From a71762bd389a4767e3667c82b384cf8b7a914197 Mon Sep 17 00:00:00 2001 From: Codex Date: Mon, 7 Sep 2026 18:49:47 +0900 Subject: [PATCH 001/276] fix(a11y): include leftover-pair evidence in button names Pair actions were named only by kind, title, and criterion, so assistive technology could not read the finite leftover badges already shown on the same control. Keep those formatters as the only evidence source. --- docs/product-technical-gap-baseline.md | 8 ++++++ frontend/src/App.test.tsx | 6 +++- .../src/components/LeftoverPairList.test.tsx | 14 ++++++++-- frontend/src/components/LeftoverPairList.tsx | 28 +++++++++++++++---- 4 files changed, 47 insertions(+), 9 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 5db914a52..fdeca0d63 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,5 +1,13 @@ # Product & Technical Gap Baseline +> Leftover-pair accessible-name overlay: 2026-09-07 KST. Issue #976 stacks +> onto leftover-map single-writer `#802` at `32f1cda10` so pair-button +> names include the same finite leftover evidence badges already rendered +> (`R`, `Y/E`, rank, unexplained, shares, reconstruction, coordinates, +> distance). Grouping-comparison pair actions stay on `#829`/`#830` and +> are not expanded here. This branch is Draft; it is not protected-main +> or independently approved evidence. +> > Exact-head rendered-UX overlay: 2026-08-31 12:16 KST. PR #802 > implementation revision `1e972d7f6` retains persisted-only `d`, `R̂`, and > `e` projection while moving dense segment captions off their plot segments diff --git a/frontend/src/App.test.tsx b/frontend/src/App.test.tsx index 790c4da69..07c30ed61 100644 --- a/frontend/src/App.test.tsx +++ b/frontend/src/App.test.tsx @@ -4175,7 +4175,11 @@ describe("App, authenticated", () => { expect(closestPair).toHaveTextContent("R̂ +0.25"); expect(closestPair).toHaveTextContent("ξ (+0.50, +0.10) ζ (+0.50, −0.02)"); expect(closestPair).toHaveTextContent("d 0.12"); - expect(closestPair).toHaveAccessibleName("Open leftover closest pair: Public post · sales-lead"); + expect(closestPair).toHaveAccessibleName(/Open leftover closest pair: Public post · sales-lead/); + expect(closestPair).toHaveAccessibleName(/R \+0\.40/); + expect(closestPair).toHaveAccessibleName(/Y 2\.40 · E 2\.00/); + expect(closestPair).toHaveAccessibleName(/rank 1/); + expect(closestPair).toHaveAccessibleName(/d 0\.12/); expect(farthestPair).toHaveTextContent("Farthest leftover: Specification revision requested · negative"); expect(farthestPair).toHaveTextContent( "Leftover map places this post at ξ (+0.90, +0.80) and the criterion at ζ (−0.70, −0.40) after IRT main effects. Open this post to read negative.", diff --git a/frontend/src/components/LeftoverPairList.test.tsx b/frontend/src/components/LeftoverPairList.test.tsx index 74f4e8a64..b1282ca1f 100644 --- a/frontend/src/components/LeftoverPairList.test.tsx +++ b/frontend/src/components/LeftoverPairList.test.tsx @@ -46,9 +46,13 @@ describe("LeftoverPairList", () => { expect(screen.getByLabelText("Leftover pairs")).toBeInTheDocument(); const closest = screen.getByRole("button", { - name: "Open leftover closest pair: Public post · sales-lead", + name: /Open leftover closest pair: Public post · sales-lead/, }); expect(closest).toHaveTextContent("Closest leftover: Public post · sales-lead"); + expect(closest).toHaveAccessibleName(/R \+0\.40/); + expect(closest).toHaveAccessibleName(/Y 2\.40 · E 2\.00/); + expect(closest).toHaveAccessibleName(/rank 1/); + expect(closest).toHaveAccessibleName(/d 0\.12/); expect(closest).toHaveTextContent( "Read leftover map rank 1, observed Y 2.40, and expected E 2.00 after IRT main effects, then open this post.", ); @@ -58,8 +62,9 @@ describe("LeftoverPairList", () => { expect(closest).toHaveTextContent("d 0.12"); const farthest = screen.getByRole("button", { - name: "Open leftover farthest pair: Specification revision requested · negative", + name: /Open leftover farthest pair: Specification revision requested · negative/, }); + expect(farthest).toHaveAccessibleName(/R −1\.10/); expect(farthest).toHaveTextContent("R −1.10"); expect(farthest).toHaveTextContent("Y 0.90 · E 2.00"); expect(farthest).toHaveTextContent("rank 1"); @@ -148,8 +153,11 @@ describe("LeftoverPairList", () => { ); const closest = screen.getByRole("button", { - name: "Open leftover closest pair: Public post · sales-lead", + name: /Open leftover closest pair: Public post · sales-lead/, }); + expect(closest).toHaveAccessibleName(/R \+0\.40/); + expect(closest).toHaveAccessibleName(/R̂²\/R² 0\.76/); + expect(closest).toHaveAccessibleName(/ξ \(\+0\.50, \+0\.10\) ζ \(\+0\.50, −0\.02\)/); expect(closest).toHaveTextContent( "Leftover map places this post at ξ (+0.50, +0.10) and the criterion at ζ (+0.50, −0.02) after IRT main effects. Open this post to read sales-lead.", ); diff --git a/frontend/src/components/LeftoverPairList.tsx b/frontend/src/components/LeftoverPairList.tsx index 75e500821..b11af71ef 100644 --- a/frontend/src/components/LeftoverPairList.tsx +++ b/frontend/src/components/LeftoverPairList.tsx @@ -33,6 +33,7 @@ import { formatLeftoverMapUnexplainedShare, LEFTOVER_MAP_UNEXPLAINED_SHARE_ACTION, } from "../leftoverMapUnexplainedShare"; +import { formatLeftoverMapDistance } from "../leftoverMapPlotLayout"; import { LeftoverMapPlot } from "./LeftoverMapPlot"; export type LeftoverPairListProps = { @@ -42,6 +43,11 @@ export type LeftoverPairListProps = { onSelectPost: (pair: LeftoverPair) => void; }; +/** Join finite leftover evidence already selected by the pair-row formatters. */ +function leftoverPairAccessibleName(parts: Array): string { + return parts.filter((part): part is string => typeof part === "string" && part.length > 0).join(" "); +} + /** * Closest and farthest leftover post–criterion pairs after IRT main effects. * @@ -216,11 +222,23 @@ export function LeftoverPairList({ ); From 8f7f54142afa9527da4996dc98ed1b4a745e6bd2 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 12 Sep 2026 18:44:59 +0900 Subject: [PATCH 003/276] docs(gaps): refresh exact-head product evidence Record protected-main authority, live aggregate inventory, the active Customer Master cycle repair, and remaining acceptance boundaries. Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 37 ++++++++++++++++++++++++++ 1 file changed, 37 insertions(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b5d31877b..24c91455b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,5 +1,42 @@ # Product & Technical Gap Baseline +> Exact-head loop overlay: 2026-09-12 18:32 KST. Protected `main` is +> `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). The live +> inventory contains 152 open PRs and 28 open issues. These counts are +> operational metadata, not release evidence. Every open PR observed in this +> pass was Draft before intervention; therefore its skipped repository-local +> test jobs are not successful Checks. PR #996 was moved to Ready and normal +> squash auto-merge was enabled at exact head +> `65d3020d819f9b5d294d2c80c8a4e93a7802c65f`; fresh tests and review are now +> pending, and independent APPROVE remains required. Earlier CodeQL +> compatibility and Strix failures on that SHA remain failed evidence until a +> current authoritative rerun classifies or replaces them. No self-approval, +> Admin bypass, force push, or stale-head transfer is permitted. +> +> Largest buyer-visible gap advanced in this pass: Customer Master can lose +> every organization in a visible parent cycle. PR #996 keeps each authorized +> organization visible exactly once, breaks only the presentation edge needed +> to draw a stable forest, labels the affected top-level row with an actionable +> ancestry explanation, and retains missing-parent and self-parent distinctions. +> The implementation is linear in the visible entity count and carries focused +> cycle, input-permutation, large-hierarchy, rendering, and responsive +> Storybook regressions. Focused local tests passed with a single-worker pool; +> an earlier fork-worker start timed out under host contention and is not a +> product failure or a successful full-suite result. Authenticated PostgreSQL +> API and rendered desktop/mobile acceptance are still unverified for this +> exact head, so this remains an active candidate rather than a protected-main +> capability. +> +> Authority and collision audit: `ContextualWisdomLab/LineageWeave`, +> `RankWeave`, `ThreadWeave`, `TEPP`, and lowercase canonical +> `ContextualWisdomLab/disksage` were rechecked against their remotes. The +> Customer Master slice changes no ADR, API, schema, model boundary, or release +> number. It does not overlap Voice-of-X persistence/export work, the +> RankWeave/ThreadWeave/TEPP calculation owners, or DiskSage safety ownership. +> PR #997 separately repairs duplicated occupational PRD identifiers, and the +> stacked #984/#992 documentation line remains non-authoritative until its +> parent is protected-merged and the child is retargeted and revalidated. + > Exact-head loop overlay: 2026-08-29 13:20 KST. Protected `main` is > `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map > explained leftover share, #775). Open ready PRs still lack independent From c12d5fc549aa6758c2e5e396a8967d3764c26620 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 12 Sep 2026 19:12:13 +0900 Subject: [PATCH 004/276] docs(gaps): bind Customer Master evidence to current head Record the current implementation SHA and the desktop/mobile Storybook audit while leaving authenticated PostgreSQL acceptance unresolved. Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 24c91455b..fab6392d3 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -7,7 +7,7 @@ > pass was Draft before intervention; therefore its skipped repository-local > test jobs are not successful Checks. PR #996 was moved to Ready and normal > squash auto-merge was enabled at exact head -> `65d3020d819f9b5d294d2c80c8a4e93a7802c65f`; fresh tests and review are now +> `a640df40839ed7e2a15b9ab95a7f86faa050a248`; fresh tests and review are now > pending, and independent APPROVE remains required. Earlier CodeQL > compatibility and Strix failures on that SHA remain failed evidence until a > current authoritative rerun classifies or replaces them. No self-approval, @@ -22,10 +22,12 @@ > cycle, input-permutation, large-hierarchy, rendering, and responsive > Storybook regressions. Focused local tests passed with a single-worker pool; > an earlier fork-worker start timed out under host contention and is not a -> product failure or a successful full-suite result. Authenticated PostgreSQL -> API and rendered desktop/mobile acceptance are still unverified for this -> exact head, so this remains an active candidate rather than a protected-main -> capability. +> product failure or a successful full-suite result. The exact-head Storybook +> scene was rendered and visually inspected at 1440x900 and 390x844: identity, +> level, and ancestry guidance remain distinct, and the mobile scene has no +> horizontal clipping. Authenticated PostgreSQL API acceptance remains +> unverified for this exact head, so this remains an active candidate rather +> than a protected-main capability. > > Authority and collision audit: `ContextualWisdomLab/LineageWeave`, > `RankWeave`, `ThreadWeave`, `TEPP`, and lowercase canonical From b3a4824009d1553f9f7cf73953224fcbfdde4aff Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 12 Sep 2026 20:09:08 +0900 Subject: [PATCH 005/276] docs(gaps): refresh current repair ownership evidence --- docs/product-technical-gap-baseline.md | 68 ++++++++++++-------------- 1 file changed, 32 insertions(+), 36 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index fab6392d3..414557a42 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,43 +1,39 @@ # Product & Technical Gap Baseline -> Exact-head loop overlay: 2026-09-12 18:32 KST. Protected `main` is -> `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). The live -> inventory contains 152 open PRs and 28 open issues. These counts are -> operational metadata, not release evidence. Every open PR observed in this -> pass was Draft before intervention; therefore its skipped repository-local -> test jobs are not successful Checks. PR #996 was moved to Ready and normal -> squash auto-merge was enabled at exact head -> `a640df40839ed7e2a15b9ab95a7f86faa050a248`; fresh tests and review are now -> pending, and independent APPROVE remains required. Earlier CodeQL -> compatibility and Strix failures on that SHA remain failed evidence until a -> current authoritative rerun classifies or replaces them. No self-approval, -> Admin bypass, force push, or stale-head transfer is permitted. +> Exact-head loop overlay: 2026-09-12 20:01 KST. Protected `main` remains +> `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). A fresh, +> date-partitioned repository search found 157 open PRs and 32 open issues. +> These counts are operational metadata, not release evidence. PR #996 is +> Draft at exact head `a640df40839ed7e2a15b9ab95a7f86faa050a248`; +> its cycle presentation remains candidate evidence only, and no Ready, +> auto-merge, protected-main, or authenticated acceptance claim is made. > -> Largest buyer-visible gap advanced in this pass: Customer Master can lose -> every organization in a visible parent cycle. PR #996 keeps each authorized -> organization visible exactly once, breaks only the presentation edge needed -> to draw a stable forest, labels the affected top-level row with an actionable -> ancestry explanation, and retains missing-parent and self-parent distinctions. -> The implementation is linear in the visible entity count and carries focused -> cycle, input-permutation, large-hierarchy, rendering, and responsive -> Storybook regressions. Focused local tests passed with a single-worker pool; -> an earlier fork-worker start timed out under host contention and is not a -> product failure or a successful full-suite result. The exact-head Storybook -> scene was rendered and visually inspected at 1440x900 and 390x844: identity, -> level, and ancestry guidance remain distinct, and the mobile scene has no -> horizontal clipping. Authenticated PostgreSQL API acceptance remains -> unverified for this exact head, so this remains an active candidate rather -> than a protected-main capability. +> Current buyer-visible security gaps have explicit product owners. Issue +> #1045 and Draft PR #1042 own Customer Master process-unit authorization; +> the PR's current caller-level contract is intentionally RED until the +> authenticated account scope reaches the relationship-network boundary. +> Issue #1044 and Draft PR #1047 own persisted post-chat derived-data replay +> authorization; legacy rows without a generation-scope receipt remain +> intentionally non-replayable in the required design. Neither candidate is +> a protected-main capability, and neither owner may be bypassed by filtering +> presentation data or copying authorization logic. > -> Authority and collision audit: `ContextualWisdomLab/LineageWeave`, -> `RankWeave`, `ThreadWeave`, `TEPP`, and lowercase canonical -> `ContextualWisdomLab/disksage` were rechecked against their remotes. The -> Customer Master slice changes no ADR, API, schema, model boundary, or release -> number. It does not overlap Voice-of-X persistence/export work, the -> RankWeave/ThreadWeave/TEPP calculation owners, or DiskSage safety ownership. -> PR #997 separately repairs duplicated occupational PRD identifiers, and the -> stacked #984/#992 documentation line remains non-authoritative until its -> parent is protected-merged and the child is retargeted and revalidated. +> Current dependency and data-operability gaps are also separated. Issue +> #1043 and PR #1046 own GHSA-82fw-gwwq-j7x9: the source manifest has moved +> to Vitest 4.1.11, while the generated pnpm lock and frozen-install evidence +> are still RED and require canonical regeneration. Issue #1048 and Draft PR +> #1049 own the duplicate forward-migration ordinal `0233`; both shipped +> deltas remain valid, so repair requires an ADR-backed compatibility identity, +> clean-install and pre-0233 replay evidence rather than deleting or casually +> renaming history. +> +> Authority remains in `ContextualWisdomLab/LineageWeave`. RankWeave, +> ThreadWeave, TEPP, and lowercase canonical +> `ContextualWisdomLab/disksage` retain their existing bounded +> responsibilities. This overlay changes no ADR, API, schema, release number, +> or owner implementation. PR #1041 remains Draft until documentation hygiene +> is rerun on its new exact head and all ordinary review/check gates are +> satisfied; historical receipts from its prior head are not reused. > Exact-head loop overlay: 2026-08-29 13:20 KST. Protected `main` is > `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map From e479c4bfc89dedc480e3c25cd5ccd5cd9d5ed643 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 12 Sep 2026 21:58:14 +0900 Subject: [PATCH 006/276] docs(gaps): refresh ready-state evidence --- docs/product-technical-gap-baseline.md | 26 ++++++++++++++++---------- 1 file changed, 16 insertions(+), 10 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 414557a42..d2fd15924 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,12 +1,14 @@ # Product & Technical Gap Baseline -> Exact-head loop overlay: 2026-09-12 20:01 KST. Protected `main` remains +> Exact-head loop overlay: 2026-09-12 21:55 KST. Protected `main` remains > `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). A fresh, > date-partitioned repository search found 157 open PRs and 32 open issues. > These counts are operational metadata, not release evidence. PR #996 is -> Draft at exact head `a640df40839ed7e2a15b9ab95a7f86faa050a248`; -> its cycle presentation remains candidate evidence only, and no Ready, -> auto-merge, protected-main, or authenticated acceptance claim is made. +> Ready at exact head `a640df40839ed7e2a15b9ab95a7f86faa050a248`, +> with normal squash auto-merge armed. Its cycle presentation remains +> candidate evidence only: current-head Checks restarted after the Ready +> transition, independent approval is absent, and authenticated PostgreSQL +> acceptance is still unverified. > > Current buyer-visible security gaps have explicit product owners. Issue > #1045 and Draft PR #1042 own Customer Master process-unit authorization; @@ -19,9 +21,11 @@ > presentation data or copying authorization logic. > > Current dependency and data-operability gaps are also separated. Issue -> #1043 and PR #1046 own GHSA-82fw-gwwq-j7x9: the source manifest has moved -> to Vitest 4.1.11, while the generated pnpm lock and frozen-install evidence -> are still RED and require canonical regeneration. Issue #1048 and Draft PR +> #1043 and Ready PR #1046 own GHSA-82fw-gwwq-j7x9: the source manifest, +> generated pnpm lock, frozen install, frontend suite, and full suite now pass +> on exact head `f80c0ec5f35fd4fc0a867125bc46dfd2d2dee9a9`. +> Normal squash auto-merge is armed, but dependency-review evidence failed +> closed on a GitHub HTTP 403 and independent approval is absent. Issue #1048 and Draft PR > #1049 own the duplicate forward-migration ordinal `0233`; both shipped > deltas remain valid, so repair requires an ADR-backed compatibility identity, > clean-install and pre-0233 replay evidence rather than deleting or casually @@ -31,9 +35,11 @@ > ThreadWeave, TEPP, and lowercase canonical > `ContextualWisdomLab/disksage` retain their existing bounded > responsibilities. This overlay changes no ADR, API, schema, release number, -> or owner implementation. PR #1041 remains Draft until documentation hygiene -> is rerun on its new exact head and all ordinary review/check gates are -> satisfied; historical receipts from its prior head are not reused. +> or owner implementation. PR #1041 is Ready at exact head +> `b3a4824009d1553f9f7cf73953224fcbfdde4aff` with normal squash auto-merge +> armed. Its current-head repository tests and review workflows pass, while +> independent approval remains absent; historical approval from its prior head +> is not reused. > Exact-head loop overlay: 2026-08-29 13:20 KST. Protected `main` is > `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map From 0b352575435a07faa3e4fd2ed89254fa7923ac8b Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 12 Sep 2026 23:03:21 +0900 Subject: [PATCH 007/276] docs(gaps): retract stale Ready evidence --- docs/product-technical-gap-baseline.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index d2fd15924..f5fa0b81d 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -35,11 +35,11 @@ > ThreadWeave, TEPP, and lowercase canonical > `ContextualWisdomLab/disksage` retain their existing bounded > responsibilities. This overlay changes no ADR, API, schema, release number, -> or owner implementation. PR #1041 is Ready at exact head -> `b3a4824009d1553f9f7cf73953224fcbfdde4aff` with normal squash auto-merge -> armed. Its current-head repository tests and review workflows pass, while -> independent approval remains absent; historical approval from its prior head -> is not reused. +> or owner implementation. PR #1041 is Draft after documentation advanced beyond +> validated candidate `b3a4824009d1553f9f7cf73953224fcbfdde4aff`. That +> candidate's repository tests and review workflows are historical evidence only; +> the current candidate requires fresh exact-head validation and an independent +> approval before Ready, auto-merge, or protected-main integration. > Exact-head loop overlay: 2026-08-29 13:20 KST. Protected `main` is > `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map From 8713a5e754ae8f4145ee6435ad3be0146fdec4da Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 12 Sep 2026 23:28:56 +0900 Subject: [PATCH 008/276] docs(gaps): refresh exact-head queue evidence --- docs/product-technical-gap-baseline.md | 24 +++++++++++++----------- 1 file changed, 13 insertions(+), 11 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index f5fa0b81d..b383cd319 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,14 +1,14 @@ # Product & Technical Gap Baseline -> Exact-head loop overlay: 2026-09-12 21:55 KST. Protected `main` remains +> Exact-head loop overlay: 2026-09-12 23:28 KST. Protected `main` remains > `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). A fresh, > date-partitioned repository search found 157 open PRs and 32 open issues. > These counts are operational metadata, not release evidence. PR #996 is -> Ready at exact head `a640df40839ed7e2a15b9ab95a7f86faa050a248`, -> with normal squash auto-merge armed. Its cycle presentation remains -> candidate evidence only: current-head Checks restarted after the Ready -> transition, independent approval is absent, and authenticated PostgreSQL -> acceptance is still unverified. +> Draft at exact head `a640df40839ed7e2a15b9ab95a7f86faa050a248`; +> normal auto-merge is not armed. Its cycle presentation remains candidate +> evidence only: repository tests are skipped by Draft policy, historical +> Checks do not transfer, independent approval is absent, and authenticated +> PostgreSQL acceptance is still unverified. > > Current buyer-visible security gaps have explicit product owners. Issue > #1045 and Draft PR #1042 own Customer Master process-unit authorization; @@ -21,11 +21,13 @@ > presentation data or copying authorization logic. > > Current dependency and data-operability gaps are also separated. Issue -> #1043 and Ready PR #1046 own GHSA-82fw-gwwq-j7x9: the source manifest, -> generated pnpm lock, frozen install, frontend suite, and full suite now pass -> on exact head `f80c0ec5f35fd4fc0a867125bc46dfd2d2dee9a9`. -> Normal squash auto-merge is armed, but dependency-review evidence failed -> closed on a GitHub HTTP 403 and independent approval is absent. Issue #1048 and Draft PR +> #1043 and Ready PR #1046 own GHSA-82fw-gwwq-j7x9 at exact head +> `f80c0ec5f35fd4fc0a867125bc46dfd2d2dee9a9`. The advisory regression, +> frozen install, lint, isolated previously timing-out test file, and production +> build pass locally. A resource-contended full frontend run is not promoted to +> passing evidence: worker-start timeouts left it non-terminal as acceptance. +> Normal squash auto-merge is armed while fresh exact-head Checks and +> independent approval remain pending. Issue #1048 and Draft PR > #1049 own the duplicate forward-migration ordinal `0233`; both shipped > deltas remain valid, so repair requires an ADR-backed compatibility identity, > clean-install and pre-0233 replay evidence rather than deleting or casually From 530eec65f8b0c13aa0d9e87090ee612a8246ab63 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 12 Sep 2026 23:39:38 +0900 Subject: [PATCH 009/276] docs(gaps): record authenticated scope repair evidence --- docs/product-technical-gap-baseline.md | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b383cd319..58794c5cf 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -11,9 +11,12 @@ > PostgreSQL acceptance is still unverified. > > Current buyer-visible security gaps have explicit product owners. Issue -> #1045 and Draft PR #1042 own Customer Master process-unit authorization; -> the PR's current caller-level contract is intentionally RED until the -> authenticated account scope reaches the relationship-network boundary. +> #1045 and Ready PR #1042 own Customer Master process-unit authorization at +> exact head `7381233b12b7160a0c0c08d9749334a9e05eb862`. The authenticated +> account scope now reaches the relationship-network boundary, and a synthetic +> OIDC/PostgreSQL API regression passes without exposing record content. +> Normal squash auto-merge is armed while fresh exact-head Checks and +> independent approval remain pending. > Issue #1044 and Draft PR #1047 own persisted post-chat derived-data replay > authorization; legacy rows without a generation-scope receipt remain > intentionally non-replayable in the required design. Neither candidate is From bb7b222440a7992469d91897648d6311e55a4e1a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 02:19:37 +0900 Subject: [PATCH 010/276] docs(gaps): refresh protected loop evidence --- docs/product-technical-gap-baseline.md | 43 ++++++++++++++++---------- 1 file changed, 27 insertions(+), 16 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 58794c5cf..e721b4d5c 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Exact-head loop overlay: 2026-09-12 23:28 KST. Protected `main` remains +> Exact-head loop overlay: 2026-09-13 02:16 KST. Protected `main` remains > `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). A fresh, > date-partitioned repository search found 157 open PRs and 32 open issues. > These counts are operational metadata, not release evidence. PR #996 is @@ -12,16 +12,24 @@ > > Current buyer-visible security gaps have explicit product owners. Issue > #1045 and Ready PR #1042 own Customer Master process-unit authorization at -> exact head `7381233b12b7160a0c0c08d9749334a9e05eb862`. The authenticated +> exact head `d39ec8cdfa1164ce2efa2bb87a836a0d22037181`. The authenticated > account scope now reaches the relationship-network boundary, and a synthetic -> OIDC/PostgreSQL API regression passes without exposing record content. -> Normal squash auto-merge is armed while fresh exact-head Checks and -> independent approval remain pending. -> Issue #1044 and Draft PR #1047 own persisted post-chat derived-data replay -> authorization; legacy rows without a generation-scope receipt remain -> intentionally non-replayable in the required design. Neither candidate is -> a protected-main capability, and neither owner may be bypassed by filtering -> presentation data or copying authorization logic. +> OIDC/PostgreSQL API regression passes without exposing record content. The +> reduced/offline coverage collector now discovers optional imports and pytest +> markers without duplicating the OpenTelemetry repair owned by Draft PR #973. +> Normal squash auto-merge remains armed. Exact-head independent approval is +> still absent; a Noema 502 is provider evidence, not a source-code finding. +> Issue #1044 and Ready PR #1047 own persisted post-chat derived-data replay +> authorization at exact head +> `560890db5bf4b83d37bf6470cd0bc4fcce4ba795`. The production replay path now +> requires the immutable reader-scope receipt, reauthorizes every captured +> contributing Post, fails legacy receipt-less rows closed to live generation, +> and persists answer, scope, sources, and citations atomically. A focused +> synthetic regression slice passed (22 passed, 3 skipped; authenticated +> PostgreSQL/API cases were unavailable in that exact-head run). Normal squash +> auto-merge is armed while hosted Checks and independent approval remain +> pending. Neither candidate is a protected-main capability, and neither owner +> may be bypassed by presentation filtering or copied authorization logic. > > Current dependency and data-operability gaps are also separated. Issue > #1043 and Ready PR #1046 own GHSA-82fw-gwwq-j7x9 at exact head @@ -39,12 +47,15 @@ > Authority remains in `ContextualWisdomLab/LineageWeave`. RankWeave, > ThreadWeave, TEPP, and lowercase canonical > `ContextualWisdomLab/disksage` retain their existing bounded -> responsibilities. This overlay changes no ADR, API, schema, release number, -> or owner implementation. PR #1041 is Draft after documentation advanced beyond -> validated candidate `b3a4824009d1553f9f7cf73953224fcbfdde4aff`. That -> candidate's repository tests and review workflows are historical evidence only; -> the current candidate requires fresh exact-head validation and an independent -> approval before Ready, auto-merge, or protected-main integration. +> responsibilities. PR #1041 remains Draft at exact head +> `530eec65f8b0c13aa0d9e87090ee612a8246ab63` until this overlay is committed. +> Its earlier tests and reviews are historical evidence only. The release +> metadata conflict (`pyproject.toml` 2.28.0 versus +> `lineageweave.__version__` 2.20.0), duplicate migration ordinal 0233 +> (#1048/#1049), and Voice authority numbering conflict remain explicit: +> ADR 0251 governs I/O psychology, while the extensible Voice-combination +> contract is ADR 0256. No release, schema, or ADR collision is silently +> repaired in this documentation-only owner PR. > Exact-head loop overlay: 2026-08-29 13:20 KST. Protected `main` is > `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map From fbe4fbd47f78fa5f87fed9fbd1119186670cd597 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 02:38:47 +0900 Subject: [PATCH 011/276] docs(gaps): track replay repair head --- docs/product-technical-gap-baseline.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e721b4d5c..14170964b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -21,18 +21,18 @@ > still absent; a Noema 502 is provider evidence, not a source-code finding. > Issue #1044 and Ready PR #1047 own persisted post-chat derived-data replay > authorization at exact head -> `560890db5bf4b83d37bf6470cd0bc4fcce4ba795`. The production replay path now +> `7e04f5df1b65ce485f619ce45189858f45223789`. The production replay path now > requires the immutable reader-scope receipt, reauthorizes every captured > contributing Post, fails legacy receipt-less rows closed to live generation, -> and persists answer, scope, sources, and citations atomically. A focused -> synthetic regression slice passed (22 passed, 3 skipped; authenticated -> PostgreSQL/API cases were unavailable in that exact-head run). Normal squash +> and persists answer, scope, sources, and citations atomically. Focused +> synthetic regression slices passed during repair; authenticated +> PostgreSQL/API cases remain unavailable on this exact head. Normal squash > auto-merge is armed while hosted Checks and independent approval remain > pending. Neither candidate is a protected-main capability, and neither owner > may be bypassed by presentation filtering or copied authorization logic. > > Current dependency and data-operability gaps are also separated. Issue -> #1043 and Ready PR #1046 own GHSA-82fw-gwwq-j7x9 at exact head +> #1043 and Draft PR #1046 own GHSA-82fw-gwwq-j7x9 at exact head > `f80c0ec5f35fd4fc0a867125bc46dfd2d2dee9a9`. The advisory regression, > frozen install, lint, isolated previously timing-out test file, and production > build pass locally. A resource-contended full frontend run is not promoted to From 7aa3f4e5bc7c36d2f854daa481db82a3feac46cc Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 02:39:29 +0900 Subject: [PATCH 012/276] docs(gaps): correct replay exact head --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 14170964b..5361db10a 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -21,7 +21,7 @@ > still absent; a Noema 502 is provider evidence, not a source-code finding. > Issue #1044 and Ready PR #1047 own persisted post-chat derived-data replay > authorization at exact head -> `7e04f5df1b65ce485f619ce45189858f45223789`. The production replay path now +> `7e04f5df1e39a9477ddbec628ff4944ebfc176f7`. The production replay path now > requires the immutable reader-scope receipt, reauthorizes every captured > contributing Post, fails legacy receipt-less rows closed to live generation, > and persists answer, scope, sources, and citations atomically. Focused From 1323f6441a06ef04601bfeeddbc80a219135adc9 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 04:49:08 +0900 Subject: [PATCH 013/276] chore(docs): stage exact-head gap baseline refresh --- .../workflows/pr1041-refresh-gap-baseline.yml | 89 +++++++++++++++++++ 1 file changed, 89 insertions(+) create mode 100644 .github/workflows/pr1041-refresh-gap-baseline.yml diff --git a/.github/workflows/pr1041-refresh-gap-baseline.yml b/.github/workflows/pr1041-refresh-gap-baseline.yml new file mode 100644 index 000000000..dfd35edc3 --- /dev/null +++ b/.github/workflows/pr1041-refresh-gap-baseline.yml @@ -0,0 +1,89 @@ +name: PR1041 refresh gap baseline + +on: + push: + branches: [codex/gap-loop-20260912] + paths: [.github/workflows/pr1041-refresh-gap-baseline.yml] + +permissions: + contents: write + +jobs: + refresh: + runs-on: ubuntu-latest + steps: + - name: Checkout candidate + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # actions/checkout@v7 + with: + ref: codex/gap-loop-20260912 + + - name: Replace stale live overlay + shell: bash + run: | + python - <<'PY' + from pathlib import Path + + path = Path("docs/product-technical-gap-baseline.md") + text = path.read_text() + title = "# Product & Technical Gap Baseline\n\n" + marker = "> Exact-head loop overlay: 2026-08-29 13:20 KST." + if not text.startswith(title): + raise SystemExit("unexpected baseline title") + if marker not in text: + raise SystemExit("historical overlay boundary missing") + + historical = text[text.index(marker):] + overlay = """> Exact-head loop overlay: 2026-09-13 04:48 KST. Protected `main` remains + > `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). Fresh live + > search reports 157 open PRs and 32 open issues. These counts and every + > candidate state below are operational evidence, not protected-main capability. + > + > Customer Master hierarchy PR #996 remains Draft at exact + > `a640df40839ed7e2a15b9ab95a7f86faa050a248`; its interrupted prior Ready + > admission is not a full repository receipt. Process-unit authorization is + > owned separately by issue #1045 / Ready PR #1042 at exact + > `d39ec8cdfa1164ce2efa2bb87a836a0d22037181`. Repository Tests, Security, + > and SAST are GREEN there, while canonical promotion gates are incomplete and + > exact-head Strix run 34704740554 is still executing `Run Strix (quick)`. + > Do not copy that authorization rule into hierarchy presentation code. + > + > Persisted Post Chat replay authorization is owned by issue #1044 / Ready PR + > #1047 at exact `41c7a86f78dddf0bcd9e9f0eb070bf90732f68e3`. + > The consumer now delegates captured-source authorization to the literal-query + > repository operation in `post_eligibility.py`; the predecessor full suite + > exposed one stale contract that still required the consumer to mention + > `source_post_scope_sql`. That contract has been repaired to assert owner + > delegation instead, and fresh exact-head Tests run 34715131667 is active. + > Ready means validation admission only; it is not merge readiness. + > + > Dependency advisory GHSA-82fw-gwwq-j7x9 remains owned by issue #1043 / + > Draft PR #1046 at exact `f80c0ec5f35fd4fc0a867125bc46dfd2d2dee9a9`. + > Duplicate migration ordinal 0233 remains owned by issue #1048 / Draft PR + > #1049 at exact `5322971193d1ff4e0ae13c054d8f99615934d4dc`. + > #1049's repository Tests, including its real-PostgreSQL repeated production + > `migrate.sh` rehearsal, are GREEN, but all exact-head workflows are terminal + > with Required CodeQL PR 34712361297 and Required Noema 34712358391 failed; + > repository-local GREEN therefore cannot promote the migration repair. + > + > Release metadata is still internally inconsistent on protected main: + > `pyproject.toml` declares 2.28.0 while `lineageweave.__version__` declares + > 2.20.0. Keep this as a release blocker rather than normalizing it in a docs + > candidate. ADR 0251 remains the I/O-psychology authority and ADR 0256 the + > extensible Voice-combination contract. RankWeave, ThreadWeave, TEPP, and + > lowercase canonical `ContextualWisdomLab/disksage` retain their own bounded + > responsibilities. PR #1041 itself remains Draft; its exact head belongs in PR + > metadata rather than a self-referential document SHA. Earlier overlays below + > are dated historical evidence only. + """ + path.write_text(title + overlay + "\n" + historical) + PY + + - name: Remove purpose-complete repair workflow and commit + shell: bash + run: | + git rm .github/workflows/pr1041-refresh-gap-baseline.yml + git add docs/product-technical-gap-baseline.md + git config user.name "github-actions[bot]" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + git commit -m "docs(gaps): refresh live exact-head authority" + git push origin HEAD:codex/gap-loop-20260912 From cb612d43c5e3a761b48d0fb43bc860056fdb9dac Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Sat, 12 Sep 2026 19:49:18 +0000 Subject: [PATCH 014/276] docs(gaps): refresh live exact-head authority --- .../workflows/pr1041-refresh-gap-baseline.yml | 89 ------------------ docs/product-technical-gap-baseline.md | 91 ++++++++----------- 2 files changed, 38 insertions(+), 142 deletions(-) delete mode 100644 .github/workflows/pr1041-refresh-gap-baseline.yml diff --git a/.github/workflows/pr1041-refresh-gap-baseline.yml b/.github/workflows/pr1041-refresh-gap-baseline.yml deleted file mode 100644 index dfd35edc3..000000000 --- a/.github/workflows/pr1041-refresh-gap-baseline.yml +++ /dev/null @@ -1,89 +0,0 @@ -name: PR1041 refresh gap baseline - -on: - push: - branches: [codex/gap-loop-20260912] - paths: [.github/workflows/pr1041-refresh-gap-baseline.yml] - -permissions: - contents: write - -jobs: - refresh: - runs-on: ubuntu-latest - steps: - - name: Checkout candidate - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # actions/checkout@v7 - with: - ref: codex/gap-loop-20260912 - - - name: Replace stale live overlay - shell: bash - run: | - python - <<'PY' - from pathlib import Path - - path = Path("docs/product-technical-gap-baseline.md") - text = path.read_text() - title = "# Product & Technical Gap Baseline\n\n" - marker = "> Exact-head loop overlay: 2026-08-29 13:20 KST." - if not text.startswith(title): - raise SystemExit("unexpected baseline title") - if marker not in text: - raise SystemExit("historical overlay boundary missing") - - historical = text[text.index(marker):] - overlay = """> Exact-head loop overlay: 2026-09-13 04:48 KST. Protected `main` remains - > `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). Fresh live - > search reports 157 open PRs and 32 open issues. These counts and every - > candidate state below are operational evidence, not protected-main capability. - > - > Customer Master hierarchy PR #996 remains Draft at exact - > `a640df40839ed7e2a15b9ab95a7f86faa050a248`; its interrupted prior Ready - > admission is not a full repository receipt. Process-unit authorization is - > owned separately by issue #1045 / Ready PR #1042 at exact - > `d39ec8cdfa1164ce2efa2bb87a836a0d22037181`. Repository Tests, Security, - > and SAST are GREEN there, while canonical promotion gates are incomplete and - > exact-head Strix run 34704740554 is still executing `Run Strix (quick)`. - > Do not copy that authorization rule into hierarchy presentation code. - > - > Persisted Post Chat replay authorization is owned by issue #1044 / Ready PR - > #1047 at exact `41c7a86f78dddf0bcd9e9f0eb070bf90732f68e3`. - > The consumer now delegates captured-source authorization to the literal-query - > repository operation in `post_eligibility.py`; the predecessor full suite - > exposed one stale contract that still required the consumer to mention - > `source_post_scope_sql`. That contract has been repaired to assert owner - > delegation instead, and fresh exact-head Tests run 34715131667 is active. - > Ready means validation admission only; it is not merge readiness. - > - > Dependency advisory GHSA-82fw-gwwq-j7x9 remains owned by issue #1043 / - > Draft PR #1046 at exact `f80c0ec5f35fd4fc0a867125bc46dfd2d2dee9a9`. - > Duplicate migration ordinal 0233 remains owned by issue #1048 / Draft PR - > #1049 at exact `5322971193d1ff4e0ae13c054d8f99615934d4dc`. - > #1049's repository Tests, including its real-PostgreSQL repeated production - > `migrate.sh` rehearsal, are GREEN, but all exact-head workflows are terminal - > with Required CodeQL PR 34712361297 and Required Noema 34712358391 failed; - > repository-local GREEN therefore cannot promote the migration repair. - > - > Release metadata is still internally inconsistent on protected main: - > `pyproject.toml` declares 2.28.0 while `lineageweave.__version__` declares - > 2.20.0. Keep this as a release blocker rather than normalizing it in a docs - > candidate. ADR 0251 remains the I/O-psychology authority and ADR 0256 the - > extensible Voice-combination contract. RankWeave, ThreadWeave, TEPP, and - > lowercase canonical `ContextualWisdomLab/disksage` retain their own bounded - > responsibilities. PR #1041 itself remains Draft; its exact head belongs in PR - > metadata rather than a self-referential document SHA. Earlier overlays below - > are dated historical evidence only. - """ - path.write_text(title + overlay + "\n" + historical) - PY - - - name: Remove purpose-complete repair workflow and commit - shell: bash - run: | - git rm .github/workflows/pr1041-refresh-gap-baseline.yml - git add docs/product-technical-gap-baseline.md - git config user.name "github-actions[bot]" - git config user.email "41898282+github-actions[bot]@users.noreply.github.com" - git commit -m "docs(gaps): refresh live exact-head authority" - git push origin HEAD:codex/gap-loop-20260912 diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 5361db10a..f6d4d48e0 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,61 +1,46 @@ # Product & Technical Gap Baseline -> Exact-head loop overlay: 2026-09-13 02:16 KST. Protected `main` remains -> `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). A fresh, -> date-partitioned repository search found 157 open PRs and 32 open issues. -> These counts are operational metadata, not release evidence. PR #996 is -> Draft at exact head `a640df40839ed7e2a15b9ab95a7f86faa050a248`; -> normal auto-merge is not armed. Its cycle presentation remains candidate -> evidence only: repository tests are skipped by Draft policy, historical -> Checks do not transfer, independent approval is absent, and authenticated -> PostgreSQL acceptance is still unverified. +> Exact-head loop overlay: 2026-09-13 04:48 KST. Protected `main` remains +> `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). Fresh live +> search reports 157 open PRs and 32 open issues. These counts and every +> candidate state below are operational evidence, not protected-main capability. > -> Current buyer-visible security gaps have explicit product owners. Issue -> #1045 and Ready PR #1042 own Customer Master process-unit authorization at -> exact head `d39ec8cdfa1164ce2efa2bb87a836a0d22037181`. The authenticated -> account scope now reaches the relationship-network boundary, and a synthetic -> OIDC/PostgreSQL API regression passes without exposing record content. The -> reduced/offline coverage collector now discovers optional imports and pytest -> markers without duplicating the OpenTelemetry repair owned by Draft PR #973. -> Normal squash auto-merge remains armed. Exact-head independent approval is -> still absent; a Noema 502 is provider evidence, not a source-code finding. -> Issue #1044 and Ready PR #1047 own persisted post-chat derived-data replay -> authorization at exact head -> `7e04f5df1e39a9477ddbec628ff4944ebfc176f7`. The production replay path now -> requires the immutable reader-scope receipt, reauthorizes every captured -> contributing Post, fails legacy receipt-less rows closed to live generation, -> and persists answer, scope, sources, and citations atomically. Focused -> synthetic regression slices passed during repair; authenticated -> PostgreSQL/API cases remain unavailable on this exact head. Normal squash -> auto-merge is armed while hosted Checks and independent approval remain -> pending. Neither candidate is a protected-main capability, and neither owner -> may be bypassed by presentation filtering or copied authorization logic. +> Customer Master hierarchy PR #996 remains Draft at exact +> `a640df40839ed7e2a15b9ab95a7f86faa050a248`; its interrupted prior Ready +> admission is not a full repository receipt. Process-unit authorization is +> owned separately by issue #1045 / Ready PR #1042 at exact +> `d39ec8cdfa1164ce2efa2bb87a836a0d22037181`. Repository Tests, Security, +> and SAST are GREEN there, while canonical promotion gates are incomplete and +> exact-head Strix run 34704740554 is still executing `Run Strix (quick)`. +> Do not copy that authorization rule into hierarchy presentation code. > -> Current dependency and data-operability gaps are also separated. Issue -> #1043 and Draft PR #1046 own GHSA-82fw-gwwq-j7x9 at exact head -> `f80c0ec5f35fd4fc0a867125bc46dfd2d2dee9a9`. The advisory regression, -> frozen install, lint, isolated previously timing-out test file, and production -> build pass locally. A resource-contended full frontend run is not promoted to -> passing evidence: worker-start timeouts left it non-terminal as acceptance. -> Normal squash auto-merge is armed while fresh exact-head Checks and -> independent approval remain pending. Issue #1048 and Draft PR -> #1049 own the duplicate forward-migration ordinal `0233`; both shipped -> deltas remain valid, so repair requires an ADR-backed compatibility identity, -> clean-install and pre-0233 replay evidence rather than deleting or casually -> renaming history. +> Persisted Post Chat replay authorization is owned by issue #1044 / Ready PR +> #1047 at exact `41c7a86f78dddf0bcd9e9f0eb070bf90732f68e3`. +> The consumer now delegates captured-source authorization to the literal-query +> repository operation in `post_eligibility.py`; the predecessor full suite +> exposed one stale contract that still required the consumer to mention +> `source_post_scope_sql`. That contract has been repaired to assert owner +> delegation instead, and fresh exact-head Tests run 34715131667 is active. +> Ready means validation admission only; it is not merge readiness. > -> Authority remains in `ContextualWisdomLab/LineageWeave`. RankWeave, -> ThreadWeave, TEPP, and lowercase canonical -> `ContextualWisdomLab/disksage` retain their existing bounded -> responsibilities. PR #1041 remains Draft at exact head -> `530eec65f8b0c13aa0d9e87090ee612a8246ab63` until this overlay is committed. -> Its earlier tests and reviews are historical evidence only. The release -> metadata conflict (`pyproject.toml` 2.28.0 versus -> `lineageweave.__version__` 2.20.0), duplicate migration ordinal 0233 -> (#1048/#1049), and Voice authority numbering conflict remain explicit: -> ADR 0251 governs I/O psychology, while the extensible Voice-combination -> contract is ADR 0256. No release, schema, or ADR collision is silently -> repaired in this documentation-only owner PR. +> Dependency advisory GHSA-82fw-gwwq-j7x9 remains owned by issue #1043 / +> Draft PR #1046 at exact `f80c0ec5f35fd4fc0a867125bc46dfd2d2dee9a9`. +> Duplicate migration ordinal 0233 remains owned by issue #1048 / Draft PR +> #1049 at exact `5322971193d1ff4e0ae13c054d8f99615934d4dc`. +> #1049's repository Tests, including its real-PostgreSQL repeated production +> `migrate.sh` rehearsal, are GREEN, but all exact-head workflows are terminal +> with Required CodeQL PR 34712361297 and Required Noema 34712358391 failed; +> repository-local GREEN therefore cannot promote the migration repair. +> +> Release metadata is still internally inconsistent on protected main: +> `pyproject.toml` declares 2.28.0 while `lineageweave.__version__` declares +> 2.20.0. Keep this as a release blocker rather than normalizing it in a docs +> candidate. ADR 0251 remains the I/O-psychology authority and ADR 0256 the +> extensible Voice-combination contract. RankWeave, ThreadWeave, TEPP, and +> lowercase canonical `ContextualWisdomLab/disksage` retain their own bounded +> responsibilities. PR #1041 itself remains Draft; its exact head belongs in PR +> metadata rather than a self-referential document SHA. Earlier overlays below +> are dated historical evidence only. > Exact-head loop overlay: 2026-08-29 13:20 KST. Protected `main` is > `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map From 75a1e8222c6e6c1bb358a025854661bb0bbf1bfe Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 05:51:20 +0900 Subject: [PATCH 015/276] chore(docs): refresh live gap overlay --- .../workflows/pr1041-refresh-gap-baseline.yml | 103 ++++++++++++++++++ 1 file changed, 103 insertions(+) create mode 100644 .github/workflows/pr1041-refresh-gap-baseline.yml diff --git a/.github/workflows/pr1041-refresh-gap-baseline.yml b/.github/workflows/pr1041-refresh-gap-baseline.yml new file mode 100644 index 000000000..d58bfb4a0 --- /dev/null +++ b/.github/workflows/pr1041-refresh-gap-baseline.yml @@ -0,0 +1,103 @@ +name: Refresh PR1041 product gap baseline + +on: + push: + branches: + - codex/gap-loop-20260912 + paths: + - .github/workflows/pr1041-refresh-gap-baseline.yml + +permissions: + contents: write + +jobs: + refresh: + runs-on: ubuntu-24.04 + steps: + - name: Checkout exact branch head + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # actions/checkout@v7 + with: + ref: codex/gap-loop-20260912 + persist-credentials: false + + - name: Replace only the live overlay and remove this workflow + shell: bash + run: | + set -euo pipefail + python - <<'PY' + from pathlib import Path + + path = Path("docs/product-technical-gap-baseline.md") + text = path.read_text(encoding="utf-8") + start_marker = "> Exact-head loop overlay: 2026-09-13 04:48 KST." + end_marker = "> Exact-head loop overlay: 2026-08-29 13:20 KST." + start = text.index(start_marker) + end = text.index(end_marker, start) + overlay = """> Exact-head loop overlay: 2026-09-13 05:46 KST. Protected `main` remains +> `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). Fresh live +> search reports 157 open PRs and 32 open issues. These counts and every +> candidate state below are operational evidence, not protected-main capability. +> +> Customer Master hierarchy PR #996 remains Draft at exact +> `a640df40839ed7e2a15b9ab95a7f86faa050a248`; its interrupted prior Ready +> admission is not a full repository receipt. Process-unit authorization is +> owned separately by issue #1045 / Ready PR #1042 at exact +> `d39ec8cdfa1164ce2efa2bb87a836a0d22037181`. Repository Tests, Security, +> and SAST are GREEN there, canonical promotion gates remain incomplete, and +> exact-head Strix run 34704740554 is still executing `Run Strix (quick)`. +> Ready therefore means live-lane preservation only, not merge readiness. Do +> not copy that authorization rule into hierarchy presentation code. +> +> Persisted Post Chat replay authorization remains owned by issue #1044 / +> Draft PR #1047 at exact `41c7a86f78dddf0bcd9e9f0eb070bf90732f68e3`. +> Its product repair delegates captured-source authorization to the literal-query +> repository operation in `post_eligibility.py` and the stale consumer/owner +> executable contract is repaired. Exact-head Tests 34715131667, Security +> 34715131625, SAST 34715131624, dynamic GitHub CodeQL 34715130159, and Code +> Quality 34715130627 are GREEN. Required CodeQL PR 34715131636, Required +> OpenCode 34715130589, Required Noema 34715130587, and Strix 34715130596 are +> terminal FAILURE, so all validation lanes are terminal and the PR has returned +> to Draft. CodeQL again failed its compatibility consumers before the producer +> dispatch started; OpenCode likewise failed closed before a later same-head +> review appeared. Both unchanged-head canaries are recorded in canonical +> `.github#1929`. Noema failed before verdict publication; Strix failed in its +> scan step after setup and uploaded reports. Do not infer a leaf vulnerability +> or provider fault from those wrapper outcomes without stronger evidence. +> +> Dependency advisory GHSA-82fw-gwwq-j7x9 remains owned by issue #1043 / +> Draft PR #1046 at exact `f80c0ec5f35fd4fc0a867125bc46dfd2d2dee9a9`. +> Duplicate migration ordinal 0233 remains owned by issue #1048 / Draft PR +> #1049 at exact `5322971193d1ff4e0ae13c054d8f99615934d4dc`. +> #1049's repository Tests, including its real-PostgreSQL repeated production +> `migrate.sh` rehearsal, are GREEN, but exact-head Required CodeQL and Required +> Noema are terminal FAILURE; repository-local GREEN therefore cannot promote +> the migration repair. +> +> Release metadata is still internally inconsistent on protected main: +> `pyproject.toml` declares 2.28.0 while `lineageweave.