docs: refresh reconciliation product gap baseline - #37
Conversation
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthrough상용화 기준선을 2026-09-02 증거 상태로 갱신했다. 조정 기능, 도메인 모델, 구매자 흐름, 보안·운영 기준, 갭 큐 및 릴리스 규칙을 재정의했다. 관련 문서와 기준선 계약 검사도 갱신했다. Changes상용화 기준선 및 도메인 모델
문서 사실 및 기준선 계약
Estimated code review effort: 3 (Moderate) | ~25 minutes Merge Risk: 🔵 Low · up to The documentation update is mergeable with owner awareness because its contract test may still miss a mutable 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@OpenCode review |
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head product diff. Coverage is a separate gate.
Changed files
README.md— repository behaviordocs/doctoring/REFERENCES.md— operator or user guidancedocs/doctoring/STANDARD_TRACEABILITY.md— operator or user guidancedocs/product-technical-gap-baseline.md— operator or user guidancetests/test_product_gap_baseline_contract.py— regression suite
Changed behavior
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Repository file: README.md"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Repository file: README.md"]
R1 --> V1["required checks"]
Evidence --> S2["Docs: REFERENCES.md (3 files)"]
S2 --> I2["operator or user guidance"]
I2 --> R2["Review risk: Docs: REFERENCES.md (3 files)"]
R2 --> V2["docs review"]
Evidence --> S3["Test: test_product_gap_baseline_contract.py"]
S3 --> I3["regression suite"]
I3 --> R3["Review risk: Test: test_product_gap_baseline_contract.py"]
R3 --> V3["targeted test run"]
Findings
No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.
- Head SHA:
3ce82bfaf6b6b81b40de23aa143928a835a3b1dd - Workflow run: 33219471093
- Workflow attempt: 1
- Coverage gate:
failure
Review outcome
Coverage is a gate, not the review. This body reviews the changed product files.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Repository file: README.md"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Repository file: README.md"]
R1 --> V1["required checks"]
Evidence --> S2["Docs: REFERENCES.md (3 files)"]
S2 --> I2["operator or user guidance"]
I2 --> R2["Review risk: Docs: REFERENCES.md (3 files)"]
R2 --> V2["docs review"]
Evidence --> S3["Test: test_product_gap_baseline_contract.py"]
S3 --> I3["regression suite"]
I3 --> R3["Review risk: Test: test_product_gap_baseline_contract.py"]
R3 --> V3["targeted test run"]
OpenCode Review Overview
Coverage evidence did not pass, so approval is blocked. The formal pull-request review is the source-backed diff review, not this status comment. |
|
Current-head documentation synchronization:\n\n- Head: f8c0394\n- Base: develop@81a2920b0ae9b054fcdcc95902341e3a5bc809c5\n- Added README contract coverage first; the test was RED until the README listed the integrated camt.053.001.14 evidence registry, deterministic reconciliation proposal/bridge, and durable run/exception/evidence foundation.\n- Kept the remaining gap explicit: full cross-run many-to-many allocation, reconciliation approval, and close-package provenance are not claimed as complete.\n- Local verification: 463 tests passed against PostgreSQL 18.6, repository validator passed, compileall passed, changed-file Ruff passed, and git diff --check passed.\n- The default local port was also checked and is not a PostgreSQL 18 runtime (uuidv7() unavailable); that environment failure is not used as passing evidence.\n\nHosted checks are being re-run for this exact head. No merge or bypass was performed. |
|
Current-head follow-up after governance mutation:\n\n- Head: 916f326\n- Base: develop@81a2920b0ae9b054fcdcc95902341e3a5bc809c5\n- Updated the durable gap baseline to record active organization ruleset 21783807: AIP main now requires the seven central workflows plus repository-owned Accounting Foundation CI; the remaining gap is fresh release evidence, not missing protection.\n- Focused documentation contract tests: 4 passed; repository validator, compileall, changed-file Ruff, and diff-check passed.\n\nAll hosted checks and independent review are pending for this exact head. No merge or bypass was performed. |
|
Reviewed the current-head informational note on : the README and baseline intentionally keep full cross-run allocation, reconciliation approval, and close-package provenance open. No source change is required; the bounded foundation claim is accurate. |
|
Reviewed the current-head informational note on commit 916f326: the README and baseline intentionally keep full cross-run allocation, reconciliation approval, and close-package provenance open. No source change is required; the bounded foundation claim is accurate. |
|
Final current-head evidence for this documentation update:\n\n- Head: 916f326\n- Base: develop@81a2920b0ae9b054fcdcc95902341e3a5bc809c5\n- Accounting Foundation CI, CodeQL, Security Scan, SAST Semgrep, Strix, Noema, scheduler, and close-empty checks passed for this head.\n- Required OpenCode Review failed only at its fail-closed current-head verdict check; the current review list has no OpenCode review for this head. This is a hosted verdict/provider gate failure, not a source-test failure.\n- Review threads: 0 unresolved. Review decision: REVIEW_REQUIRED; no qualifying independent approval is present.\n\nNo further source change, merge, bypass, or release action is justified from this evidence. |
|
Current-head scheduler follow-up (2026-08-29):
No merge or bypass was performed; fresh current-head OpenCode approval and independent approval remain required. |
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head product diff. Coverage is a separate gate.
