diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 98bc17d2a..9f869c511 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,1016 +1,344 @@ # Naruon Product and Technical Gap Baseline -**Baseline version:** 1.2 -**Observed on:** 2026-08-26 (Asia/Seoul) -**Observed protected branch (current scan; row Base-SHA values remain historical):** `develop@e5e99b4e3bb081b92c602358878856536030e2ca` +**Baseline version:** 3.02 +**Observed on:** 2026-09-30 (Asia/Seoul) +**Protected product authority:** `develop@042b0c70531b229af3acbd0421a2f23098d848b3` / tree `8fde14381aaa430eeaaf61151dab6f6800127cd3` **Observed product version:** `0.14.4` -**Canonical completion issue:** [#1428](https://github.com/ContextualWisdomLab/naruon/issues/1428) - -**Inventory observation:** the 106-PR open surface below is a fresh live -scan captured at `2026-08-25T15:52:01Z`, which returned 106 open PRs after -PR #1337 merged into protected `develop` at `2026-08-25T00:10:39Z` and -the later governance stack merge (#1448) and additional PR wave opened since -the previous observation. The -v0.2 baseline's 93-row snapshot from `2026-08-21T19:25:43Z` remains historical -context, as do the earlier 92-PR state after PR #1442 merged and the initial -83-PR observation in issue #1428; all counts are point-in-time evidence, not -current merge state. - -**Follow-up delta observation:** a seventh live scan at -`2026-08-25T15:39:22Z` found the active exact-head work relevant to this -baseline: #1465 (`70596e26…`, tenant-archive import sanitization and duplicate -identity rejection), #1466 (`a3e6762f…`, origin-integrity port validation), -#1467 (`6816bc7f…`, utility-tool JSON boundary and Strix-trigger restoration), -#1468 (`1da167de…`, PostgreSQL smoke fixture schema alignment), #1469 -(`de6d7128…`, bounded 20–64 MiB deferred attachment parse-source admission), -and #1455 (`d8757e65…`, attachment filename traversal hardening). The -governance root #1443 now has exact head `62a0d645…` after child #1448 merged -normally into its stack branch. #1448 merged at -`2026-08-25T15:31:39Z` with merge commit `62a0d645…`; its tree retains the -parent gate fix and the multiline, stale-head, and current-finding regression -cases. The merge-result Checks for that commit remain queued and are tracked -as post-merge canary evidence, not success. -The newly opened #1470 is now `aba77cf5…` (NetworkGraph edge-description -lookup cleanup); the predecessor `f8a70d37…` was discarded after a remote -commit reintroduced the dead argument and its callers. The current head also -removes the tracked 452-line `NetworkGraph.tsx.out` pre-refactor copy found by -Devin, with the 11-test focused suite, TypeScript, zero-warning ESLint, and -diff checks passing locally. Hosted Checks and independent approval remain -required. -These PRs remain open until their current-head required Checks and qualifying -independent approval satisfy the protected ruleset; this follow-up does not -reuse predecessor evidence or claim a merge. #1448 is historical after its -normal merge; #1443's current head is `62a0d645…` and must be reviewed and -checked again from that exact head. - -**Live exact-head queue refresh (2026-08-25T17:51Z):** the following -post-snapshot states supersede only the matching historical SHA references -above; the full inventory remains a point-in-time record and is not silently -rewritten. #1468 is `1da167de26b442be6961622f15bb36ae9374e6c4`; its source, -backend, and frontend evidence is successful, while the retried Strix run is -queued after the earlier NVIDIA NIM provider failure. #1469 is now -`575b0c24fd9cb98106989eb101de74c5ce383db3`, after a remote follow-up removed -the unreachable document-size branch; 109 attachment/import/NewsDOM tests -pass locally, and the PR remains stacked behind #1468 because the selected -full suite exposes the base fixture defect repaired by #1468. #1470 remains -`aba77cf5b6a47985b352e8d2c2d76413579ea88a`; backend, frontend, Strix, and -metadata checks are successful, and its exact-head CodeRabbit approval is -present, but the ruleset still requires the second qualifying approval and -the exact-head OpenCode dispatch is queued. #1455 remains -`b2b4701366bc6bb2de1347b19eac9b4ed64cc614` with backend/frontend evidence -successful and Strix still running. #1429 remains -`b93caf0e00d09de0f836d8e4b869054d792e674b`; its refreshed hosted checks are -queued or in progress. #1347 remains -`f9e1751e2d5069841b279ecd2414fbbcad2e5692`; its newest metadata result is -not merge evidence and the remaining hosted checks are queued. None of these -states satisfies the two-approval protected ruleset, and none is a force-merge -candidate. - -**Live exact-head queue refresh (2026-08-25T18:06Z):** a subsequent -re-fetch supersedes only the matching queue entries above. PR #1436 moved to -exact head `034d2ff4e0d120d1e7b7669b35ea8eea7d8c1221`; its frontend, backend, -and Strix checks were recreated and queued, with zero unresolved review -threads and no qualifying approval. PR #1470 remains -`aba77cf5b6a47985b352e8d2c2d76413579ea88a`; its metadata, OpenCode, -frontend, backend, Strix, and security checks are successful, but only the -exact-head CodeRabbit approval exists and the protected ruleset requires a -second qualifying approval. PR #1467 remains -`6816bc7f938fe361f2eb7a0ecee427f87170fbcb`; source/security checks are -successful, metadata is still in progress, and only CodeRabbit has approved. -PR #1466 remains `a3e6762f01666f5b4e9d202932012de23b942c59` with all -observed required checks successful but no current approval. PR #1468 remains -`1da167de26b442be6961622f15bb36ae9374e6c4`; its source checks are successful, -the retried Strix check is queued, and its metadata gate is not a