Skip to content

docs(gap): refresh product-technical baseline (74 repos, live census) - #1116

Draft
seonghobae wants to merge 79 commits into
developfrom
docs/gap-baseline-2026-08-31
Draft

docs(gap): refresh product-technical baseline (74 repos, live census)#1116
seonghobae wants to merge 79 commits into
developfrom
docs/gap-baseline-2026-08-31

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 31, 2026

Copy link
Copy Markdown
Collaborator

Canonical baseline owner

Single writer for docs/product-technical-gap-baseline.md. Protected source and exact-head evidence are authoritative; active PR behavior is never promoted into shipped truth here.

Current authority

Current Project Persistence evidence

The intermediate ACL-only gap is now closed further on #970. Renderer-authored sourceReference remains rejected. Resource Admission remains the owner of app-owned source bytes and publication identity; Project Persistence consumes that identity through a typed ACL and native save adapter.

Current causal chain after the ordinary #866 adoption:

  • 3a96be63445aba40b52c6a086ff8e4ee0623f466c2d3541ff3f1a3108adc6224b1dd565fa2a1bd83b0355a98d03c0e2128f0f1b8b79df9f779514d96: exact path-free identity projection, canonical Resource Admission size policy reuse, exported ACL.
  • 6eea76fdb138838d61e8af0d23ea69d99012de21cb7f4fd956278d1273e6be3f2df367171baadf9e: browser preview fails closed instead of claiming durable Save success without writing bytes.
  • cd3c67de8c9d35355aa30950733a1cf24a5d23fcffdac30e63c4faa7264416bbeec8570a0c6543ff: native Save accepts only an explicit optional BandScope project id, performs exact retained-identity lookup, revalidates through the typed ACL and injects v3 sourceReference before serialization. Renderer path/digest/artifact/byte evidence and global last-selected-project shortcuts remain forbidden.
  • 570894b91f69b0e24c26090309fe5ee5d414f514979ac4d3a948ab76a01e076fa29bece6161489d6: renderer bridge forwards only { payload, projectId }.
  • 28d94d0e9566030c53370829484f808f6763fbcf06afcbe030ef1fb8d6b2097be0e40bc4d5c7c03a: mounted local-audio analysis retains its exact project id through Save, scoped to the submitted/result aggregate rather than whatever source is selected later. YouTube replacement and project reopen do not inherit this OS-selected-local publication authority.
  • 8f441881f8d3a5b3fce4ab2bcf934f6fe8ef0397: traceability aligned with the current native handoff and restart residual gap.

The principal remaining advertised v3 source-persistence gap is now restart re-admission: persisted sourceReference must resolve only the app-owned artifact, re-establish regular/no-link containment, bounded size/SHA-256 and applicable decode/admission, reconstruct fresh bootstrap/native identity, and only then permit #1160 to resolve persisted selectedPlaybackSource against fresh stem availability. Missing preferred stems fail closed to Full mix.

Baseline source-currentness

docs/product-technical-gap-baseline.md at 3dbdecf… still names an older #970 semantic snapshot. It does not record the now-completed native retained-identity Save handoff and therefore is not fully code-current for this boundary.

Do not promote it as complete. The next product-semantic #1116 source repair must update the Project Persistence/Crash-safe Project rows through #970 8f441881… and move the residual gap to restart re-admission. Because that changes the canonical baseline blob, immediately follow with an ordinary non-force #968 reconciliation preserving all 22 queue-owned files and leaving docs/product-technical-gap-baseline.md non-divergent on #968.

Protected gate defect

Fresh branch data still reports protected develop@314ddeae… with 14 required contexts, including retired Analyze (javascript-typescript) and Analyze (python). #1172 remains the owner of exact context-name migration to the current central CodeQL producer; duplicate local scanning or weaker coverage is not an acceptable workaround.

Verification / merge gate

Keep Draft. #1116 source head has not changed in this metadata-only update. #970 exact-head workflows are newly materialized and non-terminal, so no GREEN/Ready/merge claim transfers from predecessors. No self-approval, force-push, destructive rebase, bypass, gate weakening or stale evidence transfer.