__version__` declares +> 2.20.0. Keep this as a release blocker rather than normalizing it in a docs +> candidate. ADR 0251 remains the I/O-psychology authority and ADR 0256 the +> extensible Voice-combination contract. RankWeave, ThreadWeave, TEPP, and +> lowercase canonical `ContextualWisdomLab/disksage` retain their own bounded +> responsibilities. PR #1041 itself remains Draft; its exact head belongs in PR +> metadata rather than a self-referential document SHA. Earlier overlays below +> are dated historical evidence only. + +""" + path.write_text(text[:start] + overlay + text[end:], encoding="utf-8") + PY + rm -- .github/workflows/pr1041-refresh-gap-baseline.yml + + - name: Commit bounded documentation refresh + env: + GH_TOKEN: ${{ github.token }} + shell: bash + run: | + set -euo pipefail + git config user.name "github-actions[bot]" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + git add docs/product-technical-gap-baseline.md .github/workflows/pr1041-refresh-gap-baseline.yml + git diff --cached --check + git commit -m "docs(gaps): refresh terminal validation evidence" + git remote set-url origin "https://x-access-token:${GH_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" + git push origin "HEAD:${GITHUB_REF_NAME}" From b8338dcba62f2777ee054f691dc01e19786d2a14 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 05:51:37 +0900 Subject: [PATCH 016/276] chore(docs): remove purpose-complete refresh workflow --- .../workflows/pr1041-refresh-gap-baseline.yml | 103 ------------------ 1 file changed, 103 deletions(-) delete mode 100644 .github/workflows/pr1041-refresh-gap-baseline.yml diff --git a/.github/workflows/pr1041-refresh-gap-baseline.yml b/.github/workflows/pr1041-refresh-gap-baseline.yml deleted file mode 100644 index d58bfb4a0..000000000 --- a/.github/workflows/pr1041-refresh-gap-baseline.yml +++ /dev/null @@ -1,103 +0,0 @@ -name: Refresh PR1041 product gap baseline - -on: - push: - branches: - - codex/gap-loop-20260912 - paths: - - .github/workflows/pr1041-refresh-gap-baseline.yml - -permissions: - contents: write - -jobs: - refresh: - runs-on: ubuntu-24.04 - steps: - - name: Checkout exact branch head - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # actions/checkout@v7 - with: - ref: codex/gap-loop-20260912 - persist-credentials: false - - - name: Replace only the live overlay and remove this workflow - shell: bash - run: | - set -euo pipefail - python - <<'PY' - from pathlib import Path - - path = Path("docs/product-technical-gap-baseline.md") - text = path.read_text(encoding="utf-8") - start_marker = "> Exact-head loop overlay: 2026-09-13 04:48 KST." - end_marker = "> Exact-head loop overlay: 2026-08-29 13:20 KST." - start = text.index(start_marker) - end = text.index(end_marker, start) - overlay = """> Exact-head loop overlay: 2026-09-13 05:46 KST. Protected `main` remains -> `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). Fresh live -> search reports 157 open PRs and 32 open issues. These counts and every -> candidate state below are operational evidence, not protected-main capability. -> -> Customer Master hierarchy PR #996 remains Draft at exact -> `a640df40839ed7e2a15b9ab95a7f86faa050a248`; its interrupted prior Ready -> admission is not a full repository receipt. Process-unit authorization is -> owned separately by issue #1045 / Ready PR #1042 at exact -> `d39ec8cdfa1164ce2efa2bb87a836a0d22037181`. Repository Tests, Security, -> and SAST are GREEN there, canonical promotion gates remain incomplete, and -> exact-head Strix run 34704740554 is still executing `Run Strix (quick)`. -> Ready therefore means live-lane preservation only, not merge readiness. Do -> not copy that authorization rule into hierarchy presentation code. -> -> Persisted Post Chat replay authorization remains owned by issue #1044 / -> Draft PR #1047 at exact `41c7a86f78dddf0bcd9e9f0eb070bf90732f68e3`. -> Its product repair delegates captured-source authorization to the literal-query -> repository operation in `post_eligibility.py` and the stale consumer/owner -> executable contract is repaired. Exact-head Tests 34715131667, Security -> 34715131625, SAST 34715131624, dynamic GitHub CodeQL 34715130159, and Code -> Quality 34715130627 are GREEN. Required CodeQL PR 34715131636, Required -> OpenCode 34715130589, Required Noema 34715130587, and Strix 34715130596 are -> terminal FAILURE, so all validation lanes are terminal and the PR has returned -> to Draft. CodeQL again failed its compatibility consumers before the producer -> dispatch started; OpenCode likewise failed closed before a later same-head -> review appeared. Both unchanged-head canaries are recorded in canonical -> `.github#1929`. Noema failed before verdict publication; Strix failed in its -> scan step after setup and uploaded reports. Do not infer a leaf vulnerability -> or provider fault from those wrapper outcomes without stronger evidence. -> -> Dependency advisory GHSA-82fw-gwwq-j7x9 remains owned by issue #1043 / -> Draft PR #1046 at exact `f80c0ec5f35fd4fc0a867125bc46dfd2d2dee9a9`. -> Duplicate migration ordinal 0233 remains owned by issue #1048 / Draft PR -> #1049 at exact `5322971193d1ff4e0ae13c054d8f99615934d4dc`. -> #1049's repository Tests, including its real-PostgreSQL repeated production -> `migrate.sh` rehearsal, are GREEN, but exact-head Required CodeQL and Required -> Noema are terminal FAILURE; repository-local GREEN therefore cannot promote -> the migration repair. -> -> Release metadata is still internally inconsistent on protected main: -> `pyproject.toml` declares 2.28.0 while `lineageweave.__version__` declares -> 2.20.0. Keep this as a release blocker rather than normalizing it in a docs -> candidate. ADR 0251 remains the I/O-psychology authority and ADR 0256 the -> extensible Voice-combination contract. RankWeave, ThreadWeave, TEPP, and -> lowercase canonical `ContextualWisdomLab/disksage` retain their own bounded -> responsibilities. PR #1041 itself remains Draft; its exact head belongs in PR -> metadata rather than a self-referential document SHA. Earlier overlays below -> are dated historical evidence only. - -""" - path.write_text(text[:start] + overlay + text[end:], encoding="utf-8") - PY - rm -- .github/workflows/pr1041-refresh-gap-baseline.yml - - - name: Commit bounded documentation refresh - env: - GH_TOKEN: ${{ github.token }} - shell: bash - run: | - set -euo pipefail - git config user.name "github-actions[bot]" - git config user.email "41898282+github-actions[bot]@users.noreply.github.com" - git add docs/product-technical-gap-baseline.md .github/workflows/pr1041-refresh-gap-baseline.yml - git diff --cached --check - git commit -m "docs(gaps): refresh terminal validation evidence" - git remote set-url origin "https://x-access-token:${GH_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" - git push origin "HEAD:${GITHUB_REF_NAME}" From af8fbb6a6d27c47a576e2894debafb734901d70d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 06:50:18 +0900 Subject: [PATCH 017/276] chore: stage bounded gap baseline refresh --- .../automation-1041-gap-refresh-0648.yml | 98 +++++++++++++++++++ 1 file changed, 98 insertions(+) create mode 100644 .github/workflows/automation-1041-gap-refresh-0648.yml diff --git a/.github/workflows/automation-1041-gap-refresh-0648.yml b/.github/workflows/automation-1041-gap-refresh-0648.yml new file mode 100644 index 000000000..95af26406 --- /dev/null +++ b/.github/workflows/automation-1041-gap-refresh-0648.yml @@ -0,0 +1,98 @@ +name: Bounded gap baseline refresh + +on: + push: + branches: + - codex/gap-loop-20260912 + paths: + - .github/workflows/automation-1041-gap-refresh-0648.yml + +permissions: + contents: write + +jobs: + refresh: + runs-on: ubuntu-24.04 + steps: + - name: Checkout exact pushed branch head + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # actions/checkout@v7 + with: + ref: codex/gap-loop-20260912 + fetch-depth: 0 + persist-credentials: false + + - name: Refresh only the live overlay and remove this workflow + env: + GITHUB_TOKEN: ${{ github.token }} + run: | + set -euo pipefail + python - <<'PY' + from pathlib import Path + + path = Path("docs/product-technical-gap-baseline.md") + text = path.read_text(encoding="utf-8") + title = "# Product & Technical Gap Baseline\n\n" + if not text.startswith(title): + raise SystemExit("unexpected baseline title") + marker = "> Exact-head loop overlay: 2026-08-29 13:20 KST." + marker_index = text.find(marker) + if marker_index < 0: + raise SystemExit("historical overlay anchor missing") + + overlay = '''> Exact-head loop overlay: 2026-09-13 06:48 KST. Protected `main` remains +> `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). Fresh live +> search reports 157 open PRs and 36 open issues; all 157 open PRs are Draft. +> Candidate state is operational evidence, not protected-main capability. +> +> Customer Master process-unit authorization remains owned by issue #1045 / Draft +> PR #1042 at exact `d39ec8cdfa1164ce2efa2bb87a836a0d22037181`. +> Repository Tests, Security and SAST are GREEN, while Required CodeQL and Noema +> are non-GREEN. Exact-head Strix run 34704740554 is now terminal FAILURE after +> successful admission/materialization/contextual-orchestrator setup; its retained +> `strix-reports` artifact is sha256 +> `bcdc13b76adf4a2b5b9cbbcab2de217db2e25f445f69d2de20a7d9f4cdf19b72`. +> #1042 returned to Draft without moving source head. +> +> The retained #1042 Strix artifact produced five source-traced security findings. +> Persisted Post Chat cited-source replay disclosure is the same causal defect +> already owned by #1044 / Draft PR #1047, so #1044 records the independent +> corroboration instead of creating a competing replay lane. New issues #1050, +> #1051, #1052 and #1053 own, respectively: mixed-visibility period-report +> aggregate disclosure; unbounded durable REST Global Ask admission; cross-tenant +> Customer Master customer-hint evidence/rebind; and Post Chat shared-persistence +> mutation authority. These lanes must reproduce their own REDs; generated Strix +> patch suggestions are not accepted as source authority. +> +> Persisted Post Chat replay authorization remains Draft PR #1047 at exact +> `41c7a86f78dddf0bcd9e9f0eb070bf90732f68e3`. Repository Tests, Security, +> SAST, dynamic CodeQL and Code Quality are GREEN there, while Required CodeQL, +> OpenCode, Noema and Strix are terminal FAILURE. #1047 therefore has no live +> validation lane and is not merge-ready. +> +> Dependency advisory GHSA-82fw-gwwq-j7x9 remains issue #1043 / Draft PR #1046 +> at exact `f80c0ec5f35fd4fc0a867125bc46dfd2d2dee9a9`. Duplicate migration ordinal +> 0233 remains issue #1048 / Draft PR #1049 at exact +> `5322971193d1ff4e0ae13c054d8f99615934d4dc`; its repository/PostgreSQL tests +> are GREEN but canonical Required CodeQL/Noema promotion controls are not. +> +> Release metadata is still inconsistent on protected main: `pyproject.toml` +> declares 2.28.0 while `lineageweave.__version__` declares 2.20.0. Keep this as +> a release blocker rather than normalizing it in documentation. ADR 0251 remains +> the I/O-psychology authority and ADR 0256 the extensible Voice-combination +> contract. RankWeave, ThreadWeave, TEPP, and lowercase canonical +> `ContextualWisdomLab/disksage` retain their own bounded responsibilities. +> PR #1041 remains Draft; earlier overlays below are dated historical evidence only. + +''' + path.write_text(title + overlay + text[marker_index:], encoding="utf-8") + PY + + git diff --check + test "$(git status --short docs/product-technical-gap-baseline.md | wc -l)" -eq 1 + git rm .github/workflows/automation-1041-gap-refresh-0648.yml + git add docs/product-technical-gap-baseline.md + git config user.name "LineageWeave maintenance" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + git commit -m "docs(gaps): refresh terminal Strix security evidence" + git remote set-url origin "https://x-access-token:${GITHUB_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" + git push origin HEAD:codex/gap-loop-20260912 From d387f921627c5e6e586dbe25bbf67f562170def0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 06:52:58 +0900 Subject: [PATCH 018/276] fix: make bounded gap refresh workflow parseable --- .../automation-1041-gap-refresh-0648.yml | 66 +++---------------- 1 file changed, 8 insertions(+), 58 deletions(-) diff --git a/.github/workflows/automation-1041-gap-refresh-0648.yml b/.github/workflows/automation-1041-gap-refresh-0648.yml index 95af26406..1eb95664e 100644 --- a/.github/workflows/automation-1041-gap-refresh-0648.yml +++ b/.github/workflows/automation-1041-gap-refresh-0648.yml @@ -19,80 +19,30 @@ jobs: with: ref: codex/gap-loop-20260912 fetch-depth: 0 - persist-credentials: false + persist-credentials: true - name: Refresh only the live overlay and remove this workflow env: - GITHUB_TOKEN: ${{ github.token }} + OVERLAY_B64: PiBFeGFjdC1oZWFkIGxvb3Agb3ZlcmxheTogMjAyNi0wOS0xMyAwNjo0OCBLU1QuIFByb3RlY3RlZCBgbWFpbmAgcmVtYWlucwo+IGA4M2ViYTU2MTQ5ZWI4MDJjZDYzNjQyYzUwN2MzMjRjOTk3NmVjNzhlYCAodjIuMjguMDsgIzkzMSkuIEZyZXNoIGxpdmUKPiBzZWFyY2ggcmVwb3J0cyAxNTcgb3BlbiBQUnMgYW5kIDM2IG9wZW4gaXNzdWVzOyBhbGwgMTU3IG9wZW4gUFJzIGFyZSBEcmFmdC4KPiBDYW5kaWRhdGUgc3RhdGUgaXMgb3BlcmF0aW9uYWwgZXZpZGVuY2UsIG5vdCBwcm90ZWN0ZWQtbWFpbiBjYXBhYmlsaXR5Lgo+Cj4gQ3VzdG9tZXIgTWFzdGVyIHByb2Nlc3MtdW5pdCBhdXRob3JpemF0aW9uIHJlbWFpbnMgb3duZWQgYnkgaXNzdWUgIzEwNDUgLyBEcmFmdAo+IFBSICMxMDQyIGF0IGV4YWN0IGBkMzllYzhjZGZhMTE2NGNlMmVmYTJiYjg3YTgzNmEwZDIyMDM3MTgxYC4KPiBSZXBvc2l0b3J5IFRlc3RzLCBTZWN1cml0eSBhbmQgU0FTVCBhcmUgR1JFRU4sIHdoaWxlIFJlcXVpcmVkIENvZGVRTCBhbmQgTm9lbWEKPiBhcmUgbm9uLUdSRUVOLiBFeGFjdC1oZWFkIFN0cml4IHJ1biAzNDcwNDc0MDU1NCBpcyBub3cgdGVybWluYWwgRkFJTFVSRSBhZnRlcgo+IHN1Y2Nlc3NmdWwgYWRtaXNzaW9uL21hdGVyaWFsaXphdGlvbi9jb250ZXh0dWFsLW9yY2hlc3RyYXRvciBzZXR1cDsgaXRzIHJldGFpbmVkCj4gYHN0cml4LXJlcG9ydHNgIGFydGlmYWN0IGlzIHNoYTI1Ngo+IGBiY2RjMTNiNzZhZGY0YTJiNWI5Y2JiY2FiMmRlMjE3ZGIyZTI1ZjQ0NWY2OWQyZGUyMGE3ZDlmNGNkZjE5YjcyYC4KPiAjMTA0MiByZXR1cm5lZCB0byBEcmFmdCB3aXRob3V0IG1vdmluZyBzb3VyY2UgaGVhZC4KPgo+IFRoZSByZXRhaW5lZCAjMTA0MiBTdHJpeCBhcnRpZmFjdCBwcm9kdWNlZCBmaXZlIHNvdXJjZS10cmFjZWQgc2VjdXJpdHkgZmluZGluZ3MuCj4gUGVyc2lzdGVkIFBvc3QgQ2hhdCBjaXRlZC1zb3VyY2UgcmVwbGF5IGRpc2Nsb3N1cmUgaXMgdGhlIHNhbWUgY2F1c2FsIGRlZmVjdAo+IGFscmVhZHkgb3duZWQgYnkgIzEwNDQgLyBEcmFmdCBQUiAjMTA0Nywgc28gIzEwNDQgcmVjb3JkcyB0aGUgaW5kZXBlbmRlbnQKPiBjb3Jyb2JvcmF0aW9uIGluc3RlYWQgb2YgY3JlYXRpbmcgYSBjb21wZXRpbmcgcmVwbGF5IGxhbmUuIE5ldyBpc3N1ZXMgIzEwNTAsCj4gIzEwNTEsICMxMDUyIGFuZCAjMTA1MyBvd24sIHJlc3BlY3RpdmVseTogbWl4ZWQtdmlzaWJpbGl0eSBwZXJpb2QtcmVwb3J0Cj4gYWdncmVnYXRlIGRpc2Nsb3N1cmU7IHVuYm91bmRlZCBkdXJhYmxlIFJFU1QgR2xvYmFsIEFzayBhZG1pc3Npb247IGNyb3NzLXRlbmFudAo+IEN1c3RvbWVyIE1hc3RlciBjdXN0b21lci1oaW50IGV2aWRlbmNlL3JlYmluZDsgYW5kIFBvc3QgQ2hhdCBzaGFyZWQtcGVyc2lzdGVuY2UKPiBtdXRhdGlvbiBhdXRob3JpdHkuIFRoZXNlIGxhbmVzIG11c3QgcmVwcm9kdWNlIHRoZWlyIG93biBSRURzOyBnZW5lcmF0ZWQgU3RyaXgKPiBwYXRjaCBzdWdnZXN0aW9ucyBhcmUgbm90IGFjY2VwdGVkIGFzIHNvdXJjZSBhdXRob3JpdHkuCj4KPiBQZXJzaXN0ZWQgUG9zdCBDaGF0IHJlcGxheSBhdXRob3JpemF0aW9uIHJlbWFpbnMgRHJhZnQgUFIgIzEwNDcgYXQgZXhhY3QKPiBgNDFjN2E4NmY3OGRkZGYwYmNkOWU5ZjBlYjA3MGJmOTA3MzJmNjhlM2AuIFJlcG9zaXRvcnkgVGVzdHMsIFNlY3VyaXR5LAo+IFNBU1QsIGR5bmFtaWMgQ29kZVFMIGFuZCBDb2RlIFF1YWxpdHkgYXJlIEdSRUVOIHRoZXJlLCB3aGlsZSBSZXF1aXJlZCBDb2RlUUwsCj4gT3BlbkNvZGUsIE5vZW1hIGFuZCBTdHJpeCBhcmUgdGVybWluYWwgRkFJTFVSRS4gIzEwNDcgdGhlcmVmb3JlIGhhcyBubyBsaXZlCj4gdmFsaWRhdGlvbiBsYW5lIGFuZCBpcyBub3QgbWVyZ2UtcmVhZHkuCj4KPiBEZXBlbmRlbmN5IGFkdmlzb3J5IEdIU0EtODJmdy1nd3dxLWo3eDkgcmVtYWlucyBpc3N1ZSAjMTA0MyAvIERyYWZ0IFBSICMxMDQ2Cj4gYXQgZXhhY3QgYGY4MGMwZWM1ZjM1ZmQ0ZmMwYTg2NzEyNWJjNDZkZmQyZDJkZWU5YTlgLiBEdXBsaWNhdGUgbWlncmF0aW9uIG9yZGluYWwKPiAwMjMzIHJlbWFpbnMgaXNzdWUgIzEwNDggLyBEcmFmdCBQUiAjMTA0OSBhdCBleGFjdAo+IGA1MzIyOTcxMTkzZDFmZjRlMGFlMTNjMDU0ZDhmOTk2MTU5MzRkNGRjYDsgaXRzIHJlcG9zaXRvcnkvUG9zdGdyZVNRTCB0ZXN0cwo+IGFyZSBHUkVFTiBidXQgY2Fub25pY2FsIFJlcXVpcmVkIENvZGVRTC9Ob2VtYSBwcm9tb3Rpb24gY29udHJvbHMgYXJlIG5vdC4KPgo+IFJlbGVhc2UgbWV0YWRhdGEgaXMgc3RpbGwgaW5jb25zaXN0ZW50IG9uIHByb3RlY3RlZCBtYWluOiBgcHlwcm9qZWN0LnRvbWxgCj4gZGVjbGFyZXMgMi4yOC4wIHdoaWxlIGBsaW5lYWdld2VhdmUuX192ZXJzaW9uX19gIGRlY2xhcmVzIDIuMjAuMC4gS2VlcCB0aGlzIGFzCj4gYSByZWxlYXNlIGJsb2NrZXIgcmF0aGVyIHRoYW4gbm9ybWFsaXppbmcgaXQgaW4gZG9jdW1lbnRhdGlvbi4gQURSIDAyNTEgcmVtYWlucwo+IHRoZSBJL08tcHN5Y2hvbG9neSBhdXRob3JpdHkgYW5kIEFEUiAwMjU2IHRoZSBleHRlbnNpYmxlIFZvaWNlLWNvbWJpbmF0aW9uCj4gY29udHJhY3QuIFJhbmtXZWF2ZSwgVGhyZWFkV2VhdmUsIFRFUFAsIGFuZCBsb3dlcmNhc2UgY2Fub25pY2FsCj4gYENvbnRleHR1YWxXaXNkb21MYWIvZGlza3NhZ2VgIHJldGFpbiB0aGVpciBvd24gYm91bmRlZCByZXNwb25zaWJpbGl0aWVzLgo+IFBSICMxMDQxIHJlbWFpbnMgRHJhZnQ7IGVhcmxpZXIgb3ZlcmxheXMgYmVsb3cgYXJlIGRhdGVkIGhpc3RvcmljYWwgZXZpZGVuY2Ugb25seS4KCg== run: | set -euo pipefail python - <<'PY' + import base64 + import os from pathlib import Path - path = Path("docs/product-technical-gap-baseline.md") text = path.read_text(encoding="utf-8") title = "# Product & Technical Gap Baseline\n\n" - if not text.startswith(title): - raise SystemExit("unexpected baseline title") marker = "> Exact-head loop overlay: 2026-08-29 13:20 KST." - marker_index = text.find(marker) - if marker_index < 0: - raise SystemExit("historical overlay anchor missing") - - overlay = '''> Exact-head loop overlay: 2026-09-13 06:48 KST. Protected `main` remains -> `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). Fresh live -> search reports 157 open PRs and 36 open issues; all 157 open PRs are Draft. -> Candidate state is operational evidence, not protected-main capability. -> -> Customer Master process-unit authorization remains owned by issue #1045 / Draft -> PR #1042 at exact `d39ec8cdfa1164ce2efa2bb87a836a0d22037181`. -> Repository Tests, Security and SAST are GREEN, while Required CodeQL and Noema -> are non-GREEN. Exact-head Strix run 34704740554 is now terminal FAILURE after -> successful admission/materialization/contextual-orchestrator setup; its retained -> `strix-reports` artifact is sha256 -> `bcdc13b76adf4a2b5b9cbbcab2de217db2e25f445f69d2de20a7d9f4cdf19b72`. -> #1042 returned to Draft without moving source head. -> -> The retained #1042 Strix artifact produced five source-traced security findings. -> Persisted Post Chat cited-source replay disclosure is the same causal defect -> already owned by #1044 / Draft PR #1047, so #1044 records the independent -> corroboration instead of creating a competing replay lane. New issues #1050, -> #1051, #1052 and #1053 own, respectively: mixed-visibility period-report -> aggregate disclosure; unbounded durable REST Global Ask admission; cross-tenant -> Customer Master customer-hint evidence/rebind; and Post Chat shared-persistence -> mutation authority. These lanes must reproduce their own REDs; generated Strix -> patch suggestions are not accepted as source authority. -> -> Persisted Post Chat replay authorization remains Draft PR #1047 at exact -> `41c7a86f78dddf0bcd9e9f0eb070bf90732f68e3`. Repository Tests, Security, -> SAST, dynamic CodeQL and Code Quality are GREEN there, while Required CodeQL, -> OpenCode, Noema and Strix are terminal FAILURE. #1047 therefore has no live -> validation lane and is not merge-ready. -> -> Dependency advisory GHSA-82fw-gwwq-j7x9 remains issue #1043 / Draft PR #1046 -> at exact `f80c0ec5f35fd4fc0a867125bc46dfd2d2dee9a9`. Duplicate migration ordinal -> 0233 remains issue #1048 / Draft PR #1049 at exact -> `5322971193d1ff4e0ae13c054d8f99615934d4dc`; its repository/PostgreSQL tests -> are GREEN but canonical Required CodeQL/Noema promotion controls are not. -> -> Release metadata is still inconsistent on protected main: `pyproject.toml` -> declares 2.28.0 while `lineageweave.__version__` declares 2.20.0. Keep this as -> a release blocker rather than normalizing it in documentation. ADR 0251 remains -> the I/O-psychology authority and ADR 0256 the extensible Voice-combination -> contract. RankWeave, ThreadWeave, TEPP, and lowercase canonical -> `ContextualWisdomLab/disksage` retain their own bounded responsibilities. -> PR #1041 remains Draft; earlier overlays below are dated historical evidence only. - -''' - path.write_text(title + overlay + text[marker_index:], encoding="utf-8") + if not text.startswith(title) or marker not in text: + raise SystemExit("unexpected baseline shape") + overlay = base64.b64decode(os.environ["OVERLAY_B64"]).decode("utf-8") + path.write_text(title + overlay + text[text.index(marker):], encoding="utf-8") PY - git diff --check - test "$(git status --short docs/product-technical-gap-baseline.md | wc -l)" -eq 1 git rm .github/workflows/automation-1041-gap-refresh-0648.yml git add docs/product-technical-gap-baseline.md git config user.name "LineageWeave maintenance" git config user.email "41898282+github-actions[bot]@users.noreply.github.com" git commit -m "docs(gaps): refresh terminal Strix security evidence" - git remote set-url origin "https://x-access-token:${GITHUB_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" git push origin HEAD:codex/gap-loop-20260912 From b601d497a6f2714707a10da9280767b92c07ca1e Mon Sep 17 00:00:00 2001 From: LineageWeave maintenance <41898282+github-actions[bot]@users.noreply.github.com> Date: Sat, 12 Sep 2026 21:56:35 +0000 Subject: [PATCH 019/276] docs(gaps): refresh terminal Strix security evidence --- .../automation-1041-gap-refresh-0648.yml | 48 ------------ docs/product-technical-gap-baseline.md | 74 ++++++++++--------- 2 files changed, 38 insertions(+), 84 deletions(-) delete mode 100644 .github/workflows/automation-1041-gap-refresh-0648.yml diff --git a/.github/workflows/automation-1041-gap-refresh-0648.yml b/.github/workflows/automation-1041-gap-refresh-0648.yml deleted file mode 100644 index 1eb95664e..000000000 --- a/.github/workflows/automation-1041-gap-refresh-0648.yml +++ /dev/null @@ -1,48 +0,0 @@ -name: Bounded gap baseline refresh - -on: - push: - branches: - - codex/gap-loop-20260912 - paths: - - .github/workflows/automation-1041-gap-refresh-0648.yml - -permissions: - contents: write - -jobs: - refresh: - runs-on: ubuntu-24.04 - steps: - - name: Checkout exact pushed branch head - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # actions/checkout@v7 - with: - ref: codex/gap-loop-20260912 - fetch-depth: 0 - persist-credentials: true - - - name: Refresh only the live overlay and remove this workflow - env: - OVERLAY_B64: PiBFeGFjdC1oZWFkIGxvb3Agb3ZlcmxheTogMjAyNi0wOS0xMyAwNjo0OCBLU1QuIFByb3RlY3RlZCBgbWFpbmAgcmVtYWlucwo+IGA4M2ViYTU2MTQ5ZWI4MDJjZDYzNjQyYzUwN2MzMjRjOTk3NmVjNzhlYCAodjIuMjguMDsgIzkzMSkuIEZyZXNoIGxpdmUKPiBzZWFyY2ggcmVwb3J0cyAxNTcgb3BlbiBQUnMgYW5kIDM2IG9wZW4gaXNzdWVzOyBhbGwgMTU3IG9wZW4gUFJzIGFyZSBEcmFmdC4KPiBDYW5kaWRhdGUgc3RhdGUgaXMgb3BlcmF0aW9uYWwgZXZpZGVuY2UsIG5vdCBwcm90ZWN0ZWQtbWFpbiBjYXBhYmlsaXR5Lgo+Cj4gQ3VzdG9tZXIgTWFzdGVyIHByb2Nlc3MtdW5pdCBhdXRob3JpemF0aW9uIHJlbWFpbnMgb3duZWQgYnkgaXNzdWUgIzEwNDUgLyBEcmFmdAo+IFBSICMxMDQyIGF0IGV4YWN0IGBkMzllYzhjZGZhMTE2NGNlMmVmYTJiYjg3YTgzNmEwZDIyMDM3MTgxYC4KPiBSZXBvc2l0b3J5IFRlc3RzLCBTZWN1cml0eSBhbmQgU0FTVCBhcmUgR1JFRU4sIHdoaWxlIFJlcXVpcmVkIENvZGVRTCBhbmQgTm9lbWEKPiBhcmUgbm9uLUdSRUVOLiBFeGFjdC1oZWFkIFN0cml4IHJ1biAzNDcwNDc0MDU1NCBpcyBub3cgdGVybWluYWwgRkFJTFVSRSBhZnRlcgo+IHN1Y2Nlc3NmdWwgYWRtaXNzaW9uL21hdGVyaWFsaXphdGlvbi9jb250ZXh0dWFsLW9yY2hlc3RyYXRvciBzZXR1cDsgaXRzIHJldGFpbmVkCj4gYHN0cml4LXJlcG9ydHNgIGFydGlmYWN0IGlzIHNoYTI1Ngo+IGBiY2RjMTNiNzZhZGY0YTJiNWI5Y2JiY2FiMmRlMjE3ZGIyZTI1ZjQ0NWY2OWQyZGUyMGE3ZDlmNGNkZjE5YjcyYC4KPiAjMTA0MiByZXR1cm5lZCB0byBEcmFmdCB3aXRob3V0IG1vdmluZyBzb3VyY2UgaGVhZC4KPgo+IFRoZSByZXRhaW5lZCAjMTA0MiBTdHJpeCBhcnRpZmFjdCBwcm9kdWNlZCBmaXZlIHNvdXJjZS10cmFjZWQgc2VjdXJpdHkgZmluZGluZ3MuCj4gUGVyc2lzdGVkIFBvc3QgQ2hhdCBjaXRlZC1zb3VyY2UgcmVwbGF5IGRpc2Nsb3N1cmUgaXMgdGhlIHNhbWUgY2F1c2FsIGRlZmVjdAo+IGFscmVhZHkgb3duZWQgYnkgIzEwNDQgLyBEcmFmdCBQUiAjMTA0Nywgc28gIzEwNDQgcmVjb3JkcyB0aGUgaW5kZXBlbmRlbnQKPiBjb3Jyb2JvcmF0aW9uIGluc3RlYWQgb2YgY3JlYXRpbmcgYSBjb21wZXRpbmcgcmVwbGF5IGxhbmUuIE5ldyBpc3N1ZXMgIzEwNTAsCj4gIzEwNTEsICMxMDUyIGFuZCAjMTA1MyBvd24sIHJlc3BlY3RpdmVseTogbWl4ZWQtdmlzaWJpbGl0eSBwZXJpb2QtcmVwb3J0Cj4gYWdncmVnYXRlIGRpc2Nsb3N1cmU7IHVuYm91bmRlZCBkdXJhYmxlIFJFU1QgR2xvYmFsIEFzayBhZG1pc3Npb247IGNyb3NzLXRlbmFudAo+IEN1c3RvbWVyIE1hc3RlciBjdXN0b21lci1oaW50IGV2aWRlbmNlL3JlYmluZDsgYW5kIFBvc3QgQ2hhdCBzaGFyZWQtcGVyc2lzdGVuY2UKPiBtdXRhdGlvbiBhdXRob3JpdHkuIFRoZXNlIGxhbmVzIG11c3QgcmVwcm9kdWNlIHRoZWlyIG93biBSRURzOyBnZW5lcmF0ZWQgU3RyaXgKPiBwYXRjaCBzdWdnZXN0aW9ucyBhcmUgbm90IGFjY2VwdGVkIGFzIHNvdXJjZSBhdXRob3JpdHkuCj4KPiBQZXJzaXN0ZWQgUG9zdCBDaGF0IHJlcGxheSBhdXRob3JpemF0aW9uIHJlbWFpbnMgRHJhZnQgUFIgIzEwNDcgYXQgZXhhY3QKPiBgNDFjN2E4NmY3OGRkZGYwYmNkOWU5ZjBlYjA3MGJmOTA3MzJmNjhlM2AuIFJlcG9zaXRvcnkgVGVzdHMsIFNlY3VyaXR5LAo+IFNBU1QsIGR5bmFtaWMgQ29kZVFMIGFuZCBDb2RlIFF1YWxpdHkgYXJlIEdSRUVOIHRoZXJlLCB3aGlsZSBSZXF1aXJlZCBDb2RlUUwsCj4gT3BlbkNvZGUsIE5vZW1hIGFuZCBTdHJpeCBhcmUgdGVybWluYWwgRkFJTFVSRS4gIzEwNDcgdGhlcmVmb3JlIGhhcyBubyBsaXZlCj4gdmFsaWRhdGlvbiBsYW5lIGFuZCBpcyBub3QgbWVyZ2UtcmVhZHkuCj4KPiBEZXBlbmRlbmN5IGFkdmlzb3J5IEdIU0EtODJmdy1nd3dxLWo3eDkgcmVtYWlucyBpc3N1ZSAjMTA0MyAvIERyYWZ0IFBSICMxMDQ2Cj4gYXQgZXhhY3QgYGY4MGMwZWM1ZjM1ZmQ0ZmMwYTg2NzEyNWJjNDZkZmQyZDJkZWU5YTlgLiBEdXBsaWNhdGUgbWlncmF0aW9uIG9yZGluYWwKPiAwMjMzIHJlbWFpbnMgaXNzdWUgIzEwNDggLyBEcmFmdCBQUiAjMTA0OSBhdCBleGFjdAo+IGA1MzIyOTcxMTkzZDFmZjRlMGFlMTNjMDU0ZDhmOTk2MTU5MzRkNGRjYDsgaXRzIHJlcG9zaXRvcnkvUG9zdGdyZVNRTCB0ZXN0cwo+IGFyZSBHUkVFTiBidXQgY2Fub25pY2FsIFJlcXVpcmVkIENvZGVRTC9Ob2VtYSBwcm9tb3Rpb24gY29udHJvbHMgYXJlIG5vdC4KPgo+IFJlbGVhc2UgbWV0YWRhdGEgaXMgc3RpbGwgaW5jb25zaXN0ZW50IG9uIHByb3RlY3RlZCBtYWluOiBgcHlwcm9qZWN0LnRvbWxgCj4gZGVjbGFyZXMgMi4yOC4wIHdoaWxlIGBsaW5lYWdld2VhdmUuX192ZXJzaW9uX19gIGRlY2xhcmVzIDIuMjAuMC4gS2VlcCB0aGlzIGFzCj4gYSByZWxlYXNlIGJsb2NrZXIgcmF0aGVyIHRoYW4gbm9ybWFsaXppbmcgaXQgaW4gZG9jdW1lbnRhdGlvbi4gQURSIDAyNTEgcmVtYWlucwo+IHRoZSBJL08tcHN5Y2hvbG9neSBhdXRob3JpdHkgYW5kIEFEUiAwMjU2IHRoZSBleHRlbnNpYmxlIFZvaWNlLWNvbWJpbmF0aW9uCj4gY29udHJhY3QuIFJhbmtXZWF2ZSwgVGhyZWFkV2VhdmUsIFRFUFAsIGFuZCBsb3dlcmNhc2UgY2Fub25pY2FsCj4gYENvbnRleHR1YWxXaXNkb21MYWIvZGlza3NhZ2VgIHJldGFpbiB0aGVpciBvd24gYm91bmRlZCByZXNwb25zaWJpbGl0aWVzLgo+IFBSICMxMDQxIHJlbWFpbnMgRHJhZnQ7IGVhcmxpZXIgb3ZlcmxheXMgYmVsb3cgYXJlIGRhdGVkIGhpc3RvcmljYWwgZXZpZGVuY2Ugb25seS4KCg== - run: | - set -euo pipefail - python - <<'PY' - import base64 - import os - from pathlib import Path - path = Path("docs/product-technical-gap-baseline.md") - text = path.read_text(encoding="utf-8") - title = "# Product & Technical Gap Baseline\n\n" - marker = "> Exact-head loop overlay: 2026-08-29 13:20 KST." - if not text.startswith(title) or marker not in text: - raise SystemExit("unexpected baseline shape") - overlay = base64.b64decode(os.environ["OVERLAY_B64"]).decode("utf-8") - path.write_text(title + overlay + text[text.index(marker):], encoding="utf-8") - PY - git diff --check - git rm .github/workflows/automation-1041-gap-refresh-0648.yml - git add docs/product-technical-gap-baseline.md - git config user.name "LineageWeave maintenance" - git config user.email "41898282+github-actions[bot]@users.noreply.github.com" - git commit -m "docs(gaps): refresh terminal Strix security evidence" - git push origin HEAD:codex/gap-loop-20260912 diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index f6d4d48e0..3a5e8a662 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,46 +1,48 @@ # Product & Technical Gap Baseline -> Exact-head loop overlay: 2026-09-13 04:48 KST. Protected `main` remains +> Exact-head loop overlay: 2026-09-13 06:48 KST. Protected `main` remains > `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). Fresh live -> search reports 157 open PRs and 32 open issues. These counts and every -> candidate state below are operational evidence, not protected-main capability. +> search reports 157 open PRs and 36 open issues; all 157 open PRs are Draft. +> Candidate state is operational evidence, not protected-main capability. > -> Customer Master hierarchy PR #996 remains Draft at exact -> `a640df40839ed7e2a15b9ab95a7f86faa050a248`; its interrupted prior Ready -> admission is not a full repository receipt. Process-unit authorization is -> owned separately by issue #1045 / Ready PR #1042 at exact -> `d39ec8cdfa1164ce2efa2bb87a836a0d22037181`. Repository Tests, Security, -> and SAST are GREEN there, while canonical promotion gates are incomplete and -> exact-head Strix run 34704740554 is still executing `Run Strix (quick)`. -> Do not copy that authorization rule into hierarchy presentation code. +> Customer Master process-unit authorization remains owned by issue #1045 / Draft +> PR #1042 at exact `d39ec8cdfa1164ce2efa2bb87a836a0d22037181`. +> Repository Tests, Security and SAST are GREEN, while Required CodeQL and Noema +> are non-GREEN. Exact-head Strix run 34704740554 is now terminal FAILURE after +> successful admission/materialization/contextual-orchestrator setup; its retained +> `strix-reports` artifact is sha256 +> `bcdc13b76adf4a2b5b9cbbcab2de217db2e25f445f69d2de20a7d9f4cdf19b72`. +> #1042 returned to Draft without moving source head. > -> Persisted Post Chat replay authorization is owned by issue #1044 / Ready PR -> #1047 at exact `41c7a86f78dddf0bcd9e9f0eb070bf90732f68e3`. -> The consumer now delegates captured-source authorization to the literal-query -> repository operation in `post_eligibility.py`; the predecessor full suite -> exposed one stale contract that still required the consumer to mention -> `source_post_scope_sql`. That contract has been repaired to assert owner -> delegation instead, and fresh exact-head Tests run 34715131667 is active. -> Ready means validation admission only; it is not merge readiness. +> The retained #1042 Strix artifact produced five source-traced security findings. +> Persisted Post Chat cited-source replay disclosure is the same causal defect +> already owned by #1044 / Draft PR #1047, so #1044 records the independent +> corroboration instead of creating a competing replay lane. New issues #1050, +> #1051, #1052 and #1053 own, respectively: mixed-visibility period-report +> aggregate disclosure; unbounded durable REST Global Ask admission; cross-tenant +> Customer Master customer-hint evidence/rebind; and Post Chat shared-persistence +> mutation authority. These lanes must reproduce their own REDs; generated Strix +> patch suggestions are not accepted as source authority. > -> Dependency advisory GHSA-82fw-gwwq-j7x9 remains owned by issue #1043 / -> Draft PR #1046 at exact `f80c0ec5f35fd4fc0a867125bc46dfd2d2dee9a9`. -> Duplicate migration ordinal 0233 remains owned by issue #1048 / Draft PR -> #1049 at exact `5322971193d1ff4e0ae13c054d8f99615934d4dc`. -> #1049's repository Tests, including its real-PostgreSQL repeated production -> `migrate.sh` rehearsal, are GREEN, but all exact-head workflows are terminal -> with Required CodeQL PR 34712361297 and Required Noema 34712358391 failed; -> repository-local GREEN therefore cannot promote the migration repair. +> Persisted Post Chat replay authorization remains Draft PR #1047 at exact +> `41c7a86f78dddf0bcd9e9f0eb070bf90732f68e3`. Repository Tests, Security, +> SAST, dynamic CodeQL and Code Quality are GREEN there, while Required CodeQL, +> OpenCode, Noema and Strix are terminal FAILURE. #1047 therefore has no live +> validation lane and is not merge-ready. > -> Release metadata is still internally inconsistent on protected main: -> `pyproject.toml` declares 2.28.0 while `lineageweave.__version__` declares -> 2.20.0. Keep this as a release blocker rather than normalizing it in a docs -> candidate. ADR 0251 remains the I/O-psychology authority and ADR 0256 the -> extensible Voice-combination contract. RankWeave, ThreadWeave, TEPP, and -> lowercase canonical `ContextualWisdomLab/disksage` retain their own bounded -> responsibilities. PR #1041 itself remains Draft; its exact head belongs in PR -> metadata rather than a self-referential document SHA. Earlier overlays below -> are dated historical evidence only. +> Dependency advisory GHSA-82fw-gwwq-j7x9 remains issue #1043 / Draft PR #1046 +> at exact `f80c0ec5f35fd4fc0a867125bc46dfd2d2dee9a9`. Duplicate migration ordinal +> 0233 remains issue #1048 / Draft PR #1049 at exact +> `5322971193d1ff4e0ae13c054d8f99615934d4dc`; its repository/PostgreSQL tests +> are GREEN but canonical Required CodeQL/Noema promotion controls are not. +> +> Release metadata is still inconsistent on protected main: `pyproject.toml` +> declares 2.28.0 while `lineageweave.__version__` declares 2.20.0. Keep this as +> a release blocker rather than normalizing it in documentation. ADR 0251 remains +> the I/O-psychology authority and ADR 0256 the extensible Voice-combination +> contract. RankWeave, ThreadWeave, TEPP, and lowercase canonical +> `ContextualWisdomLab/disksage` retain their own bounded responsibilities. +> PR #1041 remains Draft; earlier overlays below are dated historical evidence only. > Exact-head loop overlay: 2026-08-29 13:20 KST. Protected `main` is > `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map From df6f20dc7d98c2ddf001b10b8d3b1a59f0f7c9bd Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 07:00:49 +0900 Subject: [PATCH 020/276] chore: stage current gap baseline refresh --- .../automation-1041-gap-refresh-0701.yml | 48 +++++++++++++++++++ 1 file changed, 48 insertions(+) create mode 100644 .github/workflows/automation-1041-gap-refresh-0701.yml diff --git a/.github/workflows/automation-1041-gap-refresh-0701.yml b/.github/workflows/automation-1041-gap-refresh-0701.yml new file mode 100644 index 000000000..3214235dd --- /dev/null +++ b/.github/workflows/automation-1041-gap-refresh-0701.yml @@ -0,0 +1,48 @@ +name: Current gap baseline refresh + +on: + push: + branches: + - codex/gap-loop-20260912 + paths: + - .github/workflows/automation-1041-gap-refresh-0701.yml + +permissions: + contents: write + +jobs: + refresh: + runs-on: ubuntu-24.04 + steps: + - name: Checkout exact branch head + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # actions/checkout@v7 + with: + ref: codex/gap-loop-20260912 + fetch-depth: 0 + persist-credentials: true + + - name: Replace live overlay and remove this workflow + env: + OVERLAY_B64: PiBFeGFjdC1oZWFkIGxvb3Agb3ZlcmxheTogMjAyNi0wOS0xMyAwNzowMSBLU1QuIFByb3RlY3RlZCBgbWFpbmAgcmVtYWlucwo+IGA4M2ViYTU2MTQ5ZWI4MDJjZDYzNjQyYzUwN2MzMjRjOTk3NmVjNzhlYCAodjIuMjguMDsgIzkzMSkuIEZyZXNoIGxpdmUKPiBzZWFyY2ggcmVwb3J0cyAxNTggb3BlbiBQUnMgYW5kIDM2IG9wZW4gaXNzdWVzLiBFeGFjdGx5IG9uZSBvcGVuIFBSIGlzCj4gbm9uLURyYWZ0OiAjMTA0MiwgYW5kIGl0cyBSZWFkeSBzdGF0ZSBpcyB2YWxpZGF0aW9uIGFkbWlzc2lvbiBvbmx5Lgo+Cj4gQ3VzdG9tZXIgTWFzdGVyIHByb2Nlc3MtdW5pdCBhdXRob3JpemF0aW9uIHJlbWFpbnMgaXNzdWUgIzEwNDUgLyBQUiAjMTA0Mi4KPiBBZnRlciBwcmVkZWNlc3NvciBTdHJpeCBgMzQ3MDQ3NDA1NTRgIHRlcm1pbmFsaXplZCBGQUlMVVJFLCB0aGUgcmVtYWluaW5nCj4gQ29kZVJhYmJpdCB0b3VjaGVkLXN1cmZhY2UgZG9jc3RyaW5nIHdhcm5pbmcgd2FzIHJlcGFpcmVkIGJ5IG9yZGluYXJ5IGNvbW1pdHMuCj4gQ3VycmVudCAjMTA0MiBleGFjdCBoZWFkIGlzIGA4OGZhMTYwNWNjYmM1MmE5NzI5MTcwMTlhOWVmMDVmNmE1ZDNkMDI2YDsKPiBUZXN0cyBgMzQ3MjEzMDU0NDFgIGlzIGluIHByb2dyZXNzIGFuZCBjdXJyZW50LWhlYWQgQ29kZVFML1NlY3VyaXR5L1NBU1QgYXJlCj4gcXVldWVkLiBQcmVkZWNlc3NvciByZWNlaXB0cyBkbyBub3QgdHJhbnNmZXIgdG8gdGhpcyBjYXVzYWwgaGVhZC4gUmV0dXJuICMxMDQyCj4gdG8gRHJhZnQgd2hlbiB0aGVzZSBsYW5lcyB0ZXJtaW5hbGl6ZSB1bmxlc3MgZXZlcnkgYXV0aG9yaXRhdGl2ZSBnYXRlIGlzIEdSRUVOLgo+Cj4gVGhlIHJldGFpbmVkIHByZWRlY2Vzc29yIFN0cml4IGFydGlmYWN0IHJlbWFpbnMgc2hhMjU2Cj4gYGJjZGMxM2I3NmFkZjRhMmI1YjljYmJjYWIyZGUyMTdkYjJlMjVmNDQ1ZjY5ZDJkZTIwYTdkOWY0Y2RmMTliNzJgLgo+IEl0cyBwZXJzaXN0ZWQgUG9zdCBDaGF0IGNpdGVkLXNvdXJjZSBkaXNjbG9zdXJlIGNvcnJvYm9yYXRlcyBleGlzdGluZyAjMTA0NCAvCj4gRHJhZnQgUFIgIzEwNDcuIFNlcGFyYXRlIGlzc3VlcyAjMTA1MCwgIzEwNTEsICMxMDUyIGFuZCAjMTA1MyBvd24gbWl4ZWQtCj4gdmlzaWJpbGl0eSByZXBvcnQgYWdncmVnYXRlcywgUkVTVC9zaGFyZWQgR2xvYmFsIEFzayBhZG1pc3Npb24sIEN1c3RvbWVyIE1hc3Rlcgo+IGN1c3RvbWVyLWhpbnQgdGVuYW50IHNjb3BpbmcvcmViaW5kLCBhbmQgUG9zdCBDaGF0IHNoYXJlZC1wZXJzaXN0ZW5jZSBtdXRhdGlvbi4KPgo+ICMxMDUwIG5vdyBoYXMgZXhlY3V0YWJsZSBEcmFmdCBSRUQgUFIgIzEwNTQgYXQgZXhhY3QKPiBgZjI0ODFmYjMwMTM0NDAxN2VhYWI0OTcxZGJjNzM0NTExZWNlN2QxMGAuIEl0IHByb3ZlcyB0aGF0IHJlcG9ydCBsaXN0LAo+IGRldGFpbCBhbmQgY29tcGFyaXNvbiBwYXRocyBtdXN0IHN1cHByZXNzIHByZWNvbXB1dGVkIGFnZ3JlZ2F0ZXMgd2hlbiBhbnkgc3RvcmVkCj4gY29udHJpYnV0b3Igb3IgbGVmdG92ZXItcGFpciBldmlkZW5jZSBpcyBub3QgdmlzaWJsZSwgd2hpbGUgcHJlc2VydmluZyBhIGZ1bGx5Cj4gdmlzaWJsZSBhZ2dyZWdhdGUuIFRoZSBtaW5pbWFsIHByb2R1Y3Rpb24gZml4IGFuZCBhdXRoZW50aWNhdGVkIFBvc3RncmVTUUwvSFRUUAo+IGV2aWRlbmNlIGFyZSBzdGlsbCBhYnNlbnQsIHNvICMxMDU0IGlzIGRlbGliZXJhdGVseSBub3QgbWVyZ2UtcmVhZHkuIERvIG5vdAo+IHJlY29tcHV0ZSBwc3ljaG9tZXRyaWMgdHJ1dGggb3ZlciB0aGUgdmlzaWJsZSBzdWJzZXQ7IGZhc3QtbWxzaXJtL1RFUFAgcmVtYWluCj4gbWVhc3VyZW1lbnQgb3duZXJzLgo+Cj4gUGVyc2lzdGVkIFBvc3QgQ2hhdCByZXBsYXkgYXV0aG9yaXphdGlvbiByZW1haW5zIERyYWZ0IFBSICMxMDQ3IGF0IGV4YWN0Cj4gYDQxYzdhODZmNzhkZGRmMGJjZDllOWYwZWIwNzBiZjkwNzMyZjY4ZTNgLiBSZXBvc2l0b3J5IFRlc3RzLCBTZWN1cml0eSwKPiBTQVNULCBkeW5hbWljIENvZGVRTCBhbmQgQ29kZSBRdWFsaXR5IGFyZSBHUkVFOCB0aGVyZSwgd2hpbGUgUmVxdWlyZWQgQ29kZVFMLAo+IE9wZW5Db2RlLCBOb2VtYSBhbmQgU3RyaXggYXJlIHRlcm1pbmFsIEZBSUxVUkUuCj4KPiBEZXBlbmRlbmN5IGFkdmlzb3J5IEdIU0EtODJmdy1nd3dxLWo3eDkgcmVtYWlucyBpc3N1ZSAjMTA0MyAvIERyYWZ0IFBSICMxMDQ2Cj4gYXQgYGY4MGMwZWM1ZjM1ZmQ0ZmMwYTg2NzEyNWJjNDZkZmQyZDJkZWU5YTlgLiBEdXBsaWNhdGUgbWlncmF0aW9uIG9yZGluYWwKPiAwMjMzIHJlbWFpbnMgaXNzdWUgIzEwNDggLyBEcmFmdCBQUiAjMTA0OSBhdAo+IGA1MzIyOTcxMTkzZDFmZjRlMGFlMTNjMDU0ZDhmOTk2MTU5MzRkNGRjYC4KPgo+IFByb3RlY3RlZC1tYWluIHJlbGVhc2UgbWV0YWRhdGEgaXMgc3RpbGwgaW5jb25zaXN0ZW50OiBgcHlwcm9qZWN0LnRvbWxgIGRlY2xhcmVzCj4gMi4yOC4wIHdoaWxlIGBsaW5lYWdld2VhdmUuX192ZXJzaW9uX19gIGRlY2xhcmVzIDIuMjAuMC4gS2VlcCB0aGlzIGFzIGEgcmVsZWFzZQo+IGJsb2NrZXIgcmF0aGVyIHRoYW4gbm9ybWFsaXppbmcgaXQgaW4gZG9jdW1lbnRhdGlvbi4gQURSIDAyNTEgcmVtYWlucyB0aGUgSS9PLQo+IHBzeWNob2xvZ3kgYXV0aG9yaXR5IGFuZCBBRFIgMDI1NiB0aGUgZXh0ZW5zaWJsZSBWb2ljZS1jb21iaW5hdGlvbiBjb250cmFjdC4KPiBSYW5rV2VhdmUsIFRocmVhZFdlYXZlLCBURVBQLCBhbmQgY2Fub25pY2FsIGxvd2VyY2FzZQo+IGBDb250ZXh0dWFsV2lzZG9tTGFiL2Rpc2tzYWdlYCByZXRhaW4gdGhlaXIgb3duIGJvdW5kZWQgcmVzcG9uc2liaWxpdGllcy4KPiBQUiAjMTA0MSByZW1haW5zIERyYWZ0OyBlYXJsaWVyIG92ZXJsYXlzIGJlbG93IGFyZSBkYXRlZCBoaXN0b3JpY2FsIGV2aWRlbmNlIG9ubHkuCgo= + run: | + set -euo pipefail + python - <<'PY' + import base64 + import os + from pathlib import Path + path = Path("docs/product-technical-gap-baseline.md") + text = path.read_text(encoding="utf-8") + title = "# Product & Technical Gap Baseline\n\n" + marker = "> Exact-head loop overlay: 2026-08-29 13:20 KST." + if not text.startswith(title) or marker not in text: + raise SystemExit("unexpected baseline shape") + overlay = base64.b64decode(os.environ["OVERLAY_B64"]).decode("utf-8") + path.write_text(title + overlay + text[text.index(marker):], encoding="utf-8") + PY + git diff --check + git rm .github/workflows/automation-1041-gap-refresh-0701.yml + git add docs/product-technical-gap-baseline.md + git config user.name "LineageWeave maintenance" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + git commit -m "docs(gaps): record fresh security repair lanes" + git push origin HEAD:codex/gap-loop-20260912 From 7610827d4c21e1bc649c78748d302ee8ea0ef19d Mon Sep 17 00:00:00 2001 From: LineageWeave maintenance <41898282+github-actions[bot]@users.noreply.github.com> Date: Sat, 12 Sep 2026 22:05:32 +0000 Subject: [PATCH 021/276] docs(gaps): record fresh security repair lanes --- .../automation-1041-gap-refresh-0701.yml | 48 -------------- docs/product-technical-gap-baseline.md | 65 ++++++++++--------- 2 files changed, 34 insertions(+), 79 deletions(-) delete mode 100644 .github/workflows/automation-1041-gap-refresh-0701.yml diff --git a/.github/workflows/automation-1041-gap-refresh-0701.yml b/.github/workflows/automation-1041-gap-refresh-0701.yml deleted file mode 100644 index 3214235dd..000000000 --- a/.github/workflows/automation-1041-gap-refresh-0701.yml +++ /dev/null @@ -1,48 +0,0 @@ -name: Current gap baseline refresh - -on: - push: - branches: - - codex/gap-loop-20260912 - paths: - - .github/workflows/automation-1041-gap-refresh-0701.yml - -permissions: - contents: write - -jobs: - refresh: - runs-on: ubuntu-24.04 - steps: - - name: Checkout exact branch head - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # actions/checkout@v7 - with: - ref: codex/gap-loop-20260912 - fetch-depth: 0 - persist-credentials: true - - - name: Replace live overlay and remove this workflow - env: - OVERLAY_B64: PiBFeGFjdC1oZWFkIGxvb3Agb3ZlcmxheTogMjAyNi0wOS0xMyAwNzowMSBLU1QuIFByb3RlY3RlZCBgbWFpbmAgcmVtYWlucwo+IGA4M2ViYTU2MTQ5ZWI4MDJjZDYzNjQyYzUwN2MzMjRjOTk3NmVjNzhlYCAodjIuMjguMDsgIzkzMSkuIEZyZXNoIGxpdmUKPiBzZWFyY2ggcmVwb3J0cyAxNTggb3BlbiBQUnMgYW5kIDM2IG9wZW4gaXNzdWVzLiBFeGFjdGx5IG9uZSBvcGVuIFBSIGlzCj4gbm9uLURyYWZ0OiAjMTA0MiwgYW5kIGl0cyBSZWFkeSBzdGF0ZSBpcyB2YWxpZGF0aW9uIGFkbWlzc2lvbiBvbmx5Lgo+Cj4gQ3VzdG9tZXIgTWFzdGVyIHByb2Nlc3MtdW5pdCBhdXRob3JpemF0aW9uIHJlbWFpbnMgaXNzdWUgIzEwNDUgLyBQUiAjMTA0Mi4KPiBBZnRlciBwcmVkZWNlc3NvciBTdHJpeCBgMzQ3MDQ3NDA1NTRgIHRlcm1pbmFsaXplZCBGQUlMVVJFLCB0aGUgcmVtYWluaW5nCj4gQ29kZVJhYmJpdCB0b3VjaGVkLXN1cmZhY2UgZG9jc3RyaW5nIHdhcm5pbmcgd2FzIHJlcGFpcmVkIGJ5IG9yZGluYXJ5IGNvbW1pdHMuCj4gQ3VycmVudCAjMTA0MiBleGFjdCBoZWFkIGlzIGA4OGZhMTYwNWNjYmM1MmE5NzI5MTcwMTlhOWVmMDVmNmE1ZDNkMDI2YDsKPiBUZXN0cyBgMzQ3MjEzMDU0NDFgIGlzIGluIHByb2dyZXNzIGFuZCBjdXJyZW50LWhlYWQgQ29kZVFML1NlY3VyaXR5L1NBU1QgYXJlCj4gcXVldWVkLiBQcmVkZWNlc3NvciByZWNlaXB0cyBkbyBub3QgdHJhbnNmZXIgdG8gdGhpcyBjYXVzYWwgaGVhZC4gUmV0dXJuICMxMDQyCj4gdG8gRHJhZnQgd2hlbiB0aGVzZSBsYW5lcyB0ZXJtaW5hbGl6ZSB1bmxlc3MgZXZlcnkgYXV0aG9yaXRhdGl2ZSBnYXRlIGlzIEdSRUVOLgo+Cj4gVGhlIHJldGFpbmVkIHByZWRlY2Vzc29yIFN0cml4IGFydGlmYWN0IHJlbWFpbnMgc2hhMjU2Cj4gYGJjZGMxM2I3NmFkZjRhMmI1YjljYmJjYWIyZGUyMTdkYjJlMjVmNDQ1ZjY5ZDJkZTIwYTdkOWY0Y2RmMTliNzJgLgo+IEl0cyBwZXJzaXN0ZWQgUG9zdCBDaGF0IGNpdGVkLXNvdXJjZSBkaXNjbG9zdXJlIGNvcnJvYm9yYXRlcyBleGlzdGluZyAjMTA0NCAvCj4gRHJhZnQgUFIgIzEwNDcuIFNlcGFyYXRlIGlzc3VlcyAjMTA1MCwgIzEwNTEsICMxMDUyIGFuZCAjMTA1MyBvd24gbWl4ZWQtCj4gdmlzaWJpbGl0eSByZXBvcnQgYWdncmVnYXRlcywgUkVTVC9zaGFyZWQgR2xvYmFsIEFzayBhZG1pc3Npb24sIEN1c3RvbWVyIE1hc3Rlcgo+IGN1c3RvbWVyLWhpbnQgdGVuYW50IHNjb3BpbmcvcmViaW5kLCBhbmQgUG9zdCBDaGF0IHNoYXJlZC1wZXJzaXN0ZW5jZSBtdXRhdGlvbi4KPgo+ICMxMDUwIG5vdyBoYXMgZXhlY3V0YWJsZSBEcmFmdCBSRUQgUFIgIzEwNTQgYXQgZXhhY3QKPiBgZjI0ODFmYjMwMTM0NDAxN2VhYWI0OTcxZGJjNzM0NTExZWNlN2QxMGAuIEl0IHByb3ZlcyB0aGF0IHJlcG9ydCBsaXN0LAo+IGRldGFpbCBhbmQgY29tcGFyaXNvbiBwYXRocyBtdXN0IHN1cHByZXNzIHByZWNvbXB1dGVkIGFnZ3JlZ2F0ZXMgd2hlbiBhbnkgc3RvcmVkCj4gY29udHJpYnV0b3Igb3IgbGVmdG92ZXItcGFpciBldmlkZW5jZSBpcyBub3QgdmlzaWJsZSwgd2hpbGUgcHJlc2VydmluZyBhIGZ1bGx5Cj4gdmlzaWJsZSBhZ2dyZWdhdGUuIFRoZSBtaW5pbWFsIHByb2R1Y3Rpb24gZml4IGFuZCBhdXRoZW50aWNhdGVkIFBvc3RncmVTUUwvSFRUUAo+IGV2aWRlbmNlIGFyZSBzdGlsbCBhYnNlbnQsIHNvICMxMDU0IGlzIGRlbGliZXJhdGVseSBub3QgbWVyZ2UtcmVhZHkuIERvIG5vdAo+IHJlY29tcHV0ZSBwc3ljaG9tZXRyaWMgdHJ1dGggb3ZlciB0aGUgdmlzaWJsZSBzdWJzZXQ7IGZhc3QtbWxzaXJtL1RFUFAgcmVtYWluCj4gbWVhc3VyZW1lbnQgb3duZXJzLgo+Cj4gUGVyc2lzdGVkIFBvc3QgQ2hhdCByZXBsYXkgYXV0aG9yaXphdGlvbiByZW1haW5zIERyYWZ0IFBSICMxMDQ3IGF0IGV4YWN0Cj4gYDQxYzdhODZmNzhkZGRmMGJjZDllOWYwZWIwNzBiZjkwNzMyZjY4ZTNgLiBSZXBvc2l0b3J5IFRlc3RzLCBTZWN1cml0eSwKPiBTQVNULCBkeW5hbWljIENvZGVRTCBhbmQgQ29kZSBRdWFsaXR5IGFyZSBHUkVFOCB0aGVyZSwgd2hpbGUgUmVxdWlyZWQgQ29kZVFMLAo+IE9wZW5Db2RlLCBOb2VtYSBhbmQgU3RyaXggYXJlIHRlcm1pbmFsIEZBSUxVUkUuCj4KPiBEZXBlbmRlbmN5IGFkdmlzb3J5IEdIU0EtODJmdy1nd3dxLWo3eDkgcmVtYWlucyBpc3N1ZSAjMTA0MyAvIERyYWZ0IFBSICMxMDQ2Cj4gYXQgYGY4MGMwZWM1ZjM1ZmQ0ZmMwYTg2NzEyNWJjNDZkZmQyZDJkZWU5YTlgLiBEdXBsaWNhdGUgbWlncmF0aW9uIG9yZGluYWwKPiAwMjMzIHJlbWFpbnMgaXNzdWUgIzEwNDggLyBEcmFmdCBQUiAjMTA0OSBhdAo+IGA1MzIyOTcxMTkzZDFmZjRlMGFlMTNjMDU0ZDhmOTk2MTU5MzRkNGRjYC4KPgo+IFByb3RlY3RlZC1tYWluIHJlbGVhc2UgbWV0YWRhdGEgaXMgc3RpbGwgaW5jb25zaXN0ZW50OiBgcHlwcm9qZWN0LnRvbWxgIGRlY2xhcmVzCj4gMi4yOC4wIHdoaWxlIGBsaW5lYWdld2VhdmUuX192ZXJzaW9uX19gIGRlY2xhcmVzIDIuMjAuMC4gS2VlcCB0aGlzIGFzIGEgcmVsZWFzZQo+IGJsb2NrZXIgcmF0aGVyIHRoYW4gbm9ybWFsaXppbmcgaXQgaW4gZG9jdW1lbnRhdGlvbi4gQURSIDAyNTEgcmVtYWlucyB0aGUgSS9PLQo+IHBzeWNob2xvZ3kgYXV0aG9yaXR5IGFuZCBBRFIgMDI1NiB0aGUgZXh0ZW5zaWJsZSBWb2ljZS1jb21iaW5hdGlvbiBjb250cmFjdC4KPiBSYW5rV2VhdmUsIFRocmVhZFdlYXZlLCBURVBQLCBhbmQgY2Fub25pY2FsIGxvd2VyY2FzZQo+IGBDb250ZXh0dWFsV2lzZG9tTGFiL2Rpc2tzYWdlYCByZXRhaW4gdGhlaXIgb3duIGJvdW5kZWQgcmVzcG9uc2liaWxpdGllcy4KPiBQUiAjMTA0MSByZW1haW5zIERyYWZ0OyBlYXJsaWVyIG92ZXJsYXlzIGJlbG93IGFyZSBkYXRlZCBoaXN0b3JpY2FsIGV2aWRlbmNlIG9ubHkuCgo= - run: | - set -euo pipefail - python - <<'PY' - import base64 - import os - from pathlib import Path - path = Path("docs/product-technical-gap-baseline.md") - text = path.read_text(encoding="utf-8") - title = "# Product & Technical Gap Baseline\n\n" - marker = "> Exact-head loop overlay: 2026-08-29 13:20 KST." - if not text.startswith(title) or marker not in text: - raise SystemExit("unexpected baseline shape") - overlay = base64.b64decode(os.environ["OVERLAY_B64"]).decode("utf-8") - path.write_text(title + overlay + text[text.index(marker):], encoding="utf-8") - PY - git diff --check - git rm .github/workflows/automation-1041-gap-refresh-0701.yml - git add docs/product-technical-gap-baseline.md - git config user.name "LineageWeave maintenance" - git config user.email "41898282+github-actions[bot]@users.noreply.github.com" - git commit -m "docs(gaps): record fresh security repair lanes" - git push origin HEAD:codex/gap-loop-20260912 diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 3a5e8a662..f9d728df1 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,46 +1,49 @@ # Product & Technical Gap Baseline -> Exact-head loop overlay: 2026-09-13 06:48 KST. Protected `main` remains +> Exact-head loop overlay: 2026-09-13 07:01 KST. Protected `main` remains > `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). Fresh live -> search reports 157 open PRs and 36 open issues; all 157 open PRs are Draft. -> Candidate state is operational evidence, not protected-main capability. +> search reports 158 open PRs and 36 open issues. Exactly one open PR is +> non-Draft: #1042, and its Ready state is validation admission only. > -> Customer Master process-unit authorization remains owned by issue #1045 / Draft -> PR #1042 at exact `d39ec8cdfa1164ce2efa2bb87a836a0d22037181`. -> Repository Tests, Security and SAST are GREEN, while Required CodeQL and Noema -> are non-GREEN. Exact-head Strix run 34704740554 is now terminal FAILURE after -> successful admission/materialization/contextual-orchestrator setup; its retained -> `strix-reports` artifact is sha256 +> Customer Master process-unit authorization remains issue #1045 / PR #1042. +> After predecessor Strix `34704740554` terminalized FAILURE, the remaining +> CodeRabbit touched-surface docstring warning was repaired by ordinary commits. +> Current #1042 exact head is `88fa1605ccbc52a972917019a9ef05f6a5d3d026`; +> Tests `34721305441` is in progress and current-head CodeQL/Security/SAST are +> queued. Predecessor receipts do not transfer to this causal head. Return #1042 +> to Draft when these lanes terminalize unless every authoritative gate is GREEN. +> +> The retained predecessor Strix artifact remains sha256 > `bcdc13b76adf4a2b5b9cbbcab2de217db2e25f445f69d2de20a7d9f4cdf19b72`. -> #1042 returned to Draft without moving source head. +> Its persisted Post Chat cited-source disclosure corroborates existing #1044 / +> Draft PR #1047. Separate issues #1050, #1051, #1052 and #1053 own mixed- +> visibility report aggregates, REST/shared Global Ask admission, Customer Master +> customer-hint tenant scoping/rebind, and Post Chat shared-persistence mutation. > -> The retained #1042 Strix artifact produced five source-traced security findings. -> Persisted Post Chat cited-source replay disclosure is the same causal defect -> already owned by #1044 / Draft PR #1047, so #1044 records the independent -> corroboration instead of creating a competing replay lane. New issues #1050, -> #1051, #1052 and #1053 own, respectively: mixed-visibility period-report -> aggregate disclosure; unbounded durable REST Global Ask admission; cross-tenant -> Customer Master customer-hint evidence/rebind; and Post Chat shared-persistence -> mutation authority. These lanes must reproduce their own REDs; generated Strix -> patch suggestions are not accepted as source authority. +> #1050 now has executable Draft RED PR #1054 at exact +> `f2481fb301344017eaab4971dbc734511ece7d10`. It proves that report list, +> detail and comparison paths must suppress precomputed aggregates when any stored +> contributor or leftover-pair evidence is not visible, while preserving a fully +> visible aggregate. The minimal production fix and authenticated PostgreSQL/HTTP +> evidence are still absent, so #1054 is deliberately not merge-ready. Do not +> recompute psychometric truth over the visible subset; fast-mlsirm/TEPP remain +> measurement owners. > > Persisted Post Chat replay authorization remains Draft PR #1047 at exact > `41c7a86f78dddf0bcd9e9f0eb070bf90732f68e3`. Repository Tests, Security, -> SAST, dynamic CodeQL and Code Quality are GREEN there, while Required CodeQL, -> OpenCode, Noema and Strix are terminal FAILURE. #1047 therefore has no live -> validation lane and is not merge-ready. +> SAST, dynamic CodeQL and Code Quality are GREE8 there, while Required CodeQL, +> OpenCode, Noema and Strix are terminal FAILURE. > > Dependency advisory GHSA-82fw-gwwq-j7x9 remains issue #1043 / Draft PR #1046 -> at exact `f80c0ec5f35fd4fc0a867125bc46dfd2d2dee9a9`. Duplicate migration ordinal -> 0233 remains issue #1048 / Draft PR #1049 at exact -> `5322971193d1ff4e0ae13c054d8f99615934d4dc`; its repository/PostgreSQL tests -> are GREEN but canonical Required CodeQL/Noema promotion controls are not. +> at `f80c0ec5f35fd4fc0a867125bc46dfd2d2dee9a9`. Duplicate migration ordinal +> 0233 remains issue #1048 / Draft PR #1049 at +> `5322971193d1ff4e0ae13c054d8f99615934d4dc`. > -> Release metadata is still inconsistent on protected main: `pyproject.toml` -> declares 2.28.0 while `lineageweave.__version__` declares 2.20.0. Keep this as -> a release blocker rather than normalizing it in documentation. ADR 0251 remains -> the I/O-psychology authority and ADR 0256 the extensible Voice-combination -> contract. RankWeave, ThreadWeave, TEPP, and lowercase canonical +> Protected-main release metadata is still inconsistent: `pyproject.toml` declares +> 2.28.0 while `lineageweave.