Changed files
README.md— repository behaviordocs/doctoring/REFERENCES.md— operator or user guidancedocs/doctoring/STANDARD_TRACEABILITY.md— operator or user guidancedocs/product-technical-gap-baseline.md— operator or user guidancetests/test_product_gap_baseline_contract.py— regression suite
Changed behavior
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Repository file: README.md"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Repository file: README.md"]
R1 --> V1["required checks"]
Evidence --> S2["Docs: REFERENCES.md (3 files)"]
S2 --> I2["operator or user guidance"]
I2 --> R2["Review risk: Docs: REFERENCES.md (3 files)"]
R2 --> V2["docs review"]
Evidence --> S3["Test: test_product_gap_baseline_contract.py"]
S3 --> I3["regression suite"]
I3 --> R3["Review risk: Test: test_product_gap_baseline_contract.py"]
R3 --> V3["targeted test run"]
Findings
No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.
- Head SHA:
916f326ce8605985a506d900fb70ed3850d3b4a9 - Workflow run: 33246598124
- Workflow attempt: 1
- Coverage gate:
failure
Review outcome
Coverage is a gate, not the review. This body reviews the changed product files.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Repository file: README.md"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Repository file: README.md"]
R1 --> V1["required checks"]
Evidence --> S2["Docs: REFERENCES.md (3 files)"]
S2 --> I2["operator or user guidance"]
I2 --> R2["Review risk: Docs: REFERENCES.md (3 files)"]
R2 --> V2["docs review"]
Evidence --> S3["Test: test_product_gap_baseline_contract.py"]
S3 --> I3["regression suite"]
I3 --> R3["Review risk: Test: test_product_gap_baseline_contract.py"]
R3 --> V3["targeted test run"]
seonghobae
left a comment
There was a problem hiding this comment.
Current-head documentation integrity finding on 916f326ce8605985a506d900fb70ed3850d3b4a9: CHANGELOG.md still labels 0.1.0 as the “First tagged release,” but the repository currently has no GitHub release and neither refs/tags/0.1.0 nor refs/tags/v0.1.0 exists. That is a release-state claim without repository evidence and conflicts with the fail-closed release policy.
Please make the narrow docs correction on this existing documentation branch: describe 0.1.0 as a dated development/version baseline (or otherwise non-release baseline) unless and until an actual protected-head release/tag is created after all release gates pass together. Do not create a tag or release merely to make the sentence true. Keep CHANGELOG/README/release-readiness wording consistent and avoid certification/compliance language that is not backed by evidence. After the wording change, rerun the exact-head documentation/repository contracts and all applicable protected checks; predecessor status does not transfer.
|
Current-head documentation repair on |
|
DDD governance handoff from #41. Devin review on #41 verified that ADR 0059 materially changes accounting authority boundaries and therefore needs the repository-required |
|
Canonical gap-baseline / shared-doc handoff from Reporting-Export #50 (no competing docs write here): #50 moved to exact For the canonical |
|
PR #50 canonical-documentation handoff update for current exact head When #37 is rebuilt on the then-current protected integrated tree, preserve these Reporting-Export facts: #50 remains an exact-value proposed/unverified, non-authoritative report/XBRL formatter; caller-supplied URLs or URNs do not confer taxonomy or filing authority. The URI input boundary now distinguishes RFC 3986 generic syntax, RFC 9110 HTTP(S) origin-host semantics, and a bounded RFC 8141 URN assigned-name structure.