merge -result. PR #1469 remains `575b0c24fd9cb98106989eb101de74c5ce383db3`; its -source checks pass while image validation and Strix are running and metadata -is failed pending current review evidence. PR #1455 remains -`b2b4701366bc6bb2de1347b19eac9b4ed64cc614` with image checks successful, -coverage and metadata pending, and Strix running. PR #1347 remains -`f9e1751e2d5069841b279ecd2414fbbcad2e5692`; its three informational review -threads are resolved, but metadata is failed and Strix/coverage are still -running. PR #1429 remains `39d796d14b93484e004c13d7e2db4cc2eee5cdb1` with -the refreshed hosted suite queued. No entry satisfies the two-approval -ruleset, and no entry is a force-merge candidate. - -**Current Checks inventory:** the same live scan found 106 open PRs. Completed -failures were limited to `metadata-only gate evaluation` and `strix`; the -metadata gate reports the underlying Strix failure and, on some heads, a -current-head CodeRabbit quota/provider warning. The Naruon hosted Strix logs -for the observed #1468 run show NVIDIA NIM HTTP 429 rate limiting followed by -an unavailable direct fallback. This describes that run's provider evidence, -not the central Strix default documented in `AGENTS.md`; it is failed -infrastructure evidence rather than a clean security result or a source defect. -These PRs remain blocked and are not -force-merged; the exact head must receive a successful hosted security result. -PR #1466 has successful required Checks but remains in GitHub's protected -auto-merge queue with `REVIEW_REQUIRED` and no qualifying independent -approval, so it is also not treated as manually merged. - -The latest exact-head follow-up also records: #1347 at -`e97fa1e4…` with its governance regression tests passing but hosted required -Checks queued and no qualifying approval; #1433 at `b84255e5…` with source -checks passing but Strix failed closed after NVIDIA NIM HTTP 429 retries and a -configured direct OpenAI HTTP 404 fallback; #1450 at `073408ce…` with all -other Checks successful while the metadata gate remains in progress; #1455 at -`d8757e65…` with all hosted Checks successful but no current-head approval; -and #1466 at `a3e6762f…` with all hosted Checks successful but no qualifying -independent approval. These are live queue observations, not merge evidence. -The provider failures are retained as infrastructure evidence and are not -converted into source changes or clean security claims. - -**Exact-head maintenance ledger (2026-08-26):** PR #1347 now has exact head -`f9e1751e2d5069841b279ecd2414fbbcad2e5692` on this protected base. Its -governance normalization wrapper now fails closed when the review-unavailable -`jq` parser fails or emits a non-numeric count, and its early-exit cleanup trap -removes the wrapper-created comments snapshot when no PR number is available. -The exact-head local contract suite is 14 passed and the shell self-test remains -green. Hosted required Checks -were recreated and remain queued, so this is not a hosted pass or merge claim. -PR #1364 now has exact head -`3a3baa6b8dc9ea224f46395cb78c91a45be2090c` on this protected base. Its scoped -S3 document lifecycle, encrypted provider registry, compensation/orphan cleanup, -migrations, API, and LocalStack/PostgreSQL integration contract passed 195 -focused local tests, Ruff, compileall, and diff checks. Hosted required Checks -and independent approval remain required; protected auto-merge is enabled but -no merge is claimed. The attachment and UI work continued on independent -branches while hosted runners were queued. PR #1419 -now has exact head `2924b5598d4f527d493e1fc88cebd8fe87e1a3c4` on this protected -base, with 263 focused attachment/inline-image/email tests plus Ruff passing; -its hosted required checks were recreated for that head and remain queued, so -the normal protected squash auto-merge is enabled but not claimed as complete. -PR #1436 now has exact head -`1573be3332725bfbd05053943988d652df22a846` on the same base, with 446 frontend -tests, lint, typecheck, Next production build, Storybook build, and desktop / -mobile Storybook screenshots for source-open, low-confidence, -blocked-execution, and shared-scale states passing locally. It intentionally -remains pending because it carries a UI overlay at this document path while -PR #1429 owns the canonical commercial baseline; merge #1429 first, then -reconcile #1436 against the canonical file before enabling auto-merge. These -observations are exact-head evidence, not a release or hosted security claim. -PR #1415 now has exact head `994c6d40bb8a5a1de82e2f137300ea620bcdf933`; the -OIDC `kid` selection and strict administrator-role boundary passed 98 focused -authentication tests. PR #1417 now has exact head -`46f4b92a717361e3e4e42fcebc1d8c090a64c59b`; its PostgreSQL smoke seed now -explicitly supplies `is_read` after a real existing-schema NOT NULL failure, -and 180 focused tests pass. PR #1455 now has exact head -`b2b4701366bc6bb2de1347b19eac9b4ed64cc614`; bounded filename decoding and -Windows-separator traversal protection passed 130 focused parser/import tests. -All three have recreated hosted Checks and remain normal protected-merge -candidates; no hosted pass or merge is claimed. - -The protected-branch SHA in this header identifies the baseline's observation -point. The inventory's `Base-SHA` column is captured independently for each PR -at its scan time, so an older `develop` SHA in a row is expected snapshot -metadata rather than a second claim about the current protected branch. - -**Live exact-head queue refresh (2026-08-25T18:38Z):** PR #1468 remains at -`1da167de26b442be6961622f15bb36ae9374e6c4` and its current hosted check rollup -has no failed or pending