__version__` declares 2.20.0. Keep this as a release +> blocker rather than normalizing it in documentation. ADR 0251 remains the I/O- +> psychology authority and ADR 0256 the extensible Voice-combination contract. +> RankWeave, ThreadWeave, TEPP, and canonical lowercase > `ContextualWisdomLab/disksage` retain their own bounded responsibilities. > PR #1041 remains Draft; earlier overlays below are dated historical evidence only. From 1d0446ea611534928354a340689fc6c51e40a238 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 07:07:14 +0900 Subject: [PATCH 022/276] chore: stage final current gap baseline refresh --- .../automation-1041-gap-refresh-0707.yml | 47 +++++++++++++++++++ 1 file changed, 47 insertions(+) create mode 100644 .github/workflows/automation-1041-gap-refresh-0707.yml diff --git a/.github/workflows/automation-1041-gap-refresh-0707.yml b/.github/workflows/automation-1041-gap-refresh-0707.yml new file mode 100644 index 000000000..2796835e7 --- /dev/null +++ b/.github/workflows/automation-1041-gap-refresh-0707.yml @@ -0,0 +1,47 @@ +name: Final current gap baseline refresh + +on: + push: + branches: + - codex/gap-loop-20260912 + paths: + - .github/workflows/automation-1041-gap-refresh-0707.yml + +permissions: + contents: write + +jobs: + refresh: + runs-on: ubuntu-24.04 + steps: + - name: Checkout exact branch head + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # actions/checkout@v7 + with: + ref: codex/gap-loop-20260912 + fetch-depth: 0 + persist-credentials: true + - name: Replace live overlay and remove this workflow + env: + OVERLAY_B64: PiBFeGFjdC1oZWFkIGxvb3Agb3ZlcmxheTogMjAyNi0wOS0xMyAwNzowNyBLU1QuIFByb3RlY3RlZCBgbWFpbmAgcmVtYWlucwo+IGA4M2ViYTU2MTQ5ZWI4MDJjZDYzNjQyYzUwN2MzMjRjOTk3NmVjNzhlYCAodjIuMjguMDsgIzkzMSkuIEZyZXNoIGxpdmUKPiBzZWFyY2ggcmVwb3J0cyAxNTggb3BlbiBQUnMgYW5kIDM2IG9wZW4gaXNzdWVzLiBFeGFjdGx5IG9uZSBvcGVuIFBSIGlzCj4gbm9uLURyYWZ0OiAjMTA0Miwgd2hvc2UgUmVhZHkgc3RhdGUgaXMgdmFsaWRhdGlvbiBhZG1pc3Npb24gb25seS4KPgo+IEN1c3RvbWVyIE1hc3RlciBwcm9jZXNzLXVuaXQgYXV0aG9yaXphdGlvbiByZW1haW5zIGlzc3VlICMxMDQ1IC8gUFIgIzEwNDIuCj4gQ3VycmVudCBleGFjdCBoZWFkIGlzIGBmMjNmNWE1NjdiZDY2MTEzNjAzODM3Zjg2ZjAzMGMzYzQ1OWU2OWU2YC4KPiBBZnRlciBwcmVkZWNlc3NvciBTdHJpeCBgMzQ3MDQ3NDA1NTRgIHRlcm1pbmFsaXplZCBGQUlMVVJFLCB0aGUgdG91Y2hlZC1zdXJmYWNlCj4gZG9jc3RyaW5nIHdhcm5pbmcgd2FzIHJlcGFpcmVkIGFuZCBDb2RlUmFiYml0IHZlcmlmaWVkIDEwMCUgZG9jc3RyaW5nIGNvdmVyYWdlLgo+IFRoZSBzYW1lIHJldmlldyB0aGVuIGZvdW5kIGEgdmFsaWQgcmVkdWNlZC1jb3ZlcmFnZSBjb2xsZWN0b3IgZGVmZWN0OiBhcmJpdHJhcnkKPiBgcHl0ZXN0Lm1hcmsuPG5hbWU+YCB2YWx1ZXMgY291bGQgbWFzcXVlcmFkZSBhcyBvcHRpb25hbC1tb2R1bGUgaW1wb3J0cy4gQ3VycmVudAo+IGhlYWQgcmVjb2duaXplcyBvbmx5IGFuIGV4cGxpY2l0IHBsdWdpbi1tYXJrZXIgbWFwIChgcHl0ZXN0Lm1hcmsuYW55aW8gLT4gYW55aW9gKQo+IGFuZCBoYXMgYSByZWdyZXNzaW9uIHByb3ZpbmcgYHB5dGVzdC5tYXJrLnJlZGlzYCBkb2VzIG5vdCBzdXBwcmVzcyBhbiB1bnJlbGF0ZWQKPiB0ZXN0IHdoZW4gUmVkaXMgaXMgYWJzZW50LiBDdXJyZW50LWhlYWQgVGVzdHMgYDM0NzIxNzIxMTU1YCwgUmVxdWlyZWQgQ29kZVFMCj4gYDM0NzIxNzIxMTEzYCwgU2VjdXJpdHkgYDM0NzIxNzIxMTY3YCwgYW5kIFNBU1QgYDM0NzIxNzIxMTg2YCBhcmUgbmV3bHkgcXVldWVkIG9yCj4gcGVuZGluZzsgcHJlZGVjZXNzb3IgcmVjZWlwdHMgZG8gbm90IHRyYW5zZmVyLgo+Cj4gVGhlIHJldGFpbmVkIHByZWRlY2Vzc29yIFN0cml4IGFydGlmYWN0IHJlbWFpbnMgc2hhMjU2Cj4gYGJjZGMxM2I3NmFkZjRhMmI1YjljYmJjYWIyZGUyMTdkYjJlMjVmNDQ1ZjY5ZDJkZTIwYTdkOWY0Y2RmMTliNzJgLgo+IEl0cyBwZXJzaXN0ZWQgUG9zdCBDaGF0IGNpdGVkLXNvdXJjZSBkaXNjbG9zdXJlIGNvcnJvYm9yYXRlcyBleGlzdGluZyAjMTA0NCAvCj4gRHJhZnQgUFIgIzEwNDcuIFNlcGFyYXRlIGlzc3VlcyAjMTA1MCwgIzEwNTEsICMxMDUyIGFuZCAjMTA1MyBvd24gbWl4ZWQtCj4gdmlzaWJpbGl0eSByZXBvcnQgYWdncmVnYXRlcywgUkVTVC9zaGFyZWQgR2xvYmFsIEFzayBhZG1pc3Npb24sIEN1c3RvbWVyIE1hc3Rlcgo+IGN1c3RvbWVyLWhpbnQgdGVuYW50IHNjb3BpbmcvcmViaW5kLCBhbmQgUG9zdCBDaGF0IHNoYXJlZC1wZXJzaXN0ZW5jZSBtdXRhdGlvbi4KPgo+ICMxMDUwIGhhcyBleGVjdXRhYmxlIERyYWZ0IFJFRCBQUiAjMTA1NCBhdCBleGFjdAo+IGA0OWE0N2M4MWViNTNjZjY1ODc3ODEzYjUzNDI0YTJlMjBhNmUxZTA1YDsgaXRzIG5ldCBjYW5kaWRhdGUgZGVsdGEgaXMgb25lCj4gcmVncmVzc2lvbiBmaWxlLiBSZXBvcnQgbGlzdCwgZGV0YWlsIGFuZCBjb21wYXJpc29uIHBhdGhzIG11c3Qgc3VwcHJlc3MgYQo+IHByZWNvbXB1dGVkIGFnZ3JlZ2F0ZSB3aGVuIGFueSBzdG9yZWQgY29udHJpYnV0b3Igb3IgbGVmdG92ZXItcGFpciBldmlkZW5jZSBpcwo+IG5vdCB2aXNpYmxlLCB3aGlsZSBwcmVzZXJ2aW5nIGEgZnVsbHkgdmlzaWJsZSBhZ2dyZWdhdGUuIEJvdW5kZWQgZGlhZ25vc3RpYyBydW4KPiBgMzQ3MjE2NDU4MDdgIHdhcyBhZG1pdHRlZCBvbiBwcmVkZWNlc3NvciBgNGQ4NDZhZmMuLi5gIGFuZCBpcyBub3QgYSBwcm9tb3Rpb24KPiByZWNlaXB0LiBUaGUgbWluaW1hbCBwcm9kdWN0aW9uIGZpeCBhbmQgYXV0aGVudGljYXRlZCBQb3N0Z3JlU1FML0hUVFAgZXZpZGVuY2UKPiByZW1haW4gYWJzZW50LiBEbyBub3QgcmVjb21wdXRlIHBzeWNob21ldHJpYyB0cnV0aCBvdmVyIHRoZSB2aXNpYmxlIHN1YnNldDsKPiBmYXN0LW1sc2lybS9URVBQIHJlbWFpbiBtZWFzdXJlbWVudCBvd25lcnMuCj4KPiBQZXJzaXN0ZWQgUG9zdCBDaGF0IHJlcGxheSBhdXRob3JpemF0aW9uIHJlbWFpbnMgRHJhZnQgUFIgIzEwNDcgYXQgZXhhY3QKPiBgNDFjN2E4NmY3OGRkZGYwYmNkOWU5ZjBlYjA3MGJmOTA3MzJmNjhlM2AuIFJlcG9zaXRvcnkgVGVzdHMsIFNlY3VyaXR5LAo+IFNBU1QsIGR5bmFtaWMgQ29kZVFMIGFuZCBDb2RlIFF1YWxpdHkgYXJlIEdSRUVOIHRoZXJlLCB3aGlsZSBSZXF1aXJlZCBDb2RlUUwsCj4gT3BlbkNvZGUsIE5vZW1hIGFuZCBTdHJpeCBhcmUgdGVybWluYWwgRkFJTFVSRS4KPgo+IERlcGVuZGVuY3kgYWR2aXNvcnkgR0hTQS04MmZ3LWd3d3Etajd4OSByZW1haW5zIGlzc3VlICMxMDQzIC8gRHJhZnQgUFIgIzEwNDYKPiBhdCBgZjgwYzBlYzVmMzVmZDRmYzBhODY3MTI1YmM0NmRmZDJkMmRlZTlhOWAuIER1cGxpY2F0ZSBtaWdyYXRpb24gb3JkaW5hbAo+IDAyMzMgcmVtYWlucyBpc3N1ZSAjMTA0OCAvIERyYWZ0IFBSICMxMDQ5IGF0Cj4gYDUzMjI5NzExOTNkMWZmNGUwYWUxM2MwNTRkOGY5OTYxNTkzNGQ0ZGNgLgo+Cj4gUHJvdGVjdGVkLW1haW4gcmVsZWFzZSBtZXRhZGF0YSBpcyBzdGlsbCBpbmNvbnNpc3RlbnQ6IGBweXByb2plY3QudG9tbGAgZGVjbGFyZXMKPiAyLjI4LjAgd2hpbGUgYGxpbmVhZ2V3ZWF2ZS5fX3ZlcnNpb25fX2AgZGVjbGFyZXMgMi4yMC4wLiBLZWVwIHRoaXMgYXMgYSByZWxlYXNlCj4gYmxvY2tlciByYXRoZXIgdGhhbiBub3JtYWxpemluZyBpdCBpbiBkb2N1bWVudGF0aW9uLiBBRFIgMDI1MSByZW1haW5zIHRoZSBJL08tCj4gcHN5Y2hvbG9neSBhdXRob3JpdHkgYW5kIEFEUiAwMjU2IHRoZSBleHRlbnNpYmxlIFZvaWNlLWNvbWJpbmF0aW9uIGNvbnRyYWN0Lgo+IFJhbmtXZWF2ZSwgVGhyZWFkV2VhdmUsIFRFUFAsIGFuZCBjYW5vbmljYWwgbG93ZXJjYXNlCj4gYENvbnRleHR1YWxXaXNkb21MYWIvZGlza3NhZ2VgIHJldGFpbiB0aGVpciBvd24gYm91bmRlZCByZXNwb25zaWJpbGl0aWVzLgo+IFBSICMxMDQxIHJlbWFpbnMgRHJhZnQ7IGVhcmxpZXIgb3ZlcmxheXMgYmVsb3cgYXJlIGRhdGVkIGhpc3RvcmljYWwgZXZpZGVuY2Ugb25seS4KCg== + run: | + set -euo pipefail + python - <<'PY' + import base64 + import os + from pathlib import Path + path = Path("docs/product-technical-gap-baseline.md") + text = path.read_text(encoding="utf-8") + title = "# Product & Technical Gap Baseline\n\n" + marker = "> Exact-head loop overlay: 2026-08-29 13:20 KST." + if not text.startswith(title) or marker not in text: + raise SystemExit("unexpected baseline shape") + overlay = base64.b64decode(os.environ["OVERLAY_B64"]).decode("utf-8") + path.write_text(title + overlay + text[text.index(marker):], encoding="utf-8") + PY + git diff --check + git rm .github/workflows/automation-1041-gap-refresh-0707.yml + git add docs/product-technical-gap-baseline.md + git config user.name "LineageWeave maintenance" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + git commit -m "docs(gaps): refresh current security evidence" + git push origin HEAD:codex/gap-loop-20260912 From 6d25dfd5b386ccf09e8cdee48ef3ef8dca67962b Mon Sep 17 00:00:00 2001 From: LineageWeave maintenance <41898282+github-actions[bot]@users.noreply.github.com> Date: Sat, 12 Sep 2026 22:13:08 +0000 Subject: [PATCH 023/276] docs(gaps): refresh current security evidence --- .../automation-1041-gap-refresh-0707.yml | 47 ------------------- docs/product-technical-gap-baseline.md | 39 ++++++++------- 2 files changed, 22 insertions(+), 64 deletions(-) delete mode 100644 .github/workflows/automation-1041-gap-refresh-0707.yml diff --git a/.github/workflows/automation-1041-gap-refresh-0707.yml b/.github/workflows/automation-1041-gap-refresh-0707.yml deleted file mode 100644 index 2796835e7..000000000 --- a/.github/workflows/automation-1041-gap-refresh-0707.yml +++ /dev/null @@ -1,47 +0,0 @@ -name: Final current gap baseline refresh - -on: - push: - branches: - - codex/gap-loop-20260912 - paths: - - .github/workflows/automation-1041-gap-refresh-0707.yml - -permissions: - contents: write - -jobs: - refresh: - runs-on: ubuntu-24.04 - steps: - - name: Checkout exact branch head - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # actions/checkout@v7 - with: - ref: codex/gap-loop-20260912 - fetch-depth: 0 - persist-credentials: true - - name: Replace live overlay and remove this workflow - env: - OVERLAY_B64: PiBFeGFjdC1oZWFkIGxvb3Agb3ZlcmxheTogMjAyNi0wOS0xMyAwNzowNyBLU1QuIFByb3RlY3RlZCBgbWFpbmAgcmVtYWlucwo+IGA4M2ViYTU2MTQ5ZWI4MDJjZDYzNjQyYzUwN2MzMjRjOTk3NmVjNzhlYCAodjIuMjguMDsgIzkzMSkuIEZyZXNoIGxpdmUKPiBzZWFyY2ggcmVwb3J0cyAxNTggb3BlbiBQUnMgYW5kIDM2IG9wZW4gaXNzdWVzLiBFeGFjdGx5IG9uZSBvcGVuIFBSIGlzCj4gbm9uLURyYWZ0OiAjMTA0Miwgd2hvc2UgUmVhZHkgc3RhdGUgaXMgdmFsaWRhdGlvbiBhZG1pc3Npb24gb25seS4KPgo+IEN1c3RvbWVyIE1hc3RlciBwcm9jZXNzLXVuaXQgYXV0aG9yaXphdGlvbiByZW1haW5zIGlzc3VlICMxMDQ1IC8gUFIgIzEwNDIuCj4gQ3VycmVudCBleGFjdCBoZWFkIGlzIGBmMjNmNWE1NjdiZDY2MTEzNjAzODM3Zjg2ZjAzMGMzYzQ1OWU2OWU2YC4KPiBBZnRlciBwcmVkZWNlc3NvciBTdHJpeCBgMzQ3MDQ3NDA1NTRgIHRlcm1pbmFsaXplZCBGQUlMVVJFLCB0aGUgdG91Y2hlZC1zdXJmYWNlCj4gZG9jc3RyaW5nIHdhcm5pbmcgd2FzIHJlcGFpcmVkIGFuZCBDb2RlUmFiYml0IHZlcmlmaWVkIDEwMCUgZG9jc3RyaW5nIGNvdmVyYWdlLgo+IFRoZSBzYW1lIHJldmlldyB0aGVuIGZvdW5kIGEgdmFsaWQgcmVkdWNlZC1jb3ZlcmFnZSBjb2xsZWN0b3IgZGVmZWN0OiBhcmJpdHJhcnkKPiBgcHl0ZXN0Lm1hcmsuPG5hbWU+YCB2YWx1ZXMgY291bGQgbWFzcXVlcmFkZSBhcyBvcHRpb25hbC1tb2R1bGUgaW1wb3J0cy4gQ3VycmVudAo+IGhlYWQgcmVjb2duaXplcyBvbmx5IGFuIGV4cGxpY2l0IHBsdWdpbi1tYXJrZXIgbWFwIChgcHl0ZXN0Lm1hcmsuYW55aW8gLT4gYW55aW9gKQo+IGFuZCBoYXMgYSByZWdyZXNzaW9uIHByb3ZpbmcgYHB5dGVzdC5tYXJrLnJlZGlzYCBkb2VzIG5vdCBzdXBwcmVzcyBhbiB1bnJlbGF0ZWQKPiB0ZXN0IHdoZW4gUmVkaXMgaXMgYWJzZW50LiBDdXJyZW50LWhlYWQgVGVzdHMgYDM0NzIxNzIxMTU1YCwgUmVxdWlyZWQgQ29kZVFMCj4gYDM0NzIxNzIxMTEzYCwgU2VjdXJpdHkgYDM0NzIxNzIxMTY3YCwgYW5kIFNBU1QgYDM0NzIxNzIxMTg2YCBhcmUgbmV3bHkgcXVldWVkIG9yCj4gcGVuZGluZzsgcHJlZGVjZXNzb3IgcmVjZWlwdHMgZG8gbm90IHRyYW5zZmVyLgo+Cj4gVGhlIHJldGFpbmVkIHByZWRlY2Vzc29yIFN0cml4IGFydGlmYWN0IHJlbWFpbnMgc2hhMjU2Cj4gYGJjZGMxM2I3NmFkZjRhMmI1YjljYmJjYWIyZGUyMTdkYjJlMjVmNDQ1ZjY5ZDJkZTIwYTdkOWY0Y2RmMTliNzJgLgo+IEl0cyBwZXJzaXN0ZWQgUG9zdCBDaGF0IGNpdGVkLXNvdXJjZSBkaXNjbG9zdXJlIGNvcnJvYm9yYXRlcyBleGlzdGluZyAjMTA0NCAvCj4gRHJhZnQgUFIgIzEwNDcuIFNlcGFyYXRlIGlzc3VlcyAjMTA1MCwgIzEwNTEsICMxMDUyIGFuZCAjMTA1MyBvd24gbWl4ZWQtCj4gdmlzaWJpbGl0eSByZXBvcnQgYWdncmVnYXRlcywgUkVTVC9zaGFyZWQgR2xvYmFsIEFzayBhZG1pc3Npb24sIEN1c3RvbWVyIE1hc3Rlcgo+IGN1c3RvbWVyLWhpbnQgdGVuYW50IHNjb3BpbmcvcmViaW5kLCBhbmQgUG9zdCBDaGF0IHNoYXJlZC1wZXJzaXN0ZW5jZSBtdXRhdGlvbi4KPgo+ICMxMDUwIGhhcyBleGVjdXRhYmxlIERyYWZ0IFJFRCBQUiAjMTA1NCBhdCBleGFjdAo+IGA0OWE0N2M4MWViNTNjZjY1ODc3ODEzYjUzNDI0YTJlMjBhNmUxZTA1YDsgaXRzIG5ldCBjYW5kaWRhdGUgZGVsdGEgaXMgb25lCj4gcmVncmVzc2lvbiBmaWxlLiBSZXBvcnQgbGlzdCwgZGV0YWlsIGFuZCBjb21wYXJpc29uIHBhdGhzIG11c3Qgc3VwcHJlc3MgYQo+IHByZWNvbXB1dGVkIGFnZ3JlZ2F0ZSB3aGVuIGFueSBzdG9yZWQgY29udHJpYnV0b3Igb3IgbGVmdG92ZXItcGFpciBldmlkZW5jZSBpcwo+IG5vdCB2aXNpYmxlLCB3aGlsZSBwcmVzZXJ2aW5nIGEgZnVsbHkgdmlzaWJsZSBhZ2dyZWdhdGUuIEJvdW5kZWQgZGlhZ25vc3RpYyBydW4KPiBgMzQ3MjE2NDU4MDdgIHdhcyBhZG1pdHRlZCBvbiBwcmVkZWNlc3NvciBgNGQ4NDZhZmMuLi5gIGFuZCBpcyBub3QgYSBwcm9tb3Rpb24KPiByZWNlaXB0LiBUaGUgbWluaW1hbCBwcm9kdWN0aW9uIGZpeCBhbmQgYXV0aGVudGljYXRlZCBQb3N0Z3JlU1FML0hUVFAgZXZpZGVuY2UKPiByZW1haW4gYWJzZW50LiBEbyBub3QgcmVjb21wdXRlIHBzeWNob21ldHJpYyB0cnV0aCBvdmVyIHRoZSB2aXNpYmxlIHN1YnNldDsKPiBmYXN0LW1sc2lybS9URVBQIHJlbWFpbiBtZWFzdXJlbWVudCBvd25lcnMuCj4KPiBQZXJzaXN0ZWQgUG9zdCBDaGF0IHJlcGxheSBhdXRob3JpemF0aW9uIHJlbWFpbnMgRHJhZnQgUFIgIzEwNDcgYXQgZXhhY3QKPiBgNDFjN2E4NmY3OGRkZGYwYmNkOWU5ZjBlYjA3MGJmOTA3MzJmNjhlM2AuIFJlcG9zaXRvcnkgVGVzdHMsIFNlY3VyaXR5LAo+IFNBU1QsIGR5bmFtaWMgQ29kZVFMIGFuZCBDb2RlIFF1YWxpdHkgYXJlIEdSRUVOIHRoZXJlLCB3aGlsZSBSZXF1aXJlZCBDb2RlUUwsCj4gT3BlbkNvZGUsIE5vZW1hIGFuZCBTdHJpeCBhcmUgdGVybWluYWwgRkFJTFVSRS4KPgo+IERlcGVuZGVuY3kgYWR2aXNvcnkgR0hTQS04MmZ3LWd3d3Etajd4OSByZW1haW5zIGlzc3VlICMxMDQzIC8gRHJhZnQgUFIgIzEwNDYKPiBhdCBgZjgwYzBlYzVmMzVmZDRmYzBhODY3MTI1YmM0NmRmZDJkMmRlZTlhOWAuIER1cGxpY2F0ZSBtaWdyYXRpb24gb3JkaW5hbAo+IDAyMzMgcmVtYWlucyBpc3N1ZSAjMTA0OCAvIERyYWZ0IFBSICMxMDQ5IGF0Cj4gYDUzMjI5NzExOTNkMWZmNGUwYWUxM2MwNTRkOGY5OTYxNTkzNGQ0ZGNgLgo+Cj4gUHJvdGVjdGVkLW1haW4gcmVsZWFzZSBtZXRhZGF0YSBpcyBzdGlsbCBpbmNvbnNpc3RlbnQ6IGBweXByb2plY3QudG9tbGAgZGVjbGFyZXMKPiAyLjI4LjAgd2hpbGUgYGxpbmVhZ2V3ZWF2ZS5fX3ZlcnNpb25fX2AgZGVjbGFyZXMgMi4yMC4wLiBLZWVwIHRoaXMgYXMgYSByZWxlYXNlCj4gYmxvY2tlciByYXRoZXIgdGhhbiBub3JtYWxpemluZyBpdCBpbiBkb2N1bWVudGF0aW9uLiBBRFIgMDI1MSByZW1haW5zIHRoZSBJL08tCj4gcHN5Y2hvbG9neSBhdXRob3JpdHkgYW5kIEFEUiAwMjU2IHRoZSBleHRlbnNpYmxlIFZvaWNlLWNvbWJpbmF0aW9uIGNvbnRyYWN0Lgo+IFJhbmtXZWF2ZSwgVGhyZWFkV2VhdmUsIFRFUFAsIGFuZCBjYW5vbmljYWwgbG93ZXJjYXNlCj4gYENvbnRleHR1YWxXaXNkb21MYWIvZGlza3NhZ2VgIHJldGFpbiB0aGVpciBvd24gYm91bmRlZCByZXNwb25zaWJpbGl0aWVzLgo+IFBSICMxMDQxIHJlbWFpbnMgRHJhZnQ7IGVhcmxpZXIgb3ZlcmxheXMgYmVsb3cgYXJlIGRhdGVkIGhpc3RvcmljYWwgZXZpZGVuY2Ugb25seS4KCg== - run: | - set -euo pipefail - python - <<'PY' - import base64 - import os - from pathlib import Path - path = Path("docs/product-technical-gap-baseline.md") - text = path.read_text(encoding="utf-8") - title = "# Product & Technical Gap Baseline\n\n" - marker = "> Exact-head loop overlay: 2026-08-29 13:20 KST." - if not text.startswith(title) or marker not in text: - raise SystemExit("unexpected baseline shape") - overlay = base64.b64decode(os.environ["OVERLAY_B64"]).decode("utf-8") - path.write_text(title + overlay + text[text.index(marker):], encoding="utf-8") - PY - git diff --check - git rm .github/workflows/automation-1041-gap-refresh-0707.yml - git add docs/product-technical-gap-baseline.md - git config user.name "LineageWeave maintenance" - git config user.email "41898282+github-actions[bot]@users.noreply.github.com" - git commit -m "docs(gaps): refresh current security evidence" - git push origin HEAD:codex/gap-loop-20260912 diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index f9d728df1..6539972b5 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,17 +1,21 @@ # Product & Technical Gap Baseline -> Exact-head loop overlay: 2026-09-13 07:01 KST. Protected `main` remains +> Exact-head loop overlay: 2026-09-13 07:07 KST. Protected `main` remains > `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). Fresh live > search reports 158 open PRs and 36 open issues. Exactly one open PR is -> non-Draft: #1042, and its Ready state is validation admission only. +> non-Draft: #1042, whose Ready state is validation admission only. > > Customer Master process-unit authorization remains issue #1045 / PR #1042. -> After predecessor Strix `34704740554` terminalized FAILURE, the remaining -> CodeRabbit touched-surface docstring warning was repaired by ordinary commits. -> Current #1042 exact head is `88fa1605ccbc52a972917019a9ef05f6a5d3d026`; -> Tests `34721305441` is in progress and current-head CodeQL/Security/SAST are -> queued. Predecessor receipts do not transfer to this causal head. Return #1042 -> to Draft when these lanes terminalize unless every authoritative gate is GREEN. +> Current exact head is `f23f5a567bd66113603837f86f030c3c459e69e6`. +> After predecessor Strix `34704740554` terminalized FAILURE, the touched-surface +> docstring warning was repaired and CodeRabbit verified 100% docstring coverage. +> The same review then found a valid reduced-coverage collector defect: arbitrary +> `pytest.mark.` values could masquerade as optional-module imports. Current +> head recognizes only an explicit plugin-marker map (`pytest.mark.anyio -> anyio`) +> and has a regression proving `pytest.mark.redis` does not suppress an unrelated +> test when Redis is absent. Current-head Tests `34721721155`, Required CodeQL +> `34721721113`, Security `34721721167`, and SAST `34721721186` are newly queued or +> pending; predecessor receipts do not transfer. > > The retained predecessor Strix artifact remains sha256 > `bcdc13b76adf4a2b5b9cbbcab2de217db2e25f445f69d2de20a7d9f4cdf19b72`. @@ -20,18 +24,19 @@ > visibility report aggregates, REST/shared Global Ask admission, Customer Master > customer-hint tenant scoping/rebind, and Post Chat shared-persistence mutation. > -> #1050 now has executable Draft RED PR #1054 at exact -> `f2481fb301344017eaab4971dbc734511ece7d10`. It proves that report list, -> detail and comparison paths must suppress precomputed aggregates when any stored -> contributor or leftover-pair evidence is not visible, while preserving a fully -> visible aggregate. The minimal production fix and authenticated PostgreSQL/HTTP -> evidence are still absent, so #1054 is deliberately not merge-ready. Do not -> recompute psychometric truth over the visible subset; fast-mlsirm/TEPP remain -> measurement owners. +> #1050 has executable Draft RED PR #1054 at exact +> `49a47c81eb53cf65877813b53424a2e20a6e1e05`; its net candidate delta is one +> regression file. Report list, detail and comparison paths must suppress a +> precomputed aggregate when any stored contributor or leftover-pair evidence is +> not visible, while preserving a fully visible aggregate. Bounded diagnostic run +> `34721645807` was admitted on predecessor `4d846afc...` and is not a promotion +> receipt. The minimal production fix and authenticated PostgreSQL/HTTP evidence +> remain absent. Do not recompute psychometric truth over the visible subset; +> fast-mlsirm/TEPP remain measurement owners. > > Persisted Post Chat replay authorization remains Draft PR #1047 at exact > `41c7a86f78dddf0bcd9e9f0eb070bf90732f68e3`. Repository Tests, Security, -> SAST, dynamic CodeQL and Code Quality are GREE8 there, while Required CodeQL, +> SAST, dynamic CodeQL and Code Quality are GREEN there, while Required CodeQL, > OpenCode, Noema and Strix are terminal FAILURE. > > Dependency advisory GHSA-82fw-gwwq-j7x9 remains issue #1043 / Draft PR #1046 From 34598ed6baab0edea8363c76924207a5aa4798b1 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 08:52:34 +0900 Subject: [PATCH 024/276] ci(docs): stage bounded baseline refresh --- .../bounded-gap-baseline-refresh.yml | 95 +++++++++++++++++++ 1 file changed, 95 insertions(+) create mode 100644 .github/workflows/bounded-gap-baseline-refresh.yml diff --git a/.github/workflows/bounded-gap-baseline-refresh.yml b/.github/workflows/bounded-gap-baseline-refresh.yml new file mode 100644 index 000000000..cb730d55c --- /dev/null +++ b/.github/workflows/bounded-gap-baseline-refresh.yml @@ -0,0 +1,95 @@ +name: Bounded gap baseline refresh + +on: + push: + branches: + - codex/gap-loop-20260912 + paths: + - .github/workflows/bounded-gap-baseline-refresh.yml + +permissions: + contents: write + +jobs: + refresh: + runs-on: ubuntu-latest + steps: + - name: Checkout exact branch head + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # actions/checkout@v7 + with: + ref: codex/gap-loop-20260912 + fetch-depth: 0 + - name: Refresh current overlay and remove bounded workflow + shell: bash + run: | + set -euo pipefail + python - <<'PY' + from pathlib import Path + + path = Path("docs/product-technical-gap-baseline.md") + text = path.read_text(encoding="utf-8") + marker = "> Exact-head loop overlay:" + first = text.index(marker) + second = text.index(marker, first + len(marker)) + overlay = """> Exact-head loop overlay: 2026-09-13 08:51 KST. Protected `main` remains + > `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). Fresh live + > search reports 158 open PRs and 36 open issues. Exactly one open PR is + > non-Draft: #1042, whose Ready state is validation admission only. + > + > Customer Master process-unit authorization remains issue #1045 / PR #1042 + > at exact `f23f5a567bd66113603837f86f030c3c459e69e6`. Repository Tests + > `34721721155`, Security `34721721167`, and SAST `34721721186` are terminal + > GREEN. Required CodeQL `34721721113`, OpenCode `34721720227`, and Noema + > `34721720347` are terminal FAILURE. Strix `34721720240` is still genuinely + > in progress on the same exact head, so the admission is preserved without + > elapsed-time cancellation or source churn. The later CodeQL producer dispatch + > succeeded only after compatibility consumers had already failed; canonical + > owner repair remains `.github#1929` and predecessor receipts do not transfer. + > + > Mixed-visibility period-report authorization remains issue #1050 / Draft PR + > #1054 at exact `4519c101f13e08c10653b95ff88d66b4ce47f0b8`. Whole-population + > admission now suppresses a precomputed report aggregate when any persisted + > member or leftover-pair contributor is not visible; comparison evidence carries + > `process_unit_id`, and authenticated Keycloak + PostgreSQL regression proves + > detail/list/comparison visible before scope contraction and suppressed after a + > contributor becomes foreign-private. Repository Tests `34723167232` is terminal + > GREEN, including the full PostgreSQL suite, and dynamic GitHub CodeQL reports no + > new alerts. Draft-push central Security `34723086654`, SAST `34723086683`, and + > Required CodeQL `34723086691` stayed `action_required`; after Ready only the + > repository Tests identity rematerialized. With no live validation lane left, + > #1054 returned to Draft on the unchanged head. Canonical lifecycle repair is + > `.github#2045`; do not use empty commits, Draft/Ready oscillation, manual status, + > or leaf-side gate weakening. + > + > Persisted Post Chat replay authorization remains Draft PR #1047 at exact + > `41c7a86f78dddf0bcd9e9f0eb070bf90732f68e3`. Repository Tests, Security, + > SAST, dynamic CodeQL and Code Quality are GREEN there, while Required CodeQL, + > OpenCode, Noema and Strix are terminal FAILURE. Dependency advisory + > GHSA-82fw-gwwq-j7x9 remains issue #1043 / Draft PR #1046 at + > `f80c0ec5f35fd4fc0a867125bc46dfd2d2dee9a9`; duplicate migration ordinal + > 0233 remains issue #1048 / Draft PR #1049 at + > `5322971193d1ff4e0ae13c054d8f99615934d4dc`. + > + > Customer Master customer-hint repair remains issue #1052. ADR 0042 requires + > source-post tenant/access ownership to stay distinct from resolved customer + > identity and provenance; do not repair that issue by rebinding + > `source_post.corporate_entity_id`. Post Chat shared-persistence mutation remains + > issue #1053 and must not duplicate #1044/#1047 replay-authorization ownership. + > + > Protected-main release metadata is still inconsistent: `pyproject.toml` declares + > 2.28.0 while `lineageweave.__version__` declares 2.20.0. Keep this as a release + > blocker rather than normalizing it in documentation. ADR 0251 remains the I/O- + > psychology authority and ADR 0256 the extensible Voice-combination contract. + > RankWeave, ThreadWeave, TEPP, and canonical lowercase + > `ContextualWisdomLab/disksage` retain their own bounded responsibilities. + > PR #1041 remains Draft; earlier overlays below are dated historical evidence only.""" + overlay = "\n".join(line.strip() for line in overlay.splitlines()) + path.write_text(text[:first] + overlay + "\n\n" + text[second:], encoding="utf-8") + PY + rm .github/workflows/bounded-gap-baseline-refresh.yml + git config user.name "lineageweave-maintainer[bot]" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + git add docs/product-technical-gap-baseline.md .github/workflows/bounded-gap-baseline-refresh.yml + git diff --cached --check + git commit -m "docs(gaps): refresh live exact-head overlay" + git push origin HEAD:codex/gap-loop-20260912 From 84de446e660dd952e4dcfaf9a73b76650c413ccb Mon Sep 17 00:00:00 2001 From: "lineageweave-maintainer[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Sat, 12 Sep 2026 23:52:44 +0000 Subject: [PATCH 025/276] docs(gaps): refresh live exact-head overlay --- .../bounded-gap-baseline-refresh.yml | 95 ------------------- docs/product-technical-gap-baseline.md | 65 ++++++------- 2 files changed, 33 insertions(+), 127 deletions(-) delete mode 100644 .github/workflows/bounded-gap-baseline-refresh.yml diff --git a/.github/workflows/bounded-gap-baseline-refresh.yml b/.github/workflows/bounded-gap-baseline-refresh.yml deleted file mode 100644 index cb730d55c..000000000 --- a/.github/workflows/bounded-gap-baseline-refresh.yml +++ /dev/null @@ -1,95 +0,0 @@ -name: Bounded gap baseline refresh - -on: - push: - branches: - - codex/gap-loop-20260912 - paths: - - .github/workflows/bounded-gap-baseline-refresh.yml - -permissions: - contents: write - -jobs: - refresh: - runs-on: ubuntu-latest - steps: - - name: Checkout exact branch head - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # actions/checkout@v7 - with: - ref: codex/gap-loop-20260912 - fetch-depth: 0 - - name: Refresh current overlay and remove bounded workflow - shell: bash - run: | - set -euo pipefail - python - <<'PY' - from pathlib import Path - - path = Path("docs/product-technical-gap-baseline.md") - text = path.read_text(encoding="utf-8") - marker = "> Exact-head loop overlay:" - first = text.index(marker) - second = text.index(marker, first + len(marker)) - overlay = """> Exact-head loop overlay: 2026-09-13 08:51 KST. Protected `main` remains - > `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). Fresh live - > search reports 158 open PRs and 36 open issues. Exactly one open PR is - > non-Draft: #1042, whose Ready state is validation admission only. - > - > Customer Master process-unit authorization remains issue #1045 / PR #1042 - > at exact `f23f5a567bd66113603837f86f030c3c459e69e6`. Repository Tests - > `34721721155`, Security `34721721167`, and SAST `34721721186` are terminal - > GREEN. Required CodeQL `34721721113`, OpenCode `34721720227`, and Noema - > `34721720347` are terminal FAILURE. Strix `34721720240` is still genuinely - > in progress on the same exact head, so the admission is preserved without - > elapsed-time cancellation or source churn. The later CodeQL producer dispatch - > succeeded only after compatibility consumers had already failed; canonical - > owner repair remains `.github#1929` and predecessor receipts do not transfer. - > - > Mixed-visibility period-report authorization remains issue #1050 / Draft PR - > #1054 at exact `4519c101f13e08c10653b95ff88d66b4ce47f0b8`. Whole-population - > admission now suppresses a precomputed report aggregate when any persisted - > member or leftover-pair contributor is not visible; comparison evidence carries - > `process_unit_id`, and authenticated Keycloak + PostgreSQL regression proves - > detail/list/comparison visible before scope contraction and suppressed after a - > contributor becomes foreign-private. Repository Tests `34723167232` is terminal - > GREEN, including the full PostgreSQL suite, and dynamic GitHub CodeQL reports no - > new alerts. Draft-push central Security `34723086654`, SAST `34723086683`, and - > Required CodeQL `34723086691` stayed `action_required`; after Ready only the - > repository Tests identity rematerialized. With no live validation lane left, - > #1054 returned to Draft on the unchanged head. Canonical lifecycle repair is - > `.github#2045`; do not use empty commits, Draft/Ready oscillation, manual status, - > or leaf-side gate weakening. - > - > Persisted Post Chat replay authorization remains Draft PR #1047 at exact - > `41c7a86f78dddf0bcd9e9f0eb070bf90732f68e3`. Repository Tests, Security, - > SAST, dynamic CodeQL and Code Quality are GREEN there, while Required CodeQL, - > OpenCode, Noema and Strix are terminal FAILURE. Dependency advisory - > GHSA-82fw-gwwq-j7x9 remains issue #1043 / Draft PR #1046 at - > `f80c0ec5f35fd4fc0a867125bc46dfd2d2dee9a9`; duplicate migration ordinal - > 0233 remains issue #1048 / Draft PR #1049 at - > `5322971193d1ff4e0ae13c054d8f99615934d4dc`. - > - > Customer Master customer-hint repair remains issue #1052. ADR 0042 requires - > source-post tenant/access ownership to stay distinct from resolved customer - > identity and provenance; do not repair that issue by rebinding - > `source_post.corporate_entity_id`. Post Chat shared-persistence mutation remains - > issue #1053 and must not duplicate #1044/#1047 replay-authorization ownership. - > - > Protected-main release metadata is still inconsistent: `pyproject.toml` declares - > 2.28.0 while `lineageweave.__version__` declares 2.20.0. Keep this as a release - > blocker rather than normalizing it in documentation. ADR 0251 remains the I/O- - > psychology authority and ADR 0256 the extensible Voice-combination contract. - > RankWeave, ThreadWeave, TEPP, and canonical lowercase - > `ContextualWisdomLab/disksage` retain their own bounded responsibilities. - > PR #1041 remains Draft; earlier overlays below are dated historical evidence only.""" - overlay = "\n".join(line.strip() for line in overlay.splitlines()) - path.write_text(text[:first] + overlay + "\n\n" + text[second:], encoding="utf-8") - PY - rm .github/workflows/bounded-gap-baseline-refresh.yml - git config user.name "lineageweave-maintainer[bot]" - git config user.email "41898282+github-actions[bot]@users.noreply.github.com" - git add docs/product-technical-gap-baseline.md .github/workflows/bounded-gap-baseline-refresh.yml - git diff --cached --check - git commit -m "docs(gaps): refresh live exact-head overlay" - git push origin HEAD:codex/gap-loop-20260912 diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 6539972b5..571d53847 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,49 +1,50 @@ # Product & Technical Gap Baseline -> Exact-head loop overlay: 2026-09-13 07:07 KST. Protected `main` remains +> Exact-head loop overlay: 2026-09-13 08:51 KST. Protected `main` remains > `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). Fresh live > search reports 158 open PRs and 36 open issues. Exactly one open PR is > non-Draft: #1042, whose Ready state is validation admission only. > -> Customer Master process-unit authorization remains issue #1045 / PR #1042. -> Current exact head is `f23f5a567bd66113603837f86f030c3c459e69e6`. -> After predecessor Strix `34704740554` terminalized FAILURE, the touched-surface -> docstring warning was repaired and CodeRabbit verified 100% docstring coverage. -> The same review then found a valid reduced-coverage collector defect: arbitrary -> `pytest.mark.` values could masquerade as optional-module imports. Current -> head recognizes only an explicit plugin-marker map (`pytest.mark.anyio -> anyio`) -> and has a regression proving `pytest.mark.redis` does not suppress an unrelated -> test when Redis is absent. Current-head Tests `34721721155`, Required CodeQL -> `34721721113`, Security `34721721167`, and SAST `34721721186` are newly queued or -> pending; predecessor receipts do not transfer. +> Customer Master process-unit authorization remains issue #1045 / PR #1042 +> at exact `f23f5a567bd66113603837f86f030c3c459e69e6`. Repository Tests +> `34721721155`, Security `34721721167`, and SAST `34721721186` are terminal +> GREEN. Required CodeQL `34721721113`, OpenCode `34721720227`, and Noema +> `34721720347` are terminal FAILURE. Strix `34721720240` is still genuinely +> in progress on the same exact head, so the admission is preserved without +> elapsed-time cancellation or source churn. The later CodeQL producer dispatch +> succeeded only after compatibility consumers had already failed; canonical +> owner repair remains `.github#1929` and predecessor receipts do not transfer. > -> The retained predecessor Strix artifact remains sha256 -> `bcdc13b76adf4a2b5b9cbbcab2de217db2e25f445f69d2de20a7d9f4cdf19b72`. -> Its persisted Post Chat cited-source disclosure corroborates existing #1044 / -> Draft PR #1047. Separate issues #1050, #1051, #1052 and #1053 own mixed- -> visibility report aggregates, REST/shared Global Ask admission, Customer Master -> customer-hint tenant scoping/rebind, and Post Chat shared-persistence mutation. -> -> #1050 has executable Draft RED PR #1054 at exact -> `49a47c81eb53cf65877813b53424a2e20a6e1e05`; its net candidate delta is one -> regression file. Report list, detail and comparison paths must suppress a -> precomputed aggregate when any stored contributor or leftover-pair evidence is -> not visible, while preserving a fully visible aggregate. Bounded diagnostic run -> `34721645807` was admitted on predecessor `4d846afc...` and is not a promotion -> receipt. The minimal production fix and authenticated PostgreSQL/HTTP evidence -> remain absent. Do not recompute psychometric truth over the visible subset; -> fast-mlsirm/TEPP remain measurement owners. +> Mixed-visibility period-report authorization remains issue #1050 / Draft PR +> #1054 at exact `4519c101f13e08c10653b95ff88d66b4ce47f0b8`. Whole-population +> admission now suppresses a precomputed report aggregate when any persisted +> member or leftover-pair contributor is not visible; comparison evidence carries +> `process_unit_id`, and authenticated Keycloak + PostgreSQL regression proves +> detail/list/comparison visible before scope contraction and suppressed after a +> contributor becomes foreign-private. Repository Tests `34723167232` is terminal +> GREEN, including the full PostgreSQL suite, and dynamic GitHub CodeQL reports no +> new alerts. Draft-push central Security `34723086654`, SAST `34723086683`, and +> Required CodeQL `34723086691` stayed `action_required`; after Ready only the +> repository Tests identity rematerialized. With no live validation lane left, +> #1054 returned to Draft on the unchanged head. Canonical lifecycle repair is +> `.github#2045`; do not use empty commits, Draft/Ready oscillation, manual status, +> or leaf-side gate weakening. > > Persisted Post Chat replay authorization remains Draft PR #1047 at exact > `41c7a86f78dddf0bcd9e9f0eb070bf90732f68e3`. Repository Tests, Security, > SAST, dynamic CodeQL and Code Quality are GREEN there, while Required CodeQL, -> OpenCode, Noema and Strix are terminal FAILURE. -> -> Dependency advisory GHSA-82fw-gwwq-j7x9 remains issue #1043 / Draft PR #1046 -> at `f80c0ec5f35fd4fc0a867125bc46dfd2d2dee9a9`. Duplicate migration ordinal +> OpenCode, Noema and Strix are terminal FAILURE. Dependency advisory +> GHSA-82fw-gwwq-j7x9 remains issue #1043 / Draft PR #1046 at +> `f80c0ec5f35fd4fc0a867125bc46dfd2d2dee9a9`; duplicate migration ordinal > 0233 remains issue #1048 / Draft PR #1049 at > `5322971193d1ff4e0ae13c054d8f99615934d4dc`. > +> Customer Master customer-hint repair remains issue #1052. ADR 0042 requires +> source-post tenant/access ownership to stay distinct from resolved customer +> identity and provenance; do not repair that issue by rebinding +> `source_post.corporate_entity_id`. Post Chat shared-persistence mutation remains +> issue #1053 and must not duplicate #1044/#1047 replay-authorization ownership. +> > Protected-main release metadata is still inconsistent: `pyproject.toml` declares > 2.28.0 while `lineageweave.__version__` declares 2.20.0. Keep this as a release > blocker rather than normalizing it in documentation. ADR 0251 remains the I/O- From 6080f0776ffe5a542fe830b00277001a8e0c9bfe Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 10:04:42 +0900 Subject: [PATCH 026/276] chore(gaps): stage current authority overlay --- scripts/bounded_gap_baseline_0946.py | 56 ++++++++++++++++++++++++++++ 1 file changed, 56 insertions(+) create mode 100644 scripts/bounded_gap_baseline_0946.py diff --git a/scripts/bounded_gap_baseline_0946.py b/scripts/bounded_gap_baseline_0946.py new file mode 100644 index 000000000..45b5d2c18 --- /dev/null +++ b/scripts/bounded_gap_baseline_0946.py @@ -0,0 +1,56 @@ +"""Temporary bounded top-overlay refresh for the product/technical gap baseline.""" + +from pathlib import Path + +path = Path("docs/product-technical-gap-baseline.md") +text = path.read_text(encoding="utf-8") +marker = "# Product & Technical Gap Baseline\n" +if not text.startswith(marker): + raise SystemExit("unexpected baseline heading") +overlay = r''' + +> Exact-head loop overlay: 2026-09-13 09:46 KST. Protected `main` remains +> `83eba56149eb802cd63642c507c324c9976ec78e`. Fresh live inventory reports +> 159 open PRs and 36 open issues. Exactly two open PRs are non-Draft, #1042 +> and #1055; both are Ready only to preserve or obtain exact-head validation, +> not as merge-ready claims. +> +> Customer Master process-unit repair #1042 remains on exact +> `f23f5a567bd66113603837f86f030c3c459e69e6`. Repository Tests/Security/SAST +> are terminal GREEN and Required CodeQL/OpenCode/Noema are terminal FAILURE. +> Strix `34721720240` remains genuinely in progress on the unchanged head, so +> elapsed time alone is not used to cancel it. If that lane terminalizes while +> required failures remain, #1042 returns to Draft. +> +> Customer Master customer-hint ownership issue #1052 now has repair PR #1055 +> at exact `77e7c8bd8bacb8f0ce30dd9e5ddd71c30a7632da`. Migration 0250 and Proposed +> ADR 0374 introduce normalized `source_post_customer_resolution`; hint +> corroboration captures only caller-visible eligible evidence, releases its DB +> resource before external resolution/verification, then reacquires a short +> transaction and `FOR SHARE` revalidates the exact captured sources before an +> idempotent association write. `source_post.corporate_entity_id` and +> `process_unit_id` remain authorization ownership and are never rebound to the +> resolved customer. Customer Master read models consume the normalized +> association only after source-post ABAC. A live PostgreSQL regression covers +> two private tenants sharing one synthetic hint and requires that only the +> authorized tenant's source receives the resolution association while both +> source ownership tuples remain unchanged. +> +> On #1055, fresh repository Tests `34729447666` rematerialized after Ready; +> frontend lint/test/build/Storybook is GREEN and the full PostgreSQL suite is +> still running. Draft-time central Security `34729440550`, SAST `34729440465`, +> and Required CodeQL `34729440480` remain `action_required` and did not obtain +> fresh identities on the unchanged Ready head. Canonical Ready reconciliation +> owner `.github#2045` has this canary; no no-op commit, lifecycle flip loop, or +> manual success status is used. Authenticated HTTP/E2E cross-tenant evidence, +> central security/model gates and independent current-head approval are still +> required before integration. +> +> #1054, #1047, #1046 and #1049 remain Draft. #1053 still owns Post Chat +> read-derived compute versus shared-persistence mutation authority and must not +> duplicate #1044/#1047 replay-disclosure ownership. Protected-main release +> metadata remains inconsistent (`pyproject.toml` 2.28.0 versus +> `lineageweave.__version__` 2.20.0), so protected release remains blocked. +> PR #1041 remains Draft; every older overlay below is dated evidence only. +''' +path.write_text(marker + overlay + text[len(marker):], encoding="utf-8") From 78c4266452e8248f516b132d406aeeb0007c2ef0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 10:04:49 +0900 Subject: [PATCH 027/276] chore(gaps): apply current authority overlay --- .../workflows/bounded-gap-baseline-0946.yml | 35 +++++++++++++++++++ 1 file changed, 35 insertions(+) create mode 100644 .github/workflows/bounded-gap-baseline-0946.yml diff --git a/.github/workflows/bounded-gap-baseline-0946.yml b/.github/workflows/bounded-gap-baseline-0946.yml new file mode 100644 index 000000000..1cf4ed5d1 --- /dev/null +++ b/.github/workflows/bounded-gap-baseline-0946.yml @@ -0,0 +1,35 @@ +name: Bounded gap baseline 0946 refresh + +on: + push: + branches: + - codex/gap-loop-20260912 + +permissions: + contents: write + +jobs: + refresh: + if: github.actor != 'github-actions[bot]' + runs-on: ubuntu-latest + steps: + - name: Checkout + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 + with: + ref: codex/gap-loop-20260912 + persist-credentials: false + - name: Apply bounded overlay + run: | + python scripts/bounded_gap_baseline_0946.py + git diff --check + - name: Commit overlay and remove purpose-complete machinery + env: + GH_TOKEN: ${{ github.token }} + run: | + rm scripts/bounded_gap_baseline_0946.py + rm .github/workflows/bounded-gap-baseline-0946.yml + git config user.name 'github-actions[bot]' + git config user.email '41898282+github-actions[bot]@users.noreply.github.com' + git add docs/product-technical-gap-baseline.md scripts/bounded_gap_baseline_0946.py .github/workflows/bounded-gap-baseline-0946.yml + git commit -m 'docs(gaps): refresh customer-master exact-head authority' + git push "https://x-access-token:${GH_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" HEAD:codex/gap-loop-20260912 From b4e98ea2f2776cee5a6f5873916f1cd38cdabb24 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Sun, 13 Sep 2026 01:05:00 +0000 Subject: [PATCH 028/276] docs(gaps): refresh customer-master exact-head authority --- .../workflows/bounded-gap-baseline-0946.yml | 35 ------------ docs/product-technical-gap-baseline.md | 45 +++++++++++++++ scripts/bounded_gap_baseline_0946.py | 56 ------------------- 3 files changed, 45 insertions(+), 91 deletions(-) delete mode 100644 .github/workflows/bounded-gap-baseline-0946.yml delete mode 100644 scripts/bounded_gap_baseline_0946.py diff --git a/.github/workflows/bounded-gap-baseline-0946.yml b/.github/workflows/bounded-gap-baseline-0946.yml deleted file mode 100644 index 1cf4ed5d1..000000000 --- a/.github/workflows/bounded-gap-baseline-0946.yml +++ /dev/null @@ -1,35 +0,0 @@ -name: Bounded gap baseline 0946 refresh - -on: - push: - branches: - - codex/gap-loop-20260912 - -permissions: - contents: write - -jobs: - refresh: - if: github.actor != 'github-actions[bot]' - runs-on: ubuntu-latest - steps: - - name: Checkout - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 - with: - ref: codex/gap-loop-20260912 - persist-credentials: false - - name: Apply bounded overlay - run: | - python scripts/bounded_gap_baseline_0946.py - git diff --check - - name: Commit overlay and remove purpose-complete machinery - env: - GH_TOKEN: ${{ github.token }} - run: | - rm scripts/bounded_gap_baseline_0946.py - rm .github/workflows/bounded-gap-baseline-0946.yml - git config user.name 'github-actions[bot]' - git config user.email '41898282+github-actions[bot]@users.noreply.github.com' - git add docs/product-technical-gap-baseline.md scripts/bounded_gap_baseline_0946.py .github/workflows/bounded-gap-baseline-0946.yml - git commit -m 'docs(gaps): refresh customer-master exact-head authority' - git push "https://x-access-token:${GH_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" HEAD:codex/gap-loop-20260912 diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 571d53847..943e7d548 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,5 +1,50 @@ # Product & Technical Gap Baseline + +> Exact-head loop overlay: 2026-09-13 09:46 KST. Protected `main` remains +> `83eba56149eb802cd63642c507c324c9976ec78e`. Fresh live inventory reports +> 159 open PRs and 36 open issues. Exactly two open PRs are non-Draft, #1042 +> and #1055; both are Ready only to preserve or obtain exact-head validation, +> not as merge-ready claims. +> +> Customer Master process-unit repair #1042 remains on exact +> `f23f5a567bd66113603837f86f030c3c459e69e6`. Repository Tests/Security/SAST +> are terminal GREEN and Required CodeQL/OpenCode/Noema are terminal FAILURE. +> Strix `34721720240` remains genuinely in progress on the unchanged head, so +> elapsed time alone is not used to cancel it. If that lane terminalizes while +> required failures remain, #1042 returns to Draft. +> +> Customer Master customer-hint ownership issue #1052 now has repair PR #1055 +> at exact `77e7c8bd8bacb8f0ce30dd9e5ddd71c30a7632da`. Migration 0250 and Proposed +> ADR 0374 introduce normalized `source_post_customer_resolution`; hint +> corroboration captures only caller-visible eligible evidence, releases its DB +> resource before external resolution/verification, then reacquires a short +> transaction and `FOR SHARE` revalidates the exact captured sources before an +> idempotent association write. `source_post.corporate_entity_id` and +> `process_unit_id` remain authorization ownership and are never rebound to the +> resolved customer. Customer Master read models consume the normalized +> association only after source-post ABAC. A live PostgreSQL regression covers +> two private tenants sharing one synthetic hint and requires that only the +> authorized tenant's source receives the resolution association while both +> source ownership tuples remain unchanged. +> +> On #1055, fresh repository Tests `34729447666` rematerialized after Ready; +> frontend lint/test/build/Storybook is GREEN and the full PostgreSQL suite is +> still running. Draft-time central Security `34729440550`, SAST `34729440465`, +> and Required CodeQL `34729440480` remain `action_required` and did not obtain +> fresh identities on the unchanged Ready head. Canonical Ready reconciliation +> owner `.github#2045` has this canary; no no-op commit, lifecycle flip loop, or +> manual success status is used. Authenticated HTTP/E2E cross-tenant evidence, +> central security/model gates and independent current-head approval are still +> required before integration. +> +> #1054, #1047, #1046 and #1049 remain Draft. #1053 still owns Post Chat +> read-derived compute versus shared-persistence mutation authority and must not +> duplicate #1044/#1047 replay-disclosure ownership. Protected-main release +> metadata remains inconsistent (`pyproject.toml` 2.28.0 versus +> `lineageweave.__version__` 2.20.0), so protected release remains blocked. +> PR #1041 remains Draft; every older overlay below is dated evidence only. + > Exact-head loop overlay: 2026-09-13 08:51 KST. Protected `main` remains > `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). Fresh live > search reports 158 open PRs and 36 open issues. Exactly one open PR is diff --git a/scripts/bounded_gap_baseline_0946.py b/scripts/bounded_gap_baseline_0946.py deleted file mode 100644 index 45b5d2c18..000000000 --- a/scripts/bounded_gap_baseline_0946.py +++ /dev/null @@ -1,56 +0,0 @@ -"""Temporary bounded top-overlay refresh for the product/technical gap baseline.""" - -from pathlib import Path - -path = Path("docs/product-technical-gap-baseline.md") -text = path.read_text(encoding="utf-8") -marker = "# Product & Technical Gap Baseline\n" -if not text.startswith(marker): - raise SystemExit("unexpected baseline heading") -overlay = r''' - -> Exact-head loop overlay: 2026-09-13 09:46 KST. Protected `main` remains -> `83eba56149eb802cd63642c507c324c9976ec78e`. Fresh live inventory reports -> 159 open PRs and 36 open issues. Exactly two open PRs are non-Draft, #1042 -> and #1055; both are Ready only to preserve or obtain exact-head validation, -> not as merge-ready claims. -> -> Customer Master process-unit repair #1042 remains on exact -> `f23f5a567bd66113603837f86f030c3c459e69e6`. Repository Tests/Security/SAST -> are terminal GREEN and Required CodeQL/OpenCode/Noema are terminal FAILURE. -> Strix `34721720240` remains genuinely in progress on the unchanged head, so -> elapsed time alone is not used to cancel it. If that lane terminalizes while -> required failures remain, #1042 returns to Draft. -> -> Customer Master customer-hint ownership issue #1052 now has repair PR #1055 -> at exact `77e7c8bd8bacb8f0ce30dd9e5ddd71c30a7632da`. Migration 0250 and Proposed -> ADR 0374 introduce normalized `source_post_customer_resolution`; hint -> corroboration captures only caller-visible eligible evidence, releases its DB -> resource before external resolution/verification, then reacquires a short -> transaction and `FOR SHARE` revalidates the exact captured sources before an -> idempotent association write. `source_post.corporate_entity_id` and -> `process_unit_id` remain authorization ownership and are never rebound to the -> resolved customer. Customer Master read models consume the normalized -> association only after source-post ABAC. A live PostgreSQL regression covers -> two private tenants sharing one synthetic hint and requires that only the -> authorized tenant's source receives the resolution association while both -> source ownership tuples remain unchanged. -> -> On #1055, fresh repository Tests `34729447666` rematerialized after Ready; -> frontend lint/test/build/Storybook is GREEN and the full PostgreSQL suite is -> still running. Draft-time central Security `34729440550`, SAST `34729440465`, -> and Required CodeQL `34729440480` remain `action_required` and did not obtain -> fresh identities on the unchanged Ready head. Canonical Ready reconciliation -> owner `.github#2045` has this canary; no no-op commit, lifecycle flip loop, or -> manual success status is used. Authenticated HTTP/E2E cross-tenant evidence, -> central security/model gates and independent current-head approval are still -> required before integration. -> -> #1054, #1047, #1046 and #1049 remain Draft. #1053 still owns Post Chat -> read-derived compute versus shared-persistence mutation authority and must not -> duplicate #1044/#1047 replay-disclosure ownership. Protected-main release -> metadata remains inconsistent (`pyproject.toml` 2.28.0 versus -> `lineageweave.__version__` 2.20.0), so protected release remains blocked. -> PR #1041 remains Draft; every older overlay below is dated evidence only. -''' -path.write_text(marker + overlay + text[len(marker):], encoding="utf-8") From 049e0ef82140901d51e27d7cc9a096d17116cfac Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 10:25:44 +0900 Subject: [PATCH 029/276] chore(gaps): stage 10:14 exact-head overlay --- scripts/bounded_gap_baseline_refresh_1014.py | 57 ++++++++++++++++++++ 1 file changed, 57 insertions(+) create mode 100644 scripts/bounded_gap_baseline_refresh_1014.py diff --git a/scripts/bounded_gap_baseline_refresh_1014.py b/scripts/bounded_gap_baseline_refresh_1014.py new file mode 100644 index 000000000..def0c7706 --- /dev/null +++ b/scripts/bounded_gap_baseline_refresh_1014.py @@ -0,0 +1,57 @@ +"""Prepend the current exact-head stabilization overlay to the gap baseline.""" + +from pathlib import Path + +path = Path("docs/product-technical-gap-baseline.md") +text = path.read_text(encoding="utf-8") +heading = "# Product & Technical Gap Baseline\n" +if not text.startswith(heading): + raise SystemExit("unexpected baseline heading") + +overlay = ''' + +> Exact-head loop overlay: 2026-09-13 10:14 KST. Protected `main` remains +> `83eba56149eb802cd63642c507c324c9976ec78e`, protected with a valid verified +> commit signature. Fresh non-Draft inventory contains exactly #1042 and #1055; +> both are validation admissions only, not merge-ready claims. +> +> Customer Master process-unit repair #1042 remains at exact +> `f23f5a567bd66113603837f86f030c3c459e69e6`. Repository Tests/Security/SAST +> are terminal GREEN while Required CodeQL/OpenCode/Noema are terminal FAILURE. +> Strix `34721720240` is still genuinely in progress on the unchanged head, so +> elapsed time alone is not used to cancel it. If that lane terminalizes while +> authoritative failures remain, #1042 returns to Draft. +> +> Customer-hint ownership issue #1052 / PR #1055 advanced after review to exact +> `e11ff8698f20afc4ac628a6a86611ad1348c3fcb`. Migration 0250 and Proposed ADR +> 0374 keep `source_post.corporate_entity_id` / `process_unit_id` as access +> ownership and persist resolved customer identity in +> `source_post_customer_resolution`. Request identity is whitespace-normalized +> for matching and corroboration while the association preserves the actual raw +> `source_post.source_customer_code`. External resolution still runs with the DB +> resource released; a short persistence transaction then revalidates and +> `FOR SHARE` locks the exact captured source set before writing the association. +> Customer Master now selects resolved id/name/status/evidence coherently from one +> deterministic newest resolution row rather than independent aggregate maxima. +> The bearer + PostgreSQL regression also excludes foreign same-hint evidence, +> preserves source ownership and raw spaced hints, rejects blank HTTP hints, and +> checks coherent newest-resolution metadata. The four validated CodeRabbit +> findings are repaired and their outdated threads resolved. +> +> #1055 was marked Ready on the unchanged exact head only to admit fresh +> validation. Repository Tests `34730379137` rematerialized; frontend +> lint/test/build/Storybook is GREEN and the PostgreSQL job is still active. +> Draft-time Security `34730262196`, SAST `34730262117`, and Required CodeQL +> `34730262172` are `action_required`; no fresh central Security/SAST/Required +> CodeQL/OpenCode/Noema/Strix identity appeared at the first Ready reconciliation +> read. Canonical owner `.github#2045` now carries this unchanged-head canary. +> Do not use a no-op commit, Draft/Ready oscillation, or synthetic status to +> manufacture promotion evidence. +> +> #1054, #1047, #1046 and #1049 remain Draft. Protected-main release metadata +> remains inconsistent (`pyproject.toml` 2.28.0 versus +> `lineageweave.__version__` 2.20.0), so release remains blocked. PR #1041 stays +> Draft; every older overlay below is dated evidence only. +''' + +path.write_text(heading + overlay + text[len(heading):], encoding="utf-8") From 3a728584571c792c3c84664bf6075140f5225904 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 10:25:53 +0900 Subject: [PATCH 030/276] chore(gaps): run 10:14 exact-head overlay --- .../bounded-gap-baseline-refresh-1014.yml | 38 +++++++++++++++++++ 1 file changed, 38 insertions(+) create mode 100644 .github/workflows/bounded-gap-baseline-refresh-1014.yml diff --git a/.github/workflows/bounded-gap-baseline-refresh-1014.yml b/.github/workflows/bounded-gap-baseline-refresh-1014.yml new file mode 100644 index 000000000..f964f6a91 --- /dev/null +++ b/.github/workflows/bounded-gap-baseline-refresh-1014.yml @@ -0,0 +1,38 @@ +name: Bounded 10:14 gap baseline refresh + +on: + push: + branches: + - codex/gap-loop-20260912 + +permissions: + contents: write + +jobs: + refresh: + if: github.actor != 'github-actions[bot]' + runs-on: ubuntu-24.04 + steps: + - name: Checkout exact baseline branch + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 + with: + ref: codex/gap-loop-20260912 + persist-credentials: false + - name: Apply bounded overlay + run: | + python scripts/bounded_gap_baseline_refresh_1014.py + git diff --check + - name: Publish ordinary documentation commit + env: + GH_TOKEN: ${{ github.token }} + run: | + rm scripts/bounded_gap_baseline_refresh_1014.py + rm .github/workflows/bounded-gap-baseline-refresh-1014.yml + git config user.name 'github-actions[bot]' + git config user.email '41898282+github-actions[bot]@users.noreply.github.com' + git add docs/product-technical-gap-baseline.md \ + scripts/bounded_gap_baseline_refresh_1014.py \ + .github/workflows/bounded-gap-baseline-refresh-1014.yml + git diff --cached --check + git commit -m 'docs(gaps): refresh exact-head customer-master evidence' + git push "https://x-access-token:${GH_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" HEAD:codex/gap-loop-20260912 From c4550d20793509b4c98e98850221dab4ab5caa47 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Sun, 13 Sep 2026 01:26:24 +0000 Subject: [PATCH 031/276] docs(gaps): refresh exact-head customer-master evidence --- .../bounded-gap-baseline-refresh-1014.yml | 38 ------------- docs/product-technical-gap-baseline.md | 44 ++++++++++++++ scripts/bounded_gap_baseline_refresh_1014.py | 57 ------------------- 3 files changed, 44 insertions(+), 95 deletions(-) delete mode 100644 .github/workflows/bounded-gap-baseline-refresh-1014.yml delete mode 100644 scripts/bounded_gap_baseline_refresh_1014.py diff --git a/.github/workflows/bounded-gap-baseline-refresh-1014.yml b/.github/workflows/bounded-gap-baseline-refresh-1014.yml deleted file mode 100644 index f964f6a91..000000000 --- a/.github/workflows/bounded-gap-baseline-refresh-1014.yml +++ /dev/null @@ -1,38 +0,0 @@ -name: Bounded 10:14 gap baseline refresh - -on: - push: - branches: - - codex/gap-loop-20260912 - -permissions: - contents: write - -jobs: - refresh: - if: github.actor != 'github-actions[bot]' - runs-on: ubuntu-24.04 - steps: - - name: Checkout exact baseline branch - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 - with: - ref: codex/gap-loop-20260912 - persist-credentials: false - - name: Apply bounded overlay - run: | - python scripts/bounded_gap_baseline_refresh_1014.py - git diff --check - - name: Publish ordinary documentation commit - env: - GH_TOKEN: ${{ github.token }} - run: | - rm scripts/bounded_gap_baseline_refresh_1014.py - rm .github/workflows/bounded-gap-baseline-refresh-1014.yml - git config user.name 'github-actions[bot]' - git config user.email '41898282+github-actions[bot]@users.noreply.github.com' - git add docs/product-technical-gap-baseline.md \ - scripts/bounded_gap_baseline_refresh_1014.py \ - .github/workflows/bounded-gap-baseline-refresh-1014.yml - git diff --cached --check - git commit -m 'docs(gaps): refresh exact-head customer-master evidence' - git push "https://x-access-token:${GH_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" HEAD:codex/gap-loop-20260912 diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 943e7d548..0eab3d5a5 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,50 @@ # Product & Technical Gap Baseline +> Exact-head loop overlay: 2026-09-13 10:14 KST. Protected `main` remains +> `83eba56149eb802cd63642c507c324c9976ec78e`, protected with a valid verified +> commit signature. Fresh non-Draft inventory contains exactly #1042 and #1055; +> both are validation admissions only, not merge-ready claims. +> +> Customer Master process-unit repair #1042 remains at exact +> `f23f5a567bd66113603837f86f030c3c459e69e6`. Repository Tests/Security/SAST +> are terminal GREEN while Required CodeQL/OpenCode/Noema are terminal FAILURE. +> Strix `34721720240` is still genuinely in progress on the unchanged head, so +> elapsed time alone is not used to cancel it. If that lane terminalizes while +> authoritative failures remain, #1042 returns to Draft. +> +> Customer-hint ownership issue #1052 / PR #1055 advanced after review to exact +> `e11ff8698f20afc4ac628a6a86611ad1348c3fcb`. Migration 0250 and Proposed ADR +> 0374 keep `source_post.corporate_entity_id` / `process_unit_id` as access +> ownership and persist resolved customer identity in +> `source_post_customer_resolution`. Request identity is whitespace-normalized +> for matching and corroboration while the association preserves the actual raw +> `source_post.source_customer_code`. External resolution still runs with the DB +> resource released; a short persistence transaction then revalidates and +> `FOR SHARE` locks the exact captured source set before writing the association. +> Customer Master now selects resolved id/name/status/evidence coherently from one +> deterministic newest resolution row rather than independent aggregate maxima. +> The bearer + PostgreSQL regression also excludes foreign same-hint evidence, +> preserves source ownership and raw spaced hints, rejects blank HTTP hints, and +> checks coherent newest-resolution metadata. The four validated CodeRabbit +> findings are repaired and their outdated threads resolved. +> +> #1055 was marked Ready on the unchanged exact head only to admit fresh +> validation. Repository Tests `34730379137` rematerialized; frontend +> lint/test/build/Storybook is GREEN and the PostgreSQL job is still active. +> Draft-time Security `34730262196`, SAST `34730262117`, and Required CodeQL +> `34730262172` are `action_required`; no fresh central Security/SAST/Required +> CodeQL/OpenCode/Noema/Strix identity appeared at the first Ready reconciliation +> read. Canonical owner `.github#2045` now carries this unchanged-head canary. +> Do not use a no-op commit, Draft/Ready oscillation, or synthetic status to +> manufacture promotion evidence. +> +> #1054, #1047, #1046 and #1049 remain Draft. Protected-main release metadata +> remains inconsistent (`pyproject.toml` 2.28.0 versus +> `lineageweave.