Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
82 commits
Select commit Hold shift + click to select a range
b8791fc
test(docs): reject stale #528 candidate authority
seonghobae Sep 3, 2026
2093133
docs(context-map): mark #528 runtime foundation protected
seonghobae Sep 3, 2026
3446b0b
docs(adr): separate protected runtime truth from ADR lifecycle
seonghobae Sep 3, 2026
697dbd5
docs(adr): correct protected workflow source path
seonghobae Sep 3, 2026
b8d94b3
docs(prd): mark #528 runtime foundation protected
seonghobae Sep 3, 2026
0e26b3c
test(docs): reject stale product-gap authority
seonghobae Sep 3, 2026
a4cccf0
docs(gap): reconcile protected and active Noema authority
seonghobae Sep 3, 2026
32449cf
test(docs): reject stale pre-merge licensing authority
seonghobae Sep 3, 2026
343e5b1
docs(licensing): mark Apache source grant protected
seonghobae Sep 3, 2026
68c6114
fix(test): match canonical PRD owner formatting
seonghobae Sep 4, 2026
69bfec7
test(docs): require protected #537 integration in gap baseline
seonghobae Sep 4, 2026
49d3a1c
docs: advance commercial gap baseline to protected #537
seonghobae Sep 4, 2026
8d2151b
Merge remote-tracking branch 'origin/main' into runtime-doc-authority…
seonghobae Sep 4, 2026
e9b1969
docs(gaps): refresh reviewer provenance and active evidence
seonghobae Sep 5, 2026
799ba1d
docs: refresh commercial gap authority after CodeGraph path repair
seonghobae Sep 5, 2026
4a7dd10
docs: track current protected central trust authority
seonghobae Sep 5, 2026
19ee7d7
docs: refresh Noema commercial gap authority
seonghobae Sep 5, 2026
b4b0afa
docs: roll forward live Noema authority again
seonghobae Sep 5, 2026
75b1c9f
docs: bind latest central trust authority
seonghobae Sep 5, 2026
fcd6f2d
docs: reconcile CodeGraph retry and stacked exact heads
seonghobae Sep 5, 2026
3c0c075
docs: reconcile current reviewer and central trust authority
seonghobae Sep 5, 2026
63ea5c0
fix(docs): restore buyer-impact gap contract
seonghobae Sep 5, 2026
faed0a8
docs(gap): record reviewer context liveness repair
seonghobae Sep 5, 2026
33aa1c7
docs: record fail-before-execution reviewer authority
seonghobae Sep 5, 2026
201e9c7
docs: reconcile reviewer and central trust authority
seonghobae Sep 5, 2026
91c9891
docs: advance current central trust observation
seonghobae Sep 5, 2026
d4dd1f9
docs: reconcile JSON-safe reviewer recovery authority
seonghobae Sep 5, 2026
ee0b035
docs: refresh commercial gap baseline to current reviewer stack
seonghobae Sep 5, 2026
af5fae8
docs: refresh commercial gap authority after path-identity repair
seonghobae Sep 5, 2026
8c118cc
docs: reconcile workflow transport and central trust authority
seonghobae Sep 5, 2026
77f621e
docs: record hosted reviewer RED and exact repair stack
seonghobae Sep 5, 2026
5c8c08a
docs: record commercial-loop hosted RED repair
seonghobae Sep 5, 2026
124bc77
docs(gap): record workflow command snapshot repair
seonghobae Sep 5, 2026
da8a16a
docs: reconcile current reviewer and workflow authority
seonghobae Sep 5, 2026
1c0fc0a
docs: reconcile current commercial-loop RED evidence
seonghobae Sep 5, 2026
45e6450
docs: reconcile durable coverage and central trust authority
seonghobae Sep 5, 2026
cd3c9be
docs: reconcile governance and central trust authority
seonghobae Sep 5, 2026
4507696
docs: reconcile live reviewer and trust evidence
seonghobae Sep 5, 2026
e6d6305
merge: restack #547 on protected reviewer truth
seonghobae Sep 6, 2026
ebb9944
docs: promote merged semantic reviewer truth
seonghobae Sep 6, 2026
f1ca199
test: bind baseline to merged reviewer main
seonghobae Sep 6, 2026
e001564
docs: reconcile post-reviewer semantic restacks