Predecessor IFRS wording remains: IFRS Accounting Taxonomy 2025 is current for 2026 reporting until the next annual taxonomy in Q1 2027; 2026 Proposed Update 1/2 are proposal/consultation artifacts and must not be represented as released filing authority. Issue #51 remains the owner for AIS PostgreSQL source authority, official released taxonomy profiles, independent validation, approval, publication and external receipts. |
|
Reporting-Export handoff for the canonical documentation lane. PR #50 advanced normally from hosted-GREEN |
|
Canonical documentation handoff — no competing docs write requested. Fresh #43 review on exact The existing #43 single source-writer has been retasked to prove a realistic PostgreSQL RED and make the minimal database-owned command/status/outbox repair. Do not change #37 source merely to describe this finding again. After #43 produces a normal repaired descendant with unchanged-head GREEN and review evidence, rebuild this documentation lane against the integrated protected stack and bind the already-defined invariant to that exact migration/test/API evidence. Until then keep #37 Draft and preserve its existing event-id/created-at/published-at distinction. |
|
#43 documentation handoff — do not copy mutable source bytes. Fresh lifecycle source authority is When the reconciliation stack integrates and #37 rebuilds on the exact protected descendant, refresh the canonical product-gap/TRACEABILITY language from the released/integrated behavior rather than the PR head. The implemented deltas that must survive are: (1) migration 0021 serializes every hashed |
|
Canonical-baseline dependency correction — do not change #37 source from this coordination note. #43 is now merged history, not an open dependency. Current effective behavior stack is |
|
Follow-up exact-state correction: #29 remains |
|
Canonical-doc handoff from current reconciliation maker-checker lane; no #37 source is copied from a mutable child. Fresh #47 inventory at exact
The shared #47 docs are not reliable canonical truth: its CHANGELOG still says exception command Please preserve the semantics, not these mutable filenames, when #37 next rebuilds against integrated accounting truth: maker-checker exception resolution; command/status/outbox atomicity; post-commit outbox retention/orphan rejection; database-owned control/lifecycle system time; complete strict-JSON lifecycle source identity; committed session-lease -> fresh Do not treat this handoff as permission to mark those controls protected-integrated or release-ready. #47 current Accounting Foundation |
|
Canonical baseline prerequisite correction only; no |
|
Canonical baseline prerequisite update only: live dependency is |
|
OWNER-PATH HANDOFF — do not copy mutable branch bytes into the canonical baseline yet. Fresh 2026-09-09 source evidence advances Period Close #53 from After #53 reaches protected lineage, #37's non-destructive rebuild should record the durable rule at the accounting/evidence level: effective-dated code reuse cannot make two distinct historical account Entities evidence-equivalent for Period Close; both the emitted clearing line and its retained command/provenance digest must remain bound to the immutable posted Entity identity. Do not name the mutable Also supersede the body’s stale #52 state only for live handoff purposes: #52 is now exact |
|
Canonical-owner refresh — 2026-09-09; do not copy mutable bytes yet. Two downstream prerequisites in this PR body have advanced:
Standards handoff from Issue #51: IFRS Foundation states that no 2026 annual Accounting Taxonomy is issued; IFRS Accounting Taxonomy 2025 remains current for 2026 reporting until the 2027 taxonomy in Q1 2027. Proposed Update 1 (General Improvements, comment period closed 2026-09-07) and Proposed Update 2 (IFRS 20 / hyperinflationary presentation currency / IFRS 19 amendments, comments through 2026-09-14) are proposal authority only. When Reporting/profile work reaches protected integration, shared TRACEABILITY must distinguish released package identity + applicable reporting period + guidance digest from proposed taxonomy deltas; do not label a proposal as No #37 source/docs commit is warranted before the protected dependencies exist; this comment updates the owner acceptance without violating the single-writer/protected-truth rule. |
|
Current Period Close handoff only; no shared-doc source mutation before protected integration. #53 remains Draft/merge-conflicted at exact After #53 is normally integrated through the verified |
|
Post-integration documentation handoff for General Ledger gap #56 / RED-only #57. Do not copy mutable #57 test/source into the canonical baseline yet. After the GL repair reaches protected Current RED-only exact head is |
|
Post-integration documentation handoff for General Ledger #56/#57 only; do not copy mutable child bytes now. Protected-code review plus exact hosted PostgreSQL RED on After the causal GL repair normally integrates, reconstruct the durable invariant in |
|
Canonical post-integration docs handoff — current source authority is After the relevant production descendants reach protected integration, rebuild those shared surfaces from the integrated tree and preserve these accounting invariants:
Current exact evidence for the handoff: Accounting Foundation Fresh CodeRabbit exact-head review found no defect in the new bank-assignment RED scope and confirmed the current-clock negative control; treat that as COMMENT evidence only, never an independent Required CodeQL Single-writer boundary remains material: #29 already modifies production ADR 0022 remains Proposed for this amendment until the production DB invariant/resolver reaches protected integration. #57 ADR 0019 remains independently Proposed until full GL population/totals behavior is GREEN. Do not mark either Accepted from RED-only evidence. |
|