run; it still has zero qualifying approvals and zero -unresolved threads, so protected auto-merge has not occurred. PR #1469 remains -at `575b0c24fd9cb98106989eb101de74c5ce383db3`; its source checks are passing, -while the metadata gate remains failed on current review evidence and -OpenCode is queued. PR #1429 remains at -`f2143f9d997736040eb3152f59ce058dc22ea72b` with the refreshed hosted suite -queued or in progress. PR #1436 remains at -`034d2ff4e0d120d1e7b7669b35ea8eea7d8c1221` with frontend image, coverage, and -Strix work still running. PR #1470 has a successful current check rollup and -one exact-head bot approval, but still lacks the second qualifying approval. -None of these observations authorizes a bypass merge. - -The owning upstream sidecar `Seongho-Bae/newsdom-api` PR #682 remains at -`585bb4e0fb719ab6a576cf46d1ef12b77872557b`. Its bounded 64 MiB source and -boundary tests are present, while its only failed hosted check is the -provider-infrastructure Strix run (NVIDIA NIM rate limiting followed by an -unavailable fallback); no source vulnerability report was produced and the -normal rerun workflow is unavailable. The provider PR therefore remains -`WAIT_AND_REMEDIATE`, not a clean security pass or a force-merge candidate. -NewsDOM issue [#707](https://github.com/Seongho-Bae/newsdom-api/issues/707) -owns the follow-up resumable-upload contract for documents above 64 MiB, so -the current synchronous fallback must not be mistaken for the target -commercial large-document UX. - -The central `ContextualWisdomLab/.github` control plane has two related -current-head repairs: PR #1331 (`a1408f52…`) separates the direct-OpenAI -fallback API base from the primary provider and has all observed checks passing -except queued coverage, while PR #1333 (`5454a196…`) adds bounded provider -retry/attempt-log handling with OpenCode still queued. Both have zero -qualifying approvals and remain normal protected-merge candidates; their -changes overlap in `.github/workflows/strix.yml`, so the first protected merge -must be re-fetched before the second is restacked. - -This document defines the evidence-backed boundary between what Naruon currently -ships on protected `develop`, what is present only in open pull requests, what is -still a product-plan aspiration, and what a buyer must be able to complete before -Naruon is described as a generally available commercial product. - -Counts, branch SHAs, checks, reviews, and pull-request state are point-in-time -evidence. They must be re-fetched before a merge or release decision. - ---- - -## 1. Executive decision - -Naruon is no longer a small prototype. The protected branch already contains a -substantial, security-conscious **customer-owned communication and context -control plane**: - -```text -customer-owned mail / calendar / contact / file systems -→ Naruon ingest, thread, search, context, evidence, task, and action control -→ explicit human approval or correction -→ conflict-aware provider writeback through an outbound connector -``` - -Naruon must **not** become an SMTP server, IMAP mailbox host, public MX provider, -calendar source of truth, or file source of truth. Customer providers remain -authoritative. Naruon owns scoped context, policy, recommendation, intent, -connector command state, retry/reconciliation evidence, and the user-visible -decision/action experience. - -The accurate current product classification is: - -> **Production-oriented pre-GA communication control plane with substantial -> protected-branch capability, an unconverged ~100-open-PR integration surface (102 at the 2026-08-25 snapshot), and an -> incomplete buyer-visible release/operations contract.** - -The first sellable boundary is **GA-1: Customer-owned Mail, Calendar, Contact, -and File Control Plane**. The complete dense knowledge graph, no-ask -correct-by-exception reasoning, minimal-disclosure bridge, and third-party plugin -platform remain the north-star after GA-1 rather than prerequisites for the -first commercial release. - ---- - -## 2. Evidence hierarchy - -When sources disagree, use this order: - -1. exact protected-branch code, migrations, tests, runtime contracts, and - security boundaries; -2. exact protected-branch architecture and operations documents; -3. exact current pull-request code and current-head evidence; -4. open Issues and accepted ADRs; -5. older product plans, README limitations, and historical PR descriptions. - -A plan marked `[LIVE]` is not proof if the protected implementation contradicts -it. Conversely, an old README statement that calls a protected implementation -“future work” must be corrected rather than used to hide shipped behavior. - ---- - -## 3. Point-in-time repository snapshot - -| Item | Observation | -|---|---| -| Protected branch | `develop@e5e99b4e3bb081b92c602358878856536030e2ca` | -| Product/package version | `0.14.4` | -| Open pull requests | **102** (live scan at `2026-08-25T00:26:45Z`, post-#1337 merge) | -| Open issues | **61** (live count at the same 2026-08-25 snapshot; 59 were open before this baseline program) | -| New completion issue | #1428 | -| Required backend runtime | Python 3.14 exact-head lane | -| Core runtime | Next.js frontend, FastAPI backend, PostgreSQL + pgvector | -| Default data authority | customer-owned mail, CalDAV/CardDAV, and WebDAV providers | -| Default merge posture | strict exact-head checks plus qualifying independent review | - -The **102-open-PR** count is the live inventory snapshot captured on -2026-08-25 against the protected branch shown above, after PR #1337 merged. -The v0.2 baseline recorded **93 open PRs** on 2026-08-21 after PR #1448 -opened, an earlier same-day snapshot recorded **92 open PRs** after -PR #1442 merged, and the initial completion issue #1428 recorded **83 open -PRs** on 2026-08-20 against `develop@c9bfba2...