seonghobae Sep 6, 2026
bc2853c
docs(adr): reconcile protected context admission authority
seonghobae Sep 6, 2026
3e66643
docs(gap): reconcile protected Context Fabric authority
seonghobae Sep 6, 2026
f5804e6
merge(context-fabric): reconcile docs with protected admission truth
seonghobae Sep 6, 2026
d655663
test(docs): bind active-work contract to protected Context Fabric head
seonghobae Sep 6, 2026
fe0a66e
docs: refresh central trust and reviewer line authority
seonghobae Sep 6, 2026
2006f41
docs: record hosted CodeGraph isolation repair
seonghobae Sep 6, 2026
2d9521f
docs(gap): record restored release traceability
seonghobae Sep 6, 2026
797c6da
docs: refresh live commercial gap authority after protected #552
seonghobae Sep 6, 2026
1766380
docs: preserve current rights evidence while refreshing toolchain gap
seonghobae Sep 6, 2026
6553f6b
merge: reconcile documentation authority onto protected #552 truth
seonghobae Sep 6, 2026
a87e2f1
docs: refresh commercial gap exact-head authority
seonghobae Sep 6, 2026
fbd2d7b
test(docs): bind active-work contract to current protected heads
seonghobae Sep 6, 2026
b20f203
docs: restack current authority after OIDC trust merge
seonghobae Sep 6, 2026
f82fd75
docs: record post-527 exact candidate heads
seonghobae Sep 6, 2026
3ebbf94
docs: align active owner literals with contracts
seonghobae Sep 6, 2026
e203bb8
test(docs): require current central trust authority
seonghobae Sep 6, 2026
8b27bac
docs: record current central workflow trust prerequisite
seonghobae Sep 6, 2026
e2e4042
docs: restore canonical buyer-gap table contract
seonghobae Sep 6, 2026
7a2fa97
test(docs): require current live authority identities
seonghobae Sep 6, 2026
788ab94
docs(authority): follow current central and runtime candidates
seonghobae Sep 6, 2026
a2d8b26
test(docs): require current central trust authority
seonghobae Sep 6, 2026
84876b4
docs: advance central trust authority baseline
seonghobae Sep 6, 2026
42a0f6d
test(docs): require repaired workflow state head
seonghobae Sep 6, 2026
bf9a0e2
docs: record workflow legacy-provenance repair
seonghobae Sep 6, 2026
4aa7302
test(docs): require latest central trust authority
seonghobae Sep 6, 2026
bee3911
docs: follow latest central trust source
seonghobae Sep 6, 2026
0ae16b6
test(docs): require current protected and candidate authority
seonghobae Sep 6, 2026
beece2d
docs: reconcile protected and active commercial authority
seonghobae Sep 6, 2026
cb240c1
docs: restack commercial authority onto protected main
seonghobae Sep 6, 2026
48bf2a9
test(docs): require current workflow trust authority
seonghobae Sep 6, 2026
9cb3e18
docs: align commercial gap baseline with current trust source
seonghobae Sep 6, 2026
129affe
test(docs): require latest protected trust source
seonghobae Sep 6, 2026
a27050f
test(docs): require current central trust authority
seonghobae Sep 6, 2026
8010d08
docs: bind gap baseline to current trust authority
seonghobae Sep 6, 2026
232b602
test(docs): require post-trust-integration authority
seonghobae Sep 6, 2026
ba54ec0
docs: bind gap baseline after trust integration
seonghobae Sep 6, 2026
7b17b4e
merge(main): restack documentation authority after trust integration
seonghobae Sep 6, 2026
6a7b2a3
docs: record post-trust branch convergence
seonghobae Sep 6, 2026
2d2d86d
test(docs): bind post-trust authority to current candidates
seonghobae Sep 6, 2026
24167c3
docs: reconcile current workflow and toolchain candidates
seonghobae Sep 6, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 6 additions & 4 deletions docs/CONTEXT_MAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@