__version__` 2.20.0), so release remains blocked. PR #1041 stays +> Draft; every older overlay below is dated evidence only. + + > Exact-head loop overlay: 2026-09-13 09:46 KST. Protected `main` remains > `83eba56149eb802cd63642c507c324c9976ec78e`. Fresh live inventory reports > 159 open PRs and 36 open issues. Exactly two open PRs are non-Draft, #1042 diff --git a/scripts/bounded_gap_baseline_refresh_1014.py b/scripts/bounded_gap_baseline_refresh_1014.py deleted file mode 100644 index def0c7706..000000000 --- a/scripts/bounded_gap_baseline_refresh_1014.py +++ /dev/null @@ -1,57 +0,0 @@ -"""Prepend the current exact-head stabilization overlay to the gap baseline.""" - -from pathlib import Path - -path = Path("docs/product-technical-gap-baseline.md") -text = path.read_text(encoding="utf-8") -heading = "# Product & Technical Gap Baseline\n" -if not text.startswith(heading): - raise SystemExit("unexpected baseline heading") - -overlay = ''' - -> Exact-head loop overlay: 2026-09-13 10:14 KST. Protected `main` remains -> `83eba56149eb802cd63642c507c324c9976ec78e`, protected with a valid verified -> commit signature. Fresh non-Draft inventory contains exactly #1042 and #1055; -> both are validation admissions only, not merge-ready claims. -> -> Customer Master process-unit repair #1042 remains at exact -> `f23f5a567bd66113603837f86f030c3c459e69e6`. Repository Tests/Security/SAST -> are terminal GREEN while Required CodeQL/OpenCode/Noema are terminal FAILURE. -> Strix `34721720240` is still genuinely in progress on the unchanged head, so -> elapsed time alone is not used to cancel it. If that lane terminalizes while -> authoritative failures remain, #1042 returns to Draft. -> -> Customer-hint ownership issue #1052 / PR #1055 advanced after review to exact -> `e11ff8698f20afc4ac628a6a86611ad1348c3fcb`. Migration 0250 and Proposed ADR -> 0374 keep `source_post.corporate_entity_id` / `process_unit_id` as access -> ownership and persist resolved customer identity in -> `source_post_customer_resolution`. Request identity is whitespace-normalized -> for matching and corroboration while the association preserves the actual raw -> `source_post.source_customer_code`. External resolution still runs with the DB -> resource released; a short persistence transaction then revalidates and -> `FOR SHARE` locks the exact captured source set before writing the association. -> Customer Master now selects resolved id/name/status/evidence coherently from one -> deterministic newest resolution row rather than independent aggregate maxima. -> The bearer + PostgreSQL regression also excludes foreign same-hint evidence, -> preserves source ownership and raw spaced hints, rejects blank HTTP hints, and -> checks coherent newest-resolution metadata. The four validated CodeRabbit -> findings are repaired and their outdated threads resolved. -> -> #1055 was marked Ready on the unchanged exact head only to admit fresh -> validation. Repository Tests `34730379137` rematerialized; frontend -> lint/test/build/Storybook is GREEN and the PostgreSQL job is still active. -> Draft-time Security `34730262196`, SAST `34730262117`, and Required CodeQL -> `34730262172` are `action_required`; no fresh central Security/SAST/Required -> CodeQL/OpenCode/Noema/Strix identity appeared at the first Ready reconciliation -> read. Canonical owner `.github#2045` now carries this unchanged-head canary. -> Do not use a no-op commit, Draft/Ready oscillation, or synthetic status to -> manufacture promotion evidence. -> -> #1054, #1047, #1046 and #1049 remain Draft. Protected-main release metadata -> remains inconsistent (`pyproject.toml` 2.28.0 versus -> `lineageweave.__version__` 2.20.0), so release remains blocked. PR #1041 stays -> Draft; every older overlay below is dated evidence only. -''' - -path.write_text(heading + overlay + text[len(heading):], encoding="utf-8") From 4f94c43b52908d2a1b3b2b9927777ccd8256ce7a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 11:00:28 +0900 Subject: [PATCH 032/276] chore(docs): stage bounded gap baseline refresh --- .../bounded-gap-baseline-refresh.yml | 92 +++++++++++++++++++ 1 file changed, 92 insertions(+) create mode 100644 .github/workflows/bounded-gap-baseline-refresh.yml diff --git a/.github/workflows/bounded-gap-baseline-refresh.yml b/.github/workflows/bounded-gap-baseline-refresh.yml new file mode 100644 index 000000000..cc8d68ec3 --- /dev/null +++ b/.github/workflows/bounded-gap-baseline-refresh.yml @@ -0,0 +1,92 @@ +name: Bounded gap baseline refresh + +on: + push: + branches: [codex/gap-loop-20260912] + paths: + - .github/workflows/bounded-gap-baseline-refresh.yml + +permissions: + contents: write + +concurrency: + group: bounded-gap-baseline-refresh + cancel-in-progress: false + +jobs: + refresh: + runs-on: ubuntu-latest + steps: + - name: Checkout exact push + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # actions/checkout@v7 + with: + ref: ${{ github.sha }} + fetch-depth: 2 + + - name: Verify bounded parent + shell: bash + run: | + set -euo pipefail + test "$(git rev-parse HEAD^)" = "c4550d20793509b4c98e98850221dab4ab5caa47" + + - name: Prepend current exact-head overlay and remove helper + shell: python + run: | + from pathlib import Path + + path = Path("docs/product-technical-gap-baseline.md") + text = path.read_text(encoding="utf-8") + marker = "> Exact-head loop overlay: 2026-09-13 11:00 KST." + if marker not in text: + overlay = """> Exact-head loop overlay: 2026-09-13 11:00 KST. Protected `main` remains + > `83eba56149eb802cd63642c507c324c9976ec78e`. Customer Master process-unit + > repair #1042 is now Draft at exact + > `f23f5a567bd66113603837f86f030c3c459e69e6`: Strix `34721720240` + > terminalized FAILURE after setup and scan execution. Immutable artifact + > `10309695301` (95,509 bytes, + > `sha256:47822709dfdc45968569dbd4adf6bde167ba5eb46277503e906ee9625262d8b8`) + > contains one real Medium CWE-862 finding: mixed-visibility project/thread/team + > period-report endpoints could disclose full-population stored aggregates when + > at least one contributor remained visible. That defect is already isolated in + > #1050/#1054; #1054 is the security prerequisite and report authorization is not + > duplicated into #1042. Future #1042 integration requires a non-force descendant + > restack/reconstruction after that prerequisite lands. + > + > Customer-hint ownership repair #1055 is on exact + > `7dbd133320d8b12bde394569955e0ae6503f8f39`. Predecessor repository validation + > reached 1771 passed / 147 skipped and then exposed two owned REDs: migration + > 0250 was not replay-safe and the static SQL-review ledger still expected 36 + > suppressions after the repair legitimately removed one. Exact head now uses + > `CREATE TABLE IF NOT EXISTS` / `CREATE INDEX IF NOT EXISTS` and tracks 35 + > reviewed suppressions. Security `34731558854`, SAST `34731558875`, dynamic + > GitHub CodeQL `34731558343`, and Code Quality `34731558308` are GREEN. + > Repository Tests `34731586226`, Required Noema `34731558900`, and Strix + > `34731558917` are still live. Required CodeQL `34731558861` failed because + > compatibility consumers terminalized before the producer dispatch later + > succeeded; canonical owner `.github#1929` carries the unchanged-head canary. + > Required OpenCode `34731558957` failed closed without a current-head verdict. + > #1055 is Ready only as a live validation admission, not a merge-ready claim. + > + > #1054 remains Draft at `4519c101f13e08c10653b95ff88d66b4ce47f0b8` with + > repository Tests GREEN and central unchanged-head workflow reconciliation owned + > by `.github#2045`. Protected-main release metadata remains inconsistent: + > `pyproject.toml` declares 2.28.0 while `lineageweave.__version__` declares 2.20.0. + > No release is admitted while that blocker or any current required gate remains. + > PR #1041 remains Draft; every older overlay below is dated evidence only. + + """ + prefix = "# Product & Technical Gap Baseline\n\n" + if not text.startswith(prefix): + raise SystemExit("unexpected baseline header") + path.write_text(prefix + overlay + text[len(prefix):], encoding="utf-8") + Path(".github/workflows/bounded-gap-baseline-refresh.yml").unlink() + + - name: Commit bounded refresh + shell: bash + run: | + set -euo pipefail + git config user.name "github-actions[bot]" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + git add docs/product-technical-gap-baseline.md .github/workflows/bounded-gap-baseline-refresh.yml + git commit -m "docs(gaps): refresh exact-head security evidence" + git push origin HEAD:codex/gap-loop-20260912 From 8e0881a6328da68a6e83e205077834eec887e0f8 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Sun, 13 Sep 2026 02:01:24 +0000 Subject: [PATCH 033/276] docs(gaps): refresh exact-head security evidence --- .../bounded-gap-baseline-refresh.yml | 92 ------------------- docs/product-technical-gap-baseline.md | 36 ++++++++ 2 files changed, 36 insertions(+), 92 deletions(-) delete mode 100644 .github/workflows/bounded-gap-baseline-refresh.yml diff --git a/.github/workflows/bounded-gap-baseline-refresh.yml b/.github/workflows/bounded-gap-baseline-refresh.yml deleted file mode 100644 index cc8d68ec3..000000000 --- a/.github/workflows/bounded-gap-baseline-refresh.yml +++ /dev/null @@ -1,92 +0,0 @@ -name: Bounded gap baseline refresh - -on: - push: - branches: [codex/gap-loop-20260912] - paths: - - .github/workflows/bounded-gap-baseline-refresh.yml - -permissions: - contents: write - -concurrency: - group: bounded-gap-baseline-refresh - cancel-in-progress: false - -jobs: - refresh: - runs-on: ubuntu-latest - steps: - - name: Checkout exact push - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # actions/checkout@v7 - with: - ref: ${{ github.sha }} - fetch-depth: 2 - - - name: Verify bounded parent - shell: bash - run: | - set -euo pipefail - test "$(git rev-parse HEAD^)" = "c4550d20793509b4c98e98850221dab4ab5caa47" - - - name: Prepend current exact-head overlay and remove helper - shell: python - run: | - from pathlib import Path - - path = Path("docs/product-technical-gap-baseline.md") - text = path.read_text(encoding="utf-8") - marker = "> Exact-head loop overlay: 2026-09-13 11:00 KST." - if marker not in text: - overlay = """> Exact-head loop overlay: 2026-09-13 11:00 KST. Protected `main` remains - > `83eba56149eb802cd63642c507c324c9976ec78e`. Customer Master process-unit - > repair #1042 is now Draft at exact - > `f23f5a567bd66113603837f86f030c3c459e69e6`: Strix `34721720240` - > terminalized FAILURE after setup and scan execution. Immutable artifact - > `10309695301` (95,509 bytes, - > `sha256:47822709dfdc45968569dbd4adf6bde167ba5eb46277503e906ee9625262d8b8`) - > contains one real Medium CWE-862 finding: mixed-visibility project/thread/team - > period-report endpoints could disclose full-population stored aggregates when - > at least one contributor remained visible. That defect is already isolated in - > #1050/#1054; #1054 is the security prerequisite and report authorization is not - > duplicated into #1042. Future #1042 integration requires a non-force descendant - > restack/reconstruction after that prerequisite lands. - > - > Customer-hint ownership repair #1055 is on exact - > `7dbd133320d8b12bde394569955e0ae6503f8f39`. Predecessor repository validation - > reached 1771 passed / 147 skipped and then exposed two owned REDs: migration - > 0250 was not replay-safe and the static SQL-review ledger still expected 36 - > suppressions after the repair legitimately removed one. Exact head now uses - > `CREATE TABLE IF NOT EXISTS` / `CREATE INDEX IF NOT EXISTS` and tracks 35 - > reviewed suppressions. Security `34731558854`, SAST `34731558875`, dynamic - > GitHub CodeQL `34731558343`, and Code Quality `34731558308` are GREEN. - > Repository Tests `34731586226`, Required Noema `34731558900`, and Strix - > `34731558917` are still live. Required CodeQL `34731558861` failed because - > compatibility consumers terminalized before the producer dispatch later - > succeeded; canonical owner `.github#1929` carries the unchanged-head canary. - > Required OpenCode `34731558957` failed closed without a current-head verdict. - > #1055 is Ready only as a live validation admission, not a merge-ready claim. - > - > #1054 remains Draft at `4519c101f13e08c10653b95ff88d66b4ce47f0b8` with - > repository Tests GREEN and central unchanged-head workflow reconciliation owned - > by `.github#2045`. Protected-main release metadata remains inconsistent: - > `pyproject.toml` declares 2.28.0 while `lineageweave.__version__` declares 2.20.0. - > No release is admitted while that blocker or any current required gate remains. - > PR #1041 remains Draft; every older overlay below is dated evidence only. - - """ - prefix = "# Product & Technical Gap Baseline\n\n" - if not text.startswith(prefix): - raise SystemExit("unexpected baseline header") - path.write_text(prefix + overlay + text[len(prefix):], encoding="utf-8") - Path(".github/workflows/bounded-gap-baseline-refresh.yml").unlink() - - - name: Commit bounded refresh - shell: bash - run: | - set -euo pipefail - git config user.name "github-actions[bot]" - git config user.email "41898282+github-actions[bot]@users.noreply.github.com" - git add docs/product-technical-gap-baseline.md .github/workflows/bounded-gap-baseline-refresh.yml - git commit -m "docs(gaps): refresh exact-head security evidence" - git push origin HEAD:codex/gap-loop-20260912 diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 0eab3d5a5..b985ea41b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,5 +1,41 @@ # Product & Technical Gap Baseline +> Exact-head loop overlay: 2026-09-13 11:00 KST. Protected `main` remains +> `83eba56149eb802cd63642c507c324c9976ec78e`. Customer Master process-unit +> repair #1042 is now Draft at exact +> `f23f5a567bd66113603837f86f030c3c459e69e6`: Strix `34721720240` +> terminalized FAILURE after setup and scan execution. Immutable artifact +> `10309695301` (95,509 bytes, +> `sha256:47822709dfdc45968569dbd4adf6bde167ba5eb46277503e906ee9625262d8b8`) +> contains one real Medium CWE-862 finding: mixed-visibility project/thread/team +> period-report endpoints could disclose full-population stored aggregates when +> at least one contributor remained visible. That defect is already isolated in +> #1050/#1054; #1054 is the security prerequisite and report authorization is not +> duplicated into #1042. Future #1042 integration requires a non-force descendant +> restack/reconstruction after that prerequisite lands. +> +> Customer-hint ownership repair #1055 is on exact +> `7dbd133320d8b12bde394569955e0ae6503f8f39`. Predecessor repository validation +> reached 1771 passed / 147 skipped and then exposed two owned REDs: migration +> 0250 was not replay-safe and the static SQL-review ledger still expected 36 +> suppressions after the repair legitimately removed one. Exact head now uses +> `CREATE TABLE IF NOT EXISTS` / `CREATE INDEX IF NOT EXISTS` and tracks 35 +> reviewed suppressions. Security `34731558854`, SAST `34731558875`, dynamic +> GitHub CodeQL `34731558343`, and Code Quality `34731558308` are GREEN. +> Repository Tests `34731586226`, Required Noema `34731558900`, and Strix +> `34731558917` are still live. Required CodeQL `34731558861` failed because +> compatibility consumers terminalized before the producer dispatch later +> succeeded; canonical owner `.github#1929` carries the unchanged-head canary. +> Required OpenCode `34731558957` failed closed without a current-head verdict. +> #1055 is Ready only as a live validation admission, not a merge-ready claim. +> +> #1054 remains Draft at `4519c101f13e08c10653b95ff88d66b4ce47f0b8` with +> repository Tests GREEN and central unchanged-head workflow reconciliation owned +> by `.github#2045`. Protected-main release metadata remains inconsistent: +> `pyproject.toml` declares 2.28.0 while `lineageweave.__version__` declares 2.20.0. +> No release is admitted while that blocker or any current required gate remains. +> PR #1041 remains Draft; every older overlay below is dated evidence only. + > Exact-head loop overlay: 2026-09-13 10:14 KST. Protected `main` remains > `83eba56149eb802cd63642c507c324c9976ec78e`, protected with a valid verified From cc7b942d24789eba2f0afa0ec7646193348d2a9e Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 11:53:49 +0900 Subject: [PATCH 034/276] chore(docs): stage bounded gap baseline refresh --- .github/workflows/zz-gap-baseline-refresh.yml | 80 +++++++++++++++++++ 1 file changed, 80 insertions(+) create mode 100644 .github/workflows/zz-gap-baseline-refresh.yml diff --git a/.github/workflows/zz-gap-baseline-refresh.yml b/.github/workflows/zz-gap-baseline-refresh.yml new file mode 100644 index 000000000..27e42196d --- /dev/null +++ b/.github/workflows/zz-gap-baseline-refresh.yml @@ -0,0 +1,80 @@ +name: Bounded gap baseline refresh + +on: + push: + branches: + - codex/gap-loop-20260912 + paths: + - .github/workflows/zz-gap-baseline-refresh.yml + +permissions: + contents: write + +concurrency: + group: lineageweave-gap-baseline-refresh + cancel-in-progress: false + +jobs: + refresh: + runs-on: ubuntu-latest + steps: + - name: Checkout exact branch + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 + with: + ref: codex/gap-loop-20260912 + fetch-depth: 0 + - name: Fast-forward any intervening ordinary delta + shell: bash + run: git pull --ff-only origin codex/gap-loop-20260912 + - name: Prepend current exact-head overlay + shell: bash + run: | + python - <<'PY' + from pathlib import Path + + path = Path("docs/product-technical-gap-baseline.md") + text = path.read_text(encoding="utf-8") + marker = "# Product & Technical Gap Baseline\n" + if not text.startswith(marker): + raise SystemExit("unexpected baseline heading; refusing partial rewrite") + overlay = r''' + + > Exact-head loop overlay: 2026-09-13 11:55 KST. Protected `main` is still + > `83eba56149eb802cd63642c507c324c9976ec78e`. Customer Master customer-hint + > ownership repair #1055 now has final causal head + > `b26e5391d087e2e9610a8c0d52eaeb68f1f912a7`. Predecessor `7dbd1333...` + > completed repository/full-PostgreSQL Tests, Security, SAST, dynamic CodeQL, + > Noema and Strix successfully but remained blocked by Required CodeQL/OpenCode; + > it returned to Draft before further changes, and those receipts do not transfer. + > + > Three ordinary non-force follow-ups close the remaining docstring/test-contract + > acceptance without changing Customer Master production semantics: focused unit + > helpers now have meaningful docstrings and assert the exact association INSERT + > tuple, the live PostgreSQL ownership proof is documented, and + > `tests/test_customer_hint_docstring_contract.py` AST-enforces docstrings on every + > production function owned/touched by this repair. #1055 is Ready only as exact-head + > validation admission. The causal `b26e5391...` push materialized ten fresh lanes, + > including repository Tests/Security/SAST/CodeQL, dynamic CodeQL/Code Quality, + > Required scheduler, Strix, OpenCode and Noema; they are currently queued/running. + > No predecessor GREEN or approval counts toward promotion. + > + > #1042, #1054, #1047, #1049 and #1046 remain Draft. #1042's real Medium CWE-862 + > period-report aggregate finding remains owned by #1050/#1054 rather than duplicated + > into Customer Master relationship-network code. Canonical central workflow defects + > remain `.github#1929` (CodeQL producer/consumer ordering) and `.github#2045` + > (unchanged-head Ready reconciliation). Protected-main release metadata remains + > inconsistent (`pyproject.toml` 2.28.0 versus `lineageweave.__version__` 2.20.0), + > so no release is admitted. PR #1041 remains Draft; older overlays are dated evidence. + ''' + path.write_text(marker + overlay + text[len(marker):], encoding="utf-8") + PY + - name: Remove purpose-complete refresh workflow and publish normally + shell: bash + run: | + rm .github/workflows/zz-gap-baseline-refresh.yml + git config user.name "github-actions[bot]" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + git add docs/product-technical-gap-baseline.md .github/workflows/zz-gap-baseline-refresh.yml + git diff --cached --check + git commit -m "docs(gaps): refresh exact-head product evidence" + git push origin HEAD:codex/gap-loop-20260912 From 21fa66d985c27f67c94b1dc7e66fbd8a18346fae Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Sun, 13 Sep 2026 02:55:34 +0000 Subject: [PATCH 035/276] docs(gaps): refresh exact-head product evidence --- .github/workflows/zz-gap-baseline-refresh.yml | 80 ------------------- docs/product-technical-gap-baseline.md | 28 +++++++ 2 files changed, 28 insertions(+), 80 deletions(-) delete mode 100644 .github/workflows/zz-gap-baseline-refresh.yml diff --git a/.github/workflows/zz-gap-baseline-refresh.yml b/.github/workflows/zz-gap-baseline-refresh.yml deleted file mode 100644 index 27e42196d..000000000 --- a/.github/workflows/zz-gap-baseline-refresh.yml +++ /dev/null @@ -1,80 +0,0 @@ -name: Bounded gap baseline refresh - -on: - push: - branches: - - codex/gap-loop-20260912 - paths: - - .github/workflows/zz-gap-baseline-refresh.yml - -permissions: - contents: write - -concurrency: - group: lineageweave-gap-baseline-refresh - cancel-in-progress: false - -jobs: - refresh: - runs-on: ubuntu-latest - steps: - - name: Checkout exact branch - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 - with: - ref: codex/gap-loop-20260912 - fetch-depth: 0 - - name: Fast-forward any intervening ordinary delta - shell: bash - run: git pull --ff-only origin codex/gap-loop-20260912 - - name: Prepend current exact-head overlay - shell: bash - run: | - python - <<'PY' - from pathlib import Path - - path = Path("docs/product-technical-gap-baseline.md") - text = path.read_text(encoding="utf-8") - marker = "# Product & Technical Gap Baseline\n" - if not text.startswith(marker): - raise SystemExit("unexpected baseline heading; refusing partial rewrite") - overlay = r''' - - > Exact-head loop overlay: 2026-09-13 11:55 KST. Protected `main` is still - > `83eba56149eb802cd63642c507c324c9976ec78e`. Customer Master customer-hint - > ownership repair #1055 now has final causal head - > `b26e5391d087e2e9610a8c0d52eaeb68f1f912a7`. Predecessor `7dbd1333...` - > completed repository/full-PostgreSQL Tests, Security, SAST, dynamic CodeQL, - > Noema and Strix successfully but remained blocked by Required CodeQL/OpenCode; - > it returned to Draft before further changes, and those receipts do not transfer. - > - > Three ordinary non-force follow-ups close the remaining docstring/test-contract - > acceptance without changing Customer Master production semantics: focused unit - > helpers now have meaningful docstrings and assert the exact association INSERT - > tuple, the live PostgreSQL ownership proof is documented, and - > `tests/test_customer_hint_docstring_contract.py` AST-enforces docstrings on every - > production function owned/touched by this repair. #1055 is Ready only as exact-head - > validation admission. The causal `b26e5391...` push materialized ten fresh lanes, - > including repository Tests/Security/SAST/CodeQL, dynamic CodeQL/Code Quality, - > Required scheduler, Strix, OpenCode and Noema; they are currently queued/running. - > No predecessor GREEN or approval counts toward promotion. - > - > #1042, #1054, #1047, #1049 and #1046 remain Draft. #1042's real Medium CWE-862 - > period-report aggregate finding remains owned by #1050/#1054 rather than duplicated - > into Customer Master relationship-network code. Canonical central workflow defects - > remain `.github#1929` (CodeQL producer/consumer ordering) and `.github#2045` - > (unchanged-head Ready reconciliation). Protected-main release metadata remains - > inconsistent (`pyproject.toml` 2.28.0 versus `lineageweave.__version__` 2.20.0), - > so no release is admitted. PR #1041 remains Draft; older overlays are dated evidence. - ''' - path.write_text(marker + overlay + text[len(marker):], encoding="utf-8") - PY - - name: Remove purpose-complete refresh workflow and publish normally - shell: bash - run: | - rm .github/workflows/zz-gap-baseline-refresh.yml - git config user.name "github-actions[bot]" - git config user.email "41898282+github-actions[bot]@users.noreply.github.com" - git add docs/product-technical-gap-baseline.md .github/workflows/zz-gap-baseline-refresh.yml - git diff --cached --check - git commit -m "docs(gaps): refresh exact-head product evidence" - git push origin HEAD:codex/gap-loop-20260912 diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b985ea41b..c41184803 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,5 +1,33 @@ # Product & Technical Gap Baseline + +> Exact-head loop overlay: 2026-09-13 11:55 KST. Protected `main` is still +> `83eba56149eb802cd63642c507c324c9976ec78e`. Customer Master customer-hint +> ownership repair #1055 now has final causal head +> `b26e5391d087e2e9610a8c0d52eaeb68f1f912a7`. Predecessor `7dbd1333...` +> completed repository/full-PostgreSQL Tests, Security, SAST, dynamic CodeQL, +> Noema and Strix successfully but remained blocked by Required CodeQL/OpenCode; +> it returned to Draft before further changes, and those receipts do not transfer. +> +> Three ordinary non-force follow-ups close the remaining docstring/test-contract +> acceptance without changing Customer Master production semantics: focused unit +> helpers now have meaningful docstrings and assert the exact association INSERT +> tuple, the live PostgreSQL ownership proof is documented, and +> `tests/test_customer_hint_docstring_contract.py` AST-enforces docstrings on every +> production function owned/touched by this repair. #1055 is Ready only as exact-head +> validation admission. The causal `b26e5391...` push materialized ten fresh lanes, +> including repository Tests/Security/SAST/CodeQL, dynamic CodeQL/Code Quality, +> Required scheduler, Strix, OpenCode and Noema; they are currently queued/running. +> No predecessor GREEN or approval counts toward promotion. +> +> #1042, #1054, #1047, #1049 and #1046 remain Draft. #1042's real Medium CWE-862 +> period-report aggregate finding remains owned by #1050/#1054 rather than duplicated +> into Customer Master relationship-network code. Canonical central workflow defects +> remain `.github#1929` (CodeQL producer/consumer ordering) and `.github#2045` +> (unchanged-head Ready reconciliation). Protected-main release metadata remains +> inconsistent (`pyproject.toml` 2.28.0 versus `lineageweave.__version__` 2.20.0), +> so no release is admitted. PR #1041 remains Draft; older overlays are dated evidence. + > Exact-head loop overlay: 2026-09-13 11:00 KST. Protected `main` remains > `83eba56149eb802cd63642c507c324c9976ec78e`. Customer Master process-unit > repair #1042 is now Draft at exact From a8fd61fd55d5ac86eb54cfc00646cb78f6d65aba Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 12:05:01 +0900 Subject: [PATCH 036/276] chore(docs): stage live-authority baseline refresh --- .../zz-gap-baseline-live-refresh.yml | 87 +++++++++++++++++++ 1 file changed, 87 insertions(+) create mode 100644 .github/workflows/zz-gap-baseline-live-refresh.yml diff --git a/.github/workflows/zz-gap-baseline-live-refresh.yml b/.github/workflows/zz-gap-baseline-live-refresh.yml new file mode 100644 index 000000000..dc7b1eaf9 --- /dev/null +++ b/.github/workflows/zz-gap-baseline-live-refresh.yml @@ -0,0 +1,87 @@ +name: Live-authority gap baseline refresh + +on: + push: + branches: + - codex/gap-loop-20260912 + paths: + - .github/workflows/zz-gap-baseline-live-refresh.yml + +permissions: + contents: write + pull-requests: read + issues: read + +concurrency: + group: lineageweave-gap-baseline-live-refresh + cancel-in-progress: false + +jobs: + refresh: + runs-on: ubuntu-latest + steps: + - name: Checkout exact branch + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 + with: + ref: codex/gap-loop-20260912 + fetch-depth: 0 + - name: Adopt intervening ordinary delta + shell: bash + run: git pull --ff-only origin codex/gap-loop-20260912 + - name: Read live GitHub authority and prepend overlay + shell: bash + env: + GH_TOKEN: ${{ github.token }} + GH_REPO: ContextualWisdomLab/LineageWeave + run: | + main_sha="$(gh api repos/$GH_REPO/branches/main --jq .commit.sha)" + pr_head="$(gh api repos/$GH_REPO/pulls/1055 --jq .head.sha)" + pr_draft="$(gh api repos/$GH_REPO/pulls/1055 --jq .draft)" + open_prs="$(gh api -X GET search/issues -f q='repo:ContextualWisdomLab/LineageWeave is:pr is:open' --jq .total_count)" + open_issues="$(gh api -X GET search/issues -f q='repo:ContextualWisdomLab/LineageWeave is:issue is:open' --jq .total_count)" + export MAIN_SHA="$main_sha" PR_HEAD="$pr_head" PR_DRAFT="$pr_draft" OPEN_PRS="$open_prs" OPEN_ISSUES="$open_issues" + python - <<'PY' + import os + from datetime import datetime, timezone, timedelta + from pathlib import Path + + path = Path("docs/product-technical-gap-baseline.md") + text = path.read_text(encoding="utf-8") + marker = "# Product & Technical Gap Baseline\n" + if not text.startswith(marker): + raise SystemExit("unexpected baseline heading; refusing partial rewrite") + kst = timezone(timedelta(hours=9)) + now = datetime.now(kst).strftime("%Y-%m-%d %H:%M KST") + readiness = "Draft" if os.environ["PR_DRAFT"] == "true" else "Ready validation admission" + overlay = f'''\n\n> Live-authority overlay: {now}. Protected `main` is `{os.environ["MAIN_SHA"]}`; +> inventory is {os.environ["OPEN_PRS"]} open PR / {os.environ["OPEN_ISSUES"]} open issue. +> Customer Master ownership repair #1055 is {readiness} at exact +> `{os.environ["PR_HEAD"]}`. Current repair separates source-post corporate/process +> authorization ownership from corroborated customer identity and delegates corporate +> catalog binding to the accepted `get_or_create_corporate_entity` owner (ADR 0010, +> ADR 0012, ADR 0160) instead of a Customer Master-local display-name lookup/direct +> insert. Source authorization locks are reacquired only for the short exact-source +> revalidation/persistence transaction after external corroboration/catalog resolution. +> Validation evidence from predecessor heads does not transfer across this head. +> +> #1042, #1054, #1047, #1049 and #1046 remain repair prerequisites/Draft unless +> their own live PR authority says otherwise. #1042's Medium CWE-862 period-report +> aggregate disclosure remains owned by #1050/#1054, not duplicated into Customer +> Master relationship code. Canonical central workflow defects remain `.github#1929` +> (required CodeQL producer/consumer ordering) and `.github#2045` (unchanged-head +> Ready reconciliation). Protected-main release metadata is still blocked by the +> tracked `pyproject.toml` 2.28.0 versus `lineageweave.__version__` 2.20.0 mismatch; +> no release is admitted from this overlay. Older overlays below are dated evidence. +''' + path.write_text(marker + overlay + text[len(marker):], encoding="utf-8") + PY + - name: Remove purpose-complete workflow and publish normally + shell: bash + run: | + rm .github/workflows/zz-gap-baseline-live-refresh.yml + git config user.name "github-actions[bot]" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + git add docs/product-technical-gap-baseline.md .github/workflows/zz-gap-baseline-live-refresh.yml + git diff --cached --check + git commit -m "docs(gaps): refresh live product authority" + git push origin HEAD:codex/gap-loop-20260912 From 2a2614ffba7cd0fd17db4811be3a269c320fdd48 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 12:10:24 +0900 Subject: [PATCH 037/276] fix(docs): repair bounded live baseline workflow --- .../zz-gap-baseline-live-refresh.yml | 46 ++++++++++--------- 1 file changed, 25 insertions(+), 21 deletions(-) diff --git a/.github/workflows/zz-gap-baseline-live-refresh.yml b/.github/workflows/zz-gap-baseline-live-refresh.yml index dc7b1eaf9..2059bba38 100644 --- a/.github/workflows/zz-gap-baseline-live-refresh.yml +++ b/.github/workflows/zz-gap-baseline-live-refresh.yml @@ -53,27 +53,31 @@ jobs: kst = timezone(timedelta(hours=9)) now = datetime.now(kst).strftime("%Y-%m-%d %H:%M KST") readiness = "Draft" if os.environ["PR_DRAFT"] == "true" else "Ready validation admission" - overlay = f'''\n\n> Live-authority overlay: {now}. Protected `main` is `{os.environ["MAIN_SHA"]}`; -> inventory is {os.environ["OPEN_PRS"]} open PR / {os.environ["OPEN_ISSUES"]} open issue. -> Customer Master ownership repair #1055 is {readiness} at exact -> `{os.environ["PR_HEAD"]}`. Current repair separates source-post corporate/process -> authorization ownership from corroborated customer identity and delegates corporate -> catalog binding to the accepted `get_or_create_corporate_entity` owner (ADR 0010, -> ADR 0012, ADR 0160) instead of a Customer Master-local display-name lookup/direct -> insert. Source authorization locks are reacquired only for the short exact-source -> revalidation/persistence transaction after external corroboration/catalog resolution. -> Validation evidence from predecessor heads does not transfer across this head. -> -> #1042, #1054, #1047, #1049 and #1046 remain repair prerequisites/Draft unless -> their own live PR authority says otherwise. #1042's Medium CWE-862 period-report -> aggregate disclosure remains owned by #1050/#1054, not duplicated into Customer -> Master relationship code. Canonical central workflow defects remain `.github#1929` -> (required CodeQL producer/consumer ordering) and `.github#2045` (unchanged-head -> Ready reconciliation). Protected-main release metadata is still blocked by the -> tracked `pyproject.toml` 2.28.0 versus `lineageweave.__version__` 2.20.0 mismatch; -> no release is admitted from this overlay. Older overlays below are dated evidence. -''' - path.write_text(marker + overlay + text[len(marker):], encoding="utf-8") + lines = [ + "", + "", + f"> Live-authority overlay: {now}. Protected `main` is `{os.environ['MAIN_SHA']}`;", + f"> inventory is {os.environ['OPEN_PRS']} open PR / {os.environ['OPEN_ISSUES']} open issue.", + f"> Customer Master ownership repair #1055 is {readiness} at exact", + f"> `{os.environ['PR_HEAD']}`. Current repair separates source-post corporate/process", + "> authorization ownership from corroborated customer identity and delegates corporate", + "> catalog binding to the accepted `get_or_create_corporate_entity` owner (ADR 0010,", + "> ADR 0012, ADR 0160) instead of a Customer Master-local display-name lookup/direct", + "> insert. Source authorization locks are reacquired only for the short exact-source", + "> revalidation/persistence transaction after external corroboration/catalog resolution.", + "> Validation evidence from predecessor heads does not transfer across this head.", + ">", + "> #1042, #1054, #1047, #1049 and #1046 remain repair prerequisites/Draft unless", + "> their own live PR authority says otherwise. #1042's Medium CWE-862 period-report", + "> aggregate disclosure remains owned by #1050/#1054, not duplicated into Customer", + "> Master relationship code. Canonical central workflow defects remain `.github#1929`", + "> (required CodeQL producer/consumer ordering) and `.github#2045` (unchanged-head", + "> Ready reconciliation). Protected-main release metadata is still blocked by the", + "> tracked `pyproject.toml` 2.28.0 versus `lineageweave.__version__` 2.20.0 mismatch;", + "> no release is admitted from this overlay. Older overlays below are dated evidence.", + "", + ] + path.write_text(marker + "\n".join(lines) + text[len(marker):], encoding="utf-8") PY - name: Remove purpose-complete workflow and publish normally shell: bash From 3e81a73a667e4b173a17e64e8ef6aaa98936770d Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Sun, 13 Sep 2026 03:11:06 +0000 Subject: [PATCH 038/276] docs(gaps): refresh live product authority --- .../zz-gap-baseline-live-refresh.yml | 91 ------------------- docs/product-technical-gap-baseline.md | 21 +++++ 2 files changed, 21 insertions(+), 91 deletions(-) delete mode 100644 .github/workflows/zz-gap-baseline-live-refresh.yml diff --git a/.github/workflows/zz-gap-baseline-live-refresh.yml b/.github/workflows/zz-gap-baseline-live-refresh.yml deleted file mode 100644 index 2059bba38..000000000 --- a/.github/workflows/zz-gap-baseline-live-refresh.yml +++ /dev/null @@ -1,91 +0,0 @@ -name: Live-authority gap baseline refresh - -on: - push: - branches: - - codex/gap-loop-20260912 - paths: - - .github/workflows/zz-gap-baseline-live-refresh.yml - -permissions: - contents: write - pull-requests: read - issues: read - -concurrency: - group: lineageweave-gap-baseline-live-refresh - cancel-in-progress: false - -jobs: - refresh: - runs-on: ubuntu-latest - steps: - - name: Checkout exact branch - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 - with: - ref: codex/gap-loop-20260912 - fetch-depth: 0 - - name: Adopt intervening ordinary delta - shell: bash - run: git pull --ff-only origin codex/gap-loop-20260912 - - name: Read live GitHub authority and prepend overlay - shell: bash - env: - GH_TOKEN: ${{ github.token }} - GH_REPO: ContextualWisdomLab/LineageWeave - run: | - main_sha="$(gh api repos/$GH_REPO/branches/main --jq .commit.sha)" - pr_head="$(gh api repos/$GH_REPO/pulls/1055 --jq .head.sha)" - pr_draft="$(gh api repos/$GH_REPO/pulls/1055 --jq .draft)" - open_prs="$(gh api -X GET search/issues -f q='repo:ContextualWisdomLab/LineageWeave is:pr is:open' --jq .total_count)" - open_issues="$(gh api -X GET search/issues -f q='repo:ContextualWisdomLab/LineageWeave is:issue is:open' --jq .total_count)" - export MAIN_SHA="$main_sha" PR_HEAD="$pr_head" PR_DRAFT="$pr_draft" OPEN_PRS="$open_prs" OPEN_ISSUES="$open_issues" - python - <<'PY' - import os - from datetime import datetime, timezone, timedelta - from pathlib import Path - - path = Path("docs/product-technical-gap-baseline.md") - text = path.read_text(encoding="utf-8") - marker = "# Product & Technical Gap Baseline\n" - if not text.startswith(marker): - raise SystemExit("unexpected baseline heading; refusing partial rewrite") - kst = timezone(timedelta(hours=9)) - now = datetime.now(kst).strftime("%Y-%m-%d %H:%M KST") - readiness = "Draft" if os.environ["PR_DRAFT"] == "true" else "Ready validation admission" - lines = [ - "", - "", - f"> Live-authority overlay: {now}. Protected `main` is `{os.environ['MAIN_SHA']}`;", - f"> inventory is {os.environ['OPEN_PRS']} open PR / {os.environ['OPEN_ISSUES']} open issue.", - f"> Customer Master ownership repair #1055 is {readiness} at exact", - f"> `{os.environ['PR_HEAD']}`. Current repair separates source-post corporate/process", - "> authorization ownership from corroborated customer identity and delegates corporate", - "> catalog binding to the accepted `get_or_create_corporate_entity` owner (ADR 0010,", - "> ADR 0012, ADR 0160) instead of a Customer Master-local display-name lookup/direct", - "> insert. Source authorization locks are reacquired only for the short exact-source", - "> revalidation/persistence transaction after external corroboration/catalog resolution.", - "> Validation evidence from predecessor heads does not transfer across this head.", - ">", - "> #1042, #1054, #1047, #1049 and #1046 remain repair prerequisites/Draft unless", - "> their own live PR authority says otherwise. #1042's Medium CWE-862 period-report", - "> aggregate disclosure remains owned by #1050/#1054, not duplicated into Customer", - "> Master relationship code. Canonical central workflow defects remain `.github#1929`", - "> (required CodeQL producer/consumer ordering) and `.github#2045` (unchanged-head", - "> Ready reconciliation). Protected-main release metadata is still blocked by the", - "> tracked `pyproject.toml` 2.28.0 versus `lineageweave.__version__` 2.20.0 mismatch;", - "> no release is admitted from this overlay. Older overlays below are dated evidence.", - "", - ] - path.write_text(marker + "\n".join(lines) + text[len(marker):], encoding="utf-8") - PY - - name: Remove purpose-complete workflow and publish normally - shell: bash - run: | - rm .github/workflows/zz-gap-baseline-live-refresh.yml - git config user.name "github-actions[bot]" - git config user.email "41898282+github-actions[bot]@users.noreply.github.com" - git add docs/product-technical-gap-baseline.md .github/workflows/zz-gap-baseline-live-refresh.yml - git diff --cached --check - git commit -m "docs(gaps): refresh live product authority" - git push origin HEAD:codex/gap-loop-20260912 diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index c41184803..f6dea3dd2 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,27 @@ # Product & Technical Gap Baseline +> Live-authority overlay: 2026-09-13 12:11 KST. Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`; +> inventory is 159 open PR / 36 open issue. +> Customer Master ownership repair #1055 is Ready validation admission at exact +> `08a08108a87657ad427a6b6fa9b1b327166b0c9e`. Current repair separates source-post corporate/process +> authorization ownership from corroborated customer identity and delegates corporate +> catalog binding to the accepted `get_or_create_corporate_entity` owner (ADR 0010, +> ADR 0012, ADR 0160) instead of a Customer Master-local display-name lookup/direct +> insert. Source authorization locks are reacquired only for the short exact-source +> revalidation/persistence transaction after external corroboration/catalog resolution. +> Validation evidence from predecessor heads does not transfer across this head. +> +> #1042, #1054, #1047, #1049 and #1046 remain repair prerequisites/Draft unless +> their own live PR authority says otherwise. #1042's Medium CWE-862 period-report +> aggregate disclosure remains owned by #1050/#1054, not duplicated into Customer +> Master relationship code. Canonical central workflow defects remain `.github#1929` +> (required CodeQL producer/consumer ordering) and `.github#2045` (unchanged-head +> Ready reconciliation). Protected-main release metadata is still blocked by the +> tracked `pyproject.toml` 2.28.0 versus `lineageweave.__version__` 2.20.0 mismatch; +> no release is admitted from this overlay. Older overlays below are dated evidence. + + > Exact-head loop overlay: 2026-09-13 11:55 KST. Protected `main` is still > `83eba56149eb802cd63642c507c324c9976ec78e`. Customer Master customer-hint > ownership repair #1055 now has final causal head From 38afe0fef62b1316d9a71ccebf088dab4a439ac8 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 12:33:25 +0900 Subject: [PATCH 039/276] chore(gaps): stage bounded authority refresh --- .../bounded-gap-baseline-refresh.yml | 87 +++++++++++++++++++ 1 file changed, 87 insertions(+) create mode 100644 .github/workflows/bounded-gap-baseline-refresh.yml diff --git a/.github/workflows/bounded-gap-baseline-refresh.yml b/.github/workflows/bounded-gap-baseline-refresh.yml new file mode 100644 index 000000000..f3a880d4f --- /dev/null +++ b/.github/workflows/bounded-gap-baseline-refresh.yml @@ -0,0 +1,87 @@ +name: Bounded gap baseline refresh + +on: + push: + branches: + - codex/gap-loop-20260912 + paths: + - .github/workflows/bounded-gap-baseline-refresh.yml + +permissions: + contents: write + +jobs: + refresh: + runs-on: ubuntu-24.04 + steps: + - name: Checkout exact branch head + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # actions/checkout@v7 + with: + ref: codex/gap-loop-20260912 + fetch-depth: 1 + + - name: Prepend current authority overlay + shell: bash + run: | + python - <<'PY' + from pathlib import Path + + path = Path("docs/product-technical-gap-baseline.md") + text = path.read_text(encoding="utf-8") + prefix = "# Product & Technical Gap Baseline\n\n" + if not text.startswith(prefix): + raise SystemExit("baseline heading changed; refusing bounded rewrite") + marker = "> Live-authority overlay: 2026-09-13 12:31 KST." + if marker in text: + raise SystemExit("current overlay already present") + overlay = """> Live-authority overlay: 2026-09-13 12:31 KST. Protected `main` is +> `83eba56149eb802cd63642c507c324c9976ec78e`; fresh inventory is 159 open PR / +> 37 open issue. #1055 remains the only active Customer Master source lane, Ready +> solely as exact-head validation admission at `08a08108a87657ad427a6b6fa9b1b327166b0c9e`. +> Frontend lint/test/build/Storybook, SAST, dynamic GitHub CodeQL/Code Quality, +> Security Scorecard and Trivy are GREEN. Full PostgreSQL Tests `34734746020`, +> Required Noema, Strix and OpenCode remain live. Required CodeQL `34734709986` +> reproduced `.github#1929`: JavaScript/Python/Actions compatibility consumers +> terminalized FAILURE before the producer dispatch job existed; the producer later +> succeeded, which does not reconcile those required contexts. +> +> Current review also found one LineageWeave-owned executable RED on #1055: the +> existing exact Customer Master `source_customer_hints` assertion still expects +> the pre-resolution response shape, while production now returns resolved corporate +> id/name/evidence plus normalized-resolution provenance. Preserve the live +> PostgreSQL lane until that hosted RED terminalizes; then repair only the stale +> expected contract and revalidate the resulting causal head. Do not weaken the +> production serialization or manufacture validation with no-op commits/lifecycle +> churn. +> +> Post Chat persistence issue #1053 now owns the next buyer/security gap: protected +> `persist_post_chat` deletes and reinserts durable state keyed only by +> `(post_id, question_norm)`. Its chosen invariant is scope-owned durable answers +> whose identity also binds the #1047 authorization/evidence receipt; #1047 remains +> the replay-disclosure owner. No competing source PR is opened while #1055 is live. +> +> Release identity mismatch now has dedicated owner #1056. Protected `pyproject.toml` +> declares 2.28.0 while runtime `lineageweave.__version__` is 2.20.0 and feeds +> persisted analysis/reconstruction version evidence. LineageWeave currently has no +> GitHub Release and no local release/SBOM workflow caller; implementation must use +> a thin exact-SHA caller of canonical `.github` artifact/SBOM attestation rather +> than copying verifier policy. No immutable release is admitted until #1056 and +> all promotion gates converge. Older overlays below remain dated evidence only. + +""" + path.write_text(prefix + overlay + text[len(prefix):], encoding="utf-8") + PY + + - name: Remove purpose-complete workflow and publish ordinary commit + shell: bash + run: | + git rm .github/workflows/bounded-gap-baseline-refresh.yml + git add docs/product-technical-gap-baseline.md + if git diff --cached --quiet; then + echo "no bounded delta" + exit 1 + fi + git config user.name "Seongho Bae" + git config user.email "me@seonghobae.me" + git commit -m "docs(gaps): refresh exact-head authority" + git push origin HEAD:codex/gap-loop-20260912 From c7f25ade5181bed1b3d898018ea970efa5535a15 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 12:33:50 +0900 Subject: [PATCH 040/276] chore(gaps): remove failed bounded refresh helper --- .../bounded-gap-baseline-refresh.yml | 87 ------------------- 1 file changed, 87 deletions(-) delete mode 100644 .github/workflows/bounded-gap-baseline-refresh.yml diff --git a/.github/workflows/bounded-gap-baseline-refresh.yml b/.github/workflows/bounded-gap-baseline-refresh.yml deleted file mode 100644 index f3a880d4f..000000000 --- a/.github/workflows/bounded-gap-baseline-refresh.yml +++ /dev/null @@ -1,87 +0,0 @@ -name: Bounded gap baseline refresh - -on: - push: - branches: - - codex/gap-loop-20260912 - paths: - - .github/workflows/bounded-gap-baseline-refresh.yml - -permissions: - contents: write - -jobs: - refresh: - runs-on: ubuntu-24.04 - steps: - - name: Checkout exact branch head - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # actions/checkout@v7 - with: - ref: codex/gap-loop-20260912 - fetch-depth: 1 - - - name: Prepend current authority overlay - shell: bash - run: | - python - <<'PY' - from pathlib import Path - - path = Path("docs/product-technical-gap-baseline.md") - text = path.read_text(encoding="utf-8") - prefix = "# Product & Technical Gap Baseline\n\n" - if not text.startswith(prefix): - raise SystemExit("baseline heading changed; refusing bounded rewrite") - marker = "> Live-authority overlay: 2026-09-13 12:31 KST." - if marker in text: - raise SystemExit("current overlay already present") - overlay = """> Live-authority overlay: 2026-09-13 12:31 KST. Protected `main` is -> `83eba56149eb802cd63642c507c324c9976ec78e`; fresh inventory is 159 open PR / -> 37 open issue. #1055 remains the only active Customer Master source lane, Ready -> solely as exact-head validation admission at `08a08108a87657ad427a6b6fa9b1b327166b0c9e`. -> Frontend lint/test/build/Storybook, SAST, dynamic GitHub CodeQL/Code Quality, -> Security Scorecard and Trivy are GREEN. Full PostgreSQL Tests `34734746020`, -> Required Noema, Strix and OpenCode remain live. Required CodeQL `34734709986` -> reproduced `.github#1929`: JavaScript/Python/Actions compatibility consumers -> terminalized FAILURE before the producer dispatch job existed; the producer later -> succeeded, which does not reconcile those required contexts. -> -> Current review also found one LineageWeave-owned executable RED on #1055: the -> existing exact Customer Master `source_customer_hints` assertion still expects -> the pre-resolution response shape, while production now returns resolved corporate -> id/name/evidence plus normalized-resolution provenance. Preserve the live -> PostgreSQL lane until that hosted RED terminalizes; then repair only the stale -> expected contract and revalidate the resulting causal head. Do not weaken the -> production serialization or manufacture validation with no-op commits/lifecycle -> churn. -> -> Post Chat persistence issue #1053 now owns the next buyer/security gap: protected -> `persist_post_chat` deletes and reinserts durable state keyed only by -> `(post_id, question_norm)`. Its chosen invariant is scope-owned durable answers -> whose identity also binds the #1047 authorization/evidence receipt; #1047 remains -> the replay-disclosure owner. No competing source PR is opened while #1055 is live. -> -> Release identity mismatch now has dedicated owner #1056. Protected `pyproject.toml` -> declares 2.28.0 while runtime `lineageweave.__version__` is 2.20.0 and feeds -> persisted analysis/reconstruction version evidence. LineageWeave currently has no -> GitHub Release and no local release/SBOM workflow caller; implementation must use -> a thin exact-SHA caller of canonical `.github` artifact/SBOM attestation rather -> than copying verifier policy. No immutable release is admitted until #1056 and -> all promotion gates converge. Older overlays below remain dated evidence only. - -""" - path.write_text(prefix + overlay + text[len(prefix):], encoding="utf-8") - PY - - - name: Remove purpose-complete workflow and publish ordinary commit - shell: bash - run: | - git rm .github/workflows/bounded-gap-baseline-refresh.yml - git add docs/product-technical-gap-baseline.md - if git diff --cached --quiet; then - echo "no bounded delta" - exit 1 - fi - git config user.name "Seongho Bae" - git config user.email "me@seonghobae.me" - git commit -m "docs(gaps): refresh exact-head authority" - git push origin HEAD:codex/gap-loop-20260912 From f7933a4de38e97fdac77f42fcece03f2d46a12ce Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 15:18:30 +0900 Subject: [PATCH 041/276] chore(docs): stage bounded baseline refresh --- .../refresh-gap-baseline-20260913.yml | 67 +++++++++++++++++++ 1 file changed, 67 insertions(+) create mode 100644 .github/workflows/refresh-gap-baseline-20260913.yml diff --git a/.github/workflows/refresh-gap-baseline-20260913.yml b/.github/workflows/refresh-gap-baseline-20260913.yml new file mode 100644 index 000000000..af91ce22a --- /dev/null +++ b/.github/workflows/refresh-gap-baseline-20260913.yml @@ -0,0 +1,67 @@ +name: Bounded product gap baseline refresh + +on: + push: + branches: + - codex/gap-loop-20260912 + +permissions: + contents: write + +jobs: + refresh: + if: github.actor != 'github-actions[bot]' + runs-on: ubuntu-24.04 + steps: + - name: Checkout exact branch head + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # actions/checkout@v7 + with: + ref: codex/gap-loop-20260912 + fetch-depth: 0 + persist-credentials: false + + - name: Verify single-writer head + shell: bash + run: | + set -euo pipefail + remote_head="$(git ls-remote origin refs/heads/codex/gap-loop-20260912 | cut -f1)" + test "$remote_head" = "$GITHUB_SHA" + test "$(git rev-parse HEAD)" = "$GITHUB_SHA" + + - name: Refresh current authority overlay + shell: bash + run: | + set -euo pipefail + python - <<'PY' + from pathlib import Path + from datetime import datetime + from zoneinfo import ZoneInfo + + path = Path('docs/product-technical-gap-baseline.md') + text = path.read_text() + title = '# Product & Technical Gap Baseline\n' + if not text.startswith(title): + raise SystemExit('unexpected baseline title') + stamp = datetime.now(ZoneInfo('Asia/Seoul')).strftime('%Y-%m-%d %H:%M KST') + overlay = f'''\n\n> Live-authority overlay: {stamp}. Protected `main` remains\n> `83eba56149eb802cd63642c507c324c9976ec78e` pending final double sweep.\n> Customer Master ownership issue #1052 / Draft PR #1055 is now at exact\n> `831fc52a1969f2999109da2c061067a9dc0ae954`. Bounded repair run\n> `34741807255 / 103682639248` reproduced the ordinary-hosted response-contract\n> RED, applied the minimal serializer/E2E expectation repair, obtained focused\n> GREEN, and published a self-cleaning ordinary commit. The current head adds\n> `tests/test_customer_master_hint_response_contract.py`, updates the real-service\n> `backend/tests/test_api.py` expectation, and contains no temporary repair workflow.\n> All #1055 inline review threads are resolved.\n>\n> Current-head central workflow identities are Draft lifecycle `action_required`,\n> not GREEN receipts. Immediate parent `b9346dc681997a0274194d2ed913a22bb7488cca`\n> has SAST/Security/dynamic-CodeQL/Code-Quality/OpenCode/Strix success; Required\n> CodeQL remains the canonical `.github#1929` ordering/reconciliation failure, and\n> predecessor Noema evidence cannot authorize `831fc52...`. `.github#2045` remains\n> open for unchanged-head Draft-to-Ready materialization, so no empty commit or\n> lifecycle-flip loop is used to manufacture current-head evidence.\n>\n> Issue #1057 still owns the hosted PostgreSQL + local Keycloak development fixture\n> + Valkey bearer/JWKS/RBAC/ABAC lane. Its original #1055 response-shape canary is\n> repaired, but the service-wide-skip topology defect remains. #1042/#1054/#1047/\n> #1049/#1046 remain Draft under their own live authority. Protected-main release\n> identity remains blocked by #1056 (`pyproject.toml` 2.28.0 versus runtime\n> `lineageweave.__version__` 2.20.0); OpenTelemetry and PostgreSQL warning owners\n> remain #1036/#973 and #1038/#1040. No release is admitted by this overlay. Older\n> overlays below are dated evidence only.