…losed review-gate RCA

Base revision moved to develop@749511c3. Open-PR count 130 -> 185 (6 days,
+55; only #957 landed). Section 5 adds finding (k2): all sampled PRs pass
code gates but the three org-owned required reviews (opencode-review, strix,
noema-review) fail closed, blocking every PR. Records observed in-flight
central repair (noema call_llm timeout branch) as a do-not-duplicate item,
and re-scopes P0 #3 to gate remediation as the single top priority.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SoJBAAXwv58S8P4hQBQQAw
@coderabbitai

coderabbitai Bot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

BandScope의 제품·기술 기준선과 운영 증거 문서를 갱신했습니다. 최신 census, 제품 요구사항, 병합 증거, transport 상태, 영속성 계약, 보안 경계, 품질 및 릴리스 기준을 반영했습니다.

Changes

BandScope 기준선 문서

Layer / File(s) Summary
제품 및 배송 계약
docs/product-technical-gap-baseline.md, docs/doctoring/product-gap-baseline-2026-09-01.md
74개 저장소의 최신 census와 BandScope backlog를 갱신했습니다. 제품 요구사항, 활성 작업 흐름, 병합 승계, historical evidence 및 source-selection authority를 기록했습니다.
도메인 및 기술 설계
docs/product-technical-gap-baseline.md
도메인 모델과 시스템 토폴로지를 보완했습니다. InitialSourceSelectingReplacementSourceSelecting 상태와 source 취소·실패·교체·삭제 전이를 추가했습니다. project_format_version, 원자적 교체, last-known-good recovery 및 식별자 호환성 계약을 명시했습니다.
보안 및 추적성 기준
docs/product-technical-gap-baseline.md
실제 오디오 acceptance, allowlisted Tauri IPC, 127.0.0.1 loopback, 입력 admission, subprocess 권한, 개인정보 redaction, UI/UX evidence, 품질·릴리스 게이트 및 traceability 기준을 갱신했습니다.

Estimated code review effort: 2 (Simple) | ~15 minutes

Merge Risk: 🟡 Moderate · up to 3f29e

The recovery state model currently leaves RecoveryFailed with no documented exit, so a failed restore can dead-end users and encode an incomplete product contract. Merge should wait until the contract defines acknowledgement to NoSource or retry behavior, with regression coverage.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed PR 제목은 74개 저장소의 최신 census를 포함한 product-technical baseline 문서 갱신이라는 주요 변경을 정확하고 간결하게 설명합니다.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch docs/gap-baseline-2026-08-31

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

devin-ai-integration[bot]

This comment was marked as resolved.

… progress

Iteration-2 status: gates still fail closed. Central .github landed 8
Noema-reliability fixes (#1477-#1504) plus an active "remove fixed LLM
response timeout" branch. Local response: staged merge-ready work behind
the closed gates — PR #1116 (this baseline) and PR #1117 (temporal probe
promoted from cli hack to api integration, 100% coverage locally).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SoJBAAXwv58S8P4hQBQQAw
devin-ai-integration[bot]

This comment was marked as resolved.

Copy link
Copy Markdown
Collaborator Author

@opencode-agent Become the sole writer for canonical BandScope branch docs/gap-baseline-2026-08-31 only while it still resolves to exact head 00019c9ffe18bd630b14c4cd7c4ff4146def340f and protected develop still resolves to 749511c3ad4000090048718f685c6bee6b3d2c25. Apply superpowers:using-superpowers, receiving-code-review, systematic-debugging, and verification-before-completion. Immediately before writing refetch the exact head/base, the current blob of docs/product-technical-gap-baseline.md, and unresolved threads PRRT_kwDORjvEXs6ds6Rf, PRRT_kwDORjvEXs6ds6Sq, PRRT_kwDORjvEXs6ds6Ty, PRRT_kwDORjvEXs6duRIm; abort/adapt if the ref/blob moved. This is a BandScope-docs-only lane: do not modify central .github, foreign repos, source code, or workflows; do not create another PR, force-push, or weaken gates.

Validate every finding against fresh live evidence before editing. Current verified contradictions on this exact head include:

  1. The document says the refreshed inventory is 185 open PRs but its recorded verification still says 130. Fresh GitHub pagination returns open develop PRs across pages 1 and 2, with page 3 empty and no open main PRs. Record a reproducible current inventory command/result or, if the count has moved since this comment, use the fresh actual count consistently instead of preserving 185 as a slogan.
  2. §6 says docs has no Mermaid/sequence/class diagrams immediately before embedding two Mermaid diagrams itself; the review also notes existing doctoring Mermaid flowcharts. Replace the repository-wide absence claim with the narrower truthful gap (for example, no canonical comprehensive UML/C4/domain/state-model set, if fresh search supports that) and preserve existing diagrams as evidence rather than pretending they do not exist.
  3. P1 misroutes loop playback to Issue [Release] Ship signed, notarized, auto-updatable desktop builds with rollback evidence #960. Fresh issue authority: [Release] Ship signed, notarized, auto-updatable desktop builds with rollback evidence #960 is signed/notarized/updater/release/rollback; [Product] Add an active rehearsal player with precise looping and role controls #961 owns active rehearsal player/transport/precise loops/role controls. The adjacent crash-safe project row is also shifted: [Reliability] Add a versioned crash-safe project format, autosave, migration and recovery #962 owns crash-safe/versioned project format; [Operations] Build redacted diagnostics, crash evidence and an offline support bundle #963 owns diagnostics/support bundle. Correct the issue mapping wherever the document has this off-by-one drift.
  4. Revalidate live status claims rather than publishing remembered state. In particular, the Noema 120-second failure is now confirmed by consumer bandscope#1115@223d53f6c63dc17f7ce219faa52e5eafbd7719ed, required run/job 33386655858/99470699909, which reached call_llm only after sidecar/gateway preflight and then raised TimeoutError at the protected-main timeout=120 path. The canonical central owner is now open .github#1509 (fix(noema): raise call_llm HTTP timeout from 120s to org policy), exact current head 3d2b6a8262e323c794885387d1e70297b39366b5; a BandScope-local workaround is not appropriate. Also refetch refactor(engine): promote temporal probe from cli hack to api integration #1117 before repeating any exact-head test/readiness claim.

Keep the baseline a truth source rather than a blocker narrative: distinguish protected shipped truth, current live evidence, accepted/open work, and planned gaps. If correcting the document surfaces a concrete BandScope executable gap already owned by an issue/PR, link its canonical owner; do not implement that code in this docs lane. Run any repository doc/markdown/contract checks that apply plus git diff --check, commit the smallest correction on this same branch, reply with successor exact SHA and evidence, and resolve only threads whose exact claims are actually corrected on the successor head.

@seonghobae seonghobae changed the title docs(gap): refresh product-technical gap baseline (185 PRs, merge-train stall RCA) docs(gap): establish current product-technical baseline (190 PR capture, exact-head RCA) Sep 1, 2026
devin-ai-integration[bot]

This comment was marked as resolved.

@seonghobae seonghobae changed the title docs(gap): establish current product-technical baseline (190 PR capture, exact-head RCA) docs(gap): establish current product-technical baseline (188 PR capture, 71-repo recount) Sep 1, 2026
@seonghobae seonghobae changed the title docs(gap): establish current product-technical baseline (188 PR capture, 71-repo recount) docs(gap): establish current product-technical baseline (188 PR capture, 72-repo recount) Sep 1, 2026
devin-ai-integration[bot]

This comment was marked as resolved.

Copy link
Copy Markdown
Collaborator Author

Concurrent recount note for the new exact head 825512fed478a1a30c60756bd21fd2599bc98f8b: every one of the 72 accessible repositories was queried individually in this cycle. Because remote agents continued opening/closing PRs during the sequential sweep, those 72 per-repository observations sum to 2,689, while the organization-wide atomic search returned 2,690 at the baseline capture and then 2,691 later in the same run. This is expected live-queue skew, not a counting contract to 'fix' by freezing writers. The rank is stable by a wide margin: BandScope 188, TEPP 142, OriginWeave 140, newsdom-api 130, naruon 127. The document's 2,690 value remains a timestamped capture rather than a timeless invariant; merge decisions continue to refetch exact live state.

@seonghobae seonghobae changed the title docs(gap): establish current product-technical baseline (188 PR capture, 72-repo recount) docs(gap): establish current product-technical baseline (189 PR capture, 72-repo recount) Sep 1, 2026

seonghobae commented Sep 1, 2026

Copy link
Copy Markdown
Collaborator Author

@claude Please refresh the two canonical baseline files on exact current head 825512fed478a1a30c60756bd21fd2599bc98f8b through normal non-force history; do not create a competing PR. Superseding fresh evidence at 2026-09-01 17:43 KST: 73 repositories are now accessible through the connected ContextualWisdomLab GitHub account because ContextualWisdomLab/ConceptWeave is newly present; the organization-wide atomic is:pr is:open capture is 2,683. Current high-backlog counts remain bandscope 189, TEPP 149, OriginWeave 140, newsdom-api 130, naruon 125. This run exhaustively partitioned all 73 accessible repository names into GitHub issue-search groups; every non-BandScope partition was below 189, so the highest-backlog selection is proven without assuming a stale repository list. Treat all queue numbers as timestamped evidence because concurrent writers remain active. Replace the prior 72-repository/volatile-count snapshot in docs/product-technical-gap-baseline.md and docs/doctoring/product-gap-baseline-2026-09-01.md without rewriting immutable PRD/TRD/DDD/UML/research contracts merely because the queue moved.