This document separates protected behavior from the runtime-orchestration direction. Protected `main` remains the authority for what is shipped. A bounded context listed as a target does not become implemented merely because it appears here.

Noema currently owns an evidence-producing credential and maintenance control plane. Expansion into agent/application runtime orchestration must reuse those existing authority boundaries rather than turning Noema into a model router, a foreign product system of record, or an arbitrary command runner.
Noema owns an evidence-producing credential and maintenance control plane plus a narrow protected runtime-orchestration foundation. Expansion into broader agent/application runtime orchestration must reuse those existing authority boundaries rather than turning Noema into a model router, a foreign product system of record, or an arbitrary command runner.

## Current protected contexts

Expand Down Expand Up @@ -34,17 +34,19 @@ Owns bounded retry/timeout/cancellation semantics, fail-closed recovery evidence

## Runtime-orchestration target contexts

The following contexts are accepted decomposition targets for new runtime behavior. They are not claims that protected `main` already implements a general-purpose agent runtime.
The following contexts are the accepted decomposition for runtime behavior. Protected `main` already implements narrow foundations in Agent Runtime, Workflow / Task Execution, and State / Checkpoint; the remaining behavior in each context is added only by separately verified slices. These boundaries do not claim that Noema is already a general-purpose agent runtime.

### Agent Runtime

Owns the lifecycle of one Noema agent/application execution: accepted execution identity, lifecycle state, cancellation, completion, and recovery routing. It does not discover or route models.

Protected `main` includes the execution-lifecycle primitive introduced by #528: explicit accepted, running, cancellation-requested, and terminal transitions; exact duplicate delivery of the signal that established the current state is idempotent; contradictory or out-of-order signals fail closed; cancellation dominates late completion; retry/recovery uses a separate execution identity rather than inheriting implicit side-effect authority.

### Workflow / Task Execution

Owns explicit workflow/task dependency and execution order, bounded concurrency, idempotent step identity, and side-effect classification. Recursive/unbounded task creation and implicit duplicate side effects are forbidden.

PR #528 now carries a candidate bounded task-plan admission and runnable-task selector. It accepts one canonical execution identity, a finite acyclic dependency graph, explicit `pure`/`idempotent`/`side_effecting` classification, and bounded concurrency. Declared task order is deterministic scheduling priority. Runtime state must account for every admitted task exactly once; foreign, malformed, duplicate, or incomplete state evidence fails closed. Failed or cancelled work is never selected as an implicit retry, and failed dependencies do not release descendants. Authority-bearing plan fields and nested dependencies are detached and frozen after one-time reads so caller accessors or aliases cannot change an admitted execution plan. This remains candidate behavior until protected integration.
Protected `main` includes bounded task-plan admission and runnable-task selection. It accepts one canonical execution identity, a finite acyclic dependency graph, explicit `pure`/`idempotent`/`side_effecting` classification, and bounded concurrency. Declared task order is deterministic scheduling priority. Runtime state must account for every admitted task exactly once; foreign, malformed, duplicate, or incomplete state evidence fails closed. Failed or cancelled work is never selected as an implicit retry, and failed dependencies do not release descendants. Authority-bearing plan fields and nested dependencies are detached and frozen after one-time reads so caller accessors or aliases cannot change an admitted execution plan. This protected foundation selects candidates only; it does not itself reserve work or grant side-effect authority.

### Tool / Capability Boundary

Expand All @@ -54,7 +56,7 @@ Owns versioned allowlisted tool/capability descriptors, least-authority invocati

Owns versioned runtime checkpoint semantics needed for restart/cancellation/idempotency. Checkpoints contain only Noema runtime state and canonical foreign references; they must not copy another product's domain truth, provider credential state, or unrestricted reasoning/tool payloads.