\n''' + path.write_text(title + overlay + text[len(title):]) + PY + + - name: Publish ordinary self-cleaning docs commit + shell: bash + env: + GITHUB_TOKEN: ${{ github.token }} + run: | + set -euo pipefail + rm .github/workflows/refresh-gap-baseline-20260913.yml + git add docs/product-technical-gap-baseline.md .github/workflows/refresh-gap-baseline-20260913.yml + if git diff --cached --quiet; then + echo 'No baseline delta to publish' >&2 + exit 1 + fi + remote_head="$(git ls-remote origin refs/heads/codex/gap-loop-20260912 | cut -f1)" + test "$remote_head" = "$GITHUB_SHA" + git config user.name 'github-actions[bot]' + git config user.email '41898282+github-actions[bot]@users.noreply.github.com' + git commit -m 'docs(gaps): refresh current product authority' + git push "https://x-access-token:${GITHUB_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" HEAD:codex/gap-loop-20260912 From 015c8ea2cb88080ba7f30db570e911c25822ae1a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 15:23:05 +0900 Subject: [PATCH 042/276] docs(gaps): converge release owner authority --- .github/workflows/refresh-gap-baseline-20260913.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/refresh-gap-baseline-20260913.yml b/.github/workflows/refresh-gap-baseline-20260913.yml index af91ce22a..7c8397d7f 100644 --- a/.github/workflows/refresh-gap-baseline-20260913.yml +++ b/.github/workflows/refresh-gap-baseline-20260913.yml @@ -43,7 +43,7 @@ jobs: if not text.startswith(title): raise SystemExit('unexpected baseline title') stamp = datetime.now(ZoneInfo('Asia/Seoul')).strftime('%Y-%m-%d %H:%M KST') - overlay = f'''\n\n> Live-authority overlay: {stamp}. Protected `main` remains\n> `83eba56149eb802cd63642c507c324c9976ec78e` pending final double sweep.\n> Customer Master ownership issue #1052 / Draft PR #1055 is now at exact\n> `831fc52a1969f2999109da2c061067a9dc0ae954`. Bounded repair run\n> `34741807255 / 103682639248` reproduced the ordinary-hosted response-contract\n> RED, applied the minimal serializer/E2E expectation repair, obtained focused\n> GREEN, and published a self-cleaning ordinary commit. The current head adds\n> `tests/test_customer_master_hint_response_contract.py`, updates the real-service\n> `backend/tests/test_api.py` expectation, and contains no temporary repair workflow.\n> All #1055 inline review threads are resolved.\n>\n> Current-head central workflow identities are Draft lifecycle `action_required`,\n> not GREEN receipts. Immediate parent `b9346dc681997a0274194d2ed913a22bb7488cca`\n> has SAST/Security/dynamic-CodeQL/Code-Quality/OpenCode/Strix success; Required\n> CodeQL remains the canonical `.github#1929` ordering/reconciliation failure, and\n> predecessor Noema evidence cannot authorize `831fc52...`. `.github#2045` remains\n> open for unchanged-head Draft-to-Ready materialization, so no empty commit or\n> lifecycle-flip loop is used to manufacture current-head evidence.\n>\n> Issue #1057 still owns the hosted PostgreSQL + local Keycloak development fixture\n> + Valkey bearer/JWKS/RBAC/ABAC lane. Its original #1055 response-shape canary is\n> repaired, but the service-wide-skip topology defect remains. #1042/#1054/#1047/\n> #1049/#1046 remain Draft under their own live authority. Protected-main release\n> identity remains blocked by #1056 (`pyproject.toml` 2.28.0 versus runtime\n> `lineageweave.__version__` 2.20.0); OpenTelemetry and PostgreSQL warning owners\n> remain #1036/#973 and #1038/#1040. No release is admitted by this overlay. Older\n> overlays below are dated evidence only.\n''' + overlay = f'''\n\n> Live-authority overlay: {stamp}. Protected `main` remains\n> `83eba56149eb802cd63642c507c324c9976ec78e` pending final double sweep.\n> Customer Master ownership issue #1052 / Draft PR #1055 is now at exact\n> `831fc52a1969f2999109da2c061067a9dc0ae954`. Bounded repair run\n> `34741807255 / 103682639248` reproduced the ordinary-hosted response-contract\n> RED, applied the minimal serializer/E2E expectation repair, obtained focused\n> GREEN, and published a self-cleaning ordinary commit. The current head adds\n> `tests/test_customer_master_hint_response_contract.py`, updates the real-service\n> `backend/tests/test_api.py` expectation, and contains no temporary repair workflow.\n> All #1055 inline review threads are resolved.\n>\n> Current-head central workflow identities are Draft lifecycle `action_required`,\n> not GREEN receipts. Immediate parent `b9346dc681997a0274194d2ed913a22bb7488cca`\n> has SAST/Security/dynamic-CodeQL/Code-Quality/OpenCode/Strix success; Required\n> CodeQL remains the canonical `.github#1929` ordering/reconciliation failure, and\n> predecessor Noema evidence cannot authorize `831fc52...`. `.github#2045` remains\n> open for unchanged-head Draft-to-Ready materialization, so no empty commit or\n> lifecycle-flip loop is used to manufacture current-head evidence.\n>\n> Issue #1057 still owns the hosted PostgreSQL + local Keycloak development fixture\n> + Valkey bearer/JWKS/RBAC/ABAC lane. Its original #1055 response-shape canary is\n> repaired, but the service-wide-skip topology defect remains. #1042/#1054/#1047/\n> #1049/#1046 remain Draft under their own live authority. Protected-main release\n> identity source repair is existing Draft PR #961 at exact\n> `3bdec0504a65e63f44bd49ba15de37182a1672cc`; issue #1056 now converges release,\n> SBOM, provenance, reproducibility and rollback acceptance onto that single writer\n> rather than spawning a competing lane. Protected main itself still reports\n> `pyproject.toml` 2.28.0 versus runtime `lineageweave.__version__` 2.20.0 until\n> normal integration. OpenTelemetry and PostgreSQL warning owners remain #1036/#973\n> and #1038/#1040. No release is admitted by this overlay. Older overlays below are\n> dated evidence only.\n''' path.write_text(title + overlay + text[len(title):]) PY From d188b85ddc0219fb3ed3c9930ae13f63beed295e Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Sun, 13 Sep 2026 06:24:50 +0000 Subject: [PATCH 043/276] docs(gaps): refresh current product authority --- .../refresh-gap-baseline-20260913.yml | 67 ------------------- docs/product-technical-gap-baseline.md | 33 +++++++++ 2 files changed, 33 insertions(+), 67 deletions(-) delete mode 100644 .github/workflows/refresh-gap-baseline-20260913.yml diff --git a/.github/workflows/refresh-gap-baseline-20260913.yml b/.github/workflows/refresh-gap-baseline-20260913.yml deleted file mode 100644 index 7c8397d7f..000000000 --- a/.github/workflows/refresh-gap-baseline-20260913.yml +++ /dev/null @@ -1,67 +0,0 @@ -name: Bounded product gap baseline refresh - -on: - push: - branches: - - codex/gap-loop-20260912 - -permissions: - contents: write - -jobs: - refresh: - if: github.actor != 'github-actions[bot]' - runs-on: ubuntu-24.04 - steps: - - name: Checkout exact branch head - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # actions/checkout@v7 - with: - ref: codex/gap-loop-20260912 - fetch-depth: 0 - persist-credentials: false - - - name: Verify single-writer head - shell: bash - run: | - set -euo pipefail - remote_head="$(git ls-remote origin refs/heads/codex/gap-loop-20260912 | cut -f1)" - test "$remote_head" = "$GITHUB_SHA" - test "$(git rev-parse HEAD)" = "$GITHUB_SHA" - - - name: Refresh current authority overlay - shell: bash - run: | - set -euo pipefail - python - <<'PY' - from pathlib import Path - from datetime import datetime - from zoneinfo import ZoneInfo - - path = Path('docs/product-technical-gap-baseline.md') - text = path.read_text() - title = '# Product & Technical Gap Baseline\n' - if not text.startswith(title): - raise SystemExit('unexpected baseline title') - stamp = datetime.now(ZoneInfo('Asia/Seoul')).strftime('%Y-%m-%d %H:%M KST') - overlay = f'''\n\n> Live-authority overlay: {stamp}. Protected `main` remains\n> `83eba56149eb802cd63642c507c324c9976ec78e` pending final double sweep.\n> Customer Master ownership issue #1052 / Draft PR #1055 is now at exact\n> `831fc52a1969f2999109da2c061067a9dc0ae954`. Bounded repair run\n> `34741807255 / 103682639248` reproduced the ordinary-hosted response-contract\n> RED, applied the minimal serializer/E2E expectation repair, obtained focused\n> GREEN, and published a self-cleaning ordinary commit. The current head adds\n> `tests/test_customer_master_hint_response_contract.py`, updates the real-service\n> `backend/tests/test_api.py` expectation, and contains no temporary repair workflow.\n> All #1055 inline review threads are resolved.\n>\n> Current-head central workflow identities are Draft lifecycle `action_required`,\n> not GREEN receipts. Immediate parent `b9346dc681997a0274194d2ed913a22bb7488cca`\n> has SAST/Security/dynamic-CodeQL/Code-Quality/OpenCode/Strix success; Required\n> CodeQL remains the canonical `.github#1929` ordering/reconciliation failure, and\n> predecessor Noema evidence cannot authorize `831fc52...`. `.github#2045` remains\n> open for unchanged-head Draft-to-Ready materialization, so no empty commit or\n> lifecycle-flip loop is used to manufacture current-head evidence.\n>\n> Issue #1057 still owns the hosted PostgreSQL + local Keycloak development fixture\n> + Valkey bearer/JWKS/RBAC/ABAC lane. Its original #1055 response-shape canary is\n> repaired, but the service-wide-skip topology defect remains. #1042/#1054/#1047/\n> #1049/#1046 remain Draft under their own live authority. Protected-main release\n> identity source repair is existing Draft PR #961 at exact\n> `3bdec0504a65e63f44bd49ba15de37182a1672cc`; issue #1056 now converges release,\n> SBOM, provenance, reproducibility and rollback acceptance onto that single writer\n> rather than spawning a competing lane. Protected main itself still reports\n> `pyproject.toml` 2.28.0 versus runtime `lineageweave.__version__` 2.20.0 until\n> normal integration. OpenTelemetry and PostgreSQL warning owners remain #1036/#973\n> and #1038/#1040. No release is admitted by this overlay. Older overlays below are\n> dated evidence only.\n''' - path.write_text(title + overlay + text[len(title):]) - PY - - - name: Publish ordinary self-cleaning docs commit - shell: bash - env: - GITHUB_TOKEN: ${{ github.token }} - run: | - set -euo pipefail - rm .github/workflows/refresh-gap-baseline-20260913.yml - git add docs/product-technical-gap-baseline.md .github/workflows/refresh-gap-baseline-20260913.yml - if git diff --cached --quiet; then - echo 'No baseline delta to publish' >&2 - exit 1 - fi - remote_head="$(git ls-remote origin refs/heads/codex/gap-loop-20260912 | cut -f1)" - test "$remote_head" = "$GITHUB_SHA" - git config user.name 'github-actions[bot]' - git config user.email '41898282+github-actions[bot]@users.noreply.github.com' - git commit -m 'docs(gaps): refresh current product authority' - git push "https://x-access-token:${GITHUB_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" HEAD:codex/gap-loop-20260912 diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index f6dea3dd2..e0d7d0e57 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,39 @@ # Product & Technical Gap Baseline +> Live-authority overlay: 2026-09-13 15:24 KST. Protected `main` remains +> `83eba56149eb802cd63642c507c324c9976ec78e` pending final double sweep. +> Customer Master ownership issue #1052 / Draft PR #1055 is now at exact +> `831fc52a1969f2999109da2c061067a9dc0ae954`. Bounded repair run +> `34741807255 / 103682639248` reproduced the ordinary-hosted response-contract +> RED, applied the minimal serializer/E2E expectation repair, obtained focused +> GREEN, and published a self-cleaning ordinary commit. The current head adds +> `tests/test_customer_master_hint_response_contract.py`, updates the real-service +> `backend/tests/test_api.py` expectation, and contains no temporary repair workflow. +> All #1055 inline review threads are resolved. +> +> Current-head central workflow identities are Draft lifecycle `action_required`, +> not GREEN receipts. Immediate parent `b9346dc681997a0274194d2ed913a22bb7488cca` +> has SAST/Security/dynamic-CodeQL/Code-Quality/OpenCode/Strix success; Required +> CodeQL remains the canonical `.github#1929` ordering/reconciliation failure, and +> predecessor Noema evidence cannot authorize `831fc52...`. `.github#2045` remains +> open for unchanged-head Draft-to-Ready materialization, so no empty commit or +> lifecycle-flip loop is used to manufacture current-head evidence. +> +> Issue #1057 still owns the hosted PostgreSQL + local Keycloak development fixture +> + Valkey bearer/JWKS/RBAC/ABAC lane. Its original #1055 response-shape canary is +> repaired, but the service-wide-skip topology defect remains. #1042/#1054/#1047/ +> #1049/#1046 remain Draft under their own live authority. Protected-main release +> identity source repair is existing Draft PR #961 at exact +> `3bdec0504a65e63f44bd49ba15de37182a1672cc`; issue #1056 now converges release, +> SBOM, provenance, reproducibility and rollback acceptance onto that single writer +> rather than spawning a competing lane. Protected main itself still reports +> `pyproject.toml` 2.28.0 versus runtime `lineageweave.__version__` 2.20.0 until +> normal integration. OpenTelemetry and PostgreSQL warning owners remain #1036/#973 +> and #1038/#1040. No release is admitted by this overlay. Older overlays below are +> dated evidence only. + + > Live-authority overlay: 2026-09-13 12:11 KST. Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`; > inventory is 159 open PR / 36 open issue. > Customer Master ownership repair #1055 is Ready validation admission at exact From b21ef49fc0219ebf3b28cdc1cf0a9977d56dbf43 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 16:50:47 +0900 Subject: [PATCH 044/276] chore(docs): stage bounded gap baseline refresh --- .../refresh-gap-baseline-20260913-1650.yml | 87 +++++++++++++++++++ 1 file changed, 87 insertions(+) create mode 100644 .github/workflows/refresh-gap-baseline-20260913-1650.yml diff --git a/.github/workflows/refresh-gap-baseline-20260913-1650.yml b/.github/workflows/refresh-gap-baseline-20260913-1650.yml new file mode 100644 index 000000000..5a27a7b54 --- /dev/null +++ b/.github/workflows/refresh-gap-baseline-20260913-1650.yml @@ -0,0 +1,87 @@ +name: Refresh gap baseline 2026-09-13 1650 + +on: + push: + branches: [codex/gap-loop-20260912] + paths: + - .github/workflows/refresh-gap-baseline-20260913-1650.yml + +permissions: + contents: write + +concurrency: + group: refresh-gap-baseline-20260913-1650 + cancel-in-progress: false + +jobs: + refresh: + runs-on: ubuntu-latest + steps: + - name: Checkout documentation lane + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # actions/checkout@v7 + with: + ref: codex/gap-loop-20260912 + fetch-depth: 1 + + - name: Prepend current live-authority overlay + shell: bash + run: | + python - <<'PY' + from pathlib import Path + + path = Path("docs/product-technical-gap-baseline.md") + text = path.read_text(encoding="utf-8") + title = "# Product & Technical Gap Baseline\n" + if not text.startswith(title): + raise SystemExit("unexpected baseline title") + + overlay = r''' + +> Live-authority overlay: 2026-09-13 16:50 KST. Protected `main` remains +> `83eba56149eb802cd63642c507c324c9976ec78e`, protected and signed/verified. +> Customer Master ownership issue #1052 / PR #1055 advanced to exact +> `50c4935eef1029467595f7004818643598b737c9`, Ready only for validation +> admission. Predecessor `8448a2b4e06c6ef415dd98b3eaa1f7f36669fe94` +> exposed a real repository RED after the shared eligibility SQL qualification: +> Tests `34743575403` ended `2 failed, 1777 passed, 147 skipped`. The two failures +> were the corroborated-association/reused-catalog unit tests. RCA showed their +> fake query recognizers still expected the old unqualified `select post_id ...` +> SQL, so they returned no captured evidence after production queries were +> correctly qualified with `source_post.*`; the scope-change test also stopped +> reaching its intended revalidation phase. +> +> Causal commit `50c4935e...` changes only those unit-fake recognizers to the +> canonical qualified capture/revalidation SQL. It does not change production +> authorization, persistence, locking, provider/model selection or workflow +> gates. Fresh exact-head validation materialized without no-op churn. Frontend +> lint/test/build/Storybook is GREEN; Security `34746058657` and SAST +> `34746058639` are GREEN. Full PostgreSQL Tests `34746058653`, Required CodeQL +> `34746058693`, Noema `34746057619` and Strix `34746057545` remain live at this +> snapshot. Required OpenCode `34746057593` is terminal FAILURE, so #1055 is not +> merge-ready and no predecessor review receipt transfers. All visible inline +> review threads are resolved/outdated. +> +> #1057 remains the separate required PostgreSQL + Keycloak + Valkey +> bearer/JWKS/RBAC/ABAC hosted-topology owner. Central required-workflow repair +> remains in `.github#1929/#2106` for CodeQL producer/consumer settlement and +> `.github#2045/#2109` for Ready-transition/model-review reconciliation; +> LineageWeave does not copy those owner implementations. Draft #961 remains the +> package/runtime-version source repair and #1056 carries immutable +> release/SBOM/provenance/reproducibility/rollback acceptance. Protected main +> still has package/frontend `2.28.0` versus runtime `2.20.0` until normal +> integration. No release is admitted by this overlay. Older overlays below are +> dated evidence only. +''' + path.write_text(title + overlay + text[len(title):], encoding="utf-8") + PY + + - name: Publish ordinary self-cleaning documentation commit + shell: bash + run: | + git config user.name "LineageWeave maintenance" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + git rm .github/workflows/refresh-gap-baseline-20260913-1650.yml + git add docs/product-technical-gap-baseline.md + git diff --cached --check + git commit -m "docs(gaps): refresh current Customer Master evidence" + git push origin HEAD:codex/gap-loop-20260912 From 7af1214be952a00c9072313672294bf220b8856a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 16:52:56 +0900 Subject: [PATCH 045/276] fix(docs): repair bounded gap baseline refresh runner --- .../refresh-gap-baseline-20260913-1650.yml | 123 ++++++++++-------- 1 file changed, 67 insertions(+), 56 deletions(-) diff --git a/.github/workflows/refresh-gap-baseline-20260913-1650.yml b/.github/workflows/refresh-gap-baseline-20260913-1650.yml index 5a27a7b54..b0b531d19 100644 --- a/.github/workflows/refresh-gap-baseline-20260913-1650.yml +++ b/.github/workflows/refresh-gap-baseline-20260913-1650.yml @@ -1,87 +1,98 @@ -name: Refresh gap baseline 2026-09-13 1650 +name: Bounded product gap baseline refresh on: push: - branches: [codex/gap-loop-20260912] - paths: - - .github/workflows/refresh-gap-baseline-20260913-1650.yml + branches: + - codex/gap-loop-20260912 permissions: contents: write -concurrency: - group: refresh-gap-baseline-20260913-1650 - cancel-in-progress: false - jobs: refresh: - runs-on: ubuntu-latest + if: github.actor != 'github-actions[bot]' + runs-on: ubuntu-24.04 steps: - - name: Checkout documentation lane + - name: Checkout exact branch head uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # actions/checkout@v7 with: ref: codex/gap-loop-20260912 - fetch-depth: 1 + fetch-depth: 0 + persist-credentials: false + + - name: Verify single-writer head + shell: bash + run: | + set -euo pipefail + remote_head="$(git ls-remote origin refs/heads/codex/gap-loop-20260912 | cut -f1)" + test "$remote_head" = "$GITHUB_SHA" + test "$(git rev-parse HEAD)" = "$GITHUB_SHA" - - name: Prepend current live-authority overlay + - name: Refresh current authority overlay shell: bash run: | + set -euo pipefail python - <<'PY' from pathlib import Path + from datetime import datetime + from zoneinfo import ZoneInfo - path = Path("docs/product-technical-gap-baseline.md") - text = path.read_text(encoding="utf-8") - title = "# Product & Technical Gap Baseline\n" + path = Path('docs/product-technical-gap-baseline.md') + text = path.read_text() + title = '# Product & Technical Gap Baseline\n' if not text.startswith(title): - raise SystemExit("unexpected baseline title") - - overlay = r''' - -> Live-authority overlay: 2026-09-13 16:50 KST. Protected `main` remains -> `83eba56149eb802cd63642c507c324c9976ec78e`, protected and signed/verified. -> Customer Master ownership issue #1052 / PR #1055 advanced to exact + raise SystemExit('unexpected baseline title') + stamp = datetime.now(ZoneInfo('Asia/Seoul')).strftime('%Y-%m-%d %H:%M KST') + overlay = f'''\n\n> Live-authority overlay: {stamp}. Protected `main` remains +> `83eba56149eb802cd63642c507c324c9976ec78e` pending final double sweep. +> Customer Master ownership issue #1052 / PR #1055 is on exact > `50c4935eef1029467595f7004818643598b737c9`, Ready only for validation > admission. Predecessor `8448a2b4e06c6ef415dd98b3eaa1f7f36669fe94` > exposed a real repository RED after the shared eligibility SQL qualification: > Tests `34743575403` ended `2 failed, 1777 passed, 147 skipped`. The two failures -> were the corroborated-association/reused-catalog unit tests. RCA showed their -> fake query recognizers still expected the old unqualified `select post_id ...` -> SQL, so they returned no captured evidence after production queries were -> correctly qualified with `source_post.*`; the scope-change test also stopped -> reaching its intended revalidation phase. +> were the corroborated-association/reused-catalog unit tests. Their fake query +> recognizers still expected the old unqualified capture/revalidation SQL, so +> they returned no evidence after production queries were correctly qualified +> with `source_post.*`; the scope-change test also stopped reaching revalidation. > -> Causal commit `50c4935e...` changes only those unit-fake recognizers to the -> canonical qualified capture/revalidation SQL. It does not change production -> authorization, persistence, locking, provider/model selection or workflow -> gates. Fresh exact-head validation materialized without no-op churn. Frontend -> lint/test/build/Storybook is GREEN; Security `34746058657` and SAST -> `34746058639` are GREEN. Full PostgreSQL Tests `34746058653`, Required CodeQL -> `34746058693`, Noema `34746057619` and Strix `34746057545` remain live at this -> snapshot. Required OpenCode `34746057593` is terminal FAILURE, so #1055 is not -> merge-ready and no predecessor review receipt transfers. All visible inline -> review threads are resolved/outdated. +> Causal commit `50c4935e...` changes only those test fake recognizers to the +> canonical qualified SQL. Production authorization, persistence, locking, +> provider/model selection and workflow gates are unchanged. Fresh exact-head +> validation materialized from this causal commit without no-op churn. Frontend +> lint/test/build/Storybook, Security `34746058657`, and SAST `34746058639` are +> GREEN. Full PostgreSQL Tests `34746058653`, Required CodeQL `34746058693`, +> Noema `34746057619`, and Strix `34746057545` were still live at this snapshot; +> Required OpenCode `34746057593` is terminal FAILURE. No predecessor review +> receipt transfers, and #1055 is not merge-ready. > -> #1057 remains the separate required PostgreSQL + Keycloak + Valkey -> bearer/JWKS/RBAC/ABAC hosted-topology owner. Central required-workflow repair -> remains in `.github#1929/#2106` for CodeQL producer/consumer settlement and -> `.github#2045/#2109` for Ready-transition/model-review reconciliation; -> LineageWeave does not copy those owner implementations. Draft #961 remains the -> package/runtime-version source repair and #1056 carries immutable -> release/SBOM/provenance/reproducibility/rollback acceptance. Protected main -> still has package/frontend `2.28.0` versus runtime `2.20.0` until normal -> integration. No release is admitted by this overlay. Older overlays below are -> dated evidence only. +> #1057 remains the separate PostgreSQL + Keycloak + Valkey bearer/JWKS/RBAC/ABAC +> hosted-topology owner. Central workflow repair remains `.github#1929/#2106` +> for CodeQL producer/consumer settlement and `.github#2045/#2109` for Ready +> transition/model-review reconciliation; LineageWeave does not copy those owner +> implementations. Draft #961 remains the package/runtime-version source repair +> and #1056 carries immutable release/SBOM/provenance/reproducibility/rollback +> acceptance. Protected main still has package/frontend `2.28.0` versus runtime +> `2.20.0` until normal integration. No release is admitted by this overlay. +> Older overlays below are dated evidence only. ''' - path.write_text(title + overlay + text[len(title):], encoding="utf-8") + path.write_text(title + overlay + text[len(title):]) PY - - name: Publish ordinary self-cleaning documentation commit + - name: Publish ordinary self-cleaning docs commit shell: bash + env: + GITHUB_TOKEN: ${{ github.token }} run: | - git config user.name "LineageWeave maintenance" - git config user.email "41898282+github-actions[bot]@users.noreply.github.com" - git rm .github/workflows/refresh-gap-baseline-20260913-1650.yml - git add docs/product-technical-gap-baseline.md - git diff --cached --check - git commit -m "docs(gaps): refresh current Customer Master evidence" - git push origin HEAD:codex/gap-loop-20260912 + set -euo pipefail + rm .github/workflows/refresh-gap-baseline-20260913-1650.yml + git add docs/product-technical-gap-baseline.md .github/workflows/refresh-gap-baseline-20260913-1650.yml + if git diff --cached --quiet; then + echo 'No baseline delta to publish' >&2 + exit 1 + fi + remote_head="$(git ls-remote origin refs/heads/codex/gap-loop-20260912 | cut -f1)" + test "$remote_head" = "$GITHUB_SHA" + git config user.name 'github-actions[bot]' + git config user.email '41898282+github-actions[bot]@users.noreply.github.com' + git commit -m 'docs(gaps): refresh current Customer Master evidence' + git push "https://x-access-token:${GITHUB_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" HEAD:codex/gap-loop-20260912 From 579c4fb0e518f5ffa1fe1fc689be6469ebe2c0f0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 16:53:53 +0900 Subject: [PATCH 046/276] fix(docs): keep refresh payload inside workflow block --- .../refresh-gap-baseline-20260913-1650.yml | 67 ++++++++++--------- 1 file changed, 35 insertions(+), 32 deletions(-) diff --git a/.github/workflows/refresh-gap-baseline-20260913-1650.yml b/.github/workflows/refresh-gap-baseline-20260913-1650.yml index b0b531d19..ea2a34422 100644 --- a/.github/workflows/refresh-gap-baseline-20260913-1650.yml +++ b/.github/workflows/refresh-gap-baseline-20260913-1650.yml @@ -43,38 +43,41 @@ jobs: if not text.startswith(title): raise SystemExit('unexpected baseline title') stamp = datetime.now(ZoneInfo('Asia/Seoul')).strftime('%Y-%m-%d %H:%M KST') - overlay = f'''\n\n> Live-authority overlay: {stamp}. Protected `main` remains -> `83eba56149eb802cd63642c507c324c9976ec78e` pending final double sweep. -> Customer Master ownership issue #1052 / PR #1055 is on exact -> `50c4935eef1029467595f7004818643598b737c9`, Ready only for validation -> admission. Predecessor `8448a2b4e06c6ef415dd98b3eaa1f7f36669fe94` -> exposed a real repository RED after the shared eligibility SQL qualification: -> Tests `34743575403` ended `2 failed, 1777 passed, 147 skipped`. The two failures -> were the corroborated-association/reused-catalog unit tests. Their fake query -> recognizers still expected the old unqualified capture/revalidation SQL, so -> they returned no evidence after production queries were correctly qualified -> with `source_post.*`; the scope-change test also stopped reaching revalidation. -> -> Causal commit `50c4935e...` changes only those test fake recognizers to the -> canonical qualified SQL. Production authorization, persistence, locking, -> provider/model selection and workflow gates are unchanged. Fresh exact-head -> validation materialized from this causal commit without no-op churn. Frontend -> lint/test/build/Storybook, Security `34746058657`, and SAST `34746058639` are -> GREEN. Full PostgreSQL Tests `34746058653`, Required CodeQL `34746058693`, -> Noema `34746057619`, and Strix `34746057545` were still live at this snapshot; -> Required OpenCode `34746057593` is terminal FAILURE. No predecessor review -> receipt transfers, and #1055 is not merge-ready. -> -> #1057 remains the separate PostgreSQL + Keycloak + Valkey bearer/JWKS/RBAC/ABAC -> hosted-topology owner. Central workflow repair remains `.github#1929/#2106` -> for CodeQL producer/consumer settlement and `.github#2045/#2109` for Ready -> transition/model-review reconciliation; LineageWeave does not copy those owner -> implementations. Draft #961 remains the package/runtime-version source repair -> and #1056 carries immutable release/SBOM/provenance/reproducibility/rollback -> acceptance. Protected main still has package/frontend `2.28.0` versus runtime -> `2.20.0` until normal integration. No release is admitted by this overlay. -> Older overlays below are dated evidence only. -''' + lines = [ + f'> Live-authority overlay: {stamp}. Protected `main` remains', + '> `83eba56149eb802cd63642c507c324c9976ec78e` pending final double sweep.', + '> Customer Master ownership issue #1052 / PR #1055 is on exact', + '> `50c4935eef1029467595f7004818643598b737c9`, Ready only for validation', + '> admission. Predecessor `8448a2b4e06c6ef415dd98b3eaa1f7f36669fe94`', + '> exposed a real repository RED after shared eligibility SQL qualification:', + '> Tests `34743575403` ended `2 failed, 1777 passed, 147 skipped`. The two', + '> failures were the corroborated-association/reused-catalog unit tests. Their', + '> fake query recognizers still expected old unqualified capture/revalidation', + '> SQL, so they returned no evidence after production queries were correctly', + '> qualified with `source_post.*`; the scope-change test also stopped reaching', + '> its intended revalidation phase.', + '>', + '> Causal commit `50c4935e...` changes only those unit-fake recognizers to the', + '> canonical qualified SQL. Production authorization, persistence, locking,', + '> provider/model selection and workflow gates are unchanged. Fresh exact-head', + '> validation materialized without no-op churn. Frontend lint/test/build/', + '> Storybook, Security `34746058657`, and SAST `34746058639` are GREEN. Full', + '> PostgreSQL Tests `34746058653`, Required CodeQL `34746058693`, Noema', + '> `34746057619`, and Strix `34746057545` were still live at this snapshot;', + '> Required OpenCode `34746057593` is terminal FAILURE. No predecessor review', + '> receipt transfers, and #1055 is not merge-ready.', + '>', + '> #1057 remains the separate PostgreSQL + Keycloak + Valkey bearer/JWKS/RBAC/', + '> ABAC hosted-topology owner. Central workflow repair remains `.github#1929/', + '> #2106` for CodeQL producer/consumer settlement and `.github#2045/#2109` for', + '> Ready-transition/model-review reconciliation; LineageWeave does not copy', + '> those owner implementations. Draft #961 remains the package/runtime-version', + '> source repair and #1056 carries immutable release/SBOM/provenance/', + '> reproducibility/rollback acceptance. Protected main still has package/', + '> frontend `2.28.0` versus runtime `2.20.0` until normal integration. No', + '> release is admitted by this overlay. Older overlays below are dated evidence only.', + ] + overlay = '\n\n' + '\n'.join(lines) + '\n' path.write_text(title + overlay + text[len(title):]) PY From e8c96050993550d2cae696d916d0c423a1d405f7 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Sun, 13 Sep 2026 07:54:25 +0000 Subject: [PATCH 047/276] docs(gaps): refresh current Customer Master evidence --- .../refresh-gap-baseline-20260913-1650.yml | 101 ------------------ docs/product-technical-gap-baseline.md | 34 ++++++ 2 files changed, 34 insertions(+), 101 deletions(-) delete mode 100644 .github/workflows/refresh-gap-baseline-20260913-1650.yml diff --git a/.github/workflows/refresh-gap-baseline-20260913-1650.yml b/.github/workflows/refresh-gap-baseline-20260913-1650.yml deleted file mode 100644 index ea2a34422..000000000 --- a/.github/workflows/refresh-gap-baseline-20260913-1650.yml +++ /dev/null @@ -1,101 +0,0 @@ -name: Bounded product gap baseline refresh - -on: - push: - branches: - - codex/gap-loop-20260912 - -permissions: - contents: write - -jobs: - refresh: - if: github.actor != 'github-actions[bot]' - runs-on: ubuntu-24.04 - steps: - - name: Checkout exact branch head - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # actions/checkout@v7 - with: - ref: codex/gap-loop-20260912 - fetch-depth: 0 - persist-credentials: false - - - name: Verify single-writer head - shell: bash - run: | - set -euo pipefail - remote_head="$(git ls-remote origin refs/heads/codex/gap-loop-20260912 | cut -f1)" - test "$remote_head" = "$GITHUB_SHA" - test "$(git rev-parse HEAD)" = "$GITHUB_SHA" - - - name: Refresh current authority overlay - shell: bash - run: | - set -euo pipefail - python - <<'PY' - from pathlib import Path - from datetime import datetime - from zoneinfo import ZoneInfo - - path = Path('docs/product-technical-gap-baseline.md') - text = path.read_text() - title = '# Product & Technical Gap Baseline\n' - if not text.startswith(title): - raise SystemExit('unexpected baseline title') - stamp = datetime.now(ZoneInfo('Asia/Seoul')).strftime('%Y-%m-%d %H:%M KST') - lines = [ - f'> Live-authority overlay: {stamp}. Protected `main` remains', - '> `83eba56149eb802cd63642c507c324c9976ec78e` pending final double sweep.', - '> Customer Master ownership issue #1052 / PR #1055 is on exact', - '> `50c4935eef1029467595f7004818643598b737c9`, Ready only for validation', - '> admission. Predecessor `8448a2b4e06c6ef415dd98b3eaa1f7f36669fe94`', - '> exposed a real repository RED after shared eligibility SQL qualification:', - '> Tests `34743575403` ended `2 failed, 1777 passed, 147 skipped`. The two', - '> failures were the corroborated-association/reused-catalog unit tests. Their', - '> fake query recognizers still expected old unqualified capture/revalidation', - '> SQL, so they returned no evidence after production queries were correctly', - '> qualified with `source_post.*`; the scope-change test also stopped reaching', - '> its intended revalidation phase.', - '>', - '> Causal commit `50c4935e...` changes only those unit-fake recognizers to the', - '> canonical qualified SQL. Production authorization, persistence, locking,', - '> provider/model selection and workflow gates are unchanged. Fresh exact-head', - '> validation materialized without no-op churn. Frontend lint/test/build/', - '> Storybook, Security `34746058657`, and SAST `34746058639` are GREEN. Full', - '> PostgreSQL Tests `34746058653`, Required CodeQL `34746058693`, Noema', - '> `34746057619`, and Strix `34746057545` were still live at this snapshot;', - '> Required OpenCode `34746057593` is terminal FAILURE. No predecessor review', - '> receipt transfers, and #1055 is not merge-ready.', - '>', - '> #1057 remains the separate PostgreSQL + Keycloak + Valkey bearer/JWKS/RBAC/', - '> ABAC hosted-topology owner. Central workflow repair remains `.github#1929/', - '> #2106` for CodeQL producer/consumer settlement and `.github#2045/#2109` for', - '> Ready-transition/model-review reconciliation; LineageWeave does not copy', - '> those owner implementations. Draft #961 remains the package/runtime-version', - '> source repair and #1056 carries immutable release/SBOM/provenance/', - '> reproducibility/rollback acceptance. Protected main still has package/', - '> frontend `2.28.0` versus runtime `2.20.0` until normal integration. No', - '> release is admitted by this overlay. Older overlays below are dated evidence only.', - ] - overlay = '\n\n' + '\n'.join(lines) + '\n' - path.write_text(title + overlay + text[len(title):]) - PY - - - name: Publish ordinary self-cleaning docs commit - shell: bash - env: - GITHUB_TOKEN: ${{ github.token }} - run: | - set -euo pipefail - rm .github/workflows/refresh-gap-baseline-20260913-1650.yml - git add docs/product-technical-gap-baseline.md .github/workflows/refresh-gap-baseline-20260913-1650.yml - if git diff --cached --quiet; then - echo 'No baseline delta to publish' >&2 - exit 1 - fi - remote_head="$(git ls-remote origin refs/heads/codex/gap-loop-20260912 | cut -f1)" - test "$remote_head" = "$GITHUB_SHA" - git config user.name 'github-actions[bot]' - git config user.email '41898282+github-actions[bot]@users.noreply.github.com' - git commit -m 'docs(gaps): refresh current Customer Master evidence' - git push "https://x-access-token:${GITHUB_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" HEAD:codex/gap-loop-20260912 diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e0d7d0e57..45a2b5b1d 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,40 @@ # Product & Technical Gap Baseline +> Live-authority overlay: 2026-09-13 16:54 KST. Protected `main` remains +> `83eba56149eb802cd63642c507c324c9976ec78e` pending final double sweep. +> Customer Master ownership issue #1052 / PR #1055 is on exact +> `50c4935eef1029467595f7004818643598b737c9`, Ready only for validation +> admission. Predecessor `8448a2b4e06c6ef415dd98b3eaa1f7f36669fe94` +> exposed a real repository RED after shared eligibility SQL qualification: +> Tests `34743575403` ended `2 failed, 1777 passed, 147 skipped`. The two +> failures were the corroborated-association/reused-catalog unit tests. Their +> fake query recognizers still expected old unqualified capture/revalidation +> SQL, so they returned no evidence after production queries were correctly +> qualified with `source_post.*`; the scope-change test also stopped reaching +> its intended revalidation phase. +> +> Causal commit `50c4935e...` changes only those unit-fake recognizers to the +> canonical qualified SQL. Production authorization, persistence, locking, +> provider/model selection and workflow gates are unchanged. Fresh exact-head +> validation materialized without no-op churn. Frontend lint/test/build/ +> Storybook, Security `34746058657`, and SAST `34746058639` are GREEN. Full +> PostgreSQL Tests `34746058653`, Required CodeQL `34746058693`, Noema +> `34746057619`, and Strix `34746057545` were still live at this snapshot; +> Required OpenCode `34746057593` is terminal FAILURE. No predecessor review +> receipt transfers, and #1055 is not merge-ready. +> +> #1057 remains the separate PostgreSQL + Keycloak + Valkey bearer/JWKS/RBAC/ +> ABAC hosted-topology owner. Central workflow repair remains `.github#1929/ +> #2106` for CodeQL producer/consumer settlement and `.github#2045/#2109` for +> Ready-transition/model-review reconciliation; LineageWeave does not copy +> those owner implementations. Draft #961 remains the package/runtime-version +> source repair and #1056 carries immutable release/SBOM/provenance/ +> reproducibility/rollback acceptance. Protected main still has package/ +> frontend `2.28.0` versus runtime `2.20.0` until normal integration. No +> release is admitted by this overlay. Older overlays below are dated evidence only. + + > Live-authority overlay: 2026-09-13 15:24 KST. Protected `main` remains > `83eba56149eb802cd63642c507c324c9976ec78e` pending final double sweep. > Customer Master ownership issue #1052 / Draft PR #1055 is now at exact From 0dbb05b606fc5ac91922f8c4bc12b8cd4ab1d863 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 20:05:30 +0900 Subject: [PATCH 048/276] chore(docs): stage 20:05 gap baseline refresh --- .../refresh-gap-baseline-20260913-2005.yml | 99 +++++++++++++++++++ 1 file changed, 99 insertions(+) create mode 100644 .github/workflows/refresh-gap-baseline-20260913-2005.yml diff --git a/.github/workflows/refresh-gap-baseline-20260913-2005.yml b/.github/workflows/refresh-gap-baseline-20260913-2005.yml new file mode 100644 index 000000000..389ed77b4 --- /dev/null +++ b/.github/workflows/refresh-gap-baseline-20260913-2005.yml @@ -0,0 +1,99 @@ +name: Refresh product technical gap baseline 2026-09-13 20:05 KST + +on: + push: + branches: + - codex/gap-loop-20260912 + +permissions: + contents: write + +jobs: + refresh: + if: github.actor != 'github-actions[bot]' + runs-on: ubuntu-24.04 + steps: + - name: Check out exact triggering head + uses: actions/checkout@v5 + with: + ref: codex/gap-loop-20260912 + fetch-depth: 0 + + - name: Prepend current live-authority overlay + shell: bash + run: | + set -euo pipefail + cat > /tmp/overlay.md <<'EOF' + > Live-authority overlay: 2026-09-13 20:05 KST. Protected `main` remains + > `83eba56149eb802cd63642c507c324c9976ec78e` pending the final double sweep. + > Customer Master PR #1055 remains exact `50c4935eef1029467595f7004818643598b737c9`, + > Ready only to preserve its still-running Strix `34746057545`; repository Tests + > `34746058653`, Security `34746058657`, and SAST `34746058639` are GREEN, while + > Required CodeQL/OpenCode/Noema remain terminal failures at their canonical + > `.github#1929/#2106`, `.github#2045`, and `contextual-orchestrator#1106` owner + > boundaries. Do not cancel Strix on elapsed time alone or churn the source head. + > + > A separate buyer-facing leftover-map lineage stack repair is now active at #859. + > Exact #859 head `2550e8d88339e30297fa0aa19ffae77f9b78b73b` causally fixes the + > eight stale comparison-only accessibility expectations (16 distance assertions) + > to match the intentional localized comparison-graphic accessible name, without + > changing report-mode assertions or production semantics. Its purpose-complete + > repair workflow self-removed before the product head was published. + > + > Because #859 moved, ordinary non-force ancestry convergence was executed through + > #860→#875, then both #875 forks (#876 and #877), plus reconstructed successors + > #1033→#1034. Historical #878/#879 remain open delta carriers; their valid product + > intent is preserved through those reconstructed successor branches rather than by + > replaying stale full source/docs trees. No predecessor validation receipt transfers. + > + > #859 is Draft. The first fresh Tests identity `34752865986` ended at workflow level + > with zero jobs, then convergence-PR activity produced a cancelled and a skipped Tests + > identity on the same head. A subsequent unchanged-head Ready admission produced no + > new workflow identities and was reverted to Draft; `.github#2045` now records this + > additional Ready-reconciliation canary. Therefore the causal assertion repair is + > present, but #859 is not GREEN or merge-ready until fresh exact-head repository, + > security, browser/a11y/performance evidence and qualifying independent approval exist. + > + > #1057 remains the separate PostgreSQL + Keycloak + Valkey authenticated + > bearer/JWKS/RBAC/ABAC topology owner. Draft #961 remains the package/runtime-version + > source repair and #1056 remains immutable release/SBOM/provenance/reproducibility/ + > rollback acceptance. No release is admitted by this overlay. Older overlays below + > are dated evidence only. + EOF + python - <<'PY' + from pathlib import Path + + path = Path('docs/product-technical-gap-baseline.md') + text = path.read_text() + title = '# Product & Technical Gap Baseline\n' + if not text.startswith(title): + raise SystemExit('unexpected baseline title') + overlay = Path('/tmp/overlay.md').read_text().strip() + '\n\n\n' + marker = '> Live-authority overlay: 2026-09-13 20:05 KST.' + if marker in text: + raise SystemExit('overlay already present') + path.write_text(title + '\n\n' + overlay + text[len(title):].lstrip('\n')) + PY + git diff --check + test "$(git diff --name-only)" = "docs/product-technical-gap-baseline.md" + + - name: Remove purpose-complete refresh workflow + shell: bash + run: rm .github/workflows/refresh-gap-baseline-20260913-2005.yml + + - name: Commit and fast-forward publish exact refresh + shell: bash + env: + BRANCH: codex/gap-loop-20260912 + run: | + set -euo pipefail + remote_sha="$(git ls-remote origin "refs/heads/${BRANCH}" | cut -f1)" + if [ "$remote_sha" != "$GITHUB_SHA" ]; then + echo "branch moved: expected $GITHUB_SHA, found $remote_sha" >&2 + exit 1 + fi + git config user.name github-actions[bot] + git config user.email 41898282+github-actions[bot]@users.noreply.github.com + git add docs/product-technical-gap-baseline.md .github/workflows/refresh-gap-baseline-20260913-2005.yml + git commit -m "docs(gaps): refresh 20:05 live authority" + git push origin "HEAD:${BRANCH}" From 24afee557ca3ac965f1e26a1ddb9df9f98595f63 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 20:10:42 +0900 Subject: [PATCH 049/276] chore(docs): remove queued baseline helper --- .../refresh-gap-baseline-20260913-2005.yml | 99 ------------------- 1 file changed, 99 deletions(-) delete mode 100644 .github/workflows/refresh-gap-baseline-20260913-2005.yml diff --git a/.github/workflows/refresh-gap-baseline-20260913-2005.yml b/.github/workflows/refresh-gap-baseline-20260913-2005.yml deleted file mode 100644 index 389ed77b4..000000000 --- a/.github/workflows/refresh-gap-baseline-20260913-2005.yml +++ /dev/null @@ -1,99 +0,0 @@ -name: Refresh product technical gap baseline 2026-09-13 20:05 KST - -on: - push: - branches: - - codex/gap-loop-20260912 - -permissions: - contents: write - -jobs: - refresh: - if: github.actor != 'github-actions[bot]' - runs-on: ubuntu-24.04 - steps: - - name: Check out exact triggering head - uses: actions/checkout@v5 - with: - ref: codex/gap-loop-20260912 - fetch-depth: 0 - - - name: Prepend current live-authority overlay - shell: bash - run: | - set -euo pipefail - cat > /tmp/overlay.md <<'EOF' - > Live-authority overlay: 2026-09-13 20:05 KST. Protected `main` remains - > `83eba56149eb802cd63642c507c324c9976ec78e` pending the final double sweep. - > Customer Master PR #1055 remains exact `50c4935eef1029467595f7004818643598b737c9`, - > Ready only to preserve its still-running Strix `34746057545`; repository Tests - > `34746058653`, Security `34746058657`, and SAST `34746058639` are GREEN, while - > Required CodeQL/OpenCode/Noema remain terminal failures at their canonical - > `.github#1929/#2106`, `.github#2045`, and `contextual-orchestrator#1106` owner - > boundaries. Do not cancel Strix on elapsed time alone or churn the source head. - > - > A separate buyer-facing leftover-map lineage stack repair is now active at #859. - > Exact #859 head `2550e8d88339e30297fa0aa19ffae77f9b78b73b` causally fixes the - > eight stale comparison-only accessibility expectations (16 distance assertions) - > to match the intentional localized comparison-graphic accessible name, without - > changing report-mode assertions or production semantics. Its purpose-complete - > repair workflow self-removed before the product head was published. - > - > Because #859 moved, ordinary non-force ancestry convergence was executed through - > #860→#875, then both #875 forks (#876 and #877), plus reconstructed successors - > #1033→#1034. Historical #878/#879 remain open delta carriers; their valid product - > intent is preserved through those reconstructed successor branches rather than by - > replaying stale full source/docs trees. No predecessor validation receipt transfers. - > - > #859 is Draft. The first fresh Tests identity `34752865986` ended at workflow level - > with zero jobs, then convergence-PR activity produced a cancelled and a skipped Tests - > identity on the same head. A subsequent unchanged-head Ready admission produced no - > new workflow identities and was reverted to Draft; `.github#2045` now records this - > additional Ready-reconciliation canary. Therefore the causal assertion repair is - > present, but #859 is not GREEN or merge-ready until fresh exact-head repository, - > security, browser/a11y/performance evidence and qualifying independent approval exist. - > - > #1057 remains the separate PostgreSQL + Keycloak + Valkey authenticated - > bearer/JWKS/RBAC/ABAC topology owner. Draft #961 remains the package/runtime-version - > source repair and #1056 remains immutable release/SBOM/provenance/reproducibility/ - > rollback acceptance. No release is admitted by this overlay. Older overlays below - > are dated evidence only. - EOF - python - <<'PY' - from pathlib import Path - - path = Path('docs/product-technical-gap-baseline.md') - text = path.read_text() - title = '# Product & Technical Gap Baseline\n' - if not text.startswith(title): - raise SystemExit('unexpected baseline title') - overlay = Path('/tmp/overlay.md').read_text().strip() + '\n\n\n' - marker = '> Live-authority overlay: 2026-09-13 20:05 KST.' - if marker in text: - raise SystemExit('overlay already present') - path.write_text(title + '\n\n' + overlay + text[len(title):].lstrip('\n')) - PY - git diff --check - test "$(git diff --name-only)" = "docs/product-technical-gap-baseline.md" - - - name: Remove purpose-complete refresh workflow - shell: bash - run: rm .github/workflows/refresh-gap-baseline-20260913-2005.yml - - - name: Commit and fast-forward publish exact refresh - shell: bash - env: - BRANCH: codex/gap-loop-20260912 - run: | - set -euo pipefail - remote_sha="$(git ls-remote origin "refs/heads/${BRANCH}" | cut -f1)" - if [ "$remote_sha" != "$GITHUB_SHA" ]; then - echo "branch moved: expected $GITHUB_SHA, found $remote_sha" >&2 - exit 1 - fi - git config user.name github-actions[bot] - git config user.email 41898282+github-actions[bot]@users.noreply.github.com - git add docs/product-technical-gap-baseline.md .github/workflows/refresh-gap-baseline-20260913-2005.yml - git commit -m "docs(gaps): refresh 20:05 live authority" - git push origin "HEAD:${BRANCH}" From b3dab9e33b421dcb6b2d6d053ff1587fc3bc246b Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 13 Sep 2026 20:29:38 +0900 Subject: [PATCH 050/276] chore(docs): refresh 20:27 live gap baseline --- .../refresh-gap-baseline-20260913-2027.yml | 109 ++++++++++++++++++ 1 file changed, 109 insertions(+) create mode 100644 .github/workflows/refresh-gap-baseline-20260913-2027.yml diff --git a/.github/workflows/refresh-gap-baseline-20260913-2027.yml b/.github/workflows/refresh-gap-baseline-20260913-2027.yml new file mode 100644 index 000000000..9c0622722 --- /dev/null +++ b/.github/workflows/refresh-gap-baseline-20260913-2027.yml @@ -0,0 +1,109 @@ +name: Refresh product technical gap baseline 2026-09-13 20:27 KST + +on: + push: + branches: + - codex/gap-loop-20260912 + +permissions: + contents: write + +jobs: + refresh: + runs-on: ubuntu-24.04 + steps: + - name: Check out exact triggering head + uses: actions/checkout@v5 + with: + ref: codex/gap-loop-20260912 + fetch-depth: 0 + + - name: Prepend current live-authority overlay + shell: bash + run: | + set -euo pipefail + cat > /tmp/overlay.md <<'EOF' + > Live-authority overlay: 2026-09-13 20:27 KST. Protected `main` remains + > `83eba56149eb802cd63642c507c324c9976ec78e`, protected with a valid verified + > commit signature after two fresh sweeps. No protected-main merge or base movement + > occurred during this maintenance turn. + > + > Customer Master ownership issue #1052 / PR #1055 remains exact + > `50c4935eef1029467595f7004818643598b737c9`. Repository Tests `34746058653` + > (including full PostgreSQL), Security `34746058657`, and SAST `34746058639` + > are terminal GREEN. Required CodeQL `34746058693`, OpenCode `34746057593`, + > and Noema `34746057619` remain terminal failures at canonical `.github` / + > contextual-orchestrator owner boundaries. Strix `34746057545` / job + > `103694153476` remains genuinely `in_progress` at `Run Strix (quick)` on the + > unchanged head; elapsed time alone is not grounds to cancel it. #1055 therefore + > remains Ready only to preserve exact-head evidence and is not merge-ready. + > + > Fresh catalog-owner review identified buyer-path resilience gap #1077. The + > canonical `get_or_create_corporate_entity` correctly defers its explicit + > transaction and `pg_advisory_xact_lock` until after provider work, but existing + > Keyman/post-summary/Customer Master callers can retain a borrowed asyncpg + > connection across hierarchy inference/search corroboration. The process pool is + > bounded at `max_size=10`, so concurrent catalog misses can starve unrelated DB + > requests without any explicit DB lock. #1077 owns the causal contract: short + > candidate/alias snapshot lease, release before provider I/O, then a fresh + > under-lock catalog recheck/write with cancellation/error cleanup. It remains in + > the corporate-entity catalog bounded context and must not duplicate CO routing. + > + > The leftover-map comparison lineage suffix has also converged onto repaired #859. + > #859 exact `2550e8d88339e30297fa0aa19ffae77f9b78b73b` fixes the eight stale + > comparison-only distance cases (16 assertions) without changing production or + > report-mode semantics. The live serialized ancestry is #860 `ef29a5a9...` -> + > #861 `49973434...` -> #862 `382947ba...` -> #863 `4e8720e9...` -> #865 + > `dec97059...` -> #866 `198d6827...` -> #867 `3e338bc3...` -> #868 + > `8af935c0...` -> #869 `74bd9468...` -> #870 `d063bd97...` -> #871 + > `645a5b09...` -> #872 `57206ce8...` -> #873 `b25b3874...` -> #874 + > `ac531c41...` -> #875 `c2278234...`, with forks #876 `259e2d1a...` and + > #877 `677643a4...`; reconstructed successors #1033 `6db5cb71...` -> #1034 + > `5015f193...