`; these are historical -baselines, not contradictions. Later live counts can change as PRs open, -close, or merge, so every release decision must re-fetch the REST state. - -The protected branch requires exact-head backend, frontend, security, CodeQL, -dependency review, Scorecard, OSV, Trivy, Strix, source/evidence coverage, -backend/frontend/combined image validation, and OpenCode review contexts. Pending, -queued, stale, predecessor-head, skipped-required, neutral, author-only, -model-only, or local-only evidence is not passing evidence. - ---- - -## 4. Protected-branch product truth - -### 4.1 Shipped communication and workspace surface - -Protected `develop` exposes buyer-recognizable product surfaces for: - -- Today execution dashboard; -- Mail, thread history, search, reply, and pending-reply work; -- Calendar views, source-backed coordination, and writeback intent; -- Tasks and source-linked ticket work; -- Projects, project graph, and evidence-linked records; -- Context Search and hybrid retrieval; -- AI Hub and provider-neutral AI workflows; -- Data/document ingestion and controlled materialization; -- Security/policy/audit views; -- Settings, identity, provider, and deployment controls. - -The product already distinguishes simulated local send from real delivery, -preserves `In-Reply-To` and `References`, scopes email/provider records by owner -and organization, keeps opaque public identifiers separate from sequential -surrogates, and applies deny-first RBAC/ABAC policies. - -### 4.2 Source-of-truth and writeback sovereignty - -Protected `develop` already enforces important commercial boundaries: - -- customer mail, calendars, contacts, and files remain durable provider truth; -- browser input selects an opaque source reference but cannot assert ownership, - region, credential, or capability; -- writeback is intent-only unless the user explicitly requests provider - execution; -- provider execution re-reads server-authoritative source records; -- CalDAV and WebDAV updates preserve ETag/If-Match conflict semantics; -- private-network provider access uses an outbound-only connector rather than - inbound firewall holes or public mail hosting; -- provider credentials and command payloads are excluded from browser and - aggregate observability surfaces. - -### 4.3 Durable writeback retry is implemented - -The current protected source-of-truth document records behavior that the root -README still describes as future work: - -- scoped `provider_writeback_retry_items` rows; -- encrypted retry command payloads; -- retry dispatch with retry enqueue disabled for the nested attempt; -- exponential backoff; -- `succeeded`, rescheduled retry, and `failed_exhausted` outcomes; -- persisted connector signal events for dispatch, timeout, transport, and - adapter outcomes; -- organization-admin aggregate queue-depth reads without exposing payload, - credential, runner, source, or retry identities. - -This is a material product-truth correction. The remaining gap is not “create a -retry queue.” It is **finish connector packaging, identity/enrollment, complete -protocol coverage, dead-letter/reconciliation operations, and buyer-visible -support evidence**. - -### 4.4 AI and scientific boundary - -Naruon has grounded content segments, hybrid search, named/versioned KG -extractor seams, deterministic fallback, contextual-orchestrator routing, and -batch-embedding integration boundaries. It does **not** have a protected live -Structural Topic Model endpoint or fitted topic artifact. Deterministic keyword -metadata must not be marketed as STM or temporal event psychometrics. - -TEPP may be consumed only through a separately accepted, immutable, versioned -scientific artifact/API with preprocessing, vocabulary, covariates, posterior -uncertainty, diagnostics, provenance, and abstention. Naruon owns identity, -authorization, adapter envelopes, and disclosure policy; TEPP owns the -scientific payload. - ---- - -## 5. Product-truth and release-truth inconsistencies - -| Inconsistency | Current evidence | Buyer risk | Required correction | -|---|---|---|---| -| README says durable retry/audit remains future work | protected operations document describes encrypted retry rows, retry worker, backoff, exhaustion, and aggregate visibility | buyers and contributors cannot tell what is shipped | merge a customer/operator README based on protected truth; keep unsupported behavior explicitly limited | -| Release architecture says first candidate should be `v0.1.0` | `VERSION` and backend package are `0.14.4` | release procedure may publish or validate the wrong identity | replace historical hypothesis with current release-train policy and immutable release manifest | -| Product plan marks typed Person/Event/Commitment/Plugin concepts as new/planned | current code search does not prove authoritative `graph_persons`, `graph_events`, `graph_commitments`, or `plugin_registrations` stores | UI/marketing can imply dense-KG/product-platform completion that does not exist | keep north-star language, implement typed domains through bounded PRs, and gate claims on protected code | -| The live open-PR population (93 on 2026-08-21; 102 on 2026-08-25) contains many overlapping, stacked, micro, dependency, governance, and broad integration changes | current GitHub inventory | predecessor evidence, writer collision, stale branches, and integration starvation | establish a release train, classify every PR, close duplicates, merge parent-first, and use one writer per authority cluster | -| Required independent review exists but the current human reviewer