PR #528 currently carries candidate checkpoint admission for one retained execution identity. Sequence zero initializes the checkpoint stream; an exact same-sequence/same-digest replay is idempotent; conflicting replay, stale or gapped sequence, cross-execution identity, non-canonical execution identity, and non-SHA-256 state evidence fail closed. This remains candidate behavior until protected integration and does not itself persist checkpoint payloads or grant retry/side-effect authority.
Protected `main` includes checkpoint admission for one retained execution identity. Sequence zero initializes the checkpoint stream; an exact same-sequence/same-digest replay is idempotent; conflicting replay, stale or gapped sequence, cross-execution identity, non-canonical execution identity, and non-SHA-256 state evidence fail closed. Returned checkpoint metadata is detached and frozen so caller-owned aliases cannot mutate admitted authority after validation. This primitive does not itself persist checkpoint payloads or grant retry/side-effect authority.

## Upstream and downstream boundaries

Expand Down
24 changes: 13 additions & 11 deletions docs/LICENSING_AND_IP_TRANSFER.md
Original file line number Diff line number Diff line change
@@ -1,12 +1,12 @@
# Noema Licensing and IP Transfer

- **Status:** Repository rights policy/evidence baseline; Apache-2.0 source-license decision is integrated on protected `main@6b2b3e90dc3d5bd24cd27ed11db41b9eb7106010` through PR #530. This is not acquisition or transfer legal clearance.
- **Status:** Repository rights policy/evidence baseline. Protected `main` carries the owner-selected Apache-2.0 source grant; this is not acquisition or transfer legal clearance.
- **Scope:** Noema source rights, package/container metadata, third-party obligations, contributor/IP provenance, release distribution, and acquisition transfer evidence.
- **Decision authority:** Repository automation may detect, authenticate, inventory, and compare evidence. The repository owner has explicitly selected Apache License 2.0 for Noema source; future outbound-license changes and transfer-rights decisions remain owner/legal governance actions.

## 1. Core invariant

**Public source availability is not a grant of rights by itself.** The grant comes from the controlling repository rights file. Protected `main@6b2b3e90dc3d5bd24cd27ed11db41b9eb7106010` includes root `LICENSE` declaring Apache-2.0 for Noema source through merged PR #530.
**Public source availability is not a grant of rights by itself.** The grant comes from the controlling repository rights file. Protected `main` contains root `LICENSE` with Apache License 2.0 for Noema source, integrated through #530. That protected source-rights decision does not itself establish package/artifact distribution rights, third-party compatibility, contributor ownership, or acquisition-transfer authority.

Noema keeps source licensing, package publication, third-party obligations, and transfer authority separate:

Expand Down Expand Up @@ -96,9 +96,11 @@ Required evidence includes:

### 4.1 Current GPL-family tooling finding

The current `package-lock.json` contains optional development/build packages on the `wrangler → miniflare → sharp → @img/sharp-libvips-*` path whose declared license is `LGPL-3.0-or-later`; `@img/sharp-wasm32` declares `Apache-2.0 AND LGPL-3.0-or-later AND MIT`. These packages are not relicensed by Noema's Apache-2.0 source license.
The protected `package-lock.json` contains optional development/build packages on the `wrangler → miniflare → sharp → @img/sharp-libvips-*` path whose declared license is `LGPL-3.0-or-later`; `@img/sharp-wasm32` declares `Apache-2.0 AND LGPL-3.0-or-later AND MIT`. These packages are not relicensed by Noema's Apache-2.0 source license.