Canonical-doc handoff for Accounting Book identity prerequisite #58 / Draft #59 is current at exact The earlier current-row wording was too weak. Protected After #58/#59 production repair reaches protected integration, rebuild |
|
Post-integration canonical-doc handoff update from #58/#59: the durable Accounting Book reference invariant is now full half-open effective-time non-overlap, not current-row uniqueness. Canonical mutable evidence is |
|
Post-integration handoff for Accounting Book durable-reference authority: #58 / Draft #59 is now exact |
|
Post-integration handoff update for #58/#59: canonical mutable RED head is now The durable-reference invariant now has two distinct defense layers that the eventual baseline/TRACEABILITY/CHANGELOG should reconstruct from integrated code: (1) PostgreSQL owns half-open temporal non-overlap under serial and concurrent catalog writers; (2) every public |
|
Superseding post-integration handoff for shared-doc single writer #37 after fresh exact #59 descendant. Current source authority is Draft #59 When the production invariant/resolver normally integrates, reconstruct those shared surfaces from the integrated tree with these code-current contracts/evidence:
ADR 0022 on #59 is code-current for this amendment but remains Proposed until the production database invariant/resolver reaches protected integration. Rebuild shared docs only from that future protected exact tree and reacquire their own tests/reviews/gates. |
|
Post-integration handoff update for #58/#59: current mutable RED authority is The scoped Bank Reconciliation contract now has a post-admission relationship invariant in addition to chart-account-at-assignment-start resolution. Because After the production invariant/resolver normally reaches protected |
|
Post-integration #58/#59 handoff supersedes the immediately prior chart-containment note: current mutable authority is The exact After production repair normally reaches protected |
|
#59 post-integration handoff refresh — current mutable authority is The existing Accounting Book durable-reference/effective-time, Bank Reconciliation temporal-containment, same-bank/same-Book effective-identity, retained-command evidence, and evidenced retirement/amendment handoff remains. The newest #59 increment closes a remaining relationship-identity evidence gap: composite foreign keys prove that a tuple is internally valid, but do not prove that it is the tuple accepted by the retained assignment command.
After production repair normally reaches protected |
Summary
Canonical Accounting Information Platform repository-facing documentation lane. It owns
docs/product-technical-gap-baseline.md, its regression contract, the product-first README, sharedCHANGELOG.md,docs/doctoring/STANDARD_TRACEABILITY.md, and the bounded publicdocs/index.md. Runtime/database authority remains in source owner PRs; this lane must not copy mutable child implementation bytes ahead of integration.Exact current state — 2026-09-09
bdf076466b1cde0e7ae6247f44309fac153ae4c4;develop@239008c4edc7d305c97704c5102b593c6622b36f;#29@12e1a4bb9d8de5e4b6c72e2893107b07c515416b -> #47@263e4ffb79607dccee715686d0aa451981c2eeb8 -> #53;34237450022: 1,315 real-PostgreSQL tests, 6,211/6,211 statements, 2,330/2,330 branches, repository contracts, package/evidence, Security, SAST and dependency diff GREEN. Its P1 thread is resolved from hosted evidence, but no qualifying independentAPPROVEDreview exists; fix(close): freeze hard-close trial balance evidence #53 remains dependency-blocked until normal feat(reconciliation): add maker-checker exception resolution command #47 integration;9c3dba6f12aa58062faa6ba11537aabef91486d8, Draft/mergeable=false, still stored on the historicalfeat/reconciliation-exception-resolution-command@6f81b258...parent. The live prerequisite is feat(reconciliation): add maker-checker exception resolution command #47, not the stored parent. Its checked-in real-PostgreSQL RED proves that the closing-journal command/evidence hash can provenance-alias distinct historical Account entities after account-code reuse because_canonical_closing_hash()omits the exact historicalchart_account_ideven though the journal line and retained snapshot bind that Entity. The narrow Period Close repair remains mutable and must not be copied here before protected integration;3bdbeec6cc35e5b111739499c562f988f5fcaa18, Ready/mergeable after exact-head Accounting Foundation34239818457GREEN. Accounting102106807702passed behavior/repository, complete owned statement/branch coverage, strict denominator, repository contracts, compile/import and reproducible package/evidence; Security102106807452, SAST102106807652and dependency diff102106807711are GREEN. Integrated-head attestations remain skipped while stacked; no qualifying independentAPPROVEDreview exists;5a26eba357d09a0e65933da1e5ced99197130ecf, Draft. Accounting Foundation34271427012is terminal RED only on the two retained-snapshot mutation cases. Accounting102213693861ran 520 tests with 2 failures / 0 errors; dependency diff102213694040, SAST102213694259, and Security102213694269are GREEN. The Reporting-local raw lifecycle defect is repaired: direct SQL cannot move a report run out ofcollecting_sourcesand now fails withfinancial_report_run_lifecycle_immutable; this slice does not invent supersession/publication authority. The remaining two REDs are a Period Close fix(close): freeze hard-close trial balance evidence #53 dependency, not permission for Reporting to create a second retained-snapshot immutability authority.Commercial/product baseline
The baseline records Accounting Record & Close bounded-context relationships, normalized reconciliation ERD/lifecycle, immutable maker-checker exception-resolution requirements, FORCE-RLS migration rules, realistic PostgreSQL upgrade acceptance, database naming/3NF/lock/replay rules, buyer close/reconciliation stories, evidence-bound CSAP/SOC 2 readiness targets without certification claims, and explicit ecosystem ownership boundaries.