path is unresolved | #1371 | green automation cannot produce a lawful protected merge | resolve reviewer governance without weakening rulesets or self-approval | -| Connector is described through a self-hosted-runner analogy | protected code has protocol adapters and retry behavior but no complete released connector lifecycle | operators may deploy test infrastructure as production relay | deliver signed installable connector artifacts, enrollment/rotation, source health, fleet SLO, and runbooks | - ---- - -## 6. Current pull-request surface - -The current open PR count is too large to treat as one releasable integration -unit. This baseline does not claim that every one of the 102 PRs has been -line-by-line approved. It records the product-significant active lanes observed -and defines the inventory that must be completed before GA. - -### 6.1 Product-significant active lanes - -| PR | Lane | Baseline judgment | -|---:|---|---| -| #1364 | scoped S3 document-object backend | high-leverage GA durability lane; Draft until real PostgreSQL + S3 lifecycle, backfill, cleanup, failure, and exact-head evidence are complete | -| #1417 | shared PostgreSQL-backed email-send throttle | necessary multi-replica safety; keep isolated and merge only with current-head concurrency/security evidence | -| #1416 | provider-backed CalDAV create writeback | relevant to GA scheduling execution; preserve create vs update precondition distinction and integrate into the broader #978 contract | -| #1353 | HWP/HWPX deterministic recognition boundary | useful Korean enterprise document admission; does not complete parsing/conversion/search semantics | -| #1397 | inline-media admission/tracking-pixel classification | valid evidence-protection slice; remain Draft until the #1350 stack and independent review are coherent | -| #1419 | common image metadata | bounded local evidence extraction; no OCR/VLM claim | -| #1418 | auditable URL/contact hygiene | deterministic tool/evidence lane; ensure contact redaction is not represented as complete anonymization | -| #1317 | broad macOS/local-AI/runtime/governance integration | valuable evidence but unusually broad; must be decomposed or reconciled carefully because many active PRs overlap its surfaces | -| #1392 | customer/operator README rewrite | directly addresses product-truth debt and has reported exact-head checks; still requires independent current-head approval | -| #1300 | fail closed on unsafe global tool mutations | correct safety posture until durable tenant-scoped plugin/tool registry exists; links directly to #976 | -| #1264 | EgressWeave integration | correctly dependency-blocked on an immutable released EgressWeave package and hash lock; mutable VCS dependency is forbidden | -| #1390 / #1391 | 56- and 78-package dependency groups | excessive blast radius, including major runtime and OpenAI client changes; split by compatibility/authority and rehearse migrations before merge | -| #1426 / #1414 | review-governance gate refresh | metadata-only governance repair; must not dismiss review, weaken rulesets, or turn stale aggregate state into false success | -| #1241, #1320, #1408, #1410, #1411, #1421, #1422 | accessibility micro-lanes | useful but numerous; consolidate non-overlapping UI fixes into bounded component-level trains to reduce 17-check amplification | -| #1424, #1412, #1401 | micro performance lanes | require real benchmark or stable complexity contract; do not let automated micro-PRs displace GA integration work | -| #1455 | path-traversal attachment parser hardening | high-value Sentinel security lane; prioritize within the new wave and merge only with exact-head Strix evidence once the provider outage clears | -| #1347 | rate-limited review status governance | current head constrains repository API-scope identifiers and merges the protected base; local tests pass, while hosted Checks and independent review are still required | -| #1433 | Message-ID whitespace hardening | source/security checks pass; the observed Strix failure is provider infrastructure (NVIDIA NIM 429 and direct OpenAI 404), so retry exact-head evidence without weakening the gate | -| #1450 | stray scratch/debug cleanup | all source and security Checks passed; wait for the in-progress metadata gate and current-head independent review | -| #1465 | scoped tenant archive import hardening | portability slice now rejects duplicate identities before writes and sanitizes archive-controlled display fields; retain the bounded slice-1 query cost and require current-head hosted evidence | -| #1466 | origin-integrity URL validation | current head rejects explicit zero/out-of-range ports; keep the signed-session and SSRF contract tied to exact-head regression evidence | -| #1467 | utility-tool JSON and governance repair | deterministic URL/HTML/JSON utility surface; current head rejects non-standard JSON numbers and preserves the central Strix workflow trigger, while full smoke evidence still depends on #1468's schema fixture repair | -| #1468 | PostgreSQL smoke fixture schema alignment | small root-cause test/data-contract repair for the current `email_records.is_read` requirement; merge before dependent smoke-test PRs after exact-head hosted evidence; the observed Naruon Strix run failed at the provider boundary (NVIDIA NIM 429/OpenAI 404), not in this source change | -| #1443 | CodeRabbit approval-notice governance root | current source/test lane narrows approval-notice parsing to the exact current head and ignores pending-review prose while retaining explicit findings; the predecessor Strix provider failure is historical, while the current head requires fresh queued Checks and a qualifying independent approval | -| #1448 | stacked governance regression coverage | merged normally into #1443's stack branch at `62a0d645…`; parent gate logic plus multiline JSON, stale-head unrelated prose, mixed blocker, and explicit current-head finding fixtures passed locally; merge-result hosted Checks remain queued and are post-merge canary evidence | -| #1469 | deferred attachment parse-source admission | aligns the hidden 20 MiB parser bound with the authenticated 64 MiB import contract while keeping unsupported binaries metadata-only; current changelog states the supported 20–64 MiB range and the ADR-0006 contract remains required | -| #1470 | NetworkGraph lookup optimization | bounded frontend performance slice; current head `aba77cf5…` preserves first-instance duplicate-ID selection, removes the dead `describeEdge` input, and deletes the tracked pre-refactor `NetworkGraph.tsx.out` copy; local 11-test, TypeScript, zero-warning ESLint, and diff checks passed, while hosted Checks and independent approval remain required | -| #1456 | email-detail UX density | buyer-visible mail surface polish; hold to the responsive/accessibility evidence contract in the UI quality section before protected integration | -| #1462 | utility tool trio (URL codec, hash generator) | bounded deterministic tooling consistent with #1418/#1361; must not be represented as AI judgment or topic evidence | -| #1457–#1461 | refreshed dependency-group bumps | successor waves to the v0.2-flagged groups; the 64- and 86-package backend/CI bumps remain excessive blast radius and still require splitting and migration rehearsal | - -### 6.2 Required complete inventory - -Before a release candidate is cut, create a machine-readable and human-reviewed -inventory for **all** current open PRs with: - -```text -pr_number -head_sha -base_ref_and_sha -draft_state -mergeability -changed_authority_cluster -stack_parent -stack_children -current_review_state -unresolved_threads -required_check_summary -product_lane -disposition -next_action -``` - -Allowed dispositions: - -- direct GA-1 slice; -- ordered stacked child; -- dependency-blocked; -- governance-blocked; -- duplicate/superseded; -- experimental/north-star; -- unsafe or unrelated and to be closed. - -The inventory must be regenerated after every parent merge or branch movement. -It must not embed provider credentials, customer data, review-body secrets, or -large copied PR bodies. - -### 6.3 Merge-loop progress since v0.2 - -Point-in-time progress observed between the v0.2 snapshot (2026-08-21) and -this v0.3 observation (2026-08-25). None of this is merge evidence; every -claim requires a live exact-head re-fetch before any decision: - -- **Merge-gate progression:** #1337 completed its gate progression (CodeRabbit exact-head approval obtained, branch updated onto the base) and merged into protected `develop` at `2026-08-25T00:10:39Z`; #1438 obtained CodeRabbit exact-head approval and branch updates and remains open pending terminal required-check states. -- **Stale-snapshot repair:** #1241, #1368, #1412, and #1320 received systemic develop-baseline restores that preserved each PR's intended delta while removing predecessor-base drift from the diff surface. -- **Thread remediation waves:** unresolved review threads progressed through repeated remediation cycles on #1264, #1332, #1347, #1349, #1361, #1380, #1339, #1376, #1412, #1452, #1454, #1449, #1457, #1436, and #1441. -- **External blocker:** Naruon hosted Strix runs have observed NVIDIA NIM provider rate-limit failures (HTTP 429) since approximately 2026-08-24, emitting zero model-reported vulnerabilities before infrastructure failure. This is an observation of the affected hosted runs, not a change to the central GitHub Models default in `AGENTS.md`; per repository policy it is failed evidence, not clean-scan evidence, and Strix-dependent gates cannot pass until the provider path recovers. - -### 6.4 UI/UX quality contract and Storybook event inventory - -The UI is a buyer-facing control surface, not a decorative shell. The current -design-system implementation is carried by PR #1436 and ADR-0013; it uses the -production stylesheet as the Storybook token source and records Figma file ID -`68b5XB58w8nwT2LYOOnikK`. Until that PR is protected-branch code, its stories -are current-PR evidence rather than shipped capability. - -The UI/UX Pro Max checklist and Anti-Slop UI heuristics are adopted as review -inputs, not as normative standards or automatic approval. They help select one -coherent design direction, expose generic UI defaults, and force explicit -review of accessibility, touch targets, hierarchy, and state behavior. WCAG -2.2 and the repository's security/accessibility gates remain authoritative. - -The latest local fixed-origin capture for #1470 used `/` at desktop (1440×900), -tablet (834×1112), and mobile (390×844). Tablet and mobile presented the -responsive shell and an explicit mail-loading state. Desktop presented the -navigation shell but no data surface while the backend was intentionally not -running; the Next development server also reported a hydration mismatch for -the search-input caret style. This is local diagnostic evidence, not hosted -release evidence, and is tracked as a separate UX/runtime gap rather than -mixed into the bounded NetworkGraph change. - -| Quality axis | Required definition and applied evidence | Audit gate before GA-1 | +**Canonical completion issue:** [#1428](https://github.com/ContextualWisdomLab/naruon/issues/1428) +**Canonical Gap-ledger writer:** [#1602](https://github.com/ContextualWisdomLab/naruon/pull/1602) + +v2.99 remains audit-visible as blob `5d1d0e1f0768c1d35bd499b7b059c59ba4fa873c`; v2.98 as `74e6cf3bfbf048a7b16dc92882b1b4f8b7acea0d`; v2.97 as `13d4d7c2c871d17e9dcbf85d58ecbd180b9be5db`; v2.96 as `2286b315a7d7152254aebc466f327da300561755`; v2.95 as `8bd1c3d8a057b4b8eea4f94880e4c3e0302bb632`; v2.94 as `e4643a58abf613bba9a2bec90964ad7d9b908ae8`; v2.93 as `c72cc29a647ffca6ffcd891755a9abc6c2a17553`; v2.92 as `40b6875cc84f58cf340df4215af2b62e6db19944`; v2.91 as `9fe2b4930c27cdb089e32105840ce194e2fa5e7c`; v2.88 as `1c708286ddcd3c8ab543043aac428889b4f53c4f`. Attempted v2.89, v2.90 and the first v2.91 workflow currentizers remain transition-failure provenance only. The durable ledger is maintained by ordinary commits on the sole Gap-writer branch; self-modifying currentizers are not accepted as completion evidence. + +## 1. Evidence hierarchy and commercial release posture + +Evidence authority is exact protected code/migrations/tests/runtime contracts → protected architecture/operations docs → exact current Naruon owner PR source and current-head evidence → live Naruon Issue/Proposed ADR authority → historical snapshots. Pending, queued, cancelled, stale, predecessor-head, source-neutral, author-only, local-only or model-only evidence is not passing evidence. + +Protected `develop` remains `042b0c70531b229af3acbd0421a2f23098d848b3`, tree `8fde14381aaa430eeaaf61151dab6f6800127cd3`, with 17 required status contexts. Commercial acceptance requires one exact integrated protected head with all required contexts terminal GREEN, current security evidence, zero valid unresolved review findings, qualifying independent post-last-push review, real buyer-visible runtime acceptance, immutable publication identity, SBOM/provenance, reproducibility and rollback evidence. + +Naruon latest GitHub Release is `v0.14.4` and is not immutable. Therefore it is not current commercial release authority. + +**Merge/Release Gate: FAIL. UI Delivery Gate: FAIL. Localization Delivery: FAIL.** + +## 2. External canonical-owner boundary + +Naruon owns its domain truth, UI behavior, product contracts and migration lineage. Other ContextualWisdomLab repositories are consumed only through released/versioned contracts or explicit owner paths. Naruon does not source-copy their implementations, query their databases directly or treat mutable external heads as consumer contracts. + +Relevant optional foundations include `.github` for reusable CI/review/security/release contracts; contextual-orchestrator for LLM capability routing; Keyverse for identity; EgressWeave for outbound policy; OriginWeave for browser capability; quarantine-sandbox-runtime for hostile-workload isolation; appguardrail for SAST/SARIF; Wardnet for gateway/SOC; and the other canonical CWL owners defined by repository policy. + +Contextual-orchestrator protected `main` is currently `5665b0ad1e07ffb5e9f8c59e44b6b2a785298013`. It is an owner head, not a released Naruon contract. Its GitHub Release inventory remains exactly empty, so Naruon stays fail-closed rather than consuming mutable CO source. + +### 2.1 LLM governance source drift and released-owner handoff + +Protected Naruon governance is still inconsistent with the current CWL LLM boundary. Protected `AGENTS.md` describes central Strix in provider/model-specific terms, including direct GitHub Models selection, named fallback models, manual Vertex modes and direct OpenAI modes. Protected `ARCHITECTURE.md` contains direct OpenAI-compatible provider/fallback language that can be read as product authority outside a released contextual-orchestrator contract. Those statements are live source defects; this ledger does not supersede them. + +[#1549](https://github.com/ContextualWisdomLab/naruon/pull/1549) exact `9e47f25e256f52f13df267e0383bc3b036ac6f9e` remains the sole Naruon LLM-governance repair owner. Its effective six-file delta is `AGENTS.md`, `ARCHITECTURE.md`, `CLAUDE.md`, `backend/tests/test_agent_llm_authority_docs.py`, `backend/tests/test_release_governance.py`, and `opencode.jsonc`. The repaired contract requires model-backed Actions to request only logical `orchestrator/free` through the gateway credential, leaves provider/model/group discovery and fallback to contextual-orchestrator, forbids mutable owner source as a consumer contract, and distinguishes user cancellation/provider termination/explicit administrative limits from elapsed-time truncation. + +#1549 is source-current for the intended repair but not delivery authority. It is stacked, has no qualifying exact-head repository admission or post-last-push approval, and contextual-orchestrator has no immutable GitHub Release carrying the required API/client/schema/provenance. Required order is immutable CO publication → legitimate stacked-PR admission through #1691 or accepted successor → #1549 exact-head checks/review → normal protected integration. Naruon must not copy `.github` or contextual-orchestrator source, pin a provider/model, or bind to CO `main` while waiting. + +### 2.2 Shared telemetry runtime owner and consumer release boundary + +A new Naruon draft, [#1772](https://github.com/ContextualWisdomLab/naruon/pull/1772) exact `9a6bf11dc595171657dba2cee40366c1d29498a4`, migrates product tracing toward the shared `ContextualWisdomLab/cwl-telemetry` Port. Its product-side intent is bounded and security-positive: product-owned OTLP exporter/provider construction is removed, request spans use fixed names and declared route templates, and raw URL/query/exception data is not intentionally exported. + +The current dependency boundary is **not acceptable for integration**. #1772 pins `cwl-telemetry` directly from mutable Git source at owner commit `df1a27106111834f804ced8242ac7eff1d892843` in `backend/pyproject.toml` and `backend/uv.lock`. Canonical owner PR `ContextualWisdomLab/cwl-telemetry#1` is open at that exact head and its GitHub