Repository evidence also shows that the patch-validator runtime-image boundary explicitly excludes `wrangler`, `workerd`, and `miniflare`; therefore this finding must not be overstated as proof that LGPL code is bundled into that runtime image. It is nevertheless an inbound development/build-tooling policy gap because ContextualWisdomLab does not accept GPL-family software as the normal dependency baseline. Distribution/acquisition readiness must remain fail closed until issue #531 removes/replaces this dependency path or an explicit repository-level exception is approved for the exact use and distribution model.
Repository evidence also shows that the patch-validator runtime-image boundary explicitly excludes `wrangler`, `workerd`, and `miniflare`; therefore this finding must not be overstated as proof that LGPL code is bundled into that runtime image. It is nevertheless an inbound development/build-tooling policy gap because ContextualWisdomLab does not accept GPL-family software as the normal dependency baseline.

The active owner lane is issue #531 / PR #540. PR #540 replaces the intended Wrangler/Miniflare/Sharp/Libvips toolchain with direct `workerd`/`esbuild` and a bounded Cloudflare API adapter, but its exact-base lockfile policy must be rebound after protected-main movement and its unchanged current head must pass package, Worker dev/deploy, security, reviewer, image, SBOM, vulnerability, provenance, and license-inventory gates before integration. Distribution/acquisition readiness therefore remains fail closed until that protected evidence exists.

Unknown or unresolved obligations fail closed for distribution/acquisition readiness. Vulnerability or provenance success does not prove license compatibility.

Expand Down Expand Up @@ -158,25 +160,25 @@ owner source-license decision

Each arrow requires independent identity/consistency evidence. A mismatch, missing required record, malformed/ambiguous JSON, or unresolved right is a fail-closed condition.

## 8. Current evidence and residual gap — 2026-09-02
## 8. Current evidence and residual gap — 2026-09-06

As observed after PR #530 merged, protected `main@6b2b3e90dc3d5bd24cd27ed11db41b9eb7106010` carries the explicit owner-selected Apache-2.0 source posture:
Protected `main@5b8e620dbb01a794c1a38535bbcc32e41a80d0df` contains the owner-selected source-rights posture integrated through #530:

- root `LICENSE`: Apache License 2.0;
- root `README.md`: customer-facing Apache-2.0 source-license statement and separate third-party obligation boundary;
- `package.json`: remains private and lock-stable; no npm package distribution claim is introduced.
- `package.json`: remains private; no npm package distribution claim is introduced.

These declarations are protected-main source truth. They do not by themselves establish acquisition-transfer authority, third-party compatibility, or release/publication evidence.
That source grant is protected truth. It does not transfer later evidence classes into PASS.

Current residual gaps remain deliberately separate:

- the lockfile contains the GPL-family development/build tooling path described in §4.1 and therefore does not yet satisfy the organization default inbound-license policy;
- issue #531 / PR #540 owns removal of the GPL-family development/build tooling path; candidate source replacement exists, but current-base lock policy and unchanged exact-head verification are not complete;
- exact-release dependency/NOTICE evidence must still prove the actual distributed artifact contents;
- contributor ownership/assignment and acquisition-transfer evidence remain separate from source licensing;
- release/publication/deployment evidence remains separate from repository-source rights;
- no source file, README sentence, scanner result, or successful CI run may upgrade those missing evidence classes into a commercial or legal PASS.
- no source file, README sentence, scanner result, workflow success, SBOM, or model judgement may upgrade those missing evidence classes into a commercial or legal PASS.

Issue #5 carries acquisition owner/legal and ownership/assignment evidence. Issue #66 carries remaining release/publication, NOTICE and provenance/activation boundaries. Issue #531 owns the GPL-family development/build-tool replacement. The integrated source-license decision narrows the gap but does not close those issues.
Issue #5 carries acquisition owner/legal and ownership/assignment evidence. Issue #66 carries remaining release/publication, NOTICE and provenance/activation boundaries. Issue #531 owns the GPL-family development/build-tool replacement. The protected source-license decision closes only the source-grant gap; it does not close those later evidence families.