Also reconcile central-review status from fresh protected-central evidence. ContextualWisdomLab/.github#1546 remains protected truth at 5686de41660d51a7a7f22b8840dfa6ccfe5ff3f1, but the post-#1546 repository-wide scripts/ci coverage repair is still not protected truth. The current canonical root owner remains .github#1567, now exact head 400f2b5a63a5cdaf95a42ee4d49a4e492132738b. That branch now carries the scheduler coverage/SIGPIPE repair plus the history-preserved stacked #1491 Noema cleanup that removes the never-wired CodeGraph-context branch; because #1491 merged into #1567 rather than protected main, all predecessor #1567 evidence was invalidated and fresh exact-head evidence is required. Therefore central coverage remains an outstanding downstream prerequisite until #1567 itself reaches protected main. Do not revert to the obsolete claim that #1551's closure meant no coverage prerequisite remained, and do not promote #1567/#1491 candidate behavior to protected truth.

Keep the existing Rust core-computation ownership, bounded CPU/accelerator boundary, real-audio acceptance, 100% coverage/docstring/edge-case target, Storybook/Figma/screenshot UX contract, security/operability baseline, and APA 7 traceability intact. Update only truthful volatile evidence and directly contradicted status prose. Run the documentation/baseline contract tests and git diff --check, report the resulting exact head, and do not self-approve, force-push, weaken gates, or transfer predecessor evidence.

@seonghobae seonghobae changed the title docs(gap): establish current product-technical baseline (189 PR capture, 72-repo recount) docs(gap): establish current product-technical baseline (189 PR capture, 73-repo recount) Sep 1, 2026
devin-ai-integration[bot]

This comment was marked as resolved.

@seonghobae seonghobae changed the title docs(gap): establish current product-technical baseline (189 PR capture, 73-repo recount) docs(gap): establish current product-technical baseline (185 PR capture, 73-repo recount) Sep 1, 2026

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

This report is out of date. Scroll down for Devin Review's latest report on this PR.

Devin Review found 2 new potential issues.

Devin Review

Comment thread scripts/checks/verify_docs.py Outdated
Comment thread scripts/checks/verify_docs.py
devin-ai-integration[bot]

This comment was marked as resolved.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 new potential issue.

Devin Review

Comment thread scripts/checks/verify_docs.py
@seonghobae
seonghobae marked this pull request as draft September 4, 2026 03:07

Copy link
Copy Markdown
Collaborator Author

Active Player Draft navigation refresh (not shipped baseline truth): protected source remains develop@314ddeae7b775a4957594b599358c8255617eb2e; #971 remains 9c1b20e6df778e303fada3e170c93418c496394b, #1159 remains 22a9f18d960cc7df93db890b2a5aa9594428c2b4, and #1160 is now 1f933ec1998d53eb8f1bc4b96ac933c56b017c24. The #1160 delta now also contains test-first source-switch continuity (d3df3767…4b78eabe…) and stale-safe renderer discovery-session lifetime (899f122e…d37a7b88…), with code-current traceability in docs/traceability/playback-source-session.md. These contracts still are not mounted selector/shipped truth: RehearsalPlayer does not yet bind discovery/session state or execute the source-switch plan through the media load lifecycle; current locale infrastructure remains EN/KO only; exact-head protected workflow evidence is absent. Keep #1116 source head unchanged unless/until the canonical baseline file itself needs a semantic refresh; this comment records live Draft lineage only.

seonghobae added a commit that referenced this pull request Sep 4, 2026
Preserve the executable #966 queue-control delta while adopting #1116's code-current Active Player stack and release evidence. No force update or evidence transfer.
seonghobae added a commit that referenced this pull request Sep 5, 2026
Preserve the executable #966 queue-control tree while adopting #1116's code-current product/technical baseline through an ordinary two-parent descendant. Do not transfer predecessor checks or reviews.
seonghobae added a commit that referenced this pull request Sep 5, 2026
Preserve the executable #966 queue-control tree while adopting #1116's code-current Project Persistence v2 baseline through an ordinary two-parent descendant. Do not transfer predecessor checks or reviews.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation priority: medium Normal-priority or P2 work status: blocked Blocked by conflict, dependency, or required prerequisite type: docs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant