack obligation before descendants can inherit a coherent ancestry. The complete pinned Chromium isolated profile → BiDi session/subscription → navigation/document epoch → semantic observation → admitted node → typed click/type → correlated result plus real post-condition → credential-safe provenance → teardown/crash-cleanup path is still active-PR evidence only, not protected-main truth. - DDD ownership correction #272 is Draft at exact head `b3595ef5656ebdb5aa301d4d2f3e487f6a1f21c8` on protected `main`; its patch keeps MCP as an external adapter depending inward on stable core contracts and policy, and removes MCP protocol types from core/policy authority. Native CI, MV3, Security Scan, SAST Semgrep, Noema, scheduler, and close-empty evidence succeeded on this exact head. Required Strix run `33473689091` is cancelled before job creation, and a bounded leaf rerun attempt returned HTTP 403 (`This workflow run cannot be retried`); OpenCode run `33473689030` remains queued. Neither condition is converted to success. PR #273 remains the Draft Context Map/Ubiquitous Language child at `d75462b91fb3b3d2dbbaf01a153e3e0ca6b7a539` and cannot inherit parent evidence. - The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #199 durable WARC/PROV plus tenant persistence/KMS/retention/replay, #200 stable BAP/MCP task lifecycle and contextual-orchestrator integration, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 durable enterprise identity/tenant/policy/approval/audit/SLO operations, and #203 exact-artifact commercial benchmark/recovery acceptance. Partial PRs remain partial evidence and are not described as shipped completion. - Current evidence procedure remains fail-closed: paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. From f9846f923403cb56201370b8a61bf80051187383 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 14:15:48 +0900 Subject: [PATCH 044/250] docs: sync live delivery baseline --- docs/product-technical-gap-baseline.md | 15 ++++++++------- 1 file changed, 8 insertions(+), 7 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 0301a5339..bcfdc51ac 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -4,15 +4,16 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a ## Current live delivery state -This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. +This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. - Protected `main` remains `542ca1e9c0a863595b8b6697790005d2471f5413`. -- The complete open inventory is **141 open pull requests: 26 Ready/non-draft and 115 Draft; 11 open non-PR issues**. The increase from the prior 140-PR observation is real queue movement, not protected-main delivery; PR #274 is a new Ready documentation-only lane. -- Active organization ruleset `18156473` (`CWL Central required workflows`) remains the effective default-branch authority. It requires one approving review, resolved review threads, and the configured central required workflows. Auto-merge remains disabled, and protected-main `AGENTS.md` still forbids this scheduled writer from merging, tagging/publishing, mutating workflows/rulesets/secrets, weakening gates, or manufacturing approval. -- Issue #28 remains the P0 buyer-visible integration target. PR #271 is Draft at exact head `61bd2e00d2c60f9d846d5a5d59c7329695d5a3ed` on exact #270 head `480d411011120b40d88beec3942aee049541b71d`. Exact CI run `33548339062` is **success**: Rust contracts job `99991309941` and Production coverage job `99991309610` both completed successfully on that unchanged head. This proves only that the current #271 slice satisfies its repository-native Rust/coverage contract; it does not transfer predecessor evidence or make the stacked Chromium Agent Task protected-main behavior. -- The active WebDriver BiDi dependency chain was repaired non-destructively after prerequisite heads moved. PR #251 now sits on current #250 at exact head `9ba972838e44c15a0a88148533bec787ffd87a47` and uses command-kind-bound `SessionEnd` correlation; its exact CI run `33553936912` is queued. PR #252 is restacked on that current #251 at `f0dcf215f3f2477a18798ef302560fc43c74fac3`, uses typed `SessionEnd` response correlation, and CI run `33554087393` is queued. PR #253 is restacked on current #252 at `cf5fd422a329acbfa04ac0685d32a405942a7146`; CI run `33554207683` is queued. Queued runs remain non-passing. PR #254 still carries its unique transport-closure delta on an older #253 snapshot and therefore remains a dependency-restack obligation before descendants can inherit a coherent ancestry. The complete pinned Chromium isolated profile → BiDi session/subscription → navigation/document epoch → semantic observation → admitted node → typed click/type → correlated result plus real post-condition → credential-safe provenance → teardown/crash-cleanup path is still active-PR evidence only, not protected-main truth. -- DDD ownership correction #272 is Draft at exact head `b3595ef5656ebdb5aa301d4d2f3e487f6a1f21c8` on protected `main`; its patch keeps MCP as an external adapter depending inward on stable core contracts and policy, and removes MCP protocol types from core/policy authority. Native CI, MV3, Security Scan, SAST Semgrep, Noema, scheduler, and close-empty evidence succeeded on this exact head. Required Strix run `33473689091` is cancelled before job creation, and a bounded leaf rerun attempt returned HTTP 403 (`This workflow run cannot be retried`); OpenCode run `33473689030` remains queued. Neither condition is converted to success. PR #273 remains the Draft Context Map/Ubiquitous Language child at `d75462b91fb3b3d2dbbaf01a153e3e0ca6b7a539` and cannot inherit parent evidence. -- The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #199 durable WARC/PROV plus tenant persistence/KMS/retention/replay, #200 stable BAP/MCP task lifecycle and contextual-orchestrator integration, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 durable enterprise identity/tenant/policy/approval/audit/SLO operations, and #203 exact-artifact commercial benchmark/recovery acceptance. Partial PRs remain partial evidence and are not described as shipped completion. +- The complete open inventory is **141 open pull requests: 26 Ready/non-draft and 115 Draft; 11 open non-PR issues**. Queue movement is not protected-main delivery. +- Active organization ruleset `18156473` (`CWL Central required workflows`) remains the effective default-branch authority. It requires one approving review, resolved review threads, and the configured central required workflows. Auto-merge remains disabled, and the legacy branch payload's embedded protection state is not treated as the ruleset authority. +- Issue #28 remains the P0 buyer-visible integration target. PR #271 is Draft at exact head `426f9dcfa7c341cd436cedc69f47c805d808466a` on exact #270 head `e5b44e8470df5befa0bb26eb9f893e7106347f3d`. Exact native CI run `33574462648` is **queued/non-passing**; Rust contracts job `100075273924` and Production coverage job `100075273720` are queued. No predecessor GREEN transfers, and command ACK remains distinct from post-condition proof. +- The active WebDriver BiDi lineage is undergoing non-destructive restacks. Current exact parent/head observations include #250 `9394b9afd81670318fecf4a3f0cafa7cb62af7ff`, #251 `9ba972838e44c15a0a88148533bec787ffd87a47`, #252 `f0dcf215f3f2477a18798ef302560fc43c74fac3`, #253 `cf5fd422a329acbfa04ac0685d32a405942a7146`, #254 `2a93e7ebca897ec527ba9fb1758e05b835fdaee5`, #255 `b1712b8c4a0ebf75bb1cfaf1aab1fdee1ceeb6ed`, #256 `9d34c2346920a61e09bc4f522b1471ce58d96b6b`, #257 `c68ce817fae211ca488239d79d0a5afc3debb286`, and #258 `04b47015a69cb48cd5acee6a656b498e82f5c819`. These are active-PR ancestry observations only; the complete pinned Chromium isolated profile → BiDi session/subscription → navigation/document epoch → semantic observation → admitted node → typed click/type → correlated protocol result plus real post-condition → credential-safe provenance → teardown/crash-cleanup path is still not protected-main behavior. +- Ready root #82 remains at exact head `90c4e9a8f31eb94eb46243343160d3f6c96921ef` on protected `main`. Central Strix run `33497088613` attempt 2 remains queued at job `100091557792`, and OpenCode coverage-evidence job `100098698802` is queued. Queued reviewer evidence is non-passing; this is not a reason to mutate product source or bypass governance. +- DDD ownership correction #272 is Draft at exact head `b3595ef5656ebdb5aa301d4d2f3e487f6a1f21c8` on protected `main`; #273 is its Draft context-map/ubiquitous-language child at exact head `d75462b91fb3b3d2dbbaf01a153e3e0ca6b7a539` on that exact parent. MCP remains an external protocol adapter depending inward on stable core contracts and policy; core/policy authority must not depend outward on MCP/CDP/WebDriver transport types. Parent/child checks and reviews remain independent. +- The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #199 durable WARC/PROV plus tenant persistence/KMS/retention/legal-hold/deletion/replay, #200 stable BAP/MCP task lifecycle and contextual-orchestrator integration, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 durable enterprise identity/tenant/policy/approval/audit/SLO operations, and #203 exact-artifact commercial benchmark/recovery acceptance. Partial PRs remain partial evidence and are not described as shipped completion. - Current evidence procedure remains fail-closed: paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. ## Observed snapshot: 2026-08-29 From ffc1b66bad7bd29f32346735d9d442fda72d3e52 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 14:16:16 +0900 Subject: [PATCH 045/250] test: decouple live baseline checks from transient stack heads --- ...test_gap_snapshot_inventory_consistency.py | 32 +++++++++++-------- 1 file changed, 18 insertions(+), 14 deletions(-) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 33e33bd4c..3df78a3e6 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -20,7 +20,7 @@ def setUpClass(cls) -> None: cls.changelog = CHANGELOG.read_text(encoding="utf-8") def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: - """A volatile live section must not rely on the historical dated inventory.""" + """The live section must bind evidence structurally without freezing transient stack heads.""" current = self.baseline.split("## Current live delivery state", 1)[1].split( "## Observed snapshot: 2026-08-29", 1 )[0] @@ -31,21 +31,25 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "11 open non-PR issues", "542ca1e9c0a863595b8b6697790005d2471f5413", "18156473", - "61bd2e00d2c60f9d846d5a5d59c7329695d5a3ed", - "9ba972838e44c15a0a88148533bec787ffd87a47", - "f0dcf215f3f2477a18798ef302560fc43c74fac3", - "cf5fd422a329acbfa04ac0685d32a405942a7146", - "b3595ef5656ebdb5aa301d4d2f3e487f6a1f21c8", + "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", + "Issue #28 remains the P0 buyer-visible integration target", + "PR #271 is Draft at exact head", + "on exact #270 head", + "Exact native CI run", + "queued/non-passing", + "Ready root #82 remains at exact head", + "DDD ownership correction #272 is Draft at exact head", + "#273 is its Draft context-map/ubiquitous-language child", + "active-PR ancestry observations only", ): with self.subTest(marker=marker): self.assertIn(marker, current) - self.assertIn("CI run `33548339062` is **success**", current) - self.assertIn("CI run `33553936912` is queued", current) - self.assertIn("CI run `33554087393` is queued", current) - self.assertIn("CI run `33554207683` is queued", current) - self.assertIn("Strix run `33473689091` is cancelled before job creation", current) - self.assertIn("OpenCode run `33473689030` remains queued", current) - self.assertIn("active-PR evidence only", current) + for non_passing in ( + "queued reviewer evidence is non-passing", + "discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence", + ): + with self.subTest(non_passing=non_passing): + self.assertIn(non_passing.casefold(), current.casefold()) def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: """The dated 2026-08-29 snapshot must keep its exact historical inventory.""" @@ -72,7 +76,7 @@ def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: "111 open pull requests", "27 non-draft", "153 open pull requests", - "114 draft", + "114 draft PRs", ): with self.subTest(stale=stale): self.assertNotIn(stale, current) From 4decbc320aebc9ea517590ae284c95d9e402a665 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 16:44:48 +0900 Subject: [PATCH 046/250] test(docs): fail on stale live delivery baseline --- ...test_gap_snapshot_inventory_consistency.py | 31 ++++++++++++------- 1 file changed, 20 insertions(+), 11 deletions(-) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 3df78a3e6..283f7621f 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -1,4 +1,4 @@ -"""Regression contracts for the current dated product-gap inventory snapshot.""" +"""Regression contracts for current and historical product-gap inventory evidence.""" from __future__ import annotations @@ -12,7 +12,7 @@ class GapSnapshotInventoryConsistencyTests(unittest.TestCase): - """Prevent one dated snapshot from carrying contradictory live PR totals.""" + """Keep volatile live truth separate from immutable dated snapshots.""" @classmethod def setUpClass(cls) -> None: @@ -20,27 +20,28 @@ def setUpClass(cls) -> None: cls.changelog = CHANGELOG.read_text(encoding="utf-8") def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: - """The live section must bind evidence structurally without freezing transient stack heads.""" + """The live section must bind fresh evidence without promoting queued work.""" current = self.baseline.split("## Current live delivery state", 1)[1].split( "## Observed snapshot: 2026-08-29", 1 )[0] for marker in ( - "141 open pull requests", + "142 open pull requests", "26 Ready/non-draft", - "115 Draft", - "11 open non-PR issues", + "116 Draft", + "12 open non-PR issues", "542ca1e9c0a863595b8b6697790005d2471f5413", "18156473", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", "Issue #28 remains the P0 buyer-visible integration target", - "PR #271 is Draft at exact head", - "on exact #270 head", - "Exact native CI run", - "queued/non-passing", + "PR #261 is Draft at exact head `9769733a2dee21cd0d9be5e020be7a998a4168a3`", + "native CI run `33602342786` is queued/non-passing", + "#277 remains Draft at exact head `74fdedb6ee441a4055ee335bc5a5b96dee852661`", "Ready root #82 remains at exact head", "DDD ownership correction #272 is Draft at exact head", "#273 is its Draft context-map/ubiquitous-language child", - "active-PR ancestry observations only", + "Issue #276", + "contextual-orchestrator#1016", + "active-PR evidence only", ): with self.subTest(marker=marker): self.assertIn(marker, current) @@ -50,6 +51,14 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: ): with self.subTest(non_passing=non_passing): self.assertIn(non_passing.casefold(), current.casefold()) + for stale in ( + "141 open pull requests", + "115 Draft", + "11 open non-PR issues", + "PR #271 is Draft at exact head `426f9dcfa7c341cd436cedc69f47c805d808466a`", + ): + with self.subTest(stale=stale): + self.assertNotIn(stale, current) def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: """The dated 2026-08-29 snapshot must keep its exact historical inventory.""" From 5e4e45ed4fdd040bd0dd6b9805b5fbca68a7be9e Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 16:47:18 +0900 Subject: [PATCH 047/250] docs: refresh exact live delivery baseline --- docs/product-technical-gap-baseline.md | 16 +++++++++------- 1 file changed, 9 insertions(+), 7 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index bcfdc51ac..24efd51a8 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -7,13 +7,15 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. - Protected `main` remains `542ca1e9c0a863595b8b6697790005d2471f5413`. -- The complete open inventory is **141 open pull requests: 26 Ready/non-draft and 115 Draft; 11 open non-PR issues**. Queue movement is not protected-main delivery. -- Active organization ruleset `18156473` (`CWL Central required workflows`) remains the effective default-branch authority. It requires one approving review, resolved review threads, and the configured central required workflows. Auto-merge remains disabled, and the legacy branch payload's embedded protection state is not treated as the ruleset authority. -- Issue #28 remains the P0 buyer-visible integration target. PR #271 is Draft at exact head `426f9dcfa7c341cd436cedc69f47c805d808466a` on exact #270 head `e5b44e8470df5befa0bb26eb9f893e7106347f3d`. Exact native CI run `33574462648` is **queued/non-passing**; Rust contracts job `100075273924` and Production coverage job `100075273720` are queued. No predecessor GREEN transfers, and command ACK remains distinct from post-condition proof. -- The active WebDriver BiDi lineage is undergoing non-destructive restacks. Current exact parent/head observations include #250 `9394b9afd81670318fecf4a3f0cafa7cb62af7ff`, #251 `9ba972838e44c15a0a88148533bec787ffd87a47`, #252 `f0dcf215f3f2477a18798ef302560fc43c74fac3`, #253 `cf5fd422a329acbfa04ac0685d32a405942a7146`, #254 `2a93e7ebca897ec527ba9fb1758e05b835fdaee5`, #255 `b1712b8c4a0ebf75bb1cfaf1aab1fdee1ceeb6ed`, #256 `9d34c2346920a61e09bc4f522b1471ce58d96b6b`, #257 `c68ce817fae211ca488239d79d0a5afc3debb286`, and #258 `04b47015a69cb48cd5acee6a656b498e82f5c819`. These are active-PR ancestry observations only; the complete pinned Chromium isolated profile → BiDi session/subscription → navigation/document epoch → semantic observation → admitted node → typed click/type → correlated protocol result plus real post-condition → credential-safe provenance → teardown/crash-cleanup path is still not protected-main behavior. -- Ready root #82 remains at exact head `90c4e9a8f31eb94eb46243343160d3f6c96921ef` on protected `main`. Central Strix run `33497088613` attempt 2 remains queued at job `100091557792`, and OpenCode coverage-evidence job `100098698802` is queued. Queued reviewer evidence is non-passing; this is not a reason to mutate product source or bypass governance. -- DDD ownership correction #272 is Draft at exact head `b3595ef5656ebdb5aa301d4d2f3e487f6a1f21c8` on protected `main`; #273 is its Draft context-map/ubiquitous-language child at exact head `d75462b91fb3b3d2dbbaf01a153e3e0ca6b7a539` on that exact parent. MCP remains an external protocol adapter depending inward on stable core contracts and policy; core/policy authority must not depend outward on MCP/CDP/WebDriver transport types. Parent/child checks and reviews remain independent. -- The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #199 durable WARC/PROV plus tenant persistence/KMS/retention/legal-hold/deletion/replay, #200 stable BAP/MCP task lifecycle and contextual-orchestrator integration, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 durable enterprise identity/tenant/policy/approval/audit/SLO operations, and #203 exact-artifact commercial benchmark/recovery acceptance. Partial PRs remain partial evidence and are not described as shipped completion. +- Full pagination currently returns **142 open pull requests: 26 Ready/non-draft and 116 Draft; 12 open non-PR issues**. Queue movement is not protected-main delivery. +- Active organization ruleset `18156473` (`CWL Central required workflows`) remains the effective default-branch authority. Its live pull-request rule requires one approving review, dismissal of stale approvals after pushes, resolved review threads, no separate latest-push approval, and the configured central required workflows. Auto-merge remains disabled. A fresh Ready-PR search returned no current `review:approved` candidate, so successful checks alone do not create merge authority. The legacy branch payload's embedded protection state is not treated as the ruleset authority. +- Issue #28 remains the P0 buyer-visible integration target. PR #261 is Draft at exact head `9769733a2dee21cd0d9be5e020be7a998a4168a3` on the live #260 branch, whose current head is `24ea7fb3be0bcadabd783f5ffc9a9581776f7faf`. The #261 repair is fast-forward-only after exact rustfmt and command-kind correlation failures; native CI run `33602342786` is queued/non-passing. No queued or predecessor result is GREEN. +- #277 remains Draft at exact head `74fdedb6ee441a4055ee335bc5a5b96dee852661`. It reconstructed the verified six-file `browsingContext.navigationCommitted` subscription delta on the former #261 head `c59b31c4e7fa31546fb4c7e5bf88dc1e436fd60b`, so the branch is now behind the repaired #261 parent. Keep it Draft and do not restack again until #261 current-head native evidence is terminal GREEN. #262 stays open until replacement equivalence and independent exact-head GREEN are proven. The downstream #263–#271 stack remains active-PR evidence only; command ACK remains distinct from an observed post-condition. +- Ready root #82 remains at exact head `90c4e9a8f31eb94eb46243343160d3f6c96921ef` on protected `main`. Repository-native CI `33497090741`, Manifest V3 Compatibility `33497090663`, SAST Semgrep `33497090791`, and Security Scan `33497090707` are terminal success. Central Strix job `100091557792` and coverage-evidence job `100098698802` remain queued/non-passing. Queued reviewer evidence is non-passing; this is not a reason to mutate product source or bypass governance. +- Ready root #37 remains at exact head `5e3dfcbd7a4daea297782cb99635990368589232` on protected `main`. Repository-native CI/SAST/Security and current coverage evidence are successful, while the fresh central `opencode-review` rerun job `100098530585` remains queued. It therefore remains blocked independently of #82. +- DDD ownership correction #272 is Draft at exact head `b3595ef5656ebdb5aa301d4d2f3e487f6a1f21c8` on protected `main`; #273 is its Draft context-map/ubiquitous-language child at exact head `d75462b91fb3b3d2dbbaf01a153e3e0ca6b7a539` on that exact parent. MCP remains an external protocol adapter depending inward on stable core contracts and policy; core/policy authority must not depend outward on MCP/CDP/WebDriver transport types. The context map keeps Core, Supporting, and Generic subdomains explicit and treats adapter translation as an ACL: Aggregate, Entity, Value Object, Domain Service, Repository, Domain Event, and Invariant vocabulary must agree with code, API, persistence, and tests rather than granting authority through protocol types. +- Issue #276 is now a live integration debt: protected-main `.github/workflows/hourly-product-development.yml` still makes the scheduled model path through a repository-local NVIDIA NIM broker rather than `contextual-orchestrator` / `orchestrator/free`. Protected-main `AGENTS.md` forbids this scheduled product writer from mutating workflow source. The reusable owner dependency is open as `ContextualWisdomLab/contextual-orchestrator#1016`, which must publish a versioned, secret-safe, request-correlated provider/routing outcome contract before OriginWeave can retire its provider-specific broker without losing typed 401/403/429/provider/cancellation evidence. OriginWeave must consume that owner contract instead of duplicating provider-routing internals. +- The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #199 durable WARC/PROV plus tenant persistence/KMS/retention/legal-hold/deletion/replay, #200 stable BAP/MCP task lifecycle and contextual-orchestrator integration, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 durable enterprise identity/tenant/policy/approval/audit/SLO operations, and #203 exact-artifact commercial benchmark/recovery acceptance. Partial PRs remain partial evidence and are not described as shipped completion. No release is authorized while #201/#203 exact signed-artifact and commercial-acceptance evidence is incomplete. - Current evidence procedure remains fail-closed: paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. ## Observed snapshot: 2026-08-29 From 00f3f510dc520da534432e8f52d3db89ffc24f7e Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 20:06:35 +0900 Subject: [PATCH 048/250] test(docs): bind live baseline to current governance evidence --- tests/test_gap_snapshot_inventory_consistency.py | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 283f7621f..163783b3b 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -31,14 +31,20 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "12 open non-PR issues", "542ca1e9c0a863595b8b6697790005d2471f5413", "18156473", + "ten central required workflows", + "codeql-pr.yml", + "scorecard-pr.yml", + "osv-scanner-pr.yml", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", "Issue #28 remains the P0 buyer-visible integration target", "PR #261 is Draft at exact head `9769733a2dee21cd0d9be5e020be7a998a4168a3`", "native CI run `33602342786` is queued/non-passing", "#277 remains Draft at exact head `74fdedb6ee441a4055ee335bc5a5b96dee852661`", "Ready root #82 remains at exact head", + "coverage-evidence job `100098698802` is terminal success", + "Noema job `99943871679` remains terminal failure", "DDD ownership correction #272 is Draft at exact head", - "#273 is its Draft context-map/ubiquitous-language child", + "#273 is its Draft context-map/ubiquitous-language child at exact head `f34212f9dff07deb70dd5265ecbb00f36b0f69b0`", "Issue #276", "contextual-orchestrator#1016", "active-PR evidence only", @@ -56,6 +62,8 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "115 Draft", "11 open non-PR issues", "PR #271 is Draft at exact head `426f9dcfa7c341cd436cedc69f47c805d808466a`", + "#273 is its Draft context-map/ubiquitous-language child at exact head `d75462b91fb3b3d2dbbaf01a153e3e0ca6b7a539`", + "coverage-evidence job `100098698802` remain queued", ): with self.subTest(stale=stale): self.assertNotIn(stale, current) From 6dfe38a194367e229f718493dace6a8e2cf41cdf Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 2 Sep 2026 20:09:19 +0900 Subject: [PATCH 049/250] test(docs): keep live governance evidence ruleset-bound --- tests/test_gap_snapshot_inventory_consistency.py | 13 ++++--------- 1 file changed, 4 insertions(+), 9 deletions(-) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 163783b3b..d3e116e1e 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -31,20 +31,16 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "12 open non-PR issues", "542ca1e9c0a863595b8b6697790005d2471f5413", "18156473", - "ten central required workflows", - "codeql-pr.yml", - "scorecard-pr.yml", - "osv-scanner-pr.yml", + "configured central required workflows", + "legacy branch payload's embedded protection state is not treated as the ruleset authority", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", "Issue #28 remains the P0 buyer-visible integration target", "PR #261 is Draft at exact head `9769733a2dee21cd0d9be5e020be7a998a4168a3`", "native CI run `33602342786` is queued/non-passing", "#277 remains Draft at exact head `74fdedb6ee441a4055ee335bc5a5b96dee852661`", "Ready root #82 remains at exact head", - "coverage-evidence job `100098698802` is terminal success", - "Noema job `99943871679` remains terminal failure", "DDD ownership correction #272 is Draft at exact head", - "#273 is its Draft context-map/ubiquitous-language child at exact head `f34212f9dff07deb70dd5265ecbb00f36b0f69b0`", + "#273 is its Draft context-map/ubiquitous-language child", "Issue #276", "contextual-orchestrator#1016", "active-PR evidence only", @@ -62,8 +58,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "115 Draft", "11 open non-PR issues", "PR #271 is Draft at exact head `426f9dcfa7c341cd436cedc69f47c805d808466a`", - "#273 is its Draft context-map/ubiquitous-language child at exact head `d75462b91fb3b3d2dbbaf01a153e3e0ca6b7a539`", - "coverage-evidence job `100098698802` remain queued", + "seven required workflow entries", ): with self.subTest(stale=stale): self.assertNotIn(stale, current) From 1d3d848a28267e32a60d08c85ac34ec47e8868a4 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 3 Sep 2026 03:07:20 +0900 Subject: [PATCH 050/250] test(docs): bind live baseline to current evidence --- ...test_gap_snapshot_inventory_consistency.py | 22 ++++++++++++++----- 1 file changed, 17 insertions(+), 5 deletions(-) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index d3e116e1e..0ce127217 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -3,6 +3,7 @@ from __future__ import annotations from pathlib import Path +import re import unittest @@ -31,22 +32,30 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "12 open non-PR issues", "542ca1e9c0a863595b8b6697790005d2471f5413", "18156473", - "configured central required workflows", + "10 central required workflows", "legacy branch payload's embedded protection state is not treated as the ruleset authority", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", "Issue #28 remains the P0 buyer-visible integration target", - "PR #261 is Draft at exact head `9769733a2dee21cd0d9be5e020be7a998a4168a3`", - "native CI run `33602342786` is queued/non-passing", + "PR #261 is Draft at exact head `127e02503e48938e29a9a07410574c7e72fc661a`", + "current exact-head CI run `33659163892` is queued/non-passing", "#277 remains Draft at exact head `74fdedb6ee441a4055ee335bc5a5b96dee852661`", "Ready root #82 remains at exact head", - "DDD ownership correction #272 is Draft at exact head", - "#273 is its Draft context-map/ubiquitous-language child", + "coverage-evidence job `100098698802` is terminal success", + "Strix job `100091557792` is terminal failure", + "Ready root #37 remains at exact head", + "opencode-review job `100098530585` is terminal cancelled", + "DDD ownership correction #272 is Draft at exact head `bbe6b219a33f78e3b8b1c0166a00e5c34a2ede22`", + "#273 is its stale-parent Draft context-map/ubiquitous-language child at exact head `f34212f9dff07deb70dd5265ecbb00f36b0f69b0`", "Issue #276", "contextual-orchestrator#1016", "active-PR evidence only", ): with self.subTest(marker=marker): self.assertIn(marker, current) + self.assertRegex( + current, + re.compile(r"Observed at \(UTC\): `\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}Z`"), + ) for non_passing in ( "queued reviewer evidence is non-passing", "discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence", @@ -59,6 +68,9 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "11 open non-PR issues", "PR #271 is Draft at exact head `426f9dcfa7c341cd436cedc69f47c805d808466a`", "seven required workflow entries", + "PR #261 is Draft at exact head `9769733a2dee21cd0d9be5e020be7a998a4168a3`", + "DDD ownership correction #272 is Draft at exact head `b3595ef5656ebdb5aa301d4d2f3e487f6a1f21c8`", + "#273 is its Draft context-map/ubiquitous-language child at exact head `d75462b91fb3b3d2dbbaf01a153e3e0ca6b7a539`", ): with self.subTest(stale=stale): self.assertNotIn(stale, current) From 50b11c202f59982d70192c34df8ff0c20c4676cc Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 3 Sep 2026 03:09:41 +0900 Subject: [PATCH 051/250] docs: refresh exact live delivery evidence --- docs/product-technical-gap-baseline.md | 17 ++++++++++------- 1 file changed, 10 insertions(+), 7 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 24efd51a8..b3d6cdd38 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,15 +6,18 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. +Observed at (UTC): `2026-09-02T18:06:40Z`. + - Protected `main` remains `542ca1e9c0a863595b8b6697790005d2471f5413`. - Full pagination currently returns **142 open pull requests: 26 Ready/non-draft and 116 Draft; 12 open non-PR issues**. Queue movement is not protected-main delivery. -- Active organization ruleset `18156473` (`CWL Central required workflows`) remains the effective default-branch authority. Its live pull-request rule requires one approving review, dismissal of stale approvals after pushes, resolved review threads, no separate latest-push approval, and the configured central required workflows. Auto-merge remains disabled. A fresh Ready-PR search returned no current `review:approved` candidate, so successful checks alone do not create merge authority. The legacy branch payload's embedded protection state is not treated as the ruleset authority. -- Issue #28 remains the P0 buyer-visible integration target. PR #261 is Draft at exact head `9769733a2dee21cd0d9be5e020be7a998a4168a3` on the live #260 branch, whose current head is `24ea7fb3be0bcadabd783f5ffc9a9581776f7faf`. The #261 repair is fast-forward-only after exact rustfmt and command-kind correlation failures; native CI run `33602342786` is queued/non-passing. No queued or predecessor result is GREEN. -- #277 remains Draft at exact head `74fdedb6ee441a4055ee335bc5a5b96dee852661`. It reconstructed the verified six-file `browsingContext.navigationCommitted` subscription delta on the former #261 head `c59b31c4e7fa31546fb4c7e5bf88dc1e436fd60b`, so the branch is now behind the repaired #261 parent. Keep it Draft and do not restack again until #261 current-head native evidence is terminal GREEN. #262 stays open until replacement equivalence and independent exact-head GREEN are proven. The downstream #263–#271 stack remains active-PR evidence only; command ACK remains distinct from an observed post-condition. -- Ready root #82 remains at exact head `90c4e9a8f31eb94eb46243343160d3f6c96921ef` on protected `main`. Repository-native CI `33497090741`, Manifest V3 Compatibility `33497090663`, SAST Semgrep `33497090791`, and Security Scan `33497090707` are terminal success. Central Strix job `100091557792` and coverage-evidence job `100098698802` remain queued/non-passing. Queued reviewer evidence is non-passing; this is not a reason to mutate product source or bypass governance. -- Ready root #37 remains at exact head `5e3dfcbd7a4daea297782cb99635990368589232` on protected `main`. Repository-native CI/SAST/Security and current coverage evidence are successful, while the fresh central `opencode-review` rerun job `100098530585` remains queued. It therefore remains blocked independently of #82. -- DDD ownership correction #272 is Draft at exact head `b3595ef5656ebdb5aa301d4d2f3e487f6a1f21c8` on protected `main`; #273 is its Draft context-map/ubiquitous-language child at exact head `d75462b91fb3b3d2dbbaf01a153e3e0ca6b7a539` on that exact parent. MCP remains an external protocol adapter depending inward on stable core contracts and policy; core/policy authority must not depend outward on MCP/CDP/WebDriver transport types. The context map keeps Core, Supporting, and Generic subdomains explicit and treats adapter translation as an ACL: Aggregate, Entity, Value Object, Domain Service, Repository, Domain Event, and Invariant vocabulary must agree with code, API, persistence, and tests rather than granting authority through protocol types. -- Issue #276 is now a live integration debt: protected-main `.github/workflows/hourly-product-development.yml` still makes the scheduled model path through a repository-local NVIDIA NIM broker rather than `contextual-orchestrator` / `orchestrator/free`. Protected-main `AGENTS.md` forbids this scheduled product writer from mutating workflow source. The reusable owner dependency is open as `ContextualWisdomLab/contextual-orchestrator#1016`, which must publish a versioned, secret-safe, request-correlated provider/routing outcome contract before OriginWeave can retire its provider-specific broker without losing typed 401/403/429/provider/cancellation evidence. OriginWeave must consume that owner contract instead of duplicating provider-routing internals. +- Active organization ruleset `18156473` (`CWL Central required workflows`) remains the effective default-branch authority. Its live pull-request rule requires one approving review, dismissal of stale approvals after pushes, resolved review threads, and 10 central required workflows: `close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, `codeql-pr`, `scorecard-pr`, and `osv-scanner-pr`. A fresh Ready-PR search returned no current `review:approved` candidate, so successful checks alone do not create merge authority. The legacy branch payload's embedded protection state is not treated as the ruleset authority. +- Issue #28 remains the P0 buyer-visible integration target. PR #261 is Draft at exact head `127e02503e48938e29a9a07410574c7e72fc661a` on live #260 head `24ea7fb3be0bcadabd783f5ffc9a9581776f7faf`. Predecessor CI run `33602342786` executed and failed rustfmt plus production-coverage/correlation checks; the current exact-head CI run `33659163892` is queued/non-passing. No predecessor failure, queued result, or synthetic status is GREEN. +- #277 remains Draft at exact head `74fdedb6ee441a4055ee335bc5a5b96dee852661` on predecessor #261 head `c59b31c4e7fa31546fb4c7e5bf88dc1e436fd60b`. Its own CI `33600076214` executed stale-child RED: rustfmt failed and compilation proved that the child still calls removed generic `register_command`/`correlate_response` APIs. Keep it Draft until #261 current-head evidence is terminal GREEN, then reconstruct the verified six-file subscription delta non-destructively with typed `SessionSubscribe` correlation. #262 stays open until replacement equivalence and independent exact-head GREEN are proven. The downstream #263–#271 stack remains active-PR evidence only; command ACK remains distinct from an observed post-condition. +- Ready root #82 remains at exact head `90c4e9a8f31eb94eb46243343160d3f6c96921ef` on protected `main`. Repository-native CI `33497090741`, Manifest V3 Compatibility `33497090663`, SAST Semgrep `33497090791`, Security Scan `33497090707`, Production coverage job `99821662660`, Rust contracts job `99821662242`, and coverage-evidence job `100098698802` are terminal success. Central Strix job `100091557792` is terminal failure, Noema job `99943871679` is terminal failure, and OpenCode job `100212048205` remains queued. Queued reviewer evidence is non-passing; this is not a reason to mutate product source or bypass governance. +- Ready root #37 remains at exact head `5e3dfcbd7a4daea297782cb99635990368589232` on protected `main`. Repository-native CI `33146884129`, SAST `33146884200`, Security `33146884229`, coverage-source-tree job `100098530821`, and coverage-evidence job `100098531294` are successful. The exact-head `opencode-review` job `100098530585` is terminal cancelled, not queued or successful, so the root remains independently blocked by current central evidence and approval requirements. +- DDD ownership correction #272 is Draft at exact head `bbe6b219a33f78e3b8b1c0166a00e5c34a2ede22` on protected `main`. Its adapter-local MCP `2026-07-28` work currently ends in a test-only stdio transport contract: valid stdio `tools/call` and `tools/list` must admit request-body protocol metadata/client capabilities without fabricating an HTTP header, while Streamable HTTP retains header/body mismatch rejection. Production transport-specific constructors are intentionally absent until this test executes RED. Exact-head CI `33646560232` remains queued/non-passing and CodeQL PR `33646562998` is a central `startup_failure`; neither is product GREEN. #273 is its stale-parent Draft context-map/ubiquitous-language child at exact head `f34212f9dff07deb70dd5265ecbb00f36b0f69b0`, with stored base `b3595ef5656ebdb5aa301d4d2f3e487f6a1f21c8` behind the live #272 parent, so it remains non-mergeable until parent-first RED→minimal fix→exact-head GREEN and non-force reconstruction. MCP remains an external protocol adapter depending inward on stable core contracts and policy; core/policy authority must not depend outward on MCP/CDP/WebDriver transport types. +- The #199 retention/evidence slice #239 remains Draft at exact head `58b27e8f1a7bc00c6cd10e8553c971eba2eadbd1` on current #227 head `f028cf6c2330b47b6f13dfa1441c32c86e5ed9e5`. Its late legal-hold/deletion race repair is active-PR evidence only; exact-head CI `33624336848` remains queued/non-passing, so predecessor checks are not promoted. +- Issue #276 remains a live integration debt: protected-main `.github/workflows/hourly-product-development.yml` still makes the scheduled model path through a repository-local NVIDIA NIM broker rather than `contextual-orchestrator` / `orchestrator/free`. Protected-main `AGENTS.md` forbids this scheduled product writer from mutating workflow source. The reusable owner dependency is open as `ContextualWisdomLab/contextual-orchestrator#1016`, which must publish a versioned, secret-safe, request-correlated provider/routing outcome contract before OriginWeave can retire its provider-specific broker without losing typed 401/403/429/provider/cancellation evidence. OriginWeave must consume that owner contract instead of duplicating provider-routing internals. - The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #199 durable WARC/PROV plus tenant persistence/KMS/retention/legal-hold/deletion/replay, #200 stable BAP/MCP task lifecycle and contextual-orchestrator integration, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 durable enterprise identity/tenant/policy/approval/audit/SLO operations, and #203 exact-artifact commercial benchmark/recovery acceptance. Partial PRs remain partial evidence and are not described as shipped completion. No release is authorized while #201/#203 exact signed-artifact and commercial-acceptance evidence is incomplete. - Current evidence procedure remains fail-closed: paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. From c4e5d0669aa68f9da87f9477369843b39aac601c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 3 Sep 2026 03:10:17 +0900 Subject: [PATCH 052/250] test(docs): align grouped root-gate evidence --- tests/test_gap_snapshot_inventory_consistency.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 0ce127217..9b54f7aa2 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -40,7 +40,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "current exact-head CI run `33659163892` is queued/non-passing", "#277 remains Draft at exact head `74fdedb6ee441a4055ee335bc5a5b96dee852661`", "Ready root #82 remains at exact head", - "coverage-evidence job `100098698802` is terminal success", + "coverage-evidence job `100098698802`", "Strix job `100091557792` is terminal failure", "Ready root #37 remains at exact head", "opencode-review job `100098530585` is terminal cancelled", From 959ae477e748069ee92f258f1a5bb8c087349d8a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 3 Sep 2026 03:15:17 +0900 Subject: [PATCH 053/250] test(docs): reject volatile queue count in buyer gap --- tests/test_product_completion_gap_contract.py | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 03ed97127..a41c7abda 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -41,7 +41,7 @@ def test_baseline_records_current_inventory_and_completion_issues(self) -> None: "#201", "#202", "#203", - "Shrink the 109-PR queue", + "Shrink the open-PR queue", "durable WARC/PROV replay", "stable BAP/MCP runtime API", "signed cross-platform Chromium distribution", @@ -51,6 +51,7 @@ def test_baseline_records_current_inventory_and_completion_issues(self) -> None: with self.subTest(phrase=phrase): self.assertIn(phrase, text) + self.assertNotIn("Shrink the 109-PR queue", text) self.assertNotIn( "current-head hosted CI, security, Noema, scheduler, and OpenCode workflows were still regenerating at the recheck", text, From 356a4b3d0036f20140641ad0da39850811622594 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 3 Sep 2026 03:17:50 +0900 Subject: [PATCH 054/250] docs: remove stale volatile queue count from buyer gap --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b3d6cdd38..180efa95a 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -217,7 +217,7 @@ The hourly product-development loop is operational infrastructure, not proof tha | P1 | Buyers can install, update, verify, and roll back a supported product | **Not shipped** | #201; signed Windows/macOS/Linux/headless artifacts, Chromium revision manifest, updater security, patch SLA, SBOM, SLSA provenance, and recovery | | P1 | Enterprise teams can provision, approve, audit, operate, and recover the service | **Not shipped** | #202; Keyverse-compatible OIDC/SCIM, tenant isolation, policy/approval/evidence UI, SLO/incident controls, data residency, CSAP/SOC 2 evidence mapping, WCAG 2.2, Figma File ID, and Storybook | | P0 | A release has reproducible proof of usefulness, safety, evidence completeness, and recovery | **No product-wide release gate** | #203; deterministic, compatibility, adversarial, recovery, and enterprise suites with statistical reporting and an exact-artifact commercial acceptance gate | -| P0 | Valid changes reach protected `main` without authority improvisation or unbounded stack growth | **Blocked / high integration debt** | Shrink the 109-PR queue in dependency order, provision legitimate review authority, require exact-current evidence, and close duplicates/superseded branches | +| P0 | Valid changes reach protected `main` without authority improvisation or unbounded stack growth | **Blocked / high integration debt** | Shrink the open-PR queue in dependency order, provision legitimate review authority, require exact-current evidence, and close duplicates/superseded branches | ## Commercial completion definition From 09efb78ad4e8c3f7894e550aa6278c106aa2fe8f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 3 Sep 2026 03:18:55 +0900 Subject: [PATCH 055/250] test(docs): require terminal coverage evidence --- tests/test_gap_snapshot_inventory_consistency.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 9b54f7aa2..f520761b9 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -40,7 +40,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "current exact-head CI run `33659163892` is queued/non-passing", "#277 remains Draft at exact head `74fdedb6ee441a4055ee335bc5a5b96dee852661`", "Ready root #82 remains at exact head", - "coverage-evidence job `100098698802`", + "Production coverage job `99821662660`, Rust contracts job `99821662242`, and coverage-evidence job `100098698802` are terminal success", "Strix job `100091557792` is terminal failure", "Ready root #37 remains at exact head", "opencode-review job `100098530585` is terminal cancelled", From 817e2411139e54c477f7f994d6b3ca9e49d8ed2d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 3 Sep 2026 06:15:56 +0900 Subject: [PATCH 056/250] docs(gap): refresh live release and browser evidence --- docs/product-technical-gap-baseline.md | 24 ++++++++++++------------ 1 file changed, 12 insertions(+), 12 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 180efa95a..885c25658 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,19 +6,19 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-02T18:06:40Z`. +Observed at (UTC): `2026-09-02T21:11Z`. - Protected `main` remains `542ca1e9c0a863595b8b6697790005d2471f5413`. -- Full pagination currently returns **142 open pull requests: 26 Ready/non-draft and 116 Draft; 12 open non-PR issues**. Queue movement is not protected-main delivery. -- Active organization ruleset `18156473` (`CWL Central required workflows`) remains the effective default-branch authority. Its live pull-request rule requires one approving review, dismissal of stale approvals after pushes, resolved review threads, and 10 central required workflows: `close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, `codeql-pr`, `scorecard-pr`, and `osv-scanner-pr`. A fresh Ready-PR search returned no current `review:approved` candidate, so successful checks alone do not create merge authority. The legacy branch payload's embedded protection state is not treated as the ruleset authority. -- Issue #28 remains the P0 buyer-visible integration target. PR #261 is Draft at exact head `127e02503e48938e29a9a07410574c7e72fc661a` on live #260 head `24ea7fb3be0bcadabd783f5ffc9a9581776f7faf`. Predecessor CI run `33602342786` executed and failed rustfmt plus production-coverage/correlation checks; the current exact-head CI run `33659163892` is queued/non-passing. No predecessor failure, queued result, or synthetic status is GREEN. -- #277 remains Draft at exact head `74fdedb6ee441a4055ee335bc5a5b96dee852661` on predecessor #261 head `c59b31c4e7fa31546fb4c7e5bf88dc1e436fd60b`. Its own CI `33600076214` executed stale-child RED: rustfmt failed and compilation proved that the child still calls removed generic `register_command`/`correlate_response` APIs. Keep it Draft until #261 current-head evidence is terminal GREEN, then reconstruct the verified six-file subscription delta non-destructively with typed `SessionSubscribe` correlation. #262 stays open until replacement equivalence and independent exact-head GREEN are proven. The downstream #263–#271 stack remains active-PR evidence only; command ACK remains distinct from an observed post-condition. -- Ready root #82 remains at exact head `90c4e9a8f31eb94eb46243343160d3f6c96921ef` on protected `main`. Repository-native CI `33497090741`, Manifest V3 Compatibility `33497090663`, SAST Semgrep `33497090791`, Security Scan `33497090707`, Production coverage job `99821662660`, Rust contracts job `99821662242`, and coverage-evidence job `100098698802` are terminal success. Central Strix job `100091557792` is terminal failure, Noema job `99943871679` is terminal failure, and OpenCode job `100212048205` remains queued. Queued reviewer evidence is non-passing; this is not a reason to mutate product source or bypass governance. -- Ready root #37 remains at exact head `5e3dfcbd7a4daea297782cb99635990368589232` on protected `main`. Repository-native CI `33146884129`, SAST `33146884200`, Security `33146884229`, coverage-source-tree job `100098530821`, and coverage-evidence job `100098531294` are successful. The exact-head `opencode-review` job `100098530585` is terminal cancelled, not queued or successful, so the root remains independently blocked by current central evidence and approval requirements. -- DDD ownership correction #272 is Draft at exact head `bbe6b219a33f78e3b8b1c0166a00e5c34a2ede22` on protected `main`. Its adapter-local MCP `2026-07-28` work currently ends in a test-only stdio transport contract: valid stdio `tools/call` and `tools/list` must admit request-body protocol metadata/client capabilities without fabricating an HTTP header, while Streamable HTTP retains header/body mismatch rejection. Production transport-specific constructors are intentionally absent until this test executes RED. Exact-head CI `33646560232` remains queued/non-passing and CodeQL PR `33646562998` is a central `startup_failure`; neither is product GREEN. #273 is its stale-parent Draft context-map/ubiquitous-language child at exact head `f34212f9dff07deb70dd5265ecbb00f36b0f69b0`, with stored base `b3595ef5656ebdb5aa301d4d2f3e487f6a1f21c8` behind the live #272 parent, so it remains non-mergeable until parent-first RED→minimal fix→exact-head GREEN and non-force reconstruction. MCP remains an external protocol adapter depending inward on stable core contracts and policy; core/policy authority must not depend outward on MCP/CDP/WebDriver transport types. -- The #199 retention/evidence slice #239 remains Draft at exact head `58b27e8f1a7bc00c6cd10e8553c971eba2eadbd1` on current #227 head `f028cf6c2330b47b6f13dfa1441c32c86e5ed9e5`. Its late legal-hold/deletion race repair is active-PR evidence only; exact-head CI `33624336848` remains queued/non-passing, so predecessor checks are not promoted. -- Issue #276 remains a live integration debt: protected-main `.github/workflows/hourly-product-development.yml` still makes the scheduled model path through a repository-local NVIDIA NIM broker rather than `contextual-orchestrator` / `orchestrator/free`. Protected-main `AGENTS.md` forbids this scheduled product writer from mutating workflow source. The reusable owner dependency is open as `ContextualWisdomLab/contextual-orchestrator#1016`, which must publish a versioned, secret-safe, request-correlated provider/routing outcome contract before OriginWeave can retire its provider-specific broker without losing typed 401/403/429/provider/cancellation evidence. OriginWeave must consume that owner contract instead of duplicating provider-routing internals. -- The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #199 durable WARC/PROV plus tenant persistence/KMS/retention/legal-hold/deletion/replay, #200 stable BAP/MCP task lifecycle and contextual-orchestrator integration, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 durable enterprise identity/tenant/policy/approval/audit/SLO operations, and #203 exact-artifact commercial benchmark/recovery acceptance. Partial PRs remain partial evidence and are not described as shipped completion. No release is authorized while #201/#203 exact signed-artifact and commercial-acceptance evidence is incomplete. +- Full search currently returns **142 open pull requests: 26 Ready/non-draft and 116 Draft; 12 open non-PR issues**. Queue movement is not protected-main delivery. +- Active organization ruleset `18156473` (`CWL Central required workflows`) remains the effective default-branch authority. Its live pull-request rule requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and 10 central required workflows: `close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, `codeql-pr`, `scorecard-pr`, and `osv-scanner-pr`. Admin bypass capability is not authorization to use it. +- Issue #28 remains the P0 buyer-visible integration target. PR #260 is Draft at exact head `56600a6fd982cfafd784f4b7bb659d918113ca90` on #259 base `dd3c0493d5a1a70c8c51524d38ff9c0553434f6f`. Its predecessor `24ea7fb3be0bcadabd783f5ffc9a9581776f7faf` executed real CI RED; the one-commit causal repair moved #260 to `56600a6f...`. Exact-current CI `33660446964` remains queued/non-passing. Unavailable runner evidence is not product GREEN. +- PR #261 remains exact head `127e02503e48938e29a9a07410574c7e72fc661a`, while its stored base is predecessor #260 `24ea7fb3...`; live #260 is `56600a6f...`, so #261 remains stale-parent evidence. Formal review `5093907798` correctly found production `.expect(...)` in `webdriver_bidi_command_correlation.rs`; corrective review `5094483494` supersedes the earlier over-broad objection to deterministic `.unwrap_or(...)`. After #260 exact-current GREEN, #261 must be reconstructed non-destructively onto that current parent, remove the actual `.expect(...)` violation, preserve typed correlation/origin-binding behavior, and regain exact 100% owned production coverage. +- PR #277 remains Draft at exact head `74fdedb6ee441a4055ee335bc5a5b96dee852661` on predecessor #261 `c59b31c4...`. Executed CI `33600076214` proves its unique subscription delta still calls removed generic correlation APIs. The eventual current-parent reconstruction must wait for corrected #261 exact-head GREEN, add typed `SessionSubscribe` registration/consumption, and independently revalidate the six-file delta. #262 remains open until complete unique-delta succession and exact-head GREEN are proven; command ACK is never a post-condition. +- PR #248 remains an independent typed-correlation lane at exact head `4b9a04e2dd161115c1ca7894bd16f22638e8b6ef` on #247 `e6d5166825d0b2e7fea95b7adb6880ee64e6a6c3`; its current CI `33663685113` remains queued, so its causal repair is not exact-head GREEN and descendants remain parent-first. +- DDD ownership correction #272 remains Draft at exact head `bbe6b219a33f78e3b8b1c0166a00e5c34a2ede22` on protected `main`. Its adapter-local MCP `2026-07-28` work ends in a test-only stdio transport contract: valid stdio `tools/call` and `tools/list` must admit request-body protocol metadata/client capabilities without fabricating an HTTP header, while Streamable HTTP retains header/body mismatch rejection. Exact CI `33646560232` remains queued/non-passing; Rust contracts and Production coverage are pre-execution with `runner_id=0`; CodeQL PR `33646562998` is terminal `startup_failure`. #273 remains stale-parent Draft `f34212f9dff07deb70dd5265ecbb00f36b0f69b0`. MCP remains an external protocol adapter and core/policy must not depend outward on MCP/CDP/WebDriver transport types. +- Issue #201's release/SBOM lane advanced on Draft PR #221. Current exact head `f341ab946beb509f53a9cc8cc52fc20d650faa87` is stacked on Ready #219 exact base `94d5e1f12c959243d107c6f7bfff24faf995d633`. Fresh SPDX 3.0.1 review found that the previous recursive counter admitted a payload whose only `SpdxDocument` was nested below another graph object even though Element nodes belong at the top-level `@graph`. Formal review `5095033336` recorded the finding. Test-only commit `6ab525257912e3679a5b69f671466ca6fa45369b` adds a nested-only rejection contract; production commit `e42e8d10cc30b988724e76913598a702e037126f` requires exactly one top-level `SpdxDocument` while retaining recursive rejection of any additional nested document; ADR 0018, `docs/doctoring.md`, and `CHANGELOG.md` now describe the same boundary. Exact-current CI `33683439996` and Manifest V3 run `33683439815` remain queued. The CI's Rust contracts job `100425157624` and Production coverage job `100425157894` have zero steps, `runner_id=0`, and no assigned runner/group, so exact-head GREEN is not claimed; the canary is recorded in central queue-starvation owner `.github#712`. This slice still does not generate an SBOM, validate full SPDX JSON Schema/OWL/SHACL semantics, prove SLSA provenance/reproducibility, sign artifacts, publish releases, or establish updater/rollback authority. +- The #199 retention/evidence slice #239 remains Draft at exact head `58b27e8f1a7bc00c6cd10e8553c971eba2eadbd1`. Issue #276 remains delegated to `contextual-orchestrator#1016`; OriginWeave must consume its released provider/routing outcome contract rather than duplicate provider selection/fallback authority. +- The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #28 the first complete Chromium Agent Task vertical slice, #199 durable WARC/PROV and retention/replay, #200 stable BAP/MCP runtime API, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 enterprise identity/tenant/policy/approval/audit/SLO operations, #203 exact-artifact commercial acceptance, and #276 contextual-orchestrator migration. GitHub Releases remains empty; OriginWeave is pre-GA. - Current evidence procedure remains fail-closed: paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. ## Observed snapshot: 2026-08-29 @@ -174,7 +174,7 @@ The current queue must be processed in dependency order. A green child branch ca ### Review and merge authority -The active `CWL Central required workflows` ruleset (re-fetched for this snapshot) requires one approving review, resolved review threads, no last-push approval requirement, `merge`/`squash` merge methods, and seven configured required workflows (`close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`). The current collaborator inventory contains only `seonghobae` with administration and push permissions, creating a **reviewer-provisioning gap** for counted non-author approval. +The active `CWL Central required workflows` ruleset (re-fetched for this snapshot) requires one approving review, resolved review threads, no last-push approval requirement, `merge`/`squash` merge methods, and seven configured required workflows (`close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, and `noema-review`). The current collaborator inventory contains only `seonghobae` with administration and push permissions, creating a **reviewer-provisioning gap** for counted non-author approval. This gap does not authorize self-approval, stale-head merges, administrative bypass, or weaker checks. Because the current GitHub ruleset independently requires a counted approval, the solo-maintainer hold does not satisfy the live merge gate: an eligible non-author collaborator must submit a formal `APPROVED` review on the current head. Until that reviewer-provisioning gap is repaired, protected-main merges stop even when exact-head checks, security gates, complete coverage, rustdoc/Clippy, threads, and AI-review evidence are otherwise complete. Before any merge decision, re-fetch the exact ruleset, collaborators, PR head/base, reviews, unresolved threads, and required checks; do not assume this dated observation remains current. From 74be6f5c73f4b77ade02c3e7d40e7405b8863402 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 3 Sep 2026 17:09:36 +0900 Subject: [PATCH 057/250] docs(gaps): refresh exact live delivery baseline --- docs/product-technical-gap-baseline.md | 26 +++++++++++++------------- 1 file changed, 13 insertions(+), 13 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 885c25658..2bae80777 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,19 +6,19 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-02T21:11Z`. - -- Protected `main` remains `542ca1e9c0a863595b8b6697790005d2471f5413`. -- Full search currently returns **142 open pull requests: 26 Ready/non-draft and 116 Draft; 12 open non-PR issues**. Queue movement is not protected-main delivery. -- Active organization ruleset `18156473` (`CWL Central required workflows`) remains the effective default-branch authority. Its live pull-request rule requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and 10 central required workflows: `close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, `codeql-pr`, `scorecard-pr`, and `osv-scanner-pr`. Admin bypass capability is not authorization to use it. -- Issue #28 remains the P0 buyer-visible integration target. PR #260 is Draft at exact head `56600a6fd982cfafd784f4b7bb659d918113ca90` on #259 base `dd3c0493d5a1a70c8c51524d38ff9c0553434f6f`. Its predecessor `24ea7fb3be0bcadabd783f5ffc9a9581776f7faf` executed real CI RED; the one-commit causal repair moved #260 to `56600a6f...`. Exact-current CI `33660446964` remains queued/non-passing. Unavailable runner evidence is not product GREEN. -- PR #261 remains exact head `127e02503e48938e29a9a07410574c7e72fc661a`, while its stored base is predecessor #260 `24ea7fb3...`; live #260 is `56600a6f...`, so #261 remains stale-parent evidence. Formal review `5093907798` correctly found production `.expect(...)` in `webdriver_bidi_command_correlation.rs`; corrective review `5094483494` supersedes the earlier over-broad objection to deterministic `.unwrap_or(...)`. After #260 exact-current GREEN, #261 must be reconstructed non-destructively onto that current parent, remove the actual `.expect(...)` violation, preserve typed correlation/origin-binding behavior, and regain exact 100% owned production coverage. -- PR #277 remains Draft at exact head `74fdedb6ee441a4055ee335bc5a5b96dee852661` on predecessor #261 `c59b31c4...`. Executed CI `33600076214` proves its unique subscription delta still calls removed generic correlation APIs. The eventual current-parent reconstruction must wait for corrected #261 exact-head GREEN, add typed `SessionSubscribe` registration/consumption, and independently revalidate the six-file delta. #262 remains open until complete unique-delta succession and exact-head GREEN are proven; command ACK is never a post-condition. -- PR #248 remains an independent typed-correlation lane at exact head `4b9a04e2dd161115c1ca7894bd16f22638e8b6ef` on #247 `e6d5166825d0b2e7fea95b7adb6880ee64e6a6c3`; its current CI `33663685113` remains queued, so its causal repair is not exact-head GREEN and descendants remain parent-first. -- DDD ownership correction #272 remains Draft at exact head `bbe6b219a33f78e3b8b1c0166a00e5c34a2ede22` on protected `main`. Its adapter-local MCP `2026-07-28` work ends in a test-only stdio transport contract: valid stdio `tools/call` and `tools/list` must admit request-body protocol metadata/client capabilities without fabricating an HTTP header, while Streamable HTTP retains header/body mismatch rejection. Exact CI `33646560232` remains queued/non-passing; Rust contracts and Production coverage are pre-execution with `runner_id=0`; CodeQL PR `33646562998` is terminal `startup_failure`. #273 remains stale-parent Draft `f34212f9dff07deb70dd5265ecbb00f36b0f69b0`. MCP remains an external protocol adapter and core/policy must not depend outward on MCP/CDP/WebDriver transport types. -- Issue #201's release/SBOM lane advanced on Draft PR #221. Current exact head `f341ab946beb509f53a9cc8cc52fc20d650faa87` is stacked on Ready #219 exact base `94d5e1f12c959243d107c6f7bfff24faf995d633`. Fresh SPDX 3.0.1 review found that the previous recursive counter admitted a payload whose only `SpdxDocument` was nested below another graph object even though Element nodes belong at the top-level `@graph`. Formal review `5095033336` recorded the finding. Test-only commit `6ab525257912e3679a5b69f671466ca6fa45369b` adds a nested-only rejection contract; production commit `e42e8d10cc30b988724e76913598a702e037126f` requires exactly one top-level `SpdxDocument` while retaining recursive rejection of any additional nested document; ADR 0018, `docs/doctoring.md`, and `CHANGELOG.md` now describe the same boundary. Exact-current CI `33683439996` and Manifest V3 run `33683439815` remain queued. The CI's Rust contracts job `100425157624` and Production coverage job `100425157894` have zero steps, `runner_id=0`, and no assigned runner/group, so exact-head GREEN is not claimed; the canary is recorded in central queue-starvation owner `.github#712`. This slice still does not generate an SBOM, validate full SPDX JSON Schema/OWL/SHACL semantics, prove SLSA provenance/reproducibility, sign artifacts, publish releases, or establish updater/rollback authority. -- The #199 retention/evidence slice #239 remains Draft at exact head `58b27e8f1a7bc00c6cd10e8553c971eba2eadbd1`. Issue #276 remains delegated to `contextual-orchestrator#1016`; OriginWeave must consume its released provider/routing outcome contract rather than duplicate provider selection/fallback authority. -- The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #28 the first complete Chromium Agent Task vertical slice, #199 durable WARC/PROV and retention/replay, #200 stable BAP/MCP runtime API, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 enterprise identity/tenant/policy/approval/audit/SLO operations, #203 exact-artifact commercial acceptance, and #276 contextual-orchestrator migration. GitHub Releases remains empty; OriginWeave is pre-GA. +Observed at (UTC): `2026-09-03T08:00Z`. + +- Protected `main` is `c789b802fc98a8d7fd8c09d9327f36828054d2a1` through #280. #280 restored repository-native CI for documentation changes after #278's `paths-ignore` created a documentation-contract verification gap. +- Full live search returns **142 open pull requests: 24 Ready/non-draft and 118 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. +- Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **9** central required workflows: `close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, `scorecard-pr`, and `osv-scanner-pr`. `codeql-pr` is no longer in the active required-workflow set. Administrative bypass capability is not authorization to use it. +- Issue #279 owns the remaining documentation-CI partitioning gap. Correctness is restored on protected main, but the repository's Rust-contract job still couples Python documentation/traceability contracts with Rust-heavy verification, so prose-only changes cannot yet retain exact-head documentation validation while avoiding unnecessary Rust queue load. +- Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `56600a6fd982cfafd784f4b7bb659d918113ca90` on #259 base `dd3c0493d5a1a70c8c51524d38ff9c0553434f6f`; its predecessor produced real CI RED and the one-commit typed-correlation/rustfmt repair remains awaiting exact-head verification. PR #261 is still stale-parent Draft `127e02503e48938e29a9a07410574c7e72fc661a`, one causal parent generation behind live #260, and still carries the documented production `.expect(...)` quality-contract defect. #277 remains parent-first behind the corrected #261 reconstruction and must add typed `SessionSubscribe` correlation rather than restoring generic correlation shims. +- PR #70 is Draft at exact head `5040250e3d5070215e67d4d814b86b5c5ceafdf6`, current with protected main. Its test-only sandbox contract requires the controlled Agent Task path not to launch Chromium with `--no-sandbox`; production intentionally remains unchanged until that focused test executes and produces an observed RED. Its current CI, Manifest V3, SAST, Security, OSV, and Scorecard runs remain queued, so sandbox-enabled browser evidence is not claimed. +- DDD/MCP repair #272 is Draft at exact head `80272f18422c9946077ad9bd674f603db8f020da`. The predecessor test-only stdio contract produced an observed hosted RED; the current branch contains the adapter-local `new_for_stdio` repair and durable transport traceability. It remains active-PR evidence until this exact head obtains complete CI/coverage/rustdoc/security verification. #273 remains dependent and must not be promoted ahead of #272. +- Issue #201's release/SBOM lane remains dependency ordered. #219 is Ready at exact head `6982388fde00175c446f63beda29017ef12051e9` on current protected main; #221 is Draft at exact head `ce0440480990cb97c7a1417ce6792cabdf5d47b3` stacked on that exact parent; and #240 is Ready at `c7d6c2053e0fb3f63d936e5aaaca01b2f76ce987` on protected main as the dedicated `originweave-release` bounded-context owner candidate. Their current workflows remain non-terminal. The final Rust Release owner must preserve or strengthen byte, nesting-depth, aggregate-container, structure-token/member, graph, numeric-token, duplicate-key, non-finite-number, value-redacted diagnostic, and POSIX/Windows secure-open invariants before release authority can move out of provisional Python/core boundaries. +- The #199 retention/evidence slice #239 remains Draft at exact head `58b27e8f1a7bc00c6cd10e8553c971eba2eadbd1`. Issue #276 remains delegated to `contextual-orchestrator#1016`; OriginWeave consumes released provider/routing contracts rather than duplicating provider selection or fallback authority. +- PR #274 contains the bounded GitHub Pages source/README/CHANGELOG public-surface delta, but source presence is not publication evidence. Live HTTPS publication, repository Pages configuration, and navigation must still be verified through the authorized publication path before OriginWeave claims a published Pages surface. +- The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #28 the first complete Chromium Agent Task vertical slice, #199 durable WARC/PROV and retention/replay, #200 stable BAP/MCP runtime API, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 enterprise identity/tenant/policy/approval/audit/SLO operations, #203 exact-artifact commercial acceptance, #276 contextual-orchestrator migration, and #279 exact-head documentation verification without unnecessary Rust queue load. GitHub Releases is empty; OriginWeave remains pre-GA. - Current evidence procedure remains fail-closed: paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. ## Observed snapshot: 2026-08-29 From 53ab9fa8ec2e930072c67e1cee4e6fb3971d6f1f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Thu, 3 Sep 2026 18:28:08 +0900 Subject: [PATCH 058/250] docs(gap): refresh Agent Task sandbox repair evidence --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 2bae80777..98138678b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,14 +6,14 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-03T08:00Z`. +Observed at (UTC): `2026-09-03T09:08Z`. - Protected `main` is `c789b802fc98a8d7fd8c09d9327f36828054d2a1` through #280. #280 restored repository-native CI for documentation changes after #278's `paths-ignore` created a documentation-contract verification gap. - Full live search returns **142 open pull requests: 24 Ready/non-draft and 118 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **9** central required workflows: `close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, `scorecard-pr`, and `osv-scanner-pr`. `codeql-pr` is no longer in the active required-workflow set. Administrative bypass capability is not authorization to use it. - Issue #279 owns the remaining documentation-CI partitioning gap. Correctness is restored on protected main, but the repository's Rust-contract job still couples Python documentation/traceability contracts with Rust-heavy verification, so prose-only changes cannot yet retain exact-head documentation validation while avoiding unnecessary Rust queue load. - Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `56600a6fd982cfafd784f4b7bb659d918113ca90` on #259 base `dd3c0493d5a1a70c8c51524d38ff9c0553434f6f`; its predecessor produced real CI RED and the one-commit typed-correlation/rustfmt repair remains awaiting exact-head verification. PR #261 is still stale-parent Draft `127e02503e48938e29a9a07410574c7e72fc661a`, one causal parent generation behind live #260, and still carries the documented production `.expect(...)` quality-contract defect. #277 remains parent-first behind the corrected #261 reconstruction and must add typed `SessionSubscribe` correlation rather than restoring generic correlation shims. -- PR #70 is Draft at exact head `5040250e3d5070215e67d4d814b86b5c5ceafdf6`, current with protected main. Its test-only sandbox contract requires the controlled Agent Task path not to launch Chromium with `--no-sandbox`; production intentionally remains unchanged until that focused test executes and produces an observed RED. Its current CI, Manifest V3, SAST, Security, OSV, and Scorecard runs remain queued, so sandbox-enabled browser evidence is not claimed. +- PR #70 is Draft at exact head `ba8926eed5a6d783f781684f30c900919eecd52b`, current with protected main. The existing test-first sandbox contract produced a focused source RED against exact pre-repair source `5040250e3d5070215e67d4d814b86b5c5ceafdf6` because `_run_agent_task_browser_pass` launched Chromium with `--no-sandbox`. Causal repair `60b697095be510a129cfb61a3fd97790cf7a0679` removes exactly that Agent Task launch argument; the focused source contract is GREEN on the repaired source. The separate MV3 compatibility pass remains unchanged and is not silently promoted to sandbox-preserving security evidence. Traceability, MV3 doctoring, and CHANGELOG now record the distinction, but the current exact-head CI, Manifest V3, SAST, Security, OSV, and Scorecard workflows remain queued/pending, so sandbox-enabled pinned-Chromium browser E2E and repository-wide GREEN are not yet claimed. - DDD/MCP repair #272 is Draft at exact head `80272f18422c9946077ad9bd674f603db8f020da`. The predecessor test-only stdio contract produced an observed hosted RED; the current branch contains the adapter-local `new_for_stdio` repair and durable transport traceability. It remains active-PR evidence until this exact head obtains complete CI/coverage/rustdoc/security verification. #273 remains dependent and must not be promoted ahead of #272. - Issue #201's release/SBOM lane remains dependency ordered. #219 is Ready at exact head `6982388fde00175c446f63beda29017ef12051e9` on current protected main; #221 is Draft at exact head `ce0440480990cb97c7a1417ce6792cabdf5d47b3` stacked on that exact parent; and #240 is Ready at `c7d6c2053e0fb3f63d936e5aaaca01b2f76ce987` on protected main as the dedicated `originweave-release` bounded-context owner candidate. Their current workflows remain non-terminal. The final Rust Release owner must preserve or strengthen byte, nesting-depth, aggregate-container, structure-token/member, graph, numeric-token, duplicate-key, non-finite-number, value-redacted diagnostic, and POSIX/Windows secure-open invariants before release authority can move out of provisional Python/core boundaries. - The #199 retention/evidence slice #239 remains Draft at exact head `58b27e8f1a7bc00c6cd10e8553c971eba2eadbd1`. Issue #276 remains delegated to `contextual-orchestrator#1016`; OriginWeave consumes released provider/routing contracts rather than duplicating provider selection or fallback authority. From c4655e6018fd2ecf6c2a285bce2ed536ae9925f9 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 03:10:02 +0900 Subject: [PATCH 059/250] test(docs): bind product gap contract to current live inventory --- ...test_gap_snapshot_inventory_consistency.py | 64 ++++++++----------- 1 file changed, 27 insertions(+), 37 deletions(-) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index f520761b9..702b5fa76 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -26,29 +26,23 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "## Observed snapshot: 2026-08-29", 1 )[0] for marker in ( - "142 open pull requests", - "26 Ready/non-draft", - "116 Draft", - "12 open non-PR issues", - "542ca1e9c0a863595b8b6697790005d2471f5413", + "143 open pull requests", + "5 Ready/non-draft", + "138 Draft", + "13 open non-PR issues", + "c789b802fc98a8d7fd8c09d9327f36828054d2a1", "18156473", - "10 central required workflows", - "legacy branch payload's embedded protection state is not treated as the ruleset authority", + "9 central required workflows", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Issue #28 remains the P0 buyer-visible integration target", - "PR #261 is Draft at exact head `127e02503e48938e29a9a07410574c7e72fc661a`", - "current exact-head CI run `33659163892` is queued/non-passing", - "#277 remains Draft at exact head `74fdedb6ee441a4055ee335bc5a5b96dee852661`", - "Ready root #82 remains at exact head", - "Production coverage job `99821662660`, Rust contracts job `99821662242`, and coverage-evidence job `100098698802` are terminal success", - "Strix job `100091557792` is terminal failure", - "Ready root #37 remains at exact head", - "opencode-review job `100098530585` is terminal cancelled", - "DDD ownership correction #272 is Draft at exact head `bbe6b219a33f78e3b8b1c0166a00e5c34a2ede22`", - "#273 is its stale-parent Draft context-map/ubiquitous-language child at exact head `f34212f9dff07deb70dd5265ecbb00f36b0f69b0`", - "Issue #276", - "contextual-orchestrator#1016", - "active-PR evidence only", + "Issue #279", + "Issue #28 remains the P0 governed-browser integration target", + "PR #260 is Draft at exact head `a3741389fdc491c7ecccc20f77609c55bc56d20f`", + "PR #261 remains stale-parent Draft at exact head `127e02503e48938e29a9a07410574c7e72fc661a`", + "PR #70 is Draft at exact head `ba8926eed5a6d783f781684f30c900919eecd52b`", + "DDD/MCP repair #272 is Draft at exact head `80272f18422c9946077ad9bd674f603db8f020da`", + "PR #229 is Draft at exact head `7ae426e760e8351ee792ce9df4266d7e7483d0d4`", + "PR #281 remains Draft at exact head `3ed5d7e8cf77547c96feff2cfb24c46d74a73ebb`", + "GitHub Releases is empty", ): with self.subTest(marker=marker): self.assertIn(marker, current) @@ -63,14 +57,12 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: with self.subTest(non_passing=non_passing): self.assertIn(non_passing.casefold(), current.casefold()) for stale in ( - "141 open pull requests", - "115 Draft", - "11 open non-PR issues", - "PR #271 is Draft at exact head `426f9dcfa7c341cd436cedc69f47c805d808466a`", - "seven required workflow entries", - "PR #261 is Draft at exact head `9769733a2dee21cd0d9be5e020be7a998a4168a3`", - "DDD ownership correction #272 is Draft at exact head `b3595ef5656ebdb5aa301d4d2f3e487f6a1f21c8`", - "#273 is its Draft context-map/ubiquitous-language child at exact head `d75462b91fb3b3d2dbbaf01a153e3e0ca6b7a539`", + "142 open pull requests", + "24 Ready/non-draft", + "118 Draft", + "12 open non-PR issues", + "10 central required workflows", + "PR #260 is Draft at exact head `56600a6fd982cfafd784f4b7bb659d918113ca90`", ): with self.subTest(stale=stale): self.assertNotIn(stale, current) @@ -106,20 +98,18 @@ def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: self.assertNotIn(stale, current) def test_unreleased_changelog_uses_one_current_inventory(self) -> None: - """The historical Unreleased entry remains internally self-consistent.""" + """The current Unreleased entry must match the verified volatile inventory.""" unreleased = self.changelog.split("## [Unreleased]", 1)[1] preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "108 open pull requests (24 ready, 84 draft)" + expected = "143 open pull requests (5 ready, 138 draft)" self.assertIn(expected, preamble) - self.assertIn("on 2026-08-29", preamble) - self.assertNotIn("on 2026-08-28", preamble) + self.assertIn("13 open non-PR issues", preamble) self.assertIn(expected, added) - self.assertNotIn("126 open pull requests (54 ready, 72 draft)", preamble) - self.assertNotIn("115 open pull requests (31 ready, 84 draft)", preamble) - self.assertNotIn("126 open pull requests (54 ready, 72 draft)", added) - self.assertNotIn("110 open pull requests (26 ready, 84 draft)", preamble) + self.assertIn("13 open non-PR issues", added) + self.assertNotIn("142 open pull requests", preamble) + self.assertNotIn("108 open pull requests (24 ready, 84 draft)", preamble) def test_current_snapshot_records_recent_stack_merges_and_revalidation(self) -> None: """A stacked merge must update the dated queue and parent exact-head evidence.""" From 1e5810432865530ad4de196638ee972730beb2af Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 03:10:59 +0900 Subject: [PATCH 060/250] docs(changelog): refresh current OriginWeave delivery evidence --- CHANGELOG.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index cc5d6c747..2074fba89 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,10 +4,10 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] -- Refreshed the product-gap queue to 108 open pull requests (24 ready, 84 draft) on 2026-08-29 after #53, #67, #71, #154, #217, #233, #234, and #235 merged into unprotected feature parents; these are queue evidence, not protected-main shipment. +- Refreshed the product-gap queue to 143 open pull requests (5 ready, 138 draft) and 13 open non-PR issues on 2026-09-03; queue movement is active-PR evidence, not protected-main shipment. ### Added -- Revalidated the product-gap queue at 108 open pull requests (24 ready, 84 draft) and 11 open issues on 2026-08-29; refreshed protected-main `542ca1e9`, PR #46 exact-head evidence at `373113119446d99f578febd39efc19366e7736b1`, PR #64's post-stack-merge head at `5021d142583cb5a8e393248048bb824762a98056`, and PR #210's current post-stack-merge head at `7946dce9a3dd074047d93fca299d48c7aef40e47`. Current hosted checks and independent approval remain required; no protected-main shipment is claimed. +- Revalidated the product-gap queue at 143 open pull requests (5 ready, 138 draft) and 13 open non-PR issues on 2026-09-03; protected `main` remains `c789b802fc98a8d7fd8c09d9327f36828054d2a1`, presentation-identity PR #229 is Draft at `7ae426e760e8351ee792ce9df4266d7e7483d0d4`, WebDriver BiDi document-advance PR #260 is Draft at `a3741389fdc491c7ecccc20f77609c55bc56d20f`, and sandbox-enabled Agent Task evidence PR #70 is Draft at `ba8926eed5a6d783f781684f30c900919eecd52b`. Current-head checks remain independently required; no protected-main shipment is claimed. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. From 75c2e4b8ec1c6263d9837a1685ccd221ee191133 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 03:13:42 +0900 Subject: [PATCH 061/250] docs(gaps): refresh volatile OriginWeave delivery state --- docs/product-technical-gap-baseline.md | 24 +++++++++++++----------- 1 file changed, 13 insertions(+), 11 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 98138678b..80283a76b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,20 +6,22 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-03T09:08Z`. +Observed at (UTC): `2026-09-03T18:05:00Z`. - Protected `main` is `c789b802fc98a8d7fd8c09d9327f36828054d2a1` through #280. #280 restored repository-native CI for documentation changes after #278's `paths-ignore` created a documentation-contract verification gap. -- Full live search returns **142 open pull requests: 24 Ready/non-draft and 118 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. -- Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **9** central required workflows: `close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, `scorecard-pr`, and `osv-scanner-pr`. `codeql-pr` is no longer in the active required-workflow set. Administrative bypass capability is not authorization to use it. +- Full live search returns **143 open pull requests: 5 Ready/non-draft and 138 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. +- Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **9 central required workflows**: `close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, `scorecard-pr`, and `osv-scanner-pr`. `codeql-pr` is not in the active required-workflow set. Administrative bypass capability is not authorization to use it. - Issue #279 owns the remaining documentation-CI partitioning gap. Correctness is restored on protected main, but the repository's Rust-contract job still couples Python documentation/traceability contracts with Rust-heavy verification, so prose-only changes cannot yet retain exact-head documentation validation while avoiding unnecessary Rust queue load. -- Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `56600a6fd982cfafd784f4b7bb659d918113ca90` on #259 base `dd3c0493d5a1a70c8c51524d38ff9c0553434f6f`; its predecessor produced real CI RED and the one-commit typed-correlation/rustfmt repair remains awaiting exact-head verification. PR #261 is still stale-parent Draft `127e02503e48938e29a9a07410574c7e72fc661a`, one causal parent generation behind live #260, and still carries the documented production `.expect(...)` quality-contract defect. #277 remains parent-first behind the corrected #261 reconstruction and must add typed `SessionSubscribe` correlation rather than restoring generic correlation shims. -- PR #70 is Draft at exact head `ba8926eed5a6d783f781684f30c900919eecd52b`, current with protected main. The existing test-first sandbox contract produced a focused source RED against exact pre-repair source `5040250e3d5070215e67d4d814b86b5c5ceafdf6` because `_run_agent_task_browser_pass` launched Chromium with `--no-sandbox`. Causal repair `60b697095be510a129cfb61a3fd97790cf7a0679` removes exactly that Agent Task launch argument; the focused source contract is GREEN on the repaired source. The separate MV3 compatibility pass remains unchanged and is not silently promoted to sandbox-preserving security evidence. Traceability, MV3 doctoring, and CHANGELOG now record the distinction, but the current exact-head CI, Manifest V3, SAST, Security, OSV, and Scorecard workflows remain queued/pending, so sandbox-enabled pinned-Chromium browser E2E and repository-wide GREEN are not yet claimed. -- DDD/MCP repair #272 is Draft at exact head `80272f18422c9946077ad9bd674f603db8f020da`. The predecessor test-only stdio contract produced an observed hosted RED; the current branch contains the adapter-local `new_for_stdio` repair and durable transport traceability. It remains active-PR evidence until this exact head obtains complete CI/coverage/rustdoc/security verification. #273 remains dependent and must not be promoted ahead of #272. -- Issue #201's release/SBOM lane remains dependency ordered. #219 is Ready at exact head `6982388fde00175c446f63beda29017ef12051e9` on current protected main; #221 is Draft at exact head `ce0440480990cb97c7a1417ce6792cabdf5d47b3` stacked on that exact parent; and #240 is Ready at `c7d6c2053e0fb3f63d936e5aaaca01b2f76ce987` on protected main as the dedicated `originweave-release` bounded-context owner candidate. Their current workflows remain non-terminal. The final Rust Release owner must preserve or strengthen byte, nesting-depth, aggregate-container, structure-token/member, graph, numeric-token, duplicate-key, non-finite-number, value-redacted diagnostic, and POSIX/Windows secure-open invariants before release authority can move out of provisional Python/core boundaries. -- The #199 retention/evidence slice #239 remains Draft at exact head `58b27e8f1a7bc00c6cd10e8553c971eba2eadbd1`. Issue #276 remains delegated to `contextual-orchestrator#1016`; OriginWeave consumes released provider/routing contracts rather than duplicating provider selection or fallback authority. -- PR #274 contains the bounded GitHub Pages source/README/CHANGELOG public-surface delta, but source presence is not publication evidence. Live HTTPS publication, repository Pages configuration, and navigation must still be verified through the authorized publication path before OriginWeave claims a published Pages surface. -- The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #28 the first complete Chromium Agent Task vertical slice, #199 durable WARC/PROV and retention/replay, #200 stable BAP/MCP runtime API, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 enterprise identity/tenant/policy/approval/audit/SLO operations, #203 exact-artifact commercial acceptance, #276 contextual-orchestrator migration, and #279 exact-head documentation verification without unnecessary Rust queue load. GitHub Releases is empty; OriginWeave remains pre-GA. -- Current evidence procedure remains fail-closed: paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. +- Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `a3741389fdc491c7ecccc20f77609c55bc56d20f` on #259 base `dd3c0493d5a1a70c8c51524d38ff9c0553434f6f`; its browser/navigation behavior repair has current-head CI still non-terminal. PR #261 remains stale-parent Draft at exact head `127e02503e48938e29a9a07410574c7e72fc661a`; its declared base is an older #260 generation, while live #260 has advanced to `a3741389fdc491c7ecccc20f77609c55bc56d20f`, so the child must be reconstructed parent-first rather than force-rebased or promoted from predecessor evidence. +- PR #70 is Draft at exact head `ba8926eed5a6d783f781684f30c900919eecd52b`, current with protected main. Its focused Agent Task contract proves the pre-repair `--no-sandbox` launch as source RED and the branch removes that argument only from the Agent Task lane. Sandbox-enabled pinned-Chromium E2E and repository-wide GREEN remain unproven while its exact-head browser/CI/security runs are queued. +- DDD/MCP repair #272 is Draft at exact head `80272f18422c9946077ad9bd674f603db8f020da`. It preserves MCP as an adapter, contains an observed hosted RED for missing stdio constructors, and carries the bounded adapter-local repair; it remains active-PR evidence until exact-current CI, coverage, rustdoc, review, and security gates complete. +- PR #229 is Draft at exact head `7ae426e760e8351ee792ce9df4266d7e7483d0d4`. Test-only predecessor `ffd91290479c77ff1d675d4520e1776c990ba4d5` required a narrow presentation-identity changelog statement after the feature lane correctly relinquished volatile baseline ownership; the current repair adds exactly that feature-local entry while retaining the boundary that Chromium application and page-observed effectiveness remain separate adapter/browser-E2E work. Current-head CI/security runs remain non-terminal. +- PR #281 remains Draft at exact head `3ed5d7e8cf77547c96feff2cfb24c46d74a73ebb`. It redacts browser/page-derived HTTP, WebDriver, DOM-dataset, and click-post-condition diagnostic values before CI/audit evidence; predecessor and source-level focused checks are not promoted to repository-wide GREEN while current hosted runs remain queued. +- PR #43 is Draft at exact head `e5db34c57d7b1de61d613a196117ca2cce296bec` on current protected main. Its product/test/docs delta contains no `.github/**` mutation, and its current `_run_browser_pass` Chrome options do not disable the Chromium sandbox. Exact-head Manifest V3 and repository/security workflows remain queued, so sandbox-enabled real-browser compatibility is still required before promotion. +- PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `adc040a93be2533e15fabc4ca02deec1c5562d1d`. Source presence is not publication evidence; a fresh public search still does not establish an OriginWeave project Pages deployment. Live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. +- Issue #201's release/SBOM lane remains dependency ordered, and GitHub Releases is empty. OriginWeave remains pre-GA until exact protected-head versioning, signed artifacts, SBOM/provenance, reproducibility, rollback, compatibility, security, and commercial-acceptance evidence exist. +- The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #28 the first complete Chromium Agent Task vertical slice, #199 durable WARC/PROV and retention/replay, #200 stable BAP/MCP runtime API, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 enterprise identity/tenant/policy/approval/audit/SLO operations, #203 exact-artifact commercial acceptance, #276 contextual-orchestrator migration, and #279 exact-head documentation verification without unnecessary Rust queue load. +- Current evidence procedure remains fail-closed: queued reviewer evidence is non-passing; paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. ## Observed snapshot: 2026-08-29 From ae095c58940819940969b0094ccba44ac028e105 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 07:03:35 +0900 Subject: [PATCH 062/250] test(gap): bind live baseline to 145 PR inventory --- tests/test_gap_snapshot_inventory_consistency.py | 15 ++++++++++----- 1 file changed, 10 insertions(+), 5 deletions(-) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 702b5fa76..130230e52 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -26,9 +26,9 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "## Observed snapshot: 2026-08-29", 1 )[0] for marker in ( - "143 open pull requests", + "145 open pull requests", "5 Ready/non-draft", - "138 Draft", + "140 Draft", "13 open non-PR issues", "c789b802fc98a8d7fd8c09d9327f36828054d2a1", "18156473", @@ -41,7 +41,9 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #70 is Draft at exact head `ba8926eed5a6d783f781684f30c900919eecd52b`", "DDD/MCP repair #272 is Draft at exact head `80272f18422c9946077ad9bd674f603db8f020da`", "PR #229 is Draft at exact head `7ae426e760e8351ee792ce9df4266d7e7483d0d4`", - "PR #281 remains Draft at exact head `3ed5d7e8cf77547c96feff2cfb24c46d74a73ebb`", + "PR #281 remains Draft at exact head `e96c982b6ed7ff7b80891bd60efc5d443555d4b6`", + "PR #282 is Draft at exact head `51a1e819355306e630d1241e6e5a136cb195325e`", + "PR #283 is Draft at exact head `3cefce69a7bc71e33ad64c5e8f58a0afe0b5f7e1`", "GitHub Releases is empty", ): with self.subTest(marker=marker): @@ -57,12 +59,15 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: with self.subTest(non_passing=non_passing): self.assertIn(non_passing.casefold(), current.casefold()) for stale in ( + "143 open pull requests", "142 open pull requests", "24 Ready/non-draft", + "138 Draft", "118 Draft", "12 open non-PR issues", "10 central required workflows", "PR #260 is Draft at exact head `56600a6fd982cfafd784f4b7bb659d918113ca90`", + "PR #281 remains Draft at exact head `3ed5d7e8cf77547c96feff2cfb24c46d74a73ebb`", ): with self.subTest(stale=stale): self.assertNotIn(stale, current) @@ -103,12 +108,12 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "143 open pull requests (5 ready, 138 draft)" + expected = "145 open pull requests (5 ready, 140 draft)" self.assertIn(expected, preamble) self.assertIn("13 open non-PR issues", preamble) self.assertIn(expected, added) self.assertIn("13 open non-PR issues", added) - self.assertNotIn("142 open pull requests", preamble) + self.assertNotIn("143 open pull requests", preamble) self.assertNotIn("108 open pull requests (24 ready, 84 draft)", preamble) def test_current_snapshot_records_recent_stack_merges_and_revalidation(self) -> None: From 5d58b984575ecc2b8892f12007a562be83839f0c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 07:06:41 +0900 Subject: [PATCH 063/250] docs(gap): refresh live queue inventory to 145 PRs --- CHANGELOG.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 2074fba89..c7fc8a176 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,10 +4,10 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] -- Refreshed the product-gap queue to 143 open pull requests (5 ready, 138 draft) and 13 open non-PR issues on 2026-09-03; queue movement is active-PR evidence, not protected-main shipment. +- Refreshed the product-gap queue to 145 open pull requests (5 ready, 140 draft) and 13 open non-PR issues on 2026-09-03; queue movement is active-PR evidence, not protected-main shipment. ### Added -- Revalidated the product-gap queue at 143 open pull requests (5 ready, 138 draft) and 13 open non-PR issues on 2026-09-03; protected `main` remains `c789b802fc98a8d7fd8c09d9327f36828054d2a1`, presentation-identity PR #229 is Draft at `7ae426e760e8351ee792ce9df4266d7e7483d0d4`, WebDriver BiDi document-advance PR #260 is Draft at `a3741389fdc491c7ecccc20f77609c55bc56d20f`, and sandbox-enabled Agent Task evidence PR #70 is Draft at `ba8926eed5a6d783f781684f30c900919eecd52b`. Current-head checks remain independently required; no protected-main shipment is claimed. +- Revalidated the product-gap queue at 145 open pull requests (5 ready, 140 draft) and 13 open non-PR issues on 2026-09-03; protected `main` remains `c789b802fc98a8d7fd8c09d9327f36828054d2a1`, presentation-identity PR #229 is Draft at `7ae426e760e8351ee792ce9df4266d7e7483d0d4`, WebDriver BiDi document-advance PR #260 is Draft at `a3741389fdc491c7ecccc20f77609c55bc56d20f`, and sandbox-enabled Agent Task evidence PR #70 is Draft at `ba8926eed5a6d783f781684f30c900919eecd52b`. Current-head checks remain independently required; no protected-main shipment is claimed. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. @@ -115,4 +115,4 @@ All notable changes to OriginWeave are documented in this file. The format follo - The hourly product agent has no Git metadata or repository authority. A separate post-verification publisher opens one PR and cannot approve or merge it. - The unprivileged OpenCode user is restricted to loopback egress during model execution, preventing runner-wide allow-listed endpoints from becoming direct source-exfiltration channels. -[Unreleased]: https://github.com/ContextualWisdomLab/OriginWeave/compare/main...HEAD +[Unreleased]: https://github.com/ContextualWisdomLab/OriginWeave/compare/main...HEAD \ No newline at end of file From 38fe063348d64df2c496f640bd12719bc35878e7 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 07:10:22 +0900 Subject: [PATCH 064/250] docs(gap): refresh volatile live delivery state --- docs/product-technical-gap-baseline.md | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 80283a76b..1af28f6ed 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,17 +6,19 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-03T18:05:00Z`. +Observed at (UTC): `2026-09-03T22:01:21Z`. - Protected `main` is `c789b802fc98a8d7fd8c09d9327f36828054d2a1` through #280. #280 restored repository-native CI for documentation changes after #278's `paths-ignore` created a documentation-contract verification gap. -- Full live search returns **143 open pull requests: 5 Ready/non-draft and 138 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. +- Full live search returns **145 open pull requests: 5 Ready/non-draft and 140 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **9 central required workflows**: `close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, `scorecard-pr`, and `osv-scanner-pr`. `codeql-pr` is not in the active required-workflow set. Administrative bypass capability is not authorization to use it. - Issue #279 owns the remaining documentation-CI partitioning gap. Correctness is restored on protected main, but the repository's Rust-contract job still couples Python documentation/traceability contracts with Rust-heavy verification, so prose-only changes cannot yet retain exact-head documentation validation while avoiding unnecessary Rust queue load. - Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `a3741389fdc491c7ecccc20f77609c55bc56d20f` on #259 base `dd3c0493d5a1a70c8c51524d38ff9c0553434f6f`; its browser/navigation behavior repair has current-head CI still non-terminal. PR #261 remains stale-parent Draft at exact head `127e02503e48938e29a9a07410574c7e72fc661a`; its declared base is an older #260 generation, while live #260 has advanced to `a3741389fdc491c7ecccc20f77609c55bc56d20f`, so the child must be reconstructed parent-first rather than force-rebased or promoted from predecessor evidence. - PR #70 is Draft at exact head `ba8926eed5a6d783f781684f30c900919eecd52b`, current with protected main. Its focused Agent Task contract proves the pre-repair `--no-sandbox` launch as source RED and the branch removes that argument only from the Agent Task lane. Sandbox-enabled pinned-Chromium E2E and repository-wide GREEN remain unproven while its exact-head browser/CI/security runs are queued. - DDD/MCP repair #272 is Draft at exact head `80272f18422c9946077ad9bd674f603db8f020da`. It preserves MCP as an adapter, contains an observed hosted RED for missing stdio constructors, and carries the bounded adapter-local repair; it remains active-PR evidence until exact-current CI, coverage, rustdoc, review, and security gates complete. - PR #229 is Draft at exact head `7ae426e760e8351ee792ce9df4266d7e7483d0d4`. Test-only predecessor `ffd91290479c77ff1d675d4520e1776c990ba4d5` required a narrow presentation-identity changelog statement after the feature lane correctly relinquished volatile baseline ownership; the current repair adds exactly that feature-local entry while retaining the boundary that Chromium application and page-observed effectiveness remain separate adapter/browser-E2E work. Current-head CI/security runs remain non-terminal. -- PR #281 remains Draft at exact head `3ed5d7e8cf77547c96feff2cfb24c46d74a73ebb`. It redacts browser/page-derived HTTP, WebDriver, DOM-dataset, and click-post-condition diagnostic values before CI/audit evidence; predecessor and source-level focused checks are not promoted to repository-wide GREEN while current hosted runs remain queued. +- PR #281 remains Draft at exact head `e96c982b6ed7ff7b80891bd60efc5d443555d4b6`. It redacts browser/page-derived HTTP and WebDriver protocol data, startup exception details, returned capability values, DOM-dataset values, and click post-condition text before CI/audit evidence; predecessor and source-level focused checks are not promoted to repository-wide GREEN while exact-current hosted runs remain queued. +- PR #282 is Draft at exact head `51a1e819355306e630d1241e6e5a136cb195325e`. It contains the fail-closed `git diff --name-status -z` classifier and RED contract, including rename/copy preimage preservation, but no `.github/**` change; an authorized non-scheduled workflow owner must connect that contract to the protected-main CI partition. +- PR #283 is Draft at exact head `3cefce69a7bc71e33ad64c5e8f58a0afe0b5f7e1` stacked on #282. Its exact parent compare is one prose-only doctoring canary, yet the exact head still materializes both Rust contracts and Production coverage. That is trigger-shape RED evidence for #279; runner admission remains a separate condition. - PR #43 is Draft at exact head `e5db34c57d7b1de61d613a196117ca2cce296bec` on current protected main. Its product/test/docs delta contains no `.github/**` mutation, and its current `_run_browser_pass` Chrome options do not disable the Chromium sandbox. Exact-head Manifest V3 and repository/security workflows remain queued, so sandbox-enabled real-browser compatibility is still required before promotion. - PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `adc040a93be2533e15fabc4ca02deec1c5562d1d`. Source presence is not publication evidence; a fresh public search still does not establish an OriginWeave project Pages deployment. Live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. - Issue #201's release/SBOM lane remains dependency ordered, and GitHub Releases is empty. OriginWeave remains pre-GA until exact protected-head versioning, signed artifacts, SBOM/provenance, reproducibility, rollback, compatibility, security, and commercial-acceptance evidence exist. @@ -414,4 +416,4 @@ done The branch-scoped rules response determines the active rules affecting `main`; each PR's exact `HEAD_SHA` then determines which check runs, legacy statuses, workflow runs, reviews, and unresolved threads are current. The saved merge verdict binds counted approvals to the latest review per eligible collaborator, excludes the PR author, and requires `APPROVED` on the exact head. It deliberately does **not** infer GitHub's actual last-push actor from commit author or committer metadata: when `require_last_push_approval` is active, this portable evidence procedure records `github_rule_evaluation_required` and keeps `approval_gate_satisfied` false until GitHub's authoritative rule evaluation is consulted. The saved PR JSON also preserves the exact base reference and branch ancestry input for the dependency graph. Evidence is retained only when both `RECHECKED_HEAD_SHA` and `RECHECKED_BASE_SHA` match the collected values; a moving head or base discards the temporary verdict, and three failed attempts leave no unstable merge verdict. -For standards and binding architecture, use [`doctoring.md`](doctoring.md), [`doctoring/browser-agent-protocols.md`](doctoring/browser-agent-protocols.md), [`PRD.md`](PRD.md), [`TRD.md`](TRD.md), [`product-roadmap.md`](product-roadmap.md), and linked ADR/UML/ERD/traceability records. Issues #199-#203 contain their own APA 7th standards and research traceability. This baseline intentionally records delivery state and never promotes planned adapters or active pull-request code to implemented behavior. +For standards and binding architecture, use [`doctoring.md`](doctoring.md), [`doctoring/browser-agent-protocols.md`](doctoring/browser-agent-protocols.md), [`PRD.md`](PRD.md), [`TRD.md`](TRD.md), [`product-roadmap.md`](product-roadmap.md), and linked ADR/UML/ERD/traceability records. Issues #199-#203 contain their own APA 7th standards and research traceability. This baseline intentionally records delivery state and never promotes planned adapters or active pull-request code to implemented behavior. \ No newline at end of file From e7ff628c4dfa24863123af55bdb59a440881e7bd Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 07:18:12 +0900 Subject: [PATCH 065/250] test(gap): bind MV3 diagnostic child to canonical parent --- tests/test_gap_snapshot_inventory_consistency.py | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 130230e52..caee81904 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -41,7 +41,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #70 is Draft at exact head `ba8926eed5a6d783f781684f30c900919eecd52b`", "DDD/MCP repair #272 is Draft at exact head `80272f18422c9946077ad9bd674f603db8f020da`", "PR #229 is Draft at exact head `7ae426e760e8351ee792ce9df4266d7e7483d0d4`", - "PR #281 remains Draft at exact head `e96c982b6ed7ff7b80891bd60efc5d443555d4b6`", + "PR #281 remains Draft at exact head `0b1ddf37aa7ff017ef0974b5304cd0ba30630231`", "PR #282 is Draft at exact head `51a1e819355306e630d1241e6e5a136cb195325e`", "PR #283 is Draft at exact head `3cefce69a7bc71e33ad64c5e8f58a0afe0b5f7e1`", "GitHub Releases is empty", @@ -68,6 +68,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "10 central required workflows", "PR #260 is Draft at exact head `56600a6fd982cfafd784f4b7bb659d918113ca90`", "PR #281 remains Draft at exact head `3ed5d7e8cf77547c96feff2cfb24c46d74a73ebb`", + "PR #281 remains Draft at exact head `e96c982b6ed7ff7b80891bd60efc5d443555d4b6`", ): with self.subTest(stale=stale): self.assertNotIn(stale, current) From cebd8798637bba97e0ca5da1ac878923caadc192 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 07:19:46 +0900 Subject: [PATCH 066/250] chore(gap): keep live-head drift non-destructive Revert the transient #281 exact-head assertion until the large durable baseline can be changed with the same historical suffix preserved. The live PR body records the new child head; do not leave an intentionally RED repository contract on the branch. --- tests/test_gap_snapshot_inventory_consistency.py | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index caee81904..130230e52 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -41,7 +41,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #70 is Draft at exact head `ba8926eed5a6d783f781684f30c900919eecd52b`", "DDD/MCP repair #272 is Draft at exact head `80272f18422c9946077ad9bd674f603db8f020da`", "PR #229 is Draft at exact head `7ae426e760e8351ee792ce9df4266d7e7483d0d4`", - "PR #281 remains Draft at exact head `0b1ddf37aa7ff017ef0974b5304cd0ba30630231`", + "PR #281 remains Draft at exact head `e96c982b6ed7ff7b80891bd60efc5d443555d4b6`", "PR #282 is Draft at exact head `51a1e819355306e630d1241e6e5a136cb195325e`", "PR #283 is Draft at exact head `3cefce69a7bc71e33ad64c5e8f58a0afe0b5f7e1`", "GitHub Releases is empty", @@ -68,7 +68,6 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "10 central required workflows", "PR #260 is Draft at exact head `56600a6fd982cfafd784f4b7bb659d918113ca90`", "PR #281 remains Draft at exact head `3ed5d7e8cf77547c96feff2cfb24c46d74a73ebb`", - "PR #281 remains Draft at exact head `e96c982b6ed7ff7b80891bd60efc5d443555d4b6`", ): with self.subTest(stale=stale): self.assertNotIn(stale, current) From 31f70c3e709086d5495f47439b67a8566b153dd1 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 15:24:23 +0900 Subject: [PATCH 067/250] docs: refresh live OriginWeave delivery state --- docs/product-technical-gap-baseline.md | 21 ++++++++++----------- 1 file changed, 10 insertions(+), 11 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 1af28f6ed..40c3e1ce1 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,21 +6,20 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-03T22:01:21Z`. +Observed at (UTC): `2026-09-04T06:19:00Z`. - Protected `main` is `c789b802fc98a8d7fd8c09d9327f36828054d2a1` through #280. #280 restored repository-native CI for documentation changes after #278's `paths-ignore` created a documentation-contract verification gap. - Full live search returns **145 open pull requests: 5 Ready/non-draft and 140 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. -- Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **9 central required workflows**: `close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, `scorecard-pr`, and `osv-scanner-pr`. `codeql-pr` is not in the active required-workflow set. Administrative bypass capability is not authorization to use it. -- Issue #279 owns the remaining documentation-CI partitioning gap. Correctness is restored on protected main, but the repository's Rust-contract job still couples Python documentation/traceability contracts with Rust-heavy verification, so prose-only changes cannot yet retain exact-head documentation validation while avoiding unnecessary Rust queue load. +- Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, and `noema-review`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. +- Issue #279 owns the remaining documentation-CI partitioning gap. PR #282 is Draft at exact head `bd7046f1dbec5e26f49e68c624ebb911c4c8e674`; it contains the fail-closed mode/OID/status/path classifier contract, requires Git-canonical repository path spelling, and treats `AGENTS.md`, `CLAUDE.md`, and `GEMINI.md` as contributor/agent-instruction authority. Current GitHub Copilot instruction surfaces under `.github/**` are also outside the prose allow-surface. An authorized non-scheduled workflow owner must connect a trusted protected-base/immutable-SHA classifier to exact base/head raw evidence rather than execute mutable PR-head classification authority. +- PR #283 is Draft at exact head `6139da8b91858c881f299c5fe2a50d6c1f0a235a`, non-force stacked on #282 exact `bd7046f1dbec5e26f49e68c624ebb911c4c8e674`. Its exact parent compare is one prose-only doctoring canary (+7/-0), yet CI `33843743684` still materializes Production coverage `100931119974` and Rust contracts `100931120197`, both runner-less queued. That remains trigger-shape RED for #279; runner admission is a separate condition. - Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `a3741389fdc491c7ecccc20f77609c55bc56d20f` on #259 base `dd3c0493d5a1a70c8c51524d38ff9c0553434f6f`; its browser/navigation behavior repair has current-head CI still non-terminal. PR #261 remains stale-parent Draft at exact head `127e02503e48938e29a9a07410574c7e72fc661a`; its declared base is an older #260 generation, while live #260 has advanced to `a3741389fdc491c7ecccc20f77609c55bc56d20f`, so the child must be reconstructed parent-first rather than force-rebased or promoted from predecessor evidence. -- PR #70 is Draft at exact head `ba8926eed5a6d783f781684f30c900919eecd52b`, current with protected main. Its focused Agent Task contract proves the pre-repair `--no-sandbox` launch as source RED and the branch removes that argument only from the Agent Task lane. Sandbox-enabled pinned-Chromium E2E and repository-wide GREEN remain unproven while its exact-head browser/CI/security runs are queued. +- PR #70 is Draft at exact head `ba8926eed5a6d783f781684f30c900919eecd52b`, current with protected main. Its focused Agent Task contract proves the pre-repair `--no-sandbox` launch as source RED and the branch removes that argument only from the Agent Task lane. Sandbox-enabled pinned-Chromium E2E and repository-wide GREEN remain unproven while its exact-head browser/CI/security runs are non-passing. - DDD/MCP repair #272 is Draft at exact head `80272f18422c9946077ad9bd674f603db8f020da`. It preserves MCP as an adapter, contains an observed hosted RED for missing stdio constructors, and carries the bounded adapter-local repair; it remains active-PR evidence until exact-current CI, coverage, rustdoc, review, and security gates complete. - PR #229 is Draft at exact head `7ae426e760e8351ee792ce9df4266d7e7483d0d4`. Test-only predecessor `ffd91290479c77ff1d675d4520e1776c990ba4d5` required a narrow presentation-identity changelog statement after the feature lane correctly relinquished volatile baseline ownership; the current repair adds exactly that feature-local entry while retaining the boundary that Chromium application and page-observed effectiveness remain separate adapter/browser-E2E work. Current-head CI/security runs remain non-terminal. -- PR #281 remains Draft at exact head `e96c982b6ed7ff7b80891bd60efc5d443555d4b6`. It redacts browser/page-derived HTTP and WebDriver protocol data, startup exception details, returned capability values, DOM-dataset values, and click post-condition text before CI/audit evidence; predecessor and source-level focused checks are not promoted to repository-wide GREEN while exact-current hosted runs remain queued. -- PR #282 is Draft at exact head `51a1e819355306e630d1241e6e5a136cb195325e`. It contains the fail-closed `git diff --name-status -z` classifier and RED contract, including rename/copy preimage preservation, but no `.github/**` change; an authorized non-scheduled workflow owner must connect that contract to the protected-main CI partition. -- PR #283 is Draft at exact head `3cefce69a7bc71e33ad64c5e8f58a0afe0b5f7e1` stacked on #282. Its exact parent compare is one prose-only doctoring canary, yet the exact head still materializes both Rust contracts and Production coverage. That is trigger-shape RED evidence for #279; runner admission remains a separate condition. -- PR #43 is Draft at exact head `e5db34c57d7b1de61d613a196117ca2cce296bec` on current protected main. Its product/test/docs delta contains no `.github/**` mutation, and its current `_run_browser_pass` Chrome options do not disable the Chromium sandbox. Exact-head Manifest V3 and repository/security workflows remain queued, so sandbox-enabled real-browser compatibility is still required before promotion. -- PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `adc040a93be2533e15fabc4ca02deec1c5562d1d`. Source presence is not publication evidence; a fresh public search still does not establish an OriginWeave project Pages deployment. Live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. +- PR #281 remains Draft at exact head `0b1ddf37aa7ff017ef0974b5304cd0ba30630231` on canonical MV3 parent #43 `e5db34c57d7b1de61d613a196117ca2cce296bec`. Its child delta is diagnostic-evidence contract/doctoring only; inherited #43 implementation redacts browser/page-derived HTTP and WebDriver protocol data, startup exception details, returned capability values, DOM-dataset values, and click post-condition text before CI/audit evidence. No child GREEN is claimed while parent-first verification remains open. +- PR #43 is Draft at exact head `e5db34c57d7b1de61d613a196117ca2cce296bec` on current protected main and has a real hosted RED. CI `33740544401` fails repository contracts because the workflow does not install/configure the pinned `chrome_sandbox`, while Production coverage `100601171026` independently succeeds. Manifest V3 `33740544442` / job `100601170874` downloads Chrome/ChromeDriver `150.0.7871.129` and fails all three sandbox-preserving real-browser trials as `session not created`, repeatability `0/3`. Issue #212 owns the authorized workflow repair; restoring `--no-sandbox` is not acceptable. +- PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `adc040a93be2533e15fabc4ca02deec1c5562d1d`. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. - Issue #201's release/SBOM lane remains dependency ordered, and GitHub Releases is empty. OriginWeave remains pre-GA until exact protected-head versioning, signed artifacts, SBOM/provenance, reproducibility, rollback, compatibility, security, and commercial-acceptance evidence exist. - The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #28 the first complete Chromium Agent Task vertical slice, #199 durable WARC/PROV and retention/replay, #200 stable BAP/MCP runtime API, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 enterprise identity/tenant/policy/approval/audit/SLO operations, #203 exact-artifact commercial acceptance, #276 contextual-orchestrator migration, and #279 exact-head documentation verification without unnecessary Rust queue load. - Current evidence procedure remains fail-closed: queued reviewer evidence is non-passing; paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. @@ -45,7 +44,7 @@ This snapshot re-fetched the complete open-PR inventory, the protected `main` co During this recheck, #71, #154, #233, #234, and #235 were merged only into their unprotected feature-parent branches after exact current-head checks and review-thread resolution. Their successful stack checks are not protected-main delivery, and their child branches retain independent evidence requirements. -The sensitive-data child slice #53 was subsequently squash-merged into the unprotected #46 feature branch at merge commit `93c713a107df05385f745db4dca20091f21c4a3` after exact-head Rust/coverage checks passed and current inline review threads were resolved. PR #46 remains an active main-targeting parent. Its current exact base/head pair is protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413` to `373113119446d99f578febd39efc19366e7736b1`; the head adds the ADR 0007 predicate-boundary clarification and regression contract, with local Python/Rust verification green. Current hosted evidence remains incomplete: automatic OpenCode run `33189822385` / job `98913006386` failed closed without a current-head verdict, and central Strix run `33190794267` / job `98915422837` failed closed after three provider HTTP 500 attempts without a vulnerability report. A direct central `opencode-review` dispatch run `33192478312` / job `98921183278` was rejected because repository_dispatch actor `seonghobae` did not match configured scheduler identity `github-actions[bot]`; no qualifying non-author approval is present. +The sensitive-data child slice #53 was subsequently squash-merged into the unprotected #46 feature branch at merge commit `93c713a107df05385f745db4dca20091f21c4a3` after exact PR head `6b8a3fdeae52ad94b90086bbc9b42863b90c9614`. PR #46 remains an active main-targeting parent. Its current exact base/head pair is protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413` to `373113119446d99f578febd39efc19366e7736b1`; the head adds the ADR 0007 predicate-boundary clarification and regression contract, with local Python/Rust verification green. Current hosted evidence remains incomplete: automatic OpenCode run `33189822385` / job `98913006386` failed closed without a current-head verdict, and central Strix run `33190794267` / job `98915422837` failed closed after three provider HTTP 500 attempts without a vulnerability report. A direct central `opencode-review` dispatch run `33192478312` / job `98921183278` was rejected because repository_dispatch actor `seonghobae` did not match configured scheduler identity `github-actions[bot]`; no qualifying non-author approval is present. The WARC/PROV child slice #217 was squash-merged into the unprotected #210 feature branch at merge commit `66f360ccac5cec60c72222cc79d58e39f6f00088` from exact PR head `6b8a3fdeae52ad94b90086bbc9b42863b90c9614`. PR #210 subsequently advanced to current exact head `7946dce9a3dd074047d93fca299d48c7aef40e47` after its merged-child attribution repair, recursively encoded-control repair, and exact coverage repair; this stack remains active-PR evidence and not protected-main delivery or approval evidence. @@ -149,7 +148,7 @@ The following rows were current on 2026-08-24 and are retained only as regressio | #222 | Draft | `56fcfa56525e4f2e980e0ee05b6776d621bcddc5` | `1e2ce3d4071a1a75ee891bdcd71c506b3b50d4bc` | | #221 | Draft | `8145d40f1b028a8f4dc7e7da47ac89bb9e5bb2c7` | `6f339df1e5b3ddb265f4ddd7b262d4de1e0b5e1f` | | #220 | Ready | `0841d2ab3d8b5e60a03c0a8e818cf438e2716829` | `ed4cab16cf88c76ce1c145a22d0a274ef2d57263` | -| #219 | Ready | `0841d2ab3d8b5e60a03c0a8e818cf438e2716829` | `8145d40f1b028a8f4dc7e7da47ac89bb9e5bb2c7` | +| #219 | Ready | `0841d2ab3d8b5e60a03c0a8e818cf438e2716829` | `8145d40f1b028a8f4ddd7b262d4de1e0b5e1e1f` | | #218 | Ready | `0841d2ab3d8b5e60a03c0a8e818cf438e2716829` | `49e98fba6974219b3bb0336c822b12667f1e1c03` | | #216 | Ready | `0841d2ab3d8b5e60a03c0a8e818cf438e2716829` | `75130851a0f7ce528a7a36382eb026ac7942a0aa` | | #214 | Draft | `40d642d5470a7753b8211907c190367f742f2f12` | `f79999681866ecf0e5fe17d895170f3f6cae7361` | From 7d8406d5bdaf9c00cb8427413fe84308b298b93d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 20:40:19 +0900 Subject: [PATCH 068/250] fix(docs): align live gap evidence contracts Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 12 ++++++------ ...test_documentation_active_pr_evidence_contract.py | 6 +++--- tests/test_gap_snapshot_inventory_consistency.py | 8 ++++---- 3 files changed, 13 insertions(+), 13 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 40c3e1ce1..a280fe619 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,19 +6,19 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T06:19:00Z`. +Observed at (UTC): `2026-09-04T11:39:56Z`. - Protected `main` is `c789b802fc98a8d7fd8c09d9327f36828054d2a1` through #280. #280 restored repository-native CI for documentation changes after #278's `paths-ignore` created a documentation-contract verification gap. - Full live search returns **145 open pull requests: 5 Ready/non-draft and 140 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, and `noema-review`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. -- Issue #279 owns the remaining documentation-CI partitioning gap. PR #282 is Draft at exact head `bd7046f1dbec5e26f49e68c624ebb911c4c8e674`; it contains the fail-closed mode/OID/status/path classifier contract, requires Git-canonical repository path spelling, and treats `AGENTS.md`, `CLAUDE.md`, and `GEMINI.md` as contributor/agent-instruction authority. Current GitHub Copilot instruction surfaces under `.github/**` are also outside the prose allow-surface. An authorized non-scheduled workflow owner must connect a trusted protected-base/immutable-SHA classifier to exact base/head raw evidence rather than execute mutable PR-head classification authority. -- PR #283 is Draft at exact head `6139da8b91858c881f299c5fe2a50d6c1f0a235a`, non-force stacked on #282 exact `bd7046f1dbec5e26f49e68c624ebb911c4c8e674`. Its exact parent compare is one prose-only doctoring canary (+7/-0), yet CI `33843743684` still materializes Production coverage `100931119974` and Rust contracts `100931120197`, both runner-less queued. That remains trigger-shape RED for #279; runner admission is a separate condition. +- Issue #279 owns the remaining documentation-CI partitioning gap. PR #282 is Draft at exact head `06d04b786fc470f821cf2e91c6546cb53d488783`; it contains the fail-closed mode/OID/status/path classifier contract, requires Git-canonical repository path spelling, and treats `AGENTS.md`, `CLAUDE.md`, and `GEMINI.md` as contributor/agent-instruction authority. Current GitHub Copilot instruction surfaces under `.github/**` are also outside the prose allow-surface. An authorized non-scheduled workflow owner must connect a trusted protected-base/immutable-SHA classifier to exact base/head raw evidence rather than execute mutable PR-head classification authority. +- PR #283 is Draft at exact head `74d3ee0e7f15da2f285bd9033360df662536fc60`, non-force stacked on #282 exact `06d04b786fc470f821cf2e91c6546cb53d488783`. Its exact parent compare is one prose-only doctoring canary (+7/-0), yet CI `33843743684` still materializes Production coverage `100931119974` and Rust contracts `100931120197`, both runner-less queued. That remains trigger-shape RED for #279; runner admission is a separate condition. - Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `a3741389fdc491c7ecccc20f77609c55bc56d20f` on #259 base `dd3c0493d5a1a70c8c51524d38ff9c0553434f6f`; its browser/navigation behavior repair has current-head CI still non-terminal. PR #261 remains stale-parent Draft at exact head `127e02503e48938e29a9a07410574c7e72fc661a`; its declared base is an older #260 generation, while live #260 has advanced to `a3741389fdc491c7ecccc20f77609c55bc56d20f`, so the child must be reconstructed parent-first rather than force-rebased or promoted from predecessor evidence. - PR #70 is Draft at exact head `ba8926eed5a6d783f781684f30c900919eecd52b`, current with protected main. Its focused Agent Task contract proves the pre-repair `--no-sandbox` launch as source RED and the branch removes that argument only from the Agent Task lane. Sandbox-enabled pinned-Chromium E2E and repository-wide GREEN remain unproven while its exact-head browser/CI/security runs are non-passing. - DDD/MCP repair #272 is Draft at exact head `80272f18422c9946077ad9bd674f603db8f020da`. It preserves MCP as an adapter, contains an observed hosted RED for missing stdio constructors, and carries the bounded adapter-local repair; it remains active-PR evidence until exact-current CI, coverage, rustdoc, review, and security gates complete. - PR #229 is Draft at exact head `7ae426e760e8351ee792ce9df4266d7e7483d0d4`. Test-only predecessor `ffd91290479c77ff1d675d4520e1776c990ba4d5` required a narrow presentation-identity changelog statement after the feature lane correctly relinquished volatile baseline ownership; the current repair adds exactly that feature-local entry while retaining the boundary that Chromium application and page-observed effectiveness remain separate adapter/browser-E2E work. Current-head CI/security runs remain non-terminal. -- PR #281 remains Draft at exact head `0b1ddf37aa7ff017ef0974b5304cd0ba30630231` on canonical MV3 parent #43 `e5db34c57d7b1de61d613a196117ca2cce296bec`. Its child delta is diagnostic-evidence contract/doctoring only; inherited #43 implementation redacts browser/page-derived HTTP and WebDriver protocol data, startup exception details, returned capability values, DOM-dataset values, and click post-condition text before CI/audit evidence. No child GREEN is claimed while parent-first verification remains open. -- PR #43 is Draft at exact head `e5db34c57d7b1de61d613a196117ca2cce296bec` on current protected main and has a real hosted RED. CI `33740544401` fails repository contracts because the workflow does not install/configure the pinned `chrome_sandbox`, while Production coverage `100601171026` independently succeeds. Manifest V3 `33740544442` / job `100601170874` downloads Chrome/ChromeDriver `150.0.7871.129` and fails all three sandbox-preserving real-browser trials as `session not created`, repeatability `0/3`. Issue #212 owns the authorized workflow repair; restoring `--no-sandbox` is not acceptable. +- PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385` on canonical MV3 parent #43 `6f3134d18d3118aab33d28048671dc71a5f47b77`. Its child delta is diagnostic-evidence contract/doctoring only; inherited #43 implementation redacts browser/page-derived HTTP and WebDriver protocol data, startup exception details, returned capability values, DOM-dataset values, and click post-condition text before CI/audit evidence. No child GREEN is claimed while parent-first verification remains open. +- PR #43 is Draft at exact head `6f3134d18d3118aab33d28048671dc71a5f47b77` on current protected main. The branch now installs and configures the pinned `chrome_sandbox`; exact-head hosted verification remains required, and restoring `--no-sandbox` is not acceptable. - PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `adc040a93be2533e15fabc4ca02deec1c5562d1d`. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. - Issue #201's release/SBOM lane remains dependency ordered, and GitHub Releases is empty. OriginWeave remains pre-GA until exact protected-head versioning, signed artifacts, SBOM/provenance, reproducibility, rollback, compatibility, security, and commercial-acceptance evidence exist. - The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #28 the first complete Chromium Agent Task vertical slice, #199 durable WARC/PROV and retention/replay, #200 stable BAP/MCP runtime API, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 enterprise identity/tenant/policy/approval/audit/SLO operations, #203 exact-artifact commercial acceptance, #276 contextual-orchestrator migration, and #279 exact-head documentation verification without unnecessary Rust queue load. @@ -415,4 +415,4 @@ done The branch-scoped rules response determines the active rules affecting `main`; each PR's exact `HEAD_SHA` then determines which check runs, legacy statuses, workflow runs, reviews, and unresolved threads are current. The saved merge verdict binds counted approvals to the latest review per eligible collaborator, excludes the PR author, and requires `APPROVED` on the exact head. It deliberately does **not** infer GitHub's actual last-push actor from commit author or committer metadata: when `require_last_push_approval` is active, this portable evidence procedure records `github_rule_evaluation_required` and keeps `approval_gate_satisfied` false until GitHub's authoritative rule evaluation is consulted. The saved PR JSON also preserves the exact base reference and branch ancestry input for the dependency graph. Evidence is retained only when both `RECHECKED_HEAD_SHA` and `RECHECKED_BASE_SHA` match the collected values; a moving head or base discards the temporary verdict, and three failed attempts leave no unstable merge verdict. -For standards and binding architecture, use [`doctoring.md`](doctoring.md), [`doctoring/browser-agent-protocols.md`](doctoring/browser-agent-protocols.md), [`PRD.md`](PRD.md), [`TRD.md`](TRD.md), [`product-roadmap.md`](product-roadmap.md), and linked ADR/UML/ERD/traceability records. Issues #199-#203 contain their own APA 7th standards and research traceability. This baseline intentionally records delivery state and never promotes planned adapters or active pull-request code to implemented behavior. \ No newline at end of file +For standards and binding architecture, use [`doctoring.md`](doctoring.md), [`doctoring/browser-agent-protocols.md`](doctoring/browser-agent-protocols.md), [`PRD.md`](PRD.md), [`TRD.md`](TRD.md), [`product-roadmap.md`](product-roadmap.md), and linked ADR/UML/ERD/traceability records. Issues #199-#203 contain their own APA 7th standards and research traceability. This baseline intentionally records delivery state and never promotes planned adapters or active pull-request code to implemented behavior. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 45a98da72..993fb7394 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -80,9 +80,9 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: refresh_lines = [line for line in added.splitlines() if line.startswith(refresh_prefix)] self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] - self.assertIn("on 2026-08-29", refresh_line) - self.assertIn("108 open pull requests (24 ready, 84 draft)", refresh_line) - self.assertIn("11 open issues", refresh_line) + self.assertIn("on 2026-09-03", refresh_line) + self.assertIn("145 open pull requests (5 ready, 140 draft)", refresh_line) + self.assertIn("13 open non-PR issues", refresh_line) self.assertNotIn("- Corrected the 2026-08-28 product-gap snapshot", added) self.assertNotIn("- Revalidated the product-gap queue at", changed) self.assertNotIn("115 open pull requests (31 ready, 84 draft)", refresh_line) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 130230e52..c7cc4e766 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -32,7 +32,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "13 open non-PR issues", "c789b802fc98a8d7fd8c09d9327f36828054d2a1", "18156473", - "9 central required workflows", + "7 central required workflows", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", @@ -41,9 +41,9 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #70 is Draft at exact head `ba8926eed5a6d783f781684f30c900919eecd52b`", "DDD/MCP repair #272 is Draft at exact head `80272f18422c9946077ad9bd674f603db8f020da`", "PR #229 is Draft at exact head `7ae426e760e8351ee792ce9df4266d7e7483d0d4`", - "PR #281 remains Draft at exact head `e96c982b6ed7ff7b80891bd60efc5d443555d4b6`", - "PR #282 is Draft at exact head `51a1e819355306e630d1241e6e5a136cb195325e`", - "PR #283 is Draft at exact head `3cefce69a7bc71e33ad64c5e8f58a0afe0b5f7e1`", + "PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385`", + "PR #282 is Draft at exact head `06d04b786fc470f821cf2e91c6546cb53d488783`", + "PR #283 is Draft at exact head `74d3ee0e7f15da2f285bd9033360df662536fc60`", "GitHub Releases is empty", ): with self.subTest(marker=marker): From 8802d61193e12260419329f8a258571c8ef22590 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 20:43:40 +0900 Subject: [PATCH 069/250] fix(docs): bind baseline to active ruleset Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 2 +- tests/test_gap_snapshot_inventory_consistency.py | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index a280fe619..b3802eef0 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -10,7 +10,7 @@ Observed at (UTC): `2026-09-04T11:39:56Z`. - Protected `main` is `c789b802fc98a8d7fd8c09d9327f36828054d2a1` through #280. #280 restored repository-native CI for documentation changes after #278's `paths-ignore` created a documentation-contract verification gap. - Full live search returns **145 open pull requests: 5 Ready/non-draft and 140 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. -- Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `close-empty-pr`, `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, and `noema-review`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. +- Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **6 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, and `noema-review`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - Issue #279 owns the remaining documentation-CI partitioning gap. PR #282 is Draft at exact head `06d04b786fc470f821cf2e91c6546cb53d488783`; it contains the fail-closed mode/OID/status/path classifier contract, requires Git-canonical repository path spelling, and treats `AGENTS.md`, `CLAUDE.md`, and `GEMINI.md` as contributor/agent-instruction authority. Current GitHub Copilot instruction surfaces under `.github/**` are also outside the prose allow-surface. An authorized non-scheduled workflow owner must connect a trusted protected-base/immutable-SHA classifier to exact base/head raw evidence rather than execute mutable PR-head classification authority. - PR #283 is Draft at exact head `74d3ee0e7f15da2f285bd9033360df662536fc60`, non-force stacked on #282 exact `06d04b786fc470f821cf2e91c6546cb53d488783`. Its exact parent compare is one prose-only doctoring canary (+7/-0), yet CI `33843743684` still materializes Production coverage `100931119974` and Rust contracts `100931120197`, both runner-less queued. That remains trigger-shape RED for #279; runner admission is a separate condition. - Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `a3741389fdc491c7ecccc20f77609c55bc56d20f` on #259 base `dd3c0493d5a1a70c8c51524d38ff9c0553434f6f`; its browser/navigation behavior repair has current-head CI still non-terminal. PR #261 remains stale-parent Draft at exact head `127e02503e48938e29a9a07410574c7e72fc661a`; its declared base is an older #260 generation, while live #260 has advanced to `a3741389fdc491c7ecccc20f77609c55bc56d20f`, so the child must be reconstructed parent-first rather than force-rebased or promoted from predecessor evidence. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index c7cc4e766..848423f03 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -32,7 +32,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "13 open non-PR issues", "c789b802fc98a8d7fd8c09d9327f36828054d2a1", "18156473", - "7 central required workflows", + "6 central required workflows", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", From 80964375911ea755876c489eabd1685008d2f47d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 20:44:38 +0900 Subject: [PATCH 070/250] docs: record final live evidence timestamp Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b3802eef0..9320db484 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,7 +6,7 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T11:39:56Z`. +Observed at (UTC): `2026-09-04T11:44:26Z`. - Protected `main` is `c789b802fc98a8d7fd8c09d9327f36828054d2a1` through #280. #280 restored repository-native CI for documentation changes after #278's `paths-ignore` created a documentation-contract verification gap. - Full live search returns **145 open pull requests: 5 Ready/non-draft and 140 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. From 54945426b71c54c1e7a3fed35ac6b1c299a089df Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 20:46:51 +0900 Subject: [PATCH 071/250] docs: record required workflow correction Signed-off-by: Seongho Bae --- CHANGELOG.md | 4 +++- tests/test_documentation_active_pr_evidence_contract.py | 4 ++++ 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index c7fc8a176..a7f45a98f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -61,6 +61,8 @@ All notable changes to OriginWeave are documented in this file. The format follo ### Changed +- Corrected the active ruleset inventory to 6 required workflows from the live branch-rules API; `close-empty-pr` remains useful repository automation but is not a current protected-main requirement. + - Aligned the hourly product-development branch-coverage toolchain and its one-shot materializer with the reviewed `nightly-2026-08-18` pin, and corrected the official Dependabot Rust-toolchain reference. - Separated logical origin authority from resolved network destination authority; an origin grant no longer implies permission to connect to every resolver result. - Separated resolved-address authorization from direct transport evidence; an approved IP now becomes a usable stream only after the operating system reports the exact requested IP and port. @@ -115,4 +117,4 @@ All notable changes to OriginWeave are documented in this file. The format follo - The hourly product agent has no Git metadata or repository authority. A separate post-verification publisher opens one PR and cannot approve or merge it. - The unprivileged OpenCode user is restricted to loopback egress during model execution, preventing runner-wide allow-listed endpoints from becoming direct source-exfiltration channels. -[Unreleased]: https://github.com/ContextualWisdomLab/OriginWeave/compare/main...HEAD \ No newline at end of file +[Unreleased]: https://github.com/ContextualWisdomLab/OriginWeave/compare/main...HEAD diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 993fb7394..accc50494 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -83,6 +83,10 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertIn("on 2026-09-03", refresh_line) self.assertIn("145 open pull requests (5 ready, 140 draft)", refresh_line) self.assertIn("13 open non-PR issues", refresh_line) + self.assertIn( + "Corrected the active ruleset inventory to 6 required workflows", + changed, + ) self.assertNotIn("- Corrected the 2026-08-28 product-gap snapshot", added) self.assertNotIn("- Revalidated the product-gap queue at", changed) self.assertNotIn("115 open pull requests (31 ready, 84 draft)", refresh_line) From 8ce9ac552a6af09bc40406f8ca7f6742d1067cef Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 20:59:35 +0900 Subject: [PATCH 072/250] fix(docs): make live inventory reproducible Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 12 +++++++++--- ...test_documentation_active_pr_evidence_contract.py | 1 + tests/test_gap_snapshot_inventory_consistency.py | 8 ++++++++ tests/test_product_completion_gap_contract.py | 4 ++++ 5 files changed, 23 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index a7f45a98f..8e45b0829 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -61,6 +61,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ### Changed +- Made the open non-PR issue count reproducible in the baseline evidence procedure and corrected the historical exact heads for PRs #53 and #217. - Corrected the active ruleset inventory to 6 required workflows from the live branch-rules API; `close-empty-pr` remains useful repository automation but is not a current protected-main requirement. - Aligned the hourly product-development branch-coverage toolchain and its one-shot materializer with the reviewed `nightly-2026-08-18` pin, and corrected the official Dependabot Rust-toolchain reference. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 9320db484..8d55b98bd 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -44,9 +44,9 @@ This snapshot re-fetched the complete open-PR inventory, the protected `main` co During this recheck, #71, #154, #233, #234, and #235 were merged only into their unprotected feature-parent branches after exact current-head checks and review-thread resolution. Their successful stack checks are not protected-main delivery, and their child branches retain independent evidence requirements. -The sensitive-data child slice #53 was subsequently squash-merged into the unprotected #46 feature branch at merge commit `93c713a107df05385f745db4dca20091f21c4a3` after exact PR head `6b8a3fdeae52ad94b90086bbc9b42863b90c9614`. PR #46 remains an active main-targeting parent. Its current exact base/head pair is protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413` to `373113119446d99f578febd39efc19366e7736b1`; the head adds the ADR 0007 predicate-boundary clarification and regression contract, with local Python/Rust verification green. Current hosted evidence remains incomplete: automatic OpenCode run `33189822385` / job `98913006386` failed closed without a current-head verdict, and central Strix run `33190794267` / job `98915422837` failed closed after three provider HTTP 500 attempts without a vulnerability report. A direct central `opencode-review` dispatch run `33192478312` / job `98921183278` was rejected because repository_dispatch actor `seonghobae` did not match configured scheduler identity `github-actions[bot]`; no qualifying non-author approval is present. +The sensitive-data child slice #53 was subsequently squash-merged into the unprotected #46 feature branch at merge commit `93c713a107df05385f745db4dca20091f21c4a3`; #53 was exact head `4ecc81e59ae7bc3a640e65e2442bf30c079bd94c`. PR #46 remains an active main-targeting parent. Its current exact base/head pair is protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413` to `373113119446d99f578febd39efc19366e7736b1`; the head adds the ADR 0007 predicate-boundary clarification and regression contract, with local Python/Rust verification green. Current hosted evidence remains incomplete: automatic OpenCode run `33189822385` / job `98913006386` failed closed without a current-head verdict, and central Strix run `33190794267` / job `98915422837` failed closed after three provider HTTP 500 attempts without a vulnerability report. A direct central `opencode-review` dispatch run `33192478312` / job `98921183278` was rejected because repository_dispatch actor `seonghobae` did not match configured scheduler identity `github-actions[bot]`; no qualifying non-author approval is present. -The WARC/PROV child slice #217 was squash-merged into the unprotected #210 feature branch at merge commit `66f360ccac5cec60c72222cc79d58e39f6f00088` from exact PR head `6b8a3fdeae52ad94b90086bbc9b42863b90c9614`. PR #210 subsequently advanced to current exact head `7946dce9a3dd074047d93fca299d48c7aef40e47` after its merged-child attribution repair, recursively encoded-control repair, and exact coverage repair; this stack remains active-PR evidence and not protected-main delivery or approval evidence. +The WARC/PROV child slice #217 was squash-merged into the unprotected #210 feature branch at merge commit `66f360ccac5cec60c72222cc79d58e39f6f00088`; #217 was exact head `6b8a3fdeae52ad94b90086bbc9b42863b90c9614`. PR #210 subsequently advanced to current exact head `7946dce9a3dd074047d93fca299d48c7aef40e47` after its merged-child attribution repair, recursively encoded-control repair, and exact coverage repair; this stack remains active-PR evidence and not protected-main delivery or approval evidence. The browser-task interruption child slice #67 was squash-merged into the unprotected #64 feature branch at merge commit `5021d142583cb5a8e393248048bb824762a98056` from exact PR head `25ab76e8279d4a904d04afeb264bac3e89f46b45`. PR #64 consequently advanced from `debc761aa59aee1509b7a260474fa33216453511` to current exact head `5021d142583cb5a8e393248048bb824762a98056`; its exact-head hosted checks were regenerating at this snapshot, with no unresolved inline review threads. This stack remains active-PR evidence and not protected-main delivery or approval evidence. @@ -251,7 +251,7 @@ OriginWeave is not complete merely because every low-level primitive exists in s ## Evidence commands -The volatile counts above are reproducible by paginating the complete open-PR inventory, flattening every page, and then inspecting each PR's exact head, checks, reviews, and review threads: +The volatile counts above are reproducible by paginating the complete open-PR and open-issue inventories, excluding pull requests from the issue count, flattening every page, and then inspecting each PR's exact head, checks, reviews, and review threads: ```bash set -euo pipefail @@ -268,6 +268,12 @@ jq '{ draft: (map(select(.draft == true)) | length) }' "$EVIDENCE_DIR/open-prs.json" +gh api --paginate --slurp 'repos/ContextualWisdomLab/OriginWeave/issues?state=open&per_page=100' \ + > "$EVIDENCE_DIR/open-issue-pages.json" +jq '[.[][]] | map(select(has("pull_request") | not)) | { + open_non_pr_issues: length +}' "$EVIDENCE_DIR/open-issue-pages.json" + gh api 'repos/ContextualWisdomLab/OriginWeave/branches/main' \ > "$EVIDENCE_DIR/main-branch.json" gh api --paginate --slurp \ diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index accc50494..59594823a 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -87,6 +87,7 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: "Corrected the active ruleset inventory to 6 required workflows", changed, ) + self.assertIn("Made the open non-PR issue count reproducible", changed) self.assertNotIn("- Corrected the 2026-08-28 product-gap snapshot", added) self.assertNotIn("- Revalidated the product-gap queue at", changed) self.assertNotIn("115 open pull requests (31 ready, 84 draft)", refresh_line) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 848423f03..128a6eae5 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -127,6 +127,14 @@ def test_current_snapshot_records_recent_stack_merges_and_revalidation(self) -> self.assertIn("108 open pull requests", current) self.assertIn("24 non-draft", current) self.assertIn("#217 was squash-merged", record) + self.assertIn( + "#53 was exact head `4ecc81e59ae7bc3a640e65e2442bf30c079bd94c`", + record, + ) + self.assertIn( + "#217 was exact head `6b8a3fdeae52ad94b90086bbc9b42863b90c9614`", + record, + ) self.assertIn("66f360ccac5cec60c72222cc79d58e39f6f00088", record) self.assertIn("#67 was squash-merged", record) self.assertIn("5021d142583cb5a8e393248048bb824762a98056", record) diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index a41c7abda..4cfc7b9f1 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -154,6 +154,10 @@ def test_evidence_commands_reproduce_inventory_checks_and_review_state(self) -> 'EVIDENCE_DIR="$(mktemp -d /tmp/originweave-evidence.XXXXXX)"', '"$EVIDENCE_DIR/open-pr-pages.json"', "jq '[.[][]]' \"$EVIDENCE_DIR/open-pr-pages.json\"", + "--paginate --slurp 'repos/ContextualWisdomLab/OriginWeave/issues?state=open&per_page=100'", + '"$EVIDENCE_DIR/open-issue-pages.json"', + 'map(select(has("pull_request") | not))', + "open_non_pr_issues", '"repos/ContextualWisdomLab/OriginWeave/pulls/$PR"', '"repos/ContextualWisdomLab/OriginWeave/commits/$HEAD_SHA/check-runs?per_page=100"', '"repos/ContextualWisdomLab/OriginWeave/commits/$HEAD_SHA/statuses?per_page=100"', From 037dbbbae8374e4e4baa9be2270147d296afc72d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 21:25:06 +0900 Subject: [PATCH 073/250] docs: correct MCP and historical head claims Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + README.md | 2 +- docs/product-technical-gap-baseline.md | 2 +- tests/test_documentation_fitness_contract.py | 11 +++++++++++ tests/test_product_completion_gap_contract.py | 10 ++++++++++ 5 files changed, 24 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 8e45b0829..9f0e69da1 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,6 +5,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] - Refreshed the product-gap queue to 145 open pull requests (5 ready, 140 draft) and 13 open non-PR issues on 2026-09-03; queue movement is active-PR evidence, not protected-main shipment. +- Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. ### Added - Revalidated the product-gap queue at 145 open pull requests (5 ready, 140 draft) and 13 open non-PR issues on 2026-09-03; protected `main` remains `c789b802fc98a8d7fd8c09d9327f36828054d2a1`, presentation-identity PR #229 is Draft at `7ae426e760e8351ee792ce9df4266d7e7483d0d4`, WebDriver BiDi document-advance PR #260 is Draft at `a3741389fdc491c7ecccc20f77609c55bc56d20f`, and sandbox-enabled Agent Task evidence PR #70 is Draft at `ba8926eed5a6d783f781684f30c900919eecd52b`. Current-head checks remain independently required; no protected-main shipment is claimed. diff --git a/README.md b/README.md index 85706a92c..7ce905774 100644 --- a/README.md +++ b/README.md @@ -40,7 +40,7 @@ The repository is organized as independently consumable Rust crates: - `originweave-resource`: task-level RAM, VRAM, thread, and frame-time budgets with cumulative mitigation plans. - `originweave-evidence`: universally value-redacted network evidence and source-bound provenance records. -Protected main additionally contains an `originweave-core` MCP routing registry and `originweave-policy` binding for the MCP `2026-07-28` `tools/call` and `tools/list` boundaries, merged through PRs #168 and #170. Those shipped foundations validate explicit routing and conservative discovery metadata while preserving normal OriginWeave policy. Neither boundary implements transport parsing, OAuth, browser control, secret materialization, persistence, or ambient authority. +Protected main additionally contains an `originweave-core` MCP routing registry and `originweave-policy` binding for the MCP `2026-07-28` `tools/call` boundary, plus the `originweave-core` `tools/list` discovery contract merged through PR #170. Those shipped foundations validate explicit call routing and conservative discovery metadata without granting discovery any policy authority. Neither boundary implements transport parsing, OAuth, browser control, secret materialization, persistence, or ambient authority. See [ARCHITECTURE.md](ARCHITECTURE.md) and the [architecture decision records](docs/adr/) for binding design decisions. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 8d55b98bd..f2c6ad662 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -148,7 +148,7 @@ The following rows were current on 2026-08-24 and are retained only as regressio | #222 | Draft | `56fcfa56525e4f2e980e0ee05b6776d621bcddc5` | `1e2ce3d4071a1a75ee891bdcd71c506b3b50d4bc` | | #221 | Draft | `8145d40f1b028a8f4dc7e7da47ac89bb9e5bb2c7` | `6f339df1e5b3ddb265f4ddd7b262d4de1e0b5e1f` | | #220 | Ready | `0841d2ab3d8b5e60a03c0a8e818cf438e2716829` | `ed4cab16cf88c76ce1c145a22d0a274ef2d57263` | -| #219 | Ready | `0841d2ab3d8b5e60a03c0a8e818cf438e2716829` | `8145d40f1b028a8f4ddd7b262d4de1e0b5e1e1f` | +| #219 | Ready | `0841d2ab3d8b5e60a03c0a8e818cf438e2716829` | `8145d40f1b028a8f4dc7e7da47ac89bb9e5bb2c7` | | #218 | Ready | `0841d2ab3d8b5e60a03c0a8e818cf438e2716829` | `49e98fba6974219b3bb0336c822b12667f1e1c03` | | #216 | Ready | `0841d2ab3d8b5e60a03c0a8e818cf438e2716829` | `75130851a0f7ce528a7a36382eb026ac7942a0aa` | | #214 | Draft | `40d642d5470a7753b8211907c190367f742f2f12` | `f79999681866ecf0e5fe17d895170f3f6cae7361` | diff --git a/tests/test_documentation_fitness_contract.py b/tests/test_documentation_fitness_contract.py index b628d7cdf..35463789e 100644 --- a/tests/test_documentation_fitness_contract.py +++ b/tests/test_documentation_fitness_contract.py @@ -193,6 +193,17 @@ def test_protected_main_mcp_route_is_indexed_with_executable_evidence(self) -> N (REPOSITORY_ROOT / "crates/originweave-core/tests/mcp_tools_list_cache.rs").is_file() ) + def test_readme_separates_mcp_policy_from_discovery(self) -> None: + """The architecture summary must not claim policy evaluation for discovery.""" + readme = (REPOSITORY_ROOT / "README.md").read_text(encoding="utf-8") + + self.assertIn( + "`originweave-policy` binding for the MCP `2026-07-28` `tools/call` boundary", + readme, + ) + self.assertIn("`originweave-core` `tools/list` discovery contract", readme) + self.assertNotIn("policy` binding for the MCP `2026-07-28` `tools/call` and `tools/list`", readme) + def test_semantic_observation_lane_stays_non_shipped_and_provenance_bound(self) -> None: """The semantic observation value object must stay active-only and distinct from browser I/O.""" appendix = (DOCS_ROOT / "evidence" / "2026-08-10-active-pr-maturity.md").read_text( diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 4cfc7b9f1..fac65e919 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -131,6 +131,16 @@ def test_same_day_prior_inventory_is_bound_to_the_maintenance_record(self) -> No )[0] self.assertIn("115 open pull requests (31 ready, 84 draft)", record) + def test_historical_pr_219_head_is_a_full_exact_sha(self) -> None: + """The retained PR #219 regression anchor must identify its real commit.""" + text = BASELINE.read_text(encoding="utf-8") + + self.assertIn( + "| #219 | Ready | `0841d2ab3d8b5e60a03c0a8e818cf438e2716829` | " + "`8145d40f1b028a8f4dc7e7da47ac89bb9e5bb2c7` |", + text, + ) + def test_issue_table_distinguishes_open_issues_from_governance_signals(self) -> None: """The table total must distinguish product issues from governance signals.""" text = BASELINE.read_text(encoding="utf-8") From a030b8145032d176683f276fc5b0d5098de58d2b Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 21:41:49 +0900 Subject: [PATCH 074/250] docs: refresh documentation CI evidence heads Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 6 +++--- tests/test_gap_snapshot_inventory_consistency.py | 4 ++-- 3 files changed, 6 insertions(+), 5 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 9f0e69da1..d2c7d3933 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,6 +6,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Refreshed the product-gap queue to 145 open pull requests (5 ready, 140 draft) and 13 open non-PR issues on 2026-09-03; queue movement is active-PR evidence, not protected-main shipment. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. +- Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and the remaining rename/copy similarity-binding RED. ### Added - Revalidated the product-gap queue at 145 open pull requests (5 ready, 140 draft) and 13 open non-PR issues on 2026-09-03; protected `main` remains `c789b802fc98a8d7fd8c09d9327f36828054d2a1`, presentation-identity PR #229 is Draft at `7ae426e760e8351ee792ce9df4266d7e7483d0d4`, WebDriver BiDi document-advance PR #260 is Draft at `a3741389fdc491c7ecccc20f77609c55bc56d20f`, and sandbox-enabled Agent Task evidence PR #70 is Draft at `ba8926eed5a6d783f781684f30c900919eecd52b`. Current-head checks remain independently required; no protected-main shipment is claimed. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index f2c6ad662..5f0ea58e9 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,13 +6,13 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T11:44:26Z`. +Observed at (UTC): `2026-09-04T12:41:17Z`. - Protected `main` is `c789b802fc98a8d7fd8c09d9327f36828054d2a1` through #280. #280 restored repository-native CI for documentation changes after #278's `paths-ignore` created a documentation-contract verification gap. - Full live search returns **145 open pull requests: 5 Ready/non-draft and 140 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **6 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, and `noema-review`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. -- Issue #279 owns the remaining documentation-CI partitioning gap. PR #282 is Draft at exact head `06d04b786fc470f821cf2e91c6546cb53d488783`; it contains the fail-closed mode/OID/status/path classifier contract, requires Git-canonical repository path spelling, and treats `AGENTS.md`, `CLAUDE.md`, and `GEMINI.md` as contributor/agent-instruction authority. Current GitHub Copilot instruction surfaces under `.github/**` are also outside the prose allow-surface. An authorized non-scheduled workflow owner must connect a trusted protected-base/immutable-SHA classifier to exact base/head raw evidence rather than execute mutable PR-head classification authority. -- PR #283 is Draft at exact head `74d3ee0e7f15da2f285bd9033360df662536fc60`, non-force stacked on #282 exact `06d04b786fc470f821cf2e91c6546cb53d488783`. Its exact parent compare is one prose-only doctoring canary (+7/-0), yet CI `33843743684` still materializes Production coverage `100931119974` and Rust contracts `100931120197`, both runner-less queued. That remains trigger-shape RED for #279; runner admission is a separate condition. +- Issue #279 owns the remaining documentation-CI partitioning gap. PR #282 is Draft at exact head `b2a120f892973e76c0ea0f06e7105bdf7a268009`; its classifier now requires complete 40-character SHA-1 or 64-character SHA-256 raw-diff object identities. The current test-only head also demonstrates that rename/copy similarity scores still need binding to blob identity before production is complete. Git-canonical paths and contributor/agent-instruction authority remain fail-closed. An authorized non-scheduled workflow owner must connect a trusted protected-base/immutable-SHA classifier to exact base/head raw evidence rather than execute mutable PR-head classification authority. +- PR #283 is Draft at exact head `a9603170e848a7c029531fe75727f02992ade2de`, non-force stacked on #282 exact `b2a120f892973e76c0ea0f06e7105bdf7a268009`. Its exact parent compare remains one prose-only doctoring canary (+7/-0), yet CI `33873850950` materializes Production coverage `101025984879` and Rust contracts `101025985066`, both queued without runner steps at the observation. That remains trigger-shape RED for #279; runner admission is a separate condition. - Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `a3741389fdc491c7ecccc20f77609c55bc56d20f` on #259 base `dd3c0493d5a1a70c8c51524d38ff9c0553434f6f`; its browser/navigation behavior repair has current-head CI still non-terminal. PR #261 remains stale-parent Draft at exact head `127e02503e48938e29a9a07410574c7e72fc661a`; its declared base is an older #260 generation, while live #260 has advanced to `a3741389fdc491c7ecccc20f77609c55bc56d20f`, so the child must be reconstructed parent-first rather than force-rebased or promoted from predecessor evidence. - PR #70 is Draft at exact head `ba8926eed5a6d783f781684f30c900919eecd52b`, current with protected main. Its focused Agent Task contract proves the pre-repair `--no-sandbox` launch as source RED and the branch removes that argument only from the Agent Task lane. Sandbox-enabled pinned-Chromium E2E and repository-wide GREEN remain unproven while its exact-head browser/CI/security runs are non-passing. - DDD/MCP repair #272 is Draft at exact head `80272f18422c9946077ad9bd674f603db8f020da`. It preserves MCP as an adapter, contains an observed hosted RED for missing stdio constructors, and carries the bounded adapter-local repair; it remains active-PR evidence until exact-current CI, coverage, rustdoc, review, and security gates complete. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 128a6eae5..af98f8c96 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -42,8 +42,8 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "DDD/MCP repair #272 is Draft at exact head `80272f18422c9946077ad9bd674f603db8f020da`", "PR #229 is Draft at exact head `7ae426e760e8351ee792ce9df4266d7e7483d0d4`", "PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385`", - "PR #282 is Draft at exact head `06d04b786fc470f821cf2e91c6546cb53d488783`", - "PR #283 is Draft at exact head `74d3ee0e7f15da2f285bd9033360df662536fc60`", + "PR #282 is Draft at exact head `b2a120f892973e76c0ea0f06e7105bdf7a268009`", + "PR #283 is Draft at exact head `a9603170e848a7c029531fe75727f02992ade2de`", "GitHub Releases is empty", ): with self.subTest(marker=marker): From 1ff7436cafd1de1cafcc44e22d6310e235f9d4a5 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 22:59:41 +0900 Subject: [PATCH 075/250] docs: refresh required workflow inventory Bind the volatile gap baseline to the current seven-workflow ruleset while preserving the dated snapshot. Signed-off-by: Seongho Bae --- CHANGELOG.md | 2 +- docs/product-technical-gap-baseline.md | 2 +- tests/test_documentation_active_pr_evidence_contract.py | 3 ++- tests/test_gap_snapshot_inventory_consistency.py | 4 +++- 4 files changed, 7 insertions(+), 4 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index d2c7d3933..92efa5a73 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -64,7 +64,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ### Changed - Made the open non-PR issue count reproducible in the baseline evidence procedure and corrected the historical exact heads for PRs #53 and #217. -- Corrected the active ruleset inventory to 6 required workflows from the live branch-rules API; `close-empty-pr` remains useful repository automation but is not a current protected-main requirement. +- Revalidated the active ruleset inventory at 7 required workflows from the live branch-rules API by adding `codeql-pr`; `close-empty-pr` remains useful repository automation but is not a current protected-main requirement. - Aligned the hourly product-development branch-coverage toolchain and its one-shot materializer with the reviewed `nightly-2026-08-18` pin, and corrected the official Dependabot Rust-toolchain reference. - Separated logical origin authority from resolved network destination authority; an origin grant no longer implies permission to connect to every resolver result. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 5f0ea58e9..651d49747 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -10,7 +10,7 @@ Observed at (UTC): `2026-09-04T12:41:17Z`. - Protected `main` is `c789b802fc98a8d7fd8c09d9327f36828054d2a1` through #280. #280 restored repository-native CI for documentation changes after #278's `paths-ignore` created a documentation-contract verification gap. - Full live search returns **145 open pull requests: 5 Ready/non-draft and 140 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. -- Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **6 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, and `noema-review`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. +- Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - Issue #279 owns the remaining documentation-CI partitioning gap. PR #282 is Draft at exact head `b2a120f892973e76c0ea0f06e7105bdf7a268009`; its classifier now requires complete 40-character SHA-1 or 64-character SHA-256 raw-diff object identities. The current test-only head also demonstrates that rename/copy similarity scores still need binding to blob identity before production is complete. Git-canonical paths and contributor/agent-instruction authority remain fail-closed. An authorized non-scheduled workflow owner must connect a trusted protected-base/immutable-SHA classifier to exact base/head raw evidence rather than execute mutable PR-head classification authority. - PR #283 is Draft at exact head `a9603170e848a7c029531fe75727f02992ade2de`, non-force stacked on #282 exact `b2a120f892973e76c0ea0f06e7105bdf7a268009`. Its exact parent compare remains one prose-only doctoring canary (+7/-0), yet CI `33873850950` materializes Production coverage `101025984879` and Rust contracts `101025985066`, both queued without runner steps at the observation. That remains trigger-shape RED for #279; runner admission is a separate condition. - Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `a3741389fdc491c7ecccc20f77609c55bc56d20f` on #259 base `dd3c0493d5a1a70c8c51524d38ff9c0553434f6f`; its browser/navigation behavior repair has current-head CI still non-terminal. PR #261 remains stale-parent Draft at exact head `127e02503e48938e29a9a07410574c7e72fc661a`; its declared base is an older #260 generation, while live #260 has advanced to `a3741389fdc491c7ecccc20f77609c55bc56d20f`, so the child must be reconstructed parent-first rather than force-rebased or promoted from predecessor evidence. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 59594823a..d0b0e8788 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -84,9 +84,10 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertIn("145 open pull requests (5 ready, 140 draft)", refresh_line) self.assertIn("13 open non-PR issues", refresh_line) self.assertIn( - "Corrected the active ruleset inventory to 6 required workflows", + "Revalidated the active ruleset inventory at 7 required workflows", changed, ) + self.assertIn("`codeql-pr`", changed) self.assertIn("Made the open non-PR issue count reproducible", changed) self.assertNotIn("- Corrected the 2026-08-28 product-gap snapshot", added) self.assertNotIn("- Revalidated the product-gap queue at", changed) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index af98f8c96..c4bc2e3bb 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -32,7 +32,8 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "13 open non-PR issues", "c789b802fc98a8d7fd8c09d9327f36828054d2a1", "18156473", - "6 central required workflows", + "7 central required workflows", + "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", @@ -66,6 +67,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "118 Draft", "12 open non-PR issues", "10 central required workflows", + "6 central required workflows", "PR #260 is Draft at exact head `56600a6fd982cfafd784f4b7bb659d918113ca90`", "PR #281 remains Draft at exact head `3ed5d7e8cf77547c96feff2cfb24c46d74a73ebb`", ): From 3f8a7a26477989d5553cb7fd5de7bfe9c6683b57 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 23:06:28 +0900 Subject: [PATCH 076/250] docs: refresh active pull request evidence Update the volatile baseline to current exact heads while preserving the dated snapshot and fail-closed delivery claims. Signed-off-by: Seongho Bae --- CHANGELOG.md | 2 +- docs/product-technical-gap-baseline.md | 12 ++++++------ ...ocumentation_active_pr_evidence_contract.py | 4 +++- .../test_gap_snapshot_inventory_consistency.py | 18 ++++++++++++------ 4 files changed, 22 insertions(+), 14 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 92efa5a73..1d58f171f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -9,7 +9,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and the remaining rename/copy similarity-binding RED. ### Added -- Revalidated the product-gap queue at 145 open pull requests (5 ready, 140 draft) and 13 open non-PR issues on 2026-09-03; protected `main` remains `c789b802fc98a8d7fd8c09d9327f36828054d2a1`, presentation-identity PR #229 is Draft at `7ae426e760e8351ee792ce9df4266d7e7483d0d4`, WebDriver BiDi document-advance PR #260 is Draft at `a3741389fdc491c7ecccc20f77609c55bc56d20f`, and sandbox-enabled Agent Task evidence PR #70 is Draft at `ba8926eed5a6d783f781684f30c900919eecd52b`. Current-head checks remain independently required; no protected-main shipment is claimed. +- Revalidated the product-gap queue at 145 open pull requests (5 ready, 140 draft) and 13 open non-PR issues on 2026-09-04; protected `main` remains `c789b802fc98a8d7fd8c09d9327f36828054d2a1`, presentation-identity PR #229 is Draft at `35c4a00d24bb1429df7a306d95f49853d058baa7`, WebDriver BiDi document-advance PR #260 is Draft at `d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a`, and sandbox-enabled Agent Task evidence PR #70 is Draft at `ba8926eed5a6d783f781684f30c900919eecd52b`. Current-head checks remain independently required; no protected-main shipment is claimed. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 651d49747..ccccf2922 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,17 +6,17 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T12:41:17Z`. +Observed at (UTC): `2026-09-04T14:05:16Z`. - Protected `main` is `c789b802fc98a8d7fd8c09d9327f36828054d2a1` through #280. #280 restored repository-native CI for documentation changes after #278's `paths-ignore` created a documentation-contract verification gap. - Full live search returns **145 open pull requests: 5 Ready/non-draft and 140 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. -- Issue #279 owns the remaining documentation-CI partitioning gap. PR #282 is Draft at exact head `b2a120f892973e76c0ea0f06e7105bdf7a268009`; its classifier now requires complete 40-character SHA-1 or 64-character SHA-256 raw-diff object identities. The current test-only head also demonstrates that rename/copy similarity scores still need binding to blob identity before production is complete. Git-canonical paths and contributor/agent-instruction authority remain fail-closed. An authorized non-scheduled workflow owner must connect a trusted protected-base/immutable-SHA classifier to exact base/head raw evidence rather than execute mutable PR-head classification authority. -- PR #283 is Draft at exact head `a9603170e848a7c029531fe75727f02992ade2de`, non-force stacked on #282 exact `b2a120f892973e76c0ea0f06e7105bdf7a268009`. Its exact parent compare remains one prose-only doctoring canary (+7/-0), yet CI `33873850950` materializes Production coverage `101025984879` and Rust contracts `101025985066`, both queued without runner steps at the observation. That remains trigger-shape RED for #279; runner admission is a separate condition. -- Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `a3741389fdc491c7ecccc20f77609c55bc56d20f` on #259 base `dd3c0493d5a1a70c8c51524d38ff9c0553434f6f`; its browser/navigation behavior repair has current-head CI still non-terminal. PR #261 remains stale-parent Draft at exact head `127e02503e48938e29a9a07410574c7e72fc661a`; its declared base is an older #260 generation, while live #260 has advanced to `a3741389fdc491c7ecccc20f77609c55bc56d20f`, so the child must be reconstructed parent-first rather than force-rebased or promoted from predecessor evidence. +- Issue #279 owns the remaining documentation-CI partitioning gap. PR #282 is Draft at exact head `e3a40a4f78a3fbfc751ab9efad321b8207fb43e5`; its classifier requires complete 40-character SHA-1 or 64-character SHA-256 raw-diff object identities and binds Git rename/copy similarity to blob identity. Git-canonical paths and contributor/agent-instruction authority remain fail-closed. An authorized non-scheduled workflow owner must connect a trusted protected-base/immutable-SHA classifier to exact base/head raw evidence rather than execute mutable PR-head classification authority. +- PR #283 is Draft at exact head `85d31596c8b7251135f773b1d54d0f656fa10bbf`, non-force stacked on #282 exact `e3a40a4f78a3fbfc751ab9efad321b8207fb43e5`. Its exact parent compare remains one prose-only doctoring canary (+7/-0); exact-head hosted checks remain non-terminal, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. +- Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a` on #259 base `dd3c0493d5a1a70c8c51524d38ff9c0553434f6f`; its browser/navigation behavior repair has current-head CI still non-terminal. PR #261 is Draft at exact head `ccfa13b95295bde4e7a93621ba9add12651aa3bf`, non-force stacked on exact #260 `d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a`; parent-first exact-head verification remains required and predecessor evidence does not transfer. - PR #70 is Draft at exact head `ba8926eed5a6d783f781684f30c900919eecd52b`, current with protected main. Its focused Agent Task contract proves the pre-repair `--no-sandbox` launch as source RED and the branch removes that argument only from the Agent Task lane. Sandbox-enabled pinned-Chromium E2E and repository-wide GREEN remain unproven while its exact-head browser/CI/security runs are non-passing. -- DDD/MCP repair #272 is Draft at exact head `80272f18422c9946077ad9bd674f603db8f020da`. It preserves MCP as an adapter, contains an observed hosted RED for missing stdio constructors, and carries the bounded adapter-local repair; it remains active-PR evidence until exact-current CI, coverage, rustdoc, review, and security gates complete. -- PR #229 is Draft at exact head `7ae426e760e8351ee792ce9df4266d7e7483d0d4`. Test-only predecessor `ffd91290479c77ff1d675d4520e1776c990ba4d5` required a narrow presentation-identity changelog statement after the feature lane correctly relinquished volatile baseline ownership; the current repair adds exactly that feature-local entry while retaining the boundary that Chromium application and page-observed effectiveness remain separate adapter/browser-E2E work. Current-head CI/security runs remain non-terminal. +- DDD/MCP repair #272 is Draft at exact head `cae3e02cd2edc08db06111fb309a5b437c5a6598`. It preserves MCP as an adapter, contains an observed hosted RED for missing stdio constructors, and carries the bounded adapter-local repair; it remains active-PR evidence until exact-current CI, coverage, rustdoc, review, and security gates complete. +- PR #229 is Draft at exact head `35c4a00d24bb1429df7a306d95f49853d058baa7`. Its presentation-identity work retains the boundary that Chromium application and page-observed effectiveness remain separate adapter/browser-E2E work. Current-head CI/security runs remain non-terminal. - PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385` on canonical MV3 parent #43 `6f3134d18d3118aab33d28048671dc71a5f47b77`. Its child delta is diagnostic-evidence contract/doctoring only; inherited #43 implementation redacts browser/page-derived HTTP and WebDriver protocol data, startup exception details, returned capability values, DOM-dataset values, and click post-condition text before CI/audit evidence. No child GREEN is claimed while parent-first verification remains open. - PR #43 is Draft at exact head `6f3134d18d3118aab33d28048671dc71a5f47b77` on current protected main. The branch now installs and configures the pinned `chrome_sandbox`; exact-head hosted verification remains required, and restoring `--no-sandbox` is not acceptable. - PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `adc040a93be2533e15fabc4ca02deec1c5562d1d`. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index d0b0e8788..5d4965e33 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -80,9 +80,11 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: refresh_lines = [line for line in added.splitlines() if line.startswith(refresh_prefix)] self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] - self.assertIn("on 2026-09-03", refresh_line) + self.assertIn("on 2026-09-04", refresh_line) self.assertIn("145 open pull requests (5 ready, 140 draft)", refresh_line) self.assertIn("13 open non-PR issues", refresh_line) + self.assertIn("35c4a00d24bb1429df7a306d95f49853d058baa7", refresh_line) + self.assertIn("d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a", refresh_line) self.assertIn( "Revalidated the active ruleset inventory at 7 required workflows", changed, diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index c4bc2e3bb..9e6196f6c 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -37,14 +37,14 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", - "PR #260 is Draft at exact head `a3741389fdc491c7ecccc20f77609c55bc56d20f`", - "PR #261 remains stale-parent Draft at exact head `127e02503e48938e29a9a07410574c7e72fc661a`", + "PR #260 is Draft at exact head `d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a`", + "PR #261 is Draft at exact head `ccfa13b95295bde4e7a93621ba9add12651aa3bf`", "PR #70 is Draft at exact head `ba8926eed5a6d783f781684f30c900919eecd52b`", - "DDD/MCP repair #272 is Draft at exact head `80272f18422c9946077ad9bd674f603db8f020da`", - "PR #229 is Draft at exact head `7ae426e760e8351ee792ce9df4266d7e7483d0d4`", + "DDD/MCP repair #272 is Draft at exact head `cae3e02cd2edc08db06111fb309a5b437c5a6598`", + "PR #229 is Draft at exact head `35c4a00d24bb1429df7a306d95f49853d058baa7`", "PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385`", - "PR #282 is Draft at exact head `b2a120f892973e76c0ea0f06e7105bdf7a268009`", - "PR #283 is Draft at exact head `a9603170e848a7c029531fe75727f02992ade2de`", + "PR #282 is Draft at exact head `e3a40a4f78a3fbfc751ab9efad321b8207fb43e5`", + "PR #283 is Draft at exact head `85d31596c8b7251135f773b1d54d0f656fa10bbf`", "GitHub Releases is empty", ): with self.subTest(marker=marker): @@ -68,6 +68,12 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "12 open non-PR issues", "10 central required workflows", "6 central required workflows", + "PR #260 is Draft at exact head `a3741389fdc491c7ecccc20f77609c55bc56d20f`", + "PR #261 remains stale-parent Draft at exact head `127e02503e48938e29a9a07410574c7e72fc661a`", + "DDD/MCP repair #272 is Draft at exact head `80272f18422c9946077ad9bd674f603db8f020da`", + "PR #229 is Draft at exact head `7ae426e760e8351ee792ce9df4266d7e7483d0d4`", + "PR #282 is Draft at exact head `b2a120f892973e76c0ea0f06e7105bdf7a268009`", + "PR #283 is Draft at exact head `a9603170e848a7c029531fe75727f02992ade2de`", "PR #260 is Draft at exact head `56600a6fd982cfafd784f4b7bb659d918113ca90`", "PR #281 remains Draft at exact head `3ed5d7e8cf77547c96feff2cfb24c46d74a73ebb`", ): From 5dc7e60cf1083ff839d64bfa8abe42c0da1fa72f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 23:07:29 +0900 Subject: [PATCH 077/250] docs: close similarity evidence drift Record the current blob-identity binding and reject the superseded remaining-RED statement. Signed-off-by: Seongho Bae --- CHANGELOG.md | 2 +- tests/test_gap_snapshot_inventory_consistency.py | 2 ++ 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 1d58f171f..3b19dddb3 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,7 +6,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Refreshed the product-gap queue to 145 open pull requests (5 ready, 140 draft) and 13 open non-PR issues on 2026-09-03; queue movement is active-PR evidence, not protected-main shipment. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. -- Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and the remaining rename/copy similarity-binding RED. +- Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. ### Added - Revalidated the product-gap queue at 145 open pull requests (5 ready, 140 draft) and 13 open non-PR issues on 2026-09-04; protected `main` remains `c789b802fc98a8d7fd8c09d9327f36828054d2a1`, presentation-identity PR #229 is Draft at `35c4a00d24bb1429df7a306d95f49853d058baa7`, WebDriver BiDi document-advance PR #260 is Draft at `d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a`, and sandbox-enabled Agent Task evidence PR #70 is Draft at `ba8926eed5a6d783f781684f30c900919eecd52b`. Current-head checks remain independently required; no protected-main shipment is claimed. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 9e6196f6c..145c95c1c 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -59,6 +59,8 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: ): with self.subTest(non_passing=non_passing): self.assertIn(non_passing.casefold(), current.casefold()) + self.assertIn("binds Git rename/copy similarity to blob identity", current) + self.assertNotIn("remaining rename/copy similarity-binding RED", self.changelog) for stale in ( "143 open pull requests", "142 open pull requests", From b743a9ba4283dc88658a75deaa06b240533aec5b Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 23:13:22 +0900 Subject: [PATCH 078/250] docs: follow current partition heads Refresh the canonical live prefix after the classifier and canary branches advanced without changing the historical snapshot. Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 6 +++--- tests/test_gap_snapshot_inventory_consistency.py | 6 ++++-- 2 files changed, 7 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index ccccf2922..a7864ae60 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,13 +6,13 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T14:05:16Z`. +Observed at (UTC): `2026-09-04T14:12:35Z`. - Protected `main` is `c789b802fc98a8d7fd8c09d9327f36828054d2a1` through #280. #280 restored repository-native CI for documentation changes after #278's `paths-ignore` created a documentation-contract verification gap. - Full live search returns **145 open pull requests: 5 Ready/non-draft and 140 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. -- Issue #279 owns the remaining documentation-CI partitioning gap. PR #282 is Draft at exact head `e3a40a4f78a3fbfc751ab9efad321b8207fb43e5`; its classifier requires complete 40-character SHA-1 or 64-character SHA-256 raw-diff object identities and binds Git rename/copy similarity to blob identity. Git-canonical paths and contributor/agent-instruction authority remain fail-closed. An authorized non-scheduled workflow owner must connect a trusted protected-base/immutable-SHA classifier to exact base/head raw evidence rather than execute mutable PR-head classification authority. -- PR #283 is Draft at exact head `85d31596c8b7251135f773b1d54d0f656fa10bbf`, non-force stacked on #282 exact `e3a40a4f78a3fbfc751ab9efad321b8207fb43e5`. Its exact parent compare remains one prose-only doctoring canary (+7/-0); exact-head hosted checks remain non-terminal, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. +- Issue #279 owns the remaining documentation-CI partitioning gap. PR #282 is Draft at exact head `afe7738de3024803b0ae313ef9a233e8ff6fd2d7`; its classifier requires complete 40-character SHA-1 or 64-character SHA-256 raw-diff object identities, binds Git rename/copy similarity to blob identity, and now records that invariant in the CHANGELOG. Git-canonical paths and contributor/agent-instruction authority remain fail-closed. An authorized non-scheduled workflow owner must connect a trusted protected-base/immutable-SHA classifier to exact base/head raw evidence rather than execute mutable PR-head classification authority. +- PR #283 is Draft at exact head `2d434aefb9eff652e766a7239605b5f923705168`, non-force stacked on #282 exact `afe7738de3024803b0ae313ef9a233e8ff6fd2d7`. Its exact parent compare remains one prose-only doctoring canary (+7/-0); exact-head hosted checks remain non-terminal, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. - Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a` on #259 base `dd3c0493d5a1a70c8c51524d38ff9c0553434f6f`; its browser/navigation behavior repair has current-head CI still non-terminal. PR #261 is Draft at exact head `ccfa13b95295bde4e7a93621ba9add12651aa3bf`, non-force stacked on exact #260 `d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a`; parent-first exact-head verification remains required and predecessor evidence does not transfer. - PR #70 is Draft at exact head `ba8926eed5a6d783f781684f30c900919eecd52b`, current with protected main. Its focused Agent Task contract proves the pre-repair `--no-sandbox` launch as source RED and the branch removes that argument only from the Agent Task lane. Sandbox-enabled pinned-Chromium E2E and repository-wide GREEN remain unproven while its exact-head browser/CI/security runs are non-passing. - DDD/MCP repair #272 is Draft at exact head `cae3e02cd2edc08db06111fb309a5b437c5a6598`. It preserves MCP as an adapter, contains an observed hosted RED for missing stdio constructors, and carries the bounded adapter-local repair; it remains active-PR evidence until exact-current CI, coverage, rustdoc, review, and security gates complete. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 145c95c1c..381194fa8 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -43,8 +43,8 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "DDD/MCP repair #272 is Draft at exact head `cae3e02cd2edc08db06111fb309a5b437c5a6598`", "PR #229 is Draft at exact head `35c4a00d24bb1429df7a306d95f49853d058baa7`", "PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385`", - "PR #282 is Draft at exact head `e3a40a4f78a3fbfc751ab9efad321b8207fb43e5`", - "PR #283 is Draft at exact head `85d31596c8b7251135f773b1d54d0f656fa10bbf`", + "PR #282 is Draft at exact head `afe7738de3024803b0ae313ef9a233e8ff6fd2d7`", + "PR #283 is Draft at exact head `2d434aefb9eff652e766a7239605b5f923705168`", "GitHub Releases is empty", ): with self.subTest(marker=marker): @@ -76,6 +76,8 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #229 is Draft at exact head `7ae426e760e8351ee792ce9df4266d7e7483d0d4`", "PR #282 is Draft at exact head `b2a120f892973e76c0ea0f06e7105bdf7a268009`", "PR #283 is Draft at exact head `a9603170e848a7c029531fe75727f02992ade2de`", + "PR #282 is Draft at exact head `e3a40a4f78a3fbfc751ab9efad321b8207fb43e5`", + "PR #283 is Draft at exact head `85d31596c8b7251135f773b1d54d0f656fa10bbf`", "PR #260 is Draft at exact head `56600a6fd982cfafd784f4b7bb659d918113ca90`", "PR #281 remains Draft at exact head `3ed5d7e8cf77547c96feff2cfb24c46d74a73ebb`", ): From ee932489ebba50fae411e8d37073da63056a7eda Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 23:29:07 +0900 Subject: [PATCH 079/250] docs(governance): record protected-main bypass evidence Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 7 ++++--- ...test_gap_snapshot_inventory_consistency.py | 3 ++- tests/test_product_completion_gap_contract.py | 21 +++++++++++++++++++ 4 files changed, 28 insertions(+), 4 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 3b19dddb3..8434c2551 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. - Refreshed the product-gap queue to 145 open pull requests (5 ready, 140 draft) and 13 open non-PR issues on 2026-09-03; queue movement is active-PR evidence, not protected-main shipment. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index a7864ae60..3c0a5da3d 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,18 +6,19 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T14:12:35Z`. +Observed at (UTC): `2026-09-04T14:27:56Z`. -- Protected `main` is `c789b802fc98a8d7fd8c09d9327f36828054d2a1` through #280. #280 restored repository-native CI for documentation changes after #278's `paths-ignore` created a documentation-contract verification gap. +- Protected `main` is `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b` through #284. PR #284 changed repository workflows and removed the completed nightly materializer; its integration procedure is recorded separately from the content of that change. - Full live search returns **145 open pull requests: 5 Ready/non-draft and 140 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. +- PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - Issue #279 owns the remaining documentation-CI partitioning gap. PR #282 is Draft at exact head `afe7738de3024803b0ae313ef9a233e8ff6fd2d7`; its classifier requires complete 40-character SHA-1 or 64-character SHA-256 raw-diff object identities, binds Git rename/copy similarity to blob identity, and now records that invariant in the CHANGELOG. Git-canonical paths and contributor/agent-instruction authority remain fail-closed. An authorized non-scheduled workflow owner must connect a trusted protected-base/immutable-SHA classifier to exact base/head raw evidence rather than execute mutable PR-head classification authority. - PR #283 is Draft at exact head `2d434aefb9eff652e766a7239605b5f923705168`, non-force stacked on #282 exact `afe7738de3024803b0ae313ef9a233e8ff6fd2d7`. Its exact parent compare remains one prose-only doctoring canary (+7/-0); exact-head hosted checks remain non-terminal, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. - Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a` on #259 base `dd3c0493d5a1a70c8c51524d38ff9c0553434f6f`; its browser/navigation behavior repair has current-head CI still non-terminal. PR #261 is Draft at exact head `ccfa13b95295bde4e7a93621ba9add12651aa3bf`, non-force stacked on exact #260 `d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a`; parent-first exact-head verification remains required and predecessor evidence does not transfer. - PR #70 is Draft at exact head `ba8926eed5a6d783f781684f30c900919eecd52b`, current with protected main. Its focused Agent Task contract proves the pre-repair `--no-sandbox` launch as source RED and the branch removes that argument only from the Agent Task lane. Sandbox-enabled pinned-Chromium E2E and repository-wide GREEN remain unproven while its exact-head browser/CI/security runs are non-passing. - DDD/MCP repair #272 is Draft at exact head `cae3e02cd2edc08db06111fb309a5b437c5a6598`. It preserves MCP as an adapter, contains an observed hosted RED for missing stdio constructors, and carries the bounded adapter-local repair; it remains active-PR evidence until exact-current CI, coverage, rustdoc, review, and security gates complete. - PR #229 is Draft at exact head `35c4a00d24bb1429df7a306d95f49853d058baa7`. Its presentation-identity work retains the boundary that Chromium application and page-observed effectiveness remain separate adapter/browser-E2E work. Current-head CI/security runs remain non-terminal. -- PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385` on canonical MV3 parent #43 `6f3134d18d3118aab33d28048671dc71a5f47b77`. Its child delta is diagnostic-evidence contract/doctoring only; inherited #43 implementation redacts browser/page-derived HTTP and WebDriver protocol data, startup exception details, returned capability values, DOM-dataset values, and click post-condition text before CI/audit evidence. No child GREEN is claimed while parent-first verification remains open. +- PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385` on canonical MV3 parent #43 `6f3134d18d3118aab33d28048671dc71a5f47b77`. Its child delta is diagnostic-evidence contract/doctoring only; inherited #43 implementation redacts browser/page-derived HTTP and WebDriver protocol data, startup exception details, returned capability values, DOM-dataset values, and click post-condition text before CI/audit evidence. Exact-head CI and Manifest V3 Compatibility succeeded and review threads are resolved, but parent-first workflow-ownership verification remains open, so the child stays Draft. - PR #43 is Draft at exact head `6f3134d18d3118aab33d28048671dc71a5f47b77` on current protected main. The branch now installs and configures the pinned `chrome_sandbox`; exact-head hosted verification remains required, and restoring `--no-sandbox` is not acceptable. - PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `adc040a93be2533e15fabc4ca02deec1c5562d1d`. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. - Issue #201's release/SBOM lane remains dependency ordered, and GitHub Releases is empty. OriginWeave remains pre-GA until exact protected-head versioning, signed artifacts, SBOM/provenance, reproducibility, rollback, compatibility, security, and commercial-acceptance evidence exist. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 381194fa8..ce72a3d10 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -30,7 +30,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "5 Ready/non-draft", "140 Draft", "13 open non-PR issues", - "c789b802fc98a8d7fd8c09d9327f36828054d2a1", + "4ed08bfa7c063fc7f2ef9278ee8d281887b8296b", "18156473", "7 central required workflows", "codeql-pr", @@ -62,6 +62,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: self.assertIn("binds Git rename/copy similarity to blob identity", current) self.assertNotIn("remaining rename/copy similarity-binding RED", self.changelog) for stale in ( + "Protected `main` is `c789b802fc98a8d7fd8c09d9327f36828054d2a1` through #280", "143 open pull requests", "142 open pull requests", "24 Ready/non-draft", diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index fac65e919..6a680e11c 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -83,6 +83,27 @@ def test_active_github_approval_rule_is_not_documented_as_bypassable(self) -> No self.assertIn("reviewer-provisioning gap", text) self.assertNotIn("owner-directed administrative merge", text) + def test_current_snapshot_records_the_pr_284_admin_bypass_incident(self) -> None: + """A bypassed main update must not be presented as a policy-compliant merge.""" + text = BASELINE.read_text(encoding="utf-8") + current = text.split("## Current live delivery state", 1)[1].split( + "## Observed snapshot: ", 1 + )[0] + + for marker in ( + "4ed08bfa7c063fc7f2ef9278ee8d281887b8296b", + "#284", + "61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a", + "rule-suite `3948421709`", + "`result: bypass`", + "#215", + "post-merge checks remain non-terminal", + ): + with self.subTest(marker=marker): + self.assertIn(marker, current) + + self.assertNotIn("through #280", current) + def test_changelog_marks_superseded_warc_head_as_historical(self) -> None: """A predecessor WARC head must not look like the current exact evidence.""" text = (ROOT / "CHANGELOG.md").read_text(encoding="utf-8") From 115de7a91e4317c1a95e6bdb808893064d7bdf53 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 23:32:20 +0900 Subject: [PATCH 080/250] docs(ci): refresh partition stack evidence Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 6 +++--- tests/test_gap_snapshot_inventory_consistency.py | 4 ++-- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 3c0a5da3d..03bfa5d60 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,14 +6,14 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T14:27:56Z`. +Observed at (UTC): `2026-09-04T14:31:53Z`. - Protected `main` is `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b` through #284. PR #284 changed repository workflows and removed the completed nightly materializer; its integration procedure is recorded separately from the content of that change. - Full live search returns **145 open pull requests: 5 Ready/non-draft and 140 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. -- Issue #279 owns the remaining documentation-CI partitioning gap. PR #282 is Draft at exact head `afe7738de3024803b0ae313ef9a233e8ff6fd2d7`; its classifier requires complete 40-character SHA-1 or 64-character SHA-256 raw-diff object identities, binds Git rename/copy similarity to blob identity, and now records that invariant in the CHANGELOG. Git-canonical paths and contributor/agent-instruction authority remain fail-closed. An authorized non-scheduled workflow owner must connect a trusted protected-base/immutable-SHA classifier to exact base/head raw evidence rather than execute mutable PR-head classification authority. -- PR #283 is Draft at exact head `2d434aefb9eff652e766a7239605b5f923705168`, non-force stacked on #282 exact `afe7738de3024803b0ae313ef9a233e8ff6fd2d7`. Its exact parent compare remains one prose-only doctoring canary (+7/-0); exact-head hosted checks remain non-terminal, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. +- Issue #279 owns the remaining documentation-CI partitioning gap. PR #282 is Draft at exact head `ba0c1c998c7750d6c0bc36c1ccf47f06c0ad04a3`, non-destructively current with protected main; its classifier requires complete 40-character SHA-1 or 64-character SHA-256 raw-diff object identities, binds Git rename/copy similarity to blob identity, and records that invariant in the CHANGELOG. Git-canonical paths and contributor/agent-instruction authority remain fail-closed. An authorized non-scheduled workflow owner must connect a trusted protected-base/immutable-SHA classifier to exact base/head raw evidence rather than execute mutable PR-head classification authority. +- PR #283 is Draft at exact head `67228652d096244c6433fa4e78b0cb5949c51850`, non-force stacked on #282 exact `ba0c1c998c7750d6c0bc36c1ccf47f06c0ad04a3`. Its exact parent compare remains one prose-only doctoring canary (+7/-0); exact-head hosted checks remain non-terminal, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. - Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a` on #259 base `dd3c0493d5a1a70c8c51524d38ff9c0553434f6f`; its browser/navigation behavior repair has current-head CI still non-terminal. PR #261 is Draft at exact head `ccfa13b95295bde4e7a93621ba9add12651aa3bf`, non-force stacked on exact #260 `d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a`; parent-first exact-head verification remains required and predecessor evidence does not transfer. - PR #70 is Draft at exact head `ba8926eed5a6d783f781684f30c900919eecd52b`, current with protected main. Its focused Agent Task contract proves the pre-repair `--no-sandbox` launch as source RED and the branch removes that argument only from the Agent Task lane. Sandbox-enabled pinned-Chromium E2E and repository-wide GREEN remain unproven while its exact-head browser/CI/security runs are non-passing. - DDD/MCP repair #272 is Draft at exact head `cae3e02cd2edc08db06111fb309a5b437c5a6598`. It preserves MCP as an adapter, contains an observed hosted RED for missing stdio constructors, and carries the bounded adapter-local repair; it remains active-PR evidence until exact-current CI, coverage, rustdoc, review, and security gates complete. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index ce72a3d10..abd77ca39 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -43,8 +43,8 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "DDD/MCP repair #272 is Draft at exact head `cae3e02cd2edc08db06111fb309a5b437c5a6598`", "PR #229 is Draft at exact head `35c4a00d24bb1429df7a306d95f49853d058baa7`", "PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385`", - "PR #282 is Draft at exact head `afe7738de3024803b0ae313ef9a233e8ff6fd2d7`", - "PR #283 is Draft at exact head `2d434aefb9eff652e766a7239605b5f923705168`", + "PR #282 is Draft at exact head `ba0c1c998c7750d6c0bc36c1ccf47f06c0ad04a3`", + "PR #283 is Draft at exact head `67228652d096244c6433fa4e78b0cb5949c51850`", "GitHub Releases is empty", ): with self.subTest(marker=marker): From f2e0df2d37b6ff015b65dc2051deb600277ea036 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 23:40:40 +0900 Subject: [PATCH 081/250] docs(queue): record post-merge repair slice Signed-off-by: Seongho Bae --- CHANGELOG.md | 4 ++-- docs/product-technical-gap-baseline.md | 5 +++-- tests/test_documentation_active_pr_evidence_contract.py | 2 +- tests/test_gap_snapshot_inventory_consistency.py | 7 ++++--- 4 files changed, 10 insertions(+), 8 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 8434c2551..30ff623ab 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,12 +5,12 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. -- Refreshed the product-gap queue to 145 open pull requests (5 ready, 140 draft) and 13 open non-PR issues on 2026-09-03; queue movement is active-PR evidence, not protected-main shipment. +- Refreshed the product-gap queue to 146 open pull requests (5 ready, 141 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. ### Added -- Revalidated the product-gap queue at 145 open pull requests (5 ready, 140 draft) and 13 open non-PR issues on 2026-09-04; protected `main` remains `c789b802fc98a8d7fd8c09d9327f36828054d2a1`, presentation-identity PR #229 is Draft at `35c4a00d24bb1429df7a306d95f49853d058baa7`, WebDriver BiDi document-advance PR #260 is Draft at `d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a`, and sandbox-enabled Agent Task evidence PR #70 is Draft at `ba8926eed5a6d783f781684f30c900919eecd52b`. Current-head checks remain independently required; no protected-main shipment is claimed. +- Revalidated the product-gap queue at 146 open pull requests (5 ready, 141 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`, presentation-identity PR #229 is Draft at `35c4a00d24bb1429df7a306d95f49853d058baa7`, WebDriver BiDi document-advance PR #260 is Draft at `d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a`, sandbox-enabled Agent Task evidence PR #70 is Draft at `ba8926eed5a6d783f781684f30c900919eecd52b`, and post-merge contract repair PR #285 is Draft at `7d44caa8d4c09660fb3b5d2d9919d8141c6d5294`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 03bfa5d60..2f70a9eff 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,12 +6,13 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T14:31:53Z`. +Observed at (UTC): `2026-09-04T14:39:41Z`. - Protected `main` is `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b` through #284. PR #284 changed repository workflows and removed the completed nightly materializer; its integration procedure is recorded separately from the content of that change. -- Full live search returns **145 open pull requests: 5 Ready/non-draft and 140 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. +- Full live search returns **146 open pull requests: 5 Ready/non-draft and 141 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. +- PR #285 is Draft at exact head `7d44caa8d4c09660fb3b5d2d9919d8141c6d5294` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**`: the changelog now records the control-plane change, quality gates identify all-target Clippy as the workspace compile/check gate, and both workflow regressions require one complete concurrency block. Focused and all 152 repository contracts pass locally; hosted checks remain non-terminal. - Issue #279 owns the remaining documentation-CI partitioning gap. PR #282 is Draft at exact head `ba0c1c998c7750d6c0bc36c1ccf47f06c0ad04a3`, non-destructively current with protected main; its classifier requires complete 40-character SHA-1 or 64-character SHA-256 raw-diff object identities, binds Git rename/copy similarity to blob identity, and records that invariant in the CHANGELOG. Git-canonical paths and contributor/agent-instruction authority remain fail-closed. An authorized non-scheduled workflow owner must connect a trusted protected-base/immutable-SHA classifier to exact base/head raw evidence rather than execute mutable PR-head classification authority. - PR #283 is Draft at exact head `67228652d096244c6433fa4e78b0cb5949c51850`, non-force stacked on #282 exact `ba0c1c998c7750d6c0bc36c1ccf47f06c0ad04a3`. Its exact parent compare remains one prose-only doctoring canary (+7/-0); exact-head hosted checks remain non-terminal, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. - Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a` on #259 base `dd3c0493d5a1a70c8c51524d38ff9c0553434f6f`; its browser/navigation behavior repair has current-head CI still non-terminal. PR #261 is Draft at exact head `ccfa13b95295bde4e7a93621ba9add12651aa3bf`, non-force stacked on exact #260 `d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a`; parent-first exact-head verification remains required and predecessor evidence does not transfer. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 5d4965e33..5a85daf4c 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -81,7 +81,7 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] self.assertIn("on 2026-09-04", refresh_line) - self.assertIn("145 open pull requests (5 ready, 140 draft)", refresh_line) + self.assertIn("146 open pull requests (5 ready, 141 draft)", refresh_line) self.assertIn("13 open non-PR issues", refresh_line) self.assertIn("35c4a00d24bb1429df7a306d95f49853d058baa7", refresh_line) self.assertIn("d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a", refresh_line) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index abd77ca39..950d9d2ce 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -26,9 +26,9 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "## Observed snapshot: 2026-08-29", 1 )[0] for marker in ( - "145 open pull requests", + "146 open pull requests", "5 Ready/non-draft", - "140 Draft", + "141 Draft", "13 open non-PR issues", "4ed08bfa7c063fc7f2ef9278ee8d281887b8296b", "18156473", @@ -45,6 +45,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385`", "PR #282 is Draft at exact head `ba0c1c998c7750d6c0bc36c1ccf47f06c0ad04a3`", "PR #283 is Draft at exact head `67228652d096244c6433fa4e78b0cb5949c51850`", + "PR #285 is Draft at exact head `7d44caa8d4c09660fb3b5d2d9919d8141c6d5294`", "GitHub Releases is empty", ): with self.subTest(marker=marker): @@ -121,7 +122,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "145 open pull requests (5 ready, 140 draft)" + expected = "146 open pull requests (5 ready, 141 draft)" self.assertIn(expected, preamble) self.assertIn("13 open non-PR issues", preamble) self.assertIn(expected, added) From f966528bf18a88834bb74f46cbcb19fa6a55f756 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 23:55:41 +0900 Subject: [PATCH 082/250] docs(gaps): record current ready root heads Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 5 +++-- tests/test_gap_snapshot_inventory_consistency.py | 1 + 3 files changed, 5 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 30ff623ab..24c89854c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,6 +6,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. - Refreshed the product-gap queue to 146 open pull requests (5 ready, 141 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. +- Recorded the current Ready-root heads for #37, #50, #219, #240, and #274 after non-destructive protected-main adoption; their regenerated required checks and counted approvals remain independently required. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 2f70a9eff..c8146d47c 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,10 +6,11 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T14:39:41Z`. +Observed at (UTC): `2026-09-04T14:54:48Z`. - Protected `main` is `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b` through #284. PR #284 changed repository workflows and removed the completed nightly materializer; its integration procedure is recorded separately from the content of that change. - Full live search returns **146 open pull requests: 5 Ready/non-draft and 141 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. +- Ready roots are #37 `f0cf2fa27545d71cee06919d83169831a28f94c9`, #50 `ae2116357194de9705db6fdcfb8fef78ad44fba8`, #219 `a0b520c4aef625f6a10b7bd2f8df6f6f82479ebc`, #240 `76f30fe867ec77ff604de64497889b1026380082`, and #274 `c758e61192805a172a602c798b1d81541380e32a`. Each is mergeable against current protected main with no observed failed current-head check, but its newly generated required checks remain queued and no current-head counted approval exists; none is merge-ready under the active ruleset. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Draft at exact head `7d44caa8d4c09660fb3b5d2d9919d8141c6d5294` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**`: the changelog now records the control-plane change, quality gates identify all-target Clippy as the workspace compile/check gate, and both workflow regressions require one complete concurrency block. Focused and all 152 repository contracts pass locally; hosted checks remain non-terminal. @@ -21,7 +22,7 @@ Observed at (UTC): `2026-09-04T14:39:41Z`. - PR #229 is Draft at exact head `35c4a00d24bb1429df7a306d95f49853d058baa7`. Its presentation-identity work retains the boundary that Chromium application and page-observed effectiveness remain separate adapter/browser-E2E work. Current-head CI/security runs remain non-terminal. - PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385` on canonical MV3 parent #43 `6f3134d18d3118aab33d28048671dc71a5f47b77`. Its child delta is diagnostic-evidence contract/doctoring only; inherited #43 implementation redacts browser/page-derived HTTP and WebDriver protocol data, startup exception details, returned capability values, DOM-dataset values, and click post-condition text before CI/audit evidence. Exact-head CI and Manifest V3 Compatibility succeeded and review threads are resolved, but parent-first workflow-ownership verification remains open, so the child stays Draft. - PR #43 is Draft at exact head `6f3134d18d3118aab33d28048671dc71a5f47b77` on current protected main. The branch now installs and configures the pinned `chrome_sandbox`; exact-head hosted verification remains required, and restoring `--no-sandbox` is not acceptable. -- PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `adc040a93be2533e15fabc4ca02deec1c5562d1d`. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. +- PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `c758e61192805a172a602c798b1d81541380e32a`. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. - Issue #201's release/SBOM lane remains dependency ordered, and GitHub Releases is empty. OriginWeave remains pre-GA until exact protected-head versioning, signed artifacts, SBOM/provenance, reproducibility, rollback, compatibility, security, and commercial-acceptance evidence exist. - The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #28 the first complete Chromium Agent Task vertical slice, #199 durable WARC/PROV and retention/replay, #200 stable BAP/MCP runtime API, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 enterprise identity/tenant/policy/approval/audit/SLO operations, #203 exact-artifact commercial acceptance, #276 contextual-orchestrator migration, and #279 exact-head documentation verification without unnecessary Rust queue load. - Current evidence procedure remains fail-closed: queued reviewer evidence is non-passing; paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 950d9d2ce..d685b536e 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -35,6 +35,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", + "Ready roots are #37 `f0cf2fa27545d71cee06919d83169831a28f94c9`, #50 `ae2116357194de9705db6fdcfb8fef78ad44fba8`, #219 `a0b520c4aef625f6a10b7bd2f8df6f6f82479ebc`, #240 `76f30fe867ec77ff604de64497889b1026380082`, and #274 `c758e61192805a172a602c798b1d81541380e32a`", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", "PR #260 is Draft at exact head `d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a`", From e69ac3ed0b7886d9e72017c64431b8c8f17d0436 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 23:57:50 +0900 Subject: [PATCH 083/250] docs(gaps): follow current HTTP root head Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 4 ++-- tests/test_gap_snapshot_inventory_consistency.py | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index c8146d47c..f8af17b87 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,11 +6,11 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T14:54:48Z`. +Observed at (UTC): `2026-09-04T14:57:11Z`. - Protected `main` is `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b` through #284. PR #284 changed repository workflows and removed the completed nightly materializer; its integration procedure is recorded separately from the content of that change. - Full live search returns **146 open pull requests: 5 Ready/non-draft and 141 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. -- Ready roots are #37 `f0cf2fa27545d71cee06919d83169831a28f94c9`, #50 `ae2116357194de9705db6fdcfb8fef78ad44fba8`, #219 `a0b520c4aef625f6a10b7bd2f8df6f6f82479ebc`, #240 `76f30fe867ec77ff604de64497889b1026380082`, and #274 `c758e61192805a172a602c798b1d81541380e32a`. Each is mergeable against current protected main with no observed failed current-head check, but its newly generated required checks remain queued and no current-head counted approval exists; none is merge-ready under the active ruleset. +- Ready roots are #37 `3d5c752cbe14e69e6b72214dd8cc4dc5978d3c10`, #50 `ae2116357194de9705db6fdcfb8fef78ad44fba8`, #219 `a0b520c4aef625f6a10b7bd2f8df6f6f82479ebc`, #240 `76f30fe867ec77ff604de64497889b1026380082`, and #274 `c758e61192805a172a602c798b1d81541380e32a`. Each is mergeable against current protected main with no observed failed current-head check, but its newly generated required checks remain queued and no current-head counted approval exists; none is merge-ready under the active ruleset. PR #37's successor adds the missing `originweave-http` workspace-member assertion after adopting current CI contracts; predecessor head `f0cf2fa27545d71cee06919d83169831a28f94c9` is historical evidence only. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Draft at exact head `7d44caa8d4c09660fb3b5d2d9919d8141c6d5294` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**`: the changelog now records the control-plane change, quality gates identify all-target Clippy as the workspace compile/check gate, and both workflow regressions require one complete concurrency block. Focused and all 152 repository contracts pass locally; hosted checks remain non-terminal. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index d685b536e..d68917210 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -35,7 +35,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `f0cf2fa27545d71cee06919d83169831a28f94c9`, #50 `ae2116357194de9705db6fdcfb8fef78ad44fba8`, #219 `a0b520c4aef625f6a10b7bd2f8df6f6f82479ebc`, #240 `76f30fe867ec77ff604de64497889b1026380082`, and #274 `c758e61192805a172a602c798b1d81541380e32a`", + "Ready roots are #37 `3d5c752cbe14e69e6b72214dd8cc4dc5978d3c10`, #50 `ae2116357194de9705db6fdcfb8fef78ad44fba8`, #219 `a0b520c4aef625f6a10b7bd2f8df6f6f82479ebc`, #240 `76f30fe867ec77ff604de64497889b1026380082`, and #274 `c758e61192805a172a602c798b1d81541380e32a`", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", "PR #260 is Draft at exact head `d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a`", From 67dc4b9e5c552064f32199d6bc67f6922e7e4cbf Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 02:53:43 +0900 Subject: [PATCH 084/250] docs(gap): refresh live delivery evidence Signed-off-by: Seongho Bae --- CHANGELOG.md | 2 +- docs/product-technical-gap-baseline.md | 10 +++++----- .../test_documentation_active_pr_evidence_contract.py | 5 +++-- tests/test_gap_snapshot_inventory_consistency.py | 11 ++++++----- 4 files changed, 15 insertions(+), 13 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 24c89854c..e567fc58c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -11,7 +11,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. ### Added -- Revalidated the product-gap queue at 146 open pull requests (5 ready, 141 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`, presentation-identity PR #229 is Draft at `35c4a00d24bb1429df7a306d95f49853d058baa7`, WebDriver BiDi document-advance PR #260 is Draft at `d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a`, sandbox-enabled Agent Task evidence PR #70 is Draft at `ba8926eed5a6d783f781684f30c900919eecd52b`, and post-merge contract repair PR #285 is Draft at `7d44caa8d4c09660fb3b5d2d9919d8141c6d5294`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. +- Revalidated the product-gap queue at 146 open pull requests (5 ready, 141 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`, presentation-identity PR #229 is Draft at `7aa30c57a4af724eb4e601c52c1eaf68f27d1712`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, subscription repair PR #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`, sandbox-enabled Agent Task evidence PR #70 is Draft at `823e2e29acdbc9a16da733c5a6fc7b9f85cc7527`, and post-merge contract repair PR #285 is Draft at `7d44caa8d4c09660fb3b5d2d9919d8141c6d5294`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index f8af17b87..624037a56 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,7 +6,7 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T14:57:11Z`. +Observed at (UTC): `2026-09-04T17:52:06Z`. - Protected `main` is `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b` through #284. PR #284 changed repository workflows and removed the completed nightly materializer; its integration procedure is recorded separately from the content of that change. - Full live search returns **146 open pull requests: 5 Ready/non-draft and 141 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. @@ -16,10 +16,10 @@ Observed at (UTC): `2026-09-04T14:57:11Z`. - PR #285 is Draft at exact head `7d44caa8d4c09660fb3b5d2d9919d8141c6d5294` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**`: the changelog now records the control-plane change, quality gates identify all-target Clippy as the workspace compile/check gate, and both workflow regressions require one complete concurrency block. Focused and all 152 repository contracts pass locally; hosted checks remain non-terminal. - Issue #279 owns the remaining documentation-CI partitioning gap. PR #282 is Draft at exact head `ba0c1c998c7750d6c0bc36c1ccf47f06c0ad04a3`, non-destructively current with protected main; its classifier requires complete 40-character SHA-1 or 64-character SHA-256 raw-diff object identities, binds Git rename/copy similarity to blob identity, and records that invariant in the CHANGELOG. Git-canonical paths and contributor/agent-instruction authority remain fail-closed. An authorized non-scheduled workflow owner must connect a trusted protected-base/immutable-SHA classifier to exact base/head raw evidence rather than execute mutable PR-head classification authority. - PR #283 is Draft at exact head `67228652d096244c6433fa4e78b0cb5949c51850`, non-force stacked on #282 exact `ba0c1c998c7750d6c0bc36c1ccf47f06c0ad04a3`. Its exact parent compare remains one prose-only doctoring canary (+7/-0); exact-head hosted checks remain non-terminal, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. -- Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a` on #259 base `dd3c0493d5a1a70c8c51524d38ff9c0553434f6f`; its browser/navigation behavior repair has current-head CI still non-terminal. PR #261 is Draft at exact head `ccfa13b95295bde4e7a93621ba9add12651aa3bf`, non-force stacked on exact #260 `d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a`; parent-first exact-head verification remains required and predecessor evidence does not transfer. -- PR #70 is Draft at exact head `ba8926eed5a6d783f781684f30c900919eecd52b`, current with protected main. Its focused Agent Task contract proves the pre-repair `--no-sandbox` launch as source RED and the branch removes that argument only from the Agent Task lane. Sandbox-enabled pinned-Chromium E2E and repository-wide GREEN remain unproven while its exact-head browser/CI/security runs are non-passing. -- DDD/MCP repair #272 is Draft at exact head `cae3e02cd2edc08db06111fb309a5b437c5a6598`. It preserves MCP as an adapter, contains an observed hosted RED for missing stdio constructors, and carries the bounded adapter-local repair; it remains active-PR evidence until exact-current CI, coverage, rustdoc, review, and security gates complete. -- PR #229 is Draft at exact head `35c4a00d24bb1429df7a306d95f49853d058baa7`. Its presentation-identity work retains the boundary that Chromium application and page-observed effectiveness remain separate adapter/browser-E2E work. Current-head CI/security runs remain non-terminal. +- Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0` on #259 exact base `b089c5f584e2a7c3e2c4605a40d2173b3c506e18`. PR #261 is Draft at exact head `95f7548bf07cbba76ab8b40577a11d1b6c99acb5`, stacked on exact #260. Repair PR #277 is Draft at exact head `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`, stacked on exact #261 and preserving typed `SessionSubscribe` correlation. Their local full suites and 100% production coverage succeeded, but exact-head hosted checks remain queued; predecessor evidence does not transfer and stale #262 is not superseded until #277 reaches terminal GREEN. +- PR #70 is Draft at exact head `823e2e29acdbc9a16da733c5a6fc7b9f85cc7527`, current with protected main. Its focused Agent Task contract proves the pre-repair `--no-sandbox` launch as source RED and the branch removes that argument only from the Agent Task lane. Sandbox-enabled pinned-Chromium E2E and repository-wide GREEN remain unproven while its exact-head browser/CI/security runs are non-passing. +- DDD/MCP repair #272 is Draft at exact head `fe124e447cad3f679e22337fb6fbdfd135ab3652`. It preserves MCP as an adapter, contains an observed hosted RED for missing stdio constructors, and carries the bounded adapter-local repair; it remains active-PR evidence until exact-current CI, coverage, rustdoc, review, and security gates complete. +- PR #229 is Draft at exact head `7aa30c57a4af724eb4e601c52c1eaf68f27d1712`. Its presentation-identity work retains the boundary that Chromium application and page-observed effectiveness remain separate adapter/browser-E2E work. Current-head CI/security runs remain non-terminal. - PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385` on canonical MV3 parent #43 `6f3134d18d3118aab33d28048671dc71a5f47b77`. Its child delta is diagnostic-evidence contract/doctoring only; inherited #43 implementation redacts browser/page-derived HTTP and WebDriver protocol data, startup exception details, returned capability values, DOM-dataset values, and click post-condition text before CI/audit evidence. Exact-head CI and Manifest V3 Compatibility succeeded and review threads are resolved, but parent-first workflow-ownership verification remains open, so the child stays Draft. - PR #43 is Draft at exact head `6f3134d18d3118aab33d28048671dc71a5f47b77` on current protected main. The branch now installs and configures the pinned `chrome_sandbox`; exact-head hosted verification remains required, and restoring `--no-sandbox` is not acceptable. - PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `c758e61192805a172a602c798b1d81541380e32a`. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 5a85daf4c..bec4cf3c5 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -83,8 +83,9 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertIn("on 2026-09-04", refresh_line) self.assertIn("146 open pull requests (5 ready, 141 draft)", refresh_line) self.assertIn("13 open non-PR issues", refresh_line) - self.assertIn("35c4a00d24bb1429df7a306d95f49853d058baa7", refresh_line) - self.assertIn("d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a", refresh_line) + self.assertIn("7aa30c57a4af724eb4e601c52c1eaf68f27d1712", refresh_line) + self.assertIn("35d12949bde5e5cbc801fdfb433f4a9914bd4fb0", refresh_line) + self.assertIn("0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1", refresh_line) self.assertIn( "Revalidated the active ruleset inventory at 7 required workflows", changed, diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index d68917210..f6b4e4c42 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -38,11 +38,12 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "Ready roots are #37 `3d5c752cbe14e69e6b72214dd8cc4dc5978d3c10`, #50 `ae2116357194de9705db6fdcfb8fef78ad44fba8`, #219 `a0b520c4aef625f6a10b7bd2f8df6f6f82479ebc`, #240 `76f30fe867ec77ff604de64497889b1026380082`, and #274 `c758e61192805a172a602c798b1d81541380e32a`", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", - "PR #260 is Draft at exact head `d1f3a4f0f44f15b6dcdba8b8ce555af0bed89d0a`", - "PR #261 is Draft at exact head `ccfa13b95295bde4e7a93621ba9add12651aa3bf`", - "PR #70 is Draft at exact head `ba8926eed5a6d783f781684f30c900919eecd52b`", - "DDD/MCP repair #272 is Draft at exact head `cae3e02cd2edc08db06111fb309a5b437c5a6598`", - "PR #229 is Draft at exact head `35c4a00d24bb1429df7a306d95f49853d058baa7`", + "PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`", + "PR #261 is Draft at exact head `95f7548bf07cbba76ab8b40577a11d1b6c99acb5`", + "PR #277 is Draft at exact head `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`", + "PR #70 is Draft at exact head `823e2e29acdbc9a16da733c5a6fc7b9f85cc7527`", + "DDD/MCP repair #272 is Draft at exact head `fe124e447cad3f679e22337fb6fbdfd135ab3652`", + "PR #229 is Draft at exact head `7aa30c57a4af724eb4e601c52c1eaf68f27d1712`", "PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385`", "PR #282 is Draft at exact head `ba0c1c998c7750d6c0bc36c1ccf47f06c0ad04a3`", "PR #283 is Draft at exact head `67228652d096244c6433fa4e78b0cb5949c51850`", From 3fa08db09a23483a246f71380164b158c7a717a8 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 05:14:32 +0900 Subject: [PATCH 085/250] docs(gaps): refresh current delivery inventory Signed-off-by: Seongho Bae --- CHANGELOG.md | 4 ++-- docs/product-technical-gap-baseline.md | 12 ++++++------ ...st_documentation_active_pr_evidence_contract.py | 4 ++-- tests/test_gap_snapshot_inventory_consistency.py | 14 +++++++------- 4 files changed, 17 insertions(+), 17 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index e567fc58c..f28e58756 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,13 +5,13 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. -- Refreshed the product-gap queue to 146 open pull requests (5 ready, 141 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. +- Refreshed the product-gap queue to 135 open pull requests (5 ready, 130 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. - Recorded the current Ready-root heads for #37, #50, #219, #240, and #274 after non-destructive protected-main adoption; their regenerated required checks and counted approvals remain independently required. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. ### Added -- Revalidated the product-gap queue at 146 open pull requests (5 ready, 141 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`, presentation-identity PR #229 is Draft at `7aa30c57a4af724eb4e601c52c1eaf68f27d1712`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, subscription repair PR #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`, sandbox-enabled Agent Task evidence PR #70 is Draft at `823e2e29acdbc9a16da733c5a6fc7b9f85cc7527`, and post-merge contract repair PR #285 is Draft at `7d44caa8d4c09660fb3b5d2d9919d8141c6d5294`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. +- Revalidated the product-gap queue at 135 open pull requests (5 ready, 130 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`, presentation-identity PR #229 is Draft at `3772d6eddfd556b24397afc80780ef3cc980791e`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, subscription repair PR #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`, sandbox-enabled Agent Task evidence PR #70 is Draft at `77eb0f2ee71783e06171784b7173c0b4cd530e61`, and post-merge contract repair PR #285 is Draft at `7d44caa8d4c09660fb3b5d2d9919d8141c6d5294`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 624037a56..b5e53a78b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,20 +6,20 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T17:52:06Z`. +Observed at (UTC): `2026-09-04T20:13:21Z`. - Protected `main` is `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b` through #284. PR #284 changed repository workflows and removed the completed nightly materializer; its integration procedure is recorded separately from the content of that change. -- Full live search returns **146 open pull requests: 5 Ready/non-draft and 141 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. +- Full live search returns **135 open pull requests: 5 Ready/non-draft and 130 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. - Ready roots are #37 `3d5c752cbe14e69e6b72214dd8cc4dc5978d3c10`, #50 `ae2116357194de9705db6fdcfb8fef78ad44fba8`, #219 `a0b520c4aef625f6a10b7bd2f8df6f6f82479ebc`, #240 `76f30fe867ec77ff604de64497889b1026380082`, and #274 `c758e61192805a172a602c798b1d81541380e32a`. Each is mergeable against current protected main with no observed failed current-head check, but its newly generated required checks remain queued and no current-head counted approval exists; none is merge-ready under the active ruleset. PR #37's successor adds the missing `originweave-http` workspace-member assertion after adopting current CI contracts; predecessor head `f0cf2fa27545d71cee06919d83169831a28f94c9` is historical evidence only. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Draft at exact head `7d44caa8d4c09660fb3b5d2d9919d8141c6d5294` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**`: the changelog now records the control-plane change, quality gates identify all-target Clippy as the workspace compile/check gate, and both workflow regressions require one complete concurrency block. Focused and all 152 repository contracts pass locally; hosted checks remain non-terminal. -- Issue #279 owns the remaining documentation-CI partitioning gap. PR #282 is Draft at exact head `ba0c1c998c7750d6c0bc36c1ccf47f06c0ad04a3`, non-destructively current with protected main; its classifier requires complete 40-character SHA-1 or 64-character SHA-256 raw-diff object identities, binds Git rename/copy similarity to blob identity, and records that invariant in the CHANGELOG. Git-canonical paths and contributor/agent-instruction authority remain fail-closed. An authorized non-scheduled workflow owner must connect a trusted protected-base/immutable-SHA classifier to exact base/head raw evidence rather than execute mutable PR-head classification authority. -- PR #283 is Draft at exact head `67228652d096244c6433fa4e78b0cb5949c51850`, non-force stacked on #282 exact `ba0c1c998c7750d6c0bc36c1ccf47f06c0ad04a3`. Its exact parent compare remains one prose-only doctoring canary (+7/-0); exact-head hosted checks remain non-terminal, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. +- Issue #279 owns the remaining documentation-CI partitioning gap. PR #282 is Draft at exact head `5fd4b3d3831a86d5f862dea3bb2eb59963b47727`, non-destructively current with protected main; its classifier requires complete 40-character SHA-1 or 64-character SHA-256 raw-diff object identities, binds Git rename/copy similarity to blob identity, and records that invariant in the CHANGELOG. Git-canonical paths and contributor/agent-instruction authority remain fail-closed. An authorized non-scheduled workflow owner must connect a trusted protected-base/immutable-SHA classifier to exact base/head raw evidence rather than execute mutable PR-head classification authority. +- PR #283 is Draft at exact head `9ab10a75873e8cd6da885053b74a8f78d5e65f60`, non-force stacked on #282 exact `5fd4b3d3831a86d5f862dea3bb2eb59963b47727`. Its exact parent compare remains one prose-only doctoring canary (+7/-0); exact-head hosted checks remain non-terminal, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. - Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0` on #259 exact base `b089c5f584e2a7c3e2c4605a40d2173b3c506e18`. PR #261 is Draft at exact head `95f7548bf07cbba76ab8b40577a11d1b6c99acb5`, stacked on exact #260. Repair PR #277 is Draft at exact head `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`, stacked on exact #261 and preserving typed `SessionSubscribe` correlation. Their local full suites and 100% production coverage succeeded, but exact-head hosted checks remain queued; predecessor evidence does not transfer and stale #262 is not superseded until #277 reaches terminal GREEN. -- PR #70 is Draft at exact head `823e2e29acdbc9a16da733c5a6fc7b9f85cc7527`, current with protected main. Its focused Agent Task contract proves the pre-repair `--no-sandbox` launch as source RED and the branch removes that argument only from the Agent Task lane. Sandbox-enabled pinned-Chromium E2E and repository-wide GREEN remain unproven while its exact-head browser/CI/security runs are non-passing. +- PR #70 is Draft at exact head `77eb0f2ee71783e06171784b7173c0b4cd530e61`, current with protected main. Its focused Agent Task contract proves the pre-repair `--no-sandbox` launch as source RED and the branch removes that argument only from the Agent Task lane. Sandbox-enabled pinned-Chromium E2E and repository-wide GREEN remain unproven while its exact-head browser/CI/security runs are non-passing. - DDD/MCP repair #272 is Draft at exact head `fe124e447cad3f679e22337fb6fbdfd135ab3652`. It preserves MCP as an adapter, contains an observed hosted RED for missing stdio constructors, and carries the bounded adapter-local repair; it remains active-PR evidence until exact-current CI, coverage, rustdoc, review, and security gates complete. -- PR #229 is Draft at exact head `7aa30c57a4af724eb4e601c52c1eaf68f27d1712`. Its presentation-identity work retains the boundary that Chromium application and page-observed effectiveness remain separate adapter/browser-E2E work. Current-head CI/security runs remain non-terminal. +- PR #229 is Draft at exact head `3772d6eddfd556b24397afc80780ef3cc980791e`. Its presentation-identity work retains the boundary that Chromium application and page-observed effectiveness remain separate adapter/browser-E2E work. Current-head CI/security runs remain non-terminal. - PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385` on canonical MV3 parent #43 `6f3134d18d3118aab33d28048671dc71a5f47b77`. Its child delta is diagnostic-evidence contract/doctoring only; inherited #43 implementation redacts browser/page-derived HTTP and WebDriver protocol data, startup exception details, returned capability values, DOM-dataset values, and click post-condition text before CI/audit evidence. Exact-head CI and Manifest V3 Compatibility succeeded and review threads are resolved, but parent-first workflow-ownership verification remains open, so the child stays Draft. - PR #43 is Draft at exact head `6f3134d18d3118aab33d28048671dc71a5f47b77` on current protected main. The branch now installs and configures the pinned `chrome_sandbox`; exact-head hosted verification remains required, and restoring `--no-sandbox` is not acceptable. - PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `c758e61192805a172a602c798b1d81541380e32a`. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index bec4cf3c5..20066c5c0 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -81,9 +81,9 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] self.assertIn("on 2026-09-04", refresh_line) - self.assertIn("146 open pull requests (5 ready, 141 draft)", refresh_line) + self.assertIn("135 open pull requests (5 ready, 130 draft)", refresh_line) self.assertIn("13 open non-PR issues", refresh_line) - self.assertIn("7aa30c57a4af724eb4e601c52c1eaf68f27d1712", refresh_line) + self.assertIn("3772d6eddfd556b24397afc80780ef3cc980791e", refresh_line) self.assertIn("35d12949bde5e5cbc801fdfb433f4a9914bd4fb0", refresh_line) self.assertIn("0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1", refresh_line) self.assertIn( diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index f6b4e4c42..4ef857be0 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -26,9 +26,9 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "## Observed snapshot: 2026-08-29", 1 )[0] for marker in ( - "146 open pull requests", + "135 open pull requests", "5 Ready/non-draft", - "141 Draft", + "130 Draft", "13 open non-PR issues", "4ed08bfa7c063fc7f2ef9278ee8d281887b8296b", "18156473", @@ -41,12 +41,12 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`", "PR #261 is Draft at exact head `95f7548bf07cbba76ab8b40577a11d1b6c99acb5`", "PR #277 is Draft at exact head `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`", - "PR #70 is Draft at exact head `823e2e29acdbc9a16da733c5a6fc7b9f85cc7527`", + "PR #70 is Draft at exact head `77eb0f2ee71783e06171784b7173c0b4cd530e61`", "DDD/MCP repair #272 is Draft at exact head `fe124e447cad3f679e22337fb6fbdfd135ab3652`", - "PR #229 is Draft at exact head `7aa30c57a4af724eb4e601c52c1eaf68f27d1712`", + "PR #229 is Draft at exact head `3772d6eddfd556b24397afc80780ef3cc980791e`", "PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385`", - "PR #282 is Draft at exact head `ba0c1c998c7750d6c0bc36c1ccf47f06c0ad04a3`", - "PR #283 is Draft at exact head `67228652d096244c6433fa4e78b0cb5949c51850`", + "PR #282 is Draft at exact head `5fd4b3d3831a86d5f862dea3bb2eb59963b47727`", + "PR #283 is Draft at exact head `9ab10a75873e8cd6da885053b74a8f78d5e65f60`", "PR #285 is Draft at exact head `7d44caa8d4c09660fb3b5d2d9919d8141c6d5294`", "GitHub Releases is empty", ): @@ -124,7 +124,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "146 open pull requests (5 ready, 141 draft)" + expected = "135 open pull requests (5 ready, 130 draft)" self.assertIn(expected, preamble) self.assertIn("13 open non-PR issues", preamble) self.assertIn(expected, added) From 3494b1f5bc4b430af8f9e3f88bdf644cd4be7bd2 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 05:20:18 +0900 Subject: [PATCH 086/250] docs(gaps): record reduced active queue Signed-off-by: Seongho Bae --- CHANGELOG.md | 4 ++-- docs/product-technical-gap-baseline.md | 4 ++-- tests/test_documentation_active_pr_evidence_contract.py | 2 +- tests/test_gap_snapshot_inventory_consistency.py | 6 +++--- 4 files changed, 8 insertions(+), 8 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index f28e58756..40b5cb006 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,13 +5,13 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. -- Refreshed the product-gap queue to 135 open pull requests (5 ready, 130 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. +- Refreshed the product-gap queue to 129 open pull requests (5 ready, 124 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. - Recorded the current Ready-root heads for #37, #50, #219, #240, and #274 after non-destructive protected-main adoption; their regenerated required checks and counted approvals remain independently required. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. ### Added -- Revalidated the product-gap queue at 135 open pull requests (5 ready, 130 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`, presentation-identity PR #229 is Draft at `3772d6eddfd556b24397afc80780ef3cc980791e`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, subscription repair PR #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`, sandbox-enabled Agent Task evidence PR #70 is Draft at `77eb0f2ee71783e06171784b7173c0b4cd530e61`, and post-merge contract repair PR #285 is Draft at `7d44caa8d4c09660fb3b5d2d9919d8141c6d5294`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. +- Revalidated the product-gap queue at 129 open pull requests (5 ready, 124 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`, presentation-identity PR #229 is Draft at `3772d6eddfd556b24397afc80780ef3cc980791e`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, subscription repair PR #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`, sandbox-enabled Agent Task evidence PR #70 is Draft at `77eb0f2ee71783e06171784b7173c0b4cd530e61`, and post-merge contract repair PR #285 is Draft at `7d44caa8d4c09660fb3b5d2d9919d8141c6d5294`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b5e53a78b..ae4cf9b47 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,10 +6,10 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T20:13:21Z`. +Observed at (UTC): `2026-09-04T20:19:52Z`. - Protected `main` is `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b` through #284. PR #284 changed repository workflows and removed the completed nightly materializer; its integration procedure is recorded separately from the content of that change. -- Full live search returns **135 open pull requests: 5 Ready/non-draft and 130 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. +- Full live search returns **129 open pull requests: 5 Ready/non-draft and 124 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. - Ready roots are #37 `3d5c752cbe14e69e6b72214dd8cc4dc5978d3c10`, #50 `ae2116357194de9705db6fdcfb8fef78ad44fba8`, #219 `a0b520c4aef625f6a10b7bd2f8df6f6f82479ebc`, #240 `76f30fe867ec77ff604de64497889b1026380082`, and #274 `c758e61192805a172a602c798b1d81541380e32a`. Each is mergeable against current protected main with no observed failed current-head check, but its newly generated required checks remain queued and no current-head counted approval exists; none is merge-ready under the active ruleset. PR #37's successor adds the missing `originweave-http` workspace-member assertion after adopting current CI contracts; predecessor head `f0cf2fa27545d71cee06919d83169831a28f94c9` is historical evidence only. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 20066c5c0..515987b0a 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -81,7 +81,7 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] self.assertIn("on 2026-09-04", refresh_line) - self.assertIn("135 open pull requests (5 ready, 130 draft)", refresh_line) + self.assertIn("129 open pull requests (5 ready, 124 draft)", refresh_line) self.assertIn("13 open non-PR issues", refresh_line) self.assertIn("3772d6eddfd556b24397afc80780ef3cc980791e", refresh_line) self.assertIn("35d12949bde5e5cbc801fdfb433f4a9914bd4fb0", refresh_line) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 4ef857be0..c523f5588 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -26,9 +26,9 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "## Observed snapshot: 2026-08-29", 1 )[0] for marker in ( - "135 open pull requests", + "129 open pull requests", "5 Ready/non-draft", - "130 Draft", + "124 Draft", "13 open non-PR issues", "4ed08bfa7c063fc7f2ef9278ee8d281887b8296b", "18156473", @@ -124,7 +124,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "135 open pull requests (5 ready, 130 draft)" + expected = "129 open pull requests (5 ready, 124 draft)" self.assertIn(expected, preamble) self.assertIn("13 open non-PR issues", preamble) self.assertIn(expected, added) From dc5b08e7b9d61763fe75114b61b04eb7ff04b449 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 05:25:41 +0900 Subject: [PATCH 087/250] docs(gaps): record latest queue reduction Signed-off-by: Seongho Bae --- CHANGELOG.md | 4 ++-- docs/product-technical-gap-baseline.md | 4 ++-- tests/test_documentation_active_pr_evidence_contract.py | 2 +- tests/test_gap_snapshot_inventory_consistency.py | 6 +++--- 4 files changed, 8 insertions(+), 8 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 40b5cb006..e0f1cda41 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,13 +5,13 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. -- Refreshed the product-gap queue to 129 open pull requests (5 ready, 124 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. +- Refreshed the product-gap queue to 126 open pull requests (5 ready, 121 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. - Recorded the current Ready-root heads for #37, #50, #219, #240, and #274 after non-destructive protected-main adoption; their regenerated required checks and counted approvals remain independently required. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. ### Added -- Revalidated the product-gap queue at 129 open pull requests (5 ready, 124 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`, presentation-identity PR #229 is Draft at `3772d6eddfd556b24397afc80780ef3cc980791e`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, subscription repair PR #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`, sandbox-enabled Agent Task evidence PR #70 is Draft at `77eb0f2ee71783e06171784b7173c0b4cd530e61`, and post-merge contract repair PR #285 is Draft at `7d44caa8d4c09660fb3b5d2d9919d8141c6d5294`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. +- Revalidated the product-gap queue at 126 open pull requests (5 ready, 121 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`, presentation-identity PR #229 is Draft at `3772d6eddfd556b24397afc80780ef3cc980791e`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, subscription repair PR #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`, sandbox-enabled Agent Task evidence PR #70 is Draft at `77eb0f2ee71783e06171784b7173c0b4cd530e61`, and post-merge contract repair PR #285 is Draft at `7d44caa8d4c09660fb3b5d2d9919d8141c6d5294`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index ae4cf9b47..a0f3a4ddc 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,10 +6,10 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T20:19:52Z`. +Observed at (UTC): `2026-09-04T20:25:14Z`. - Protected `main` is `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b` through #284. PR #284 changed repository workflows and removed the completed nightly materializer; its integration procedure is recorded separately from the content of that change. -- Full live search returns **129 open pull requests: 5 Ready/non-draft and 124 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. +- Full live search returns **126 open pull requests: 5 Ready/non-draft and 121 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. - Ready roots are #37 `3d5c752cbe14e69e6b72214dd8cc4dc5978d3c10`, #50 `ae2116357194de9705db6fdcfb8fef78ad44fba8`, #219 `a0b520c4aef625f6a10b7bd2f8df6f6f82479ebc`, #240 `76f30fe867ec77ff604de64497889b1026380082`, and #274 `c758e61192805a172a602c798b1d81541380e32a`. Each is mergeable against current protected main with no observed failed current-head check, but its newly generated required checks remain queued and no current-head counted approval exists; none is merge-ready under the active ruleset. PR #37's successor adds the missing `originweave-http` workspace-member assertion after adopting current CI contracts; predecessor head `f0cf2fa27545d71cee06919d83169831a28f94c9` is historical evidence only. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 515987b0a..7531776d5 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -81,7 +81,7 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] self.assertIn("on 2026-09-04", refresh_line) - self.assertIn("129 open pull requests (5 ready, 124 draft)", refresh_line) + self.assertIn("126 open pull requests (5 ready, 121 draft)", refresh_line) self.assertIn("13 open non-PR issues", refresh_line) self.assertIn("3772d6eddfd556b24397afc80780ef3cc980791e", refresh_line) self.assertIn("35d12949bde5e5cbc801fdfb433f4a9914bd4fb0", refresh_line) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index c523f5588..ad688a212 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -26,9 +26,9 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "## Observed snapshot: 2026-08-29", 1 )[0] for marker in ( - "129 open pull requests", + "126 open pull requests", "5 Ready/non-draft", - "124 Draft", + "121 Draft", "13 open non-PR issues", "4ed08bfa7c063fc7f2ef9278ee8d281887b8296b", "18156473", @@ -124,7 +124,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "129 open pull requests (5 ready, 124 draft)" + expected = "126 open pull requests (5 ready, 121 draft)" self.assertIn(expected, preamble) self.assertIn("13 open non-PR issues", preamble) self.assertIn(expected, added) From e884e7958c07790883bb38650adb1f35ca7b4435 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 05:29:49 +0900 Subject: [PATCH 088/250] docs(gaps): record cleanup queue reduction Signed-off-by: Seongho Bae --- CHANGELOG.md | 4 ++-- docs/product-technical-gap-baseline.md | 4 ++-- tests/test_documentation_active_pr_evidence_contract.py | 2 +- tests/test_gap_snapshot_inventory_consistency.py | 8 ++++---- 4 files changed, 9 insertions(+), 9 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index e0f1cda41..45ff091d2 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,13 +5,13 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. -- Refreshed the product-gap queue to 126 open pull requests (5 ready, 121 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. +- Refreshed the product-gap queue to 123 open pull requests (5 ready, 118 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. - Recorded the current Ready-root heads for #37, #50, #219, #240, and #274 after non-destructive protected-main adoption; their regenerated required checks and counted approvals remain independently required. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. ### Added -- Revalidated the product-gap queue at 126 open pull requests (5 ready, 121 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`, presentation-identity PR #229 is Draft at `3772d6eddfd556b24397afc80780ef3cc980791e`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, subscription repair PR #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`, sandbox-enabled Agent Task evidence PR #70 is Draft at `77eb0f2ee71783e06171784b7173c0b4cd530e61`, and post-merge contract repair PR #285 is Draft at `7d44caa8d4c09660fb3b5d2d9919d8141c6d5294`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. +- Revalidated the product-gap queue at 123 open pull requests (5 ready, 118 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`, presentation-identity PR #229 is Draft at `3772d6eddfd556b24397afc80780ef3cc980791e`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, subscription repair PR #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`, sandbox-enabled Agent Task evidence PR #70 is Draft at `77eb0f2ee71783e06171784b7173c0b4cd530e61`, and post-merge contract repair PR #285 is Draft at `7d44caa8d4c09660fb3b5d2d9919d8141c6d5294`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index a0f3a4ddc..d8a67a267 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,10 +6,10 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T20:25:14Z`. +Observed at (UTC): `2026-09-04T20:28:51Z`. - Protected `main` is `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b` through #284. PR #284 changed repository workflows and removed the completed nightly materializer; its integration procedure is recorded separately from the content of that change. -- Full live search returns **126 open pull requests: 5 Ready/non-draft and 121 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. +- Full live search returns **123 open pull requests: 5 Ready/non-draft and 118 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. - Ready roots are #37 `3d5c752cbe14e69e6b72214dd8cc4dc5978d3c10`, #50 `ae2116357194de9705db6fdcfb8fef78ad44fba8`, #219 `a0b520c4aef625f6a10b7bd2f8df6f6f82479ebc`, #240 `76f30fe867ec77ff604de64497889b1026380082`, and #274 `c758e61192805a172a602c798b1d81541380e32a`. Each is mergeable against current protected main with no observed failed current-head check, but its newly generated required checks remain queued and no current-head counted approval exists; none is merge-ready under the active ruleset. PR #37's successor adds the missing `originweave-http` workspace-member assertion after adopting current CI contracts; predecessor head `f0cf2fa27545d71cee06919d83169831a28f94c9` is historical evidence only. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 7531776d5..ee180be6a 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -81,7 +81,7 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] self.assertIn("on 2026-09-04", refresh_line) - self.assertIn("126 open pull requests (5 ready, 121 draft)", refresh_line) + self.assertIn("123 open pull requests (5 ready, 118 draft)", refresh_line) self.assertIn("13 open non-PR issues", refresh_line) self.assertIn("3772d6eddfd556b24397afc80780ef3cc980791e", refresh_line) self.assertIn("35d12949bde5e5cbc801fdfb433f4a9914bd4fb0", refresh_line) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index ad688a212..213693f04 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -26,9 +26,9 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "## Observed snapshot: 2026-08-29", 1 )[0] for marker in ( - "126 open pull requests", + "123 open pull requests", "5 Ready/non-draft", - "121 Draft", + "118 Draft", "13 open non-PR issues", "4ed08bfa7c063fc7f2ef9278ee8d281887b8296b", "18156473", @@ -70,7 +70,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "142 open pull requests", "24 Ready/non-draft", "138 Draft", - "118 Draft", + "121 Draft", "12 open non-PR issues", "10 central required workflows", "6 central required workflows", @@ -124,7 +124,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "126 open pull requests (5 ready, 121 draft)" + expected = "123 open pull requests (5 ready, 118 draft)" self.assertIn(expected, preamble) self.assertIn("13 open non-PR issues", preamble) self.assertIn(expected, added) From a08b3665f3ea4bc22545bc3fb7af24712302044f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 07:36:10 +0900 Subject: [PATCH 089/250] docs: refresh ready-root exact heads Signed-off-by: Seongho Bae --- CHANGELOG.md | 2 +- docs/product-technical-gap-baseline.md | 6 +++--- tests/test_gap_snapshot_inventory_consistency.py | 2 +- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 9fa313057..383bbc80e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,7 +6,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. - Refreshed the product-gap queue to 124 open pull requests (5 ready, 119 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. -- Recorded the current Ready-root heads for #37, #50, #219, #240, and #274; each still requires adoption of the current protected-main generation, exact-head checks, and counted approval. +- Recorded the current Ready-root heads for #37, #50, #219, #240, and #274 after non-force adoption of the current protected-main generation; regenerated hosted checks and counted approval remain independently required. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 8df80863c..1914aeb90 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,11 +6,11 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T22:17:58Z`. +Observed at (UTC): `2026-09-04T22:35:39Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **124 open pull requests: 5 Ready/non-draft and 119 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. -- Ready roots are #37 `3d5c752cbe14e69e6b72214dd8cc4dc5978d3c10`, #50 `ae2116357194de9705db6fdcfb8fef78ad44fba8`, #219 `a0b520c4aef625f6a10b7bd2f8df6f6f82479ebc`, #240 `76f30fe867ec77ff604de64497889b1026380082`, and #274 `c758e61192805a172a602c798b1d81541380e32a`. All five still name the previous protected-main generation `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b` as their base, so exact-current-base checks and counted approval are absent. PR #37 and #50 Noema reruns are queued after their predecessor attempts failed closed on an upstream gateway HTTP 502; none of the five is merge-ready. +- Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, and #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`. Each now contains current protected main through a non-force merge and passed its exact-head local Python/Rust/100%-coverage gates. Hosted checks were regenerated and counted approval remains absent, so none is merge-ready. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Draft at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass; draft-hosted jobs are skipped and central checks remain non-terminal. @@ -22,7 +22,7 @@ Observed at (UTC): `2026-09-04T22:17:58Z`. - PR #229 is Draft at exact head `3772d6eddfd556b24397afc80780ef3cc980791e`. Its presentation-identity work retains the boundary that Chromium application and page-observed effectiveness remain separate adapter/browser-E2E work. Current-head CI/security runs remain non-terminal. - PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385` on canonical MV3 parent #43 `6f3134d18d3118aab33d28048671dc71a5f47b77`. Its child delta is diagnostic-evidence contract/doctoring only; inherited #43 implementation redacts browser/page-derived HTTP and WebDriver protocol data, startup exception details, returned capability values, DOM-dataset values, and click post-condition text before CI/audit evidence. Exact-head CI and Manifest V3 Compatibility succeeded and review threads are resolved, but parent-first workflow-ownership verification remains open, so the child stays Draft. - PR #43 is Draft at exact head `6f3134d18d3118aab33d28048671dc71a5f47b77`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. The branch now installs and configures the pinned `chrome_sandbox`; exact-head hosted verification remains required, and restoring `--no-sandbox` is not acceptable. -- PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `c758e61192805a172a602c798b1d81541380e32a`. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. +- PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. - Issue #201's release/SBOM lane remains dependency ordered, and GitHub Releases is empty. OriginWeave remains pre-GA until exact protected-head versioning, signed artifacts, SBOM/provenance, reproducibility, rollback, compatibility, security, and commercial-acceptance evidence exist. - The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #28 the first complete Chromium Agent Task vertical slice, #199 durable WARC/PROV and retention/replay, #200 stable BAP/MCP runtime API, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 enterprise identity/tenant/policy/approval/audit/SLO operations, #203 exact-artifact commercial acceptance, #276 contextual-orchestrator migration, and #279 exact-head documentation verification without unnecessary Rust queue load. - Current evidence procedure remains fail-closed: queued reviewer evidence is non-passing; paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index a129a3cb1..4ce3d2168 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -35,7 +35,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `3d5c752cbe14e69e6b72214dd8cc4dc5978d3c10`, #50 `ae2116357194de9705db6fdcfb8fef78ad44fba8`, #219 `a0b520c4aef625f6a10b7bd2f8df6f6f82479ebc`, #240 `76f30fe867ec77ff604de64497889b1026380082`, and #274 `c758e61192805a172a602c798b1d81541380e32a`", + "Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, and #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", "PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`", From 742d2067958c238e88f31d4504b7e1818086b78f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 07:39:09 +0900 Subject: [PATCH 090/250] docs: record baseline review readiness Signed-off-by: Seongho Bae --- CHANGELOG.md | 4 ++-- docs/product-technical-gap-baseline.md | 4 ++-- tests/test_documentation_active_pr_evidence_contract.py | 2 +- tests/test_gap_snapshot_inventory_consistency.py | 6 +++--- 4 files changed, 8 insertions(+), 8 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 383bbc80e..415af4a48 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,13 +5,13 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. -- Refreshed the product-gap queue to 124 open pull requests (5 ready, 119 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. +- Refreshed the product-gap queue to 124 open pull requests (6 ready, 118 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. - Recorded the current Ready-root heads for #37, #50, #219, #240, and #274 after non-force adoption of the current protected-main generation; regenerated hosted checks and counted approval remain independently required. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. ### Added -- Revalidated the product-gap queue at 124 open pull requests (5 ready, 119 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Draft at `3772d6eddfd556b24397afc80780ef3cc980791e`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, subscription repair PR #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`, sandbox-enabled Agent Task evidence PR #70 is Draft at `77eb0f2ee71783e06171784b7173c0b4cd530e61`, classifier foundation PR #287 is Draft at `bb052af8a9c27d88561bd5b2f98b6a7a74808af9`, and post-merge contract repair PR #285 is Draft at `f455c2cd64b3dd3f027c91d396103792a205ddd0`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. +- Revalidated the product-gap queue at 124 open pull requests (6 ready, 118 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Draft at `3772d6eddfd556b24397afc80780ef3cc980791e`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, subscription repair PR #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`, sandbox-enabled Agent Task evidence PR #70 is Draft at `77eb0f2ee71783e06171784b7173c0b4cd530e61`, classifier foundation PR #287 is Draft at `bb052af8a9c27d88561bd5b2f98b6a7a74808af9`, and post-merge contract repair PR #285 is Draft at `f455c2cd64b3dd3f027c91d396103792a205ddd0`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 1914aeb90..7bad09652 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,10 +6,10 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T22:35:39Z`. +Observed at (UTC): `2026-09-04T22:38:44Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. -- Full live search returns **124 open pull requests: 5 Ready/non-draft and 119 Draft; 13 open non-PR issues**. Queue movement is not protected-main delivery. +- Full live search returns **124 open pull requests: 6 Ready/non-draft and 118 Draft; 13 open non-PR issues**. PR #238 is the sixth Ready item after its exact-head local gates completed; queue movement is not protected-main delivery. - Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, and #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`. Each now contains current protected main through a non-force merge and passed its exact-head local Python/Rust/100%-coverage gates. Hosted checks were regenerated and counted approval remains absent, so none is merge-ready. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 15b3092da..743b91399 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -81,7 +81,7 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] self.assertIn("on 2026-09-04", refresh_line) - self.assertIn("124 open pull requests (5 ready, 119 draft)", refresh_line) + self.assertIn("124 open pull requests (6 ready, 118 draft)", refresh_line) self.assertIn("13 open non-PR issues", refresh_line) self.assertIn("3772d6eddfd556b24397afc80780ef3cc980791e", refresh_line) self.assertIn("35d12949bde5e5cbc801fdfb433f4a9914bd4fb0", refresh_line) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 4ce3d2168..cc91d2fbb 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -27,8 +27,8 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: )[0] for marker in ( "124 open pull requests", - "5 Ready/non-draft", - "119 Draft", + "6 Ready/non-draft", + "118 Draft", "13 open non-PR issues", "87c4daa1830bac5a5228b6036752ad5633232085", "18156473", @@ -126,7 +126,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "124 open pull requests (5 ready, 119 draft)" + expected = "124 open pull requests (6 ready, 118 draft)" self.assertIn(expected, preamble) self.assertIn("13 open non-PR issues", preamble) self.assertIn(expected, added) From 31749f22a951119c838cf090748e56b6a4cfabcc Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 08:12:30 +0900 Subject: [PATCH 091/250] docs: refresh exact live delivery state Signed-off-by: Seongho Bae --- CHANGELOG.md | 6 +++--- docs/product-technical-gap-baseline.md | 11 ++++++----- .../test_documentation_active_pr_evidence_contract.py | 2 +- tests/test_gap_snapshot_inventory_consistency.py | 10 +++++----- 4 files changed, 15 insertions(+), 14 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 415af4a48..5d773908d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,13 +5,13 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. -- Refreshed the product-gap queue to 124 open pull requests (6 ready, 118 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. -- Recorded the current Ready-root heads for #37, #50, #219, #240, and #274 after non-force adoption of the current protected-main generation; regenerated hosted checks and counted approval remain independently required. +- Refreshed the product-gap queue to 124 open pull requests (7 ready, 117 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. +- Recorded the current Ready-root heads for #37, #50, #219, #238, #240, #274, and #287; hosted exact-head checks remain queued and counted approval remains absent. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. ### Added -- Revalidated the product-gap queue at 124 open pull requests (6 ready, 118 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Draft at `3772d6eddfd556b24397afc80780ef3cc980791e`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, subscription repair PR #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`, sandbox-enabled Agent Task evidence PR #70 is Draft at `77eb0f2ee71783e06171784b7173c0b4cd530e61`, classifier foundation PR #287 is Draft at `bb052af8a9c27d88561bd5b2f98b6a7a74808af9`, and post-merge contract repair PR #285 is Draft at `f455c2cd64b3dd3f027c91d396103792a205ddd0`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. +- Revalidated the product-gap queue at 124 open pull requests (7 ready, 117 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Draft at `3772d6eddfd556b24397afc80780ef3cc980791e`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, subscription repair #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1` with cancelled hosted Rust and coverage checks, classifier foundation #287 is Ready at `ab6d5d1a04a020f37727e2f5a6950c58feae8559`, and stacked repairs #178/#85 are conflict-free at their new exact heads. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 7bad09652..d43ed4e1f 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,17 +6,18 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T22:38:44Z`. +Observed at (UTC): `2026-09-04T23:08:49Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. -- Full live search returns **124 open pull requests: 6 Ready/non-draft and 118 Draft; 13 open non-PR issues**. PR #238 is the sixth Ready item after its exact-head local gates completed; queue movement is not protected-main delivery. -- Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, and #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`. Each now contains current protected main through a non-force merge and passed its exact-head local Python/Rust/100%-coverage gates. Hosted checks were regenerated and counted approval remains absent, so none is merge-ready. +- Full live search returns **124 open pull requests: 7 Ready/non-draft and 117 Draft; 13 open non-PR issues**. PR #287 became the seventh Ready item after its workflow-independent classifier repair; queue movement is not protected-main delivery. +- Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #238 `742d2067958c238e88f31d4504b7e1818086b78f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`. Their hosted exact-head checks remain queued and none has an eligible exact-head approval, so none is merge-ready. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Draft at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass; draft-hosted jobs are skipped and central checks remain non-terminal. -- Issue #279 owns the remaining documentation-CI partitioning gap. PR #287 is Draft at exact head `bb052af8a9c27d88561bd5b2f98b6a7a74808af9` on current protected main; it is the workflow-independent classifier foundation, changes no `.github/**` path, and is the prerequisite for an authorized workflow owner. PR #282 is Draft at exact head `b54a5856d8201911f05d69622f0d5594a371adf0` on current protected main; its trusted protected-base classifier successor requires exact base/head raw evidence, binds Git rename/copy similarity to blob identity, and retains fail-closed path and instruction-authority rules. Local checks do not substitute for its skipped draft jobs or current-head hosted evidence. +- Issue #279 owns the remaining documentation-CI partitioning gap. PR #287 is Ready at exact head `ab6d5d1a04a020f37727e2f5a6950c58feae8559` on current protected main; it is the workflow-independent classifier foundation, changes no `.github/**` path, and is the prerequisite for an authorized workflow owner. Its exact-head hosted checks remain queued and no eligible approval exists. PR #282 is Draft at exact head `b54a5856d8201911f05d69622f0d5594a371adf0` on current protected main; its trusted protected-base classifier successor requires exact base/head raw evidence, binds Git rename/copy similarity to blob identity, and retains fail-closed path and instruction-authority rules. Local checks do not substitute for its skipped draft jobs or current-head hosted evidence. - PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`, non-force stacked on #282 exact `b54a5856d8201911f05d69622f0d5594a371adf0`. Its exact parent compare remains one prose-only doctoring canary; draft-hosted jobs are skipped, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. -- Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0` on #259 exact base `b089c5f584e2a7c3e2c4605a40d2173b3c506e18`. PR #261 is Draft at exact head `95f7548bf07cbba76ab8b40577a11d1b6c99acb5`, stacked on exact #260. Repair PR #277 is Draft at exact head `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`, stacked on exact #261 and preserving typed `SessionSubscribe` correlation. Their local full suites and 100% production coverage succeeded, but exact-head hosted checks remain queued; predecessor evidence does not transfer and stale #262 is not superseded until #277 reaches terminal GREEN. +- Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0` on #259 exact base `b089c5f584e2c4605a40d2173b3c506e18`. PR #261 is Draft at exact head `95f7548bf07cbba76ab8b40577a11d1b6c99acb5`, stacked on exact #260. Repair PR #277 is Draft at exact head `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`, stacked on exact #261 and preserving typed `SessionSubscribe` correlation. Its hosted Rust and production-coverage jobs were cancelled, so stale conflicting #262 is not superseded and remains dependency-blocked until #277 reaches terminal GREEN on the unchanged head. +- Stacked PRs #178 and #85 were repaired without force pushes at exact heads `640e594dbc0a64f251a0f28b8e80943f53337e40` and `c9adea680d6186f1842a280e248ce55da4f1305b`. Parent-relative deltas now preserve the current MV3 diagnostic and extension-authority contracts; local full suites and exact 100% coverage passed, while hosted exact-head acceptance remains independently required. - PR #70 is Draft at exact head `77eb0f2ee71783e06171784b7173c0b4cd530e61`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. Its focused Agent Task contract proves the pre-repair `--no-sandbox` launch as source RED and the branch removes that argument only from the Agent Task lane. Sandbox-enabled pinned-Chromium E2E and repository-wide GREEN remain unproven while its exact-head browser/CI/security runs are non-passing. - DDD/MCP repair #272 is Draft at exact head `fe124e447cad3f679e22337fb6fbdfd135ab3652`. Its documentation child PR #273 is Draft at exact head `e5c8fcb66bf644dfa750bb1b40ba3d600cb7805a` on that exact parent; all 159 repository contracts, full Rust gates, and exact 100% local coverage pass, while remote jobs remain queued. Both remain active-PR evidence until exact-current CI, review, and security gates complete. - PR #229 is Draft at exact head `3772d6eddfd556b24397afc80780ef3cc980791e`. Its presentation-identity work retains the boundary that Chromium application and page-observed effectiveness remain separate adapter/browser-E2E work. Current-head CI/security runs remain non-terminal. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 743b91399..b70525706 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -81,7 +81,7 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] self.assertIn("on 2026-09-04", refresh_line) - self.assertIn("124 open pull requests (6 ready, 118 draft)", refresh_line) + self.assertIn("124 open pull requests (7 ready, 117 draft)", refresh_line) self.assertIn("13 open non-PR issues", refresh_line) self.assertIn("3772d6eddfd556b24397afc80780ef3cc980791e", refresh_line) self.assertIn("35d12949bde5e5cbc801fdfb433f4a9914bd4fb0", refresh_line) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index cc91d2fbb..685a496b1 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -27,15 +27,15 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: )[0] for marker in ( "124 open pull requests", - "6 Ready/non-draft", - "118 Draft", + "7 Ready/non-draft", + "117 Draft", "13 open non-PR issues", "87c4daa1830bac5a5228b6036752ad5633232085", "18156473", "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, and #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`", + "Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #238 `742d2067958c238e88f31d4504b7e1818086b78f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", "PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`", @@ -48,7 +48,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #282 is Draft at exact head `b54a5856d8201911f05d69622f0d5594a371adf0`", "PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`", "PR #285 is Draft at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0`", - "PR #287 is Draft at exact head `bb052af8a9c27d88561bd5b2f98b6a7a74808af9`", + "PR #287 is Ready at exact head `ab6d5d1a04a020f37727e2f5a6950c58feae8559`", "PR #273 is Draft at exact head `e5c8fcb66bf644dfa750bb1b40ba3d600cb7805a`", "GitHub Releases is empty", ): @@ -126,7 +126,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "124 open pull requests (6 ready, 118 draft)" + expected = "124 open pull requests (7 ready, 117 draft)" self.assertIn(expected, preamble) self.assertIn("13 open non-PR issues", preamble) self.assertIn(expected, added) From 69079755450a4e3e316e75c7c32cadb17231d1f0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 08:22:05 +0900 Subject: [PATCH 092/250] docs: record enterprise approval review readiness Signed-off-by: Seongho Bae --- CHANGELOG.md | 6 +++--- docs/product-technical-gap-baseline.md | 6 +++--- tests/test_documentation_active_pr_evidence_contract.py | 2 +- tests/test_gap_snapshot_inventory_consistency.py | 8 ++++---- 4 files changed, 11 insertions(+), 11 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 5d773908d..37c42868c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,13 +5,13 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. -- Refreshed the product-gap queue to 124 open pull requests (7 ready, 117 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. -- Recorded the current Ready-root heads for #37, #50, #219, #238, #240, #274, and #287; hosted exact-head checks remain queued and counted approval remains absent. +- Refreshed the product-gap queue to 124 open pull requests (8 ready, 116 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. +- Recorded the current Ready-root heads for #37, #50, #219, #220, #238, #240, #274, and #287; hosted exact-head checks remain non-terminal and counted approval remains absent. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. ### Added -- Revalidated the product-gap queue at 124 open pull requests (7 ready, 117 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Draft at `3772d6eddfd556b24397afc80780ef3cc980791e`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, subscription repair #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1` with cancelled hosted Rust and coverage checks, classifier foundation #287 is Ready at `ab6d5d1a04a020f37727e2f5a6950c58feae8559`, and stacked repairs #178/#85 are conflict-free at their new exact heads. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. +- Revalidated the product-gap queue at 124 open pull requests (8 ready, 116 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Draft at `3772d6eddfd556b24397afc80780ef3cc980791e`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, subscription repair #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1` with a fresh rerun queued, classifier foundation #287 is Ready at `ab6d5d1a04a020f37727e2f5a6950c58feae8559`, and stacked repairs #178/#85 are conflict-free at their new exact heads. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index d43ed4e1f..8c4037b88 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,11 +6,11 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T23:08:49Z`. +Observed at (UTC): `2026-09-04T23:19:40Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. -- Full live search returns **124 open pull requests: 7 Ready/non-draft and 117 Draft; 13 open non-PR issues**. PR #287 became the seventh Ready item after its workflow-independent classifier repair; queue movement is not protected-main delivery. -- Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #238 `742d2067958c238e88f31d4504b7e1818086b78f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`. Their hosted exact-head checks remain queued and none has an eligible exact-head approval, so none is merge-ready. +- Full live search returns **124 open pull requests: 8 Ready/non-draft and 116 Draft; 13 open non-PR issues**. PR #220 became the eighth Ready item after adopting current protected main and passing its full local gates; queue movement is not protected-main delivery. +- Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #238 `31749f22a951119c838cf090748e56b6a4cfabcc`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Draft at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass; draft-hosted jobs are skipped and central checks remain non-terminal. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index b70525706..624b62447 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -81,7 +81,7 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] self.assertIn("on 2026-09-04", refresh_line) - self.assertIn("124 open pull requests (7 ready, 117 draft)", refresh_line) + self.assertIn("124 open pull requests (8 ready, 116 draft)", refresh_line) self.assertIn("13 open non-PR issues", refresh_line) self.assertIn("3772d6eddfd556b24397afc80780ef3cc980791e", refresh_line) self.assertIn("35d12949bde5e5cbc801fdfb433f4a9914bd4fb0", refresh_line) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 685a496b1..e71d918d1 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -27,15 +27,15 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: )[0] for marker in ( "124 open pull requests", - "7 Ready/non-draft", - "117 Draft", + "8 Ready/non-draft", + "116 Draft", "13 open non-PR issues", "87c4daa1830bac5a5228b6036752ad5633232085", "18156473", "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #238 `742d2067958c238e88f31d4504b7e1818086b78f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`", + "Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #238 `31749f22a951119c838cf090748e56b6a4cfabcc`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", "PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`", @@ -126,7 +126,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "124 open pull requests (7 ready, 117 draft)" + expected = "124 open pull requests (8 ready, 116 draft)" self.assertIn(expected, preamble) self.assertIn("13 open non-PR issues", preamble) self.assertIn(expected, added) From b28424647849eff829f1c9c5fd155988c7785c79 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 08:24:54 +0900 Subject: [PATCH 093/250] docs: record JSON envelope review readiness Signed-off-by: Seongho Bae --- CHANGELOG.md | 6 +++--- docs/product-technical-gap-baseline.md | 6 +++--- tests/test_documentation_active_pr_evidence_contract.py | 2 +- tests/test_gap_snapshot_inventory_consistency.py | 8 ++++---- 4 files changed, 11 insertions(+), 11 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 37c42868c..b62ca0797 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,13 +5,13 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. -- Refreshed the product-gap queue to 124 open pull requests (8 ready, 116 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. -- Recorded the current Ready-root heads for #37, #50, #219, #220, #238, #240, #274, and #287; hosted exact-head checks remain non-terminal and counted approval remains absent. +- Refreshed the product-gap queue to 124 open pull requests (9 ready, 115 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. +- Recorded the current Ready-root heads for #37, #50, #219, #220, #238, #240, #247, #274, and #287; hosted exact-head checks remain non-terminal and counted approval remains absent. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. ### Added -- Revalidated the product-gap queue at 124 open pull requests (8 ready, 116 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Draft at `3772d6eddfd556b24397afc80780ef3cc980791e`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, subscription repair #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1` with a fresh rerun queued, classifier foundation #287 is Ready at `ab6d5d1a04a020f37727e2f5a6950c58feae8559`, and stacked repairs #178/#85 are conflict-free at their new exact heads. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. +- Revalidated the product-gap queue at 124 open pull requests (9 ready, 115 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Draft at `3772d6eddfd556b24397afc80780ef3cc980791e`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 is Ready at `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, subscription repair #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1` with a fresh rerun queued, classifier foundation #287 is Ready at `ab6d5d1a04a020f37727e2f5a6950c58feae8559`, and stacked repairs #178/#85 are conflict-free at their new exact heads. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 8c4037b88..3929fb340 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,11 +6,11 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T23:19:40Z`. +Observed at (UTC): `2026-09-04T23:23:16Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. -- Full live search returns **124 open pull requests: 8 Ready/non-draft and 116 Draft; 13 open non-PR issues**. PR #220 became the eighth Ready item after adopting current protected main and passing its full local gates; queue movement is not protected-main delivery. -- Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #238 `31749f22a951119c838cf090748e56b6a4cfabcc`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Full live search returns **124 open pull requests: 9 Ready/non-draft and 115 Draft; 13 open non-PR issues**. PR #247 also became Ready on a new exact head while this snapshot was being refreshed; queue movement is not protected-main delivery. +- Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #238 `69079755450a4e3e316e75c7c32cadb17231d1f0`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Draft at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass; draft-hosted jobs are skipped and central checks remain non-terminal. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 624b62447..d0b98f4fa 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -81,7 +81,7 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] self.assertIn("on 2026-09-04", refresh_line) - self.assertIn("124 open pull requests (8 ready, 116 draft)", refresh_line) + self.assertIn("124 open pull requests (9 ready, 115 draft)", refresh_line) self.assertIn("13 open non-PR issues", refresh_line) self.assertIn("3772d6eddfd556b24397afc80780ef3cc980791e", refresh_line) self.assertIn("35d12949bde5e5cbc801fdfb433f4a9914bd4fb0", refresh_line) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index e71d918d1..014931cce 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -27,15 +27,15 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: )[0] for marker in ( "124 open pull requests", - "8 Ready/non-draft", - "116 Draft", + "9 Ready/non-draft", + "115 Draft", "13 open non-PR issues", "87c4daa1830bac5a5228b6036752ad5633232085", "18156473", "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #238 `31749f22a951119c838cf090748e56b6a4cfabcc`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`", + "Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #238 `69079755450a4e3e316e75c7c32cadb17231d1f0`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", "PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`", @@ -126,7 +126,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "124 open pull requests (8 ready, 116 draft)" + expected = "124 open pull requests (9 ready, 115 draft)" self.assertIn(expected, preamble) self.assertIn("13 open non-PR issues", preamble) self.assertIn(expected, added) From 674cb0763973d8d1b5757402a9b847530db4c654 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 08:31:04 +0900 Subject: [PATCH 094/250] docs: record denial error review readiness Signed-off-by: Seongho Bae --- CHANGELOG.md | 6 +++--- docs/product-technical-gap-baseline.md | 6 +++--- tests/test_documentation_active_pr_evidence_contract.py | 2 +- tests/test_gap_snapshot_inventory_consistency.py | 8 ++++---- 4 files changed, 11 insertions(+), 11 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index b62ca0797..c5a24b8dc 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,13 +5,13 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. -- Refreshed the product-gap queue to 124 open pull requests (9 ready, 115 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. -- Recorded the current Ready-root heads for #37, #50, #219, #220, #238, #240, #247, #274, and #287; hosted exact-head checks remain non-terminal and counted approval remains absent. +- Refreshed the product-gap queue to 124 open pull requests (10 ready, 114 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. +- Recorded the current Ready-root heads for #37, #50, #166, #219, #220, #238, #240, #247, #274, and #287; hosted exact-head checks remain non-terminal and counted approval remains absent. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. ### Added -- Revalidated the product-gap queue at 124 open pull requests (9 ready, 115 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Draft at `3772d6eddfd556b24397afc80780ef3cc980791e`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 is Ready at `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, subscription repair #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1` with a fresh rerun queued, classifier foundation #287 is Ready at `ab6d5d1a04a020f37727e2f5a6950c58feae8559`, and stacked repairs #178/#85 are conflict-free at their new exact heads. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. +- Revalidated the product-gap queue at 124 open pull requests (10 ready, 114 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Draft at `3772d6eddfd556b24397afc80780ef3cc980791e`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, denial-error PR #166 is Ready at `e84a1a2cc82b1c666218efd441da97849f47b8c2`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 is Ready at `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, subscription repair #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1` with a fresh rerun queued, and classifier foundation #287 is Ready at `ab6d5d1a04a020f37727e2f5a6950c58feae8559`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 3929fb340..fa63dbb8c 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,11 +6,11 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T23:23:16Z`. +Observed at (UTC): `2026-09-04T23:29:48Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. -- Full live search returns **124 open pull requests: 9 Ready/non-draft and 115 Draft; 13 open non-PR issues**. PR #247 also became Ready on a new exact head while this snapshot was being refreshed; queue movement is not protected-main delivery. -- Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #238 `69079755450a4e3e316e75c7c32cadb17231d1f0`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Full live search returns **124 open pull requests: 10 Ready/non-draft and 114 Draft; 13 open non-PR issues**. PR #166 became Ready after adopting current protected main and passing its full local gates; queue movement is not protected-main delivery. +- Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #238 `b28424647849eff829f1c9c5fd155988c7785c79`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Draft at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass; draft-hosted jobs are skipped and central checks remain non-terminal. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index d0b98f4fa..98972c9db 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -81,7 +81,7 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] self.assertIn("on 2026-09-04", refresh_line) - self.assertIn("124 open pull requests (9 ready, 115 draft)", refresh_line) + self.assertIn("124 open pull requests (10 ready, 114 draft)", refresh_line) self.assertIn("13 open non-PR issues", refresh_line) self.assertIn("3772d6eddfd556b24397afc80780ef3cc980791e", refresh_line) self.assertIn("35d12949bde5e5cbc801fdfb433f4a9914bd4fb0", refresh_line) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 014931cce..8f560997a 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -27,15 +27,15 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: )[0] for marker in ( "124 open pull requests", - "9 Ready/non-draft", - "115 Draft", + "10 Ready/non-draft", + "114 Draft", "13 open non-PR issues", "87c4daa1830bac5a5228b6036752ad5633232085", "18156473", "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #238 `69079755450a4e3e316e75c7c32cadb17231d1f0`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`", + "Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #238 `b28424647849eff829f1c9c5fd155988c7785c79`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", "PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`", @@ -126,7 +126,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "124 open pull requests (9 ready, 115 draft)" + expected = "124 open pull requests (10 ready, 114 draft)" self.assertIn(expected, preamble) self.assertIn("13 open non-PR issues", preamble) self.assertIn(expected, added) From e8565d30a64fa9f8b78f85dcfdd7c77f0f173973 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 08:31:04 +0900 Subject: [PATCH 095/250] docs: record denial error review readiness Signed-off-by: Seongho Bae --- CHANGELOG.md | 6 +++--- docs/product-technical-gap-baseline.md | 6 +++--- tests/test_documentation_active_pr_evidence_contract.py | 2 +- tests/test_gap_snapshot_inventory_consistency.py | 8 ++++---- 4 files changed, 11 insertions(+), 11 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index b62ca0797..c5a24b8dc 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,13 +5,13 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. -- Refreshed the product-gap queue to 124 open pull requests (9 ready, 115 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. -- Recorded the current Ready-root heads for #37, #50, #219, #220, #238, #240, #247, #274, and #287; hosted exact-head checks remain non-terminal and counted approval remains absent. +- Refreshed the product-gap queue to 124 open pull requests (10 ready, 114 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. +- Recorded the current Ready-root heads for #37, #50, #166, #219, #220, #238, #240, #247, #274, and #287; hosted exact-head checks remain non-terminal and counted approval remains absent. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. ### Added -- Revalidated the product-gap queue at 124 open pull requests (9 ready, 115 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Draft at `3772d6eddfd556b24397afc80780ef3cc980791e`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 is Ready at `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, subscription repair #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1` with a fresh rerun queued, classifier foundation #287 is Ready at `ab6d5d1a04a020f37727e2f5a6950c58feae8559`, and stacked repairs #178/#85 are conflict-free at their new exact heads. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. +- Revalidated the product-gap queue at 124 open pull requests (10 ready, 114 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Draft at `3772d6eddfd556b24397afc80780ef3cc980791e`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, denial-error PR #166 is Ready at `e84a1a2cc82b1c666218efd441da97849f47b8c2`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 is Ready at `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, subscription repair #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1` with a fresh rerun queued, and classifier foundation #287 is Ready at `ab6d5d1a04a020f37727e2f5a6950c58feae8559`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 3929fb340..fa63dbb8c 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,11 +6,11 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T23:23:16Z`. +Observed at (UTC): `2026-09-04T23:29:48Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. -- Full live search returns **124 open pull requests: 9 Ready/non-draft and 115 Draft; 13 open non-PR issues**. PR #247 also became Ready on a new exact head while this snapshot was being refreshed; queue movement is not protected-main delivery. -- Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #238 `69079755450a4e3e316e75c7c32cadb17231d1f0`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Full live search returns **124 open pull requests: 10 Ready/non-draft and 114 Draft; 13 open non-PR issues**. PR #166 became Ready after adopting current protected main and passing its full local gates; queue movement is not protected-main delivery. +- Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #238 `b28424647849eff829f1c9c5fd155988c7785c79`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Draft at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass; draft-hosted jobs are skipped and central checks remain non-terminal. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index d0b98f4fa..98972c9db 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -81,7 +81,7 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] self.assertIn("on 2026-09-04", refresh_line) - self.assertIn("124 open pull requests (9 ready, 115 draft)", refresh_line) + self.assertIn("124 open pull requests (10 ready, 114 draft)", refresh_line) self.assertIn("13 open non-PR issues", refresh_line) self.assertIn("3772d6eddfd556b24397afc80780ef3cc980791e", refresh_line) self.assertIn("35d12949bde5e5cbc801fdfb433f4a9914bd4fb0", refresh_line) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 014931cce..8f560997a 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -27,15 +27,15 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: )[0] for marker in ( "124 open pull requests", - "9 Ready/non-draft", - "115 Draft", + "10 Ready/non-draft", + "114 Draft", "13 open non-PR issues", "87c4daa1830bac5a5228b6036752ad5633232085", "18156473", "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #238 `69079755450a4e3e316e75c7c32cadb17231d1f0`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`", + "Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #238 `b28424647849eff829f1c9c5fd155988c7785c79`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", "PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`", @@ -126,7 +126,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "124 open pull requests (9 ready, 115 draft)" + expected = "124 open pull requests (10 ready, 114 draft)" self.assertIn(expected, preamble) self.assertIn("13 open non-PR issues", preamble) self.assertIn(expected, added) From 21d8a367c9f725a06af0bd2fb781d63f7c8c849c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 08:39:11 +0900 Subject: [PATCH 096/250] docs: record governance repair readiness Signed-off-by: Seongho Bae --- CHANGELOG.md | 6 +++--- docs/product-technical-gap-baseline.md | 10 +++++----- ...test_documentation_active_pr_evidence_contract.py | 2 +- tests/test_gap_snapshot_inventory_consistency.py | 12 ++++++------ 4 files changed, 15 insertions(+), 15 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index c5a24b8dc..412fe9de8 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,13 +5,13 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. -- Refreshed the product-gap queue to 124 open pull requests (10 ready, 114 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. -- Recorded the current Ready-root heads for #37, #50, #166, #219, #220, #238, #240, #247, #274, and #287; hosted exact-head checks remain non-terminal and counted approval remains absent. +- Refreshed the product-gap queue to 124 open pull requests (12 ready, 112 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. +- Recorded the current Ready-root heads for #37, #50, #166, #219, #220, #238, #240, #247, #272, #274, #285, and #287; hosted exact-head checks remain non-terminal and counted approval remains absent. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. ### Added -- Revalidated the product-gap queue at 124 open pull requests (10 ready, 114 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Draft at `3772d6eddfd556b24397afc80780ef3cc980791e`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, denial-error PR #166 is Ready at `e84a1a2cc82b1c666218efd441da97849f47b8c2`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 is Ready at `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, subscription repair #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1` with a fresh rerun queued, and classifier foundation #287 is Ready at `ab6d5d1a04a020f37727e2f5a6950c58feae8559`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. +- Revalidated the product-gap queue at 124 open pull requests (12 ready, 112 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Draft at `3772d6eddfd556b24397afc80780ef3cc980791e`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, denial-error PR #166 is Ready at `e84a1a2cc82b1c666218efd441da97849f47b8c2`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 is Ready at `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, DDD/MCP repair #272 is Ready at `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, governance repair #285 is Ready at `f455c2cd64b3dd3f027c91d396103792a205ddd0`, subscription repair #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1` with a fresh rerun queued, and classifier foundation #287 is Ready at `ab6d5d1a04a020f37727e2f5a6950c58feae8559`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index fa63dbb8c..120ff965f 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,20 +6,20 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T23:29:48Z`. +Observed at (UTC): `2026-09-04T23:38:06Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. -- Full live search returns **124 open pull requests: 10 Ready/non-draft and 114 Draft; 13 open non-PR issues**. PR #166 became Ready after adopting current protected main and passing its full local gates; queue movement is not protected-main delivery. -- Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #238 `b28424647849eff829f1c9c5fd155988c7785c79`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Full live search returns **124 open pull requests: 12 Ready/non-draft and 112 Draft; 13 open non-PR issues**. PRs #166, #272, and #285 became Ready after adopting current protected main; queue movement is not protected-main delivery. +- Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #238 `8c56de3a22790f8b35111ac935dfabfef80dafc0`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. -- PR #285 is Draft at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass; draft-hosted jobs are skipped and central checks remain non-terminal. +- PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass; hosted exact-head checks remain queued and no eligible approval exists. - Issue #279 owns the remaining documentation-CI partitioning gap. PR #287 is Ready at exact head `ab6d5d1a04a020f37727e2f5a6950c58feae8559` on current protected main; it is the workflow-independent classifier foundation, changes no `.github/**` path, and is the prerequisite for an authorized workflow owner. Its exact-head hosted checks remain queued and no eligible approval exists. PR #282 is Draft at exact head `b54a5856d8201911f05d69622f0d5594a371adf0` on current protected main; its trusted protected-base classifier successor requires exact base/head raw evidence, binds Git rename/copy similarity to blob identity, and retains fail-closed path and instruction-authority rules. Local checks do not substitute for its skipped draft jobs or current-head hosted evidence. - PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`, non-force stacked on #282 exact `b54a5856d8201911f05d69622f0d5594a371adf0`. Its exact parent compare remains one prose-only doctoring canary; draft-hosted jobs are skipped, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. - Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0` on #259 exact base `b089c5f584e2c4605a40d2173b3c506e18`. PR #261 is Draft at exact head `95f7548bf07cbba76ab8b40577a11d1b6c99acb5`, stacked on exact #260. Repair PR #277 is Draft at exact head `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`, stacked on exact #261 and preserving typed `SessionSubscribe` correlation. Its hosted Rust and production-coverage jobs were cancelled, so stale conflicting #262 is not superseded and remains dependency-blocked until #277 reaches terminal GREEN on the unchanged head. - Stacked PRs #178 and #85 were repaired without force pushes at exact heads `640e594dbc0a64f251a0f28b8e80943f53337e40` and `c9adea680d6186f1842a280e248ce55da4f1305b`. Parent-relative deltas now preserve the current MV3 diagnostic and extension-authority contracts; local full suites and exact 100% coverage passed, while hosted exact-head acceptance remains independently required. - PR #70 is Draft at exact head `77eb0f2ee71783e06171784b7173c0b4cd530e61`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. Its focused Agent Task contract proves the pre-repair `--no-sandbox` launch as source RED and the branch removes that argument only from the Agent Task lane. Sandbox-enabled pinned-Chromium E2E and repository-wide GREEN remain unproven while its exact-head browser/CI/security runs are non-passing. -- DDD/MCP repair #272 is Draft at exact head `fe124e447cad3f679e22337fb6fbdfd135ab3652`. Its documentation child PR #273 is Draft at exact head `e5c8fcb66bf644dfa750bb1b40ba3d600cb7805a` on that exact parent; all 159 repository contracts, full Rust gates, and exact 100% local coverage pass, while remote jobs remain queued. Both remain active-PR evidence until exact-current CI, review, and security gates complete. +- DDD/MCP repair #272 is Ready at exact head `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3` on current protected main. Its exact-head hosted checks remain queued and no eligible approval exists. Documentation child PR #273 is Draft at exact head `e5c8fcb66bf644dfa750bb1b40ba3d600cb7805a` on predecessor #272 head `fe124e447cad3f679e22337fb6fbdfd135ab3652`, so it must adopt the parent only after #272's current head completes its gates. Both remain active-PR evidence. - PR #229 is Draft at exact head `3772d6eddfd556b24397afc80780ef3cc980791e`. Its presentation-identity work retains the boundary that Chromium application and page-observed effectiveness remain separate adapter/browser-E2E work. Current-head CI/security runs remain non-terminal. - PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385` on canonical MV3 parent #43 `6f3134d18d3118aab33d28048671dc71a5f47b77`. Its child delta is diagnostic-evidence contract/doctoring only; inherited #43 implementation redacts browser/page-derived HTTP and WebDriver protocol data, startup exception details, returned capability values, DOM-dataset values, and click post-condition text before CI/audit evidence. Exact-head CI and Manifest V3 Compatibility succeeded and review threads are resolved, but parent-first workflow-ownership verification remains open, so the child stays Draft. - PR #43 is Draft at exact head `6f3134d18d3118aab33d28048671dc71a5f47b77`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. The branch now installs and configures the pinned `chrome_sandbox`; exact-head hosted verification remains required, and restoring `--no-sandbox` is not acceptable. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 98972c9db..fa0552218 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -81,7 +81,7 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] self.assertIn("on 2026-09-04", refresh_line) - self.assertIn("124 open pull requests (10 ready, 114 draft)", refresh_line) + self.assertIn("124 open pull requests (12 ready, 112 draft)", refresh_line) self.assertIn("13 open non-PR issues", refresh_line) self.assertIn("3772d6eddfd556b24397afc80780ef3cc980791e", refresh_line) self.assertIn("35d12949bde5e5cbc801fdfb433f4a9914bd4fb0", refresh_line) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 8f560997a..1bac73b1a 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -27,27 +27,27 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: )[0] for marker in ( "124 open pull requests", - "10 Ready/non-draft", - "114 Draft", + "12 Ready/non-draft", + "112 Draft", "13 open non-PR issues", "87c4daa1830bac5a5228b6036752ad5633232085", "18156473", "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #238 `b28424647849eff829f1c9c5fd155988c7785c79`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`", + "Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #238 `8c56de3a22790f8b35111ac935dfabfef80dafc0`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", "PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`", "PR #261 is Draft at exact head `95f7548bf07cbba76ab8b40577a11d1b6c99acb5`", "PR #277 is Draft at exact head `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`", "PR #70 is Draft at exact head `77eb0f2ee71783e06171784b7173c0b4cd530e61`", - "DDD/MCP repair #272 is Draft at exact head `fe124e447cad3f679e22337fb6fbdfd135ab3652`", + "DDD/MCP repair #272 is Ready at exact head `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`", "PR #229 is Draft at exact head `3772d6eddfd556b24397afc80780ef3cc980791e`", "PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385`", "PR #282 is Draft at exact head `b54a5856d8201911f05d69622f0d5594a371adf0`", "PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`", - "PR #285 is Draft at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0`", + "PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0`", "PR #287 is Ready at exact head `ab6d5d1a04a020f37727e2f5a6950c58feae8559`", "PR #273 is Draft at exact head `e5c8fcb66bf644dfa750bb1b40ba3d600cb7805a`", "GitHub Releases is empty", @@ -126,7 +126,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "124 open pull requests (10 ready, 114 draft)" + expected = "124 open pull requests (12 ready, 112 draft)" self.assertIn(expected, preamble) self.assertIn("13 open non-PR issues", preamble) self.assertIn(expected, added) From 126dc8fa877623bc5ae90cb3e039f971b13835c0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 08:45:17 +0900 Subject: [PATCH 097/250] docs: record presentation kernel readiness Signed-off-by: Seongho Bae --- CHANGELOG.md | 6 +++--- docs/product-technical-gap-baseline.md | 8 ++++---- .../test_documentation_active_pr_evidence_contract.py | 4 ++-- tests/test_gap_snapshot_inventory_consistency.py | 10 +++++----- 4 files changed, 14 insertions(+), 14 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 412fe9de8..19fe5e8ba 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,13 +5,13 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. -- Refreshed the product-gap queue to 124 open pull requests (12 ready, 112 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. -- Recorded the current Ready-root heads for #37, #50, #166, #219, #220, #238, #240, #247, #272, #274, #285, and #287; hosted exact-head checks remain non-terminal and counted approval remains absent. +- Refreshed the product-gap queue to 124 open pull requests (13 ready, 111 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. +- Recorded the current Ready-root heads for #37, #50, #166, #219, #220, #229, #238, #240, #247, #272, #274, #285, and #287; hosted exact-head checks remain non-terminal and counted approval remains absent. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. ### Added -- Revalidated the product-gap queue at 124 open pull requests (12 ready, 112 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Draft at `3772d6eddfd556b24397afc80780ef3cc980791e`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, denial-error PR #166 is Ready at `e84a1a2cc82b1c666218efd441da97849f47b8c2`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 is Ready at `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, DDD/MCP repair #272 is Ready at `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, governance repair #285 is Ready at `f455c2cd64b3dd3f027c91d396103792a205ddd0`, subscription repair #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1` with a fresh rerun queued, and classifier foundation #287 is Ready at `ab6d5d1a04a020f37727e2f5a6950c58feae8559`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. +- Revalidated the product-gap queue at 124 open pull requests (13 ready, 111 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Ready at `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, denial-error PR #166 is Ready at `e84a1a2cc82b1c666218efd441da97849f47b8c2`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 is Ready at `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, DDD/MCP repair #272 is Ready at `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, governance repair #285 is Ready at `f455c2cd64b3dd3f027c91d396103792a205ddd0`, subscription repair #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1` with a fresh rerun queued, and classifier foundation #287 is Ready at `ab6d5d1a04a020f37727e2f5a6950c58feae8559`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 120ff965f..a6922db3d 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,11 +6,11 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T23:38:06Z`. +Observed at (UTC): `2026-09-04T23:44:00Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. -- Full live search returns **124 open pull requests: 12 Ready/non-draft and 112 Draft; 13 open non-PR issues**. PRs #166, #272, and #285 became Ready after adopting current protected main; queue movement is not protected-main delivery. -- Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #238 `8c56de3a22790f8b35111ac935dfabfef80dafc0`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Full live search returns **124 open pull requests: 13 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PRs #166, #229, #272, and #285 became Ready after adopting current protected main; queue movement is not protected-main delivery. +- Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #238 `21d8a367c94919b244ac058d99df4ac2ef970c4f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass; hosted exact-head checks remain queued and no eligible approval exists. @@ -20,7 +20,7 @@ Observed at (UTC): `2026-09-04T23:38:06Z`. - Stacked PRs #178 and #85 were repaired without force pushes at exact heads `640e594dbc0a64f251a0f28b8e80943f53337e40` and `c9adea680d6186f1842a280e248ce55da4f1305b`. Parent-relative deltas now preserve the current MV3 diagnostic and extension-authority contracts; local full suites and exact 100% coverage passed, while hosted exact-head acceptance remains independently required. - PR #70 is Draft at exact head `77eb0f2ee71783e06171784b7173c0b4cd530e61`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. Its focused Agent Task contract proves the pre-repair `--no-sandbox` launch as source RED and the branch removes that argument only from the Agent Task lane. Sandbox-enabled pinned-Chromium E2E and repository-wide GREEN remain unproven while its exact-head browser/CI/security runs are non-passing. - DDD/MCP repair #272 is Ready at exact head `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3` on current protected main. Its exact-head hosted checks remain queued and no eligible approval exists. Documentation child PR #273 is Draft at exact head `e5c8fcb66bf644dfa750bb1b40ba3d600cb7805a` on predecessor #272 head `fe124e447cad3f679e22337fb6fbdfd135ab3652`, so it must adopt the parent only after #272's current head completes its gates. Both remain active-PR evidence. -- PR #229 is Draft at exact head `3772d6eddfd556b24397afc80780ef3cc980791e`. Its presentation-identity work retains the boundary that Chromium application and page-observed effectiveness remain separate adapter/browser-E2E work. Current-head CI/security runs remain non-terminal. +- PR #229 is Ready at exact head `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6` on current protected main. Its 157 Python contracts, full Rust gates, and exact 100% local coverage pass, while hosted exact-head checks remain queued and no eligible approval exists. The presentation-identity work retains the boundary that Chromium application and page-observed effectiveness remain separate adapter/browser-E2E work. - PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385` on canonical MV3 parent #43 `6f3134d18d3118aab33d28048671dc71a5f47b77`. Its child delta is diagnostic-evidence contract/doctoring only; inherited #43 implementation redacts browser/page-derived HTTP and WebDriver protocol data, startup exception details, returned capability values, DOM-dataset values, and click post-condition text before CI/audit evidence. Exact-head CI and Manifest V3 Compatibility succeeded and review threads are resolved, but parent-first workflow-ownership verification remains open, so the child stays Draft. - PR #43 is Draft at exact head `6f3134d18d3118aab33d28048671dc71a5f47b77`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. The branch now installs and configures the pinned `chrome_sandbox`; exact-head hosted verification remains required, and restoring `--no-sandbox` is not acceptable. - PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index fa0552218..81c42943d 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -81,9 +81,9 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] self.assertIn("on 2026-09-04", refresh_line) - self.assertIn("124 open pull requests (12 ready, 112 draft)", refresh_line) + self.assertIn("124 open pull requests (13 ready, 111 draft)", refresh_line) self.assertIn("13 open non-PR issues", refresh_line) - self.assertIn("3772d6eddfd556b24397afc80780ef3cc980791e", refresh_line) + self.assertIn("024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6", refresh_line) self.assertIn("35d12949bde5e5cbc801fdfb433f4a9914bd4fb0", refresh_line) self.assertIn("0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1", refresh_line) self.assertIn( diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 1bac73b1a..6df73dac2 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -27,15 +27,15 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: )[0] for marker in ( "124 open pull requests", - "12 Ready/non-draft", - "112 Draft", + "13 Ready/non-draft", + "111 Draft", "13 open non-PR issues", "87c4daa1830bac5a5228b6036752ad5633232085", "18156473", "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #238 `8c56de3a22790f8b35111ac935dfabfef80dafc0`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`", + "Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #238 `21d8a367c94919b244ac058d99df4ac2ef970c4f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", "PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`", @@ -43,7 +43,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #277 is Draft at exact head `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`", "PR #70 is Draft at exact head `77eb0f2ee71783e06171784b7173c0b4cd530e61`", "DDD/MCP repair #272 is Ready at exact head `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`", - "PR #229 is Draft at exact head `3772d6eddfd556b24397afc80780ef3cc980791e`", + "PR #229 is Ready at exact head `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`", "PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385`", "PR #282 is Draft at exact head `b54a5856d8201911f05d69622f0d5594a371adf0`", "PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`", @@ -126,7 +126,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "124 open pull requests (12 ready, 112 draft)" + expected = "124 open pull requests (13 ready, 111 draft)" self.assertIn(expected, preamble) self.assertIn("13 open non-PR issues", preamble) self.assertIn(expected, added) From 864679c4189125116efd948645180975d02ad7ae Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 09:06:49 +0900 Subject: [PATCH 098/250] docs: refresh PR 287 exact-head evidence Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 6 +++--- tests/test_gap_snapshot_inventory_consistency.py | 4 ++-- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index a6922db3d..4bc979bc5 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,15 +6,15 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-04T23:44:00Z`. +Observed at (UTC): `2026-09-05T00:05:47Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **124 open pull requests: 13 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PRs #166, #229, #272, and #285 became Ready after adopting current protected main; queue movement is not protected-main delivery. -- Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #238 `21d8a367c94919b244ac058d99df4ac2ef970c4f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #238 `21d8a367c94919b244ac058d99df4ac2ef970c4f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass; hosted exact-head checks remain queued and no eligible approval exists. -- Issue #279 owns the remaining documentation-CI partitioning gap. PR #287 is Ready at exact head `ab6d5d1a04a020f37727e2f5a6950c58feae8559` on current protected main; it is the workflow-independent classifier foundation, changes no `.github/**` path, and is the prerequisite for an authorized workflow owner. Its exact-head hosted checks remain queued and no eligible approval exists. PR #282 is Draft at exact head `b54a5856d8201911f05d69622f0d5594a371adf0` on current protected main; its trusted protected-base classifier successor requires exact base/head raw evidence, binds Git rename/copy similarity to blob identity, and retains fail-closed path and instruction-authority rules. Local checks do not substitute for its skipped draft jobs or current-head hosted evidence. +- Issue #279 owns the remaining documentation-CI partitioning gap. PR #287 is Ready at exact head `af83c40dd2990a03064a92ca75430a9cc400f098` on current protected main; it is the workflow-independent classifier foundation, changes no `.github/**` path, and is the prerequisite for an authorized workflow owner. Its predecessor failed its own release-record contract; the current head adds the missing rename/copy similarity-to-blob-identity record, and its focused and full local suites plus exact 100% Rust coverage pass. Hosted exact-head checks remain queued and no eligible approval exists. PR #282 is Draft at exact head `b54a5856d8201911f05d69622f0d5594a371adf0` on current protected main; its trusted protected-base classifier successor requires exact base/head raw evidence, binds Git rename/copy similarity to blob identity, and retains fail-closed path and instruction-authority rules. Local checks do not substitute for its skipped draft jobs or current-head hosted evidence. - PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`, non-force stacked on #282 exact `b54a5856d8201911f05d69622f0d5594a371adf0`. Its exact parent compare remains one prose-only doctoring canary; draft-hosted jobs are skipped, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. - Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0` on #259 exact base `b089c5f584e2c4605a40d2173b3c506e18`. PR #261 is Draft at exact head `95f7548bf07cbba76ab8b40577a11d1b6c99acb5`, stacked on exact #260. Repair PR #277 is Draft at exact head `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`, stacked on exact #261 and preserving typed `SessionSubscribe` correlation. Its hosted Rust and production-coverage jobs were cancelled, so stale conflicting #262 is not superseded and remains dependency-blocked until #277 reaches terminal GREEN on the unchanged head. - Stacked PRs #178 and #85 were repaired without force pushes at exact heads `640e594dbc0a64f251a0f28b8e80943f53337e40` and `c9adea680d6186f1842a280e248ce55da4f1305b`. Parent-relative deltas now preserve the current MV3 diagnostic and extension-authority contracts; local full suites and exact 100% coverage passed, while hosted exact-head acceptance remains independently required. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 6df73dac2..4d8dacfc4 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -35,7 +35,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #238 `21d8a367c94919b244ac058d99df4ac2ef970c4f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `ab6d5d1a04a020f37727e2f5a6950c58feae8559`", + "Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #238 `21d8a367c94919b244ac058d99df4ac2ef970c4f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", "PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`", @@ -48,7 +48,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #282 is Draft at exact head `b54a5856d8201911f05d69622f0d5594a371adf0`", "PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`", "PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0`", - "PR #287 is Ready at exact head `ab6d5d1a04a020f37727e2f5a6950c58feae8559`", + "PR #287 is Ready at exact head `af83c40dd2990a03064a92ca75430a9cc400f098`", "PR #273 is Draft at exact head `e5c8fcb66bf644dfa750bb1b40ba3d600cb7805a`", "GitHub Releases is empty", ): From ca4c46edcfe8a60d4edffc3003185e0058a58f76 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 09:08:47 +0900 Subject: [PATCH 099/250] docs: record Agent Task successor evidence Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- CHANGELOG.md | 4 ++-- docs/product-technical-gap-baseline.md | 5 +++-- tests/test_documentation_active_pr_evidence_contract.py | 4 ++-- tests/test_gap_snapshot_inventory_consistency.py | 7 ++++--- 4 files changed, 11 insertions(+), 9 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 19fe5e8ba..02756d167 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,13 +5,13 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. -- Refreshed the product-gap queue to 124 open pull requests (13 ready, 111 draft) and 13 open non-PR issues on 2026-09-04; queue movement is active-PR evidence, not protected-main shipment. +- Refreshed the product-gap queue to 125 open pull requests (13 ready, 112 draft) and 13 open non-PR issues on 2026-09-05; queue movement is active-PR evidence, not protected-main shipment. - Recorded the current Ready-root heads for #37, #50, #166, #219, #220, #229, #238, #240, #247, #272, #274, #285, and #287; hosted exact-head checks remain non-terminal and counted approval remains absent. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. ### Added -- Revalidated the product-gap queue at 124 open pull requests (13 ready, 111 draft) and 13 open non-PR issues on 2026-09-04; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Ready at `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, denial-error PR #166 is Ready at `e84a1a2cc82b1c666218efd441da97849f47b8c2`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 is Ready at `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, DDD/MCP repair #272 is Ready at `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, governance repair #285 is Ready at `f455c2cd64b3dd3f027c91d396103792a205ddd0`, subscription repair #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1` with a fresh rerun queued, and classifier foundation #287 is Ready at `ab6d5d1a04a020f37727e2f5a6950c58feae8559`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. +- Revalidated the product-gap queue at 125 open pull requests (13 ready, 112 draft) and 13 open non-PR issues on 2026-09-05; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Ready at `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, denial-error PR #166 is Ready at `e84a1a2cc82b1c666218efd441da97849f47b8c2`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 is Ready at `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, DDD/MCP repair #272 is Ready at `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, governance repair #285 is Ready at `f455c2cd64b3dd3f027c91d396103792a205ddd0`, subscription repair #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1` with a fresh rerun queued, classifier foundation #287 is Ready at `af83c40dd2990a03064a92ca75430a9cc400f098`, and workflow-free Agent Task successor #288 is Draft at `e051a3d06a613233781272ffdc0e564023ba52b0`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 4bc979bc5..eea8029b0 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,16 +6,17 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T00:05:47Z`. +Observed at (UTC): `2026-09-05T00:07:36Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. -- Full live search returns **124 open pull requests: 13 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PRs #166, #229, #272, and #285 became Ready after adopting current protected main; queue movement is not protected-main delivery. +- Full live search returns **125 open pull requests: 13 Ready/non-draft and 112 Draft; 13 open non-PR issues**. PRs #166, #229, #272, and #285 became Ready after adopting current protected main; queue movement is not protected-main delivery. - Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #238 `21d8a367c94919b244ac058d99df4ac2ef970c4f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass; hosted exact-head checks remain queued and no eligible approval exists. - Issue #279 owns the remaining documentation-CI partitioning gap. PR #287 is Ready at exact head `af83c40dd2990a03064a92ca75430a9cc400f098` on current protected main; it is the workflow-independent classifier foundation, changes no `.github/**` path, and is the prerequisite for an authorized workflow owner. Its predecessor failed its own release-record contract; the current head adds the missing rename/copy similarity-to-blob-identity record, and its focused and full local suites plus exact 100% Rust coverage pass. Hosted exact-head checks remain queued and no eligible approval exists. PR #282 is Draft at exact head `b54a5856d8201911f05d69622f0d5594a371adf0` on current protected main; its trusted protected-base classifier successor requires exact base/head raw evidence, binds Git rename/copy similarity to blob identity, and retains fail-closed path and instruction-authority rules. Local checks do not substitute for its skipped draft jobs or current-head hosted evidence. - PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`, non-force stacked on #282 exact `b54a5856d8201911f05d69622f0d5594a371adf0`. Its exact parent compare remains one prose-only doctoring canary; draft-hosted jobs are skipped, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. +- PR #288 is Draft at exact head `e051a3d06a613233781272ffdc0e564023ba52b0` on current protected main. It stages #70's controlled Agent Task product, test, and documentation delta without any `.github/**` mutation; hosted CI and MV3 jobs are skipped while Draft, and #212 still owns authorized workflow activation plus sandboxed pinned-Chromium execution evidence. - Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0` on #259 exact base `b089c5f584e2c4605a40d2173b3c506e18`. PR #261 is Draft at exact head `95f7548bf07cbba76ab8b40577a11d1b6c99acb5`, stacked on exact #260. Repair PR #277 is Draft at exact head `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`, stacked on exact #261 and preserving typed `SessionSubscribe` correlation. Its hosted Rust and production-coverage jobs were cancelled, so stale conflicting #262 is not superseded and remains dependency-blocked until #277 reaches terminal GREEN on the unchanged head. - Stacked PRs #178 and #85 were repaired without force pushes at exact heads `640e594dbc0a64f251a0f28b8e80943f53337e40` and `c9adea680d6186f1842a280e248ce55da4f1305b`. Parent-relative deltas now preserve the current MV3 diagnostic and extension-authority contracts; local full suites and exact 100% coverage passed, while hosted exact-head acceptance remains independently required. - PR #70 is Draft at exact head `77eb0f2ee71783e06171784b7173c0b4cd530e61`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. Its focused Agent Task contract proves the pre-repair `--no-sandbox` launch as source RED and the branch removes that argument only from the Agent Task lane. Sandbox-enabled pinned-Chromium E2E and repository-wide GREEN remain unproven while its exact-head browser/CI/security runs are non-passing. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 81c42943d..a9be4fcac 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -80,8 +80,8 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: refresh_lines = [line for line in added.splitlines() if line.startswith(refresh_prefix)] self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] - self.assertIn("on 2026-09-04", refresh_line) - self.assertIn("124 open pull requests (13 ready, 111 draft)", refresh_line) + self.assertIn("on 2026-09-05", refresh_line) + self.assertIn("125 open pull requests (13 ready, 112 draft)", refresh_line) self.assertIn("13 open non-PR issues", refresh_line) self.assertIn("024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6", refresh_line) self.assertIn("35d12949bde5e5cbc801fdfb433f4a9914bd4fb0", refresh_line) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 4d8dacfc4..2f606bc8f 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -26,9 +26,9 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "## Observed snapshot: 2026-08-29", 1 )[0] for marker in ( - "124 open pull requests", + "125 open pull requests", "13 Ready/non-draft", - "111 Draft", + "112 Draft", "13 open non-PR issues", "87c4daa1830bac5a5228b6036752ad5633232085", "18156473", @@ -47,6 +47,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385`", "PR #282 is Draft at exact head `b54a5856d8201911f05d69622f0d5594a371adf0`", "PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`", + "PR #288 is Draft at exact head `e051a3d06a613233781272ffdc0e564023ba52b0`", "PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0`", "PR #287 is Ready at exact head `af83c40dd2990a03064a92ca75430a9cc400f098`", "PR #273 is Draft at exact head `e5c8fcb66bf644dfa750bb1b40ba3d600cb7805a`", @@ -126,7 +127,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "124 open pull requests (13 ready, 111 draft)" + expected = "125 open pull requests (13 ready, 112 draft)" self.assertIn(expected, preamble) self.assertIn("13 open non-PR issues", preamble) self.assertIn(expected, added) From f48957a3f391ff1727926733cc9f20b1114bd4e9 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 09:36:49 +0900 Subject: [PATCH 100/250] docs: refresh public surface head evidence Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 4 ++-- tests/test_gap_snapshot_inventory_consistency.py | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index eea8029b0..cd84dddbd 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -10,7 +10,7 @@ Observed at (UTC): `2026-09-05T00:07:36Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 13 Ready/non-draft and 112 Draft; 13 open non-PR issues**. PRs #166, #229, #272, and #285 became Ready after adopting current protected main; queue movement is not protected-main delivery. -- Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #238 `21d8a367c94919b244ac058d99df4ac2ef970c4f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #238 `21d8a367c94919b244ac058d99df4ac2ef970c4f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `9e37e835cfab999f72a5f04d911d46a092b7ac73`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass; hosted exact-head checks remain queued and no eligible approval exists. @@ -24,7 +24,7 @@ Observed at (UTC): `2026-09-05T00:07:36Z`. - PR #229 is Ready at exact head `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6` on current protected main. Its 157 Python contracts, full Rust gates, and exact 100% local coverage pass, while hosted exact-head checks remain queued and no eligible approval exists. The presentation-identity work retains the boundary that Chromium application and page-observed effectiveness remain separate adapter/browser-E2E work. - PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385` on canonical MV3 parent #43 `6f3134d18d3118aab33d28048671dc71a5f47b77`. Its child delta is diagnostic-evidence contract/doctoring only; inherited #43 implementation redacts browser/page-derived HTTP and WebDriver protocol data, startup exception details, returned capability values, DOM-dataset values, and click post-condition text before CI/audit evidence. Exact-head CI and Manifest V3 Compatibility succeeded and review threads are resolved, but parent-first workflow-ownership verification remains open, so the child stays Draft. - PR #43 is Draft at exact head `6f3134d18d3118aab33d28048671dc71a5f47b77`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. The branch now installs and configures the pinned `chrome_sandbox`; exact-head hosted verification remains required, and restoring `--no-sandbox` is not acceptable. -- PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. +- PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `9e37e835cfab999f72a5f04d911d46a092b7ac73`, with a repository regression contract for the badge, pre-alpha status, active-PR non-promotion statement, and publication boundary. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. - Issue #201's release/SBOM lane remains dependency ordered, and GitHub Releases is empty. OriginWeave remains pre-GA until exact protected-head versioning, signed artifacts, SBOM/provenance, reproducibility, rollback, compatibility, security, and commercial-acceptance evidence exist. - The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #28 the first complete Chromium Agent Task vertical slice, #199 durable WARC/PROV and retention/replay, #200 stable BAP/MCP runtime API, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 enterprise identity/tenant/policy/approval/audit/SLO operations, #203 exact-artifact commercial acceptance, #276 contextual-orchestrator migration, and #279 exact-head documentation verification without unnecessary Rust queue load. - Current evidence procedure remains fail-closed: queued reviewer evidence is non-passing; paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 2f606bc8f..6cfb7e63a 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -35,7 +35,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #238 `21d8a367c94919b244ac058d99df4ac2ef970c4f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `9440cb652d0acd7a95fff4d2bbf85152ce7c3c8f`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", + "Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #238 `21d8a367c94919b244ac058d99df4ac2ef970c4f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `9e37e835cfab999f72a5f04d911d46a092b7ac73`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", "PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`", From e69a3c2239f568bd260cd9d7dd4dc37d2fa274ec Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 09:45:25 +0900 Subject: [PATCH 101/250] docs: correct MCP and merge evidence Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- README.md | 2 +- docs/product-technical-gap-baseline.md | 6 +++--- tests/test_documentation_fitness_contract.py | 2 ++ tests/test_gap_snapshot_inventory_consistency.py | 2 +- 4 files changed, 7 insertions(+), 5 deletions(-) diff --git a/README.md b/README.md index 7ce905774..eda4b8acb 100644 --- a/README.md +++ b/README.md @@ -4,7 +4,7 @@ OriginWeave is a Chromium-compatible, Rust-first control plane for governed AI agents on the web. It is designed to let an agent observe, extract, and act without turning untrusted page content into authority, exposing secrets to a model, connecting to an unapproved network destination, accepting an unauthenticated web service, or losing the evidence required to explain what happened. -> Project status: pre-alpha. The current protected repository contains independently reusable safety, resolved-destination, direct TCP peer-binding, authenticated TLS service-identity, and bounded MCP `2026-07-28` stateless `tools/call`/`tools/list` routing and policy foundations. Chromium, WebDriver BiDi, CDP, complete MCP, HTTP, proxy, WARC, and persistent provenance adapters are planned but not yet shipped. The merged `tools/list` contract does not make the complete MCP adapter available. +> Project status: pre-alpha. The current protected repository contains independently reusable safety, resolved-destination, direct TCP peer-binding, authenticated TLS service-identity, and bounded MCP `2026-07-28` stateless `tools/call` routing/policy and `tools/list` discovery foundations. Chromium, WebDriver BiDi, CDP, complete MCP, HTTP, proxy, WARC, and persistent provenance adapters are planned but not yet shipped. The merged `tools/list` contract does not make the complete MCP adapter available. ## Why OriginWeave diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index cd84dddbd..524df5848 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -10,7 +10,7 @@ Observed at (UTC): `2026-09-05T00:07:36Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 13 Ready/non-draft and 112 Draft; 13 open non-PR issues**. PRs #166, #229, #272, and #285 became Ready after adopting current protected main; queue movement is not protected-main delivery. -- Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #238 `21d8a367c94919b244ac058d99df4ac2ef970c4f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `9e37e835cfab999f72a5f04d911d46a092b7ac73`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #238 `21d8a367c94919b244ac058d99df4ac2ef970c4f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass; hosted exact-head checks remain queued and no eligible approval exists. @@ -24,7 +24,7 @@ Observed at (UTC): `2026-09-05T00:07:36Z`. - PR #229 is Ready at exact head `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6` on current protected main. Its 157 Python contracts, full Rust gates, and exact 100% local coverage pass, while hosted exact-head checks remain queued and no eligible approval exists. The presentation-identity work retains the boundary that Chromium application and page-observed effectiveness remain separate adapter/browser-E2E work. - PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385` on canonical MV3 parent #43 `6f3134d18d3118aab33d28048671dc71a5f47b77`. Its child delta is diagnostic-evidence contract/doctoring only; inherited #43 implementation redacts browser/page-derived HTTP and WebDriver protocol data, startup exception details, returned capability values, DOM-dataset values, and click post-condition text before CI/audit evidence. Exact-head CI and Manifest V3 Compatibility succeeded and review threads are resolved, but parent-first workflow-ownership verification remains open, so the child stays Draft. - PR #43 is Draft at exact head `6f3134d18d3118aab33d28048671dc71a5f47b77`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. The branch now installs and configures the pinned `chrome_sandbox`; exact-head hosted verification remains required, and restoring `--no-sandbox` is not acceptable. -- PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `9e37e835cfab999f72a5f04d911d46a092b7ac73`, with a repository regression contract for the badge, pre-alpha status, active-PR non-promotion statement, and publication boundary. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. +- PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, with a repository regression contract for the exact badge target, pre-alpha status, active-PR non-promotion statement, and publication boundary. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. - Issue #201's release/SBOM lane remains dependency ordered, and GitHub Releases is empty. OriginWeave remains pre-GA until exact protected-head versioning, signed artifacts, SBOM/provenance, reproducibility, rollback, compatibility, security, and commercial-acceptance evidence exist. - The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #28 the first complete Chromium Agent Task vertical slice, #199 durable WARC/PROV and retention/replay, #200 stable BAP/MCP runtime API, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 enterprise identity/tenant/policy/approval/audit/SLO operations, #203 exact-artifact commercial acceptance, #276 contextual-orchestrator migration, and #279 exact-head documentation verification without unnecessary Rust queue load. - Current evidence procedure remains fail-closed: queued reviewer evidence is non-passing; paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. @@ -49,7 +49,7 @@ This snapshot re-fetched the complete open-PR inventory, the protected `main` co During this recheck, #71, #154, #233, #234, and #235 were merged only into their unprotected feature-parent branches after exact current-head checks and review-thread resolution. Their successful stack checks are not protected-main delivery, and their child branches retain independent evidence requirements. -The sensitive-data child slice #53 was subsequently squash-merged into the unprotected #46 feature branch at merge commit `93c713a107df05385f745db4dca20091f21c4a3`; #53 was exact head `4ecc81e59ae7bc3a640e65e2442bf30c079bd94c`. PR #46 remains an active main-targeting parent. Its current exact base/head pair is protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413` to `373113119446d99f578febd39efc19366e7736b1`; the head adds the ADR 0007 predicate-boundary clarification and regression contract, with local Python/Rust verification green. Current hosted evidence remains incomplete: automatic OpenCode run `33189822385` / job `98913006386` failed closed without a current-head verdict, and central Strix run `33190794267` / job `98915422837` failed closed after three provider HTTP 500 attempts without a vulnerability report. A direct central `opencode-review` dispatch run `33192478312` / job `98921183278` was rejected because repository_dispatch actor `seonghobae` did not match configured scheduler identity `github-actions[bot]`; no qualifying non-author approval is present. +The sensitive-data child slice #53 was subsequently squash-merged into the unprotected #46 feature branch at merge commit `93c713a107df05385f745db4dca20091f21c4a3a`; #53 was exact head `4ecc81e59ae7bc3a640e65e2442bf30c079bd94c`. PR #46 remains an active main-targeting parent. Its current exact base/head pair is protected `main` `542ca1e9c0a863595b8b6697790005d2471f5413` to `373113119446d99f578febd39efc19366e7736b1`; the head adds the ADR 0007 predicate-boundary clarification and regression contract, with local Python/Rust verification green. Current hosted evidence remains incomplete: automatic OpenCode run `33189822385` / job `98913006386` failed closed without a current-head verdict, and central Strix run `33190794267` / job `98915422837` failed closed after three provider HTTP 500 attempts without a vulnerability report. A direct central `opencode-review` dispatch run `33192478312` / job `98921183278` was rejected because repository_dispatch actor `seonghobae` did not match configured scheduler identity `github-actions[bot]`; no qualifying non-author approval is present. The WARC/PROV child slice #217 was squash-merged into the unprotected #210 feature branch at merge commit `66f360ccac5cec60c72222cc79d58e39f6f00088`; #217 was exact head `6b8a3fdeae52ad94b90086bbc9b42863b90c9614`. PR #210 subsequently advanced to current exact head `7946dce9a3dd074047d93fca299d48c7aef40e47` after its merged-child attribution repair, recursively encoded-control repair, and exact coverage repair; this stack remains active-PR evidence and not protected-main delivery or approval evidence. diff --git a/tests/test_documentation_fitness_contract.py b/tests/test_documentation_fitness_contract.py index 35463789e..c5c3c6785 100644 --- a/tests/test_documentation_fitness_contract.py +++ b/tests/test_documentation_fitness_contract.py @@ -188,6 +188,8 @@ def test_protected_main_mcp_route_is_indexed_with_executable_evidence(self) -> N index, ) self.assertIn("`tools/list`", route) + self.assertIn("`tools/list` capability maturity:** `IMPLEMENTED_ON_PROTECTED_MAIN`", route) + self.assertIn("**Discovery refinement:** merged PR #170", route) self.assertIn("crates/originweave-core/tests/mcp_tools_list_cache.rs", route) self.assertTrue( (REPOSITORY_ROOT / "crates/originweave-core/tests/mcp_tools_list_cache.rs").is_file() diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 6cfb7e63a..5ea86e143 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -35,7 +35,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #238 `21d8a367c94919b244ac058d99df4ac2ef970c4f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `9e37e835cfab999f72a5f04d911d46a092b7ac73`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", + "Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #238 `21d8a367c94919b244ac058d99df4ac2ef970c4f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", "PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`", From f82e2c91fa6862db927c5713c1a2d7e6d6b14770 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 10:05:09 +0900 Subject: [PATCH 102/250] docs(gaps): record http reset-content repair Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 5 +++-- tests/test_gap_snapshot_inventory_consistency.py | 2 +- 3 files changed, 5 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 02756d167..b368d2ff5 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Refreshed the live product-gap baseline with PR #37's RFC 9110 `205 Reset Content` repair head and exact local verification evidence. - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. - Refreshed the product-gap queue to 125 open pull requests (13 ready, 112 draft) and 13 open non-PR issues on 2026-09-05; queue movement is active-PR evidence, not protected-main shipment. - Recorded the current Ready-root heads for #37, #50, #166, #219, #220, #229, #238, #240, #247, #272, #274, #285, and #287; hosted exact-head checks remain non-terminal and counted approval remains absent. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 524df5848..ee9cb88ba 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,11 +6,11 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T00:07:36Z`. +Observed at (UTC): `2026-09-05T01:02:15Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 13 Ready/non-draft and 112 Draft; 13 open non-PR issues**. PRs #166, #229, #272, and #285 became Ready after adopting current protected main; queue movement is not protected-main delivery. -- Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #238 `21d8a367c94919b244ac058d99df4ac2ef970c4f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Ready roots are #37 `357fa97dc3cd4a3afff78c29151392b50be6f50a`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #238 `21d8a367c94919b244ac058d99df4ac2ef970c4f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass; hosted exact-head checks remain queued and no eligible approval exists. @@ -25,6 +25,7 @@ Observed at (UTC): `2026-09-05T00:07:36Z`. - PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385` on canonical MV3 parent #43 `6f3134d18d3118aab33d28048671dc71a5f47b77`. Its child delta is diagnostic-evidence contract/doctoring only; inherited #43 implementation redacts browser/page-derived HTTP and WebDriver protocol data, startup exception details, returned capability values, DOM-dataset values, and click post-condition text before CI/audit evidence. Exact-head CI and Manifest V3 Compatibility succeeded and review threads are resolved, but parent-first workflow-ownership verification remains open, so the child stays Draft. - PR #43 is Draft at exact head `6f3134d18d3118aab33d28048671dc71a5f47b77`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. The branch now installs and configures the pinned `chrome_sandbox`; exact-head hosted verification remains required, and restoring `--no-sandbox` is not acceptable. - PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, with a repository regression contract for the exact badge target, pre-alpha status, active-PR non-promotion statement, and publication boundary. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. +- PR #37 is Ready at exact head `357fa97dc3cd4a3afff78c29151392b50be6f50a`. Current review found and repaired the RFC 9110 `205 Reset Content` semantic gap test-first: response content is now suppressed, the doctoring and changelog evidence are current, and 165 repository contracts plus the full Rust gates and exact 100% local coverage pass. Hosted exact-head checks and an eligible approval remain required. - Issue #201's release/SBOM lane remains dependency ordered, and GitHub Releases is empty. OriginWeave remains pre-GA until exact protected-head versioning, signed artifacts, SBOM/provenance, reproducibility, rollback, compatibility, security, and commercial-acceptance evidence exist. - The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #28 the first complete Chromium Agent Task vertical slice, #199 durable WARC/PROV and retention/replay, #200 stable BAP/MCP runtime API, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 enterprise identity/tenant/policy/approval/audit/SLO operations, #203 exact-artifact commercial acceptance, #276 contextual-orchestrator migration, and #279 exact-head documentation verification without unnecessary Rust queue load. - Current evidence procedure remains fail-closed: queued reviewer evidence is non-passing; paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 5ea86e143..1dc524a3e 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -35,7 +35,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `8a4f2d8377a14565b259e03839e370223c92877f`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #238 `21d8a367c94919b244ac058d99df4ac2ef970c4f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", + "Ready roots are #37 `357fa97dc3cd4a3afff78c29151392b50be6f50a`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #238 `21d8a367c94919b244ac058d99df4ac2ef970c4f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", "PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`", From 6ffaa7b5f7b650dd8f94b4d106cb5c6f05a943ae Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 10:20:03 +0900 Subject: [PATCH 103/250] docs(gaps): record ready workflow gap Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 4 ++-- tests/test_gap_snapshot_inventory_consistency.py | 5 +++++ 3 files changed, 8 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index b368d2ff5..b7c4d8182 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded PR #285's Ready-event materialization gap: repository-native exact-head CI restarted, while the earlier central Security, Semgrep, and CodeQL runs remained cancelled and no fresh required-workflow replacements appeared. - Refreshed the live product-gap baseline with PR #37's RFC 9110 `205 Reset Content` repair head and exact local verification evidence. - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. - Refreshed the product-gap queue to 125 open pull requests (13 ready, 112 draft) and 13 open non-PR issues on 2026-09-05; queue movement is active-PR evidence, not protected-main shipment. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index ee9cb88ba..5f288d936 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,14 +6,14 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T01:02:15Z`. +Observed at (UTC): `2026-09-05T01:18:23Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 13 Ready/non-draft and 112 Draft; 13 open non-PR issues**. PRs #166, #229, #272, and #285 became Ready after adopting current protected main; queue movement is not protected-main delivery. - Ready roots are #37 `357fa97dc3cd4a3afff78c29151392b50be6f50a`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #238 `21d8a367c94919b244ac058d99df4ac2ef970c4f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. -- PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass; hosted exact-head checks remain queued and no eligible approval exists. +- PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass. Its Ready transition materialized repository-native CI `33930234387`, which remains queued, but did not materialize fresh central required-workflow runs: the only exact-head Security Scan `33924016851`, SAST Semgrep `33924016903`, and CodeQL PR `33924016883` runs came from the earlier Draft event and were cancelled. Missing current lifecycle evidence and the absent eligible approval remain merge blockers; toggling Draft or creating a no-op commit is not an acceptable substitute. - Issue #279 owns the remaining documentation-CI partitioning gap. PR #287 is Ready at exact head `af83c40dd2990a03064a92ca75430a9cc400f098` on current protected main; it is the workflow-independent classifier foundation, changes no `.github/**` path, and is the prerequisite for an authorized workflow owner. Its predecessor failed its own release-record contract; the current head adds the missing rename/copy similarity-to-blob-identity record, and its focused and full local suites plus exact 100% Rust coverage pass. Hosted exact-head checks remain queued and no eligible approval exists. PR #282 is Draft at exact head `b54a5856d8201911f05d69622f0d5594a371adf0` on current protected main; its trusted protected-base classifier successor requires exact base/head raw evidence, binds Git rename/copy similarity to blob identity, and retains fail-closed path and instruction-authority rules. Local checks do not substitute for its skipped draft jobs or current-head hosted evidence. - PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`, non-force stacked on #282 exact `b54a5856d8201911f05d69622f0d5594a371adf0`. Its exact parent compare remains one prose-only doctoring canary; draft-hosted jobs are skipped, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. - PR #288 is Draft at exact head `e051a3d06a613233781272ffdc0e564023ba52b0` on current protected main. It stages #70's controlled Agent Task product, test, and documentation delta without any `.github/**` mutation; hosted CI and MV3 jobs are skipped while Draft, and #212 still owns authorized workflow activation plus sandboxed pinned-Chromium execution evidence. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 1dc524a3e..b2a41f12f 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -49,6 +49,11 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`", "PR #288 is Draft at exact head `e051a3d06a613233781272ffdc0e564023ba52b0`", "PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0`", + "CI `33930234387`", + "Security Scan `33924016851`", + "SAST Semgrep `33924016903`", + "CodeQL PR `33924016883`", + "did not materialize fresh central required-workflow runs", "PR #287 is Ready at exact head `af83c40dd2990a03064a92ca75430a9cc400f098`", "PR #273 is Draft at exact head `e5c8fcb66bf644dfa750bb1b40ba3d600cb7805a`", "GitHub Releases is empty", From f41eead8091788cdba053fa4bc2cc8ace62e3e15 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 10:21:27 +0900 Subject: [PATCH 104/250] docs(gaps): remove moving self reference Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- CHANGELOG.md | 2 +- docs/product-technical-gap-baseline.md | 2 +- tests/test_gap_snapshot_inventory_consistency.py | 3 ++- 3 files changed, 4 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index b7c4d8182..536a0a729 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -8,7 +8,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Refreshed the live product-gap baseline with PR #37's RFC 9110 `205 Reset Content` repair head and exact local verification evidence. - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. - Refreshed the product-gap queue to 125 open pull requests (13 ready, 112 draft) and 13 open non-PR issues on 2026-09-05; queue movement is active-PR evidence, not protected-main shipment. -- Recorded the current Ready-root heads for #37, #50, #166, #219, #220, #229, #238, #240, #247, #272, #274, #285, and #287; hosted exact-head checks remain non-terminal and counted approval remains absent. +- Recorded the current Ready-root heads for #37, #50, #166, #219, #220, #229, #240, #247, #272, #274, #285, and #287; #238's moving self-reference is intentionally delegated to live PR metadata, hosted exact-head checks remain non-terminal, and counted approval remains absent. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 5f288d936..eeef4bcb2 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -10,7 +10,7 @@ Observed at (UTC): `2026-09-05T01:18:23Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 13 Ready/non-draft and 112 Draft; 13 open non-PR issues**. PRs #166, #229, #272, and #285 became Ready after adopting current protected main; queue movement is not protected-main delivery. -- Ready roots are #37 `357fa97dc3cd4a3afff78c29151392b50be6f50a`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #238 `21d8a367c94919b244ac058d99df4ac2ef970c4f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Ready roots are #37 `357fa97dc3cd4a3afff78c29151392b50be6f50a`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass. Its Ready transition materialized repository-native CI `33930234387`, which remains queued, but did not materialize fresh central required-workflow runs: the only exact-head Security Scan `33924016851`, SAST Semgrep `33924016903`, and CodeQL PR `33924016883` runs came from the earlier Draft event and were cancelled. Missing current lifecycle evidence and the absent eligible approval remain merge blockers; toggling Draft or creating a no-op commit is not an acceptable substitute. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index b2a41f12f..455d1b6d8 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -35,7 +35,8 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `357fa97dc3cd4a3afff78c29151392b50be6f50a`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #238 `21d8a367c94919b244ac058d99df4ac2ef970c4f`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", + "Ready roots are #37 `357fa97dc3cd4a3afff78c29151392b50be6f50a`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", + "PR #238's moving exact head is intentionally omitted", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", "PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`", From e93c6276d893f300df2de2090ce7d92dc8f63df2 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 10:26:01 +0900 Subject: [PATCH 105/250] docs(gaps): record PR 288 contract repair Pin the corrected workflow-free head and distinguish local Python GREEN from the still-missing hosted sandbox execution. Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index eeef4bcb2..703ebb0ac 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -16,7 +16,7 @@ Observed at (UTC): `2026-09-05T01:18:23Z`. - PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass. Its Ready transition materialized repository-native CI `33930234387`, which remains queued, but did not materialize fresh central required-workflow runs: the only exact-head Security Scan `33924016851`, SAST Semgrep `33924016903`, and CodeQL PR `33924016883` runs came from the earlier Draft event and were cancelled. Missing current lifecycle evidence and the absent eligible approval remain merge blockers; toggling Draft or creating a no-op commit is not an acceptable substitute. - Issue #279 owns the remaining documentation-CI partitioning gap. PR #287 is Ready at exact head `af83c40dd2990a03064a92ca75430a9cc400f098` on current protected main; it is the workflow-independent classifier foundation, changes no `.github/**` path, and is the prerequisite for an authorized workflow owner. Its predecessor failed its own release-record contract; the current head adds the missing rename/copy similarity-to-blob-identity record, and its focused and full local suites plus exact 100% Rust coverage pass. Hosted exact-head checks remain queued and no eligible approval exists. PR #282 is Draft at exact head `b54a5856d8201911f05d69622f0d5594a371adf0` on current protected main; its trusted protected-base classifier successor requires exact base/head raw evidence, binds Git rename/copy similarity to blob identity, and retains fail-closed path and instruction-authority rules. Local checks do not substitute for its skipped draft jobs or current-head hosted evidence. - PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`, non-force stacked on #282 exact `b54a5856d8201911f05d69622f0d5594a371adf0`. Its exact parent compare remains one prose-only doctoring canary; draft-hosted jobs are skipped, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. -- PR #288 is Draft at exact head `e051a3d06a613233781272ffdc0e564023ba52b0` on current protected main. It stages #70's controlled Agent Task product, test, and documentation delta without any `.github/**` mutation; hosted CI and MV3 jobs are skipped while Draft, and #212 still owns authorized workflow activation plus sandboxed pinned-Chromium execution evidence. +- PR #288 is Draft at exact head `39e36256651f62940ec3ca6149067f0cfcb2285a` on current protected main. It stages #70's controlled Agent Task product, test, and documentation delta without any `.github/**` mutation; its workflow-owned sandbox-helper assertion was removed after it made the workflow-free branch's full Python contract suite fail, and all 172 Python contracts now pass locally. Hosted CI and MV3 jobs remain skipped while Draft, and #212 still owns authorized workflow activation plus sandboxed pinned-Chromium execution evidence. - Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0` on #259 exact base `b089c5f584e2c4605a40d2173b3c506e18`. PR #261 is Draft at exact head `95f7548bf07cbba76ab8b40577a11d1b6c99acb5`, stacked on exact #260. Repair PR #277 is Draft at exact head `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`, stacked on exact #261 and preserving typed `SessionSubscribe` correlation. Its hosted Rust and production-coverage jobs were cancelled, so stale conflicting #262 is not superseded and remains dependency-blocked until #277 reaches terminal GREEN on the unchanged head. - Stacked PRs #178 and #85 were repaired without force pushes at exact heads `640e594dbc0a64f251a0f28b8e80943f53337e40` and `c9adea680d6186f1842a280e248ce55da4f1305b`. Parent-relative deltas now preserve the current MV3 diagnostic and extension-authority contracts; local full suites and exact 100% coverage passed, while hosted exact-head acceptance remains independently required. - PR #70 is Draft at exact head `77eb0f2ee71783e06171784b7173c0b4cd530e61`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. Its focused Agent Task contract proves the pre-repair `--no-sandbox` launch as source RED and the branch removes that argument only from the Agent Task lane. Sandbox-enabled pinned-Chromium E2E and repository-wide GREEN remain unproven while its exact-head browser/CI/security runs are non-passing. From bd70a3dba4b40a67cf54542c8b0022c3ea6f7fa5 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 10:35:07 +0900 Subject: [PATCH 106/250] docs(gaps): record corrected 205 framing head Pin PR 37 after the segmented TLS repair and retain the exact local coverage versus hosted-check boundary. Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 703ebb0ac..a8ead71ec 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -10,7 +10,7 @@ Observed at (UTC): `2026-09-05T01:18:23Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 13 Ready/non-draft and 112 Draft; 13 open non-PR issues**. PRs #166, #229, #272, and #285 became Ready after adopting current protected main; queue movement is not protected-main delivery. -- Ready roots are #37 `357fa97dc3cd4a3afff78c29151392b50be6f50a`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Ready roots are #37 `dbff45d26291a9a1482494b46790ae9e433e669d`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass. Its Ready transition materialized repository-native CI `33930234387`, which remains queued, but did not materialize fresh central required-workflow runs: the only exact-head Security Scan `33924016851`, SAST Semgrep `33924016903`, and CodeQL PR `33924016883` runs came from the earlier Draft event and were cancelled. Missing current lifecycle evidence and the absent eligible approval remain merge blockers; toggling Draft or creating a no-op commit is not an acceptable substitute. @@ -25,7 +25,7 @@ Observed at (UTC): `2026-09-05T01:18:23Z`. - PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385` on canonical MV3 parent #43 `6f3134d18d3118aab33d28048671dc71a5f47b77`. Its child delta is diagnostic-evidence contract/doctoring only; inherited #43 implementation redacts browser/page-derived HTTP and WebDriver protocol data, startup exception details, returned capability values, DOM-dataset values, and click post-condition text before CI/audit evidence. Exact-head CI and Manifest V3 Compatibility succeeded and review threads are resolved, but parent-first workflow-ownership verification remains open, so the child stays Draft. - PR #43 is Draft at exact head `6f3134d18d3118aab33d28048671dc71a5f47b77`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. The branch now installs and configures the pinned `chrome_sandbox`; exact-head hosted verification remains required, and restoring `--no-sandbox` is not acceptable. - PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, with a repository regression contract for the exact badge target, pre-alpha status, active-PR non-promotion statement, and publication boundary. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. -- PR #37 is Ready at exact head `357fa97dc3cd4a3afff78c29151392b50be6f50a`. Current review found and repaired the RFC 9110 `205 Reset Content` semantic gap test-first: response content is now suppressed, the doctoring and changelog evidence are current, and 165 repository contracts plus the full Rust gates and exact 100% local coverage pass. Hosted exact-head checks and an eligible approval remain required. +- PR #37 is Ready at exact head `dbff45d26291a9a1482494b46790ae9e433e669d`. A real segmented TLS test proved the preceding repair could return early before a delayed prohibited `205 Reset Content` body arrived. The current head applies ordinary HTTP/1.1 wire framing first and then rejects non-empty 205 content; 165 repository contracts, full Rust gates, and exact 100% local function/line/region/branch coverage pass. Hosted exact-head checks and an eligible approval remain required. - Issue #201's release/SBOM lane remains dependency ordered, and GitHub Releases is empty. OriginWeave remains pre-GA until exact protected-head versioning, signed artifacts, SBOM/provenance, reproducibility, rollback, compatibility, security, and commercial-acceptance evidence exist. - The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #28 the first complete Chromium Agent Task vertical slice, #199 durable WARC/PROV and retention/replay, #200 stable BAP/MCP runtime API, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 enterprise identity/tenant/policy/approval/audit/SLO operations, #203 exact-artifact commercial acceptance, #276 contextual-orchestrator migration, and #279 exact-head documentation verification without unnecessary Rust queue load. - Current evidence procedure remains fail-closed: queued reviewer evidence is non-passing; paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. From 501c223fbac6a2c3df4f82e4a09a41510f066f0c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 10:43:34 +0900 Subject: [PATCH 107/250] docs(product): record text observation boundary Bind the live gap baseline to PR #269's fixed observation primitive and repair stale exact-head inventory assertions for the already-recorded #37 and #288 updates.\n\nCommit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 1 + tests/test_gap_snapshot_inventory_consistency.py | 5 +++-- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index a8ead71ec..f1c87cbbf 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -26,6 +26,7 @@ Observed at (UTC): `2026-09-05T01:18:23Z`. - PR #43 is Draft at exact head `6f3134d18d3118aab33d28048671dc71a5f47b77`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. The branch now installs and configures the pinned `chrome_sandbox`; exact-head hosted verification remains required, and restoring `--no-sandbox` is not acceptable. - PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, with a repository regression contract for the exact badge target, pre-alpha status, active-PR non-promotion statement, and publication boundary. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. - PR #37 is Ready at exact head `dbff45d26291a9a1482494b46790ae9e433e669d`. A real segmented TLS test proved the preceding repair could return early before a delayed prohibited `205 Reset Content` body arrived. The current head applies ordinary HTTP/1.1 wire framing first and then rejects non-empty 205 content; 165 repository contracts, full Rust gates, and exact 100% local function/line/region/branch coverage pass. Hosted exact-head checks and an eligible approval remain required. +- PR #269 is Draft at exact head `7854394266d3f292e779193c01413a34f6798d7c`, stacked on #268 exact `8d4027e40b790d28d866051ba741db12927ec22c`. It adds only a fixed, product-owned `script.callFunction` text-value observation for the exact admitted current node; it performs no browser I/O and proves no post-condition. Its new documentation boundary contract and all 140 Python contracts pass locally, while hosted exact-head CI is queued and the parent-first dependency keeps it Draft. - Issue #201's release/SBOM lane remains dependency ordered, and GitHub Releases is empty. OriginWeave remains pre-GA until exact protected-head versioning, signed artifacts, SBOM/provenance, reproducibility, rollback, compatibility, security, and commercial-acceptance evidence exist. - The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #28 the first complete Chromium Agent Task vertical slice, #199 durable WARC/PROV and retention/replay, #200 stable BAP/MCP runtime API, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 enterprise identity/tenant/policy/approval/audit/SLO operations, #203 exact-artifact commercial acceptance, #276 contextual-orchestrator migration, and #279 exact-head documentation verification without unnecessary Rust queue load. - Current evidence procedure remains fail-closed: queued reviewer evidence is non-passing; paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 455d1b6d8..2daa171e2 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -35,7 +35,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `357fa97dc3cd4a3afff78c29151392b50be6f50a`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", + "Ready roots are #37 `dbff45d26291a9a1482494b46790ae9e433e669d`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", "PR #238's moving exact head is intentionally omitted", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", @@ -48,7 +48,8 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385`", "PR #282 is Draft at exact head `b54a5856d8201911f05d69622f0d5594a371adf0`", "PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`", - "PR #288 is Draft at exact head `e051a3d06a613233781272ffdc0e564023ba52b0`", + "PR #288 is Draft at exact head `39e36256651f62940ec3ca6149067f0cfcb2285a`", + "PR #269 is Draft at exact head `7854394266d3f292e779193c01413a34f6798d7c`", "PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0`", "CI `33930234387`", "Security Scan `33924016851`", From 31b5a543896212d8d42fb5b08d1051c233595110 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 10:51:41 +0900 Subject: [PATCH 108/250] docs(product): record observation transport sync Bind the live gap baseline to PR #270's current parent-synchronized head and preserve its transport-only maturity boundary.\n\nCommit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 1 + tests/test_gap_snapshot_inventory_consistency.py | 1 + 2 files changed, 2 insertions(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index f1c87cbbf..0058bd760 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -27,6 +27,7 @@ Observed at (UTC): `2026-09-05T01:18:23Z`. - PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, with a repository regression contract for the exact badge target, pre-alpha status, active-PR non-promotion statement, and publication boundary. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. - PR #37 is Ready at exact head `dbff45d26291a9a1482494b46790ae9e433e669d`. A real segmented TLS test proved the preceding repair could return early before a delayed prohibited `205 Reset Content` body arrived. The current head applies ordinary HTTP/1.1 wire framing first and then rejects non-empty 205 content; 165 repository contracts, full Rust gates, and exact 100% local function/line/region/branch coverage pass. Hosted exact-head checks and an eligible approval remain required. - PR #269 is Draft at exact head `7854394266d3f292e779193c01413a34f6798d7c`, stacked on #268 exact `8d4027e40b790d28d866051ba741db12927ec22c`. It adds only a fixed, product-owned `script.callFunction` text-value observation for the exact admitted current node; it performs no browser I/O and proves no post-condition. Its new documentation boundary contract and all 140 Python contracts pass locally, while hosted exact-head CI is queued and the parent-first dependency keeps it Draft. +- PR #270 is Draft at exact head `191a14535219ea8033777fa4c970efb281b62418`, now non-force synchronized onto #269 exact `7854394266d3f292e779193c01413a34f6798d7c`. Its parent-relative transport delta is unchanged; 140 Python contracts, full Rust gates, and exact 100% local production function/line/region/branch coverage pass. Dispatch still proves neither the correlated result nor text-entry success, and fresh hosted exact-head checks plus parent-first integration remain required. - Issue #201's release/SBOM lane remains dependency ordered, and GitHub Releases is empty. OriginWeave remains pre-GA until exact protected-head versioning, signed artifacts, SBOM/provenance, reproducibility, rollback, compatibility, security, and commercial-acceptance evidence exist. - The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #28 the first complete Chromium Agent Task vertical slice, #199 durable WARC/PROV and retention/replay, #200 stable BAP/MCP runtime API, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 enterprise identity/tenant/policy/approval/audit/SLO operations, #203 exact-artifact commercial acceptance, #276 contextual-orchestrator migration, and #279 exact-head documentation verification without unnecessary Rust queue load. - Current evidence procedure remains fail-closed: queued reviewer evidence is non-passing; paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 2daa171e2..1324e0230 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -50,6 +50,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`", "PR #288 is Draft at exact head `39e36256651f62940ec3ca6149067f0cfcb2285a`", "PR #269 is Draft at exact head `7854394266d3f292e779193c01413a34f6798d7c`", + "PR #270 is Draft at exact head `191a14535219ea8033777fa4c970efb281b62418`", "PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0`", "CI `33930234387`", "Security Scan `33924016851`", From fee81e8d92e655fe6d7a74ebeaeed441e31eb393 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 10:58:12 +0900 Subject: [PATCH 109/250] docs(product): record postcondition response sync Bind the live baseline to PR #271's exact equality-only post-condition evidence and page-text non-retention boundary.\n\nCommit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 1 + tests/test_gap_snapshot_inventory_consistency.py | 1 + 2 files changed, 2 insertions(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 0058bd760..e50cf6827 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -28,6 +28,7 @@ Observed at (UTC): `2026-09-05T01:18:23Z`. - PR #37 is Ready at exact head `dbff45d26291a9a1482494b46790ae9e433e669d`. A real segmented TLS test proved the preceding repair could return early before a delayed prohibited `205 Reset Content` body arrived. The current head applies ordinary HTTP/1.1 wire framing first and then rejects non-empty 205 content; 165 repository contracts, full Rust gates, and exact 100% local function/line/region/branch coverage pass. Hosted exact-head checks and an eligible approval remain required. - PR #269 is Draft at exact head `7854394266d3f292e779193c01413a34f6798d7c`, stacked on #268 exact `8d4027e40b790d28d866051ba741db12927ec22c`. It adds only a fixed, product-owned `script.callFunction` text-value observation for the exact admitted current node; it performs no browser I/O and proves no post-condition. Its new documentation boundary contract and all 140 Python contracts pass locally, while hosted exact-head CI is queued and the parent-first dependency keeps it Draft. - PR #270 is Draft at exact head `191a14535219ea8033777fa4c970efb281b62418`, now non-force synchronized onto #269 exact `7854394266d3f292e779193c01413a34f6798d7c`. Its parent-relative transport delta is unchanged; 140 Python contracts, full Rust gates, and exact 100% local production function/line/region/branch coverage pass. Dispatch still proves neither the correlated result nor text-entry success, and fresh hosted exact-head checks plus parent-first integration remain required. +- PR #271 is Draft at exact head `802ec806cdd4560eab48c484f435766ecabda353`, non-force synchronized onto #270 exact `191a14535219ea8033777fa4c970efb281b62418`. It admits only the exact typed observation response, treats unequal text as `PostconditionMismatch`, and retains no page-controlled or expected text in public evidence or diagnostics. Its test-first documentation contract, all 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - Issue #201's release/SBOM lane remains dependency ordered, and GitHub Releases is empty. OriginWeave remains pre-GA until exact protected-head versioning, signed artifacts, SBOM/provenance, reproducibility, rollback, compatibility, security, and commercial-acceptance evidence exist. - The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #28 the first complete Chromium Agent Task vertical slice, #199 durable WARC/PROV and retention/replay, #200 stable BAP/MCP runtime API, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 enterprise identity/tenant/policy/approval/audit/SLO operations, #203 exact-artifact commercial acceptance, #276 contextual-orchestrator migration, and #279 exact-head documentation verification without unnecessary Rust queue load. - Current evidence procedure remains fail-closed: queued reviewer evidence is non-passing; paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 1324e0230..f911cea74 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -51,6 +51,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #288 is Draft at exact head `39e36256651f62940ec3ca6149067f0cfcb2285a`", "PR #269 is Draft at exact head `7854394266d3f292e779193c01413a34f6798d7c`", "PR #270 is Draft at exact head `191a14535219ea8033777fa4c970efb281b62418`", + "PR #271 is Draft at exact head `802ec806cdd4560eab48c484f435766ecabda353`", "PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0`", "CI `33930234387`", "Security Scan `33924016851`", From 524a13ac311c416fcfb6a08a4521612a9dd5fbb9 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 11:13:58 +0900 Subject: [PATCH 110/250] docs(product): record repaired BiDi lineage Refresh the active-stack baseline and executable inventory contracts with the exact #195 and #93 heads, their local verification, and the remaining authority boundaries. Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 5 +++- ...cumentation_active_pr_evidence_contract.py | 3 +- tests/test_product_completion_gap_contract.py | 28 +++++++++++++++++++ 3 files changed, 34 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e50cf6827..791f84ecd 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -29,6 +29,8 @@ Observed at (UTC): `2026-09-05T01:18:23Z`. - PR #269 is Draft at exact head `7854394266d3f292e779193c01413a34f6798d7c`, stacked on #268 exact `8d4027e40b790d28d866051ba741db12927ec22c`. It adds only a fixed, product-owned `script.callFunction` text-value observation for the exact admitted current node; it performs no browser I/O and proves no post-condition. Its new documentation boundary contract and all 140 Python contracts pass locally, while hosted exact-head CI is queued and the parent-first dependency keeps it Draft. - PR #270 is Draft at exact head `191a14535219ea8033777fa4c970efb281b62418`, now non-force synchronized onto #269 exact `7854394266d3f292e779193c01413a34f6798d7c`. Its parent-relative transport delta is unchanged; 140 Python contracts, full Rust gates, and exact 100% local production function/line/region/branch coverage pass. Dispatch still proves neither the correlated result nor text-entry success, and fresh hosted exact-head checks plus parent-first integration remain required. - PR #271 is Draft at exact head `802ec806cdd4560eab48c484f435766ecabda353`, non-force synchronized onto #270 exact `191a14535219ea8033777fa4c970efb281b62418`. It admits only the exact typed observation response, treats unequal text as `PostconditionMismatch`, and retains no page-controlled or expected text in public evidence or diagnostics. Its test-first documentation contract, all 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. +- PR #195 is Draft at exact head `b852245aa8da9ddc14ac5dbff5ebf1bcc665e65c`. Its loopback regression now holds the accepted peer until the bounded opening-write timeout is cleared, removing a macOS close race without weakening production cleanup failures. The affected test passed 50 consecutive focused regression passes, followed by 139 Python contracts, full Rust gates, and exact 100% local production coverage; fresh hosted exact-head checks and prerequisite integration remain required. +- PR #93 is Draft at exact head `82b0ebb6c541ce35bd49ca58f6b5d89861f64fd0`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #195's shared timeout-race repair. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - Issue #201's release/SBOM lane remains dependency ordered, and GitHub Releases is empty. OriginWeave remains pre-GA until exact protected-head versioning, signed artifacts, SBOM/provenance, reproducibility, rollback, compatibility, security, and commercial-acceptance evidence exist. - The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #28 the first complete Chromium Agent Task vertical slice, #199 durable WARC/PROV and retention/replay, #200 stable BAP/MCP runtime API, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 enterprise identity/tenant/policy/approval/audit/SLO operations, #203 exact-artifact commercial acceptance, #276 contextual-orchestrator migration, and #279 exact-head documentation verification without unnecessary Rust queue load. - Current evidence procedure remains fail-closed: queued reviewer evidence is non-passing; paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. @@ -88,7 +90,8 @@ The following representative slices were re-fetched from GitHub for this snapsho | #220 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `b11db2be68f9b6d71aa4c4290b97a8b22097b353` | | #211 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `52a918577958a5701e1146c7eb8b62fe8f8ccd44` | | #152 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `81407a0e5189a413d1be0963fea90a0c2f254ce1` | -| #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | `05e440948840afff1dc6e62cdb6fa52e03ebdaa9` | +| #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | `b852245aa8da9ddc14ac5dbff5ebf1bcc665e65c` | +| #93 | Draft | `802ec806cdd4560eab48c484f435766ecabda353` | `82b0ebb6c541ce35bd49ca58f6b5d89861f64fd0` | | #124 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fdb88698ca20626a6643bc2ad7944fb968835700` | | #37 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `5e3dfcbd7a4daea297782cb99635990368589232` | diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index a9be4fcac..18c403aef 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -63,7 +63,8 @@ def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> No "| #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0145ccba5901e301b41d4be674ca1ed23483ad37` |", "| #220 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `b11db2be68f9b6d71aa4c4290b97a8b22097b353` |", "| #211 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `52a918577958a5701e1146c7eb8b62fe8f8ccd44` |", - "| #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | `05e440948840afff1dc6e62cdb6fa52e03ebdaa9` |", + "| #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | `b852245aa8da9ddc14ac5dbff5ebf1bcc665e65c` |", + "| #93 | Draft | `802ec806cdd4560eab48c484f435766ecabda353` | `82b0ebb6c541ce35bd49ca58f6b5d89861f64fd0` |", "| #124 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fdb88698ca20626a6643bc2ad7944fb968835700` |", "| #37 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `5e3dfcbd7a4daea297782cb99635990368589232` |", ): diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index dc7d7a21d..48b495578 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -104,6 +104,34 @@ def test_current_snapshot_records_the_pr_284_admin_bypass_incident(self) -> None self.assertNotIn("through #280", current) + def test_current_snapshot_records_repaired_webdriver_bidi_lineage(self) -> None: + """The active stack must retain exact heads and the macOS race boundary.""" + text = BASELINE.read_text(encoding="utf-8") + current = text.split("## Current live delivery state", 1)[1].split( + "## Observed snapshot: ", 1 + )[0] + + for marker in ( + "#195 is Draft at exact head `b852245aa8da9ddc14ac5dbff5ebf1bcc665e65c`", + "50 consecutive focused regression passes", + "#93 is Draft at exact head `82b0ebb6c541ce35bd49ca58f6b5d89861f64fd0`", + "SemanticNodeActionBinding", + "does not authorize policy or execute input", + ): + with self.subTest(marker=marker): + self.assertIn(marker, current) + + self.assertIn( + "| #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | " + "`b852245aa8da9ddc14ac5dbff5ebf1bcc665e65c` |", + text, + ) + self.assertIn( + "| #93 | Draft | `802ec806cdd4560eab48c484f435766ecabda353` | " + "`82b0ebb6c541ce35bd49ca58f6b5d89861f64fd0` |", + text, + ) + def test_changelog_marks_superseded_warc_head_as_historical(self) -> None: """A predecessor WARC head must not look like the current exact evidence.""" text = (ROOT / "CHANGELOG.md").read_text(encoding="utf-8") From ded8b878d2f872a17e7e32cbce87a6d7baea4dde Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 11:17:30 +0900 Subject: [PATCH 111/250] docs(product): record HTTP persistence repair Advance the live Ready-root evidence to PR #37 exact head fa34a696 and preserve the Content-Length message-boundary contract in the executable baseline. Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 4 ++-- tests/test_gap_snapshot_inventory_consistency.py | 2 +- tests/test_product_completion_gap_contract.py | 16 ++++++++++++++++ 3 files changed, 19 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 791f84ecd..97b86f585 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -10,7 +10,7 @@ Observed at (UTC): `2026-09-05T01:18:23Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 13 Ready/non-draft and 112 Draft; 13 open non-PR issues**. PRs #166, #229, #272, and #285 became Ready after adopting current protected main; queue movement is not protected-main delivery. -- Ready roots are #37 `dbff45d26291a9a1482494b46790ae9e433e669d`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Ready roots are #37 `fa34a696e4ed9b2529a65a7d6a45ac8b72ecefb3`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass. Its Ready transition materialized repository-native CI `33930234387`, which remains queued, but did not materialize fresh central required-workflow runs: the only exact-head Security Scan `33924016851`, SAST Semgrep `33924016903`, and CodeQL PR `33924016883` runs came from the earlier Draft event and were cancelled. Missing current lifecycle evidence and the absent eligible approval remain merge blockers; toggling Draft or creating a no-op commit is not an acceptable substitute. @@ -25,7 +25,7 @@ Observed at (UTC): `2026-09-05T01:18:23Z`. - PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385` on canonical MV3 parent #43 `6f3134d18d3118aab33d28048671dc71a5f47b77`. Its child delta is diagnostic-evidence contract/doctoring only; inherited #43 implementation redacts browser/page-derived HTTP and WebDriver protocol data, startup exception details, returned capability values, DOM-dataset values, and click post-condition text before CI/audit evidence. Exact-head CI and Manifest V3 Compatibility succeeded and review threads are resolved, but parent-first workflow-ownership verification remains open, so the child stays Draft. - PR #43 is Draft at exact head `6f3134d18d3118aab33d28048671dc71a5f47b77`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. The branch now installs and configures the pinned `chrome_sandbox`; exact-head hosted verification remains required, and restoring `--no-sandbox` is not acceptable. - PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, with a repository regression contract for the exact badge target, pre-alpha status, active-PR non-promotion statement, and publication boundary. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. -- PR #37 is Ready at exact head `dbff45d26291a9a1482494b46790ae9e433e669d`. A real segmented TLS test proved the preceding repair could return early before a delayed prohibited `205 Reset Content` body arrived. The current head applies ordinary HTTP/1.1 wire framing first and then rejects non-empty 205 content; 165 repository contracts, full Rust gates, and exact 100% local function/line/region/branch coverage pass. Hosted exact-head checks and an eligible approval remain required. +- PR #37 is Ready at exact head `fa34a696e4ed9b2529a65a7d6a45ac8b72ecefb3`. After the 205 framing repair, a realistic TLS keep-alive RED proved that exact `Content-Length` completion still waited for connection closure. The current reader returns after the exact declared bytes, already-buffered surplus remains fail-closed, and valid self-delimited content does not require TLS EOF. The focused persistence regression passes; full hosted exact-head checks and an eligible approval remain required. - PR #269 is Draft at exact head `7854394266d3f292e779193c01413a34f6798d7c`, stacked on #268 exact `8d4027e40b790d28d866051ba741db12927ec22c`. It adds only a fixed, product-owned `script.callFunction` text-value observation for the exact admitted current node; it performs no browser I/O and proves no post-condition. Its new documentation boundary contract and all 140 Python contracts pass locally, while hosted exact-head CI is queued and the parent-first dependency keeps it Draft. - PR #270 is Draft at exact head `191a14535219ea8033777fa4c970efb281b62418`, now non-force synchronized onto #269 exact `7854394266d3f292e779193c01413a34f6798d7c`. Its parent-relative transport delta is unchanged; 140 Python contracts, full Rust gates, and exact 100% local production function/line/region/branch coverage pass. Dispatch still proves neither the correlated result nor text-entry success, and fresh hosted exact-head checks plus parent-first integration remain required. - PR #271 is Draft at exact head `802ec806cdd4560eab48c484f435766ecabda353`, non-force synchronized onto #270 exact `191a14535219ea8033777fa4c970efb281b62418`. It admits only the exact typed observation response, treats unequal text as `PostconditionMismatch`, and retains no page-controlled or expected text in public evidence or diagnostics. Its test-first documentation contract, all 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index f911cea74..f1baa38ff 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -35,7 +35,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `dbff45d26291a9a1482494b46790ae9e433e669d`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", + "Ready roots are #37 `fa34a696e4ed9b2529a65a7d6a45ac8b72ecefb3`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", "PR #238's moving exact head is intentionally omitted", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 48b495578..74f9b51a8 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -132,6 +132,22 @@ def test_current_snapshot_records_repaired_webdriver_bidi_lineage(self) -> None: text, ) + def test_current_snapshot_records_content_length_persistence_repair(self) -> None: + """A declared body boundary must not be confused with transport closure.""" + text = BASELINE.read_text(encoding="utf-8") + current = text.split("## Current live delivery state", 1)[1].split( + "## Observed snapshot: ", 1 + )[0] + + for marker in ( + "PR #37 is Ready at exact head `fa34a696e4ed9b2529a65a7d6a45ac8b72ecefb3`", + "returns after the exact declared bytes", + "already-buffered surplus remains fail-closed", + "does not require TLS EOF", + ): + with self.subTest(marker=marker): + self.assertIn(marker, current) + def test_changelog_marks_superseded_warc_head_as_historical(self) -> None: """A predecessor WARC head must not look like the current exact evidence.""" text = (ROOT / "CHANGELOG.md").read_text(encoding="utf-8") From 650db22d70faf3b4c561c47580d180b0d4cad176 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 11:45:53 +0900 Subject: [PATCH 112/250] docs: refresh semantic action stack evidence Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 12 ++++++---- ...cumentation_active_pr_evidence_contract.py | 6 +++-- tests/test_product_completion_gap_contract.py | 22 +++++++++++++++---- 4 files changed, 31 insertions(+), 10 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 536a0a729..cca7f87a0 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Refreshed the active WebDriver BiDi and semantic-action stack evidence for exact heads #195, #242, #93, and #95, including the macOS fixture-race repairs and fail-closed policy-authorization boundary. - Recorded PR #285's Ready-event materialization gap: repository-native exact-head CI restarted, while the earlier central Security, Semgrep, and CodeQL runs remained cancelled and no fresh required-workflow replacements appeared. - Refreshed the live product-gap baseline with PR #37's RFC 9110 `205 Reset Content` repair head and exact local verification evidence. - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 97b86f585..d31f99a63 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -29,8 +29,10 @@ Observed at (UTC): `2026-09-05T01:18:23Z`. - PR #269 is Draft at exact head `7854394266d3f292e779193c01413a34f6798d7c`, stacked on #268 exact `8d4027e40b790d28d866051ba741db12927ec22c`. It adds only a fixed, product-owned `script.callFunction` text-value observation for the exact admitted current node; it performs no browser I/O and proves no post-condition. Its new documentation boundary contract and all 140 Python contracts pass locally, while hosted exact-head CI is queued and the parent-first dependency keeps it Draft. - PR #270 is Draft at exact head `191a14535219ea8033777fa4c970efb281b62418`, now non-force synchronized onto #269 exact `7854394266d3f292e779193c01413a34f6798d7c`. Its parent-relative transport delta is unchanged; 140 Python contracts, full Rust gates, and exact 100% local production function/line/region/branch coverage pass. Dispatch still proves neither the correlated result nor text-entry success, and fresh hosted exact-head checks plus parent-first integration remain required. - PR #271 is Draft at exact head `802ec806cdd4560eab48c484f435766ecabda353`, non-force synchronized onto #270 exact `191a14535219ea8033777fa4c970efb281b62418`. It admits only the exact typed observation response, treats unequal text as `PostconditionMismatch`, and retains no page-controlled or expected text in public evidence or diagnostics. Its test-first documentation contract, all 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. -- PR #195 is Draft at exact head `b852245aa8da9ddc14ac5dbff5ebf1bcc665e65c`. Its loopback regression now holds the accepted peer until the bounded opening-write timeout is cleared, removing a macOS close race without weakening production cleanup failures. The affected test passed 50 consecutive focused regression passes, followed by 139 Python contracts, full Rust gates, and exact 100% local production coverage; fresh hosted exact-head checks and prerequisite integration remain required. -- PR #93 is Draft at exact head `82b0ebb6c541ce35bd49ca58f6b5d89861f64fd0`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #195's shared timeout-race repair. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. +- PR #195 is Draft at exact head `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its loopback regressions hold the accepted peer through opening-write timeout cleanup and locally revoked-stream classification, removing macOS close races without weakening production failures. The original affected test passed 50 consecutive focused regression passes, followed by 139 Python contracts, full Rust gates, and exact 100% local production coverage; fresh hosted exact-head checks and prerequisite integration remain required. +- PR #242 is Draft at exact head `55fef0c3fae1724eddada53e52c4a0311f509aa3`, stacked on #195 exact `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its zero-deadline regression holds the accepted peer until validation completes, so macOS cannot race socket teardown against the intended invalid-input result. Its 139 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. +- PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. +- PR #95 is Draft at exact head `97aa0f2e340ee6fd920d0418f97af276b190554f`, stacked on #93 exact `0664f0452cb329cd692cce7f61f9001652abfda2`. Only `Decision::Allow` creates policy-authorized value; other decisions fail closed, and registry-owned current authority returns `NotAdmitted` after document advance removes the node. The slice performs no browser I/O or postcondition proof. Its 142 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - Issue #201's release/SBOM lane remains dependency ordered, and GitHub Releases is empty. OriginWeave remains pre-GA until exact protected-head versioning, signed artifacts, SBOM/provenance, reproducibility, rollback, compatibility, security, and commercial-acceptance evidence exist. - The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #28 the first complete Chromium Agent Task vertical slice, #199 durable WARC/PROV and retention/replay, #200 stable BAP/MCP runtime API, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 enterprise identity/tenant/policy/approval/audit/SLO operations, #203 exact-artifact commercial acceptance, #276 contextual-orchestrator migration, and #279 exact-head documentation verification without unnecessary Rust queue load. - Current evidence procedure remains fail-closed: queued reviewer evidence is non-passing; paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. @@ -90,8 +92,10 @@ The following representative slices were re-fetched from GitHub for this snapsho | #220 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `b11db2be68f9b6d71aa4c4290b97a8b22097b353` | | #211 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `52a918577958a5701e1146c7eb8b62fe8f8ccd44` | | #152 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `81407a0e5189a413d1be0963fea90a0c2f254ce1` | -| #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | `b852245aa8da9ddc14ac5dbff5ebf1bcc665e65c` | -| #93 | Draft | `802ec806cdd4560eab48c484f435766ecabda353` | `82b0ebb6c541ce35bd49ca58f6b5d89861f64fd0` | +| #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | `48eb2d23009c1c804520dd5efcd0d4d072aacef1` | +| #242 | Draft | `48eb2d23009c1c804520dd5efcd0d4d072aacef1` | `55fef0c3fae1724eddada53e52c4a0311f509aa3` | +| #93 | Draft | `802ec806cdd4560eab48c484f435766ecabda353` | `0664f0452cb329cd692cce7f61f9001652abfda2` | +| #95 | Draft | `0664f0452cb329cd692cce7f61f9001652abfda2` | `97aa0f2e340ee6fd920d0418f97af276b190554f` | | #124 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fdb88698ca20626a6643bc2ad7944fb968835700` | | #37 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `5e3dfcbd7a4daea297782cb99635990368589232` | diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 18c403aef..84f9a285e 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -63,8 +63,10 @@ def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> No "| #229 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `0145ccba5901e301b41d4be674ca1ed23483ad37` |", "| #220 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `b11db2be68f9b6d71aa4c4290b97a8b22097b353` |", "| #211 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `52a918577958a5701e1146c7eb8b62fe8f8ccd44` |", - "| #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | `b852245aa8da9ddc14ac5dbff5ebf1bcc665e65c` |", - "| #93 | Draft | `802ec806cdd4560eab48c484f435766ecabda353` | `82b0ebb6c541ce35bd49ca58f6b5d89861f64fd0` |", + "| #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | `48eb2d23009c1c804520dd5efcd0d4d072aacef1` |", + "| #242 | Draft | `48eb2d23009c1c804520dd5efcd0d4d072aacef1` | `55fef0c3fae1724eddada53e52c4a0311f509aa3` |", + "| #93 | Draft | `802ec806cdd4560eab48c484f435766ecabda353` | `0664f0452cb329cd692cce7f61f9001652abfda2` |", + "| #95 | Draft | `0664f0452cb329cd692cce7f61f9001652abfda2` | `97aa0f2e340ee6fd920d0418f97af276b190554f` |", "| #124 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fdb88698ca20626a6643bc2ad7944fb968835700` |", "| #37 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `5e3dfcbd7a4daea297782cb99635990368589232` |", ): diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 74f9b51a8..e4ace69b7 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -112,23 +112,37 @@ def test_current_snapshot_records_repaired_webdriver_bidi_lineage(self) -> None: )[0] for marker in ( - "#195 is Draft at exact head `b852245aa8da9ddc14ac5dbff5ebf1bcc665e65c`", + "#195 is Draft at exact head `48eb2d23009c1c804520dd5efcd0d4d072aacef1`", "50 consecutive focused regression passes", - "#93 is Draft at exact head `82b0ebb6c541ce35bd49ca58f6b5d89861f64fd0`", + "#242 is Draft at exact head `55fef0c3fae1724eddada53e52c4a0311f509aa3`", + "#93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`", "SemanticNodeActionBinding", "does not authorize policy or execute input", + "#95 is Draft at exact head `97aa0f2e340ee6fd920d0418f97af276b190554f`", + "Only `Decision::Allow`", + "`NotAdmitted`", ): with self.subTest(marker=marker): self.assertIn(marker, current) self.assertIn( "| #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | " - "`b852245aa8da9ddc14ac5dbff5ebf1bcc665e65c` |", + "`48eb2d23009c1c804520dd5efcd0d4d072aacef1` |", text, ) self.assertIn( "| #93 | Draft | `802ec806cdd4560eab48c484f435766ecabda353` | " - "`82b0ebb6c541ce35bd49ca58f6b5d89861f64fd0` |", + "`0664f0452cb329cd692cce7f61f9001652abfda2` |", + text, + ) + self.assertIn( + "| #242 | Draft | `48eb2d23009c1c804520dd5efcd0d4d072aacef1` | " + "`55fef0c3fae1724eddada53e52c4a0311f509aa3` |", + text, + ) + self.assertIn( + "| #95 | Draft | `0664f0452cb329cd692cce7f61f9001652abfda2` | " + "`97aa0f2e340ee6fd920d0418f97af276b190554f` |", text, ) From 064d2d8932c3e00acc24b4943ed008ec481e3490 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 12:05:28 +0900 Subject: [PATCH 113/250] docs: extend semantic stack baseline Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- CHANGELOG.md | 2 +- docs/product-technical-gap-baseline.md | 6 ++++++ ...cumentation_active_pr_evidence_contract.py | 3 +++ tests/test_product_completion_gap_contract.py | 21 +++++++++++++++++++ 4 files changed, 31 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index cca7f87a0..e7618f549 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,7 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] -- Refreshed the active WebDriver BiDi and semantic-action stack evidence for exact heads #195, #242, #93, and #95, including the macOS fixture-race repairs and fail-closed policy-authorization boundary. +- Refreshed the active WebDriver BiDi and semantic-action stack evidence through exact heads #195, #242, #93, #95, #96, #101, and #102, including macOS fixture-race repairs and fail-closed policy, dispatch, disabled-state, and current-observation boundaries. - Recorded PR #285's Ready-event materialization gap: repository-native exact-head CI restarted, while the earlier central Security, Semgrep, and CodeQL runs remained cancelled and no fresh required-workflow replacements appeared. - Refreshed the live product-gap baseline with PR #37's RFC 9110 `205 Reset Content` repair head and exact local verification evidence. - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index d31f99a63..235b64069 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -33,6 +33,9 @@ Observed at (UTC): `2026-09-05T01:18:23Z`. - PR #242 is Draft at exact head `55fef0c3fae1724eddada53e52c4a0311f509aa3`, stacked on #195 exact `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its zero-deadline regression holds the accepted peer until validation completes, so macOS cannot race socket teardown against the intended invalid-input result. Its 139 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #95 is Draft at exact head `97aa0f2e340ee6fd920d0418f97af276b190554f`, stacked on #93 exact `0664f0452cb329cd692cce7f61f9001652abfda2`. Only `Decision::Allow` creates policy-authorized value; other decisions fail closed, and registry-owned current authority returns `NotAdmitted` after document advance removes the node. The slice performs no browser I/O or postcondition proof. Its 142 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. +- PR #96 is Draft at exact head `b7ba8dd1433410cee43084a73e31816da841b2a2`, stacked on #95 exact `97aa0f2e340ee6fd920d0418f97af276b190554f`. Registry-owned node authority is revalidated before one adapter callback, and the callback is never invoked after admission is removed. Adapter completion remains separate from postcondition proof. Its 143 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. +- PR #101 is Draft at exact head `bc810b121bb0303f55afa8777a23cc0f9748c1db`, stacked on #96 exact `b7ba8dd1433410cee43084a73e31816da841b2a2`. A known-disabled interactive action fails as `NodeNotEnabled`, while `ScrollIntoView` remains selectable; retained observation state is neither current Chromium proof nor dispatch authority. Its 144 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. +- PR #102 is Draft at exact head `a123c55d4839dae1db7e6671f7d4d158c7cfd9db`, stacked on #101 exact `bc810b121bb0303f55afa8777a23cc0f9748c1db`. Fresh semantic comparison rejects another node as `ObservationAuthorityMismatch`, removed action support, and newly disabled interactive state, but does not obtain or authenticate the observation or dispatch input. Its 145 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - Issue #201's release/SBOM lane remains dependency ordered, and GitHub Releases is empty. OriginWeave remains pre-GA until exact protected-head versioning, signed artifacts, SBOM/provenance, reproducibility, rollback, compatibility, security, and commercial-acceptance evidence exist. - The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #28 the first complete Chromium Agent Task vertical slice, #199 durable WARC/PROV and retention/replay, #200 stable BAP/MCP runtime API, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 enterprise identity/tenant/policy/approval/audit/SLO operations, #203 exact-artifact commercial acceptance, #276 contextual-orchestrator migration, and #279 exact-head documentation verification without unnecessary Rust queue load. - Current evidence procedure remains fail-closed: queued reviewer evidence is non-passing; paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. @@ -96,6 +99,9 @@ The following representative slices were re-fetched from GitHub for this snapsho | #242 | Draft | `48eb2d23009c1c804520dd5efcd0d4d072aacef1` | `55fef0c3fae1724eddada53e52c4a0311f509aa3` | | #93 | Draft | `802ec806cdd4560eab48c484f435766ecabda353` | `0664f0452cb329cd692cce7f61f9001652abfda2` | | #95 | Draft | `0664f0452cb329cd692cce7f61f9001652abfda2` | `97aa0f2e340ee6fd920d0418f97af276b190554f` | +| #96 | Draft | `97aa0f2e340ee6fd920d0418f97af276b190554f` | `b7ba8dd1433410cee43084a73e31816da841b2a2` | +| #101 | Draft | `b7ba8dd1433410cee43084a73e31816da841b2a2` | `bc810b121bb0303f55afa8777a23cc0f9748c1db` | +| #102 | Draft | `bc810b121bb0303f55afa8777a23cc0f9748c1db` | `a123c55d4839dae1db7e6671f7d4d158c7cfd9db` | | #124 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fdb88698ca20626a6643bc2ad7944fb968835700` | | #37 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `5e3dfcbd7a4daea297782cb99635990368589232` | diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 84f9a285e..9f102a32d 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -67,6 +67,9 @@ def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> No "| #242 | Draft | `48eb2d23009c1c804520dd5efcd0d4d072aacef1` | `55fef0c3fae1724eddada53e52c4a0311f509aa3` |", "| #93 | Draft | `802ec806cdd4560eab48c484f435766ecabda353` | `0664f0452cb329cd692cce7f61f9001652abfda2` |", "| #95 | Draft | `0664f0452cb329cd692cce7f61f9001652abfda2` | `97aa0f2e340ee6fd920d0418f97af276b190554f` |", + "| #96 | Draft | `97aa0f2e340ee6fd920d0418f97af276b190554f` | `b7ba8dd1433410cee43084a73e31816da841b2a2` |", + "| #101 | Draft | `b7ba8dd1433410cee43084a73e31816da841b2a2` | `bc810b121bb0303f55afa8777a23cc0f9748c1db` |", + "| #102 | Draft | `bc810b121bb0303f55afa8777a23cc0f9748c1db` | `a123c55d4839dae1db7e6671f7d4d158c7cfd9db` |", "| #124 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fdb88698ca20626a6643bc2ad7944fb968835700` |", "| #37 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `5e3dfcbd7a4daea297782cb99635990368589232` |", ): diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index e4ace69b7..75527d45c 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -121,6 +121,12 @@ def test_current_snapshot_records_repaired_webdriver_bidi_lineage(self) -> None: "#95 is Draft at exact head `97aa0f2e340ee6fd920d0418f97af276b190554f`", "Only `Decision::Allow`", "`NotAdmitted`", + "#96 is Draft at exact head `b7ba8dd1433410cee43084a73e31816da841b2a2`", + "callback is never invoked", + "#101 is Draft at exact head `bc810b121bb0303f55afa8777a23cc0f9748c1db`", + "known-disabled interactive action", + "#102 is Draft at exact head `a123c55d4839dae1db7e6671f7d4d158c7cfd9db`", + "ObservationAuthorityMismatch", ): with self.subTest(marker=marker): self.assertIn(marker, current) @@ -145,6 +151,21 @@ def test_current_snapshot_records_repaired_webdriver_bidi_lineage(self) -> None: "`97aa0f2e340ee6fd920d0418f97af276b190554f` |", text, ) + self.assertIn( + "| #96 | Draft | `97aa0f2e340ee6fd920d0418f97af276b190554f` | " + "`b7ba8dd1433410cee43084a73e31816da841b2a2` |", + text, + ) + self.assertIn( + "| #101 | Draft | `b7ba8dd1433410cee43084a73e31816da841b2a2` | " + "`bc810b121bb0303f55afa8777a23cc0f9748c1db` |", + text, + ) + self.assertIn( + "| #102 | Draft | `bc810b121bb0303f55afa8777a23cc0f9748c1db` | " + "`a123c55d4839dae1db7e6671f7d4d158c7cfd9db` |", + text, + ) def test_current_snapshot_records_content_length_persistence_repair(self) -> None: """A declared body boundary must not be confused with transport closure.""" From 3bc6bb002ef22c269294dc3cfb3b46470e8a2bde Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 12:14:25 +0900 Subject: [PATCH 114/250] docs: record current semantic dispatch head Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- CHANGELOG.md | 2 +- docs/product-technical-gap-baseline.md | 2 ++ tests/test_documentation_active_pr_evidence_contract.py | 1 + tests/test_product_completion_gap_contract.py | 7 +++++++ 4 files changed, 11 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index e7618f549..f67a4cb79 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,7 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] -- Refreshed the active WebDriver BiDi and semantic-action stack evidence through exact heads #195, #242, #93, #95, #96, #101, and #102, including macOS fixture-race repairs and fail-closed policy, dispatch, disabled-state, and current-observation boundaries. +- Refreshed the active WebDriver BiDi and semantic-action stack evidence through exact heads #195, #242, #93, #95, #96, #101, #102, and #103, including macOS fixture-race repairs and fail-closed policy, dispatch, disabled-state, and current-observation boundaries. - Recorded PR #285's Ready-event materialization gap: repository-native exact-head CI restarted, while the earlier central Security, Semgrep, and CodeQL runs remained cancelled and no fresh required-workflow replacements appeared. - Refreshed the live product-gap baseline with PR #37's RFC 9110 `205 Reset Content` repair head and exact local verification evidence. - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 235b64069..6b3fdd881 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -36,6 +36,7 @@ Observed at (UTC): `2026-09-05T01:18:23Z`. - PR #96 is Draft at exact head `b7ba8dd1433410cee43084a73e31816da841b2a2`, stacked on #95 exact `97aa0f2e340ee6fd920d0418f97af276b190554f`. Registry-owned node authority is revalidated before one adapter callback, and the callback is never invoked after admission is removed. Adapter completion remains separate from postcondition proof. Its 143 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - PR #101 is Draft at exact head `bc810b121bb0303f55afa8777a23cc0f9748c1db`, stacked on #96 exact `b7ba8dd1433410cee43084a73e31816da841b2a2`. A known-disabled interactive action fails as `NodeNotEnabled`, while `ScrollIntoView` remains selectable; retained observation state is neither current Chromium proof nor dispatch authority. Its 144 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - PR #102 is Draft at exact head `a123c55d4839dae1db7e6671f7d4d158c7cfd9db`, stacked on #101 exact `bc810b121bb0303f55afa8777a23cc0f9748c1db`. Fresh semantic comparison rejects another node as `ObservationAuthorityMismatch`, removed action support, and newly disabled interactive state, but does not obtain or authenticate the observation or dispatch input. Its 145 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. +- PR #103 is Draft at exact head `8b3416169346fa04b53c915b813d55ccf47d1876`, stacked on #102 exact `a123c55d4839dae1db7e6671f7d4d158c7cfd9db`. Same-call dispatch checks registry-owned browser authority first and fresh semantic state second; the callback is never invoked on either failure, and completion is not postcondition proof. Its 146 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - Issue #201's release/SBOM lane remains dependency ordered, and GitHub Releases is empty. OriginWeave remains pre-GA until exact protected-head versioning, signed artifacts, SBOM/provenance, reproducibility, rollback, compatibility, security, and commercial-acceptance evidence exist. - The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #28 the first complete Chromium Agent Task vertical slice, #199 durable WARC/PROV and retention/replay, #200 stable BAP/MCP runtime API, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 enterprise identity/tenant/policy/approval/audit/SLO operations, #203 exact-artifact commercial acceptance, #276 contextual-orchestrator migration, and #279 exact-head documentation verification without unnecessary Rust queue load. - Current evidence procedure remains fail-closed: queued reviewer evidence is non-passing; paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. @@ -102,6 +103,7 @@ The following representative slices were re-fetched from GitHub for this snapsho | #96 | Draft | `97aa0f2e340ee6fd920d0418f97af276b190554f` | `b7ba8dd1433410cee43084a73e31816da841b2a2` | | #101 | Draft | `b7ba8dd1433410cee43084a73e31816da841b2a2` | `bc810b121bb0303f55afa8777a23cc0f9748c1db` | | #102 | Draft | `bc810b121bb0303f55afa8777a23cc0f9748c1db` | `a123c55d4839dae1db7e6671f7d4d158c7cfd9db` | +| #103 | Draft | `a123c55d4839dae1db7e6671f7d4d158c7cfd9db` | `8b3416169346fa04b53c915b813d55ccf47d1876` | | #124 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fdb88698ca20626a6643bc2ad7944fb968835700` | | #37 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `5e3dfcbd7a4daea297782cb99635990368589232` | diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 9f102a32d..99e67cb6f 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -70,6 +70,7 @@ def test_latest_live_pr_snapshot_is_recorded_in_the_product_baseline(self) -> No "| #96 | Draft | `97aa0f2e340ee6fd920d0418f97af276b190554f` | `b7ba8dd1433410cee43084a73e31816da841b2a2` |", "| #101 | Draft | `b7ba8dd1433410cee43084a73e31816da841b2a2` | `bc810b121bb0303f55afa8777a23cc0f9748c1db` |", "| #102 | Draft | `bc810b121bb0303f55afa8777a23cc0f9748c1db` | `a123c55d4839dae1db7e6671f7d4d158c7cfd9db` |", + "| #103 | Draft | `a123c55d4839dae1db7e6671f7d4d158c7cfd9db` | `8b3416169346fa04b53c915b813d55ccf47d1876` |", "| #124 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `fdb88698ca20626a6643bc2ad7944fb968835700` |", "| #37 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `5e3dfcbd7a4daea297782cb99635990368589232` |", ): diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 75527d45c..d4dcc7742 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -127,6 +127,8 @@ def test_current_snapshot_records_repaired_webdriver_bidi_lineage(self) -> None: "known-disabled interactive action", "#102 is Draft at exact head `a123c55d4839dae1db7e6671f7d4d158c7cfd9db`", "ObservationAuthorityMismatch", + "#103 is Draft at exact head `8b3416169346fa04b53c915b813d55ccf47d1876`", + "browser authority first", ): with self.subTest(marker=marker): self.assertIn(marker, current) @@ -166,6 +168,11 @@ def test_current_snapshot_records_repaired_webdriver_bidi_lineage(self) -> None: "`a123c55d4839dae1db7e6671f7d4d158c7cfd9db` |", text, ) + self.assertIn( + "| #103 | Draft | `a123c55d4839dae1db7e6671f7d4d158c7cfd9db` | " + "`8b3416169346fa04b53c915b813d55ccf47d1876` |", + text, + ) def test_current_snapshot_records_content_length_persistence_repair(self) -> None: """A declared body boundary must not be confused with transport closure.""" From b8d1dd806429e0fbdc025ae602da9d57d388112f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 12:28:08 +0900 Subject: [PATCH 115/250] docs: record session status coverage repair Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 6b3fdd881..077586608 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -31,6 +31,7 @@ Observed at (UTC): `2026-09-05T01:18:23Z`. - PR #271 is Draft at exact head `802ec806cdd4560eab48c484f435766ecabda353`, non-force synchronized onto #270 exact `191a14535219ea8033777fa4c970efb281b62418`. It admits only the exact typed observation response, treats unequal text as `PostconditionMismatch`, and retains no page-controlled or expected text in public evidence or diagnostics. Its test-first documentation contract, all 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #195 is Draft at exact head `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its loopback regressions hold the accepted peer through opening-write timeout cleanup and locally revoked-stream classification, removing macOS close races without weakening production failures. The original affected test passed 50 consecutive focused regression passes, followed by 139 Python contracts, full Rust gates, and exact 100% local production coverage; fresh hosted exact-head checks and prerequisite integration remain required. - PR #242 is Draft at exact head `55fef0c3fae1724eddada53e52c4a0311f509aa3`, stacked on #195 exact `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its zero-deadline regression holds the accepted peer until validation completes, so macOS cannot race socket teardown against the intended invalid-input result. Its 139 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. +- PR #249 is Draft at exact head `44387182ddd2c416e5c5182c8eeee1957fed6ade`, non-force synchronized onto #248 exact `7349dc4b5f4564824a04a0edc8b3bbebbec974ce`. Its correlation-state regression no longer creates uncovered assertion-internal failure regions while still proving local preflight retirement and ambiguous-write retention. Its 139 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks are queued and ordered parent integration remains required. - PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #95 is Draft at exact head `97aa0f2e340ee6fd920d0418f97af276b190554f`, stacked on #93 exact `0664f0452cb329cd692cce7f61f9001652abfda2`. Only `Decision::Allow` creates policy-authorized value; other decisions fail closed, and registry-owned current authority returns `NotAdmitted` after document advance removes the node. The slice performs no browser I/O or postcondition proof. Its 142 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - PR #96 is Draft at exact head `b7ba8dd1433410cee43084a73e31816da841b2a2`, stacked on #95 exact `97aa0f2e340ee6fd920d0418f97af276b190554f`. Registry-owned node authority is revalidated before one adapter callback, and the callback is never invoked after admission is removed. Adapter completion remains separate from postcondition proof. Its 143 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. @@ -98,6 +99,7 @@ The following representative slices were re-fetched from GitHub for this snapsho | #152 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `81407a0e5189a413d1be0963fea90a0c2f254ce1` | | #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | `48eb2d23009c1c804520dd5efcd0d4d072aacef1` | | #242 | Draft | `48eb2d23009c1c804520dd5efcd0d4d072aacef1` | `55fef0c3fae1724eddada53e52c4a0311f509aa3` | +| #249 | Draft | `7349dc4b5f4564824a04a0edc8b3bbebbec974ce` | `44387182ddd2c416e5c5182c8eeee1957fed6ade` | | #93 | Draft | `802ec806cdd4560eab48c484f435766ecabda353` | `0664f0452cb329cd692cce7f61f9001652abfda2` | | #95 | Draft | `0664f0452cb329cd692cce7f61f9001652abfda2` | `97aa0f2e340ee6fd920d0418f97af276b190554f` | | #96 | Draft | `97aa0f2e340ee6fd920d0418f97af276b190554f` | `b7ba8dd1433410cee43084a73e31816da841b2a2` | From 3a1f184694e2b76690b1b4beb0990a02472710b8 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 12:39:20 +0900 Subject: [PATCH 116/250] docs: refresh WebDriver BiDi stack evidence Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 12 +++++++----- tests/test_gap_snapshot_inventory_consistency.py | 6 +++--- 2 files changed, 10 insertions(+), 8 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 077586608..3b47721d4 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,11 +6,11 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T01:18:23Z`. +Observed at (UTC): `2026-09-05T03:38:02Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. -- Full live search returns **125 open pull requests: 13 Ready/non-draft and 112 Draft; 13 open non-PR issues**. PRs #166, #229, #272, and #285 became Ready after adopting current protected main; queue movement is not protected-main delivery. -- Ready roots are #37 `fa34a696e4ed9b2529a65a7d6a45ac8b72ecefb3`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Full live search returns **124 open pull requests: 13 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PR #247 merged only into its unprotected feature parent, and #248 became Ready after adopting that exact parent head; queue movement is not protected-main delivery. +- Ready roots are #37 `fa34a696e4ed9b2529a65a7d6a45ac8b72ecefb3`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass. Its Ready transition materialized repository-native CI `33930234387`, which remains queued, but did not materialize fresh central required-workflow runs: the only exact-head Security Scan `33924016851`, SAST Semgrep `33924016903`, and CodeQL PR `33924016883` runs came from the earlier Draft event and were cancelled. Missing current lifecycle evidence and the absent eligible approval remain merge blockers; toggling Draft or creating a no-op commit is not an acceptable substitute. @@ -31,7 +31,8 @@ Observed at (UTC): `2026-09-05T01:18:23Z`. - PR #271 is Draft at exact head `802ec806cdd4560eab48c484f435766ecabda353`, non-force synchronized onto #270 exact `191a14535219ea8033777fa4c970efb281b62418`. It admits only the exact typed observation response, treats unequal text as `PostconditionMismatch`, and retains no page-controlled or expected text in public evidence or diagnostics. Its test-first documentation contract, all 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #195 is Draft at exact head `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its loopback regressions hold the accepted peer through opening-write timeout cleanup and locally revoked-stream classification, removing macOS close races without weakening production failures. The original affected test passed 50 consecutive focused regression passes, followed by 139 Python contracts, full Rust gates, and exact 100% local production coverage; fresh hosted exact-head checks and prerequisite integration remain required. - PR #242 is Draft at exact head `55fef0c3fae1724eddada53e52c4a0311f509aa3`, stacked on #195 exact `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its zero-deadline regression holds the accepted peer until validation completes, so macOS cannot race socket teardown against the intended invalid-input result. Its 139 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. -- PR #249 is Draft at exact head `44387182ddd2c416e5c5182c8eeee1957fed6ade`, non-force synchronized onto #248 exact `7349dc4b5f4564824a04a0edc8b3bbebbec974ce`. Its correlation-state regression no longer creates uncovered assertion-internal failure regions while still proving local preflight retirement and ambiguous-write retention. Its 139 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks are queued and ordered parent integration remains required. +- PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 is Ready at exact head `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb` on that merged #247 head. Its 141 Python contracts, full Rust gates, and CI-equivalent pinned-nightly 100% production coverage pass; hosted exact-head checks are queued. +- PR #249 is Draft at exact head `2279d18189fcd6cdb2b38aca53b877434d41c913`, non-force synchronized onto #248 exact `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`. Its correlation-state regression no longer creates uncovered assertion-internal failure regions while still proving local preflight retirement and ambiguous-write retention. Its 141 Python contracts, full Rust gates, and CI-equivalent pinned-nightly 100% production coverage pass; hosted exact-head checks are queued and ordered parent integration remains required. - PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #95 is Draft at exact head `97aa0f2e340ee6fd920d0418f97af276b190554f`, stacked on #93 exact `0664f0452cb329cd692cce7f61f9001652abfda2`. Only `Decision::Allow` creates policy-authorized value; other decisions fail closed, and registry-owned current authority returns `NotAdmitted` after document advance removes the node. The slice performs no browser I/O or postcondition proof. Its 142 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - PR #96 is Draft at exact head `b7ba8dd1433410cee43084a73e31816da841b2a2`, stacked on #95 exact `97aa0f2e340ee6fd920d0418f97af276b190554f`. Registry-owned node authority is revalidated before one adapter callback, and the callback is never invoked after admission is removed. Adapter completion remains separate from postcondition proof. Its 143 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. @@ -99,7 +100,8 @@ The following representative slices were re-fetched from GitHub for this snapsho | #152 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `81407a0e5189a413d1be0963fea90a0c2f254ce1` | | #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | `48eb2d23009c1c804520dd5efcd0d4d072aacef1` | | #242 | Draft | `48eb2d23009c1c804520dd5efcd0d4d072aacef1` | `55fef0c3fae1724eddada53e52c4a0311f509aa3` | -| #249 | Draft | `7349dc4b5f4564824a04a0edc8b3bbebbec974ce` | `44387182ddd2c416e5c5182c8eeee1957fed6ade` | +| #248 | Ready | `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` | `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb` | +| #249 | Draft | `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb` | `2279d18189fcd6cdb2b38aca53b877434d41c913` | | #93 | Draft | `802ec806cdd4560eab48c484f435766ecabda353` | `0664f0452cb329cd692cce7f61f9001652abfda2` | | #95 | Draft | `0664f0452cb329cd692cce7f61f9001652abfda2` | `97aa0f2e340ee6fd920d0418f97af276b190554f` | | #96 | Draft | `97aa0f2e340ee6fd920d0418f97af276b190554f` | `b7ba8dd1433410cee43084a73e31816da841b2a2` | diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index f1baa38ff..b8d71ce46 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -26,16 +26,16 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "## Observed snapshot: 2026-08-29", 1 )[0] for marker in ( - "125 open pull requests", + "124 open pull requests", "13 Ready/non-draft", - "112 Draft", + "111 Draft", "13 open non-PR issues", "87c4daa1830bac5a5228b6036752ad5633232085", "18156473", "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `fa34a696e4ed9b2529a65a7d6a45ac8b72ecefb3`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #247 `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", + "Ready roots are #37 `fa34a696e4ed9b2529a65a7d6a45ac8b72ecefb3`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", "PR #238's moving exact head is intentionally omitted", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", From 44057276bd14daeac83a52959b81e7a06cfa487d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 12:47:20 +0900 Subject: [PATCH 117/250] docs: record session lifecycle stack heads Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 3b47721d4..575eb448c 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,7 +6,7 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T03:38:02Z`. +Observed at (UTC): `2026-09-05T03:46:55Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **124 open pull requests: 13 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PR #247 merged only into its unprotected feature parent, and #248 became Ready after adopting that exact parent head; queue movement is not protected-main delivery. @@ -33,6 +33,7 @@ Observed at (UTC): `2026-09-05T03:38:02Z`. - PR #242 is Draft at exact head `55fef0c3fae1724eddada53e52c4a0311f509aa3`, stacked on #195 exact `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its zero-deadline regression holds the accepted peer until validation completes, so macOS cannot race socket teardown against the intended invalid-input result. Its 139 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 is Ready at exact head `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb` on that merged #247 head. Its 141 Python contracts, full Rust gates, and CI-equivalent pinned-nightly 100% production coverage pass; hosted exact-head checks are queued. - PR #249 is Draft at exact head `2279d18189fcd6cdb2b38aca53b877434d41c913`, non-force synchronized onto #248 exact `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`. Its correlation-state regression no longer creates uncovered assertion-internal failure regions while still proving local preflight retirement and ambiguous-write retention. Its 141 Python contracts, full Rust gates, and CI-equivalent pinned-nightly 100% production coverage pass; hosted exact-head checks are queued and ordered parent integration remains required. +- PRs #250, #251, and #252 remain Draft and are non-force synchronized in order at exact heads `cbddf507ac41080ee65230a8d6047dd8d06fd719`, `99e2eb946e7ebbffa68f65a00d25243a2cf4242a`, and `881a599fb3a920b6bfd4f0a276f3cf24a61d8194`. They preserve typed `session.status` response, `session.end` command, and correlated `session.end` response boundaries without promoting frame writes to completion evidence. Each final tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; hosted exact-head checks and ordered parent integration remain required. - PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #95 is Draft at exact head `97aa0f2e340ee6fd920d0418f97af276b190554f`, stacked on #93 exact `0664f0452cb329cd692cce7f61f9001652abfda2`. Only `Decision::Allow` creates policy-authorized value; other decisions fail closed, and registry-owned current authority returns `NotAdmitted` after document advance removes the node. The slice performs no browser I/O or postcondition proof. Its 142 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - PR #96 is Draft at exact head `b7ba8dd1433410cee43084a73e31816da841b2a2`, stacked on #95 exact `97aa0f2e340ee6fd920d0418f97af276b190554f`. Registry-owned node authority is revalidated before one adapter callback, and the callback is never invoked after admission is removed. Adapter completion remains separate from postcondition proof. Its 143 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. @@ -102,6 +103,9 @@ The following representative slices were re-fetched from GitHub for this snapsho | #242 | Draft | `48eb2d23009c1c804520dd5efcd0d4d072aacef1` | `55fef0c3fae1724eddada53e52c4a0311f509aa3` | | #248 | Ready | `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` | `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb` | | #249 | Draft | `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb` | `2279d18189fcd6cdb2b38aca53b877434d41c913` | +| #250 | Draft | `2279d18189fcd6cdb2b38aca53b877434d41c913` | `cbddf507ac41080ee65230a8d6047dd8d06fd719` | +| #251 | Draft | `cbddf507ac41080ee65230a8d6047dd8d06fd719` | `99e2eb946e7ebbffa68f65a00d25243a2cf4242a` | +| #252 | Draft | `99e2eb946e7ebbffa68f65a00d25243a2cf4242a` | `881a599fb3a920b6bfd4f0a276f3cf24a61d8194` | | #93 | Draft | `802ec806cdd4560eab48c484f435766ecabda353` | `0664f0452cb329cd692cce7f61f9001652abfda2` | | #95 | Draft | `0664f0452cb329cd692cce7f61f9001652abfda2` | `97aa0f2e340ee6fd920d0418f97af276b190554f` | | #96 | Draft | `97aa0f2e340ee6fd920d0418f97af276b190554f` | `b7ba8dd1433410cee43084a73e31816da841b2a2` | From ce6bed54848957c383c1ee81d0a7bee94d78d3be Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 12:50:17 +0900 Subject: [PATCH 118/250] docs: extend session lifecycle stack evidence Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 575eb448c..420c9cc83 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,7 +6,7 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T03:46:55Z`. +Observed at (UTC): `2026-09-05T03:49:53Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **124 open pull requests: 13 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PR #247 merged only into its unprotected feature parent, and #248 became Ready after adopting that exact parent head; queue movement is not protected-main delivery. @@ -33,7 +33,7 @@ Observed at (UTC): `2026-09-05T03:46:55Z`. - PR #242 is Draft at exact head `55fef0c3fae1724eddada53e52c4a0311f509aa3`, stacked on #195 exact `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its zero-deadline regression holds the accepted peer until validation completes, so macOS cannot race socket teardown against the intended invalid-input result. Its 139 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 is Ready at exact head `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb` on that merged #247 head. Its 141 Python contracts, full Rust gates, and CI-equivalent pinned-nightly 100% production coverage pass; hosted exact-head checks are queued. - PR #249 is Draft at exact head `2279d18189fcd6cdb2b38aca53b877434d41c913`, non-force synchronized onto #248 exact `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`. Its correlation-state regression no longer creates uncovered assertion-internal failure regions while still proving local preflight retirement and ambiguous-write retention. Its 141 Python contracts, full Rust gates, and CI-equivalent pinned-nightly 100% production coverage pass; hosted exact-head checks are queued and ordered parent integration remains required. -- PRs #250, #251, and #252 remain Draft and are non-force synchronized in order at exact heads `cbddf507ac41080ee65230a8d6047dd8d06fd719`, `99e2eb946e7ebbffa68f65a00d25243a2cf4242a`, and `881a599fb3a920b6bfd4f0a276f3cf24a61d8194`. They preserve typed `session.status` response, `session.end` command, and correlated `session.end` response boundaries without promoting frame writes to completion evidence. Each final tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; hosted exact-head checks and ordered parent integration remain required. +- PRs #250 through #253 remain Draft and are non-force synchronized in order at exact heads `cbddf507ac41080ee65230a8d6047dd8d06fd719`, `99e2eb946e7ebbffa68f65a00d25243a2cf4242a`, `881a599fb3a920b6bfd4f0a276f3cf24a61d8194`, and `5e2b17c7a8d1953bb06a41e0296f801f0d015a9a`. They preserve typed `session.status` response, `session.end` command, correlated `session.end` response, and operational teardown-evidence boundaries without promoting frame writes or protocol acknowledgement to completed teardown. Each final tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; hosted exact-head checks and ordered parent integration remain required. - PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #95 is Draft at exact head `97aa0f2e340ee6fd920d0418f97af276b190554f`, stacked on #93 exact `0664f0452cb329cd692cce7f61f9001652abfda2`. Only `Decision::Allow` creates policy-authorized value; other decisions fail closed, and registry-owned current authority returns `NotAdmitted` after document advance removes the node. The slice performs no browser I/O or postcondition proof. Its 142 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - PR #96 is Draft at exact head `b7ba8dd1433410cee43084a73e31816da841b2a2`, stacked on #95 exact `97aa0f2e340ee6fd920d0418f97af276b190554f`. Registry-owned node authority is revalidated before one adapter callback, and the callback is never invoked after admission is removed. Adapter completion remains separate from postcondition proof. Its 143 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. @@ -106,6 +106,7 @@ The following representative slices were re-fetched from GitHub for this snapsho | #250 | Draft | `2279d18189fcd6cdb2b38aca53b877434d41c913` | `cbddf507ac41080ee65230a8d6047dd8d06fd719` | | #251 | Draft | `cbddf507ac41080ee65230a8d6047dd8d06fd719` | `99e2eb946e7ebbffa68f65a00d25243a2cf4242a` | | #252 | Draft | `99e2eb946e7ebbffa68f65a00d25243a2cf4242a` | `881a599fb3a920b6bfd4f0a276f3cf24a61d8194` | +| #253 | Draft | `881a599fb3a920b6bfd4f0a276f3cf24a61d8194` | `5e2b17c7a8d1953bb06a41e0296f801f0d015a9a` | | #93 | Draft | `802ec806cdd4560eab48c484f435766ecabda353` | `0664f0452cb329cd692cce7f61f9001652abfda2` | | #95 | Draft | `0664f0452cb329cd692cce7f61f9001652abfda2` | `97aa0f2e340ee6fd920d0418f97af276b190554f` | | #96 | Draft | `97aa0f2e340ee6fd920d0418f97af276b190554f` | `b7ba8dd1433410cee43084a73e31816da841b2a2` | From dfb36a1723a5a9821bcae316a893c870181f932b Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 12:54:41 +0900 Subject: [PATCH 119/250] docs: extend teardown stack evidence Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 420c9cc83..e7f0f1097 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,7 +6,7 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T03:49:53Z`. +Observed at (UTC): `2026-09-05T03:54:16Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **124 open pull requests: 13 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PR #247 merged only into its unprotected feature parent, and #248 became Ready after adopting that exact parent head; queue movement is not protected-main delivery. @@ -33,7 +33,7 @@ Observed at (UTC): `2026-09-05T03:49:53Z`. - PR #242 is Draft at exact head `55fef0c3fae1724eddada53e52c4a0311f509aa3`, stacked on #195 exact `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its zero-deadline regression holds the accepted peer until validation completes, so macOS cannot race socket teardown against the intended invalid-input result. Its 139 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 is Ready at exact head `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb` on that merged #247 head. Its 141 Python contracts, full Rust gates, and CI-equivalent pinned-nightly 100% production coverage pass; hosted exact-head checks are queued. - PR #249 is Draft at exact head `2279d18189fcd6cdb2b38aca53b877434d41c913`, non-force synchronized onto #248 exact `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`. Its correlation-state regression no longer creates uncovered assertion-internal failure regions while still proving local preflight retirement and ambiguous-write retention. Its 141 Python contracts, full Rust gates, and CI-equivalent pinned-nightly 100% production coverage pass; hosted exact-head checks are queued and ordered parent integration remains required. -- PRs #250 through #253 remain Draft and are non-force synchronized in order at exact heads `cbddf507ac41080ee65230a8d6047dd8d06fd719`, `99e2eb946e7ebbffa68f65a00d25243a2cf4242a`, `881a599fb3a920b6bfd4f0a276f3cf24a61d8194`, and `5e2b17c7a8d1953bb06a41e0296f801f0d015a9a`. They preserve typed `session.status` response, `session.end` command, correlated `session.end` response, and operational teardown-evidence boundaries without promoting frame writes or protocol acknowledgement to completed teardown. Each final tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; hosted exact-head checks and ordered parent integration remain required. +- PRs #250 through #255 remain Draft and are non-force synchronized in order at exact heads `cbddf507ac41080ee65230a8d6047dd8d06fd719`, `99e2eb946e7ebbffa68f65a00d25243a2cf4242a`, `881a599fb3a920b6bfd4f0a276f3cf24a61d8194`, `5e2b17c7a8d1953bb06a41e0296f801f0d015a9a`, `a4841016b94cb18e917d250a9ca9149af54ceef0`, and `f8edec38cf8ab7fde22b8d1de9305728c1a2f25b`. They preserve typed session lifecycle, operational teardown, transport-close observation, and typed teardown-transport binding without promoting frame writes, protocol acknowledgement, or a local close observation to completed browser-process teardown. Each final tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; hosted exact-head checks and ordered parent integration remain required. - PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #95 is Draft at exact head `97aa0f2e340ee6fd920d0418f97af276b190554f`, stacked on #93 exact `0664f0452cb329cd692cce7f61f9001652abfda2`. Only `Decision::Allow` creates policy-authorized value; other decisions fail closed, and registry-owned current authority returns `NotAdmitted` after document advance removes the node. The slice performs no browser I/O or postcondition proof. Its 142 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - PR #96 is Draft at exact head `b7ba8dd1433410cee43084a73e31816da841b2a2`, stacked on #95 exact `97aa0f2e340ee6fd920d0418f97af276b190554f`. Registry-owned node authority is revalidated before one adapter callback, and the callback is never invoked after admission is removed. Adapter completion remains separate from postcondition proof. Its 143 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. @@ -107,6 +107,8 @@ The following representative slices were re-fetched from GitHub for this snapsho | #251 | Draft | `cbddf507ac41080ee65230a8d6047dd8d06fd719` | `99e2eb946e7ebbffa68f65a00d25243a2cf4242a` | | #252 | Draft | `99e2eb946e7ebbffa68f65a00d25243a2cf4242a` | `881a599fb3a920b6bfd4f0a276f3cf24a61d8194` | | #253 | Draft | `881a599fb3a920b6bfd4f0a276f3cf24a61d8194` | `5e2b17c7a8d1953bb06a41e0296f801f0d015a9a` | +| #254 | Draft | `5e2b17c7a8d1953bb06a41e0296f801f0d015a9a` | `a4841016b94cb18e917d250a9ca9149af54ceef0` | +| #255 | Draft | `a4841016b94cb18e917d250a9ca9149af54ceef0` | `f8edec38cf8ab7fde22b8d1de9305728c1a2f25b` | | #93 | Draft | `802ec806cdd4560eab48c484f435766ecabda353` | `0664f0452cb329cd692cce7f61f9001652abfda2` | | #95 | Draft | `0664f0452cb329cd692cce7f61f9001652abfda2` | `97aa0f2e340ee6fd920d0418f97af276b190554f` | | #96 | Draft | `97aa0f2e340ee6fd920d0418f97af276b190554f` | `b7ba8dd1433410cee43084a73e31816da841b2a2` | From 50a127b0bfd32ca666b676aac61ca5e7c087b2d6 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 12:59:53 +0900 Subject: [PATCH 120/250] docs: record pointer click stack heads Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e7f0f1097..79c544dec 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,7 +6,7 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T03:54:16Z`. +Observed at (UTC): `2026-09-05T03:59:27Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **124 open pull requests: 13 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PR #247 merged only into its unprotected feature parent, and #248 became Ready after adopting that exact parent head; queue movement is not protected-main delivery. @@ -33,7 +33,7 @@ Observed at (UTC): `2026-09-05T03:54:16Z`. - PR #242 is Draft at exact head `55fef0c3fae1724eddada53e52c4a0311f509aa3`, stacked on #195 exact `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its zero-deadline regression holds the accepted peer until validation completes, so macOS cannot race socket teardown against the intended invalid-input result. Its 139 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 is Ready at exact head `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb` on that merged #247 head. Its 141 Python contracts, full Rust gates, and CI-equivalent pinned-nightly 100% production coverage pass; hosted exact-head checks are queued. - PR #249 is Draft at exact head `2279d18189fcd6cdb2b38aca53b877434d41c913`, non-force synchronized onto #248 exact `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`. Its correlation-state regression no longer creates uncovered assertion-internal failure regions while still proving local preflight retirement and ambiguous-write retention. Its 141 Python contracts, full Rust gates, and CI-equivalent pinned-nightly 100% production coverage pass; hosted exact-head checks are queued and ordered parent integration remains required. -- PRs #250 through #255 remain Draft and are non-force synchronized in order at exact heads `cbddf507ac41080ee65230a8d6047dd8d06fd719`, `99e2eb946e7ebbffa68f65a00d25243a2cf4242a`, `881a599fb3a920b6bfd4f0a276f3cf24a61d8194`, `5e2b17c7a8d1953bb06a41e0296f801f0d015a9a`, `a4841016b94cb18e917d250a9ca9149af54ceef0`, and `f8edec38cf8ab7fde22b8d1de9305728c1a2f25b`. They preserve typed session lifecycle, operational teardown, transport-close observation, and typed teardown-transport binding without promoting frame writes, protocol acknowledgement, or a local close observation to completed browser-process teardown. Each final tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; hosted exact-head checks and ordered parent integration remain required. +- PRs #250 through #257 remain Draft and are non-force synchronized in order through exact heads #255 `f8edec38cf8ab7fde22b8d1de9305728c1a2f25b`, #256 `bd1f5ac60a76d2edb35e63095d406e53bc43931f`, and #257 `ac73abfe7edd5786a7eb3eaab1a8c773093be7d3`. The stack preserves typed session lifecycle, teardown evidence, transport binding, inert pointer-click serialization, and bounded frame send without promoting a frame write or close observation to browser-action or process-teardown completion. Each final tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; #257 also passed the exact focused retry after one macOS fixture teardown race. Hosted exact-head checks and ordered parent integration remain required. - PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #95 is Draft at exact head `97aa0f2e340ee6fd920d0418f97af276b190554f`, stacked on #93 exact `0664f0452cb329cd692cce7f61f9001652abfda2`. Only `Decision::Allow` creates policy-authorized value; other decisions fail closed, and registry-owned current authority returns `NotAdmitted` after document advance removes the node. The slice performs no browser I/O or postcondition proof. Its 142 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - PR #96 is Draft at exact head `b7ba8dd1433410cee43084a73e31816da841b2a2`, stacked on #95 exact `97aa0f2e340ee6fd920d0418f97af276b190554f`. Registry-owned node authority is revalidated before one adapter callback, and the callback is never invoked after admission is removed. Adapter completion remains separate from postcondition proof. Its 143 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. @@ -109,6 +109,8 @@ The following representative slices were re-fetched from GitHub for this snapsho | #253 | Draft | `881a599fb3a920b6bfd4f0a276f3cf24a61d8194` | `5e2b17c7a8d1953bb06a41e0296f801f0d015a9a` | | #254 | Draft | `5e2b17c7a8d1953bb06a41e0296f801f0d015a9a` | `a4841016b94cb18e917d250a9ca9149af54ceef0` | | #255 | Draft | `a4841016b94cb18e917d250a9ca9149af54ceef0` | `f8edec38cf8ab7fde22b8d1de9305728c1a2f25b` | +| #256 | Draft | `f8edec38cf8ab7fde22b8d1de9305728c1a2f25b` | `bd1f5ac60a76d2edb35e63095d406e53bc43931f` | +| #257 | Draft | `bd1f5ac60a76d2edb35e63095d406e53bc43931f` | `ac73abfe7edd5786a7eb3eaab1a8c773093be7d3` | | #93 | Draft | `802ec806cdd4560eab48c484f435766ecabda353` | `0664f0452cb329cd692cce7f61f9001652abfda2` | | #95 | Draft | `0664f0452cb329cd692cce7f61f9001652abfda2` | `97aa0f2e340ee6fd920d0418f97af276b190554f` | | #96 | Draft | `97aa0f2e340ee6fd920d0418f97af276b190554f` | `b7ba8dd1433410cee43084a73e31816da841b2a2` | From cdd1adf76aeee9c8d26914592a42b0e581b978b0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 13:03:55 +0900 Subject: [PATCH 121/250] docs: refresh concurrent delivery evidence Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 13 +++++++------ tests/test_gap_snapshot_inventory_consistency.py | 8 ++++---- 2 files changed, 11 insertions(+), 10 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 79c544dec..3bc40db9f 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,15 +6,16 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T03:59:27Z`. +Observed at (UTC): `2026-09-05T04:01:01Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. -- Full live search returns **124 open pull requests: 13 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PR #247 merged only into its unprotected feature parent, and #248 became Ready after adopting that exact parent head; queue movement is not protected-main delivery. -- Ready roots are #37 `fa34a696e4ed9b2529a65a7d6a45ac8b72ecefb3`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Full live search returns **125 open pull requests: 14 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PR #290 is the newly opened Ready workflow-admission child of #245; queue movement is not protected-main delivery. +- Ready roots are #37 `fa34a696e4ed9b2529a65a7d6a45ac8b72ecefb3`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `e522826b654bfd4637307e1766b426501cfcbcc3`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass. Its Ready transition materialized repository-native CI `33930234387`, which remains queued, but did not materialize fresh central required-workflow runs: the only exact-head Security Scan `33924016851`, SAST Semgrep `33924016903`, and CodeQL PR `33924016883` runs came from the earlier Draft event and were cancelled. Missing current lifecycle evidence and the absent eligible approval remain merge blockers; toggling Draft or creating a no-op commit is not an acceptable substitute. -- Issue #279 owns the remaining documentation-CI partitioning gap. PR #287 is Ready at exact head `af83c40dd2990a03064a92ca75430a9cc400f098` on current protected main; it is the workflow-independent classifier foundation, changes no `.github/**` path, and is the prerequisite for an authorized workflow owner. Its predecessor failed its own release-record contract; the current head adds the missing rename/copy similarity-to-blob-identity record, and its focused and full local suites plus exact 100% Rust coverage pass. Hosted exact-head checks remain queued and no eligible approval exists. PR #282 is Draft at exact head `b54a5856d8201911f05d69622f0d5594a371adf0` on current protected main; its trusted protected-base classifier successor requires exact base/head raw evidence, binds Git rename/copy similarity to blob identity, and retains fail-closed path and instruction-authority rules. Local checks do not substitute for its skipped draft jobs or current-head hosted evidence. +- Issue #279 owns the remaining documentation-CI partitioning gap. PR #287 is Ready at exact head `af83c40dd2990a03064a92ca75430a9cc400f098` on current protected main; it is the workflow-independent classifier foundation, changes no `.github/**` path, and is the prerequisite for an authorized workflow owner. Its predecessor failed its own release-record contract; the current head binds Git rename/copy similarity to blob identity, and its focused and full local suites plus exact 100% Rust coverage pass. Hosted exact-head checks remain queued and no eligible approval exists. PR #282 is Draft at externally advanced exact head `b64e0708584beff3fb54acf226cb3e667773e473` on current protected main; its new hosted jobs remain queued or skipped under the Draft policy, so predecessor local evidence is not transferred. +- PR #290 is Ready at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2` on #245 exact `a769f484e2c110e0523b3b28cd21573f43867562`. It scopes MV3 pull-request concurrency and draft admission, but its newly queued hosted Rust, pinned-Chromium, and coverage checks remain non-passing evidence until terminal. - PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`, non-force stacked on #282 exact `b54a5856d8201911f05d69622f0d5594a371adf0`. Its exact parent compare remains one prose-only doctoring canary; draft-hosted jobs are skipped, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. - PR #288 is Draft at exact head `39e36256651f62940ec3ca6149067f0cfcb2285a` on current protected main. It stages #70's controlled Agent Task product, test, and documentation delta without any `.github/**` mutation; its workflow-owned sandbox-helper assertion was removed after it made the workflow-free branch's full Python contract suite fail, and all 172 Python contracts now pass locally. Hosted CI and MV3 jobs remain skipped while Draft, and #212 still owns authorized workflow activation plus sandboxed pinned-Chromium execution evidence. - Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0` on #259 exact base `b089c5f584e2c4605a40d2173b3c506e18`. PR #261 is Draft at exact head `95f7548bf07cbba76ab8b40577a11d1b6c99acb5`, stacked on exact #260. Repair PR #277 is Draft at exact head `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`, stacked on exact #261 and preserving typed `SessionSubscribe` correlation. Its hosted Rust and production-coverage jobs were cancelled, so stale conflicting #262 is not superseded and remains dependency-blocked until #277 reaches terminal GREEN on the unchanged head. @@ -31,7 +32,7 @@ Observed at (UTC): `2026-09-05T03:59:27Z`. - PR #271 is Draft at exact head `802ec806cdd4560eab48c484f435766ecabda353`, non-force synchronized onto #270 exact `191a14535219ea8033777fa4c970efb281b62418`. It admits only the exact typed observation response, treats unequal text as `PostconditionMismatch`, and retains no page-controlled or expected text in public evidence or diagnostics. Its test-first documentation contract, all 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #195 is Draft at exact head `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its loopback regressions hold the accepted peer through opening-write timeout cleanup and locally revoked-stream classification, removing macOS close races without weakening production failures. The original affected test passed 50 consecutive focused regression passes, followed by 139 Python contracts, full Rust gates, and exact 100% local production coverage; fresh hosted exact-head checks and prerequisite integration remain required. - PR #242 is Draft at exact head `55fef0c3fae1724eddada53e52c4a0311f509aa3`, stacked on #195 exact `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its zero-deadline regression holds the accepted peer until validation completes, so macOS cannot race socket teardown against the intended invalid-input result. Its 139 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. -- PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 is Ready at exact head `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb` on that merged #247 head. Its 141 Python contracts, full Rust gates, and CI-equivalent pinned-nightly 100% production coverage pass; hosted exact-head checks are queued. +- PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 externally advanced to Ready exact head `e522826b654bfd4637307e1766b426501cfcbcc3` after adding a release-record documentation contract. The prior local full-suite evidence applies only to predecessor `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`; new hosted checks are queued and must prove the current head independently. - PR #249 is Draft at exact head `2279d18189fcd6cdb2b38aca53b877434d41c913`, non-force synchronized onto #248 exact `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`. Its correlation-state regression no longer creates uncovered assertion-internal failure regions while still proving local preflight retirement and ambiguous-write retention. Its 141 Python contracts, full Rust gates, and CI-equivalent pinned-nightly 100% production coverage pass; hosted exact-head checks are queued and ordered parent integration remains required. - PRs #250 through #257 remain Draft and are non-force synchronized in order through exact heads #255 `f8edec38cf8ab7fde22b8d1de9305728c1a2f25b`, #256 `bd1f5ac60a76d2edb35e63095d406e53bc43931f`, and #257 `ac73abfe7edd5786a7eb3eaab1a8c773093be7d3`. The stack preserves typed session lifecycle, teardown evidence, transport binding, inert pointer-click serialization, and bounded frame send without promoting a frame write or close observation to browser-action or process-teardown completion. Each final tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; #257 also passed the exact focused retry after one macOS fixture teardown race. Hosted exact-head checks and ordered parent integration remain required. - PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. @@ -101,7 +102,7 @@ The following representative slices were re-fetched from GitHub for this snapsho | #152 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `81407a0e5189a413d1be0963fea90a0c2f254ce1` | | #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | `48eb2d23009c1c804520dd5efcd0d4d072aacef1` | | #242 | Draft | `48eb2d23009c1c804520dd5efcd0d4d072aacef1` | `55fef0c3fae1724eddada53e52c4a0311f509aa3` | -| #248 | Ready | `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` | `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb` | +| #248 | Ready | `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` | `e522826b654bfd4637307e1766b426501cfcbcc3` | | #249 | Draft | `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb` | `2279d18189fcd6cdb2b38aca53b877434d41c913` | | #250 | Draft | `2279d18189fcd6cdb2b38aca53b877434d41c913` | `cbddf507ac41080ee65230a8d6047dd8d06fd719` | | #251 | Draft | `cbddf507ac41080ee65230a8d6047dd8d06fd719` | `99e2eb946e7ebbffa68f65a00d25243a2cf4242a` | diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index b8d71ce46..73a4a26eb 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -26,8 +26,8 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "## Observed snapshot: 2026-08-29", 1 )[0] for marker in ( - "124 open pull requests", - "13 Ready/non-draft", + "125 open pull requests", + "14 Ready/non-draft", "111 Draft", "13 open non-PR issues", "87c4daa1830bac5a5228b6036752ad5633232085", @@ -35,7 +35,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `fa34a696e4ed9b2529a65a7d6a45ac8b72ecefb3`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", + "Ready roots are #37 `fa34a696e4ed9b2529a65a7d6a45ac8b72ecefb3`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `e522826b654bfd4637307e1766b426501cfcbcc3`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`", "PR #238's moving exact head is intentionally omitted", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", @@ -46,7 +46,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "DDD/MCP repair #272 is Ready at exact head `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`", "PR #229 is Ready at exact head `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`", "PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385`", - "PR #282 is Draft at exact head `b54a5856d8201911f05d69622f0d5594a371adf0`", + "PR #282 is Draft at externally advanced exact head `b64e0708584beff3fb54acf226cb3e667773e473`", "PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`", "PR #288 is Draft at exact head `39e36256651f62940ec3ca6149067f0cfcb2285a`", "PR #269 is Draft at exact head `7854394266d3f292e779193c01413a34f6798d7c`", From 04ce6a56459d423954ae228bf9ff3d193edcfd24 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 13:06:02 +0900 Subject: [PATCH 122/250] docs: bind latest correlation head Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 8 ++++---- tests/test_gap_snapshot_inventory_consistency.py | 2 +- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 3bc40db9f..341381b9a 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,11 +6,11 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T04:01:01Z`. +Observed at (UTC): `2026-09-05T04:05:00Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 14 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PR #290 is the newly opened Ready workflow-admission child of #245; queue movement is not protected-main delivery. -- Ready roots are #37 `fa34a696e4ed9b2529a65a7d6a45ac8b72ecefb3`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `e522826b654bfd4637307e1766b426501cfcbcc3`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Ready roots are #37 `fa34a696e4ed9b2529a65a7d6a45ac8b72ecefb3`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass. Its Ready transition materialized repository-native CI `33930234387`, which remains queued, but did not materialize fresh central required-workflow runs: the only exact-head Security Scan `33924016851`, SAST Semgrep `33924016903`, and CodeQL PR `33924016883` runs came from the earlier Draft event and were cancelled. Missing current lifecycle evidence and the absent eligible approval remain merge blockers; toggling Draft or creating a no-op commit is not an acceptable substitute. @@ -32,7 +32,7 @@ Observed at (UTC): `2026-09-05T04:01:01Z`. - PR #271 is Draft at exact head `802ec806cdd4560eab48c484f435766ecabda353`, non-force synchronized onto #270 exact `191a14535219ea8033777fa4c970efb281b62418`. It admits only the exact typed observation response, treats unequal text as `PostconditionMismatch`, and retains no page-controlled or expected text in public evidence or diagnostics. Its test-first documentation contract, all 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #195 is Draft at exact head `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its loopback regressions hold the accepted peer through opening-write timeout cleanup and locally revoked-stream classification, removing macOS close races without weakening production failures. The original affected test passed 50 consecutive focused regression passes, followed by 139 Python contracts, full Rust gates, and exact 100% local production coverage; fresh hosted exact-head checks and prerequisite integration remain required. - PR #242 is Draft at exact head `55fef0c3fae1724eddada53e52c4a0311f509aa3`, stacked on #195 exact `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its zero-deadline regression holds the accepted peer until validation completes, so macOS cannot race socket teardown against the intended invalid-input result. Its 139 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. -- PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 externally advanced to Ready exact head `e522826b654bfd4637307e1766b426501cfcbcc3` after adding a release-record documentation contract. The prior local full-suite evidence applies only to predecessor `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`; new hosted checks are queued and must prove the current head independently. +- PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 externally advanced to Ready exact head `7d6db16b2ead201fcec320854923f90d3ad0d8bc` after scoping its BiDi release contract to the owned record. The prior local full-suite evidence applies only to predecessor `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`; new hosted checks are queued and must prove the current head independently. - PR #249 is Draft at exact head `2279d18189fcd6cdb2b38aca53b877434d41c913`, non-force synchronized onto #248 exact `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`. Its correlation-state regression no longer creates uncovered assertion-internal failure regions while still proving local preflight retirement and ambiguous-write retention. Its 141 Python contracts, full Rust gates, and CI-equivalent pinned-nightly 100% production coverage pass; hosted exact-head checks are queued and ordered parent integration remains required. - PRs #250 through #257 remain Draft and are non-force synchronized in order through exact heads #255 `f8edec38cf8ab7fde22b8d1de9305728c1a2f25b`, #256 `bd1f5ac60a76d2edb35e63095d406e53bc43931f`, and #257 `ac73abfe7edd5786a7eb3eaab1a8c773093be7d3`. The stack preserves typed session lifecycle, teardown evidence, transport binding, inert pointer-click serialization, and bounded frame send without promoting a frame write or close observation to browser-action or process-teardown completion. Each final tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; #257 also passed the exact focused retry after one macOS fixture teardown race. Hosted exact-head checks and ordered parent integration remain required. - PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. @@ -102,7 +102,7 @@ The following representative slices were re-fetched from GitHub for this snapsho | #152 | Ready | `542ca1e9c0a863595b8b6697790005d2471f5413` | `81407a0e5189a413d1be0963fea90a0c2f254ce1` | | #195 | Draft | `6922dd98779e8f8aad132a3b1f563d7ba6e6d070` | `48eb2d23009c1c804520dd5efcd0d4d072aacef1` | | #242 | Draft | `48eb2d23009c1c804520dd5efcd0d4d072aacef1` | `55fef0c3fae1724eddada53e52c4a0311f509aa3` | -| #248 | Ready | `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` | `e522826b654bfd4637307e1766b426501cfcbcc3` | +| #248 | Ready | `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` | `7d6db16b2ead201fcec320854923f90d3ad0d8bc` | | #249 | Draft | `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb` | `2279d18189fcd6cdb2b38aca53b877434d41c913` | | #250 | Draft | `2279d18189fcd6cdb2b38aca53b877434d41c913` | `cbddf507ac41080ee65230a8d6047dd8d06fd719` | | #251 | Draft | `cbddf507ac41080ee65230a8d6047dd8d06fd719` | `99e2eb946e7ebbffa68f65a00d25243a2cf4242a` | diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 73a4a26eb..b211ab521 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -35,7 +35,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `fa34a696e4ed9b2529a65a7d6a45ac8b72ecefb3`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `e522826b654bfd4637307e1766b426501cfcbcc3`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`", + "Ready roots are #37 `fa34a696e4ed9b2529a65a7d6a45ac8b72ecefb3`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`", "PR #238's moving exact head is intentionally omitted", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", From f281ffb90edb3f205fa01ef331ccca34c6eb89de Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 13:17:05 +0900 Subject: [PATCH 123/250] docs: record navigation stack restacks Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 5 +++-- tests/test_gap_snapshot_inventory_consistency.py | 8 +++++--- 2 files changed, 8 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 341381b9a..7e9026859 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,7 +6,7 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T04:05:00Z`. +Observed at (UTC): `2026-09-05T04:16:00Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 14 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PR #290 is the newly opened Ready workflow-admission child of #245; queue movement is not protected-main delivery. @@ -18,7 +18,7 @@ Observed at (UTC): `2026-09-05T04:05:00Z`. - PR #290 is Ready at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2` on #245 exact `a769f484e2c110e0523b3b28cd21573f43867562`. It scopes MV3 pull-request concurrency and draft admission, but its newly queued hosted Rust, pinned-Chromium, and coverage checks remain non-passing evidence until terminal. - PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`, non-force stacked on #282 exact `b54a5856d8201911f05d69622f0d5594a371adf0`. Its exact parent compare remains one prose-only doctoring canary; draft-hosted jobs are skipped, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. - PR #288 is Draft at exact head `39e36256651f62940ec3ca6149067f0cfcb2285a` on current protected main. It stages #70's controlled Agent Task product, test, and documentation delta without any `.github/**` mutation; its workflow-owned sandbox-helper assertion was removed after it made the workflow-free branch's full Python contract suite fail, and all 172 Python contracts now pass locally. Hosted CI and MV3 jobs remain skipped while Draft, and #212 still owns authorized workflow activation plus sandboxed pinned-Chromium execution evidence. -- Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0` on #259 exact base `b089c5f584e2c4605a40d2173b3c506e18`. PR #261 is Draft at exact head `95f7548bf07cbba76ab8b40577a11d1b6c99acb5`, stacked on exact #260. Repair PR #277 is Draft at exact head `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`, stacked on exact #261 and preserving typed `SessionSubscribe` correlation. Its hosted Rust and production-coverage jobs were cancelled, so stale conflicting #262 is not superseded and remains dependency-blocked until #277 reaches terminal GREEN on the unchanged head. +- Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `9b6c6038de8c1ed7872b513f113c6392987a8217` on #259 exact base `3a36bd2aaacc4051a7a2b92ebe114307034481eb`. PR #261 is Draft at exact head `7388e6a893b34e87ba965f061aaa26bf4d155b61`, stacked on exact #260. Repair PR #277 is Draft at exact head `16ab6d67fe668306224af0c17c4e7b3d423f2c97`, stacked on exact #261 and preserving typed `SessionSubscribe` correlation. Each restacked tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. Fresh hosted checks remain non-terminal, so stale conflicting #262 is not superseded and remains dependency-blocked until #277 reaches terminal GREEN on the unchanged head. - Stacked PRs #178 and #85 were repaired without force pushes at exact heads `640e594dbc0a64f251a0f28b8e80943f53337e40` and `c9adea680d6186f1842a280e248ce55da4f1305b`. Parent-relative deltas now preserve the current MV3 diagnostic and extension-authority contracts; local full suites and exact 100% coverage passed, while hosted exact-head acceptance remains independently required. - PR #70 is Draft at exact head `77eb0f2ee71783e06171784b7173c0b4cd530e61`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. Its focused Agent Task contract proves the pre-repair `--no-sandbox` launch as source RED and the branch removes that argument only from the Agent Task lane. Sandbox-enabled pinned-Chromium E2E and repository-wide GREEN remain unproven while its exact-head browser/CI/security runs are non-passing. - DDD/MCP repair #272 is Ready at exact head `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3` on current protected main. Its exact-head hosted checks remain queued and no eligible approval exists. Documentation child PR #273 is Draft at exact head `e5c8fcb66bf644dfa750bb1b40ba3d600cb7805a` on predecessor #272 head `fe124e447cad3f679e22337fb6fbdfd135ab3652`, so it must adopt the parent only after #272's current head completes its gates. Both remain active-PR evidence. @@ -35,6 +35,7 @@ Observed at (UTC): `2026-09-05T04:05:00Z`. - PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 externally advanced to Ready exact head `7d6db16b2ead201fcec320854923f90d3ad0d8bc` after scoping its BiDi release contract to the owned record. The prior local full-suite evidence applies only to predecessor `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`; new hosted checks are queued and must prove the current head independently. - PR #249 is Draft at exact head `2279d18189fcd6cdb2b38aca53b877434d41c913`, non-force synchronized onto #248 exact `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`. Its correlation-state regression no longer creates uncovered assertion-internal failure regions while still proving local preflight retirement and ambiguous-write retention. Its 141 Python contracts, full Rust gates, and CI-equivalent pinned-nightly 100% production coverage pass; hosted exact-head checks are queued and ordered parent integration remains required. - PRs #250 through #257 remain Draft and are non-force synchronized in order through exact heads #255 `f8edec38cf8ab7fde22b8d1de9305728c1a2f25b`, #256 `bd1f5ac60a76d2edb35e63095d406e53bc43931f`, and #257 `ac73abfe7edd5786a7eb3eaab1a8c773093be7d3`. The stack preserves typed session lifecycle, teardown evidence, transport binding, inert pointer-click serialization, and bounded frame send without promoting a frame write or close observation to browser-action or process-teardown completion. Each final tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; #257 also passed the exact focused retry after one macOS fixture teardown race. Hosted exact-head checks and ordered parent integration remain required. +- PR #258 is Draft at exact head `a61c717e525eb94f5a4aaa68d3bfdabc9152edfd` on exact #257, and PR #259 is Draft at exact head `3a36bd2aaacc4051a7a2b92ebe114307034481eb` on exact #258. Both non-force restacks passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; fresh hosted exact-head checks and ordered parent integration remain required. - PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #95 is Draft at exact head `97aa0f2e340ee6fd920d0418f97af276b190554f`, stacked on #93 exact `0664f0452cb329cd692cce7f61f9001652abfda2`. Only `Decision::Allow` creates policy-authorized value; other decisions fail closed, and registry-owned current authority returns `NotAdmitted` after document advance removes the node. The slice performs no browser I/O or postcondition proof. Its 142 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - PR #96 is Draft at exact head `b7ba8dd1433410cee43084a73e31816da841b2a2`, stacked on #95 exact `97aa0f2e340ee6fd920d0418f97af276b190554f`. Registry-owned node authority is revalidated before one adapter callback, and the callback is never invoked after admission is removed. Adapter completion remains separate from postcondition proof. Its 143 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index b211ab521..c8ddd229b 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -39,9 +39,11 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #238's moving exact head is intentionally omitted", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", - "PR #260 is Draft at exact head `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`", - "PR #261 is Draft at exact head `95f7548bf07cbba76ab8b40577a11d1b6c99acb5`", - "PR #277 is Draft at exact head `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1`", + "PR #260 is Draft at exact head `9b6c6038de8c1ed7872b513f113c6392987a8217`", + "PR #258 is Draft at exact head `a61c717e525eb94f5a4aaa68d3bfdabc9152edfd`", + "PR #259 is Draft at exact head `3a36bd2aaacc4051a7a2b92ebe114307034481eb`", + "PR #261 is Draft at exact head `7388e6a893b34e87ba965f061aaa26bf4d155b61`", + "Repair PR #277 is Draft at exact head `16ab6d67fe668306224af0c17c4e7b3d423f2c97`", "PR #70 is Draft at exact head `77eb0f2ee71783e06171784b7173c0b4cd530e61`", "DDD/MCP repair #272 is Ready at exact head `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`", "PR #229 is Ready at exact head `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`", From 0136613e9abaf887a884f5bd63cb65a3ec89b1a3 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 13:28:41 +0900 Subject: [PATCH 124/250] docs: record session stack restacks Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 6 +++--- tests/test_gap_snapshot_inventory_consistency.py | 5 +++++ 2 files changed, 8 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 7e9026859..86e25716f 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,7 +6,7 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T04:16:00Z`. +Observed at (UTC): `2026-09-05T04:31:00Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 14 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PR #290 is the newly opened Ready workflow-admission child of #245; queue movement is not protected-main delivery. @@ -33,8 +33,8 @@ Observed at (UTC): `2026-09-05T04:16:00Z`. - PR #195 is Draft at exact head `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its loopback regressions hold the accepted peer through opening-write timeout cleanup and locally revoked-stream classification, removing macOS close races without weakening production failures. The original affected test passed 50 consecutive focused regression passes, followed by 139 Python contracts, full Rust gates, and exact 100% local production coverage; fresh hosted exact-head checks and prerequisite integration remain required. - PR #242 is Draft at exact head `55fef0c3fae1724eddada53e52c4a0311f509aa3`, stacked on #195 exact `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its zero-deadline regression holds the accepted peer until validation completes, so macOS cannot race socket teardown against the intended invalid-input result. Its 139 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 externally advanced to Ready exact head `7d6db16b2ead201fcec320854923f90d3ad0d8bc` after scoping its BiDi release contract to the owned record. The prior local full-suite evidence applies only to predecessor `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`; new hosted checks are queued and must prove the current head independently. -- PR #249 is Draft at exact head `2279d18189fcd6cdb2b38aca53b877434d41c913`, non-force synchronized onto #248 exact `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`. Its correlation-state regression no longer creates uncovered assertion-internal failure regions while still proving local preflight retirement and ambiguous-write retention. Its 141 Python contracts, full Rust gates, and CI-equivalent pinned-nightly 100% production coverage pass; hosted exact-head checks are queued and ordered parent integration remains required. -- PRs #250 through #257 remain Draft and are non-force synchronized in order through exact heads #255 `f8edec38cf8ab7fde22b8d1de9305728c1a2f25b`, #256 `bd1f5ac60a76d2edb35e63095d406e53bc43931f`, and #257 `ac73abfe7edd5786a7eb3eaab1a8c773093be7d3`. The stack preserves typed session lifecycle, teardown evidence, transport binding, inert pointer-click serialization, and bounded frame send without promoting a frame write or close observation to browser-action or process-teardown completion. Each final tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; #257 also passed the exact focused retry after one macOS fixture teardown race. Hosted exact-head checks and ordered parent integration remain required. +- PR #249 is Draft at exact head `017d6e816f5a86544a63821b3ceaba94d5f17f44`, non-force synchronized onto #248 exact `7d6db16b2ead201fcec320854923f90d3ad0d8bc`. Its correlation-state regression no longer creates uncovered assertion-internal failure regions while still proving local preflight retirement and ambiguous-write retention. The current parent and child trees passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; hosted exact-head checks are queued and ordered parent integration remains required. +- PRs #250 through #257 remain Draft. The synchronized prefix now reaches #250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`, #251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`, #252 `2015259529ada99af836989079cc85a15779a2d8`, and #253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`; #254 and later still name predecessor parents. Each updated tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. #250's first coverage run hit the known macOS socket-timeout cleanup race, then the exact focused retry and complete coverage rerun passed. Hosted exact-head checks and ordered parent integration remain required. - PR #258 is Draft at exact head `a61c717e525eb94f5a4aaa68d3bfdabc9152edfd` on exact #257, and PR #259 is Draft at exact head `3a36bd2aaacc4051a7a2b92ebe114307034481eb` on exact #258. Both non-force restacks passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; fresh hosted exact-head checks and ordered parent integration remain required. - PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #95 is Draft at exact head `97aa0f2e340ee6fd920d0418f97af276b190554f`, stacked on #93 exact `0664f0452cb329cd692cce7f61f9001652abfda2`. Only `Decision::Allow` creates policy-authorized value; other decisions fail closed, and registry-owned current authority returns `NotAdmitted` after document advance removes the node. The slice performs no browser I/O or postcondition proof. Its 142 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index c8ddd229b..969f6c84a 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -37,6 +37,11 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", "Ready roots are #37 `fa34a696e4ed9b2529a65a7d6a45ac8b72ecefb3`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`", "PR #238's moving exact head is intentionally omitted", + "PR #249 is Draft at exact head `017d6e816f5a86544a63821b3ceaba94d5f17f44`", + "#250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`", + "#251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`", + "#252 `2015259529ada99af836989079cc85a15779a2d8`", + "#253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", "PR #260 is Draft at exact head `9b6c6038de8c1ed7872b513f113c6392987a8217`", From a3697c54a0bccb13c759b97b85203d317c8d201f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 13:37:34 +0900 Subject: [PATCH 125/250] docs: record completed pointer restack Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 6 +++--- tests/test_gap_snapshot_inventory_consistency.py | 4 ++++ 2 files changed, 7 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 86e25716f..747351ff9 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,7 +6,7 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T04:31:00Z`. +Observed at (UTC): `2026-09-05T04:41:00Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 14 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PR #290 is the newly opened Ready workflow-admission child of #245; queue movement is not protected-main delivery. @@ -34,8 +34,8 @@ Observed at (UTC): `2026-09-05T04:31:00Z`. - PR #242 is Draft at exact head `55fef0c3fae1724eddada53e52c4a0311f509aa3`, stacked on #195 exact `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its zero-deadline regression holds the accepted peer until validation completes, so macOS cannot race socket teardown against the intended invalid-input result. Its 139 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 externally advanced to Ready exact head `7d6db16b2ead201fcec320854923f90d3ad0d8bc` after scoping its BiDi release contract to the owned record. The prior local full-suite evidence applies only to predecessor `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`; new hosted checks are queued and must prove the current head independently. - PR #249 is Draft at exact head `017d6e816f5a86544a63821b3ceaba94d5f17f44`, non-force synchronized onto #248 exact `7d6db16b2ead201fcec320854923f90d3ad0d8bc`. Its correlation-state regression no longer creates uncovered assertion-internal failure regions while still proving local preflight retirement and ambiguous-write retention. The current parent and child trees passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; hosted exact-head checks are queued and ordered parent integration remains required. -- PRs #250 through #257 remain Draft. The synchronized prefix now reaches #250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`, #251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`, #252 `2015259529ada99af836989079cc85a15779a2d8`, and #253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`; #254 and later still name predecessor parents. Each updated tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. #250's first coverage run hit the known macOS socket-timeout cleanup race, then the exact focused retry and complete coverage rerun passed. Hosted exact-head checks and ordered parent integration remain required. -- PR #258 is Draft at exact head `a61c717e525eb94f5a4aaa68d3bfdabc9152edfd` on exact #257, and PR #259 is Draft at exact head `3a36bd2aaacc4051a7a2b92ebe114307034481eb` on exact #258. Both non-force restacks passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; fresh hosted exact-head checks and ordered parent integration remain required. +- PRs #250 through #257 remain Draft and are again synchronized in order through exact heads #250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`, #251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`, #252 `2015259529ada99af836989079cc85a15779a2d8`, #253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`, #254 `cbaf50dcc97753cc73135497ea8225e8b18de190`, #255 `a13de5f9321e72c1867974eb7a43230f031e58df`, #256 `9f2e6f29be46371762e3031a97c1cac04720694f`, and #257 `ea2b5b78868917219c46f1304558b92490a7f6fe`. Each updated tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. #250 and #257 each had one known macOS socket-observation race; their exact focused retries and complete coverage reruns passed. Hosted exact-head checks and ordered parent integration remain required. +- PR #258 is Draft at exact head `a61c717e525eb94f5a4aaa68d3bfdabc9152edfd` and now names predecessor #257 `ac73abfe7edd5786a7eb3eaab1a8c773093be7d3`; PR #259 is Draft at exact head `3a36bd2aaacc4051a7a2b92ebe114307034481eb` and remains on #258. Their prior local evidence remains head-bound, but the changed #257 parent makes the downstream stack stale until it is non-force synchronized again. - PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #95 is Draft at exact head `97aa0f2e340ee6fd920d0418f97af276b190554f`, stacked on #93 exact `0664f0452cb329cd692cce7f61f9001652abfda2`. Only `Decision::Allow` creates policy-authorized value; other decisions fail closed, and registry-owned current authority returns `NotAdmitted` after document advance removes the node. The slice performs no browser I/O or postcondition proof. Its 142 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - PR #96 is Draft at exact head `b7ba8dd1433410cee43084a73e31816da841b2a2`, stacked on #95 exact `97aa0f2e340ee6fd920d0418f97af276b190554f`. Registry-owned node authority is revalidated before one adapter callback, and the callback is never invoked after admission is removed. Adapter completion remains separate from postcondition proof. Its 143 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 969f6c84a..8acaebe1c 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -42,6 +42,10 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "#251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`", "#252 `2015259529ada99af836989079cc85a15779a2d8`", "#253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`", + "#254 `cbaf50dcc97753cc73135497ea8225e8b18de190`", + "#255 `a13de5f9321e72c1867974eb7a43230f031e58df`", + "#256 `9f2e6f29be46371762e3031a97c1cac04720694f`", + "#257 `ea2b5b78868917219c46f1304558b92490a7f6fe`", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", "PR #260 is Draft at exact head `9b6c6038de8c1ed7872b513f113c6392987a8217`", From 574213b0af88363340a718b3e9a1d3927754e28d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 13:47:27 +0900 Subject: [PATCH 126/250] docs: record downstream stack repair Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 6 +++--- tests/test_gap_snapshot_inventory_consistency.py | 10 +++++----- 2 files changed, 8 insertions(+), 8 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 747351ff9..e9eb31f8f 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,7 +6,7 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T04:41:00Z`. +Observed at (UTC): `2026-09-05T04:54:00Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 14 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PR #290 is the newly opened Ready workflow-admission child of #245; queue movement is not protected-main delivery. @@ -18,7 +18,7 @@ Observed at (UTC): `2026-09-05T04:41:00Z`. - PR #290 is Ready at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2` on #245 exact `a769f484e2c110e0523b3b28cd21573f43867562`. It scopes MV3 pull-request concurrency and draft admission, but its newly queued hosted Rust, pinned-Chromium, and coverage checks remain non-passing evidence until terminal. - PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`, non-force stacked on #282 exact `b54a5856d8201911f05d69622f0d5594a371adf0`. Its exact parent compare remains one prose-only doctoring canary; draft-hosted jobs are skipped, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. - PR #288 is Draft at exact head `39e36256651f62940ec3ca6149067f0cfcb2285a` on current protected main. It stages #70's controlled Agent Task product, test, and documentation delta without any `.github/**` mutation; its workflow-owned sandbox-helper assertion was removed after it made the workflow-free branch's full Python contract suite fail, and all 172 Python contracts now pass locally. Hosted CI and MV3 jobs remain skipped while Draft, and #212 still owns authorized workflow activation plus sandboxed pinned-Chromium execution evidence. -- Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `9b6c6038de8c1ed7872b513f113c6392987a8217` on #259 exact base `3a36bd2aaacc4051a7a2b92ebe114307034481eb`. PR #261 is Draft at exact head `7388e6a893b34e87ba965f061aaa26bf4d155b61`, stacked on exact #260. Repair PR #277 is Draft at exact head `16ab6d67fe668306224af0c17c4e7b3d423f2c97`, stacked on exact #261 and preserving typed `SessionSubscribe` correlation. Each restacked tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. Fresh hosted checks remain non-terminal, so stale conflicting #262 is not superseded and remains dependency-blocked until #277 reaches terminal GREEN on the unchanged head. +- Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `3a651967c421f77088fe25e86a63faae295390b3` on #259 exact base `e1105ddf86f6c79443af8b4d306b9d34cb703c17`. PR #261 is Draft at exact head `323ac9e147691e9f6572711f5a748e13f1036624`, stacked on exact #260. Repair PR #277 is Draft at exact head `01038ba71fb276426cc67f90a91a3c431e194db5`, stacked on exact #261 and preserving typed `SessionSubscribe` correlation. Each restacked tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. Fresh hosted checks remain non-terminal, so stale conflicting #262 is not superseded and remains dependency-blocked until #277 reaches terminal GREEN on the unchanged head. - Stacked PRs #178 and #85 were repaired without force pushes at exact heads `640e594dbc0a64f251a0f28b8e80943f53337e40` and `c9adea680d6186f1842a280e248ce55da4f1305b`. Parent-relative deltas now preserve the current MV3 diagnostic and extension-authority contracts; local full suites and exact 100% coverage passed, while hosted exact-head acceptance remains independently required. - PR #70 is Draft at exact head `77eb0f2ee71783e06171784b7173c0b4cd530e61`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. Its focused Agent Task contract proves the pre-repair `--no-sandbox` launch as source RED and the branch removes that argument only from the Agent Task lane. Sandbox-enabled pinned-Chromium E2E and repository-wide GREEN remain unproven while its exact-head browser/CI/security runs are non-passing. - DDD/MCP repair #272 is Ready at exact head `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3` on current protected main. Its exact-head hosted checks remain queued and no eligible approval exists. Documentation child PR #273 is Draft at exact head `e5c8fcb66bf644dfa750bb1b40ba3d600cb7805a` on predecessor #272 head `fe124e447cad3f679e22337fb6fbdfd135ab3652`, so it must adopt the parent only after #272's current head completes its gates. Both remain active-PR evidence. @@ -35,7 +35,7 @@ Observed at (UTC): `2026-09-05T04:41:00Z`. - PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 externally advanced to Ready exact head `7d6db16b2ead201fcec320854923f90d3ad0d8bc` after scoping its BiDi release contract to the owned record. The prior local full-suite evidence applies only to predecessor `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`; new hosted checks are queued and must prove the current head independently. - PR #249 is Draft at exact head `017d6e816f5a86544a63821b3ceaba94d5f17f44`, non-force synchronized onto #248 exact `7d6db16b2ead201fcec320854923f90d3ad0d8bc`. Its correlation-state regression no longer creates uncovered assertion-internal failure regions while still proving local preflight retirement and ambiguous-write retention. The current parent and child trees passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; hosted exact-head checks are queued and ordered parent integration remains required. - PRs #250 through #257 remain Draft and are again synchronized in order through exact heads #250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`, #251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`, #252 `2015259529ada99af836989079cc85a15779a2d8`, #253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`, #254 `cbaf50dcc97753cc73135497ea8225e8b18de190`, #255 `a13de5f9321e72c1867974eb7a43230f031e58df`, #256 `9f2e6f29be46371762e3031a97c1cac04720694f`, and #257 `ea2b5b78868917219c46f1304558b92490a7f6fe`. Each updated tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. #250 and #257 each had one known macOS socket-observation race; their exact focused retries and complete coverage reruns passed. Hosted exact-head checks and ordered parent integration remain required. -- PR #258 is Draft at exact head `a61c717e525eb94f5a4aaa68d3bfdabc9152edfd` and now names predecessor #257 `ac73abfe7edd5786a7eb3eaab1a8c773093be7d3`; PR #259 is Draft at exact head `3a36bd2aaacc4051a7a2b92ebe114307034481eb` and remains on #258. Their prior local evidence remains head-bound, but the changed #257 parent makes the downstream stack stale until it is non-force synchronized again. +- PR #258 is Draft at exact head `f2ceabb3ea50b1959e936503c50cae12f3e6e480` on exact #257, and PR #259 is Draft at exact head `e1105ddf86f6c79443af8b4d306b9d34cb703c17` on exact #258. Both final trees passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; fresh hosted exact-head checks and ordered parent integration remain required. - PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #95 is Draft at exact head `97aa0f2e340ee6fd920d0418f97af276b190554f`, stacked on #93 exact `0664f0452cb329cd692cce7f61f9001652abfda2`. Only `Decision::Allow` creates policy-authorized value; other decisions fail closed, and registry-owned current authority returns `NotAdmitted` after document advance removes the node. The slice performs no browser I/O or postcondition proof. Its 142 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - PR #96 is Draft at exact head `b7ba8dd1433410cee43084a73e31816da841b2a2`, stacked on #95 exact `97aa0f2e340ee6fd920d0418f97af276b190554f`. Registry-owned node authority is revalidated before one adapter callback, and the callback is never invoked after admission is removed. Adapter completion remains separate from postcondition proof. Its 143 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 8acaebe1c..ae071bc3b 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -48,11 +48,11 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "#257 `ea2b5b78868917219c46f1304558b92490a7f6fe`", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", - "PR #260 is Draft at exact head `9b6c6038de8c1ed7872b513f113c6392987a8217`", - "PR #258 is Draft at exact head `a61c717e525eb94f5a4aaa68d3bfdabc9152edfd`", - "PR #259 is Draft at exact head `3a36bd2aaacc4051a7a2b92ebe114307034481eb`", - "PR #261 is Draft at exact head `7388e6a893b34e87ba965f061aaa26bf4d155b61`", - "Repair PR #277 is Draft at exact head `16ab6d67fe668306224af0c17c4e7b3d423f2c97`", + "PR #260 is Draft at exact head `3a651967c421f77088fe25e86a63faae295390b3`", + "PR #258 is Draft at exact head `f2ceabb3ea50b1959e936503c50cae12f3e6e480`", + "PR #259 is Draft at exact head `e1105ddf86f6c79443af8b4d306b9d34cb703c17`", + "PR #261 is Draft at exact head `323ac9e147691e9f6572711f5a748e13f1036624`", + "Repair PR #277 is Draft at exact head `01038ba71fb276426cc67f90a91a3c431e194db5`", "PR #70 is Draft at exact head `77eb0f2ee71783e06171784b7173c0b4cd530e61`", "DDD/MCP repair #272 is Ready at exact head `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`", "PR #229 is Ready at exact head `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`", From fdbe548785f3d0114260069a8490bdff70fe6a4a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 13:52:42 +0900 Subject: [PATCH 127/250] docs: bind latest HTTP persistence head Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 6 +++--- tests/test_gap_snapshot_inventory_consistency.py | 2 +- tests/test_product_completion_gap_contract.py | 2 +- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e9eb31f8f..e79efbc49 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,11 +6,11 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T04:54:00Z`. +Observed at (UTC): `2026-09-05T05:02:00Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 14 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PR #290 is the newly opened Ready workflow-admission child of #245; queue movement is not protected-main delivery. -- Ready roots are #37 `fa34a696e4ed9b2529a65a7d6a45ac8b72ecefb3`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Ready roots are #37 `28721edcc67bb5379ffb11a259d746396ac7ae03`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass. Its Ready transition materialized repository-native CI `33930234387`, which remains queued, but did not materialize fresh central required-workflow runs: the only exact-head Security Scan `33924016851`, SAST Semgrep `33924016903`, and CodeQL PR `33924016883` runs came from the earlier Draft event and were cancelled. Missing current lifecycle evidence and the absent eligible approval remain merge blockers; toggling Draft or creating a no-op commit is not an acceptable substitute. @@ -26,7 +26,7 @@ Observed at (UTC): `2026-09-05T04:54:00Z`. - PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385` on canonical MV3 parent #43 `6f3134d18d3118aab33d28048671dc71a5f47b77`. Its child delta is diagnostic-evidence contract/doctoring only; inherited #43 implementation redacts browser/page-derived HTTP and WebDriver protocol data, startup exception details, returned capability values, DOM-dataset values, and click post-condition text before CI/audit evidence. Exact-head CI and Manifest V3 Compatibility succeeded and review threads are resolved, but parent-first workflow-ownership verification remains open, so the child stays Draft. - PR #43 is Draft at exact head `6f3134d18d3118aab33d28048671dc71a5f47b77`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. The branch now installs and configures the pinned `chrome_sandbox`; exact-head hosted verification remains required, and restoring `--no-sandbox` is not acceptable. - PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, with a repository regression contract for the exact badge target, pre-alpha status, active-PR non-promotion statement, and publication boundary. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. -- PR #37 is Ready at exact head `fa34a696e4ed9b2529a65a7d6a45ac8b72ecefb3`. After the 205 framing repair, a realistic TLS keep-alive RED proved that exact `Content-Length` completion still waited for connection closure. The current reader returns after the exact declared bytes, already-buffered surplus remains fail-closed, and valid self-delimited content does not require TLS EOF. The focused persistence regression passes; full hosted exact-head checks and an eligible approval remain required. +- PR #37 externally advanced to Ready exact head `28721edcc67bb5379ffb11a259d746396ac7ae03` to add its Content-Length persistence release record. Its predecessor reader returns after the exact declared bytes, already-buffered surplus remains fail-closed, and valid self-delimited content does not require TLS EOF, but that local evidence is predecessor-bound. The new hosted Rust, coverage, and central workflow jobs are queued, and no eligible exact-head approval exists. - PR #269 is Draft at exact head `7854394266d3f292e779193c01413a34f6798d7c`, stacked on #268 exact `8d4027e40b790d28d866051ba741db12927ec22c`. It adds only a fixed, product-owned `script.callFunction` text-value observation for the exact admitted current node; it performs no browser I/O and proves no post-condition. Its new documentation boundary contract and all 140 Python contracts pass locally, while hosted exact-head CI is queued and the parent-first dependency keeps it Draft. - PR #270 is Draft at exact head `191a14535219ea8033777fa4c970efb281b62418`, now non-force synchronized onto #269 exact `7854394266d3f292e779193c01413a34f6798d7c`. Its parent-relative transport delta is unchanged; 140 Python contracts, full Rust gates, and exact 100% local production function/line/region/branch coverage pass. Dispatch still proves neither the correlated result nor text-entry success, and fresh hosted exact-head checks plus parent-first integration remain required. - PR #271 is Draft at exact head `802ec806cdd4560eab48c484f435766ecabda353`, non-force synchronized onto #270 exact `191a14535219ea8033777fa4c970efb281b62418`. It admits only the exact typed observation response, treats unequal text as `PostconditionMismatch`, and retains no page-controlled or expected text in public evidence or diagnostics. Its test-first documentation contract, all 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index ae071bc3b..6b75049f5 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -35,7 +35,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `fa34a696e4ed9b2529a65a7d6a45ac8b72ecefb3`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`", + "Ready roots are #37 `28721edcc67bb5379ffb11a259d746396ac7ae03`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`", "PR #238's moving exact head is intentionally omitted", "PR #249 is Draft at exact head `017d6e816f5a86544a63821b3ceaba94d5f17f44`", "#250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`", diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index d4dcc7742..9716bdd2a 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -182,7 +182,7 @@ def test_current_snapshot_records_content_length_persistence_repair(self) -> Non )[0] for marker in ( - "PR #37 is Ready at exact head `fa34a696e4ed9b2529a65a7d6a45ac8b72ecefb3`", + "PR #37 externally advanced to Ready exact head `28721edcc67bb5379ffb11a259d746396ac7ae03`", "returns after the exact declared bytes", "already-buffered surplus remains fail-closed", "does not require TLS EOF", From fdb2516a8fbd006cb625b81fecf5befda87ca1b5 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 13:56:02 +0900 Subject: [PATCH 128/250] docs: record formal review blockers Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 3 ++- tests/test_gap_snapshot_inventory_consistency.py | 4 ++++ 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e79efbc49..a58c8e800 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,11 +6,12 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T05:02:00Z`. +Observed at (UTC): `2026-09-05T05:08:00Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 14 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PR #290 is the newly opened Ready workflow-admission child of #245; queue movement is not protected-main delivery. - Ready roots are #37 `28721edcc67bb5379ffb11a259d746396ac7ae03`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2` and PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd` retain formal `CHANGES_REQUESTED` decisions even though every current review thread is resolved. The decisions remain merge blockers until the governing reviewer state changes; thread resolution alone is not approval and is not grounds to dismiss a review. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass. Its Ready transition materialized repository-native CI `33930234387`, which remains queued, but did not materialize fresh central required-workflow runs: the only exact-head Security Scan `33924016851`, SAST Semgrep `33924016903`, and CodeQL PR `33924016883` runs came from the earlier Draft event and were cancelled. Missing current lifecycle evidence and the absent eligible approval remain merge blockers; toggling Draft or creating a no-op commit is not an acceptable substitute. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 6b75049f5..837c6d920 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -37,6 +37,10 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", "Ready roots are #37 `28721edcc67bb5379ffb11a259d746396ac7ae03`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`", "PR #238's moving exact head is intentionally omitted", + "PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2`", + "PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd`", + "retain formal `CHANGES_REQUESTED` decisions", + "every current review thread is resolved", "PR #249 is Draft at exact head `017d6e816f5a86544a63821b3ceaba94d5f17f44`", "#250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`", "#251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`", From 23e7aa15c09837ce567ecb1da6537aed15ed407d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 13:57:02 +0900 Subject: [PATCH 129/250] docs: correct baseline observation time Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index a58c8e800..1202f4cc8 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,7 +6,7 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T05:08:00Z`. +Observed at (UTC): `2026-09-05T04:56:34Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 14 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PR #290 is the newly opened Ready workflow-admission child of #245; queue movement is not protected-main delivery. From 208d77ac14906054c3f81457043cb93b731cdd31 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 13:59:59 +0900 Subject: [PATCH 130/250] docs: record runner admission backlog Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 3 ++- tests/test_gap_snapshot_inventory_consistency.py | 5 +++++ 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 1202f4cc8..1a294ca79 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,12 +6,13 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T04:56:34Z`. +Observed at (UTC): `2026-09-05T04:57:10Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 14 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PR #290 is the newly opened Ready workflow-admission child of #245; queue movement is not protected-main delivery. - Ready roots are #37 `28721edcc67bb5379ffb11a259d746396ac7ae03`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2` and PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd` retain formal `CHANGES_REQUESTED` decisions even though every current review thread is resolved. The decisions remain merge blockers until the governing reviewer state changes; thread resolution alone is not approval and is not grounds to dismiss a review. +- PR #238 exact head `23e7aa15c09837ce567ecb1da6537aed15ed407d` materialized native CI run `33945915264`; both `ubuntu-24.04` jobs are queued without an assigned runner. Across the latest 100 repository workflow runs, 22 are queued and none is in progress, with the oldest queued run created at `2026-09-05T04:20:26Z`. This is current runner-admission evidence, not a code failure or passing check; rerunning would only add duplicate queue load. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass. Its Ready transition materialized repository-native CI `33930234387`, which remains queued, but did not materialize fresh central required-workflow runs: the only exact-head Security Scan `33924016851`, SAST Semgrep `33924016903`, and CodeQL PR `33924016883` runs came from the earlier Draft event and were cancelled. Missing current lifecycle evidence and the absent eligible approval remain merge blockers; toggling Draft or creating a no-op commit is not an acceptable substitute. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 837c6d920..cebe3e4a3 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -41,6 +41,11 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd`", "retain formal `CHANGES_REQUESTED` decisions", "every current review thread is resolved", + "PR #238 exact head `23e7aa15c09837ce567ecb1da6537aed15ed407d`", + "native CI run `33945915264`", + "both `ubuntu-24.04` jobs are queued without an assigned runner", + "22 are queued and none is in progress", + "rerunning would only add duplicate queue load", "PR #249 is Draft at exact head `017d6e816f5a86544a63821b3ceaba94d5f17f44`", "#250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`", "#251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`", From ec9c3d70c84f6fa08a841f27ce0bfd2192e5f51f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 14:06:52 +0900 Subject: [PATCH 131/250] test(docs): reject non-convergent baseline self-SHA --- tests/test_gap_snapshot_inventory_consistency.py | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index cebe3e4a3..ca9555166 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -41,9 +41,6 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd`", "retain formal `CHANGES_REQUESTED` decisions", "every current review thread is resolved", - "PR #238 exact head `23e7aa15c09837ce567ecb1da6537aed15ed407d`", - "native CI run `33945915264`", - "both `ubuntu-24.04` jobs are queued without an assigned runner", "22 are queued and none is in progress", "rerunning would only add duplicate queue load", "PR #249 is Draft at exact head `017d6e816f5a86544a63821b3ceaba94d5f17f44`", @@ -84,6 +81,11 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: ): with self.subTest(marker=marker): self.assertIn(marker, current) + self.assertNotRegex( + current, + re.compile(r"PR #238 exact head `[0-9a-f]{40}`"), + "The self-referential baseline cannot pin the SHA produced by its own commit; read #238 live metadata instead.", + ) self.assertRegex( current, re.compile(r"Observed at \(UTC\): `\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}Z`"), From ce74ab253b7da7d2a8f02790dff4a54f5b9d2693 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 14:07:11 +0900 Subject: [PATCH 132/250] docs: record exact HTTP formatting repair Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 8 ++++---- tests/test_gap_snapshot_inventory_consistency.py | 4 ++-- tests/test_product_completion_gap_contract.py | 2 +- 3 files changed, 7 insertions(+), 7 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 1a294ca79..8bb2c3a6c 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,13 +6,13 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T04:57:10Z`. +Observed at (UTC): `2026-09-05T05:04:59Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 14 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PR #290 is the newly opened Ready workflow-admission child of #245; queue movement is not protected-main delivery. -- Ready roots are #37 `28721edcc67bb5379ffb11a259d746396ac7ae03`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2` and PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd` retain formal `CHANGES_REQUESTED` decisions even though every current review thread is resolved. The decisions remain merge blockers until the governing reviewer state changes; thread resolution alone is not approval and is not grounds to dismiss a review. -- PR #238 exact head `23e7aa15c09837ce567ecb1da6537aed15ed407d` materialized native CI run `33945915264`; both `ubuntu-24.04` jobs are queued without an assigned runner. Across the latest 100 repository workflow runs, 22 are queued and none is in progress, with the oldest queued run created at `2026-09-05T04:20:26Z`. This is current runner-admission evidence, not a code failure or passing check; rerunning would only add duplicate queue load. +- A predecessor #238 head materialized native CI run `33945915264`; both `ubuntu-24.04` jobs were queued without an assigned runner. Across the latest 100 repository workflow runs, 22 were queued and none was in progress, with the oldest queued run created at `2026-09-05T04:20:26Z`. This is runner-admission evidence, not a code failure or passing check; rerunning would only add duplicate queue load. The moving PR's exact current head remains live-metadata-only to avoid a non-convergent self-reference. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass. Its Ready transition materialized repository-native CI `33930234387`, which remains queued, but did not materialize fresh central required-workflow runs: the only exact-head Security Scan `33924016851`, SAST Semgrep `33924016903`, and CodeQL PR `33924016883` runs came from the earlier Draft event and were cancelled. Missing current lifecycle evidence and the absent eligible approval remain merge blockers; toggling Draft or creating a no-op commit is not an acceptable substitute. @@ -28,7 +28,7 @@ Observed at (UTC): `2026-09-05T04:57:10Z`. - PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385` on canonical MV3 parent #43 `6f3134d18d3118aab33d28048671dc71a5f47b77`. Its child delta is diagnostic-evidence contract/doctoring only; inherited #43 implementation redacts browser/page-derived HTTP and WebDriver protocol data, startup exception details, returned capability values, DOM-dataset values, and click post-condition text before CI/audit evidence. Exact-head CI and Manifest V3 Compatibility succeeded and review threads are resolved, but parent-first workflow-ownership verification remains open, so the child stays Draft. - PR #43 is Draft at exact head `6f3134d18d3118aab33d28048671dc71a5f47b77`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. The branch now installs and configures the pinned `chrome_sandbox`; exact-head hosted verification remains required, and restoring `--no-sandbox` is not acceptable. - PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, with a repository regression contract for the exact badge target, pre-alpha status, active-PR non-promotion statement, and publication boundary. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. -- PR #37 externally advanced to Ready exact head `28721edcc67bb5379ffb11a259d746396ac7ae03` to add its Content-Length persistence release record. Its predecessor reader returns after the exact declared bytes, already-buffered surplus remains fail-closed, and valid self-delimited content does not require TLS EOF, but that local evidence is predecessor-bound. The new hosted Rust, coverage, and central workflow jobs are queued, and no eligible exact-head approval exists. +- PR #37 is Ready at exact head `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`. The head repairs the Rust 1.97.1 formatting failure in its segmented Content-Length regression; formatting, locked workspace check/test, strict Clippy, rustdoc, all 167 Python contracts, and pinned-nightly production function/line/region/branch coverage pass locally at 100%. The reader returns after the exact declared bytes, already-buffered surplus remains fail-closed, and valid self-delimited content does not require TLS EOF. New hosted exact-head jobs are queued and no eligible approval exists. - PR #269 is Draft at exact head `7854394266d3f292e779193c01413a34f6798d7c`, stacked on #268 exact `8d4027e40b790d28d866051ba741db12927ec22c`. It adds only a fixed, product-owned `script.callFunction` text-value observation for the exact admitted current node; it performs no browser I/O and proves no post-condition. Its new documentation boundary contract and all 140 Python contracts pass locally, while hosted exact-head CI is queued and the parent-first dependency keeps it Draft. - PR #270 is Draft at exact head `191a14535219ea8033777fa4c970efb281b62418`, now non-force synchronized onto #269 exact `7854394266d3f292e779193c01413a34f6798d7c`. Its parent-relative transport delta is unchanged; 140 Python contracts, full Rust gates, and exact 100% local production function/line/region/branch coverage pass. Dispatch still proves neither the correlated result nor text-entry success, and fresh hosted exact-head checks plus parent-first integration remain required. - PR #271 is Draft at exact head `802ec806cdd4560eab48c484f435766ecabda353`, non-force synchronized onto #270 exact `191a14535219ea8033777fa4c970efb281b62418`. It admits only the exact typed observation response, treats unequal text as `PostconditionMismatch`, and retains no page-controlled or expected text in public evidence or diagnostics. Its test-first documentation contract, all 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index ca9555166..e6df10827 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -35,13 +35,13 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `28721edcc67bb5379ffb11a259d746396ac7ae03`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`", + "Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`", "PR #238's moving exact head is intentionally omitted", "PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2`", "PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd`", "retain formal `CHANGES_REQUESTED` decisions", "every current review thread is resolved", - "22 are queued and none is in progress", + "22 were queued and none was in progress", "rerunning would only add duplicate queue load", "PR #249 is Draft at exact head `017d6e816f5a86544a63821b3ceaba94d5f17f44`", "#250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`", diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 9716bdd2a..b002507dc 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -182,7 +182,7 @@ def test_current_snapshot_records_content_length_persistence_repair(self) -> Non )[0] for marker in ( - "PR #37 externally advanced to Ready exact head `28721edcc67bb5379ffb11a259d746396ac7ae03`", + "PR #37 is Ready at exact head `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`", "returns after the exact declared bytes", "already-buffered surplus remains fail-closed", "does not require TLS EOF", From 4ecd2e35b6175159247a76a9448d0d3f4c00b92e Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 14:39:01 +0900 Subject: [PATCH 133/250] docs: record origin-bound socket repair Refresh the live baseline and lock the exact PR #50 security head in repository contracts. Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 5 +++-- tests/test_gap_snapshot_inventory_consistency.py | 2 +- tests/test_product_completion_gap_contract.py | 16 ++++++++++++++++ 3 files changed, 20 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 8bb2c3a6c..fde3d5616 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,11 +6,11 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T05:04:59Z`. +Observed at (UTC): `2026-09-05T05:39:00Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 14 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PR #290 is the newly opened Ready workflow-admission child of #245; queue movement is not protected-main delivery. -- Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `ddbefc91fbcbc1bfd1e1af63846620f7ccb7a9b4`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2` and PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd` retain formal `CHANGES_REQUESTED` decisions even though every current review thread is resolved. The decisions remain merge blockers until the governing reviewer state changes; thread resolution alone is not approval and is not grounds to dismiss a review. - A predecessor #238 head materialized native CI run `33945915264`; both `ubuntu-24.04` jobs were queued without an assigned runner. Across the latest 100 repository workflow runs, 22 were queued and none was in progress, with the oldest queued run created at `2026-09-05T04:20:26Z`. This is runner-admission evidence, not a code failure or passing check; rerunning would only add duplicate queue load. The moving PR's exact current head remains live-metadata-only to avoid a non-convergent self-reference. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. @@ -29,6 +29,7 @@ Observed at (UTC): `2026-09-05T05:04:59Z`. - PR #43 is Draft at exact head `6f3134d18d3118aab33d28048671dc71a5f47b77`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. The branch now installs and configures the pinned `chrome_sandbox`; exact-head hosted verification remains required, and restoring `--no-sandbox` is not acceptable. - PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, with a repository regression contract for the exact badge target, pre-alpha status, active-PR non-promotion statement, and publication boundary. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. - PR #37 is Ready at exact head `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`. The head repairs the Rust 1.97.1 formatting failure in its segmented Content-Length regression; formatting, locked workspace check/test, strict Clippy, rustdoc, all 167 Python contracts, and pinned-nightly production function/line/region/branch coverage pass locally at 100%. The reader returns after the exact declared bytes, already-buffered surplus remains fail-closed, and valid self-delimited content does not require TLS EOF. New hosted exact-head jobs are queued and no eligible approval exists. +- PR #50 is Ready at exact head `ddbefc91fbcbc1bfd1e1af63846620f7ccb7a9b4` on protected main. A realistic predecessor regression proved that an origin-approved IP could be paired with a different service port; the shared direct planner now binds the socket port to the effective scheme-host-port origin before I/O. All 152 Python contracts, full Rust gates, and exact production function/line/region/branch coverage pass locally at 100%; the push invalidated predecessor hosted checks and approvals, so fresh terminal evidence remains required. - PR #269 is Draft at exact head `7854394266d3f292e779193c01413a34f6798d7c`, stacked on #268 exact `8d4027e40b790d28d866051ba741db12927ec22c`. It adds only a fixed, product-owned `script.callFunction` text-value observation for the exact admitted current node; it performs no browser I/O and proves no post-condition. Its new documentation boundary contract and all 140 Python contracts pass locally, while hosted exact-head CI is queued and the parent-first dependency keeps it Draft. - PR #270 is Draft at exact head `191a14535219ea8033777fa4c970efb281b62418`, now non-force synchronized onto #269 exact `7854394266d3f292e779193c01413a34f6798d7c`. Its parent-relative transport delta is unchanged; 140 Python contracts, full Rust gates, and exact 100% local production function/line/region/branch coverage pass. Dispatch still proves neither the correlated result nor text-entry success, and fresh hosted exact-head checks plus parent-first integration remain required. - PR #271 is Draft at exact head `802ec806cdd4560eab48c484f435766ecabda353`, non-force synchronized onto #270 exact `191a14535219ea8033777fa4c970efb281b62418`. It admits only the exact typed observation response, treats unequal text as `PostconditionMismatch`, and retains no page-controlled or expected text in public evidence or diagnostics. Its test-first documentation contract, all 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index e6df10827..97f7fbe6a 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -35,7 +35,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `30d032b64c8eca669fa029a9d9915519cc467e99`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`", + "Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `ddbefc91fbcbc1bfd1e1af63846620f7ccb7a9b4`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`", "PR #238's moving exact head is intentionally omitted", "PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2`", "PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd`", diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index b002507dc..c620a5eec 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -174,6 +174,22 @@ def test_current_snapshot_records_repaired_webdriver_bidi_lineage(self) -> None: text, ) + def test_current_snapshot_records_origin_bound_socket_ports(self) -> None: + """The live network root must retain its exact port-authority repair.""" + text = BASELINE.read_text(encoding="utf-8") + current = text.split("## Current live delivery state", 1)[1].split( + "## Observed snapshot: ", 1 + )[0] + + for marker in ( + "PR #50 is Ready at exact head `ddbefc91fbcbc1bfd1e1af63846620f7ccb7a9b4`", + "origin-approved IP could be paired with a different service port", + "binds the socket port to the effective scheme-host-port origin", + "function/line/region/branch coverage pass locally at 100%", + ): + with self.subTest(marker=marker): + self.assertIn(marker, current) + def test_current_snapshot_records_content_length_persistence_repair(self) -> None: """A declared body boundary must not be confused with transport closure.""" text = BASELINE.read_text(encoding="utf-8") From bf88ff20809bcc978ac37980c31e8c89f7be4bc2 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 14:58:37 +0900 Subject: [PATCH 134/250] docs: record teardown evidence gap Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 4 ++-- tests/test_gap_snapshot_inventory_consistency.py | 2 ++ 3 files changed, 5 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index f67a4cb79..3f0c57ed1 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded the #253 teardown-evidence gap: a correlated protocol acknowledgement plus raw caller booleans cannot constitute authenticated transport, process-exit, or profile-removal completion evidence. - Refreshed the active WebDriver BiDi and semantic-action stack evidence through exact heads #195, #242, #93, #95, #96, #101, #102, and #103, including macOS fixture-race repairs and fail-closed policy, dispatch, disabled-state, and current-observation boundaries. - Recorded PR #285's Ready-event materialization gap: repository-native exact-head CI restarted, while the earlier central Security, Semgrep, and CodeQL runs remained cancelled and no fresh required-workflow replacements appeared. - Refreshed the live product-gap baseline with PR #37's RFC 9110 `205 Reset Content` repair head and exact local verification evidence. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index fde3d5616..b069c1430 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,7 +6,7 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T05:39:00Z`. +Observed at (UTC): `2026-09-05T05:57:11Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 14 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PR #290 is the newly opened Ready workflow-admission child of #245; queue movement is not protected-main delivery. @@ -37,7 +37,7 @@ Observed at (UTC): `2026-09-05T05:39:00Z`. - PR #242 is Draft at exact head `55fef0c3fae1724eddada53e52c4a0311f509aa3`, stacked on #195 exact `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its zero-deadline regression holds the accepted peer until validation completes, so macOS cannot race socket teardown against the intended invalid-input result. Its 139 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 externally advanced to Ready exact head `7d6db16b2ead201fcec320854923f90d3ad0d8bc` after scoping its BiDi release contract to the owned record. The prior local full-suite evidence applies only to predecessor `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`; new hosted checks are queued and must prove the current head independently. - PR #249 is Draft at exact head `017d6e816f5a86544a63821b3ceaba94d5f17f44`, non-force synchronized onto #248 exact `7d6db16b2ead201fcec320854923f90d3ad0d8bc`. Its correlation-state regression no longer creates uncovered assertion-internal failure regions while still proving local preflight retirement and ambiguous-write retention. The current parent and child trees passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; hosted exact-head checks are queued and ordered parent integration remains required. -- PRs #250 through #257 remain Draft and are again synchronized in order through exact heads #250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`, #251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`, #252 `2015259529ada99af836989079cc85a15779a2d8`, #253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`, #254 `cbaf50dcc97753cc73135497ea8225e8b18de190`, #255 `a13de5f9321e72c1867974eb7a43230f031e58df`, #256 `9f2e6f29be46371762e3031a97c1cac04720694f`, and #257 `ea2b5b78868917219c46f1304558b92490a7f6fe`. Each updated tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. #250 and #257 each had one known macOS socket-observation race; their exact focused retries and complete coverage reruns passed. Hosted exact-head checks and ordered parent integration remain required. +- PRs #250 through #257 remain Draft and are again synchronized in order through exact heads #250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`, #251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`, #252 `2015259529ada99af836989079cc85a15779a2d8`, #253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`, #254 `cbaf50dcc97753cc73135497ea8225e8b18de190`, #255 `a13de5f9321e72c1867974eb7a43230f031e58df`, #256 `9f2e6f29be46371762e3031a97c1cac04720694f`, and #257 `ea2b5b78868917219c46f1304558b92490a7f6fe`. Each updated tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. #250 and #257 each had one known macOS socket-observation race; their exact focused retries and complete coverage reruns passed. Exact-head review found that #253 still lets three unauthenticated caller booleans mint `OperationallyComplete`; raw teardown claims must remain explicitly unverified until session-bound transport, process-exit, and profile-removal evidence types are issued by their owning runtime boundaries. Hosted exact-head checks and ordered parent integration remain required. - PR #258 is Draft at exact head `f2ceabb3ea50b1959e936503c50cae12f3e6e480` on exact #257, and PR #259 is Draft at exact head `e1105ddf86f6c79443af8b4d306b9d34cb703c17` on exact #258. Both final trees passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; fresh hosted exact-head checks and ordered parent integration remain required. - PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #95 is Draft at exact head `97aa0f2e340ee6fd920d0418f97af276b190554f`, stacked on #93 exact `0664f0452cb329cd692cce7f61f9001652abfda2`. Only `Decision::Allow` creates policy-authorized value; other decisions fail closed, and registry-owned current authority returns `NotAdmitted` after document advance removes the node. The slice performs no browser I/O or postcondition proof. Its 142 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 97f7fbe6a..192009b74 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -48,6 +48,8 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "#251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`", "#252 `2015259529ada99af836989079cc85a15779a2d8`", "#253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`", + "three unauthenticated caller booleans mint `OperationallyComplete`", + "raw teardown claims must remain explicitly unverified", "#254 `cbaf50dcc97753cc73135497ea8225e8b18de190`", "#255 `a13de5f9321e72c1867974eb7a43230f031e58df`", "#256 `9f2e6f29be46371762e3031a97c1cac04720694f`", From 6fef50a1673cf0a6d55e657b752a58423a71f621 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 14:59:29 +0900 Subject: [PATCH 135/250] docs: mark stale classifier parent Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- CHANGELOG.md | 2 +- docs/product-technical-gap-baseline.md | 4 ++-- tests/test_gap_snapshot_inventory_consistency.py | 2 ++ 3 files changed, 5 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 3f0c57ed1..1049437aa 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,7 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] -- Recorded the #253 teardown-evidence gap: a correlated protocol acknowledgement plus raw caller booleans cannot constitute authenticated transport, process-exit, or profile-removal completion evidence. +- Recorded the #253 teardown-evidence gap and corrected #283's stale #282 predecessor-base classification; raw caller claims and stale parent compares cannot become current completion evidence. - Refreshed the active WebDriver BiDi and semantic-action stack evidence through exact heads #195, #242, #93, #95, #96, #101, #102, and #103, including macOS fixture-race repairs and fail-closed policy, dispatch, disabled-state, and current-observation boundaries. - Recorded PR #285's Ready-event materialization gap: repository-native exact-head CI restarted, while the earlier central Security, Semgrep, and CodeQL runs remained cancelled and no fresh required-workflow replacements appeared. - Refreshed the live product-gap baseline with PR #37's RFC 9110 `205 Reset Content` repair head and exact local verification evidence. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b069c1430..3d4d86724 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,7 +6,7 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T05:57:11Z`. +Observed at (UTC): `2026-09-05T05:59:00Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 14 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PR #290 is the newly opened Ready workflow-admission child of #245; queue movement is not protected-main delivery. @@ -18,7 +18,7 @@ Observed at (UTC): `2026-09-05T05:57:11Z`. - PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass. Its Ready transition materialized repository-native CI `33930234387`, which remains queued, but did not materialize fresh central required-workflow runs: the only exact-head Security Scan `33924016851`, SAST Semgrep `33924016903`, and CodeQL PR `33924016883` runs came from the earlier Draft event and were cancelled. Missing current lifecycle evidence and the absent eligible approval remain merge blockers; toggling Draft or creating a no-op commit is not an acceptable substitute. - Issue #279 owns the remaining documentation-CI partitioning gap. PR #287 is Ready at exact head `af83c40dd2990a03064a92ca75430a9cc400f098` on current protected main; it is the workflow-independent classifier foundation, changes no `.github/**` path, and is the prerequisite for an authorized workflow owner. Its predecessor failed its own release-record contract; the current head binds Git rename/copy similarity to blob identity, and its focused and full local suites plus exact 100% Rust coverage pass. Hosted exact-head checks remain queued and no eligible approval exists. PR #282 is Draft at externally advanced exact head `b64e0708584beff3fb54acf226cb3e667773e473` on current protected main; its new hosted jobs remain queued or skipped under the Draft policy, so predecessor local evidence is not transferred. - PR #290 is Ready at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2` on #245 exact `a769f484e2c110e0523b3b28cd21573f43867562`. It scopes MV3 pull-request concurrency and draft admission, but its newly queued hosted Rust, pinned-Chromium, and coverage checks remain non-passing evidence until terminal. -- PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`, non-force stacked on #282 exact `b54a5856d8201911f05d69622f0d5594a371adf0`. Its exact parent compare remains one prose-only doctoring canary; draft-hosted jobs are skipped, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. +- PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`, stacked on predecessor #282 head `b54a5856d8201911f05d69622f0d5594a371adf0` rather than current #282 exact `b64e0708584beff3fb54acf226cb3e667773e473`. It must adopt the current parent before its compare can become current evidence. The predecessor-parent compare remains one prose-only doctoring canary; draft-hosted jobs are skipped, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. - PR #288 is Draft at exact head `39e36256651f62940ec3ca6149067f0cfcb2285a` on current protected main. It stages #70's controlled Agent Task product, test, and documentation delta without any `.github/**` mutation; its workflow-owned sandbox-helper assertion was removed after it made the workflow-free branch's full Python contract suite fail, and all 172 Python contracts now pass locally. Hosted CI and MV3 jobs remain skipped while Draft, and #212 still owns authorized workflow activation plus sandboxed pinned-Chromium execution evidence. - Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `3a651967c421f77088fe25e86a63faae295390b3` on #259 exact base `e1105ddf86f6c79443af8b4d306b9d34cb703c17`. PR #261 is Draft at exact head `323ac9e147691e9f6572711f5a748e13f1036624`, stacked on exact #260. Repair PR #277 is Draft at exact head `01038ba71fb276426cc67f90a91a3c431e194db5`, stacked on exact #261 and preserving typed `SessionSubscribe` correlation. Each restacked tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. Fresh hosted checks remain non-terminal, so stale conflicting #262 is not superseded and remains dependency-blocked until #277 reaches terminal GREEN on the unchanged head. - Stacked PRs #178 and #85 were repaired without force pushes at exact heads `640e594dbc0a64f251a0f28b8e80943f53337e40` and `c9adea680d6186f1842a280e248ce55da4f1305b`. Parent-relative deltas now preserve the current MV3 diagnostic and extension-authority contracts; local full suites and exact 100% coverage passed, while hosted exact-head acceptance remains independently required. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 192009b74..b9cb24625 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -67,6 +67,8 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385`", "PR #282 is Draft at externally advanced exact head `b64e0708584beff3fb54acf226cb3e667773e473`", "PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`", + "stacked on predecessor #282 head `b54a5856d8201911f05d69622f0d5594a371adf0` rather than current #282 exact `b64e0708584beff3fb54acf226cb3e667773e473`", + "must adopt the current parent before its compare can become current evidence", "PR #288 is Draft at exact head `39e36256651f62940ec3ca6149067f0cfcb2285a`", "PR #269 is Draft at exact head `7854394266d3f292e779193c01413a34f6798d7c`", "PR #270 is Draft at exact head `191a14535219ea8033777fa4c970efb281b62418`", From 6ddae59dac15156b43952d853798cf9405a8dfda Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 15:01:48 +0900 Subject: [PATCH 136/250] docs: correct current queue lineage Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- CHANGELOG.md | 6 +++--- docs/product-technical-gap-baseline.md | 2 +- tests/test_gap_snapshot_inventory_consistency.py | 3 ++- 3 files changed, 6 insertions(+), 5 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 1049437aa..6460a8a93 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -9,13 +9,13 @@ All notable changes to OriginWeave are documented in this file. The format follo - Recorded PR #285's Ready-event materialization gap: repository-native exact-head CI restarted, while the earlier central Security, Semgrep, and CodeQL runs remained cancelled and no fresh required-workflow replacements appeared. - Refreshed the live product-gap baseline with PR #37's RFC 9110 `205 Reset Content` repair head and exact local verification evidence. - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. -- Refreshed the product-gap queue to 125 open pull requests (13 ready, 112 draft) and 13 open non-PR issues on 2026-09-05; queue movement is active-PR evidence, not protected-main shipment. -- Recorded the current Ready-root heads for #37, #50, #166, #219, #220, #229, #240, #247, #272, #274, #285, and #287; #238's moving self-reference is intentionally delegated to live PR metadata, hosted exact-head checks remain non-terminal, and counted approval remains absent. +- Refreshed the product-gap queue to 125 open pull requests (14 ready, 111 draft) and 13 open non-PR issues on 2026-09-05; queue movement is active-PR evidence, not protected-main shipment. +- Recorded the current Ready-root heads for #37, #50, #166, #219, #220, #229, #240, #248, #272, #274, #285, and #287; Ready #290 remains a #245-dependent child, #238's moving self-reference is delegated to live PR metadata, hosted exact-head checks remain non-terminal, and counted approval remains absent. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. ### Added -- Revalidated the product-gap queue at 125 open pull requests (13 ready, 112 draft) and 13 open non-PR issues on 2026-09-05; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Ready at `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, WebDriver BiDi document-advance PR #260 is Draft at `35d12949bde5e5cbc801fdfb433f4a9914bd4fb0`, denial-error PR #166 is Ready at `e84a1a2cc82b1c666218efd441da97849f47b8c2`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 is Ready at `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a`, DDD/MCP repair #272 is Ready at `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, governance repair #285 is Ready at `f455c2cd64b3dd3f027c91d396103792a205ddd0`, subscription repair #277 is Draft at `0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1` with a fresh rerun queued, classifier foundation #287 is Ready at `af83c40dd2990a03064a92ca75430a9cc400f098`, and workflow-free Agent Task successor #288 is Draft at `e051a3d06a613233781272ffdc0e564023ba52b0`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. +- Revalidated the product-gap queue at 125 open pull requests (14 ready, 111 draft) and 13 open non-PR issues on 2026-09-05; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Ready at `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, WebDriver BiDi document-advance PR #260 is Draft at `3a651967c421f77088fe25e86a63faae295390b3`, denial-error PR #166 is Ready at `e84a1a2cc82b1c666218efd441da97849f47b8c2`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 has merged into its unprotected parent and successor #248 is Ready at `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, DDD/MCP repair #272 is Ready at `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, governance repair #285 is Ready at `f455c2cd64b3dd3f027c91d396103792a205ddd0`, subscription repair #277 is Draft at `01038ba71fb276426cc67f90a91a3c431e194db5`, classifier foundation #287 is Ready at `af83c40dd2990a03064a92ca75430a9cc400f098`, and workflow-free Agent Task successor #288 is Draft at `39e36256651f62940ec3ca6149067f0cfcb2285a`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 3d4d86724..21d08dbf1 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -10,7 +10,7 @@ Observed at (UTC): `2026-09-05T05:59:00Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 14 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PR #290 is the newly opened Ready workflow-admission child of #245; queue movement is not protected-main delivery. -- Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `ddbefc91fbcbc1bfd1e1af63846620f7ccb7a9b4`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `ddbefc91fbcbc1bfd1e1af63846620f7ccb7a9b4`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. Ready PR #290 is a dependent child of #245, not a root, and remains #245-first. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2` and PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd` retain formal `CHANGES_REQUESTED` decisions even though every current review thread is resolved. The decisions remain merge blockers until the governing reviewer state changes; thread resolution alone is not approval and is not grounds to dismiss a review. - A predecessor #238 head materialized native CI run `33945915264`; both `ubuntu-24.04` jobs were queued without an assigned runner. Across the latest 100 repository workflow runs, 22 were queued and none was in progress, with the oldest queued run created at `2026-09-05T04:20:26Z`. This is runner-admission evidence, not a code failure or passing check; rerunning would only add duplicate queue load. The moving PR's exact current head remains live-metadata-only to avoid a non-convergent self-reference. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index b9cb24625..13d4b5dbf 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -35,7 +35,8 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `ddbefc91fbcbc1bfd1e1af63846620f7ccb7a9b4`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, #287 `af83c40dd2990a03064a92ca75430a9cc400f098`, and #290 `ebeefcd534db4324498fdb18046ebc6255ddcdf2`", + "Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `ddbefc91fbcbc1bfd1e1af63846620f7ccb7a9b4`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", + "Ready PR #290 is a dependent child of #245, not a root, and remains #245-first", "PR #238's moving exact head is intentionally omitted", "PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2`", "PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd`", From 87b423bf2eb84785b9811b0b02fa8788676e4aab Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 15:03:07 +0900 Subject: [PATCH 137/250] test: align live queue contracts Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- tests/test_documentation_active_pr_evidence_contract.py | 6 +++--- tests/test_gap_snapshot_inventory_consistency.py | 2 +- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 99e67cb6f..95f5ef8dc 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -88,11 +88,11 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] self.assertIn("on 2026-09-05", refresh_line) - self.assertIn("125 open pull requests (13 ready, 112 draft)", refresh_line) + self.assertIn("125 open pull requests (14 ready, 111 draft)", refresh_line) self.assertIn("13 open non-PR issues", refresh_line) self.assertIn("024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6", refresh_line) - self.assertIn("35d12949bde5e5cbc801fdfb433f4a9914bd4fb0", refresh_line) - self.assertIn("0a7070b8fdc4a53d4b35f0b93be79a404d8d68c1", refresh_line) + self.assertIn("3a651967c421f77088fe25e86a63faae295390b3", refresh_line) + self.assertIn("01038ba71fb276426cc67f90a91a3c431e194db5", refresh_line) self.assertIn( "Revalidated the active ruleset inventory at 7 required workflows", changed, diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 13d4b5dbf..2f92122f4 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -163,7 +163,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "125 open pull requests (13 ready, 112 draft)" + expected = "125 open pull requests (14 ready, 111 draft)" self.assertIn(expected, preamble) self.assertIn("13 open non-PR issues", preamble) self.assertIn(expected, added) From f32ecb1d9802d8e9df9fa925f3a162df5e447b6a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 15:11:14 +0900 Subject: [PATCH 138/250] test(docs): bind live queue after workflow draft repair --- tests/test_gap_snapshot_inventory_consistency.py | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 2f92122f4..f90ba1570 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -27,8 +27,8 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: )[0] for marker in ( "125 open pull requests", - "14 Ready/non-draft", - "111 Draft", + "13 Ready/non-draft", + "112 Draft", "13 open non-PR issues", "87c4daa1830bac5a5228b6036752ad5633232085", "18156473", @@ -36,7 +36,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", "Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `ddbefc91fbcbc1bfd1e1af63846620f7ccb7a9b4`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", - "Ready PR #290 is a dependent child of #245, not a root, and remains #245-first", + "PR #290 is Draft at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2`", "PR #238's moving exact head is intentionally omitted", "PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2`", "PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd`", @@ -163,7 +163,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "125 open pull requests (14 ready, 111 draft)" + expected = "125 open pull requests (13 ready, 112 draft)" self.assertIn(expected, preamble) self.assertIn("13 open non-PR issues", preamble) self.assertIn(expected, added) From bb2f18570f319a763acc24d7c4206ec9d0a11a29 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 15:12:21 +0900 Subject: [PATCH 139/250] docs: record workflow draft repair in live queue --- CHANGELOG.md | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 6460a8a93..7c4e3f9bc 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,18 +4,19 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Converted PR #290 back to Draft after exact review showed its #245-relative MV3 workflow would drop protected #286 `converted_to_draft`/`closed` lifecycle coverage and the closed-event fail-closed guard; the valid concurrency/manual-dispatch intent remains assigned to canonical workflow owner #212. - Recorded the #253 teardown-evidence gap and corrected #283's stale #282 predecessor-base classification; raw caller claims and stale parent compares cannot become current completion evidence. - Refreshed the active WebDriver BiDi and semantic-action stack evidence through exact heads #195, #242, #93, #95, #96, #101, #102, and #103, including macOS fixture-race repairs and fail-closed policy, dispatch, disabled-state, and current-observation boundaries. - Recorded PR #285's Ready-event materialization gap: repository-native exact-head CI restarted, while the earlier central Security, Semgrep, and CodeQL runs remained cancelled and no fresh required-workflow replacements appeared. - Refreshed the live product-gap baseline with PR #37's RFC 9110 `205 Reset Content` repair head and exact local verification evidence. - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. -- Refreshed the product-gap queue to 125 open pull requests (14 ready, 111 draft) and 13 open non-PR issues on 2026-09-05; queue movement is active-PR evidence, not protected-main shipment. -- Recorded the current Ready-root heads for #37, #50, #166, #219, #220, #229, #240, #248, #272, #274, #285, and #287; Ready #290 remains a #245-dependent child, #238's moving self-reference is delegated to live PR metadata, hosted exact-head checks remain non-terminal, and counted approval remains absent. +- Refreshed the product-gap queue to 125 open pull requests (13 ready, 112 draft) and 13 open non-PR issues on 2026-09-05; queue movement is active-PR evidence, not protected-main shipment. +- Recorded the current Ready-root heads for #37, #50, #166, #219, #220, #229, #240, #248, #272, #274, #285, and #287; Draft #290 remains a #245-dependent workflow-owner candidate, #238's moving self-reference is delegated to live PR metadata, hosted exact-head checks remain non-terminal, and counted approval remains absent. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. ### Added -- Revalidated the product-gap queue at 125 open pull requests (14 ready, 111 draft) and 13 open non-PR issues on 2026-09-05; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Ready at `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, WebDriver BiDi document-advance PR #260 is Draft at `3a651967c421f77088fe25e86a63faae295390b3`, denial-error PR #166 is Ready at `e84a1a2cc82b1c666218efd441da97849f47b8c2`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 has merged into its unprotected parent and successor #248 is Ready at `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, DDD/MCP repair #272 is Ready at `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, governance repair #285 is Ready at `f455c2cd64b3dd3f027c91d396103792a205ddd0`, subscription repair #277 is Draft at `01038ba71fb276426cc67f90a91a3c431e194db5`, classifier foundation #287 is Ready at `af83c40dd2990a03064a92ca75430a9cc400f098`, and workflow-free Agent Task successor #288 is Draft at `39e36256651f62940ec3ca6149067f0cfcb2285a`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. +- Revalidated the product-gap queue at 125 open pull requests (13 ready, 112 draft) and 13 open non-PR issues on 2026-09-05; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Ready at `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, WebDriver BiDi document-advance PR #260 is Draft at `3a651967c421f77088fe25e86a63faae295390b3`, denial-error PR #166 is Ready at `e84a1a2cc82b1c666218efd441da97849f47b8c2`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 has merged into its unprotected parent and successor #248 is Ready at `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, DDD/MCP repair #272 is Ready at `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, governance repair #285 is Ready at `f455c2cd64b3dd3f027c91d396103792a205ddd0`, subscription repair #277 is Draft at `01038ba71fb276426cc67f90a91a3c431e194db5`, classifier foundation #287 is Ready at `af83c40dd2990a03064a92ca75430a9cc400f098`, workflow-free Agent Task successor #288 is Draft at `39e36256651f62940ec3ca6149067f0cfcb2285a`, and workflow-owner candidate #290 is Draft at `ebeefcd534db4324498fdb18046ebc6255ddcdf2`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. @@ -34,7 +35,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Added `originweave_core::release_acceptance`, a deterministic fail-closed benchmark release-decision contract that requires one authoritative result for every mandatory suite, bounds explicit buyer-visible limitations, rejects duplicate limitation claim identities, and rejects non-canonical surrounding whitespace rather than normalizing it into an alternate claim spelling. - Refreshed the product and technical gap baseline with the 2026-08-24 live inventory: 158 open pull requests (44 ready, 114 draft), refreshed exact base/head evidence for the #208–#222 release, enterprise-approval, BAP, and WARC/PROV chains, the governance issue additions #212 and #215, and a required-check provider-failure record for the fail-closed Strix re-dispatches on #208/#218/#220. - Added a dated product and technical gap baseline that separates protected-main implementation truth, active pull-request evidence, live review/check blockers, and the next buyer-visible Phase 1 acceptance work. -- Refreshed the product and technical gap baseline with the current open-PR inventory and exact base/head evidence for the newest Chromium, BAP, extraction, WARC, and idempotency slices. +- Refreshed the product and technical gap baseline with the current open-PR inventory and exact-head evidence for the newest Chromium, BAP, extraction, WARC, and idempotency slices. - Bound explicit extension-to-Agent grants to exclusive trusted-time expiry in addition to extension identity, session, browsing context, and canonical origin, so a same-origin grant cannot be reused at or after the deadline. - Bound explicit extension-to-Agent grants to the exact canonical origin in addition to extension identity, session, and browsing context, so a same-session navigation or port change cannot reuse the grant. - Rust workspace for independently reusable core, policy, destination, network, TLS, resource, and evidence modules. From 09c841a5b6aec6a0ad0ca407eff9544b25b25dbd Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 15:17:33 +0900 Subject: [PATCH 140/250] docs: refresh workflow-owner queue evidence --- docs/product-technical-gap-baseline.md | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 21d08dbf1..918340b04 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,19 +6,19 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T05:59:00Z`. +Observed at (UTC): `2026-09-05T06:12:27Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. -- Full live search returns **125 open pull requests: 14 Ready/non-draft and 111 Draft; 13 open non-PR issues**. PR #290 is the newly opened Ready workflow-admission child of #245; queue movement is not protected-main delivery. -- Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `ddbefc91fbcbc1bfd1e1af63846620f7ccb7a9b4`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. Ready PR #290 is a dependent child of #245, not a root, and remains #245-first. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Full live search returns **125 open pull requests: 13 Ready/non-draft and 112 Draft; 13 open non-PR issues**. PR #290 was converted back to Draft after current-protected workflow review found that its #245-relative patch would drop protected #286 lifecycle controls; queue movement is not protected-main delivery. +- Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `ddbefc91fbcbc1bfd1e1af63846620f7ccb7a9b4`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. PR #290 is Draft at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2`, remains a #245-dependent workflow-owner candidate, and is not a root. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2` and PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd` retain formal `CHANGES_REQUESTED` decisions even though every current review thread is resolved. The decisions remain merge blockers until the governing reviewer state changes; thread resolution alone is not approval and is not grounds to dismiss a review. -- A predecessor #238 head materialized native CI run `33945915264`; both `ubuntu-24.04` jobs were queued without an assigned runner. Across the latest 100 repository workflow runs, 22 were queued and none was in progress, with the oldest queued run created at `2026-09-05T04:20:26Z`. This is runner-admission evidence, not a code failure or passing check; rerunning would only add duplicate queue load. The moving PR's exact current head remains live-metadata-only to avoid a non-convergent self-reference. +- A fresh repository Actions query at `2026-09-05T06:12:27Z` returned **115 queued workflow runs**; the newest sampled run was #238 CI `33949183271` on predecessor head `bb2f18570f319a763acc24d7c4206ec9d0a11a29`. This is runner-admission/backlog evidence, not a code failure or passing check; rerunning unchanged heads would only add duplicate queue load. The moving PR's exact current head remains live-metadata-only to avoid a non-convergent self-reference. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass. Its Ready transition materialized repository-native CI `33930234387`, which remains queued, but did not materialize fresh central required-workflow runs: the only exact-head Security Scan `33924016851`, SAST Semgrep `33924016903`, and CodeQL PR `33924016883` runs came from the earlier Draft event and were cancelled. Missing current lifecycle evidence and the absent eligible approval remain merge blockers; toggling Draft or creating a no-op commit is not an acceptable substitute. -- Issue #279 owns the remaining documentation-CI partitioning gap. PR #287 is Ready at exact head `af83c40dd2990a03064a92ca75430a9cc400f098` on current protected main; it is the workflow-independent classifier foundation, changes no `.github/**` path, and is the prerequisite for an authorized workflow owner. Its predecessor failed its own release-record contract; the current head binds Git rename/copy similarity to blob identity, and its focused and full local suites plus exact 100% Rust coverage pass. Hosted exact-head checks remain queued and no eligible approval exists. PR #282 is Draft at externally advanced exact head `b64e0708584beff3fb54acf226cb3e667773e473` on current protected main; its new hosted jobs remain queued or skipped under the Draft policy, so predecessor local evidence is not transferred. -- PR #290 is Ready at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2` on #245 exact `a769f484e2c110e0523b3b28cd21573f43867562`. It scopes MV3 pull-request concurrency and draft admission, but its newly queued hosted Rust, pinned-Chromium, and coverage checks remain non-passing evidence until terminal. -- PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`, stacked on predecessor #282 head `b54a5856d8201911f05d69622f0d5594a371adf0` rather than current #282 exact `b64e0708584beff3fb54acf226cb3e667773e473`. It must adopt the current parent before its compare can become current evidence. The predecessor-parent compare remains one prose-only doctoring canary; draft-hosted jobs are skipped, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. +- Issue #279 owns the remaining documentation-CI partitioning gap. PR #287 is Ready at exact head `af83c40dd2990a03064a92ca75430a9cc400f098` on current protected main; it is the workflow-independent classifier foundation, changes no `.github/**` path, and is the prerequisite for an authorized workflow owner. Its predecessor failed its own release-record contract; the current head binds Git rename/copy similarity to blob identity, and its focused and full local suites plus exact 100% Rust coverage pass. Hosted exact-head checks remain queued and no eligible approval exists. PR #282 is Draft at exact head `b64e0708584beff3fb54acf226cb3e667773e473` on current protected main. Its latest workflow/test delta removes `converted_to_draft` and `closed` from the CI event list, removes #286's closed-event guard, and makes the repository contract assert those protections are absent. Exact review `5120043505` therefore requires the authorized #279 owner to reconstruct the valid trusted-base classifier/contract partition while preserving #286's lifecycle and closed+Draft fail-closed controls; Draft checks do not transfer as GREEN. +- PR #290 is Draft at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2` on #245 exact `a769f484e2c110e0523b3b28cd21573f43867562`. Its workflow/repository/PR-number concurrency isolation and manual-dispatch non-cancellation intent are valid, but its predecessor-relative MV3 patch would remove protected #286 `converted_to_draft`/`closed` lifecycle events and the closed-event job guard. Exact review `5120039692` and canonical-owner issue #212 comment `5549868655` require reconstruction on the current protected MV3 workflow; the scheduled product writer did not mutate `.github/**`. +- PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`, stacked on predecessor #282 head `b54a5856d8201911f05d69622f0d5594a371adf0` rather than current #282 exact `b64e0708584beff3fb54acf226cb3e667773e473`. It must adopt the corrected current parent before its compare can become current evidence. The child remains one prose-only doctoring canary; Draft-hosted jobs are skipped, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. - PR #288 is Draft at exact head `39e36256651f62940ec3ca6149067f0cfcb2285a` on current protected main. It stages #70's controlled Agent Task product, test, and documentation delta without any `.github/**` mutation; its workflow-owned sandbox-helper assertion was removed after it made the workflow-free branch's full Python contract suite fail, and all 172 Python contracts now pass locally. Hosted CI and MV3 jobs remain skipped while Draft, and #212 still owns authorized workflow activation plus sandboxed pinned-Chromium execution evidence. - Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `3a651967c421f77088fe25e86a63faae295390b3` on #259 exact base `e1105ddf86f6c79443af8b4d306b9d34cb703c17`. PR #261 is Draft at exact head `323ac9e147691e9f6572711f5a748e13f1036624`, stacked on exact #260. Repair PR #277 is Draft at exact head `01038ba71fb276426cc67f90a91a3c431e194db5`, stacked on exact #261 and preserving typed `SessionSubscribe` correlation. Each restacked tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. Fresh hosted checks remain non-terminal, so stale conflicting #262 is not superseded and remains dependency-blocked until #277 reaches terminal GREEN on the unchanged head. - Stacked PRs #178 and #85 were repaired without force pushes at exact heads `640e594dbc0a64f251a0f28b8e80943f53337e40` and `c9adea680d6186f1842a280e248ce55da4f1305b`. Parent-relative deltas now preserve the current MV3 diagnostic and extension-authority contracts; local full suites and exact 100% coverage passed, while hosted exact-head acceptance remains independently required. From cb3ac4ae9e0bd95605a80c201cb2f27d8c3746dc Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 15:18:29 +0900 Subject: [PATCH 141/250] test(docs): align current workflow queue evidence --- tests/test_gap_snapshot_inventory_consistency.py | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index f90ba1570..69216a2ca 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -42,8 +42,8 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd`", "retain formal `CHANGES_REQUESTED` decisions", "every current review thread is resolved", - "22 were queued and none was in progress", - "rerunning would only add duplicate queue load", + "115 queued workflow runs", + "rerunning unchanged heads would only add duplicate queue load", "PR #249 is Draft at exact head `017d6e816f5a86544a63821b3ceaba94d5f17f44`", "#250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`", "#251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`", @@ -66,10 +66,10 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "DDD/MCP repair #272 is Ready at exact head `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`", "PR #229 is Ready at exact head `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`", "PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385`", - "PR #282 is Draft at externally advanced exact head `b64e0708584beff3fb54acf226cb3e667773e473`", + "PR #282 is Draft at exact head `b64e0708584beff3fb54acf226cb3e667773e473`", "PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`", "stacked on predecessor #282 head `b54a5856d8201911f05d69622f0d5594a371adf0` rather than current #282 exact `b64e0708584beff3fb54acf226cb3e667773e473`", - "must adopt the current parent before its compare can become current evidence", + "must adopt the corrected current parent before its compare can become current evidence", "PR #288 is Draft at exact head `39e36256651f62940ec3ca6149067f0cfcb2285a`", "PR #269 is Draft at exact head `7854394266d3f292e779193c01413a34f6798d7c`", "PR #270 is Draft at exact head `191a14535219ea8033777fa4c970efb281b62418`", From 9be7b98f15d5b88cf8a37b393ffc0d02658d32c2 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 15:22:55 +0900 Subject: [PATCH 142/250] docs: record BiDi connection evidence review Record the reproduced cross-connection teardown finding and its prerequisite repair order. Compare changelog queue counts with the current baseline to prevent duplicated stale count failures. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 2 ++ docs/product-technical-gap-baseline.md | 1 + ...documentation_active_pr_evidence_contract.py | 17 +++++++++++++++-- 3 files changed, 18 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 7c4e3f9bc..553dc6e1f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,8 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded a reproduced cross-connection teardown-evidence gap in #254/#255 and its prerequisite repair order; another connection's closure must not be reported as closure of the acknowledged connection. +- Made the changelog queue-consistency check compare the current baseline counts directly, preventing a duplicated older count from rejecting a verified Ready-to-Draft transition. - Converted PR #290 back to Draft after exact review showed its #245-relative MV3 workflow would drop protected #286 `converted_to_draft`/`closed` lifecycle coverage and the closed-event fail-closed guard; the valid concurrency/manual-dispatch intent remains assigned to canonical workflow owner #212. - Recorded the #253 teardown-evidence gap and corrected #283's stale #282 predecessor-base classification; raw caller claims and stale parent compares cannot become current completion evidence. - Refreshed the active WebDriver BiDi and semantic-action stack evidence through exact heads #195, #242, #93, #95, #96, #101, #102, and #103, including macOS fixture-race repairs and fail-closed policy, dispatch, disabled-state, and current-observation boundaries. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 918340b04..bca31d552 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -38,6 +38,7 @@ Observed at (UTC): `2026-09-05T06:12:27Z`. - PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 externally advanced to Ready exact head `7d6db16b2ead201fcec320854923f90d3ad0d8bc` after scoping its BiDi release contract to the owned record. The prior local full-suite evidence applies only to predecessor `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`; new hosted checks are queued and must prove the current head independently. - PR #249 is Draft at exact head `017d6e816f5a86544a63821b3ceaba94d5f17f44`, non-force synchronized onto #248 exact `7d6db16b2ead201fcec320854923f90d3ad0d8bc`. Its correlation-state regression no longer creates uncovered assertion-internal failure regions while still proving local preflight retirement and ambiguous-write retention. The current parent and child trees passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; hosted exact-head checks are queued and ordered parent integration remains required. - PRs #250 through #257 remain Draft and are again synchronized in order through exact heads #250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`, #251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`, #252 `2015259529ada99af836989079cc85a15779a2d8`, #253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`, #254 `cbaf50dcc97753cc73135497ea8225e8b18de190`, #255 `a13de5f9321e72c1867974eb7a43230f031e58df`, #256 `9f2e6f29be46371762e3031a97c1cac04720694f`, and #257 `ea2b5b78868917219c46f1304558b92490a7f6fe`. Each updated tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. #250 and #257 each had one known macOS socket-observation race; their exact focused retries and complete coverage reruns passed. Exact-head review found that #253 still lets three unauthenticated caller booleans mint `OperationallyComplete`; raw teardown claims must remain explicitly unverified until session-bound transport, process-exit, and profile-removal evidence types are issued by their owning runtime boundaries. Hosted exact-head checks and ordered parent integration remain required. +- Reviews [#254](https://github.com/ContextualWisdomLab/OriginWeave/pull/254#pullrequestreview-5120077272) at `cbaf50dcc97753cc73135497ea8225e8b18de190` and [#255](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120077213) at `a13de5f9321e72c1867974eb7a43230f031e58df` found a remaining connection-provenance gap. #254 passed six focused closure tests, formatting, strict network Clippy and network rustdoc locally. #255 removes the parent process/profile booleans and keeps overall teardown pending, but a new loopback regression fails when an acknowledgment from connection A is combined with closure from connection B: the assessment reports the acknowledged transport closed. Both connections can use command id 7; #254 retains only closure kind/status and the acknowledgment retains only its command id. Repair the established-stream, frame/message and command-correlation owners to preserve a non-forgeable connection-generation binding, carry it into acknowledgment and closure evidence, then reject mismatches in #255. Different-session and same-session reconnect regressions are required; endpoint equality, command-id equality and caller-supplied markers are insufficient. This is unresolved evidence integrity, not operational-completion authority or shipped behavior. Both PRs remain Draft with hosted checks queued. - PR #258 is Draft at exact head `f2ceabb3ea50b1959e936503c50cae12f3e6e480` on exact #257, and PR #259 is Draft at exact head `e1105ddf86f6c79443af8b4d306b9d34cb703c17` on exact #258. Both final trees passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; fresh hosted exact-head checks and ordered parent integration remain required. - PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #95 is Draft at exact head `97aa0f2e340ee6fd920d0418f97af276b190554f`, stacked on #93 exact `0664f0452cb329cd692cce7f61f9001652abfda2`. Only `Decision::Allow` creates policy-authorized value; other decisions fail closed, and registry-owned current authority returns `NotAdmitted` after document advance removes the node. The slice performs no browser I/O or postcondition proof. Its 142 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 95f5ef8dc..7549d4e58 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -1,6 +1,7 @@ """Regression contracts for volatile active-PR evidence in canonical documentation.""" from pathlib import Path +import re import unittest @@ -88,8 +89,20 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] self.assertIn("on 2026-09-05", refresh_line) - self.assertIn("125 open pull requests (14 ready, 111 draft)", refresh_line) - self.assertIn("13 open non-PR issues", refresh_line) + current = bounded_section( + self.baseline, + "## Current live delivery state", + "## Observed snapshot: 2026-08-29", + ) + queue_counts = re.findall( + r"\*\*(\d+) open pull requests: (\d+) Ready/non-draft and (\d+) Draft; " + r"(\d+) open non-PR issues\*\*", + current, + ) + self.assertEqual(1, len(queue_counts)) + total, ready, draft, issues = queue_counts[0] + self.assertIn(f"{total} open pull requests ({ready} ready, {draft} draft)", refresh_line) + self.assertIn(f"{issues} open non-PR issues", refresh_line) self.assertIn("024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6", refresh_line) self.assertIn("3a651967c421f77088fe25e86a63faae295390b3", refresh_line) self.assertIn("01038ba71fb276426cc67f90a91a3c431e194db5", refresh_line) From fab93ac66121f6d8abfab34c66be2e53518d601c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 15:33:14 +0900 Subject: [PATCH 143/250] docs: record fresh connection review correction Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 4 ++-- tests/test_gap_snapshot_inventory_consistency.py | 2 +- tests/test_product_completion_gap_contract.py | 2 +- 4 files changed, 5 insertions(+), 4 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 553dc6e1f..e1ca126f3 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded #50's current documentation-repair head and resolved review, preserving predecessor-only full-coverage evidence and the new head's independent hosted-check requirement. - Recorded a reproduced cross-connection teardown-evidence gap in #254/#255 and its prerequisite repair order; another connection's closure must not be reported as closure of the acknowledged connection. - Made the changelog queue-consistency check compare the current baseline counts directly, preventing a duplicated older count from rejecting a verified Ready-to-Draft transition. - Converted PR #290 back to Draft after exact review showed its #245-relative MV3 workflow would drop protected #286 `converted_to_draft`/`closed` lifecycle coverage and the closed-event fail-closed guard; the valid concurrency/manual-dispatch intent remains assigned to canonical workflow owner #212. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index bca31d552..5856710fd 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -10,7 +10,7 @@ Observed at (UTC): `2026-09-05T06:12:27Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 13 Ready/non-draft and 112 Draft; 13 open non-PR issues**. PR #290 was converted back to Draft after current-protected workflow review found that its #245-relative patch would drop protected #286 lifecycle controls; queue movement is not protected-main delivery. -- Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `ddbefc91fbcbc1bfd1e1af63846620f7ccb7a9b4`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. PR #290 is Draft at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2`, remains a #245-dependent workflow-owner candidate, and is not a root. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `2bd85188a3b3d798824ac04cf3638df84ac2a8bb`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. PR #290 is Draft at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2`, remains a #245-dependent workflow-owner candidate, and is not a root. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2` and PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd` retain formal `CHANGES_REQUESTED` decisions even though every current review thread is resolved. The decisions remain merge blockers until the governing reviewer state changes; thread resolution alone is not approval and is not grounds to dismiss a review. - A fresh repository Actions query at `2026-09-05T06:12:27Z` returned **115 queued workflow runs**; the newest sampled run was #238 CI `33949183271` on predecessor head `bb2f18570f319a763acc24d7c4206ec9d0a11a29`. This is runner-admission/backlog evidence, not a code failure or passing check; rerunning unchanged heads would only add duplicate queue load. The moving PR's exact current head remains live-metadata-only to avoid a non-convergent self-reference. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. @@ -29,7 +29,7 @@ Observed at (UTC): `2026-09-05T06:12:27Z`. - PR #43 is Draft at exact head `6f3134d18d3118aab33d28048671dc71a5f47b77`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. The branch now installs and configures the pinned `chrome_sandbox`; exact-head hosted verification remains required, and restoring `--no-sandbox` is not acceptable. - PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, with a repository regression contract for the exact badge target, pre-alpha status, active-PR non-promotion statement, and publication boundary. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. - PR #37 is Ready at exact head `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`. The head repairs the Rust 1.97.1 formatting failure in its segmented Content-Length regression; formatting, locked workspace check/test, strict Clippy, rustdoc, all 167 Python contracts, and pinned-nightly production function/line/region/branch coverage pass locally at 100%. The reader returns after the exact declared bytes, already-buffered surplus remains fail-closed, and valid self-delimited content does not require TLS EOF. New hosted exact-head jobs are queued and no eligible approval exists. -- PR #50 is Ready at exact head `ddbefc91fbcbc1bfd1e1af63846620f7ccb7a9b4` on protected main. A realistic predecessor regression proved that an origin-approved IP could be paired with a different service port; the shared direct planner now binds the socket port to the effective scheme-host-port origin before I/O. All 152 Python contracts, full Rust gates, and exact production function/line/region/branch coverage pass locally at 100%; the push invalidated predecessor hosted checks and approvals, so fresh terminal evidence remains required. +- PR #50 is Ready at exact head `2bd85188a3b3d798824ac04cf3638df84ac2a8bb` on protected main. The origin-port repair and its full Rust/100% local coverage evidence belong to predecessor `ddbefc91fbcbc1bfd1e1af63846620f7ccb7a9b4`; the runtime source is unchanged by this head. The regression proved that an origin-approved IP could be paired with a different service port; the shared direct planner now binds the socket port to the effective scheme-host-port origin before I/O. A new documentation regression exposed that ADR 0005 and doctoring still described the old untimed public contract. Both now document the public freshness-checked plan, trusted monotonic time, and revalidation before socket I/O. All 152 Python contracts and six fresh-resolution integration tests pass; the current review thread is resolved. Fresh hosted checks remain required on this new head. - PR #269 is Draft at exact head `7854394266d3f292e779193c01413a34f6798d7c`, stacked on #268 exact `8d4027e40b790d28d866051ba741db12927ec22c`. It adds only a fixed, product-owned `script.callFunction` text-value observation for the exact admitted current node; it performs no browser I/O and proves no post-condition. Its new documentation boundary contract and all 140 Python contracts pass locally, while hosted exact-head CI is queued and the parent-first dependency keeps it Draft. - PR #270 is Draft at exact head `191a14535219ea8033777fa4c970efb281b62418`, now non-force synchronized onto #269 exact `7854394266d3f292e779193c01413a34f6798d7c`. Its parent-relative transport delta is unchanged; 140 Python contracts, full Rust gates, and exact 100% local production function/line/region/branch coverage pass. Dispatch still proves neither the correlated result nor text-entry success, and fresh hosted exact-head checks plus parent-first integration remain required. - PR #271 is Draft at exact head `802ec806cdd4560eab48c484f435766ecabda353`, non-force synchronized onto #270 exact `191a14535219ea8033777fa4c970efb281b62418`. It admits only the exact typed observation response, treats unequal text as `PostconditionMismatch`, and retains no page-controlled or expected text in public evidence or diagnostics. Its test-first documentation contract, all 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 69216a2ca..3db9ed97f 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -35,7 +35,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `ddbefc91fbcbc1bfd1e1af63846620f7ccb7a9b4`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", + "Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `2bd85188a3b3d798824ac04cf3638df84ac2a8bb`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", "PR #290 is Draft at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2`", "PR #238's moving exact head is intentionally omitted", "PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2`", diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index c620a5eec..f023cdbba 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -182,7 +182,7 @@ def test_current_snapshot_records_origin_bound_socket_ports(self) -> None: )[0] for marker in ( - "PR #50 is Ready at exact head `ddbefc91fbcbc1bfd1e1af63846620f7ccb7a9b4`", + "PR #50 is Ready at exact head `2bd85188a3b3d798824ac04cf3638df84ac2a8bb`", "origin-approved IP could be paired with a different service port", "binds the socket port to the effective scheme-host-port origin", "function/line/region/branch coverage pass locally at 100%", From a3e70b00659dbdc10c751d492c587b9a03251857 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 15:35:30 +0900 Subject: [PATCH 144/250] docs: distinguish active teardown repair from prior verification Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 5856710fd..c81c0893d 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -37,7 +37,7 @@ Observed at (UTC): `2026-09-05T06:12:27Z`. - PR #242 is Draft at exact head `55fef0c3fae1724eddada53e52c4a0311f509aa3`, stacked on #195 exact `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its zero-deadline regression holds the accepted peer until validation completes, so macOS cannot race socket teardown against the intended invalid-input result. Its 139 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 externally advanced to Ready exact head `7d6db16b2ead201fcec320854923f90d3ad0d8bc` after scoping its BiDi release contract to the owned record. The prior local full-suite evidence applies only to predecessor `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`; new hosted checks are queued and must prove the current head independently. - PR #249 is Draft at exact head `017d6e816f5a86544a63821b3ceaba94d5f17f44`, non-force synchronized onto #248 exact `7d6db16b2ead201fcec320854923f90d3ad0d8bc`. Its correlation-state regression no longer creates uncovered assertion-internal failure regions while still proving local preflight retirement and ambiguous-write retention. The current parent and child trees passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; hosted exact-head checks are queued and ordered parent integration remains required. -- PRs #250 through #257 remain Draft and are again synchronized in order through exact heads #250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`, #251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`, #252 `2015259529ada99af836989079cc85a15779a2d8`, #253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`, #254 `cbaf50dcc97753cc73135497ea8225e8b18de190`, #255 `a13de5f9321e72c1867974eb7a43230f031e58df`, #256 `9f2e6f29be46371762e3031a97c1cac04720694f`, and #257 `ea2b5b78868917219c46f1304558b92490a7f6fe`. Each updated tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. #250 and #257 each had one known macOS socket-observation race; their exact focused retries and complete coverage reruns passed. Exact-head review found that #253 still lets three unauthenticated caller booleans mint `OperationallyComplete`; raw teardown claims must remain explicitly unverified until session-bound transport, process-exit, and profile-removal evidence types are issued by their owning runtime boundaries. Hosted exact-head checks and ordered parent integration remain required. +- PRs #250 through #257 remain Draft. The recorded fully locally verified chain used exact heads #250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`, #251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`, #252 `2015259529ada99af836989079cc85a15779a2d8`, #253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`, #254 `cbaf50dcc97753cc73135497ea8225e8b18de190`, #255 `a13de5f9321e72c1867974eb7a43230f031e58df`, #256 `9f2e6f29be46371762e3031a97c1cac04720694f`, and #257 `ea2b5b78868917219c46f1304558b92490a7f6fe`. Each updated tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. #250 and #257 each had one known macOS socket-observation race; their exact focused retries and complete coverage reruns passed. Exact-head review found that #253 still lets three unauthenticated caller booleans mint `OperationallyComplete`; raw teardown claims must remain explicitly unverified until session-bound transport, process-exit, and profile-removal evidence types are issued by their owning runtime boundaries. Hosted exact-head checks and ordered parent integration remain required. Since that observation, #255 has advanced beyond reviewed head `a13de5f9321e72c1867974eb7a43230f031e58df` with an in-progress connection-provenance repair. Its moving current head is live-metadata-only until the complete repair is reverified; neither the predecessor GREEN nor the earlier #256 parent comparison transfers to those commits. - Reviews [#254](https://github.com/ContextualWisdomLab/OriginWeave/pull/254#pullrequestreview-5120077272) at `cbaf50dcc97753cc73135497ea8225e8b18de190` and [#255](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120077213) at `a13de5f9321e72c1867974eb7a43230f031e58df` found a remaining connection-provenance gap. #254 passed six focused closure tests, formatting, strict network Clippy and network rustdoc locally. #255 removes the parent process/profile booleans and keeps overall teardown pending, but a new loopback regression fails when an acknowledgment from connection A is combined with closure from connection B: the assessment reports the acknowledged transport closed. Both connections can use command id 7; #254 retains only closure kind/status and the acknowledgment retains only its command id. Repair the established-stream, frame/message and command-correlation owners to preserve a non-forgeable connection-generation binding, carry it into acknowledgment and closure evidence, then reject mismatches in #255. Different-session and same-session reconnect regressions are required; endpoint equality, command-id equality and caller-supplied markers are insufficient. This is unresolved evidence integrity, not operational-completion authority or shipped behavior. Both PRs remain Draft with hosted checks queued. - PR #258 is Draft at exact head `f2ceabb3ea50b1959e936503c50cae12f3e6e480` on exact #257, and PR #259 is Draft at exact head `e1105ddf86f6c79443af8b4d306b9d34cb703c17` on exact #258. Both final trees passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; fresh hosted exact-head checks and ordered parent integration remain required. - PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. From a13a0b947e76c4f925c305604400f38ed12ed38f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 15:46:45 +0900 Subject: [PATCH 145/250] docs: record received-response provenance and CI retry evidence Keep cross-connection ACK substitution distinct from the sender/closure repair. Record exact Noema retry admission without claiming provider recovery or duplicating queued CodeQL scans. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 2 ++ docs/product-technical-gap-baseline.md | 2 ++ tests/test_gap_snapshot_inventory_consistency.py | 4 ++++ 3 files changed, 8 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index e1ca126f3..d1956b2db 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,8 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded #255's remaining cross-connection response substitution after the sender/closure repair, with a failing real-socket regression and the prerequisite incoming-message binding. +- Separated #219/#240 terminal Noema gateway failures from queued central CodeQL scans; one failed-job retry per unchanged head is admitted, but no provider recovery or passing review is claimed. - Recorded #50's current documentation-repair head and resolved review, preserving predecessor-only full-coverage evidence and the new head's independent hosted-check requirement. - Recorded a reproduced cross-connection teardown-evidence gap in #254/#255 and its prerequisite repair order; another connection's closure must not be reported as closure of the acknowledged connection. - Made the changelog queue-consistency check compare the current baseline counts directly, preventing a duplicated older count from rejecting a verified Ready-to-Draft transition. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index c81c0893d..e57f6a4b7 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -12,6 +12,7 @@ Observed at (UTC): `2026-09-05T06:12:27Z`. - Full live search returns **125 open pull requests: 13 Ready/non-draft and 112 Draft; 13 open non-PR issues**. PR #290 was converted back to Draft after current-protected workflow review found that its #245-relative patch would drop protected #286 lifecycle controls; queue movement is not protected-main delivery. - Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `2bd85188a3b3d798824ac04cf3638df84ac2a8bb`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. PR #290 is Draft at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2`, remains a #245-dependent workflow-owner candidate, and is not a root. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2` and PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd` retain formal `CHANGES_REQUESTED` decisions even though every current review thread is resolved. The decisions remain merge blockers until the governing reviewer state changes; thread resolution alone is not approval and is not grounds to dismiss a review. +- Targeted CI RCA at `2026-09-05T06:45Z` confirmed that #219 Noema run `33925442322` / job `101226941175` and #240 run `33925596923` / job `101227537529` had terminated on gateway HTTP 502 without review verdicts. Neither unchanged exact head had a successor Noema run. One supported failed-job rerun per head created attempt 2, with queued jobs `101264704581` and `101264705575`; Noema attempt 2 is queue-admission evidence, not provider recovery or a review verdict. Successful sampled Noema wrapper runs skipped their review jobs and cannot establish recovery. The CodeQL failures independently record dispatch handoff: #219 central runs `33947047322`, `33947036734`, `33947037072` and #240 runs `33947189162`, `33947189634`, `33947187643` match those exact heads; these central CodeQL dispatches remain queued and were not duplicated. Active Strix runs were left untouched. Revisit these exact attempts after a terminal result; do not create repeated retries while they remain queued. - A fresh repository Actions query at `2026-09-05T06:12:27Z` returned **115 queued workflow runs**; the newest sampled run was #238 CI `33949183271` on predecessor head `bb2f18570f319a763acc24d7c4206ec9d0a11a29`. This is runner-admission/backlog evidence, not a code failure or passing check; rerunning unchanged heads would only add duplicate queue load. The moving PR's exact current head remains live-metadata-only to avoid a non-convergent self-reference. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. @@ -39,6 +40,7 @@ Observed at (UTC): `2026-09-05T06:12:27Z`. - PR #249 is Draft at exact head `017d6e816f5a86544a63821b3ceaba94d5f17f44`, non-force synchronized onto #248 exact `7d6db16b2ead201fcec320854923f90d3ad0d8bc`. Its correlation-state regression no longer creates uncovered assertion-internal failure regions while still proving local preflight retirement and ambiguous-write retention. The current parent and child trees passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; hosted exact-head checks are queued and ordered parent integration remains required. - PRs #250 through #257 remain Draft. The recorded fully locally verified chain used exact heads #250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`, #251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`, #252 `2015259529ada99af836989079cc85a15779a2d8`, #253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`, #254 `cbaf50dcc97753cc73135497ea8225e8b18de190`, #255 `a13de5f9321e72c1867974eb7a43230f031e58df`, #256 `9f2e6f29be46371762e3031a97c1cac04720694f`, and #257 `ea2b5b78868917219c46f1304558b92490a7f6fe`. Each updated tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. #250 and #257 each had one known macOS socket-observation race; their exact focused retries and complete coverage reruns passed. Exact-head review found that #253 still lets three unauthenticated caller booleans mint `OperationallyComplete`; raw teardown claims must remain explicitly unverified until session-bound transport, process-exit, and profile-removal evidence types are issued by their owning runtime boundaries. Hosted exact-head checks and ordered parent integration remain required. Since that observation, #255 has advanced beyond reviewed head `a13de5f9321e72c1867974eb7a43230f031e58df` with an in-progress connection-provenance repair. Its moving current head is live-metadata-only until the complete repair is reverified; neither the predecessor GREEN nor the earlier #256 parent comparison transfers to those commits. - Reviews [#254](https://github.com/ContextualWisdomLab/OriginWeave/pull/254#pullrequestreview-5120077272) at `cbaf50dcc97753cc73135497ea8225e8b18de190` and [#255](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120077213) at `a13de5f9321e72c1867974eb7a43230f031e58df` found a remaining connection-provenance gap. #254 passed six focused closure tests, formatting, strict network Clippy and network rustdoc locally. #255 removes the parent process/profile booleans and keeps overall teardown pending, but a new loopback regression fails when an acknowledgment from connection A is combined with closure from connection B: the assessment reports the acknowledged transport closed. Both connections can use command id 7; #254 retains only closure kind/status and the acknowledgment retains only its command id. Repair the established-stream, frame/message and command-correlation owners to preserve a non-forgeable connection-generation binding, carry it into acknowledgment and closure evidence, then reject mismatches in #255. Different-session and same-session reconnect regressions are required; endpoint equality, command-id equality and caller-supplied markers are insufficient. This is unresolved evidence integrity, not operational-completion authority or shipped behavior. Both PRs remain Draft with hosted checks queued. +- Follow-up review `5120203295` at #255 head `92392b2da33bcd5446c6d2eb1b5504c39e60e3d6` confirms that sender and closure generations now reject independently parsed cross-connection evidence, but received-message provenance must be checked before correlation is consumed. A two-real-socket regression still fails: response B combined with outstanding-command state A becomes acknowledgment A because its generation is copied from the registry, not authenticated against the received text. Preserve private connection evidence through frame reading and message assembly, reject mixed-connection fragments, and compare the received and registered generations before consuming either success or error responses; mismatches must leave the original command outstanding. The [exact-head review and runnable regression](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120203295) remain active repair evidence, not operational-completion authority or protected-main delivery. The writer continues on #255; descendant parent adoption and complete exact-head verification remain pending. - PR #258 is Draft at exact head `f2ceabb3ea50b1959e936503c50cae12f3e6e480` on exact #257, and PR #259 is Draft at exact head `e1105ddf86f6c79443af8b4d306b9d34cb703c17` on exact #258. Both final trees passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; fresh hosted exact-head checks and ordered parent integration remain required. - PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #95 is Draft at exact head `97aa0f2e340ee6fd920d0418f97af276b190554f`, stacked on #93 exact `0664f0452cb329cd692cce7f61f9001652abfda2`. Only `Decision::Allow` creates policy-authorized value; other decisions fail closed, and registry-owned current authority returns `NotAdmitted` after document advance removes the node. The slice performs no browser I/O or postcondition proof. Its 142 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 3db9ed97f..e7f13fd3c 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -53,6 +53,10 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "raw teardown claims must remain explicitly unverified", "#254 `cbaf50dcc97753cc73135497ea8225e8b18de190`", "#255 `a13de5f9321e72c1867974eb7a43230f031e58df`", + "Follow-up review `5120203295` at #255 head `92392b2da33bcd5446c6d2eb1b5504c39e60e3d6`", + "received-message provenance must be checked before correlation is consumed", + "Noema attempt 2 is queue-admission evidence, not provider recovery or a review verdict", + "central CodeQL dispatches remain queued and were not duplicated", "#256 `9f2e6f29be46371762e3031a97c1cac04720694f`", "#257 `ea2b5b78868917219c46f1304558b92490a7f6fe`", "Issue #279", From 9a36ee44ccd2bf5dbbc927b67ebf18f983753439 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 15:54:33 +0900 Subject: [PATCH 146/250] docs: correct PR 285 native CI and replay evidence Record successful exact-head Rust jobs and distinguish security replay admission from terminal scan or lifecycle-trigger repair. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 2 +- tests/test_gap_snapshot_inventory_consistency.py | 2 ++ 3 files changed, 4 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index d1956b2db..be99d70ab 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Corrected #285's stale native-CI pending claim to exact-head Rust and coverage success, and recorded supported replay admission for its three cancelled security workflows without claiming scan results or lifecycle-trigger repair. - Recorded #255's remaining cross-connection response substitution after the sender/closure repair, with a failing real-socket regression and the prerequisite incoming-message binding. - Separated #219/#240 terminal Noema gateway failures from queued central CodeQL scans; one failed-job retry per unchanged head is admitted, but no provider recovery or passing review is claimed. - Recorded #50's current documentation-repair head and resolved review, preserving predecessor-only full-coverage evidence and the new head's independent hosted-check requirement. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e57f6a4b7..062c406f4 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -16,7 +16,7 @@ Observed at (UTC): `2026-09-05T06:12:27Z`. - A fresh repository Actions query at `2026-09-05T06:12:27Z` returned **115 queued workflow runs**; the newest sampled run was #238 CI `33949183271` on predecessor head `bb2f18570f319a763acc24d7c4206ec9d0a11a29`. This is runner-admission/backlog evidence, not a code failure or passing check; rerunning unchanged heads would only add duplicate queue load. The moving PR's exact current head remains live-metadata-only to avoid a non-convergent self-reference. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. -- PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass. Its Ready transition materialized repository-native CI `33930234387`, which remains queued, but did not materialize fresh central required-workflow runs: the only exact-head Security Scan `33924016851`, SAST Semgrep `33924016903`, and CodeQL PR `33924016883` runs came from the earlier Draft event and were cancelled. Missing current lifecycle evidence and the absent eligible approval remain merge blockers; toggling Draft or creating a no-op commit is not an acceptable substitute. +- PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass. Its Ready transition materialized repository-native CI `33930234387`: Rust contracts `101207153048` and Production coverage `101207153244` succeeded by `2026-09-05T03:16:29Z`; native CI success does not replace the seven required central workflows. The Ready event did not materialize fresh central required-workflow runs. Targeted RCA at `2026-09-05T06:53Z` verified that the previously cancelled Security Scan `33924016851`, SAST Semgrep `33924016903`, and CodeQL PR `33924016883` still bind the current head and protected base, with no duplicate central CodeQL dispatch. The convenience CLI failed on a cross-repository workflow lookup before rerunning anything; the supported run-ID REST route then created attempt 2 for all three, with queued scope/language jobs `101265706025`, `101265708882`, and `101265710202`. These are verified replay admissions, not terminal scan results or proof that Ready-event materialization is repaired. Remaining required review evidence and the absent eligible approval still block merge; toggling Draft or creating a no-op commit is not an acceptable substitute. - Issue #279 owns the remaining documentation-CI partitioning gap. PR #287 is Ready at exact head `af83c40dd2990a03064a92ca75430a9cc400f098` on current protected main; it is the workflow-independent classifier foundation, changes no `.github/**` path, and is the prerequisite for an authorized workflow owner. Its predecessor failed its own release-record contract; the current head binds Git rename/copy similarity to blob identity, and its focused and full local suites plus exact 100% Rust coverage pass. Hosted exact-head checks remain queued and no eligible approval exists. PR #282 is Draft at exact head `b64e0708584beff3fb54acf226cb3e667773e473` on current protected main. Its latest workflow/test delta removes `converted_to_draft` and `closed` from the CI event list, removes #286's closed-event guard, and makes the repository contract assert those protections are absent. Exact review `5120043505` therefore requires the authorized #279 owner to reconstruct the valid trusted-base classifier/contract partition while preserving #286's lifecycle and closed+Draft fail-closed controls; Draft checks do not transfer as GREEN. - PR #290 is Draft at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2` on #245 exact `a769f484e2c110e0523b3b28cd21573f43867562`. Its workflow/repository/PR-number concurrency isolation and manual-dispatch non-cancellation intent are valid, but its predecessor-relative MV3 patch would remove protected #286 `converted_to_draft`/`closed` lifecycle events and the closed-event job guard. Exact review `5120039692` and canonical-owner issue #212 comment `5549868655` require reconstruction on the current protected MV3 workflow; the scheduled product writer did not mutate `.github/**`. - PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`, stacked on predecessor #282 head `b54a5856d8201911f05d69622f0d5594a371adf0` rather than current #282 exact `b64e0708584beff3fb54acf226cb3e667773e473`. It must adopt the corrected current parent before its compare can become current evidence. The child remains one prose-only doctoring canary; Draft-hosted jobs are skipped, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index e7f13fd3c..195c19d37 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -80,6 +80,8 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #271 is Draft at exact head `802ec806cdd4560eab48c484f435766ecabda353`", "PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0`", "CI `33930234387`", + "Rust contracts `101207153048` and Production coverage `101207153244` succeeded", + "native CI success does not replace the seven required central workflows", "Security Scan `33924016851`", "SAST Semgrep `33924016903`", "CodeQL PR `33924016883`", From a08b0148822c10c6c6622c8837e1a6f4c9f4d4b0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 16:29:41 +0900 Subject: [PATCH 147/250] docs: record connection repair and fixture integration evidence Separate passing provenance regressions from the remaining exact-snapshot quality failures, record restored documentation reviews, and bind the fixture owner and integrated child to their verified heads. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 2 ++ docs/product-technical-gap-baseline.md | 7 +++++-- tests/test_gap_snapshot_inventory_consistency.py | 6 ++++++ tests/test_product_completion_gap_contract.py | 3 ++- 4 files changed, 15 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index be99d70ab..22bd83510 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,8 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded the shared opening-exchange fixture repair in #242 and its non-force adoption by #243, with full local gates, exact coverage and queued hosted checks kept distinct. +- Recorded #255's passing received-connection regressions alongside its remaining exact-snapshot quality failures, and #139's verified documentation recovery with three resolved review findings. - Corrected #285's stale native-CI pending claim to exact-head Rust and coverage success, and recorded supported replay admission for its three cancelled security workflows without claiming scan results or lifecycle-trigger repair. - Recorded #255's remaining cross-connection response substitution after the sender/closure repair, with a failing real-socket regression and the prerequisite incoming-message binding. - Separated #219/#240 terminal Noema gateway failures from queued central CodeQL scans; one failed-job retry per unchanged head is admitted, but no provider recovery or passing review is claimed. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 062c406f4..1c009aa30 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -35,12 +35,15 @@ Observed at (UTC): `2026-09-05T06:12:27Z`. - PR #270 is Draft at exact head `191a14535219ea8033777fa4c970efb281b62418`, now non-force synchronized onto #269 exact `7854394266d3f292e779193c01413a34f6798d7c`. Its parent-relative transport delta is unchanged; 140 Python contracts, full Rust gates, and exact 100% local production function/line/region/branch coverage pass. Dispatch still proves neither the correlated result nor text-entry success, and fresh hosted exact-head checks plus parent-first integration remain required. - PR #271 is Draft at exact head `802ec806cdd4560eab48c484f435766ecabda353`, non-force synchronized onto #270 exact `191a14535219ea8033777fa4c970efb281b62418`. It admits only the exact typed observation response, treats unequal text as `PostconditionMismatch`, and retains no page-controlled or expected text in public evidence or diagnostics. Its test-first documentation contract, all 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #195 is Draft at exact head `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its loopback regressions hold the accepted peer through opening-write timeout cleanup and locally revoked-stream classification, removing macOS close races without weakening production failures. The original affected test passed 50 consecutive focused regression passes, followed by 139 Python contracts, full Rust gates, and exact 100% local production coverage; fresh hosted exact-head checks and prerequisite integration remain required. -- PR #242 is Draft at exact head `55fef0c3fae1724eddada53e52c4a0311f509aa3`, stacked on #195 exact `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its zero-deadline regression holds the accepted peer until validation completes, so macOS cannot race socket teardown against the intended invalid-input result. Its 139 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. +- Opening-exchange fixture repair at #242 is Draft at exact head `2d0e9f69df9ade21d8e8e3d807c3ff644d83b310`, stacked on #195 exact `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. A complete descendant Rust run reproduced a premature peer-close race in the mismatched-accept fixture after the existing invalid-deadline repair had been adopted. One shared test-only server now reads the complete request before replying and retains the peer through assertions in all three exchange fixtures. Fifty suite runs passed all 250 cases, followed by 139 Python contracts, complete Rust gates and exact 100% local coverage (809 functions, 7802 lines, 9959 regions, 942 branches). Production cleanup errors remain fail-closed. Native CI `33952463254` is queued; repeated local passes do not establish a zero flake rate or hosted acceptance. +- PR #243 adopts that corrected parent by ordinary merge at `97fab641ed9d76e6c515eadcef0629edfc8064a3`, with exact base `2d0e9f69df9ade21d8e8e3d807c3ff644d83b310`. The parent-relative delta preserves the existing bounded frame transport and adds only its integration evidence; the shared fixture is identical to the owner version. All 139 Python contracts, full Rust gates and exact 100% local coverage pass (884 functions, 8733 lines, 11176 regions, 1008 branches). Native CI `33952588687` is queued, and the PR remains Draft. This repairs the previously stale #242-to-#243 dependency edge; later descendants still need ordered parent adoption and their own exact-head verification. - PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 externally advanced to Ready exact head `7d6db16b2ead201fcec320854923f90d3ad0d8bc` after scoping its BiDi release contract to the owned record. The prior local full-suite evidence applies only to predecessor `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`; new hosted checks are queued and must prove the current head independently. - PR #249 is Draft at exact head `017d6e816f5a86544a63821b3ceaba94d5f17f44`, non-force synchronized onto #248 exact `7d6db16b2ead201fcec320854923f90d3ad0d8bc`. Its correlation-state regression no longer creates uncovered assertion-internal failure regions while still proving local preflight retirement and ambiguous-write retention. The current parent and child trees passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; hosted exact-head checks are queued and ordered parent integration remains required. - PRs #250 through #257 remain Draft. The recorded fully locally verified chain used exact heads #250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`, #251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`, #252 `2015259529ada99af836989079cc85a15779a2d8`, #253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`, #254 `cbaf50dcc97753cc73135497ea8225e8b18de190`, #255 `a13de5f9321e72c1867974eb7a43230f031e58df`, #256 `9f2e6f29be46371762e3031a97c1cac04720694f`, and #257 `ea2b5b78868917219c46f1304558b92490a7f6fe`. Each updated tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. #250 and #257 each had one known macOS socket-observation race; their exact focused retries and complete coverage reruns passed. Exact-head review found that #253 still lets three unauthenticated caller booleans mint `OperationallyComplete`; raw teardown claims must remain explicitly unverified until session-bound transport, process-exit, and profile-removal evidence types are issued by their owning runtime boundaries. Hosted exact-head checks and ordered parent integration remain required. Since that observation, #255 has advanced beyond reviewed head `a13de5f9321e72c1867974eb7a43230f031e58df` with an in-progress connection-provenance repair. Its moving current head is live-metadata-only until the complete repair is reverified; neither the predecessor GREEN nor the earlier #256 parent comparison transfers to those commits. - Reviews [#254](https://github.com/ContextualWisdomLab/OriginWeave/pull/254#pullrequestreview-5120077272) at `cbaf50dcc97753cc73135497ea8225e8b18de190` and [#255](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120077213) at `a13de5f9321e72c1867974eb7a43230f031e58df` found a remaining connection-provenance gap. #254 passed six focused closure tests, formatting, strict network Clippy and network rustdoc locally. #255 removes the parent process/profile booleans and keeps overall teardown pending, but a new loopback regression fails when an acknowledgment from connection A is combined with closure from connection B: the assessment reports the acknowledged transport closed. Both connections can use command id 7; #254 retains only closure kind/status and the acknowledgment retains only its command id. Repair the established-stream, frame/message and command-correlation owners to preserve a non-forgeable connection-generation binding, carry it into acknowledgment and closure evidence, then reject mismatches in #255. Different-session and same-session reconnect regressions are required; endpoint equality, command-id equality and caller-supplied markers are insufficient. This is unresolved evidence integrity, not operational-completion authority or shipped behavior. Both PRs remain Draft with hosted checks queued. -- Follow-up review `5120203295` at #255 head `92392b2da33bcd5446c6d2eb1b5504c39e60e3d6` confirms that sender and closure generations now reject independently parsed cross-connection evidence, but received-message provenance must be checked before correlation is consumed. A two-real-socket regression still fails: response B combined with outstanding-command state A becomes acknowledgment A because its generation is copied from the registry, not authenticated against the received text. Preserve private connection evidence through frame reading and message assembly, reject mixed-connection fragments, and compare the received and registered generations before consuming either success or error responses; mismatches must leave the original command outstanding. The [exact-head review and runnable regression](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120203295) remain active repair evidence, not operational-completion authority or protected-main delivery. The writer continues on #255; descendant parent adoption and complete exact-head verification remain pending. +- Follow-up review `5120203295` at #255 head `92392b2da33bcd5446c6d2eb1b5504c39e60e3d6` established that received-message provenance must be checked before correlation is consumed. At that reviewed head, sender/closure generations rejected independently parsed evidence, but the two-real-socket response-substitution regression still failed: response B combined with outstanding-command state A became acknowledgment A because its generation came from the registry rather than the received text. The [exact-head review and runnable regression](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120203295) preserve the RED lineage; the later repair evidence below supersedes this failure only for its explicitly tested snapshot. +- Received-connection verification at #255 head `e7bfec4488b7cb4776df7b546cacb46c8c9eb13e` found that all 12 focused tests passed: the trusted reader retains one non-cloneable stream and assembler through fragments/control messages, the parser rejects a foreign generation before consuming the original command, and cross-connection closure cannot satisfy the acknowledgment. All 141 Python contracts and strict rustdoc passed. Full quality remained incomplete: formatting and Clippy failed, and pinned-nightly coverage rejected lines=11046/11049 and regions=14067/14071 even though functions and branches reached 100%. The first complete stable Rust run also exposed the inherited fixture race; its unchanged retry passed, which was not treated as repair. The fixture root cause is now repaired at #242 and integrated into #243 as recorded above. [Verification and exact uncovered paths](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#issuecomment-5550208364) remain snapshot-specific; later #255 changes, hosted checks and descendant adoption need fresh verification. Overall teardown remains pending and none of this is protected-main delivery. +- PR #139 at `b7ea5bfe336456fb263dd479a60b1cd0193d8a47`, based on #136 `1cffb2e23d4002f12e8462c4c8c24f404a4eeee7`, preserves all inherited documentation and limits its unique delta to the intended cleanup wrapper, regression and changelog. Both indexes retain ADRs 0007–0010 and ADR 0009 remains Proposed. All 179 Python contracts passed; [review evidence](https://github.com/ContextualWisdomLab/OriginWeave/pull/139#issuecomment-5550147096) records all three resolved findings. Current hosted Rust, coverage and pinned-Chromium runs were cancelled, so this Draft has no current hosted or browser-runtime GREEN from that verification. - PR #258 is Draft at exact head `f2ceabb3ea50b1959e936503c50cae12f3e6e480` on exact #257, and PR #259 is Draft at exact head `e1105ddf86f6c79443af8b4d306b9d34cb703c17` on exact #258. Both final trees passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; fresh hosted exact-head checks and ordered parent integration remain required. - PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #95 is Draft at exact head `97aa0f2e340ee6fd920d0418f97af276b190554f`, stacked on #93 exact `0664f0452cb329cd692cce7f61f9001652abfda2`. Only `Decision::Allow` creates policy-authorized value; other decisions fail closed, and registry-owned current authority returns `NotAdmitted` after document advance removes the node. The slice performs no browser I/O or postcondition proof. Its 142 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 195c19d37..bd55e0d16 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -55,6 +55,12 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "#255 `a13de5f9321e72c1867974eb7a43230f031e58df`", "Follow-up review `5120203295` at #255 head `92392b2da33bcd5446c6d2eb1b5504c39e60e3d6`", "received-message provenance must be checked before correlation is consumed", + "Received-connection verification at #255 head `e7bfec4488b7cb4776df7b546cacb46c8c9eb13e`", + "12 focused tests passed", + "lines=11046/11049 and regions=14067/14071", + "PR #139 at `b7ea5bfe336456fb263dd479a60b1cd0193d8a47`", + "Opening-exchange fixture repair at #242", + "PR #243 adopts that corrected parent by ordinary merge", "Noema attempt 2 is queue-admission evidence, not provider recovery or a review verdict", "central CodeQL dispatches remain queued and were not duplicated", "#256 `9f2e6f29be46371762e3031a97c1cac04720694f`", diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index f023cdbba..77ce56f59 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -114,7 +114,8 @@ def test_current_snapshot_records_repaired_webdriver_bidi_lineage(self) -> None: for marker in ( "#195 is Draft at exact head `48eb2d23009c1c804520dd5efcd0d4d072aacef1`", "50 consecutive focused regression passes", - "#242 is Draft at exact head `55fef0c3fae1724eddada53e52c4a0311f509aa3`", + "#242 is Draft at exact head `2d0e9f69df9ade21d8e8e3d807c3ff644d83b310`", + "PR #243 adopts that corrected parent by ordinary merge at `97fab641ed9d76e6c515eadcef0629edfc8064a3`", "#93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`", "SemanticNodeActionBinding", "does not authorize policy or execute input", From 7070d864af2ce959f750b67a1398d46ec5433782 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 16:46:04 +0900 Subject: [PATCH 148/250] docs: record verified message parent and cleanup review Bind the #246 parent integration and complete local coverage to its exact head. Record #141's unchanged-head cleanup diagnostics and informational thread resolution without promoting cancelled hosted checks or local tests to protected delivery. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 2 ++ tests/test_gap_snapshot_inventory_consistency.py | 5 +++++ 3 files changed, 8 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 22bd83510..e9ed9fd29 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded #246's verified parent integration and exact local coverage, plus #141's unchanged-head cleanup review and two resolved informational findings; hosted and protected-main acceptance remain separate. - Recorded the shared opening-exchange fixture repair in #242 and its non-force adoption by #243, with full local gates, exact coverage and queued hosted checks kept distinct. - Recorded #255's passing received-connection regressions alongside its remaining exact-snapshot quality failures, and #139's verified documentation recovery with three resolved review findings. - Corrected #285's stale native-CI pending claim to exact-head Rust and coverage success, and recorded supported replay admission for its three cancelled security workflows without claiming scan results or lifecycle-trigger repair. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 1c009aa30..1b4895cd2 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -37,6 +37,7 @@ Observed at (UTC): `2026-09-05T06:12:27Z`. - PR #195 is Draft at exact head `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its loopback regressions hold the accepted peer through opening-write timeout cleanup and locally revoked-stream classification, removing macOS close races without weakening production failures. The original affected test passed 50 consecutive focused regression passes, followed by 139 Python contracts, full Rust gates, and exact 100% local production coverage; fresh hosted exact-head checks and prerequisite integration remain required. - Opening-exchange fixture repair at #242 is Draft at exact head `2d0e9f69df9ade21d8e8e3d807c3ff644d83b310`, stacked on #195 exact `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. A complete descendant Rust run reproduced a premature peer-close race in the mismatched-accept fixture after the existing invalid-deadline repair had been adopted. One shared test-only server now reads the complete request before replying and retains the peer through assertions in all three exchange fixtures. Fifty suite runs passed all 250 cases, followed by 139 Python contracts, complete Rust gates and exact 100% local coverage (809 functions, 7802 lines, 9959 regions, 942 branches). Production cleanup errors remain fail-closed. Native CI `33952463254` is queued; repeated local passes do not establish a zero flake rate or hosted acceptance. - PR #243 adopts that corrected parent by ordinary merge at `97fab641ed9d76e6c515eadcef0629edfc8064a3`, with exact base `2d0e9f69df9ade21d8e8e3d807c3ff644d83b310`. The parent-relative delta preserves the existing bounded frame transport and adds only its integration evidence; the shared fixture is identical to the owner version. All 139 Python contracts, full Rust gates and exact 100% local coverage pass (884 functions, 8733 lines, 11176 regions, 1008 branches). Native CI `33952588687` is queued, and the PR remains Draft. This repairs the previously stale #242-to-#243 dependency edge; later descendants still need ordered parent adoption and their own exact-head verification. +- PR #246 adopts #243 at `585791f3641fbe757c3bd9fd36d5316adcc78d63`, with exact parent `97fab641ed9d76e6c515eadcef0629edfc8064a3`. Its ordinary merge preserves the message/JSON source and test blobs while carrying the owner fixture repairs. All 141 Python contracts, complete Rust gates and exact 100% pinned-nightly local coverage pass (962 functions, 9701 lines, 12427 regions, 1084 branches). Native CI `33953247053` is queued and this PR remains Draft. Fifty pre-integration fixture-suite runs passed, so no newly reproduced failure or measured failure-rate improvement is claimed. Raw protocol messages still carry no received-connection provenance or browser authority; child integration and hosted acceptance remain pending. - PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 externally advanced to Ready exact head `7d6db16b2ead201fcec320854923f90d3ad0d8bc` after scoping its BiDi release contract to the owned record. The prior local full-suite evidence applies only to predecessor `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`; new hosted checks are queued and must prove the current head independently. - PR #249 is Draft at exact head `017d6e816f5a86544a63821b3ceaba94d5f17f44`, non-force synchronized onto #248 exact `7d6db16b2ead201fcec320854923f90d3ad0d8bc`. Its correlation-state regression no longer creates uncovered assertion-internal failure regions while still proving local preflight retirement and ambiguous-write retention. The current parent and child trees passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; hosted exact-head checks are queued and ordered parent integration remains required. - PRs #250 through #257 remain Draft. The recorded fully locally verified chain used exact heads #250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`, #251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`, #252 `2015259529ada99af836989079cc85a15779a2d8`, #253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`, #254 `cbaf50dcc97753cc73135497ea8225e8b18de190`, #255 `a13de5f9321e72c1867974eb7a43230f031e58df`, #256 `9f2e6f29be46371762e3031a97c1cac04720694f`, and #257 `ea2b5b78868917219c46f1304558b92490a7f6fe`. Each updated tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. #250 and #257 each had one known macOS socket-observation race; their exact focused retries and complete coverage reruns passed. Exact-head review found that #253 still lets three unauthenticated caller booleans mint `OperationallyComplete`; raw teardown claims must remain explicitly unverified until session-bound transport, process-exit, and profile-removal evidence types are issued by their owning runtime boundaries. Hosted exact-head checks and ordered parent integration remain required. Since that observation, #255 has advanced beyond reviewed head `a13de5f9321e72c1867974eb7a43230f031e58df` with an in-progress connection-provenance repair. Its moving current head is live-metadata-only until the complete repair is reverified; neither the predecessor GREEN nor the earlier #256 parent comparison transfers to those commits. @@ -44,6 +45,7 @@ Observed at (UTC): `2026-09-05T06:12:27Z`. - Follow-up review `5120203295` at #255 head `92392b2da33bcd5446c6d2eb1b5504c39e60e3d6` established that received-message provenance must be checked before correlation is consumed. At that reviewed head, sender/closure generations rejected independently parsed evidence, but the two-real-socket response-substitution regression still failed: response B combined with outstanding-command state A became acknowledgment A because its generation came from the registry rather than the received text. The [exact-head review and runnable regression](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120203295) preserve the RED lineage; the later repair evidence below supersedes this failure only for its explicitly tested snapshot. - Received-connection verification at #255 head `e7bfec4488b7cb4776df7b546cacb46c8c9eb13e` found that all 12 focused tests passed: the trusted reader retains one non-cloneable stream and assembler through fragments/control messages, the parser rejects a foreign generation before consuming the original command, and cross-connection closure cannot satisfy the acknowledgment. All 141 Python contracts and strict rustdoc passed. Full quality remained incomplete: formatting and Clippy failed, and pinned-nightly coverage rejected lines=11046/11049 and regions=14067/14071 even though functions and branches reached 100%. The first complete stable Rust run also exposed the inherited fixture race; its unchanged retry passed, which was not treated as repair. The fixture root cause is now repaired at #242 and integrated into #243 as recorded above. [Verification and exact uncovered paths](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#issuecomment-5550208364) remain snapshot-specific; later #255 changes, hosted checks and descendant adoption need fresh verification. Overall teardown remains pending and none of this is protected-main delivery. - PR #139 at `b7ea5bfe336456fb263dd479a60b1cd0193d8a47`, based on #136 `1cffb2e23d4002f12e8462c4c8c24f404a4eeee7`, preserves all inherited documentation and limits its unique delta to the intended cleanup wrapper, regression and changelog. Both indexes retain ADRs 0007–0010 and ADR 0009 remains Proposed. All 179 Python contracts passed; [review evidence](https://github.com/ContextualWisdomLab/OriginWeave/pull/139#issuecomment-5550147096) records all three resolved findings. Current hosted Rust, coverage and pinned-Chromium runs were cancelled, so this Draft has no current hosted or browser-runtime GREEN from that verification. +- PR #141 at `fbdf64f5818ce0c53b475196d5bcfa2ac9900846`, based on #139 `b7ea5bfe336456fb263dd479a60b1cd0193d8a47`, retains the reviewed failure/surface/timeout cleanup contracts. All 183 Python contracts passed; controlled probes confirmed that unexpected exceptions propagate after temporary-profile removal and cleanup-exit failures cannot return false cleanup evidence. The remaining two informational threads were resolved without source changes, leaving all four threads resolved; [review evidence](https://github.com/ContextualWisdomLab/OriginWeave/pull/141#issuecomment-5550364179) binds these results to the unchanged head. Hosted CI `33916583623` and pinned-Chromium run `33916583506` were cancelled. This is not current browser-runtime GREEN, adversarial erasure proof, counted approval or protected-main delivery; the PR remains Draft. - PR #258 is Draft at exact head `f2ceabb3ea50b1959e936503c50cae12f3e6e480` on exact #257, and PR #259 is Draft at exact head `e1105ddf86f6c79443af8b4d306b9d34cb703c17` on exact #258. Both final trees passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; fresh hosted exact-head checks and ordered parent integration remain required. - PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #95 is Draft at exact head `97aa0f2e340ee6fd920d0418f97af276b190554f`, stacked on #93 exact `0664f0452cb329cd692cce7f61f9001652abfda2`. Only `Decision::Allow` creates policy-authorized value; other decisions fail closed, and registry-owned current authority returns `NotAdmitted` after document advance removes the node. The slice performs no browser I/O or postcondition proof. Its 142 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index bd55e0d16..c37856ae4 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -61,6 +61,11 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #139 at `b7ea5bfe336456fb263dd479a60b1cd0193d8a47`", "Opening-exchange fixture repair at #242", "PR #243 adopts that corrected parent by ordinary merge", + "PR #246 adopts #243 at `585791f3641fbe757c3bd9fd36d5316adcc78d63`", + "962 functions, 9701 lines, 12427 regions, 1084 branches", + "PR #141 at `fbdf64f5818ce0c53b475196d5bcfa2ac9900846`", + "183 Python contracts passed", + "two informational threads were resolved without source changes", "Noema attempt 2 is queue-admission evidence, not provider recovery or a review verdict", "central CodeQL dispatches remain queued and were not duplicated", "#256 `9f2e6f29be46371762e3031a97c1cac04720694f`", From af0d8e69d557e67de51e70429ca7839ac5419257 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 16:55:27 +0900 Subject: [PATCH 149/250] docs: record correlation discovery repair and current stack Update the live queue to 12 Ready and 113 Draft PRs after #248's parent repair. Preserve the zero-test RED, exact local gates and coverage, current parent lineage, and #249's remaining dependency adoption without claiming hosted or protected delivery. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 7 ++++--- docs/product-technical-gap-baseline.md | 10 +++++----- tests/test_gap_snapshot_inventory_consistency.py | 11 +++++++---- 3 files changed, 16 insertions(+), 12 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index e9ed9fd29..86cff0ba7 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Repaired #248's uncollected release-record test and obsolete merged-parent dependency; recorded 142 passing Python contracts, full local Rust gates and exact coverage while preserving Draft and hosted-check boundaries. - Recorded #246's verified parent integration and exact local coverage, plus #141's unchanged-head cleanup review and two resolved informational findings; hosted and protected-main acceptance remain separate. - Recorded the shared opening-exchange fixture repair in #242 and its non-force adoption by #243, with full local gates, exact coverage and queued hosted checks kept distinct. - Recorded #255's passing received-connection regressions alongside its remaining exact-snapshot quality failures, and #139's verified documentation recovery with three resolved review findings. @@ -19,13 +20,13 @@ All notable changes to OriginWeave are documented in this file. The format follo - Recorded PR #285's Ready-event materialization gap: repository-native exact-head CI restarted, while the earlier central Security, Semgrep, and CodeQL runs remained cancelled and no fresh required-workflow replacements appeared. - Refreshed the live product-gap baseline with PR #37's RFC 9110 `205 Reset Content` repair head and exact local verification evidence. - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. -- Refreshed the product-gap queue to 125 open pull requests (13 ready, 112 draft) and 13 open non-PR issues on 2026-09-05; queue movement is active-PR evidence, not protected-main shipment. -- Recorded the current Ready-root heads for #37, #50, #166, #219, #220, #229, #240, #248, #272, #274, #285, and #287; Draft #290 remains a #245-dependent workflow-owner candidate, #238's moving self-reference is delegated to live PR metadata, hosted exact-head checks remain non-terminal, and counted approval remains absent. +- Refreshed the product-gap queue to 125 open pull requests (12 ready, 113 draft) and 13 open non-PR issues on 2026-09-05; queue movement is active-PR evidence, not protected-main shipment. +- Recorded the current Ready-root heads for #37, #50, #166, #219, #220, #229, #240, #272, #274, #285, and #287; Draft #290 remains a #245-dependent workflow-owner candidate, #238's moving self-reference is delegated to live PR metadata, hosted exact-head checks remain non-terminal, and counted approval remains absent. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. ### Added -- Revalidated the product-gap queue at 125 open pull requests (13 ready, 112 draft) and 13 open non-PR issues on 2026-09-05; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Ready at `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, WebDriver BiDi document-advance PR #260 is Draft at `3a651967c421f77088fe25e86a63faae295390b3`, denial-error PR #166 is Ready at `e84a1a2cc82b1c666218efd441da97849f47b8c2`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 has merged into its unprotected parent and successor #248 is Ready at `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, DDD/MCP repair #272 is Ready at `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, governance repair #285 is Ready at `f455c2cd64b3dd3f027c91d396103792a205ddd0`, subscription repair #277 is Draft at `01038ba71fb276426cc67f90a91a3c431e194db5`, classifier foundation #287 is Ready at `af83c40dd2990a03064a92ca75430a9cc400f098`, workflow-free Agent Task successor #288 is Draft at `39e36256651f62940ec3ca6149067f0cfcb2285a`, and workflow-owner candidate #290 is Draft at `ebeefcd534db4324498fdb18046ebc6255ddcdf2`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. +- Revalidated the product-gap queue at 125 open pull requests (12 ready, 113 draft) and 13 open non-PR issues on 2026-09-05; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Ready at `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, WebDriver BiDi document-advance PR #260 is Draft at `3a651967c421f77088fe25e86a63faae295390b3`, denial-error PR #166 is Ready at `e84a1a2cc82b1c666218efd441da97849f47b8c2`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 has merged into its unprotected parent and successor #248 is Draft at `b386f17c4826adabebda084bff2fba35aee94dd0`, DDD/MCP repair #272 is Ready at `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, governance repair #285 is Ready at `f455c2cd64b3dd3f027c91d396103792a205ddd0`, subscription repair #277 is Draft at `01038ba71fb276426cc67f90a91a3c431e194db5`, classifier foundation #287 is Ready at `af83c40dd2990a03064a92ca75430a9cc400f098`, workflow-free Agent Task successor #288 is Draft at `39e36256651f62940ec3ca6149067f0cfcb2285a`, and workflow-owner candidate #290 is Draft at `ebeefcd534db4324498fdb18046ebc6255ddcdf2`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 1b4895cd2..691bebd0c 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,11 +6,11 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T06:12:27Z`. +Observed at (UTC): `2026-09-05T07:54:18Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. -- Full live search returns **125 open pull requests: 13 Ready/non-draft and 112 Draft; 13 open non-PR issues**. PR #290 was converted back to Draft after current-protected workflow review found that its #245-relative patch would drop protected #286 lifecycle controls; queue movement is not protected-main delivery. -- Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `2bd85188a3b3d798824ac04cf3638df84ac2a8bb`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. PR #290 is Draft at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2`, remains a #245-dependent workflow-owner candidate, and is not a root. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Full live search returns **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. PR #290 was converted back to Draft after current-protected workflow review found that its #245-relative patch would drop protected #286 lifecycle controls; queue movement is not protected-main delivery. PR #248 also returned to Draft for current-parent adoption and complete revalidation; no PR was closed. +- Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `2bd85188a3b3d798824ac04cf3638df84ac2a8bb`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. PR #290 is Draft at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2`, remains a #245-dependent workflow-owner candidate, and is not a root. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2` and PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd` retain formal `CHANGES_REQUESTED` decisions even though every current review thread is resolved. The decisions remain merge blockers until the governing reviewer state changes; thread resolution alone is not approval and is not grounds to dismiss a review. - Targeted CI RCA at `2026-09-05T06:45Z` confirmed that #219 Noema run `33925442322` / job `101226941175` and #240 run `33925596923` / job `101227537529` had terminated on gateway HTTP 502 without review verdicts. Neither unchanged exact head had a successor Noema run. One supported failed-job rerun per head created attempt 2, with queued jobs `101264704581` and `101264705575`; Noema attempt 2 is queue-admission evidence, not provider recovery or a review verdict. Successful sampled Noema wrapper runs skipped their review jobs and cannot establish recovery. The CodeQL failures independently record dispatch handoff: #219 central runs `33947047322`, `33947036734`, `33947037072` and #240 runs `33947189162`, `33947189634`, `33947187643` match those exact heads; these central CodeQL dispatches remain queued and were not duplicated. Active Strix runs were left untouched. Revisit these exact attempts after a terminal result; do not create repeated retries while they remain queued. - A fresh repository Actions query at `2026-09-05T06:12:27Z` returned **115 queued workflow runs**; the newest sampled run was #238 CI `33949183271` on predecessor head `bb2f18570f319a763acc24d7c4206ec9d0a11a29`. This is runner-admission/backlog evidence, not a code failure or passing check; rerunning unchanged heads would only add duplicate queue load. The moving PR's exact current head remains live-metadata-only to avoid a non-convergent self-reference. @@ -38,8 +38,8 @@ Observed at (UTC): `2026-09-05T06:12:27Z`. - Opening-exchange fixture repair at #242 is Draft at exact head `2d0e9f69df9ade21d8e8e3d807c3ff644d83b310`, stacked on #195 exact `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. A complete descendant Rust run reproduced a premature peer-close race in the mismatched-accept fixture after the existing invalid-deadline repair had been adopted. One shared test-only server now reads the complete request before replying and retains the peer through assertions in all three exchange fixtures. Fifty suite runs passed all 250 cases, followed by 139 Python contracts, complete Rust gates and exact 100% local coverage (809 functions, 7802 lines, 9959 regions, 942 branches). Production cleanup errors remain fail-closed. Native CI `33952463254` is queued; repeated local passes do not establish a zero flake rate or hosted acceptance. - PR #243 adopts that corrected parent by ordinary merge at `97fab641ed9d76e6c515eadcef0629edfc8064a3`, with exact base `2d0e9f69df9ade21d8e8e3d807c3ff644d83b310`. The parent-relative delta preserves the existing bounded frame transport and adds only its integration evidence; the shared fixture is identical to the owner version. All 139 Python contracts, full Rust gates and exact 100% local coverage pass (884 functions, 8733 lines, 11176 regions, 1008 branches). Native CI `33952588687` is queued, and the PR remains Draft. This repairs the previously stale #242-to-#243 dependency edge; later descendants still need ordered parent adoption and their own exact-head verification. - PR #246 adopts #243 at `585791f3641fbe757c3bd9fd36d5316adcc78d63`, with exact parent `97fab641ed9d76e6c515eadcef0629edfc8064a3`. Its ordinary merge preserves the message/JSON source and test blobs while carrying the owner fixture repairs. All 141 Python contracts, complete Rust gates and exact 100% pinned-nightly local coverage pass (962 functions, 9701 lines, 12427 regions, 1084 branches). Native CI `33953247053` is queued and this PR remains Draft. Fifty pre-integration fixture-suite runs passed, so no newly reproduced failure or measured failure-rate improvement is claimed. Raw protocol messages still carry no received-connection provenance or browser authority; child integration and hosted acceptance remain pending. -- PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 externally advanced to Ready exact head `7d6db16b2ead201fcec320854923f90d3ad0d8bc` after scoping its BiDi release contract to the owned record. The prior local full-suite evidence applies only to predecessor `de7754aaeb97ccb0fd47bcbe1c4d99c10eaf84eb`; new hosted checks are queued and must prove the current head independently. -- PR #249 is Draft at exact head `017d6e816f5a86544a63821b3ceaba94d5f17f44`, non-force synchronized onto #248 exact `7d6db16b2ead201fcec320854923f90d3ad0d8bc`. Its correlation-state regression no longer creates uncovered assertion-internal failure regions while still proving local preflight retirement and ambiguous-write retention. The current parent and child trees passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; hosted exact-head checks are queued and ordered parent integration remains required. +- PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 is Draft at `b386f17c4826adabebda084bff2fba35aee94dd0`, now based on #246 `585791f3641fbe757c3bd9fd36d5316adcc78d63` by ordinary merge and explicit retargeting away from the merged #247 branch. Correlation production and Rust test blobs remain unchanged. Review reproduced that native unittest discovery collected zero checks from the free-function release contract; the same assertions now use the repository's TestCase format, collect one check and reject a missing release record. All 142 Python contracts, full Rust gates and exact 100% pinned-nightly local coverage pass (975 functions, 9848 lines, 12563 regions, 1092 branches). Native CI `33953719566` is queued. Previous Ready status and local totals did not prove enforcement of the uncollected check; current hosted verification, protected parents and received-connection authority remain unproven. +- PR #249 is Draft at exact head `017d6e816f5a86544a63821b3ceaba94d5f17f44`. Its previous non-force synchronization used #248 predecessor `7d6db16b2ead201fcec320854923f90d3ad0d8bc`; it still needs current #248 `b386f17c4826adabebda084bff2fba35aee94dd0` adoption. The earlier correlation-state regression preserved local preflight retirement and ambiguous-write retention while removing uncovered assertion-internal failure regions. Its recorded 141 Python contracts, full Rust gates and exact 100% local coverage apply to that previous tree only, before the parent's release-test discovery repair. Hosted exact-head checks and ordered parent integration remain required. - PRs #250 through #257 remain Draft. The recorded fully locally verified chain used exact heads #250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`, #251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`, #252 `2015259529ada99af836989079cc85a15779a2d8`, #253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`, #254 `cbaf50dcc97753cc73135497ea8225e8b18de190`, #255 `a13de5f9321e72c1867974eb7a43230f031e58df`, #256 `9f2e6f29be46371762e3031a97c1cac04720694f`, and #257 `ea2b5b78868917219c46f1304558b92490a7f6fe`. Each updated tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. #250 and #257 each had one known macOS socket-observation race; their exact focused retries and complete coverage reruns passed. Exact-head review found that #253 still lets three unauthenticated caller booleans mint `OperationallyComplete`; raw teardown claims must remain explicitly unverified until session-bound transport, process-exit, and profile-removal evidence types are issued by their owning runtime boundaries. Hosted exact-head checks and ordered parent integration remain required. Since that observation, #255 has advanced beyond reviewed head `a13de5f9321e72c1867974eb7a43230f031e58df` with an in-progress connection-provenance repair. Its moving current head is live-metadata-only until the complete repair is reverified; neither the predecessor GREEN nor the earlier #256 parent comparison transfers to those commits. - Reviews [#254](https://github.com/ContextualWisdomLab/OriginWeave/pull/254#pullrequestreview-5120077272) at `cbaf50dcc97753cc73135497ea8225e8b18de190` and [#255](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120077213) at `a13de5f9321e72c1867974eb7a43230f031e58df` found a remaining connection-provenance gap. #254 passed six focused closure tests, formatting, strict network Clippy and network rustdoc locally. #255 removes the parent process/profile booleans and keeps overall teardown pending, but a new loopback regression fails when an acknowledgment from connection A is combined with closure from connection B: the assessment reports the acknowledged transport closed. Both connections can use command id 7; #254 retains only closure kind/status and the acknowledgment retains only its command id. Repair the established-stream, frame/message and command-correlation owners to preserve a non-forgeable connection-generation binding, carry it into acknowledgment and closure evidence, then reject mismatches in #255. Different-session and same-session reconnect regressions are required; endpoint equality, command-id equality and caller-supplied markers are insufficient. This is unresolved evidence integrity, not operational-completion authority or shipped behavior. Both PRs remain Draft with hosted checks queued. - Follow-up review `5120203295` at #255 head `92392b2da33bcd5446c6d2eb1b5504c39e60e3d6` established that received-message provenance must be checked before correlation is consumed. At that reviewed head, sender/closure generations rejected independently parsed evidence, but the two-real-socket response-substitution regression still failed: response B combined with outstanding-command state A became acknowledgment A because its generation came from the registry rather than the received text. The [exact-head review and runnable regression](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120203295) preserve the RED lineage; the later repair evidence below supersedes this failure only for its explicitly tested snapshot. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index c37856ae4..66007aced 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -27,15 +27,15 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: )[0] for marker in ( "125 open pull requests", - "13 Ready/non-draft", - "112 Draft", + "12 Ready/non-draft", + "113 Draft", "13 open non-PR issues", "87c4daa1830bac5a5228b6036752ad5633232085", "18156473", "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `2bd85188a3b3d798824ac04cf3638df84ac2a8bb`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #248 `7d6db16b2ead201fcec320854923f90d3ad0d8bc`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", + "Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `2bd85188a3b3d798824ac04cf3638df84ac2a8bb`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", "PR #290 is Draft at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2`", "PR #238's moving exact head is intentionally omitted", "PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2`", @@ -62,6 +62,9 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "Opening-exchange fixture repair at #242", "PR #243 adopts that corrected parent by ordinary merge", "PR #246 adopts #243 at `585791f3641fbe757c3bd9fd36d5316adcc78d63`", + "PR #248 is Draft at `b386f17c4826adabebda084bff2fba35aee94dd0`", + "native unittest discovery collected zero checks", + "975 functions, 9848 lines, 12563 regions, 1092 branches", "962 functions, 9701 lines, 12427 regions, 1084 branches", "PR #141 at `fbdf64f5818ce0c53b475196d5bcfa2ac9900846`", "183 Python contracts passed", @@ -180,7 +183,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "125 open pull requests (13 ready, 112 draft)" + expected = "125 open pull requests (12 ready, 113 draft)" self.assertIn(expected, preamble) self.assertIn("13 open non-PR issues", preamble) self.assertIn(expected, added) From 2d7e31d91009986a6e4fc49c1d7ac8ca5ff30396 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 17:22:47 +0900 Subject: [PATCH 150/250] docs(product): refresh integration and cleanup review evidence Record #249 parent adoption, #142/#143 verified failure boundaries, and the exact #255 remaining quality failures. Preserve historical snapshots and separate local proof from hosted acceptance. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 2 ++ docs/product-technical-gap-baseline.md | 7 +++++-- tests/test_gap_snapshot_inventory_consistency.py | 12 +++++++++++- 3 files changed, 18 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 86cff0ba7..06aa673cf 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -26,6 +26,8 @@ All notable changes to OriginWeave are documented in this file. The format follo - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. ### Added + +- Recorded the verified #249 parent integration, #142/#143 failure-cleanup review evidence, and #255's remaining formatting/lint/coverage failures, keeping local results distinct from pending browser/hosted acceptance. - Revalidated the product-gap queue at 125 open pull requests (12 ready, 113 draft) and 13 open non-PR issues on 2026-09-05; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Ready at `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, WebDriver BiDi document-advance PR #260 is Draft at `3a651967c421f77088fe25e86a63faae295390b3`, denial-error PR #166 is Ready at `e84a1a2cc82b1c666218efd441da97849f47b8c2`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 has merged into its unprotected parent and successor #248 is Draft at `b386f17c4826adabebda084bff2fba35aee94dd0`, DDD/MCP repair #272 is Ready at `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, governance repair #285 is Ready at `f455c2cd64b3dd3f027c91d396103792a205ddd0`, subscription repair #277 is Draft at `01038ba71fb276426cc67f90a91a3c431e194db5`, classifier foundation #287 is Ready at `af83c40dd2990a03064a92ca75430a9cc400f098`, workflow-free Agent Task successor #288 is Draft at `39e36256651f62940ec3ca6149067f0cfcb2285a`, and workflow-owner candidate #290 is Draft at `ebeefcd534db4324498fdb18046ebc6255ddcdf2`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 691bebd0c..2d497d1b9 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,7 +6,7 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T07:54:18Z`. +Observed at (UTC): `2026-09-05T08:18:00Z` (full inventory); targeted verification through `2026-09-05T08:20:00Z`. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. PR #290 was converted back to Draft after current-protected workflow review found that its #245-relative patch would drop protected #286 lifecycle controls; queue movement is not protected-main delivery. PR #248 also returned to Draft for current-parent adoption and complete revalidation; no PR was closed. @@ -39,13 +39,16 @@ Observed at (UTC): `2026-09-05T07:54:18Z`. - PR #243 adopts that corrected parent by ordinary merge at `97fab641ed9d76e6c515eadcef0629edfc8064a3`, with exact base `2d0e9f69df9ade21d8e8e3d807c3ff644d83b310`. The parent-relative delta preserves the existing bounded frame transport and adds only its integration evidence; the shared fixture is identical to the owner version. All 139 Python contracts, full Rust gates and exact 100% local coverage pass (884 functions, 8733 lines, 11176 regions, 1008 branches). Native CI `33952588687` is queued, and the PR remains Draft. This repairs the previously stale #242-to-#243 dependency edge; later descendants still need ordered parent adoption and their own exact-head verification. - PR #246 adopts #243 at `585791f3641fbe757c3bd9fd36d5316adcc78d63`, with exact parent `97fab641ed9d76e6c515eadcef0629edfc8064a3`. Its ordinary merge preserves the message/JSON source and test blobs while carrying the owner fixture repairs. All 141 Python contracts, complete Rust gates and exact 100% pinned-nightly local coverage pass (962 functions, 9701 lines, 12427 regions, 1084 branches). Native CI `33953247053` is queued and this PR remains Draft. Fifty pre-integration fixture-suite runs passed, so no newly reproduced failure or measured failure-rate improvement is claimed. Raw protocol messages still carry no received-connection provenance or browser authority; child integration and hosted acceptance remain pending. - PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 is Draft at `b386f17c4826adabebda084bff2fba35aee94dd0`, now based on #246 `585791f3641fbe757c3bd9fd36d5316adcc78d63` by ordinary merge and explicit retargeting away from the merged #247 branch. Correlation production and Rust test blobs remain unchanged. Review reproduced that native unittest discovery collected zero checks from the free-function release contract; the same assertions now use the repository's TestCase format, collect one check and reject a missing release record. All 142 Python contracts, full Rust gates and exact 100% pinned-nightly local coverage pass (975 functions, 9848 lines, 12563 regions, 1092 branches). Native CI `33953719566` is queued. Previous Ready status and local totals did not prove enforcement of the uncollected check; current hosted verification, protected parents and received-connection authority remain unproven. -- PR #249 is Draft at exact head `017d6e816f5a86544a63821b3ceaba94d5f17f44`. Its previous non-force synchronization used #248 predecessor `7d6db16b2ead201fcec320854923f90d3ad0d8bc`; it still needs current #248 `b386f17c4826adabebda084bff2fba35aee94dd0` adoption. The earlier correlation-state regression preserved local preflight retirement and ambiguous-write retention while removing uncovered assertion-internal failure regions. Its recorded 141 Python contracts, full Rust gates and exact 100% local coverage apply to that previous tree only, before the parent's release-test discovery repair. Hosted exact-head checks and ordered parent integration remain required. +- PR #249 is Draft at exact head `84b9407978ae0f6c115f01170b6069c601b21104`, ordinarily merged onto current #248 `b386f17c4826adabebda084bff2fba35aee94dd0`. The old `017d6e816f5a86544a63821b3ceaba94d5f17f44` tree lacked that parent and its newly discoverable release check; the parent adoption also reproduced a CHANGELOG-only merge conflict. The integration retains both release records, the parent's canonical opening fixture and native TestCase, and all four child-owned production/Rust-test blobs unchanged. All 142 Python contracts, the full Rust 1.97.1 gates and pinned-nightly 100% coverage pass locally: 989 functions, 9978 lines, 12717 regions, 1098 branches. Fresh exact-head CI `33954334610` is pending, not acceptance. #250 must adopt this parent before its comparison is current. - PRs #250 through #257 remain Draft. The recorded fully locally verified chain used exact heads #250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`, #251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`, #252 `2015259529ada99af836989079cc85a15779a2d8`, #253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`, #254 `cbaf50dcc97753cc73135497ea8225e8b18de190`, #255 `a13de5f9321e72c1867974eb7a43230f031e58df`, #256 `9f2e6f29be46371762e3031a97c1cac04720694f`, and #257 `ea2b5b78868917219c46f1304558b92490a7f6fe`. Each updated tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. #250 and #257 each had one known macOS socket-observation race; their exact focused retries and complete coverage reruns passed. Exact-head review found that #253 still lets three unauthenticated caller booleans mint `OperationallyComplete`; raw teardown claims must remain explicitly unverified until session-bound transport, process-exit, and profile-removal evidence types are issued by their owning runtime boundaries. Hosted exact-head checks and ordered parent integration remain required. Since that observation, #255 has advanced beyond reviewed head `a13de5f9321e72c1867974eb7a43230f031e58df` with an in-progress connection-provenance repair. Its moving current head is live-metadata-only until the complete repair is reverified; neither the predecessor GREEN nor the earlier #256 parent comparison transfers to those commits. - Reviews [#254](https://github.com/ContextualWisdomLab/OriginWeave/pull/254#pullrequestreview-5120077272) at `cbaf50dcc97753cc73135497ea8225e8b18de190` and [#255](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120077213) at `a13de5f9321e72c1867974eb7a43230f031e58df` found a remaining connection-provenance gap. #254 passed six focused closure tests, formatting, strict network Clippy and network rustdoc locally. #255 removes the parent process/profile booleans and keeps overall teardown pending, but a new loopback regression fails when an acknowledgment from connection A is combined with closure from connection B: the assessment reports the acknowledged transport closed. Both connections can use command id 7; #254 retains only closure kind/status and the acknowledgment retains only its command id. Repair the established-stream, frame/message and command-correlation owners to preserve a non-forgeable connection-generation binding, carry it into acknowledgment and closure evidence, then reject mismatches in #255. Different-session and same-session reconnect regressions are required; endpoint equality, command-id equality and caller-supplied markers are insufficient. This is unresolved evidence integrity, not operational-completion authority or shipped behavior. Both PRs remain Draft with hosted checks queued. - Follow-up review `5120203295` at #255 head `92392b2da33bcd5446c6d2eb1b5504c39e60e3d6` established that received-message provenance must be checked before correlation is consumed. At that reviewed head, sender/closure generations rejected independently parsed evidence, but the two-real-socket response-substitution regression still failed: response B combined with outstanding-command state A became acknowledgment A because its generation came from the registry rather than the received text. The [exact-head review and runnable regression](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120203295) preserve the RED lineage; the later repair evidence below supersedes this failure only for its explicitly tested snapshot. - Received-connection verification at #255 head `e7bfec4488b7cb4776df7b546cacb46c8c9eb13e` found that all 12 focused tests passed: the trusted reader retains one non-cloneable stream and assembler through fragments/control messages, the parser rejects a foreign generation before consuming the original command, and cross-connection closure cannot satisfy the acknowledgment. All 141 Python contracts and strict rustdoc passed. Full quality remained incomplete: formatting and Clippy failed, and pinned-nightly coverage rejected lines=11046/11049 and regions=14067/14071 even though functions and branches reached 100%. The first complete stable Rust run also exposed the inherited fixture race; its unchanged retry passed, which was not treated as repair. The fixture root cause is now repaired at #242 and integrated into #243 as recorded above. [Verification and exact uncovered paths](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#issuecomment-5550208364) remain snapshot-specific; later #255 changes, hosted checks and descendant adoption need fresh verification. Overall teardown remains pending and none of this is protected-main delivery. +- Follow-up quality verification at #255 head `63cbca0a98cf9496af981819d98029e656fc4342` completed locally at `2026-09-05T08:20Z`: 141 Python contracts, compileall and the complete Rust 1.97.1 tests passed. Formatting still failed, and strict Clippy rejected an unused private accessor left after the impossible provenance fallback was removed. Workspace check and strict rustdoc completed with that compiler warning. Pinned-nightly coverage enforcement failed at functions=1082/1083, lines=11046/11051, regions=14071/14074; branches=1202/1202. The missing-lines report identifies only the obsolete accessor's five lines; prior event/null-id and generation-exhaustion gaps are covered. The minimal owner correction is removal of that uncalled accessor plus actual pinned rustfmt, preserving received-connection validation and rejecting warning/coverage exclusions. All read-only validation handles are terminal and the existing #255 source owner has the diagnostics; no competing source change was made. Exact CI `33953476003` remains pending. These results supersede the earlier local snapshot only at this tested head, not at later repairs or protected main. - PR #139 at `b7ea5bfe336456fb263dd479a60b1cd0193d8a47`, based on #136 `1cffb2e23d4002f12e8462c4c8c24f404a4eeee7`, preserves all inherited documentation and limits its unique delta to the intended cleanup wrapper, regression and changelog. Both indexes retain ADRs 0007–0010 and ADR 0009 remains Proposed. All 179 Python contracts passed; [review evidence](https://github.com/ContextualWisdomLab/OriginWeave/pull/139#issuecomment-5550147096) records all three resolved findings. Current hosted Rust, coverage and pinned-Chromium runs were cancelled, so this Draft has no current hosted or browser-runtime GREEN from that verification. - PR #141 at `fbdf64f5818ce0c53b475196d5bcfa2ac9900846`, based on #139 `b7ea5bfe336456fb263dd479a60b1cd0193d8a47`, retains the reviewed failure/surface/timeout cleanup contracts. All 183 Python contracts passed; controlled probes confirmed that unexpected exceptions propagate after temporary-profile removal and cleanup-exit failures cannot return false cleanup evidence. The remaining two informational threads were resolved without source changes, leaving all four threads resolved; [review evidence](https://github.com/ContextualWisdomLab/OriginWeave/pull/141#issuecomment-5550364179) binds these results to the unchanged head. Hosted CI `33916583623` and pinned-Chromium run `33916583506` were cancelled. This is not current browser-runtime GREEN, adversarial erasure proof, counted approval or protected-main delivery; the PR remains Draft. +- PR #142 at `015025f2539e4fb1dbd7d259ec22dad50f944396` passed fresh read-only failure-boundary review: 187 Python contracts passed, and controlled probes preserve unknown identity on observation failure, reject a still-live identity at the existing deadline, and accept absence or a different start-time as exit of the original identity. Both informational threads were resolved without production changes. Its exact-head CI `33916627099` and compatibility `33916627091` remain cancelled, not Linux/browser runtime GREEN. +- PR #143 at `44fd9a450f864feff5cf2ba2883425a71ba10b9b` is a documentation and real-path regression repair on exact #142. The release-record check first failed for the missing failure-cleanup entry, then all five focused and 192 Python contracts, full Rust 1.97.1 gates and pinned-nightly 100% coverage passed: 415 functions, 3555 lines, 4444 regions, 476 branches. The production runner is unchanged. Observed exit and a surviving identity both retain failed-task status; process-observation errors leave termination unproven and record only the bounded observation-error type, losing the original browser-failure type in that fallback record. Private exception messages remain absent, and profile cleanup cannot turn a failed task into a pass. Both informational threads are resolved with this limitation documented. CI `33954715539` and compatibility `33954715568` are queued; controlled local probes do not prove real Linux/pinned-Chromium acceptance. #144 needs current-parent adoption. - PR #258 is Draft at exact head `f2ceabb3ea50b1959e936503c50cae12f3e6e480` on exact #257, and PR #259 is Draft at exact head `e1105ddf86f6c79443af8b4d306b9d34cb703c17` on exact #258. Both final trees passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; fresh hosted exact-head checks and ordered parent integration remain required. - PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #95 is Draft at exact head `97aa0f2e340ee6fd920d0418f97af276b190554f`, stacked on #93 exact `0664f0452cb329cd692cce7f61f9001652abfda2`. Only `Decision::Allow` creates policy-authorized value; other decisions fail closed, and registry-owned current authority returns `NotAdmitted` after document advance removes the node. The slice performs no browser I/O or postcondition proof. Its 142 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 66007aced..2eff2ec9c 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -44,7 +44,14 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "every current review thread is resolved", "115 queued workflow runs", "rerunning unchanged heads would only add duplicate queue load", - "PR #249 is Draft at exact head `017d6e816f5a86544a63821b3ceaba94d5f17f44`", + "PR #249 is Draft at exact head `84b9407978ae0f6c115f01170b6069c601b21104`", + "989 functions, 9978 lines, 12717 regions, 1098 branches", + "PR #142 at `015025f2539e4fb1dbd7d259ec22dad50f944396`", + "187 Python contracts passed", + "PR #143 at `44fd9a450f864feff5cf2ba2883425a71ba10b9b`", + "192 Python contracts", + "415 functions, 3555 lines, 4444 regions, 476 branches", + "process-observation errors leave termination unproven", "#250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`", "#251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`", "#252 `2015259529ada99af836989079cc85a15779a2d8`", @@ -58,6 +65,9 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "Received-connection verification at #255 head `e7bfec4488b7cb4776df7b546cacb46c8c9eb13e`", "12 focused tests passed", "lines=11046/11049 and regions=14067/14071", + "Follow-up quality verification at #255 head `63cbca0a98cf9496af981819d98029e656fc4342`", + "functions=1082/1083, lines=11046/11051, regions=14071/14074", + "unused private accessor", "PR #139 at `b7ea5bfe336456fb263dd479a60b1cd0193d8a47`", "Opening-exchange fixture repair at #242", "PR #243 adopts that corrected parent by ordinary merge", From b76dc391c3abcf4ac87815cef252d3a8bf07245a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 17:35:45 +0900 Subject: [PATCH 151/250] docs(product): record status integration and CodeQL handoff Bind #250 current-parent and #144 read-only review evidence, and distinguish #287's queued central CodeQL handoff from a terminal scan verdict. Preserve live target and central workflow revision boundaries. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 9 ++++++--- tests/test_gap_snapshot_inventory_consistency.py | 9 +++++++++ 3 files changed, 16 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 06aa673cf..79ab11573 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -27,6 +27,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ### Added +- Recorded the verified #250 status-response parent adoption, #144's conservative process-set review limits and #287's authenticated CodeQL dispatch handoff, without promoting cancelled or pending hosted evidence to acceptance. - Recorded the verified #249 parent integration, #142/#143 failure-cleanup review evidence, and #255's remaining formatting/lint/coverage failures, keeping local results distinct from pending browser/hosted acceptance. - Revalidated the product-gap queue at 125 open pull requests (12 ready, 113 draft) and 13 open non-PR issues on 2026-09-05; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Ready at `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, WebDriver BiDi document-advance PR #260 is Draft at `3a651967c421f77088fe25e86a63faae295390b3`, denial-error PR #166 is Ready at `e84a1a2cc82b1c666218efd441da97849f47b8c2`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 has merged into its unprotected parent and successor #248 is Draft at `b386f17c4826adabebda084bff2fba35aee94dd0`, DDD/MCP repair #272 is Ready at `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, governance repair #285 is Ready at `f455c2cd64b3dd3f027c91d396103792a205ddd0`, subscription repair #277 is Draft at `01038ba71fb276426cc67f90a91a3c431e194db5`, classifier foundation #287 is Ready at `af83c40dd2990a03064a92ca75430a9cc400f098`, workflow-free Agent Task successor #288 is Draft at `39e36256651f62940ec3ca6149067f0cfcb2285a`, and workflow-owner candidate #290 is Draft at `ebeefcd534db4324498fdb18046ebc6255ddcdf2`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 2d497d1b9..c50c0c2f9 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,7 +6,7 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T08:18:00Z` (full inventory); targeted verification through `2026-09-05T08:20:00Z`. +Observed at (UTC): `2026-09-05T08:34:00Z` (full inventory and targeted review/check evidence). - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. PR #290 was converted back to Draft after current-protected workflow review found that its #245-relative patch would drop protected #286 lifecycle controls; queue movement is not protected-main delivery. PR #248 also returned to Draft for current-parent adoption and complete revalidation; no PR was closed. @@ -17,7 +17,8 @@ Observed at (UTC): `2026-09-05T08:18:00Z` (full inventory); targeted verificatio - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. - PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass. Its Ready transition materialized repository-native CI `33930234387`: Rust contracts `101207153048` and Production coverage `101207153244` succeeded by `2026-09-05T03:16:29Z`; native CI success does not replace the seven required central workflows. The Ready event did not materialize fresh central required-workflow runs. Targeted RCA at `2026-09-05T06:53Z` verified that the previously cancelled Security Scan `33924016851`, SAST Semgrep `33924016903`, and CodeQL PR `33924016883` still bind the current head and protected base, with no duplicate central CodeQL dispatch. The convenience CLI failed on a cross-repository workflow lookup before rerunning anything; the supported run-ID REST route then created attempt 2 for all three, with queued scope/language jobs `101265706025`, `101265708882`, and `101265710202`. These are verified replay admissions, not terminal scan results or proof that Ready-event materialization is repaired. Remaining required review evidence and the absent eligible approval still block merge; toggling Draft or creating a no-op commit is not an acceptable substitute. -- Issue #279 owns the remaining documentation-CI partitioning gap. PR #287 is Ready at exact head `af83c40dd2990a03064a92ca75430a9cc400f098` on current protected main; it is the workflow-independent classifier foundation, changes no `.github/**` path, and is the prerequisite for an authorized workflow owner. Its predecessor failed its own release-record contract; the current head binds Git rename/copy similarity to blob identity, and its focused and full local suites plus exact 100% Rust coverage pass. Hosted exact-head checks remain queued and no eligible approval exists. PR #282 is Draft at exact head `b64e0708584beff3fb54acf226cb3e667773e473` on current protected main. Its latest workflow/test delta removes `converted_to_draft` and `closed` from the CI event list, removes #286's closed-event guard, and makes the repository contract assert those protections are absent. Exact review `5120043505` therefore requires the authorized #279 owner to reconstruct the valid trusted-base classifier/contract partition while preserving #286's lifecycle and closed+Draft fail-closed controls; Draft checks do not transfer as GREEN. +- Issue #279 owns the remaining documentation-CI partitioning gap. PR #287 is Ready at exact head `af83c40dd2990a03064a92ca75430a9cc400f098` on current protected main; it is the workflow-independent classifier foundation, changes no `.github/**` path, and is the prerequisite for an authorized workflow owner. Its predecessor failed its own release-record contract; the current head binds Git rename/copy similarity to blob identity, and its focused and full local suites plus exact 100% Rust coverage pass. Exact native CI, Semgrep and scoped Security Scan have now completed as described next; remaining required review/CodeQL evidence and eligible approval are not complete. PR #282 is Draft at exact head `b64e0708584beff3fb54acf226cb3e667773e473` on current protected main. Its latest workflow/test delta removes `converted_to_draft` and `closed` from the CI event list, removes #286's closed-event guard, and makes the repository contract assert those protections are absent. Exact review `5120043505` therefore requires the authorized #279 owner to reconstruct the valid trusted-base classifier/contract partition while preserving #286's lifecycle and closed+Draft fail-closed controls; Draft checks do not transfer as GREEN. +- #287 CodeQL handoff RCA at `2026-09-05T08:34Z` confirms that exact native CI `33931806137` passed, Semgrep `33931806165` executed its scan successfully, and Security Scan `33931806226` executed Scorecard/Trivy while scope-skipping gitleaks/OSV/dependency-review. CodeQL wrapper `33931806139` failed intentionally after its three language jobs recorded successful dispatch and a pending verdict, not a failed terminal scan. The cross-repository convenience CLI returned 404; direct REST job logs identify the handoff. Central `.github` dispatches `33954721186`, `33955024697` and `33955164029` have display titles identifying the exact OriginWeave target head, but their immutable run heads are central-owner revisions (`71dd84d...` / `27d7331...`), not the product source head. All three remain queued and were not duplicated; acceptance still requires validated target checkout, an authenticated terminal verdict and the original-job replay. OpenCode is queued, Noema/Strix remain in progress, and no eligible formal approval exists. - PR #290 is Draft at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2` on #245 exact `a769f484e2c110e0523b3b28cd21573f43867562`. Its workflow/repository/PR-number concurrency isolation and manual-dispatch non-cancellation intent are valid, but its predecessor-relative MV3 patch would remove protected #286 `converted_to_draft`/`closed` lifecycle events and the closed-event job guard. Exact review `5120039692` and canonical-owner issue #212 comment `5549868655` require reconstruction on the current protected MV3 workflow; the scheduled product writer did not mutate `.github/**`. - PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`, stacked on predecessor #282 head `b54a5856d8201911f05d69622f0d5594a371adf0` rather than current #282 exact `b64e0708584beff3fb54acf226cb3e667773e473`. It must adopt the corrected current parent before its compare can become current evidence. The child remains one prose-only doctoring canary; Draft-hosted jobs are skipped, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. - PR #288 is Draft at exact head `39e36256651f62940ec3ca6149067f0cfcb2285a` on current protected main. It stages #70's controlled Agent Task product, test, and documentation delta without any `.github/**` mutation; its workflow-owned sandbox-helper assertion was removed after it made the workflow-free branch's full Python contract suite fail, and all 172 Python contracts now pass locally. Hosted CI and MV3 jobs remain skipped while Draft, and #212 still owns authorized workflow activation plus sandboxed pinned-Chromium execution evidence. @@ -39,7 +40,8 @@ Observed at (UTC): `2026-09-05T08:18:00Z` (full inventory); targeted verificatio - PR #243 adopts that corrected parent by ordinary merge at `97fab641ed9d76e6c515eadcef0629edfc8064a3`, with exact base `2d0e9f69df9ade21d8e8e3d807c3ff644d83b310`. The parent-relative delta preserves the existing bounded frame transport and adds only its integration evidence; the shared fixture is identical to the owner version. All 139 Python contracts, full Rust gates and exact 100% local coverage pass (884 functions, 8733 lines, 11176 regions, 1008 branches). Native CI `33952588687` is queued, and the PR remains Draft. This repairs the previously stale #242-to-#243 dependency edge; later descendants still need ordered parent adoption and their own exact-head verification. - PR #246 adopts #243 at `585791f3641fbe757c3bd9fd36d5316adcc78d63`, with exact parent `97fab641ed9d76e6c515eadcef0629edfc8064a3`. Its ordinary merge preserves the message/JSON source and test blobs while carrying the owner fixture repairs. All 141 Python contracts, complete Rust gates and exact 100% pinned-nightly local coverage pass (962 functions, 9701 lines, 12427 regions, 1084 branches). Native CI `33953247053` is queued and this PR remains Draft. Fifty pre-integration fixture-suite runs passed, so no newly reproduced failure or measured failure-rate improvement is claimed. Raw protocol messages still carry no received-connection provenance or browser authority; child integration and hosted acceptance remain pending. - PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 is Draft at `b386f17c4826adabebda084bff2fba35aee94dd0`, now based on #246 `585791f3641fbe757c3bd9fd36d5316adcc78d63` by ordinary merge and explicit retargeting away from the merged #247 branch. Correlation production and Rust test blobs remain unchanged. Review reproduced that native unittest discovery collected zero checks from the free-function release contract; the same assertions now use the repository's TestCase format, collect one check and reject a missing release record. All 142 Python contracts, full Rust gates and exact 100% pinned-nightly local coverage pass (975 functions, 9848 lines, 12563 regions, 1092 branches). Native CI `33953719566` is queued. Previous Ready status and local totals did not prove enforcement of the uncollected check; current hosted verification, protected parents and received-connection authority remain unproven. -- PR #249 is Draft at exact head `84b9407978ae0f6c115f01170b6069c601b21104`, ordinarily merged onto current #248 `b386f17c4826adabebda084bff2fba35aee94dd0`. The old `017d6e816f5a86544a63821b3ceaba94d5f17f44` tree lacked that parent and its newly discoverable release check; the parent adoption also reproduced a CHANGELOG-only merge conflict. The integration retains both release records, the parent's canonical opening fixture and native TestCase, and all four child-owned production/Rust-test blobs unchanged. All 142 Python contracts, the full Rust 1.97.1 gates and pinned-nightly 100% coverage pass locally: 989 functions, 9978 lines, 12717 regions, 1098 branches. Fresh exact-head CI `33954334610` is pending, not acceptance. #250 must adopt this parent before its comparison is current. +- PR #249 is Draft at exact head `84b9407978ae0f6c115f01170b6069c601b21104`, ordinarily merged onto current #248 `b386f17c4826adabebda084bff2fba35aee94dd0`. The old `017d6e816f5a86544a63821b3ceaba94d5f17f44` tree lacked that parent and its newly discoverable release check; the parent adoption also reproduced a CHANGELOG-only merge conflict. The integration retains both release records, the parent's canonical opening fixture and native TestCase, and all four child-owned production/Rust-test blobs unchanged. All 142 Python contracts, the full Rust 1.97.1 gates and pinned-nightly 100% coverage pass locally: 989 functions, 9978 lines, 12717 regions, 1098 branches. Fresh exact-head CI `33954334610` is pending, not acceptance. The current #250 adoption is recorded next. +- PR #250 now adopts #249 at `ec433b844a121f8554c062f92267991af9cacb6f`, with exact parent `84b9407978ae0f6c115f01170b6069c601b21104`. The conflict-free ordinary merge preserves all five child-owned production/Rust-test blobs and propagates the canonical fixture and native release TestCase. The pre-integration zero-test discovery RED becomes one executed check; all 142 Python contracts, full Rust 1.97.1 gates and pinned-nightly 100% coverage pass: 1023 functions, 10518 lines, 13525 regions, 1186 branches. Fresh exact-head CI `33955410724` is pending. Bounded status parsing still grants no authority and does not claim the later received-connection capability; #251 must adopt this new parent and revalidate. - PRs #250 through #257 remain Draft. The recorded fully locally verified chain used exact heads #250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`, #251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`, #252 `2015259529ada99af836989079cc85a15779a2d8`, #253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`, #254 `cbaf50dcc97753cc73135497ea8225e8b18de190`, #255 `a13de5f9321e72c1867974eb7a43230f031e58df`, #256 `9f2e6f29be46371762e3031a97c1cac04720694f`, and #257 `ea2b5b78868917219c46f1304558b92490a7f6fe`. Each updated tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. #250 and #257 each had one known macOS socket-observation race; their exact focused retries and complete coverage reruns passed. Exact-head review found that #253 still lets three unauthenticated caller booleans mint `OperationallyComplete`; raw teardown claims must remain explicitly unverified until session-bound transport, process-exit, and profile-removal evidence types are issued by their owning runtime boundaries. Hosted exact-head checks and ordered parent integration remain required. Since that observation, #255 has advanced beyond reviewed head `a13de5f9321e72c1867974eb7a43230f031e58df` with an in-progress connection-provenance repair. Its moving current head is live-metadata-only until the complete repair is reverified; neither the predecessor GREEN nor the earlier #256 parent comparison transfers to those commits. - Reviews [#254](https://github.com/ContextualWisdomLab/OriginWeave/pull/254#pullrequestreview-5120077272) at `cbaf50dcc97753cc73135497ea8225e8b18de190` and [#255](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120077213) at `a13de5f9321e72c1867974eb7a43230f031e58df` found a remaining connection-provenance gap. #254 passed six focused closure tests, formatting, strict network Clippy and network rustdoc locally. #255 removes the parent process/profile booleans and keeps overall teardown pending, but a new loopback regression fails when an acknowledgment from connection A is combined with closure from connection B: the assessment reports the acknowledged transport closed. Both connections can use command id 7; #254 retains only closure kind/status and the acknowledgment retains only its command id. Repair the established-stream, frame/message and command-correlation owners to preserve a non-forgeable connection-generation binding, carry it into acknowledgment and closure evidence, then reject mismatches in #255. Different-session and same-session reconnect regressions are required; endpoint equality, command-id equality and caller-supplied markers are insufficient. This is unresolved evidence integrity, not operational-completion authority or shipped behavior. Both PRs remain Draft with hosted checks queued. - Follow-up review `5120203295` at #255 head `92392b2da33bcd5446c6d2eb1b5504c39e60e3d6` established that received-message provenance must be checked before correlation is consumed. At that reviewed head, sender/closure generations rejected independently parsed evidence, but the two-real-socket response-substitution regression still failed: response B combined with outstanding-command state A became acknowledgment A because its generation came from the registry rather than the received text. The [exact-head review and runnable regression](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120203295) preserve the RED lineage; the later repair evidence below supersedes this failure only for its explicitly tested snapshot. @@ -49,6 +51,7 @@ Observed at (UTC): `2026-09-05T08:18:00Z` (full inventory); targeted verificatio - PR #141 at `fbdf64f5818ce0c53b475196d5bcfa2ac9900846`, based on #139 `b7ea5bfe336456fb263dd479a60b1cd0193d8a47`, retains the reviewed failure/surface/timeout cleanup contracts. All 183 Python contracts passed; controlled probes confirmed that unexpected exceptions propagate after temporary-profile removal and cleanup-exit failures cannot return false cleanup evidence. The remaining two informational threads were resolved without source changes, leaving all four threads resolved; [review evidence](https://github.com/ContextualWisdomLab/OriginWeave/pull/141#issuecomment-5550364179) binds these results to the unchanged head. Hosted CI `33916583623` and pinned-Chromium run `33916583506` were cancelled. This is not current browser-runtime GREEN, adversarial erasure proof, counted approval or protected-main delivery; the PR remains Draft. - PR #142 at `015025f2539e4fb1dbd7d259ec22dad50f944396` passed fresh read-only failure-boundary review: 187 Python contracts passed, and controlled probes preserve unknown identity on observation failure, reject a still-live identity at the existing deadline, and accept absence or a different start-time as exit of the original identity. Both informational threads were resolved without production changes. Its exact-head CI `33916627099` and compatibility `33916627091` remain cancelled, not Linux/browser runtime GREEN. - PR #143 at `44fd9a450f864feff5cf2ba2883425a71ba10b9b` is a documentation and real-path regression repair on exact #142. The release-record check first failed for the missing failure-cleanup entry, then all five focused and 192 Python contracts, full Rust 1.97.1 gates and pinned-nightly 100% coverage passed: 415 functions, 3555 lines, 4444 regions, 476 branches. The production runner is unchanged. Observed exit and a surviving identity both retain failed-task status; process-observation errors leave termination unproven and record only the bounded observation-error type, losing the original browser-failure type in that fallback record. Private exception messages remain absent, and profile cleanup cannot turn a failed task into a pass. Both informational threads are resolved with this limitation documented. CI `33954715539` and compatibility `33954715568` are queued; controlled local probes do not prove real Linux/pinned-Chromium acceptance. #144 needs current-parent adoption. +- PR #144 at `09f2e087d0c20fe81386c18099e739a9e611a8ad` completed read-only informational review: 194 Python contracts passed, and controlled real-helper probes confirmed conservative failure when a descendant PID is reused before start-time capture, separate root and process-set deadline budgets, and the defensive exit-count invariant across all eight absent/live combinations of three descendants. Three informational threads are resolved with those limits recorded; no runtime code or timeout changed. CI `33916685294` and compatibility `33916685137` remain cancelled, not current browser acceptance. The branch must still adopt #143 `44fd9a450f864feff5cf2ba2883425a71ba10b9b`; process identities appearing after sampling, cgroup ownership and OS-wide orphan absence remain outside this evidence. - PR #258 is Draft at exact head `f2ceabb3ea50b1959e936503c50cae12f3e6e480` on exact #257, and PR #259 is Draft at exact head `e1105ddf86f6c79443af8b4d306b9d34cb703c17` on exact #258. Both final trees passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; fresh hosted exact-head checks and ordered parent integration remain required. - PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #95 is Draft at exact head `97aa0f2e340ee6fd920d0418f97af276b190554f`, stacked on #93 exact `0664f0452cb329cd692cce7f61f9001652abfda2`. Only `Decision::Allow` creates policy-authorized value; other decisions fail closed, and registry-owned current authority returns `NotAdmitted` after document advance removes the node. The slice performs no browser I/O or postcondition proof. Its 142 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 2eff2ec9c..9eb3ae64a 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -46,12 +46,17 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "rerunning unchanged heads would only add duplicate queue load", "PR #249 is Draft at exact head `84b9407978ae0f6c115f01170b6069c601b21104`", "989 functions, 9978 lines, 12717 regions, 1098 branches", + "PR #250 now adopts #249 at `ec433b844a121f8554c062f92267991af9cacb6f`", + "1023 functions, 10518 lines, 13525 regions, 1186 branches", "PR #142 at `015025f2539e4fb1dbd7d259ec22dad50f944396`", "187 Python contracts passed", "PR #143 at `44fd9a450f864feff5cf2ba2883425a71ba10b9b`", "192 Python contracts", "415 functions, 3555 lines, 4444 regions, 476 branches", "process-observation errors leave termination unproven", + "PR #144 at `09f2e087d0c20fe81386c18099e739a9e611a8ad`", + "194 Python contracts passed", + "separate root and process-set deadline budgets", "#250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`", "#251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`", "#252 `2015259529ada99af836989079cc85a15779a2d8`", @@ -111,6 +116,10 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "CodeQL PR `33924016883`", "did not materialize fresh central required-workflow runs", "PR #287 is Ready at exact head `af83c40dd2990a03064a92ca75430a9cc400f098`", + "#287 CodeQL handoff RCA", + "33954721186", + "33955024697", + "33955164029", "PR #273 is Draft at exact head `e5c8fcb66bf644dfa750bb1b40ba3d600cb7805a`", "GitHub Releases is empty", ): From b09de4729a829a2c13c70d5ec1c896e02757584f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 18:11:55 +0900 Subject: [PATCH 152/250] docs: record cleanup evidence repairs and review outcomes Record current parent adoption through #146, reproduced evidence-boundary fixes, retained concurrent history, and complete local verification. Distinguish executed Strix, Noema gateway failure and queued replay from hosted acceptance and counted approval; preserve dated historical inventory. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 11 ++++++++--- tests/test_gap_snapshot_inventory_consistency.py | 10 ++++++++++ 3 files changed, 19 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 79ab11573..c19f632f4 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded #144/#145 parent adoption, #146's reproduced cleanup-evidence fixes and preserved concurrent integration, with complete local verification separated from queued hosted compatibility; refreshed #287's executed Strix scan and failed Noema gateway retry evidence without claiming recovery or approval. - Repaired #248's uncollected release-record test and obsolete merged-parent dependency; recorded 142 passing Python contracts, full local Rust gates and exact coverage while preserving Draft and hosted-check boundaries. - Recorded #246's verified parent integration and exact local coverage, plus #141's unchanged-head cleanup review and two resolved informational findings; hosted and protected-main acceptance remain separate. - Recorded the shared opening-exchange fixture repair in #242 and its non-force adoption by #243, with full local gates, exact coverage and queued hosted checks kept distinct. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index c50c0c2f9..21ab34fd0 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,7 +6,7 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T08:34:00Z` (full inventory and targeted review/check evidence). +Observed at (UTC): `2026-09-05T09:10:00Z` (full inventory and targeted review/check evidence). - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. PR #290 was converted back to Draft after current-protected workflow review found that its #245-relative patch would drop protected #286 lifecycle controls; queue movement is not protected-main delivery. PR #248 also returned to Draft for current-parent adoption and complete revalidation; no PR was closed. @@ -50,8 +50,8 @@ Observed at (UTC): `2026-09-05T08:34:00Z` (full inventory and targeted review/ch - PR #139 at `b7ea5bfe336456fb263dd479a60b1cd0193d8a47`, based on #136 `1cffb2e23d4002f12e8462c4c8c24f404a4eeee7`, preserves all inherited documentation and limits its unique delta to the intended cleanup wrapper, regression and changelog. Both indexes retain ADRs 0007–0010 and ADR 0009 remains Proposed. All 179 Python contracts passed; [review evidence](https://github.com/ContextualWisdomLab/OriginWeave/pull/139#issuecomment-5550147096) records all three resolved findings. Current hosted Rust, coverage and pinned-Chromium runs were cancelled, so this Draft has no current hosted or browser-runtime GREEN from that verification. - PR #141 at `fbdf64f5818ce0c53b475196d5bcfa2ac9900846`, based on #139 `b7ea5bfe336456fb263dd479a60b1cd0193d8a47`, retains the reviewed failure/surface/timeout cleanup contracts. All 183 Python contracts passed; controlled probes confirmed that unexpected exceptions propagate after temporary-profile removal and cleanup-exit failures cannot return false cleanup evidence. The remaining two informational threads were resolved without source changes, leaving all four threads resolved; [review evidence](https://github.com/ContextualWisdomLab/OriginWeave/pull/141#issuecomment-5550364179) binds these results to the unchanged head. Hosted CI `33916583623` and pinned-Chromium run `33916583506` were cancelled. This is not current browser-runtime GREEN, adversarial erasure proof, counted approval or protected-main delivery; the PR remains Draft. - PR #142 at `015025f2539e4fb1dbd7d259ec22dad50f944396` passed fresh read-only failure-boundary review: 187 Python contracts passed, and controlled probes preserve unknown identity on observation failure, reject a still-live identity at the existing deadline, and accept absence or a different start-time as exit of the original identity. Both informational threads were resolved without production changes. Its exact-head CI `33916627099` and compatibility `33916627091` remain cancelled, not Linux/browser runtime GREEN. -- PR #143 at `44fd9a450f864feff5cf2ba2883425a71ba10b9b` is a documentation and real-path regression repair on exact #142. The release-record check first failed for the missing failure-cleanup entry, then all five focused and 192 Python contracts, full Rust 1.97.1 gates and pinned-nightly 100% coverage passed: 415 functions, 3555 lines, 4444 regions, 476 branches. The production runner is unchanged. Observed exit and a surviving identity both retain failed-task status; process-observation errors leave termination unproven and record only the bounded observation-error type, losing the original browser-failure type in that fallback record. Private exception messages remain absent, and profile cleanup cannot turn a failed task into a pass. Both informational threads are resolved with this limitation documented. CI `33954715539` and compatibility `33954715568` are queued; controlled local probes do not prove real Linux/pinned-Chromium acceptance. #144 needs current-parent adoption. -- PR #144 at `09f2e087d0c20fe81386c18099e739a9e611a8ad` completed read-only informational review: 194 Python contracts passed, and controlled real-helper probes confirmed conservative failure when a descendant PID is reused before start-time capture, separate root and process-set deadline budgets, and the defensive exit-count invariant across all eight absent/live combinations of three descendants. Three informational threads are resolved with those limits recorded; no runtime code or timeout changed. CI `33916685294` and compatibility `33916685137` remain cancelled, not current browser acceptance. The branch must still adopt #143 `44fd9a450f864feff5cf2ba2883425a71ba10b9b`; process identities appearing after sampling, cgroup ownership and OS-wide orphan absence remain outside this evidence. +- PR #143 at `44fd9a450f864feff5cf2ba2883425a71ba10b9b` is a documentation and real-path regression repair on exact #142. The release-record check first failed for the missing failure-cleanup entry, then all five focused and 192 Python contracts, full Rust 1.97.1 gates and pinned-nightly 100% coverage passed: 415 functions, 3555 lines, 4444 regions, 476 branches. The production runner is unchanged. Observed exit and a surviving identity both retain failed-task status; process-observation errors leave termination unproven and record only the bounded observation-error type, losing the original browser-failure type in that fallback record. Private exception messages remain absent, and profile cleanup cannot turn a failed task into a pass. Both informational threads are resolved with this limitation documented. CI `33954715539` and compatibility `33954715568` are queued; controlled local probes do not prove real Linux/pinned-Chromium acceptance. Current #144 adoption is recorded below. +- PR #144 at `09f2e087d0c20fe81386c18099e739a9e611a8ad` completed read-only informational review: 194 Python contracts passed, and controlled real-helper probes confirmed conservative failure when a descendant PID is reused before start-time capture, separate root and process-set deadline budgets, and the defensive exit-count invariant across all eight absent/live combinations of three descendants. Three informational threads are resolved with those limits recorded; no runtime code or timeout changed. CI `33916685294` and compatibility `33916685137` remain cancelled, not current browser acceptance. This is predecessor evidence superseded by the current adoption below; process identities appearing after sampling, cgroup ownership and OS-wide orphan absence remain outside this evidence. - PR #258 is Draft at exact head `f2ceabb3ea50b1959e936503c50cae12f3e6e480` on exact #257, and PR #259 is Draft at exact head `e1105ddf86f6c79443af8b4d306b9d34cb703c17` on exact #258. Both final trees passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; fresh hosted exact-head checks and ordered parent integration remain required. - PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #95 is Draft at exact head `97aa0f2e340ee6fd920d0418f97af276b190554f`, stacked on #93 exact `0664f0452cb329cd692cce7f61f9001652abfda2`. Only `Decision::Allow` creates policy-authorized value; other decisions fail closed, and registry-owned current authority returns `NotAdmitted` after document advance removes the node. The slice performs no browser I/O or postcondition proof. Its 142 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. @@ -63,6 +63,11 @@ Observed at (UTC): `2026-09-05T08:34:00Z` (full inventory and targeted review/ch - The principal commercial gaps remain #27 Manifest V3/native-host isolation, #9 bounded HTTP/browser-network consumption, #10 purpose-bound protected-data runtime, #28 the first complete Chromium Agent Task vertical slice, #199 durable WARC/PROV and retention/replay, #200 stable BAP/MCP runtime API, #201 signed cross-platform distribution/update/rollback/SBOM/SLSA, #202 enterprise identity/tenant/policy/approval/audit/SLO operations, #203 exact-artifact commercial acceptance, #276 contextual-orchestrator migration, and #279 exact-head documentation verification without unnecessary Rust queue load. - Current evidence procedure remains fail-closed: queued reviewer evidence is non-passing; paginate the full PR inventory, bind checks/reviews/threads/workflow runs to each unchanged exact head and independently resolved live base, consult the active ruleset, and discard queued, skipped, cancelled, absent, predecessor, synthetic, status-only, and model-only evidence as passing proof. +- Current PR #144 parent adoption is `3c0c5c363c2da0b4e8a621226e2f7766c735b743`, ordinarily integrating #143 `44fd9a450f864feff5cf2ba2883425a71ba10b9b`. The previous child collected three inherited failure-path contracts instead of five. Both release records and the parent's real failure-path regression now coexist with unchanged child production and process-set tests. All five focused and all 196 Python contracts, complete Rust 1.97.1 gates and pinned-nightly 100% coverage pass locally: 415 functions, 3555 lines, 4444 regions, 476 branches. Exact CI `33956094018` and compatibility `33956094011` are queued, not acceptance; the prior informational review limits remain unchanged. +- PR #145 now adopts #144 at `bb5e8f834c37f9ce35f84db8ed1146da3659d6aa`. The ordinary merge preserves the child runner and both process-set/forced-close regressions while moving the missing inherited-contract count from three to five. All five focused and all 202 Python contracts, full Rust gates and the same four-dimension 100% coverage pass. Ten controlled actual browser-pass/trial probes distinguish observed root/set survival, observation errors and interrupted capture; session/driver cleanup alone does not prove process exit. Both informational threads are resolved with that corrected limit. Exact CI `33956596014` and compatibility `33956596013` remain queued. +- PR #146 review repair is `812c0020bd2ecdb3eda39d999ed3327647550bdf`. Five new tests first reproduced 10 assertion failures and 7 uncaught protocol-error cases despite the predecessor's 216 passing contracts. The repair restores the non-boolean pre-shutdown count range, preserves only validated known ordinary cleanup fields, records typed terminal protocol errors without remote messages, and removes the obsolete HTTP-body close recognizer. Startup retry policy, request redaction and owned-process deadlines remain unchanged. Six new behavioral tests and all 224 Python contracts, complete Rust gates and the same 100% production coverage pass. The concurrent parent-adoption `11944410450684809ee1a71a35c77abafc5358db` is retained through an ordinary merge whose tree is identical to verified repair `d636a1829332610ada458df7b5b9d267f038a2f8`. All four review threads are resolved; exact CI `33957036553` and compatibility `33957036650` are queued, not browser acceptance. #147 must adopt this parent while retaining its own shared-deadline behavior. These three PRs remain Draft and no protected delivery, eligible approval or release is claimed. +- Follow-up #287 review evidence at `2026-09-05T09:07Z`: Strix scan job `101243872506` executed successfully, including its quick scan and report upload. Noema job `101245089068` failed with HTTP 502 after 2739.2 seconds and one caller attempt. A fresh exact-head inventory showed no duplicate Noema run, so the same failed job was queued for a supported rerun; attempt 2 now has successful exact-head admission and queued review job `101282290732`. Queue admission is not provider recovery, executed review, a verdict or eligible approval. No caller timeout, provider, model, workflow or quality gate changed. The three central CodeQL dispatches remain queued and were not duplicated. This supersedes the earlier in-progress Noema/Strix snapshot above without transferring any old result to a new source head. + ## Observed snapshot: 2026-08-29 ### Protected-main truth diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 9eb3ae64a..fc9d1af42 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -57,6 +57,16 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #144 at `09f2e087d0c20fe81386c18099e739a9e611a8ad`", "194 Python contracts passed", "separate root and process-set deadline budgets", + "Current PR #144 parent adoption is `3c0c5c363c2da0b4e8a621226e2f7766c735b743`", + "all 196 Python contracts", + "PR #145 now adopts #144 at `bb5e8f834c37f9ce35f84db8ed1146da3659d6aa`", + "all 202 Python contracts", + "PR #146 review repair is `812c0020bd2ecdb3eda39d999ed3327647550bdf`", + "10 assertion failures and 7 uncaught protocol-error cases", + "all 224 Python contracts", + "concurrent parent-adoption `11944410450684809ee1a71a35c77abafc5358db`", + "Noema job `101245089068` failed with HTTP 502 after 2739.2 seconds", + "Strix scan job `101243872506` executed successfully", "#250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`", "#251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`", "#252 `2015259529ada99af836989079cc85a15779a2d8`", From 6154c87f50a219b9ff475fb961885826db036b8c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 18:21:04 +0900 Subject: [PATCH 153/250] docs: distinguish owner repair and instrumentation limits Preserve the new #255 owner verification separately from old quality failures and experimental branch instrumentation. Record the exact #147 lossy-adoption RED and required non-lossy reconciliation without claiming review resolution or delivery. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 6 +++++- tests/test_gap_snapshot_inventory_consistency.py | 3 +++ 3 files changed, 9 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index c19f632f4..9007f2363 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded #255's new owner-verified repair separately from its prior quality failures, retained the real branch-instrumentation warning, and identified #147's lossy parent adoption with a failing replay of six omitted regressions. - Recorded #144/#145 parent adoption, #146's reproduced cleanup-evidence fixes and preserved concurrent integration, with complete local verification separated from queued hosted compatibility; refreshed #287's executed Strix scan and failed Noema gateway retry evidence without claiming recovery or approval. - Repaired #248's uncollected release-record test and obsolete merged-parent dependency; recorded 142 passing Python contracts, full local Rust gates and exact coverage while preserving Draft and hosted-check boundaries. - Recorded #246's verified parent integration and exact local coverage, plus #141's unchanged-head cleanup review and two resolved informational findings; hosted and protected-main acceptance remain separate. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 21ab34fd0..0d2d3b7c6 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,7 +6,7 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T09:10:00Z` (full inventory and targeted review/check evidence). +Observed at (UTC): `2026-09-05T09:20:00Z` (full inventory and targeted review/check evidence). - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. PR #290 was converted back to Draft after current-protected workflow review found that its #245-relative patch would drop protected #286 lifecycle controls; queue movement is not protected-main delivery. PR #248 also returned to Draft for current-parent adoption and complete revalidation; no PR was closed. @@ -68,6 +68,10 @@ Observed at (UTC): `2026-09-05T09:10:00Z` (full inventory and targeted review/ch - PR #146 review repair is `812c0020bd2ecdb3eda39d999ed3327647550bdf`. Five new tests first reproduced 10 assertion failures and 7 uncaught protocol-error cases despite the predecessor's 216 passing contracts. The repair restores the non-boolean pre-shutdown count range, preserves only validated known ordinary cleanup fields, records typed terminal protocol errors without remote messages, and removes the obsolete HTTP-body close recognizer. Startup retry policy, request redaction and owned-process deadlines remain unchanged. Six new behavioral tests and all 224 Python contracts, complete Rust gates and the same 100% production coverage pass. The concurrent parent-adoption `11944410450684809ee1a71a35c77abafc5358db` is retained through an ordinary merge whose tree is identical to verified repair `d636a1829332610ada458df7b5b9d267f038a2f8`. All four review threads are resolved; exact CI `33957036553` and compatibility `33957036650` are queued, not browser acceptance. #147 must adopt this parent while retaining its own shared-deadline behavior. These three PRs remain Draft and no protected delivery, eligible approval or release is claimed. - Follow-up #287 review evidence at `2026-09-05T09:07Z`: Strix scan job `101243872506` executed successfully, including its quick scan and report upload. Noema job `101245089068` failed with HTTP 502 after 2739.2 seconds and one caller attempt. A fresh exact-head inventory showed no duplicate Noema run, so the same failed job was queued for a supported rerun; attempt 2 now has successful exact-head admission and queued review job `101282290732`. Queue admission is not provider recovery, executed review, a verdict or eligible approval. No caller timeout, provider, model, workflow or quality gate changed. The three central CodeQL dispatches remain queued and were not duplicated. This supersedes the earlier in-progress Noema/Strix snapshot above without transferring any old result to a new source head. +- Current #255 source-owner repair is `ebac126d1632c94775c2454423575275eec45def`, now verified in remote PR metadata on unchanged #254. Its 11-file delta removes the obsolete private accessor, applies pinned formatting and repairs the Rust documentation link without removing received-connection validation. The source owner reports 141 Python contracts, full Rust 1.97.1 verification and coverage functions=1082/1082, lines=11025/11025, regions=14071/14071, branches=1202/1202. This is the owner's new exact-tree local verification, not an independent rerun by this documentation lane or a transfer of earlier GREEN. Exact hosted CI `33957423557` is queued; the earlier `63cbca0...` quality RED is retained as historical RCA, and ordered parent adoption still remains. +- The pinned cargo-llvm-cov 0.8.6 branch report emits `warning: --branch option is unstable`. The warning was independently reproduced when reporting the existing #144/#145/#146 measurements, whose numerical verifiers still pass. Thus numerical coverage enforcement is distinct from warning-free instrumentation. The #255 source owner likewise leaves warning-free measurement acceptance outstanding. No warning suppression, coverage exclusion, denominator manipulation or alternate unreviewed measurement is used; compiler/Clippy/rustdoc results, instrumentation maturity, hosted acceptance and release readiness remain separate. +- Current #147 `46e75859ef5aff2054fd6ca1720d518438e97d0f` includes #146 `812c0020...` in ancestry but drops the parent's six review-evidence regressions and reverses their associated production repairs. Native discovery collects zero tests; read-only replay of the exact parent module against this child reproduces 10 assertion failures and 8 uncaught protocol-error cases. Preserve the shared forced-close observer while restoring those valid parent deltas and adapting its observer-specific test injection. Source writer coordination is in progress; the merge title, ancestor presence and earlier 222 passing child tests do not establish successful inheritance or current acceptance. + ## Observed snapshot: 2026-08-29 ### Protected-main truth diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index fc9d1af42..ae3d95810 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -83,6 +83,9 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "Follow-up quality verification at #255 head `63cbca0a98cf9496af981819d98029e656fc4342`", "functions=1082/1083, lines=11046/11051, regions=14071/14074", "unused private accessor", + "Current #255 source-owner repair is `ebac126d1632c94775c2454423575275eec45def`", + "warning: --branch option is unstable", + "numerical coverage enforcement is distinct from warning-free instrumentation", "PR #139 at `b7ea5bfe336456fb263dd479a60b1cd0193d8a47`", "Opening-exchange fixture repair at #242", "PR #243 adopts that corrected parent by ordinary merge", From 907c71aa35a0d5fe47867ad09ba51c69e6d97fe8 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 18:24:54 +0900 Subject: [PATCH 154/250] docs: track active non-lossy stack repair inventory Two complete live inventories include temporary Draft #291. Keep 126 open / 12 Ready / 114 Draft distinct from dated history and record the active parent-repair route without claiming source inheritance, merge or acceptance. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 4 ++-- docs/product-technical-gap-baseline.md | 6 ++++-- tests/test_gap_snapshot_inventory_consistency.py | 6 +++--- 3 files changed, 9 insertions(+), 7 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 9007f2363..7e8013152 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -22,7 +22,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Recorded PR #285's Ready-event materialization gap: repository-native exact-head CI restarted, while the earlier central Security, Semgrep, and CodeQL runs remained cancelled and no fresh required-workflow replacements appeared. - Refreshed the live product-gap baseline with PR #37's RFC 9110 `205 Reset Content` repair head and exact local verification evidence. - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. -- Refreshed the product-gap queue to 125 open pull requests (12 ready, 113 draft) and 13 open non-PR issues on 2026-09-05; queue movement is active-PR evidence, not protected-main shipment. +- Refreshed the product-gap queue to 126 open pull requests (12 ready, 114 draft) and 13 open non-PR issues on 2026-09-05; queue movement is active-PR evidence, not protected-main shipment. - Recorded the current Ready-root heads for #37, #50, #166, #219, #220, #229, #240, #272, #274, #285, and #287; Draft #290 remains a #245-dependent workflow-owner candidate, #238's moving self-reference is delegated to live PR metadata, hosted exact-head checks remain non-terminal, and counted approval remains absent. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. @@ -31,7 +31,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Recorded the verified #250 status-response parent adoption, #144's conservative process-set review limits and #287's authenticated CodeQL dispatch handoff, without promoting cancelled or pending hosted evidence to acceptance. - Recorded the verified #249 parent integration, #142/#143 failure-cleanup review evidence, and #255's remaining formatting/lint/coverage failures, keeping local results distinct from pending browser/hosted acceptance. -- Revalidated the product-gap queue at 125 open pull requests (12 ready, 113 draft) and 13 open non-PR issues on 2026-09-05; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Ready at `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, WebDriver BiDi document-advance PR #260 is Draft at `3a651967c421f77088fe25e86a63faae295390b3`, denial-error PR #166 is Ready at `e84a1a2cc82b1c666218efd441da97849f47b8c2`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 has merged into its unprotected parent and successor #248 is Draft at `b386f17c4826adabebda084bff2fba35aee94dd0`, DDD/MCP repair #272 is Ready at `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, governance repair #285 is Ready at `f455c2cd64b3dd3f027c91d396103792a205ddd0`, subscription repair #277 is Draft at `01038ba71fb276426cc67f90a91a3c431e194db5`, classifier foundation #287 is Ready at `af83c40dd2990a03064a92ca75430a9cc400f098`, workflow-free Agent Task successor #288 is Draft at `39e36256651f62940ec3ca6149067f0cfcb2285a`, and workflow-owner candidate #290 is Draft at `ebeefcd534db4324498fdb18046ebc6255ddcdf2`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. +- Revalidated the product-gap queue at 126 open pull requests (12 ready, 114 draft) and 13 open non-PR issues on 2026-09-05; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Ready at `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, WebDriver BiDi document-advance PR #260 is Draft at `3a651967c421f77088fe25e86a63faae295390b3`, denial-error PR #166 is Ready at `e84a1a2cc82b1c666218efd441da97849f47b8c2`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 has merged into its unprotected parent and successor #248 is Draft at `b386f17c4826adabebda084bff2fba35aee94dd0`, DDD/MCP repair #272 is Ready at `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, governance repair #285 is Ready at `f455c2cd64b3dd3f027c91d396103792a205ddd0`, subscription repair #277 is Draft at `01038ba71fb276426cc67f90a91a3c431e194db5`, classifier foundation #287 is Ready at `af83c40dd2990a03064a92ca75430a9cc400f098`, workflow-free Agent Task successor #288 is Draft at `39e36256651f62940ec3ca6149067f0cfcb2285a`, and workflow-owner candidate #290 is Draft at `ebeefcd534db4324498fdb18046ebc6255ddcdf2`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 0d2d3b7c6..5817aef33 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,10 +6,10 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T09:20:00Z` (full inventory and targeted review/check evidence). +Observed at (UTC): `2026-09-05T09:24:51Z` (full inventory and targeted review/check evidence). - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. -- Full live search returns **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. PR #290 was converted back to Draft after current-protected workflow review found that its #245-relative patch would drop protected #286 lifecycle controls; queue movement is not protected-main delivery. PR #248 also returned to Draft for current-parent adoption and complete revalidation; no PR was closed. +- Full live search returns **126 open pull requests: 12 Ready/non-draft and 114 Draft; 13 open non-PR issues**. PR #290 was converted back to Draft after current-protected workflow review found that its #245-relative patch would drop protected #286 lifecycle controls; queue movement is not protected-main delivery. PR #248 also returned to Draft for current-parent adoption and complete revalidation; no PR was closed. - Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `2bd85188a3b3d798824ac04cf3638df84ac2a8bb`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. PR #290 is Draft at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2`, remains a #245-dependent workflow-owner candidate, and is not a root. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2` and PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd` retain formal `CHANGES_REQUESTED` decisions even though every current review thread is resolved. The decisions remain merge blockers until the governing reviewer state changes; thread resolution alone is not approval and is not grounds to dismiss a review. - Targeted CI RCA at `2026-09-05T06:45Z` confirmed that #219 Noema run `33925442322` / job `101226941175` and #240 run `33925596923` / job `101227537529` had terminated on gateway HTTP 502 without review verdicts. Neither unchanged exact head had a successor Noema run. One supported failed-job rerun per head created attempt 2, with queued jobs `101264704581` and `101264705575`; Noema attempt 2 is queue-admission evidence, not provider recovery or a review verdict. Successful sampled Noema wrapper runs skipped their review jobs and cannot establish recovery. The CodeQL failures independently record dispatch handoff: #219 central runs `33947047322`, `33947036734`, `33947037072` and #240 runs `33947189162`, `33947189634`, `33947187643` match those exact heads; these central CodeQL dispatches remain queued and were not duplicated. Active Strix runs were left untouched. Revisit these exact attempts after a terminal result; do not create repeated retries while they remain queued. @@ -72,6 +72,8 @@ Observed at (UTC): `2026-09-05T09:20:00Z` (full inventory and targeted review/ch - The pinned cargo-llvm-cov 0.8.6 branch report emits `warning: --branch option is unstable`. The warning was independently reproduced when reporting the existing #144/#145/#146 measurements, whose numerical verifiers still pass. Thus numerical coverage enforcement is distinct from warning-free instrumentation. The #255 source owner likewise leaves warning-free measurement acceptance outstanding. No warning suppression, coverage exclusion, denominator manipulation or alternate unreviewed measurement is used; compiler/Clippy/rustdoc results, instrumentation maturity, hosted acceptance and release readiness remain separate. - Current #147 `46e75859ef5aff2054fd6ca1720d518438e97d0f` includes #146 `812c0020...` in ancestry but drops the parent's six review-evidence regressions and reverses their associated production repairs. Native discovery collects zero tests; read-only replay of the exact parent module against this child reproduces 10 assertion failures and 8 uncaught protocol-error cases. Preserve the shared forced-close observer while restoring those valid parent deltas and adapting its observer-specific test injection. Source writer coordination is in progress; the merge title, ancestor presence and earlier 222 passing child tests do not establish successful inheritance or current acceptance. +- A second complete inventory now includes temporary Draft #291, making the live total 126 open / 12 Ready / 114 Draft. Its head `221bcd6fdf0f07e1a873e253993b82d7209b7f52` is the original #147 child, while synthetic base branch `automation/147-merge-base-20260905` points to #146 `812c0020...`. The stated purpose is non-lossy three-way integration, not product acceptance or replacement of #147. This visible active repair route is kept separate from the lossy #147 snapshot; no competing source mutation, merge, closure or inferred successful transfer is performed by this lane. Verify the synthesized content, full inherited tests and real #147 forward adoption before making any succession claim. + ## Observed snapshot: 2026-08-29 ### Protected-main truth diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index ae3d95810..77d580070 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -26,9 +26,9 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "## Observed snapshot: 2026-08-29", 1 )[0] for marker in ( - "125 open pull requests", + "126 open pull requests", "12 Ready/non-draft", - "113 Draft", + "114 Draft", "13 open non-PR issues", "87c4daa1830bac5a5228b6036752ad5633232085", "18156473", @@ -215,7 +215,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "125 open pull requests (12 ready, 113 draft)" + expected = "126 open pull requests (12 ready, 114 draft)" self.assertIn(expected, preamble) self.assertIn("13 open non-PR issues", preamble) self.assertIn(expected, added) From eac47f1d36532bb28b439c5258ab11812f0cf096 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 18:57:48 +0900 Subject: [PATCH 155/250] docs: record session end integration and remaining teardown red Refresh live inventory to 125 open PRs, 12 Ready and 113 Draft after the external temporary synthesis closed. Preserve historical lossy-integration evidence and record the restored six tests with two remaining forced-close injection failures. Record #251 current-parent verification and queued hosted CI without claiming warning-free instrumentation or protected delivery. Eight stale marker/count assertions failed before the documentation update; all169 repository contracts and compileall now pass. Historical snapshots and existing source-owned quality evidence remain intact. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 5 +++-- docs/product-technical-gap-baseline.md | 12 +++++++----- tests/test_gap_snapshot_inventory_consistency.py | 11 ++++++++--- 3 files changed, 18 insertions(+), 10 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 7e8013152..e0ecda399 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded #251's verified parent integration and #147's restored parent evidence with two remaining test-reconciliation failures; distinguished the externally closed temporary synthesis from product acceptance and refreshed the live inventory. - Recorded #255's new owner-verified repair separately from its prior quality failures, retained the real branch-instrumentation warning, and identified #147's lossy parent adoption with a failing replay of six omitted regressions. - Recorded #144/#145 parent adoption, #146's reproduced cleanup-evidence fixes and preserved concurrent integration, with complete local verification separated from queued hosted compatibility; refreshed #287's executed Strix scan and failed Noema gateway retry evidence without claiming recovery or approval. - Repaired #248's uncollected release-record test and obsolete merged-parent dependency; recorded 142 passing Python contracts, full local Rust gates and exact coverage while preserving Draft and hosted-check boundaries. @@ -22,7 +23,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Recorded PR #285's Ready-event materialization gap: repository-native exact-head CI restarted, while the earlier central Security, Semgrep, and CodeQL runs remained cancelled and no fresh required-workflow replacements appeared. - Refreshed the live product-gap baseline with PR #37's RFC 9110 `205 Reset Content` repair head and exact local verification evidence. - Recorded PR #284's rule-suite `3948421709` administrative bypass into protected `main` at `4ed08bfa7c063fc7f2ef9278ee8d281887b8296b`; post-merge checks remain independently required and cannot retroactively turn the bypass into policy-compliant integration. -- Refreshed the product-gap queue to 126 open pull requests (12 ready, 114 draft) and 13 open non-PR issues on 2026-09-05; queue movement is active-PR evidence, not protected-main shipment. +- Refreshed the product-gap queue to 125 open pull requests (12 ready, 113 draft) and 13 open non-PR issues on 2026-09-05; queue movement is active-PR evidence, not protected-main shipment. - Recorded the current Ready-root heads for #37, #50, #166, #219, #220, #229, #240, #272, #274, #285, and #287; Draft #290 remains a #245-dependent workflow-owner candidate, #238's moving self-reference is delegated to live PR metadata, hosted exact-head checks remain non-terminal, and counted approval remains absent. - Corrected the retained PR #219 exact-head regression anchor and separated the shipped `tools/call` policy binding from the core-only `tools/list` discovery contract. - Refreshed the #279 evidence to the current #282/#283 heads, including complete raw-diff object identities and rename/copy similarity binding to blob identity. @@ -31,7 +32,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Recorded the verified #250 status-response parent adoption, #144's conservative process-set review limits and #287's authenticated CodeQL dispatch handoff, without promoting cancelled or pending hosted evidence to acceptance. - Recorded the verified #249 parent integration, #142/#143 failure-cleanup review evidence, and #255's remaining formatting/lint/coverage failures, keeping local results distinct from pending browser/hosted acceptance. -- Revalidated the product-gap queue at 126 open pull requests (12 ready, 114 draft) and 13 open non-PR issues on 2026-09-05; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Ready at `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, WebDriver BiDi document-advance PR #260 is Draft at `3a651967c421f77088fe25e86a63faae295390b3`, denial-error PR #166 is Ready at `e84a1a2cc82b1c666218efd441da97849f47b8c2`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 has merged into its unprotected parent and successor #248 is Draft at `b386f17c4826adabebda084bff2fba35aee94dd0`, DDD/MCP repair #272 is Ready at `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, governance repair #285 is Ready at `f455c2cd64b3dd3f027c91d396103792a205ddd0`, subscription repair #277 is Draft at `01038ba71fb276426cc67f90a91a3c431e194db5`, classifier foundation #287 is Ready at `af83c40dd2990a03064a92ca75430a9cc400f098`, workflow-free Agent Task successor #288 is Draft at `39e36256651f62940ec3ca6149067f0cfcb2285a`, and workflow-owner candidate #290 is Draft at `ebeefcd534db4324498fdb18046ebc6255ddcdf2`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. +- Revalidated the product-gap queue at 125 open pull requests (12 ready, 113 draft) and 13 open non-PR issues on 2026-09-05; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Ready at `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, WebDriver BiDi document-advance PR #260 is Draft at `3a651967c421f77088fe25e86a63faae295390b3`, denial-error PR #166 is Ready at `e84a1a2cc82b1c666218efd441da97849f47b8c2`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 has merged into its unprotected parent and successor #248 is Draft at `b386f17c4826adabebda084bff2fba35aee94dd0`, DDD/MCP repair #272 is Ready at `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, governance repair #285 is Ready at `f455c2cd64b3dd3f027c91d396103792a205ddd0`, subscription repair #277 is Draft at `01038ba71fb276426cc67f90a91a3c431e194db5`, classifier foundation #287 is Ready at `af83c40dd2990a03064a92ca75430a9cc400f098`, workflow-free Agent Task successor #288 is Draft at `39e36256651f62940ec3ca6149067f0cfcb2285a`, and workflow-owner candidate #290 is Draft at `ebeefcd534db4324498fdb18046ebc6255ddcdf2`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. - Recorded PR #67's exact-head squash merge into unprotected parent #64 at `5021d142583cb5a8e393248048bb824762a98056`; #64's hosted checks restarted on its new exact head, so neither child nor parent evidence is promoted to protected-main delivery. - Recorded PR #217's squash merge into the unprotected #210 feature parent at `66f360ccac5cec60c72222cc79d58e39f6f00088`; #210's current exact-head checks are regenerating, so the merged child evidence was not promoted to protected-main delivery. - Recorded PR #210's superseded exact-head failures at `bea65643109449d63d367a35b8d9bf327ee7cb2c`: OpenCode had no current-head verdict and Strix exhausted three provider HTTP 500 attempts without a vulnerability report; its direct attempt-2 rerun (`33172708455` / `98915847518`) reached the same fail-closed result, so no failure was promoted to passing evidence for the new head. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 5817aef33..3f4fe357d 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,10 +6,10 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T09:24:51Z` (full inventory and targeted review/check evidence). +Observed at (UTC): `2026-09-05T09:54:54Z` (full inventory and targeted review/check evidence). - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. -- Full live search returns **126 open pull requests: 12 Ready/non-draft and 114 Draft; 13 open non-PR issues**. PR #290 was converted back to Draft after current-protected workflow review found that its #245-relative patch would drop protected #286 lifecycle controls; queue movement is not protected-main delivery. PR #248 also returned to Draft for current-parent adoption and complete revalidation; no PR was closed. +- Full live search returns **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. PR #290 was converted back to Draft after current-protected workflow review found that its #245-relative patch would drop protected #286 lifecycle controls; queue movement is not protected-main delivery. PR #248 also returned to Draft for current-parent adoption and complete revalidation. Temporary synthesis #291 has since been externally merged and closed as recorded below; its closure does not establish product acceptance. - Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `2bd85188a3b3d798824ac04cf3638df84ac2a8bb`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. PR #290 is Draft at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2`, remains a #245-dependent workflow-owner candidate, and is not a root. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2` and PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd` retain formal `CHANGES_REQUESTED` decisions even though every current review thread is resolved. The decisions remain merge blockers until the governing reviewer state changes; thread resolution alone is not approval and is not grounds to dismiss a review. - Targeted CI RCA at `2026-09-05T06:45Z` confirmed that #219 Noema run `33925442322` / job `101226941175` and #240 run `33925596923` / job `101227537529` had terminated on gateway HTTP 502 without review verdicts. Neither unchanged exact head had a successor Noema run. One supported failed-job rerun per head created attempt 2, with queued jobs `101264704581` and `101264705575`; Noema attempt 2 is queue-admission evidence, not provider recovery or a review verdict. Successful sampled Noema wrapper runs skipped their review jobs and cannot establish recovery. The CodeQL failures independently record dispatch handoff: #219 central runs `33947047322`, `33947036734`, `33947037072` and #240 runs `33947189162`, `33947189634`, `33947187643` match those exact heads; these central CodeQL dispatches remain queued and were not duplicated. Active Strix runs were left untouched. Revisit these exact attempts after a terminal result; do not create repeated retries while they remain queued. @@ -41,7 +41,8 @@ Observed at (UTC): `2026-09-05T09:24:51Z` (full inventory and targeted review/ch - PR #246 adopts #243 at `585791f3641fbe757c3bd9fd36d5316adcc78d63`, with exact parent `97fab641ed9d76e6c515eadcef0629edfc8064a3`. Its ordinary merge preserves the message/JSON source and test blobs while carrying the owner fixture repairs. All 141 Python contracts, complete Rust gates and exact 100% pinned-nightly local coverage pass (962 functions, 9701 lines, 12427 regions, 1084 branches). Native CI `33953247053` is queued and this PR remains Draft. Fifty pre-integration fixture-suite runs passed, so no newly reproduced failure or measured failure-rate improvement is claimed. Raw protocol messages still carry no received-connection provenance or browser authority; child integration and hosted acceptance remain pending. - PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 is Draft at `b386f17c4826adabebda084bff2fba35aee94dd0`, now based on #246 `585791f3641fbe757c3bd9fd36d5316adcc78d63` by ordinary merge and explicit retargeting away from the merged #247 branch. Correlation production and Rust test blobs remain unchanged. Review reproduced that native unittest discovery collected zero checks from the free-function release contract; the same assertions now use the repository's TestCase format, collect one check and reject a missing release record. All 142 Python contracts, full Rust gates and exact 100% pinned-nightly local coverage pass (975 functions, 9848 lines, 12563 regions, 1092 branches). Native CI `33953719566` is queued. Previous Ready status and local totals did not prove enforcement of the uncollected check; current hosted verification, protected parents and received-connection authority remain unproven. - PR #249 is Draft at exact head `84b9407978ae0f6c115f01170b6069c601b21104`, ordinarily merged onto current #248 `b386f17c4826adabebda084bff2fba35aee94dd0`. The old `017d6e816f5a86544a63821b3ceaba94d5f17f44` tree lacked that parent and its newly discoverable release check; the parent adoption also reproduced a CHANGELOG-only merge conflict. The integration retains both release records, the parent's canonical opening fixture and native TestCase, and all four child-owned production/Rust-test blobs unchanged. All 142 Python contracts, the full Rust 1.97.1 gates and pinned-nightly 100% coverage pass locally: 989 functions, 9978 lines, 12717 regions, 1098 branches. Fresh exact-head CI `33954334610` is pending, not acceptance. The current #250 adoption is recorded next. -- PR #250 now adopts #249 at `ec433b844a121f8554c062f92267991af9cacb6f`, with exact parent `84b9407978ae0f6c115f01170b6069c601b21104`. The conflict-free ordinary merge preserves all five child-owned production/Rust-test blobs and propagates the canonical fixture and native release TestCase. The pre-integration zero-test discovery RED becomes one executed check; all 142 Python contracts, full Rust 1.97.1 gates and pinned-nightly 100% coverage pass: 1023 functions, 10518 lines, 13525 regions, 1186 branches. Fresh exact-head CI `33955410724` is pending. Bounded status parsing still grants no authority and does not claim the later received-connection capability; #251 must adopt this new parent and revalidate. +- PR #250 now adopts #249 at `ec433b844a121f8554c062f92267991af9cacb6f`, with exact parent `84b9407978ae0f6c115f01170b6069c601b21104`. The conflict-free ordinary merge preserves all five child-owned production/Rust-test blobs and propagates the canonical fixture and native release TestCase. The pre-integration zero-test discovery RED becomes one executed check; all 142 Python contracts, full Rust 1.97.1 gates and pinned-nightly 100% coverage pass: 1023 functions, 10518 lines, 13525 regions, 1186 branches. Fresh exact-head CI `33955410724` is pending. Bounded status parsing still grants no authority and does not claim the later received-connection capability; current #251 adoption is recorded next. +- PR #251 now adopts #250 at `f02af6d0dd01708d495cc08dec785675f3d58898`, ordinarily retaining both exact parents `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc` and `ec433b844a121f8554c062f92267991af9cacb6f`. Only the changelog required content reconciliation; both release records remain. The sender, public exports and both child-owned Rust integration tests are byte-identical to the predecessor. Native release-contract discovery first failed at zero and now executes one test; all 142 Python contracts, compileall, complete Rust 1.97.1 gates and enforced 100% coverage pass: 1037 functions, 10647 lines, 13681 regions, 1192 branches. The pinned branch-instrumentation warning below was independently reproduced on this tree too. Exact CI `33959168801` is queued; Draft, current-parent protection and hosted acceptance remain separate. A successful session-end frame write is not remote completion or process/profile teardown proof. #252 must next adopt this parent non-destructively and revalidate. - PRs #250 through #257 remain Draft. The recorded fully locally verified chain used exact heads #250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`, #251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`, #252 `2015259529ada99af836989079cc85a15779a2d8`, #253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`, #254 `cbaf50dcc97753cc73135497ea8225e8b18de190`, #255 `a13de5f9321e72c1867974eb7a43230f031e58df`, #256 `9f2e6f29be46371762e3031a97c1cac04720694f`, and #257 `ea2b5b78868917219c46f1304558b92490a7f6fe`. Each updated tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. #250 and #257 each had one known macOS socket-observation race; their exact focused retries and complete coverage reruns passed. Exact-head review found that #253 still lets three unauthenticated caller booleans mint `OperationallyComplete`; raw teardown claims must remain explicitly unverified until session-bound transport, process-exit, and profile-removal evidence types are issued by their owning runtime boundaries. Hosted exact-head checks and ordered parent integration remain required. Since that observation, #255 has advanced beyond reviewed head `a13de5f9321e72c1867974eb7a43230f031e58df` with an in-progress connection-provenance repair. Its moving current head is live-metadata-only until the complete repair is reverified; neither the predecessor GREEN nor the earlier #256 parent comparison transfers to those commits. - Reviews [#254](https://github.com/ContextualWisdomLab/OriginWeave/pull/254#pullrequestreview-5120077272) at `cbaf50dcc97753cc73135497ea8225e8b18de190` and [#255](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120077213) at `a13de5f9321e72c1867974eb7a43230f031e58df` found a remaining connection-provenance gap. #254 passed six focused closure tests, formatting, strict network Clippy and network rustdoc locally. #255 removes the parent process/profile booleans and keeps overall teardown pending, but a new loopback regression fails when an acknowledgment from connection A is combined with closure from connection B: the assessment reports the acknowledged transport closed. Both connections can use command id 7; #254 retains only closure kind/status and the acknowledgment retains only its command id. Repair the established-stream, frame/message and command-correlation owners to preserve a non-forgeable connection-generation binding, carry it into acknowledgment and closure evidence, then reject mismatches in #255. Different-session and same-session reconnect regressions are required; endpoint equality, command-id equality and caller-supplied markers are insufficient. This is unresolved evidence integrity, not operational-completion authority or shipped behavior. Both PRs remain Draft with hosted checks queued. - Follow-up review `5120203295` at #255 head `92392b2da33bcd5446c6d2eb1b5504c39e60e3d6` established that received-message provenance must be checked before correlation is consumed. At that reviewed head, sender/closure generations rejected independently parsed evidence, but the two-real-socket response-substitution regression still failed: response B combined with outstanding-command state A became acknowledgment A because its generation came from the registry rather than the received text. The [exact-head review and runnable regression](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120203295) preserve the RED lineage; the later repair evidence below supersedes this failure only for its explicitly tested snapshot. @@ -70,9 +71,10 @@ Observed at (UTC): `2026-09-05T09:24:51Z` (full inventory and targeted review/ch - Current #255 source-owner repair is `ebac126d1632c94775c2454423575275eec45def`, now verified in remote PR metadata on unchanged #254. Its 11-file delta removes the obsolete private accessor, applies pinned formatting and repairs the Rust documentation link without removing received-connection validation. The source owner reports 141 Python contracts, full Rust 1.97.1 verification and coverage functions=1082/1082, lines=11025/11025, regions=14071/14071, branches=1202/1202. This is the owner's new exact-tree local verification, not an independent rerun by this documentation lane or a transfer of earlier GREEN. Exact hosted CI `33957423557` is queued; the earlier `63cbca0...` quality RED is retained as historical RCA, and ordered parent adoption still remains. - The pinned cargo-llvm-cov 0.8.6 branch report emits `warning: --branch option is unstable`. The warning was independently reproduced when reporting the existing #144/#145/#146 measurements, whose numerical verifiers still pass. Thus numerical coverage enforcement is distinct from warning-free instrumentation. The #255 source owner likewise leaves warning-free measurement acceptance outstanding. No warning suppression, coverage exclusion, denominator manipulation or alternate unreviewed measurement is used; compiler/Clippy/rustdoc results, instrumentation maturity, hosted acceptance and release readiness remain separate. -- Current #147 `46e75859ef5aff2054fd6ca1720d518438e97d0f` includes #146 `812c0020...` in ancestry but drops the parent's six review-evidence regressions and reverses their associated production repairs. Native discovery collects zero tests; read-only replay of the exact parent module against this child reproduces 10 assertion failures and 8 uncaught protocol-error cases. Preserve the shared forced-close observer while restoring those valid parent deltas and adapting its observer-specific test injection. Source writer coordination is in progress; the merge title, ancestor presence and earlier 222 passing child tests do not establish successful inheritance or current acceptance. +- Historical #147 `46e75859ef5aff2054fd6ca1720d518438e97d0f` included #146 `812c0020...` in ancestry but dropped the parent's six review-evidence regressions and reversed their associated production repairs. Native discovery collected zero tests; read-only replay of the exact parent module against that child reproduced 10 assertion failures and 8 uncaught protocol-error cases. The merge title, ancestor presence and earlier 222 passing child tests did not establish successful inheritance. +- Current #147 `af1b98ba377c73b88baa9633e2232e7f76e76f36` restores those parent runtime repairs and all six methods through the external synthesis and preserves the combined forced-close observer. Fresh focused discovery executes six methods; all 228 native tests execute but two forced-close protocol-fault subcases fail. The inherited test still patches and asserts the individual root waiter, while the production forced-close lane correctly calls the combined observer. Preserve the ordinary-lane injection and all cleanup, failure-denominator, root-alive, driver-termination and redaction assertions; the forced-close subcases need the combined observer injection and exact root-only identity tuple assertion. This bounded test reconciliation is recorded in [review evidence](https://github.com/ContextualWisdomLab/OriginWeave/pull/147#issuecomment-5550841022) and relayed for writer coordination. Exact CI `33958194363` and compatibility `33958194463` remain non-terminal. No source repair or current GREEN is claimed by this read-only lane. -- A second complete inventory now includes temporary Draft #291, making the live total 126 open / 12 Ready / 114 Draft. Its head `221bcd6fdf0f07e1a873e253993b82d7209b7f52` is the original #147 child, while synthetic base branch `automation/147-merge-base-20260905` points to #146 `812c0020...`. The stated purpose is non-lossy three-way integration, not product acceptance or replacement of #147. This visible active repair route is kept separate from the lossy #147 snapshot; no competing source mutation, merge, closure or inferred successful transfer is performed by this lane. Verify the synthesized content, full inherited tests and real #147 forward adoption before making any succession claim. +- Temporary integration PR #291 is now closed after an external merge into `automation/147-merge-base-20260905`, whose base was #146 `812c0020...`. Live API metadata records head `52575632de07bcb90791e491b9a64b6875532ebe` and merge `24fad0498a49267982805d35d2dd57484efb4671`; Git confirms that merge is an ancestor of current #147 through forward integration `07369a37b54c11c32f810c3d5c107ad6d4b9feb4`. The temporary route neither replaced #147 nor reached protected main. The recovered runtime and test content, remaining two native failures and ordered acceptance requirements are evaluated separately from its merged/closed label. This lane performed no merge or closure. The fresh full inventory is 125 open / 12 Ready / 113 Draft. ## Observed snapshot: 2026-08-29 diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 77d580070..6f962be51 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -26,9 +26,9 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "## Observed snapshot: 2026-08-29", 1 )[0] for marker in ( - "126 open pull requests", + "125 open pull requests", "12 Ready/non-draft", - "114 Draft", + "113 Draft", "13 open non-PR issues", "87c4daa1830bac5a5228b6036752ad5633232085", "18156473", @@ -48,6 +48,11 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "989 functions, 9978 lines, 12717 regions, 1098 branches", "PR #250 now adopts #249 at `ec433b844a121f8554c062f92267991af9cacb6f`", "1023 functions, 10518 lines, 13525 regions, 1186 branches", + "PR #251 now adopts #250 at `f02af6d0dd01708d495cc08dec785675f3d58898`", + "1037 functions, 10647 lines, 13681 regions, 1192 branches", + "Current #147 `af1b98ba377c73b88baa9633e2232e7f76e76f36`", + "all 228 native tests execute but two forced-close protocol-fault subcases fail", + "Temporary integration PR #291 is now closed", "PR #142 at `015025f2539e4fb1dbd7d259ec22dad50f944396`", "187 Python contracts passed", "PR #143 at `44fd9a450f864feff5cf2ba2883425a71ba10b9b`", @@ -215,7 +220,7 @@ def test_unreleased_changelog_uses_one_current_inventory(self) -> None: preamble, remainder = unreleased.split("### Added", 1) added = remainder.split("### Changed", 1)[0] - expected = "126 open pull requests (12 ready, 114 draft)" + expected = "125 open pull requests (12 ready, 113 draft)" self.assertIn(expected, preamble) self.assertIn("13 open non-PR issues", preamble) self.assertIn(expected, added) From 6a2ff086c526eca4122a15dd49dc6845bdb0034d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 19:17:10 +0900 Subject: [PATCH 156/250] docs: preserve teardown red to green and response integration Record #252 current-parent verification and #147 test-only reconciliation while retaining the preceding lossy-integration and two-failure evidence. Keep ordinary-pass deadlines, instrumentation warning, hosted checks and protected delivery separate. Four missing current-evidence assertions failed before this update; all 169 repository tests, compileall and diff checks now pass. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 10 ++++++---- tests/test_gap_snapshot_inventory_consistency.py | 5 ++++- 3 files changed, 11 insertions(+), 5 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index e0ecda399..9acc85a95 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded #252's verified current-parent integration and #147's test-only repair from two reproduced failures to all 228 passing tests, preserving the earlier RED history, ordinary-pass deadline finding and instrumentation warning. - Recorded #251's verified parent integration and #147's restored parent evidence with two remaining test-reconciliation failures; distinguished the externally closed temporary synthesis from product acceptance and refreshed the live inventory. - Recorded #255's new owner-verified repair separately from its prior quality failures, retained the real branch-instrumentation warning, and identified #147's lossy parent adoption with a failing replay of six omitted regressions. - Recorded #144/#145 parent adoption, #146's reproduced cleanup-evidence fixes and preserved concurrent integration, with complete local verification separated from queued hosted compatibility; refreshed #287's executed Strix scan and failed Noema gateway retry evidence without claiming recovery or approval. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 3f4fe357d..0858438f3 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,7 +6,7 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T09:54:54Z` (full inventory and targeted review/check evidence). +Observed at (UTC): `2026-09-05T10:14:40Z` (full inventory and targeted review/check evidence). - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. PR #290 was converted back to Draft after current-protected workflow review found that its #245-relative patch would drop protected #286 lifecycle controls; queue movement is not protected-main delivery. PR #248 also returned to Draft for current-parent adoption and complete revalidation. Temporary synthesis #291 has since been externally merged and closed as recorded below; its closure does not establish product acceptance. @@ -42,7 +42,8 @@ Observed at (UTC): `2026-09-05T09:54:54Z` (full inventory and targeted review/ch - PR #247 exact head `6407895f4db4bee640074cb9c9d3cbe8b0e9e13a` merged as `b87191bcb6a95dfd7e0ed234e600639a1093c43a` into unprotected parent `feat/webdriver-bidi-text-message-assembly`; this is stack integration, not protected-main delivery. PR #248 is Draft at `b386f17c4826adabebda084bff2fba35aee94dd0`, now based on #246 `585791f3641fbe757c3bd9fd36d5316adcc78d63` by ordinary merge and explicit retargeting away from the merged #247 branch. Correlation production and Rust test blobs remain unchanged. Review reproduced that native unittest discovery collected zero checks from the free-function release contract; the same assertions now use the repository's TestCase format, collect one check and reject a missing release record. All 142 Python contracts, full Rust gates and exact 100% pinned-nightly local coverage pass (975 functions, 9848 lines, 12563 regions, 1092 branches). Native CI `33953719566` is queued. Previous Ready status and local totals did not prove enforcement of the uncollected check; current hosted verification, protected parents and received-connection authority remain unproven. - PR #249 is Draft at exact head `84b9407978ae0f6c115f01170b6069c601b21104`, ordinarily merged onto current #248 `b386f17c4826adabebda084bff2fba35aee94dd0`. The old `017d6e816f5a86544a63821b3ceaba94d5f17f44` tree lacked that parent and its newly discoverable release check; the parent adoption also reproduced a CHANGELOG-only merge conflict. The integration retains both release records, the parent's canonical opening fixture and native TestCase, and all four child-owned production/Rust-test blobs unchanged. All 142 Python contracts, the full Rust 1.97.1 gates and pinned-nightly 100% coverage pass locally: 989 functions, 9978 lines, 12717 regions, 1098 branches. Fresh exact-head CI `33954334610` is pending, not acceptance. The current #250 adoption is recorded next. - PR #250 now adopts #249 at `ec433b844a121f8554c062f92267991af9cacb6f`, with exact parent `84b9407978ae0f6c115f01170b6069c601b21104`. The conflict-free ordinary merge preserves all five child-owned production/Rust-test blobs and propagates the canonical fixture and native release TestCase. The pre-integration zero-test discovery RED becomes one executed check; all 142 Python contracts, full Rust 1.97.1 gates and pinned-nightly 100% coverage pass: 1023 functions, 10518 lines, 13525 regions, 1186 branches. Fresh exact-head CI `33955410724` is pending. Bounded status parsing still grants no authority and does not claim the later received-connection capability; current #251 adoption is recorded next. -- PR #251 now adopts #250 at `f02af6d0dd01708d495cc08dec785675f3d58898`, ordinarily retaining both exact parents `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc` and `ec433b844a121f8554c062f92267991af9cacb6f`. Only the changelog required content reconciliation; both release records remain. The sender, public exports and both child-owned Rust integration tests are byte-identical to the predecessor. Native release-contract discovery first failed at zero and now executes one test; all 142 Python contracts, compileall, complete Rust 1.97.1 gates and enforced 100% coverage pass: 1037 functions, 10647 lines, 13681 regions, 1192 branches. The pinned branch-instrumentation warning below was independently reproduced on this tree too. Exact CI `33959168801` is queued; Draft, current-parent protection and hosted acceptance remain separate. A successful session-end frame write is not remote completion or process/profile teardown proof. #252 must next adopt this parent non-destructively and revalidate. +- PR #251 now adopts #250 at `f02af6d0dd01708d495cc08dec785675f3d58898`, ordinarily retaining both exact parents `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc` and `ec433b844a121f8554c062f92267991af9cacb6f`. Only the changelog required content reconciliation; both release records remain. The sender, public exports and both child-owned Rust integration tests are byte-identical to the predecessor. Native release-contract discovery first failed at zero and now executes one test; all 142 Python contracts, compileall, complete Rust 1.97.1 gates and enforced 100% coverage pass: 1037 functions, 10647 lines, 13681 regions, 1192 branches. The pinned branch-instrumentation warning below was independently reproduced on this tree too. Exact CI `33959168801` is queued; Draft, current-parent protection and hosted acceptance remain separate. A successful session-end frame write is not remote completion or process/profile teardown proof. Current #252 adoption is recorded next. +- PR #252 now adopts #251 at `6569bf40b6595ac74c2f0a997d202137f07ba1db`, retaining predecessor `2015259529ada99af836989079cc85a15779a2d8` and current parent `f02af6d0...` by ordinary merge. The response implementation, public exports and four loopback response tests are unchanged; both conflicting release records remain. The inherited release-contract loader moves from zero RED to one executed GREEN, and all 142 Python contracts, compileall and complete Rust 1.97.1 gates pass. Enforced numerical coverage is 100%: 1044 functions, 10699 lines, 13751 regions, 1192 branches; the branch-instrumentation warning remains. Exact CI `33959789688` is queued. This response layer does not authenticate the received connection or prove resource teardown. #253 must adopt the current parent and revalidate; the later #255 provenance repair remains separately owned. - PRs #250 through #257 remain Draft. The recorded fully locally verified chain used exact heads #250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`, #251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`, #252 `2015259529ada99af836989079cc85a15779a2d8`, #253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`, #254 `cbaf50dcc97753cc73135497ea8225e8b18de190`, #255 `a13de5f9321e72c1867974eb7a43230f031e58df`, #256 `9f2e6f29be46371762e3031a97c1cac04720694f`, and #257 `ea2b5b78868917219c46f1304558b92490a7f6fe`. Each updated tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. #250 and #257 each had one known macOS socket-observation race; their exact focused retries and complete coverage reruns passed. Exact-head review found that #253 still lets three unauthenticated caller booleans mint `OperationallyComplete`; raw teardown claims must remain explicitly unverified until session-bound transport, process-exit, and profile-removal evidence types are issued by their owning runtime boundaries. Hosted exact-head checks and ordered parent integration remain required. Since that observation, #255 has advanced beyond reviewed head `a13de5f9321e72c1867974eb7a43230f031e58df` with an in-progress connection-provenance repair. Its moving current head is live-metadata-only until the complete repair is reverified; neither the predecessor GREEN nor the earlier #256 parent comparison transfers to those commits. - Reviews [#254](https://github.com/ContextualWisdomLab/OriginWeave/pull/254#pullrequestreview-5120077272) at `cbaf50dcc97753cc73135497ea8225e8b18de190` and [#255](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120077213) at `a13de5f9321e72c1867974eb7a43230f031e58df` found a remaining connection-provenance gap. #254 passed six focused closure tests, formatting, strict network Clippy and network rustdoc locally. #255 removes the parent process/profile booleans and keeps overall teardown pending, but a new loopback regression fails when an acknowledgment from connection A is combined with closure from connection B: the assessment reports the acknowledged transport closed. Both connections can use command id 7; #254 retains only closure kind/status and the acknowledgment retains only its command id. Repair the established-stream, frame/message and command-correlation owners to preserve a non-forgeable connection-generation binding, carry it into acknowledgment and closure evidence, then reject mismatches in #255. Different-session and same-session reconnect regressions are required; endpoint equality, command-id equality and caller-supplied markers are insufficient. This is unresolved evidence integrity, not operational-completion authority or shipped behavior. Both PRs remain Draft with hosted checks queued. - Follow-up review `5120203295` at #255 head `92392b2da33bcd5446c6d2eb1b5504c39e60e3d6` established that received-message provenance must be checked before correlation is consumed. At that reviewed head, sender/closure generations rejected independently parsed evidence, but the two-real-socket response-substitution regression still failed: response B combined with outstanding-command state A became acknowledgment A because its generation came from the registry rather than the received text. The [exact-head review and runnable regression](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120203295) preserve the RED lineage; the later repair evidence below supersedes this failure only for its explicitly tested snapshot. @@ -72,9 +73,10 @@ Observed at (UTC): `2026-09-05T09:54:54Z` (full inventory and targeted review/ch - Current #255 source-owner repair is `ebac126d1632c94775c2454423575275eec45def`, now verified in remote PR metadata on unchanged #254. Its 11-file delta removes the obsolete private accessor, applies pinned formatting and repairs the Rust documentation link without removing received-connection validation. The source owner reports 141 Python contracts, full Rust 1.97.1 verification and coverage functions=1082/1082, lines=11025/11025, regions=14071/14071, branches=1202/1202. This is the owner's new exact-tree local verification, not an independent rerun by this documentation lane or a transfer of earlier GREEN. Exact hosted CI `33957423557` is queued; the earlier `63cbca0...` quality RED is retained as historical RCA, and ordered parent adoption still remains. - The pinned cargo-llvm-cov 0.8.6 branch report emits `warning: --branch option is unstable`. The warning was independently reproduced when reporting the existing #144/#145/#146 measurements, whose numerical verifiers still pass. Thus numerical coverage enforcement is distinct from warning-free instrumentation. The #255 source owner likewise leaves warning-free measurement acceptance outstanding. No warning suppression, coverage exclusion, denominator manipulation or alternate unreviewed measurement is used; compiler/Clippy/rustdoc results, instrumentation maturity, hosted acceptance and release readiness remain separate. - Historical #147 `46e75859ef5aff2054fd6ca1720d518438e97d0f` included #146 `812c0020...` in ancestry but dropped the parent's six review-evidence regressions and reversed their associated production repairs. Native discovery collected zero tests; read-only replay of the exact parent module against that child reproduced 10 assertion failures and 8 uncaught protocol-error cases. The merge title, ancestor presence and earlier 222 passing child tests did not establish successful inheritance. -- Current #147 `af1b98ba377c73b88baa9633e2232e7f76e76f36` restores those parent runtime repairs and all six methods through the external synthesis and preserves the combined forced-close observer. Fresh focused discovery executes six methods; all 228 native tests execute but two forced-close protocol-fault subcases fail. The inherited test still patches and asserts the individual root waiter, while the production forced-close lane correctly calls the combined observer. Preserve the ordinary-lane injection and all cleanup, failure-denominator, root-alive, driver-termination and redaction assertions; the forced-close subcases need the combined observer injection and exact root-only identity tuple assertion. This bounded test reconciliation is recorded in [review evidence](https://github.com/ContextualWisdomLab/OriginWeave/pull/147#issuecomment-5550841022) and relayed for writer coordination. Exact CI `33958194363` and compatibility `33958194463` remain non-terminal. No source repair or current GREEN is claimed by this read-only lane. +- At predecessor #147 `af1b98ba377c73b88baa9633e2232e7f76e76f36`, the external synthesis restored parent runtime repairs and all six methods while preserving the combined forced-close observer. Its recorded RED is that all 228 native tests execute but two forced-close protocol-fault subcases fail. The inherited test injected the individual root waiter although the forced-close lane called the combined observer; a fresh focused reproduction took 10.417 seconds. The [review evidence](https://github.com/ContextualWisdomLab/OriginWeave/pull/147#issuecomment-5550841022) retains this failure and its subsequent repair rather than treating recovered ancestry as acceptance. +- Current #147 `3dff28d9bf2dd27b72507e39979d51b8bf140fb4` repairs only that lane-specific test injection and its documentation. Ordinary cases retain the individual False result; forced-close cases inject the combined (False, False) result and assert the exact root-only identity tuple. Every existing assertion and all six methods remain; all six focused and all 228 native tests now pass, along with compileall, complete Rust 1.97.1 gates and the same 415/3555/4444/476 numerical 100% coverage. Production, deadlines, retry policy and failure denominators are unchanged; the branch warning remains explicit. Writer reassessment occurred after the temporary route closed and contacted tasks confirmed read-only status; the current repair is a normal forward push. CI `33959982049` is pending and compatibility `33959982033` is queued. The ordinary-pass two-deadline finding stays unresolved in the separate #150 scope; no hosted, protected-main or real-browser acceptance is claimed. -- Temporary integration PR #291 is now closed after an external merge into `automation/147-merge-base-20260905`, whose base was #146 `812c0020...`. Live API metadata records head `52575632de07bcb90791e491b9a64b6875532ebe` and merge `24fad0498a49267982805d35d2dd57484efb4671`; Git confirms that merge is an ancestor of current #147 through forward integration `07369a37b54c11c32f810c3d5c107ad6d4b9feb4`. The temporary route neither replaced #147 nor reached protected main. The recovered runtime and test content, remaining two native failures and ordered acceptance requirements are evaluated separately from its merged/closed label. This lane performed no merge or closure. The fresh full inventory is 125 open / 12 Ready / 113 Draft. +- Temporary integration PR #291 is now closed after an external merge into `automation/147-merge-base-20260905`, whose base was #146 `812c0020...`. Live API metadata records head `52575632de07bcb90791e491b9a64b6875532ebe` and merge `24fad0498a49267982805d35d2dd57484efb4671`; Git confirms that merge is an ancestor of current #147 through forward integration `07369a37b54c11c32f810c3d5c107ad6d4b9feb4`. The temporary route neither replaced #147 nor reached protected main. The recovered runtime and test content, subsequent test-reconciliation repair and ordered acceptance requirements are evaluated separately from its merged/closed label. This lane performed no merge or closure. The fresh full inventory is 125 open / 12 Ready / 113 Draft. ## Observed snapshot: 2026-08-29 diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 6f962be51..41941c57b 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -50,7 +50,10 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "1023 functions, 10518 lines, 13525 regions, 1186 branches", "PR #251 now adopts #250 at `f02af6d0dd01708d495cc08dec785675f3d58898`", "1037 functions, 10647 lines, 13681 regions, 1192 branches", - "Current #147 `af1b98ba377c73b88baa9633e2232e7f76e76f36`", + "PR #252 now adopts #251 at `6569bf40b6595ac74c2f0a997d202137f07ba1db`", + "1044 functions, 10699 lines, 13751 regions, 1192 branches", + "Current #147 `3dff28d9bf2dd27b72507e39979d51b8bf140fb4`", + "all six focused and all 228 native tests now pass", "all 228 native tests execute but two forced-close protocol-fault subcases fail", "Temporary integration PR #291 is now closed", "PR #142 at `015025f2539e4fb1dbd7d259ec22dad50f944396`", From b40e33b19734bd72befe78be42832ab0bfeaaebd Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 19:35:49 +0900 Subject: [PATCH 157/250] docs: record teardown parent integration limits Preserve the unresolved teardown-evidence finding beside exact-head local validation, without promoting coverage to operational acceptance. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 5 +++-- tests/test_gap_snapshot_inventory_consistency.py | 3 +++ 3 files changed, 7 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 9acc85a95..d4220f0bd 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded #253's verified current-parent integration while retaining its unresolved teardown-evidence finding, downstream repair ownership and instrumentation warning; local passing checks do not establish operational completion. - Recorded #252's verified current-parent integration and #147's test-only repair from two reproduced failures to all 228 passing tests, preserving the earlier RED history, ordinary-pass deadline finding and instrumentation warning. - Recorded #251's verified parent integration and #147's restored parent evidence with two remaining test-reconciliation failures; distinguished the externally closed temporary synthesis from product acceptance and refreshed the live inventory. - Recorded #255's new owner-verified repair separately from its prior quality failures, retained the real branch-instrumentation warning, and identified #147's lossy parent adoption with a failing replay of six omitted regressions. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 0858438f3..dbb570b80 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,7 +6,7 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T10:14:40Z` (full inventory and targeted review/check evidence). +Observed at (UTC): `2026-09-05T10:30:00Z` (full inventory and targeted review/check evidence). - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. PR #290 was converted back to Draft after current-protected workflow review found that its #245-relative patch would drop protected #286 lifecycle controls; queue movement is not protected-main delivery. PR #248 also returned to Draft for current-parent adoption and complete revalidation. Temporary synthesis #291 has since been externally merged and closed as recorded below; its closure does not establish product acceptance. @@ -43,7 +43,8 @@ Observed at (UTC): `2026-09-05T10:14:40Z` (full inventory and targeted review/ch - PR #249 is Draft at exact head `84b9407978ae0f6c115f01170b6069c601b21104`, ordinarily merged onto current #248 `b386f17c4826adabebda084bff2fba35aee94dd0`. The old `017d6e816f5a86544a63821b3ceaba94d5f17f44` tree lacked that parent and its newly discoverable release check; the parent adoption also reproduced a CHANGELOG-only merge conflict. The integration retains both release records, the parent's canonical opening fixture and native TestCase, and all four child-owned production/Rust-test blobs unchanged. All 142 Python contracts, the full Rust 1.97.1 gates and pinned-nightly 100% coverage pass locally: 989 functions, 9978 lines, 12717 regions, 1098 branches. Fresh exact-head CI `33954334610` is pending, not acceptance. The current #250 adoption is recorded next. - PR #250 now adopts #249 at `ec433b844a121f8554c062f92267991af9cacb6f`, with exact parent `84b9407978ae0f6c115f01170b6069c601b21104`. The conflict-free ordinary merge preserves all five child-owned production/Rust-test blobs and propagates the canonical fixture and native release TestCase. The pre-integration zero-test discovery RED becomes one executed check; all 142 Python contracts, full Rust 1.97.1 gates and pinned-nightly 100% coverage pass: 1023 functions, 10518 lines, 13525 regions, 1186 branches. Fresh exact-head CI `33955410724` is pending. Bounded status parsing still grants no authority and does not claim the later received-connection capability; current #251 adoption is recorded next. - PR #251 now adopts #250 at `f02af6d0dd01708d495cc08dec785675f3d58898`, ordinarily retaining both exact parents `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc` and `ec433b844a121f8554c062f92267991af9cacb6f`. Only the changelog required content reconciliation; both release records remain. The sender, public exports and both child-owned Rust integration tests are byte-identical to the predecessor. Native release-contract discovery first failed at zero and now executes one test; all 142 Python contracts, compileall, complete Rust 1.97.1 gates and enforced 100% coverage pass: 1037 functions, 10647 lines, 13681 regions, 1192 branches. The pinned branch-instrumentation warning below was independently reproduced on this tree too. Exact CI `33959168801` is queued; Draft, current-parent protection and hosted acceptance remain separate. A successful session-end frame write is not remote completion or process/profile teardown proof. Current #252 adoption is recorded next. -- PR #252 now adopts #251 at `6569bf40b6595ac74c2f0a997d202137f07ba1db`, retaining predecessor `2015259529ada99af836989079cc85a15779a2d8` and current parent `f02af6d0...` by ordinary merge. The response implementation, public exports and four loopback response tests are unchanged; both conflicting release records remain. The inherited release-contract loader moves from zero RED to one executed GREEN, and all 142 Python contracts, compileall and complete Rust 1.97.1 gates pass. Enforced numerical coverage is 100%: 1044 functions, 10699 lines, 13751 regions, 1192 branches; the branch-instrumentation warning remains. Exact CI `33959789688` is queued. This response layer does not authenticate the received connection or prove resource teardown. #253 must adopt the current parent and revalidate; the later #255 provenance repair remains separately owned. +- PR #252 now adopts #251 at `6569bf40b6595ac74c2f0a997d202137f07ba1db`, retaining predecessor `2015259529ada99af836989079cc85a15779a2d8` and current parent `f02af6d0...` by ordinary merge. The response implementation, public exports and four loopback response tests are unchanged; both conflicting release records remain. The inherited release-contract loader moves from zero RED to one executed GREEN, and all 142 Python contracts, compileall and complete Rust 1.97.1 gates pass. Enforced numerical coverage is 100%: 1044 functions, 10699 lines, 13751 regions, 1192 branches; the branch-instrumentation warning remains. Exact CI `33959789688` is queued. This response layer does not authenticate the received connection or prove resource teardown. #253's current-parent adoption is recorded next; the later #255 provenance repair remains separately owned. +- PR #253 now adopts #252 at `afb623e4449b7cbf926fdcef7225ceaca822cfcf`, retaining predecessor `0d72082e595c0e1fcc03d609ba337896ed14e2fc` and current parent `6569bf40...` by ordinary merge. The assessment implementation, public exports and two child tests are unchanged; both conflicting release records remain. Native inherited release-contract discovery moves from zero RED to one executed GREEN. All 142 Python contracts, compileall and complete Rust 1.97.1 gates pass, with enforced numerical 100% coverage: 1054 functions, 10747 lines, 13787 regions, 1194 branches. The branch-instrumentation warning remains, and exact CI `33960670119` is queued. Review `5120013340` remains unresolved: caller-supplied teardown claims still cannot authenticate operational completion, regardless of local coverage. #254 must adopt this parent and revalidate while preserving #255's separately owned removal/provenance repair. This intermediate Draft is not security or operational acceptance. - PRs #250 through #257 remain Draft. The recorded fully locally verified chain used exact heads #250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`, #251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`, #252 `2015259529ada99af836989079cc85a15779a2d8`, #253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`, #254 `cbaf50dcc97753cc73135497ea8225e8b18de190`, #255 `a13de5f9321e72c1867974eb7a43230f031e58df`, #256 `9f2e6f29be46371762e3031a97c1cac04720694f`, and #257 `ea2b5b78868917219c46f1304558b92490a7f6fe`. Each updated tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. #250 and #257 each had one known macOS socket-observation race; their exact focused retries and complete coverage reruns passed. Exact-head review found that #253 still lets three unauthenticated caller booleans mint `OperationallyComplete`; raw teardown claims must remain explicitly unverified until session-bound transport, process-exit, and profile-removal evidence types are issued by their owning runtime boundaries. Hosted exact-head checks and ordered parent integration remain required. Since that observation, #255 has advanced beyond reviewed head `a13de5f9321e72c1867974eb7a43230f031e58df` with an in-progress connection-provenance repair. Its moving current head is live-metadata-only until the complete repair is reverified; neither the predecessor GREEN nor the earlier #256 parent comparison transfers to those commits. - Reviews [#254](https://github.com/ContextualWisdomLab/OriginWeave/pull/254#pullrequestreview-5120077272) at `cbaf50dcc97753cc73135497ea8225e8b18de190` and [#255](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120077213) at `a13de5f9321e72c1867974eb7a43230f031e58df` found a remaining connection-provenance gap. #254 passed six focused closure tests, formatting, strict network Clippy and network rustdoc locally. #255 removes the parent process/profile booleans and keeps overall teardown pending, but a new loopback regression fails when an acknowledgment from connection A is combined with closure from connection B: the assessment reports the acknowledged transport closed. Both connections can use command id 7; #254 retains only closure kind/status and the acknowledgment retains only its command id. Repair the established-stream, frame/message and command-correlation owners to preserve a non-forgeable connection-generation binding, carry it into acknowledgment and closure evidence, then reject mismatches in #255. Different-session and same-session reconnect regressions are required; endpoint equality, command-id equality and caller-supplied markers are insufficient. This is unresolved evidence integrity, not operational-completion authority or shipped behavior. Both PRs remain Draft with hosted checks queued. - Follow-up review `5120203295` at #255 head `92392b2da33bcd5446c6d2eb1b5504c39e60e3d6` established that received-message provenance must be checked before correlation is consumed. At that reviewed head, sender/closure generations rejected independently parsed evidence, but the two-real-socket response-substitution regression still failed: response B combined with outstanding-command state A became acknowledgment A because its generation came from the registry rather than the received text. The [exact-head review and runnable regression](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120203295) preserve the RED lineage; the later repair evidence below supersedes this failure only for its explicitly tested snapshot. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 41941c57b..ca591056b 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -52,6 +52,9 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "1037 functions, 10647 lines, 13681 regions, 1192 branches", "PR #252 now adopts #251 at `6569bf40b6595ac74c2f0a997d202137f07ba1db`", "1044 functions, 10699 lines, 13751 regions, 1192 branches", + "PR #253 now adopts #252 at `afb623e4449b7cbf926fdcef7225ceaca822cfcf`", + "1054 functions, 10747 lines, 13787 regions, 1194 branches", + "Review `5120013340` remains unresolved", "Current #147 `3dff28d9bf2dd27b72507e39979d51b8bf140fb4`", "all six focused and all 228 native tests now pass", "all 228 native tests execute but two forced-close protocol-fault subcases fail", From 6be4771652382990000d034e6731028c103a5087 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 20:29:21 +0900 Subject: [PATCH 158/250] docs: record cleanup verification and scan failure evidence Preserve current-parent source validation and actual Linux contract evidence while separating hosted scan classification failures from gateway and execution-limit failures. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 11 +++++++++-- tests/test_gap_snapshot_inventory_consistency.py | 12 ++++++++++++ 3 files changed, 22 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index d4220f0bd..d17282a70 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded #254 parent adoption, #148's crash-launch sandbox repair and #150's shared-observer test reconciliation, including complete local verification and matched-source Linux runs; separated the reproduced central scan-classifier defect from a gateway failure and hosted execution-limit cancellation. - Recorded #253's verified current-parent integration while retaining its unresolved teardown-evidence finding, downstream repair ownership and instrumentation warning; local passing checks do not establish operational completion. - Recorded #252's verified current-parent integration and #147's test-only repair from two reproduced failures to all 228 passing tests, preserving the earlier RED history, ordinary-pass deadline finding and instrumentation warning. - Recorded #251's verified parent integration and #147's restored parent evidence with two remaining test-reconciliation failures; distinguished the externally closed temporary synthesis from product acceptance and refreshed the live inventory. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index dbb570b80..a9c8f96f7 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,7 +6,7 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T10:30:00Z` (full inventory and targeted review/check evidence). +Observed at (UTC): `2026-09-05T11:25:43Z` (full inventory and targeted review/check evidence). - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. PR #290 was converted back to Draft after current-protected workflow review found that its #245-relative patch would drop protected #286 lifecycle controls; queue movement is not protected-main delivery. PR #248 also returned to Draft for current-parent adoption and complete revalidation. Temporary synthesis #291 has since been externally merged and closed as recorded below; its closure does not establish product acceptance. @@ -44,7 +44,8 @@ Observed at (UTC): `2026-09-05T10:30:00Z` (full inventory and targeted review/ch - PR #250 now adopts #249 at `ec433b844a121f8554c062f92267991af9cacb6f`, with exact parent `84b9407978ae0f6c115f01170b6069c601b21104`. The conflict-free ordinary merge preserves all five child-owned production/Rust-test blobs and propagates the canonical fixture and native release TestCase. The pre-integration zero-test discovery RED becomes one executed check; all 142 Python contracts, full Rust 1.97.1 gates and pinned-nightly 100% coverage pass: 1023 functions, 10518 lines, 13525 regions, 1186 branches. Fresh exact-head CI `33955410724` is pending. Bounded status parsing still grants no authority and does not claim the later received-connection capability; current #251 adoption is recorded next. - PR #251 now adopts #250 at `f02af6d0dd01708d495cc08dec785675f3d58898`, ordinarily retaining both exact parents `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc` and `ec433b844a121f8554c062f92267991af9cacb6f`. Only the changelog required content reconciliation; both release records remain. The sender, public exports and both child-owned Rust integration tests are byte-identical to the predecessor. Native release-contract discovery first failed at zero and now executes one test; all 142 Python contracts, compileall, complete Rust 1.97.1 gates and enforced 100% coverage pass: 1037 functions, 10647 lines, 13681 regions, 1192 branches. The pinned branch-instrumentation warning below was independently reproduced on this tree too. Exact CI `33959168801` is queued; Draft, current-parent protection and hosted acceptance remain separate. A successful session-end frame write is not remote completion or process/profile teardown proof. Current #252 adoption is recorded next. - PR #252 now adopts #251 at `6569bf40b6595ac74c2f0a997d202137f07ba1db`, retaining predecessor `2015259529ada99af836989079cc85a15779a2d8` and current parent `f02af6d0...` by ordinary merge. The response implementation, public exports and four loopback response tests are unchanged; both conflicting release records remain. The inherited release-contract loader moves from zero RED to one executed GREEN, and all 142 Python contracts, compileall and complete Rust 1.97.1 gates pass. Enforced numerical coverage is 100%: 1044 functions, 10699 lines, 13751 regions, 1192 branches; the branch-instrumentation warning remains. Exact CI `33959789688` is queued. This response layer does not authenticate the received connection or prove resource teardown. #253's current-parent adoption is recorded next; the later #255 provenance repair remains separately owned. -- PR #253 now adopts #252 at `afb623e4449b7cbf926fdcef7225ceaca822cfcf`, retaining predecessor `0d72082e595c0e1fcc03d609ba337896ed14e2fc` and current parent `6569bf40...` by ordinary merge. The assessment implementation, public exports and two child tests are unchanged; both conflicting release records remain. Native inherited release-contract discovery moves from zero RED to one executed GREEN. All 142 Python contracts, compileall and complete Rust 1.97.1 gates pass, with enforced numerical 100% coverage: 1054 functions, 10747 lines, 13787 regions, 1194 branches. The branch-instrumentation warning remains, and exact CI `33960670119` is queued. Review `5120013340` remains unresolved: caller-supplied teardown claims still cannot authenticate operational completion, regardless of local coverage. #254 must adopt this parent and revalidate while preserving #255's separately owned removal/provenance repair. This intermediate Draft is not security or operational acceptance. +- PR #253 now adopts #252 at `afb623e4449b7cbf926fdcef7225ceaca822cfcf`, retaining predecessor `0d72082e595c0e1fcc03d609ba337896ed14e2fc` and current parent `6569bf40...` by ordinary merge. The assessment implementation, public exports and two child tests are unchanged; both conflicting release records remain. Native inherited release-contract discovery moves from zero RED to one executed GREEN. All 142 Python contracts, compileall and complete Rust 1.97.1 gates pass, with enforced numerical 100% coverage: 1054 functions, 10747 lines, 13787 regions, 1194 branches. The branch-instrumentation warning remains, and exact CI `33960670119` is queued. Review `5120013340` remains unresolved: caller-supplied teardown claims still cannot authenticate operational completion, regardless of local coverage. The #254 adoption below preserves #255's separately owned removal/provenance repair as a remaining prerequisite. This intermediate Draft is not security or operational acceptance. +- PR #254 now adopts #253 at `b11b6c9bccd8335b58a4fb599f8ad29ac419637f`, retaining predecessor `cbaf50dcc97753cc73135497ea8225e8b18de190` by ordinary merge. The closure implementation, public exports and all six real-loopback child tests are byte-identical to that predecessor; both release records survive the changelog conflict. The inherited correlation release test moves from zero collected RED to one executed GREEN. All 142 Python contracts, compileall and complete Rust 1.97.1 gates pass, with numerical 100% coverage: 1061 functions, 10802 lines, 13843 regions, 1200 branches. Review `5120077272` remains actionable: closure kind/status still cannot establish that the acknowledged connection generation closed. Exact CI `33961562189` is queued; #255 must adopt this parent while preserving its connection-provenance repair. Neither coverage nor loopback tests authenticate the missing connection binding, and the instrumentation warning remains. - PRs #250 through #257 remain Draft. The recorded fully locally verified chain used exact heads #250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`, #251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`, #252 `2015259529ada99af836989079cc85a15779a2d8`, #253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`, #254 `cbaf50dcc97753cc73135497ea8225e8b18de190`, #255 `a13de5f9321e72c1867974eb7a43230f031e58df`, #256 `9f2e6f29be46371762e3031a97c1cac04720694f`, and #257 `ea2b5b78868917219c46f1304558b92490a7f6fe`. Each updated tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. #250 and #257 each had one known macOS socket-observation race; their exact focused retries and complete coverage reruns passed. Exact-head review found that #253 still lets three unauthenticated caller booleans mint `OperationallyComplete`; raw teardown claims must remain explicitly unverified until session-bound transport, process-exit, and profile-removal evidence types are issued by their owning runtime boundaries. Hosted exact-head checks and ordered parent integration remain required. Since that observation, #255 has advanced beyond reviewed head `a13de5f9321e72c1867974eb7a43230f031e58df` with an in-progress connection-provenance repair. Its moving current head is live-metadata-only until the complete repair is reverified; neither the predecessor GREEN nor the earlier #256 parent comparison transfers to those commits. - Reviews [#254](https://github.com/ContextualWisdomLab/OriginWeave/pull/254#pullrequestreview-5120077272) at `cbaf50dcc97753cc73135497ea8225e8b18de190` and [#255](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120077213) at `a13de5f9321e72c1867974eb7a43230f031e58df` found a remaining connection-provenance gap. #254 passed six focused closure tests, formatting, strict network Clippy and network rustdoc locally. #255 removes the parent process/profile booleans and keeps overall teardown pending, but a new loopback regression fails when an acknowledgment from connection A is combined with closure from connection B: the assessment reports the acknowledged transport closed. Both connections can use command id 7; #254 retains only closure kind/status and the acknowledgment retains only its command id. Repair the established-stream, frame/message and command-correlation owners to preserve a non-forgeable connection-generation binding, carry it into acknowledgment and closure evidence, then reject mismatches in #255. Different-session and same-session reconnect regressions are required; endpoint equality, command-id equality and caller-supplied markers are insufficient. This is unresolved evidence integrity, not operational-completion authority or shipped behavior. Both PRs remain Draft with hosted checks queued. - Follow-up review `5120203295` at #255 head `92392b2da33bcd5446c6d2eb1b5504c39e60e3d6` established that received-message provenance must be checked before correlation is consumed. At that reviewed head, sender/closure generations rejected independently parsed evidence, but the two-real-socket response-substitution regression still failed: response B combined with outstanding-command state A became acknowledgment A because its generation came from the registry rather than the received text. The [exact-head review and runnable regression](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120203295) preserve the RED lineage; the later repair evidence below supersedes this failure only for its explicitly tested snapshot. @@ -76,6 +77,12 @@ Observed at (UTC): `2026-09-05T10:30:00Z` (full inventory and targeted review/ch - Historical #147 `46e75859ef5aff2054fd6ca1720d518438e97d0f` included #146 `812c0020...` in ancestry but dropped the parent's six review-evidence regressions and reversed their associated production repairs. Native discovery collected zero tests; read-only replay of the exact parent module against that child reproduced 10 assertion failures and 8 uncaught protocol-error cases. The merge title, ancestor presence and earlier 222 passing child tests did not establish successful inheritance. - At predecessor #147 `af1b98ba377c73b88baa9633e2232e7f76e76f36`, the external synthesis restored parent runtime repairs and all six methods while preserving the combined forced-close observer. Its recorded RED is that all 228 native tests execute but two forced-close protocol-fault subcases fail. The inherited test injected the individual root waiter although the forced-close lane called the combined observer; a fresh focused reproduction took 10.417 seconds. The [review evidence](https://github.com/ContextualWisdomLab/OriginWeave/pull/147#issuecomment-5550841022) retains this failure and its subsequent repair rather than treating recovered ancestry as acceptance. - Current #147 `3dff28d9bf2dd27b72507e39979d51b8bf140fb4` repairs only that lane-specific test injection and its documentation. Ordinary cases retain the individual False result; forced-close cases inject the combined (False, False) result and assert the exact root-only identity tuple. Every existing assertion and all six methods remain; all six focused and all 228 native tests now pass, along with compileall, complete Rust 1.97.1 gates and the same 415/3555/4444/476 numerical 100% coverage. Production, deadlines, retry policy and failure denominators are unchanged; the branch warning remains explicit. Writer reassessment occurred after the temporary route closed and contacted tasks confirmed read-only status; the current repair is a normal forward push. CI `33959982049` is pending and compatibility `33959982033` is queued. The ordinary-pass two-deadline finding stays unresolved in the separate #150 scope; no hosted, protected-main or real-browser acceptance is claimed. +- Current #148 `bded4fc9d32e5e047cea99d182aa05ae2cd03bf6` adopts that exact #147 by ordinary merge and repairs review `5120692604`: a real crash-trial startup probe first failed because the emitted browser arguments disabled Chromium's sandbox. Removing that single argument preserves the startup-failure path, driver termination and temporary-profile removal, with no unsandboxed fallback. The inherited six review regressions and both child crash-cleanup/exit-detection test blobs remain intact. The 247-test macOS run has 244 passes and three explicitly skipped Linux pidfd cases; all 247 Python contracts pass on Linux with zero skips, including a killed unreaped child, non-terminating signal and stale process identity. Complete Rust 1.97.1 gates and numerical 100% coverage pass at 415/3555/4444/476, with the branch warning retained. CI `33962062616` and compatibility `33962062608` are queued. Three other launch lanes still disable the sandbox in this branch and require their separate owner repairs; this is not runner-wide sandbox completion, pinned-Chromium acceptance, review dismissal or protected delivery. +- Current #150 `d3c29359fd10e540ca9b3b2723bde6f94866cdb6` adopts the same #147 while preserving its existing combined ordinary-pass observer and both child test blobs. The inherited six review methods were absent before adoption. Their restoration exposed two ordinary protocol-fault failures, and full replay then exposed three sibling failure-observation cases still injecting the superseded individual waiter. Test-only reconciliation now injects paired observer outcomes and asserts the exact root-only identity tuple; incomplete process capture cannot claim full-set termination. No production timeout, retry, polling rule, success condition or denominator changed. All inherited and child checks execute, and all 229 Python contracts pass on macOS and Linux. Complete Rust gates and the same four-dimension numerical 100% coverage pass with the instrumentation warning retained. CI `33962429156` and compatibility `33962429172` are queued. The ordinary-pass deadline finding remains valid on #147 until this separate child is actually integrated; it was not resolved early. +- Supplemental Linux verification used the existing Colima guest (Python 3.12.3, kernel 6.8.0-117-generic), without installing dependencies or changing VM configuration. A first macOS archive introduced binary AppleDouble files and caused two unrelated TLS source-decoding failures; exporting the same tracked files without filesystem metadata repaired the transport, not the tests. Final host/guest tracked-file SHA-256 manifests match exactly: #148 `c808905cbea16fd85b9519fa0a7c431d032f6692bea172950e5ba23613e7e98b`, #150 `0f5f93ed8789843ca4f228d1117328d029e3fab461f0450c75964f2ef6b98324`. These are actual Linux contract runs, not actual pinned-Chromium browser trials, hosted CI or release evidence. +- #166 Strix run `33929688857` / job `101237371800` failed at `2026-09-05T10:53:36Z` on unchanged `e84a1a2...`. Its executed trusted central source was `a9aeee8fc94ad6002a059b380b268590ce496ef0`. The final scanner attempt exited zero, recorded completion from `10:25:17Z` to `10:53:29Z` and emitted zero SARIF results, but the console classifier also matches ordinary denied-policy prose. Replaying its exact first predicate against the sanitized final console log matches two policy-description lines and independently explains the final provider-unavailable classification. The final scanner report log has no corresponding failure-token match; the initial report-directory hypothesis was rejected. Artifact `9968177796` has SHA-256 `1ed63eb46e83d8acb61e281a6563400269a45c0924ae989ee30a4addc041048b`. Earlier attempts did have errors, so neither all-attempt success nor authoritative security acceptance is inferred. The reproduced classifier defect and exact evidence were sent to the existing central owner; no central source, provider, timeout, gate or required status was changed here, and repeating the same classifier was not used as a remedy. +- #219 Strix run `33925442296` / job `101226800608` on `65e4315...` is a distinct failure: a real gateway HTTP 500 occurred at `08:08Z`, and the job was cancelled at `10:51:35Z` with the six-hour GitHub job execution limit explicitly recorded in its check annotation. This is neither a passing scan nor evidence that the #166 console defect caused that cancellation. Its already admitted Noema attempt 2 remains a separate queued item. Canonical provider/orchestration and runner feasibility must be reassessed before another attempt; no caller timeout or model fallback was expanded. +- #240 Strix run `33925596890` / job `101227893828` on unchanged `24930a3...` was also cancelled at `11:20:05Z`; its annotation independently confirms the same six-hour hosted execution limit. Its actual console records gateway HTTP 500 at `07:01Z` and `10:34Z`, followed by cancellation at `11:19:59Z`. These are observed failures, not a generic inference from a red status. No successor Strix run existed in the refreshed exact-head inventory, but an unchanged retry would not repair the canonical provider or classification defects; this source/documentation lane did not start one or alter execution limits. - Temporary integration PR #291 is now closed after an external merge into `automation/147-merge-base-20260905`, whose base was #146 `812c0020...`. Live API metadata records head `52575632de07bcb90791e491b9a64b6875532ebe` and merge `24fad0498a49267982805d35d2dd57484efb4671`; Git confirms that merge is an ancestor of current #147 through forward integration `07369a37b54c11c32f810c3d5c107ad6d4b9feb4`. The temporary route neither replaced #147 nor reached protected main. The recovered runtime and test content, subsequent test-reconciliation repair and ordered acceptance requirements are evaluated separately from its merged/closed label. This lane performed no merge or closure. The fresh full inventory is 125 open / 12 Ready / 113 Draft. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index ca591056b..900a51b52 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -55,6 +55,18 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #253 now adopts #252 at `afb623e4449b7cbf926fdcef7225ceaca822cfcf`", "1054 functions, 10747 lines, 13787 regions, 1194 branches", "Review `5120013340` remains unresolved", + "PR #254 now adopts #253 at `b11b6c9bccd8335b58a4fb599f8ad29ac419637f`", + "1061 functions, 10802 lines, 13843 regions, 1200 branches", + "Review `5120077272` remains actionable", + "Current #148 `bded4fc9d32e5e047cea99d182aa05ae2cd03bf6`", + "all 247 Python contracts pass on Linux with zero skips", + "Current #150 `d3c29359fd10e540ca9b3b2723bde6f94866cdb6`", + "all 229 Python contracts pass on macOS and Linux", + "#166 Strix run `33929688857` / job `101237371800` failed", + "console classifier also matches ordinary denied-policy prose", + "#219 Strix run `33925442296` / job `101226800608`", + "six-hour GitHub job execution limit", + "#240 Strix run `33925596890` / job `101227893828`", "Current #147 `3dff28d9bf2dd27b72507e39979d51b8bf140fb4`", "all six focused and all 228 native tests now pass", "all 228 native tests execute but two forced-close protocol-fault subcases fail", From 858071f56c0bea909ff8566791cb82facf5e00ab Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 20:36:51 +0900 Subject: [PATCH 159/250] docs: bind freshness review evidence to current head Retain predecessor-only passing evidence after the final live inventory revealed the newer default-port regression head. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 6 +++--- tests/test_gap_snapshot_inventory_consistency.py | 2 +- tests/test_product_completion_gap_contract.py | 3 ++- 4 files changed, 7 insertions(+), 5 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index d17282a70..00dd7d3b1 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Corrected #50's live head after the exit sweep found its newer default-port regression, keeping earlier passing results attached to their tested predecessors. - Recorded #254 parent adoption, #148's crash-launch sandbox repair and #150's shared-observer test reconciliation, including complete local verification and matched-source Linux runs; separated the reproduced central scan-classifier defect from a gateway failure and hosted execution-limit cancellation. - Recorded #253's verified current-parent integration while retaining its unresolved teardown-evidence finding, downstream repair ownership and instrumentation warning; local passing checks do not establish operational completion. - Recorded #252's verified current-parent integration and #147's test-only repair from two reproduced failures to all 228 passing tests, preserving the earlier RED history, ordinary-pass deadline finding and instrumentation warning. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index a9c8f96f7..50b831924 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,11 +6,11 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T11:25:43Z` (full inventory and targeted review/check evidence). +Observed at (UTC): `2026-09-05T11:33:50Z` (full inventory and targeted review/check evidence). - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. PR #290 was converted back to Draft after current-protected workflow review found that its #245-relative patch would drop protected #286 lifecycle controls; queue movement is not protected-main delivery. PR #248 also returned to Draft for current-parent adoption and complete revalidation. Temporary synthesis #291 has since been externally merged and closed as recorded below; its closure does not establish product acceptance. -- Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `2bd85188a3b3d798824ac04cf3638df84ac2a8bb`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. PR #290 is Draft at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2`, remains a #245-dependent workflow-owner candidate, and is not a root. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `e981ac45d0bfcd3906fc64dae5f4490edf39f9e5`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. PR #290 is Draft at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2`, remains a #245-dependent workflow-owner candidate, and is not a root. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2` and PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd` retain formal `CHANGES_REQUESTED` decisions even though every current review thread is resolved. The decisions remain merge blockers until the governing reviewer state changes; thread resolution alone is not approval and is not grounds to dismiss a review. - Targeted CI RCA at `2026-09-05T06:45Z` confirmed that #219 Noema run `33925442322` / job `101226941175` and #240 run `33925596923` / job `101227537529` had terminated on gateway HTTP 502 without review verdicts. Neither unchanged exact head had a successor Noema run. One supported failed-job rerun per head created attempt 2, with queued jobs `101264704581` and `101264705575`; Noema attempt 2 is queue-admission evidence, not provider recovery or a review verdict. Successful sampled Noema wrapper runs skipped their review jobs and cannot establish recovery. The CodeQL failures independently record dispatch handoff: #219 central runs `33947047322`, `33947036734`, `33947037072` and #240 runs `33947189162`, `33947189634`, `33947187643` match those exact heads; these central CodeQL dispatches remain queued and were not duplicated. Active Strix runs were left untouched. Revisit these exact attempts after a terminal result; do not create repeated retries while they remain queued. - A fresh repository Actions query at `2026-09-05T06:12:27Z` returned **115 queued workflow runs**; the newest sampled run was #238 CI `33949183271` on predecessor head `bb2f18570f319a763acc24d7c4206ec9d0a11a29`. This is runner-admission/backlog evidence, not a code failure or passing check; rerunning unchanged heads would only add duplicate queue load. The moving PR's exact current head remains live-metadata-only to avoid a non-convergent self-reference. @@ -31,7 +31,7 @@ Observed at (UTC): `2026-09-05T11:25:43Z` (full inventory and targeted review/ch - PR #43 is Draft at exact head `6f3134d18d3118aab33d28048671dc71a5f47b77`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. The branch now installs and configures the pinned `chrome_sandbox`; exact-head hosted verification remains required, and restoring `--no-sandbox` is not acceptable. - PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, with a repository regression contract for the exact badge target, pre-alpha status, active-PR non-promotion statement, and publication boundary. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. - PR #37 is Ready at exact head `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`. The head repairs the Rust 1.97.1 formatting failure in its segmented Content-Length regression; formatting, locked workspace check/test, strict Clippy, rustdoc, all 167 Python contracts, and pinned-nightly production function/line/region/branch coverage pass locally at 100%. The reader returns after the exact declared bytes, already-buffered surplus remains fail-closed, and valid self-delimited content does not require TLS EOF. New hosted exact-head jobs are queued and no eligible approval exists. -- PR #50 is Ready at exact head `2bd85188a3b3d798824ac04cf3638df84ac2a8bb` on protected main. The origin-port repair and its full Rust/100% local coverage evidence belong to predecessor `ddbefc91fbcbc1bfd1e1af63846620f7ccb7a9b4`; the runtime source is unchanged by this head. The regression proved that an origin-approved IP could be paired with a different service port; the shared direct planner now binds the socket port to the effective scheme-host-port origin before I/O. A new documentation regression exposed that ADR 0005 and doctoring still described the old untimed public contract. Both now document the public freshness-checked plan, trusted monotonic time, and revalidation before socket I/O. All 152 Python contracts and six fresh-resolution integration tests pass; the current review thread is resolved. Fresh hosted checks remain required on this new head. +- PR #50 is Ready at exact head `e981ac45d0bfcd3906fc64dae5f4490edf39f9e5` on protected main. The owner reports a new default HTTP/HTTPS port regression without production changes; this documentation lane has not independently rerun that new tree. CI `33962389397` and compatibility `33962389406` are queued. The earlier documentation repair at `2bd85188a3b3d798824ac04cf3638df84ac2a8bb` passed 152 Python contracts and six fresh-resolution tests and resolved its review thread, but those results do not transfer to the new head. The origin-port production repair and full Rust/100% local coverage evidence belong to still-earlier `ddbefc91fbcbc1bfd1e1af63846620f7ccb7a9b4`. That regression proved that an origin-approved IP could be paired with a different service port; the shared planner now binds the socket port to the effective scheme-host-port origin before I/O. ADR 0005 and doctoring document the public freshness-checked plan, trusted monotonic time and revalidation before socket I/O. Current exact-head verification and governing approval remain required. - PR #269 is Draft at exact head `7854394266d3f292e779193c01413a34f6798d7c`, stacked on #268 exact `8d4027e40b790d28d866051ba741db12927ec22c`. It adds only a fixed, product-owned `script.callFunction` text-value observation for the exact admitted current node; it performs no browser I/O and proves no post-condition. Its new documentation boundary contract and all 140 Python contracts pass locally, while hosted exact-head CI is queued and the parent-first dependency keeps it Draft. - PR #270 is Draft at exact head `191a14535219ea8033777fa4c970efb281b62418`, now non-force synchronized onto #269 exact `7854394266d3f292e779193c01413a34f6798d7c`. Its parent-relative transport delta is unchanged; 140 Python contracts, full Rust gates, and exact 100% local production function/line/region/branch coverage pass. Dispatch still proves neither the correlated result nor text-entry success, and fresh hosted exact-head checks plus parent-first integration remain required. - PR #271 is Draft at exact head `802ec806cdd4560eab48c484f435766ecabda353`, non-force synchronized onto #270 exact `191a14535219ea8033777fa4c970efb281b62418`. It admits only the exact typed observation response, treats unequal text as `PostconditionMismatch`, and retains no page-controlled or expected text in public evidence or diagnostics. Its test-first documentation contract, all 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 900a51b52..2d43a14fb 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -35,7 +35,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `2bd85188a3b3d798824ac04cf3638df84ac2a8bb`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", + "Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `e981ac45d0bfcd3906fc64dae5f4490edf39f9e5`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", "PR #290 is Draft at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2`", "PR #238's moving exact head is intentionally omitted", "PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2`", diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 77ce56f59..384faad24 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -183,7 +183,8 @@ def test_current_snapshot_records_origin_bound_socket_ports(self) -> None: )[0] for marker in ( - "PR #50 is Ready at exact head `2bd85188a3b3d798824ac04cf3638df84ac2a8bb`", + "PR #50 is Ready at exact head `e981ac45d0bfcd3906fc64dae5f4490edf39f9e5`", + "those results do not transfer to the new head", "origin-approved IP could be paired with a different service port", "binds the socket port to the effective scheme-host-port origin", "function/line/region/branch coverage pass locally at 100%", From 6f80f3a88c78c3db200e269e16289bf5420c25bd Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 21:35:53 +0900 Subject: [PATCH 160/250] docs: record verified navigation dependency integrations Replace stale current-head assertions with independently verified formatting and parent-adoption evidence for #50 and #255 through #260. Preserve dated history, source ownership, instrumentation limits, canonical scan RCA and unfulfilled hosted, reviewer and browser acceptance gates. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 23 ++++++++++++------- ...test_gap_snapshot_inventory_consistency.py | 21 +++++++++++++---- tests/test_product_completion_gap_contract.py | 4 ++-- 4 files changed, 34 insertions(+), 15 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 00dd7d3b1..223971c49 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded #50's reproduced formatting repair and verified current-parent integrations through #255–#260, preserving their exact local test/coverage evidence, child-source ownership, warning and runtime limits, and remaining hosted/approval gates. - Corrected #50's live head after the exit sweep found its newer default-port regression, keeping earlier passing results attached to their tested predecessors. - Recorded #254 parent adoption, #148's crash-launch sandbox repair and #150's shared-observer test reconciliation, including complete local verification and matched-source Linux runs; separated the reproduced central scan-classifier defect from a gateway failure and hosted execution-limit cancellation. - Recorded #253's verified current-parent integration while retaining its unresolved teardown-evidence finding, downstream repair ownership and instrumentation warning; local passing checks do not establish operational completion. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 50b831924..079c99bce 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,11 +6,11 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T11:33:50Z` (full inventory and targeted review/check evidence). +Observed at (UTC): `2026-09-05T12:34:17Z` (full inventory and targeted review/check evidence). - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. - Full live search returns **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. PR #290 was converted back to Draft after current-protected workflow review found that its #245-relative patch would drop protected #286 lifecycle controls; queue movement is not protected-main delivery. PR #248 also returned to Draft for current-parent adoption and complete revalidation. Temporary synthesis #291 has since been externally merged and closed as recorded below; its closure does not establish product acceptance. -- Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `e981ac45d0bfcd3906fc64dae5f4490edf39f9e5`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. PR #290 is Draft at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2`, remains a #245-dependent workflow-owner candidate, and is not a root. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. +- Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `ad87cfea59db711cb29ef90559790ba77e22029f`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. PR #290 is Draft at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2`, remains a #245-dependent workflow-owner candidate, and is not a root. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. - PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2` and PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd` retain formal `CHANGES_REQUESTED` decisions even though every current review thread is resolved. The decisions remain merge blockers until the governing reviewer state changes; thread resolution alone is not approval and is not grounds to dismiss a review. - Targeted CI RCA at `2026-09-05T06:45Z` confirmed that #219 Noema run `33925442322` / job `101226941175` and #240 run `33925596923` / job `101227537529` had terminated on gateway HTTP 502 without review verdicts. Neither unchanged exact head had a successor Noema run. One supported failed-job rerun per head created attempt 2, with queued jobs `101264704581` and `101264705575`; Noema attempt 2 is queue-admission evidence, not provider recovery or a review verdict. Successful sampled Noema wrapper runs skipped their review jobs and cannot establish recovery. The CodeQL failures independently record dispatch handoff: #219 central runs `33947047322`, `33947036734`, `33947037072` and #240 runs `33947189162`, `33947189634`, `33947187643` match those exact heads; these central CodeQL dispatches remain queued and were not duplicated. Active Strix runs were left untouched. Revisit these exact attempts after a terminal result; do not create repeated retries while they remain queued. - A fresh repository Actions query at `2026-09-05T06:12:27Z` returned **115 queued workflow runs**; the newest sampled run was #238 CI `33949183271` on predecessor head `bb2f18570f319a763acc24d7c4206ec9d0a11a29`. This is runner-admission/backlog evidence, not a code failure or passing check; rerunning unchanged heads would only add duplicate queue load. The moving PR's exact current head remains live-metadata-only to avoid a non-convergent self-reference. @@ -22,7 +22,7 @@ Observed at (UTC): `2026-09-05T11:33:50Z` (full inventory and targeted review/ch - PR #290 is Draft at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2` on #245 exact `a769f484e2c110e0523b3b28cd21573f43867562`. Its workflow/repository/PR-number concurrency isolation and manual-dispatch non-cancellation intent are valid, but its predecessor-relative MV3 patch would remove protected #286 `converted_to_draft`/`closed` lifecycle events and the closed-event job guard. Exact review `5120039692` and canonical-owner issue #212 comment `5549868655` require reconstruction on the current protected MV3 workflow; the scheduled product writer did not mutate `.github/**`. - PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`, stacked on predecessor #282 head `b54a5856d8201911f05d69622f0d5594a371adf0` rather than current #282 exact `b64e0708584beff3fb54acf226cb3e667773e473`. It must adopt the corrected current parent before its compare can become current evidence. The child remains one prose-only doctoring canary; Draft-hosted jobs are skipped, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. - PR #288 is Draft at exact head `39e36256651f62940ec3ca6149067f0cfcb2285a` on current protected main. It stages #70's controlled Agent Task product, test, and documentation delta without any `.github/**` mutation; its workflow-owned sandbox-helper assertion was removed after it made the workflow-free branch's full Python contract suite fail, and all 172 Python contracts now pass locally. Hosted CI and MV3 jobs remain skipped while Draft, and #212 still owns authorized workflow activation plus sandboxed pinned-Chromium execution evidence. -- Issue #28 remains the P0 governed-browser integration target. PR #260 is Draft at exact head `3a651967c421f77088fe25e86a63faae295390b3` on #259 exact base `e1105ddf86f6c79443af8b4d306b9d34cb703c17`. PR #261 is Draft at exact head `323ac9e147691e9f6572711f5a748e13f1036624`, stacked on exact #260. Repair PR #277 is Draft at exact head `01038ba71fb276426cc67f90a91a3c431e194db5`, stacked on exact #261 and preserving typed `SessionSubscribe` correlation. Each restacked tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. Fresh hosted checks remain non-terminal, so stale conflicting #262 is not superseded and remains dependency-blocked until #277 reaches terminal GREEN on the unchanged head. +- Issue #28 remains the P0 governed-browser integration target. The earlier #260 generation `3a651967c421f77088fe25e86a63faae295390b3` used #259 `e1105ddf86f6c79443af8b4d306b9d34cb703c17`; its current integration is recorded below. PR #261 is Draft at exact head `323ac9e147691e9f6572711f5a748e13f1036624`, still stacked on that earlier #260 generation. Repair PR #277 is Draft at exact head `01038ba71fb276426cc67f90a91a3c431e194db5`, stacked on exact #261 and preserving typed `SessionSubscribe` correlation. Those earlier restacked trees passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. Fresh hosted checks remain non-terminal, so stale conflicting #262 is not superseded and remains dependency-blocked until #277 reaches terminal GREEN on the unchanged head. For #261, the recorded #260 parent is stale; adopt actual `2c5049aff97a90958e8262b1d403bdcbd64a1e8b` normally and reverify before advancing later children. This is the next source item after the current invocation's verification budget, not a merge-ready or released feature. - Stacked PRs #178 and #85 were repaired without force pushes at exact heads `640e594dbc0a64f251a0f28b8e80943f53337e40` and `c9adea680d6186f1842a280e248ce55da4f1305b`. Parent-relative deltas now preserve the current MV3 diagnostic and extension-authority contracts; local full suites and exact 100% coverage passed, while hosted exact-head acceptance remains independently required. - PR #70 is Draft at exact head `77eb0f2ee71783e06171784b7173c0b4cd530e61`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. Its focused Agent Task contract proves the pre-repair `--no-sandbox` launch as source RED and the branch removes that argument only from the Agent Task lane. Sandbox-enabled pinned-Chromium E2E and repository-wide GREEN remain unproven while its exact-head browser/CI/security runs are non-passing. - DDD/MCP repair #272 is Ready at exact head `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3` on current protected main. Its exact-head hosted checks remain queued and no eligible approval exists. Documentation child PR #273 is Draft at exact head `e5c8fcb66bf644dfa750bb1b40ba3d600cb7805a` on predecessor #272 head `fe124e447cad3f679e22337fb6fbdfd135ab3652`, so it must adopt the parent only after #272's current head completes its gates. Both remain active-PR evidence. @@ -31,7 +31,7 @@ Observed at (UTC): `2026-09-05T11:33:50Z` (full inventory and targeted review/ch - PR #43 is Draft at exact head `6f3134d18d3118aab33d28048671dc71a5f47b77`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. The branch now installs and configures the pinned `chrome_sandbox`; exact-head hosted verification remains required, and restoring `--no-sandbox` is not acceptable. - PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, with a repository regression contract for the exact badge target, pre-alpha status, active-PR non-promotion statement, and publication boundary. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. - PR #37 is Ready at exact head `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`. The head repairs the Rust 1.97.1 formatting failure in its segmented Content-Length regression; formatting, locked workspace check/test, strict Clippy, rustdoc, all 167 Python contracts, and pinned-nightly production function/line/region/branch coverage pass locally at 100%. The reader returns after the exact declared bytes, already-buffered surplus remains fail-closed, and valid self-delimited content does not require TLS EOF. New hosted exact-head jobs are queued and no eligible approval exists. -- PR #50 is Ready at exact head `e981ac45d0bfcd3906fc64dae5f4490edf39f9e5` on protected main. The owner reports a new default HTTP/HTTPS port regression without production changes; this documentation lane has not independently rerun that new tree. CI `33962389397` and compatibility `33962389406` are queued. The earlier documentation repair at `2bd85188a3b3d798824ac04cf3638df84ac2a8bb` passed 152 Python contracts and six fresh-resolution tests and resolved its review thread, but those results do not transfer to the new head. The origin-port production repair and full Rust/100% local coverage evidence belong to still-earlier `ddbefc91fbcbc1bfd1e1af63846620f7ccb7a9b4`. That regression proved that an origin-approved IP could be paired with a different service port; the shared planner now binds the socket port to the effective scheme-host-port origin before I/O. ADR 0005 and doctoring document the public freshness-checked plan, trusted monotonic time and revalidation before socket I/O. Current exact-head verification and governing approval remain required. +- PR #50 is Ready at exact head `ad87cfea59db711cb29ef90559790ba77e22029f` on protected main. At predecessor `e981ac45d0bfcd3906fc64dae5f4490edf39f9e5`, seven focused tests passed but pinned Rust formatting failed on the default-port regression. The formatter-only repair preserves all default HTTP/HTTPS and explicit-port assertions and every production source. Fresh independent verification passed all seven fresh-resolution tests and 152 Python contracts, compileall and complete Rust 1.97.1 format/check/workspace-test/strict-Clippy/rustdoc gates. Numerical coverage is 530 functions, 4509 lines, 5441 regions and 660 branches at 100%, with the unstable branch-option warning retained. Current CI `33964793228` and compatibility `33964793282` remain non-passing queue evidence. Earlier `2bd85188...` documentation and `ddbefc91...` origin-port repairs remain historical: an origin-approved IP could be paired with a different service port; the planner now binds the socket port to the effective scheme-host-port origin before I/O. ADR 0005 and doctoring retain trusted monotonic time and revalidation before socket I/O. Local admission tests do not prove an HTTP/TLS exchange, browser navigation, hosted acceptance or required approval. - PR #269 is Draft at exact head `7854394266d3f292e779193c01413a34f6798d7c`, stacked on #268 exact `8d4027e40b790d28d866051ba741db12927ec22c`. It adds only a fixed, product-owned `script.callFunction` text-value observation for the exact admitted current node; it performs no browser I/O and proves no post-condition. Its new documentation boundary contract and all 140 Python contracts pass locally, while hosted exact-head CI is queued and the parent-first dependency keeps it Draft. - PR #270 is Draft at exact head `191a14535219ea8033777fa4c970efb281b62418`, now non-force synchronized onto #269 exact `7854394266d3f292e779193c01413a34f6798d7c`. Its parent-relative transport delta is unchanged; 140 Python contracts, full Rust gates, and exact 100% local production function/line/region/branch coverage pass. Dispatch still proves neither the correlated result nor text-entry success, and fresh hosted exact-head checks plus parent-first integration remain required. - PR #271 is Draft at exact head `802ec806cdd4560eab48c484f435766ecabda353`, non-force synchronized onto #270 exact `191a14535219ea8033777fa4c970efb281b62418`. It admits only the exact typed observation response, treats unequal text as `PostconditionMismatch`, and retains no page-controlled or expected text in public evidence or diagnostics. Its test-first documentation contract, all 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. @@ -45,8 +45,14 @@ Observed at (UTC): `2026-09-05T11:33:50Z` (full inventory and targeted review/ch - PR #251 now adopts #250 at `f02af6d0dd01708d495cc08dec785675f3d58898`, ordinarily retaining both exact parents `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc` and `ec433b844a121f8554c062f92267991af9cacb6f`. Only the changelog required content reconciliation; both release records remain. The sender, public exports and both child-owned Rust integration tests are byte-identical to the predecessor. Native release-contract discovery first failed at zero and now executes one test; all 142 Python contracts, compileall, complete Rust 1.97.1 gates and enforced 100% coverage pass: 1037 functions, 10647 lines, 13681 regions, 1192 branches. The pinned branch-instrumentation warning below was independently reproduced on this tree too. Exact CI `33959168801` is queued; Draft, current-parent protection and hosted acceptance remain separate. A successful session-end frame write is not remote completion or process/profile teardown proof. Current #252 adoption is recorded next. - PR #252 now adopts #251 at `6569bf40b6595ac74c2f0a997d202137f07ba1db`, retaining predecessor `2015259529ada99af836989079cc85a15779a2d8` and current parent `f02af6d0...