Release inventory is exactly `[]`; it explicitly states that hosted checks, independent current-head review, a released hash-pinned wheel/checksum, production credential bootstrap and deployment evidence are absent. A mutable source commit is provenance evidence, not a consumer contract. + +Required order is canonical owner exact-head GREEN + independent review → immutable cwl-telemetry release/package/checksum/SBOM/provenance → Naruon replaces the VCS dependency with the released versioned contract and records the checksum/version → Naruon reacquires exact-head API/schema/security/runtime evidence → normal protected integration. Until then #1772 remains Draft/RED at the external-owner boundary. Naruon must not vendor or copy cwl-telemetry source to bypass publication. + +## 3. Product source-owner graph + +### 3.1 Backend dependency/security owner + +[#1565](https://github.com/ContextualWisdomLab/naruon/pull/1565) remains the canonical Starlette TestClient/httpx2 and coherent backend-lock owner. Resolver exact `d166c9208b275ab88895e7711d999c4729a81025` produced the coherent five-file `httpx2/httpcore2==2.13.0` candidate. Artifact `10748790356` was re-downloaded again on 2026-09-24 and its SHA-256 values still match the accepted bytes: + +- `backend/requirements.txt`: `87f603d06eb05fa234163003a2feda98f024b80751cc9eb919aedb261136482f` +- `backend/pyproject.toml`: `faab5edd236153c28a321e431dc1a6d5f99bcaa64f26f21c60222a1db2057365` +- `backend/requirements-hashes.txt`: `551f6aa4a6a8f1efb7f6259dc63777c40c09b2f520dea217575b94b12178f7d5` +- `backend/requirements-agent.txt`: `761ceb9f7042ffa9538c5a596ad113a3ee59f27381c4a44d34df82338e5b913a` +- `backend/uv.lock`: `fa28138f637a2c2baddd528893cfb04be2d9064afcadd538fb7fa5000be7f82b` + +That candidate resolves AnyIO `4.14.2`. Effective protected/product source still carries the vulnerable predecessor state. #1767 Security run `35925494018` is terminal FAILURE in `trivy-fs` with inherited AnyIO findings `CVE-2026-63374`, `CVE-2026-63349`, and `CVE-2026-64847`; this is backend dependency Security RED, not a NetworkGraph defect. + +The transition has now separated the helper defects from the candidate bytes. Run `35957638723` failed while the old helper attempted workflow-file self-mutation; `4e5f8609f627c7d1bd24bf148fa11682ae67e503` replaced it with a product-only adopter. Run `35977315662` then exposed the extras-blind hash-lock parser defect, repaired at `2a87cb99205d29c04db188d4ddc0a44795bb1553` without changing dependency bytes or gate policy. + +Product adopter run `36001401538` is now terminal **SUCCESS**. It verified the frozen artifact, `uv lock --check`, combined core+agent `--require-hashes` installation and the focused dependency contract, then created product commit `42e7bc510027ee99bd9b0871835bf8b55a921055`. That commit adopts `httpx2==2.13.0` / `httpcore2==2.13.0`, keeps the core and Noema-agent hash sets coherent and records the corresponding generated lock graph. + +The transition is still not helper-free: `.github/workflows/temporary-httpx2-product-adopter.yml` remains in the current PR delta at `42e7bc51...`. Fresh normal workflows on that exact head are terminal `action_required`, not acceptance evidence. Required next step is an ordinary non-force helper removal, followed by focused dependency tests and fresh Application CI/Security/CodeQL/Bandit/Semgrep/Docker on the resulting unchanged product tree. Product adoption is source PASS; helper-free Delivery and repository-wide Security remain FAIL/PENDING, and predecessor receipts do not transfer. + +### 3.2 Frontend dependency/security owner + +[#1623](https://github.com/ContextualWisdomLab/naruon/pull/1623) exact `509be4c1d9b6c7ba239a108656e2382681a85341` remains the canonical frontend dependency-security owner. It carries the reviewed frontend dependency floor (`next`/`eslint-config-next` `16.3.4`, resolved `sharp` `0.35.4`) and has a bounded current-database frontend PASS. + +The same #1767 Security run `35925494018` reported inherited Next.js findings `CVE-2026-75604`, `GHSA-2xp9-vwfh-vxw4` and Sharp `GHSA-rgj7-g3m4-5g8c` on the protected dependency state. Intervening #1767 commit `f111866d1f28e1dc52fc770834af08048003032a` attempted to repair dependency manifests/locks directly in the NetworkGraph lane. Ordinary-forward `157894a526165005e686f81c1f7b7a14c39f1973` restored the owner-neutral blobs. A second intervening commit, `9e9116cb0b888a6f50caf5f049d09745fea63d47` (`chore: update vulnerable dependencies detected by trivy-fs`), again modified only `backend/uv.lock`, `frontend/package.json` and `frontend/pnpm-lock.yaml` inside the NetworkGraph lane, including AnyIO 4.15.1 and Next/eslint-config-next 16.3.6. That repeated cross-owner repair was not accepted. Ordinary-forward `7651810c142159ef8c3c5226098bf3801125282c` preserves both intervening commits while restoring the three dependency files to the prior owner-neutral blobs; `157894a...→7651810...` is ahead 2 / behind 0 with zero effective files and the tree is again `e41e825b0675d7d80c56e9756031c8994570cdb0`. + +#1623 ordinary-adopts accepted backend ancestry only after #1565 settles and must reacquire repository-wide dependency/security evidence on that resulting exact head. [#1752](https://github.com/ContextualWisdomLab/naruon/pull/1752) remains the Dependabot grouping/manifest-scan policy owner and must not absorb dependency repair. + +### 3.2.1 SMTP connector recipient mailbox boundary + +Protected API send requests already use Pydantic `EmailStr`, but protected `backend/runner/local_mail_adapters.py` accepts any non-empty SMTP `to` string. The downstream `EmailMessage` parser can reinterpret malformed address text instead of rejecting it; `user@example.com> AUTH=