## 9. Non-goals

Expand Down
10 changes: 6 additions & 4 deletions docs/PRD.md
Original file line number Diff line number Diff line change
Expand Up @@ -88,13 +88,15 @@ Protected acquisition-integrity controls authenticate retained evidence and exac

### 4.7 Agent/application runtime orchestration

On PR #528 this mode is **candidate truth only** until protected integration. Noema owns the lifecycle and safe execution mechanics of a Noema Agent/application execution; it does not acquire another CWL product's domain truth and does not become a model-provider router.
Protected `main` includes the Agent Runtime lifecycle and State / Checkpoint admission foundation introduced by #528, together with bounded Workflow / Task plan admission and runnable-task candidate selection. Noema owns the lifecycle and safe execution mechanics of a Noema Agent/application execution; it does not acquire another CWL product's domain truth and does not become a model-provider router.

The candidate Agent Runtime primitive owns explicit accepted, running, cancellation-requested, and terminal transitions. Exact duplicate delivery of the signal that already established the current state is idempotent, while contradictory or out-of-order signals fail closed. Cancellation dominates late completion. Retry/recovery uses a separate execution identity rather than receiving implicit duplicate-side-effect authority.
The protected Agent Runtime primitive owns explicit accepted, running, cancellation-requested, and terminal transitions. Exact duplicate delivery of the signal that already established the current state is idempotent, while contradictory or out-of-order signals fail closed. Cancellation dominates late completion. Retry/recovery uses a separate execution identity rather than receiving implicit duplicate-side-effect authority.

The candidate State / Checkpoint primitive admits sequence zero as initialization, an exact same-sequence/same-digest replay as idempotent, and only the immediately next sequence for the same canonical execution identity. Conflicting replay, stale/gapped sequence, cross-execution identity, malformed identity, or non-SHA-256 state evidence is rejected. Returned checkpoint metadata is a detached frozen snapshot so caller-owned aliases cannot mutate admitted authority after validation. This primitive does not persist checkpoint payloads by itself.
The protected State / Checkpoint primitive admits sequence zero as initialization, an exact same-sequence/same-digest replay as idempotent, and only the immediately next sequence for the same canonical execution identity. Conflicting replay, stale/gapped sequence, cross-execution identity, malformed identity, or non-SHA-256 state evidence is rejected. Returned checkpoint metadata is a detached frozen snapshot so caller-owned aliases cannot mutate admitted authority after validation. This primitive does not persist checkpoint payloads by itself.

`contextual-orchestrator remains the sole model discovery and routing owner`; Noema does not add direct provider SDKs, provider credentials, provider fallback lists, or local routing policy. Workflow / Task Execution, Tool / Capability Boundary, Isolation Integration, Policy / Approval, Observability, and Recovery remain separate bounded contexts under ADR 0012 and the canonical Context Map. Context Graph/EA integration requires an immutable released `context-graph-contracts` contract/profile and preserves EA Core as the authoritative Decision Plane; cross-service SQL is forbidden.
The protected Workflow / Task foundation admits one canonical execution identity, a finite acyclic dependency graph, explicit `pure`/`idempotent`/`side_effecting` classification, bounded concurrency, and detached immutable authority-bearing plan data. Runnable selection fails closed on foreign, malformed, duplicate, incomplete, cross-execution, over-concurrency, or causally impossible state. Selection is candidate scheduling evidence only; it does not reserve work or grant side-effect authority. Durable workflow-state persistence, atomic claim/checkpoint execution, and richer recovery remain separate slices until independently integrated.

`contextual-orchestrator` remains the sole model discovery and routing owner; Noema does not add direct provider SDKs, provider credentials, provider fallback lists, or local routing policy. Tool / Capability Boundary, Isolation Integration, Policy / Approval, Observability, and Recovery remain separate bounded contexts under ADR 0012 and the canonical Context Map. Context Graph/EA integration requires an immutable released `context-graph-contracts` contract/profile and preserves EA Core as the authoritative Decision Plane; cross-service SQL is forbidden.

## 5. Functional requirements

Expand Down
Loading