` by ordinary merge. The response implementation, public exports and four loopback response tests are unchanged; both conflicting release records remain. The inherited release-contract loader moves from zero RED to one executed GREEN, and all 142 Python contracts, compileall and complete Rust 1.97.1 gates pass. Enforced numerical coverage is 100%: 1044 functions, 10699 lines, 13751 regions, 1192 branches; the branch-instrumentation warning remains. Exact CI `33959789688` is queued. This response layer does not authenticate the received connection or prove resource teardown. #253's current-parent adoption is recorded next; the later #255 provenance repair remains separately owned. - PR #253 now adopts #252 at `afb623e4449b7cbf926fdcef7225ceaca822cfcf`, retaining predecessor `0d72082e595c0e1fcc03d609ba337896ed14e2fc` and current parent `6569bf40...` by ordinary merge. The assessment implementation, public exports and two child tests are unchanged; both conflicting release records remain. Native inherited release-contract discovery moves from zero RED to one executed GREEN. All 142 Python contracts, compileall and complete Rust 1.97.1 gates pass, with enforced numerical 100% coverage: 1054 functions, 10747 lines, 13787 regions, 1194 branches. The branch-instrumentation warning remains, and exact CI `33960670119` is queued. Review `5120013340` remains unresolved: caller-supplied teardown claims still cannot authenticate operational completion, regardless of local coverage. The #254 adoption below preserves #255's separately owned removal/provenance repair as a remaining prerequisite. This intermediate Draft is not security or operational acceptance. -- PR #254 now adopts #253 at `b11b6c9bccd8335b58a4fb599f8ad29ac419637f`, retaining predecessor `cbaf50dcc97753cc73135497ea8225e8b18de190` by ordinary merge. The closure implementation, public exports and all six real-loopback child tests are byte-identical to that predecessor; both release records survive the changelog conflict. The inherited correlation release test moves from zero collected RED to one executed GREEN. All 142 Python contracts, compileall and complete Rust 1.97.1 gates pass, with numerical 100% coverage: 1061 functions, 10802 lines, 13843 regions, 1200 branches. Review `5120077272` remains actionable: closure kind/status still cannot establish that the acknowledged connection generation closed. Exact CI `33961562189` is queued; #255 must adopt this parent while preserving its connection-provenance repair. Neither coverage nor loopback tests authenticate the missing connection binding, and the instrumentation warning remains. -- PRs #250 through #257 remain Draft. The recorded fully locally verified chain used exact heads #250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`, #251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`, #252 `2015259529ada99af836989079cc85a15779a2d8`, #253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`, #254 `cbaf50dcc97753cc73135497ea8225e8b18de190`, #255 `a13de5f9321e72c1867974eb7a43230f031e58df`, #256 `9f2e6f29be46371762e3031a97c1cac04720694f`, and #257 `ea2b5b78868917219c46f1304558b92490a7f6fe`. Each updated tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. #250 and #257 each had one known macOS socket-observation race; their exact focused retries and complete coverage reruns passed. Exact-head review found that #253 still lets three unauthenticated caller booleans mint `OperationallyComplete`; raw teardown claims must remain explicitly unverified until session-bound transport, process-exit, and profile-removal evidence types are issued by their owning runtime boundaries. Hosted exact-head checks and ordered parent integration remain required. Since that observation, #255 has advanced beyond reviewed head `a13de5f9321e72c1867974eb7a43230f031e58df` with an in-progress connection-provenance repair. Its moving current head is live-metadata-only until the complete repair is reverified; neither the predecessor GREEN nor the earlier #256 parent comparison transfers to those commits. +- PR #254 now adopts #253 at `b11b6c9bccd8335b58a4fb599f8ad29ac419637f`, retaining predecessor `cbaf50dcc97753cc73135497ea8225e8b18de190` by ordinary merge. The closure implementation, public exports and all six real-loopback child tests are byte-identical to that predecessor; both release records survive the changelog conflict. The inherited correlation release test moves from zero collected RED to one executed GREEN. All 142 Python contracts, compileall and complete Rust 1.97.1 gates pass, with numerical 100% coverage: 1061 functions, 10802 lines, 13843 regions, 1200 branches. Review `5120077272` remains actionable: closure kind/status still cannot establish that the acknowledged connection generation closed. Exact CI `33961562189` is queued; #255's current adoption below preserves its connection-provenance repair. Neither coverage nor loopback tests authenticate the missing connection binding, and the instrumentation warning remains. +- PR #255 now adopts #254 at `3e7057443d7c9532ff526acb5eefe8cd4778c767`, retaining predecessor `ebac126d1632c94775c2454423575275eec45def` and parent `b11b6c9bccd8335b58a4fb599f8ad29ac419637f` by ordinary merge. All 15 owner production/test blobs are byte-identical to the predecessor. Native release-contract discovery moves from zero RED to one executed GREEN; 13 focused real-loopback tests, 142 Python contracts, compileall and the complete Rust 1.97.1 gates pass. Numerical 100% coverage is 1082 functions, 11032 lines, 14086 regions, 1202 branches. CI `33964381844` was queued at new-head observation. The previous unused-accessor repair is correctly attributed to `ebac126d...`, not its failing `63cbca0...` predecessor. Process/profile cleanup and hosted acceptance remain unproven. +- PR #256 now adopts #255 at `ced4a851ca66c08d895a098725c7f0ad3ecf0c38`, preserving predecessor `9f2e6f29be46371762e3031a97c1cac04720694f` and current parent `3e705744...`. The core click implementation, exports and four tests are byte-identical; the correlation child delta remains only its typed click kind. Four click tests, 13 provenance/teardown tests, 142 Python contracts and complete Rust gates pass after inherited release discovery changes from zero RED to one GREEN. Numerical 100% coverage is 1088 functions, 11077 lines, 14146 regions, 1210 branches. CI `33965138401` and compatibility `33965138418` were queued; inert serialization remains distinct from authorized input or an observed browser click. +- PR #257 now adopts #256 at `f4a8f2cbf515bea348f500b59615a9581c1b96a2`, preserving predecessor `ea2b5b78868917219c46f1304558b92490a7f6fe` and parent `ced4a851...`. The sender and two child-test files are byte-identical; the composition conflict retains both the sender and connection-bound reader. Ten focused tests, 142 Python contracts and full Rust gates pass after the inherited zero-to-one release-contract repair. Numerical 100% coverage is 1093 functions, 11131 lines, 14202 regions, 1214 branches. CI `33965440517` was queued. No focused retry was needed in this run; that does not repair the unchanged fixture's previously observed platform-level socket race. Frame-write completion is not browser-action completion. +- PR #258 is Draft at exact head `5f830324f6d5a47ac213a57528ef95649bdfd0df`, retaining predecessor `f2ceabb3ea50b1959e936503c50cae12f3e6e480` and actual #257 `f4a8f2cb...` by ordinary merge. Its response implementation, four loopback tests and child-owned bounded socket-observation adjustment are byte-identical. Fourteen focused tests, 142 Python contracts and full Rust gates pass; numerical 100% coverage is 1100 functions, 11185 lines, 14272 regions, 1214 branches. CI `33965695405` was queued. The inherited release contract now executes. This click-response API remains protocol correlation only; the separate received-connection proof for session teardown does not automatically authenticate it or establish a browser post-condition. +- PR #259 is Draft at exact head `66731982ed51ad62a04fcfbc759b0a33721a0254`, retaining predecessor `e1105ddf86f6c79443af8b4d306b9d34cb703c17` and current #258 `5f830324...`. Seven child production/test blobs remain byte-identical, including context admission, navigation projection and all three navigation suites. Fifteen focused tests, 142 Python contracts and full Rust gates pass after native release-contract discovery is restored. Numerical 100% coverage is 1140 functions, 11841 lines, 15129 regions, 1332 branches. CI `33965966736` and compatibility `33965966679` were queued. Exact context/URL matching is observation evidence, not transport authentication, click causation, origin rebinding or document advancement. +- PR #260 is Draft at exact head `2c5049aff97a90958e8262b1d403bdcbd64a1e8b`, retaining predecessor `3a651967c421f77088fe25e86a63faae295390b3` and current #259 `66731982...`. The document-advance implementation, two loopback tests and Proposed ADR 0103 are byte-identical. Seventeen focused tests, 142 Python contracts and full Rust gates pass after the inherited release contract becomes executable. Numerical 100% coverage is 1154 functions, 11969 lines, 15314 regions, 1334 branches. CI `33966229736` was queued. Stale-epoch and retired-context rejection remain intact; registry advancement cannot authenticate the observation, bind the new origin or prove action causation. All six current integrations above retain the unstable branch-option warning, remain Draft and unmerged, and require their own hosted checks and policy-satisfied promotion. +- PRs #250 through #257 remain Draft. The recorded fully locally verified chain used exact heads #250 `0eab23d5e388c5c8b984c0021a58316680c9ba8b`, #251 `86e8ad76838f2a64aa7e0cd56ba1f931c8d0c3dc`, #252 `2015259529ada99af836989079cc85a15779a2d8`, #253 `0d72082e595c0e1fcc03d609ba337896ed14e2fc`, #254 `cbaf50dcc97753cc73135497ea8225e8b18de190`, #255 `a13de5f9321e72c1867974eb7a43230f031e58df`, #256 `9f2e6f29be46371762e3031a97c1cac04720694f`, and #257 `ea2b5b78868917219c46f1304558b92490a7f6fe`. Each updated tree passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. #250 and #257 each had one known macOS socket-observation race; their exact focused retries and complete coverage reruns passed. Exact-head review found that #253 still lets three unauthenticated caller booleans mint `OperationallyComplete`; raw teardown claims must remain explicitly unverified until session-bound transport, process-exit, and profile-removal evidence types are issued by their owning runtime boundaries. Hosted exact-head checks and ordered parent integration remain required. The current #255–#260 rows above supersede this older lineage only at their explicitly verified heads; no predecessor GREEN transfers to later hosted checks or protected-main delivery. - Reviews [#254](https://github.com/ContextualWisdomLab/OriginWeave/pull/254#pullrequestreview-5120077272) at `cbaf50dcc97753cc73135497ea8225e8b18de190` and [#255](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120077213) at `a13de5f9321e72c1867974eb7a43230f031e58df` found a remaining connection-provenance gap. #254 passed six focused closure tests, formatting, strict network Clippy and network rustdoc locally. #255 removes the parent process/profile booleans and keeps overall teardown pending, but a new loopback regression fails when an acknowledgment from connection A is combined with closure from connection B: the assessment reports the acknowledged transport closed. Both connections can use command id 7; #254 retains only closure kind/status and the acknowledgment retains only its command id. Repair the established-stream, frame/message and command-correlation owners to preserve a non-forgeable connection-generation binding, carry it into acknowledgment and closure evidence, then reject mismatches in #255. Different-session and same-session reconnect regressions are required; endpoint equality, command-id equality and caller-supplied markers are insufficient. This is unresolved evidence integrity, not operational-completion authority or shipped behavior. Both PRs remain Draft with hosted checks queued. - Follow-up review `5120203295` at #255 head `92392b2da33bcd5446c6d2eb1b5504c39e60e3d6` established that received-message provenance must be checked before correlation is consumed. At that reviewed head, sender/closure generations rejected independently parsed evidence, but the two-real-socket response-substitution regression still failed: response B combined with outstanding-command state A became acknowledgment A because its generation came from the registry rather than the received text. The [exact-head review and runnable regression](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#pullrequestreview-5120203295) preserve the RED lineage; the later repair evidence below supersedes this failure only for its explicitly tested snapshot. - Received-connection verification at #255 head `e7bfec4488b7cb4776df7b546cacb46c8c9eb13e` found that all 12 focused tests passed: the trusted reader retains one non-cloneable stream and assembler through fragments/control messages, the parser rejects a foreign generation before consuming the original command, and cross-connection closure cannot satisfy the acknowledgment. All 141 Python contracts and strict rustdoc passed. Full quality remained incomplete: formatting and Clippy failed, and pinned-nightly coverage rejected lines=11046/11049 and regions=14067/14071 even though functions and branches reached 100%. The first complete stable Rust run also exposed the inherited fixture race; its unchanged retry passed, which was not treated as repair. The fixture root cause is now repaired at #242 and integrated into #243 as recorded above. [Verification and exact uncovered paths](https://github.com/ContextualWisdomLab/OriginWeave/pull/255#issuecomment-5550208364) remain snapshot-specific; later #255 changes, hosted checks and descendant adoption need fresh verification. Overall teardown remains pending and none of this is protected-main delivery. @@ -56,7 +62,7 @@ Observed at (UTC): `2026-09-05T11:33:50Z` (full inventory and targeted review/ch - PR #142 at `015025f2539e4fb1dbd7d259ec22dad50f944396` passed fresh read-only failure-boundary review: 187 Python contracts passed, and controlled probes preserve unknown identity on observation failure, reject a still-live identity at the existing deadline, and accept absence or a different start-time as exit of the original identity. Both informational threads were resolved without production changes. Its exact-head CI `33916627099` and compatibility `33916627091` remain cancelled, not Linux/browser runtime GREEN. - PR #143 at `44fd9a450f864feff5cf2ba2883425a71ba10b9b` is a documentation and real-path regression repair on exact #142. The release-record check first failed for the missing failure-cleanup entry, then all five focused and 192 Python contracts, full Rust 1.97.1 gates and pinned-nightly 100% coverage passed: 415 functions, 3555 lines, 4444 regions, 476 branches. The production runner is unchanged. Observed exit and a surviving identity both retain failed-task status; process-observation errors leave termination unproven and record only the bounded observation-error type, losing the original browser-failure type in that fallback record. Private exception messages remain absent, and profile cleanup cannot turn a failed task into a pass. Both informational threads are resolved with this limitation documented. CI `33954715539` and compatibility `33954715568` are queued; controlled local probes do not prove real Linux/pinned-Chromium acceptance. Current #144 adoption is recorded below. - PR #144 at `09f2e087d0c20fe81386c18099e739a9e611a8ad` completed read-only informational review: 194 Python contracts passed, and controlled real-helper probes confirmed conservative failure when a descendant PID is reused before start-time capture, separate root and process-set deadline budgets, and the defensive exit-count invariant across all eight absent/live combinations of three descendants. Three informational threads are resolved with those limits recorded; no runtime code or timeout changed. CI `33916685294` and compatibility `33916685137` remain cancelled, not current browser acceptance. This is predecessor evidence superseded by the current adoption below; process identities appearing after sampling, cgroup ownership and OS-wide orphan absence remain outside this evidence. -- PR #258 is Draft at exact head `f2ceabb3ea50b1959e936503c50cae12f3e6e480` on exact #257, and PR #259 is Draft at exact head `e1105ddf86f6c79443af8b4d306b9d34cb703c17` on exact #258. Both final trees passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage; fresh hosted exact-head checks and ordered parent integration remain required. +- Earlier #258 `f2ceabb3ea50b1959e936503c50cae12f3e6e480` and #259 `e1105ddf86f6c79443af8b4d306b9d34cb703c17` each passed 141 Python contracts and full Rust/numerical-coverage checks on the older #257 lineage. Their new current-parent integrations and independent 142-contract verification are recorded above; the historical measurements do not transfer. - PR #93 is Draft at exact head `0664f0452cb329cd692cce7f61f9001652abfda2`, based on #271 exact `802ec806cdd4560eab48c484f435766ecabda353` and synchronized with #242's complete opening-fixture cleanup. `SemanticNodeActionBinding` preserves semantic-node and business-origin identity, but does not authorize policy or execute input. Its 141 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered ancestor integration remain required. - PR #95 is Draft at exact head `97aa0f2e340ee6fd920d0418f97af276b190554f`, stacked on #93 exact `0664f0452cb329cd692cce7f61f9001652abfda2`. Only `Decision::Allow` creates policy-authorized value; other decisions fail closed, and registry-owned current authority returns `NotAdmitted` after document advance removes the node. The slice performs no browser I/O or postcondition proof. Its 142 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. - PR #96 is Draft at exact head `b7ba8dd1433410cee43084a73e31816da841b2a2`, stacked on #95 exact `97aa0f2e340ee6fd920d0418f97af276b190554f`. Registry-owned node authority is revalidated before one adapter callback, and the callback is never invoked after admission is removed. Adapter completion remains separate from postcondition proof. Its 143 Python contracts, full Rust gates, and exact 100% local production coverage pass; hosted exact-head checks and ordered parent integration remain required. @@ -72,8 +78,9 @@ Observed at (UTC): `2026-09-05T11:33:50Z` (full inventory and targeted review/ch - PR #146 review repair is `812c0020bd2ecdb3eda39d999ed3327647550bdf`. Five new tests first reproduced 10 assertion failures and 7 uncaught protocol-error cases despite the predecessor's 216 passing contracts. The repair restores the non-boolean pre-shutdown count range, preserves only validated known ordinary cleanup fields, records typed terminal protocol errors without remote messages, and removes the obsolete HTTP-body close recognizer. Startup retry policy, request redaction and owned-process deadlines remain unchanged. Six new behavioral tests and all 224 Python contracts, complete Rust gates and the same 100% production coverage pass. The concurrent parent-adoption `11944410450684809ee1a71a35c77abafc5358db` is retained through an ordinary merge whose tree is identical to verified repair `d636a1829332610ada458df7b5b9d267f038a2f8`. All four review threads are resolved; exact CI `33957036553` and compatibility `33957036650` are queued, not browser acceptance. #147 must adopt this parent while retaining its own shared-deadline behavior. These three PRs remain Draft and no protected delivery, eligible approval or release is claimed. - Follow-up #287 review evidence at `2026-09-05T09:07Z`: Strix scan job `101243872506` executed successfully, including its quick scan and report upload. Noema job `101245089068` failed with HTTP 502 after 2739.2 seconds and one caller attempt. A fresh exact-head inventory showed no duplicate Noema run, so the same failed job was queued for a supported rerun; attempt 2 now has successful exact-head admission and queued review job `101282290732`. Queue admission is not provider recovery, executed review, a verdict or eligible approval. No caller timeout, provider, model, workflow or quality gate changed. The three central CodeQL dispatches remain queued and were not duplicated. This supersedes the earlier in-progress Noema/Strix snapshot above without transferring any old result to a new source head. -- Current #255 source-owner repair is `ebac126d1632c94775c2454423575275eec45def`, now verified in remote PR metadata on unchanged #254. Its 11-file delta removes the obsolete private accessor, applies pinned formatting and repairs the Rust documentation link without removing received-connection validation. The source owner reports 141 Python contracts, full Rust 1.97.1 verification and coverage functions=1082/1082, lines=11025/11025, regions=14071/14071, branches=1202/1202. This is the owner's new exact-tree local verification, not an independent rerun by this documentation lane or a transfer of earlier GREEN. Exact hosted CI `33957423557` is queued; the earlier `63cbca0...` quality RED is retained as historical RCA, and ordered parent adoption still remains. +- Prior #255 source-owner repair is `ebac126d1632c94775c2454423575275eec45def`, verified at that earlier owner snapshot before current-parent adoption. Its 11-file delta removes the obsolete private accessor, applies pinned formatting and repairs the Rust documentation link without removing received-connection validation. The source owner reports 141 Python contracts, full Rust 1.97.1 verification and coverage functions=1082/1082, lines=11025/11025, regions=14071/14071, branches=1202/1202. This is the owner's historical exact-tree local verification, not an independent rerun by this documentation lane or a transfer of earlier GREEN. At that observation, hosted CI `33957423557` was queued; the earlier `63cbca0...` quality RED is retained as historical RCA, and the new independent parent-adoption results are recorded above. - The pinned cargo-llvm-cov 0.8.6 branch report emits `warning: --branch option is unstable`. The warning was independently reproduced when reporting the existing #144/#145/#146 measurements, whose numerical verifiers still pass. Thus numerical coverage enforcement is distinct from warning-free instrumentation. The #255 source owner likewise leaves warning-free measurement acceptance outstanding. No warning suppression, coverage exclusion, denominator manipulation or alternate unreviewed measurement is used; compiler/Clippy/rustdoc results, instrumentation maturity, hosted acceptance and release readiness remain separate. +- Central Strix #1563 remains at `1221b1604e1a6cfde8ca5ab7fd3e93e0fe9faf69`. The existing canonical owner received the exact #166 console-prose false-positive reproduction and acknowledged its narrow classifier/provenance boundary. No new owner commit or executed regression receipt was available at this snapshot; acknowledgement is not a repair, and no consumer rerun or passing status was manufactured. Actual #219/#240 gateway and hosted execution-limit failures remain distinct. - Historical #147 `46e75859ef5aff2054fd6ca1720d518438e97d0f` included #146 `812c0020...` in ancestry but dropped the parent's six review-evidence regressions and reversed their associated production repairs. Native discovery collected zero tests; read-only replay of the exact parent module against that child reproduced 10 assertion failures and 8 uncaught protocol-error cases. The merge title, ancestor presence and earlier 222 passing child tests did not establish successful inheritance. - At predecessor #147 `af1b98ba377c73b88baa9633e2232e7f76e76f36`, the external synthesis restored parent runtime repairs and all six methods while preserving the combined forced-close observer. Its recorded RED is that all 228 native tests execute but two forced-close protocol-fault subcases fail. The inherited test injected the individual root waiter although the forced-close lane called the combined observer; a fresh focused reproduction took 10.417 seconds. The [review evidence](https://github.com/ContextualWisdomLab/OriginWeave/pull/147#issuecomment-5550841022) retains this failure and its subsequent repair rather than treating recovered ancestry as acceptance. - Current #147 `3dff28d9bf2dd27b72507e39979d51b8bf140fb4` repairs only that lane-specific test injection and its documentation. Ordinary cases retain the individual False result; forced-close cases inject the combined (False, False) result and assert the exact root-only identity tuple. Every existing assertion and all six methods remain; all six focused and all 228 native tests now pass, along with compileall, complete Rust 1.97.1 gates and the same 415/3555/4444/476 numerical 100% coverage. Production, deadlines, retry policy and failure denominators are unchanged; the branch warning remains explicit. Writer reassessment occurred after the temporary route closed and contacted tasks confirmed read-only status; the current repair is a normal forward push. CI `33959982049` is pending and compatibility `33959982033` is queued. The ordinary-pass two-deadline finding stays unresolved in the separate #150 scope; no hosted, protected-main or real-browser acceptance is claimed. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 2d43a14fb..8827c0cbc 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -35,7 +35,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "7 central required workflows", "codeql-pr", "Live GitHub PR/base/head/check APIs are authoritative over PR bodies", - "Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `e981ac45d0bfcd3906fc64dae5f4490edf39f9e5`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", + "Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `ad87cfea59db711cb29ef90559790ba77e22029f`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`", "PR #290 is Draft at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2`", "PR #238's moving exact head is intentionally omitted", "PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2`", @@ -106,7 +106,18 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "Follow-up quality verification at #255 head `63cbca0a98cf9496af981819d98029e656fc4342`", "functions=1082/1083, lines=11046/11051, regions=14071/14074", "unused private accessor", - "Current #255 source-owner repair is `ebac126d1632c94775c2454423575275eec45def`", + "Prior #255 source-owner repair is `ebac126d1632c94775c2454423575275eec45def`", + "PR #255 now adopts #254 at `3e7057443d7c9532ff526acb5eefe8cd4778c767`", + "PR #256 now adopts #255 at `ced4a851ca66c08d895a098725c7f0ad3ecf0c38`", + "PR #257 now adopts #256 at `f4a8f2cbf515bea348f500b59615a9581c1b96a2`", + "1082 functions, 11032 lines, 14086 regions, 1202 branches", + "1088 functions, 11077 lines, 14146 regions, 1210 branches", + "1093 functions, 11131 lines, 14202 regions, 1214 branches", + "1100 functions, 11185 lines, 14272 regions, 1214 branches", + "1140 functions, 11841 lines, 15129 regions, 1332 branches", + "1154 functions, 11969 lines, 15314 regions, 1334 branches", + "Central Strix #1563 remains at `1221b1604e1a6cfde8ca5ab7fd3e93e0fe9faf69`", + "For #261, the recorded #260 parent is stale", "warning: --branch option is unstable", "numerical coverage enforcement is distinct from warning-free instrumentation", "PR #139 at `b7ea5bfe336456fb263dd479a60b1cd0193d8a47`", @@ -126,9 +137,9 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "#257 `ea2b5b78868917219c46f1304558b92490a7f6fe`", "Issue #279", "Issue #28 remains the P0 governed-browser integration target", - "PR #260 is Draft at exact head `3a651967c421f77088fe25e86a63faae295390b3`", - "PR #258 is Draft at exact head `f2ceabb3ea50b1959e936503c50cae12f3e6e480`", - "PR #259 is Draft at exact head `e1105ddf86f6c79443af8b4d306b9d34cb703c17`", + "PR #260 is Draft at exact head `2c5049aff97a90958e8262b1d403bdcbd64a1e8b`", + "PR #258 is Draft at exact head `5f830324f6d5a47ac213a57528ef95649bdfd0df`", + "PR #259 is Draft at exact head `66731982ed51ad62a04fcfbc759b0a33721a0254`", "PR #261 is Draft at exact head `323ac9e147691e9f6572711f5a748e13f1036624`", "Repair PR #277 is Draft at exact head `01038ba71fb276426cc67f90a91a3c431e194db5`", "PR #70 is Draft at exact head `77eb0f2ee71783e06171784b7173c0b4cd530e61`", diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 384faad24..2485a8a32 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -183,8 +183,8 @@ def test_current_snapshot_records_origin_bound_socket_ports(self) -> None: )[0] for marker in ( - "PR #50 is Ready at exact head `e981ac45d0bfcd3906fc64dae5f4490edf39f9e5`", - "those results do not transfer to the new head", + "PR #50 is Ready at exact head `ad87cfea59db711cb29ef90559790ba77e22029f`", + "Fresh independent verification passed all seven fresh-resolution tests and 152 Python contracts", "origin-approved IP could be paired with a different service port", "binds the socket port to the effective scheme-host-port origin", "function/line/region/branch coverage pass locally at 100%", From a2600ee8422c69cf5af60e3ea41fbc3bcb7cfaf4 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 16:00:16 +0900 Subject: [PATCH 161/250] docs: separate current queue from prior verification cuts Record the restored foundation workflow failures and exact successor checks. Preserve the interrupted source-proof refresh and immutable historical tail. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 2 + docs/product-technical-gap-baseline.md | 60 +++++++++++++++---- ...test_gap_snapshot_inventory_consistency.py | 49 +++++++++++++-- tests/test_product_completion_gap_contract.py | 2 +- 4 files changed, 96 insertions(+), 17 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 223971c49..198a924d9 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,8 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Separated the September 6 verified queue from prior measurements, recording restored-foundation workflow failures, current successor CI results, completed sandbox doctoring, and unreleased runtime/central-owner prerequisites. +- Recorded verified #261/#277 parent adoption, the reproduced subscription-deadline slot repair, current #288 sandbox-source verification, and the central report-classification source repair; retained hosted, review, runtime, and independent-verification limits and the REST refresh boundary. - Recorded #50's reproduced formatting repair and verified current-parent integrations through #255–#260, preserving their exact local test/coverage evidence, child-source ownership, warning and runtime limits, and remaining hosted/approval gates. - Corrected #50's live head after the exit sweep found its newer default-port regression, keeping earlier passing results attached to their tested predecessors. - Recorded #254 parent adoption, #148's crash-launch sandbox repair and #150's shared-observer test reconciliation, including complete local verification and matched-source Linux runs; separated the reproduced central scan-classifier defect from a gateway failure and hosted execution-limit cancellation. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 079c99bce..7b457662f 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,31 +6,71 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -Observed at (UTC): `2026-09-05T12:34:17Z` (full inventory and targeted review/check evidence). +### Latest verified cut: 2026-09-06 + +Observed at (UTC): `2026-09-06T06:55:11Z`. This cut supersedes volatile claims in the prior observation section below; those earlier exact-head measurements remain historical rather than transferable acceptance evidence. + +The inventory remains **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`; no release or tag is proven. The Ready-root source heads listed in the prior cut are unchanged. GraphQL thread resolution was refreshed for all 125 open PRs using smaller paginated queries after the combined query returned an invalid response. No thread pagination remains; #147 retains the sole unresolved thread. #166/#220 retain `CHANGES_REQUESTED`, and the other Ready roots retain `REVIEW_REQUIRED`; all twelve are `BLOCKED`. REST reviews, checks and combined statuses were also refreshed for every exact head, with two incomplete review responses recovered separately. None of this authorizes a bypass or substitutes for an eligible counted approval. + +The restored foundation changes the next executable queue. #195 is Draft at `63997bcf555e2c5c8e91ba287734ffba3837a1b7`, on `6922dd98779e8f8aad132a3b1f563d7ba6e6d070`. Its owner restored product/evidence assets lost by historical whole-tree repair `5c111d0db6c363f9d1786c21cc01c5c7398007bd`; this is a content-recovery boundary, not permission to copy an old tree over later work. Fresh hosted CI `34013251657` fails in repository contracts while exact production coverage and MV3 `34013251651` succeed. The exercised failures compare inherited workflow concurrency and `nightly-2026-08-01` against the protected repository-scoped identity and `nightly-2026-08-18`. #279 owns current-workflow reconstruction; weakening the restored tests does not repair the generation mismatch. #242 remains at `2d0e9f69df9ade21d8e8e3d807c3ff644d83b310`, with a stale pre-recovery #195 base `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its old CI success is not recovered-foundation acceptance. After the owner prerequisite, adopt the verified foundation content-aware and non-destructively before regenerating descendant checks. + +The owner has already moved #255 directly onto #252 so the valid #253/#254 deltas and connection-bound repair travel together. #253/#254 remain open, not silently discarded. Current native Rust and coverage checks succeed on each of these exact heads; earlier local coverage counts do not validate these newer heads: + +| PR | Current head | Exact native CI | +| --- | --- | --- | +| #255 | `6865faa8185c5fe6a8b6aaba9535d774575b0061` | `34003175242` success | +| #256 | `881c7f09ee9161ce8664dd75226938ecf60b85e5` | `34003259914` success | +| #257 | `8f1507346f65798a6bf4eaf370d65a2d406a6f44` | `34003269343` success | +| #258 | `b8eaa97f7a417c79250b6b760ff214ac03d39b8a` | `34003285350` success | +| #259 | `91d95423cf31947f691db5ebbd3072c481d86542` | `34003299669` success | +| #260 | `e5228396be8d9faade44a30aed704cacbeb91b46` | `34003322381` success | +| #261 | `572fc4224ddc09c010bd9ccf100764076899495a` | `34003334868` success | +| #277 | `973e34bc24ae9bdd96a50764f2be6c8603eff66c` | `34003345253` success | +| #263 | `3f22de94b63da83eaa8b5b1270912b21a3ecd006` | `34009256997` success | + +#263 now targets actual #277. Its current Rust and exact-coverage jobs `101422055630` / `101422055538` succeed after the owner repaired formatting and exercised the unsubscribe frame-error branch. This is native exact-tree evidence, not protected integration, authenticated browser post-condition, or central review acceptance. The deeper #195 foundation prerequisite still applies to this whole stack. + +#288 is now Draft at `fd589cd693946ef1ce2c9270c2dfb6a1087bdfb9`. The independently inspected two-file diff from `0f434bc...` contains documentation-consistency RED `e74acd7...` and the doctoring correction `fd589cd...`, with no production or workflow change. Its sandbox-source and historical mock-fixture boundaries are explicit. Current Strix and Noema succeed, CodeQL fails, and native Rust/coverage/MV3 are skipped; predecessor local 173-test/coverage proof is not current browser execution. The earlier planned documentation repair is done and must not be duplicated. + +#148 is now Draft at `0135984f1bc1f68d89d7777f49c4999474105a12`. Current native CI `33990522263` succeeds, but pinned-Chromium MV3 `33990522248` fails. The later bounded diagnostic artifact locates browser-crash failure at session creation; #212 records 0/3 for every real-browser lane after all sandbox-disabling overrides were removed. #43's separate helper-generation MV3 `33866932365` succeeds only on its own exact source. #212 owns sandbox-helper adoption against the current protected workflow, followed by fresh consumer execution; cleanup bookkeeping and leaf success are not transferable runtime evidence. + +On #238's pre-publication head, native CI `33966500232` and Strix `33966499362` succeed, while Noema `33966499292` and CodeQL `33966500187` fail. This document's next commit requires new exact-head checks; it cannot inherit those results. Existing central CodeQL dispatch/verdict work remains with `.github#712`. Central Strix #1563 remains unmerged at `eaf9594f7fe8d8e1994349289183d6cbad056579`, now reported behind its base: the earlier `13fbb48e...` source repair and owner-reported harness results do not prove consumer recovery. The unrelated #37 local 900-second deadline remains distinct from the #166 completed-report classifier defect and #219/#240 actual gateway/hosted-limit incidents. + +### Prior observation cut: 2026-09-05 + +The following cut preserves prior source measurements and diagnostics. Present-tense wording within this dated cut describes its observation time only; use the latest verified cut above and live APIs for the current queue. + +Observed at (UTC): `2026-09-05T13:50:14Z` (full REST inventory/review/check refresh and targeted source verification; subsequent bounded diagnostics are recorded below). + +GraphQL rejected both the inventory query and a minimal probe with its rate-limit error while the REST endpoints remained available. REST reviews, check runs, and combined statuses were read for all 125 open PRs; truncated output was recovered by querying the exact missing records. New source heads were refreshed separately after pushes. Review-thread resolution cannot be inferred from these REST endpoints: earlier thread-resolution statements below retain their prior observation date and are not refreshed merge evidence. No query failure, queued check, or metadata update relaxes a quality or review gate. + +- #37 Strix run `33946242342` / job `101285198427` failed at 13:26 UTC. Artifact `9970303662` (SHA256 `93ce81a9c3060f52a23d0910b5a995a2b491aeb3889a54432d954747a97010ca`) records `Strix run timed out after 900s`, 903 seconds elapsed and exit 124; its current-attempt record is interrupted, not completed. The provider-unavailable wrapper label does not establish a provider outage. Canonical Strix deadline/classification ownership received the exact artifact; no consumer timeout change or blind rerun was made. +- #148 hosted compatibility run `33962062608` / job `101295542349` failed at 13:33 UTC on `bded4fc9d32e5e047cea99d182aa05ae2cd03bf6`: browser-crash recovery fails 0/3 trials, while ordinary Agent Task and forced-close each pass 3/3 and profiles are cleaned. Artifact `9970408851` (SHA256 `daefc93ff2792cbc82a8937107e7992e91447f56692c4ea7071bc2b39c0faa7b`) initially exposed only `RuntimeError`; the stage was not reconstructible from it. Subsequent owner diagnostics and newer all-sandboxed results are recorded in the latest cut, not backdated into this earlier artifact. - Protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085` through #286. PR #286 skips repository-native CI jobs for draft pull requests; a skipped job is not passing evidence. -- Full live search returns **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. PR #290 was converted back to Draft after current-protected workflow review found that its #245-relative patch would drop protected #286 lifecycle controls; queue movement is not protected-main delivery. PR #248 also returned to Draft for current-parent adoption and complete revalidation. Temporary synthesis #291 has since been externally merged and closed as recorded below; its closure does not establish product acceptance. +- The September 5 search also returned 125 PRs (12 Ready, 113 Draft) and 13 non-PR issues. PR #290 was converted back to Draft after current-protected workflow review found that its #245-relative patch would drop protected #286 lifecycle controls; queue movement is not protected-main delivery. PR #248 also returned to Draft for current-parent adoption and complete revalidation. Temporary synthesis #291 has since been externally merged and closed as recorded below; its closure does not establish product acceptance. - Ready roots are #37 `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`, #50 `ad87cfea59db711cb29ef90559790ba77e22029f`, #166 `e84a1a2cc82b1c666218efd441da97849f47b8c2`, #219 `65e4315d80137badc0b55e1b9617015beb1db568`, #220 `e545b94e1de499b96b867694f80ac04ad247becd`, #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, #240 `24930a3a9ee79c0b712ee3df6589b0592eb6e18f`, #272 `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, #274 `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, #285 `f455c2cd64b3dd3f027c91d396103792a205ddd0`, and #287 `af83c40dd2990a03064a92ca75430a9cc400f098`. PR #290 is Draft at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2`, remains a #245-dependent workflow-owner candidate, and is not a root. PR #238's moving exact head is intentionally omitted from its self-referential document; live PR metadata is authoritative. Their hosted exact-head checks remain non-terminal and none has an eligible exact-head approval, so none is merge-ready. -- PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2` and PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd` retain formal `CHANGES_REQUESTED` decisions even though every current review thread is resolved. The decisions remain merge blockers until the governing reviewer state changes; thread resolution alone is not approval and is not grounds to dismiss a review. +- PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2` and PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd` retain formal `CHANGES_REQUESTED` decisions. REST review records were refreshed; thread-resolution state could not be refreshed because GraphQL rejected the current read. The last successful thread-resolution snapshot was the prior 12:36 UTC sweep, not this REST refresh. Thread resolution alone is not approval or grounds to dismiss a review, and the active counted-approval gate remains unmet. - Targeted CI RCA at `2026-09-05T06:45Z` confirmed that #219 Noema run `33925442322` / job `101226941175` and #240 run `33925596923` / job `101227537529` had terminated on gateway HTTP 502 without review verdicts. Neither unchanged exact head had a successor Noema run. One supported failed-job rerun per head created attempt 2, with queued jobs `101264704581` and `101264705575`; Noema attempt 2 is queue-admission evidence, not provider recovery or a review verdict. Successful sampled Noema wrapper runs skipped their review jobs and cannot establish recovery. The CodeQL failures independently record dispatch handoff: #219 central runs `33947047322`, `33947036734`, `33947037072` and #240 runs `33947189162`, `33947189634`, `33947187643` match those exact heads; these central CodeQL dispatches remain queued and were not duplicated. Active Strix runs were left untouched. Revisit these exact attempts after a terminal result; do not create repeated retries while they remain queued. - A fresh repository Actions query at `2026-09-05T06:12:27Z` returned **115 queued workflow runs**; the newest sampled run was #238 CI `33949183271` on predecessor head `bb2f18570f319a763acc24d7c4206ec9d0a11a29`. This is runner-admission/backlog evidence, not a code failure or passing check; rerunning unchanged heads would only add duplicate queue load. The moving PR's exact current head remains live-metadata-only to avoid a non-convergent self-reference. - Active organization ruleset `18156473` (`CWL Central required workflows`) applies to the default branch. It requires one approving review, dismissal of stale approvals after pushes, resolved review threads, extra approval for unattributed changes, and **7 central required workflows**: `opencode-review`, `pr-review-merge-scheduler`, `security-scan`, `strix`, `sast-semgrep`, `noema-review`, and `codeql-pr`. Current `ContextualWisdomLab/.github` consolidates OSV and Scorecard PR scanning into the required `security-scan.yml`; standalone `osv-scanner-pr.yml` and `scorecard-pr.yml` are no longer ruleset entries. Administrative bypass capability is not authorization to use it. -- PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration, and the new main's repository-native post-merge checks remain non-terminal. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. +- PR #284 head `61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a` reached `main` through rule-suite `3948421709`, whose live result is **`result: bypass`** with actor `seonghobae`. The required non-author approval and workflows were not proven before integration. The earlier pending post-merge state is historical: fresh native Rust and production-coverage checks now succeed on `87c4daa1830bac5a5228b6036752ad5633232085`. This is a governance incident tracked by #215, not a policy-compliant merge or evidence that later checks can retroactively authorize it. - PR #285 is Ready at exact head `f455c2cd64b3dd3f027c91d396103792a205ddd0` on current protected main. It addresses #284's three post-merge review findings without changing `.github/**` and adds a dedicated regression contract. All 154 repository contracts, the full Rust gates, and exact 100% local coverage pass. Its Ready transition materialized repository-native CI `33930234387`: Rust contracts `101207153048` and Production coverage `101207153244` succeeded by `2026-09-05T03:16:29Z`; native CI success does not replace the seven required central workflows. The Ready event did not materialize fresh central required-workflow runs. Targeted RCA at `2026-09-05T06:53Z` verified that the previously cancelled Security Scan `33924016851`, SAST Semgrep `33924016903`, and CodeQL PR `33924016883` still bind the current head and protected base, with no duplicate central CodeQL dispatch. The convenience CLI failed on a cross-repository workflow lookup before rerunning anything; the supported run-ID REST route then created attempt 2 for all three, with queued scope/language jobs `101265706025`, `101265708882`, and `101265710202`. These are verified replay admissions, not terminal scan results or proof that Ready-event materialization is repaired. Remaining required review evidence and the absent eligible approval still block merge; toggling Draft or creating a no-op commit is not an acceptable substitute. - Issue #279 owns the remaining documentation-CI partitioning gap. PR #287 is Ready at exact head `af83c40dd2990a03064a92ca75430a9cc400f098` on current protected main; it is the workflow-independent classifier foundation, changes no `.github/**` path, and is the prerequisite for an authorized workflow owner. Its predecessor failed its own release-record contract; the current head binds Git rename/copy similarity to blob identity, and its focused and full local suites plus exact 100% Rust coverage pass. Exact native CI, Semgrep and scoped Security Scan have now completed as described next; remaining required review/CodeQL evidence and eligible approval are not complete. PR #282 is Draft at exact head `b64e0708584beff3fb54acf226cb3e667773e473` on current protected main. Its latest workflow/test delta removes `converted_to_draft` and `closed` from the CI event list, removes #286's closed-event guard, and makes the repository contract assert those protections are absent. Exact review `5120043505` therefore requires the authorized #279 owner to reconstruct the valid trusted-base classifier/contract partition while preserving #286's lifecycle and closed+Draft fail-closed controls; Draft checks do not transfer as GREEN. - #287 CodeQL handoff RCA at `2026-09-05T08:34Z` confirms that exact native CI `33931806137` passed, Semgrep `33931806165` executed its scan successfully, and Security Scan `33931806226` executed Scorecard/Trivy while scope-skipping gitleaks/OSV/dependency-review. CodeQL wrapper `33931806139` failed intentionally after its three language jobs recorded successful dispatch and a pending verdict, not a failed terminal scan. The cross-repository convenience CLI returned 404; direct REST job logs identify the handoff. Central `.github` dispatches `33954721186`, `33955024697` and `33955164029` have display titles identifying the exact OriginWeave target head, but their immutable run heads are central-owner revisions (`71dd84d...` / `27d7331...`), not the product source head. All three remain queued and were not duplicated; acceptance still requires validated target checkout, an authenticated terminal verdict and the original-job replay. OpenCode is queued, Noema/Strix remain in progress, and no eligible formal approval exists. - PR #290 is Draft at exact head `ebeefcd534db4324498fdb18046ebc6255ddcdf2` on #245 exact `a769f484e2c110e0523b3b28cd21573f43867562`. Its workflow/repository/PR-number concurrency isolation and manual-dispatch non-cancellation intent are valid, but its predecessor-relative MV3 patch would remove protected #286 `converted_to_draft`/`closed` lifecycle events and the closed-event job guard. Exact review `5120039692` and canonical-owner issue #212 comment `5549868655` require reconstruction on the current protected MV3 workflow; the scheduled product writer did not mutate `.github/**`. - PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`, stacked on predecessor #282 head `b54a5856d8201911f05d69622f0d5594a371adf0` rather than current #282 exact `b64e0708584beff3fb54acf226cb3e667773e473`. It must adopt the corrected current parent before its compare can become current evidence. The child remains one prose-only doctoring canary; Draft-hosted jobs are skipped, so no trigger-shape GREEN is claimed for #279. Runner admission is a separate condition. -- PR #288 is Draft at exact head `39e36256651f62940ec3ca6149067f0cfcb2285a` on current protected main. It stages #70's controlled Agent Task product, test, and documentation delta without any `.github/**` mutation; its workflow-owned sandbox-helper assertion was removed after it made the workflow-free branch's full Python contract suite fail, and all 172 Python contracts now pass locally. Hosted CI and MV3 jobs remain skipped while Draft, and #212 still owns authorized workflow activation plus sandboxed pinned-Chromium execution evidence. -- Issue #28 remains the P0 governed-browser integration target. The earlier #260 generation `3a651967c421f77088fe25e86a63faae295390b3` used #259 `e1105ddf86f6c79443af8b4d306b9d34cb703c17`; its current integration is recorded below. PR #261 is Draft at exact head `323ac9e147691e9f6572711f5a748e13f1036624`, still stacked on that earlier #260 generation. Repair PR #277 is Draft at exact head `01038ba71fb276426cc67f90a91a3c431e194db5`, stacked on exact #261 and preserving typed `SessionSubscribe` correlation. Those earlier restacked trees passed 141 Python contracts, the full Rust gates, and CI-equivalent pinned-nightly 100% production coverage. Fresh hosted checks remain non-terminal, so stale conflicting #262 is not superseded and remains dependency-blocked until #277 reaches terminal GREEN on the unchanged head. For #261, the recorded #260 parent is stale; adopt actual `2c5049aff97a90958e8262b1d403bdcbd64a1e8b` normally and reverify before advancing later children. This is the next source item after the current invocation's verification budget, not a merge-ready or released feature. +- PR #288 is Draft at exact head `0f434bc29d468127412366b6864b733b40b83c4d` on current protected main. Predecessor `39e36256651f62940ec3ca6149067f0cfcb2285a` had 172 passing Python contracts; that evidence is historical. The subsequent test-first sandbox contract and doctoring change led to the ordinary launch override removal, followed by restoration of the original bounded ChromeDriver diagnostic. Direct cumulative comparison from `99fea8985b4649c444ecc72c11e72c0693b17f5b` to current `0f434bc...` confirms one net production line removed: `--no-sandbox`. Fresh isolated verification confirms all 173 Python contracts pass on that unchanged head, including the source contract for both ordinary and Agent Task launch paths. Complete Rust gates and numeric 100% coverage also pass: 521 functions, 4420 lines, 5349 regions, 654 branches; the unstable branch-option warning remains. The doctoring problem paragraph still describes the historical override as current, so its existing author owns a bounded documentation/test correction after this writer releases. Unit-fixture output is not executed browser evidence. #212 still owns authorized workflow activation and fresh sandboxed pinned-Chromium compatibility/Agent Task trials; no workflow, sandbox-helper configuration, or hosted replay was changed here. +- Issue #28 remains the P0 governed-browser integration target. PR #261 is Draft at exact head `934eb7d37568b439c442ffe1d1f6a9c8f8ed58a0`; #261 now includes actual #260 `2c5049aff97a90958e8262b1d403bdcbd64a1e8b` by normal merge. Its origin-binding implementation and tests remain byte-identical to predecessor `323ac9e147691e9f6572711f5a748e13f1036624`. Native release-contract discovery reproduced zero tests before parent adoption and one passing test after it. Fresh verification passed 18 focused loopback tests, 142 Python contracts, full Rust gates, and numeric 100% coverage: 1173 functions, 12104 lines, 15511 regions, 1334 branches. Exact CI `33967462582` is queued; no previous check is transferred. +- Repair PR #277 is Draft at exact head `117f6414e8a6db46eb2b32f4ebae85cf2a208371`, based on actual #261 `934eb7d37568b439c442ffe1d1f6a9c8f8ed58a0`. Parent adoption `3c0484174eeda0703492ba76b530be125e3e99dd` preserved its two subscription production files, three test files, and Proposed ADR, with 16 focused tests, 142 Python contracts, full Rust gates, and numeric 100% coverage at 1220 functions, 12774 lines, 16397 regions, 1418 branches. The subsequent deadline repair reused the existing frame validator before registration: its RED observed no subscription bytes but two outstanding commands where only one pre-existing command should remain. Zero and over-limit deadlines now preserve that command and leave the rejected identifier reusable. Post-registration frame-failure retention remains conservative, including the separately tested repeated-mask rejection. Fresh current-tree verification passed 11 focused tests, 142 Python contracts, complete Rust gates, and numeric 100% coverage: 1221 functions, 12781 lines, 16404 regions, 1418 branches. The actual typed family is `NavigationCommittedSubscription`, not the historical proposed `SessionSubscribe` name. The response parser and authority boundaries are unchanged; exact CI `33968278171` is queued, and `warning: --branch option is unstable` remains. Stale conflicting #262 is not superseded, and #263+ are not retargeted or promoted until current-parent hosted acceptance and complete successor evidence exist. - Stacked PRs #178 and #85 were repaired without force pushes at exact heads `640e594dbc0a64f251a0f28b8e80943f53337e40` and `c9adea680d6186f1842a280e248ce55da4f1305b`. Parent-relative deltas now preserve the current MV3 diagnostic and extension-authority contracts; local full suites and exact 100% coverage passed, while hosted exact-head acceptance remains independently required. - PR #70 is Draft at exact head `77eb0f2ee71783e06171784b7173c0b4cd530e61`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. Its focused Agent Task contract proves the pre-repair `--no-sandbox` launch as source RED and the branch removes that argument only from the Agent Task lane. Sandbox-enabled pinned-Chromium E2E and repository-wide GREEN remain unproven while its exact-head browser/CI/security runs are non-passing. -- DDD/MCP repair #272 is Ready at exact head `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3` on current protected main. Its exact-head hosted checks remain queued and no eligible approval exists. Documentation child PR #273 is Draft at exact head `e5c8fcb66bf644dfa750bb1b40ba3d600cb7805a` on predecessor #272 head `fe124e447cad3f679e22337fb6fbdfd135ab3652`, so it must adopt the parent only after #272's current head completes its gates. Both remain active-PR evidence. -- PR #229 is Ready at exact head `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6` on current protected main. Its 157 Python contracts, full Rust gates, and exact 100% local coverage pass, while hosted exact-head checks remain queued and no eligible approval exists. The presentation-identity work retains the boundary that Chromium application and page-observed effectiveness remain separate adapter/browser-E2E work. +- DDD/MCP repair #272 is Ready at exact head `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3` on current protected main. Its exact-head hosted acceptance remains incomplete and no eligible approval exists. Documentation child PR #273 is Draft at exact head `e5c8fcb66bf644dfa750bb1b40ba3d600cb7805a` on predecessor #272 head `fe124e447cad3f679e22337fb6fbdfd135ab3652`, so it must adopt the parent only after #272's current head completes its gates. Both remain active-PR evidence. +- PR #229 is Ready at exact head `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6` on current protected main. Its 157 Python contracts, full Rust gates, and exact 100% local coverage pass, while hosted exact-head acceptance remains incomplete and no eligible approval exists. The presentation-identity work retains the boundary that Chromium application and page-observed effectiveness remain separate adapter/browser-E2E work. - PR #281 remains Draft at exact head `adaca6427d68f550b39293a69b7c733430d1c385` on canonical MV3 parent #43 `6f3134d18d3118aab33d28048671dc71a5f47b77`. Its child delta is diagnostic-evidence contract/doctoring only; inherited #43 implementation redacts browser/page-derived HTTP and WebDriver protocol data, startup exception details, returned capability values, DOM-dataset values, and click post-condition text before CI/audit evidence. Exact-head CI and Manifest V3 Compatibility succeeded and review threads are resolved, but parent-first workflow-ownership verification remains open, so the child stays Draft. - PR #43 is Draft at exact head `6f3134d18d3118aab33d28048671dc71a5f47b77`; it targets protected main but has not adopted current main `87c4daa1830bac5a5228b6036752ad5633232085`. The branch now installs and configures the pinned `chrome_sandbox`; exact-head hosted verification remains required, and restoring `--no-sandbox` is not acceptable. - PR #274 remains the bounded GitHub Pages source/README/CHANGELOG public-surface delta at exact head `802d0bdff7536d9ac253305d3e0237b4e4a1789e`, with a repository regression contract for the exact badge target, pre-alpha status, active-PR non-promotion statement, and publication boundary. Source presence is not publication evidence; live HTTPS publication and navigation remain required after the authorized Pages configuration/deployment path. -- PR #37 is Ready at exact head `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`. The head repairs the Rust 1.97.1 formatting failure in its segmented Content-Length regression; formatting, locked workspace check/test, strict Clippy, rustdoc, all 167 Python contracts, and pinned-nightly production function/line/region/branch coverage pass locally at 100%. The reader returns after the exact declared bytes, already-buffered surplus remains fail-closed, and valid self-delimited content does not require TLS EOF. New hosted exact-head jobs are queued and no eligible approval exists. +- PR #37 is Ready at exact head `1e2f41072854edcdbaf0f9ecf14697a3bfd62195`. The head repairs the Rust 1.97.1 formatting failure in its segmented Content-Length regression; formatting, locked workspace check/test, strict Clippy, rustdoc, all 167 Python contracts, and pinned-nightly production function/line/region/branch coverage pass locally at 100%. The reader returns after the exact declared bytes, already-buffered surplus remains fail-closed, and valid self-delimited content does not require TLS EOF. Native Rust contracts and coverage have succeeded on this head, but central workflow evidence remains incomplete and no eligible approval exists. - PR #50 is Ready at exact head `ad87cfea59db711cb29ef90559790ba77e22029f` on protected main. At predecessor `e981ac45d0bfcd3906fc64dae5f4490edf39f9e5`, seven focused tests passed but pinned Rust formatting failed on the default-port regression. The formatter-only repair preserves all default HTTP/HTTPS and explicit-port assertions and every production source. Fresh independent verification passed all seven fresh-resolution tests and 152 Python contracts, compileall and complete Rust 1.97.1 format/check/workspace-test/strict-Clippy/rustdoc gates. Numerical coverage is 530 functions, 4509 lines, 5441 regions and 660 branches at 100%, with the unstable branch-option warning retained. Current CI `33964793228` and compatibility `33964793282` remain non-passing queue evidence. Earlier `2bd85188...` documentation and `ddbefc91...` origin-port repairs remain historical: an origin-approved IP could be paired with a different service port; the planner now binds the socket port to the effective scheme-host-port origin before I/O. ADR 0005 and doctoring retain trusted monotonic time and revalidation before socket I/O. Local admission tests do not prove an HTTP/TLS exchange, browser navigation, hosted acceptance or required approval. - PR #269 is Draft at exact head `7854394266d3f292e779193c01413a34f6798d7c`, stacked on #268 exact `8d4027e40b790d28d866051ba741db12927ec22c`. It adds only a fixed, product-owned `script.callFunction` text-value observation for the exact admitted current node; it performs no browser I/O and proves no post-condition. Its new documentation boundary contract and all 140 Python contracts pass locally, while hosted exact-head CI is queued and the parent-first dependency keeps it Draft. - PR #270 is Draft at exact head `191a14535219ea8033777fa4c970efb281b62418`, now non-force synchronized onto #269 exact `7854394266d3f292e779193c01413a34f6798d7c`. Its parent-relative transport delta is unchanged; 140 Python contracts, full Rust gates, and exact 100% local production function/line/region/branch coverage pass. Dispatch still proves neither the correlated result nor text-entry success, and fresh hosted exact-head checks plus parent-first integration remain required. @@ -80,7 +120,7 @@ Observed at (UTC): `2026-09-05T12:34:17Z` (full inventory and targeted review/ch - Prior #255 source-owner repair is `ebac126d1632c94775c2454423575275eec45def`, verified at that earlier owner snapshot before current-parent adoption. Its 11-file delta removes the obsolete private accessor, applies pinned formatting and repairs the Rust documentation link without removing received-connection validation. The source owner reports 141 Python contracts, full Rust 1.97.1 verification and coverage functions=1082/1082, lines=11025/11025, regions=14071/14071, branches=1202/1202. This is the owner's historical exact-tree local verification, not an independent rerun by this documentation lane or a transfer of earlier GREEN. At that observation, hosted CI `33957423557` was queued; the earlier `63cbca0...` quality RED is retained as historical RCA, and the new independent parent-adoption results are recorded above. - The pinned cargo-llvm-cov 0.8.6 branch report emits `warning: --branch option is unstable`. The warning was independently reproduced when reporting the existing #144/#145/#146 measurements, whose numerical verifiers still pass. Thus numerical coverage enforcement is distinct from warning-free instrumentation. The #255 source owner likewise leaves warning-free measurement acceptance outstanding. No warning suppression, coverage exclusion, denominator manipulation or alternate unreviewed measurement is used; compiler/Clippy/rustdoc results, instrumentation maturity, hosted acceptance and release readiness remain separate. -- Central Strix #1563 remains at `1221b1604e1a6cfde8ca5ab7fd3e93e0fe9faf69`. The existing canonical owner received the exact #166 console-prose false-positive reproduction and acknowledged its narrow classifier/provenance boundary. No new owner commit or executed regression receipt was available at this snapshot; acknowledgement is not a repair, and no consumer rerun or passing status was manufactured. Actual #219/#240 gateway and hosted execution-limit failures remain distinct. +- Central Strix #1563 advanced to `13fbb48e0b3eeca4ce7d9678add934f9bd87ad3f` from `1221b1604e1a6cfde8ca5ab7fd3e93e0fe9faf69`. The independently inspected four-file source diff adds a completed-artifact regression using the exact #166 denied-report prose and restricts console denial matching to explicit diagnostic lines while retaining warning, fatal, and workflow-error signals. This establishes a source repair, not an executed Origin acceptance result. The focused and full shell harness results plus 2890 passed, 1 skipped, and 21 subtests are owner-reported; this consumer lane did not execute them, and the skipped case is not passing evidence. At 13:46 UTC, ordinary merge `eaf9594f7fe8d8e1994349289183d6cbad056579` retained `13fbb48e...` and adopted protected central main `6f8c51d7389c22ebaf294fe8fe9ef495257883c0`. That fresh head is unmerged and hosted checks are queued; its cancelled predecessor checks and earlier local results do not validate the new merge. No Origin #166 consumer rerun was performed, so its historical executed failure remains unreplaced. Actual #219/#240 gateway and hosted execution-limit failures remain distinct. - Historical #147 `46e75859ef5aff2054fd6ca1720d518438e97d0f` included #146 `812c0020...` in ancestry but dropped the parent's six review-evidence regressions and reversed their associated production repairs. Native discovery collected zero tests; read-only replay of the exact parent module against that child reproduced 10 assertion failures and 8 uncaught protocol-error cases. The merge title, ancestor presence and earlier 222 passing child tests did not establish successful inheritance. - At predecessor #147 `af1b98ba377c73b88baa9633e2232e7f76e76f36`, the external synthesis restored parent runtime repairs and all six methods while preserving the combined forced-close observer. Its recorded RED is that all 228 native tests execute but two forced-close protocol-fault subcases fail. The inherited test injected the individual root waiter although the forced-close lane called the combined observer; a fresh focused reproduction took 10.417 seconds. The [review evidence](https://github.com/ContextualWisdomLab/OriginWeave/pull/147#issuecomment-5550841022) retains this failure and its subsequent repair rather than treating recovered ancestry as acceptance. - Current #147 `3dff28d9bf2dd27b72507e39979d51b8bf140fb4` repairs only that lane-specific test injection and its documentation. Ordinary cases retain the individual False result; forced-close cases inject the combined (False, False) result and assert the exact root-only identity tuple. Every existing assertion and all six methods remain; all six focused and all 228 native tests now pass, along with compileall, complete Rust 1.97.1 gates and the same 415/3555/4444/476 numerical 100% coverage. Production, deadlines, retry policy and failure denominators are unchanged; the branch warning remains explicit. Writer reassessment occurred after the temporary route closed and contacted tasks confirmed read-only status; the current repair is a normal forward push. CI `33959982049` is pending and compatibility `33959982033` is queued. The ordinary-pass two-deadline finding stays unresolved in the separate #150 scope; no hosted, protected-main or real-browser acceptance is claimed. diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 8827c0cbc..162bb815e 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -41,7 +41,7 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #166 exact head `e84a1a2cc82b1c666218efd441da97849f47b8c2`", "PR #220 exact head `e545b94e1de499b96b867694f80ac04ad247becd`", "retain formal `CHANGES_REQUESTED` decisions", - "every current review thread is resolved", + "thread-resolution state could not be refreshed", "115 queued workflow runs", "rerunning unchanged heads would only add duplicate queue load", "PR #249 is Draft at exact head `84b9407978ae0f6c115f01170b6069c601b21104`", @@ -116,8 +116,20 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "1100 functions, 11185 lines, 14272 regions, 1214 branches", "1140 functions, 11841 lines, 15129 regions, 1332 branches", "1154 functions, 11969 lines, 15314 regions, 1334 branches", - "Central Strix #1563 remains at `1221b1604e1a6cfde8ca5ab7fd3e93e0fe9faf69`", - "For #261, the recorded #260 parent is stale", + "Central Strix #1563 advanced to `13fbb48e0b3eeca4ce7d9678add934f9bd87ad3f`", + "independently inspected four-file source diff", + "2890 passed, 1 skipped, and 21 subtests are owner-reported", + "521 functions, 4420 lines, 5349 regions, 654 branches", + "#37 Strix run `33946242342`", + "Strix run timed out after 900s", + "#148 hosted compatibility run `33962062608`", + "browser-crash recovery fails 0/3 trials", + "#261 now includes actual #260", + "1173 functions, 12104 lines, 15511 regions, 1334 branches", + "1221 functions, 12781 lines, 16404 regions, 1418 branches", + "no subscription bytes but two outstanding commands", + "GraphQL rejected both the inventory query and a minimal probe", + "REST reviews, check runs, and combined statuses were read for all 125 open PRs", "warning: --branch option is unstable", "numerical coverage enforcement is distinct from warning-free instrumentation", "PR #139 at `b7ea5bfe336456fb263dd479a60b1cd0193d8a47`", @@ -140,8 +152,8 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #260 is Draft at exact head `2c5049aff97a90958e8262b1d403bdcbd64a1e8b`", "PR #258 is Draft at exact head `5f830324f6d5a47ac213a57528ef95649bdfd0df`", "PR #259 is Draft at exact head `66731982ed51ad62a04fcfbc759b0a33721a0254`", - "PR #261 is Draft at exact head `323ac9e147691e9f6572711f5a748e13f1036624`", - "Repair PR #277 is Draft at exact head `01038ba71fb276426cc67f90a91a3c431e194db5`", + "PR #261 is Draft at exact head `934eb7d37568b439c442ffe1d1f6a9c8f8ed58a0`", + "Repair PR #277 is Draft at exact head `117f6414e8a6db46eb2b32f4ebae85cf2a208371`", "PR #70 is Draft at exact head `77eb0f2ee71783e06171784b7173c0b4cd530e61`", "DDD/MCP repair #272 is Ready at exact head `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`", "PR #229 is Ready at exact head `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`", @@ -150,7 +162,8 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: "PR #283 is Draft at exact head `c904300a6a1bda83af24f84d586f1c5f6a6491aa`", "stacked on predecessor #282 head `b54a5856d8201911f05d69622f0d5594a371adf0` rather than current #282 exact `b64e0708584beff3fb54acf226cb3e667773e473`", "must adopt the corrected current parent before its compare can become current evidence", - "PR #288 is Draft at exact head `39e36256651f62940ec3ca6149067f0cfcb2285a`", + "PR #288 is Draft at exact head `0f434bc29d468127412366b6864b733b40b83c4d`", + "all 173 Python contracts pass on that unchanged head", "PR #269 is Draft at exact head `7854394266d3f292e779193c01413a34f6798d7c`", "PR #270 is Draft at exact head `191a14535219ea8033777fa4c970efb281b62418`", "PR #271 is Draft at exact head `802ec806cdd4560eab48c484f435766ecabda353`", @@ -213,6 +226,30 @@ def test_current_live_state_is_distinct_from_dated_snapshot(self) -> None: with self.subTest(stale=stale): self.assertNotIn(stale, current) + def test_latest_cut_does_not_promote_prior_observations(self) -> None: + """Fresh queue evidence must precede the explicitly historical cut.""" + latest = self.baseline.split("## Current live delivery state", 1)[1].split( + "### Prior observation cut: 2026-09-05", 1 + )[0] + for marker in ( + "Latest verified cut: 2026-09-06", + "63997bcf555e2c5c8e91ba287734ffba3837a1b7", + "fd589cd693946ef1ce2c9270c2dfb6a1087bdfb9", + "0135984f1bc1f68d89d7777f49c4999474105a12", + "973e34bc24ae9bdd96a50764f2be6c8603eff66c", + "3f22de94b63da83eaa8b5b1270912b21a3ecd006", + "GraphQL thread resolution was refreshed for all 125 open PRs", + "#147 retains the sole unresolved thread", + "34013251657", + "33990522248", + "34009256997", + "#279 owns current-workflow reconstruction", + "#212 owns sandbox-helper adoption", + "earlier local coverage counts do not validate these newer heads", + ): + with self.subTest(marker=marker): + self.assertIn(marker, latest) + def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: """The dated 2026-08-29 snapshot must keep its exact historical inventory.""" current = self.baseline.split("### Open pull requests", 1)[1].split( diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 2485a8a32..7ce701d93 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -97,7 +97,7 @@ def test_current_snapshot_records_the_pr_284_admin_bypass_incident(self) -> None "rule-suite `3948421709`", "`result: bypass`", "#215", - "post-merge checks remain non-terminal", + "fresh native Rust and production-coverage checks now succeed", ): with self.subTest(marker=marker): self.assertIn(marker, current) From 70d9c9750dd3de89a2fa11309620e147c6933afb Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 16:49:36 +0900 Subject: [PATCH 162/250] docs: record current sandbox and subscription identity evidence Refresh all 125 open PR review/check states and preserve the immutable August baseline. Separate new local repair proof from queued hosted checks, counted approval and unreleased provenance boundaries. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 10 +++++++--- .../test_gap_snapshot_inventory_consistency.py | 18 ++++++++++++++++++ 3 files changed, 26 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 198a924d9..8fea7f7a2 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Refreshed the live delivery baseline with sandbox-parent adoption, subscription request-identity repair, current review gates and explicit limits on browser acceptance evidence. - Separated the September 6 verified queue from prior measurements, recording restored-foundation workflow failures, current successor CI results, completed sandbox doctoring, and unreleased runtime/central-owner prerequisites. - Recorded verified #261/#277 parent adoption, the reproduced subscription-deadline slot repair, current #288 sandbox-source verification, and the central report-classification source repair; retained hosted, review, runtime, and independent-verification limits and the REST refresh boundary. - Recorded #50's reproduced formatting repair and verified current-parent integrations through #255–#260, preserving their exact local test/coverage evidence, child-source ownership, warning and runtime limits, and remaining hosted/approval gates. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 7b457662f..e8549cfb7 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -8,9 +8,9 @@ This volatile section is refreshed from live GitHub state and is authoritative o ### Latest verified cut: 2026-09-06 -Observed at (UTC): `2026-09-06T06:55:11Z`. This cut supersedes volatile claims in the prior observation section below; those earlier exact-head measurements remain historical rather than transferable acceptance evidence. +Observed through (UTC): `2026-09-06T07:47:47Z`. This cut supersedes volatile claims in the prior observation section below; those earlier exact-head measurements remain historical rather than transferable acceptance evidence. -The inventory remains **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`; no release or tag is proven. The Ready-root source heads listed in the prior cut are unchanged. GraphQL thread resolution was refreshed for all 125 open PRs using smaller paginated queries after the combined query returned an invalid response. No thread pagination remains; #147 retains the sole unresolved thread. #166/#220 retain `CHANGES_REQUESTED`, and the other Ready roots retain `REVIEW_REQUIRED`; all twelve are `BLOCKED`. REST reviews, checks and combined statuses were also refreshed for every exact head, with two incomplete review responses recovered separately. None of this authorizes a bypass or substitutes for an eligible counted approval. +The inventory remains **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`; release and tag inventories are both empty. Ready-root source heads other than this document's moving branch are unchanged. GraphQL thread resolution was refreshed for all 125 open PRs after the rate-limit window recovered. No thread pagination remains; #147 retains the sole unresolved thread. #166/#220 retain `CHANGES_REQUESTED`, and the other Ready roots retain `REVIEW_REQUIRED`; all twelve are `BLOCKED`. The 375 REST review/check/status reads completed without errors; #264 was refreshed separately after its subsequent push. Active ruleset `18156473` still requires a counted approval and seven central workflows, while the collaborator inventory still contains only the author. None of this authorizes a bypass or substitutes for an eligible counted approval. The restored foundation changes the next executable queue. #195 is Draft at `63997bcf555e2c5c8e91ba287734ffba3837a1b7`, on `6922dd98779e8f8aad132a3b1f563d7ba6e6d070`. Its owner restored product/evidence assets lost by historical whole-tree repair `5c111d0db6c363f9d1786c21cc01c5c7398007bd`; this is a content-recovery boundary, not permission to copy an old tree over later work. Fresh hosted CI `34013251657` fails in repository contracts while exact production coverage and MV3 `34013251651` succeed. The exercised failures compare inherited workflow concurrency and `nightly-2026-08-01` against the protected repository-scoped identity and `nightly-2026-08-18`. #279 owns current-workflow reconstruction; weakening the restored tests does not repair the generation mismatch. #242 remains at `2d0e9f69df9ade21d8e8e3d807c3ff644d83b310`, with a stale pre-recovery #195 base `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its old CI success is not recovered-foundation acceptance. After the owner prerequisite, adopt the verified foundation content-aware and non-destructively before regenerating descendant checks. @@ -34,7 +34,11 @@ The owner has already moved #255 directly onto #252 so the valid #253/#254 delta #148 is now Draft at `0135984f1bc1f68d89d7777f49c4999474105a12`. Current native CI `33990522263` succeeds, but pinned-Chromium MV3 `33990522248` fails. The later bounded diagnostic artifact locates browser-crash failure at session creation; #212 records 0/3 for every real-browser lane after all sandbox-disabling overrides were removed. #43's separate helper-generation MV3 `33866932365` succeeds only on its own exact source. #212 owns sandbox-helper adoption against the current protected workflow, followed by fresh consumer execution; cleanup bookkeeping and leaf success are not transferable runtime evidence. -On #238's pre-publication head, native CI `33966500232` and Strix `33966499362` succeed, while Noema `33966499292` and CodeQL `33966500187` fail. This document's next commit requires new exact-head checks; it cannot inherit those results. Existing central CodeQL dispatch/verdict work remains with `.github#712`. Central Strix #1563 remains unmerged at `eaf9594f7fe8d8e1994349289183d6cbad056579`, now reported behind its base: the earlier `13fbb48e...` source repair and owner-reported harness results do not prove consumer recovery. The unrelated #37 local 900-second deadline remains distinct from the #166 completed-report classifier defect and #219/#240 actual gateway/hosted-limit incidents. +#150 is Draft at `6ab7fc9166f397f49442243492ae88d6ccad56cf`, ordinarily adopting #148 `0135984f1bc1f68d89d7777f49c4999474105a12` while preserving its combined ordinary-pass teardown waiter. Reused parent regressions first exposed three unsafe browser-launch paths and missing crash-stage diagnostics on the child predecessor. The repair preserves all sandboxed parent launch/cleanup behavior and the child waiter delta. All 253 Python contracts pass on Linux without skips; the corresponding macOS run explicitly skips three Linux pidfd cases. Host/guest tracked manifests match `985411ef6a7d3b812be086b43b6341a96f6b8acace63c0161fa8453aae065bd3`. Complete local Rust gates and 415/3555/4444/476 exact 100% coverage pass. Native CI `34018588292` and MV3 `34018588298` remain queued, not passing browser evidence. #147's ordinary-deadline review thread remains unresolved until this child is actually integrated. + +#264 is Draft at `43d3b5a3a2b5ce4f51a93d1152a0ee82620f4f3e`, on actual #263 `3f22de94b63da83eaa8b5b1270912b21a3ecd006`. Ordinary adoption `cf0f2452...` preserved parent received-connection provenance and child admission bodies after an unchanged inherited regression failed to compile. Subsequent test-first `73f11de2232060ac7680e188db88ef7609123296` reproduced two existing defects: a sent receipt accepted an unsent same-id binding, and public correlation re-registration could reconstruct a consumed receipt without another send. An additional two-registry regression disproved numeric tuple provenance. The final repair retains private original-command identity through existing correlation/receipt state and rejects independently constructed unsent bindings even when all fields match. Five admission loopback tests, all 144 Python contracts, full Rust gates and 1273/13294/16963/1430 exact 100% coverage pass. Independent read-only review found no production defect in this bounded repair; it is not counted approval. Exact CI `34020055803` has queued Rust/coverage jobs `101450853421` / `101450853476`. Connection-authenticated events, actual-resend freshness, binding the current caller-supplied registry to transport, and real-browser causality remain unproven. The #195/#279 prerequisite, branch-instrumentation warning and Draft status remain; no workflow, dependency, deadline or gate changed. + +On #238's pre-publication head, native CI `34018002926` now succeeds while central review/security jobs remain queued. This document's next commit requires new exact-head checks; it cannot inherit those results. Existing central CodeQL dispatch/verdict work remains with `.github#712`. Central Strix #1563 remains unmerged at `eaf9594f7fe8d8e1994349289183d6cbad056579`, reported behind its base: the earlier `13fbb48e...` source repair and owner-reported harness results do not prove consumer recovery. The unrelated #37 local 900-second deadline remains distinct from the #166 completed-report classifier defect and #219/#240 actual gateway/hosted-limit incidents. The active central Noema owner additionally reports source REDs under `.github#1641`; owner reports and comments are not released transport or SDK-compatibility evidence, and no consumer workaround is introduced here. ### Prior observation cut: 2026-09-05 diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 162bb815e..380e5a237 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -250,6 +250,24 @@ def test_latest_cut_does_not_promote_prior_observations(self) -> None: with self.subTest(marker=marker): self.assertIn(marker, latest) + def test_current_cut_records_parent_adoption_and_sent_command_repair(self) -> None: + """New source evidence must not inherit earlier native or browser acceptance.""" + latest = self.baseline.split("## Current live delivery state", 1)[1].split( + "### Prior observation cut: 2026-09-05", 1 + )[0] + for marker in ( + "6ab7fc9166f397f49442243492ae88d6ccad56cf", + "43d3b5a3a2b5ce4f51a93d1152a0ee82620f4f3e", + "73f11de2232060ac7680e188db88ef7609123296", + "253 Python contracts", + "1273/13294/16963/1430", + "34020055803", + "actual-resend freshness", + "current caller-supplied registry", + ): + with self.subTest(marker=marker): + self.assertIn(marker, latest) + def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: """The dated 2026-08-29 snapshot must keep its exact historical inventory.""" current = self.baseline.split("### Open pull requests", 1)[1].split( From 38e5eb44f44c7a7fc3dc0b4af7dea6ab2ef91be4 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 17:24:32 +0900 Subject: [PATCH 163/250] docs: separate hosted browser failure from private repair evidence Record the exact current150 sandboxed session-creation failure and owner212artifact, completed125PR review/check audit, and unpublished264receive-provenance checkpoint versus moving remote writer. Preserve both contributor deltas and the immutable historical snapshot. One new contract reproduced nine stale or missing evidence assertions before repair; all172Pythoncontracts, compileall, CodeGraph and diff checks pass. No source, workflows, approval, runtime acceptance or release state is changed. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 14 +++++++----- ...test_gap_snapshot_inventory_consistency.py | 22 +++++++++++++++++++ 3 files changed, 32 insertions(+), 5 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 8fea7f7a2..2560331f3 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Corrected the browser acceptance status after hosted trials failed, and separated verified unpublished subscription safeguards from another task's ongoing changes. - Refreshed the live delivery baseline with sandbox-parent adoption, subscription request-identity repair, current review gates and explicit limits on browser acceptance evidence. - Separated the September 6 verified queue from prior measurements, recording restored-foundation workflow failures, current successor CI results, completed sandbox doctoring, and unreleased runtime/central-owner prerequisites. - Recorded verified #261/#277 parent adoption, the reproduced subscription-deadline slot repair, current #288 sandbox-source verification, and the central report-classification source repair; retained hosted, review, runtime, and independent-verification limits and the REST refresh boundary. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e8549cfb7..eda7e1b92 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -8,9 +8,9 @@ This volatile section is refreshed from live GitHub state and is authoritative o ### Latest verified cut: 2026-09-06 -Observed through (UTC): `2026-09-06T07:47:47Z`. This cut supersedes volatile claims in the prior observation section below; those earlier exact-head measurements remain historical rather than transferable acceptance evidence. +Observed through (UTC): `2026-09-06T08:21:57Z`. This cut supersedes volatile claims in the prior observation section below; those earlier exact-head measurements remain historical rather than transferable acceptance evidence. -The inventory remains **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`; release and tag inventories are both empty. Ready-root source heads other than this document's moving branch are unchanged. GraphQL thread resolution was refreshed for all 125 open PRs after the rate-limit window recovered. No thread pagination remains; #147 retains the sole unresolved thread. #166/#220 retain `CHANGES_REQUESTED`, and the other Ready roots retain `REVIEW_REQUIRED`; all twelve are `BLOCKED`. The 375 REST review/check/status reads completed without errors; #264 was refreshed separately after its subsequent push. Active ruleset `18156473` still requires a counted approval and seven central workflows, while the collaborator inventory still contains only the author. None of this authorizes a bypass or substitutes for an eligible counted approval. +The inventory remains **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`; release and tag inventories are both empty. Ready-root source heads other than this document's moving branch are unchanged. GraphQL thread resolution was refreshed for all 125 open PRs together with exact-head check rollups and reviews. The initial oversized query timed out; smaller pages succeeded, and follow-up thread queries plus paginated REST reviews completed every truncated history. No thread pagination remains; #147 retains the sole unresolved thread. #166/#220 retain `CHANGES_REQUESTED`, and the other Ready roots retain `REVIEW_REQUIRED`; all twelve are `BLOCKED`. The preceding 375 REST audit remains a separate earlier observation, not a claim about this later refresh. Active ruleset `18156473` still requires a counted approval and seven central workflows, while the collaborator inventory still contains only the author. #219 has a same-head formal bot approval, but its current GitHub decision remains `REVIEW_REQUIRED`; an uncounted review does not satisfy the gate. None of this authorizes a bypass or substitutes for an eligible counted approval. The restored foundation changes the next executable queue. #195 is Draft at `63997bcf555e2c5c8e91ba287734ffba3837a1b7`, on `6922dd98779e8f8aad132a3b1f563d7ba6e6d070`. Its owner restored product/evidence assets lost by historical whole-tree repair `5c111d0db6c363f9d1786c21cc01c5c7398007bd`; this is a content-recovery boundary, not permission to copy an old tree over later work. Fresh hosted CI `34013251657` fails in repository contracts while exact production coverage and MV3 `34013251651` succeed. The exercised failures compare inherited workflow concurrency and `nightly-2026-08-01` against the protected repository-scoped identity and `nightly-2026-08-18`. #279 owns current-workflow reconstruction; weakening the restored tests does not repair the generation mismatch. #242 remains at `2d0e9f69df9ade21d8e8e3d807c3ff644d83b310`, with a stale pre-recovery #195 base `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its old CI success is not recovered-foundation acceptance. After the owner prerequisite, adopt the verified foundation content-aware and non-destructively before regenerating descendant checks. @@ -34,11 +34,15 @@ The owner has already moved #255 directly onto #252 so the valid #253/#254 delta #148 is now Draft at `0135984f1bc1f68d89d7777f49c4999474105a12`. Current native CI `33990522263` succeeds, but pinned-Chromium MV3 `33990522248` fails. The later bounded diagnostic artifact locates browser-crash failure at session creation; #212 records 0/3 for every real-browser lane after all sandbox-disabling overrides were removed. #43's separate helper-generation MV3 `33866932365` succeeds only on its own exact source. #212 owns sandbox-helper adoption against the current protected workflow, followed by fresh consumer execution; cleanup bookkeeping and leaf success are not transferable runtime evidence. -#150 is Draft at `6ab7fc9166f397f49442243492ae88d6ccad56cf`, ordinarily adopting #148 `0135984f1bc1f68d89d7777f49c4999474105a12` while preserving its combined ordinary-pass teardown waiter. Reused parent regressions first exposed three unsafe browser-launch paths and missing crash-stage diagnostics on the child predecessor. The repair preserves all sandboxed parent launch/cleanup behavior and the child waiter delta. All 253 Python contracts pass on Linux without skips; the corresponding macOS run explicitly skips three Linux pidfd cases. Host/guest tracked manifests match `985411ef6a7d3b812be086b43b6341a96f6b8acace63c0161fa8453aae065bd3`. Complete local Rust gates and 415/3555/4444/476 exact 100% coverage pass. Native CI `34018588292` and MV3 `34018588298` remain queued, not passing browser evidence. #147's ordinary-deadline review thread remains unresolved until this child is actually integrated. +#150 is Draft at `6ab7fc9166f397f49442243492ae88d6ccad56cf`, ordinarily adopting #148 `0135984f1bc1f68d89d7777f49c4999474105a12` while preserving its combined ordinary-pass teardown waiter. Reused parent regressions first exposed three unsafe browser-launch paths and missing crash-stage diagnostics on the child predecessor. The repair preserves all sandboxed parent launch/cleanup behavior and the child waiter delta. All 253 Python contracts pass on Linux without skips; the corresponding macOS run explicitly skips three Linux pidfd cases. Host/guest tracked manifests match `985411ef6a7d3b812be086b43b6341a96f6b8acace63c0161fa8453aae065bd3`. Complete local Rust gates and 415/3555/4444/476 exact 100% coverage pass. Native CI `34018588292` now succeeds, but MV3 `34018588298` / job `101446865332` fails on that same head. Artifact `9985228944`, digest `sha256:05b6d1cd6092a9e2e18a5003a5a1faeb73b8a8d9b4fd7533f7f24bc938833436`, records all four browser lanes at 0/3, with each browser-crash trial failing at `session_create` and all profiles cleaned. This identifies the failed stage, not the underlying Chrome startup cause. The bounded diagnostic and sandboxed runner/helper follow-up is attached to [#212 comment 5557994915](https://github.com/ContextualWisdomLab/OriginWeave/issues/212#issuecomment-5557994915); no sandbox bypass or unchanged rerun was attempted. #147's ordinary-deadline review thread remains unresolved until this child is actually integrated. -#264 is Draft at `43d3b5a3a2b5ce4f51a93d1152a0ee82620f4f3e`, on actual #263 `3f22de94b63da83eaa8b5b1270912b21a3ecd006`. Ordinary adoption `cf0f2452...` preserved parent received-connection provenance and child admission bodies after an unchanged inherited regression failed to compile. Subsequent test-first `73f11de2232060ac7680e188db88ef7609123296` reproduced two existing defects: a sent receipt accepted an unsent same-id binding, and public correlation re-registration could reconstruct a consumed receipt without another send. An additional two-registry regression disproved numeric tuple provenance. The final repair retains private original-command identity through existing correlation/receipt state and rejects independently constructed unsent bindings even when all fields match. Five admission loopback tests, all 144 Python contracts, full Rust gates and 1273/13294/16963/1430 exact 100% coverage pass. Independent read-only review found no production defect in this bounded repair; it is not counted approval. Exact CI `34020055803` has queued Rust/coverage jobs `101450853421` / `101450853476`. Connection-authenticated events, actual-resend freshness, binding the current caller-supplied registry to transport, and real-browser causality remain unproven. The #195/#279 prerequisite, branch-instrumentation warning and Draft status remain; no workflow, dependency, deadline or gate changed. +#264 remains Draft on actual #263 `3f22de94b63da83eaa8b5b1270912b21a3ecd006`. The preceding published head `43d3b5a3a2b5ce4f51a93d1152a0ee82620f4f3e` retained private original-command identity after test-first `73f11de2232060ac7680e188db88ef7609123296` and the two-registry collision regression. Its five admission tests, 144 Python contracts and 1273/13294/16963/1430 exact 100% local coverage are predecessor evidence; native CI `34020055803` is now cancelled, not current acceptance. -On #238's pre-publication head, native CI `34018002926` now succeeds while central review/security jobs remain queued. This document's next commit requires new exact-head checks; it cannot inherit those results. Existing central CodeQL dispatch/verdict work remains with `.github#712`. Central Strix #1563 remains unmerged at `eaf9594f7fe8d8e1994349289183d6cbad056579`, reported behind its base: the earlier `13fbb48e...` source repair and owner-reported harness results do not prove consumer recovery. The unrelated #37 local 900-second deadline remains distinct from the #166 completed-report classifier defect and #219/#240 actual gateway/hosted-limit incidents. The active central Noema owner additionally reports source REDs under `.github#1641`; owner reports and comments are not released transport or SDK-compatibility evidence, and no consumer workaround is introduced here. +The next inbound-provenance repair is preserved as unpublished checkpoint `bd29f405a6c927b2f7d1c437dccbfb8bcec424f1`, following real crossed-connection RED `918c4ebe`. It reuses the existing connection-owned reader and private connection generation to reject foreign success, protocol-error and navigation-event messages before pending-command or document mutation, then proves original-connection recovery. Seven admission tests, 23 focused tests, all 144 Python contracts, full Rust gates and 1273/13311/16973/1432 exact 100% coverage pass on that private tree. Independent read-only review found no actionable defect; it is not counted approval. This evidence has not been pushed and must not be attached to the moving remote head. + +A separately active writer advanced the remote through `bc2e69d5`, `a3dfd190`, `c46642e2`, `ed434fc7`, `d8983d50`, `ced211a7`, `7ae9657c` and observed head `7c20907b50da06e4b0de340adec7b336c2503e81`. The inspected intervening commits contain valid regression and connection-provenance work. [Writer coordination comment 5557964460](https://github.com/ContextualWisdomLab/OriginWeave/pull/264#issuecomment-5557964460) requests task identification, writer acknowledgement and a final exact-head handoff. The private writer claim was released without a competing push. Preserve both complete deltas by ordinary content-aware integration after ownership is settled; do not force-push, close the PR or treat either contributor's work as disposable. The current caller-supplied registry binding, actual-resend freshness on the same connection, unsubscribe transport/lifetime provenance and real-browser causality remain distinct unproven boundaries. The #195/#279 prerequisite, branch-instrumentation warning and Draft status remain; no workflow, dependency, deadline or gate changed. + +On #238's earlier `a2600ee8...` head, native CI `34018002926` succeeded. The later pre-publication head `70d9c975...` has native CI `34020189988` still queued, together with central review/security work. This document's next commit requires new exact-head checks; it cannot inherit those results. Existing central CodeQL dispatch/verdict work remains with `.github#712`. Central Strix #1563 remains unmerged at `eaf9594f7fe8d8e1994349289183d6cbad056579`, reported behind its base: the earlier `13fbb48e...` source repair and owner-reported harness results do not prove consumer recovery. The unrelated #37 local 900-second deadline remains distinct from the #166 completed-report classifier defect and #219/#240 actual gateway/hosted-limit incidents. The active central Noema owner additionally reports source REDs under `.github#1641`; owner reports and comments are not released transport or SDK-compatibility evidence, and no consumer workaround is introduced here. ### Prior observation cut: 2026-09-05 diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 380e5a237..2035fc8e0 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -268,6 +268,28 @@ def test_current_cut_records_parent_adoption_and_sent_command_repair(self) -> No with self.subTest(marker=marker): self.assertIn(marker, latest) + def test_current_cut_separates_browser_failure_and_unpublished_repair(self) -> None: + """Hosted browser failure and private source proof must stay distinct.""" + latest = self.baseline.split("## Current live delivery state", 1)[1].split( + "### Prior observation cut: 2026-09-05", 1 + )[0] + for marker in ( + "9985228944", + "05b6d1cd6092a9e2e18a5003a5a1faeb73b8a8d9b4fd7533f7f24bc938833436", + "5557994915", + "bd29f405a6c927b2f7d1c437dccbfb8bcec424f1", + "1273/13311/16973/1432", + "unpublished checkpoint", + "5557964460", + "writer acknowledgement", + ): + with self.subTest(marker=marker): + self.assertIn(marker, latest) + self.assertNotIn( + "Native CI `34018588292` and MV3 `34018588298` remain queued", + latest, + ) + def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: """The dated 2026-08-29 snapshot must keep its exact historical inventory.""" current = self.baseline.split("### Open pull requests", 1)[1].split( From 7ca86a2f546adf3a0af3fec41d97675115db384d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 17:42:39 +0900 Subject: [PATCH 164/250] docs: distinguish remote quality failures from private repair proof Record exact remote subscription formatting and coverage failures, the independent preservation map, and the completed live queue refresh. Six current-cut assertions failed before repair; all 172 repository contracts, compileall, CodeGraph and diff checks now pass. The dated historical snapshot remains byte-identical. No production, workflow, quality gate or release state changes. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 8 +++++--- tests/test_gap_snapshot_inventory_consistency.py | 6 ++++++ 3 files changed, 12 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 2560331f3..3e9a44391 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded failed quality checks on the current subscription revision without transferring passing results from an unpublished repair. - Corrected the browser acceptance status after hosted trials failed, and separated verified unpublished subscription safeguards from another task's ongoing changes. - Refreshed the live delivery baseline with sandbox-parent adoption, subscription request-identity repair, current review gates and explicit limits on browser acceptance evidence. - Separated the September 6 verified queue from prior measurements, recording restored-foundation workflow failures, current successor CI results, completed sandbox doctoring, and unreleased runtime/central-owner prerequisites. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index eda7e1b92..247bf08a0 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -8,7 +8,7 @@ This volatile section is refreshed from live GitHub state and is authoritative o ### Latest verified cut: 2026-09-06 -Observed through (UTC): `2026-09-06T08:21:57Z`. This cut supersedes volatile claims in the prior observation section below; those earlier exact-head measurements remain historical rather than transferable acceptance evidence. +Observed through (UTC): `2026-09-06T08:40:11Z`. This cut supersedes volatile claims in the prior observation section below; those earlier exact-head measurements remain historical rather than transferable acceptance evidence. The inventory remains **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`; release and tag inventories are both empty. Ready-root source heads other than this document's moving branch are unchanged. GraphQL thread resolution was refreshed for all 125 open PRs together with exact-head check rollups and reviews. The initial oversized query timed out; smaller pages succeeded, and follow-up thread queries plus paginated REST reviews completed every truncated history. No thread pagination remains; #147 retains the sole unresolved thread. #166/#220 retain `CHANGES_REQUESTED`, and the other Ready roots retain `REVIEW_REQUIRED`; all twelve are `BLOCKED`. The preceding 375 REST audit remains a separate earlier observation, not a claim about this later refresh. Active ruleset `18156473` still requires a counted approval and seven central workflows, while the collaborator inventory still contains only the author. #219 has a same-head formal bot approval, but its current GitHub decision remains `REVIEW_REQUIRED`; an uncounted review does not satisfy the gate. None of this authorizes a bypass or substitutes for an eligible counted approval. @@ -40,9 +40,11 @@ The owner has already moved #255 directly onto #252 so the valid #253/#254 delta The next inbound-provenance repair is preserved as unpublished checkpoint `bd29f405a6c927b2f7d1c437dccbfb8bcec424f1`, following real crossed-connection RED `918c4ebe`. It reuses the existing connection-owned reader and private connection generation to reject foreign success, protocol-error and navigation-event messages before pending-command or document mutation, then proves original-connection recovery. Seven admission tests, 23 focused tests, all 144 Python contracts, full Rust gates and 1273/13311/16973/1432 exact 100% coverage pass on that private tree. Independent read-only review found no actionable defect; it is not counted approval. This evidence has not been pushed and must not be attached to the moving remote head. -A separately active writer advanced the remote through `bc2e69d5`, `a3dfd190`, `c46642e2`, `ed434fc7`, `d8983d50`, `ced211a7`, `7ae9657c` and observed head `7c20907b50da06e4b0de340adec7b336c2503e81`. The inspected intervening commits contain valid regression and connection-provenance work. [Writer coordination comment 5557964460](https://github.com/ContextualWisdomLab/OriginWeave/pull/264#issuecomment-5557964460) requests task identification, writer acknowledgement and a final exact-head handoff. The private writer claim was released without a competing push. Preserve both complete deltas by ordinary content-aware integration after ownership is settled; do not force-push, close the PR or treat either contributor's work as disposable. The current caller-supplied registry binding, actual-resend freshness on the same connection, unsubscribe transport/lifetime provenance and real-browser causality remain distinct unproven boundaries. The #195/#279 prerequisite, branch-instrumentation warning and Draft status remain; no workflow, dependency, deadline or gate changed. +A separately active writer advanced the remote through `bc2e69d5`, `a3dfd190`, `c46642e2`, `ed434fc7`, `d8983d50`, `ced211a7`, `7ae9657c`, `7c20907b` and current head `8ebcc6131a5dd6bf0b4720c2f1ff8d40d1cc39f8`. The inspected intervening commits contain valid regression and connection-provenance work. [Writer coordination comment 5557964460](https://github.com/ContextualWisdomLab/OriginWeave/pull/264#issuecomment-5557964460) requests task identification, writer acknowledgement and a final exact-head handoff. The private writer claim was released without a competing push. Preserve both complete deltas by ordinary content-aware integration after ownership is settled; do not force-push, close the PR or treat either contributor's work as disposable. The current caller-supplied registry binding, actual-resend freshness on the same connection, unsubscribe transport/lifetime provenance and real-browser causality remain distinct unproven boundaries. The #195/#279 prerequisite, branch-instrumentation warning and Draft status remain; no workflow, dependency, deadline or gate changed. -On #238's earlier `a2600ee8...` head, native CI `34018002926` succeeded. The later pre-publication head `70d9c975...` has native CI `34020189988` still queued, together with central review/security work. This document's next commit requires new exact-head checks; it cannot inherit those results. Existing central CodeQL dispatch/verdict work remains with `.github#712`. Central Strix #1563 remains unmerged at `eaf9594f7fe8d8e1994349289183d6cbad056579`, reported behind its base: the earlier `13fbb48e...` source repair and owner-reported harness results do not prove consumer recovery. The unrelated #37 local 900-second deadline remains distinct from the #166 completed-report classifier defect and #219/#240 actual gateway/hosted-limit incidents. The active central Noema owner additionally reports source REDs under `.github#1641`; owner reports and comments are not released transport or SDK-compatibility evidence, and no consumer workaround is introduced here. +A fresh unmodified detached checkout of remote `8ebcc613` passes Rust 1.97.1 network/all-targets checking, strict workspace/all-targets/all-features Clippy and all 145 Python contracts. Its Rust 1.97.1 formatting check fails in five test/support files. The pinned nightly coverage test run completes, but the unchanged numerical verifier fails at lines 13327/13330 and regions 17004/17008; functions 1274/1274 and branches 1434/1434 are exactly covered. Coverage artifact SHA-256 is `f352e3f04bdc3ed1912be7c452c5c426d9caaec7dd1a613b7d3ab9c6486ab69e`. The uncovered regions are the duplicated missing-generation propagation in correlation completion at line 240 and the admission diagnostic at lines 396–397. Independent source review confirms that the former follows an intent check whose retained constructor always sets the generation; shared validation and a real rejected-event diagnostic/recovery test address these causes without exclusions or fabricated production state. The comparison found no reachable authority bypass and identifies remote typed-send malformed/unknown/error fixtures, stronger rustdoc and the source contract as deltas to preserve together with private original-connection recovery, unchanged document state, authentic receipt redaction assertions and bounded evidence. Neither private nor remote results establish combined-source acceptance. Current remote native CI `34021674375` is still queued; formatting, numerical coverage and hosted execution remain separate gates. The existing coordination comment records the exact diagnostic and preservation map; no shared-source integration or writer acknowledgement occurred. + +On #238's earlier `a2600ee8...` head, native CI `34018002926` succeeded. The current pre-publication head `38e5eb44...` has native CI `34021771606` still queued, together with central review/security work. This document's next commit requires new exact-head checks; it cannot inherit those results. Existing central CodeQL dispatch/verdict work remains with `.github#712`. Central Strix #1563 remains unmerged at `eaf9594f7fe8d8e1994349289183d6cbad056579`, reported behind its base: the earlier `13fbb48e...` source repair and owner-reported harness results do not prove consumer recovery. The unrelated #37 local 900-second deadline remains distinct from the #166 completed-report classifier defect and #219/#240 actual gateway/hosted-limit incidents. The active central Noema owner additionally reports source REDs under `.github#1641`; owner reports and comments are not released transport or SDK-compatibility evidence, and no consumer workaround is introduced here. ### Prior observation cut: 2026-09-05 diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 2035fc8e0..b8db97ecb 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -282,6 +282,12 @@ def test_current_cut_separates_browser_failure_and_unpublished_repair(self) -> N "unpublished checkpoint", "5557964460", "writer acknowledgement", + "8ebcc6131a5dd6bf0b4720c2f1ff8d40d1cc39f8", + "lines 13327/13330 and regions 17004/17008", + "functions 1274/1274 and branches 1434/1434", + "f352e3f04bdc3ed1912be7c452c5c426d9caaec7dd1a613b7d3ab9c6486ab69e", + "formatting check fails in five test/support files", + "Neither private nor remote results establish combined-source acceptance", ): with self.subTest(marker=marker): self.assertIn(marker, latest) From 545551f046129d561eb3293ec12aa567d3714e4f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 18:25:32 +0900 Subject: [PATCH 165/250] test(docs): require integrated subscription publication evidence Record the missing current published integration and retained automation update failure boundary before refreshing the volatile delivery cut; preserve historical predecessor markers. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- tests/test_gap_snapshot_inventory_consistency.py | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index b8db97ecb..77c0fafa3 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -288,6 +288,14 @@ def test_current_cut_separates_browser_failure_and_unpublished_repair(self) -> N "f352e3f04bdc3ed1912be7c452c5c426d9caaec7dd1a613b7d3ab9c6486ab69e", "formatting check fails in five test/support files", "Neither private nor remote results establish combined-source acceptance", + "2a9fdc5418b9af10353cdad0f6f6470655bf457d", + "52cff96954c3fec7b8cda5409e4560e970bfcbdf", + "1273/13317/16984/1432", + "f7e71e6fd67723688535053c389b4ff718c4563b403924af462848d3d51b541f", + "34024499232", + "5558261278", + "both complete lineages are now ancestors", + "too_many_active_automations", ): with self.subTest(marker=marker): self.assertIn(marker, latest) From 70b9a9862319417c7664d0b90b64a58a0ace57d8 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 18:31:18 +0900 Subject: [PATCH 166/250] docs: bind subscription integration proof to published revision Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 16 ++++++++++------ 2 files changed, 11 insertions(+), 6 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 3e9a44391..6012eae2a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded the published subscription integration and its complete local verification, preserving earlier failures and the separate hosted-check and release requirements. - Recorded failed quality checks on the current subscription revision without transferring passing results from an unpublished repair. - Corrected the browser acceptance status after hosted trials failed, and separated verified unpublished subscription safeguards from another task's ongoing changes. - Refreshed the live delivery baseline with sandbox-parent adoption, subscription request-identity repair, current review gates and explicit limits on browser acceptance evidence. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 247bf08a0..9884cbfde 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -8,9 +8,9 @@ This volatile section is refreshed from live GitHub state and is authoritative o ### Latest verified cut: 2026-09-06 -Observed through (UTC): `2026-09-06T08:40:11Z`. This cut supersedes volatile claims in the prior observation section below; those earlier exact-head measurements remain historical rather than transferable acceptance evidence. +Observed through (UTC): `2026-09-06T09:29:22Z`. This cut supersedes volatile claims in the prior observation section below; those earlier exact-head measurements remain historical rather than transferable acceptance evidence. -The inventory remains **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`; release and tag inventories are both empty. Ready-root source heads other than this document's moving branch are unchanged. GraphQL thread resolution was refreshed for all 125 open PRs together with exact-head check rollups and reviews. The initial oversized query timed out; smaller pages succeeded, and follow-up thread queries plus paginated REST reviews completed every truncated history. No thread pagination remains; #147 retains the sole unresolved thread. #166/#220 retain `CHANGES_REQUESTED`, and the other Ready roots retain `REVIEW_REQUIRED`; all twelve are `BLOCKED`. The preceding 375 REST audit remains a separate earlier observation, not a claim about this later refresh. Active ruleset `18156473` still requires a counted approval and seven central workflows, while the collaborator inventory still contains only the author. #219 has a same-head formal bot approval, but its current GitHub decision remains `REVIEW_REQUIRED`; an uncounted review does not satisfy the gate. None of this authorizes a bypass or substitutes for an eligible counted approval. +The inventory remains **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`; release and tag inventories are both empty. Ready-root source heads other than this document's moving branch are unchanged. GraphQL thread resolution was refreshed for all 125 open PRs together with exact-head check rollups and reviews in five 25-item pages. Follow-up queries completed 12 truncated thread histories and paginated REST reads completed 14 truncated review histories. No thread pagination remains; #147 retains the sole unresolved thread. #166/#220 retain `CHANGES_REQUESTED`, and the other Ready roots retain `REVIEW_REQUIRED`; all twelve are `BLOCKED`. Earlier oversized-query failures and the preceding 375 REST audit remain separate observations, not claims about this later refresh. Active ruleset `18156473` still requires a counted approval and seven central workflows, while the collaborator inventory still contains only the author. #219 has a same-head formal bot approval, but its current GitHub decision remains `REVIEW_REQUIRED`; an uncounted review does not satisfy the gate. None of this authorizes a bypass or substitutes for an eligible counted approval. The restored foundation changes the next executable queue. #195 is Draft at `63997bcf555e2c5c8e91ba287734ffba3837a1b7`, on `6922dd98779e8f8aad132a3b1f563d7ba6e6d070`. Its owner restored product/evidence assets lost by historical whole-tree repair `5c111d0db6c363f9d1786c21cc01c5c7398007bd`; this is a content-recovery boundary, not permission to copy an old tree over later work. Fresh hosted CI `34013251657` fails in repository contracts while exact production coverage and MV3 `34013251651` succeed. The exercised failures compare inherited workflow concurrency and `nightly-2026-08-01` against the protected repository-scoped identity and `nightly-2026-08-18`. #279 owns current-workflow reconstruction; weakening the restored tests does not repair the generation mismatch. #242 remains at `2d0e9f69df9ade21d8e8e3d807c3ff644d83b310`, with a stale pre-recovery #195 base `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its old CI success is not recovered-foundation acceptance. After the owner prerequisite, adopt the verified foundation content-aware and non-destructively before regenerating descendant checks. @@ -38,13 +38,17 @@ The owner has already moved #255 directly onto #252 so the valid #253/#254 delta #264 remains Draft on actual #263 `3f22de94b63da83eaa8b5b1270912b21a3ecd006`. The preceding published head `43d3b5a3a2b5ce4f51a93d1152a0ee82620f4f3e` retained private original-command identity after test-first `73f11de2232060ac7680e188db88ef7609123296` and the two-registry collision regression. Its five admission tests, 144 Python contracts and 1273/13294/16963/1430 exact 100% local coverage are predecessor evidence; native CI `34020055803` is now cancelled, not current acceptance. -The next inbound-provenance repair is preserved as unpublished checkpoint `bd29f405a6c927b2f7d1c437dccbfb8bcec424f1`, following real crossed-connection RED `918c4ebe`. It reuses the existing connection-owned reader and private connection generation to reject foreign success, protocol-error and navigation-event messages before pending-command or document mutation, then proves original-connection recovery. Seven admission tests, 23 focused tests, all 144 Python contracts, full Rust gates and 1273/13311/16973/1432 exact 100% coverage pass on that private tree. Independent read-only review found no actionable defect; it is not counted approval. This evidence has not been pushed and must not be attached to the moving remote head. +The inbound-provenance repair was first preserved as unpublished checkpoint `bd29f405a6c927b2f7d1c437dccbfb8bcec424f1`, following real crossed-connection RED `918c4ebe`. It reused the existing connection-owned reader and private connection generation to reject foreign success, protocol-error and navigation-event messages before pending-command or document mutation, then proved original-connection recovery. Seven admission tests, 23 focused tests, all 144 Python contracts, full Rust gates and 1273/13311/16973/1432 exact 100% coverage passed on that private tree. Independent read-only review found no actionable defect; it is not counted approval. Those measurements remain attached to that predecessor, not transferred to the later integration below. -A separately active writer advanced the remote through `bc2e69d5`, `a3dfd190`, `c46642e2`, `ed434fc7`, `d8983d50`, `ced211a7`, `7ae9657c`, `7c20907b` and current head `8ebcc6131a5dd6bf0b4720c2f1ff8d40d1cc39f8`. The inspected intervening commits contain valid regression and connection-provenance work. [Writer coordination comment 5557964460](https://github.com/ContextualWisdomLab/OriginWeave/pull/264#issuecomment-5557964460) requests task identification, writer acknowledgement and a final exact-head handoff. The private writer claim was released without a competing push. Preserve both complete deltas by ordinary content-aware integration after ownership is settled; do not force-push, close the PR or treat either contributor's work as disposable. The current caller-supplied registry binding, actual-resend freshness on the same connection, unsubscribe transport/lifetime provenance and real-browser causality remain distinct unproven boundaries. The #195/#279 prerequisite, branch-instrumentation warning and Draft status remain; no workflow, dependency, deadline or gate changed. +A separately active writer advanced the remote through `bc2e69d5`, `a3dfd190`, `c46642e2`, `ed434fc7`, `d8983d50`, `ced211a7`, `7ae9657c`, `7c20907b` and then-current head `8ebcc6131a5dd6bf0b4720c2f1ff8d40d1cc39f8`. The inspected intervening commits contain valid regression and connection-provenance work. [Writer coordination comment 5557964460](https://github.com/ContextualWisdomLab/OriginWeave/pull/264#issuecomment-5557964460) requested task identification, writer acknowledgement and a final exact-head handoff. The private writer claim was released without a competing push; the subsequent integration and release are recorded below. The current caller-supplied registry binding, actual-resend freshness on the same connection, unsubscribe transport/lifetime provenance and real-browser causality remain distinct unproven boundaries. The #195/#279 prerequisite, branch-instrumentation warning and Draft status remain; no workflow, dependency, deadline or gate changed. -A fresh unmodified detached checkout of remote `8ebcc613` passes Rust 1.97.1 network/all-targets checking, strict workspace/all-targets/all-features Clippy and all 145 Python contracts. Its Rust 1.97.1 formatting check fails in five test/support files. The pinned nightly coverage test run completes, but the unchanged numerical verifier fails at lines 13327/13330 and regions 17004/17008; functions 1274/1274 and branches 1434/1434 are exactly covered. Coverage artifact SHA-256 is `f352e3f04bdc3ed1912be7c452c5c426d9caaec7dd1a613b7d3ab9c6486ab69e`. The uncovered regions are the duplicated missing-generation propagation in correlation completion at line 240 and the admission diagnostic at lines 396–397. Independent source review confirms that the former follows an intent check whose retained constructor always sets the generation; shared validation and a real rejected-event diagnostic/recovery test address these causes without exclusions or fabricated production state. The comparison found no reachable authority bypass and identifies remote typed-send malformed/unknown/error fixtures, stronger rustdoc and the source contract as deltas to preserve together with private original-connection recovery, unchanged document state, authentic receipt redaction assertions and bounded evidence. Neither private nor remote results establish combined-source acceptance. Current remote native CI `34021674375` is still queued; formatting, numerical coverage and hosted execution remain separate gates. The existing coordination comment records the exact diagnostic and preservation map; no shared-source integration or writer acknowledgement occurred. +A fresh unmodified detached checkout at the earlier remote `8ebcc613` diagnostic cut passed Rust 1.97.1 network/all-targets checking, strict workspace/all-targets/all-features Clippy and all 145 Python contracts. At that cut, the Rust 1.97.1 formatting check fails in five test/support files. The pinned nightly coverage test run completed, but the unchanged numerical verifier failed at lines 13327/13330 and regions 17004/17008; functions 1274/1274 and branches 1434/1434 are exactly covered. Coverage artifact SHA-256 is `f352e3f04bdc3ed1912be7c452c5c426d9caaec7dd1a613b7d3ab9c6486ab69e`. The uncovered regions were the duplicated missing-generation propagation in correlation completion at line 240 and the admission diagnostic at lines 396–397. Independent source review confirmed that the former follows an intent check whose retained constructor always sets the generation; shared validation and a real rejected-event diagnostic/recovery test addressed these causes without exclusions or fabricated production state. The comparison found no reachable authority bypass and identified remote typed-send malformed/unknown/error fixtures, stronger rustdoc and the source contract as deltas to preserve together with private original-connection recovery, unchanged document state, authentic receipt redaction assertions and bounded evidence. Neither private nor remote results establish combined-source acceptance. Earlier native CI `34021674375` was queued at that diagnostic cut; formatting, numerical coverage and hosted execution remain separate gates. The coordination comment recorded the diagnostic and preservation map before shared-source integration or writer acknowledgement occurred. -On #238's earlier `a2600ee8...` head, native CI `34018002926` succeeded. The current pre-publication head `38e5eb44...` has native CI `34021771606` still queued, together with central review/security work. This document's next commit requires new exact-head checks; it cannot inherit those results. Existing central CodeQL dispatch/verdict work remains with `.github#712`. Central Strix #1563 remains unmerged at `eaf9594f7fe8d8e1994349289183d6cbad056579`, reported behind its base: the earlier `13fbb48e...` source repair and owner-reported harness results do not prove consumer recovery. The unrelated #37 local 900-second deadline remains distinct from the #166 completed-report classifier defect and #219/#240 actual gateway/hosted-limit incidents. The active central Noema owner additionally reports source REDs under `.github#1641`; owner reports and comments are not released transport or SDK-compatibility evidence, and no consumer workaround is introduced here. +After the other writer's explicit [release at 52cff969, comment 5558261278](https://github.com/ContextualWisdomLab/OriginWeave/pull/264#issuecomment-5558261278), ordinary content-aware merges preserved both complete contributor histories. Published #264 head `2a9fdc5418b9af10353cdad0f6f6470655bf457d` contains private `bd29f405a6c927b2f7d1c437dccbfb8bcec424f1` and remote `52cff96954c3fec7b8cda5409e4560e970bfcbdf`: both complete lineages are now ancestors. Independent read-only review found no actionable preservation defect. Final-tree Rust 1.97.1 formatting, locked workspace/all-targets/all-features check/test/strict Clippy, strict rustdoc and all 145 Python contracts pass; the workspace run retains all 26 focused socket tests. The unchanged pinned-nightly verifier confirms 1273/13317/16984/1432 functions/lines/regions/branches at exactly 100%, with coverage artifact SHA-256 `f7e71e6fd67723688535053c389b4ff718c4563b403924af462848d3d51b541f`. No test exclusion or quality-gate change was introduced. The normal push and exact remote head were verified, and the integration writer released. Fresh exact-head native CI `34024499232` remains queued; this is local combined-source acceptance, not hosted acceptance, counted approval, protected-main delivery, browser causality or release evidence. The unstable branch-instrumentation warning and all unproven boundaries above remain. + +The existing hourly-task owner attempted a prompt-only coordination/evidence improvement, but the scheduler rejected the update with `too_many_active_automations` at the ten-active-task limit. The owner reports that a subsequent read confirmed the old prompt and update timestamp, cadence, enabled state and notification preferences were unchanged. This is a failed update, not an applied scheduling improvement; no duplicate schedule or unrelated-task pause was created. + +On #238's earlier `a2600ee8...` head, native CI `34018002926` succeeded. The later `38e5eb44...` cut recorded queued CI `34021771606`; subsequent published `7ca86a2f546adf3a0af3fec41d97675115db384d` still had queued native CI `34022635038` before this refresh, together with central review/security work. This document's next commit requires new exact-head checks; it cannot inherit those results. Existing central CodeQL dispatch/verdict work remains with `.github#712`. Central Strix #1563 remains unmerged at `eaf9594f7fe8d8e1994349289183d6cbad056579`, reported behind its base: the earlier `13fbb48e...` source repair and owner-reported harness results do not prove consumer recovery. The unrelated #37 local 900-second deadline remains distinct from the #166 completed-report classifier defect and #219/#240 actual gateway/hosted-limit incidents. The active central Noema owner additionally reports source REDs under `.github#1641`; owner reports and comments are not released transport or SDK-compatibility evidence, and no consumer workaround is introduced here. ### Prior observation cut: 2026-09-05 From b447b6371c520b335f70022c5767ea8f566f66a0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 19:10:04 +0900 Subject: [PATCH 167/250] test(docs): require current registry ownership repair evidence Record missing published ownership regression, final coverage and hosted-run evidence before updating the volatile cut; preserve existing historical contracts. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- tests/test_gap_snapshot_inventory_consistency.py | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 77c0fafa3..a3c437611 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -296,6 +296,14 @@ def test_current_cut_separates_browser_failure_and_unpublished_repair(self) -> N "5558261278", "both complete lineages are now ancestors", "too_many_active_automations", + "10f138f8787d596e8b556fe50c9e4e52bc1295b7", + "b3ffeac9", + "1278/13371/17056/1434", + "9f5b4942d6a040a83f09593a2b81406c44bc9d2b402fa995a95294ce8e9cbb7e", + "34026519860", + "34026519878", + "owner destruction", + "registry-to-transport association", ): with self.subTest(marker=marker): self.assertIn(marker, latest) From 8e6284f5f89965983d025ce302d7c99e2f5c38d5 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 19:14:36 +0900 Subject: [PATCH 168/250] docs: record exact original-registry repair and audit boundaries Bind the published subscription ownership repair to its four real-socket REDs, final local verification, fresh queued hosted runs and remaining transport/browser limits. Preserve all prior contributor evidence and the byte-identical historical tail. Distinguish the last complete GraphQL thread snapshot from the later successful REST audit. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 18 ++++++++++++++++-- 2 files changed, 17 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 6012eae2a..073f930bf 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded the original-browser-state subscription repair and its final verification, keeping pending hosted checks and unfinished browser acceptance separate. - Recorded the published subscription integration and its complete local verification, preserving earlier failures and the separate hosted-check and release requirements. - Recorded failed quality checks on the current subscription revision without transferring passing results from an unpublished repair. - Corrected the browser acceptance status after hosted trials failed, and separated verified unpublished subscription safeguards from another task's ongoing changes. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 9884cbfde..98ea5783d 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -8,9 +8,9 @@ This volatile section is refreshed from live GitHub state and is authoritative o ### Latest verified cut: 2026-09-06 -Observed through (UTC): `2026-09-06T09:29:22Z`. This cut supersedes volatile claims in the prior observation section below; those earlier exact-head measurements remain historical rather than transferable acceptance evidence. +Observed through (UTC): `2026-09-06T10:12:37Z`. This cut supersedes volatile claims in the prior observation section below; those earlier exact-head measurements remain historical rather than transferable acceptance evidence. -The inventory remains **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`; release and tag inventories are both empty. Ready-root source heads other than this document's moving branch are unchanged. GraphQL thread resolution was refreshed for all 125 open PRs together with exact-head check rollups and reviews in five 25-item pages. Follow-up queries completed 12 truncated thread histories and paginated REST reads completed 14 truncated review histories. No thread pagination remains; #147 retains the sole unresolved thread. #166/#220 retain `CHANGES_REQUESTED`, and the other Ready roots retain `REVIEW_REQUIRED`; all twelve are `BLOCKED`. Earlier oversized-query failures and the preceding 375 REST audit remain separate observations, not claims about this later refresh. Active ruleset `18156473` still requires a counted approval and seven central workflows, while the collaborator inventory still contains only the author. #219 has a same-head formal bot approval, but its current GitHub decision remains `REVIEW_REQUIRED`; an uncounted review does not satisfy the gate. None of this authorizes a bypass or substitutes for an eligible counted approval. +The inventory remains **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`; release and tag inventories are both empty. Ready-root source heads other than this document's moving branch are unchanged. GraphQL thread resolution was refreshed for all 125 open PRs together with exact-head check rollups and reviews in five 25-item pages; follow-up GraphQL reads completed 12 truncated thread histories and 14 truncated review histories by `10:00:47 UTC`. In that complete thread snapshot, #147 retains the sole unresolved thread. #166/#220 retain `CHANGES_REQUESTED`, and the other Ready roots retain `REVIEW_REQUIRED`; all twelve are `BLOCKED`. The final GraphQL inventory attempt and a minimal probe both failed with a rate-limit error. Paginated REST inventory and 375 check-run/status/review reads then completed for all 125 exact PR heads with no errors and no new submitted review after the successful GraphQL cut. REST cannot refresh thread-resolution or merge-decision fields, so those remain attached to the earlier successful read, not the later REST timestamp. Active ruleset `18156473` still requires a counted approval and seven central workflows, while the collaborator inventory still contains only the author. #219 has a same-head formal bot approval, but its latest verified GitHub decision remains `REVIEW_REQUIRED`; an uncounted review does not satisfy the gate. None of this authorizes a bypass or substitutes for an eligible counted approval. The restored foundation changes the next executable queue. #195 is Draft at `63997bcf555e2c5c8e91ba287734ffba3837a1b7`, on `6922dd98779e8f8aad132a3b1f563d7ba6e6d070`. Its owner restored product/evidence assets lost by historical whole-tree repair `5c111d0db6c363f9d1786c21cc01c5c7398007bd`; this is a content-recovery boundary, not permission to copy an old tree over later work. Fresh hosted CI `34013251657` fails in repository contracts while exact production coverage and MV3 `34013251651` succeed. The exercised failures compare inherited workflow concurrency and `nightly-2026-08-01` against the protected repository-scoped identity and `nightly-2026-08-18`. #279 owns current-workflow reconstruction; weakening the restored tests does not repair the generation mismatch. #242 remains at `2d0e9f69df9ade21d8e8e3d807c3ff644d83b310`, with a stale pre-recovery #195 base `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its old CI success is not recovered-foundation acceptance. After the owner prerequisite, adopt the verified foundation content-aware and non-destructively before regenerating descendant checks. @@ -36,6 +36,10 @@ The owner has already moved #255 directly onto #252 so the valid #253/#254 delta #150 is Draft at `6ab7fc9166f397f49442243492ae88d6ccad56cf`, ordinarily adopting #148 `0135984f1bc1f68d89d7777f49c4999474105a12` while preserving its combined ordinary-pass teardown waiter. Reused parent regressions first exposed three unsafe browser-launch paths and missing crash-stage diagnostics on the child predecessor. The repair preserves all sandboxed parent launch/cleanup behavior and the child waiter delta. All 253 Python contracts pass on Linux without skips; the corresponding macOS run explicitly skips three Linux pidfd cases. Host/guest tracked manifests match `985411ef6a7d3b812be086b43b6341a96f6b8acace63c0161fa8453aae065bd3`. Complete local Rust gates and 415/3555/4444/476 exact 100% coverage pass. Native CI `34018588292` now succeeds, but MV3 `34018588298` / job `101446865332` fails on that same head. Artifact `9985228944`, digest `sha256:05b6d1cd6092a9e2e18a5003a5a1faeb73b8a8d9b4fd7533f7f24bc938833436`, records all four browser lanes at 0/3, with each browser-crash trial failing at `session_create` and all profiles cleaned. This identifies the failed stage, not the underlying Chrome startup cause. The bounded diagnostic and sandboxed runner/helper follow-up is attached to [#212 comment 5557994915](https://github.com/ContextualWisdomLab/OriginWeave/issues/212#issuecomment-5557994915); no sandbox bypass or unchanged rerun was attempted. #147's ordinary-deadline review thread remains unresolved until this child is actually integrated. +#### Subscription provenance predecessors + +The following paragraphs preserve exact predecessor observations. Their remaining-boundary statements and queued checks describe those revisions, not the newer original-registry repair below. + #264 remains Draft on actual #263 `3f22de94b63da83eaa8b5b1270912b21a3ecd006`. The preceding published head `43d3b5a3a2b5ce4f51a93d1152a0ee82620f4f3e` retained private original-command identity after test-first `73f11de2232060ac7680e188db88ef7609123296` and the two-registry collision regression. Its five admission tests, 144 Python contracts and 1273/13294/16963/1430 exact 100% local coverage are predecessor evidence; native CI `34020055803` is now cancelled, not current acceptance. The inbound-provenance repair was first preserved as unpublished checkpoint `bd29f405a6c927b2f7d1c437dccbfb8bcec424f1`, following real crossed-connection RED `918c4ebe`. It reused the existing connection-owned reader and private connection generation to reject foreign success, protocol-error and navigation-event messages before pending-command or document mutation, then proved original-connection recovery. Seven admission tests, 23 focused tests, all 144 Python contracts, full Rust gates and 1273/13311/16973/1432 exact 100% coverage passed on that private tree. Independent read-only review found no actionable defect; it is not counted approval. Those measurements remain attached to that predecessor, not transferred to the later integration below. @@ -46,6 +50,16 @@ A fresh unmodified detached checkout at the earlier remote `8ebcc613` diagnostic After the other writer's explicit [release at 52cff969, comment 5558261278](https://github.com/ContextualWisdomLab/OriginWeave/pull/264#issuecomment-5558261278), ordinary content-aware merges preserved both complete contributor histories. Published #264 head `2a9fdc5418b9af10353cdad0f6f6470655bf457d` contains private `bd29f405a6c927b2f7d1c437dccbfb8bcec424f1` and remote `52cff96954c3fec7b8cda5409e4560e970bfcbdf`: both complete lineages are now ancestors. Independent read-only review found no actionable preservation defect. Final-tree Rust 1.97.1 formatting, locked workspace/all-targets/all-features check/test/strict Clippy, strict rustdoc and all 145 Python contracts pass; the workspace run retains all 26 focused socket tests. The unchanged pinned-nightly verifier confirms 1273/13317/16984/1432 functions/lines/regions/branches at exactly 100%, with coverage artifact SHA-256 `f7e71e6fd67723688535053c389b4ff718c4563b403924af462848d3d51b541f`. No test exclusion or quality-gate change was introduced. The normal push and exact remote head were verified, and the integration writer released. Fresh exact-head native CI `34024499232` remains queued; this is local combined-source acceptance, not hosted acceptance, counted approval, protected-main delivery, browser causality or release evidence. The unstable branch-instrumentation warning and all unproven boundaries above remain. +#### Current original-registry ownership + +Published #264 is now `10f138f8787d596e8b556fe50c9e4e52bc1295b7`, still Draft on the same #263 base. Four real-socket REDs at `b3ffeac9` proved original-command send, original-receipt admission, original-event admission and document mutation could use a replacement registry with colliding local identifiers. The document-mutation case did not require matching external context text. The repair retains one opaque core-owned allocation witness through the existing command, binding and subscribed observation, rejecting foreign ownership before correlation/I/O, replay insertion or the common document-mutation sink. Origin binding uses that same sink. Original registry moves and cloned witnesses remain valid; owner destruction does not let a replacement inherit the old identity. The socket receipt regression drops the original registry before creating its replacement, and the existing core diagnostic contract exercises the real dropped-owner mismatch. + +The final exact head passes all four new socket regressions, all 145 Python contracts without skips, complete Rust 1.97.1 formatting/check/tests/strict Clippy/rustdoc, compileall, graph and diff checks. Unchanged pinned-nightly coverage is exactly 100% at **1278/13371/17056/1434** functions/lines/regions/branches, artifact SHA-256 `9f5b4942d6a040a83f09593a2b81406c44bc9d2b402fa995a95294ce8e9cbb7e`. Initial `e686b3a0` coverage missed one diagnostic line and three regions in the core unit copy; the genuine error path now exercises that copy. Intermediate `33787617` reached 100% but failed the strict test-lint rule; the final test uses the established error-collection/cardinality assertion style. No exclusion, lint allowance, dependency or production authority relaxation was introduced. Independent read-only review found no actionable authority, lifetime, construction, preservation or documentation finding. Both complete contributor lineages remain ancestors; normal publication, the current PR body and explicit writer release were verified. + +New native CI `34026519860` has Rust `101468348712` and coverage `101468348775` queued; new MV3 `34026519878` / job `101468347302` is also queued. This is not hosted, protected-main or browser acceptance. The repair pins the original registry but does not authenticate the registry-to-transport association. Actual-resend freshness on the same connection, unsubscribe lifetime/transport provenance, action causality and real Chromium acceptance remain unfinished. ADR 0107 stays Proposed, #195/#279 remain prerequisites, and the unstable branch-instrumentation warning remains. No workflow, gate, merge, tag or release mutation occurred. + +#### Scheduling and central-owner follow-up + The existing hourly-task owner attempted a prompt-only coordination/evidence improvement, but the scheduler rejected the update with `too_many_active_automations` at the ten-active-task limit. The owner reports that a subsequent read confirmed the old prompt and update timestamp, cadence, enabled state and notification preferences were unchanged. This is a failed update, not an applied scheduling improvement; no duplicate schedule or unrelated-task pause was created. On #238's earlier `a2600ee8...` head, native CI `34018002926` succeeded. The later `38e5eb44...` cut recorded queued CI `34021771606`; subsequent published `7ca86a2f546adf3a0af3fec41d97675115db384d` still had queued native CI `34022635038` before this refresh, together with central review/security work. This document's next commit requires new exact-head checks; it cannot inherit those results. Existing central CodeQL dispatch/verdict work remains with `.github#712`. Central Strix #1563 remains unmerged at `eaf9594f7fe8d8e1994349289183d6cbad056579`, reported behind its base: the earlier `13fbb48e...` source repair and owner-reported harness results do not prove consumer recovery. The unrelated #37 local 900-second deadline remains distinct from the #166 completed-report classifier defect and #219/#240 actual gateway/hosted-limit incidents. The active central Noema owner additionally reports source REDs under `.github#1641`; owner reports and comments are not released transport or SDK-compatibility evidence, and no consumer workaround is introduced here. From f114a2645b43357c011590cdd0f3fc2bbdc5165c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 20:19:39 +0900 Subject: [PATCH 169/250] test(docs): distinguish dispatch repair from predecessor check success Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- tests/test_gap_snapshot_inventory_consistency.py | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index a3c437611..cce1e43d3 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -304,6 +304,14 @@ def test_current_cut_separates_browser_failure_and_unpublished_repair(self) -> N "34026519878", "owner destruction", "registry-to-transport association", + "805051527cf95e14ba126c9dd3159db86d190224", + "1279/13409/17087/1436", + "64a62b1e03ee3ed3d62654a3227495e82b7ff93357038ae146d8584c581ac060", + "34029687813", + "34029687816", + "terminal-success predecessor evidence", + "actual Edge visual inspection", + "GraphQL access recovered", ): with self.subTest(marker=marker): self.assertIn(marker, latest) From 31a7d4cb0b89a0ded0a09a4351326f5b54733ae3 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 20:21:26 +0900 Subject: [PATCH 170/250] docs: refresh dispatch freshness and exact hosted evidence Preserve predecessor failures and the dated historical suffix; record new local source proof and actual Edge visual inspection without treating queued checks as product acceptance. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 18 +++++++++++++----- 2 files changed, 14 insertions(+), 5 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 073f930bf..8685b21af 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded the repeated-response safeguard, its complete local verification and visual review, separating successful predecessor checks from the new revision's pending checks. - Recorded the original-browser-state subscription repair and its final verification, keeping pending hosted checks and unfinished browser acceptance separate. - Recorded the published subscription integration and its complete local verification, preserving earlier failures and the separate hosted-check and release requirements. - Recorded failed quality checks on the current subscription revision without transferring passing results from an unpublished repair. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 98ea5783d..d1624d540 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -8,9 +8,9 @@ This volatile section is refreshed from live GitHub state and is authoritative o ### Latest verified cut: 2026-09-06 -Observed through (UTC): `2026-09-06T10:12:37Z`. This cut supersedes volatile claims in the prior observation section below; those earlier exact-head measurements remain historical rather than transferable acceptance evidence. +Observed through (UTC): `2026-09-06T11:20:05Z`. This cut supersedes volatile claims in the prior observation section below; those earlier exact-head measurements remain historical rather than transferable acceptance evidence. -The inventory remains **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`; release and tag inventories are both empty. Ready-root source heads other than this document's moving branch are unchanged. GraphQL thread resolution was refreshed for all 125 open PRs together with exact-head check rollups and reviews in five 25-item pages; follow-up GraphQL reads completed 12 truncated thread histories and 14 truncated review histories by `10:00:47 UTC`. In that complete thread snapshot, #147 retains the sole unresolved thread. #166/#220 retain `CHANGES_REQUESTED`, and the other Ready roots retain `REVIEW_REQUIRED`; all twelve are `BLOCKED`. The final GraphQL inventory attempt and a minimal probe both failed with a rate-limit error. Paginated REST inventory and 375 check-run/status/review reads then completed for all 125 exact PR heads with no errors and no new submitted review after the successful GraphQL cut. REST cannot refresh thread-resolution or merge-decision fields, so those remain attached to the earlier successful read, not the later REST timestamp. Active ruleset `18156473` still requires a counted approval and seven central workflows, while the collaborator inventory still contains only the author. #219 has a same-head formal bot approval, but its latest verified GitHub decision remains `REVIEW_REQUIRED`; an uncounted review does not satisfy the gate. None of this authorizes a bypass or substitutes for an eligible counted approval. +The inventory remains **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`; release and tag inventories are both empty. Ready-root source heads other than this document's moving branch are unchanged. GraphQL access recovered after the earlier rate-limit failure. A complete five-page refresh of all 125 exact heads, bases, check rollups, formal reviews and review threads finished at `11:19:04 UTC`; all nested histories fit their 100-item pages, with no remaining pagination flags. #147 retains the sole unresolved thread `PRRT_kwDOTulPlM6coZwc`. #166/#220 retain `CHANGES_REQUESTED`, and the other Ready roots retain `REVIEW_REQUIRED`; all twelve are `BLOCKED`. The earlier successful GraphQL cut at `10:00:47 UTC`, subsequent failed inventory/minimal probe and complete 375-read REST fallback at `10:12:37 UTC` remain historical diagnostics, not the current freshness boundary. Active ruleset `18156473` still requires a counted approval and seven central workflows, while the collaborator inventory still contains only the author. #219 has a same-head formal bot approval, but its freshly verified GitHub decision remains `REVIEW_REQUIRED`; an uncounted review does not satisfy the gate. None of this authorizes a bypass or substitutes for an eligible counted approval. The restored foundation changes the next executable queue. #195 is Draft at `63997bcf555e2c5c8e91ba287734ffba3837a1b7`, on `6922dd98779e8f8aad132a3b1f563d7ba6e6d070`. Its owner restored product/evidence assets lost by historical whole-tree repair `5c111d0db6c363f9d1786c21cc01c5c7398007bd`; this is a content-recovery boundary, not permission to copy an old tree over later work. Fresh hosted CI `34013251657` fails in repository contracts while exact production coverage and MV3 `34013251651` succeed. The exercised failures compare inherited workflow concurrency and `nightly-2026-08-01` against the protected repository-scoped identity and `nightly-2026-08-18`. #279 owns current-workflow reconstruction; weakening the restored tests does not repair the generation mismatch. #242 remains at `2d0e9f69df9ade21d8e8e3d807c3ff644d83b310`, with a stale pre-recovery #195 base `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its old CI success is not recovered-foundation acceptance. After the owner prerequisite, adopt the verified foundation content-aware and non-destructively before regenerating descendant checks. @@ -50,13 +50,21 @@ A fresh unmodified detached checkout at the earlier remote `8ebcc613` diagnostic After the other writer's explicit [release at 52cff969, comment 5558261278](https://github.com/ContextualWisdomLab/OriginWeave/pull/264#issuecomment-5558261278), ordinary content-aware merges preserved both complete contributor histories. Published #264 head `2a9fdc5418b9af10353cdad0f6f6470655bf457d` contains private `bd29f405a6c927b2f7d1c437dccbfb8bcec424f1` and remote `52cff96954c3fec7b8cda5409e4560e970bfcbdf`: both complete lineages are now ancestors. Independent read-only review found no actionable preservation defect. Final-tree Rust 1.97.1 formatting, locked workspace/all-targets/all-features check/test/strict Clippy, strict rustdoc and all 145 Python contracts pass; the workspace run retains all 26 focused socket tests. The unchanged pinned-nightly verifier confirms 1273/13317/16984/1432 functions/lines/regions/branches at exactly 100%, with coverage artifact SHA-256 `f7e71e6fd67723688535053c389b4ff718c4563b403924af462848d3d51b541f`. No test exclusion or quality-gate change was introduced. The normal push and exact remote head were verified, and the integration writer released. Fresh exact-head native CI `34024499232` remains queued; this is local combined-source acceptance, not hosted acceptance, counted approval, protected-main delivery, browser causality or release evidence. The unstable branch-instrumentation warning and all unproven boundaries above remain. -#### Current original-registry ownership +#### Original-registry ownership predecessor -Published #264 is now `10f138f8787d596e8b556fe50c9e4e52bc1295b7`, still Draft on the same #263 base. Four real-socket REDs at `b3ffeac9` proved original-command send, original-receipt admission, original-event admission and document mutation could use a replacement registry with colliding local identifiers. The document-mutation case did not require matching external context text. The repair retains one opaque core-owned allocation witness through the existing command, binding and subscribed observation, rejecting foreign ownership before correlation/I/O, replay insertion or the common document-mutation sink. Origin binding uses that same sink. Original registry moves and cloned witnesses remain valid; owner destruction does not let a replacement inherit the old identity. The socket receipt regression drops the original registry before creating its replacement, and the existing core diagnostic contract exercises the real dropped-owner mismatch. +The preceding published #264 head is `10f138f8787d596e8b556fe50c9e4e52bc1295b7`, still Draft on the same #263 base at that cut. Four real-socket REDs at `b3ffeac9` proved original-command send, original-receipt admission, original-event admission and document mutation could use a replacement registry with colliding local identifiers. The document-mutation case did not require matching external context text. The repair retains one opaque core-owned allocation witness through the existing command, binding and subscribed observation, rejecting foreign ownership before correlation/I/O, replay insertion or the common document-mutation sink. Origin binding uses that same sink. Original registry moves and cloned witnesses remain valid; owner destruction does not let a replacement inherit the old identity. The socket receipt regression drops the original registry before creating its replacement, and the existing core diagnostic contract exercises the real dropped-owner mismatch. The final exact head passes all four new socket regressions, all 145 Python contracts without skips, complete Rust 1.97.1 formatting/check/tests/strict Clippy/rustdoc, compileall, graph and diff checks. Unchanged pinned-nightly coverage is exactly 100% at **1278/13371/17056/1434** functions/lines/regions/branches, artifact SHA-256 `9f5b4942d6a040a83f09593a2b81406c44bc9d2b402fa995a95294ce8e9cbb7e`. Initial `e686b3a0` coverage missed one diagnostic line and three regions in the core unit copy; the genuine error path now exercises that copy. Intermediate `33787617` reached 100% but failed the strict test-lint rule; the final test uses the established error-collection/cardinality assertion style. No exclusion, lint allowance, dependency or production authority relaxation was introduced. Independent read-only review found no actionable authority, lifetime, construction, preservation or documentation finding. Both complete contributor lineages remain ancestors; normal publication, the current PR body and explicit writer release were verified. -New native CI `34026519860` has Rust `101468348712` and coverage `101468348775` queued; new MV3 `34026519878` / job `101468347302` is also queued. This is not hosted, protected-main or browser acceptance. The repair pins the original registry but does not authenticate the registry-to-transport association. Actual-resend freshness on the same connection, unsubscribe lifetime/transport provenance, action causality and real Chromium acceptance remain unfinished. ADR 0107 stays Proposed, #195/#279 remain prerequisites, and the unstable branch-instrumentation warning remains. No workflow, gate, merge, tag or release mutation occurred. +Native CI `34026519860`, Rust `101468348712` and coverage `101468348775`, and real MV3 `34026519878` / job `101468347302` now all completed successfully on `10f138f8`. These are terminal-success predecessor evidence, correcting the earlier queued observation without validating a later head. The repair pins the original registry but does not authenticate the registry-to-transport association. Actual-resend freshness was still unfinished on this predecessor; the next section records its separate repair. Unsubscribe lifetime/transport provenance, action causality and end-to-end Chromium product acceptance remain unfinished. ADR 0107 stays Proposed, #195/#279 remain prerequisites, and the unstable branch-instrumentation warning remains. No workflow, gate, merge, tag or release mutation occurred. + +#### Current command-response freshness + +Published #264 is now `805051527cf95e14ba126c9dd3159db86d190224`, Draft on unchanged #263 `3f22de94b63da83eaa8b5b1270912b21a3ecd006`. Actual success-first RED `92fd0b07` and error-first RED `15aea15e` each exposed four repeated-send lifecycles: completed, retired, replacement correlation and unread buffered response. Three additional actual-wire REDs exposed raw/typed mixing and repeated identifiers; a compile-fail contract exposed the pre-upgrade socket alias. The shared established owner now enforces strictly increasing typed identifiers and exclusive raw-text/typed mode across all five typed senders. Zero is valid first, out-of-order replies for distinct outstanding commands remain valid, and reader reconstruction/Pong cannot reset history. The consuming socket handoff remains; its nonconsuming alias is removed. This is a stricter local dispatch policy, not a W3C requirement or authenticated browser-session association. + +All 22 focused admission/frame tests and the added real public opening-deadline test pass within the complete Rust 1.97.1 workspace verification. Formatting, locked all-target/all-feature check, strict Clippy, warning-denying rustdoc, all workspace tests, all 145 Python contracts, compileall, CodeGraph and diff checks pass. Unchanged pinned-nightly coverage is exactly **1279/13409/17087/1436** functions/lines/regions/branches, artifact SHA-256 `64a62b1e03ee3ed3d62654a3227495e82b7ff93357038ae146d8584c581ac060`. Earlier buffered-fixture BrokenPipe/reset failures and `e6c02cf`'s 17086/17087 region result remain recorded. The latter combined complementary ordinary-library/unit-test gaps rather than unioning source regions; the real public deadline case covers the ordinary copy, retaining the private real revoked-socket test without production or verifier changes. That one-nanosecond case has local passing evidence; portability beyond executed targets remains unproven. Independent read-only review found no actionable finding and does not count as GitHub approval. + +Fresh exact-head CI `34029687813`, Rust `101476824185` and coverage `101476824305`, and MV3 `34029687816` / `101476824298` are queued. Post-publication actual Edge visual inspection covered the new PR body and Checks page: exact head/base, Draft state and three queued checks matched the API; desktop screenshots showed readable wrapping with no observed clipping or overlap. GitHub presentation evidence is not OriginWeave product-browser acceptance. Both contributor histories remain ancestors, ordinary publication was verified, and the #264 writer was explicitly released before this documentation-only slice. Registry-to-transport authentication, unsubscribe lifetime/transport provenance, action causality, real browser acceptance, #195/#279 integration, protected delivery and release gates remain open. #### Scheduling and central-owner follow-up From 81e334aff063290bde3298671cfd20e77c7c1fff Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 20:21:56 +0900 Subject: [PATCH 171/250] docs: retain the full-inventory freshness contract Record recovered all-PR thread reads in the established contract wording and separate successful predecessor documentation CI from this pending revision. Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index d1624d540..9a08651f0 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -10,7 +10,7 @@ This volatile section is refreshed from live GitHub state and is authoritative o Observed through (UTC): `2026-09-06T11:20:05Z`. This cut supersedes volatile claims in the prior observation section below; those earlier exact-head measurements remain historical rather than transferable acceptance evidence. -The inventory remains **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`; release and tag inventories are both empty. Ready-root source heads other than this document's moving branch are unchanged. GraphQL access recovered after the earlier rate-limit failure. A complete five-page refresh of all 125 exact heads, bases, check rollups, formal reviews and review threads finished at `11:19:04 UTC`; all nested histories fit their 100-item pages, with no remaining pagination flags. #147 retains the sole unresolved thread `PRRT_kwDOTulPlM6coZwc`. #166/#220 retain `CHANGES_REQUESTED`, and the other Ready roots retain `REVIEW_REQUIRED`; all twelve are `BLOCKED`. The earlier successful GraphQL cut at `10:00:47 UTC`, subsequent failed inventory/minimal probe and complete 375-read REST fallback at `10:12:37 UTC` remain historical diagnostics, not the current freshness boundary. Active ruleset `18156473` still requires a counted approval and seven central workflows, while the collaborator inventory still contains only the author. #219 has a same-head formal bot approval, but its freshly verified GitHub decision remains `REVIEW_REQUIRED`; an uncounted review does not satisfy the gate. None of this authorizes a bypass or substitutes for an eligible counted approval. +The inventory remains **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`; release and tag inventories are both empty. Ready-root source heads other than this document's moving branch are unchanged. GraphQL access recovered after the earlier rate-limit failure. GraphQL thread resolution was refreshed for all 125 open PRs alongside exact heads, bases, check rollups and formal reviews in five pages, finishing at `11:19:04 UTC`; all nested histories fit their 100-item pages, with no remaining pagination flags. #147 retains the sole unresolved thread `PRRT_kwDOTulPlM6coZwc`. #166/#220 retain `CHANGES_REQUESTED`, and the other Ready roots retain `REVIEW_REQUIRED`; all twelve are `BLOCKED`. The earlier successful GraphQL cut at `10:00:47 UTC`, subsequent failed inventory/minimal probe and complete 375-read REST fallback at `10:12:37 UTC` remain historical diagnostics, not the current freshness boundary. Active ruleset `18156473` still requires a counted approval and seven central workflows, while the collaborator inventory still contains only the author. #219 has a same-head formal bot approval, but its freshly verified GitHub decision remains `REVIEW_REQUIRED`; an uncounted review does not satisfy the gate. None of this authorizes a bypass or substitutes for an eligible counted approval. The restored foundation changes the next executable queue. #195 is Draft at `63997bcf555e2c5c8e91ba287734ffba3837a1b7`, on `6922dd98779e8f8aad132a3b1f563d7ba6e6d070`. Its owner restored product/evidence assets lost by historical whole-tree repair `5c111d0db6c363f9d1786c21cc01c5c7398007bd`; this is a content-recovery boundary, not permission to copy an old tree over later work. Fresh hosted CI `34013251657` fails in repository contracts while exact production coverage and MV3 `34013251651` succeed. The exercised failures compare inherited workflow concurrency and `nightly-2026-08-01` against the protected repository-scoped identity and `nightly-2026-08-18`. #279 owns current-workflow reconstruction; weakening the restored tests does not repair the generation mismatch. #242 remains at `2d0e9f69df9ade21d8e8e3d807c3ff644d83b310`, with a stale pre-recovery #195 base `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its old CI success is not recovered-foundation acceptance. After the owner prerequisite, adopt the verified foundation content-aware and non-destructively before regenerating descendant checks. @@ -70,7 +70,7 @@ Fresh exact-head CI `34029687813`, Rust `101476824185` and coverage `10147682430 The existing hourly-task owner attempted a prompt-only coordination/evidence improvement, but the scheduler rejected the update with `too_many_active_automations` at the ten-active-task limit. The owner reports that a subsequent read confirmed the old prompt and update timestamp, cadence, enabled state and notification preferences were unchanged. This is a failed update, not an applied scheduling improvement; no duplicate schedule or unrelated-task pause was created. -On #238's earlier `a2600ee8...` head, native CI `34018002926` succeeded. The later `38e5eb44...` cut recorded queued CI `34021771606`; subsequent published `7ca86a2f546adf3a0af3fec41d97675115db384d` still had queued native CI `34022635038` before this refresh, together with central review/security work. This document's next commit requires new exact-head checks; it cannot inherit those results. Existing central CodeQL dispatch/verdict work remains with `.github#712`. Central Strix #1563 remains unmerged at `eaf9594f7fe8d8e1994349289183d6cbad056579`, reported behind its base: the earlier `13fbb48e...` source repair and owner-reported harness results do not prove consumer recovery. The unrelated #37 local 900-second deadline remains distinct from the #166 completed-report classifier defect and #219/#240 actual gateway/hosted-limit incidents. The active central Noema owner additionally reports source REDs under `.github#1641`; owner reports and comments are not released transport or SDK-compatibility evidence, and no consumer workaround is introduced here. +On #238's earlier `a2600ee8...` head, native CI `34018002926` succeeded. The later `38e5eb44...