The retained authority-event invariant remains: lifecycle-completion and exception-resolution commands preserve exactly one matching outbox event after commit; deletion/re-key, duplicate exact insertion, manufacturing the authority identity from an unrelated event, or rewriting retained event identity/creation time fails closed, while
published_atremains publication metadata.The lifecycle-lease continuity invariant is verified on mutable #47 but remains a prerequisite for this lane's later protected-tree rebuild rather than being copied from branch bytes. Once protected integration exists, the baseline must state that successful authority-relevant reconciliation mutation invalidates older tenant/run lifecycle leases and that a stale repeatable-read transaction cannot promote a snapshot-visible invalidated lease into close authority.
ADR 0059/Context Map remains an owner-path prerequisite rather than copied content. #41's fitness ratchet rejects ownership rows for absent paths and its Context Map no longer advertises deleted
reconciliation_completion.py. The still-valid shared-record finding belongs here: after #41 reaches protected integration, this lane must non-destructively rebuild on that exact tree and record ADR 0059/Context Map/UL provenance, including the no-stale-owner-row and one-most-specific-primary-owner constraints, in shared CHANGELOG/TRACEABILITY before #37 itself can merge.Period Close and Reporting have a separate protected-tree handoff. #53 owns retained
trial_balance_snapshot/trial_balance_lineimmutability, one-population identity, scope/currency/conservation, chronology, concurrency and historical Account-entity provenance. After #53 reaches protected lineage, the durable baseline must record that effective-dated account-code reuse cannot make distinct historical Account entities identical in retained snapshot or closing-command/journal evidence. #52 may bind a report run to that retained AIS evidence and owns its own report-run lifecycle guard, but it may not synthesize close control or a narrower report-only snapshot authority. The baseline must not describe a report-localfinancial_report_source_population_frozentrigger as canonical. After #52 is non-force rebuilt/renumbered on protected #53 authority, this lane must record the integrated consumer contract and exact migration/API/test evidence; until then the two #52 mutation REDs and #53 closing-evidence RED stay live PR evidence rather than product truth.Current docs evidence
This docs lane's exact head
bdf0764...previously passed focused documentation contracts and Accounting Foundation34066240615/ Accounting101575389275: behavior/repository suite, exact 100% coverage over 4,981 statements and 1,796 branches, repository validation, compile/import and reproducible package; same-run dependency diff, SAST and security also passed. Required central CodeQL/review evidence remains independent, so this Draft is not merge-ready.Rebuild / merge boundary
After
#29 -> #47 -> #53integrates normally into protecteddevelop, after #41's architecture decision reaches protected integration, and after downstream #52 is rebuilt on the protected Period Close authority rather than its current provisional migration identity, non-destructively rebuild this lane on the resulting exact protected tree and reacquire repository validation, product-gap/data-model/foundation-install documentation contracts, applicable repository/organization workflows, current reviews/threads and exact ancestry on one unchanged head.That rebuild must update
docs/product-technical-gap-baseline.mdto exact integrated migration/API/test evidence, including the surviving reconciliation chain and #53/#52 eventual renumbering, adopt protected lifecycle-lease continuity evidence, adopt protected ADR 0059/Context Map truth into sharedCHANGELOG.mdanddocs/doctoring/STANDARD_TRACEABILITY.md, record the historical Account-entity provenance invariant from protected #53, and record Reporting as a consumer of Period Close-retained snapshot immutability rather than a competing source of that truth.Do not absorb mutable #47 branch-local source/test/doctoring repair or mutable #41/#53/#52 implementation into this baseline ahead of integration. PR #49 separately owns repository CI admission for documentation/Markdown changes. Do not treat skipped documentation CI as passing evidence. Do not merge, auto-merge, tag, version or release this sibling ahead of the dependency stack.