` cut recorded queued CI `34021771606`; subsequent published `7ca86a2f546adf3a0af3fec41d97675115db384d` still had queued native CI `34022635038` before this refresh, together with central review/security work. At the now-predecessor `8e6284f5f89965983d025ce302d7c99e2f5c38d5`, native CI `34027019757`, Rust `101469694749` and coverage `101469694911` have completed successfully; nine central security/review jobs remain queued. This document's next commit requires new exact-head checks; it cannot inherit those results. Existing central CodeQL dispatch/verdict work remains with `.github#712`. Central Strix #1563 remains unmerged at `eaf9594f7fe8d8e1994349289183d6cbad056579`, reported behind its base: the earlier `13fbb48e...` source repair and owner-reported harness results do not prove consumer recovery. The unrelated #37 local 900-second deadline remains distinct from the #166 completed-report classifier defect and #219/#240 actual gateway/hosted-limit incidents. The active central Noema owner additionally reports source REDs under `.github#1641`; owner reports and comments are not released transport or SDK-compatibility evidence, and no consumer workaround is introduced here. ### Prior observation cut: 2026-09-05 From cbd6c40c9cbfeeeb3e3e808d18e6ac84d3db0758 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 20:50:51 +0900 Subject: [PATCH 172/250] test(docs): require current subscription teardown evidence Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- tests/test_gap_snapshot_inventory_consistency.py | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index cce1e43d3..560563fdf 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -312,6 +312,13 @@ def test_current_cut_separates_browser_failure_and_unpublished_repair(self) -> N "terminal-success predecessor evidence", "actual Edge visual inspection", "GraphQL access recovered", + "7fb93e77b800f27187a5c02333298cc31a025bd6", + "1279/13421/17106/1438", + "277c5bc0a17f16966a8eb388d54e4e172be36356d7dead5bbead9ed53ad8cff6", + "34031281825", + "34031281812", + "new-head visual inspection remains incomplete", + "Mac is locked", ): with self.subTest(marker=marker): self.assertIn(marker, latest) From 88447b7d43e4a87b48fb8fde33f93b2e3ce8cbc5 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 20:52:01 +0900 Subject: [PATCH 173/250] docs: record subscription teardown proof and visual inspection gap Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 48 +++++++++++++++++++++++--- 2 files changed, 45 insertions(+), 4 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 8685b21af..757b3a92a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded subscription-shutdown safeguards and their complete local verification, keeping queued hosted checks and the locked-screen visual-inspection gap explicit. - Recorded the repeated-response safeguard, its complete local verification and visual review, separating successful predecessor checks from the new revision's pending checks. - Recorded the original-browser-state subscription repair and its final verification, keeping pending hosted checks and unfinished browser acceptance separate. - Recorded the published subscription integration and its complete local verification, preserving earlier failures and the separate hosted-check and release requirements. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 9a08651f0..672b0f355 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -8,9 +8,9 @@ This volatile section is refreshed from live GitHub state and is authoritative o ### Latest verified cut: 2026-09-06 -Observed through (UTC): `2026-09-06T11:20:05Z`. This cut supersedes volatile claims in the prior observation section below; those earlier exact-head measurements remain historical rather than transferable acceptance evidence. +Observed through (UTC): `2026-09-06T11:49:46Z`. This cut supersedes volatile claims in the prior observation section below; those earlier exact-head measurements remain historical rather than transferable acceptance evidence. The complete queue read finished at `11:47:46 UTC`; #264 publication and writer release were verified afterward at the stated head. -The inventory remains **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`; release and tag inventories are both empty. Ready-root source heads other than this document's moving branch are unchanged. GraphQL access recovered after the earlier rate-limit failure. GraphQL thread resolution was refreshed for all 125 open PRs alongside exact heads, bases, check rollups and formal reviews in five pages, finishing at `11:19:04 UTC`; all nested histories fit their 100-item pages, with no remaining pagination flags. #147 retains the sole unresolved thread `PRRT_kwDOTulPlM6coZwc`. #166/#220 retain `CHANGES_REQUESTED`, and the other Ready roots retain `REVIEW_REQUIRED`; all twelve are `BLOCKED`. The earlier successful GraphQL cut at `10:00:47 UTC`, subsequent failed inventory/minimal probe and complete 375-read REST fallback at `10:12:37 UTC` remain historical diagnostics, not the current freshness boundary. Active ruleset `18156473` still requires a counted approval and seven central workflows, while the collaborator inventory still contains only the author. #219 has a same-head formal bot approval, but its freshly verified GitHub decision remains `REVIEW_REQUIRED`; an uncounted review does not satisfy the gate. None of this authorizes a bypass or substitutes for an eligible counted approval. +The inventory remains **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`; release and tag inventories are both empty. Ready-root source heads other than this document's moving branch are unchanged. GraphQL access recovered after the earlier rate-limit failure. GraphQL thread resolution was refreshed for all 125 open PRs alongside exact heads, bases, check rollups and formal reviews in five pages, finishing at `11:47:46 UTC`; all nested histories fit their 100-item pages, with no remaining pagination flags. #147 retains the sole unresolved thread `PRRT_kwDOTulPlM6coZwc`. #166/#220 retain `CHANGES_REQUESTED`, and the other Ready roots retain `REVIEW_REQUIRED`; all twelve are `BLOCKED`. The earlier successful GraphQL cut at `10:00:47 UTC`, subsequent failed inventory/minimal probe and complete 375-read REST fallback at `10:12:37 UTC` remain historical diagnostics, not the current freshness boundary. Active ruleset `18156473` still requires a counted approval and seven central workflows, while the collaborator inventory still contains only the author. #219 has a same-head formal bot approval, but its freshly verified GitHub decision remains `REVIEW_REQUIRED`; an uncounted review does not satisfy the gate. None of this authorizes a bypass or substitutes for an eligible counted approval. The restored foundation changes the next executable queue. #195 is Draft at `63997bcf555e2c5c8e91ba287734ffba3837a1b7`, on `6922dd98779e8f8aad132a3b1f563d7ba6e6d070`. Its owner restored product/evidence assets lost by historical whole-tree repair `5c111d0db6c363f9d1786c21cc01c5c7398007bd`; this is a content-recovery boundary, not permission to copy an old tree over later work. Fresh hosted CI `34013251657` fails in repository contracts while exact production coverage and MV3 `34013251651` succeed. The exercised failures compare inherited workflow concurrency and `nightly-2026-08-01` against the protected repository-scoped identity and `nightly-2026-08-18`. #279 owns current-workflow reconstruction; weakening the restored tests does not repair the generation mismatch. #242 remains at `2d0e9f69df9ade21d8e8e3d807c3ff644d83b310`, with a stale pre-recovery #195 base `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its old CI success is not recovered-foundation acceptance. After the owner prerequisite, adopt the verified foundation content-aware and non-destructively before regenerating descendant checks. @@ -58,16 +58,56 @@ The final exact head passes all four new socket regressions, all 145 Python cont Native CI `34026519860`, Rust `101468348712` and coverage `101468348775`, and real MV3 `34026519878` / job `101468347302` now all completed successfully on `10f138f8`. These are terminal-success predecessor evidence, correcting the earlier queued observation without validating a later head. The repair pins the original registry but does not authenticate the registry-to-transport association. Actual-resend freshness was still unfinished on this predecessor; the next section records its separate repair. Unsubscribe lifetime/transport provenance, action causality and end-to-end Chromium product acceptance remain unfinished. ADR 0107 stays Proposed, #195/#279 remain prerequisites, and the unstable branch-instrumentation warning remains. No workflow, gate, merge, tag or release mutation occurred. -#### Current command-response freshness +#### Command-response freshness predecessor -Published #264 is now `805051527cf95e14ba126c9dd3159db86d190224`, Draft on unchanged #263 `3f22de94b63da83eaa8b5b1270912b21a3ecd006`. Actual success-first RED `92fd0b07` and error-first RED `15aea15e` each exposed four repeated-send lifecycles: completed, retired, replacement correlation and unread buffered response. Three additional actual-wire REDs exposed raw/typed mixing and repeated identifiers; a compile-fail contract exposed the pre-upgrade socket alias. The shared established owner now enforces strictly increasing typed identifiers and exclusive raw-text/typed mode across all five typed senders. Zero is valid first, out-of-order replies for distinct outstanding commands remain valid, and reader reconstruction/Pong cannot reset history. The consuming socket handoff remains; its nonconsuming alias is removed. This is a stricter local dispatch policy, not a W3C requirement or authenticated browser-session association. +The preceding published #264 head `805051527cf95e14ba126c9dd3159db86d190224` was Draft on unchanged #263 `3f22de94b63da83eaa8b5b1270912b21a3ecd006`. Actual success-first RED `92fd0b07` and error-first RED `15aea15e` each exposed four repeated-send lifecycles: completed, retired, replacement correlation and unread buffered response. Three additional actual-wire REDs exposed raw/typed mixing and repeated identifiers; a compile-fail contract exposed the pre-upgrade socket alias. The shared established owner enforces strictly increasing typed identifiers and exclusive raw-text/typed mode across all five typed senders. Zero is valid first, out-of-order replies for distinct outstanding commands remain valid, and reader reconstruction/Pong cannot reset history. The consuming socket handoff remains; its nonconsuming alias is removed. This is a stricter local dispatch policy, not a W3C requirement or authenticated browser-session association. The next section records its later teardown refinement; this predecessor's unfinished boundaries and screenshots are not current-head acceptance. All 22 focused admission/frame tests and the added real public opening-deadline test pass within the complete Rust 1.97.1 workspace verification. Formatting, locked all-target/all-feature check, strict Clippy, warning-denying rustdoc, all workspace tests, all 145 Python contracts, compileall, CodeGraph and diff checks pass. Unchanged pinned-nightly coverage is exactly **1279/13409/17087/1436** functions/lines/regions/branches, artifact SHA-256 `64a62b1e03ee3ed3d62654a3227495e82b7ff93357038ae146d8584c581ac060`. Earlier buffered-fixture BrokenPipe/reset failures and `e6c02cf`'s 17086/17087 region result remain recorded. The latter combined complementary ordinary-library/unit-test gaps rather than unioning source regions; the real public deadline case covers the ordinary copy, retaining the private real revoked-socket test without production or verifier changes. That one-nanosecond case has local passing evidence; portability beyond executed targets remains unproven. Independent read-only review found no actionable finding and does not count as GitHub approval. Fresh exact-head CI `34029687813`, Rust `101476824185` and coverage `101476824305`, and MV3 `34029687816` / `101476824298` are queued. Post-publication actual Edge visual inspection covered the new PR body and Checks page: exact head/base, Draft state and three queued checks matched the API; desktop screenshots showed readable wrapping with no observed clipping or overlap. GitHub presentation evidence is not OriginWeave product-browser acceptance. Both contributor histories remain ancestors, ordinary publication was verified, and the #264 writer was explicitly released before this documentation-only slice. Registry-to-transport authentication, unsubscribe lifetime/transport provenance, action causality, real browser acceptance, #195/#279 integration, protected delivery and release gates remain open. +#### Current subscription teardown ownership and provenance + +Published #264 is now `7fb93e77b800f27187a5c02333298cc31a025bd6`, Draft on unchanged #263 +`3f22de94b63da83eaa8b5b1270912b21a3ecd006`. Lifetime RED `2c45cea8` reproduced event admission +after borrowed teardown construction. Transport RED `ce6f6fd4` reproduced 91 actual masked bytes +on a foreign connection and foreign success/error consuming the original pending command. Genuine +original replies then failed as no longer outstanding; real servers were joined before assertions. + +The repair consumes the existing non-cloneable subscription receipt and retains its original +connection identity through teardown dispatch and acknowledgment. It reuses connection-aware +correlation and the existing connection-bound reader; no revocation registry, dependency, workflow +or quality-gate change is added. Receipt reuse is now rejected by the compiler with `E0382`, not +merely by a fixture setup error. Construction failure also ends local admission availability. +Previously admitted observations are not retroactively revoked, and acknowledgment does not prove +event drainage or browser cleanup. Proposed ADR 0107 records these costs and rejected alternatives. + +All three transport regressions, eight preserved failure cases, fourteen admission tests and the +escaped-identifier round trip pass. Full Rust 1.97.1 workspace/all-feature formatting, locked check, +strict Clippy, warning-denying rustdoc and tests pass, including three network doctests. All 145 +Python contracts, compileall, CodeGraph and diff checks pass. Unchanged pinned coverage is exactly +**1279/13421/17106/1438** functions/lines/regions/branches; artifact SHA-256 +`277c5bc0a17f16966a8eb388d54e4e172be36356d7dead5bbead9ed53ad8cff6`. The unstable branch warning +remains. Independent read-only source review found no actionable issue, not counted GitHub approval. + +New exact-head CI `34031281825`, Rust `101481131938` and coverage `101481131907`, and MV3 +`34031281812` / `101481131930` are queued, not GREEN. Both contributor histories are preserved, +normal publication was verified, and source writer `5557964460` was explicitly released before +this documentation writer began. The required new-head visual inspection remains incomplete: +actual browser control reports that the Mac is locked and automatic unlock is unavailable. Manual +unlock was requested; neither the previous #264 screenshots nor the previous #238 Preview validates +these new heads. Registry-to-browser authentication, action causality, real Chromium acceptance, +#195/#279 integration, protected delivery and release gates remain open. + +At this read, #238 predecessor `81e334aff063290bde3298671cfd20e77c7c1fff` still has queued native +CI `34030165220` plus central review/security work. This documentation commit needs its own checks; +neither its earlier 172 local Python passes nor #264's source coverage transfers to the new head. + #### Scheduling and central-owner follow-up +This section retains owner-reported scheduling and central-repository evidence. Those reports are +not refreshed owner-source or released-consumer acceptance in this bounded documentation slice. + The existing hourly-task owner attempted a prompt-only coordination/evidence improvement, but the scheduler rejected the update with `too_many_active_automations` at the ten-active-task limit. The owner reports that a subsequent read confirmed the old prompt and update timestamp, cadence, enabled state and notification preferences were unchanged. This is a failed update, not an applied scheduling improvement; no duplicate schedule or unrelated-task pause was created. On #238's earlier `a2600ee8...` head, native CI `34018002926` succeeded. The later `38e5eb44...` cut recorded queued CI `34021771606`; subsequent published `7ca86a2f546adf3a0af3fec41d97675115db384d` still had queued native CI `34022635038` before this refresh, together with central review/security work. At the now-predecessor `8e6284f5f89965983d025ce302d7c99e2f5c38d5`, native CI `34027019757`, Rust `101469694749` and coverage `101469694911` have completed successfully; nine central security/review jobs remain queued. This document's next commit requires new exact-head checks; it cannot inherit those results. Existing central CodeQL dispatch/verdict work remains with `.github#712`. Central Strix #1563 remains unmerged at `eaf9594f7fe8d8e1994349289183d6cbad056579`, reported behind its base: the earlier `13fbb48e...` source repair and owner-reported harness results do not prove consumer recovery. The unrelated #37 local 900-second deadline remains distinct from the #166 completed-report classifier defect and #219/#240 actual gateway/hosted-limit incidents. The active central Noema owner additionally reports source REDs under `.github#1641`; owner reports and comments are not released transport or SDK-compatibility evidence, and no consumer workaround is introduced here. From 5d8ffb11b4e38381c5784c02c5d371d81db71b90 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 21:23:17 +0900 Subject: [PATCH 174/250] test(docs): require pointer integration evidence boundaries Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- ...test_gap_snapshot_inventory_consistency.py | 22 +++++++++++++++++++ 1 file changed, 22 insertions(+) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 560563fdf..94eaf5df6 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -327,6 +327,28 @@ def test_current_cut_separates_browser_failure_and_unpublished_repair(self) -> N latest, ) + def test_pointer_integration_cut_separates_parent_and_hosted_acceptance(self) -> None: + """Published pointer proof must retain the newer parent and visual evidence gaps.""" + latest = self.baseline.split("## Current live delivery state", 1)[1].split( + "### Prior observation cut: 2026-09-05", 1 + )[0] + for marker in ( + "35555d0f8491d4ee95c2e61d1a2aaa2c02a0635c", + "3f9cdc1a", + "1293/13567/17273/1440", + "b1374f65538fb6557b4e5d877aa067e183202ed1f56c75be047b3ff2dfdc92a0", + "34032661775", + "34032661781", + "b4702cd503fa3f721e0d1f44b355563753dac0a2", + "5559076006", + "not latest-parent acceptance", + "four silently deleted parent postcondition tests", + ): + with self.subTest(marker=marker): + self.assertIn(marker, latest) + self.assertIn("new-head visual inspection remains incomplete", latest) + self.assertIn("Mac is locked", latest) + def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: """The dated 2026-08-29 snapshot must keep its exact historical inventory.""" current = self.baseline.split("### Open pull requests", 1)[1].split( From f29244ef20e32c2afee417a8d7725ca32c1e6d54 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 21:29:07 +0900 Subject: [PATCH 175/250] test(docs): require current delivery checkpoint evidence --- ...t_delivery_checkpoint_20260906_contract.py | 56 +++++++++++++++++++ 1 file changed, 56 insertions(+) create mode 100644 tests/test_current_delivery_checkpoint_20260906_contract.py diff --git a/tests/test_current_delivery_checkpoint_20260906_contract.py b/tests/test_current_delivery_checkpoint_20260906_contract.py new file mode 100644 index 000000000..a4ae623b7 --- /dev/null +++ b/tests/test_current_delivery_checkpoint_20260906_contract.py @@ -0,0 +1,56 @@ +"""Contracts for the 2026-09-06 volatile delivery checkpoint.""" + +from pathlib import Path +import unittest + + +ROOT = Path(__file__).resolve().parents[1] +CHECKPOINT = ROOT / "docs" / "evidence" / "2026-09-06-delivery-checkpoint.md" + + +class CurrentDeliveryCheckpointContractTests(unittest.TestCase): + """Keep source, dependency, hosted and visual evidence boundaries explicit.""" + + @classmethod + def setUpClass(cls) -> None: + cls.checkpoint = CHECKPOINT.read_text(encoding="utf-8") + + def test_current_source_heads_and_parent_boundary_are_exact(self) -> None: + for marker in ( + "`b4702cd503fa3f721e0d1f44b355563753dac0a2`", + "`35555d0f8491d4ee95c2e61d1a2aaa2c02a0635c`", + "`7fb93e77b800f27187a5c02333298cc31a025bd6`", + "latest-parent acceptance is not claimed", + ): + with self.subTest(marker=marker): + self.assertIn(marker, self.checkpoint) + + def test_red_green_and_hosted_boundaries_are_not_conflated(self) -> None: + for marker in ( + "RED-only checkpoint", + "no production repair or GREEN is claimed for #264", + "1293/1293 functions", + "13567/13567 lines", + "17273/17273 regions", + "1440/1440 branches", + "CI `34032661775`", + "MV3 `34032661781`", + "queued", + ): + with self.subTest(marker=marker): + self.assertIn(marker, self.checkpoint) + + def test_visual_and_review_boundaries_remain_open(self) -> None: + for marker in ( + "Mac remains locked", + "no stale screenshot substitution", + "#147", + "`PRRT_kwDOTulPlM6coZwc`", + "valid unresolved finding", + ): + with self.subTest(marker=marker): + self.assertIn(marker, self.checkpoint) + + +if __name__ == "__main__": + unittest.main() From ad1a7a8bfc8cdefed1706d8b167ca5cd32cb93b2 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 21:29:27 +0900 Subject: [PATCH 176/250] docs: record current OriginWeave delivery checkpoint --- .../2026-09-06-delivery-checkpoint.md | 27 +++++++++++++++++++ 1 file changed, 27 insertions(+) create mode 100644 docs/evidence/2026-09-06-delivery-checkpoint.md diff --git a/docs/evidence/2026-09-06-delivery-checkpoint.md b/docs/evidence/2026-09-06-delivery-checkpoint.md new file mode 100644 index 000000000..ddaff3580 --- /dev/null +++ b/docs/evidence/2026-09-06-delivery-checkpoint.md @@ -0,0 +1,27 @@ +# OriginWeave delivery checkpoint — 2026-09-06 + +This note is a volatile evidence supplement for the current delivery queue. It does not replace protected-main truth, a counted review, hosted exact-head execution, browser acceptance, or release evidence. + +## Source and dependency state + +PR #264 is Draft on #263. Its current published head is `b4702cd503fa3f721e0d1f44b355563753dac0a2`, a test-first registry-to-BiDi-session transport-provenance **RED-only checkpoint**. The real loopback regression requires a subscription bound to registry session A to be rejected before correlation registration and before any command-frame byte when the established transport is correlated to session B. The bounded writer released in comment 5559140277 because the organization runner-admission incident prevented executable observation; **no production repair or GREEN is claimed for #264** at this head. + +PR #265 is Draft at exact head `35555d0f8491d4ee95c2e61d1a2aaa2c02a0635c`. Its ordinary two-parent integration preserves original child history and parent `7fb93e77b800f27187a5c02333298cc31a025bd6`, including admitted-node authority, the shared registry witness, typed sealed dispatch, preflight retirement, ambiguous-I/O retention, and four restored parent postcondition regressions. The parent subsequently advanced to `b4702cd5`; adoption is intentionally deferred until the parent repair has executable evidence. **latest-parent acceptance is not claimed**. + +#265 exact-head local verification passes Rust 1.97.1 formatting/check/tests/strict Clippy/rustdoc, all 145 Python contracts, compileall, CodeGraph and diff checks. Pinned production coverage is exactly **1293/1293 functions**, **13567/13567 lines**, **17273/17273 regions**, and **1440/1440 branches**. This evidence validates only `35555d0f` against the preserved `7fb93e77` parent state. + +## Hosted and browser boundaries + +#265 exact-head CI `34032661775` and MV3 `34032661781` remain **queued**; no predecessor result transfers. The #264 RED-only CI `34031977586` is also queued after the runner-admission incident. No rerun/no-op churn or gate weakening is used to manufacture progress. + +Fresh visual inspection is still unavailable because the actual Mac remains locked. There is **no stale screenshot substitution** for #264, #265, or this documentation checkpoint. GitHub presentation evidence would not itself establish OriginWeave product-browser acceptance. + +## Review and queue boundary + +The sole known unresolved review thread remains #147 `PRRT_kwDOTulPlM6coZwc`. Fresh thread inspection confirms it is a **valid unresolved finding**, not stale review noise: the ordinary Agent Task pass still has two sequential `PROCESS_EXIT_TIMEOUT_SECONDS` budgets, while #147 intentionally repaired only the forced-close path. The next causal source slice should reuse the combined teardown observer with a focused fake-clock RED rather than resolving the thread administratively. + +Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`. The last complete queue sweep recorded 125 open PRs, 12 Ready roots all BLOCKED, 113 Draft PRs, 13 non-PR issues, and no releases or tags. These counts are freshness evidence, not merge authorization. + +## Documentation integration boundary + +`docs/product-technical-gap-baseline.md` still contains the preceding `88447b7d` volatile cut. This supplement records the newer #264/#265 facts without rewriting the large dated baseline through an unsafe partial-content replacement path. The next safe full-file documentation refresh must incorporate this checkpoint into the volatile baseline and Unreleased CHANGELOG while preserving the dated historical suffix byte-for-byte. Until then, the baseline's older volatile #264/#265 wording must not be treated as current exact-head evidence. From e933fd9c1e4acb5f4c5ea5b87732dc72eb40a9a3 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 21:29:35 +0900 Subject: [PATCH 177/250] docs: refresh pointer integration and visual evidence Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 49 +++++++++++++++++++++++--- 2 files changed, 46 insertions(+), 4 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 757b3a92a..f4242c159 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded the current click safeguards, restored regression coverage and completed PR visual inspection, keeping the separately owned parent repair and queued hosted checks distinct from delivery. - Recorded subscription-shutdown safeguards and their complete local verification, keeping queued hosted checks and the locked-screen visual-inspection gap explicit. - Recorded the repeated-response safeguard, its complete local verification and visual review, separating successful predecessor checks from the new revision's pending checks. - Recorded the original-browser-state subscription repair and its final verification, keeping pending hosted checks and unfinished browser acceptance separate. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 672b0f355..af9055968 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -8,9 +8,9 @@ This volatile section is refreshed from live GitHub state and is authoritative o ### Latest verified cut: 2026-09-06 -Observed through (UTC): `2026-09-06T11:49:46Z`. This cut supersedes volatile claims in the prior observation section below; those earlier exact-head measurements remain historical rather than transferable acceptance evidence. The complete queue read finished at `11:47:46 UTC`; #264 publication and writer release were verified afterward at the stated head. +Observed through (UTC): `2026-09-06T12:28:16Z`. This cut supersedes volatile claims in the prior observation section below; those earlier exact-head measurements remain historical rather than transferable acceptance evidence. The complete queue read finished at `12:28:16 UTC`, after #265 publication and writer release. The new parent #264 regression is independently owned and is not yet adopted by #265. -The inventory remains **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`; release and tag inventories are both empty. Ready-root source heads other than this document's moving branch are unchanged. GraphQL access recovered after the earlier rate-limit failure. GraphQL thread resolution was refreshed for all 125 open PRs alongside exact heads, bases, check rollups and formal reviews in five pages, finishing at `11:47:46 UTC`; all nested histories fit their 100-item pages, with no remaining pagination flags. #147 retains the sole unresolved thread `PRRT_kwDOTulPlM6coZwc`. #166/#220 retain `CHANGES_REQUESTED`, and the other Ready roots retain `REVIEW_REQUIRED`; all twelve are `BLOCKED`. The earlier successful GraphQL cut at `10:00:47 UTC`, subsequent failed inventory/minimal probe and complete 375-read REST fallback at `10:12:37 UTC` remain historical diagnostics, not the current freshness boundary. Active ruleset `18156473` still requires a counted approval and seven central workflows, while the collaborator inventory still contains only the author. #219 has a same-head formal bot approval, but its freshly verified GitHub decision remains `REVIEW_REQUIRED`; an uncounted review does not satisfy the gate. None of this authorizes a bypass or substitutes for an eligible counted approval. +The inventory remains **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`; release and tag inventories are both empty. Ready-root source heads other than this document's moving branch are unchanged. GraphQL access recovered after the earlier rate-limit failure. GraphQL thread resolution was refreshed for all 125 open PRs alongside exact heads, bases, check rollups and formal reviews in five pages, finishing at `12:28:16 UTC`; all nested histories fit their 100-item pages, with no remaining pagination flags. #147 retains the sole unresolved thread `PRRT_kwDOTulPlM6coZwc`. #166/#220 retain `CHANGES_REQUESTED`, and the other Ready roots retain `REVIEW_REQUIRED`; all twelve are `BLOCKED`. The earlier successful GraphQL cut at `10:00:47 UTC`, subsequent failed inventory/minimal probe and complete 375-read REST fallback at `10:12:37 UTC` remain historical diagnostics, not the current freshness boundary. Active ruleset `18156473` still requires a counted approval and seven central workflows, while the collaborator inventory still contains only the author. #219 has a same-head formal bot approval, but its freshly verified GitHub decision remains `REVIEW_REQUIRED`; an uncounted review does not satisfy the gate. None of this authorizes a bypass or substitutes for an eligible counted approval. The restored foundation changes the next executable queue. #195 is Draft at `63997bcf555e2c5c8e91ba287734ffba3837a1b7`, on `6922dd98779e8f8aad132a3b1f563d7ba6e6d070`. Its owner restored product/evidence assets lost by historical whole-tree repair `5c111d0db6c363f9d1786c21cc01c5c7398007bd`; this is a content-recovery boundary, not permission to copy an old tree over later work. Fresh hosted CI `34013251657` fails in repository contracts while exact production coverage and MV3 `34013251651` succeed. The exercised failures compare inherited workflow concurrency and `nightly-2026-08-01` against the protected repository-scoped identity and `nightly-2026-08-18`. #279 owns current-workflow reconstruction; weakening the restored tests does not repair the generation mismatch. #242 remains at `2d0e9f69df9ade21d8e8e3d807c3ff644d83b310`, with a stale pre-recovery #195 base `48eb2d23009c1c804520dd5efcd0d4d072aacef1`. Its old CI success is not recovered-foundation acceptance. After the owner prerequisite, adopt the verified foundation content-aware and non-destructively before regenerating descendant checks. @@ -66,9 +66,9 @@ All 22 focused admission/frame tests and the added real public opening-deadline Fresh exact-head CI `34029687813`, Rust `101476824185` and coverage `101476824305`, and MV3 `34029687816` / `101476824298` are queued. Post-publication actual Edge visual inspection covered the new PR body and Checks page: exact head/base, Draft state and three queued checks matched the API; desktop screenshots showed readable wrapping with no observed clipping or overlap. GitHub presentation evidence is not OriginWeave product-browser acceptance. Both contributor histories remain ancestors, ordinary publication was verified, and the #264 writer was explicitly released before this documentation-only slice. Registry-to-transport authentication, unsubscribe lifetime/transport provenance, action causality, real browser acceptance, #195/#279 integration, protected delivery and release gates remain open. -#### Current subscription teardown ownership and provenance +#### Subscription teardown ownership and provenance predecessor -Published #264 is now `7fb93e77b800f27187a5c02333298cc31a025bd6`, Draft on unchanged #263 +At the preceding cut, published #264 was `7fb93e77b800f27187a5c02333298cc31a025bd6`, Draft on unchanged #263 `3f22de94b63da83eaa8b5b1270912b21a3ecd006`. Lifetime RED `2c45cea8` reproduced event admission after borrowed teardown construction. Transport RED `ce6f6fd4` reproduced 91 actual masked bytes on a foreign connection and foreign success/error consuming the original pending command. Genuine @@ -103,6 +103,47 @@ At this read, #238 predecessor `81e334aff063290bde3298671cfd20e77c7c1fff` still CI `34030165220` plus central review/security work. This documentation commit needs its own checks; neither its earlier 172 local Python passes nor #264's source coverage transfers to the new head. +#### Current pointer integration and independently owned parent repair + +Published #265 is `35555d0f8491d4ee95c2e61d1a2aaa2c02a0635c`, still Draft. Ordinary two-parent +integration `7535d8af` preserves original child `ffa70ee0f499b86ff51837fb95733fd5cf57ff89` and +parent `7fb93e77b800f27187a5c02333298cc31a025bd6`. Real-socket RED `3f9cdc1a` observed no command +bytes but one outstanding command after a zero deadline. The repair retains the child's immediate +admitted-node revalidation and the parent's typed dispatch, local no-write retirement and ambiguous +write retention. Both use the existing registry identity allocation. Independent review identified +four silently deleted parent postcondition tests and two obsolete sender calls; all were restored +or migrated without dropping assertions. The final review found no remaining actionable finding, +which is not a counted GitHub approval. + +All 19 focused tests, complete Rust 1.97.1 formatting/check/tests/strict Clippy/rustdoc, all 145 +Python contracts, compileall, CodeGraph and diff checks pass. The exact-head pinned-nightly rerun +passes unchanged production coverage at **1293/13567/17273/1440** functions/lines/regions/branches, +each 100%; artifact SHA-256 is +`b1374f65538fb6557b4e5d877aa067e183202ed1f56c75be047b3ff2dfdc92a0`. This is local source evidence. +CI `34032661775`, Rust `101484986934` and coverage `101484987071`, and MV3 `34032661781` / +`101484986948` remain queued. Normal publication was verified; writer `5559058158` released. + +The live parent #264 subsequently advanced to test-only `b4702cd503fa3f721e0d1f44b355563753dac0a2`. +Its 129-line socket regression targets registry-session A dispatch over transport-session B; +active writer [5559076006](https://github.com/ContextualWisdomLab/OriginWeave/pull/264#issuecomment-5559076006) +owns that repair. Parent CI `34031977586` and MV3 `34031977597` remain queued. Adoption is deferred +until the parent repair and writer release: #265's local GREEN is **not latest-parent acceptance**. +The PR base snapshot still names `7fb93e77`, so it must not replace the fetched live parent as +dependency evidence. No parent source was changed during this documentation slice. + +Browser access recovered after the earlier locked-screen failures. Fresh actual Edge visual +inspection of #265's published body and Checks page verified head `35555d0f`, Draft state and the +three queued checks. The inspected desktop screenshots show readable wrapping with no observed +clipping or overlap. This replaces the earlier lock blocker only for that inspected presentation; +the new documentation head still requires its own visual inspection. GitHub presentation is not +OriginWeave product-browser acceptance, browser-process authentication or navigation causality. + +The #238 predecessor `88447b7d43e4a87b48fb8fde33f93b2e3ce8cbc5` still has pending native CI +`34031539064` and central review/security work. Its 172 local Python passes and #265's source +coverage do not transfer to this documentation commit. The next executable items are this dated +evidence update, then verified parent adoption after the separate writer releases; #195/#279, +#212 and protected-main/release gates remain prerequisite work. + #### Scheduling and central-owner follow-up This section retains owner-reported scheduling and central-repository evidence. Those reports are From bbe0bd087c82665c6557da593875ffd7f8bba4b2 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 21:41:00 +0900 Subject: [PATCH 178/250] test(docs): scope recovered visual evidence to current checkpoint Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- ...st_current_delivery_checkpoint_20260906_contract.py | 3 +++ tests/test_gap_snapshot_inventory_consistency.py | 10 ++++++---- 2 files changed, 9 insertions(+), 4 deletions(-) diff --git a/tests/test_current_delivery_checkpoint_20260906_contract.py b/tests/test_current_delivery_checkpoint_20260906_contract.py index a4ae623b7..1a9821f98 100644 --- a/tests/test_current_delivery_checkpoint_20260906_contract.py +++ b/tests/test_current_delivery_checkpoint_20260906_contract.py @@ -43,6 +43,9 @@ def test_red_green_and_hosted_boundaries_are_not_conflated(self) -> None: def test_visual_and_review_boundaries_remain_open(self) -> None: for marker in ( "Mac remains locked", + "Browser access recovered", + "published body and Checks page", + "incorporated into the volatile baseline", "no stale screenshot substitution", "#147", "`PRRT_kwDOTulPlM6coZwc`", diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 94eaf5df6..80414372e 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -329,8 +329,8 @@ def test_current_cut_separates_browser_failure_and_unpublished_repair(self) -> N def test_pointer_integration_cut_separates_parent_and_hosted_acceptance(self) -> None: """Published pointer proof must retain the newer parent and visual evidence gaps.""" - latest = self.baseline.split("## Current live delivery state", 1)[1].split( - "### Prior observation cut: 2026-09-05", 1 + latest = self.baseline.split("#### Current pointer integration and independently owned parent repair", 1)[1].split( + "#### Scheduling and central-owner follow-up", 1 )[0] for marker in ( "35555d0f8491d4ee95c2e61d1a2aaa2c02a0635c", @@ -346,8 +346,10 @@ def test_pointer_integration_cut_separates_parent_and_hosted_acceptance(self) -> ): with self.subTest(marker=marker): self.assertIn(marker, latest) - self.assertIn("new-head visual inspection remains incomplete", latest) - self.assertIn("Mac is locked", latest) + self.assertIn("Browser access recovered", latest) + self.assertIn("published body and Checks page", latest) + self.assertIn("new documentation head still requires its own visual inspection", latest) + self.assertIn("5559140277", latest) def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: """The dated 2026-08-29 snapshot must keep its exact historical inventory.""" From 112ba13a5ba905230cfaa8eedf71e7870480f60b Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 21:41:58 +0900 Subject: [PATCH 179/250] docs: reconcile released checkpoint and recovered visual evidence Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- docs/evidence/2026-09-06-delivery-checkpoint.md | 6 +++--- docs/product-technical-gap-baseline.md | 10 ++++++---- 2 files changed, 9 insertions(+), 7 deletions(-) diff --git a/docs/evidence/2026-09-06-delivery-checkpoint.md b/docs/evidence/2026-09-06-delivery-checkpoint.md index ddaff3580..eb7c63135 100644 --- a/docs/evidence/2026-09-06-delivery-checkpoint.md +++ b/docs/evidence/2026-09-06-delivery-checkpoint.md @@ -14,14 +14,14 @@ PR #265 is Draft at exact head `35555d0f8491d4ee95c2e61d1a2aaa2c02a0635c`. Its o #265 exact-head CI `34032661775` and MV3 `34032661781` remain **queued**; no predecessor result transfers. The #264 RED-only CI `34031977586` is also queued after the runner-admission incident. No rerun/no-op churn or gate weakening is used to manufacture progress. -Fresh visual inspection is still unavailable because the actual Mac remains locked. There is **no stale screenshot substitution** for #264, #265, or this documentation checkpoint. GitHub presentation evidence would not itself establish OriginWeave product-browser acceptance. +The contributing writer's earlier observation was "Mac remains locked". Browser access recovered for the integrating writer: fresh actual Edge inspection of #265's published body and Checks page showed readable wrapping, no observed clipping or overlap, exact head `35555d0f` and three queued checks. The new documentation head still requires its own visual inspection. There is **no stale screenshot substitution** for #264, #265, or this documentation checkpoint. GitHub presentation evidence does not establish OriginWeave product-browser acceptance. ## Review and queue boundary -The sole known unresolved review thread remains #147 `PRRT_kwDOTulPlM6coZwc`. Fresh thread inspection confirms it is a **valid unresolved finding**, not stale review noise: the ordinary Agent Task pass still has two sequential `PROCESS_EXIT_TIMEOUT_SECONDS` budgets, while #147 intentionally repaired only the forced-close path. The next causal source slice should reuse the combined teardown observer with a focused fake-clock RED rather than resolving the thread administratively. +The sole known unresolved review thread remains #147 `PRRT_kwDOTulPlM6coZwc`. The contributing writer reported a **valid unresolved finding**: the ordinary Agent Task pass on #147 still has two sequential `PROCESS_EXIT_TIMEOUT_SECONDS` budgets, while #147 intentionally repaired only the forced-close path. #150 already contains a combined ordinary teardown waiter; fresh source comparison and verified integration must precede any additional repair. Do not duplicate that implementation or resolve the thread administratively without acceptance evidence. Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`. The last complete queue sweep recorded 125 open PRs, 12 Ready roots all BLOCKED, 113 Draft PRs, 13 non-PR issues, and no releases or tags. These counts are freshness evidence, not merge authorization. ## Documentation integration boundary -`docs/product-technical-gap-baseline.md` still contains the preceding `88447b7d` volatile cut. This supplement records the newer #264/#265 facts without rewriting the large dated baseline through an unsafe partial-content replacement path. The next safe full-file documentation refresh must incorporate this checkpoint into the volatile baseline and Unreleased CHANGELOG while preserving the dated historical suffix byte-for-byte. Until then, the baseline's older volatile #264/#265 wording must not be treated as current exact-head evidence. +This supplement originally accompanied the preceding `88447b7d` volatile cut. Its two contribution commits were preserved by an ordinary merge after the contributing writer released in comment 5559241313. The newer #264/#265 facts are now incorporated into the volatile baseline and Unreleased CHANGELOG, with the dated historical suffix preserved byte-for-byte. Historical observations remain dated evidence rather than current acceptance claims. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index af9055968..3b4e88a1b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -125,9 +125,11 @@ CI `34032661775`, Rust `101484986934` and coverage `101484987071`, and MV3 `3403 The live parent #264 subsequently advanced to test-only `b4702cd503fa3f721e0d1f44b355563753dac0a2`. Its 129-line socket regression targets registry-session A dispatch over transport-session B; -active writer [5559076006](https://github.com/ContextualWisdomLab/OriginWeave/pull/264#issuecomment-5559076006) -owns that repair. Parent CI `34031977586` and MV3 `34031977597` remain queued. Adoption is deferred -until the parent repair and writer release: #265's local GREEN is **not latest-parent acceptance**. +writer [5559076006](https://github.com/ContextualWisdomLab/OriginWeave/pull/264#issuecomment-5559076006) +released in [5559140277](https://github.com/ContextualWisdomLab/OriginWeave/pull/264#issuecomment-5559140277) +without executing the regression or implementing a production repair. Parent CI `34031977586` +and MV3 `34031977597` remain queued. The available local backend can now execute that regression +under a new source lease. Adoption waits for verified repair: #265's local GREEN is **not latest-parent acceptance**. The PR base snapshot still names `7fb93e77`, so it must not replace the fetched live parent as dependency evidence. No parent source was changed during this documentation slice. @@ -141,7 +143,7 @@ OriginWeave product-browser acceptance, browser-process authentication or naviga The #238 predecessor `88447b7d43e4a87b48fb8fde33f93b2e3ce8cbc5` still has pending native CI `34031539064` and central review/security work. Its 172 local Python passes and #265's source coverage do not transfer to this documentation commit. The next executable items are this dated -evidence update, then verified parent adoption after the separate writer releases; #195/#279, +evidence update, then an executed parent regression and verified repair under a new writer lease; #195/#279, #212 and protected-main/release gates remain prerequisite work. #### Scheduling and central-owner follow-up From 8d3b20bdce8e4ea635bfa62392f027f403cc9c68 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 22:34:12 +0900 Subject: [PATCH 180/250] test(docs): require executed session-adoption evidence Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- .../test_gap_snapshot_inventory_consistency.py | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/tests/test_gap_snapshot_inventory_consistency.py b/tests/test_gap_snapshot_inventory_consistency.py index 80414372e..d4c9c0599 100644 --- a/tests/test_gap_snapshot_inventory_consistency.py +++ b/tests/test_gap_snapshot_inventory_consistency.py @@ -351,6 +351,23 @@ def test_pointer_integration_cut_separates_parent_and_hosted_acceptance(self) -> self.assertIn("new documentation head still requires its own visual inspection", latest) self.assertIn("5559140277", latest) + def test_session_adoption_cut_records_executed_and_visual_evidence(self) -> None: + """Current source evidence must not inherit earlier pending-adoption claims.""" + latest = self.baseline.split("### Latest verified cut: 2026-09-06", 1)[1].split( + "#### Prior observation: 12:28 UTC", 1 + )[0] + for marker in ( + "7147893c96ca95c9b5b275d8011c5bfe99aab065", + "6f331a5b220349a1aaa1b1841d5e8ec027b9ad49", + "98621adf", "1296/13601/17303/1442", + "480d6d3ca492565e8a04bfce4b0c135dffbff276532d129c410674838e8fec2f", + "34036335342", "34036335505", "queued", + "actual Edge visual inspection", "not product-browser acceptance", + "5559497861", "not protected-main delivery", + ): + with self.subTest(marker=marker): + self.assertIn(marker, latest) + def test_current_baseline_inventory_matches_the_verified_snapshot(self) -> None: """The dated 2026-08-29 snapshot must keep its exact historical inventory.""" current = self.baseline.split("### Open pull requests", 1)[1].split( From ca8f8475033f9924ddadd518659b6c75d25066a5 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 22:35:04 +0900 Subject: [PATCH 181/250] docs: record verified session repair and child adoption Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 48 ++++++++++++++++++++++++++ 2 files changed, 49 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index f4242c159..8a127b7dc 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded the executed session-isolation repair and its verified adoption, separating complete local checks and PR visual inspection from pending hosted checks and unreleased browser acceptance. - Recorded the current click safeguards, restored regression coverage and completed PR visual inspection, keeping the separately owned parent repair and queued hosted checks distinct from delivery. - Recorded subscription-shutdown safeguards and their complete local verification, keeping queued hosted checks and the locked-screen visual-inspection gap explicit. - Recorded the repeated-response safeguard, its complete local verification and visual review, separating successful predecessor checks from the new revision's pending checks. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 3b4e88a1b..ce98c18bd 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -8,6 +8,54 @@ This volatile section is refreshed from live GitHub state and is authoritative o ### Latest verified cut: 2026-09-06 +#### Session repair and child adoption: 13:35 UTC + +This update supersedes the 12:28 source/adoption and visual-boundary claims below. +The complete five-page live inventory read at 13:29 UTC still found 125 open PRs +(12 Ready/non-draft, all BLOCKED; 113 Draft), with only #147's unresolved thread +`PRRT_kwDOTulPlM6coZwc`. Subsequent REST reads confirmed 13 non-PR issues, no releases +or tags, and unchanged protected main `87c4daa1830bac5a5228b6036752ad5633232085`. + +Parent #264 is now `6f331a5b220349a1aaa1b1841d5e8ec027b9ad49`, Draft on #263 +`3f22de94b63da83eaa8b5b1270912b21a3ecd006`. Its original actual-socket regression +was executed and reproduced foreign-session dispatch before the canonical session +mapping guard repaired it. Unknown, retired and mismatched mappings reject without +creating state, registering correlation or emitting command bytes. The fixture now +waits for seed-Pong setup before simulating disconnection; the diagnostic unit-copy +coverage case is retained. Full Rust 1.97.1 gates, 145 Python contracts and exact +1282/13455/17136/1440 production functions/lines/regions/branches each pass at 100%. +Artifact SHA-256 is `b85acd79c3e3a3a49561b9148b6aafadc26cd292a542ec74ef2b523e88c42eaa`. +Current CI `34035628391` and MV3 `34035628337` remain queued, not hosted GREEN. +The source writer released in comment `5559331330`; actual Edge visual inspection +of its published body and Checks page was completed on this head. + +Child #265 now publishes `7147893c96ca95c9b5b275d8011c5bfe99aab065` and actually +adopts that parent. Original parent regression replay `98621adf` first reproduced +the same socket failure on the child (0 passed, 1 failed). An ordinary merge then +preserved both histories, admitted-node/current-document authority, typed dispatch, +deadline and ambiguous-write safeguards, all four previously restored postcondition +tests, and both Proposed ADR refinements. All 16 focused regressions, full Rust +1.97.1 gates, 145 Python contracts, compileall, CodeGraph and diff checks pass. +Exact pinned-nightly coverage is 1296/13601/17303/1442, each 100%; artifact SHA-256 +is `480d6d3ca492565e8a04bfce4b0c135dffbff276532d129c410674838e8fec2f`. +CI `34036335342` and MV3 `34036335505` remain queued. Fresh actual Edge visual inspection +verified the published body and Checks page at this head: readable wrapping, no +observed clipping or overlap, and exact job IDs matching the API. This is GitHub +presentation evidence, not product-browser acceptance. Writer `5559497861` released +after normal publication and readback. Independent preservation review found no +actionable finding; it is not counted approval. + +These are local parent/child acceptance results, not protected-main delivery. +The branch-instrumentation warning, #195/#279 foundation prerequisite, counted-review +rule, browser authentication, action authorization, pointer-reply connection binding, +navigation causality and release gates remain separate. Earlier revision measurements +and screenshots are historical. This new documentation revision still requires its +own post-publication visual inspection; prior #238 `112ba13a` inspection is not transferred. + +#### Prior observation: 12:28 UTC + +All current-state wording in this prior observation is scoped to its recorded time. + Observed through (UTC): `2026-09-06T12:28:16Z`. This cut supersedes volatile claims in the prior observation section below; those earlier exact-head measurements remain historical rather than transferable acceptance evidence. The complete queue read finished at `12:28:16 UTC`, after #265 publication and writer release. The new parent #264 regression is independently owned and is not yet adopted by #265. The inventory remains **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`; release and tag inventories are both empty. Ready-root source heads other than this document's moving branch are unchanged. GraphQL access recovered after the earlier rate-limit failure. GraphQL thread resolution was refreshed for all 125 open PRs alongside exact heads, bases, check rollups and formal reviews in five pages, finishing at `12:28:16 UTC`; all nested histories fit their 100-item pages, with no remaining pagination flags. #147 retains the sole unresolved thread `PRRT_kwDOTulPlM6coZwc`. #166/#220 retain `CHANGES_REQUESTED`, and the other Ready roots retain `REVIEW_REQUIRED`; all twelve are `BLOCKED`. The earlier successful GraphQL cut at `10:00:47 UTC`, subsequent failed inventory/minimal probe and complete 375-read REST fallback at `10:12:37 UTC` remain historical diagnostics, not the current freshness boundary. Active ruleset `18156473` still requires a counted approval and seven central workflows, while the collaborator inventory still contains only the author. #219 has a same-head formal bot approval, but its freshly verified GitHub decision remains `REVIEW_REQUIRED`; an uncounted review does not satisfy the gate. None of this authorizes a bypass or substitutes for an eligible counted approval. From 6fe2af69a474a83069c713f971754a2a0eee57e4 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 22:50:09 +0900 Subject: [PATCH 182/250] test(docs): expose historical evidence masking current state Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- ...t_current_delivery_checkpoint_20260906_contract.py | 4 ++++ .../test_documentation_active_pr_evidence_contract.py | 11 +++++++++++ 2 files changed, 15 insertions(+) diff --git a/tests/test_current_delivery_checkpoint_20260906_contract.py b/tests/test_current_delivery_checkpoint_20260906_contract.py index 1a9821f98..ecc627bf6 100644 --- a/tests/test_current_delivery_checkpoint_20260906_contract.py +++ b/tests/test_current_delivery_checkpoint_20260906_contract.py @@ -16,6 +16,10 @@ def setUpClass(cls) -> None: cls.checkpoint = CHECKPOINT.read_text(encoding="utf-8") def test_current_source_heads_and_parent_boundary_are_exact(self) -> None: + self.assertIn("Historical checkpoint: 2026-09-06 12:28 UTC", self.checkpoint) + self.assertIn("## Historical source and dependency state", self.checkpoint) + self.assertIn("## Historical hosted and browser boundaries", self.checkpoint) + self.assertIn("## Historical review and queue boundary", self.checkpoint) for marker in ( "`b4702cd503fa3f721e0d1f44b355563753dac0a2`", "`35555d0f8491d4ee95c2e61d1a2aaa2c02a0635c`", diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 7549d4e58..64d91f9e5 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -119,6 +119,17 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertNotIn("128 open pull requests (54 ready, 74 draft)", refresh_line) self.assertNotIn("153 open pull requests (39 ready, 114 draft)", refresh_line) + def test_latest_inventory_drift_cannot_be_hidden_by_historical_counts(self) -> None: + """Changing only the newest count must invalidate an unchanged changelog.""" + probe = ActivePullRequestDocumentationContractTests( + "test_baseline_refresh_changelog_matches_the_live_snapshot" + ) + probe.baseline = self.baseline.replace("125 open", "126 open", 1) + self.assertNotEqual(self.baseline, probe.baseline) + probe.changelog = self.changelog + with self.assertRaises(AssertionError): + probe.test_baseline_refresh_changelog_matches_the_live_snapshot() + def test_current_warc_provider_failures_are_bound_to_current_head(self) -> None: """WARC evidence must describe the current parent head after stack merge.""" for marker in ( From 65ff43615fc865e4879e6c2a08fe5be9700342c3 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 22:51:20 +0900 Subject: [PATCH 183/250] fix(docs): isolate current inventory from historical evidence Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 2 ++ .../2026-09-06-delivery-checkpoint.md | 8 ++--- docs/product-technical-gap-baseline.md | 31 +++++++++++++++++-- ...t_delivery_checkpoint_20260906_contract.py | 4 +-- ...cumentation_active_pr_evidence_contract.py | 15 ++++++--- 5 files changed, 47 insertions(+), 13 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 8a127b7dc..ddb8da083 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,8 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Current delivery inventory: 125 open pull requests (12 ready, 113 draft); 13 open non-PR issues. Observed 2026-09-06; source acceptance remains revision-specific. +- Corrected historical checkpoint labels and made the current inventory check reject stale counts; recorded verified text-input parent adoption without claiming browser execution. - Recorded the executed session-isolation repair and its verified adoption, separating complete local checks and PR visual inspection from pending hosted checks and unreleased browser acceptance. - Recorded the current click safeguards, restored regression coverage and completed PR visual inspection, keeping the separately owned parent repair and queued hosted checks distinct from delivery. - Recorded subscription-shutdown safeguards and their complete local verification, keeping queued hosted checks and the locked-screen visual-inspection gap explicit. diff --git a/docs/evidence/2026-09-06-delivery-checkpoint.md b/docs/evidence/2026-09-06-delivery-checkpoint.md index eb7c63135..5047821a3 100644 --- a/docs/evidence/2026-09-06-delivery-checkpoint.md +++ b/docs/evidence/2026-09-06-delivery-checkpoint.md @@ -1,8 +1,8 @@ # OriginWeave delivery checkpoint — 2026-09-06 -This note is a volatile evidence supplement for the current delivery queue. It does not replace protected-main truth, a counted review, hosted exact-head execution, browser acceptance, or release evidence. +**Historical checkpoint: 2026-09-06 12:28 UTC.** Source heads, queued checks and dependency claims below describe that predecessor observation, not the current queue. The subsequent visual-recovery note describes the integrating writer's later observation at the same source heads. Consult the [latest verified baseline](../product-technical-gap-baseline.md#latest-verified-cut-2026-09-06) for the repaired parent and adopted children. This note does not replace protected-main truth, a counted review, hosted exact-head execution, browser acceptance, or release evidence. -## Source and dependency state +## Historical source and dependency state PR #264 is Draft on #263. Its current published head is `b4702cd503fa3f721e0d1f44b355563753dac0a2`, a test-first registry-to-BiDi-session transport-provenance **RED-only checkpoint**. The real loopback regression requires a subscription bound to registry session A to be rejected before correlation registration and before any command-frame byte when the established transport is correlated to session B. The bounded writer released in comment 5559140277 because the organization runner-admission incident prevented executable observation; **no production repair or GREEN is claimed for #264** at this head. @@ -10,13 +10,13 @@ PR #265 is Draft at exact head `35555d0f8491d4ee95c2e61d1a2aaa2c02a0635c`. Its o #265 exact-head local verification passes Rust 1.97.1 formatting/check/tests/strict Clippy/rustdoc, all 145 Python contracts, compileall, CodeGraph and diff checks. Pinned production coverage is exactly **1293/1293 functions**, **13567/13567 lines**, **17273/17273 regions**, and **1440/1440 branches**. This evidence validates only `35555d0f` against the preserved `7fb93e77` parent state. -## Hosted and browser boundaries +## Historical hosted and browser boundaries #265 exact-head CI `34032661775` and MV3 `34032661781` remain **queued**; no predecessor result transfers. The #264 RED-only CI `34031977586` is also queued after the runner-admission incident. No rerun/no-op churn or gate weakening is used to manufacture progress. The contributing writer's earlier observation was "Mac remains locked". Browser access recovered for the integrating writer: fresh actual Edge inspection of #265's published body and Checks page showed readable wrapping, no observed clipping or overlap, exact head `35555d0f` and three queued checks. The new documentation head still requires its own visual inspection. There is **no stale screenshot substitution** for #264, #265, or this documentation checkpoint. GitHub presentation evidence does not establish OriginWeave product-browser acceptance. -## Review and queue boundary +## Historical review and queue boundary The sole known unresolved review thread remains #147 `PRRT_kwDOTulPlM6coZwc`. The contributing writer reported a **valid unresolved finding**: the ordinary Agent Task pass on #147 still has two sequential `PROCESS_EXIT_TIMEOUT_SECONDS` budgets, while #147 intentionally repaired only the forced-close path. #150 already contains a combined ordinary teardown waiter; fresh source comparison and verified integration must precede any additional repair. Do not duplicate that implementation or resolve the thread administratively without acceptance evidence. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index ce98c18bd..e86c6b28f 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -11,8 +11,8 @@ This volatile section is refreshed from live GitHub state and is authoritative o #### Session repair and child adoption: 13:35 UTC This update supersedes the 12:28 source/adoption and visual-boundary claims below. -The complete five-page live inventory read at 13:29 UTC still found 125 open PRs -(12 Ready/non-draft, all BLOCKED; 113 Draft), with only #147's unresolved thread +The complete five-page live inventory read at 13:29 UTC still found **125 open pull requests: 12 Ready/non-draft and 113 Draft; 13 open non-PR issues**. +All 12 Ready PRs were BLOCKED, with only #147's unresolved thread `PRRT_kwDOTulPlM6coZwc`. Subsequent REST reads confirmed 13 non-PR issues, no releases or tags, and unchanged protected main `87c4daa1830bac5a5228b6036752ad5633232085`. @@ -52,6 +52,33 @@ navigation causality and release gates remain separate. Earlier revision measure and screenshots are historical. This new documentation revision still requires its own post-publication visual inspection; prior #238 `112ba13a` inspection is not transferred. +#### Text-input adoption and review correction: 13:52 UTC + +Published #266 `eb6c236ff2f4a58b807a2f2c914bd1ddb6079fb3` adopts #265 `7147893c` +through ordinary merge `5a722867`, preserving original child `cc9980c0` and its unchanged +text-input source/eight tests. Actual inherited socket RED `18a64573` failed before +adoption. All 24 focused regressions, complete Rust 1.97.1 gates, 145 Python contracts, +compileall, CodeGraph and diff checks pass. Exact pinned-nightly production coverage is +1309/13749/17512/1452, each 100%; SHA-256 +`596097f5545490f6a4bd29a7b718a61aeb43f0ef738e02a61f372232ecd64543`. +CI `34037184023` and MV3 `34037183844` remain queued. Actual Edge inspection of the +published body and Checks page confirms the exact head, Draft state and queued jobs, +with readable wrapping and no observed clipping or overlap. Writer `5559594727` is +released. This is not product-browser acceptance or protected delivery. #267 already +owns typed text transport and needs separate current-parent adoption and dispatch review; +#266 itself still provides construction, not text dispatch or observed action success. + +The later complete queue read still found 125 PRs and 12 Ready roots all BLOCKED, but +found two new #238 review threads in addition to #147: `PRRT_kwDOTulPlM6fsIep` and +`PRRT_kwDOTulPlM6fsIet`. Both findings were verified against `ca8f8475`: the supplement +presented predecessor source claims as current, and the inventory assertion selected +historical counts by formatting. Regression `6fe2af69` observed both failures. The +repair explicitly labels the supplement historical and bounds current inventory checks +to this latest cut, paired with the dedicated current CHANGELOG entry. A mutation test +proves that a changed latest count cannot be hidden by unchanged historical counts. +Thread resolution requires published repair evidence; this documentation revision still +needs its own post-publication visual inspection and exact-head hosted checks. + #### Prior observation: 12:28 UTC All current-state wording in this prior observation is scoped to its recorded time. diff --git a/tests/test_current_delivery_checkpoint_20260906_contract.py b/tests/test_current_delivery_checkpoint_20260906_contract.py index ecc627bf6..b3f86f341 100644 --- a/tests/test_current_delivery_checkpoint_20260906_contract.py +++ b/tests/test_current_delivery_checkpoint_20260906_contract.py @@ -1,4 +1,4 @@ -"""Contracts for the 2026-09-06 volatile delivery checkpoint.""" +"""Contracts preserving the dated 2026-09-06 historical delivery checkpoint.""" from pathlib import Path import unittest @@ -15,7 +15,7 @@ class CurrentDeliveryCheckpointContractTests(unittest.TestCase): def setUpClass(cls) -> None: cls.checkpoint = CHECKPOINT.read_text(encoding="utf-8") - def test_current_source_heads_and_parent_boundary_are_exact(self) -> None: + def test_historical_source_heads_and_parent_boundary_are_exact(self) -> None: self.assertIn("Historical checkpoint: 2026-09-06 12:28 UTC", self.checkpoint) self.assertIn("## Historical source and dependency state", self.checkpoint) self.assertIn("## Historical hosted and browser boundaries", self.checkpoint) diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 64d91f9e5..bdb54c49c 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -91,18 +91,23 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertIn("on 2026-09-05", refresh_line) current = bounded_section( self.baseline, - "## Current live delivery state", - "## Observed snapshot: 2026-08-29", + "### Latest verified cut: 2026-09-06", + "#### Prior observation: 12:28 UTC", ) queue_counts = re.findall( r"\*\*(\d+) open pull requests: (\d+) Ready/non-draft and (\d+) Draft; " r"(\d+) open non-PR issues\*\*", - current, + " ".join(current.split()), ) self.assertEqual(1, len(queue_counts)) total, ready, draft, issues = queue_counts[0] - self.assertIn(f"{total} open pull requests ({ready} ready, {draft} draft)", refresh_line) - self.assertIn(f"{issues} open non-PR issues", refresh_line) + inventory_lines = [ + line for line in self.changelog.splitlines() + if line.startswith("- Current delivery inventory:") + ] + self.assertEqual(1, len(inventory_lines)) + self.assertIn(f"{total} open pull requests ({ready} ready, {draft} draft)", inventory_lines[0]) + self.assertIn(f"{issues} open non-PR issues", inventory_lines[0]) self.assertIn("024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6", refresh_line) self.assertIn("3a651967c421f77088fe25e86a63faae295390b3", refresh_line) self.assertIn("01038ba71fb276426cc67f90a91a3c431e194db5", refresh_line) From 63bd50c8cd8487755eb961faceb3b5cb8805f5ce Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 22:55:28 +0900 Subject: [PATCH 184/250] docs: keep one canonical current delivery inventory Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e86c6b28f..658af8272 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -68,8 +68,8 @@ released. This is not product-browser acceptance or protected delivery. #267 alr owns typed text transport and needs separate current-parent adoption and dispatch review; #266 itself still provides construction, not text dispatch or observed action success. -The later complete queue read still found 125 PRs and 12 Ready roots all BLOCKED, but -found two new #238 review threads in addition to #147: `PRRT_kwDOTulPlM6fsIep` and +The later complete queue read confirmed the canonical inventory above and all Ready +roots remained BLOCKED, but found two new #238 review threads in addition to #147: `PRRT_kwDOTulPlM6fsIep` and `PRRT_kwDOTulPlM6fsIet`. Both findings were verified against `ca8f8475`: the supplement presented predecessor source claims as current, and the inventory assertion selected historical counts by formatting. Regression `6fe2af69` observed both failures. The From 0d9278fb2988a076ce0d700069628ce91c7bc725 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 23:16:02 +0900 Subject: [PATCH 185/250] test(docs): require latest roots and lineage without historical fallback Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- tests/test_product_completion_gap_contract.py | 27 +++++++++++++++++++ 1 file changed, 27 insertions(+) diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 7ce701d93..1aefdadde 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -3,8 +3,11 @@ from __future__ import annotations import pathlib +import re import unittest +from test_documentation_active_pr_evidence_contract import bounded_section + ROOT = pathlib.Path(__file__).resolve().parents[1] BASELINE = ROOT / "docs/product-technical-gap-baseline.md" @@ -105,6 +108,30 @@ def test_current_snapshot_records_the_pr_284_admin_bypass_incident(self) -> None self.assertNotIn("through #280", current) def test_current_snapshot_records_repaired_webdriver_bidi_lineage(self) -> None: + """Only the latest cut may establish current foundation and transport heads.""" + current = bounded_section( + BASELINE.read_text(encoding="utf-8"), + "### Latest verified cut: 2026-09-06", + "#### Prior observation: 12:28 UTC", + ) + self.assertIn("#195 `63997bcf555e2c5c8e91ba287734ffba3837a1b7`", current) + self.assertIn("#267 `4435ce5f561ca069c1844a1a5bd9b603505e25f7`", current) + + def test_latest_executable_queue_uses_current_ready_roots(self) -> None: + text = BASELINE.read_text(encoding="utf-8") + current = bounded_section( + text, "### Latest verified cut: 2026-09-06", "#### Prior observation: 12:28 UTC" + ) + roots = [line for line in current.splitlines() if line.startswith("Ready roots:")] + self.assertEqual(len(roots), 1) + self.assertEqual( + set(re.findall(r"#(\d+)", roots[0])), + {"37", "50", "166", "219", "220", "229", "238", "240", "272", "274", "285", "287"}, + ) + self.assertIn("## Historical next executable queue", text) + self.assertNotIn("## Next executable queue", text) + + def test_historical_snapshot_preserves_webdriver_bidi_lineage(self) -> None: """The active stack must retain exact heads and the macOS race boundary.""" text = BASELINE.read_text(encoding="utf-8") current = text.split("## Current live delivery state", 1)[1].split( From fcb4982c1dfdb78398fab00c15aed7b9024508c8 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 23:16:52 +0900 Subject: [PATCH 186/250] fix(docs): bind active queue and lineage to latest verified evidence Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 39 +++++++++++++++++++++++++- 2 files changed, 39 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index ddb8da083..31492f2d1 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Separate the current maintenance queue and source lineage from preserved historical observations, and record the text-entry session and pending-request safeguards without claiming released browser behavior. - Current delivery inventory: 125 open pull requests (12 ready, 113 draft); 13 open non-PR issues. Observed 2026-09-06; source acceptance remains revision-specific. - Corrected historical checkpoint labels and made the current inventory check reject stale counts; recorded verified text-input parent adoption without claiming browser execution. - Recorded the executed session-isolation repair and its verified adoption, separating complete local checks and PR visual inspection from pending hosted checks and unreleased browser acceptance. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 658af8272..72f83c3a6 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -79,6 +79,43 @@ proves that a changed latest count cannot be hidden by unchanged historical coun Thread resolution requires published repair evidence; this documentation revision still needs its own post-publication visual inspection and exact-head hosted checks. +#### Current executable queue and lineage: 14:18 UTC + +Ready roots: #37, #50, #166, #219, #220, #229, #238, #240, #272, #274, #285, #287. + +The fresh complete inventory confirms the canonical counts above. These are Ready +review candidates, not merge-ready approvals: all remain BLOCKED. Re-fetch each +head, base, checks, findings and counted approval before acting; do not substitute +the historical root list below. #238's moving head remains live metadata rather than +a self-referential SHA in this document. + +Current foundation #195 `63997bcf555e2c5c8e91ba287734ffba3837a1b7` remains Draft on +`6922dd98779e8f8aad132a3b1f563d7ba6e6d070`. The earlier `48eb2d` observations are +historical, not current lineage. #279's workflow-generation prerequisite and #212's +sandbox-helper boundary still require their own evidence and must not be bypassed. + +Published transport #267 `4435ce5f561ca069c1844a1a5bd9b603505e25f7` adopts #266 +`eb6c236ff2f4a58b807a2f2c914bd1ddb6079fb3` through ordinary merge `d903cf6b`, preserving +both histories. Actual REDs `2b960002`, `e2b49e68` and `10131eb7` preceded repairs for +invalid deadlines, no-write preflight retention and foreign-session dispatch. The +implementation reuses canonical timeout/session checks and sealed typed dispatch; +ambiguous writes remain pending. Ten focused socket tests, full Rust 1.97.1 gates, +145 Python contracts and exact production coverage 1317/13832/17596/1456 each at 100% +pass. Coverage SHA-256 is +`065e535fd49c34699b35d53b4cc6b09f22b3dff506f07eb5549c21b73074bdc8`. +Actual Edge inspection verified its published body and Checks page at that head, +with readable wrapping and no observed clipping or overlap. CI `34038399969` remains +queued; this is not hosted acceptance, counted approval or product-browser evidence. +Source writer `5559716889` is released. + +Execute the verified #238 root/lineage review repairs first, then adopt #267 into +existing response owner #268 `8d4027e40b790d28d866051ba741db12927ec22c`. That consumer +still uses removed generic correlation; migrate to the parent's distinct text family +without restoring generic routing, weakening malformed-response retention, or treating +response admission as observed action success. Received-message provenance remains a +separate unproven boundary. Keep source and documentation writers separate. This +documentation revision needs its own publication, visual inspection and hosted checks. + #### Prior observation: 12:28 UTC All current-state wording in this prior observation is scoped to its recorded time. @@ -557,7 +594,7 @@ OriginWeave is not complete merely because every low-level primitive exists in s 9. No required check, browser/platform lane, security case, benchmark case, or independent review is skipped, stale, inherited, or represented by status-only evidence. 10. The open PR queue is reduced to bounded active work rather than being the only place where the product exists. -## Next executable queue +## Historical next executable queue 1. Drain the merge gate in dependency order: for every ready root PR whose current head is check-green with resolved threads, obtain the current ruleset's counted `APPROVED` review from an eligible non-author collaborator; OpenCode approval or skip evidence does not substitute for that GitHub review. If no eligible approver exists, record the reviewer-provisioning gap and do not merge. Root candidates include #37, #40, #43, #45–#48, #51, #62–#65, #74, #82, #124, #149, #152, #156–#166, #173, #175, #208, #209, #211, #218, #219, #229, #237, #238, and #239 as their current checks land. Treat dependent children separately: only after a predecessor reaches protected `main`, retarget and independently revalidate its immediate child; preserve orders such as #218 → #221 → #220 rather than treating #208–#220 as a flat merge range. 2. Keep the organization review pipeline healthy: monitor the central Actions backlog recorded above; if OpenCode reviews stop landing on OriginWeave heads while the queue is idle, repair `ContextualWisdomLab/.github` dispatch/concurrency configuration rather than weakening any gate. From 1488fb48ebf3fb66cd6fb34facc74a42063e371c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 23:17:34 +0900 Subject: [PATCH 187/250] test(docs): prove historical prose cannot mask latest evidence removal Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- tests/test_product_completion_gap_contract.py | 23 +++++++++++++++++++ 1 file changed, 23 insertions(+) diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 1aefdadde..68d3eb71e 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -5,6 +5,7 @@ import pathlib import re import unittest +from unittest.mock import patch from test_documentation_active_pr_evidence_contract import bounded_section @@ -131,6 +132,28 @@ def test_latest_executable_queue_uses_current_ready_roots(self) -> None: self.assertIn("## Historical next executable queue", text) self.assertNotIn("## Next executable queue", text) + def test_historical_prose_cannot_hide_latest_root_or_lineage_removal(self) -> None: + text = BASELINE.read_text(encoding="utf-8") + cases = ( + ( + "#195 `63997bcf555e2c5c8e91ba287734ffba3837a1b7`", + "foundation evidence removed", + self.test_current_snapshot_records_repaired_webdriver_bidi_lineage, + ), + ( + "Ready roots: #37, #50,", + "Ready roots: #37,", + self.test_latest_executable_queue_uses_current_ready_roots, + ), + ) + for original, replacement, check in cases: + with self.subTest(original=original): + mutated = text.replace(original, replacement, 1) + self.assertNotEqual(mutated, text) + with patch.object(pathlib.Path, "read_text", return_value=mutated): + with self.assertRaises(AssertionError): + check() + def test_historical_snapshot_preserves_webdriver_bidi_lineage(self) -> None: """The active stack must retain exact heads and the macOS race boundary.""" text = BASELINE.read_text(encoding="utf-8") From 1016bcb845454f7cdef8e02c863b6abaf38cc223 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 23:51:26 +0900 Subject: [PATCH 188/250] test(docs): require current text receipt provenance evidence Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- tests/test_product_completion_gap_contract.py | 14 +++++++++++--- 1 file changed, 11 insertions(+), 3 deletions(-) diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 68d3eb71e..ca34dab42 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -112,11 +112,19 @@ def test_current_snapshot_records_repaired_webdriver_bidi_lineage(self) -> None: """Only the latest cut may establish current foundation and transport heads.""" current = bounded_section( BASELINE.read_text(encoding="utf-8"), - "### Latest verified cut: 2026-09-06", - "#### Prior observation: 12:28 UTC", + "#### Connection-bound text responses: 14:54 UTC", + "#### Session repair and child adoption: 13:35 UTC", ) self.assertIn("#195 `63997bcf555e2c5c8e91ba287734ffba3837a1b7`", current) - self.assertIn("#267 `4435ce5f561ca069c1844a1a5bd9b603505e25f7`", current) + self.assertIn("#267 `3346d8ecc72932b98ec495d9cc52d6e5727c3064`", current) + self.assertIn("#268 `e567af9e678fd4791776df795e89ed666975e6c2`", current) + for marker in ( + "4632f2df", "d6889c80", "e1188c86", + "34040202356", "34040306372", "queued", + "pointer and status", "not product-browser acceptance", + ): + with self.subTest(marker=marker): + self.assertIn(marker, current) def test_latest_executable_queue_uses_current_ready_roots(self) -> None: text = BASELINE.read_text(encoding="utf-8") From 6abe40096d977f1ebb254034c48cfb99af93033b Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 23:52:58 +0900 Subject: [PATCH 189/250] docs: refresh connection-bound text repair baseline Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 48 +++++++++++++++++++++++++- 2 files changed, 48 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 31492f2d1..29e58f566 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded the published text-entry connection safeguards and their test evidence, separating queued hosted checks and remaining pointer/status repairs from released browser behavior. - Separate the current maintenance queue and source lineage from preserved historical observations, and record the text-entry session and pending-request safeguards without claiming released browser behavior. - Current delivery inventory: 125 open pull requests (12 ready, 113 draft); 13 open non-PR issues. Observed 2026-09-06; source acceptance remains revision-specific. - Corrected historical checkpoint labels and made the current inventory check reject stale counts; recorded verified text-input parent adoption without claiming browser execution. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 72f83c3a6..add24db22 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -8,6 +8,52 @@ This volatile section is refreshed from live GitHub state and is authoritative o ### Latest verified cut: 2026-09-06 +#### Connection-bound text responses: 14:54 UTC + +This checkpoint supersedes the source status and executable actions in the earlier +timed checkpoints below, which remain historical evidence. The fresh complete +five-page inventory still contains 125 open PRs (12 Ready, 113 Draft) and 13 open +non-PR issues. All Ready candidates remain BLOCKED; only #147 retains unresolved +thread `PRRT_kwDOTulPlM6coZwc`. Protected main is unchanged at +`87c4daa1830bac5a5228b6036752ad5633232085`; release and tag inventories are empty. + +Ready roots: #37, #50, #166, #219, #220, #229, #238, #240, #272, #274, #285, #287. + +Published sender #267 `3346d8ecc72932b98ec495d9cc52d6e5727c3064` remains on #266 +`eb6c236ff2f4a58b807a2f2c914bd1ddb6079fb3`. Published response owner +#268 `e567af9e678fd4791776df795e89ed666975e6c2` adopts it by ordinary merge +`e1188c86`. Actual socket RED `4632f2df` accepted a reply from a replacement +connection using the same listener/session. Sealed consumer `d6889c80` exposed +missing sender provenance; the parent now records its private connection generation +before I/O and the consumer checks the sealed receipt before consuming pending work. +Foreign success/error replies retain both pending entries; the original reply still +completes its request and leaves unrelated work pending. Seven focused response tests +preserve real remote-error consumption, extensible success, malformed/unknown +retention, family isolation and missing-provenance rejection. + +Both exact source heads pass full local Rust1.97.1 gates, 145 Python contracts, +compileall, CodeGraph and diff checks. Their function/line/region/branch coverage is +1317/13835/17598/1456 for #267 and 1324/13890/17670/1456 for #268, each 100%. +Coverage SHA-256 values are respectively +`8d7a3687557d067ee99fd512936077c0c9662d40d9d6544232bb5a377dc88e23` and +`5865d6e69dc5584bad8ef4e866970eb6aa845ad692aa5421a0ffb6f6f01e1540`. +CI `34040202356` and `34040306372` remain queued; formal reviews are empty. +Actual Edge screenshots verified the published source PRs' exact heads, Draft state +and readable evidence without observed clipping or overlap. This is GitHub +presentation evidence, not product-browser acceptance or protected-main delivery. +Writers `5559965531` and `5559948553` are released. This documentation revision +requires its own publication, visual inspection and exact-head checks. + +Next source work must address pointer and status receipt provenance in their existing +owners, plus the separate pointer outbound session-binding gap, before promoting +their evidence. Reuse the sealed reader and canonical connection checks; status +projection must still validate before correlation consumption. Browser ownership, +policy approval and observed field/DOM postconditions remain unfinished. Current +foundation #195 `63997bcf555e2c5c8e91ba287734ffba3837a1b7` remains on +`6922dd98779e8f8aad132a3b1f563d7ba6e6d070`; #279 workflow generation and #212 +sandbox boundaries remain prerequisites. Counted approval and central workflow +requirements must not be bypassed. Source and documentation writers stay separate. + #### Session repair and child adoption: 13:35 UTC This update supersedes the 12:28 source/adoption and visual-boundary claims below. @@ -81,7 +127,7 @@ needs its own post-publication visual inspection and exact-head hosted checks. #### Current executable queue and lineage: 14:18 UTC -Ready roots: #37, #50, #166, #219, #220, #229, #238, #240, #272, #274, #285, #287. +Historical Ready roots: #37, #50, #166, #219, #220, #229, #238, #240, #272, #274, #285, #287. The fresh complete inventory confirms the canonical counts above. These are Ready review candidates, not merge-ready approvals: all remain BLOCKED. Re-fetch each From bb5900e6466ff1d5e68391e2c1ac9602a1d1a0ed Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 6 Sep 2026 23:53:40 +0900 Subject: [PATCH 190/250] fix(docs): bind inventory validation to the newest checkpoint Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 4 ++-- tests/test_documentation_active_pr_evidence_contract.py | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index add24db22..a3f8487e1 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -12,8 +12,8 @@ This volatile section is refreshed from live GitHub state and is authoritative o This checkpoint supersedes the source status and executable actions in the earlier timed checkpoints below, which remain historical evidence. The fresh complete -five-page inventory still contains 125 open PRs (12 Ready, 113 Draft) and 13 open -non-PR issues. All Ready candidates remain BLOCKED; only #147 retains unresolved +five-page inventory still contains **125 open pull requests: 12 Ready/non-draft and +113 Draft; 13 open non-PR issues**. All Ready candidates remain BLOCKED; only #147 retains unresolved thread `PRRT_kwDOTulPlM6coZwc`. Protected main is unchanged at `87c4daa1830bac5a5228b6036752ad5633232085`; release and tag inventories are empty. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index bdb54c49c..60de88c33 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -91,8 +91,8 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertIn("on 2026-09-05", refresh_line) current = bounded_section( self.baseline, - "### Latest verified cut: 2026-09-06", - "#### Prior observation: 12:28 UTC", + "#### Connection-bound text responses: 14:54 UTC", + "#### Session repair and child adoption: 13:35 UTC", ) queue_counts = re.findall( r"\*\*(\d+) open pull requests: (\d+) Ready/non-draft and (\d+) Draft; " From e7b0f615954d59f8189aa60ad50ea08fb03b3cd0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 00:28:10 +0900 Subject: [PATCH 191/250] test(docs): require current pointer receipt evidence Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- tests/test_product_completion_gap_contract.py | 27 +++++++++++++++++++ 1 file changed, 27 insertions(+) diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index ca34dab42..4e1dd4dc5 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -140,6 +140,33 @@ def test_latest_executable_queue_uses_current_ready_roots(self) -> None: self.assertIn("## Historical next executable queue", text) self.assertNotIn("## Next executable queue", text) + def test_pointer_checkpoint_records_published_receipt_repair(self) -> None: + current = bounded_section( + BASELINE.read_text(encoding="utf-8"), + "##### Pointer receipt follow-up: 15:31 UTC", + "#### Session repair and child adoption: 13:35 UTC", + ) + for marker in ( + "#257 `9451fd8a23dec95b31749376bc78c2eaca977fe8`", + "#258 `5417ce32ed957aa166807f1023647caccc2920cb`", + "8193fcd5", "d9396f05", "588fe731", "0234b587", + "2 → 2 → 1", "34041977863", "34042223733", "queued", + "not product-browser acceptance", "outbound session authority", + "#249", "#250", "descendant adoption", + ): + with self.subTest(marker=marker): + self.assertIn(marker, current) + + def test_historical_text_cannot_supply_missing_pointer_receipt_head(self) -> None: + text = BASELINE.read_text(encoding="utf-8") + marker = "#258 `5417ce32ed957aa166807f1023647caccc2920cb`" + mutated = text.replace(marker, "response head removed", 1) + self.assertNotEqual(mutated, text) + mutated += "\nHistorical evidence: " + marker + with patch.object(pathlib.Path, "read_text", return_value=mutated): + with self.assertRaises(AssertionError): + self.test_pointer_checkpoint_records_published_receipt_repair() + def test_historical_prose_cannot_hide_latest_root_or_lineage_removal(self) -> None: text = BASELINE.read_text(encoding="utf-8") cases = ( From e4a4d474eba0c05179855c576689a47e710fb63b Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 00:29:04 +0900 Subject: [PATCH 192/250] docs: record published pointer receipt repair and remaining gaps Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 43 ++++++++++++++++++- tests/test_product_completion_gap_contract.py | 2 +- 3 files changed, 44 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 29e58f566..d3f653a5f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded the verified pointer-reply connection repair and recovery tests, keeping pending hosted checks, remaining authority gaps and browser acceptance separate. - Recorded the published text-entry connection safeguards and their test evidence, separating queued hosted checks and remaining pointer/status repairs from released browser behavior. - Separate the current maintenance queue and source lineage from preserved historical observations, and record the text-entry session and pending-request safeguards without claiming released browser behavior. - Current delivery inventory: 125 open pull requests (12 ready, 113 draft); 13 open non-PR issues. Observed 2026-09-06; source acceptance remains revision-specific. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index a3f8487e1..01d785e6e 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -44,7 +44,7 @@ presentation evidence, not product-browser acceptance or protected-main delivery Writers `5559965531` and `5559948553` are released. This documentation revision requires its own publication, visual inspection and exact-head checks. -Next source work must address pointer and status receipt provenance in their existing +At the 14:54 checkpoint, next source work was to address pointer and status receipt provenance in their existing owners, plus the separate pointer outbound session-binding gap, before promoting their evidence. Reuse the sealed reader and canonical connection checks; status projection must still validate before correlation consumption. Browser ownership, @@ -54,6 +54,47 @@ foundation #195 `63997bcf555e2c5c8e91ba287734ffba3837a1b7` remains on sandbox boundaries remain prerequisites. Counted approval and central workflow requirements must not be bypassed. Source and documentation writers stay separate. +##### Pointer receipt follow-up: 15:28 UTC + +This later checkpoint supersedes the preceding pointer next-action claim, not the +dated text-entry evidence. Published sender #257 `9451fd8a23dec95b31749376bc78c2eaca977fe8` +remains based on #256 `881c7f09ee9161ce8664dd75226938ecf60b85e5`; published +response owner #258 `5417ce32ed957aa166807f1023647caccc2920cb` adopts that sender +by ordinary merge `0234b587`, preserving the existing hourly writer's test history. + +Executed RED `8193fcd5` accepted a replacement connection's reply. Stronger RED +`d9396f05` held the listener address and session constant and reproduced both foreign +success and error consumption. Consumer-only `588fe731` failed original-response +acceptance with missing sender provenance. The integrated sender registers its +private connection generation before I/O; the consumer validates the existing sealed +receipt before consuming pending work. Six focused tests pass, including exact +foreign-connection mismatch, unchanged pending work and original-reply recovery +with counts **2 → 2 → 1**, extensible success, real remote error, malformed input +and unknown-id retention. No public receipt constructor or raw fallback was added. + +Both source heads passed full local Rust 1.97.1 gates, 142 Python contracts, +compileall, CodeGraph and diff checks. Exact function/line/region/branch coverage is +1093/11134/14204/1214 for #257 and 1100/11191/14276/1214 for #258, each 100%. +Their artifact SHA-256 values are +`a976c273d86d43eef366044cca5b73566064844612a35ba02ac4b7fe59a0969f` and +`ed46b5881d952723eec724a74e6ebb8856a0801e4db0570c9f8a6e6cf04eadb5`. +CI `34041977863` and `34042223733` remain queued; successful advisory statuses +are not counted approval. Actual Edge screenshots verified both published PR +heads, parent boundaries and readable evidence without observed clipping/overlap. +This is GitHub presentation evidence, not product-browser acceptance. Writers +`5560144371` and `5560167022` are released. This baseline update requires its own +publication, rendered inspection and hosted checks; source coverage is not its proof. + +The next source queue is content-aware descendant adoption, separate pointer +outbound session authority, and status receipt provenance. Existing status owners +#249 `84b9407978ae0f6c115f01170b6069c601b21104` and +#250 `7e85a7e5f0147f4b712129cd19aaa3d0a0a54634` precede the shared sealed-receipt +and connection-registration helpers: establish the canonical prerequisites in +dependency order rather than copying a later descendant or creating a cyclic stack. +Status projection must remain validated before state consumption. Browser ownership, +policy approval, same-connection freshness and observed page effects remain unproven; +protected-main approval, central workflows and release gates still apply. + #### Session repair and child adoption: 13:35 UTC This update supersedes the 12:28 source/adoption and visual-boundary claims below. diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 4e1dd4dc5..4b4fa7ba5 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -143,7 +143,7 @@ def test_latest_executable_queue_uses_current_ready_roots(self) -> None: def test_pointer_checkpoint_records_published_receipt_repair(self) -> None: current = bounded_section( BASELINE.read_text(encoding="utf-8"), - "##### Pointer receipt follow-up: 15:31 UTC", + "##### Pointer receipt follow-up: 15:28 UTC", "#### Session repair and child adoption: 13:35 UTC", ) for marker in ( From efe39b8aa6ae277d7d286fd820ec99c1ecf713f0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 00:29:18 +0900 Subject: [PATCH 193/250] test(docs): propagate pointer checkpoint mutation failures Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- tests/test_product_completion_gap_contract.py | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 4b4fa7ba5..b3c6595a0 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -154,8 +154,7 @@ def test_pointer_checkpoint_records_published_receipt_repair(self) -> None: "not product-browser acceptance", "outbound session authority", "#249", "#250", "descendant adoption", ): - with self.subTest(marker=marker): - self.assertIn(marker, current) + self.assertIn(marker, current) def test_historical_text_cannot_supply_missing_pointer_receipt_head(self) -> None: text = BASELINE.read_text(encoding="utf-8") From 591ca38ac4be734a4bfce00fee5ff1ec9b942526 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 01:17:35 +0900 Subject: [PATCH 194/250] test(docs): require current receipt descendant checkpoint Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- tests/test_product_completion_gap_contract.py | 27 +++++++++++++++++++ 1 file changed, 27 insertions(+) diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index b3c6595a0..93bc59fb1 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -166,6 +166,33 @@ def test_historical_text_cannot_supply_missing_pointer_receipt_head(self) -> Non with self.assertRaises(AssertionError): self.test_pointer_checkpoint_records_published_receipt_repair() + def test_descendant_checkpoint_records_exact_receipt_adoptions(self) -> None: + current = bounded_section( + BASELINE.read_text(encoding="utf-8"), + "##### Receipt descendant adoption: 16:17 UTC", + "#### Session repair and child adoption: 13:35 UTC", + ) + for marker in ( + "180c168ecbdcd5eb7a4ad14ab4a53e8670646bf7", + "3807aabeb22f9622610c3c8d504d1c686d25d896", + "ba100fbc39e1ac4f10ee4faade38418551bb8298", + "121578a43adda12221a9ca9ab8ada0a4fd03efef", + "34043222194", "34043664230", "34044193429", "34044857929", + "queued", "144 Python", "subscription response provenance", + "protected-main asset", "not product-browser acceptance", + ): + self.assertIn(marker, current) + + def test_historical_text_cannot_supply_missing_descendant_head(self) -> None: + text = BASELINE.read_text(encoding="utf-8") + marker = "121578a43adda12221a9ca9ab8ada0a4fd03efef" + mutated = text.replace(marker, "subscription head removed", 1) + self.assertNotEqual(mutated, text) + mutated += "\nHistorical evidence: " + marker + with patch.object(pathlib.Path, "read_text", return_value=mutated): + with self.assertRaises(AssertionError): + self.test_descendant_checkpoint_records_exact_receipt_adoptions() + def test_historical_prose_cannot_hide_latest_root_or_lineage_removal(self) -> None: text = BASELINE.read_text(encoding="utf-8") cases = ( From 8f565945c7ecd83de36aae959bdf6b2257871464 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 01:18:17 +0900 Subject: [PATCH 195/250] docs: record verified receipt descendant adoptions Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 42 ++++++++++++++++++++++++++ 2 files changed, 43 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index d3f653a5f..20bffad24 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded verified navigation and subscription adoption of the click-reply repair, distinguishing local checks and rendered evidence from queued hosted acceptance and remaining provenance gaps. - Recorded the verified pointer-reply connection repair and recovery tests, keeping pending hosted checks, remaining authority gaps and browser acceptance separate. - Recorded the published text-entry connection safeguards and their test evidence, separating queued hosted checks and remaining pointer/status repairs from released browser behavior. - Separate the current maintenance queue and source lineage from preserved historical observations, and record the text-entry session and pending-request safeguards without claiming released browser behavior. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 01d785e6e..b1c2e7ba9 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -95,6 +95,48 @@ Status projection must remain validated before state consumption. Browser owners policy approval, same-connection freshness and observed page effects remain unproven; protected-main approval, central workflows and release gates still apply. +##### Receipt descendant adoption: 16:17 UTC + +This checkpoint supersedes the earlier descendant-adoption next action for the +following four owners. They now include the pointer receipt repair by ordinary +parent merges; no history was rewritten and no protected merge occurred. + +| Owner | Published exact head | Parent | Fresh CI | +| --- | --- | --- | --- | +| #259 | `180c168ecbdcd5eb7a4ad14ab4a53e8670646bf7` | #258 `5417ce32` | `34043222194` queued | +| #260 | `3807aabeb22f9622610c3c8d504d1c686d25d896` | #259 `180c168e` | `34043664230` queued | +| #261 | `ba100fbc39e1ac4f10ee4faade38418551bb8298` | #260 `3807aabe` | `34044193429` queued | +| #277 | `121578a43adda12221a9ca9ab8ada0a4fd03efef` | #261 `ba100fbc` | `34044857929` queued | + +Canonical regression replays `6999252e`, `8f6b5a0c`, `c03e0dcc` and `3734a874` +each reproduced a replacement connection consuming an original pending pointer +command. #259's merge also exposed a raw-response fixture compile failure; +`d1fd06bf` adopted the existing sealed reader and retained its returned connection +for the subsequent event. Descendants preserve that repair and the stronger +foreign-success/error rejection with original-response recovery. Their respective +focused suites passed 16, 18, 21 and 23 tests; full local Rust 1.97.1 gates passed. +#259–#261 passed 142 Python contracts each; #277 passed 144 Python contracts. + +Exact numerical function/line/region/branch coverage is +1140/11847/15133/1332, 1154/11975/15318/1334, 1173/12110/15515/1334 and +1222/12821/16447/1418 respectively, each 100%. The unstable branch-instrumentation +warning remains visible. #259's Manifest V3 run `34043222184` is also queued. +Independent read-only reviews found no actionable preservation findings; they are +not counted GitHub approvals. Actual Edge screenshots verified the published PR +evidence, not product-browser acceptance. All four source writers are released. + +Document-epoch, origin-validation and subscription-specific production/tests remain +unchanged. Subscription deadlines still fail before registration; proven no-byte +failures retire only that request, while uncertain writes preserve pending state. +The next bounded source work is subscription response provenance in #277, followed +by content-aware descendant integration. Preserve result projection before state +consumption. Status receipt prerequisites and pointer outbound session authority +remain separate gaps. The protected-main asset-preservation finding also remains: +the active source stack lacks this baseline file, so pairwise CI cannot prove safe +main integration. Browser ownership, event provenance, causality and release gates +remain unfulfilled. This documentation update requires its own checks and visual +inspection; source coverage does not validate the documentation revision. + #### Session repair and child adoption: 13:35 UTC This update supersedes the 12:28 source/adoption and visual-boundary claims below. From 347e0dbc1e4d6a9e5571797967bec980818dd6b6 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 01:37:34 +0900 Subject: [PATCH 196/250] test(docs): require bounded subscription repair evidence Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- tests/test_product_completion_gap_contract.py | 24 +++++++++++++++++++ 1 file changed, 24 insertions(+) diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 93bc59fb1..0546367aa 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -193,6 +193,30 @@ def test_historical_text_cannot_supply_missing_descendant_head(self) -> None: with self.assertRaises(AssertionError): self.test_descendant_checkpoint_records_exact_receipt_adoptions() + def test_subscription_checkpoint_records_verified_repair_and_visual_gap(self) -> None: + current = bounded_section( + BASELINE.read_text(encoding="utf-8"), + "##### Subscription response repair: 16:37 UTC", + "#### Session repair and child adoption: 13:35 UTC", + ) + for marker in ( + "46ae62aa31e35c702cd61c16322d05c7a9c35da1", "122ca139", "8b1508c8", + "0/2", "14 focused", "144 Python", "1222/12824/16453/1418", + "34045953423", "queued", "Mac is locked", "visual inspection remains pending", + "outbound session binding", "protected-main asset", "not product-browser acceptance", + ): + self.assertIn(marker, current) + + def test_historical_text_cannot_supply_missing_subscription_repair_head(self) -> None: + text = BASELINE.read_text(encoding="utf-8") + marker = "46ae62aa31e35c702cd61c16322d05c7a9c35da1" + mutated = text.replace(marker, "subscription repair head removed", 1) + self.assertNotEqual(mutated, text) + mutated += "\nHistorical evidence: " + marker + with patch.object(pathlib.Path, "read_text", return_value=mutated): + with self.assertRaises(AssertionError): + self.test_subscription_checkpoint_records_verified_repair_and_visual_gap() + def test_historical_prose_cannot_hide_latest_root_or_lineage_removal(self) -> None: text = BASELINE.read_text(encoding="utf-8") cases = ( From d9e49c0b7c9a208758c62752ec91e181d1fb309a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 01:38:05 +0900 Subject: [PATCH 197/250] docs(product): record subscription reply provenance checkpoint Commit-Message-Assisted-by: Codex (via Codex) Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 30 ++++++++++++++++++++++++++ 2 files changed, 31 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 20bffad24..65bfa0219 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded the verified subscription-reply connection repair, preserving queued hosted checks, the locked-screen visual-inspection gap and remaining authority and delivery work. - Recorded verified navigation and subscription adoption of the click-reply repair, distinguishing local checks and rendered evidence from queued hosted acceptance and remaining provenance gaps. - Recorded the verified pointer-reply connection repair and recovery tests, keeping pending hosted checks, remaining authority gaps and browser acceptance separate. - Recorded the published text-entry connection safeguards and their test evidence, separating queued hosted checks and remaining pointer/status repairs from released browser behavior. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b1c2e7ba9..8d6936c16 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -137,6 +137,36 @@ main integration. Browser ownership, event provenance, causality and release gat remain unfulfilled. This documentation update requires its own checks and visual inspection; source coverage does not validate the documentation revision. +##### Subscription response repair: 16:37 UTC + +This checkpoint supersedes the subscription response provenance next action above. +#277 is published at `46ae62aa31e35c702cd61c16322d05c7a9c35da1`, with unchanged +#261 parent `ba100fbc39e1ac4f10ee4faade38418551bb8298`. On baseline `122ca139`, +both success and error replies from a second connection to the same listener/session +consumed the original subscription (0/2 regressions passed). Repair `8b1508c8` +reuses private sender registration and the sealed receiving-message consumer; +replacement replies now leave both requests outstanding and the original reply +completes only its own request. Required result projection still precedes state +consumption; deadline and proven no-write safeguards remain unchanged. + +All 14 focused subscription tests, full Rust 1.97.1 gates, 144 Python contracts, +compileall, CodeGraph and diff checks pass locally. Numerical production coverage +is 1222/12824/16453/1418 functions/lines/regions/branches, each 100%; artifact SHA-256 +is `68183d40d92663f604db48342c0eee0428e18836ed008fee1268e6cf14b5d60a`. +The unstable branch-measurement warning remains. Exact-head CI `34045953423` is +queued. Independent source and documentation reviews found no actionable findings; +they are not counted approval. Source writer `5560556181` is released. + +Current-head visual inspection remains pending: the actual browser tool reports +the Mac is locked and automatic unlock failed. Earlier screenshots do not validate +this repair or the present baseline update, and are not product-browser acceptance. +The next safe source queue is canonical outbound session binding, same-connection +freshness, status receipt prerequisites and protected-main asset preservation, +with owner-first dependency integration rather than a cyclic descendant merge. +Navigation-event authenticity and causal page effects remain unproven. No workflow, +approval, protected merge, tag or release changed. This baseline revision requires +its own documentation tests, hosted checks and visual inspection. + #### Session repair and child adoption: 13:35 UTC This update supersedes the 12:28 source/adoption and visual-boundary claims below. From 82b75111ca3c72e9f87146d3610b848c8f7cea4f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 08:27:25 +0900 Subject: [PATCH 198/250] test(docs): bind descendant evidence to current published rows --- ...cumentation_active_pr_evidence_contract.py | 2 +- tests/test_product_completion_gap_contract.py | 41 ++++++++++++++++++- 2 files changed, 41 insertions(+), 2 deletions(-) diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 60de88c33..11b54b0d6 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -91,8 +91,8 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertIn("on 2026-09-05", refresh_line) current = bounded_section( self.baseline, + "#### Published subscription descendants: 23:27 UTC", "#### Connection-bound text responses: 14:54 UTC", - "#### Session repair and child adoption: 13:35 UTC", ) queue_counts = re.findall( r"\*\*(\d+) open pull requests: (\d+) Ready/non-draft and (\d+) Draft; " diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 0546367aa..dd6d0d4e3 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -7,7 +7,7 @@ import unittest from unittest.mock import patch -from test_documentation_active_pr_evidence_contract import bounded_section +from test_documentation_active_pr_evidence_contract import active_pr_row, bounded_section ROOT = pathlib.Path(__file__).resolve().parents[1] BASELINE = ROOT / "docs/product-technical-gap-baseline.md" @@ -207,6 +207,45 @@ def test_subscription_checkpoint_records_verified_repair_and_visual_gap(self) -> ): self.assertIn(marker, current) + def test_published_descendants_bind_evidence_to_current_owner_rows(self) -> None: + current = bounded_section( + BASELINE.read_text(encoding="utf-8"), + "#### Published subscription descendants: 23:27 UTC", + "#### Connection-bound text responses: 14:54 UTC", + ) + for owner, head, parent, coverage in ( + (263, "4868d3e9f19133ac3382ee8532878aef27468893", "46ae62aa", "1244/13053/16729/1422"), + (264, "433957117ad9e29b26715b062f5adcc9789744ba", "4868d3e9", "1282/13461/17140/1440"), + ): + row = active_pr_row(current, owner) + for marker in ("Published; Draft", head, parent, coverage): + self.assertIn(marker, row) + for marker in ( + "zero unresolved review threads", "supersedes the older sole-#147", + "12 Ready candidates remain BLOCKED", "one counted approval", "seven required workflows", + "13 focused", "145 Python", "actual in-app screenshots", "not product-browser acceptance", + "34065055213", "34066516991", "34066516992", "queued", + ".github#1929", "protected-main asset preservation", "own checks and visual inspection", + ): + self.assertIn(marker, current) + + def test_historical_rows_cannot_hide_current_descendant_evidence_changes(self) -> None: + text = BASELINE.read_text(encoding="utf-8") + current = bounded_section( + text, + "#### Published subscription descendants: 23:27 UTC", + "#### Connection-bound text responses: 14:54 UTC", + ) + for owner in (263, 264): + row = active_pr_row(current, owner) + for replacement in ("", row.replace("Published; Draft", "Local only; Draft")): + with self.subTest(owner=owner, replacement=replacement): + mutated = text.replace(row, replacement, 1) + "\nHistorical evidence:\n" + row + self.assertNotEqual(text, mutated) + with patch.object(pathlib.Path, "read_text", return_value=mutated): + with self.assertRaises(AssertionError): + self.test_published_descendants_bind_evidence_to_current_owner_rows() + def test_historical_text_cannot_supply_missing_subscription_repair_head(self) -> None: text = BASELINE.read_text(encoding="utf-8") marker = "46ae62aa31e35c702cd61c16322d05c7a9c35da1" From fb8de504a8543212fc58caa6c5050226709943fd Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 08:29:04 +0900 Subject: [PATCH 199/250] docs: refresh published descendant and visual evidence --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 48 ++++++++++++++++++++++++++ 2 files changed, 49 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 65bfa0219..e994087c0 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded the published subscription descendants and completed visual inspection, correcting the stale unresolved-review count while keeping queued checks, required approval and unreleased browser acceptance distinct. - Recorded the verified subscription-reply connection repair, preserving queued hosted checks, the locked-screen visual-inspection gap and remaining authority and delivery work. - Recorded verified navigation and subscription adoption of the click-reply repair, distinguishing local checks and rendered evidence from queued hosted acceptance and remaining provenance gaps. - Recorded the verified pointer-reply connection repair and recovery tests, keeping pending hosted checks, remaining authority gaps and browser acceptance separate. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 8d6936c16..51aed8408 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -8,6 +8,54 @@ This volatile section is refreshed from live GitHub state and is authoritative o ### Latest verified cut: 2026-09-06 +#### Published subscription descendants: 23:27 UTC + +The complete five-page live inventory contains **125 open pull requests: 12 Ready/non-draft and +113 Draft; 13 open non-PR issues**. It has zero unresolved review threads and no +unfinished review/check/thread pagination. This supersedes the older sole-#147 +thread observation below. All 12 Ready candidates remain BLOCKED. The active ruleset +still requires one counted approval and seven required workflows; only one repository +collaborator is available, so independent reviewer provisioning remains unresolved. +Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`; there are no tags or releases. + +| Owner | Publication | Exact head | Parent | Local functions/lines/regions/branches, all 100% | +| --- | --- | --- | --- | --- | +| #263 | Published; Draft | `4868d3e9f19133ac3382ee8532878aef27468893` | #277 `46ae62aa` | 1244/13053/16729/1422 | +| #264 | Published; Draft | `433957117ad9e29b26715b062f5adcc9789744ba` | #263 `4868d3e9` | 1282/13461/17140/1440 | + +Both owners adopted their parents by ordinary merges after actual replacement-reply +regressions failed. #263 replay `90395f81` failed 0/2, followed by merge `9e85cadc` +and sealed-reader fixture adaptation `cb0c4261`. Its 10 focused tests and full local +Rust 1.97.1 gates passed, alongside 144 Python contracts. #264 replay `637fd97d` +failed 0/2 before merge `92e576c8`; its 13 focused tests, full local Rust 1.97.1 gates +and 145 Python contracts passed. Both passed compileall, CodeGraph and diff checks. +The unchanged pinned coverage verifier passed the counts above; experimental branch +instrumentation remains explicit. Their coverage artifacts have SHA-256 values +`1e51cd7d08ebacc80ecadb568e0bca94384ffc0e1d721237b018cae31daa1336` and +`e102bda45da886bc3138b981dac73f4239e2f6e5cd893688f10ed72b1f5af771`, respectively. + +The child keeps its original browser-state association, increasing request identifiers, +separate raw/typed traffic and consuming subscription-shutdown ownership. Original +replies still complete their own request after a foreign reply is rejected; unrelated +work remains pending. Independent read-only preservation reviews found no actionable +findings, but are not counted GitHub approval. Writers `5562611932` and `5562770321` +are released. CI `34065055213` for #263 and CI `34066516991` plus MV3 `34066516992` +for #264 were queued at the recorded readbacks; predecessor success is not new-head proof. + +Actual visual inspection used actual in-app screenshots of both published exact-head +traceability sections: wrapping and historical/current boundaries were readable without +observed clipping or overlap. This is GitHub presentation evidence, not product-browser acceptance. +Earlier locked-Mac and pending-visual observations remain historical. This new baseline +revision needs its own checks and visual inspection; source coverage does not validate it. + +Central dispatch identity admission remains separately owned by .github#1929 +([verified diagnostics](https://github.com/ContextualWisdomLab/.github/issues/1929#issuecomment-5562597667)); +the documented actor/sender mismatch is not evidence of recovery. Do not change owner +settings or repeat a disproven dispatch route under this documentation task. Next safe +source work is content-aware descendant adoption, pointer outbound authority and status +receipt prerequisites, alongside protected-main asset preservation. Browser authentication, +navigation-event authenticity, causal page effects and release acceptance remain unproven. + #### Connection-bound text responses: 14:54 UTC This checkpoint supersedes the source status and executable actions in the earlier From e7f541d505c8ad0f92ec87b00853e4af0e8c47d7 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 08:30:42 +0900 Subject: [PATCH 200/250] test(docs): require compact linked checkpoint heads --- tests/test_product_completion_gap_contract.py | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index dd6d0d4e3..a46cfe931 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -220,6 +220,10 @@ def test_published_descendants_bind_evidence_to_current_owner_rows(self) -> None row = active_pr_row(current, owner) for marker in ("Published; Draft", head, parent, coverage): self.assertIn(marker, row) + self.assertIn( + f"[`{head[:8]}`](https://github.com/ContextualWisdomLab/OriginWeave/commit/{head})", + row, + ) for marker in ( "zero unresolved review threads", "supersedes the older sole-#147", "12 Ready candidates remain BLOCKED", "one counted approval", "seven required workflows", From e57e9308d40f25a774e1898cd31c4b543d0f1e88 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 08:31:28 +0900 Subject: [PATCH 201/250] docs: keep checkpoint coverage visible beside linked revisions --- CHANGELOG.md | 2 +- docs/product-technical-gap-baseline.md | 8 +++++--- 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index e994087c0..85f2c7315 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,7 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] -- Recorded the published subscription descendants and completed visual inspection, correcting the stale unresolved-review count while keeping queued checks, required approval and unreleased browser acceptance distinct. +- Recorded the published subscription descendants and completed source visual inspection, correcting the stale unresolved-review count while keeping queued checks, required approval and unreleased browser acceptance distinct. Compact linked revisions keep the new evidence table readable without hiding coverage off-screen. - Recorded the verified subscription-reply connection repair, preserving queued hosted checks, the locked-screen visual-inspection gap and remaining authority and delivery work. - Recorded verified navigation and subscription adoption of the click-reply repair, distinguishing local checks and rendered evidence from queued hosted acceptance and remaining provenance gaps. - Recorded the verified pointer-reply connection repair and recovery tests, keeping pending hosted checks, remaining authority gaps and browser acceptance separate. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 51aed8408..7bc4116f8 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -18,10 +18,12 @@ still requires one counted approval and seven required workflows; only one repos collaborator is available, so independent reviewer provisioning remains unresolved. Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`; there are no tags or releases. -| Owner | Publication | Exact head | Parent | Local functions/lines/regions/branches, all 100% | +| Owner | Publication | Exact head | Parent | Local coverage (F/L/R/B) | | --- | --- | --- | --- | --- | -| #263 | Published; Draft | `4868d3e9f19133ac3382ee8532878aef27468893` | #277 `46ae62aa` | 1244/13053/16729/1422 | -| #264 | Published; Draft | `433957117ad9e29b26715b062f5adcc9789744ba` | #263 `4868d3e9` | 1282/13461/17140/1440 | +| #263 | Published; Draft | [`4868d3e9`](https://github.com/ContextualWisdomLab/OriginWeave/commit/4868d3e9f19133ac3382ee8532878aef27468893) | #277 `46ae62aa` | 1244/13053/16729/1422 | +| #264 | Published; Draft | [`43395711`](https://github.com/ContextualWisdomLab/OriginWeave/commit/433957117ad9e29b26715b062f5adcc9789744ba) | #263 `4868d3e9` | 1282/13461/17140/1440 | + +F/L/R/B denotes functions, lines, regions and branches; every metric is 100% covered. Both owners adopted their parents by ordinary merges after actual replacement-reply regressions failed. #263 replay `90395f81` failed 0/2, followed by merge `9e85cadc` From 3ceec7ebdae089802c92bb5570200041c7e16508 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 09:41:27 +0900 Subject: [PATCH 202/250] test(docs): require current published input evidence --- ...cumentation_active_pr_evidence_contract.py | 4 +- tests/test_product_completion_gap_contract.py | 45 ++++++++++++++++++- 2 files changed, 46 insertions(+), 3 deletions(-) diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 11b54b0d6..d02204b73 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -91,8 +91,8 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertIn("on 2026-09-05", refresh_line) current = bounded_section( self.baseline, - "#### Published subscription descendants: 23:27 UTC", - "#### Connection-bound text responses: 14:54 UTC", + "#### Published input descendants: 00:40 UTC", + "### Latest verified cut: 2026-09-06", ) queue_counts = re.findall( r"\*\*(\d+) open pull requests: (\d+) Ready/non-draft and (\d+) Draft; " diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index a46cfe931..87f18a3dc 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -129,7 +129,7 @@ def test_current_snapshot_records_repaired_webdriver_bidi_lineage(self) -> None: def test_latest_executable_queue_uses_current_ready_roots(self) -> None: text = BASELINE.read_text(encoding="utf-8") current = bounded_section( - text, "### Latest verified cut: 2026-09-06", "#### Prior observation: 12:28 UTC" + text, "### Latest verified cut: 2026-09-07", "### Latest verified cut: 2026-09-06" ) roots = [line for line in current.splitlines() if line.startswith("Ready roots:")] self.assertEqual(len(roots), 1) @@ -207,6 +207,49 @@ def test_subscription_checkpoint_records_verified_repair_and_visual_gap(self) -> ): self.assertIn(marker, current) + def test_input_descendants_bind_publication_and_coverage_to_each_owner(self) -> None: + current = bounded_section( + BASELINE.read_text(encoding="utf-8"), + "#### Published input descendants: 00:40 UTC", + "### Latest verified cut: 2026-09-06", + ) + for owner, head, parent, coverage in ( + (265, "e94a2372fe3771f9ddf70291d34fc9a7e4770ec9", "43395711", "1297/13618/17315/1442"), + (266, "e3885f69df2cf3899184209efdee5b11bba1bd86", "e94a2372", "1310/13766/17524/1452"), + (267, "ebd507ae56c3064e3cae5566502f539c20618a8f", "e3885f69", "1318/13852/17610/1456"), + ): + row = active_pr_row(current, owner) + for marker in ("Published; Draft", parent, coverage): + self.assertIn(marker, row) + self.assertIn( + f"[`{head[:8]}`](https://github.com/ContextualWisdomLab/OriginWeave/commit/{head})", + row, + ) + for marker in ( + "e7fb1527", "009f9a41", "4e020e16", "23 focused", "145 Python", + "34068277243", "34068882527", "34070121583", "queued", + "zero unresolved review threads", "one counted approval", "seven required workflows", + "actual screenshots", "not product-browser acceptance", "own checks and visual inspection", + "#268", "protected-main asset preservation", "status receipt", + ): + self.assertIn(marker, current) + + def test_historical_rows_cannot_hide_current_input_evidence_changes(self) -> None: + text = BASELINE.read_text(encoding="utf-8") + current = bounded_section( + text, "#### Published input descendants: 00:40 UTC", + "### Latest verified cut: 2026-09-06", + ) + for owner in (265, 266, 267): + row = active_pr_row(current, owner) + for replacement in ("", row.replace("Published; Draft", "Local only; Draft")): + with self.subTest(owner=owner, replacement=replacement): + mutated = text.replace(row, replacement, 1) + "\nHistorical evidence:\n" + row + self.assertNotEqual(text, mutated) + with patch.object(pathlib.Path, "read_text", return_value=mutated): + with self.assertRaises(AssertionError): + self.test_input_descendants_bind_publication_and_coverage_to_each_owner() + def test_published_descendants_bind_evidence_to_current_owner_rows(self) -> None: current = bounded_section( BASELINE.read_text(encoding="utf-8"), From 9e83af129059aff600bee1a66d74736a1d1f4acf Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 09:42:58 +0900 Subject: [PATCH 203/250] docs: record published input stack verification --- CHANGELOG.md | 3 +- docs/product-technical-gap-baseline.md | 54 ++++++++++++++++++++++++++ 2 files changed, 56 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 85f2c7315..bcac6275c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,13 +4,14 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded published click and text-entry safeguards with their own test, coverage and visual evidence, keeping queued hosted checks and remaining browser outcomes separate from delivery. - Recorded the published subscription descendants and completed source visual inspection, correcting the stale unresolved-review count while keeping queued checks, required approval and unreleased browser acceptance distinct. Compact linked revisions keep the new evidence table readable without hiding coverage off-screen. - Recorded the verified subscription-reply connection repair, preserving queued hosted checks, the locked-screen visual-inspection gap and remaining authority and delivery work. - Recorded verified navigation and subscription adoption of the click-reply repair, distinguishing local checks and rendered evidence from queued hosted acceptance and remaining provenance gaps. - Recorded the verified pointer-reply connection repair and recovery tests, keeping pending hosted checks, remaining authority gaps and browser acceptance separate. - Recorded the published text-entry connection safeguards and their test evidence, separating queued hosted checks and remaining pointer/status repairs from released browser behavior. - Separate the current maintenance queue and source lineage from preserved historical observations, and record the text-entry session and pending-request safeguards without claiming released browser behavior. -- Current delivery inventory: 125 open pull requests (12 ready, 113 draft); 13 open non-PR issues. Observed 2026-09-06; source acceptance remains revision-specific. +- Current delivery inventory: 125 open pull requests (12 ready, 113 draft); 13 open non-PR issues. Observed 2026-09-07; source acceptance remains revision-specific. - Corrected historical checkpoint labels and made the current inventory check reject stale counts; recorded verified text-input parent adoption without claiming browser execution. - Recorded the executed session-isolation repair and its verified adoption, separating complete local checks and PR visual inspection from pending hosted checks and unreleased browser acceptance. - Recorded the current click safeguards, restored regression coverage and completed PR visual inspection, keeping the separately owned parent repair and queued hosted checks distinct from delivery. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 7bc4116f8..14f93d9f9 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,6 +6,60 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. +### Latest verified cut: 2026-09-07 + +#### Published input descendants: 00:40 UTC + +The latest complete five-page review/check/thread inventory contains **125 open pull requests: +12 Ready/non-draft and 113 Draft; 13 open non-PR issues**, with zero unresolved review threads +and no unfinished pagination. All 12 Ready candidates remain BLOCKED. Current rules require +one counted approval and seven required workflows; the sole collaborator is the author. +Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`, with no tags or releases. +REST release inventory was rate-limited; GraphQL independently confirmed both empty inventories. + +Ready roots: #37, #50, #166, #219, #220, #229, #238, #240, #272, #274, #285, #287. + +| Owner | Publication | Exact head | Parent | Local coverage (F/L/R/B) | +| --- | --- | --- | --- | --- | +| #265 | Published; Draft | [`e94a2372`](https://github.com/ContextualWisdomLab/OriginWeave/commit/e94a2372fe3771f9ddf70291d34fc9a7e4770ec9) | #264 `43395711` | 1297/13618/17315/1442 | +| #266 | Published; Draft | [`e3885f69`](https://github.com/ContextualWisdomLab/OriginWeave/commit/e3885f69df2cf3899184209efdee5b11bba1bd86) | #265 `e94a2372` | 1310/13766/17524/1452 | +| #267 | Published; Draft | [`ebd507ae`](https://github.com/ContextualWisdomLab/OriginWeave/commit/ebd507ae56c3064e3cae5566502f539c20618a8f) | #266 `e3885f69` | 1318/13852/17610/1456 | + +Functions, lines, regions and branches are each 100% covered on these exact local source trees. +#265 replay `e7fb1527` first failed both replacement-reply tests before ordinary merge +`d847b530`. The contributor's existing outbound-session guard remains intact. #266 replay +`009f9a41` and #267 replay `4e020e16` each failed all three inherited pointer regressions +before ordinary merges `d9503b30` and `7e4bd76d`. The repaired click path rejects a foreign +session before reserving or sending work, and rejects replacement success/error replies +without consuming either pending request. The original reply completes only its own request. + +#265 passed 14 focused tests; #266 passed 21; #267 passed 23 focused tests. Each exact head +passed full local Rust 1.97.1 gates, 145 Python contracts, compileall, CodeGraph and diff checks. +The text constructor, privacy checks and eight core text tests were preserved in #266. +#267 also preserves its existing text sender, public exports and ten text-send tests unchanged. +Coverage artifact SHA-256 values for #265, #266 and #267, respectively, are +`fc9aebce5e633be1c4faa10755e56bb792a0f2679daeef3a0a1984d4a4b58404`, +`a06aebb7c2f30c153c3a3867f3b7847d9c485ae2db5ba2b23029ca0375e4ec79` and +`8bd32ad83ba5f9ef65bad8a3503f5e6cff38335b8526bff9f974bd6ee7fabceb`. +The pinned nightly branch-instrumentation warning remains explicit; no coverage gate changed. + +Native CI `34068277243`, `34068882527` and `34070121583` remains queued for those three heads; +#265/#266 MV3 runs `34068277244` and `34068882439` are also queued. Independent read-only +preservation reviews found no actionable findings, but are not counted approval. Source writer +leases `5563064004`, `5563186050` and `5563277731` are released. Actual visual inspection +used actual screenshots of published exact-head evidence: in-app for #265/#266 and isolated +installed Edge for #267 after browser-control connection failures. Revisions, caveats and +wrapping were readable without observed clipping or overlap. This is GitHub presentation, +not product-browser acceptance. This baseline needs its own checks and visual inspection. + +Next source work is #268's content-aware adoption of #267, retaining its existing sealed +text-response consumer rather than rebuilding it. Then continue status receipt prerequisites +and protected-main asset preservation at their canonical owners. #195/#279 workflow recovery, +#212 sandboxed browser acceptance and .github#1929 dispatch identity admission remain separate. +Text transport and pointer acknowledgments do not prove field values, browser authentication, +policy approval, navigation causality or release acceptance. Earlier dated observations below +remain unchanged historical evidence and do not override this checkpoint. + ### Latest verified cut: 2026-09-06 #### Published subscription descendants: 23:27 UTC From 1a906869686c1c833691e25832151f590cee0d3f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 10:42:56 +0900 Subject: [PATCH 204/250] test(docs): bind published response and observation evidence --- tests/test_product_completion_gap_contract.py | 28 +++++++++++++++++++ 1 file changed, 28 insertions(+) diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 87f18a3dc..d554eba34 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -207,6 +207,34 @@ def test_subscription_checkpoint_records_verified_repair_and_visual_gap(self) -> ): self.assertIn(marker, current) + def test_response_observation_checkpoint_binds_each_published_owner(self) -> None: + current = bounded_section( + BASELINE.read_text(encoding="utf-8"), + "#### Published response and observation: 01:45 UTC", + "#### Published input descendants: 00:40 UTC", + ) + for owner, head, parent, coverage in ( + (268, "ff27220cb5eb4d11ca1dc5614a4181e1a397a3f1", "ebd507ae", "1325/13907/17682/1456"), + (269, "3df2a631bacd7109b3982fdd7ac599d0bd92a589", "ff27220c", "1338/14025/17843/1460"), + ): + row = active_pr_row(current, owner) + for marker in ("Published; Draft", parent, coverage): + self.assertIn(marker, row) + self.assertIn(f"[`{head[:8]}`](https://github.com/ContextualWisdomLab/OriginWeave/commit/{head})", row) + for marker in ("658fb676", "49d18f5f", "147 Python", "34072645796", "34073733364", "34073733355", "queued", "actual visual inspection", "not product-browser acceptance", "#270"): + self.assertIn(marker, current) + + def test_historical_rows_cannot_replace_response_observation_checkpoint(self) -> None: + text = BASELINE.read_text(encoding="utf-8") + current = bounded_section(text, "#### Published response and observation: 01:45 UTC", "#### Published input descendants: 00:40 UTC") + for owner in (268, 269): + row = active_pr_row(current, owner) + for replacement in ("", row.replace("Published; Draft", "Local only; Draft")): + mutated = text.replace(row, replacement, 1) + "\nHistorical evidence:\n" + row + with patch.object(pathlib.Path, "read_text", return_value=mutated): + with self.assertRaises(AssertionError): + self.test_response_observation_checkpoint_binds_each_published_owner() + def test_input_descendants_bind_publication_and_coverage_to_each_owner(self) -> None: current = bounded_section( BASELINE.read_text(encoding="utf-8"), From 8d963285fcacdda2092f4f893c8e21106797f4ff Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 10:43:46 +0900 Subject: [PATCH 205/250] docs: record published response and observation checkpoint --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 43 ++++++++++++++++++++++++++ 2 files changed, 44 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index bcac6275c..09fd467b8 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded published text-response and fixed-observation progress with separate local, hosted and visual evidence; browser outcome verification remains unfinished. - Recorded published click and text-entry safeguards with their own test, coverage and visual evidence, keeping queued hosted checks and remaining browser outcomes separate from delivery. - Recorded the published subscription descendants and completed source visual inspection, correcting the stale unresolved-review count while keeping queued checks, required approval and unreleased browser acceptance distinct. Compact linked revisions keep the new evidence table readable without hiding coverage off-screen. - Recorded the verified subscription-reply connection repair, preserving queued hosted checks, the locked-screen visual-inspection gap and remaining authority and delivery work. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 14f93d9f9..05857488f 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -8,6 +8,49 @@ This volatile section is refreshed from live GitHub state and is authoritative o ### Latest verified cut: 2026-09-07 +#### Published response and observation: 01:45 UTC + +The fresh five-page inventory still contains **125 open PRs: 12 Ready and 113 Draft**, +13 open issues and zero unresolved review threads. All Ready candidates remain BLOCKED. +Main remains `87c4daa1830bac5a5228b6036752ad5633232085`; there are no tags or releases. +Active ruleset `18156473` requires one counted approval and seven central workflows; +the sole collaborator is the author. No advisory review is counted as that approval. + +| Owner | Publication | Exact head | Parent | Local coverage (F/L/R/B) | +| --- | --- | --- | --- | --- | +| #268 | Published; Draft | [`ff27220c`](https://github.com/ContextualWisdomLab/OriginWeave/commit/ff27220cb5eb4d11ca1dc5614a4181e1a397a3f1) | #267 `ebd507ae` | 1325/13907/17682/1456 | +| #269 | Published; Draft | [`3df2a631`](https://github.com/ContextualWisdomLab/OriginWeave/commit/3df2a631bacd7109b3982fdd7ac599d0bd92a589) | #268 `ff27220c` | 1338/14025/17843/1460 | + +Each dimension is 100% covered locally. #268's actual RED `716fd842` reproduced three +pointer/session failures before ordinary parent adoption. The sealed text consumer and +all original text tests were preserved. Review exposed an unqualified historical limitation; +RED `49d18f5f` reproduced it, and the correction anchors it to predecessor `35cb1197`. +#269's RED `658fb676` reproduced dispatch to the wrong browser session before ordinary +merge `f883fd6f`. Its fixed field-observation command and all eight child tests remain +byte-identical to the predecessor; the entire network crate matches its parent. + +#268 passed 20 focused tests and 146 Python contracts; #269 passed 18 focused tests and +147 Python contracts. Both passed complete local Rust 1.97.1 gates, compileall, CodeGraph +and diff checks. Coverage artifact SHA-256 values are respectively +`bce553c93d5b5dd3cb59c78bbb75c9f1225b659ec7ea22b674c54455e5067a07` and +`1e203e6c0801bedbbcdbeb1be500b533a3d68e0ac842de221f7f470c5e742c66`. +The pinned nightly branch-instrumentation warning remains visible. + +Exact-head native CI `34072645796` and `34073733364`, and #269 MV3 `34073733355`, +are queued, not passing evidence. Independent read-only reviews found no remaining +actionable findings. Source leases `5563501468` and `5563726066` are released. +Both published PRs and dated dossiers received actual visual inspection in isolated Edge: +revision links, current/historical separation and text were readable without visible +clipping or overlap. This is GitHub documentation presentation, not product-browser acceptance. +This baseline requires its own exact-head tests and visual inspection. + +Next is #270's content-aware adoption of #269, followed by response/value verification, +status receipts and protected-foundation work. Request construction and protocol replies +still do not prove field changes, authenticated browser ownership, policy approval or +authorized action success. #195/#279 workflow recovery, #212 sandbox acceptance and +.github#1929 dispatch identity admission retain their separate owners. Earlier checkpoints +below remain unchanged historical observations, including their superseded next actions. + #### Published input descendants: 00:40 UTC The latest complete five-page review/check/thread inventory contains **125 open pull requests: From 0ea2aaf72bd6a33564bd6a60cecd209ed184149d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 10:44:19 +0900 Subject: [PATCH 206/250] fix(docs): validate newest inventory instead of historical counts --- docs/product-technical-gap-baseline.md | 5 +++-- tests/test_documentation_active_pr_evidence_contract.py | 2 +- 2 files changed, 4 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 05857488f..aaa544bd0 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -10,8 +10,9 @@ This volatile section is refreshed from live GitHub state and is authoritative o #### Published response and observation: 01:45 UTC -The fresh five-page inventory still contains **125 open PRs: 12 Ready and 113 Draft**, -13 open issues and zero unresolved review threads. All Ready candidates remain BLOCKED. +The fresh five-page inventory still contains **125 open pull requests: 12 Ready/non-draft +and 113 Draft; 13 open non-PR issues**, with zero unresolved review threads. +All Ready candidates remain BLOCKED. Main remains `87c4daa1830bac5a5228b6036752ad5633232085`; there are no tags or releases. Active ruleset `18156473` requires one counted approval and seven central workflows; the sole collaborator is the author. No advisory review is counted as that approval. diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index d02204b73..7d55a9fea 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -91,8 +91,8 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertIn("on 2026-09-05", refresh_line) current = bounded_section( self.baseline, + "#### Published response and observation: 01:45 UTC", "#### Published input descendants: 00:40 UTC", - "### Latest verified cut: 2026-09-06", ) queue_counts = re.findall( r"\*\*(\d+) open pull requests: (\d+) Ready/non-draft and (\d+) Draft; " From 30bc34b8ab625a9f6a448c1d47e6e49cc04e69c4 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 10:48:18 +0900 Subject: [PATCH 207/250] test(docs): require ready roster in newest checkpoint --- tests/test_product_completion_gap_contract.py | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index d554eba34..ead09be9a 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -129,7 +129,8 @@ def test_current_snapshot_records_repaired_webdriver_bidi_lineage(self) -> None: def test_latest_executable_queue_uses_current_ready_roots(self) -> None: text = BASELINE.read_text(encoding="utf-8") current = bounded_section( - text, "### Latest verified cut: 2026-09-07", "### Latest verified cut: 2026-09-06" + text, "#### Published response and observation: 01:45 UTC", + "#### Published input descendants: 00:40 UTC", ) roots = [line for line in current.splitlines() if line.startswith("Ready roots:")] self.assertEqual(len(roots), 1) From 4ac48306d4cf59a4a882a147748748220bb8e8dc Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 10:48:39 +0900 Subject: [PATCH 208/250] docs: reaffirm current ready roster without historical fallback --- docs/product-technical-gap-baseline.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index aaa544bd0..daddf6e2d 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -17,6 +17,8 @@ Main remains `87c4daa1830bac5a5228b6036752ad5633232085`; there are no tags or re Active ruleset `18156473` requires one counted approval and seven central workflows; the sole collaborator is the author. No advisory review is counted as that approval. +Ready roots: #37, #50, #166, #219, #220, #229, #238, #240, #272, #274, #285, #287. + | Owner | Publication | Exact head | Parent | Local coverage (F/L/R/B) | | --- | --- | --- | --- | --- | | #268 | Published; Draft | [`ff27220c`](https://github.com/ContextualWisdomLab/OriginWeave/commit/ff27220cb5eb4d11ca1dc5614a4181e1a397a3f1) | #267 `ebd507ae` | 1325/13907/17682/1456 | From 0751ea1e7d8685f65c2699311b20e6f97e10f153 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 12:00:12 +0900 Subject: [PATCH 209/250] test(docs): require published observation safeguard evidence --- ...cumentation_active_pr_evidence_contract.py | 2 +- tests/test_product_completion_gap_contract.py | 35 +++++++++++++++++-- 2 files changed, 34 insertions(+), 3 deletions(-) diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 7d55a9fea..a72ff84f9 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -91,8 +91,8 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertIn("on 2026-09-05", refresh_line) current = bounded_section( self.baseline, + "#### Published observation safeguards: 03:00 UTC", "#### Published response and observation: 01:45 UTC", - "#### Published input descendants: 00:40 UTC", ) queue_counts = re.findall( r"\*\*(\d+) open pull requests: (\d+) Ready/non-draft and (\d+) Draft; " diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index ead09be9a..428734138 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -129,8 +129,8 @@ def test_current_snapshot_records_repaired_webdriver_bidi_lineage(self) -> None: def test_latest_executable_queue_uses_current_ready_roots(self) -> None: text = BASELINE.read_text(encoding="utf-8") current = bounded_section( - text, "#### Published response and observation: 01:45 UTC", - "#### Published input descendants: 00:40 UTC", + text, "#### Published observation safeguards: 03:00 UTC", + "#### Published response and observation: 01:45 UTC", ) roots = [line for line in current.splitlines() if line.startswith("Ready roots:")] self.assertEqual(len(roots), 1) @@ -208,6 +208,37 @@ def test_subscription_checkpoint_records_verified_repair_and_visual_gap(self) -> ): self.assertIn(marker, current) + def test_observation_safeguards_bind_each_published_owner(self) -> None: + current = bounded_section( + BASELINE.read_text(encoding="utf-8"), + "#### Published observation safeguards: 03:00 UTC", + "#### Published response and observation: 01:45 UTC", + ) + for owner, head, parent, coverage in ( + (270, "8eda96915dbbe4cc617f834267c7464689c2844d", "3df2a631", "1346/14113/17928/1464"), + (271, "b0410ae92bd20eaf31d09b7d49390e13cb045999", "8eda9691", "1393/14770/18899/1546"), + ): + row = active_pr_row(current, owner) + for marker in ("Published; Draft", parent, coverage, f"/commit/{head}"): + self.assertIn(marker, row) + for marker in ( + "29cd0d66", "14efb678", "148 Python", "34076117534", "34077987302", + "queued", "actual visual inspection", "not product-browser acceptance", + "original connection", "status receipts", "#195/#279", + ): + self.assertIn(marker, current) + + def test_historical_rows_cannot_replace_observation_safeguards(self) -> None: + text = BASELINE.read_text(encoding="utf-8") + current = bounded_section(text, "#### Published observation safeguards: 03:00 UTC", "#### Published response and observation: 01:45 UTC") + for owner in (270, 271): + row = active_pr_row(current, owner) + for replacement in ("", row.replace("Published; Draft", "Local only; Draft")): + mutated = text.replace(row, replacement, 1) + "\nHistorical evidence:\n" + row + with patch.object(pathlib.Path, "read_text", return_value=mutated): + with self.assertRaises(AssertionError): + self.test_observation_safeguards_bind_each_published_owner() + def test_response_observation_checkpoint_binds_each_published_owner(self) -> None: current = bounded_section( BASELINE.read_text(encoding="utf-8"), From e81bd58bbf6a8cea8f373cc55738817f99225349 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 12:00:49 +0900 Subject: [PATCH 210/250] docs: record published observation safeguards and recovery --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 44 ++++++++++++++++++++++++++ 2 files changed, 45 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 09fd467b8..62ebdfd93 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded published observation safeguards and original-connection recovery with separate local, queued hosted and visual evidence; full browser acceptance remains unfinished. - Recorded published text-response and fixed-observation progress with separate local, hosted and visual evidence; browser outcome verification remains unfinished. - Recorded published click and text-entry safeguards with their own test, coverage and visual evidence, keeping queued hosted checks and remaining browser outcomes separate from delivery. - Recorded the published subscription descendants and completed source visual inspection, correcting the stale unresolved-review count while keeping queued checks, required approval and unreleased browser acceptance distinct. Compact linked revisions keep the new evidence table readable without hiding coverage off-screen. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index daddf6e2d..c0f8599d7 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -8,6 +8,50 @@ This volatile section is refreshed from live GitHub state and is authoritative o ### Latest verified cut: 2026-09-07 +#### Published observation safeguards: 03:00 UTC + +The complete five-page inventory contains **125 open pull requests: 12 Ready/non-draft +and 113 Draft; 13 open non-PR issues**, with zero unresolved review threads and no +pagination gaps. All Ready candidates remain BLOCKED. Protected main remains +`87c4daa1830bac5a5228b6036752ad5633232085`; no tags or releases exist. +Active ruleset `18156473` requires one counted approval and seven central workflows; +the sole collaborator is the author. Advisory review does not satisfy that approval. + +Ready roots: #37, #50, #166, #219, #220, #229, #238, #240, #272, #274, #285, #287. + +| Owner | Publication | Exact head | Parent | Local coverage (F/L/R/B) | +| --- | --- | --- | --- | --- | +| #270 | Published; Draft | [`8eda9691`](https://github.com/ContextualWisdomLab/OriginWeave/commit/8eda96915dbbe4cc617f834267c7464689c2844d) | #269 `3df2a631` | 1346/14113/17928/1464 | +| #271 | Published; Draft | [`b0410ae9`](https://github.com/ContextualWisdomLab/OriginWeave/commit/b0410ae92bd20eaf31d09b7d49390e13cb045999) | #270 `8eda9691` | 1393/14770/18899/1546 | + +Every listed coverage dimension is 100% locally. #270 repaired wrong-session dispatch, +invalid deadlines and reused masking keys through existing transport guards, preserving +the fixed observation command and ordinary parent history. Its 11 focused tests, +147 Python contracts and complete stable Rust gates passed. Coverage artifact SHA-256: +`7748d42c541140314995ffa2087b3aca87d52875f98a6ffa36614a0453b30260`. + +#271 reproduced replacement-connection completion at RED `29cd0d66`, still failing after +parent adoption `14efb678`. The existing sealed receipt and connection-aware correlation +now reject foreign success, protocol error and script exception. A same-listener test +proves the original connection can still complete its command, leaving unrelated work +pending. Earlier fixture compile errors are not runtime RED evidence. All 148 Python +contracts, focused recovery tests and complete stable Rust gates passed. Coverage SHA-256: +`8f211170f9e7b691b95b12151e9e87827e4cb741ca8fa2892576adf8421e8a30`. + +Exact-head native CI `34076117534` and `34077987302` remain queued, not passing evidence. +Independent read-only review found no remaining actionable findings; it is not counted +approval. Source leases `5563898819` and `5564211278` are released. Both revisions received +actual visual inspection in isolated Edge: generated API documentation and published +commit views were readable without observed clipping or overlap. This is documentation +presentation, not product-browser acceptance. This baseline needs its own verification +and visual inspection; it cannot inherit source coverage or hosted acceptance. + +Next are downstream semantic-action adoption, status receipts and protected-foundation +work. Matching text replies do not establish authenticated browser ownership, policy +approval or complete authorized action success. #195/#279 workflow recovery and #212 +sandbox acceptance retain their separate owners. Earlier checkpoints below are unchanged +historical observations, including superseded next actions; no release is claimed. + #### Published response and observation: 01:45 UTC The fresh five-page inventory still contains **125 open pull requests: 12 Ready/non-draft From cb1d7f2cf12116ef3d929314b688afdc29af386f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 13:00:36 +0900 Subject: [PATCH 211/250] test(docs): require verified maintenance lessons Co-Authored-By: OpenAI Codex Signed-off-by: Seongho Bae --- tests/test_agent_maintenance_lessons.py | 28 +++++++++++++++++++++++++ 1 file changed, 28 insertions(+) create mode 100644 tests/test_agent_maintenance_lessons.py diff --git a/tests/test_agent_maintenance_lessons.py b/tests/test_agent_maintenance_lessons.py new file mode 100644 index 000000000..634fe9329 --- /dev/null +++ b/tests/test_agent_maintenance_lessons.py @@ -0,0 +1,28 @@ +"""Keep verified maintenance lessons discoverable without relaxing release gates.""" + +from pathlib import Path +import unittest + + +class AgentMaintenanceLessonsTests(unittest.TestCase): + def test_verification_lessons_remain_actionable(self) -> None: + text = (Path(__file__).resolve().parents[1] / "AGENTS.md").read_text() + for instruction in ( + "## Verified maintenance lessons", + "Resume the existing process", + "cargo doc --workspace", + "open the link destinations", + "original connection can still complete", + ): + with self.subTest(instruction=instruction): + self.assertIn(instruction, text) + + def test_publishing_credentials_do_not_override_release_readiness(self) -> None: + text = (Path(__file__).resolve().parents[1] / "AGENTS.md").read_text() + self.assertIn("Secret availability is not release readiness", text) + self.assertIn("Do not remove `publish = false` merely to make a publish command succeed", text) + self.assertIn("an explicit version decision", text) + + +if __name__ == "__main__": + unittest.main() From de06d65e983da4fb24fc9dd4115fb69c173928dd Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 13:01:06 +0900 Subject: [PATCH 212/250] docs: retain verified maintenance and publishing lessons Co-Authored-By: OpenAI Codex Signed-off-by: Seongho Bae --- AGENTS.md | 16 ++++++++++++++++ CHANGELOG.md | 2 ++ 2 files changed, 18 insertions(+) diff --git a/AGENTS.md b/AGENTS.md index 6f747c38e..f13e5122e 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -116,3 +116,19 @@ A skipped security, GPU, browser, TLS, or statistical test is not passing eviden ## Release contract A release requires all current-head checks, complete coverage and docs, updated `CHANGELOG.md`, SBOM and provenance, reproducible artifacts, compatibility evidence, security review, and an explicit version decision. Pre-alpha commits are not releases. + +## Package Manager + +- Use the pinned Rust toolchain and Cargo workspace with the checked-in `Cargo.lock`; use `--locked` for release verification. + +## Commit Attribution + +- AI-assisted commits include `Co-Authored-By` with the actual agent identity; never attribute work to an agent that did not contribute. + +## Verified maintenance lessons + +- Add concise, reproducible lessons here as work establishes them. Keep transient heads, job IDs and incident snapshots in PR evidence, not permanent instructions; never record secret values. +- Resume the existing process after a tool observation timeout; inspect its terminal status and logs before starting another copy. A timeout waiting for output is not a failed test. +- For rustdoc visual inspection, use `RUSTDOCFLAGS='-D warnings' cargo doc --workspace` when `--no-deps` leaves cross-crate references unlinked. Inspect the actual rendered page and open the link destinations before claiming success; do not patch valid source links to hide a build artifact. +- In parent adoption, preserve the child's behavior and tests, and compare inherited security boundaries against the exact parent. A rejected replacement reply must preserve pending work and prove that the original connection can still complete its own request. +- Secret availability is not release readiness. Verify the intended package, registry, version, protected revision and release evidence before publishing. Inspect only secret metadata; an empty repository list does not prove organization or environment secrets are absent. Do not remove `publish = false` merely to make a publish command succeed. diff --git a/CHANGELOG.md b/CHANGELOG.md index 62ebdfd93..e12a5bff7 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,8 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Record verified maintenance lessons for resumable checks, rendered documentation links, parent-preserving repairs and release-readiness checks without exposing credentials. + - Recorded published observation safeguards and original-connection recovery with separate local, queued hosted and visual evidence; full browser acceptance remains unfinished. - Recorded published text-response and fixed-observation progress with separate local, hosted and visual evidence; browser outcome verification remains unfinished. - Recorded published click and text-entry safeguards with their own test, coverage and visual evidence, keeping queued hosted checks and remaining browser outcomes separate from delivery. From 4a71692bfa6af555eabb51c633e258d9582c7ca5 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 13:11:13 +0900 Subject: [PATCH 213/250] test(docs): require current action adoption checkpoint Co-Authored-By: OpenAI Codex Signed-off-by: Seongho Bae --- tests/test_product_completion_gap_contract.py | 32 +++++++++++++++++++ 1 file changed, 32 insertions(+) diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 428734138..2d3937afc 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -228,6 +228,38 @@ def test_observation_safeguards_bind_each_published_owner(self) -> None: ): self.assertIn(marker, current) + def test_action_adoption_checkpoint_binds_published_owners(self) -> None: + current = bounded_section( + BASELINE.read_text(encoding="utf-8"), + "#### Published semantic-action adoption: 04:15 UTC", + "#### Published observation safeguards: 03:00 UTC", + ) + for owner, head, parent, coverage in ( + (93, "82056d13aa94c106060b84ee76be56fcb7787fc8", "b0410ae9", "1403/14852/18976/1552"), + (95, "6b29d890245ed2f612c2998198f4e8c8a06da312", "82056d13", "1408/14897/19022/1552"), + (96, "cbabf55c6a25b979fa0d9e3c1677338665975ab7", "6b29d890", "1410/14908/19030/1552"), + ): + row = active_pr_row(current, owner) + for marker in ("Published; Draft", parent, coverage, f"/commit/{head}"): + self.assertIn(marker, row) + for marker in ( + "34079739018", "34080772063", "34081979602", "queued", + "actual visual inspection", "not product-browser acceptance", + "original connection", "status receipts", "publish = false", + ): + self.assertIn(marker, current) + + def test_historical_rows_cannot_replace_action_adoption(self) -> None: + text = BASELINE.read_text(encoding="utf-8") + current = bounded_section(text, "#### Published semantic-action adoption: 04:15 UTC", "#### Published observation safeguards: 03:00 UTC") + for owner in (93, 95, 96): + row = active_pr_row(current, owner) + for replacement in ("", row.replace("Published; Draft", "Local only; Draft")): + mutated = text.replace(row, replacement, 1) + "\nHistorical evidence:\n" + row + with patch.object(pathlib.Path, "read_text", return_value=mutated): + with self.assertRaises(AssertionError): + self.test_action_adoption_checkpoint_binds_published_owners() + def test_historical_rows_cannot_replace_observation_safeguards(self) -> None: text = BASELINE.read_text(encoding="utf-8") current = bounded_section(text, "#### Published observation safeguards: 03:00 UTC", "#### Published response and observation: 01:45 UTC") From c73fdbd67193e58368b3113b0fd1030a29266fd6 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 13:12:49 +0900 Subject: [PATCH 214/250] docs: record published semantic action adoption evidence Co-Authored-By: OpenAI Codex Signed-off-by: Seongho Bae --- CHANGELOG.md | 2 + docs/product-technical-gap-baseline.md | 54 +++++++++++++++++++ ...cumentation_active_pr_evidence_contract.py | 2 +- tests/test_product_completion_gap_contract.py | 8 +-- 4 files changed, 61 insertions(+), 5 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index e12a5bff7..a2ff9bd31 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,8 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Record the published semantic-action adoption stack and its local verification, visual evidence and unmet release prerequisites without treating open pull requests as shipped behavior. + - Record verified maintenance lessons for resumable checks, rendered documentation links, parent-preserving repairs and release-readiness checks without exposing credentials. - Recorded published observation safeguards and original-connection recovery with separate local, queued hosted and visual evidence; full browser acceptance remains unfinished. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index c0f8599d7..26502f74d 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -8,6 +8,60 @@ This volatile section is refreshed from live GitHub state and is authoritative o ### Latest verified cut: 2026-09-07 +#### Published semantic-action adoption: 04:11 UTC + +The five-page inventory contains **125 open pull requests: 12 Ready/non-draft +and 113 Draft; 13 open non-PR issues**, with zero unresolved review threads and no +pagination gaps. All Ready candidates remain BLOCKED. Protected main remains +`87c4daa1830bac5a5228b6036752ad5633232085`; no tags or releases exist. +Active ruleset `18156473` still requires one counted approval and seven central +workflows; the only listed collaborator is the author. Advisory review is not approval. + +Ready roots: #37, #50, #166, #219, #220, #229, #238, #240, #272, #274, #285, #287. + +| Owner | Publication | Exact head | Parent | Local coverage (F/L/R/B) | +| --- | --- | --- | --- | --- | +| #93 | Published; Draft | [`82056d13`](https://github.com/ContextualWisdomLab/OriginWeave/commit/82056d13aa94c106060b84ee76be56fcb7787fc8) | #271 `b0410ae9` | 1403/14852/18976/1552 | +| #95 | Published; Draft | [`6b29d890`](https://github.com/ContextualWisdomLab/OriginWeave/commit/6b29d890245ed2f612c2998198f4e8c8a06da312) | #93 `82056d13` | 1408/14897/19022/1552 | +| #96 | Published; Draft | [`cbabf55c`](https://github.com/ContextualWisdomLab/OriginWeave/commit/cbabf55c6a25b979fa0d9e3c1677338665975ab7) | #95 `6b29d890` | 1410/14908/19030/1552 | + +Each listed coverage dimension is 100% locally. These ordinary parent adoptions retain +node-action binding, explicit policy allow and dispatch-time node validation while +inheriting connection-bound reply rejection. The original connection can still complete +its own pending request; unrelated pending work survives. The child implementations +and original tests were preserved. Node authority, policy decisions, callback execution +and reply provenance remain separate checks, not proof of the requested browser outcome. + +#93 passed 10 focused Rust tests and 149 Python contracts; #95 passed eight focused tests +and 150 Python contracts; #96 passed six focused tests and 151 Python contracts. Complete +local Rust gates passed. #93's final Python/Markdown-only correction preserved the entire +measured Rust tree and manifests. Coverage artifact SHA-256 values, in owner order: +`9479014b94c1575a379d31fea09309deaf00143374b6dd6f04a539aaf452a685`, +`666797dec8486f0f196616525303bd24dc52ef5d035f1c548e1bddde3fb48a22`, +`f69829e1968a75c8d3c8ea7d08df87669d47a7d6adfbbb88d08d9bb0d384b10d`. + +Exact-head CI `34079739018`, `34080772063` and `34081979602` remain queued. +#93's MV3 run `34079739021` is also queued. Independent read-only review found no +remaining actionable findings; it is not counted approval. Source leases are released. +All three revisions received actual visual inspection in isolated Edge, with readable +API documentation and no observed clipping or overlap. Dependency-inclusive workspace +rustdoc restored cross-crate links omitted by the no-dependencies build. This is +documentation presentation, not product-browser acceptance. + +The user-requested `AGENTS.md` lessons were published at `de06d65e` with 197 Python +contracts and their own rendered visual inspection. Automatic package publishing was +checked but not attempted: protected main's core manifest has `publish = false`, no +publishing workflow or Python package manifest is present, and the release contract +still requires its evidence and an explicit version decision. Repository/environment +secret metadata lists were empty; organization-secret listing returned 403, so those +keys remain unverified, not proven absent. No secret values were accessed. + +Next are status receipts, protected-foundation work and release-readiness evidence. +#195/#279 workflow recovery and #212 sandbox acceptance retain their separate owners. +This baseline requires its own exact-head verification and visual inspection; it cannot +inherit source coverage or hosted acceptance. Earlier checkpoints below are unchanged +historical observations. No merge, package publication or release is claimed. + #### Published observation safeguards: 03:00 UTC The complete five-page inventory contains **125 open pull requests: 12 Ready/non-draft diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index a72ff84f9..49c5bb413 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -91,8 +91,8 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertIn("on 2026-09-05", refresh_line) current = bounded_section( self.baseline, + "#### Published semantic-action adoption: 04:11 UTC", "#### Published observation safeguards: 03:00 UTC", - "#### Published response and observation: 01:45 UTC", ) queue_counts = re.findall( r"\*\*(\d+) open pull requests: (\d+) Ready/non-draft and (\d+) Draft; " diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 2d3937afc..f6d1b898e 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -129,8 +129,8 @@ def test_current_snapshot_records_repaired_webdriver_bidi_lineage(self) -> None: def test_latest_executable_queue_uses_current_ready_roots(self) -> None: text = BASELINE.read_text(encoding="utf-8") current = bounded_section( - text, "#### Published observation safeguards: 03:00 UTC", - "#### Published response and observation: 01:45 UTC", + text, "#### Published semantic-action adoption: 04:11 UTC", + "#### Published observation safeguards: 03:00 UTC", ) roots = [line for line in current.splitlines() if line.startswith("Ready roots:")] self.assertEqual(len(roots), 1) @@ -231,7 +231,7 @@ def test_observation_safeguards_bind_each_published_owner(self) -> None: def test_action_adoption_checkpoint_binds_published_owners(self) -> None: current = bounded_section( BASELINE.read_text(encoding="utf-8"), - "#### Published semantic-action adoption: 04:15 UTC", + "#### Published semantic-action adoption: 04:11 UTC", "#### Published observation safeguards: 03:00 UTC", ) for owner, head, parent, coverage in ( @@ -251,7 +251,7 @@ def test_action_adoption_checkpoint_binds_published_owners(self) -> None: def test_historical_rows_cannot_replace_action_adoption(self) -> None: text = BASELINE.read_text(encoding="utf-8") - current = bounded_section(text, "#### Published semantic-action adoption: 04:15 UTC", "#### Published observation safeguards: 03:00 UTC") + current = bounded_section(text, "#### Published semantic-action adoption: 04:11 UTC", "#### Published observation safeguards: 03:00 UTC") for owner in (93, 95, 96): row = active_pr_row(current, owner) for replacement in ("", row.replace("Published; Draft", "Local only; Draft")): From 1160196af11d838786e351a1279341ce05be14c3 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 13:45:39 +0900 Subject: [PATCH 215/250] test(docs): require published status repair evidence and coverage guidance Co-Authored-By: OpenAI Codex Signed-off-by: Seongho Bae --- tests/test_agent_maintenance_lessons.py | 2 ++ tests/test_product_completion_gap_contract.py | 28 +++++++++++++++++++ 2 files changed, 30 insertions(+) diff --git a/tests/test_agent_maintenance_lessons.py b/tests/test_agent_maintenance_lessons.py index 634fe9329..0c0f7a3d9 100644 --- a/tests/test_agent_maintenance_lessons.py +++ b/tests/test_agent_maintenance_lessons.py @@ -13,6 +13,8 @@ def test_verification_lessons_remain_actionable(self) -> None: "cargo doc --workspace", "open the link destinations", "original connection can still complete", + "public integration path", + "Do not weaken coverage exclusions", ): with self.subTest(instruction=instruction): self.assertIn(instruction, text) diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index f6d1b898e..50f854ca0 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -16,6 +16,34 @@ class ProductCompletionGapContractTests(unittest.TestCase): """Keep the exact repository snapshot and completion tracks reviewable.""" + def test_status_repair_checkpoint_binds_published_evidence(self) -> None: + current = bounded_section( + BASELINE.read_text(encoding="utf-8"), + "#### Published status-response repair: 04:45 UTC", + "#### Published semantic-action adoption: 04:11 UTC", + ) + for marker in ( + "bbdc6ace7a5932adf24836700f806850e6b230bc", + "Published; Draft", + "1043/10711/13717/1188", + "34084134654", + "e1fccefc6b56eabe653ae41377fbcec0aa89b4be1ada92dba73d3ef87e841029", + "not hosted acceptance", + ): + with self.subTest(marker=marker): + self.assertIn(marker, current) + + def test_historical_evidence_cannot_replace_status_repair(self) -> None: + text = BASELINE.read_text(encoding="utf-8") + current = bounded_section( + text, "#### Published status-response repair: 04:45 UTC", + "#### Published semantic-action adoption: 04:11 UTC", + ) + stale = text.replace(current, current.replace("Published; Draft", "Local only"), 1) + with patch.object(pathlib.Path, "read_text", return_value=stale + current): + with self.assertRaises(AssertionError): + self.test_status_repair_checkpoint_binds_published_evidence() + def test_current_snapshot_checks_do_not_route_by_phrase_substrings(self) -> None: """Current-snapshot assertions must not depend on count-word substrings.""" source = pathlib.Path(__file__).read_text(encoding="utf-8") From 665e981ce92e42dd13195f794a56c39cb03b37b6 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 13:47:29 +0900 Subject: [PATCH 216/250] docs: record published status repair and coverage lessons Preserve the complete prior checkpoint history and keep local coverage, hosted checks, review authority, and release readiness distinct. Co-Authored-By: OpenAI Codex Signed-off-by: Seongho Bae --- AGENTS.md | 1 + CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 42 +++++++++++++++++++ ...cumentation_active_pr_evidence_contract.py | 2 +- tests/test_product_completion_gap_contract.py | 7 ++-- 5 files changed, 48 insertions(+), 5 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index f13e5122e..6d0643514 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -128,6 +128,7 @@ A release requires all current-head checks, complete coverage and docs, updated ## Verified maintenance lessons - Add concise, reproducible lessons here as work establishes them. Keep transient heads, job IDs and incident snapshots in PR evidence, not permanent instructions; never record secret values. +- For coverage repairs, inspect uncovered regions in each linked crate instance and prefer the existing public integration path. Reuse shared validation before adding test-only authority accessors; keep validation before state consumption. Do not weaken coverage exclusions or production lint gates to hide uncovered fixture or production paths. - Resume the existing process after a tool observation timeout; inspect its terminal status and logs before starting another copy. A timeout waiting for output is not a failed test. - For rustdoc visual inspection, use `RUSTDOCFLAGS='-D warnings' cargo doc --workspace` when `--no-deps` leaves cross-crate references unlinked. Inspect the actual rendered page and open the link destinations before claiming success; do not patch valid source links to hide a build artifact. - In parent adoption, preserve the child's behavior and tests, and compare inherited security boundaries against the exact parent. A rejected replacement reply must preserve pending work and prove that the original connection can still complete its own request. diff --git a/CHANGELOG.md b/CHANGELOG.md index a2ff9bd31..364393e4f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -61,6 +61,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ### Added +- Recorded the published browser-status repair with exact local coverage and pending hosted checks; added verified coverage-repair guidance to `AGENTS.md` without changing release or approval gates. - Recorded the verified #250 status-response parent adoption, #144's conservative process-set review limits and #287's authenticated CodeQL dispatch handoff, without promoting cancelled or pending hosted evidence to acceptance. - Recorded the verified #249 parent integration, #142/#143 failure-cleanup review evidence, and #255's remaining formatting/lint/coverage failures, keeping local results distinct from pending browser/hosted acceptance. - Revalidated the product-gap queue at 125 open pull requests (12 ready, 113 draft) and 13 open non-PR issues on 2026-09-05; protected `main` is `87c4daa1830bac5a5228b6036752ad5633232085`, presentation-identity PR #229 is Ready at `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`, WebDriver BiDi document-advance PR #260 is Draft at `3a651967c421f77088fe25e86a63faae295390b3`, denial-error PR #166 is Ready at `e84a1a2cc82b1c666218efd441da97849f47b8c2`, enterprise-approval PR #220 is Ready at `e545b94e1de499b96b867694f80ac04ad247becd`, JSON-envelope PR #247 has merged into its unprotected parent and successor #248 is Draft at `b386f17c4826adabebda084bff2fba35aee94dd0`, DDD/MCP repair #272 is Ready at `b1cae8ad1cbd8eb6992037c830aea30b9aa436b3`, governance repair #285 is Ready at `f455c2cd64b3dd3f027c91d396103792a205ddd0`, subscription repair #277 is Draft at `01038ba71fb276426cc67f90a91a3c431e194db5`, classifier foundation #287 is Ready at `af83c40dd2990a03064a92ca75430a9cc400f098`, workflow-free Agent Task successor #288 is Draft at `39e36256651f62940ec3ca6149067f0cfcb2285a`, and workflow-owner candidate #290 is Draft at `ebeefcd534db4324498fdb18046ebc6255ddcdf2`. Current-head checks remain independently required; no active-PR work is claimed as protected-main shipment. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 26502f74d..134691a76 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -8,6 +8,48 @@ This volatile section is refreshed from live GitHub state and is authoritative o ### Latest verified cut: 2026-09-07 +#### Published status-response repair: 04:45 UTC + +The refreshed five-page inventory contains **125 open pull requests: 12 Ready/non-draft +and 113 Draft; 13 open non-PR issues**, with zero unresolved review threads and no +pagination gaps. All Ready candidates remain BLOCKED. Protected main remains +`87c4daa1830bac5a5228b6036752ad5633232085`; no tags or releases exist. Active ruleset +`18156473` requires one counted approval and seven central workflows; the author is +the only listed collaborator. This reviewer-provisioning gap does not permit bypass. + +Ready roots: #37, #50, #166, #219, #220, #229, #238, #240, #272, #274, #285, #287. + +| Owner | Publication | Exact head | Parent | Local coverage (F/L/R/B) | +| --- | --- | --- | --- | --- | +| #250 | Published; Draft | [`bbdc6ace`](https://github.com/ContextualWisdomLab/OriginWeave/commit/bbdc6ace7a5932adf24836700f806850e6b230bc) | #249 `65ac3ab9` | 1043/10711/13717/1188 | + +All four coverage dimensions are 100% locally. Prior exact-head CI `34064507212` +failed formatting and coverage; that terminal evidence supersedes its historical +queued description. The repair reuses the sealed-reader tests and a shared, pure +reply-routing check. Validation and connection provenance still precede completion. +Public loopback checks reject events, unattributable errors and unbound requests +without consuming pending work. After an unbound request rejects a sealed reply, +the original request can still accept it. This does not prove a browser outcome. + +All 142 Python contracts, compileall and full Rust formatting, check, tests, Clippy +and warnings-denied workspace documentation passed at the published head. Coverage +artifact SHA-256: `e1fccefc6b56eabe653ae41377fbcec0aa89b4be1ada92dba73d3ef87e841029`. +Actual Edge inspection confirmed readable API documentation and the published commit. +Independent source review found no actionable findings; it is not counted approval. + +Exact-head CI `34084134654` has Rust job `101624834145` and coverage job `101624834026` +queued. Local verification is not hosted acceptance. The source writer lease is +released; this documentation checkpoint needs its own verification and visual inspection. +Earlier checkpoints remain unchanged historical records, not current acceptance. + +Automatic publishing remains unattempted: the protected package disables publication, +no Python package or publishing workflow is present, and release evidence and an +explicit version decision are still required. Empty repository/environment secret +metadata does not prove organization keys absent; their listing remains unavailable +under current permissions. No credential values, workflow gates or release settings +were changed. Next executable work remains parent-first status-receipt adoption, +protected foundations and release-readiness evidence under their separate owners. + #### Published semantic-action adoption: 04:11 UTC The five-page inventory contains **125 open pull requests: 12 Ready/non-draft diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 49c5bb413..17453abfe 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -91,8 +91,8 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertIn("on 2026-09-05", refresh_line) current = bounded_section( self.baseline, + "#### Published status-response repair: 04:45 UTC", "#### Published semantic-action adoption: 04:11 UTC", - "#### Published observation safeguards: 03:00 UTC", ) queue_counts = re.findall( r"\*\*(\d+) open pull requests: (\d+) Ready/non-draft and (\d+) Draft; " diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 50f854ca0..82e4ab653 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -30,8 +30,7 @@ def test_status_repair_checkpoint_binds_published_evidence(self) -> None: "e1fccefc6b56eabe653ae41377fbcec0aa89b4be1ada92dba73d3ef87e841029", "not hosted acceptance", ): - with self.subTest(marker=marker): - self.assertIn(marker, current) + self.assertIn(marker, current) def test_historical_evidence_cannot_replace_status_repair(self) -> None: text = BASELINE.read_text(encoding="utf-8") @@ -157,8 +156,8 @@ def test_current_snapshot_records_repaired_webdriver_bidi_lineage(self) -> None: def test_latest_executable_queue_uses_current_ready_roots(self) -> None: text = BASELINE.read_text(encoding="utf-8") current = bounded_section( - text, "#### Published semantic-action adoption: 04:11 UTC", - "#### Published observation safeguards: 03:00 UTC", + text, "#### Published status-response repair: 04:45 UTC", + "#### Published semantic-action adoption: 04:11 UTC", ) roots = [line for line in current.splitlines() if line.startswith("Ready roots:")] self.assertEqual(len(roots), 1) From 7dafc8ead8fdf54c1bd0735cec066320afb3e738 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 14:34:59 +0900 Subject: [PATCH 217/250] test(docs): require published end-reply evidence and recovery limits Co-Authored-By: OpenAI Codex Signed-off-by: Seongho Bae --- tests/test_agent_maintenance_lessons.py | 2 ++ tests/test_product_completion_gap_contract.py | 29 +++++++++++++++++++ 2 files changed, 31 insertions(+) diff --git a/tests/test_agent_maintenance_lessons.py b/tests/test_agent_maintenance_lessons.py index 0c0f7a3d9..17db790bd 100644 --- a/tests/test_agent_maintenance_lessons.py +++ b/tests/test_agent_maintenance_lessons.py @@ -15,6 +15,8 @@ def test_verification_lessons_remain_actionable(self) -> None: "original connection can still complete", "public integration path", "Do not weaken coverage exclusions", + "Retained receipt recovery is not live-stream recovery", + "same endpoint", ): with self.subTest(instruction=instruction): self.assertIn(instruction, text) diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 82e4ab653..cdbb5917e 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -16,6 +16,35 @@ class ProductCompletionGapContractTests(unittest.TestCase): """Keep the exact repository snapshot and completion tracks reviewable.""" + def test_end_reply_checkpoint_binds_published_evidence(self) -> None: + current = bounded_section( + BASELINE.read_text(encoding="utf-8"), + "#### Published session-end reply binding: 05:35 UTC", + "#### Published status-response repair: 04:45 UTC", + ) + for marker in ( + "924ad97551750d4a901ded38b89488cc5438e54f", + "363a78e36e7690e9ed5bf49829567e00e2ec5d59", + "Published; Draft", + "1057/10840/13873/1194", + "1064/10898/13947/1194", + "34085877650", "34087239755", + "9f2249637f31916acf9874baec724ddedfe621e5b14fdb6f4bd850620e89f307", + "not hosted acceptance", "retained receipts", "#255", "#292", + ): + self.assertIn(marker, current) + + def test_historical_evidence_cannot_replace_end_reply_checkpoint(self) -> None: + text = BASELINE.read_text(encoding="utf-8") + current = bounded_section( + text, "#### Published session-end reply binding: 05:35 UTC", + "#### Published status-response repair: 04:45 UTC", + ) + stale = text.replace(current, current.replace("Published; Draft", "Local only"), 1) + with patch.object(pathlib.Path, "read_text", return_value=stale + current): + with self.assertRaises(AssertionError): + self.test_end_reply_checkpoint_binds_published_evidence() + def test_status_repair_checkpoint_binds_published_evidence(self) -> None: current = bounded_section( BASELINE.read_text(encoding="utf-8"), From 2ce9b62a22db2b92a6f4c164abb08ea509096ef9 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 14:37:43 +0900 Subject: [PATCH 218/250] docs: record published end-reply binding and recovery limits Co-Authored-By: OpenAI Codex Signed-off-by: Seongho Bae --- AGENTS.md | 1 + CHANGELOG.md | 4 +- docs/product-technical-gap-baseline.md | 48 +++++++++++++++++++ ...cumentation_active_pr_evidence_contract.py | 2 +- tests/test_product_completion_gap_contract.py | 4 +- 5 files changed, 55 insertions(+), 4 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index 6d0643514..39d5fafc5 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -128,6 +128,7 @@ A release requires all current-head checks, complete coverage and docs, updated ## Verified maintenance lessons - Add concise, reproducible lessons here as work establishes them. Keep transient heads, job IDs and incident snapshots in PR evidence, not permanent instructions; never record secret values. +- Retained receipt recovery is not live-stream recovery. State whether a fixture keeps the original connection open and uses the same endpoint; claim live recovery only when a synchronized test reads and completes the original request after rejecting the replacement reply. - For coverage repairs, inspect uncovered regions in each linked crate instance and prefer the existing public integration path. Reuse shared validation before adding test-only authority accessors; keep validation before state consumption. Do not weaken coverage exclusions or production lint gates to hide uncovered fixture or production paths. - Resume the existing process after a tool observation timeout; inspect its terminal status and logs before starting another copy. A timeout waiting for output is not a failed test. - For rustdoc visual inspection, use `RUSTDOCFLAGS='-D warnings' cargo doc --workspace` when `--no-deps` leaves cross-crate references unlinked. Inspect the actual rendered page and open the link destinations before claiming success; do not patch valid source links to hide a build artifact. diff --git a/CHANGELOG.md b/CHANGELOG.md index 364393e4f..3acbf1696 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,8 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded published session-end reply protections, their visual and local verification, and the new browser-presentation evidence gap without treating queued checks or retained replies as release or live-stream acceptance. + - Record the published semantic-action adoption stack and its local verification, visual evidence and unmet release prerequisites without treating open pull requests as shipped behavior. - Record verified maintenance lessons for resumable checks, rendered documentation links, parent-preserving repairs and release-readiness checks without exposing credentials. @@ -17,7 +19,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Recorded the verified pointer-reply connection repair and recovery tests, keeping pending hosted checks, remaining authority gaps and browser acceptance separate. - Recorded the published text-entry connection safeguards and their test evidence, separating queued hosted checks and remaining pointer/status repairs from released browser behavior. - Separate the current maintenance queue and source lineage from preserved historical observations, and record the text-entry session and pending-request safeguards without claiming released browser behavior. -- Current delivery inventory: 125 open pull requests (12 ready, 113 draft); 13 open non-PR issues. Observed 2026-09-07; source acceptance remains revision-specific. +- Current delivery inventory: 125 open pull requests (12 ready, 113 draft); 14 open non-PR issues. Observed 2026-09-07; source acceptance remains revision-specific. - Corrected historical checkpoint labels and made the current inventory check reject stale counts; recorded verified text-input parent adoption without claiming browser execution. - Recorded the executed session-isolation repair and its verified adoption, separating complete local checks and PR visual inspection from pending hosted checks and unreleased browser acceptance. - Recorded the current click safeguards, restored regression coverage and completed PR visual inspection, keeping the separately owned parent repair and queued hosted checks distinct from delivery. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 134691a76..0750fbbb0 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -8,6 +8,54 @@ This volatile section is refreshed from live GitHub state and is authoritative o ### Latest verified cut: 2026-09-07 +#### Published session-end reply binding: 05:35 UTC + +The refreshed five-page inventory contains **125 open pull requests: 12 Ready/non-draft +and 113 Draft; 14 open non-PR issues**, with zero unresolved review threads and no +pagination gaps. All Ready candidates remain BLOCKED. Protected main remains +`87c4daa1830bac5a5228b6036752ad5633232085`; no tags or releases exist. Active ruleset +`18156473` requires one counted approval and seven central workflows; the author +remains the only listed collaborator. This reviewer-provisioning gap permits no bypass. + +Ready roots: #37, #50, #166, #219, #220, #229, #238, #240, #272, #274, #285, #287. + +| Owner | Publication | Exact head | Parent | Local coverage (F/L/R/B) | +| --- | --- | --- | --- | --- | +| #251 | Published; Draft | [`924ad975`](https://github.com/ContextualWisdomLab/OriginWeave/commit/924ad97551750d4a901ded38b89488cc5438e54f) | #250 `bbdc6ace` | 1057/10840/13873/1194 | +| #252 | Published; Draft | [`363a78e3`](https://github.com/ContextualWisdomLab/OriginWeave/commit/363a78e36e7690e9ed5bf49829567e00e2ec5d59) | #251 `924ad975` | 1064/10898/13947/1194 | + +Both heads passed all four coverage dimensions at 100%, 142 Python contracts, +compileall and full stable Rust formatting, check, tests, strict Clippy and +dependency-inclusive warnings-denied rustdoc. Actual Edge inspection covered the +rendered APIs, the end-response link to its sealed-reply type, and published commits. +Independent source review found no actionable findings; it is not counted approval. + +#251 preserves its sender and original tests while adopting status-reply safeguards. +#252 reproduced replacement end-reply acceptance before and after parent adoption, +then reused connection-bound registration and sealed reply correlation. Replacement +success and error replies now leave the original request pending, and its original +reply can still complete it. The fixtures use retained receipts after separate +listener servers finish: they do not establish same-endpoint or live-stream recovery, +browser shutdown, profile cleanup or protected delivery. + +Coverage artifact SHA-256 for #251 is +`5cbb52b50b5740a22d269490f6296380d4b53bbe61ceae632376f6de63ff1054`; +for #252 it is `9f2249637f31916acf9874baec724ddedfe621e5b14fdb6f4bd850620e89f307`. +Exact-head CI `34085877650` (Rust `101629699915`, coverage `101629699750`) and +`34087239755` (Rust `101633511589`, coverage `101633511320`) are queued. +Local verification is not hosted acceptance. Both source writer leases are released. + +Next, safe successor #255 must adopt #252 while preserving its stronger closure +provenance; #253/#254 remain open and are not safe intermediate prerequisites. +New issue #292 owns version-pinned browser presentation evidence after #229; its +requested implementation and real-browser acceptance remain unverified. Existing +release, runtime, extraction, API and enterprise gaps remain open. Automatic package +publishing is still unattempted: the protected package disables publication, no +Python package or registry-publishing workflow exists, and release evidence plus an +explicit version decision are required. Secret metadata is not release readiness; +organization key availability remains unverified. No gates or credentials changed. +Earlier checkpoints remain unchanged historical evidence. + #### Published status-response repair: 04:45 UTC The refreshed five-page inventory contains **125 open pull requests: 12 Ready/non-draft diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 17453abfe..e62b1dc83 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -91,8 +91,8 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertIn("on 2026-09-05", refresh_line) current = bounded_section( self.baseline, + "#### Published session-end reply binding: 05:35 UTC", "#### Published status-response repair: 04:45 UTC", - "#### Published semantic-action adoption: 04:11 UTC", ) queue_counts = re.findall( r"\*\*(\d+) open pull requests: (\d+) Ready/non-draft and (\d+) Draft; " diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index cdbb5917e..85ce5ca25 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -185,8 +185,8 @@ def test_current_snapshot_records_repaired_webdriver_bidi_lineage(self) -> None: def test_latest_executable_queue_uses_current_ready_roots(self) -> None: text = BASELINE.read_text(encoding="utf-8") current = bounded_section( - text, "#### Published status-response repair: 04:45 UTC", - "#### Published semantic-action adoption: 04:11 UTC", + text, "#### Published session-end reply binding: 05:35 UTC", + "#### Published status-response repair: 04:45 UTC", ) roots = [line for line in current.splitlines() if line.startswith("Ready roots:")] self.assertEqual(len(roots), 1) From fb0c9ddac703405ea94483b1d7f4c8232f503ff8 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 14:39:48 +0900 Subject: [PATCH 219/250] test(docs): reject per-owner publication evidence loss Co-Authored-By: OpenAI Codex Signed-off-by: Seongho Bae --- tests/test_product_completion_gap_contract.py | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 85ce5ca25..cb7cbebef 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -40,10 +40,12 @@ def test_historical_evidence_cannot_replace_end_reply_checkpoint(self) -> None: text, "#### Published session-end reply binding: 05:35 UTC", "#### Published status-response repair: 04:45 UTC", ) - stale = text.replace(current, current.replace("Published; Draft", "Local only"), 1) - with patch.object(pathlib.Path, "read_text", return_value=stale + current): - with self.assertRaises(AssertionError): - self.test_end_reply_checkpoint_binds_published_evidence() + for owner in (251, 252): + row = active_pr_row(current, owner) + stale = text.replace(row, row.replace("Published; Draft", "Local only"), 1) + with patch.object(pathlib.Path, "read_text", return_value=stale + row): + with self.assertRaises(AssertionError): + self.test_end_reply_checkpoint_binds_published_evidence() def test_status_repair_checkpoint_binds_published_evidence(self) -> None: current = bounded_section( From 8741f16f911454338bc4b285e077045bf0e94fb9 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 7 Sep 2026 14:40:14 +0900 Subject: [PATCH 220/250] fix(docs): bind checkpoint evidence to each owning pull request Co-Authored-By: OpenAI Codex Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + tests/test_product_completion_gap_contract.py | 12 +++++++----- 2 files changed, 8 insertions(+), 5 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 3acbf1696..13b8c1b41 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,6 +5,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] - Recorded published session-end reply protections, their visual and local verification, and the new browser-presentation evidence gap without treating queued checks or retained replies as release or live-stream acceptance. +- Bound each new delivery-evidence row to its own publication state, revision, parent and coverage so one row cannot hide another row's missing evidence. - Record the published semantic-action adoption stack and its local verification, visual evidence and unmet release prerequisites without treating open pull requests as shipped behavior. diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index cb7cbebef..5719e774f 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -22,12 +22,14 @@ def test_end_reply_checkpoint_binds_published_evidence(self) -> None: "#### Published session-end reply binding: 05:35 UTC", "#### Published status-response repair: 04:45 UTC", ) + for owner, head, parent, coverage in ( + (251, "924ad97551750d4a901ded38b89488cc5438e54f", "#250 `bbdc6ace`", "1057/10840/13873/1194"), + (252, "363a78e36e7690e9ed5bf49829567e00e2ec5d59", "#251 `924ad975`", "1064/10898/13947/1194"), + ): + row = active_pr_row(current, owner) + for marker in (head, parent, coverage, "Published; Draft"): + self.assertIn(marker, row) for marker in ( - "924ad97551750d4a901ded38b89488cc5438e54f", - "363a78e36e7690e9ed5bf49829567e00e2ec5d59", - "Published; Draft", - "1057/10840/13873/1194", - "1064/10898/13947/1194", "34085877650", "34087239755", "9f2249637f31916acf9874baec724ddedfe621e5b14fdb6f4bd850620e89f307", "not hosted acceptance", "retained receipts", "#255", "#292", From 0d4cd6e89fdaffd496e59bd3aac7baddb8fee962 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 11:40:05 +0900 Subject: [PATCH 221/250] docs: refresh closure verification checkpoint Separate verified predecessor coverage from the pending masking-fixture repair, preserve historical evidence, and record remaining product gaps. New scoped evidence contract failed before the refresh; all 204 repository contracts now pass. Co-Authored-By: OpenAI Codex --- AGENTS.md | 2 + CHANGELOG.md | 2 + docs/product-technical-gap-baseline.md | 39 ++++++++++++++++++- tests/test_product_completion_gap_contract.py | 17 ++++++++ 4 files changed, 59 insertions(+), 1 deletion(-) diff --git a/AGENTS.md b/AGENTS.md index 39d5fafc5..1a724acb5 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -127,6 +127,8 @@ A release requires all current-head checks, complete coverage and docs, updated ## Verified maintenance lessons +- When updating a delivery checkpoint, separate a verified predecessor from a newer pending head. A passing coverage summary does not validate a fixture that ignores peer errors; preserve the failing reproduction and the repaired wire-level assertions in the evidence trail. + - Add concise, reproducible lessons here as work establishes them. Keep transient heads, job IDs and incident snapshots in PR evidence, not permanent instructions; never record secret values. - Retained receipt recovery is not live-stream recovery. State whether a fixture keeps the original connection open and uses the same endpoint; claim live recovery only when a synchronized test reads and completes the original request after rejecting the replacement reply. - For coverage repairs, inspect uncovered regions in each linked crate instance and prefer the existing public integration path. Reuse shared validation before adding test-only authority accessors; keep validation before state consumption. Do not weaken coverage exclusions or production lint gates to hide uncovered fixture or production paths. diff --git a/CHANGELOG.md b/CHANGELOG.md index 13b8c1b41..a28609735 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,8 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Refreshed transport-closure evidence with completed predecessor CI, the separately pending test-integrity repair, and the remaining deadline and control-frame behavior gaps. + - Recorded published session-end reply protections, their visual and local verification, and the new browser-presentation evidence gap without treating queued checks or retained replies as release or live-stream acceptance. - Bound each new delivery-evidence row to its own publication state, revision, parent and coverage so one row cannot hide another row's missing evidence. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 0750fbbb0..3ffce790c 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,7 +6,44 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -### Latest verified cut: 2026-09-07 +### Latest verified cut: 2026-09-08 + +#### Transport-closure verification and test-integrity repair + +The latest inventory contains **126 open pull requests: 12 Ready/non-draft and +114 Draft; 14 open non-PR issues**. All 12 Ready candidates remain BLOCKED. +Protected main remains `87c4daa1830bac5a5228b6036752ad5633232085`, with +no package release. These counts do not establish review-thread resolution. + +PR #255 has adopted parent #252 at +`363a78e36e7690e9ed5bf49829567e00e2ec5d59`; the previous instruction to perform +that adoption is now historical. It remains Draft and is not protected-main acceptance. + +- Verified predecessor: [`d126242c7198c447d0fab7983d529441340fd1c9`](https://github.com/ContextualWisdomLab/OriginWeave/commit/d126242c7198c447d0fab7983d529441340fd1c9) + passed both Rust contracts and Production coverage in + [run 34179452950](https://github.com/ContextualWisdomLab/OriginWeave/actions/runs/34179452950). + Full local functions/lines/regions/branches were **1090/11218/14328/1210**, all 100%. +- Published follow-up: [`07ef43ec71b6dbd8540629bf1df5a63b81541ee4`](https://github.com/ContextualWisdomLab/OriginWeave/commit/07ef43ec71b6dbd8540629bf1df5a63b81541ee4) + corrects three masking-rejection test peers. Propagating peer failures first + reproduced two false-green fixtures; all 16 closure tests and the full workspace + suite including doctests then passed. Hosted + [run 34180304951](https://github.com/ContextualWisdomLab/OriginWeave/actions/runs/34180304951) + was queued at this checkpoint; predecessor coverage does not prove this head passed. + +The direct writer tests compare literal Close bytes with and without a status code, +invalid deadlines, and adjacent masking-key rejection. The repaired observer fixtures +consume the real preceding text/Pong before testing reuse and verify no rejected +response bytes. Broad transport errors with ignored server failures were insufficient. + +Remaining buyer-visible gap: repeated Ping/Pong traffic and an operation-wide deadline +still need implementation and acceptance; unassigned Close status handling needs +protocol review. Browser-process exit and profile cleanup remain unproven. The next +source work belongs to #255 before downstream adoption; no PR is closed as a substitute +for carrying its delta. Actual Edge inspection verified the PR page and corrected +evidence presentation, not the OriginWeave product browser. Package publication remains +withheld until protected-source, version, artifact and release requirements are met. + +### Historical verified cut: 2026-09-07 #### Published session-end reply binding: 05:35 UTC diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 5719e774f..066c4f375 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -16,6 +16,23 @@ class ProductCompletionGapContractTests(unittest.TestCase): """Keep the exact repository snapshot and completion tracks reviewable.""" + def test_closure_checkpoint_separates_verified_and_pending_heads(self) -> None: + current = bounded_section( + BASELINE.read_text(encoding="utf-8"), + "### Latest verified cut: 2026-09-08", + "### Historical verified cut: 2026-09-07", + ) + for marker in ( + "d126242c7198c447d0fab7983d529441340fd1c9", + "07ef43ec71b6dbd8540629bf1df5a63b81541ee4", + "363a78e36e7690e9ed5bf49829567e00e2ec5d59", + "34179452950", "34180304951", "1090/11218/14328/1210", + "126 open pull requests", "114 Draft", "14 open non-PR issues", + "not protected-main acceptance", "operation-wide deadline", + "repeated Ping/Pong", "no package release", + ): + self.assertIn(marker, current) + def test_end_reply_checkpoint_binds_published_evidence(self) -> None: current = bounded_section( BASELINE.read_text(encoding="utf-8"), From 37b081917d2088dcade0a45274f7e3345ae3567f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 12:33:02 +0900 Subject: [PATCH 222/250] docs: refresh verified closure repair checkpoint Co-Authored-By: OpenAI Codex --- AGENTS.md | 2 ++ CHANGELOG.md | 2 ++ docs/product-technical-gap-baseline.md | 27 +++++++++++++++++++ tests/test_product_completion_gap_contract.py | 14 ++++++++++ 4 files changed, 45 insertions(+) diff --git a/AGENTS.md b/AGENTS.md index 1a724acb5..0592cb3a4 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -1,5 +1,7 @@ # Agent Development Contract +When a follow-up closes a documented gap, add a bounded current checkpoint and label the predecessor as historical. Pin new local metrics and hosted run separately; do not leave an earlier pending implementation claim as the current next action. + This file is authoritative for humans and automated contributors working in OriginWeave. ## Product objective diff --git a/CHANGELOG.md b/CHANGELOG.md index a28609735..36d587f13 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -123,6 +123,8 @@ All notable changes to OriginWeave are documented in this file. The format follo ### Changed +- Refreshed the delivery checkpoint for completed local shutdown-deadline and reserved-code repairs while keeping hosted acceptance and release gaps explicit. + - Made the open non-PR issue count reproducible in the baseline evidence procedure and corrected the historical exact heads for PRs #53 and #217. - Revalidated the active ruleset inventory at 7 required workflows from the live branch-rules API by adding `codeql-pr`; `close-empty-pr` remains useful repository automation but is not a current protected-main requirement. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 3ffce790c..08fee8299 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -8,6 +8,33 @@ This volatile section is refreshed from live GitHub state and is authoritative o ### Latest verified cut: 2026-09-08 +#### Published deadline and Close-code repairs + +Published #255 head +[`8716b9d441960a112446c1f89ab417ad9abe28d2`](https://github.com/ContextualWisdomLab/OriginWeave/commit/8716b9d441960a112446c1f89ab417ad9abe28d2) +retains parent #252 `363a78e36e7690e9ed5bf49829567e00e2ec5d59` and is **not shipped**. +One operation-wide monotonic deadline now covers the complete closure exchange. +A delayed real-peer test first reproduced budget renewal; controlled-clock tests +then verified every deadline transition and final evidence admission. + +The shared Close validator also rejects unassigned protocol codes **1016–2999** +against the current IANA registry, while preserving application/private ranges. +The boundary test first failed on 1016; real peers now verify no reply or closure +evidence for 1016, 2000, and 2999. Local functions/lines/regions/branches are +**1101/11492/14662/1218**, all 100%. All **18 closure** integration tests, +**142 repository** contracts, strict Clippy, doctests and warnings-denied rustdoc pass. +Hosted [run 34183766437](https://github.com/ContextualWisdomLab/OriginWeave/actions/runs/34183766437) +is pending at this checkpoint: local verification is **not hosted acceptance**. + +The fresh inventory remains 126 open PRs (12 Ready, all BLOCKED; 114 Draft), +14 issues and zero releases; protected main remains +`87c4daa1830bac5a5228b6036752ad5633232085`. The current rule still requires one +counted approval and seven central workflows. Remaining #255 work is **repeated Ping/Pong** +with fresh masking keys; browser **process exit** and **profile cleanup** remain unproven. +Publication still requires protected source, an explicit version and complete release +artifacts/evidence. The earlier checkpoint below records its own earlier state, +not the current implementation gaps. + #### Transport-closure verification and test-integrity repair The latest inventory contains **126 open pull requests: 12 Ready/non-draft and diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 066c4f375..faa3e4866 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -16,6 +16,20 @@ class ProductCompletionGapContractTests(unittest.TestCase): """Keep the exact repository snapshot and completion tracks reviewable.""" + def test_close_code_checkpoint_does_not_claim_hosted_acceptance(self) -> None: + current = bounded_section( + BASELINE.read_text(encoding="utf-8"), + "#### Published deadline and Close-code repairs", + "#### Transport-closure verification and test-integrity repair", + ) + for marker in ( + "8716b9d441960a112446c1f89ab417ad9abe28d2", "34183766437", + "1101/11492/14662/1218", "18 closure", "142 repository", + "not hosted acceptance", "repeated Ping/Pong", "1016–2999", + "process exit", "profile cleanup", "not shipped", + ): + self.assertIn(marker, current) + def test_closure_checkpoint_separates_verified_and_pending_heads(self) -> None: current = bounded_section( BASELINE.read_text(encoding="utf-8"), From 847f45398e5a8d90798d8d0c3b2aca9357634661 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 12:51:31 +0900 Subject: [PATCH 223/250] docs: record repeated control verification checkpoint Co-Authored-By: OpenAI Codex --- CHANGELOG.md | 2 ++ docs/product-technical-gap-baseline.md | 25 +++++++++++++++++++ tests/test_product_completion_gap_contract.py | 14 +++++++++++ 3 files changed, 41 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 36d587f13..c791b07c9 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -123,6 +123,8 @@ All notable changes to OriginWeave are documented in this file. The format follo ### Changed +- Updated the delivery checkpoint for bounded repeated keepalive handling, retaining the distinction between local verification, hosted acceptance and operational completion. + - Refreshed the delivery checkpoint for completed local shutdown-deadline and reserved-code repairs while keeping hosted acceptance and release gaps explicit. - Made the open non-PR issue count reproducible in the baseline evidence procedure and corrected the historical exact heads for PRs #53 and #217. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 08fee8299..e81e8c27f 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -8,6 +8,31 @@ This volatile section is refreshed from live GitHub state and is authoritative o ### Latest verified cut: 2026-09-08 +#### Published repeated-control repair + +Published #255 head +[`3a8e6f4f89db2f53c144adb3351c153d89adca58`](https://github.com/ContextualWisdomLab/OriginWeave/commit/3a8e6f4f89db2f53c144adb3351c153d89adca58) +retains parent #252 `363a78e36e7690e9ed5bf49829567e00e2ec5d59` and is **not shipped**. +The two-Pong real-peer case first failed. The observer now handles up to **64** +pre-Close Ping/Pong frames under one total deadline, with fresh caller-supplied keys +consumed only by Ping responses. A separate key remains reserved for Close. +Tests prove exact-budget success, **65th** control rejection, exhausted and reused +key rejection without an extra reply, and literal separately masked Pong payloads. + +Frozen-final-source local coverage is **1104/11553/14758/1216** +(functions/lines/regions/branches), all 100%. All **20 closure** integration tests, +six controlled-clock tests, 142 repository contracts, strict Clippy, doctests, and +warnings-denied rustdoc pass. Actual Edge inspection verified the rendered key-slice +API, local resource limit and total-deadline contract. Hosted +[run 34184829970](https://github.com/ContextualWisdomLab/OriginWeave/actions/runs/34184829970) +is queued at this checkpoint: local verification is **not hosted acceptance**. + +The repeated-control implementation gap is closed locally, not released. Current-head +review/check acceptance and protected-parent adoption remain required; **process exit** +and **profile cleanup** still lack runtime evidence. Inventory remains 126 open PRs, +14 issues and zero releases. The following same-day sections preserve earlier +checkpoints; their pending implementation claims are superseded by this section. + #### Published deadline and Close-code repairs Published #255 head diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index faa3e4866..6833e1219 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -16,6 +16,20 @@ class ProductCompletionGapContractTests(unittest.TestCase): """Keep the exact repository snapshot and completion tracks reviewable.""" + def test_repeated_control_checkpoint_keeps_operational_gaps_open(self) -> None: + current = bounded_section( + BASELINE.read_text(encoding="utf-8"), + "#### Published repeated-control repair", + "#### Published deadline and Close-code repairs", + ) + for marker in ( + "3a8e6f4f89db2f53c144adb3351c153d89adca58", "34184829970", + "1104/11553/14758/1216", "20 closure", "64", "65th", + "not hosted acceptance", "process exit", "profile cleanup", + "not shipped", "fresh", "exhausted", "reused", + ): + self.assertIn(marker, current) + def test_close_code_checkpoint_does_not_claim_hosted_acceptance(self) -> None: current = bounded_section( BASELINE.read_text(encoding="utf-8"), From 74f7590f8c6c1187e28e67aa38cb9fefeaca99c4 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 13:21:47 +0900 Subject: [PATCH 224/250] docs: record verified intent acknowledgment repair Co-authored-by: OpenAI Codex --- CHANGELOG.md | 2 ++ docs/product-technical-gap-baseline.md | 28 +++++++++++++++++++ tests/test_product_completion_gap_contract.py | 15 ++++++++++ 3 files changed, 45 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index c791b07c9..673ea9e57 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,8 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded completed local reply-verification checks and visual inspection, distinguishing queued hosted checks and superseded runs from release acceptance. + - Refreshed transport-closure evidence with completed predecessor CI, the separately pending test-integrity repair, and the remaining deadline and control-frame behavior gaps. - Recorded published session-end reply protections, their visual and local verification, and the new browser-presentation evidence gap without treating queued checks or retained replies as release or live-stream acceptance. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e81e8c27f..71ba93397 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -8,6 +8,34 @@ This volatile section is refreshed from live GitHub state and is authoritative o ### Latest verified cut: 2026-09-08 +#### Published intent acknowledgment verification + +Published #271 head +[`46db0045904f0289738df843d0a2f179c26673d3`](https://github.com/ContextualWisdomLab/OriginWeave/commit/46db0045904f0289738df843d0a2f179c26673d3) +retains parent #270 `8eda96915dbbe4cc617f834267c7464689c2844d` and is **not shipped**. +The previous head's formatter and coverage failures were reproduced. The repair +retains connection and command pre-consumption guards, removes only a proven +unreachable duplicate check, and tests genuine socket replies, pending-request +preservation and private-text-safe diagnostics. + +Frozen-source local coverage is **1406/14894/19018/1552** +(functions/lines/regions/branches), all 100%. Nine focused integration tests, +148 repository contracts, complete workspace coverage tests, strict Clippy, +formatting, five doctests and warnings-denied rustdoc pass. Actual Edge visual +inspection verified the rendered acknowledgment contract and readable layout. +Hosted [run 34186280263](https://github.com/ContextualWisdomLab/OriginWeave/actions/runs/34186280263) +is queued at this checkpoint: local verification is **not hosted acceptance**. +Both review threads remain unresolved pending current-head hosted verification; +protected-parent adoption and real browser outcome evidence remain required. + +Separately, #255 advanced to test-only head +`10d5e1ff78d46bbad004d4e0971d0ffceac757fa`, preserving the prior repair and +testing rejection of server Close 1010. Its predecessor run 34184829970 was +cancelled because it was superseded, not because the new head failed. +That independent writer retains the source lease. Inventory remains 126 open +PRs, 14 issues and zero releases. Earlier sections below retain dated evidence, +not the current status of their superseded runs. + #### Published repeated-control repair Published #255 head diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 6833e1219..63a986e94 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -16,6 +16,21 @@ class ProductCompletionGapContractTests(unittest.TestCase): """Keep the exact repository snapshot and completion tracks reviewable.""" + def test_ack_checkpoint_separates_local_repair_from_review_acceptance(self) -> None: + current = bounded_section( + BASELINE.read_text(encoding="utf-8"), + "#### Published intent acknowledgment verification", + "#### Published repeated-control repair", + ) + for marker in ( + "46db0045904f0289738df843d0a2f179c26673d3", "34186280263", + "8eda96915dbbe4cc617f834267c7464689c2844d", + "1406/14894/19018/1552", "pre-consumption", "unresolved", + "not hosted acceptance", "not shipped", "148 repository", + "10d5e1ff78d46bbad004d4e0971d0ffceac757fa", "superseded", + ): + self.assertIn(marker, current) + def test_repeated_control_checkpoint_keeps_operational_gaps_open(self) -> None: current = bounded_section( BASELINE.read_text(encoding="utf-8"), From 6a4bd338cc499d7b2d1694507e9b7ec34f16f8d7 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 14:00:27 +0900 Subject: [PATCH 225/250] docs: record server Close role repair Co-authored-by: OpenAI Codex --- CHANGELOG.md | 2 ++ docs/product-technical-gap-baseline.md | 21 ++++++++++++------- tests/test_product_completion_gap_contract.py | 3 +++ 3 files changed, 19 insertions(+), 7 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 673ea9e57..5c5a10395 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,8 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded the server Close-role RED-to-GREEN repair with exact local coverage and visual evidence, keeping queued hosted checks and release acceptance separate. + - Recorded completed local reply-verification checks and visual inspection, distinguishing queued hosted checks and superseded runs from release acceptance. - Refreshed transport-closure evidence with completed predecessor CI, the separately pending test-integrity repair, and the remaining deadline and control-frame behavior gaps. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 71ba93397..f50f878b2 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -28,13 +28,20 @@ is queued at this checkpoint: local verification is **not hosted acceptance**. Both review threads remain unresolved pending current-head hosted verification; protected-parent adoption and real browser outcome evidence remain required. -Separately, #255 advanced to test-only head -`10d5e1ff78d46bbad004d4e0971d0ffceac757fa`, preserving the prior repair and -testing rejection of server Close 1010. Its predecessor run 34184829970 was -cancelled because it was superseded, not because the new head failed. -That independent writer retains the source lease. Inventory remains 126 open -PRs, 14 issues and zero releases. Earlier sections below retain dated evidence, -not the current status of their superseded runs. +Separately, #255 advanced from superseded test-only head +`10d5e1ff78d46bbad004d4e0971d0ffceac757fa` to published repair +`6b6c90ed3919ea84b69527ab688a087eeb45224d`. A real server-sent Close 1010 +first reproduced RED because the client mirrored the client-only code. The +role guard now rejects it before reply or closure evidence while the paired +server 1011 control remains valid. Exact-head local coverage is +**1105/11574/14787/1218**, all 100%; 142 repository contracts, strict Clippy, +formatting, doctests and warnings-denied rustdoc pass. Actual Edge inspection +verified the rendered role, masking-key, control-budget and deadline contract. +Hosted [run 34188785932](https://github.com/ContextualWisdomLab/OriginWeave/actions/runs/34188785932) +is queued, so this is not hosted acceptance or shipped behavior. The source +writer lease is released. Inventory remains 126 open PRs, 14 issues and zero +releases. Earlier sections below retain dated evidence, not the current status +of their superseded runs. #### Published repeated-control repair diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 63a986e94..b32cb687d 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -28,6 +28,9 @@ def test_ack_checkpoint_separates_local_repair_from_review_acceptance(self) -> N "1406/14894/19018/1552", "pre-consumption", "unresolved", "not hosted acceptance", "not shipped", "148 repository", "10d5e1ff78d46bbad004d4e0971d0ffceac757fa", "superseded", + "6b6c90ed3919ea84b69527ab688a087eeb45224d", + "1105/11574/14787/1218", "34188785932", "server-sent", + "RED", "1010", "1011", "Actual Edge", ): self.assertIn(marker, current) From 8c11b90064bb74671aa322baa154216184c1c537 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 14:04:59 +0900 Subject: [PATCH 226/250] docs: record hosted intent verification Co-authored-by: OpenAI Codex --- CHANGELOG.md | 2 +- docs/product-technical-gap-baseline.md | 7 ++++--- tests/test_product_completion_gap_contract.py | 4 ++-- 3 files changed, 7 insertions(+), 6 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 5c5a10395..9e4281867 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,7 +6,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Recorded the server Close-role RED-to-GREEN repair with exact local coverage and visual evidence, keeping queued hosted checks and release acceptance separate. -- Recorded completed local reply-verification checks and visual inspection, distinguishing queued hosted checks and superseded runs from release acceptance. +- Recorded completed local reply-verification checks, visual inspection and exact-head hosted success, distinguishing clean Draft state from protected-main and release acceptance. - Refreshed transport-closure evidence with completed predecessor CI, the separately pending test-integrity repair, and the remaining deadline and control-frame behavior gaps. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index f50f878b2..f6c0aaa66 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -24,9 +24,10 @@ Frozen-source local coverage is **1406/14894/19018/1552** formatting, five doctests and warnings-denied rustdoc pass. Actual Edge visual inspection verified the rendered acknowledgment contract and readable layout. Hosted [run 34186280263](https://github.com/ContextualWisdomLab/OriginWeave/actions/runs/34186280263) -is queued at this checkpoint: local verification is **not hosted acceptance**. -Both review threads remain unresolved pending current-head hosted verification; -protected-parent adoption and real browser outcome evidence remain required. +is terminal SUCCESS on this exact head: Rust contracts and Production coverage +both pass. Both review threads are resolved and GitHub reports the Draft head +**CLEAN**. Protected-parent adoption, governing approval and real browser +outcome evidence remain required; this is still **not shipped**. Separately, #255 advanced from superseded test-only head `10d5e1ff78d46bbad004d4e0971d0ffceac757fa` to published repair diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index b32cb687d..0b7424613 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -25,8 +25,8 @@ def test_ack_checkpoint_separates_local_repair_from_review_acceptance(self) -> N for marker in ( "46db0045904f0289738df843d0a2f179c26673d3", "34186280263", "8eda96915dbbe4cc617f834267c7464689c2844d", - "1406/14894/19018/1552", "pre-consumption", "unresolved", - "not hosted acceptance", "not shipped", "148 repository", + "1406/14894/19018/1552", "pre-consumption", "resolved", + "terminal SUCCESS", "CLEAN", "not shipped", "148 repository", "10d5e1ff78d46bbad004d4e0971d0ffceac757fa", "superseded", "6b6c90ed3919ea84b69527ab688a087eeb45224d", "1105/11574/14787/1218", "34188785932", "server-sent", From 8e0bab6e01fdf97d43ee847d18f30abad691c51f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 14:33:02 +0900 Subject: [PATCH 227/250] docs: refresh BiDi capability evidence Co-authored-by: OpenAI Codex --- CHANGELOG.md | 2 ++ docs/product-technical-gap-baseline.md | 21 +++++++++++++++---- tests/test_product_completion_gap_contract.py | 5 ++++- 3 files changed, 23 insertions(+), 5 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 9e4281867..91af6184e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,8 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded #255 exact-head hosted success and #293's narrow standard-BiDi capability repair, preserving the blocked visual-inspection and real-browser evidence gaps. + - Recorded the server Close-role RED-to-GREEN repair with exact local coverage and visual evidence, keeping queued hosted checks and release acceptance separate. - Recorded completed local reply-verification checks, visual inspection and exact-head hosted success, distinguishing clean Draft state from protected-main and release acceptance. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index f6c0aaa66..22f5353fc 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -39,10 +39,23 @@ server 1011 control remains valid. Exact-head local coverage is formatting, doctests and warnings-denied rustdoc pass. Actual Edge inspection verified the rendered role, masking-key, control-budget and deadline contract. Hosted [run 34188785932](https://github.com/ContextualWisdomLab/OriginWeave/actions/runs/34188785932) -is queued, so this is not hosted acceptance or shipped behavior. The source -writer lease is released. Inventory remains 126 open PRs, 14 issues and zero -releases. Earlier sections below retain dated evidence, not the current status -of their superseded runs. +is terminal SUCCESS: Rust contracts and Production coverage both pass on that +exact head. The Draft is CLEAN, but this remains neither protected-main nor +shipped behavior. + +Draft #293 now publishes exact head +`6b5241c164f5283f8dd51b1846ef0e4dacec0b29` on parent #229. Its executed RED +showed that standard BiDi was overstating complete Screen and Languages +support. The minimal repair retains only Viewport, DevicePixelRatio, TimeZone +and ReducedMotion. Exact local coverage is **587/4886/5881/748**, all 100%; 159 +repository contracts, strict Clippy, formatting, doctests and warnings-denied +rustdoc pass. Visual inspection is unproven: browser safety policy blocked the +local rustdoc page and prohibited an indirect workaround. The Draft is CLEAN; +real Chromium application and page-observed evidence remain in #292. + +Both source writer leases are released. Inventory remains 126 open PRs, 14 +issues and zero releases. Earlier sections below retain dated evidence, not the +current status of their superseded runs. #### Published repeated-control repair diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 0b7424613..a94c86fde 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -30,7 +30,10 @@ def test_ack_checkpoint_separates_local_repair_from_review_acceptance(self) -> N "10d5e1ff78d46bbad004d4e0971d0ffceac757fa", "superseded", "6b6c90ed3919ea84b69527ab688a087eeb45224d", "1105/11574/14787/1218", "34188785932", "server-sent", - "RED", "1010", "1011", "Actual Edge", + "RED", "1010", "1011", "Actual Edge", "terminal SUCCESS", + "6b5241c164f5283f8dd51b1846ef0e4dacec0b29", + "587/4886/5881/748", "#293", "Visual inspection is unproven", + "Viewport", "DevicePixelRatio", "TimeZone", "ReducedMotion", ): self.assertIn(marker, current) From fb705d23d0266ef22fc7678d0b70def0a227c12f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 14:37:23 +0900 Subject: [PATCH 228/250] docs: record Edge capability inspection Co-authored-by: OpenAI Codex --- CHANGELOG.md | 2 +- docs/product-technical-gap-baseline.md | 6 ++++-- tests/test_product_completion_gap_contract.py | 3 ++- 3 files changed, 7 insertions(+), 4 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 91af6184e..eb7b30a58 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,7 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] -- Recorded #255 exact-head hosted success and #293's narrow standard-BiDi capability repair, preserving the blocked visual-inspection and real-browser evidence gaps. +- Recorded #255 exact-head hosted success and #293's narrow standard-BiDi capability repair with an actual Edge diff inspection, preserving the blocked rustdoc-view and real-browser evidence gaps. - Recorded the server Close-role RED-to-GREEN repair with exact local coverage and visual evidence, keeping queued hosted checks and release acceptance separate. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 22f5353fc..670cb423a 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -49,8 +49,10 @@ showed that standard BiDi was overstating complete Screen and Languages support. The minimal repair retains only Viewport, DevicePixelRatio, TimeZone and ReducedMotion. Exact local coverage is **587/4886/5881/748**, all 100%; 159 repository contracts, strict Clippy, formatting, doctests and warnings-denied -rustdoc pass. Visual inspection is unproven: browser safety policy blocked the -local rustdoc page and prohibited an indirect workaround. The Draft is CLEAN; +rustdoc pass. Actual Edge inspection of the GitHub-rendered exact-head diff +showed the four admitted surfaces and exclusion contract with no clipping or overlap. +Generated-rustdoc visual acceptance remains unproven because browser safety policy +blocked the local page and prohibited an indirect workaround. The Draft is CLEAN; real Chromium application and page-observed evidence remain in #292. Both source writer leases are released. Inventory remains 126 open PRs, 14 diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index a94c86fde..9d225fe07 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -32,7 +32,8 @@ def test_ack_checkpoint_separates_local_repair_from_review_acceptance(self) -> N "1105/11574/14787/1218", "34188785932", "server-sent", "RED", "1010", "1011", "Actual Edge", "terminal SUCCESS", "6b5241c164f5283f8dd51b1846ef0e4dacec0b29", - "587/4886/5881/748", "#293", "Visual inspection is unproven", + "587/4886/5881/748", "#293", "GitHub-rendered exact-head", + "no clipping or overlap", "rustdoc visual acceptance remains unproven", "Viewport", "DevicePixelRatio", "TimeZone", "ReducedMotion", ): self.assertIn(marker, current) From 2127c0a974adfd5ce76fc055b52cc168fc892347 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 15:05:50 +0900 Subject: [PATCH 229/250] docs: record typed BiDi command planning Co-authored-by: OpenAI Codex --- CHANGELOG.md | 2 +- docs/product-technical-gap-baseline.md | 19 +++++++++++-------- tests/test_product_completion_gap_contract.py | 7 ++++--- 3 files changed, 16 insertions(+), 12 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index eb7b30a58..d4a8276dd 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,7 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] -- Recorded #255 exact-head hosted success and #293's narrow standard-BiDi capability repair with an actual Edge diff inspection, preserving the blocked rustdoc-view and real-browser evidence gaps. +- Recorded #255 exact-head hosted success and #293's narrow standard-BiDi capability and typed-command planning progress, preserving exact-head visual, rustdoc-view, transport, and real-browser evidence gaps. - Recorded the server Close-role RED-to-GREEN repair with exact local coverage and visual evidence, keeping queued hosted checks and release acceptance separate. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 670cb423a..a1f275fea 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -43,17 +43,20 @@ is terminal SUCCESS: Rust contracts and Production coverage both pass on that exact head. The Draft is CLEAN, but this remains neither protected-main nor shipped behavior. -Draft #293 now publishes exact head -`6b5241c164f5283f8dd51b1846ef0e4dacec0b29` on parent #229. Its executed RED +Draft #293 advanced from visually inspected predecessor +`6b5241c164f5283f8dd51b1846ef0e4dacec0b29` to exact head +`30941dc0d0b2640f14c9b66ff32b05ea58082d38` on parent #229. Its executed RED showed that standard BiDi was overstating complete Screen and Languages support. The minimal repair retains only Viewport, DevicePixelRatio, TimeZone -and ReducedMotion. Exact local coverage is **587/4886/5881/748**, all 100%; 159 +and ReducedMotion. The current head binds three typed command intents for those +four surfaces to one bounded opaque browsing context without sending them or +minting evidence. Exact local coverage is **592/4960/5966/754**, all 100%; 159 repository contracts, strict Clippy, formatting, doctests and warnings-denied -rustdoc pass. Actual Edge inspection of the GitHub-rendered exact-head diff -showed the four admitted surfaces and exclusion contract with no clipping or overlap. -Generated-rustdoc visual acceptance remains unproven because browser safety policy -blocked the local page and prohibited an indirect workaround. The Draft is CLEAN; -real Chromium application and page-observed evidence remain in #292. +rustdoc pass. Exact-head Edge inspection was attempted, but the extension +session repeatedly timed out; current-head visual acceptance is unproven. +Generated-rustdoc inspection is separately blocked by local-file browser policy. +The Draft is CLEAN; real Chromium application and page-observed evidence remain +in #292. Both source writer leases are released. Inventory remains 126 open PRs, 14 issues and zero releases. Earlier sections below retain dated evidence, not the diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 9d225fe07..3e588cfcd 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -31,9 +31,10 @@ def test_ack_checkpoint_separates_local_repair_from_review_acceptance(self) -> N "6b6c90ed3919ea84b69527ab688a087eeb45224d", "1105/11574/14787/1218", "34188785932", "server-sent", "RED", "1010", "1011", "Actual Edge", "terminal SUCCESS", - "6b5241c164f5283f8dd51b1846ef0e4dacec0b29", - "587/4886/5881/748", "#293", "GitHub-rendered exact-head", - "no clipping or overlap", "rustdoc visual acceptance remains unproven", + "6b5241c164f5283f8dd51b1846ef0e4dacec0b29", "predecessor", + "30941dc0d0b2640f14c9b66ff32b05ea58082d38", + "592/4960/5966/754", "#293", "three typed command intents", + "current-head visual acceptance is unproven", "Viewport", "DevicePixelRatio", "TimeZone", "ReducedMotion", ): self.assertIn(marker, current) From 27b33c66d160fb65adcce88b1a20952def859c1f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 15:45:58 +0900 Subject: [PATCH 230/250] docs: refresh bidi gap evidence --- CHANGELOG.md | 2 +- docs/product-technical-gap-baseline.md | 18 ++++++++++-------- tests/test_product_completion_gap_contract.py | 4 ++-- 3 files changed, 13 insertions(+), 11 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index d4a8276dd..589a073b3 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,7 +4,7 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] -- Recorded #255 exact-head hosted success and #293's narrow standard-BiDi capability and typed-command planning progress, preserving exact-head visual, rustdoc-view, transport, and real-browser evidence gaps. +- Recorded #255 exact-head hosted success and #293's narrow standard-BiDi capability, typed command planning, dated-TR provenance pin, and explicit viewport/DPR cleanup intent, preserving exact-head visual, rustdoc-view, transport, and real-browser evidence gaps. - Recorded the server Close-role RED-to-GREEN repair with exact local coverage and visual evidence, keeping queued hosted checks and release acceptance separate. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index a1f275fea..e9e750c10 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -45,15 +45,17 @@ shipped behavior. Draft #293 advanced from visually inspected predecessor `6b5241c164f5283f8dd51b1846ef0e4dacec0b29` to exact head -`30941dc0d0b2640f14c9b66ff32b05ea58082d38` on parent #229. Its executed RED -showed that standard BiDi was overstating complete Screen and Languages -support. The minimal repair retains only Viewport, DevicePixelRatio, TimeZone -and ReducedMotion. The current head binds three typed command intents for those -four surfaces to one bounded opaque browsing context without sending them or -minting evidence. Exact local coverage is **592/4960/5966/754**, all 100%; 159 +`0c077445` on parent #229. Its executed RED showed that standard BiDi was +overstating complete Screen and Languages support. The minimal repair retains +only Viewport, DevicePixelRatio, TimeZone and ReducedMotion, pins the immutable +3 September 2026 dated W3C Working Draft identity, and adds an explicit typed +viewport/DPR reset intent because session teardown does not clear that override. +The current head binds three command intents for those four surfaces plus one +cleanup intent to one bounded opaque browsing context without sending them or +minting evidence. Exact local coverage is **594/4974/5980/754**, all 100%; 159 repository contracts, strict Clippy, formatting, doctests and warnings-denied -rustdoc pass. Exact-head Edge inspection was attempted, but the extension -session repeatedly timed out; current-head visual acceptance is unproven. +rustdoc pass. Exact-head Edge inspection was attempted, but the foreground Edge +tab was a different repository and was not navigated; current-head visual acceptance is unproven. Generated-rustdoc inspection is separately blocked by local-file browser policy. The Draft is CLEAN; real Chromium application and page-observed evidence remain in #292. diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 3e588cfcd..9cd70908a 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -32,8 +32,8 @@ def test_ack_checkpoint_separates_local_repair_from_review_acceptance(self) -> N "1105/11574/14787/1218", "34188785932", "server-sent", "RED", "1010", "1011", "Actual Edge", "terminal SUCCESS", "6b5241c164f5283f8dd51b1846ef0e4dacec0b29", "predecessor", - "30941dc0d0b2640f14c9b66ff32b05ea58082d38", - "592/4960/5966/754", "#293", "three typed command intents", + "0c077445", "594/4974/5980/754", "#293", "three command intents", + "3 September 2026", "viewport/DPR reset intent", "current-head visual acceptance is unproven", "Viewport", "DevicePixelRatio", "TimeZone", "ReducedMotion", ): From f4ac8da20b6a32b10d88f8eca52435f96a9b24d5 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 06:10:50 +0900 Subject: [PATCH 231/250] test(docs): fail closed on live evidence provenance --- ...st_live_gap_evidence_integrity_contract.py | 81 +++++++++++++++++++ 1 file changed, 81 insertions(+) create mode 100644 tests/test_live_gap_evidence_integrity_contract.py diff --git a/tests/test_live_gap_evidence_integrity_contract.py b/tests/test_live_gap_evidence_integrity_contract.py new file mode 100644 index 000000000..6e56ebaaf --- /dev/null +++ b/tests/test_live_gap_evidence_integrity_contract.py @@ -0,0 +1,81 @@ +"""Fail-closed contracts for the current product-gap evidence procedure.""" + +from pathlib import Path +import unittest + + +ROOT = Path(__file__).resolve().parents[1] +BASELINE = ROOT / "docs" / "product-technical-gap-baseline.md" +CHANGELOG = ROOT / "CHANGELOG.md" + + +def bounded(text: str, start: str, end: str) -> str: + """Return one current section without accepting a historical substitute.""" + if start not in text: + raise AssertionError(f"missing start marker: {start}") + remainder = text.split(start, 1)[1] + if end not in remainder: + raise AssertionError(f"missing end marker after {start}: {end}") + return remainder.split(end, 1)[0] + + +class LiveGapEvidenceIntegrityContractTests(unittest.TestCase): + """Keep merge evidence bound to the exact current PR state.""" + + @classmethod + def setUpClass(cls) -> None: + cls.baseline = BASELINE.read_text(encoding="utf-8") + cls.changelog = CHANGELOG.read_text(encoding="utf-8") + cls.latest = bounded( + cls.baseline, + "### Latest verified cut: 2026-09-08", + "### Historical verified cut: 2026-09-07", + ) + cls.evidence = cls.baseline.split("## Evidence commands", 1)[1] + + def test_latest_inventory_and_changelog_use_the_september_8_cut(self) -> None: + marker = ( + "126 open pull requests: 12 Ready/non-draft and " + "114 Draft; 14 open non-PR issues" + ) + self.assertIn(marker, " ".join(self.latest.split())) + inventory = [ + line + for line in self.changelog.splitlines() + if line.startswith("- Current delivery inventory:") + ] + self.assertEqual(1, len(inventory)) + self.assertIn("126 open pull requests (12 ready, 114 draft)", inventory[0]) + self.assertIn("14 open non-PR issues", inventory[0]) + self.assertIn("Observed 2026-09-08", inventory[0]) + + def test_presentation_snapshot_uses_full_exact_sha(self) -> None: + full_sha = "0c077445d73640a6299ea4d379faa4b0ab0226c2" + self.assertIn(full_sha, self.latest) + self.assertNotIn("to exact head\n`0c077445`", self.latest) + + def test_current_change_requests_block_the_approval_verdict(self) -> None: + self.assertIn("as $current_change_requests", self.evidence) + self.assertIn("blocking_change_requests: $current_change_requests", self.evidence) + self.assertIn("($current_change_requests | length) == 0", self.evidence) + + def test_every_unresolved_thread_remains_blocking_when_outdated(self) -> None: + self.assertIn("select(.isResolved == false)", self.evidence) + self.assertNotIn( + "select(.isResolved == false and .isOutdated == false)", + self.evidence, + ) + + def test_workflow_evidence_is_bound_to_pr_head_and_base(self) -> None: + for marker in ( + ".number == ($pr[0].number)", + ".head.sha == $head", + ".base.sha == $base", + ): + with self.subTest(marker=marker): + self.assertIn(marker, self.evidence) + self.assertIn("workflow_runs_without_exact_pr_base_provenance", self.evidence) + + +if __name__ == "__main__": + unittest.main() From bab87196d907b7947c5cd6780969084f102c48ac Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 06:13:00 +0900 Subject: [PATCH 232/250] fix(docs): bind merge evidence to current authority --- scripts/ci/collect_live_merge_evidence.sh | 197 ++++++++++++++++++++++ 1 file changed, 197 insertions(+) create mode 100644 scripts/ci/collect_live_merge_evidence.sh diff --git a/scripts/ci/collect_live_merge_evidence.sh b/scripts/ci/collect_live_merge_evidence.sh new file mode 100644 index 000000000..db8e6a355 --- /dev/null +++ b/scripts/ci/collect_live_merge_evidence.sh @@ -0,0 +1,197 @@ +#!/usr/bin/env bash +set -euo pipefail + +REPOSITORY="${ORIGINWEAVE_REPOSITORY:-ContextualWisdomLab/OriginWeave}" +EVIDENCE_DIR="${1:-$(mktemp -d /tmp/originweave-evidence.XXXXXX)}" +mkdir -p "$EVIDENCE_DIR" +printf 'Evidence directory: %s\n' "$EVIDENCE_DIR" >&2 + +gh api --paginate --slurp "repos/$REPOSITORY/pulls?state=open&per_page=100" \ + > "$EVIDENCE_DIR/open-pr-pages.json" +jq '[.[][]]' "$EVIDENCE_DIR/open-pr-pages.json" \ + > "$EVIDENCE_DIR/open-prs.json" +jq '{ + open_pull_requests: length, + non_draft: (map(select(.draft == false)) | length), + draft: (map(select(.draft == true)) | length) +}' "$EVIDENCE_DIR/open-prs.json" + +gh api --paginate --slurp "repos/$REPOSITORY/issues?state=open&per_page=100" \ + > "$EVIDENCE_DIR/open-issue-pages.json" +jq '[.[][]] | map(select(has("pull_request") | not)) | { + open_non_pr_issues: length +}' "$EVIDENCE_DIR/open-issue-pages.json" + +gh api "repos/$REPOSITORY/branches/main" \ + > "$EVIDENCE_DIR/main-branch.json" +gh api --paginate --slurp \ + "repos/$REPOSITORY/rules/branches/main?per_page=100" \ + > "$EVIDENCE_DIR/main-branch-rule-pages.json" +jq '[.[][]]' "$EVIDENCE_DIR/main-branch-rule-pages.json" \ + > "$EVIDENCE_DIR/main-branch-rules.json" +gh api --paginate --slurp \ + "repos/$REPOSITORY/collaborators?affiliation=all&per_page=100" \ + > "$EVIDENCE_DIR/collaborator-pages.json" +jq '[.[][]]' "$EVIDENCE_DIR/collaborator-pages.json" \ + > "$EVIDENCE_DIR/collaborators.json" + +jq -r '.[].number' "$EVIDENCE_DIR/open-prs.json" | while read -r PR; do + STABLE_HEAD=false + for ATTEMPT in 1 2 3; do + VERDICT_PATH="$EVIDENCE_DIR/pr-${PR}-merge-verdict.json" + VERDICT_TMP="$EVIDENCE_DIR/pr-${PR}-merge-verdict.json.tmp" + PR_JSON="$EVIDENCE_DIR/pr-${PR}.json" + RECHECKED_PR_JSON="$EVIDENCE_DIR/pr-${PR}-rechecked.json" + rm -f "$VERDICT_PATH" "$VERDICT_TMP" "$RECHECKED_PR_JSON" + + gh api "repos/$REPOSITORY/pulls/$PR" > "$PR_JSON" + HEAD_SHA=$(jq -r '.head.sha' "$PR_JSON") + BASE_SHA=$(jq -r '.base.sha' "$PR_JSON") + + gh api --paginate --slurp \ + "repos/$REPOSITORY/commits/$HEAD_SHA/check-runs?per_page=100" \ + > "$EVIDENCE_DIR/pr-${PR}-check-runs.json" + gh api --paginate --slurp \ + "repos/$REPOSITORY/commits/$HEAD_SHA/statuses?per_page=100" \ + > "$EVIDENCE_DIR/pr-${PR}-statuses.json" + gh api --paginate --slurp \ + "repos/$REPOSITORY/pulls/$PR/reviews?per_page=100" \ + > "$EVIDENCE_DIR/pr-${PR}-reviews.json" + gh api --paginate --slurp \ + "repos/$REPOSITORY/actions/runs?head_sha=$HEAD_SHA&per_page=100" \ + > "$EVIDENCE_DIR/pr-${PR}-workflow-runs.json" + gh api graphql --paginate --slurp \ + -F owner="${REPOSITORY%%/*}" \ + -F name="${REPOSITORY#*/}" \ + -F number="$PR" \ + -f query=' +query($owner: String!, $name: String!, $number: Int!, $endCursor: String) { + repository(owner: $owner, name: $name) { + pullRequest(number: $number) { + reviewThreads(first: 100, after: $endCursor) { + nodes { id isResolved isOutdated } + pageInfo { hasNextPage endCursor } + } + } + } +}' > "$EVIDENCE_DIR/pr-${PR}-review-threads.json" + + jq -n \ + --arg head "$HEAD_SHA" \ + --arg base "$BASE_SHA" \ + --slurpfile pr "$PR_JSON" \ + --slurpfile checks "$EVIDENCE_DIR/pr-${PR}-check-runs.json" \ + --slurpfile statuses "$EVIDENCE_DIR/pr-${PR}-statuses.json" \ + --slurpfile reviews "$EVIDENCE_DIR/pr-${PR}-reviews.json" \ + --slurpfile workflow_runs "$EVIDENCE_DIR/pr-${PR}-workflow-runs.json" \ + --slurpfile rules "$EVIDENCE_DIR/main-branch-rules.json" \ + --slurpfile collaborators "$EVIDENCE_DIR/collaborators.json" \ + --slurpfile threads "$EVIDENCE_DIR/pr-${PR}-review-threads.json" \ + '( + [ + $rules[][]? + | select(.type == "pull_request") + | .parameters + ] | first // {} + ) as $pull_request_parameters + | ( + [ + $reviews[][][]? + | {reviewer: .user.login, state, submitted_at, commit_id} + | select(.submitted_at != null) + | select(.state == "APPROVED" or .state == "CHANGES_REQUESTED") + | select(.reviewer != $pr[0].user.login) + | select(.reviewer as $reviewer | + any($collaborators[][]?; + .login == $reviewer and + (.permissions.push == true or + .permissions.maintain == true or + .permissions.admin == true))) + ] + | group_by(.reviewer) + | map(sort_by(.submitted_at) | last) + ) as $current_review_decisions + | ( + $current_review_decisions + | map(select(.state == "APPROVED" and .commit_id == $head)) + ) as $current_approvals + | ( + $current_review_decisions + | map(select(.state == "CHANGES_REQUESTED")) + ) as $current_change_requests + | ( + [$workflow_runs[][].workflow_runs[]?] + ) as $all_workflow_runs + | ( + $all_workflow_runs + | map(select( + any(.pull_requests[]?; + .number == ($pr[0].number) and + .head.sha == $head and + .base.sha == $base) + )) + ) as $exact_pr_base_workflow_runs + | ($pull_request_parameters.required_approving_review_count // 0) as $required_review_count + | ($pull_request_parameters.require_last_push_approval // false) as $require_last_push_approval + | { + head_sha: $head, + base_sha: $base, + required_status_checks: { + check_runs: [$checks[][].check_runs[]?], + legacy_statuses: [$statuses[][][]?] + }, + workflow_runs: $exact_pr_base_workflow_runs, + workflow_runs_without_exact_pr_base_provenance: ( + ($all_workflow_runs | length) - ($exact_pr_base_workflow_runs | length) + ), + counted_approvals: ($current_approvals | length), + blocking_change_requests: $current_change_requests, + required_approving_review_count: $required_review_count, + require_last_push_approval: $require_last_push_approval, + last_push_approval_authority: ( + if $require_last_push_approval == true + then "github_rule_evaluation_required" + else "not_required" + end + ), + approval_gate_satisfied: ( + if $require_last_push_approval == true then false + else ( + (($current_approvals | length) >= $required_review_count) and + (($current_change_requests | length) == 0) + ) + end + ), + required_workflows: [ + $rules[][]? + | select(.type == "workflows") + | .parameters.workflows[] + ], + unresolved_threads: [ + $threads[][].data.repository.pullRequest.reviewThreads.nodes[]? + | select(.isResolved == false) + ] + }' > "$VERDICT_TMP" + + RECHECKED_HEAD_SHA=$(gh api "repos/$REPOSITORY/pulls/$PR" \ + | tee "$RECHECKED_PR_JSON" \ + | jq -r '.head.sha') + RECHECKED_BASE_SHA=$(jq -r '.base.sha' "$RECHECKED_PR_JSON") + if [[ "$RECHECKED_HEAD_SHA" == "$HEAD_SHA" && "$RECHECKED_BASE_SHA" == "$BASE_SHA" ]]; then + mv "$VERDICT_TMP" "$VERDICT_PATH" + mv "$RECHECKED_PR_JSON" "$PR_JSON" + STABLE_HEAD=true + break + fi + + rm -f "$VERDICT_TMP" "$RECHECKED_PR_JSON" + printf 'Discarding moving head/base evidence for PR #%s (head %s -> %s, base %s -> %s) and retrying.\n' \ + "$PR" "$HEAD_SHA" "$RECHECKED_HEAD_SHA" "$BASE_SHA" "$RECHECKED_BASE_SHA" >&2 + done + + if [[ "$STABLE_HEAD" != true ]]; then + rm -f "$EVIDENCE_DIR"/pr-${PR}-*.json + printf 'Unable to collect stable exact-head/base evidence for PR #%s after 3 attempts.\n' "$PR" >&2 + exit 1 + fi +done From ac7e4b816e11845f045b2d1a405515a798079849 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 06:15:47 +0900 Subject: [PATCH 233/250] test(docs): bind queue contract to September 8 cut --- ...cumentation_active_pr_evidence_contract.py | 28 +++++++++++++++---- 1 file changed, 23 insertions(+), 5 deletions(-) diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index e62b1dc83..f319c48a3 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -89,11 +89,18 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] self.assertIn("on 2026-09-05", refresh_line) - current = bounded_section( + latest_cut = bounded_section( self.baseline, - "#### Published session-end reply binding: 05:35 UTC", - "#### Published status-response repair: 04:45 UTC", + "### Latest verified cut: 2026-09-08", + "### Historical verified cut: 2026-09-07", ) + current = bounded_section( + latest_cut, + "#### Transport-closure verification and test-integrity repair", + "### Historical verified cut: 2026-09-07", + ) if "### Historical verified cut: 2026-09-07" in latest_cut else latest_cut.split( + "#### Transport-closure verification and test-integrity repair", 1 + )[1] queue_counts = re.findall( r"\*\*(\d+) open pull requests: (\d+) Ready/non-draft and (\d+) Draft; " r"(\d+) open non-PR issues\*\*", @@ -126,11 +133,22 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: def test_latest_inventory_drift_cannot_be_hidden_by_historical_counts(self) -> None: """Changing only the newest count must invalidate an unchanged changelog.""" + latest = bounded_section( + self.baseline, + "### Latest verified cut: 2026-09-08", + "### Historical verified cut: 2026-09-07", + ) + self.assertIn("126 open pull requests", latest) + mutated_latest = latest.replace( + "126 open pull requests", + "127 open pull requests", + 1, + ) + self.assertNotEqual(latest, mutated_latest) probe = ActivePullRequestDocumentationContractTests( "test_baseline_refresh_changelog_matches_the_live_snapshot" ) - probe.baseline = self.baseline.replace("125 open", "126 open", 1) - self.assertNotEqual(self.baseline, probe.baseline) + probe.baseline = self.baseline.replace(latest, mutated_latest, 1) probe.changelog = self.changelog with self.assertRaises(AssertionError): probe.test_baseline_refresh_changelog_matches_the_live_snapshot() From 60374c64045f25d44492472b4bc6c33999773218 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 06:16:11 +0900 Subject: [PATCH 234/250] test(docs): separate executable evidence contract --- tests/test_live_gap_evidence_integrity_contract.py | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/tests/test_live_gap_evidence_integrity_contract.py b/tests/test_live_gap_evidence_integrity_contract.py index 6e56ebaaf..fc20d1ace 100644 --- a/tests/test_live_gap_evidence_integrity_contract.py +++ b/tests/test_live_gap_evidence_integrity_contract.py @@ -7,6 +7,7 @@ ROOT = Path(__file__).resolve().parents[1] BASELINE = ROOT / "docs" / "product-technical-gap-baseline.md" CHANGELOG = ROOT / "CHANGELOG.md" +EVIDENCE_SCRIPT = ROOT / "scripts" / "ci" / "collect_live_merge_evidence.sh" def bounded(text: str, start: str, end: str) -> str: @@ -26,12 +27,12 @@ class LiveGapEvidenceIntegrityContractTests(unittest.TestCase): def setUpClass(cls) -> None: cls.baseline = BASELINE.read_text(encoding="utf-8") cls.changelog = CHANGELOG.read_text(encoding="utf-8") + cls.evidence = EVIDENCE_SCRIPT.read_text(encoding="utf-8") cls.latest = bounded( cls.baseline, "### Latest verified cut: 2026-09-08", "### Historical verified cut: 2026-09-07", ) - cls.evidence = cls.baseline.split("## Evidence commands", 1)[1] def test_latest_inventory_and_changelog_use_the_september_8_cut(self) -> None: marker = ( @@ -54,6 +55,10 @@ def test_presentation_snapshot_uses_full_exact_sha(self) -> None: self.assertIn(full_sha, self.latest) self.assertNotIn("to exact head\n`0c077445`", self.latest) + def test_baseline_names_the_executable_current_evidence_collector(self) -> None: + current_evidence = self.baseline.split("## Evidence commands", 1)[1] + self.assertIn("scripts/ci/collect_live_merge_evidence.sh", current_evidence) + def test_current_change_requests_block_the_approval_verdict(self) -> None: self.assertIn("as $current_change_requests", self.evidence) self.assertIn("blocking_change_requests: $current_change_requests", self.evidence) From 3e7e48844c6f47ac39a02261a4f8afbc1d619ba4 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 06:22:00 +0900 Subject: [PATCH 235/250] test(docs): validate evidence collector syntax and stability --- ...st_live_gap_evidence_integrity_contract.py | 20 +++++++++++++++++++ 1 file changed, 20 insertions(+) diff --git a/tests/test_live_gap_evidence_integrity_contract.py b/tests/test_live_gap_evidence_integrity_contract.py index fc20d1ace..c9dd075f3 100644 --- a/tests/test_live_gap_evidence_integrity_contract.py +++ b/tests/test_live_gap_evidence_integrity_contract.py @@ -1,6 +1,7 @@ """Fail-closed contracts for the current product-gap evidence procedure.""" from pathlib import Path +import subprocess import unittest @@ -59,6 +60,16 @@ def test_baseline_names_the_executable_current_evidence_collector(self) -> None: current_evidence = self.baseline.split("## Evidence commands", 1)[1] self.assertIn("scripts/ci/collect_live_merge_evidence.sh", current_evidence) + def test_evidence_collector_is_valid_bash(self) -> None: + result = subprocess.run( + ["bash", "-n", str(EVIDENCE_SCRIPT)], + cwd=ROOT, + check=False, + capture_output=True, + text=True, + ) + self.assertEqual(0, result.returncode, result.stderr) + def test_current_change_requests_block_the_approval_verdict(self) -> None: self.assertIn("as $current_change_requests", self.evidence) self.assertIn("blocking_change_requests: $current_change_requests", self.evidence) @@ -81,6 +92,15 @@ def test_workflow_evidence_is_bound_to_pr_head_and_base(self) -> None: self.assertIn(marker, self.evidence) self.assertIn("workflow_runs_without_exact_pr_base_provenance", self.evidence) + def test_verdict_materializes_only_after_head_and_base_stabilize(self) -> None: + for marker in ( + 'RECHECKED_HEAD_SHA=$(gh api "repos/$REPOSITORY/pulls/$PR"', + "RECHECKED_BASE_SHA=$(jq -r '.base.sha' \"$RECHECKED_PR_JSON\")", + '[[ "$RECHECKED_HEAD_SHA" == "$HEAD_SHA" && "$RECHECKED_BASE_SHA" == "$BASE_SHA" ]]', + ): + with self.subTest(marker=marker): + self.assertIn(marker, self.evidence) + if __name__ == "__main__": unittest.main() From 257f2ed15cd2e555316df252a526e41198556eaa Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 11:31:18 +0900 Subject: [PATCH 236/250] experiment: align live evidence contracts (#296) --- AGENTS.md | 1 + CHANGELOG.md | 2 +- CLAUDE.md | 1 + docs/product-technical-gap-baseline.md | 4 +++- 4 files changed, 6 insertions(+), 2 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index 0592cb3a4..81425046e 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -130,6 +130,7 @@ A release requires all current-head checks, complete coverage and docs, updated ## Verified maintenance lessons - When updating a delivery checkpoint, separate a verified predecessor from a newer pending head. A passing coverage summary does not validate a fixture that ignores peer errors; preserve the failing reproduction and the repaired wire-level assertions in the evidence trail. +- A live-inventory contract must update its dated baseline, `CHANGELOG.md`, and full exact SHA together. Use `scripts/ci/collect_live_merge_evidence.sh` for reusable head/base evidence; do not infer current state from an abbreviated SHA or a historical inventory line. - Add concise, reproducible lessons here as work establishes them. Keep transient heads, job IDs and incident snapshots in PR evidence, not permanent instructions; never record secret values. - Retained receipt recovery is not live-stream recovery. State whether a fixture keeps the original connection open and uses the same endpoint; claim live recovery only when a synchronized test reads and completes the original request after rejecting the replacement reply. diff --git a/CHANGELOG.md b/CHANGELOG.md index 589a073b3..84207cb33 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -28,7 +28,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Recorded the verified pointer-reply connection repair and recovery tests, keeping pending hosted checks, remaining authority gaps and browser acceptance separate. - Recorded the published text-entry connection safeguards and their test evidence, separating queued hosted checks and remaining pointer/status repairs from released browser behavior. - Separate the current maintenance queue and source lineage from preserved historical observations, and record the text-entry session and pending-request safeguards without claiming released browser behavior. -- Current delivery inventory: 125 open pull requests (12 ready, 113 draft); 14 open non-PR issues. Observed 2026-09-07; source acceptance remains revision-specific. +- Current delivery inventory: 126 open pull requests (12 ready, 114 draft); 14 open non-PR issues. Observed 2026-09-08; source acceptance remains revision-specific. - Corrected historical checkpoint labels and made the current inventory check reject stale counts; recorded verified text-input parent adoption without claiming browser execution. - Recorded the executed session-isolation repair and its verified adoption, separating complete local checks and PR visual inspection from pending hosted checks and unreleased browser acceptance. - Recorded the current click safeguards, restored regression coverage and completed PR visual inspection, keeping the separately owned parent repair and queued hosted checks distinct from delivery. diff --git a/CLAUDE.md b/CLAUDE.md index ab08bc16f..cbeb8220b 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -12,3 +12,4 @@ Additional constraints: - Do not add hostname reconnect, proxy-environment inheritance, dangerous certificate-verifier hooks, Common Name fallback, TLS 0-RTT, key logging, or secret extraction to a production TLS path. - Keep changes bounded to one product gap and preserve modular crate boundaries. - Never claim a test, benchmark, browser integration, TLS identity, GPU execution, release, or merge succeeded without current exact-head evidence. +- When refreshing live delivery evidence, update the dated baseline, `CHANGELOG.md`, and full exact SHA atomically; use `scripts/ci/collect_live_merge_evidence.sh` rather than an abbreviated SHA or historical count. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e9e750c10..315696654 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -45,7 +45,7 @@ shipped behavior. Draft #293 advanced from visually inspected predecessor `6b5241c164f5283f8dd51b1846ef0e4dacec0b29` to exact head -`0c077445` on parent #229. Its executed RED showed that standard BiDi was +`0c077445d73640a6299ea4d379faa4b0ab0226c2` on parent #229. Its executed RED showed that standard BiDi was overstating complete Screen and Languages support. The minimal repair retains only Viewport, DevicePixelRatio, TimeZone and ReducedMotion, pins the immutable 3 September 2026 dated W3C Working Draft identity, and adds an explicit typed @@ -1250,6 +1250,8 @@ OriginWeave is not complete merely because every low-level primitive exists in s ## Evidence commands +Run `scripts/ci/collect_live_merge_evidence.sh` to collect reusable, exact-head and exact-base merge evidence before interpreting the volatile inventory below. + The volatile counts above are reproducible by paginating the complete open-PR and open-issue inventories, excluding pull requests from the issue count, flattening every page, and then inspecting each PR's exact head, checks, reviews, and review threads: ```bash From 45aaaedf871e6cd9b192af119fb79db5e34c7464 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 13:09:12 +0900 Subject: [PATCH 237/250] test(docs): fail closed on unstable live evidence generations --- ...st_live_gap_evidence_integrity_contract.py | 42 ++++++++++++++++--- 1 file changed, 37 insertions(+), 5 deletions(-) diff --git a/tests/test_live_gap_evidence_integrity_contract.py b/tests/test_live_gap_evidence_integrity_contract.py index c9dd075f3..6910b1d0a 100644 --- a/tests/test_live_gap_evidence_integrity_contract.py +++ b/tests/test_live_gap_evidence_integrity_contract.py @@ -8,6 +8,7 @@ ROOT = Path(__file__).resolve().parents[1] BASELINE = ROOT / "docs" / "product-technical-gap-baseline.md" CHANGELOG = ROOT / "CHANGELOG.md" +AGENTS = ROOT / "AGENTS.md" EVIDENCE_SCRIPT = ROOT / "scripts" / "ci" / "collect_live_merge_evidence.sh" @@ -28,6 +29,7 @@ class LiveGapEvidenceIntegrityContractTests(unittest.TestCase): def setUpClass(cls) -> None: cls.baseline = BASELINE.read_text(encoding="utf-8") cls.changelog = CHANGELOG.read_text(encoding="utf-8") + cls.agents = AGENTS.read_text(encoding="utf-8") cls.evidence = EVIDENCE_SCRIPT.read_text(encoding="utf-8") cls.latest = bounded( cls.baseline, @@ -58,7 +60,8 @@ def test_presentation_snapshot_uses_full_exact_sha(self) -> None: def test_baseline_names_the_executable_current_evidence_collector(self) -> None: current_evidence = self.baseline.split("## Evidence commands", 1)[1] - self.assertIn("scripts/ci/collect_live_merge_evidence.sh", current_evidence) + self.assertIn("bash scripts/ci/collect_live_merge_evidence.sh", current_evidence) + self.assertIn("bash scripts/ci/collect_live_merge_evidence.sh", self.agents) def test_evidence_collector_is_valid_bash(self) -> None: result = subprocess.run( @@ -92,11 +95,40 @@ def test_workflow_evidence_is_bound_to_pr_head_and_base(self) -> None: self.assertIn(marker, self.evidence) self.assertIn("workflow_runs_without_exact_pr_base_provenance", self.evidence) - def test_verdict_materializes_only_after_head_and_base_stabilize(self) -> None: + def test_rules_are_evaluated_for_each_pull_requests_actual_base(self) -> None: for marker in ( - 'RECHECKED_HEAD_SHA=$(gh api "repos/$REPOSITORY/pulls/$PR"', - "RECHECKED_BASE_SHA=$(jq -r '.base.sha' \"$RECHECKED_PR_JSON\")", - '[[ "$RECHECKED_HEAD_SHA" == "$HEAD_SHA" && "$RECHECKED_BASE_SHA" == "$BASE_SHA" ]]', + "BASE_REF=$(jq -r '.base.ref' \"$PR_JSON\")", + 'BASE_REF_ENCODED=$(jq -rn --arg value "$BASE_REF" \'$value | @uri\')', + '"repos/$REPOSITORY/rules/branches/$BASE_REF_ENCODED?per_page=100"', + '--slurpfile rules "$EVIDENCE_DIR/pr-${PR}-branch-rules.json"', + ): + with self.subTest(marker=marker): + self.assertIn(marker, self.evidence) + self.assertNotIn( + '--slurpfile rules "$EVIDENCE_DIR/main-branch-rules.json"', + self.evidence, + ) + + def test_verdict_materializes_only_after_inventory_and_final_state_stabilize(self) -> None: + for marker in ( + "INVENTORY_DRAFT=$(jq -r --argjson pr \"$PR\"", + "PR_STATE=$(jq -r '.state' \"$PR_JSON\")", + "PR_DRAFT=$(jq -r '.draft' \"$PR_JSON\")", + "RECHECKED_STATE=$(jq -r '.state' \"$RECHECKED_PR_JSON\")", + "RECHECKED_DRAFT=$(jq -r '.draft' \"$RECHECKED_PR_JSON\")", + '"$PR_STATE" == "open"', + '"$RECHECKED_STATE" == "$PR_STATE"', + '"$RECHECKED_DRAFT" == "$PR_DRAFT"', + '"$PR_DRAFT" == "$INVENTORY_DRAFT"', + ): + with self.subTest(marker=marker): + self.assertIn(marker, self.evidence) + + def test_explicit_evidence_directory_must_start_empty(self) -> None: + for marker in ( + 'if [[ $# -gt 0 ]]; then', + 'find "$EVIDENCE_DIR" -mindepth 1 -print -quit', + 'Evidence directory must be empty:', ): with self.subTest(marker=marker): self.assertIn(marker, self.evidence) From 67151a6ac90e994c360f2500be783fc05fc95354 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 13:09:49 +0900 Subject: [PATCH 238/250] fix(docs): bind live evidence to final PR state --- scripts/ci/collect_live_merge_evidence.sh | 50 +++++++++++++++++++---- 1 file changed, 43 insertions(+), 7 deletions(-) diff --git a/scripts/ci/collect_live_merge_evidence.sh b/scripts/ci/collect_live_merge_evidence.sh index db8e6a355..d204b1ce4 100644 --- a/scripts/ci/collect_live_merge_evidence.sh +++ b/scripts/ci/collect_live_merge_evidence.sh @@ -2,8 +2,23 @@ set -euo pipefail REPOSITORY="${ORIGINWEAVE_REPOSITORY:-ContextualWisdomLab/OriginWeave}" -EVIDENCE_DIR="${1:-$(mktemp -d /tmp/originweave-evidence.XXXXXX)}" -mkdir -p "$EVIDENCE_DIR" +if [[ $# -gt 0 ]]; then + EVIDENCE_DIR="$1" + if [[ -e "$EVIDENCE_DIR" ]]; then + if [[ ! -d "$EVIDENCE_DIR" ]]; then + printf 'Evidence path is not a directory: %s\n' "$EVIDENCE_DIR" >&2 + exit 1 + fi + if [[ -n "$(find "$EVIDENCE_DIR" -mindepth 1 -print -quit)" ]]; then + printf 'Evidence directory must be empty: %s\n' "$EVIDENCE_DIR" >&2 + exit 1 + fi + else + mkdir -p "$EVIDENCE_DIR" + fi +else + EVIDENCE_DIR="$(mktemp -d /tmp/originweave-evidence.XXXXXX)" +fi printf 'Evidence directory: %s\n' "$EVIDENCE_DIR" >&2 gh api --paginate --slurp "repos/$REPOSITORY/pulls?state=open&per_page=100" \ @@ -37,6 +52,8 @@ jq '[.[][]]' "$EVIDENCE_DIR/collaborator-pages.json" \ jq -r '.[].number' "$EVIDENCE_DIR/open-prs.json" | while read -r PR; do STABLE_HEAD=false + INVENTORY_DRAFT=$(jq -r --argjson pr "$PR" \ + '.[] | select(.number == $pr) | .draft' "$EVIDENCE_DIR/open-prs.json") for ATTEMPT in 1 2 3; do VERDICT_PATH="$EVIDENCE_DIR/pr-${PR}-merge-verdict.json" VERDICT_TMP="$EVIDENCE_DIR/pr-${PR}-merge-verdict.json.tmp" @@ -47,7 +64,16 @@ jq -r '.[].number' "$EVIDENCE_DIR/open-prs.json" | while read -r PR; do gh api "repos/$REPOSITORY/pulls/$PR" > "$PR_JSON" HEAD_SHA=$(jq -r '.head.sha' "$PR_JSON") BASE_SHA=$(jq -r '.base.sha' "$PR_JSON") + BASE_REF=$(jq -r '.base.ref' "$PR_JSON") + PR_STATE=$(jq -r '.state' "$PR_JSON") + PR_DRAFT=$(jq -r '.draft' "$PR_JSON") + BASE_REF_ENCODED=$(jq -rn --arg value "$BASE_REF" '$value | @uri') + gh api --paginate --slurp \ + "repos/$REPOSITORY/rules/branches/$BASE_REF_ENCODED?per_page=100" \ + > "$EVIDENCE_DIR/pr-${PR}-branch-rule-pages.json" + jq '[.[][]]' "$EVIDENCE_DIR/pr-${PR}-branch-rule-pages.json" \ + > "$EVIDENCE_DIR/pr-${PR}-branch-rules.json" gh api --paginate --slurp \ "repos/$REPOSITORY/commits/$HEAD_SHA/check-runs?per_page=100" \ > "$EVIDENCE_DIR/pr-${PR}-check-runs.json" @@ -84,7 +110,7 @@ query($owner: String!, $name: String!, $number: Int!, $endCursor: String) { --slurpfile statuses "$EVIDENCE_DIR/pr-${PR}-statuses.json" \ --slurpfile reviews "$EVIDENCE_DIR/pr-${PR}-reviews.json" \ --slurpfile workflow_runs "$EVIDENCE_DIR/pr-${PR}-workflow-runs.json" \ - --slurpfile rules "$EVIDENCE_DIR/main-branch-rules.json" \ + --slurpfile rules "$EVIDENCE_DIR/pr-${PR}-branch-rules.json" \ --slurpfile collaborators "$EVIDENCE_DIR/collaborators.json" \ --slurpfile threads "$EVIDENCE_DIR/pr-${PR}-review-threads.json" \ '( @@ -177,7 +203,16 @@ query($owner: String!, $name: String!, $number: Int!, $endCursor: String) { | tee "$RECHECKED_PR_JSON" \ | jq -r '.head.sha') RECHECKED_BASE_SHA=$(jq -r '.base.sha' "$RECHECKED_PR_JSON") - if [[ "$RECHECKED_HEAD_SHA" == "$HEAD_SHA" && "$RECHECKED_BASE_SHA" == "$BASE_SHA" ]]; then + RECHECKED_BASE_REF=$(jq -r '.base.ref' "$RECHECKED_PR_JSON") + RECHECKED_STATE=$(jq -r '.state' "$RECHECKED_PR_JSON") + RECHECKED_DRAFT=$(jq -r '.draft' "$RECHECKED_PR_JSON") + if [[ "$RECHECKED_HEAD_SHA" == "$HEAD_SHA" && \ + "$RECHECKED_BASE_SHA" == "$BASE_SHA" && \ + "$RECHECKED_BASE_REF" == "$BASE_REF" && \ + "$PR_STATE" == "open" && \ + "$RECHECKED_STATE" == "$PR_STATE" && \ + "$RECHECKED_DRAFT" == "$PR_DRAFT" && \ + "$PR_DRAFT" == "$INVENTORY_DRAFT" ]]; then mv "$VERDICT_TMP" "$VERDICT_PATH" mv "$RECHECKED_PR_JSON" "$PR_JSON" STABLE_HEAD=true @@ -185,13 +220,14 @@ query($owner: String!, $name: String!, $number: Int!, $endCursor: String) { fi rm -f "$VERDICT_TMP" "$RECHECKED_PR_JSON" - printf 'Discarding moving head/base evidence for PR #%s (head %s -> %s, base %s -> %s) and retrying.\n' \ - "$PR" "$HEAD_SHA" "$RECHECKED_HEAD_SHA" "$BASE_SHA" "$RECHECKED_BASE_SHA" >&2 + printf 'Discarding moving PR evidence for #%s (head %s -> %s, base %s/%s -> %s/%s, state %s -> %s, draft %s -> %s, inventory draft %s) and retrying.\n' \ + "$PR" "$HEAD_SHA" "$RECHECKED_HEAD_SHA" "$BASE_REF" "$BASE_SHA" "$RECHECKED_BASE_REF" "$RECHECKED_BASE_SHA" \ + "$PR_STATE" "$RECHECKED_STATE" "$PR_DRAFT" "$RECHECKED_DRAFT" "$INVENTORY_DRAFT" >&2 done if [[ "$STABLE_HEAD" != true ]]; then rm -f "$EVIDENCE_DIR"/pr-${PR}-*.json - printf 'Unable to collect stable exact-head/base evidence for PR #%s after 3 attempts.\n' "$PR" >&2 + printf 'Unable to collect stable exact PR evidence for #%s after 3 attempts.\n' "$PR" >&2 exit 1 fi done From 1cf9f56ad886385b691ef8a17f0dce07015a455b Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 13:10:20 +0900 Subject: [PATCH 239/250] test(docs): require collector executable mode --- tests/test_live_gap_evidence_integrity_contract.py | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/tests/test_live_gap_evidence_integrity_contract.py b/tests/test_live_gap_evidence_integrity_contract.py index 6910b1d0a..c33dda050 100644 --- a/tests/test_live_gap_evidence_integrity_contract.py +++ b/tests/test_live_gap_evidence_integrity_contract.py @@ -58,10 +58,11 @@ def test_presentation_snapshot_uses_full_exact_sha(self) -> None: self.assertIn(full_sha, self.latest) self.assertNotIn("to exact head\n`0c077445`", self.latest) - def test_baseline_names_the_executable_current_evidence_collector(self) -> None: + def test_documented_current_evidence_collector_is_executable(self) -> None: current_evidence = self.baseline.split("## Evidence commands", 1)[1] - self.assertIn("bash scripts/ci/collect_live_merge_evidence.sh", current_evidence) - self.assertIn("bash scripts/ci/collect_live_merge_evidence.sh", self.agents) + self.assertIn("scripts/ci/collect_live_merge_evidence.sh", current_evidence) + self.assertIn("scripts/ci/collect_live_merge_evidence.sh", self.agents) + self.assertNotEqual(0, EVIDENCE_SCRIPT.stat().st_mode & 0o111) def test_evidence_collector_is_valid_bash(self) -> None: result = subprocess.run( From f18e799c2544adeb171d64fb6d7eb91f42b9ba38 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 13:10:38 +0900 Subject: [PATCH 240/250] fix(docs): make live evidence collector executable --- scripts/ci/collect_live_merge_evidence.sh | 0 1 file changed, 0 insertions(+), 0 deletions(-) mode change 100644 => 100755 scripts/ci/collect_live_merge_evidence.sh diff --git a/scripts/ci/collect_live_merge_evidence.sh b/scripts/ci/collect_live_merge_evidence.sh old mode 100644 new mode 100755 From 6c04808902920b1852ab401cbd6aaef7cf32013e Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 13:13:00 +0900 Subject: [PATCH 241/250] docs(traceability): bind live merge evidence to stable PR state --- .../live-merge-evidence-stability.md | 53 +++++++++++++++++++ 1 file changed, 53 insertions(+) create mode 100644 docs/traceability/live-merge-evidence-stability.md diff --git a/docs/traceability/live-merge-evidence-stability.md b/docs/traceability/live-merge-evidence-stability.md new file mode 100644 index 000000000..96603a3a7 --- /dev/null +++ b/docs/traceability/live-merge-evidence-stability.md @@ -0,0 +1,53 @@ +# Live merge evidence stability + +## Problem + +`scripts/ci/collect_live_merge_evidence.sh` is the canonical reproducible evidence collector for the volatile delivery baseline. Four review findings showed that its prior contract could produce misleading merge-readiness evidence even while preserving exact head/base SHA fields: + +1. every pull request was evaluated with the rules for `main`, although stacked pull requests can target feature-parent branches with different rule evaluation; +2. the final stability check re-read only head/base, so a pull request could close, reopen, or change Draft state without invalidating the captured inventory and verdict; +3. an explicitly supplied evidence directory could contain artifacts from an earlier generation, allowing closed pull requests or partial failed runs to survive alongside current output; +4. the collector was documented as directly executable while committed without executable mode. + +These are provenance defects, not reasons to close or flatten stacked work. A merge verdict is useful only when the rules, inventory state, PR lifecycle state, and artifacts belong to the same evidence generation. + +## Constraints + +- Preserve exact head and base SHA binding, current review-decision semantics, unresolved-thread blocking, and fail-closed handling of required workflows. +- Do not weaken protected-branch rules, synthesize approvals, or reinterpret stacked children as `main`-based roots. +- Do not delete historical baseline evidence to hide drift. +- Keep the collector repository-native (`bash`, `gh`, `jq`) and deterministic from one fresh destination directory. +- A moving PR may be retried, but a verdict is not materialized until its head, base SHA, base ref, open state, and Draft flag agree between the inventory, initial detail read, and final detail read. + +## Alternatives considered + +**Keep using `main` rules for every PR.** Rejected because branch rules are target-specific and this can both invent blockers for stacked children and miss stricter rules on another base. + +**Refresh only the queue summary after all per-PR work.** Rejected as insufficient: a per-PR verdict could still have been built from rules/reviews/checks belonging to an earlier lifecycle state. + +**Delete or overwrite files in a caller-provided directory.** Rejected because a typo or shared directory could destroy unrelated evidence, and partial cleanup is itself difficult to prove. An explicit destination must instead start empty. + +**Document `bash scripts/ci/collect_live_merge_evidence.sh` and leave mode `100644`.** Valid in principle, but rejected because both the baseline and repository maintenance guidance already expose the script itself as the executable interface. The committed mode is therefore made `100755` instead of changing that interface. + +## Selected repair + +Test-first commit `45aaaedf871e6cd9b192af119fb79db5e34c7464` added fail-closed repository contracts for per-base rules, final state/Draft stability, and empty-generation isolation. Production commit `67151a6ac90e994c360f2500be783fc05fc95354` then: + +- captures `.base.ref` for each PR, URL-encodes it, fetches rules for that exact base, and feeds those rules into that PR's verdict; +- binds the verdict to the original open-inventory Draft flag plus initial/final `state`, `draft`, head SHA, base SHA, and base ref; +- writes the verdict only after those values are stable, otherwise discarding the attempt and retrying up to the existing bounded limit; +- rejects a non-directory or non-empty explicit evidence destination while retaining `mktemp` for the default path. + +Commit `1cf9f56ad886385b691ef8a17f0dce07015a455b` added the executable-mode contract. Commit `f18e799c2544adeb171d64fb6d7eb91f42b9ba38` changes only the Git mode of `scripts/ci/collect_live_merge_evidence.sh` to `100755`; its blob remains `d204b1ce4ada2dcd3e842182e254bc99ea34e725`. + +## Risk and effect + +The collector now makes more GitHub API calls because rules are fetched per base. That cost is accepted: correctness of a merge-readiness dossier is more important than minimizing API requests, and the existing bounded retry prevents infinite collection on moving PRs. An unusually active queue can still fail closed after three unstable attempts; that is preferable to publishing a mixed-generation dossier. + +The change does not establish that any pull request is merge-ready. It only strengthens the provenance of the evidence used to decide that question. + +## Verification and remaining evidence + +Source/tree verification on `f18e799c2544adeb171d64fb6d7eb91f42b9ba38` confirms the collector blob is present with mode `100755`. The current review findings are repaired in source semantics. Hosted CI for this exact head is Draft-admission skipped, while Security Scan, Semgrep, and CodeQL are independently generated; therefore skipped repository tests are not claimed as GREEN. + +Before promotion, the exact current head still requires executable repository contracts and the repository's normal required checks. Any later queue snapshot must be recollected into a fresh directory rather than inheriting files from this evidence generation. \ No newline at end of file From ceecca9d89fa1fcdbe0febf627b258cdb3c1a331 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 13:15:19 +0900 Subject: [PATCH 242/250] test(docs): require whole-generation inventory closure --- ...est_live_gap_evidence_integrity_contract.py | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/tests/test_live_gap_evidence_integrity_contract.py b/tests/test_live_gap_evidence_integrity_contract.py index c33dda050..fe5ba4b02 100644 --- a/tests/test_live_gap_evidence_integrity_contract.py +++ b/tests/test_live_gap_evidence_integrity_contract.py @@ -125,6 +125,24 @@ def test_verdict_materializes_only_after_inventory_and_final_state_stabilize(sel with self.subTest(marker=marker): self.assertIn(marker, self.evidence) + def test_whole_generation_closes_against_fresh_pr_and_issue_inventories(self) -> None: + for marker in ( + 'open-pr-pages-rechecked.json', + 'open-prs-rechecked.json', + 'open-issue-pages-rechecked.json', + 'open-issues-rechecked.json', + 'INITIAL_PR_INVENTORY_PROJECTION=', + 'FINAL_PR_INVENTORY_PROJECTION=', + 'INITIAL_ISSUE_INVENTORY_PROJECTION=', + 'FINAL_ISSUE_INVENTORY_PROJECTION=', + 'Live inventory changed during evidence collection.', + 'rm -f "$EVIDENCE_DIR"/pr-*-merge-verdict.json', + 'evidence-generation.json', + 'complete: true', + ): + with self.subTest(marker=marker): + self.assertIn(marker, self.evidence) + def test_explicit_evidence_directory_must_start_empty(self) -> None: for marker in ( 'if [[ $# -gt 0 ]]; then', From b98c25882a7c4e5464b989b885a0596e2ce539e1 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 13:16:11 +0900 Subject: [PATCH 243/250] fix(docs): close live evidence over the full inventory --- scripts/ci/collect_live_merge_evidence.sh | 74 ++++++++++++++++++++++- 1 file changed, 71 insertions(+), 3 deletions(-) diff --git a/scripts/ci/collect_live_merge_evidence.sh b/scripts/ci/collect_live_merge_evidence.sh index d204b1ce4..f530df1aa 100755 --- a/scripts/ci/collect_live_merge_evidence.sh +++ b/scripts/ci/collect_live_merge_evidence.sh @@ -33,9 +33,10 @@ jq '{ gh api --paginate --slurp "repos/$REPOSITORY/issues?state=open&per_page=100" \ > "$EVIDENCE_DIR/open-issue-pages.json" -jq '[.[][]] | map(select(has("pull_request") | not)) | { - open_non_pr_issues: length -}' "$EVIDENCE_DIR/open-issue-pages.json" +jq '[.[][]] | map(select(has("pull_request") | not))' \ + "$EVIDENCE_DIR/open-issue-pages.json" \ + > "$EVIDENCE_DIR/open-issues.json" +jq '{open_non_pr_issues: length}' "$EVIDENCE_DIR/open-issues.json" gh api "repos/$REPOSITORY/branches/main" \ > "$EVIDENCE_DIR/main-branch.json" @@ -231,3 +232,70 @@ query($owner: String!, $name: String!, $number: Int!, $endCursor: String) { exit 1 fi done + +gh api --paginate --slurp "repos/$REPOSITORY/pulls?state=open&per_page=100" \ + > "$EVIDENCE_DIR/open-pr-pages-rechecked.json" +jq '[.[][]]' "$EVIDENCE_DIR/open-pr-pages-rechecked.json" \ + > "$EVIDENCE_DIR/open-prs-rechecked.json" +gh api --paginate --slurp "repos/$REPOSITORY/issues?state=open&per_page=100" \ + > "$EVIDENCE_DIR/open-issue-pages-rechecked.json" +jq '[.[][]] | map(select(has("pull_request") | not))' \ + "$EVIDENCE_DIR/open-issue-pages-rechecked.json" \ + > "$EVIDENCE_DIR/open-issues-rechecked.json" + +INITIAL_PR_INVENTORY_PROJECTION=$(jq -S -c ' + [.[] | { + number, + draft, + head_sha: .head.sha, + base_ref: .base.ref, + base_sha: .base.sha + }] | sort_by(.number) +' "$EVIDENCE_DIR/open-prs.json") +FINAL_PR_INVENTORY_PROJECTION=$(jq -S -c ' + [.[] | { + number, + draft, + head_sha: .head.sha, + base_ref: .base.ref, + base_sha: .base.sha + }] | sort_by(.number) +' "$EVIDENCE_DIR/open-prs-rechecked.json") +INITIAL_ISSUE_INVENTORY_PROJECTION=$(jq -S -c \ + '[.[] | {number}] | sort_by(.number)' \ + "$EVIDENCE_DIR/open-issues.json") +FINAL_ISSUE_INVENTORY_PROJECTION=$(jq -S -c \ + '[.[] | {number}] | sort_by(.number)' \ + "$EVIDENCE_DIR/open-issues-rechecked.json") + +if [[ "$FINAL_PR_INVENTORY_PROJECTION" != "$INITIAL_PR_INVENTORY_PROJECTION" || \ + "$FINAL_ISSUE_INVENTORY_PROJECTION" != "$INITIAL_ISSUE_INVENTORY_PROJECTION" ]]; then + rm -f "$EVIDENCE_DIR"/pr-*-merge-verdict.json \ + "$EVIDENCE_DIR/evidence-generation.json" + printf 'Live inventory changed during evidence collection. No merge verdict generation is complete.\n' >&2 + exit 1 +fi + +COMPLETED_AT=$(date -u +'%Y-%m-%dT%H:%M:%SZ') +OPEN_PR_COUNT=$(jq 'length' "$EVIDENCE_DIR/open-prs-rechecked.json") +READY_PR_COUNT=$(jq 'map(select(.draft == false)) | length' \ + "$EVIDENCE_DIR/open-prs-rechecked.json") +DRAFT_PR_COUNT=$(jq 'map(select(.draft == true)) | length' \ + "$EVIDENCE_DIR/open-prs-rechecked.json") +OPEN_ISSUE_COUNT=$(jq 'length' "$EVIDENCE_DIR/open-issues-rechecked.json") +jq -n \ + --arg completed_at "$COMPLETED_AT" \ + --argjson open_pull_requests "$OPEN_PR_COUNT" \ + --argjson non_draft "$READY_PR_COUNT" \ + --argjson draft "$DRAFT_PR_COUNT" \ + --argjson open_non_pr_issues "$OPEN_ISSUE_COUNT" \ + '{ + complete: true, + completed_at: $completed_at, + open_pull_requests: $open_pull_requests, + non_draft: $non_draft, + draft: $draft, + open_non_pr_issues: $open_non_pr_issues + }' > "$EVIDENCE_DIR/evidence-generation.json.tmp" +mv "$EVIDENCE_DIR/evidence-generation.json.tmp" \ + "$EVIDENCE_DIR/evidence-generation.json" From a2ddb536e65fa20c3b0832cda946f2799b1914b9 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 13:17:01 +0900 Subject: [PATCH 244/250] docs(traceability): close the complete evidence generation --- .../live-merge-evidence-stability.md | 29 +++++++++++++++---- 1 file changed, 24 insertions(+), 5 deletions(-) diff --git a/docs/traceability/live-merge-evidence-stability.md b/docs/traceability/live-merge-evidence-stability.md index 96603a3a7..97f5d9bd5 100644 --- a/docs/traceability/live-merge-evidence-stability.md +++ b/docs/traceability/live-merge-evidence-stability.md @@ -9,7 +9,9 @@ 3. an explicitly supplied evidence directory could contain artifacts from an earlier generation, allowing closed pull requests or partial failed runs to survive alongside current output; 4. the collector was documented as directly executable while committed without executable mode. -These are provenance defects, not reasons to close or flatten stacked work. A merge verdict is useful only when the rules, inventory state, PR lifecycle state, and artifacts belong to the same evidence generation. +After those four defects were repaired, a second provenance gap remained: the collector checked each PR immediately after collecting that PR, but did not close the whole generation against a fresh inventory after the long all-PR traversal. A PR processed early could therefore close, open, move head/base, or change Draft state while later PRs were still being collected; non-PR issue membership could change for the same reason. Every per-PR verdict might have been valid at its own observation time while the directory as a whole no longer represented one current inventory. + +These are provenance defects, not reasons to close or flatten stacked work. A merge verdict is useful only when the rules, inventory state, PR lifecycle state, and artifacts belong to the same bounded evidence generation. ## Constraints @@ -18,6 +20,7 @@ These are provenance defects, not reasons to close or flatten stacked work. A me - Do not delete historical baseline evidence to hide drift. - Keep the collector repository-native (`bash`, `gh`, `jq`) and deterministic from one fresh destination directory. - A moving PR may be retried, but a verdict is not materialized until its head, base SHA, base ref, open state, and Draft flag agree between the inventory, initial detail read, and final detail read. +- A collection is not complete merely because every per-PR loop returned. Final open-PR and non-PR-issue membership must still match the generation's initial inventory before a completion receipt exists. ## Alternatives considered @@ -25,6 +28,8 @@ These are provenance defects, not reasons to close or flatten stacked work. A me **Refresh only the queue summary after all per-PR work.** Rejected as insufficient: a per-PR verdict could still have been built from rules/reviews/checks belonging to an earlier lifecycle state. +**Treat per-PR final checks as a coherent whole-generation snapshot.** Rejected because those checks occur at different times. With a large queue, an early PR may change after its own recheck but before the collector finishes later PRs. + **Delete or overwrite files in a caller-provided directory.** Rejected because a typo or shared directory could destroy unrelated evidence, and partial cleanup is itself difficult to prove. An explicit destination must instead start empty. **Document `bash scripts/ci/collect_live_merge_evidence.sh` and leave mode `100644`.** Valid in principle, but rejected because both the baseline and repository maintenance guidance already expose the script itself as the executable interface. The committed mode is therefore made `100755` instead of changing that interface. @@ -38,16 +43,30 @@ Test-first commit `45aaaedf871e6cd9b192af119fb79db5e34c7464` added fail-closed r - writes the verdict only after those values are stable, otherwise discarding the attempt and retrying up to the existing bounded limit; - rejects a non-directory or non-empty explicit evidence destination while retaining `mktemp` for the default path. -Commit `1cf9f56ad886385b691ef8a17f0dce07015a455b` added the executable-mode contract. Commit `f18e799c2544adeb171d64fb6d7eb91f42b9ba38` changes only the Git mode of `scripts/ci/collect_live_merge_evidence.sh` to `100755`; its blob remains `d204b1ce4ada2dcd3e842182e254bc99ea34e725`. +Commit `1cf9f56ad886385b691ef8a17f0dce07015a455b` added the executable-mode contract. Commit `f18e799c2544adeb171d64fb6d7eb91f42b9ba38` changes only the Git mode of `scripts/ci/collect_live_merge_evidence.sh` to `100755`; the then-current script blob remained unchanged. + +Fresh review then identified the whole-generation closure gap. Test-first `ceecca9d89fa1fcdbe0febf627b258cdb3c1a331` requires a fresh PR and non-PR-issue inventory at the end of collection, explicit initial/final projections, fail-closed invalidation of merge verdicts when membership or PR head/base/Draft identity drifts, and an `evidence-generation.json` completion receipt. Production `b98c25882a7c4e5464b989b885a0596e2ce539e1` implements that contract: + +- the initial non-PR issue set is materialized as `open-issues.json` rather than only printing its count; +- after all per-PR evidence is collected, open PRs and non-PR issues are fetched again into separate `*-rechecked.json` files; +- PR generation identity compares `{number, draft, head SHA, base ref, base SHA}` sorted by PR number; issue generation identity compares the sorted set of open non-PR issue numbers; +- any mismatch deletes all `pr-*-merge-verdict.json` files, emits a fixed failure diagnostic, and exits non-zero; +- only a stable generation receives `evidence-generation.json` with `complete: true`, completion time, and the final PR/Ready/Draft/non-PR-issue counts. + +The contents-API source update preserved executable mode `100755`; exact tree `3ecd93163027765da1be955cbc03671b1be9e09b` records `scripts/ci/collect_live_merge_evidence.sh` as mode `100755`, blob `f530df1aaf2eb3265037c4a416ddb20d28cb3a46`. ## Risk and effect -The collector now makes more GitHub API calls because rules are fetched per base. That cost is accepted: correctness of a merge-readiness dossier is more important than minimizing API requests, and the existing bounded retry prevents infinite collection on moving PRs. An unusually active queue can still fail closed after three unstable attempts; that is preferable to publishing a mixed-generation dossier. +The collector now makes more GitHub API calls because rules are fetched per base and both PR and issue inventories are fetched again at generation close. That cost is accepted: correctness of a merge-readiness dossier is more important than minimizing API requests, and the existing bounded retry prevents infinite per-PR collection on moving heads. + +An active queue can now cause the whole run to fail after substantial work if membership or PR identity changes before closure. That is deliberate. The raw evidence remains available for RCA, but merge-verdict files are removed and no completion receipt is published, so a partial run cannot be mistaken for a complete generation merely because its directory exists. + +This does not make GitHub observation transactional: review decisions, branch rules, collaborator authority, and workflow state can still change after their individual reads. The selected boundary makes the inventory/lifecycle claim explicit and fail-closed without pretending GitHub supplies a repository-wide snapshot transaction. Future evidence contracts should extend the completion receipt rather than weakening this distinction. The change does not establish that any pull request is merge-ready. It only strengthens the provenance of the evidence used to decide that question. ## Verification and remaining evidence -Source/tree verification on `f18e799c2544adeb171d64fb6d7eb91f42b9ba38` confirms the collector blob is present with mode `100755`. The current review findings are repaired in source semantics. Hosted CI for this exact head is Draft-admission skipped, while Security Scan, Semgrep, and CodeQL are independently generated; therefore skipped repository tests are not claimed as GREEN. +Source/tree verification after `b98c25882a7c4e5464b989b885a0596e2ce539e1` confirms the current collector blob is present with mode `100755`. The original four P2 review findings were resolved after exact-source verification. The whole-generation closure was added as a new test-first successor rather than retroactively claiming the earlier review covered it. -Before promotion, the exact current head still requires executable repository contracts and the repository's normal required checks. Any later queue snapshot must be recollected into a fresh directory rather than inheriting files from this evidence generation. \ No newline at end of file +Hosted repository CI on these Draft heads is admission-skipped, so the new Python contract and Bash syntax check are not claimed as hosted GREEN. Security, Semgrep, and CodeQL run independently and must be evaluated on the final exact head. Before promotion, the exact current head still requires executable repository contracts and the repository's normal required checks. Any later queue snapshot must be recollected into a fresh directory and accepted only when its `evidence-generation.json` receipt exists. \ No newline at end of file From d2684f30f28e11f5f04a9588df27a1216f815727 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 16:37:12 +0900 Subject: [PATCH 245/250] docs(evidence): link canonical merge collector --- AGENTS.md | 1 + CHANGELOG.md | 2 + CLAUDE.md | 1 + docs/product-technical-gap-baseline.md | 168 +----------------- tests/test_product_completion_gap_contract.py | 51 +++--- 5 files changed, 33 insertions(+), 190 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index 81425046e..67837d1fa 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -131,6 +131,7 @@ A release requires all current-head checks, complete coverage and docs, updated - When updating a delivery checkpoint, separate a verified predecessor from a newer pending head. A passing coverage summary does not validate a fixture that ignores peer errors; preserve the failing reproduction and the repaired wire-level assertions in the evidence trail. - A live-inventory contract must update its dated baseline, `CHANGELOG.md`, and full exact SHA together. Use `scripts/ci/collect_live_merge_evidence.sh` for reusable head/base evidence; do not infer current state from an abbreviated SHA or a historical inventory line. +- Keep the delivery baseline decision-sized: GitHub truncates large Markdown code blocks. Link the canonical executable evidence collector instead of copying it into the rendered baseline, and keep its contract test pointed at that executable source. - Add concise, reproducible lessons here as work establishes them. Keep transient heads, job IDs and incident snapshots in PR evidence, not permanent instructions; never record secret values. - Retained receipt recovery is not live-stream recovery. State whether a fixture keeps the original connection open and uses the same endpoint; claim live recovery only when a synchronized test reads and completes the original request after rejecting the replacement reply. diff --git a/CHANGELOG.md b/CHANGELOG.md index 84207cb33..23635db9a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,8 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Replaced the truncated inline merge-evidence command copy with its canonical executable collector and kept the collector's exact-head contract under test. + - Recorded #255 exact-head hosted success and #293's narrow standard-BiDi capability, typed command planning, dated-TR provenance pin, and explicit viewport/DPR cleanup intent, preserving exact-head visual, rustdoc-view, transport, and real-browser evidence gaps. - Recorded the server Close-role RED-to-GREEN repair with exact local coverage and visual evidence, keeping queued hosted checks and release acceptance separate. diff --git a/CLAUDE.md b/CLAUDE.md index cbeb8220b..1c762e5ca 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -13,3 +13,4 @@ Additional constraints: - Keep changes bounded to one product gap and preserve modular crate boundaries. - Never claim a test, benchmark, browser integration, TLS identity, GPU execution, release, or merge succeeded without current exact-head evidence. - When refreshing live delivery evidence, update the dated baseline, `CHANGELOG.md`, and full exact SHA atomically; use `scripts/ci/collect_live_merge_evidence.sh` rather than an abbreviated SHA or historical count. +- Keep rendered delivery evidence concise: link the canonical collector rather than embedding its long shell body, because GitHub truncates oversized code blocks. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 315696654..f1b462277 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1252,173 +1252,7 @@ OriginWeave is not complete merely because every low-level primitive exists in s Run `scripts/ci/collect_live_merge_evidence.sh` to collect reusable, exact-head and exact-base merge evidence before interpreting the volatile inventory below. -The volatile counts above are reproducible by paginating the complete open-PR and open-issue inventories, excluding pull requests from the issue count, flattening every page, and then inspecting each PR's exact head, checks, reviews, and review threads: - -```bash -set -euo pipefail -EVIDENCE_DIR="$(mktemp -d /tmp/originweave-evidence.XXXXXX)" -printf 'Evidence directory: %s\n' "$EVIDENCE_DIR" >&2 - -gh api --paginate --slurp 'repos/ContextualWisdomLab/OriginWeave/pulls?state=open&per_page=100' \ - > "$EVIDENCE_DIR/open-pr-pages.json" -jq '[.[][]]' "$EVIDENCE_DIR/open-pr-pages.json" \ - > "$EVIDENCE_DIR/open-prs.json" -jq '{ - open_pull_requests: length, - non_draft: (map(select(.draft == false)) | length), - draft: (map(select(.draft == true)) | length) -}' "$EVIDENCE_DIR/open-prs.json" - -gh api --paginate --slurp 'repos/ContextualWisdomLab/OriginWeave/issues?state=open&per_page=100' \ - > "$EVIDENCE_DIR/open-issue-pages.json" -jq '[.[][]] | map(select(has("pull_request") | not)) | { - open_non_pr_issues: length -}' "$EVIDENCE_DIR/open-issue-pages.json" - -gh api 'repos/ContextualWisdomLab/OriginWeave/branches/main' \ - > "$EVIDENCE_DIR/main-branch.json" -gh api --paginate --slurp \ - 'repos/ContextualWisdomLab/OriginWeave/rules/branches/main?per_page=100' \ - > "$EVIDENCE_DIR/main-branch-rule-pages.json" -jq '[.[][]]' "$EVIDENCE_DIR/main-branch-rule-pages.json" \ - > "$EVIDENCE_DIR/main-branch-rules.json" -gh api --paginate --slurp \ - 'repos/ContextualWisdomLab/OriginWeave/collaborators?affiliation=all&per_page=100' \ - > "$EVIDENCE_DIR/collaborator-pages.json" -jq '[.[][]]' "$EVIDENCE_DIR/collaborator-pages.json" \ - > "$EVIDENCE_DIR/collaborators.json" - -jq -r '.[].number' "$EVIDENCE_DIR/open-prs.json" | while read -r PR; do - STABLE_HEAD=false - for ATTEMPT in 1 2 3; do - VERDICT_PATH="$EVIDENCE_DIR/pr-${PR}-merge-verdict.json" - VERDICT_TMP="$EVIDENCE_DIR/pr-${PR}-merge-verdict.json.tmp" - rm -f "$VERDICT_PATH" "$VERDICT_TMP" "$EVIDENCE_DIR/pr-${PR}-rechecked.json" - PR_JSON="$EVIDENCE_DIR/pr-${PR}.json" - gh api "repos/ContextualWisdomLab/OriginWeave/pulls/$PR" > "$PR_JSON" - HEAD_SHA=$(jq -r '.head.sha' "$PR_JSON") - BASE_SHA=$(jq -r '.base.sha' "$PR_JSON") - - gh api --paginate --slurp \ - "repos/ContextualWisdomLab/OriginWeave/commits/$HEAD_SHA/check-runs?per_page=100" \ - > "$EVIDENCE_DIR/pr-${PR}-check-runs.json" - gh api --paginate --slurp \ - "repos/ContextualWisdomLab/OriginWeave/commits/$HEAD_SHA/statuses?per_page=100" \ - > "$EVIDENCE_DIR/pr-${PR}-statuses.json" - gh api --paginate --slurp \ - "repos/ContextualWisdomLab/OriginWeave/pulls/$PR/reviews?per_page=100" \ - > "$EVIDENCE_DIR/pr-${PR}-reviews.json" - gh api --paginate --slurp \ - "repos/ContextualWisdomLab/OriginWeave/actions/runs?head_sha=$HEAD_SHA&per_page=100" \ - > "$EVIDENCE_DIR/pr-${PR}-workflow-runs.json" - gh api graphql --paginate --slurp \ - -F owner=ContextualWisdomLab \ - -F name=OriginWeave \ - -F number="$PR" \ - -f query=' -query($owner: String!, $name: String!, $number: Int!, $endCursor: String) { - repository(owner: $owner, name: $name) { - pullRequest(number: $number) { - reviewThreads(first: 100, after: $endCursor) { - nodes { id isResolved isOutdated } - pageInfo { hasNextPage endCursor } - } - } - } -}' > "$EVIDENCE_DIR/pr-${PR}-review-threads.json" - - jq -n \ - --arg head "$HEAD_SHA" \ - --slurpfile pr "$PR_JSON" \ - --slurpfile checks "$EVIDENCE_DIR/pr-${PR}-check-runs.json" \ - --slurpfile statuses "$EVIDENCE_DIR/pr-${PR}-statuses.json" \ - --slurpfile reviews "$EVIDENCE_DIR/pr-${PR}-reviews.json" \ - --slurpfile workflow_runs "$EVIDENCE_DIR/pr-${PR}-workflow-runs.json" \ - --slurpfile rules "$EVIDENCE_DIR/main-branch-rules.json" \ - --slurpfile collaborators "$EVIDENCE_DIR/collaborators.json" \ - --slurpfile threads "$EVIDENCE_DIR/pr-${PR}-review-threads.json" \ - --arg base "$BASE_SHA" \ - '( - [ - $rules[][]? - | select(.type == "pull_request") - | .parameters - ] | first // {} - ) as $pull_request_parameters - | ( - [ - $reviews[][][]? - | {reviewer: .user.login, state, submitted_at, commit_id} - | select(.submitted_at != null) - | select(.reviewer != $pr[0].user.login) - | select(.reviewer as $reviewer | - any($collaborators[][]?; - .login == $reviewer and - (.permissions.push == true or - .permissions.maintain == true or - .permissions.admin == true))) - ] - | group_by(.reviewer) - | map(sort_by(.submitted_at) | last) - | map(select(.state == "APPROVED" and .commit_id == $head)) - ) as $current_approvals - | ($pull_request_parameters.required_approving_review_count // 0) as $required_review_count - | ($pull_request_parameters.require_last_push_approval // false) as $require_last_push_approval - | { - head_sha: $head, - base_sha: $base, - required_status_checks: { - check_runs: [$checks[][].check_runs[]?], - legacy_statuses: [$statuses[][][]?] - }, - workflow_runs: [$workflow_runs[][].workflow_runs[]?], - counted_approvals: ($current_approvals | length), - required_approving_review_count: $required_review_count, - require_last_push_approval: $require_last_push_approval, - last_push_approval_authority: ( - if $require_last_push_approval == true - then "github_rule_evaluation_required" - else "not_required" - end - ), - approval_gate_satisfied: ( - if $pull_request_parameters.require_last_push_approval == true then false - else (($current_approvals | length) >= $required_review_count) - end - ), - required_workflows: [ - $rules[][]? - | select(.type == "workflows") - | .parameters.workflows[] - ], - unresolved_threads: [ - $threads[][].data.repository.pullRequest.reviewThreads.nodes[]? - | select(.isResolved == false and .isOutdated == false) - ] - }' > "$VERDICT_TMP" - - RECHECKED_PR_JSON="$EVIDENCE_DIR/pr-${PR}-rechecked.json" - RECHECKED_HEAD_SHA=$(gh api "repos/ContextualWisdomLab/OriginWeave/pulls/$PR" \ - | tee "$RECHECKED_PR_JSON" \ - | jq -r '.head.sha') - RECHECKED_BASE_SHA=$(jq -r '.base.sha' "$RECHECKED_PR_JSON") - if [[ "$RECHECKED_HEAD_SHA" == "$HEAD_SHA" && "$RECHECKED_BASE_SHA" == "$BASE_SHA" ]]; then - mv "$VERDICT_TMP" "$VERDICT_PATH" - mv "$RECHECKED_PR_JSON" "$PR_JSON" - STABLE_HEAD=true - break - fi - rm -f "$VERDICT_TMP" "$RECHECKED_PR_JSON" - printf 'Discarding moving head/base evidence for PR #%s (head %s -> %s, base %s -> %s) and retrying.\n' \ - "$PR" "$HEAD_SHA" "$RECHECKED_HEAD_SHA" "$BASE_SHA" "$RECHECKED_BASE_SHA" >&2 - done - if [[ "$STABLE_HEAD" != true ]]; then - rm -f "$EVIDENCE_DIR"/pr-${PR}-*.json - printf 'Unable to collect stable exact-head/base evidence for PR #%s after 3 attempts.\n' "$PR" >&2 - exit 1 - fi -done -``` +The executable [collect_live_merge_evidence.sh](../scripts/ci/collect_live_merge_evidence.sh) procedure paginates the complete open-PR and open-issue inventories, excludes pull requests from the issue count, and binds each merge verdict to the exact head, base, checks, reviews, and review threads. It is the canonical procedure; do not copy it into this baseline. The branch-scoped rules response determines the active rules affecting `main`; each PR's exact `HEAD_SHA` then determines which check runs, legacy statuses, workflow runs, reviews, and unresolved threads are current. The saved merge verdict binds counted approvals to the latest review per eligible collaborator, excludes the PR author, and requires `APPROVED` on the exact head. It deliberately does **not** infer GitHub's actual last-push actor from commit author or committer metadata: when `require_last_push_approval` is active, this portable evidence procedure records `github_rule_evaluation_required` and keeps `approval_gate_satisfied` false until GitHub's authoritative rule evaluation is consulted. The saved PR JSON also preserves the exact base reference and branch ancestry input for the dependency graph. Evidence is retained only when both `RECHECKED_HEAD_SHA` and `RECHECKED_BASE_SHA` match the collected values; a moving head or base discards the temporary verdict, and three failed attempts leave no unstable merge verdict. diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 9cd70908a..2485d3f3b 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -719,29 +719,34 @@ def test_issue_table_distinguishes_open_issues_from_governance_signals(self) -> self.assertIn("Issue or signal", table) def test_evidence_commands_reproduce_inventory_checks_and_review_state(self) -> None: - """The evidence procedure must paginate the queue and inspect each exact PR head.""" + """The baseline links to the executable procedure without duplicating it.""" text = BASELINE.read_text(encoding="utf-8") evidence = text.split("## Evidence commands", 1)[1].split("\n## ", 1)[0] - shell = evidence.split("```bash", 1)[1].split("```", 1)[0] + script = (ROOT / "scripts" / "ci" / "collect_live_merge_evidence.sh").read_text( + encoding="utf-8" + ) + + self.assertIn("[collect_live_merge_evidence.sh]", evidence) + self.assertNotIn("```bash", evidence) for phrase in ( - "--paginate --slurp 'repos/ContextualWisdomLab/OriginWeave/pulls?state=open&per_page=100'", + '"repos/$REPOSITORY/pulls?state=open&per_page=100"', "set -euo pipefail", 'EVIDENCE_DIR="$(mktemp -d /tmp/originweave-evidence.XXXXXX)"', '"$EVIDENCE_DIR/open-pr-pages.json"', "jq '[.[][]]' \"$EVIDENCE_DIR/open-pr-pages.json\"", - "--paginate --slurp 'repos/ContextualWisdomLab/OriginWeave/issues?state=open&per_page=100'", + '"repos/$REPOSITORY/issues?state=open&per_page=100"', '"$EVIDENCE_DIR/open-issue-pages.json"', 'map(select(has("pull_request") | not))', "open_non_pr_issues", - '"repos/ContextualWisdomLab/OriginWeave/pulls/$PR"', - '"repos/ContextualWisdomLab/OriginWeave/commits/$HEAD_SHA/check-runs?per_page=100"', - '"repos/ContextualWisdomLab/OriginWeave/commits/$HEAD_SHA/statuses?per_page=100"', - '"repos/ContextualWisdomLab/OriginWeave/pulls/$PR/reviews?per_page=100"', - '"repos/ContextualWisdomLab/OriginWeave/actions/runs?head_sha=$HEAD_SHA&per_page=100"', + '"repos/$REPOSITORY/pulls/$PR"', + '"repos/$REPOSITORY/commits/$HEAD_SHA/check-runs?per_page=100"', + '"repos/$REPOSITORY/commits/$HEAD_SHA/statuses?per_page=100"', + '"repos/$REPOSITORY/pulls/$PR/reviews?per_page=100"', + '"repos/$REPOSITORY/actions/runs?head_sha=$HEAD_SHA&per_page=100"', "check_runs: [$checks[][].check_runs[]?],", "legacy_statuses: [$statuses[][][]?]", - "workflow_runs: [$workflow_runs[][].workflow_runs[]?],", + "workflow_runs: $exact_pr_base_workflow_runs,", "reviewThreads(first: 100, after: $endCursor)", "rules/branches/main?per_page=100", '"$EVIDENCE_DIR/main-branch-rule-pages.json"', @@ -756,7 +761,7 @@ def test_evidence_commands_reproduce_inventory_checks_and_review_state(self) -> "require_last_push_approval", "last_push_approval_authority", '"github_rule_evaluation_required"', - "if $pull_request_parameters.require_last_push_approval == true then false", + "if $require_last_push_approval == true then false", "$pr[0].user.login", '.type == "workflows"', ".parameters.workflows", @@ -765,20 +770,20 @@ def test_evidence_commands_reproduce_inventory_checks_and_review_state(self) -> "for ATTEMPT in 1 2 3; do", "RECHECKED_HEAD_SHA=", "RECHECKED_BASE_SHA=", - 'if [[ "$RECHECKED_HEAD_SHA" == "$HEAD_SHA" && "$RECHECKED_BASE_SHA" == "$BASE_SHA" ]]; then', + '"$RECHECKED_BASE_SHA" == "$BASE_SHA" &&', ): with self.subTest(phrase=phrase): - self.assertIn(phrase, shell) - - self.assertNotIn("while :; do", shell) - self.assertNotIn("/tmp/originweave-open-pr", shell) - self.assertNotIn("check_runs: [$checks[]?.check_runs[]?],", shell) - self.assertNotIn("legacy_statuses: [$statuses[][]?]", shell) - self.assertNotIn("workflow_runs: [$workflow_runs[]?.workflow_runs[]?],", shell) - self.assertNotIn("$reviews[][]?\n | select(.state", shell) - self.assertNotIn("head-commit.json", shell) - self.assertNotIn("$head_commit[0].committer.login", shell) - self.assertNotIn("$head_commit[0].author.login", shell) + self.assertIn(phrase, script) + + self.assertNotIn("while :; do", script) + self.assertNotIn("/tmp/originweave-open-pr", script) + self.assertNotIn("check_runs: [$checks[]?.check_runs[]?],", script) + self.assertNotIn("legacy_statuses: [$statuses[][]?]", script) + self.assertNotIn("workflow_runs: [$workflow_runs[]?.workflow_runs[]?],", script) + self.assertNotIn("$reviews[][]?\n | select(.state", script) + self.assertNotIn("head-commit.json", script) + self.assertNotIn("$head_commit[0].committer.login", script) + self.assertNotIn("$head_commit[0].author.login", script) if __name__ == "__main__": From 4c2ce60eefdc285b97ffb1ea928f5868c90ca37a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 17:44:18 +0900 Subject: [PATCH 246/250] docs: refresh live product gap baseline --- AGENTS.md | 1 + CHANGELOG.md | 2 +- CLAUDE.md | 1 + docs/product-technical-gap-baseline.md | 30 ++++++++++++++++++- ...cumentation_active_pr_evidence_contract.py | 27 ++++++----------- ...st_live_gap_evidence_integrity_contract.py | 18 +++++------ 6 files changed, 50 insertions(+), 29 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index 81425046e..baa645ac9 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -99,6 +99,7 @@ A skipped security, GPU, browser, TLS, or statistical test is not passing eviden ## Documentation and research - Update `docs/doctoring.md` when a standard or research claim affects design. +- Refreshing the volatile product-gap baseline requires paginated live PR and issue counts, full exact heads, and the matching `CHANGELOG.md` inventory line; run its documentation contracts before publication. A local browser policy that blocks loopback or file rendering is not visual evidence—inspect the GitHub-rendered exact head after push instead. - Use primary specifications, official documentation, or peer-reviewed/primary papers. - Format references in APA 7th style. - Update an ADR for binding architectural changes. diff --git a/CHANGELOG.md b/CHANGELOG.md index 84207cb33..72fdb4f01 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -28,7 +28,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Recorded the verified pointer-reply connection repair and recovery tests, keeping pending hosted checks, remaining authority gaps and browser acceptance separate. - Recorded the published text-entry connection safeguards and their test evidence, separating queued hosted checks and remaining pointer/status repairs from released browser behavior. - Separate the current maintenance queue and source lineage from preserved historical observations, and record the text-entry session and pending-request safeguards without claiming released browser behavior. -- Current delivery inventory: 126 open pull requests (12 ready, 114 draft); 14 open non-PR issues. Observed 2026-09-08; source acceptance remains revision-specific. +- Current delivery inventory: 130 open pull requests (13 ready, 117 draft); 14 open non-PR issues. Observed 2026-09-09; source acceptance remains revision-specific. - Corrected historical checkpoint labels and made the current inventory check reject stale counts; recorded verified text-input parent adoption without claiming browser execution. - Recorded the executed session-isolation repair and its verified adoption, separating complete local checks and PR visual inspection from pending hosted checks and unreleased browser acceptance. - Recorded the current click safeguards, restored regression coverage and completed PR visual inspection, keeping the separately owned parent repair and queued hosted checks distinct from delivery. diff --git a/CLAUDE.md b/CLAUDE.md index cbeb8220b..4adce7dc3 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -12,4 +12,5 @@ Additional constraints: - Do not add hostname reconnect, proxy-environment inheritance, dangerous certificate-verifier hooks, Common Name fallback, TLS 0-RTT, key logging, or secret extraction to a production TLS path. - Keep changes bounded to one product gap and preserve modular crate boundaries. - Never claim a test, benchmark, browser integration, TLS identity, GPU execution, release, or merge succeeded without current exact-head evidence. +- For volatile gap-baseline refreshes, bind the dated inventory, full PR heads, and `CHANGELOG.md` line to the same live observation; if local rendering is blocked, visually inspect the GitHub-rendered exact head after push. - When refreshing live delivery evidence, update the dated baseline, `CHANGELOG.md`, and full exact SHA atomically; use `scripts/ci/collect_live_merge_evidence.sh` rather than an abbreviated SHA or historical count. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 315696654..cbb515340 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,7 +6,35 @@ This is a dated delivery baseline, not a substitute for the PRD, TRD, roadmap, a This volatile section is refreshed from live GitHub state and is authoritative only for the exact observations recorded here. The dated snapshot below remains historical evidence and is not promoted to current acceptance evidence. Live GitHub PR/base/head/check APIs are authoritative over PR bodies and prior maintenance prose; a body that still names an older head is stale evidence, not merge evidence. -### Latest verified cut: 2026-09-08 +### Latest verified cut: 2026-09-09 + +#### Presentation identity and controlled-browser evidence + +At `2026-09-09T08:45:00Z`, the live inventory was **130 open pull requests: +13 Ready/non-draft and 117 Draft; 14 open non-PR issues**. Protected `main` +remains `87c4daa1830bac5a5228b6036752ad5633232085`; no GitHub Release exists. +Ruleset `18156473` still requires one counted approval and seven central required +workflows. Queued reviewer evidence is non-passing: discard queued, skipped, +cancelled, absent, predecessor, synthetic, status-only, and model-only evidence. + +Issue #292 remains the buyer-visible presentation-identity gap. Draft #293 is +at exact head `6855e2578ae94279cc9ab4a14527b016e8c049ee` on Ready #229 +`024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`. Its reusable lifecycle deliberately +does not apply reduced motion without a complete restore or disposable-context +owner. Thus command planning cannot be presented as full profile application. +Pinned Chromium application, page-observed post-conditions, and cleanup evidence +remain unimplemented and unreleased. Issue #212 owns the sandbox-helper contract; +the product branch must consume it rather than copy or weaken workflow behavior. + +#### Transport-closure verification and test-integrity repair + +The current queue also leaves Ready #287 at +`3975daf48e01a5e9d1cf9fb104a3be1aa03b0402` with exact-head native and central +checks queued. Its prior CodeQL dispatch outcome was an absent central verdict, +not a classifier-source finding. No release, protected-main shipment, or approval +is inferred from local work, a child merge, or queued checks. + +### Previous verified cut: 2026-09-08 #### Published intent acknowledgment verification diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index f319c48a3..937e6f476 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -88,19 +88,12 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: refresh_lines = [line for line in added.splitlines() if line.startswith(refresh_prefix)] self.assertEqual(1, len(refresh_lines)) refresh_line = refresh_lines[0] - self.assertIn("on 2026-09-05", refresh_line) latest_cut = bounded_section( self.baseline, - "### Latest verified cut: 2026-09-08", - "### Historical verified cut: 2026-09-07", + "### Latest verified cut: 2026-09-09", + "### Previous verified cut: 2026-09-08", ) - current = bounded_section( - latest_cut, - "#### Transport-closure verification and test-integrity repair", - "### Historical verified cut: 2026-09-07", - ) if "### Historical verified cut: 2026-09-07" in latest_cut else latest_cut.split( - "#### Transport-closure verification and test-integrity repair", 1 - )[1] + current = latest_cut queue_counts = re.findall( r"\*\*(\d+) open pull requests: (\d+) Ready/non-draft and (\d+) Draft; " r"(\d+) open non-PR issues\*\*", @@ -115,9 +108,7 @@ def test_baseline_refresh_changelog_matches_the_live_snapshot(self) -> None: self.assertEqual(1, len(inventory_lines)) self.assertIn(f"{total} open pull requests ({ready} ready, {draft} draft)", inventory_lines[0]) self.assertIn(f"{issues} open non-PR issues", inventory_lines[0]) - self.assertIn("024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6", refresh_line) - self.assertIn("3a651967c421f77088fe25e86a63faae295390b3", refresh_line) - self.assertIn("01038ba71fb276426cc67f90a91a3c431e194db5", refresh_line) + self.assertIn("Observed 2026-09-09", inventory_lines[0]) self.assertIn( "Revalidated the active ruleset inventory at 7 required workflows", changed, @@ -135,13 +126,13 @@ def test_latest_inventory_drift_cannot_be_hidden_by_historical_counts(self) -> N """Changing only the newest count must invalidate an unchanged changelog.""" latest = bounded_section( self.baseline, - "### Latest verified cut: 2026-09-08", - "### Historical verified cut: 2026-09-07", + "### Latest verified cut: 2026-09-09", + "### Previous verified cut: 2026-09-08", ) - self.assertIn("126 open pull requests", latest) + self.assertIn("130 open pull requests", latest) mutated_latest = latest.replace( - "126 open pull requests", - "127 open pull requests", + "130 open pull requests", + "131 open pull requests", 1, ) self.assertNotEqual(latest, mutated_latest) diff --git a/tests/test_live_gap_evidence_integrity_contract.py b/tests/test_live_gap_evidence_integrity_contract.py index fe5ba4b02..78e930178 100644 --- a/tests/test_live_gap_evidence_integrity_contract.py +++ b/tests/test_live_gap_evidence_integrity_contract.py @@ -33,14 +33,14 @@ def setUpClass(cls) -> None: cls.evidence = EVIDENCE_SCRIPT.read_text(encoding="utf-8") cls.latest = bounded( cls.baseline, - "### Latest verified cut: 2026-09-08", - "### Historical verified cut: 2026-09-07", + "### Latest verified cut: 2026-09-09", + "### Previous verified cut: 2026-09-08", ) - def test_latest_inventory_and_changelog_use_the_september_8_cut(self) -> None: + def test_latest_inventory_and_changelog_use_the_september_9_cut(self) -> None: marker = ( - "126 open pull requests: 12 Ready/non-draft and " - "114 Draft; 14 open non-PR issues" + "130 open pull requests: 13 Ready/non-draft and " + "117 Draft; 14 open non-PR issues" ) self.assertIn(marker, " ".join(self.latest.split())) inventory = [ @@ -49,14 +49,14 @@ def test_latest_inventory_and_changelog_use_the_september_8_cut(self) -> None: if line.startswith("- Current delivery inventory:") ] self.assertEqual(1, len(inventory)) - self.assertIn("126 open pull requests (12 ready, 114 draft)", inventory[0]) + self.assertIn("130 open pull requests (13 ready, 117 draft)", inventory[0]) self.assertIn("14 open non-PR issues", inventory[0]) - self.assertIn("Observed 2026-09-08", inventory[0]) + self.assertIn("Observed 2026-09-09", inventory[0]) def test_presentation_snapshot_uses_full_exact_sha(self) -> None: - full_sha = "0c077445d73640a6299ea4d379faa4b0ab0226c2" + full_sha = "6855e2578ae94279cc9ab4a14527b016e8c049ee" self.assertIn(full_sha, self.latest) - self.assertNotIn("to exact head\n`0c077445`", self.latest) + self.assertNotIn("to exact head\n`6855e257`", self.latest) def test_documented_current_evidence_collector_is_executable(self) -> None: current_evidence = self.baseline.split("## Evidence commands", 1)[1] From 20e8573b62a0d2db9a5803235349297c93a52af7 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 17:52:40 +0900 Subject: [PATCH 247/250] docs: refresh live inventory after publication --- CHANGELOG.md | 2 +- docs/product-technical-gap-baseline.md | 4 ++-- tests/test_documentation_active_pr_evidence_contract.py | 4 ++-- tests/test_live_gap_evidence_integrity_contract.py | 4 ++-- 4 files changed, 7 insertions(+), 7 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 72fdb4f01..c3a7c2355 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -28,7 +28,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Recorded the verified pointer-reply connection repair and recovery tests, keeping pending hosted checks, remaining authority gaps and browser acceptance separate. - Recorded the published text-entry connection safeguards and their test evidence, separating queued hosted checks and remaining pointer/status repairs from released browser behavior. - Separate the current maintenance queue and source lineage from preserved historical observations, and record the text-entry session and pending-request safeguards without claiming released browser behavior. -- Current delivery inventory: 130 open pull requests (13 ready, 117 draft); 14 open non-PR issues. Observed 2026-09-09; source acceptance remains revision-specific. +- Current delivery inventory: 131 open pull requests (14 ready, 117 draft); 14 open non-PR issues. Observed 2026-09-09; source acceptance remains revision-specific. - Corrected historical checkpoint labels and made the current inventory check reject stale counts; recorded verified text-input parent adoption without claiming browser execution. - Recorded the executed session-isolation repair and its verified adoption, separating complete local checks and PR visual inspection from pending hosted checks and unreleased browser acceptance. - Recorded the current click safeguards, restored regression coverage and completed PR visual inspection, keeping the separately owned parent repair and queued hosted checks distinct from delivery. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index cbb515340..b4ce2eba0 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -10,8 +10,8 @@ This volatile section is refreshed from live GitHub state and is authoritative o #### Presentation identity and controlled-browser evidence -At `2026-09-09T08:45:00Z`, the live inventory was **130 open pull requests: -13 Ready/non-draft and 117 Draft; 14 open non-PR issues**. Protected `main` +At `2026-09-09T08:49:58Z`, the live inventory was **131 open pull requests: +14 Ready/non-draft and 117 Draft; 14 open non-PR issues**. Protected `main` remains `87c4daa1830bac5a5228b6036752ad5633232085`; no GitHub Release exists. Ruleset `18156473` still requires one counted approval and seven central required workflows. Queued reviewer evidence is non-passing: discard queued, skipped, diff --git a/tests/test_documentation_active_pr_evidence_contract.py b/tests/test_documentation_active_pr_evidence_contract.py index 937e6f476..a0d2ff3d0 100644 --- a/tests/test_documentation_active_pr_evidence_contract.py +++ b/tests/test_documentation_active_pr_evidence_contract.py @@ -129,10 +129,10 @@ def test_latest_inventory_drift_cannot_be_hidden_by_historical_counts(self) -> N "### Latest verified cut: 2026-09-09", "### Previous verified cut: 2026-09-08", ) - self.assertIn("130 open pull requests", latest) + self.assertIn("131 open pull requests", latest) mutated_latest = latest.replace( - "130 open pull requests", "131 open pull requests", + "132 open pull requests", 1, ) self.assertNotEqual(latest, mutated_latest) diff --git a/tests/test_live_gap_evidence_integrity_contract.py b/tests/test_live_gap_evidence_integrity_contract.py index 78e930178..7e5c0646e 100644 --- a/tests/test_live_gap_evidence_integrity_contract.py +++ b/tests/test_live_gap_evidence_integrity_contract.py @@ -39,7 +39,7 @@ def setUpClass(cls) -> None: def test_latest_inventory_and_changelog_use_the_september_9_cut(self) -> None: marker = ( - "130 open pull requests: 13 Ready/non-draft and " + "131 open pull requests: 14 Ready/non-draft and " "117 Draft; 14 open non-PR issues" ) self.assertIn(marker, " ".join(self.latest.split())) @@ -49,7 +49,7 @@ def test_latest_inventory_and_changelog_use_the_september_9_cut(self) -> None: if line.startswith("- Current delivery inventory:") ] self.assertEqual(1, len(inventory)) - self.assertIn("130 open pull requests (13 ready, 117 draft)", inventory[0]) + self.assertIn("131 open pull requests (14 ready, 117 draft)", inventory[0]) self.assertIn("14 open non-PR issues", inventory[0]) self.assertIn("Observed 2026-09-09", inventory[0]) From fb9acab7a7a5385ff2806c46514f431fc70332de Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 17:55:38 +0900 Subject: [PATCH 248/250] docs: distinguish harness from runtime acceptance --- CHANGELOG.md | 1 + docs/product-technical-gap-baseline.md | 6 ++++-- tests/test_live_gap_evidence_integrity_contract.py | 6 ++++++ 3 files changed, 11 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index c3a7c2355..d146b822f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -29,6 +29,7 @@ All notable changes to OriginWeave are documented in this file. The format follo - Recorded the published text-entry connection safeguards and their test evidence, separating queued hosted checks and remaining pointer/status repairs from released browser behavior. - Separate the current maintenance queue and source lineage from preserved historical observations, and record the text-entry session and pending-request safeguards without claiming released browser behavior. - Current delivery inventory: 131 open pull requests (14 ready, 117 draft); 14 open non-PR issues. Observed 2026-09-09; source acceptance remains revision-specific. +- Clarified that the active presentation-evidence harness is implemented while its failed browser run does not establish product runtime or release acceptance. - Corrected historical checkpoint labels and made the current inventory check reject stale counts; recorded verified text-input parent adoption without claiming browser execution. - Recorded the executed session-isolation repair and its verified adoption, separating complete local checks and PR visual inspection from pending hosted checks and unreleased browser acceptance. - Recorded the current click safeguards, restored regression coverage and completed PR visual inspection, keeping the separately owned parent repair and queued hosted checks distinct from delivery. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b4ce2eba0..38dc1bf7c 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -22,8 +22,10 @@ at exact head `6855e2578ae94279cc9ab4a14527b016e8c049ee` on Ready #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`. Its reusable lifecycle deliberately does not apply reduced motion without a complete restore or disposable-context owner. Thus command planning cannot be presented as full profile application. -Pinned Chromium application, page-observed post-conditions, and cleanup evidence -remain unimplemented and unreleased. Issue #212 owns the sandbox-helper contract; +An active controlled evidence harness is implemented, but it does not establish a +product Browser Session adapter: its exact browser lane failed 0/3 at session +creation before navigation, so application, page-observed post-conditions, cleanup +acceptance, and release remain unproven. Issue #212 owns the sandbox-helper contract; the product branch must consume it rather than copy or weaken workflow behavior. #### Transport-closure verification and test-integrity repair diff --git a/tests/test_live_gap_evidence_integrity_contract.py b/tests/test_live_gap_evidence_integrity_contract.py index 7e5c0646e..36a21fc91 100644 --- a/tests/test_live_gap_evidence_integrity_contract.py +++ b/tests/test_live_gap_evidence_integrity_contract.py @@ -58,6 +58,12 @@ def test_presentation_snapshot_uses_full_exact_sha(self) -> None: self.assertIn(full_sha, self.latest) self.assertNotIn("to exact head\n`6855e257`", self.latest) + def test_active_presentation_harness_is_not_described_as_unimplemented(self) -> None: + normalized = " ".join(self.latest.split()) + self.assertIn("active controlled evidence harness is implemented", normalized) + self.assertIn("failed 0/3 at session creation before navigation", normalized) + self.assertIn("product Browser Session adapter", normalized) + def test_documented_current_evidence_collector_is_executable(self) -> None: current_evidence = self.baseline.split("## Evidence commands", 1)[1] self.assertIn("scripts/ci/collect_live_merge_evidence.sh", current_evidence) From cc6e1c7dcc7a9eda8fce954b0880437ff078dcd7 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 18:06:13 +0900 Subject: [PATCH 249/250] docs(gaps): record repaired BiDi successor contract Signed-off-by: Seongho Bae --- CHANGELOG.md | 3 +++ docs/product-technical-gap-baseline.md | 8 ++++++++ tests/test_live_gap_evidence_integrity_contract.py | 8 ++++++++ 3 files changed, 19 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index d146b822f..f3a7c683b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,9 @@ All notable changes to OriginWeave are documented in this file. The format follo ## [Unreleased] +- Recorded #298/#305's repaired reduced-motion command contract while keeping + its Draft-only checks and missing Chromium runtime evidence explicit. + - Recorded #255 exact-head hosted success and #293's narrow standard-BiDi capability, typed command planning, dated-TR provenance pin, and explicit viewport/DPR cleanup intent, preserving exact-head visual, rustdoc-view, transport, and real-browser evidence gaps. - Recorded the server Close-role RED-to-GREEN repair with exact local coverage and visual evidence, keeping queued hosted checks and release acceptance separate. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 38dc1bf7c..37a097e14 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -22,6 +22,14 @@ at exact head `6855e2578ae94279cc9ab4a14527b016e8c049ee` on Ready #229 `024f63690cf05cfe6f0d4a430f0e18ea8fd2c4d6`. Its reusable lifecycle deliberately does not apply reduced motion without a complete restore or disposable-context owner. Thus command planning cannot be presented as full profile application. +Draft successor #298 is at exact head +`d01f45c2c8ac7b0fc4dbc3d3ada60238732cdf8c` on that #293 head. Its non-force +merge of #305 repaired an older source contract so it now asserts both that +ReducedMotion remains a discoverable protocol capability and that the reusable +planner exposes no media-mutation command. This removes an API/documentation +contradiction only; #298's Draft checks are skipped and it does not establish +live Chromium transport, page observation, cleanup, protected-main shipment, +or release acceptance. An active controlled evidence harness is implemented, but it does not establish a product Browser Session adapter: its exact browser lane failed 0/3 at session creation before navigation, so application, page-observed post-conditions, cleanup diff --git a/tests/test_live_gap_evidence_integrity_contract.py b/tests/test_live_gap_evidence_integrity_contract.py index 36a21fc91..998be0669 100644 --- a/tests/test_live_gap_evidence_integrity_contract.py +++ b/tests/test_live_gap_evidence_integrity_contract.py @@ -64,6 +64,14 @@ def test_active_presentation_harness_is_not_described_as_unimplemented(self) -> self.assertIn("failed 0/3 at session creation before navigation", normalized) self.assertIn("product Browser Session adapter", normalized) + def test_presentation_successor_records_its_repaired_contract_boundary(self) -> None: + """Keep the active child repair distinct from browser-runtime acceptance.""" + normalized = " ".join(self.latest.split()) + self.assertIn("Draft successor #298", normalized) + self.assertIn("d01f45c2c8ac7b0fc4dbc3d3ada60238732cdf8c", normalized) + self.assertIn("#305", normalized) + self.assertIn("does not establish live Chromium transport", normalized) + def test_documented_current_evidence_collector_is_executable(self) -> None: current_evidence = self.baseline.split("## Evidence commands", 1)[1] self.assertIn("scripts/ci/collect_live_merge_evidence.sh", current_evidence) From 01d87b8fc91eacabcdfad2618867e839ad739bbe Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 18:07:55 +0900 Subject: [PATCH 250/250] test(docs): preserve dated checkpoint verification Signed-off-by: Seongho Bae --- AGENTS.md | 1 + CHANGELOG.md | 3 +++ CLAUDE.md | 1 + tests/test_product_completion_gap_contract.py | 4 ++-- 4 files changed, 7 insertions(+), 2 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index baa645ac9..4034353a1 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -132,6 +132,7 @@ A release requires all current-head checks, complete coverage and docs, updated - When updating a delivery checkpoint, separate a verified predecessor from a newer pending head. A passing coverage summary does not validate a fixture that ignores peer errors; preserve the failing reproduction and the repaired wire-level assertions in the evidence trail. - A live-inventory contract must update its dated baseline, `CHANGELOG.md`, and full exact SHA together. Use `scripts/ci/collect_live_merge_evidence.sh` for reusable head/base evidence; do not infer current state from an abbreviated SHA or a historical inventory line. +- A regression that verifies a dated baseline cut must select that named cut, not assume it remains the latest heading after a newer live cut is added; run the full Python repository contract suite after changing cut markers. - Add concise, reproducible lessons here as work establishes them. Keep transient heads, job IDs and incident snapshots in PR evidence, not permanent instructions; never record secret values. - Retained receipt recovery is not live-stream recovery. State whether a fixture keeps the original connection open and uses the same endpoint; claim live recovery only when a synchronized test reads and completes the original request after rejecting the replacement reply. diff --git a/CHANGELOG.md b/CHANGELOG.md index f3a7c683b..29d6a6b53 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,9 @@ All notable changes to OriginWeave are documented in this file. The format follo - Recorded #298/#305's repaired reduced-motion command contract while keeping its Draft-only checks and missing Chromium runtime evidence explicit. +- Repaired the dated product-gap checkpoint contract so historical verification + remains bounded after a newer live cut is added. + - Recorded #255 exact-head hosted success and #293's narrow standard-BiDi capability, typed command planning, dated-TR provenance pin, and explicit viewport/DPR cleanup intent, preserving exact-head visual, rustdoc-view, transport, and real-browser evidence gaps. - Recorded the server Close-role RED-to-GREEN repair with exact local coverage and visual evidence, keeping queued hosted checks and release acceptance separate. diff --git a/CLAUDE.md b/CLAUDE.md index 4adce7dc3..734be6015 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -14,3 +14,4 @@ Additional constraints: - Never claim a test, benchmark, browser integration, TLS identity, GPU execution, release, or merge succeeded without current exact-head evidence. - For volatile gap-baseline refreshes, bind the dated inventory, full PR heads, and `CHANGELOG.md` line to the same live observation; if local rendering is blocked, visually inspect the GitHub-rendered exact head after push. - When refreshing live delivery evidence, update the dated baseline, `CHANGELOG.md`, and full exact SHA atomically; use `scripts/ci/collect_live_merge_evidence.sh` rather than an abbreviated SHA or historical count. +- Date-bound baseline tests must locate their named checkpoint rather than assuming it remains the newest cut; run the complete Python contract suite after changing checkpoint markers. diff --git a/tests/test_product_completion_gap_contract.py b/tests/test_product_completion_gap_contract.py index 9cd70908a..40a44a209 100644 --- a/tests/test_product_completion_gap_contract.py +++ b/tests/test_product_completion_gap_contract.py @@ -70,8 +70,8 @@ def test_close_code_checkpoint_does_not_claim_hosted_acceptance(self) -> None: def test_closure_checkpoint_separates_verified_and_pending_heads(self) -> None: current = bounded_section( BASELINE.read_text(encoding="utf-8"), - "### Latest verified cut: 2026-09-08", - "### Historical verified cut: 2026-09-07", + "### Previous verified cut: 2026-09-08", + "## Observed snapshot: 2026-08-29", ) for marker in ( "d126242c7198c447d0fab7983d529441340fd1c9",