` preserve valid #878/#879 intent. PR bodies for this suffix were + > corrected to the live base/head authority and no longer claim #859's repaired + > consumer-test RED is still active. All remain Draft because current validation / + > local intentional REDs are unresolved; no ancestor receipt transfers. + > + > #1057 remains the separate hosted PostgreSQL + Keycloak + Valkey authenticated + > bearer/JWKS/RBAC/ABAC topology owner. Draft #961 remains the runtime-version + > source repair and #1056 retains immutable release/SBOM/provenance/ + > reproducibility/rollback acceptance. No release is admitted by this overlay. + > Older overlays below are dated evidence only. + EOF + python - <<'PY' + from pathlib import Path + + path = Path('docs/product-technical-gap-baseline.md') + text = path.read_text() + title = '# Product & Technical Gap Baseline\n' + if not text.startswith(title): + raise SystemExit('unexpected baseline title') + marker = '> Live-authority overlay: 2026-09-13 20:27 KST.' + if marker in text: + raise SystemExit('overlay already present') + overlay = Path('/tmp/overlay.md').read_text().strip() + '\n\n\n' + path.write_text(title + '\n\n' + overlay + text[len(title):].lstrip('\n')) + PY + git diff --check + test "$(git diff --name-only)" = "docs/product-technical-gap-baseline.md" + + - name: Remove purpose-complete refresh workflow + shell: bash + run: rm .github/workflows/refresh-gap-baseline-20260913-2027.yml + + - name: Commit and fast-forward publish exact refresh + shell: bash + env: + BRANCH: codex/gap-loop-20260912 + run: | + set -euo pipefail + remote_sha="$(git ls-remote origin "refs/heads/${BRANCH}" | cut -f1)" + if [ "$remote_sha" != "$GITHUB_SHA" ]; then + echo "branch moved: expected $GITHUB_SHA, found $remote_sha" >&2 + exit 1 + fi + git config user.name github-actions[bot] + git config user.email 41898282+github-actions[bot]@users.noreply.github.com + git add docs/product-technical-gap-baseline.md .github/workflows/refresh-gap-baseline-20260913-2027.yml + git commit -m "docs(gaps): refresh 20:27 live authority" + git push origin "HEAD:${BRANCH}" From 0c5336444f355ad1d9e5ce75c15413ecb61f2588 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Sun, 13 Sep 2026 11:31:07 +0000 Subject: [PATCH 051/276] docs(gaps): refresh 20:27 live authority --- .../refresh-gap-baseline-20260913-2027.yml | 109 ------------------ docs/product-technical-gap-baseline.md | 48 ++++++++ 2 files changed, 48 insertions(+), 109 deletions(-) delete mode 100644 .github/workflows/refresh-gap-baseline-20260913-2027.yml diff --git a/.github/workflows/refresh-gap-baseline-20260913-2027.yml b/.github/workflows/refresh-gap-baseline-20260913-2027.yml deleted file mode 100644 index 9c0622722..000000000 --- a/.github/workflows/refresh-gap-baseline-20260913-2027.yml +++ /dev/null @@ -1,109 +0,0 @@ -name: Refresh product technical gap baseline 2026-09-13 20:27 KST - -on: - push: - branches: - - codex/gap-loop-20260912 - -permissions: - contents: write - -jobs: - refresh: - runs-on: ubuntu-24.04 - steps: - - name: Check out exact triggering head - uses: actions/checkout@v5 - with: - ref: codex/gap-loop-20260912 - fetch-depth: 0 - - - name: Prepend current live-authority overlay - shell: bash - run: | - set -euo pipefail - cat > /tmp/overlay.md <<'EOF' - > Live-authority overlay: 2026-09-13 20:27 KST. Protected `main` remains - > `83eba56149eb802cd63642c507c324c9976ec78e`, protected with a valid verified - > commit signature after two fresh sweeps. No protected-main merge or base movement - > occurred during this maintenance turn. - > - > Customer Master ownership issue #1052 / PR #1055 remains exact - > `50c4935eef1029467595f7004818643598b737c9`. Repository Tests `34746058653` - > (including full PostgreSQL), Security `34746058657`, and SAST `34746058639` - > are terminal GREEN. Required CodeQL `34746058693`, OpenCode `34746057593`, - > and Noema `34746057619` remain terminal failures at canonical `.github` / - > contextual-orchestrator owner boundaries. Strix `34746057545` / job - > `103694153476` remains genuinely `in_progress` at `Run Strix (quick)` on the - > unchanged head; elapsed time alone is not grounds to cancel it. #1055 therefore - > remains Ready only to preserve exact-head evidence and is not merge-ready. - > - > Fresh catalog-owner review identified buyer-path resilience gap #1077. The - > canonical `get_or_create_corporate_entity` correctly defers its explicit - > transaction and `pg_advisory_xact_lock` until after provider work, but existing - > Keyman/post-summary/Customer Master callers can retain a borrowed asyncpg - > connection across hierarchy inference/search corroboration. The process pool is - > bounded at `max_size=10`, so concurrent catalog misses can starve unrelated DB - > requests without any explicit DB lock. #1077 owns the causal contract: short - > candidate/alias snapshot lease, release before provider I/O, then a fresh - > under-lock catalog recheck/write with cancellation/error cleanup. It remains in - > the corporate-entity catalog bounded context and must not duplicate CO routing. - > - > The leftover-map comparison lineage suffix has also converged onto repaired #859. - > #859 exact `2550e8d88339e30297fa0aa19ffae77f9b78b73b` fixes the eight stale - > comparison-only distance cases (16 assertions) without changing production or - > report-mode semantics. The live serialized ancestry is #860 `ef29a5a9...` -> - > #861 `49973434...` -> #862 `382947ba...` -> #863 `4e8720e9...` -> #865 - > `dec97059...` -> #866 `198d6827...` -> #867 `3e338bc3...` -> #868 - > `8af935c0...` -> #869 `74bd9468...` -> #870 `d063bd97...` -> #871 - > `645a5b09...` -> #872 `57206ce8...` -> #873 `b25b3874...` -> #874 - > `ac531c41...` -> #875 `c2278234...`, with forks #876 `259e2d1a...` and - > #877 `677643a4...`; reconstructed successors #1033 `6db5cb71...` -> #1034 - > `5015f193...` preserve valid #878/#879 intent. PR bodies for this suffix were - > corrected to the live base/head authority and no longer claim #859's repaired - > consumer-test RED is still active. All remain Draft because current validation / - > local intentional REDs are unresolved; no ancestor receipt transfers. - > - > #1057 remains the separate hosted PostgreSQL + Keycloak + Valkey authenticated - > bearer/JWKS/RBAC/ABAC topology owner. Draft #961 remains the runtime-version - > source repair and #1056 retains immutable release/SBOM/provenance/ - > reproducibility/rollback acceptance. No release is admitted by this overlay. - > Older overlays below are dated evidence only. - EOF - python - <<'PY' - from pathlib import Path - - path = Path('docs/product-technical-gap-baseline.md') - text = path.read_text() - title = '# Product & Technical Gap Baseline\n' - if not text.startswith(title): - raise SystemExit('unexpected baseline title') - marker = '> Live-authority overlay: 2026-09-13 20:27 KST.' - if marker in text: - raise SystemExit('overlay already present') - overlay = Path('/tmp/overlay.md').read_text().strip() + '\n\n\n' - path.write_text(title + '\n\n' + overlay + text[len(title):].lstrip('\n')) - PY - git diff --check - test "$(git diff --name-only)" = "docs/product-technical-gap-baseline.md" - - - name: Remove purpose-complete refresh workflow - shell: bash - run: rm .github/workflows/refresh-gap-baseline-20260913-2027.yml - - - name: Commit and fast-forward publish exact refresh - shell: bash - env: - BRANCH: codex/gap-loop-20260912 - run: | - set -euo pipefail - remote_sha="$(git ls-remote origin "refs/heads/${BRANCH}" | cut -f1)" - if [ "$remote_sha" != "$GITHUB_SHA" ]; then - echo "branch moved: expected $GITHUB_SHA, found $remote_sha" >&2 - exit 1 - fi - git config user.name github-actions[bot] - git config user.email 41898282+github-actions[bot]@users.noreply.github.com - git add docs/product-technical-gap-baseline.md .github/workflows/refresh-gap-baseline-20260913-2027.yml - git commit -m "docs(gaps): refresh 20:27 live authority" - git push origin "HEAD:${BRANCH}" diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 45a2b5b1d..2d5abe565 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,54 @@ # Product & Technical Gap Baseline +> Live-authority overlay: 2026-09-13 20:27 KST. Protected `main` remains +> `83eba56149eb802cd63642c507c324c9976ec78e`, protected with a valid verified +> commit signature after two fresh sweeps. No protected-main merge or base movement +> occurred during this maintenance turn. +> +> Customer Master ownership issue #1052 / PR #1055 remains exact +> `50c4935eef1029467595f7004818643598b737c9`. Repository Tests `34746058653` +> (including full PostgreSQL), Security `34746058657`, and SAST `34746058639` +> are terminal GREEN. Required CodeQL `34746058693`, OpenCode `34746057593`, +> and Noema `34746057619` remain terminal failures at canonical `.github` / +> contextual-orchestrator owner boundaries. Strix `34746057545` / job +> `103694153476` remains genuinely `in_progress` at `Run Strix (quick)` on the +> unchanged head; elapsed time alone is not grounds to cancel it. #1055 therefore +> remains Ready only to preserve exact-head evidence and is not merge-ready. +> +> Fresh catalog-owner review identified buyer-path resilience gap #1077. The +> canonical `get_or_create_corporate_entity` correctly defers its explicit +> transaction and `pg_advisory_xact_lock` until after provider work, but existing +> Keyman/post-summary/Customer Master callers can retain a borrowed asyncpg +> connection across hierarchy inference/search corroboration. The process pool is +> bounded at `max_size=10`, so concurrent catalog misses can starve unrelated DB +> requests without any explicit DB lock. #1077 owns the causal contract: short +> candidate/alias snapshot lease, release before provider I/O, then a fresh +> under-lock catalog recheck/write with cancellation/error cleanup. It remains in +> the corporate-entity catalog bounded context and must not duplicate CO routing. +> +> The leftover-map comparison lineage suffix has also converged onto repaired #859. +> #859 exact `2550e8d88339e30297fa0aa19ffae77f9b78b73b` fixes the eight stale +> comparison-only distance cases (16 assertions) without changing production or +> report-mode semantics. The live serialized ancestry is #860 `ef29a5a9...` -> +> #861 `49973434...` -> #862 `382947ba...` -> #863 `4e8720e9...` -> #865 +> `dec97059...` -> #866 `198d6827...` -> #867 `3e338bc3...` -> #868 +> `8af935c0...` -> #869 `74bd9468...` -> #870 `d063bd97...` -> #871 +> `645a5b09...` -> #872 `57206ce8...` -> #873 `b25b3874...` -> #874 +> `ac531c41...` -> #875 `c2278234...`, with forks #876 `259e2d1a...` and +> #877 `677643a4...`; reconstructed successors #1033 `6db5cb71...` -> #1034 +> `5015f193...` preserve valid #878/#879 intent. PR bodies for this suffix were +> corrected to the live base/head authority and no longer claim #859's repaired +> consumer-test RED is still active. All remain Draft because current validation / +> local intentional REDs are unresolved; no ancestor receipt transfers. +> +> #1057 remains the separate hosted PostgreSQL + Keycloak + Valkey authenticated +> bearer/JWKS/RBAC/ABAC topology owner. Draft #961 remains the runtime-version +> source repair and #1056 retains immutable release/SBOM/provenance/ +> reproducibility/rollback acceptance. No release is admitted by this overlay. +> Older overlays below are dated evidence only. + + > Live-authority overlay: 2026-09-13 16:54 KST. Protected `main` remains > `83eba56149eb802cd63642c507c324c9976ec78e` pending final double sweep. > Customer Master ownership issue #1052 / PR #1055 is on exact From 01e3016bc0665d9e07b57036e969b2dd45de33b3 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 14 Sep 2026 20:49:07 +0900 Subject: [PATCH 052/276] docs(gaps): make current baseline projection explicit --- ...l-gap-baseline-history-through-20260913.md | 1276 ++++++++++++++++ docs/product-technical-gap-baseline.md | 1345 +---------------- 2 files changed, 1347 insertions(+), 1274 deletions(-) create mode 100644 docs/evidence/product-technical-gap-baseline-history-through-20260913.md diff --git a/docs/evidence/product-technical-gap-baseline-history-through-20260913.md b/docs/evidence/product-technical-gap-baseline-history-through-20260913.md new file mode 100644 index 000000000..2d5abe565 --- /dev/null +++ b/docs/evidence/product-technical-gap-baseline-history-through-20260913.md @@ -0,0 +1,1276 @@ +# Product & Technical Gap Baseline + + +> Live-authority overlay: 2026-09-13 20:27 KST. Protected `main` remains +> `83eba56149eb802cd63642c507c324c9976ec78e`, protected with a valid verified +> commit signature after two fresh sweeps. No protected-main merge or base movement +> occurred during this maintenance turn. +> +> Customer Master ownership issue #1052 / PR #1055 remains exact +> `50c4935eef1029467595f7004818643598b737c9`. Repository Tests `34746058653` +> (including full PostgreSQL), Security `34746058657`, and SAST `34746058639` +> are terminal GREEN. Required CodeQL `34746058693`, OpenCode `34746057593`, +> and Noema `34746057619` remain terminal failures at canonical `.github` / +> contextual-orchestrator owner boundaries. Strix `34746057545` / job +> `103694153476` remains genuinely `in_progress` at `Run Strix (quick)` on the +> unchanged head; elapsed time alone is not grounds to cancel it. #1055 therefore +> remains Ready only to preserve exact-head evidence and is not merge-ready. +> +> Fresh catalog-owner review identified buyer-path resilience gap #1077. The +> canonical `get_or_create_corporate_entity` correctly defers its explicit +> transaction and `pg_advisory_xact_lock` until after provider work, but existing +> Keyman/post-summary/Customer Master callers can retain a borrowed asyncpg +> connection across hierarchy inference/search corroboration. The process pool is +> bounded at `max_size=10`, so concurrent catalog misses can starve unrelated DB +> requests without any explicit DB lock. #1077 owns the causal contract: short +> candidate/alias snapshot lease, release before provider I/O, then a fresh +> under-lock catalog recheck/write with cancellation/error cleanup. It remains in +> the corporate-entity catalog bounded context and must not duplicate CO routing. +> +> The leftover-map comparison lineage suffix has also converged onto repaired #859. +> #859 exact `2550e8d88339e30297fa0aa19ffae77f9b78b73b` fixes the eight stale +> comparison-only distance cases (16 assertions) without changing production or +> report-mode semantics. The live serialized ancestry is #860 `ef29a5a9...` -> +> #861 `49973434...` -> #862 `382947ba...` -> #863 `4e8720e9...` -> #865 +> `dec97059...` -> #866 `198d6827...` -> #867 `3e338bc3...` -> #868 +> `8af935c0...` -> #869 `74bd9468...` -> #870 `d063bd97...` -> #871 +> `645a5b09...` -> #872 `57206ce8...` -> #873 `b25b3874...` -> #874 +> `ac531c41...` -> #875 `c2278234...`, with forks #876 `259e2d1a...` and +> #877 `677643a4...`; reconstructed successors #1033 `6db5cb71...` -> #1034 +> `5015f193...` preserve valid #878/#879 intent. PR bodies for this suffix were +> corrected to the live base/head authority and no longer claim #859's repaired +> consumer-test RED is still active. All remain Draft because current validation / +> local intentional REDs are unresolved; no ancestor receipt transfers. +> +> #1057 remains the separate hosted PostgreSQL + Keycloak + Valkey authenticated +> bearer/JWKS/RBAC/ABAC topology owner. Draft #961 remains the runtime-version +> source repair and #1056 retains immutable release/SBOM/provenance/ +> reproducibility/rollback acceptance. No release is admitted by this overlay. +> Older overlays below are dated evidence only. + + +> Live-authority overlay: 2026-09-13 16:54 KST. Protected `main` remains +> `83eba56149eb802cd63642c507c324c9976ec78e` pending final double sweep. +> Customer Master ownership issue #1052 / PR #1055 is on exact +> `50c4935eef1029467595f7004818643598b737c9`, Ready only for validation +> admission. Predecessor `8448a2b4e06c6ef415dd98b3eaa1f7f36669fe94` +> exposed a real repository RED after shared eligibility SQL qualification: +> Tests `34743575403` ended `2 failed, 1777 passed, 147 skipped`. The two +> failures were the corroborated-association/reused-catalog unit tests. Their +> fake query recognizers still expected old unqualified capture/revalidation +> SQL, so they returned no evidence after production queries were correctly +> qualified with `source_post.*`; the scope-change test also stopped reaching +> its intended revalidation phase. +> +> Causal commit `50c4935e...` changes only those unit-fake recognizers to the +> canonical qualified SQL. Production authorization, persistence, locking, +> provider/model selection and workflow gates are unchanged. Fresh exact-head +> validation materialized without no-op churn. Frontend lint/test/build/ +> Storybook, Security `34746058657`, and SAST `34746058639` are GREEN. Full +> PostgreSQL Tests `34746058653`, Required CodeQL `34746058693`, Noema +> `34746057619`, and Strix `34746057545` were still live at this snapshot; +> Required OpenCode `34746057593` is terminal FAILURE. No predecessor review +> receipt transfers, and #1055 is not merge-ready. +> +> #1057 remains the separate PostgreSQL + Keycloak + Valkey bearer/JWKS/RBAC/ +> ABAC hosted-topology owner. Central workflow repair remains `.github#1929/ +> #2106` for CodeQL producer/consumer settlement and `.github#2045/#2109` for +> Ready-transition/model-review reconciliation; LineageWeave does not copy +> those owner implementations. Draft #961 remains the package/runtime-version +> source repair and #1056 carries immutable release/SBOM/provenance/ +> reproducibility/rollback acceptance. Protected main still has package/ +> frontend `2.28.0` versus runtime `2.20.0` until normal integration. No +> release is admitted by this overlay. Older overlays below are dated evidence only. + + +> Live-authority overlay: 2026-09-13 15:24 KST. Protected `main` remains +> `83eba56149eb802cd63642c507c324c9976ec78e` pending final double sweep. +> Customer Master ownership issue #1052 / Draft PR #1055 is now at exact +> `831fc52a1969f2999109da2c061067a9dc0ae954`. Bounded repair run +> `34741807255 / 103682639248` reproduced the ordinary-hosted response-contract +> RED, applied the minimal serializer/E2E expectation repair, obtained focused +> GREEN, and published a self-cleaning ordinary commit. The current head adds +> `tests/test_customer_master_hint_response_contract.py`, updates the real-service +> `backend/tests/test_api.py` expectation, and contains no temporary repair workflow. +> All #1055 inline review threads are resolved. +> +> Current-head central workflow identities are Draft lifecycle `action_required`, +> not GREEN receipts. Immediate parent `b9346dc681997a0274194d2ed913a22bb7488cca` +> has SAST/Security/dynamic-CodeQL/Code-Quality/OpenCode/Strix success; Required +> CodeQL remains the canonical `.github#1929` ordering/reconciliation failure, and +> predecessor Noema evidence cannot authorize `831fc52...`. `.github#2045` remains +> open for unchanged-head Draft-to-Ready materialization, so no empty commit or +> lifecycle-flip loop is used to manufacture current-head evidence. +> +> Issue #1057 still owns the hosted PostgreSQL + local Keycloak development fixture +> + Valkey bearer/JWKS/RBAC/ABAC lane. Its original #1055 response-shape canary is +> repaired, but the service-wide-skip topology defect remains. #1042/#1054/#1047/ +> #1049/#1046 remain Draft under their own live authority. Protected-main release +> identity source repair is existing Draft PR #961 at exact +> `3bdec0504a65e63f44bd49ba15de37182a1672cc`; issue #1056 now converges release, +> SBOM, provenance, reproducibility and rollback acceptance onto that single writer +> rather than spawning a competing lane. Protected main itself still reports +> `pyproject.toml` 2.28.0 versus runtime `lineageweave.__version__` 2.20.0 until +> normal integration. OpenTelemetry and PostgreSQL warning owners remain #1036/#973 +> and #1038/#1040. No release is admitted by this overlay. Older overlays below are +> dated evidence only. + + +> Live-authority overlay: 2026-09-13 12:11 KST. Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`; +> inventory is 159 open PR / 36 open issue. +> Customer Master ownership repair #1055 is Ready validation admission at exact +> `08a08108a87657ad427a6b6fa9b1b327166b0c9e`. Current repair separates source-post corporate/process +> authorization ownership from corroborated customer identity and delegates corporate +> catalog binding to the accepted `get_or_create_corporate_entity` owner (ADR 0010, +> ADR 0012, ADR 0160) instead of a Customer Master-local display-name lookup/direct +> insert. Source authorization locks are reacquired only for the short exact-source +> revalidation/persistence transaction after external corroboration/catalog resolution. +> Validation evidence from predecessor heads does not transfer across this head. +> +> #1042, #1054, #1047, #1049 and #1046 remain repair prerequisites/Draft unless +> their own live PR authority says otherwise. #1042's Medium CWE-862 period-report +> aggregate disclosure remains owned by #1050/#1054, not duplicated into Customer +> Master relationship code. Canonical central workflow defects remain `.github#1929` +> (required CodeQL producer/consumer ordering) and `.github#2045` (unchanged-head +> Ready reconciliation). Protected-main release metadata is still blocked by the +> tracked `pyproject.toml` 2.28.0 versus `lineageweave.__version__` 2.20.0 mismatch; +> no release is admitted from this overlay. Older overlays below are dated evidence. + + +> Exact-head loop overlay: 2026-09-13 11:55 KST. Protected `main` is still +> `83eba56149eb802cd63642c507c324c9976ec78e`. Customer Master customer-hint +> ownership repair #1055 now has final causal head +> `b26e5391d087e2e9610a8c0d52eaeb68f1f912a7`. Predecessor `7dbd1333...` +> completed repository/full-PostgreSQL Tests, Security, SAST, dynamic CodeQL, +> Noema and Strix successfully but remained blocked by Required CodeQL/OpenCode; +> it returned to Draft before further changes, and those receipts do not transfer. +> +> Three ordinary non-force follow-ups close the remaining docstring/test-contract +> acceptance without changing Customer Master production semantics: focused unit +> helpers now have meaningful docstrings and assert the exact association INSERT +> tuple, the live PostgreSQL ownership proof is documented, and +> `tests/test_customer_hint_docstring_contract.py` AST-enforces docstrings on every +> production function owned/touched by this repair. #1055 is Ready only as exact-head +> validation admission. The causal `b26e5391...` push materialized ten fresh lanes, +> including repository Tests/Security/SAST/CodeQL, dynamic CodeQL/Code Quality, +> Required scheduler, Strix, OpenCode and Noema; they are currently queued/running. +> No predecessor GREEN or approval counts toward promotion. +> +> #1042, #1054, #1047, #1049 and #1046 remain Draft. #1042's real Medium CWE-862 +> period-report aggregate finding remains owned by #1050/#1054 rather than duplicated +> into Customer Master relationship-network code. Canonical central workflow defects +> remain `.github#1929` (CodeQL producer/consumer ordering) and `.github#2045` +> (unchanged-head Ready reconciliation). Protected-main release metadata remains +> inconsistent (`pyproject.toml` 2.28.0 versus `lineageweave.__version__` 2.20.0), +> so no release is admitted. PR #1041 remains Draft; older overlays are dated evidence. + +> Exact-head loop overlay: 2026-09-13 11:00 KST. Protected `main` remains +> `83eba56149eb802cd63642c507c324c9976ec78e`. Customer Master process-unit +> repair #1042 is now Draft at exact +> `f23f5a567bd66113603837f86f030c3c459e69e6`: Strix `34721720240` +> terminalized FAILURE after setup and scan execution. Immutable artifact +> `10309695301` (95,509 bytes, +> `sha256:47822709dfdc45968569dbd4adf6bde167ba5eb46277503e906ee9625262d8b8`) +> contains one real Medium CWE-862 finding: mixed-visibility project/thread/team +> period-report endpoints could disclose full-population stored aggregates when +> at least one contributor remained visible. That defect is already isolated in +> #1050/#1054; #1054 is the security prerequisite and report authorization is not +> duplicated into #1042. Future #1042 integration requires a non-force descendant +> restack/reconstruction after that prerequisite lands. +> +> Customer-hint ownership repair #1055 is on exact +> `7dbd133320d8b12bde394569955e0ae6503f8f39`. Predecessor repository validation +> reached 1771 passed / 147 skipped and then exposed two owned REDs: migration +> 0250 was not replay-safe and the static SQL-review ledger still expected 36 +> suppressions after the repair legitimately removed one. Exact head now uses +> `CREATE TABLE IF NOT EXISTS` / `CREATE INDEX IF NOT EXISTS` and tracks 35 +> reviewed suppressions. Security `34731558854`, SAST `34731558875`, dynamic +> GitHub CodeQL `34731558343`, and Code Quality `34731558308` are GREEN. +> Repository Tests `34731586226`, Required Noema `34731558900`, and Strix +> `34731558917` are still live. Required CodeQL `34731558861` failed because +> compatibility consumers terminalized before the producer dispatch later +> succeeded; canonical owner `.github#1929` carries the unchanged-head canary. +> Required OpenCode `34731558957` failed closed without a current-head verdict. +> #1055 is Ready only as a live validation admission, not a merge-ready claim. +> +> #1054 remains Draft at `4519c101f13e08c10653b95ff88d66b4ce47f0b8` with +> repository Tests GREEN and central unchanged-head workflow reconciliation owned +> by `.github#2045`. Protected-main release metadata remains inconsistent: +> `pyproject.toml` declares 2.28.0 while `lineageweave.__version__` declares 2.20.0. +> No release is admitted while that blocker or any current required gate remains. +> PR #1041 remains Draft; every older overlay below is dated evidence only. + + +> Exact-head loop overlay: 2026-09-13 10:14 KST. Protected `main` remains +> `83eba56149eb802cd63642c507c324c9976ec78e`, protected with a valid verified +> commit signature. Fresh non-Draft inventory contains exactly #1042 and #1055; +> both are validation admissions only, not merge-ready claims. +> +> Customer Master process-unit repair #1042 remains at exact +> `f23f5a567bd66113603837f86f030c3c459e69e6`. Repository Tests/Security/SAST +> are terminal GREEN while Required CodeQL/OpenCode/Noema are terminal FAILURE. +> Strix `34721720240` is still genuinely in progress on the unchanged head, so +> elapsed time alone is not used to cancel it. If that lane terminalizes while +> authoritative failures remain, #1042 returns to Draft. +> +> Customer-hint ownership issue #1052 / PR #1055 advanced after review to exact +> `e11ff8698f20afc4ac628a6a86611ad1348c3fcb`. Migration 0250 and Proposed ADR +> 0374 keep `source_post.corporate_entity_id` / `process_unit_id` as access +> ownership and persist resolved customer identity in +> `source_post_customer_resolution`. Request identity is whitespace-normalized +> for matching and corroboration while the association preserves the actual raw +> `source_post.source_customer_code`. External resolution still runs with the DB +> resource released; a short persistence transaction then revalidates and +> `FOR SHARE` locks the exact captured source set before writing the association. +> Customer Master now selects resolved id/name/status/evidence coherently from one +> deterministic newest resolution row rather than independent aggregate maxima. +> The bearer + PostgreSQL regression also excludes foreign same-hint evidence, +> preserves source ownership and raw spaced hints, rejects blank HTTP hints, and +> checks coherent newest-resolution metadata. The four validated CodeRabbit +> findings are repaired and their outdated threads resolved. +> +> #1055 was marked Ready on the unchanged exact head only to admit fresh +> validation. Repository Tests `34730379137` rematerialized; frontend +> lint/test/build/Storybook is GREEN and the PostgreSQL job is still active. +> Draft-time Security `34730262196`, SAST `34730262117`, and Required CodeQL +> `34730262172` are `action_required`; no fresh central Security/SAST/Required +> CodeQL/OpenCode/Noema/Strix identity appeared at the first Ready reconciliation +> read. Canonical owner `.github#2045` now carries this unchanged-head canary. +> Do not use a no-op commit, Draft/Ready oscillation, or synthetic status to +> manufacture promotion evidence. +> +> #1054, #1047, #1046 and #1049 remain Draft. Protected-main release metadata +> remains inconsistent (`pyproject.toml` 2.28.0 versus +> `lineageweave.__version__` 2.20.0), so release remains blocked. PR #1041 stays +> Draft; every older overlay below is dated evidence only. + + +> Exact-head loop overlay: 2026-09-13 09:46 KST. Protected `main` remains +> `83eba56149eb802cd63642c507c324c9976ec78e`. Fresh live inventory reports +> 159 open PRs and 36 open issues. Exactly two open PRs are non-Draft, #1042 +> and #1055; both are Ready only to preserve or obtain exact-head validation, +> not as merge-ready claims. +> +> Customer Master process-unit repair #1042 remains on exact +> `f23f5a567bd66113603837f86f030c3c459e69e6`. Repository Tests/Security/SAST +> are terminal GREEN and Required CodeQL/OpenCode/Noema are terminal FAILURE. +> Strix `34721720240` remains genuinely in progress on the unchanged head, so +> elapsed time alone is not used to cancel it. If that lane terminalizes while +> required failures remain, #1042 returns to Draft. +> +> Customer Master customer-hint ownership issue #1052 now has repair PR #1055 +> at exact `77e7c8bd8bacb8f0ce30dd9e5ddd71c30a7632da`. Migration 0250 and Proposed +> ADR 0374 introduce normalized `source_post_customer_resolution`; hint +> corroboration captures only caller-visible eligible evidence, releases its DB +> resource before external resolution/verification, then reacquires a short +> transaction and `FOR SHARE` revalidates the exact captured sources before an +> idempotent association write. `source_post.corporate_entity_id` and +> `process_unit_id` remain authorization ownership and are never rebound to the +> resolved customer. Customer Master read models consume the normalized +> association only after source-post ABAC. A live PostgreSQL regression covers +> two private tenants sharing one synthetic hint and requires that only the +> authorized tenant's source receives the resolution association while both +> source ownership tuples remain unchanged. +> +> On #1055, fresh repository Tests `34729447666` rematerialized after Ready; +> frontend lint/test/build/Storybook is GREEN and the full PostgreSQL suite is +> still running. Draft-time central Security `34729440550`, SAST `34729440465`, +> and Required CodeQL `34729440480` remain `action_required` and did not obtain +> fresh identities on the unchanged Ready head. Canonical Ready reconciliation +> owner `.github#2045` has this canary; no no-op commit, lifecycle flip loop, or +> manual success status is used. Authenticated HTTP/E2E cross-tenant evidence, +> central security/model gates and independent current-head approval are still +> required before integration. +> +> #1054, #1047, #1046 and #1049 remain Draft. #1053 still owns Post Chat +> read-derived compute versus shared-persistence mutation authority and must not +> duplicate #1044/#1047 replay-disclosure ownership. Protected-main release +> metadata remains inconsistent (`pyproject.toml` 2.28.0 versus +> `lineageweave.__version__` 2.20.0), so protected release remains blocked. +> PR #1041 remains Draft; every older overlay below is dated evidence only. + +> Exact-head loop overlay: 2026-09-13 08:51 KST. Protected `main` remains +> `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). Fresh live +> search reports 158 open PRs and 36 open issues. Exactly one open PR is +> non-Draft: #1042, whose Ready state is validation admission only. +> +> Customer Master process-unit authorization remains issue #1045 / PR #1042 +> at exact `f23f5a567bd66113603837f86f030c3c459e69e6`. Repository Tests +> `34721721155`, Security `34721721167`, and SAST `34721721186` are terminal +> GREEN. Required CodeQL `34721721113`, OpenCode `34721720227`, and Noema +> `34721720347` are terminal FAILURE. Strix `34721720240` is still genuinely +> in progress on the same exact head, so the admission is preserved without +> elapsed-time cancellation or source churn. The later CodeQL producer dispatch +> succeeded only after compatibility consumers had already failed; canonical +> owner repair remains `.github#1929` and predecessor receipts do not transfer. +> +> Mixed-visibility period-report authorization remains issue #1050 / Draft PR +> #1054 at exact `4519c101f13e08c10653b95ff88d66b4ce47f0b8`. Whole-population +> admission now suppresses a precomputed report aggregate when any persisted +> member or leftover-pair contributor is not visible; comparison evidence carries +> `process_unit_id`, and authenticated Keycloak + PostgreSQL regression proves +> detail/list/comparison visible before scope contraction and suppressed after a +> contributor becomes foreign-private. Repository Tests `34723167232` is terminal +> GREEN, including the full PostgreSQL suite, and dynamic GitHub CodeQL reports no +> new alerts. Draft-push central Security `34723086654`, SAST `34723086683`, and +> Required CodeQL `34723086691` stayed `action_required`; after Ready only the +> repository Tests identity rematerialized. With no live validation lane left, +> #1054 returned to Draft on the unchanged head. Canonical lifecycle repair is +> `.github#2045`; do not use empty commits, Draft/Ready oscillation, manual status, +> or leaf-side gate weakening. +> +> Persisted Post Chat replay authorization remains Draft PR #1047 at exact +> `41c7a86f78dddf0bcd9e9f0eb070bf90732f68e3`. Repository Tests, Security, +> SAST, dynamic CodeQL and Code Quality are GREEN there, while Required CodeQL, +> OpenCode, Noema and Strix are terminal FAILURE. Dependency advisory +> GHSA-82fw-gwwq-j7x9 remains issue #1043 / Draft PR #1046 at +> `f80c0ec5f35fd4fc0a867125bc46dfd2d2dee9a9`; duplicate migration ordinal +> 0233 remains issue #1048 / Draft PR #1049 at +> `5322971193d1ff4e0ae13c054d8f99615934d4dc`. +> +> Customer Master customer-hint repair remains issue #1052. ADR 0042 requires +> source-post tenant/access ownership to stay distinct from resolved customer +> identity and provenance; do not repair that issue by rebinding +> `source_post.corporate_entity_id`. Post Chat shared-persistence mutation remains +> issue #1053 and must not duplicate #1044/#1047 replay-authorization ownership. +> +> Protected-main release metadata is still inconsistent: `pyproject.toml` declares +> 2.28.0 while `lineageweave.__version__` declares 2.20.0. Keep this as a release +> blocker rather than normalizing it in documentation. ADR 0251 remains the I/O- +> psychology authority and ADR 0256 the extensible Voice-combination contract. +> RankWeave, ThreadWeave, TEPP, and canonical lowercase +> `ContextualWisdomLab/disksage` retain their own bounded responsibilities. +> PR #1041 remains Draft; earlier overlays below are dated historical evidence only. + +> Exact-head loop overlay: 2026-08-29 13:20 KST. Protected `main` is +> `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map +> explained leftover share, #775). Open ready PRs still lack independent +> APPROVE. #782 leftover-map coordinates + graphic + axis share + ticks +> (v2.24.0–v2.27.0 / ADR 0267–0270) is on +> `2a203bf8b75b987ba899a0006a312d81259b9124` after #799 squash-merged +> into the unprotected leftover branch. Auto-merge squash remains armed +> on #782/#780/#774/#772/#771/#770. Independent APPROVE is still +> required for protected main. Drafts remain dirty against `main`. #96 +> stays closed as a weaker duplicate of #91. GitHub writes through +> `gh`/MCP succeed. Copilot review is not independent APPROVE. Do not +> self-approve. Do not `gh pr merge` stacked leftover PRs onto an +> unprotected leftover base. +> +> Next buyer increment on this cycle: leftover-map distance on +> graphic-display pair segments (ADR 0271 / v2.28.0). Caption each +> closest/farthest segment with persisted leftover-map distance `d` so +> the pair-row badge matches the graphic line. UI-only; no new columns. +> Missing/non-finite `d` omits that segment caption. Do not invent `d` +> from plotted coordinates. Do not invent leftover scores. Stack onto +> leftover branch `feat/leftover-map-coordinates-v2240`; leave the PR +> open for independent review. + +> Exact-head loop overlay: 2026-08-29 13:15 KST. Protected `main` is +> `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map +> explained leftover share, #775). Open ready PRs still lack independent +> APPROVE. #782 leftover-map coordinates + graphic display + axis share +> (v2.24.0 / v2.25.0 / v2.26.0 / ADR 0267 / ADR 0268 / ADR 0269) is on +> `4a0afbf4804d9862bba58869db20ccdfb0a0b37e`; Strix fail-closed and no +> independent APPROVE. Auto-merge squash remains armed on +> #782/#780/#774/#772/#771/#770. Drafts remain dirty against `main`. +> #96 stays closed as a weaker duplicate of #91. GitHub writes through +> `gh`/MCP succeed (comment/create-branch/auto-merge). `git push` HTTPS +> still fails (empty `X-OAuth-Scopes`). Copilot review is not +> independent APPROVE. Do not self-approve. +> +> Next buyer increment on this cycle: leftover-map coordinate ticks +> (ADR 0270 / v2.27.0). Tick leftover-map axes at the origin and at each +> unique finite persisted `ξ` / `ζ` so pair-row `ξ (x, y) ζ (x, y)` +> matches the graphic. UI-only; no new columns. Rank-0 unused axes name +> only `0` and do not invent drawing-scale `−1` / `+1` ticks. Do not +> invent leftover scores. Do not mix into #782; stack onto leftover +> branch `feat/leftover-map-coordinates-v2240`. + +> Exact-head loop overlay: 2026-08-28 19:15 KST. Protected `main` is +> `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map +> explained leftover share, #775). Open ready PRs still lack independent +> APPROVE. #782 leftover-map coordinates + graphic display (v2.24.0 / +> v2.25.0 / ADR 0267 / ADR 0268) is on +> `2f7e9c8df695f12d03964d5caa68fa3355bdd923`; Strix fail-closed and no +> independent APPROVE. Drafts remain dirty against `main`. #96 stays +> closed as a weaker duplicate of #91. GitHub writes through MCP succeed +> (comment/create-branch/git push/auto-merge). Copilot review is not +> independent APPROVE. Do not self-approve. +> +> Next buyer increment on this cycle: leftover-map axis share on the +> graphic display (ADR 0269 / v2.26.0). Caption plot axes with persisted +> ADR 0148 `leftover_map_axes` inertia `σ_k² / Σ_j σ_j²`. UI-only; no +> new columns. Rank-0 zero-share axes still named. Missing/non-finite +> share omits that axis badge and keeps existing leftover-map axis +> text. Do not invent leftover scores. Do not mix into dashboard stacks +> #640/#778/#781. + +> Exact-head loop overlay: 2026-08-28 16:05 KST. Protected `main` is +> `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map +> explained leftover share, #775). Open ready PRs still lack independent +> APPROVE. #782 leftover-map coordinates (v2.24.0 / ADR 0267) is on +> `e2d13019004a5d8c019fecf7a39ceeef4093b8dd`; Strix fail-closed and no +> independent APPROVE. Drafts remain dirty against `main`. #96 stays +> closed as a weaker duplicate of #91. GitHub writes through MCP succeed. +> +> Next buyer increment on this cycle: leftover-map graphic display +> of already-persisted `ξ_{1:2}` / `ζ_{1:2}` (ADR 0268 / v2.25.0). +> UI-only; no new columns. `R̂` and `d` already are inner product and +> length. Do not invent leftover scores. Do not mix into dashboard +> stacks #640/#778/#781. + +> Exact-head loop overlay: 2026-08-28 13:00 KST. Protected `main` is +> `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map +> explained leftover share, #775). Open ready PRs still lack independent +> APPROVE. Drafts remain dirty against `main`. #96 stays closed as a +> weaker duplicate of #91. GitHub writes through `gh` succeed. +> +> Next buyer increment on this cycle: leftover-map coordinates +> `ξ_{1:2}` / `ζ_{1:2}` (ADR 0267 / migration 0245 / v2.24.0) so +> `R̂ = ξ · ζ` and `d = ‖ξ − ζ‖` are buyer-auditable. Do not name +> leftover-map inner product, cosine, or length as separate columns. + +> Exact-head loop overlay: 2026-08-28 10:00 KST. Protected `main` was +> `edf22ee39aee2a8481f9bda8fff59801821e79c2` (#773 similar-VOC coverage). +> Open ready PRs: #772 (ask_time_axis coverage), #771 (fixtures/vision +> coverage), #770 (project-history empty-state). Auto-merge squash is +> enabled on all three; none has an independent APPROVE (only bot +> COMMENT). Drafts #702, #679, #672, #667, #640 remain dirty against +> `main`. #96 stays closed as a weaker duplicate of #91. Writes through +> the Grok GitHub App now succeed (comment/close/auto-merge/update-branch) +> despite empty `X-OAuth-Scopes`; git push is the remaining probe this +> cycle. This overlay supersedes every older queue count below. +> +> Next buyer increment on this cycle: leftover-map explained leftover +> share `e = R̂² / R²` (ADR 0266 / migration 0244 / v2.23.0) so +> `e + s + x = 1` is buyer-auditable. Do not persist leftover-map +> coordinates in this slice. + +> Exact-head loop overlay: 2026-08-28 KST. Protected `main` was +> `bbb191924e9881a5201f1ecf63c854d92992cc1c`; seven PRs and nine issues were +> open. PR #763 was `b51d3bd8872b` and PR #762 was `e6ca33dba1b5`; both were +> mergeable, normal squash auto-merge was enabled, exact-head Checks were still +> running, and no qualifying independent approval existed. PRs #702 +> (`93e7b81d096d`), #679 (`135dfe7c4266`), #672 (`a3e87a89185f`), #667 +> (`0c0f4af572a9`), and #640 (`bd73e0a43ae1`) remained draft and dirty against +> `main`. Central ruleset 18156473 and repository no-force-push ruleset +> 21065108 remain active. This overlay supersedes every older queue count below. +> Checks from older heads, stacked bases, or merged PRs are not transferred. +> +> Current-runtime boundary: the official Compose project was healthy at the +> HTTP health route, but its PostgreSQL schema did not yet contain +> `source_post_voice`; therefore no current Voice-history aggregate, +> authenticated project-history API result, or rendered authenticated UI result +> is claimed. Older aggregate observations below remain dated supporting +> evidence, not confirmation of this exact head. The checked repository names +> are `ContextualWisdomLab/LineageWeave`, `RankWeave`, `ThreadWeave`, `TEPP`, +> and lowercase canonical `ContextualWisdomLab/disksage`. + +> Voice-of-X delivery snapshot: 2026-08-27 KST. Protected `main` was +> `ff7431bd1851c03e737808d22c6a2d43968582f9`; PR #713 was +> `850494c3861703862a76cfe564381a41243c6c2d`; stacked PR #717 was +> audited at implementation head +> `d5fe4828e9005f0157c308e8ea3c3a590cdf465b`. This candidate and the +> historical evidence below are not protected-main release evidence. +> Loop snapshot: 2026-08-27. Protected `main` advanced through the +> I/O-Psychology job-family and occupational-classification delivery: PRs +> #709 (DOT/FJA worker functions, ADR 0232), #718 (evidence-bound construct +> classes, ADR 0248), +#726 (catalog-bound construct extraction, ADR 0253), +> #733 (construct evidence navigation, ADR 0255), #713 (Voice-of-X ADR 0246), +> #753 (FJA I/O-Psychology semantic layer, ADR 0251), #751 (SOC/O*NET/RIASEC +> taxonomy, ADR 0245), #749 (authorized job-family and job-series snapshot +> import, ADR 0263), #657 (TEPP lifecycle evidence), #704, #720, and #754 are +> now merged. The still-open queue is carried in section 1. No row below is +> release evidence until re-verified on a specific head. + +## Voice-of-X product and technical gap + +ADR 0246 and PR #713 add Supplier, Employee, Business, Regulator, Investor, +Society, and Process to the original Customer, Customer's Customer, +Competitor, Market, and Partner source-post vocabulary. The migration, +published SKOS concepts, product requirements, changelog, and ontology +round-trip tests agree on the twelve codes. The design is organization-type +neutral: public bodies, nonprofits, communities, and automated processes do +not need to be forced into a B2B2C customer chain. + +The phrase "all Voice-of-X combinations" does not have a standards-backed +finite enumeration. ISO's own stakeholder-category guidance says that the +relevant category set varies by committee and subject; ISO 26000 requires +stakeholder identification and engagement across organizational contexts; +AA1000SES requires an inclusive, continuing identification process; and +Mitchell, Agle, and Wood (1997) model stakeholder salience from combinations +of power, legitimacy, and urgency rather than a fixed industry-role list. +Accordingly, ADR 0246 keeps the controlled vocabulary extensible and refuses +keyword inference, defaults, invented weights, or an asserted exhaustive +cross-product. + +ADR 0256 and migration 0237 now define the persistence contract for +evidence-bearing composition. A post keeps one source-provided +`voc_type_code`, mirrored as its sole primary association, while every +additional voice requires a normalized PROV-O assertion and explicit truth +status. Half-open assignment intervals preserve a backfilled primary at +historical cutoffs, close a replaced primary without deleting it, and permit a +later return to the same Voice. The #717 candidate therefore addresses #748's +A → B → A storage root cause without adding Cartesian-product codes. Protected +delivery and synthetic PostgreSQL concurrency/cutoff evidence remain required. +The remaining acceptance boundary is: + +1. preserve the imported primary voice without reclassification (implemented + in the candidate migration; migration 0237 replayed twice successfully on + an isolated PostgreSQL stack on 2026-08-27, including both primary-sync + triggers; a synthetic real-OIDC PostgreSQL API write also proved that the + imported primary remains unchanged); +2. record each additional voice with its own source/evidence and truth state + (schema-enforced and candidate `post_admin` API plus live Post-popup + authoring implemented; synthetic authenticated PostgreSQL integration + proved denial before permission, the authorized write, and its normalized + PROV-O derivation on 2026-08-27); +3. keeps post voice distinct from named-counterparty relationship, actor role, + topic, channel, lifecycle, and stakeholder-salience attributes; +4. return only authorized associations through API, JSON-LD, CSV, filters, + and UI (candidate API list/detail, filters, combined post-card labels, + qualified JSON-LD, exact-value CSV, SHACL, and source-post evidence + navigation implemented; the board re-filter matches every associated voice + and all twelve governed atomic labels are localized across English, Korean, + Chinese, Japanese, and Vietnamese; one bounded query projects assignments + for every authorized Post even when another node type is the focus; post + detail lists primary and evidence-connected perspectives separately and + honors its knowledge cutoff; client-side JSON-LD filtering retains only + exact canonical repository-case node and Voice-assignment IRIs rather than + accepting cross-origin suffix matches; the exact-value row exposes distinct + carrying-Post and authorized derivation-evidence actions, while hidden + evidence emits neither an identifier nor a fabricated evidence count; + paged JSON-LD merges properties for one subject and unions its multi-Voice + relation rather than overwriting an earlier page); and +5. proves zero-, one-, and multi-voice states with synthetic fixtures, + migration replay, ontology/SHACL, API, accessibility, and Storybook edge + tests before any release claim. The candidate `CombinedVoiceEvidence` scene + covers primary-plus-additional assignments; desktop and mobile screenshots + were inspected on 2026-08-27. At 390 CSS pixels the document did not + overflow, the named exact-value region remained horizontally scrollable, + and the source-post evidence action remained visible and labeled. The + `Post/Recorded perspectives` desktop and 390-pixel scenes were also inspected + on 2026-08-27; both kept each complete Voice label paired with its imported + or evidence-connected state without clipping or horizontal overflow. The + `Post/Connect perspective` ready/success scenes were inspected at 1440 and + 390 CSS pixels on 2026-08-27: labels stay above controls, the mobile form is + a single column, controls meet the 44-pixel touch target, and no horizontal + overflow was visible. + +At this snapshot the repository had 42 open PRs and 11 open issues. PR #713 +head `850494c3` includes the review-driven localization of all twelve governed +Voice labels. Its frontend, ontology publication, static-analysis, dependency, +coverage, full-suite, CodeRabbit, Devin, and OpenCode checks passed. Strix +failed closed before producing a vulnerability report: +the primary NVIDIA NIM model returned HTTP 429, one configured fallback had +reached end of life, and the OpenAI fallback reported exhausted credits. A +same-head retry completed on 2026-08-27 with the explicit +`STRIX_PROVIDER_UNAVAILABLE` annotation and again produced no vulnerability +report. This +is provider/control-plane unavailability, not a vulnerability result or +permission to transfer an older success. Auto-merge remains enabled, while an +independent approval is still required. PR #717 implementation head +`d5fe4828` merges that +parent change without force-pushing and separates the complete governed Voice +catalog used for authoring from usage-derived Board filters, so an authorized +administrator can attach a Voice that no visible Post carries yet. It also +labels Voice exact-value navigation as opening the carrying Post rather than +misrepresenting that Post as the separately recorded derivation evidence. Its +CodeRabbit and hosted Frontend/Storybook checks passed at predecessor head +`ebb4ef1d`; refreshed checks for exact head `d5fe4828` were queued. Focused local +backend tests, frontend type checking/lint, and the new unused-Voice authoring +regression passed, and the exact-value navigation tests, lint, and type check +passed after the label repair. The paged JSON-LD union regression and Voice +evidence navigation suite passed 23 focused frontend tests; 48 focused backend +ontology/docstring tests also passed. The full backend suite at predecessor +head `ebb4ef1d` passed 1,366 tests with 148 environment-dependent skips. The +real-integration fixture now applies +the existing migration 0042 before the expanded taxonomy migrations instead +of seeding an incomplete or duplicate legacy catalog; the exact +`d5fe4828` authenticated post-list integration passed in 91.54 seconds. The +wider local frontend run had 400 passes and eight five-second timeouts under +concurrent backend-suite load; a later App-only run had 94 passes and five +five-second timeouts, while the hosted Frontend/Storybook job passed on +`ebb4ef1d`. Neither local timeout run is promoted to full-suite success. An initial +authenticated integration attempt was unavailable while Keycloak initialized; +a later retry against the shared synthetic stack succeeded in 56.18 seconds +and proved the permission, API, PostgreSQL, +PROV-O, and primary-preservation assertions; no identifying source data was +used or retained. No self-approval, admin bypass, or stale-head check transfer +is permitted. + +Stacked PR #717 carries ADR 0256, migration 0237, qualified +ontology terms, persistence/API/UI tests, and the category-validation review +repairs plus a local candidate admin write path that creates its PROV-O +derivation from an authorized evidence Post. Its JSON-LD projection names that +evidence Post only when it is in the authorized visible set and omits the whole +additional assignment otherwise, preserving the SHACL evidence minimum without +substituting the assigned Post. It targets +#713's branch, not protected `main`; +its checks and review are candidate evidence only. After +#713 reaches protected main, #717 must be synchronized, retargeted to `main`, +and revalidated on its then-current head. + +Downstream Dashboard repair PR #737 exact head `a837ee5d` is stacked on base +`7c7bb2cf`, which contains migration 0235 through a non-#713 composition but +does not contain #713's twelve-label locale update. Its added Voice labels are +therefore necessary on that exact base, yet overlap #713 and must be reconciled +when the stack is eventually rebuilt on protected `main`; neither branch is a +second taxonomy authority, and pre-parent Checks cannot transfer across that +restack. +The remaining user-visible gap is evidence-bearing composition. A post still +has one source-provided `voc_type_code`; the product cannot yet represent a +single record that intentionally carries multiple independently evidenced +voices, nor expose the combination in filters, exports, or the ontology +neighborhood. Do not solve this by adding every Cartesian-product code. The +acceptance boundary for a later ADR is a normalized, provenance-bearing +multi-voice association that: + +1. preserves the imported primary voice without reclassification; +2. records each additional voice with its own source/evidence and truth state; +3. keeps post voice distinct from named-counterparty relationship, actor role, + topic, channel, lifecycle, and stakeholder-salience attributes; +4. returns only authorized associations through API, JSON-LD, CSV, filters, + and UI; and +5. proves zero-, one-, and multi-voice states with synthetic fixtures, + migration replay, ontology/SHACL, API, accessibility, and Storybook edge + tests before any release claim. + +At this snapshot the repository had 23 open PRs and 10 open issues. PR #713 +was `MERGEABLE` but policy-blocked: exact-head backend, frontend, CodeQL, +ontology-publication, Semgrep, OSV, Trivy, Scorecard, Noema, Devin, and +CodeRabbit checks were successful; `coverage-source-tree` was queued; Strix +failed closed with `STRIX_PROVIDER_UNAVAILABLE`; and an independent approval +was still required. Auto-merge remains enabled. No self-approval, admin bypass, +or stale-head check transfer is permitted. + +References for this gap use the APA 7 entries in ADR 0246. Current supporting +standards pages were rechecked on 2026-08-27: ISO 26000:2010 remains applicable +to all organization types and AA1000SES v3 is under development for a planned +2027 release, so the repository continues to cite the published AA1000SES +(2015) contract rather than treating the draft as adopted policy. + +> Current queue overlay: 2026-08-27 KST. Protected `main` was +> `ff7431bd1851c03e737808d22c6a2d43968582f9`; 26 PRs and 10 issues were +> open. This overlay supersedes the older queue count and exact-head table +> below, which remain historical evidence. Re-fetch the head, checks, reviews, +> threads, applicable rulesets, and merge SHA immediately before any lifecycle +> claim. No local branch or stacked-branch result is protected-main evidence. + +## Current occupational semantic-layer gap + +ADR 0245's candidate branch publishes only a provenance-safe classification +foundation: 23 2018 SOC major groups, four O*NET 31.0 Job Zone categories, six RIASEC interest +types and their published adjacency, six explicitly legacy work-value clusters, seven +revised work-style dimensions, and four ability domains. It asserts no +occupation-to-characteristic instance profile and therefore does **not** yet +satisfy the requested job-family, job-series, and occupation-level coverage of +work cognition, affect, behavior, or their empirical relations. This is an +explicit unavailable state, not a reason to infer mappings from labels. + +| Gap | Current evidence | Acceptance requirement | +|---|---|---| +| Classification depth | ADR 0245 and `lineageweave/io_taxonomy.py` expose SOC major groups only; schemes now name versioned PROV source entities and the stable O*NET 31.0 Job Zone JSON digest | Import a versioned authoritative classification release with provenance-preserving major, minor, broad, and detailed occupation identifiers; add ISCO/ESCO crosswalks only where the publishing authority supplies them | +| Construct granularity | The candidate ontology exposes 23 high-level characteristic concepts | Publish source-versioned O*NET abilities, skills, knowledge, work activities, work context, interests, and work styles without collapsing cognition, affect, and behavior into one dimension; preserve removed Work Values only as versioned legacy content | +| Occupation-to-construct relations | ADR 0245 deliberately declares relation properties without instance assertions | Persist released source observations with source version, occupation code, element identifier, scale identifier, value, sample/error metadata when supplied, and provenance; never invent or locally normalize a weight | +| Job-family and job-series semantics | No authoritative employer-specific job architecture is present | Define an organization-neutral import contract that preserves the authorized source hierarchy and distinguishes standard occupation codes from employer job families/series; no label-based binding | +| Temporal and multilevel interpretation | Static vocabulary only; no person-level inference is asserted | Version valid and transaction time, preserve occupation/organization/unit nesting and multiple membership, and require TEPP or the owning Rust psychometric service before any calibrated temporal or multilevel result | +| Product consumption | The read model has no persisted semantic-layer consumer or authenticated UI evidence | Add a provenance-bearing API and accessible ontology exploration flow, then verify synthetic Storybook edge states plus authenticated aggregate runtime evidence without exposing identifying records | + +### Current exact-head PR queue + +| PR | Exact observed head | Base | Observed gate state | +|---:|---|---|---| +| #719 | `0cea830a` | `feat/fja-worker-function-ontology` | unstable; 1 pending check(s) | +| #718 | `a3fb32bb` | `feat/fja-worker-function-ontology` | clean; no non-passing check observed | +| #717 | `771a8edf` | `feat/voice-of-x-complete-taxonomy` | unstable; 1 pending check(s) | +| #716 | `8b54b2f7` | `fix/structured-workflow-exact-pin` | clean; no non-passing check observed | +| #714 | `aa93318f` | `main` | blocked; no non-passing check observed | +| #713 | `cc3dfc14` | `main` | blocked; review required; 13 pending check(s) | +| #711 | `8902e37f` | `feat/dashboard-case-metrics` | clean; no non-passing check observed | +| #710 | `8df04b68` | `main` | blocked; review required; no non-passing check observed | +| #709 | `8ef4090c` | `main` | blocked; review required; 11 pending check(s) | +| #704 | `027323cf` | `main` | blocked; review required; 2 failed check(s) | +| #702 | `5de66ab9` | `main` | blocked; review required; 2 pending check(s) | +| #701 | `cc3351a9` | `main` | blocked; review required; 1 failed check(s) | +| #700 | `1bc99eca` | `main` | blocked; review required; 1 failed check(s) | +| #680 | `efe864e5` | `main` | blocked; 1 failed check(s) | +| #679 | `13ecf41d` | `main` | blocked; no non-passing check observed | +| #672 | `a3e87a89` | `main` | blocked; review required; 1 failed check(s) | +| #668 | `1194f44d` | `main` | blocked; review required; 1 failed check(s) | +| #667 | `c2d11a8a` | `main` | blocked; review required; 2 pending check(s) | +| #658 | `15d670f0` | `main` | blocked; review required; 1 failed check(s) | +| #657 | `9f71681c` | `main` | blocked; review required; 1 failed check(s) | +| #644 | `f53dd28e` | `main` | blocked; review required; 1 failed check(s) | +| #643 | `8767de1b` | `main` | blocked; review required; 1 failed check(s); 1 pending check(s) | +| #640 | `5594029c` | `main` | blocked; no non-passing check observed | +| #639 | `2f4b1bff` | `main` | blocked; review required; 1 failed check(s) | +| #632 | `24262a99` | `main` | blocked; review required; 1 failed check(s) | +| #629 | `b721b0f2` | `main` | blocked; review required; 1 failed check(s) | + +> Dashboard delivery snapshot: 2026-08-26 07:15 KST. Protected `main` was +> `494b54e2245040bcf02b45376f221c37cd437e76`. This local branch is not +> protected-main release evidence. + +## Operations Dashboard PRD/TRD traceability + +| Requirement | Evidence contract | Delivery state | +|---|---|---| +| Claim cause delay: order, specification change, originating order, sales pool, Event/post counts | ADR 0206; contextual-orchestrator case classification with cited spans; Event Lineage context | Candidate implementation; authenticated runtime acceptance pending | +| Rebid/handover: discussion, counterparties, our owner, decisions, Event/post counts | ADR 0206; normalized case facts plus persisted summary actions/roles | Candidate implementation; corpus backfill pending | +| External information count/rate and sales/project relation | ADR 0206; semantic `external_information` classification inside Dashboard GNB | Candidate implementation; no separate Board by product decision | +| Project-specific journey | Explicit source/semantic project membership plus event-time ordering | Candidate API and ordered journey UI implemented; authenticated runtime acceptance pending | +| Repeat issue to design improvement | `repeat_issue`, `issue_pattern`, and `improvement_action` cited facts | Candidate semantic contract; design-system connector acceptance pending | +| Natural-language Ask with evidence, report, alert, MCP | Persisted semantic-unit embeddings plus versioned delivery/resource contract | Candidate implementation uses whole-question embedding retrieval with no lexical fallback; authenticated runtime acceptance pending | +| Similar VOC, customer cohort, prior action | Persisted repeat-issue candidate semantics plus orchestrator pair adjudication and extractive evidence | Candidate live post endpoint and post-detail UI implemented; authenticated runtime acceptance pending | +| TEPP independent Event Lineage anchor | Accepted, persisted TEPP criterion bound to exact snapshot/cutoff before fast-mlsirm activation | Consumer PR #606 is on protected main; TEPP producer PR #237 remains open, so no end-to-end accepted artifact is release evidence yet | +| Temporal Lineage topics and multilevel important posts | ADR 0210; TEPP posterior topic/plausible-value contract followed by fast-mlsirm observed-information case-deletion influence | Product/technical contract is protected on `main`; neither required Rust CPU/GPU producer envelope is shipped, so the Dashboard surface remains unavailable (ADR 0208: no local Python substitute) | + +### Technical contract and flow + +```mermaid +sequenceDiagram + participant Source as Authorized source_post + participant CO as contextual-orchestrator + participant Case as operations_case_* (3NF) + participant TEPP as TEPP criterion run + participant MLS as fast-mlsirm + participant API as Dashboard/Ask API + Source->>CO: semantic units + lineage + ontology context + CO-->>Case: cases, cited facts, session provenance + Source->>TEPP: versioned snapshot and independent criterion + TEPP-->>MLS: exact accepted anchor only + MLS-->>API: anchored vector or unavailable + Case-->>API: ABAC-filtered evidence and counts +``` + +Security/operability: every aggregation applies `post_read` plus row-level +corporate-entity visibility before counting; source-body digests invalidate +stale inference; provider errors persist no positive/negative result; PII +remains authorized at the UI boundary and is excluded from telemetry. The +tables use composite keys and bounded kind-first indexes; production hot-path +acceptance still requires `EXPLAIN (ANALYZE, BUFFERS)` on an anonymized runtime +snapshot. + +### Historical UI audit evidence + +The `f0b96029` Storybook build was rendered at 1440×1100 and 402×1200 with +synthetic evidence; `416fd19d` changes only post-navigation request isolation. +Desktop inspection showed all four case kinds, five non-conflated metrics, +project-journey ordering, cited facts, and evidence actions without horizontal +card overflow. Narrow inspection showed two-column metrics, readable cards and +44px-class actions; the project journey remains intentionally horizontally +scrollable. No identifying runtime record or screenshot is committed. The +`EvidenceReady`, `NarrowViewport`, `AnalysisPendingAndMissingEvidence`, +`AnalysisFailed`, and `LoadError` scenes cover the ADR 0206 state inventory. +Authenticated authorized-corpus acceptance remains separate and may return +only aggregate, non-identifying evidence to this repository. + +### Exact open-PR boundary + +At this snapshot there were 11 open PRs and 10 open issues. PRs #660 and #659 +merged to protected `main`; PR #666 remains only non-default-branch stack +composition inside #663. Every remaining open head required refreshed hosted +gates and/or independent review after the base changed. These observations are +not merge readiness. Re-fetch exact heads, unresolved threads, checks, +approvals, rulesets, and merge SHA before any lifecycle claim. + +> Audit snapshot: 2026-08-26 07:15 KST (refreshed by the autonomous merge +> loop). This repository records synthetic fixtures and aggregate, +> non-identifying runtime evidence only. Open PRs and local checks are not +> protected-default-branch release evidence. Identifying post identifiers, +> organization names, and production record keys must never appear in this +> file. + +## 1. Exact-head and governance evidence + +The protected default branch was `494b54e2245040bcf02b45376f221c37cd437e76` +when this baseline was refreshed. The live queue contained 11 open PRs and 10 +open issues. The exact-head inventory below supersedes older per-PR snapshots +elsewhere in this document; those older rows remain useful historical delivery +context only. + +| PR | Exact observed head | Merge/check state at this snapshot | +| ---: | --- | --- | +| #667 | `3bc662d7` | refreshes protected-main and open-queue documentation evidence; base conflict remains to be repaired | +| #663 | `6fd2f701` | combined Project ontology candidate plus #666's non-default-branch removal of sampled region-coverage arithmetic; base conflict remains to be repaired | +| #658 | `f007a5ed` | evidence-honest Global Ask cutoff; hosted checks and independent review required | +| #657 | `2d9b43b7` | TEPP asynchronous lifecycle persistence while unpublished producer work stays unavailable; hosted checks and independent review required | +| #644 | `ed8d97f3` | native frontend surface code splitting; hosted checks and independent review required | +| #643 | `7fb4d18c` | shared token-backed status notice; hosted checks and independent review required | +| #640 | `2d50fa01` | dashboard case metrics and project journeys; base conflict remains to be repaired | +| #639 | `48065ad1` | restores Running action and Compose contracts; hosted checks and independent review required | +| #632 | `29aee18d` | graph-fact provenance, public verification, MCP admission, and k6 evidence; hosted checks and independent review required | +| #631 | `665046dc` (observed parent) | decomposes closed PR #490; this merge refresh advances its head and restarts hosted review evidence | +| #629 | `0138db5f` | provider-work release and bounded landing reads refreshed onto protected `main`; hosted checks and independent review restarted | + +No row above is merge evidence. Immediately before any lifecycle action, +re-fetch the head, unresolved threads, formal reviews, rulesets, and same-head +check conclusions. In particular, queued checks are infrastructure state and +do not transfer evidence from an earlier SHA. + +PR #607 first merged as `61fd631c7bb3c57113fd19763c2c43161eeb2824` +into #606's non-default branch. PR #606 subsequently passed the protected gate, +so the combined TEPP-consumer and operations-dashboard implementation is now +on `main`; the still-open TEPP producer PR #237 keeps end-to-end anchor +acceptance unavailable. + +PR #604 was closed unmerged after its exact OIDC repair was composed into #605; +its green or pending checks are not delivery evidence. PR #482 merged as +protected-main commit `464ff25002044b9d933c8eefd36c8def7ca0ffd8` +with package conflict markers, identifying baseline records, and an OIDC +return-context regression. PR #603 repaired the package/privacy and +analysis-run transaction defects through protected main at `4f53190b`; the +OIDC defect remains delivered until #604 or the composed #605 passes the +protected gate. Protected main is therefore not yet a release candidate. + +PR #592 first merged as `3b3af3b4fe9c439354433a43444e05f37ab24ea3` +into #590's non-default stack base at `2f033ba3`. The complete stack then +passed the protected gate and #590 merged to `main` as +`1d1379fc59d9dac6e9c8bfa4812313e3b9e8f3c8`. + +PR #521 merged through protected `main` as +`3797f063b1a7396972a749aa81f23745acccbee1`; it is release evidence and no +longer part of the open queue. That merge also left a standalone conflict +marker and duplicated stale tail in `CLAUDE.md`; #594 repaired it through +protected `main` as `241be2dddf657f854cb8be54fe11d4ef48d37976`. + +Protected main now contains the ADR 0109 OIDC return restoration from #605, +including fragment preservation and storage fallback. The #606 dashboard +landing must additionally route `?post=` deep links to the Board; that focused +regression is part of the current candidate and is not delivery evidence yet. + +Three systemic gates currently dominate the queue: + +1. **Strix visibility lookup failure (org control plane).** PR #600 exact head + `7580bdc9` failed before scanning because the required-workflow token could + not resolve this public repository after six API retries. The root repair is + ContextualWisdomLab/.github#1320 at `3b9b2380`: ordinary PR, push, and + schedule runs use trusted event visibility; cross-repository dispatch keeps + authoritative public/private/internal visibility; private and internal + repositories remain on private-capable providers. The exact head also + composes the executable fallback contract and classifies bounded NVIDIA + `ServiceUnavailableError` overload evidence as retryable across configured + distinct models without weakening exhaustion or vulnerability fail-close. + A hosted fallback then completed with zero vulnerabilities but was rejected + because the generic warning gate treated Strix's fallback-model banner and + a Hugging Face unauthenticated-download notice as provider failures. The + current head removes only those two exact scanner notices before the + existing general warning and explicit 429/provider failure checks. The + current head also clears a foreign NVIDIA/OpenRouter endpoint before a + direct-OpenAI fallback while retaining an explicitly configured + direct-OpenAI primary endpoint. The prior full quick-gate harness, overload + path, 12 visibility-contract tests, and the focused cross-provider endpoint + contract passed; exact-head hosted revalidation remains pending. It is blocked on + hosted exact-head gates and independent review, so no repaired + protected-main Strix runtime evidence exists yet. +2. **Strix provider unavailability (org control plane).** The central required + Strix scan on .github#1320 failed when NVIDIA returned `Service temporarily + overloaded`; the gate correctly failed closed but did not try its configured + distinct fallbacks because the service-unavailable classifier excluded the + NVIDIA provider. Exact head `3b9b2380` composes that execution repair and the + two exact non-fatal scanner-notice exclusions while keeping + incomplete exhaustion non-passing. This is still an unmerged control-plane + proposal, not protected-main or downstream runtime evidence. +3. **Current-head independent approval.** The org merge scheduler requires + `reviewDecision == APPROVED` plus complete Strix evidence on the exact + head. Bot review evidence regenerates per push, so any repair push resets + the review clock by design; this is expected and not a bypass target. + +Recent protected-default-branch delivery evidence (squash merges onto +`main`, newest first): + +| PR | Merged (UTC) | Delivered | +| ---: | --- | --- | +| #628 | 2026-08-25 12:39 | one-round-trip authorized post filter options without narrowing the complete ABAC-visible set | +| #627 | 2026-08-25 12:35 | preserved valid k6 lifecycle evidence across setup, scenario execution, and teardown | +| #468 | 2026-08-25 08:44 | fast-mlsirm, Keyverse, contextual-orchestrator, and TEPP integration boundaries | +| #493 | 2026-08-25 08:44 | evidence-grounded Event Lineage isolation reasons | +| #600 | 2026-08-25 08:44 | then-current exact-head product/technical baseline | +| #605 | 2026-08-25 08:44 | dialog focus order, evidence readability, and OIDC return-context restoration | +| #608 | 2026-08-25 08:43 | Naruon projection consumed by Workspace Calendar | +| #603 | 2026-08-25 07:24 | short analysis-run transactions, session advisory locking, package-marker/privacy repair, and provider-work lease release | +| #602 | 2026-08-25 07:24 | post-detail modal semantics, Escape close, initial focus, and opener restoration; navigation-refocus edge case continues on #605 | +| #582 | 2026-08-25 07:24 | bounded batched cited-lineage graph fetch | +| #588 | 2026-08-25 07:23 | named two-axis leftover-map reconstruction and raw-residual identity | +| #482 | 2026-08-25 07:03 | corroborated SKOS companion organization chips; regressions subsequently tracked above | +| #601 | 2026-08-25 06:38 | APA 7th PROV-O and PROV-DM references for ADRs 0011 and 0065 | +| #595 | 2026-08-25 04:39 | audited no-draft import door, nullable updated-at fallback, and event-time import | +| #484 | 2026-08-25 04:39 | Allen interval relations with deferred FK validation | +| #383 | 2026-08-25 04:39 | reader-safe OTel diagnostics and service-peer-bounded session metadata | +| #599 | 2026-08-25 04:28 | raw-residual leftover-map cross-share identity aligned without arbitrary weighting | +| #598 | 2026-08-25 03:32 | 5W1H roles/events remain readable across a stale summary contract version | +| #597 | 2026-08-25 03:32 | related posts open Customer Master detail in place without stale graph state | +| #591 | 2026-08-25 03:32 | prior exact-head product-gap baseline snapshot | +| #584 | 2026-08-25 03:32 | TEPP topic-lineage consumption boundary grounded in cited temporal models | +| #581 | 2026-08-25 03:32 | relative-time Ask filtering bound to event time | +| #596 | 2026-08-25 03:27 | hierarchy/name-resolution deep-work timeouts aligned at 600 seconds | +| #585 | 2026-08-25 03:27 | raw Global Ask transport exceptions replaced by bounded client-safe detail | +| #355 | 2026-08-25 02:38 | Naruon calendar projection contract and conformance fixture | +| #562 | 2026-08-24 02:05 | parameter-free classic RRF; deleted the last hand-picked fused score | +| #561 | 2026-08-24 01:47 | knowledge-graph precedence/hierarchy relation classification and layout order | +| #555 | 2026-08-24 01:29 | per-channel score breakdown persisted on `post_lineage_edge.channel_scores` (ADR 0195) | +| #559 | 2026-08-24 01:26 | deleted `DEFAULT_CHANNEL_WEIGHTS` hand-picked fallback | +| #549 | 2026-08-24 00:43 | clamped embedding cosine into `[0, 1]` instead of remapping from `[-1, 1]` (ADR 0190) | +| #548 | 2026-08-24 00:37 | mid-reconstruction provider failure maps to an explicit unavailable state | +| #544 | 2026-08-24 00:27 | fusion weights accepted only via fast-mlsirm estimation | +| #538 | 2026-08-23 23:39 | real embeddings wired into the Event Lineage text channel | + +This documentation is owned by protected `main` again: the #426 stack landed, +so hidden-stack merges (#494, #497, #499, #505, #509 into unprotected parent +branches) are historical context only and no longer gate anything. + +The current protected-`main` and exact #507 trees are clean of the private +runtime source-table identifier present in the closed #506 head and older +public history. Do not reproduce or hint at its value. Historical remediation +requires the ADR 0001 incident process and security/privacy-owner coordination; +never force-push or delete evidence ad hoc. + +The Grok durable hourly loop and the central thin GitHub Actions caller +ContextualWisdomLab/.github#1259 (minute 4, `pr-review-fix-scheduler.yml`) +both target this repository. Do not add a LineageWeave-local duplicate +workflow. ContextualWisdomLab/.github#1258 merged at exact head `897819c4` to +repair the pnpm/coverage-evidence workflow; newly created exact PR heads must +still prove the runtime behavior because merged workflow source alone is not +check evidence. + +Figma design-system boundary (ADR 0002): File ID `1Su3lDRmiZdcUs47t1QwIX`. +The sanitized file now contains synthetic Event Lineage desktop (`5:14`) and +mobile (`5:15`) frames with graph direction, event dates, an inference +boundary, and exact fused-score evidence. Do not copy source-organization +content into this repository. Storybook remains the executable scene and +edge-case inventory for repeated web objects; rendered code-to-Figma parity +still requires same-viewport browser comparison on an exact candidate head. + +## 2. User-visible capability baseline + +Substantially present on protected `main`: + +- PostgreSQL-backed import, normalized provenance, cutoff-aware analysis runs, + source revisions, lineage reconstruction, and explicit unavailable states. +- Authenticated workspace navigation, post detail, localized summaries, 5W1H, + R&R/Keyman, evidence citations, chat, organization hierarchy, and lineage DAG + (`frontend/src/LineageDag.tsx` is on `main`; the old “DAG view missing” + baseline entry is stale). +- Semantic paragraph/list/table/image-region units that preserve the source + representation and provenance instead of flattening it into one body string. +- FJA→I/O-Psychology semantic layer (ADR 0251): the published DOT/FJA + Data/People/Things worker functions (ADR 0232) project into disjoint + cognitive, affective, and behavioral constructs with APA 7th anchors, + SHACL validation, and a deterministic typed read model + (`lineageweave/iopsy_taxonomy.py`); no fitted weight or O*NET/ADR 0248 + crosswalk is asserted (ADR 0145). +- Contextual-orchestrator boundaries for adjudication, extraction, summaries, + chat, embeddings, and VISION; null channels remain unavailable and are + dropped from score fusion. +- W3C PROV-O projection through normalized provenance tables, with the + knowledge graph retained as an explicit navigation projection. +- Keyverse/Keycloak OIDC, RankWeave fusion port, TEPP measurement client, + ThreadWeave tree assembly. + +These statements describe source capability, not authenticated production +corpus acceptance or protected release. + +## 3. Historical open-PR inventory (superseded by §1) + +Heads below are queue evidence captured at snapshot time; recheck SHA, +checks, unresolved threads, and independent approval immediately before any +merge claim. Do not self-approve, force-push, or transfer stale review +evidence across heads. The org merge scheduler merges only when +`reviewDecision == APPROVED` on the exact head and Strix evidence is complete. + +### 3.0 Shared systemic gate + +| Gate | Evidence | Durable repair | +| --- | --- | --- | +| Strix provider unavailability | `nvidia_nim/nvidia/nemotron-3-super-120b-a12b` and `openai-direct/gpt-5.6-luna` failed authoritatively across unrelated heads | ContextualWisdomLab/.github#1263 at `ab3d7645` proposes executable Azure/cross-provider fallbacks but remains open/conflicting; repair that branch without weakening the required gate | +| ADR 0109 login repair debt | Eight branches cut from the pre-repair base carried the unauthenticated `AdminPanel` + unused-OIDC-helper `tsc -b` failure | Same verified two-line repair applied to #521, #522, #552, #553, #554, #556, #558, #560 during this loop; frontend lint/test/build verified locally | + +### 3.1 Workspace root and product surfaces + +| PR | Head | Intent | Notes | +| ---: | --- | --- | --- | +| #258 | `f0b5234d` | Workspace evidence board and source-grounded ontology surface (root stack) | Largest surface; historical CHANGES_REQUESTED is stale relative to current head | +| #349 | `bef4a858` | Bounded ontology and provenance explorer (v2.13.0) | Issue #341 | +| #355 | `2f3f308c` | Naruon event projection contract | Issues #336/#338 | +| #387 | `5ef0f2e6` | Persist and explain Event Lineage channel evidence | Issue #274 | +| #405 | `ec62d9f0` | Persisted image-region locations (v2.12.8) | VISION region provenance | +| #484 | `878c4a87` | Allen interval relations on Event Lineage edges (v2.15.0) | Temporal modeling; Allen (1983) | +| #490 | `d0cad030` | Wire remaining ADR 0133–0137 surfaces | Consolidated product stack incl. Knowledge Graph token repair | +| #493 | `499c8b1b` | Name Event Lineage isolation reasons (v2.16.0) | Honest unavailable/failed states | + +### 3.2 SKOS organization aliases and leftover-map family (stacked) + +| PR | Head | Intent | +| ---: | --- | --- | +| #480 | `f18b421d` | Bind corroborated SKOS org aliases to one catalog row | +| #482 | `c38c08d6` | Corroborated SKOS companion caption on organization chips (v2.14.0) | +| #481 | `32944979` | Persist leftover interaction-map coordinates (v2.12.7) | +| #485 | `dcaa6320` | Leftover pair clicks land on the named Post quality criterion (v2.12.8) | +| #518 | `3117823f` | Name leftover complete-case coverage (v2.12.17) | +| #519 | `31c150c8` | Persist leftover-map axis share on period reports (v2.12.16) | +| #521 | `40677c75` | Leftover pairs on the grouping comparison strip (v2.12.17) | +| #522 | `9be3712e` | Leftover-map distances on two Gabriel axes (v2.12.18) | +| #535 | `1fb5d69a` | Name leftover-map unexplained leftover (v2.12.26) | +| #537 | `9a639554` | Name leftover-map unexplained share (v2.12.27) | +| #539 | `740629d0` | Name leftover-map explained share (v2.12.28) | +| #563 | `740d50f3` | Name leftover-map cross share (v2.12.29) | +| #564 | `ac5de72a` | Name leftover-map reconstruction share (v2.12.30) | + +The leftover-map naming series (#518–#564) is a stacked ladder of honest +leftover-pair labeling increments; merge in ascending order once each exact +head clears gates. + +### 3.3 Repairs and operability + +| PR | Head | Intent | +| ---: | --- | --- | +| #393 | `4ddd3a83` | Detach provider parse error context (honest orchestrator failure) | +| #394 | `cf9505b7` | Preserve source indentation evidence for adjudication | +| #434 | `01d6cca5` | Wire adjudication client into corpus-wide rebuild (issue #289) | +| #541 | `3d93ea9b` | Bootstrap repo-root sys.path in operator scripts | +| #546 | `d210c20c` | Strip Keycloak OIDC callback params from post share links | +| #547 | `fb7fe2db` | Shorten orchestrator healthcheck retry budget | +| #552 | `89000280` | Footer text contrast passes WCAG 1.4.3 AA | +| #553 | `e5152f5c` | `.post-meta` contrast in both themes | +| #554 | `689e42e4` | Event Lineage DAG node marks get a 24×24 px hit target | +| #556 | `21cf9991` | Citation chip grows to a 24px touch target | +| #558 | `91dd1bfc` | Bare loading text exposed as live regions | +| #560 | `59b769e3` | Secondary details/summary toggles sized to `--size-control-min` | + +### 3.4 Integration and measurement boundary + +| PR | Head | Intent | +| ---: | --- | --- | +| #417 | `cb08377c` | TEPP topic-lineage consumption boundary (TRSL-TM + CHRONOS/TDT) ADR | +| #468 | `228f13dd` | Bind fast-mlsirm, Keyverse, orchestrator, and TEPP integration tests | +| #258-family measurement note | — | GRM/GPCM/CAT/FIPC parameter recovery (#451–#454) landed earlier; true-parameter RMSE remains the acceptance bar | + +### 3.5 Documentation + +| PR | Intent | +| ---: | --- | +| #565 | Sync AGENTS.md / CLAUDE.md with accepted ADR boundaries | +| this file | Non-identifying gap baseline refresh (ADR 0001) | + +Closed as superseded during this loop: #368 (baseline rewrite superseded by +this file per §3.5 of the prior snapshot). + +## 4. Open issues (complete live queue; product acceptance remaining on `main`) + +| Issue | User-visible gap | Active PR | +| ---: | --- | --- | +| #79 | Milestone 2: port verified direct-PostgreSQL analysis into the protected architecture | analysis-run registry on `main`; remaining runtime bridge | +| #87 | Milestone 2.1 normalized runtime-analysis schema bridge | related analysis-run work | +| #269 | Authenticated Global Ask MCP browser-safe and admission-bounded | Ask stack | +| #271 | Evidence-honest knowledge-cutoff scope on Global Ask | #658; still open and not protected-main evidence | +| #272 | Verify Global Ask KG/ontology/semantic claims with public SearXNG evidence | #632 preserves internal provenance; public verification acceptance remains open | +| #277 | TEPP: persist accepted receipts, poll completed results, keep measurement authority distinct | #657 consumer lifecycle; executable producer route remains unavailable | +| #280 | Full project-lifecycle history and handover intervals | #640 adds case/project journeys and #663 adds evidence-backed Project exploration; authoritative lifecycle reconciliation remains #284 | +| #284 | Authoritative lifecycle ingestion and idempotent reconciliation | No active delivery PR confirmed | +| #338 | Evidence-bounded email/project lineage contract for Naruon consumption | #704 recreates the provider-side contract on current `main` without arbitrary fusion weights; #343 remains only a non-default-stack merge and #355 is a distinct calendar contract | +| #611 | Decompose closed PR #490 ADR 0133–0137 evidence without transferring stale branch state | #631 supplies the current-main inventory only; focused implementation PRs and tests for every unmet criterion are still required | + +## 5. Open product and technical gaps + +| Gap | Current evidence | Acceptance requirement | +| --- | --- | --- | +| Protected release | 12 open PRs at snapshot, all targeting `main` with normal auto-merge enabled. None has the required independent approval, and running checks on #631/#632/#663 are not treated as blockers for safe work on other PRs. #666's merge into the non-default #663 branch is not protected-main delivery | Terminal exact-head checks, no unresolved threads, two independent approvals including last-push approval, protected squash-merge SHA | +| CI queue release latency | Two Tests runs for already merged PRs occupied the available runner slots while 54 newer runs remained queued. Manual cancellation released the stale work, but the central close workflow was itself queued behind those runs. #634 merged into #631's non-default branch and reuses the repository's existing per-PR concurrency group so a jobless close event can cancel obsolete Tests work before runner allocation; this is not protected-main delivery | Merge #631 through its refreshed protected gate; close a synthetic PR while its Tests run is active and verify the old run becomes cancelled, the close-event jobs remain skipped, and a newer exact-head run starts without manual intervention | +| Evidence-grounded operations workspace | Protected-main #614 delivers governed semantic Ask, live Similar VOC, disjoint pending/failed analysis metrics, full Storybook state inventory, and current desktop/mobile screenshot evidence. Authorized-corpus backfill acceptance remains unavailable | Perform authenticated authorized-corpus acceptance with aggregate evidence and retain fail-closed no-match behavior | +| Shared frontend gate | The ADR 0109 login repair is on protected `main`; eight older branches carried the defect and received the same verified repair this loop (#521–#560) | Keep every future branch cut from post-repair bases; re-verify with frontend lint/test/build before push | +| Identifying baseline regression | `main` gap file listed real post identifiers; separately, closed #506 and pre-existing public history contain a private runtime source-table identifier, while current `main` and #507 trees are clean | Land this non-identifying rewrite, then coordinate ADR 0001 history remediation with security/privacy owners; do not reproduce the value, force-push, or delete evidence ad hoc | +| Authorized-corpus runtime | Repository tests use synthetic fixtures; private records remain outside git | Authenticated runtime validation returning only aggregate, non-identifying evidence | +| Concurrent web responsiveness | ADR 0204 releases pooled transactions during provider work, and the synthetic Compose boundary has an authenticated k6 E2E harness for Ask enqueue, concurrent reads, and job polling. PR #633's measured landing-query and event-loop work merged into open parent #629 rather than protected `main`; its aggregate observation improved 25-VU throughput but did not establish a latency SLO. The current exact #629 also persists each completed relation verification before propagating a later provider failure | Land #629 through its refreshed protected gate, rebuild that exact-head application image, and repeat `make load-http` with declared environment concurrency/window and retained raw distributions/resource configuration; set no SLO until representative capacity evidence is approved | +| Image understanding | Region, OCR, and description work exists across active heads (#405, #419), but current runtime acceptance has not yet proved table-image structure, complete region coverage, or summary/image readiness together | Orchestrator-backed rendered workflow, original/derived asset provenance, region-before-OCR processing, and honest unsupported states; reconcile ADR 0052's image-bearing summary readiness with ADR 0098 before changing sequencing | +| Semantic source rendering | Paragraph, table, list, formula, and indentation work exists across stacks (#394, #427, #448–#450); #515 adds synthetic backend/frontend parity for deterministic rows/cells, footnote boundaries, and encoded scripts | Land the #427 → #515 stack, then gather authenticated browser evidence that list nesting, continuation alignment, and formula units render without authoring-layout artifacts | +| Event and project semantics | #663 is the largest current user-visible gap slice: evidence-backed Project nodes, bounded traversal, cutoff/snapshot fencing, exact-value table parity, and localized graph labels. Focus visibility, label-bound, and temporal test-double regressions are repaired. #666's heuristic removal is composed into this parent but is not separately protected-main evidence. #640 separately adds project journeys without claiming authoritative lifecycle status | Combined #663 must pass exact-head checks and independent approval before protected merge. Aggregate authenticated evidence must still prove distinct projects/events and handover intervals without promoting co-occurrence | +| Voice primary history | Protected `main` `bbb19192` includes ADR 0252 / #761 (migration 0243, GiST primary-period exclusion, `clock_timestamp()` after the source-row lock, API/ontology half-open cutoff SQL). v2.22.1 adds synthetic PostgreSQL integration tests for A → B → A at before/between/after cutoffs, concurrent primary updates, additional-assignment close, and 0237→0243 trigger replay. This is not yet protected-main evidence | Land the live-test slice through the protected gate with independent exact-head APPROVE; close #748 only after that protected delivery | +| Knowledge Graph readability | #659 recreates the token-backed node-type repair on current `main`, including regression coverage; it is open and therefore not protected-main evidence | Merge #659 normally, then verify light/dark contrast, keyboard graph navigation, full labels, and evidence tables in the authenticated rendered surface | +| Source-code lookup UX | Source state/detail codes remain evidence-bearing machine values and current detail presentation is dense | Catalog-backed display labels with raw-code provenance, compact 5W1H/source-detail hierarchy, keyboard access, and no unsupported customer/project binding | +| Calendar / Naruon | #355 delivered the projection contract; v2.17.0 wires operator consumption without forwarding the end-user token. Naruon producer, provider/consumer fixtures, and protected merge remain open (#336) | Verify observed events against the published schema without invented events; keep commitments available when the channel is unwired | +| SKOS organization aliases | Catalog binding and chip caption live on #480 / #482 | One catalog row per corroborated org; companion caption is hint-only until bound | +| Event Lineage evidence | Channel evidence and Allen relations live on #387 / #484 | Persist channel scores, explain them in the popup, never invent a fused score | +| Scientific measurement | Durable accepted TEPP receipts and LineageWeave #614's exact accepted snapshot/cutoff/run/pair-count consumer are protected; TEPP #237 remains open, so no registered producer artifact exists yet. #387 removes inferred/default persistence weights, but several older reconstruction tests still pass hand-authored numeric dictionaries that are not estimator evidence | Land TEPP #237 through its protected gate, then replace remaining reconstruction-test constants with provenance-bearing fast-mlsirm estimates over synthetic fixtures. Retain true-parameter RMSE recovery as the acceptance bar | +| Asynchronous authorization | Protected `main` rebuilds Global Ask worker scope after the bearer token leaves the request; #468 now persists exact Keyverse organization/process-unit scope in 3NF child tables and intersects it with current affiliations | Land #468 through the protected gate; prove a second affiliation and a revoked process unit cannot widen delayed-job evidence | +| Planned-facility intent | Planned-facility relationship intent remains only on closed, unmerged #490; earlier stack-only merges were not protected delivery | Recreate the evidence-backed slice on a current base and land through protected `main` before a release claim | +| Accessibility and responsive UX | #602 delivered base post-detail modal semantics; #605 adds selected-post refocus, collapsed/hidden/inert/CSS-invisible focus exclusion across both modal types, readable evidence separators, focused tests, and desktop/mobile Storybook screenshots | Land #605 through the protected gate, then complete screen-reader and authenticated Playwright acceptance on the exact release head | +| Design tokens and repeated objects | Token extraction started; sanitized Figma Event Lineage desktop/mobile frames exist, while other repeated product surfaces remain incomplete | Tokens in CSS + Storybook stories for board, popup, DAG, Ask, calendar, forms, charts; same-viewport Figma/runtime visual comparison before release | +| Frontend delivery performance | #644 implements a native dynamic-import boundary for conditional workspace surfaces and retains accessible loading/error states; exact-head checks passed but the PR is not protected-main evidence | Merge #644 normally, rebuild the protected-main production bundle, and retain the measured chunk inventory rather than raising the warning limit | +| External integrations | Search, Zotero, calendar, Keyverse, orchestrator, RankWeave, ThreadWeave, TEPP, DiskSage, wardnet | Provider conformance, failure/reconciliation behavior, and provenance-bearing integration evidence | +| Naruon email/project lineage | #704 provides a strict store-agnostic v1 contract, opaque evidence references, observed/inferred truth separation, knowledge-cutoff admission, and explicit unavailable states. Inferred edges require an injected provenance-bearing fast-mlsirm estimate; no local default weight exists | Merge #704 through protected `main`, publish an immutable attested artifact, then enable the Naruon consumer only against that released version and its contract fixtures | +| MSA / modular reuse | LineageWeave must run standalone and as a consumer of org packages | Do not reimplement RankWeave/TEPP/orchestrator/ThreadWeave/Keyverse; fix upstream and PR there | +| Accelerator runtime ownership | ADR 0076/0208 already prohibit local model and mathematical ownership; ADR 0237 now defines MLX as a native orchestrator-side service and TEPP/fast-mlsirm CUDA/OpenCL/CPU profiles as scientific-compute-owner deployments, so LineageWeave Compose remains device-neutral. RankWeave remains the dependency-free Python retrieval-fusion/evaluation owner behind its published contract | TEPP and fast-mlsirm must publish deterministic CPU recovery plus conformance evidence for every advertised CUDA/OpenCL profile; contextual-orchestrator must prove native MLX availability through its provider-neutral health/contract boundary. LineageWeave accepts only versioned, provenance-bearing envelopes and fails closed when the owner is unavailable | +| Product contract authority | The current LineageWeave PRD records exact-case ecosystem authorities. TEPP, fast-mlsirm, keyverse, ThreadWeave, and RankWeave PR #41 have standalone PRDs; RankWeave's remains unmerged. contextual-orchestrator, disksage, and wardnet still rely on product/architecture documents, and naruon has only a scoped Topic Intelligence PRD | Keep ADRs normative, preserve canonical repository case in machine references, land the pending PRDs, and add standalone PRDs in each remaining owning repository before cross-product release claims exceed its documented boundary | +| Release quality | PR #660 is now on protected `main`; its pre-merge full Python suite passed 1,352 tests with 17 skips, but release-wide frontend, Storybook, security, browser, and runtime acceptance remain unproven on one exact protected head | Repository-wide coverage, docstrings, Storybook, security, browser, and release evidence on one exact head | +| PII | Masking would paralyze the product; ADR 0001 forbids identifying artifacts in git | ABAC + authorized runtime; synthetic fixtures in git; no mask-in-place that drops names the operator must read | +| Database | PostgreSQL, 3NF, snake_case ≥ two words, hot-partition and lock policy | No file DBs; read/write split if lock management fails; whitelist every migration | + +### 5.1 Closed PR #490 decomposition (issue #611) + +Protected `main` at `04e6b610` and the three open PRs present during the initial +decomposition were rechecked; the later audit snapshot above includes #631 +itself as the fourth open PR. Protected `main` contains none of PR #490. That PR remains +closed, unmerged branch evidence; its ADR 0133–0137 files are not normative and +its 321-file tree must not be replayed. Current-main code and schema searches +give this delivery matrix: + +| Closed-branch decision | Current-main classification | Smallest remaining delivery | +| --- | --- | --- | +| ADR 0133 source-reference research | Partial foundation: protected `main` has the self-hosted SearXNG relation-verification client and fail-closed configuration, but it verifies an already extracted relation. It has no source-unit/image-region lead, cited-resource retrieval, claim judgment, or normalized research citation workflow | One post-scoped lead-to-citation slice that reuses the self-hosted SearXNG search boundary, adds public-target SSRF/redirect rejection for result retrieval, and judges through contextual-orchestrator with explicit unavailable outcomes | +| ADR 0134 token-backed exception messages | Partial: sanitized next-action failures exist, but no shared token-backed exception component or complete Storybook error inventory exists | Migrate one existing unavailable flow to one shared accessible alert and verify its success, unavailable, and retry states | +| ADR 0135 kind/status-exact analysis actions | Partial: protected `main` has kind-aware start/retry controls plus normative analysis-run, TEPP, cutoff-body, and channel-evidence contracts; it does not contain the closed branch's unified guidance component or its full kind × status interaction inventory | Test the current run-kind/status matrix first, then add only a proven missing state/control pair rather than copying the closed-branch function | +| ADR 0136 per-post Ask history | Partial: `post_chat_result` / `post_chat_citation`, the authorized post Chat API, and its linear exchange history are on protected `main`. Account-and-post-scoped sessions, ordered turns, list/select/new controls, and batched citation reauthorization are not | Define the 3NF account/post session boundary, bounded batch reauthorization, and one authorized list/load/write path before adding the conversation picker | +| ADR 0137 cross-post customer identity | Partial foundation: protected `main` preserves source customer hints and has corporate-catalog unique/miss/tie safeguards, but it has no normalized cross-post customer-identity judgment, supporting-post binding, or corporate-name-history workflow | Add only after external corroboration, orchestrator judgment, TEPP ordering, and unique-catalog fail-close can be verified together; never promote a one-post hint | + +This matrix satisfies only #611's current-main inventory step. Issue #611 +remains open: every unmet criterion above still needs a focused regression test +and exact-head current-main implementation PR before its acceptance criteria +are satisfied. No stale check, review, or implementation is transferred from +#490. + +## 6. UI-UX acceptance inventory (must be defined, reviewed, applied, audited) + +Each item needs a Storybook scene, an edge-case story, and an automated check +before a commercial release claim. Figma File ID `1Su3lDRmiZdcUs47t1QwIX`. + +| Dimension | Current | Gap | +| --- | --- | --- | +| Accessibility | Partial labels/roles on board, popup, login | WCAG 2.2 AA on login, board, popup, Ask, calendar, admin; focus order; live regions | +| Touch & Interaction | Click-first popup and lists | 44px targets, swipe/escape to dismiss popup, no hover-only actions | +| Performance | Board caps and hint render limits exist | Interaction-to-next-paint on board search, DAG, Ask; no N+1 (#358) | +| Style Selection | Korean UI standards merged (#347) | Tokenized light/dark; Anti-Slop-UI density; no decorative noise | +| Layout & Responsive | Desktop popup shell | 402px-class phone layout; stacked GNB; readable DAG | +| Typography & Color | Badge tokens extracted | Contrast on badges, links, error/status; no raw hex in components | +| Animation | Minimal | Reduced-motion; no blocking animation on evidence open | +| Forms & Feedback | Login, Ask, tickets, admin brand | Inline validation, next-action copy, unavailable vs failed distinction | +| Navigation Patterns | Board / customers / calendar / Ask / admin | Deep-link post + OIDC return URL (#426); bookmarkable Ask | +| Charts & Data | Period reports, leftover pairs, Rankings, DAG | Honest empty/unavailable; no invented theta; Storybook chart states | + +## 7. Ecosystem leverage order + +Reuse before rebuild. Consume these ContextualWisdomLab packages in this order +of leverage; open connector PRs there when the defect is upstream: + +1. **contextual-orchestrator** — every LLM/VISION/embedding call (Fugu / Conductor / TRINITY routing). Never a raw provider SDK. +2. **Keyverse** — OIDC issuer, JWKS, tenant principals. +3. **RankWeave** — fused scores and rankings; never invent a fused score or theta. +4. **TEPP** — calibrated measurement; persist receipts; no local reimplementation. +5. **fast-mlsirm** — GRM/GPCM/CAT/FIPC recovery tests (#451–#454) must stay true-parameter RMSE. +6. **ThreadWeave** — tree assembly. +7. **Naruon** — calendar and email/project lineage projection (#336, #338, #355). +8. **DiskSage / wardnet** — storage and network policy as needed. +9. **ContextualWisdomLab/.github** — required review workflows (OpenCode, Strix, Noema) and the LineageWeave hourly caller (#1259). If stacked PRs miss central review or coverage-evidence fails on pnpm 9 (`--trust-lockfile` is pnpm 11.3) or a missing Vitest coverage provider, fix the org workflow (#1258), not a local bypass. + +## 8. Public ontology publication boundary + +- PR #426 publishes fragment-addressable HTML, byte-identical Turtle, + isomorphic JSON-LD and N-Triples, the PROV-O support profile, and a + source-digest manifest from the authoritative ontology. +- Pull requests validate only. Only protected `main` may publish, and the + generated-directory marker, linked-IRI, duplicate-fragment, symlink, and + source-overlap checks fail closed. +- The lowercase knowledge-graph namespace and repository-case support-profile + namespace remain distinct until issue #372 delivers a versioned migration + and compatibility decision; this publication PR rewrites neither identity. +- Until the protected deployment and exact URL checks succeed, the public + ontology endpoint remains unavailable and must not be represented as live. + +## 9. Evidence boundaries + +- Never add a real record, title, name, identifier, screenshot, log, benchmark + artifact, or documentation example to this repository. +- Attendance or co-occurrence is not responsibility, project, customer, or + affiliation evidence. Preserve uncertainty and provenance. +- Missing transport, model capability, accepted envelope, or persistence is + unavailable or failed evidence, never a placeholder result. +- Local green tests, bot statuses, auto-merge, and warning-only checks do not + prove a protected merge. +- Re-fetch base/head SHAs, checks, review threads, approvals, rulesets, and the + merge SHA immediately before any lifecycle claim. +- Do not self-approve. Independent OpenCode / Strix / Noema review is required. +- Do not force-push. Do not treat GitHub Checks duration as a blocker; repair + the failing check instead. +- `COPILOT_GITHUB_TOKEN` is not used. + +## 10. Next acceptance loop (autonomous merge order) + +Process every open PR in ascending number order, considering leverage; for +each: check reviews → repair → re-verify Checks → merge → continue. Checks and +review latency are never blockers — keep working while they settle. + +1. Revalidate Strix after merged ContextualWisdomLab/.github#1320, reconcile + open .github#1263, and land the atomic hourly LineageWeave caller in open + .github#1288 only through their protected gates. +2. Process main-targeted PRs #629, #631, #632, #639, #640, #643, #644, #657, + #658, #659, #660, and #663 only after each exact head shows terminal green + required checks plus current-head independent approval. Treat #666's + non-default-branch merge only as part of #663's combined candidate and + collect all protected evidence on #663's exact head. +3. While hosted checks or independent reviews wait, resume user-visible gaps + from §5 in leverage order: + external semantic verification (#272), Naruon calendar (#355/#336), and + authenticated operations/ontology publication acceptance. Event Lineage + evidence shipped in merged PR #387 and closed issue #274 is not an open gap. +4. Rename remaining `[Buyer Gap]` issue titles to neutral product-object + naming per repository convention (no "Buyer" for internal objects). +5. Keep psychometric tests as true-parameter recovery (RMSE); never fixture + tautologies, invented theta, or hand-authored numeric weights. Remove + weights from tests that do not exercise fusion; fusion tests must consume + provenance-bearing fast-mlsirm estimates over synthetic fixtures. +6. Run frontend lint/test/build/Storybook, backend tests, and authenticated + browser/accessibility checks on the exact candidate release head. +7. Fix only evidence-backed failures and repeat the protected merge gate. +8. Refresh this file each loop with the exact queue state. + +## 11. Spec pointers (derive, do not fork) + +- Product/architecture: `ARCHITECTURE.md`, `AGENTS.md`, `CLAUDE.md` +- Research grounding: ADR 0084, `docs/lineage-bi-research-notes.md` +- Demo identity: ADR 0001 +- Figma boundary: ADR 0002 (File ID `1Su3lDRmiZdcUs47t1QwIX`) +- Orchestrator / paper-grounded models: ADR 0015, ADR 0076 (Fugu, TRINITY, Conductor) +- Ontology / PROV-O / SKOS: ADR 0004, ADR 0011, issue #372 +- Analysis runs / TEPP: ADR 0013–0023, issue #79 / #277 +- Calendar / Naruon: issues #336 / #338, PR #355, operator consumption v2.17.0 +- Ask Agent: issues #269–#272, #358–#363 + +Citations in doctoring and ADRs use APA 7th. Do not invent a heuristic where +the papers leave the decision undecided. + +## 12. Delivery snapshot (2026-08-27) + +Fresh merges on protected `main`, verified from PR lifecycle state and +post-merge reruns (not transferable evidence for later heads): + +| PR | Delivery | Governing ADR / reference | +| ---: | --- | --- | +| #643 | Shared StatusNotice (ADR 0220): success/unavailable/retry states, WorkspaceCalendar auth-unavailable copy, 5-locale i18n; CI Full suite 22m54s green | ADR 0220 | +| #644 | Native workspace surface split: 9 conditionally rendered components as lazy() dynamic imports behind a SurfaceBoundary error boundary; build emits 9 chunks (1.5-37 kB), main bundle 543 kB; 470 frontend tests, tsc, Storybook green | — | +| #762 | Evidence-bound project history (ADR 0243): /api/projects/{key}/history endpoint, project_history.py projection, fetchProjectHistory client, standalone ProjectHistoryTimeline component; supersedes #668 (3-way merge kept only the additive +2279/-0, dropping the branch's 8k shared-file reverts; popup UI hookup deferred as a scoped follow-up) | ADR 0243 | +| #763 | Live-PostgreSQL A→B→A Voice history validation (ADR 0252) proving effective_from/effective_to interval replacement across repeated primary-Voice imports | ADR 0252 | +| #764 | Test-only coverage lift: observability 78%→96%, post_summary 77%→89%, claim_verification 86%→99%; package line coverage 93.5%→95% (484→371 missing); 1651 Python tests green | — | +| #761 | Temporal imported-primary Voice history (ADR 0252): migration 0243 (`effective_to` + GiST primary-period exclusion + synchronize trigger), refined 0237 `least()` effective_from backfill, `effective_from/effective_to` dataclass/export + `coalesce($2,$3)` cutoff predicate. Completes the half-shipped main layer that queried `voice.effective_to` against a missing column. CI Full suite 19m13s green | ADR 0252 | +| #629 | Provider work released before embedding pool bound; landing reads bounded (k6-verified concurrency); merged with strix-only infra timeout (Full suite + all other gates green) | — | +| #750 | Leftover-map unexplained leftover share persisted (`report_leftover_map_unexplained_share`, share `s = U² / R²`) | ADR 0233 | +| #749 | Authorized job-family/job-series import snapshots (`0223_authorized_job_architecture`) | ADR 0263 | +| #759 | ***Promoted** the ONET rating-store stack to `main`: migrations 0222/0223, authenticated rating/rating-sources/rating-occupations endpoints, `OccupationRatingProfile` UI + stories, rating client functions, import scripts, ADR 0252–0263 references. Semgrep SQLi nullified by PL/pgSQL `format(%I/%L)` DDL + documented `nosemgrep`; 1583 Python + 447 frontend tests green | ADR 0257–0263 | +| #747 | Current product and MCP manuals (`docs/manuals/*`, contract tests) | ADR 0118-family | +| #754 | Customer-actionable copy and ADR 0237 accelerator runtime boundary; share/bookmark/verification call sites reworded and ko/zh/ja/vi translations completed after review | ADR 0237 | +| #700 | Source conversation-turn evidence ingestion (`0233_source_conversation_turn_evidence`, choke/adjacency resilience) | ADR 0238 | +| #658 | Optional Global Ask knowledge cutoff honoring `source_post_revision` cover | ADR 0216 | +| #632 | Graph-fact source provenance preserved through MCP streaming + verified psql-parity migration fixture | ADR 0166 | +| #742 | Evidence-bound product-operations relations (stack base) | ADR 0235 | +| #743 | Imported occupation-rating source catalog (stack base) | ADR 0260 | +| #745 | Occupation catalog title filter (stack base) | ADR 0262 | +| #746 | Rating-source occupation selector (stack base) | ADR 0261 | +| #740 | Occupation rating evidence view (stack base) | ADR 0259 | +| #720 | Cancel stale test runs on PR close | — | +| #716 | Prioritized evidence-bound operations backfill | — | +| #711 | Pinned validated structured-workflow runtime | — | +| #704 | Current-main external lineage contract publication | — | + +The ONET rows stacked into base branches (#743/#745/#746/#740/#732) reached +`main` together through the #759 promotion; their per-base merge records are +historical evidence only. The job-architecture artifact ship originally via +#749 is now re-verified on `main` from the promotion. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 2d5abe565..ef583a23b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,1276 +1,73 @@ # Product & Technical Gap Baseline - -> Live-authority overlay: 2026-09-13 20:27 KST. Protected `main` remains -> `83eba56149eb802cd63642c507c324c9976ec78e`, protected with a valid verified -> commit signature after two fresh sweeps. No protected-main merge or base movement -> occurred during this maintenance turn. -> -> Customer Master ownership issue #1052 / PR #1055 remains exact -> `50c4935eef1029467595f7004818643598b737c9`. Repository Tests `34746058653` -> (including full PostgreSQL), Security `34746058657`, and SAST `34746058639` -> are terminal GREEN. Required CodeQL `34746058693`, OpenCode `34746057593`, -> and Noema `34746057619` remain terminal failures at canonical `.github` / -> contextual-orchestrator owner boundaries. Strix `34746057545` / job -> `103694153476` remains genuinely `in_progress` at `Run Strix (quick)` on the -> unchanged head; elapsed time alone is not grounds to cancel it. #1055 therefore -> remains Ready only to preserve exact-head evidence and is not merge-ready. -> -> Fresh catalog-owner review identified buyer-path resilience gap #1077. The -> canonical `get_or_create_corporate_entity` correctly defers its explicit -> transaction and `pg_advisory_xact_lock` until after provider work, but existing -> Keyman/post-summary/Customer Master callers can retain a borrowed asyncpg -> connection across hierarchy inference/search corroboration. The process pool is -> bounded at `max_size=10`, so concurrent catalog misses can starve unrelated DB -> requests without any explicit DB lock. #1077 owns the causal contract: short -> candidate/alias snapshot lease, release before provider I/O, then a fresh -> under-lock catalog recheck/write with cancellation/error cleanup. It remains in -> the corporate-entity catalog bounded context and must not duplicate CO routing. -> -> The leftover-map comparison lineage suffix has also converged onto repaired #859. -> #859 exact `2550e8d88339e30297fa0aa19ffae77f9b78b73b` fixes the eight stale -> comparison-only distance cases (16 assertions) without changing production or -> report-mode semantics. The live serialized ancestry is #860 `ef29a5a9...` -> -> #861 `49973434...` -> #862 `382947ba...` -> #863 `4e8720e9...` -> #865 -> `dec97059...` -> #866 `198d6827...` -> #867 `3e338bc3...` -> #868 -> `8af935c0...` -> #869 `74bd9468...` -> #870 `d063bd97...` -> #871 -> `645a5b09...` -> #872 `57206ce8...` -> #873 `b25b3874...` -> #874 -> `ac531c41...` -> #875 `c2278234...`, with forks #876 `259e2d1a...` and -> #877 `677643a4...`; reconstructed successors #1033 `6db5cb71...` -> #1034 -> `5015f193...` preserve valid #878/#879 intent. PR bodies for this suffix were -> corrected to the live base/head authority and no longer claim #859's repaired -> consumer-test RED is still active. All remain Draft because current validation / -> local intentional REDs are unresolved; no ancestor receipt transfers. -> -> #1057 remains the separate hosted PostgreSQL + Keycloak + Valkey authenticated -> bearer/JWKS/RBAC/ABAC topology owner. Draft #961 remains the runtime-version -> source repair and #1056 retains immutable release/SBOM/provenance/ -> reproducibility/rollback acceptance. No release is admitted by this overlay. -> Older overlays below are dated evidence only. - - -> Live-authority overlay: 2026-09-13 16:54 KST. Protected `main` remains -> `83eba56149eb802cd63642c507c324c9976ec78e` pending final double sweep. -> Customer Master ownership issue #1052 / PR #1055 is on exact -> `50c4935eef1029467595f7004818643598b737c9`, Ready only for validation -> admission. Predecessor `8448a2b4e06c6ef415dd98b3eaa1f7f36669fe94` -> exposed a real repository RED after shared eligibility SQL qualification: -> Tests `34743575403` ended `2 failed, 1777 passed, 147 skipped`. The two -> failures were the corroborated-association/reused-catalog unit tests. Their -> fake query recognizers still expected old unqualified capture/revalidation -> SQL, so they returned no evidence after production queries were correctly -> qualified with `source_post.*`; the scope-change test also stopped reaching -> its intended revalidation phase. -> -> Causal commit `50c4935e...` changes only those unit-fake recognizers to the -> canonical qualified SQL. Production authorization, persistence, locking, -> provider/model selection and workflow gates are unchanged. Fresh exact-head -> validation materialized without no-op churn. Frontend lint/test/build/ -> Storybook, Security `34746058657`, and SAST `34746058639` are GREEN. Full -> PostgreSQL Tests `34746058653`, Required CodeQL `34746058693`, Noema -> `34746057619`, and Strix `34746057545` were still live at this snapshot; -> Required OpenCode `34746057593` is terminal FAILURE. No predecessor review -> receipt transfers, and #1055 is not merge-ready. -> -> #1057 remains the separate PostgreSQL + Keycloak + Valkey bearer/JWKS/RBAC/ -> ABAC hosted-topology owner. Central workflow repair remains `.github#1929/ -> #2106` for CodeQL producer/consumer settlement and `.github#2045/#2109` for -> Ready-transition/model-review reconciliation; LineageWeave does not copy -> those owner implementations. Draft #961 remains the package/runtime-version -> source repair and #1056 carries immutable release/SBOM/provenance/ -> reproducibility/rollback acceptance. Protected main still has package/ -> frontend `2.28.0` versus runtime `2.20.0` until normal integration. No -> release is admitted by this overlay. Older overlays below are dated evidence only. - - -> Live-authority overlay: 2026-09-13 15:24 KST. Protected `main` remains -> `83eba56149eb802cd63642c507c324c9976ec78e` pending final double sweep. -> Customer Master ownership issue #1052 / Draft PR #1055 is now at exact -> `831fc52a1969f2999109da2c061067a9dc0ae954`. Bounded repair run -> `34741807255 / 103682639248` reproduced the ordinary-hosted response-contract -> RED, applied the minimal serializer/E2E expectation repair, obtained focused -> GREEN, and published a self-cleaning ordinary commit. The current head adds -> `tests/test_customer_master_hint_response_contract.py`, updates the real-service -> `backend/tests/test_api.py` expectation, and contains no temporary repair workflow. -> All #1055 inline review threads are resolved. -> -> Current-head central workflow identities are Draft lifecycle `action_required`, -> not GREEN receipts. Immediate parent `b9346dc681997a0274194d2ed913a22bb7488cca` -> has SAST/Security/dynamic-CodeQL/Code-Quality/OpenCode/Strix success; Required -> CodeQL remains the canonical `.github#1929` ordering/reconciliation failure, and -> predecessor Noema evidence cannot authorize `831fc52...`. `.github#2045` remains -> open for unchanged-head Draft-to-Ready materialization, so no empty commit or -> lifecycle-flip loop is used to manufacture current-head evidence. -> -> Issue #1057 still owns the hosted PostgreSQL + local Keycloak development fixture -> + Valkey bearer/JWKS/RBAC/ABAC lane. Its original #1055 response-shape canary is -> repaired, but the service-wide-skip topology defect remains. #1042/#1054/#1047/ -> #1049/#1046 remain Draft under their own live authority. Protected-main release -> identity source repair is existing Draft PR #961 at exact -> `3bdec0504a65e63f44bd49ba15de37182a1672cc`; issue #1056 now converges release, -> SBOM, provenance, reproducibility and rollback acceptance onto that single writer -> rather than spawning a competing lane. Protected main itself still reports -> `pyproject.toml` 2.28.0 versus runtime `lineageweave.__version__` 2.20.0 until -> normal integration. OpenTelemetry and PostgreSQL warning owners remain #1036/#973 -> and #1038/#1040. No release is admitted by this overlay. Older overlays below are -> dated evidence only. - - -> Live-authority overlay: 2026-09-13 12:11 KST. Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`; -> inventory is 159 open PR / 36 open issue. -> Customer Master ownership repair #1055 is Ready validation admission at exact -> `08a08108a87657ad427a6b6fa9b1b327166b0c9e`. Current repair separates source-post corporate/process -> authorization ownership from corroborated customer identity and delegates corporate -> catalog binding to the accepted `get_or_create_corporate_entity` owner (ADR 0010, -> ADR 0012, ADR 0160) instead of a Customer Master-local display-name lookup/direct -> insert. Source authorization locks are reacquired only for the short exact-source -> revalidation/persistence transaction after external corroboration/catalog resolution. -> Validation evidence from predecessor heads does not transfer across this head. -> -> #1042, #1054, #1047, #1049 and #1046 remain repair prerequisites/Draft unless -> their own live PR authority says otherwise. #1042's Medium CWE-862 period-report -> aggregate disclosure remains owned by #1050/#1054, not duplicated into Customer -> Master relationship code. Canonical central workflow defects remain `.github#1929` -> (required CodeQL producer/consumer ordering) and `.github#2045` (unchanged-head -> Ready reconciliation). Protected-main release metadata is still blocked by the -> tracked `pyproject.toml` 2.28.0 versus `lineageweave.__version__` 2.20.0 mismatch; -> no release is admitted from this overlay. Older overlays below are dated evidence. - - -> Exact-head loop overlay: 2026-09-13 11:55 KST. Protected `main` is still -> `83eba56149eb802cd63642c507c324c9976ec78e`. Customer Master customer-hint -> ownership repair #1055 now has final causal head -> `b26e5391d087e2e9610a8c0d52eaeb68f1f912a7`. Predecessor `7dbd1333...` -> completed repository/full-PostgreSQL Tests, Security, SAST, dynamic CodeQL, -> Noema and Strix successfully but remained blocked by Required CodeQL/OpenCode; -> it returned to Draft before further changes, and those receipts do not transfer. -> -> Three ordinary non-force follow-ups close the remaining docstring/test-contract -> acceptance without changing Customer Master production semantics: focused unit -> helpers now have meaningful docstrings and assert the exact association INSERT -> tuple, the live PostgreSQL ownership proof is documented, and -> `tests/test_customer_hint_docstring_contract.py` AST-enforces docstrings on every -> production function owned/touched by this repair. #1055 is Ready only as exact-head -> validation admission. The causal `b26e5391...` push materialized ten fresh lanes, -> including repository Tests/Security/SAST/CodeQL, dynamic CodeQL/Code Quality, -> Required scheduler, Strix, OpenCode and Noema; they are currently queued/running. -> No predecessor GREEN or approval counts toward promotion. -> -> #1042, #1054, #1047, #1049 and #1046 remain Draft. #1042's real Medium CWE-862 -> period-report aggregate finding remains owned by #1050/#1054 rather than duplicated -> into Customer Master relationship-network code. Canonical central workflow defects -> remain `.github#1929` (CodeQL producer/consumer ordering) and `.github#2045` -> (unchanged-head Ready reconciliation). Protected-main release metadata remains -> inconsistent (`pyproject.toml` 2.28.0 versus `lineageweave.__version__` 2.20.0), -> so no release is admitted. PR #1041 remains Draft; older overlays are dated evidence. - -> Exact-head loop overlay: 2026-09-13 11:00 KST. Protected `main` remains -> `83eba56149eb802cd63642c507c324c9976ec78e`. Customer Master process-unit -> repair #1042 is now Draft at exact -> `f23f5a567bd66113603837f86f030c3c459e69e6`: Strix `34721720240` -> terminalized FAILURE after setup and scan execution. Immutable artifact -> `10309695301` (95,509 bytes, -> `sha256:47822709dfdc45968569dbd4adf6bde167ba5eb46277503e906ee9625262d8b8`) -> contains one real Medium CWE-862 finding: mixed-visibility project/thread/team -> period-report endpoints could disclose full-population stored aggregates when -> at least one contributor remained visible. That defect is already isolated in -> #1050/#1054; #1054 is the security prerequisite and report authorization is not -> duplicated into #1042. Future #1042 integration requires a non-force descendant -> restack/reconstruction after that prerequisite lands. -> -> Customer-hint ownership repair #1055 is on exact -> `7dbd133320d8b12bde394569955e0ae6503f8f39`. Predecessor repository validation -> reached 1771 passed / 147 skipped and then exposed two owned REDs: migration -> 0250 was not replay-safe and the static SQL-review ledger still expected 36 -> suppressions after the repair legitimately removed one. Exact head now uses -> `CREATE TABLE IF NOT EXISTS` / `CREATE INDEX IF NOT EXISTS` and tracks 35 -> reviewed suppressions. Security `34731558854`, SAST `34731558875`, dynamic -> GitHub CodeQL `34731558343`, and Code Quality `34731558308` are GREEN. -> Repository Tests `34731586226`, Required Noema `34731558900`, and Strix -> `34731558917` are still live. Required CodeQL `34731558861` failed because -> compatibility consumers terminalized before the producer dispatch later -> succeeded; canonical owner `.github#1929` carries the unchanged-head canary. -> Required OpenCode `34731558957` failed closed without a current-head verdict. -> #1055 is Ready only as a live validation admission, not a merge-ready claim. -> -> #1054 remains Draft at `4519c101f13e08c10653b95ff88d66b4ce47f0b8` with -> repository Tests GREEN and central unchanged-head workflow reconciliation owned -> by `.github#2045`. Protected-main release metadata remains inconsistent: -> `pyproject.toml` declares 2.28.0 while `lineageweave.__version__` declares 2.20.0. -> No release is admitted while that blocker or any current required gate remains. -> PR #1041 remains Draft; every older overlay below is dated evidence only. - - -> Exact-head loop overlay: 2026-09-13 10:14 KST. Protected `main` remains -> `83eba56149eb802cd63642c507c324c9976ec78e`, protected with a valid verified -> commit signature. Fresh non-Draft inventory contains exactly #1042 and #1055; -> both are validation admissions only, not merge-ready claims. -> -> Customer Master process-unit repair #1042 remains at exact -> `f23f5a567bd66113603837f86f030c3c459e69e6`. Repository Tests/Security/SAST -> are terminal GREEN while Required CodeQL/OpenCode/Noema are terminal FAILURE. -> Strix `34721720240` is still genuinely in progress on the unchanged head, so -> elapsed time alone is not used to cancel it. If that lane terminalizes while -> authoritative failures remain, #1042 returns to Draft. -> -> Customer-hint ownership issue #1052 / PR #1055 advanced after review to exact -> `e11ff8698f20afc4ac628a6a86611ad1348c3fcb`. Migration 0250 and Proposed ADR -> 0374 keep `source_post.corporate_entity_id` / `process_unit_id` as access -> ownership and persist resolved customer identity in -> `source_post_customer_resolution`. Request identity is whitespace-normalized -> for matching and corroboration while the association preserves the actual raw -> `source_post.source_customer_code`. External resolution still runs with the DB -> resource released; a short persistence transaction then revalidates and -> `FOR SHARE` locks the exact captured source set before writing the association. -> Customer Master now selects resolved id/name/status/evidence coherently from one -> deterministic newest resolution row rather than independent aggregate maxima. -> The bearer + PostgreSQL regression also excludes foreign same-hint evidence, -> preserves source ownership and raw spaced hints, rejects blank HTTP hints, and -> checks coherent newest-resolution metadata. The four validated CodeRabbit -> findings are repaired and their outdated threads resolved. -> -> #1055 was marked Ready on the unchanged exact head only to admit fresh -> validation. Repository Tests `34730379137` rematerialized; frontend -> lint/test/build/Storybook is GREEN and the PostgreSQL job is still active. -> Draft-time Security `34730262196`, SAST `34730262117`, and Required CodeQL -> `34730262172` are `action_required`; no fresh central Security/SAST/Required -> CodeQL/OpenCode/Noema/Strix identity appeared at the first Ready reconciliation -> read. Canonical owner `.github#2045` now carries this unchanged-head canary. -> Do not use a no-op commit, Draft/Ready oscillation, or synthetic status to -> manufacture promotion evidence. -> -> #1054, #1047, #1046 and #1049 remain Draft. Protected-main release metadata -> remains inconsistent (`pyproject.toml` 2.28.0 versus -> `lineageweave.__version__` 2.20.0), so release remains blocked. PR #1041 stays -> Draft; every older overlay below is dated evidence only. - - -> Exact-head loop overlay: 2026-09-13 09:46 KST. Protected `main` remains -> `83eba56149eb802cd63642c507c324c9976ec78e`. Fresh live inventory reports -> 159 open PRs and 36 open issues. Exactly two open PRs are non-Draft, #1042 -> and #1055; both are Ready only to preserve or obtain exact-head validation, -> not as merge-ready claims. -> -> Customer Master process-unit repair #1042 remains on exact -> `f23f5a567bd66113603837f86f030c3c459e69e6`. Repository Tests/Security/SAST -> are terminal GREEN and Required CodeQL/OpenCode/Noema are terminal FAILURE. -> Strix `34721720240` remains genuinely in progress on the unchanged head, so -> elapsed time alone is not used to cancel it. If that lane terminalizes while -> required failures remain, #1042 returns to Draft. -> -> Customer Master customer-hint ownership issue #1052 now has repair PR #1055 -> at exact `77e7c8bd8bacb8f0ce30dd9e5ddd71c30a7632da`. Migration 0250 and Proposed -> ADR 0374 introduce normalized `source_post_customer_resolution`; hint -> corroboration captures only caller-visible eligible evidence, releases its DB -> resource before external resolution/verification, then reacquires a short -> transaction and `FOR SHARE` revalidates the exact captured sources before an -> idempotent association write. `source_post.corporate_entity_id` and -> `process_unit_id` remain authorization ownership and are never rebound to the -> resolved customer. Customer Master read models consume the normalized -> association only after source-post ABAC. A live PostgreSQL regression covers -> two private tenants sharing one synthetic hint and requires that only the -> authorized tenant's source receives the resolution association while both -> source ownership tuples remain unchanged. -> -> On #1055, fresh repository Tests `34729447666` rematerialized after Ready; -> frontend lint/test/build/Storybook is GREEN and the full PostgreSQL suite is -> still running. Draft-time central Security `34729440550`, SAST `34729440465`, -> and Required CodeQL `34729440480` remain `action_required` and did not obtain -> fresh identities on the unchanged Ready head. Canonical Ready reconciliation -> owner `.github#2045` has this canary; no no-op commit, lifecycle flip loop, or -> manual success status is used. Authenticated HTTP/E2E cross-tenant evidence, -> central security/model gates and independent current-head approval are still -> required before integration. -> -> #1054, #1047, #1046 and #1049 remain Draft. #1053 still owns Post Chat -> read-derived compute versus shared-persistence mutation authority and must not -> duplicate #1044/#1047 replay-disclosure ownership. Protected-main release -> metadata remains inconsistent (`pyproject.toml` 2.28.0 versus -> `lineageweave.__version__` 2.20.0), so protected release remains blocked. -> PR #1041 remains Draft; every older overlay below is dated evidence only. - -> Exact-head loop overlay: 2026-09-13 08:51 KST. Protected `main` remains -> `83eba56149eb802cd63642c507c324c9976ec78e` (v2.28.0; #931). Fresh live -> search reports 158 open PRs and 36 open issues. Exactly one open PR is -> non-Draft: #1042, whose Ready state is validation admission only. -> -> Customer Master process-unit authorization remains issue #1045 / PR #1042 -> at exact `f23f5a567bd66113603837f86f030c3c459e69e6`. Repository Tests -> `34721721155`, Security `34721721167`, and SAST `34721721186` are terminal -> GREEN. Required CodeQL `34721721113`, OpenCode `34721720227`, and Noema -> `34721720347` are terminal FAILURE. Strix `34721720240` is still genuinely -> in progress on the same exact head, so the admission is preserved without -> elapsed-time cancellation or source churn. The later CodeQL producer dispatch -> succeeded only after compatibility consumers had already failed; canonical -> owner repair remains `.github#1929` and predecessor receipts do not transfer. -> -> Mixed-visibility period-report authorization remains issue #1050 / Draft PR -> #1054 at exact `4519c101f13e08c10653b95ff88d66b4ce47f0b8`. Whole-population -> admission now suppresses a precomputed report aggregate when any persisted -> member or leftover-pair contributor is not visible; comparison evidence carries -> `process_unit_id`, and authenticated Keycloak + PostgreSQL regression proves -> detail/list/comparison visible before scope contraction and suppressed after a -> contributor becomes foreign-private. Repository Tests `34723167232` is terminal -> GREEN, including the full PostgreSQL suite, and dynamic GitHub CodeQL reports no -> new alerts. Draft-push central Security `34723086654`, SAST `34723086683`, and -> Required CodeQL `34723086691` stayed `action_required`; after Ready only the -> repository Tests identity rematerialized. With no live validation lane left, -> #1054 returned to Draft on the unchanged head. Canonical lifecycle repair is -> `.github#2045`; do not use empty commits, Draft/Ready oscillation, manual status, -> or leaf-side gate weakening. -> -> Persisted Post Chat replay authorization remains Draft PR #1047 at exact -> `41c7a86f78dddf0bcd9e9f0eb070bf90732f68e3`. Repository Tests, Security, -> SAST, dynamic CodeQL and Code Quality are GREEN there, while Required CodeQL, -> OpenCode, Noema and Strix are terminal FAILURE. Dependency advisory -> GHSA-82fw-gwwq-j7x9 remains issue #1043 / Draft PR #1046 at -> `f80c0ec5f35fd4fc0a867125bc46dfd2d2dee9a9`; duplicate migration ordinal -> 0233 remains issue #1048 / Draft PR #1049 at -> `5322971193d1ff4e0ae13c054d8f99615934d4dc`. -> -> Customer Master customer-hint repair remains issue #1052. ADR 0042 requires -> source-post tenant/access ownership to stay distinct from resolved customer -> identity and provenance; do not repair that issue by rebinding -> `source_post.corporate_entity_id`. Post Chat shared-persistence mutation remains -> issue #1053 and must not duplicate #1044/#1047 replay-authorization ownership. -> -> Protected-main release metadata is still inconsistent: `pyproject.toml` declares -> 2.28.0 while `lineageweave.__version__` declares 2.20.0. Keep this as a release -> blocker rather than normalizing it in documentation. ADR 0251 remains the I/O- -> psychology authority and ADR 0256 the extensible Voice-combination contract. -> RankWeave, ThreadWeave, TEPP, and canonical lowercase -> `ContextualWisdomLab/disksage` retain their own bounded responsibilities. -> PR #1041 remains Draft; earlier overlays below are dated historical evidence only. - -> Exact-head loop overlay: 2026-08-29 13:20 KST. Protected `main` is -> `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map -> explained leftover share, #775). Open ready PRs still lack independent -> APPROVE. #782 leftover-map coordinates + graphic + axis share + ticks -> (v2.24.0–v2.27.0 / ADR 0267–0270) is on -> `2a203bf8b75b987ba899a0006a312d81259b9124` after #799 squash-merged -> into the unprotected leftover branch. Auto-merge squash remains armed -> on #782/#780/#774/#772/#771/#770. Independent APPROVE is still -> required for protected main. Drafts remain dirty against `main`. #96 -> stays closed as a weaker duplicate of #91. GitHub writes through -> `gh`/MCP succeed. Copilot review is not independent APPROVE. Do not -> self-approve. Do not `gh pr merge` stacked leftover PRs onto an -> unprotected leftover base. -> -> Next buyer increment on this cycle: leftover-map distance on -> graphic-display pair segments (ADR 0271 / v2.28.0). Caption each -> closest/farthest segment with persisted leftover-map distance `d` so -> the pair-row badge matches the graphic line. UI-only; no new columns. -> Missing/non-finite `d` omits that segment caption. Do not invent `d` -> from plotted coordinates. Do not invent leftover scores. Stack onto -> leftover branch `feat/leftover-map-coordinates-v2240`; leave the PR -> open for independent review. - -> Exact-head loop overlay: 2026-08-29 13:15 KST. Protected `main` is -> `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map -> explained leftover share, #775). Open ready PRs still lack independent -> APPROVE. #782 leftover-map coordinates + graphic display + axis share -> (v2.24.0 / v2.25.0 / v2.26.0 / ADR 0267 / ADR 0268 / ADR 0269) is on -> `4a0afbf4804d9862bba58869db20ccdfb0a0b37e`; Strix fail-closed and no -> independent APPROVE. Auto-merge squash remains armed on -> #782/#780/#774/#772/#771/#770. Drafts remain dirty against `main`. -> #96 stays closed as a weaker duplicate of #91. GitHub writes through -> `gh`/MCP succeed (comment/create-branch/auto-merge). `git push` HTTPS -> still fails (empty `X-OAuth-Scopes`). Copilot review is not -> independent APPROVE. Do not self-approve. -> -> Next buyer increment on this cycle: leftover-map coordinate ticks -> (ADR 0270 / v2.27.0). Tick leftover-map axes at the origin and at each -> unique finite persisted `ξ` / `ζ` so pair-row `ξ (x, y) ζ (x, y)` -> matches the graphic. UI-only; no new columns. Rank-0 unused axes name -> only `0` and do not invent drawing-scale `−1` / `+1` ticks. Do not -> invent leftover scores. Do not mix into #782; stack onto leftover -> branch `feat/leftover-map-coordinates-v2240`. - -> Exact-head loop overlay: 2026-08-28 19:15 KST. Protected `main` is -> `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map -> explained leftover share, #775). Open ready PRs still lack independent -> APPROVE. #782 leftover-map coordinates + graphic display (v2.24.0 / -> v2.25.0 / ADR 0267 / ADR 0268) is on -> `2f7e9c8df695f12d03964d5caa68fa3355bdd923`; Strix fail-closed and no -> independent APPROVE. Drafts remain dirty against `main`. #96 stays -> closed as a weaker duplicate of #91. GitHub writes through MCP succeed -> (comment/create-branch/git push/auto-merge). Copilot review is not -> independent APPROVE. Do not self-approve. -> -> Next buyer increment on this cycle: leftover-map axis share on the -> graphic display (ADR 0269 / v2.26.0). Caption plot axes with persisted -> ADR 0148 `leftover_map_axes` inertia `σ_k² / Σ_j σ_j²`. UI-only; no -> new columns. Rank-0 zero-share axes still named. Missing/non-finite -> share omits that axis badge and keeps existing leftover-map axis -> text. Do not invent leftover scores. Do not mix into dashboard stacks -> #640/#778/#781. - -> Exact-head loop overlay: 2026-08-28 16:05 KST. Protected `main` is -> `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map -> explained leftover share, #775). Open ready PRs still lack independent -> APPROVE. #782 leftover-map coordinates (v2.24.0 / ADR 0267) is on -> `e2d13019004a5d8c019fecf7a39ceeef4093b8dd`; Strix fail-closed and no -> independent APPROVE. Drafts remain dirty against `main`. #96 stays -> closed as a weaker duplicate of #91. GitHub writes through MCP succeed. -> -> Next buyer increment on this cycle: leftover-map graphic display -> of already-persisted `ξ_{1:2}` / `ζ_{1:2}` (ADR 0268 / v2.25.0). -> UI-only; no new columns. `R̂` and `d` already are inner product and -> length. Do not invent leftover scores. Do not mix into dashboard -> stacks #640/#778/#781. - -> Exact-head loop overlay: 2026-08-28 13:00 KST. Protected `main` is -> `fc13acaa20adca11968238e398d4aafcf62b6cee` (v2.23.0 leftover-map -> explained leftover share, #775). Open ready PRs still lack independent -> APPROVE. Drafts remain dirty against `main`. #96 stays closed as a -> weaker duplicate of #91. GitHub writes through `gh` succeed. -> -> Next buyer increment on this cycle: leftover-map coordinates -> `ξ_{1:2}` / `ζ_{1:2}` (ADR 0267 / migration 0245 / v2.24.0) so -> `R̂ = ξ · ζ` and `d = ‖ξ − ζ‖` are buyer-auditable. Do not name -> leftover-map inner product, cosine, or length as separate columns. - -> Exact-head loop overlay: 2026-08-28 10:00 KST. Protected `main` was -> `edf22ee39aee2a8481f9bda8fff59801821e79c2` (#773 similar-VOC coverage). -> Open ready PRs: #772 (ask_time_axis coverage), #771 (fixtures/vision -> coverage), #770 (project-history empty-state). Auto-merge squash is -> enabled on all three; none has an independent APPROVE (only bot -> COMMENT). Drafts #702, #679, #672, #667, #640 remain dirty against -> `main`. #96 stays closed as a weaker duplicate of #91. Writes through -> the Grok GitHub App now succeed (comment/close/auto-merge/update-branch) -> despite empty `X-OAuth-Scopes`; git push is the remaining probe this -> cycle. This overlay supersedes every older queue count below. -> -> Next buyer increment on this cycle: leftover-map explained leftover -> share `e = R̂² / R²` (ADR 0266 / migration 0244 / v2.23.0) so -> `e + s + x = 1` is buyer-auditable. Do not persist leftover-map -> coordinates in this slice. - -> Exact-head loop overlay: 2026-08-28 KST. Protected `main` was -> `bbb191924e9881a5201f1ecf63c854d92992cc1c`; seven PRs and nine issues were -> open. PR #763 was `b51d3bd8872b` and PR #762 was `e6ca33dba1b5`; both were -> mergeable, normal squash auto-merge was enabled, exact-head Checks were still -> running, and no qualifying independent approval existed. PRs #702 -> (`93e7b81d096d`), #679 (`135dfe7c4266`), #672 (`a3e87a89185f`), #667 -> (`0c0f4af572a9`), and #640 (`bd73e0a43ae1`) remained draft and dirty against -> `main`. Central ruleset 18156473 and repository no-force-push ruleset -> 21065108 remain active. This overlay supersedes every older queue count below. -> Checks from older heads, stacked bases, or merged PRs are not transferred. -> -> Current-runtime boundary: the official Compose project was healthy at the -> HTTP health route, but its PostgreSQL schema did not yet contain -> `source_post_voice`; therefore no current Voice-history aggregate, -> authenticated project-history API result, or rendered authenticated UI result -> is claimed. Older aggregate observations below remain dated supporting -> evidence, not confirmation of this exact head. The checked repository names -> are `ContextualWisdomLab/LineageWeave`, `RankWeave`, `ThreadWeave`, `TEPP`, -> and lowercase canonical `ContextualWisdomLab/disksage`. - -> Voice-of-X delivery snapshot: 2026-08-27 KST. Protected `main` was -> `ff7431bd1851c03e737808d22c6a2d43968582f9`; PR #713 was -> `850494c3861703862a76cfe564381a41243c6c2d`; stacked PR #717 was -> audited at implementation head -> `d5fe4828e9005f0157c308e8ea3c3a590cdf465b`. This candidate and the -> historical evidence below are not protected-main release evidence. -> Loop snapshot: 2026-08-27. Protected `main` advanced through the -> I/O-Psychology job-family and occupational-classification delivery: PRs -> #709 (DOT/FJA worker functions, ADR 0232), #718 (evidence-bound construct -> classes, ADR 0248), +#726 (catalog-bound construct extraction, ADR 0253), -> #733 (construct evidence navigation, ADR 0255), #713 (Voice-of-X ADR 0246), -> #753 (FJA I/O-Psychology semantic layer, ADR 0251), #751 (SOC/O*NET/RIASEC -> taxonomy, ADR 0245), #749 (authorized job-family and job-series snapshot -> import, ADR 0263), #657 (TEPP lifecycle evidence), #704, #720, and #754 are -> now merged. The still-open queue is carried in section 1. No row below is -> release evidence until re-verified on a specific head. - -## Voice-of-X product and technical gap - -ADR 0246 and PR #713 add Supplier, Employee, Business, Regulator, Investor, -Society, and Process to the original Customer, Customer's Customer, -Competitor, Market, and Partner source-post vocabulary. The migration, -published SKOS concepts, product requirements, changelog, and ontology -round-trip tests agree on the twelve codes. The design is organization-type -neutral: public bodies, nonprofits, communities, and automated processes do -not need to be forced into a B2B2C customer chain. - -The phrase "all Voice-of-X combinations" does not have a standards-backed -finite enumeration. ISO's own stakeholder-category guidance says that the -relevant category set varies by committee and subject; ISO 26000 requires -stakeholder identification and engagement across organizational contexts; -AA1000SES requires an inclusive, continuing identification process; and -Mitchell, Agle, and Wood (1997) model stakeholder salience from combinations -of power, legitimacy, and urgency rather than a fixed industry-role list. -Accordingly, ADR 0246 keeps the controlled vocabulary extensible and refuses -keyword inference, defaults, invented weights, or an asserted exhaustive -cross-product. - -ADR 0256 and migration 0237 now define the persistence contract for -evidence-bearing composition. A post keeps one source-provided -`voc_type_code`, mirrored as its sole primary association, while every -additional voice requires a normalized PROV-O assertion and explicit truth -status. Half-open assignment intervals preserve a backfilled primary at -historical cutoffs, close a replaced primary without deleting it, and permit a -later return to the same Voice. The #717 candidate therefore addresses #748's -A → B → A storage root cause without adding Cartesian-product codes. Protected -delivery and synthetic PostgreSQL concurrency/cutoff evidence remain required. -The remaining acceptance boundary is: - -1. preserve the imported primary voice without reclassification (implemented - in the candidate migration; migration 0237 replayed twice successfully on - an isolated PostgreSQL stack on 2026-08-27, including both primary-sync - triggers; a synthetic real-OIDC PostgreSQL API write also proved that the - imported primary remains unchanged); -2. record each additional voice with its own source/evidence and truth state - (schema-enforced and candidate `post_admin` API plus live Post-popup - authoring implemented; synthetic authenticated PostgreSQL integration - proved denial before permission, the authorized write, and its normalized - PROV-O derivation on 2026-08-27); -3. keeps post voice distinct from named-counterparty relationship, actor role, - topic, channel, lifecycle, and stakeholder-salience attributes; -4. return only authorized associations through API, JSON-LD, CSV, filters, - and UI (candidate API list/detail, filters, combined post-card labels, - qualified JSON-LD, exact-value CSV, SHACL, and source-post evidence - navigation implemented; the board re-filter matches every associated voice - and all twelve governed atomic labels are localized across English, Korean, - Chinese, Japanese, and Vietnamese; one bounded query projects assignments - for every authorized Post even when another node type is the focus; post - detail lists primary and evidence-connected perspectives separately and - honors its knowledge cutoff; client-side JSON-LD filtering retains only - exact canonical repository-case node and Voice-assignment IRIs rather than - accepting cross-origin suffix matches; the exact-value row exposes distinct - carrying-Post and authorized derivation-evidence actions, while hidden - evidence emits neither an identifier nor a fabricated evidence count; - paged JSON-LD merges properties for one subject and unions its multi-Voice - relation rather than overwriting an earlier page); and -5. proves zero-, one-, and multi-voice states with synthetic fixtures, - migration replay, ontology/SHACL, API, accessibility, and Storybook edge - tests before any release claim. The candidate `CombinedVoiceEvidence` scene - covers primary-plus-additional assignments; desktop and mobile screenshots - were inspected on 2026-08-27. At 390 CSS pixels the document did not - overflow, the named exact-value region remained horizontally scrollable, - and the source-post evidence action remained visible and labeled. The - `Post/Recorded perspectives` desktop and 390-pixel scenes were also inspected - on 2026-08-27; both kept each complete Voice label paired with its imported - or evidence-connected state without clipping or horizontal overflow. The - `Post/Connect perspective` ready/success scenes were inspected at 1440 and - 390 CSS pixels on 2026-08-27: labels stay above controls, the mobile form is - a single column, controls meet the 44-pixel touch target, and no horizontal - overflow was visible. - -At this snapshot the repository had 42 open PRs and 11 open issues. PR #713 -head `850494c3` includes the review-driven localization of all twelve governed -Voice labels. Its frontend, ontology publication, static-analysis, dependency, -coverage, full-suite, CodeRabbit, Devin, and OpenCode checks passed. Strix -failed closed before producing a vulnerability report: -the primary NVIDIA NIM model returned HTTP 429, one configured fallback had -reached end of life, and the OpenAI fallback reported exhausted credits. A -same-head retry completed on 2026-08-27 with the explicit -`STRIX_PROVIDER_UNAVAILABLE` annotation and again produced no vulnerability -report. This -is provider/control-plane unavailability, not a vulnerability result or -permission to transfer an older success. Auto-merge remains enabled, while an -independent approval is still required. PR #717 implementation head -`d5fe4828` merges that -parent change without force-pushing and separates the complete governed Voice -catalog used for authoring from usage-derived Board filters, so an authorized -administrator can attach a Voice that no visible Post carries yet. It also -labels Voice exact-value navigation as opening the carrying Post rather than -misrepresenting that Post as the separately recorded derivation evidence. Its -CodeRabbit and hosted Frontend/Storybook checks passed at predecessor head -`ebb4ef1d`; refreshed checks for exact head `d5fe4828` were queued. Focused local -backend tests, frontend type checking/lint, and the new unused-Voice authoring -regression passed, and the exact-value navigation tests, lint, and type check -passed after the label repair. The paged JSON-LD union regression and Voice -evidence navigation suite passed 23 focused frontend tests; 48 focused backend -ontology/docstring tests also passed. The full backend suite at predecessor -head `ebb4ef1d` passed 1,366 tests with 148 environment-dependent skips. The -real-integration fixture now applies -the existing migration 0042 before the expanded taxonomy migrations instead -of seeding an incomplete or duplicate legacy catalog; the exact -`d5fe4828` authenticated post-list integration passed in 91.54 seconds. The -wider local frontend run had 400 passes and eight five-second timeouts under -concurrent backend-suite load; a later App-only run had 94 passes and five -five-second timeouts, while the hosted Frontend/Storybook job passed on -`ebb4ef1d`. Neither local timeout run is promoted to full-suite success. An initial -authenticated integration attempt was unavailable while Keycloak initialized; -a later retry against the shared synthetic stack succeeded in 56.18 seconds -and proved the permission, API, PostgreSQL, -PROV-O, and primary-preservation assertions; no identifying source data was -used or retained. No self-approval, admin bypass, or stale-head check transfer -is permitted. - -Stacked PR #717 carries ADR 0256, migration 0237, qualified -ontology terms, persistence/API/UI tests, and the category-validation review -repairs plus a local candidate admin write path that creates its PROV-O -derivation from an authorized evidence Post. Its JSON-LD projection names that -evidence Post only when it is in the authorized visible set and omits the whole -additional assignment otherwise, preserving the SHACL evidence minimum without -substituting the assigned Post. It targets -#713's branch, not protected `main`; -its checks and review are candidate evidence only. After -#713 reaches protected main, #717 must be synchronized, retargeted to `main`, -and revalidated on its then-current head. - -Downstream Dashboard repair PR #737 exact head `a837ee5d` is stacked on base -`7c7bb2cf`, which contains migration 0235 through a non-#713 composition but -does not contain #713's twelve-label locale update. Its added Voice labels are -therefore necessary on that exact base, yet overlap #713 and must be reconciled -when the stack is eventually rebuilt on protected `main`; neither branch is a -second taxonomy authority, and pre-parent Checks cannot transfer across that -restack. -The remaining user-visible gap is evidence-bearing composition. A post still -has one source-provided `voc_type_code`; the product cannot yet represent a -single record that intentionally carries multiple independently evidenced -voices, nor expose the combination in filters, exports, or the ontology -neighborhood. Do not solve this by adding every Cartesian-product code. The -acceptance boundary for a later ADR is a normalized, provenance-bearing -multi-voice association that: - -1. preserves the imported primary voice without reclassification; -2. records each additional voice with its own source/evidence and truth state; -3. keeps post voice distinct from named-counterparty relationship, actor role, - topic, channel, lifecycle, and stakeholder-salience attributes; -4. returns only authorized associations through API, JSON-LD, CSV, filters, - and UI; and -5. proves zero-, one-, and multi-voice states with synthetic fixtures, - migration replay, ontology/SHACL, API, accessibility, and Storybook edge - tests before any release claim. - -At this snapshot the repository had 23 open PRs and 10 open issues. PR #713 -was `MERGEABLE` but policy-blocked: exact-head backend, frontend, CodeQL, -ontology-publication, Semgrep, OSV, Trivy, Scorecard, Noema, Devin, and -CodeRabbit checks were successful; `coverage-source-tree` was queued; Strix -failed closed with `STRIX_PROVIDER_UNAVAILABLE`; and an independent approval -was still required. Auto-merge remains enabled. No self-approval, admin bypass, -or stale-head check transfer is permitted. - -References for this gap use the APA 7 entries in ADR 0246. Current supporting -standards pages were rechecked on 2026-08-27: ISO 26000:2010 remains applicable -to all organization types and AA1000SES v3 is under development for a planned -2027 release, so the repository continues to cite the published AA1000SES -(2015) contract rather than treating the draft as adopted policy. - -> Current queue overlay: 2026-08-27 KST. Protected `main` was -> `ff7431bd1851c03e737808d22c6a2d43968582f9`; 26 PRs and 10 issues were -> open. This overlay supersedes the older queue count and exact-head table -> below, which remain historical evidence. Re-fetch the head, checks, reviews, -> threads, applicable rulesets, and merge SHA immediately before any lifecycle -> claim. No local branch or stacked-branch result is protected-main evidence. - -## Current occupational semantic-layer gap - -ADR 0245's candidate branch publishes only a provenance-safe classification -foundation: 23 2018 SOC major groups, four O*NET 31.0 Job Zone categories, six RIASEC interest -types and their published adjacency, six explicitly legacy work-value clusters, seven -revised work-style dimensions, and four ability domains. It asserts no -occupation-to-characteristic instance profile and therefore does **not** yet -satisfy the requested job-family, job-series, and occupation-level coverage of -work cognition, affect, behavior, or their empirical relations. This is an -explicit unavailable state, not a reason to infer mappings from labels. - -| Gap | Current evidence | Acceptance requirement | -|---|---|---| -| Classification depth | ADR 0245 and `lineageweave/io_taxonomy.py` expose SOC major groups only; schemes now name versioned PROV source entities and the stable O*NET 31.0 Job Zone JSON digest | Import a versioned authoritative classification release with provenance-preserving major, minor, broad, and detailed occupation identifiers; add ISCO/ESCO crosswalks only where the publishing authority supplies them | -| Construct granularity | The candidate ontology exposes 23 high-level characteristic concepts | Publish source-versioned O*NET abilities, skills, knowledge, work activities, work context, interests, and work styles without collapsing cognition, affect, and behavior into one dimension; preserve removed Work Values only as versioned legacy content | -| Occupation-to-construct relations | ADR 0245 deliberately declares relation properties without instance assertions | Persist released source observations with source version, occupation code, element identifier, scale identifier, value, sample/error metadata when supplied, and provenance; never invent or locally normalize a weight | -| Job-family and job-series semantics | No authoritative employer-specific job architecture is present | Define an organization-neutral import contract that preserves the authorized source hierarchy and distinguishes standard occupation codes from employer job families/series; no label-based binding | -| Temporal and multilevel interpretation | Static vocabulary only; no person-level inference is asserted | Version valid and transaction time, preserve occupation/organization/unit nesting and multiple membership, and require TEPP or the owning Rust psychometric service before any calibrated temporal or multilevel result | -| Product consumption | The read model has no persisted semantic-layer consumer or authenticated UI evidence | Add a provenance-bearing API and accessible ontology exploration flow, then verify synthetic Storybook edge states plus authenticated aggregate runtime evidence without exposing identifying records | - -### Current exact-head PR queue - -| PR | Exact observed head | Base | Observed gate state | -|---:|---|---|---| -| #719 | `0cea830a` | `feat/fja-worker-function-ontology` | unstable; 1 pending check(s) | -| #718 | `a3fb32bb` | `feat/fja-worker-function-ontology` | clean; no non-passing check observed | -| #717 | `771a8edf` | `feat/voice-of-x-complete-taxonomy` | unstable; 1 pending check(s) | -| #716 | `8b54b2f7` | `fix/structured-workflow-exact-pin` | clean; no non-passing check observed | -| #714 | `aa93318f` | `main` | blocked; no non-passing check observed | -| #713 | `cc3dfc14` | `main` | blocked; review required; 13 pending check(s) | -| #711 | `8902e37f` | `feat/dashboard-case-metrics` | clean; no non-passing check observed | -| #710 | `8df04b68` | `main` | blocked; review required; no non-passing check observed | -| #709 | `8ef4090c` | `main` | blocked; review required; 11 pending check(s) | -| #704 | `027323cf` | `main` | blocked; review required; 2 failed check(s) | -| #702 | `5de66ab9` | `main` | blocked; review required; 2 pending check(s) | -| #701 | `cc3351a9` | `main` | blocked; review required; 1 failed check(s) | -| #700 | `1bc99eca` | `main` | blocked; review required; 1 failed check(s) | -| #680 | `efe864e5` | `main` | blocked; 1 failed check(s) | -| #679 | `13ecf41d` | `main` | blocked; no non-passing check observed | -| #672 | `a3e87a89` | `main` | blocked; review required; 1 failed check(s) | -| #668 | `1194f44d` | `main` | blocked; review required; 1 failed check(s) | -| #667 | `c2d11a8a` | `main` | blocked; review required; 2 pending check(s) | -| #658 | `15d670f0` | `main` | blocked; review required; 1 failed check(s) | -| #657 | `9f71681c` | `main` | blocked; review required; 1 failed check(s) | -| #644 | `f53dd28e` | `main` | blocked; review required; 1 failed check(s) | -| #643 | `8767de1b` | `main` | blocked; review required; 1 failed check(s); 1 pending check(s) | -| #640 | `5594029c` | `main` | blocked; no non-passing check observed | -| #639 | `2f4b1bff` | `main` | blocked; review required; 1 failed check(s) | -| #632 | `24262a99` | `main` | blocked; review required; 1 failed check(s) | -| #629 | `b721b0f2` | `main` | blocked; review required; 1 failed check(s) | - -> Dashboard delivery snapshot: 2026-08-26 07:15 KST. Protected `main` was -> `494b54e2245040bcf02b45376f221c37cd437e76`. This local branch is not -> protected-main release evidence. - -## Operations Dashboard PRD/TRD traceability - -| Requirement | Evidence contract | Delivery state | -|---|---|---| -| Claim cause delay: order, specification change, originating order, sales pool, Event/post counts | ADR 0206; contextual-orchestrator case classification with cited spans; Event Lineage context | Candidate implementation; authenticated runtime acceptance pending | -| Rebid/handover: discussion, counterparties, our owner, decisions, Event/post counts | ADR 0206; normalized case facts plus persisted summary actions/roles | Candidate implementation; corpus backfill pending | -| External information count/rate and sales/project relation | ADR 0206; semantic `external_information` classification inside Dashboard GNB | Candidate implementation; no separate Board by product decision | -| Project-specific journey | Explicit source/semantic project membership plus event-time ordering | Candidate API and ordered journey UI implemented; authenticated runtime acceptance pending | -| Repeat issue to design improvement | `repeat_issue`, `issue_pattern`, and `improvement_action` cited facts | Candidate semantic contract; design-system connector acceptance pending | -| Natural-language Ask with evidence, report, alert, MCP | Persisted semantic-unit embeddings plus versioned delivery/resource contract | Candidate implementation uses whole-question embedding retrieval with no lexical fallback; authenticated runtime acceptance pending | -| Similar VOC, customer cohort, prior action | Persisted repeat-issue candidate semantics plus orchestrator pair adjudication and extractive evidence | Candidate live post endpoint and post-detail UI implemented; authenticated runtime acceptance pending | -| TEPP independent Event Lineage anchor | Accepted, persisted TEPP criterion bound to exact snapshot/cutoff before fast-mlsirm activation | Consumer PR #606 is on protected main; TEPP producer PR #237 remains open, so no end-to-end accepted artifact is release evidence yet | -| Temporal Lineage topics and multilevel important posts | ADR 0210; TEPP posterior topic/plausible-value contract followed by fast-mlsirm observed-information case-deletion influence | Product/technical contract is protected on `main`; neither required Rust CPU/GPU producer envelope is shipped, so the Dashboard surface remains unavailable (ADR 0208: no local Python substitute) | - -### Technical contract and flow - -```mermaid -sequenceDiagram - participant Source as Authorized source_post - participant CO as contextual-orchestrator - participant Case as operations_case_* (3NF) - participant TEPP as TEPP criterion run - participant MLS as fast-mlsirm - participant API as Dashboard/Ask API - Source->>CO: semantic units + lineage + ontology context - CO-->>Case: cases, cited facts, session provenance - Source->>TEPP: versioned snapshot and independent criterion - TEPP-->>MLS: exact accepted anchor only - MLS-->>API: anchored vector or unavailable - Case-->>API: ABAC-filtered evidence and counts -``` - -Security/operability: every aggregation applies `post_read` plus row-level -corporate-entity visibility before counting; source-body digests invalidate -stale inference; provider errors persist no positive/negative result; PII -remains authorized at the UI boundary and is excluded from telemetry. The -tables use composite keys and bounded kind-first indexes; production hot-path -acceptance still requires `EXPLAIN (ANALYZE, BUFFERS)` on an anonymized runtime -snapshot. - -### Historical UI audit evidence - -The `f0b96029` Storybook build was rendered at 1440×1100 and 402×1200 with -synthetic evidence; `416fd19d` changes only post-navigation request isolation. -Desktop inspection showed all four case kinds, five non-conflated metrics, -project-journey ordering, cited facts, and evidence actions without horizontal -card overflow. Narrow inspection showed two-column metrics, readable cards and -44px-class actions; the project journey remains intentionally horizontally -scrollable. No identifying runtime record or screenshot is committed. The -`EvidenceReady`, `NarrowViewport`, `AnalysisPendingAndMissingEvidence`, -`AnalysisFailed`, and `LoadError` scenes cover the ADR 0206 state inventory. -Authenticated authorized-corpus acceptance remains separate and may return -only aggregate, non-identifying evidence to this repository. - -### Exact open-PR boundary - -At this snapshot there were 11 open PRs and 10 open issues. PRs #660 and #659 -merged to protected `main`; PR #666 remains only non-default-branch stack -composition inside #663. Every remaining open head required refreshed hosted -gates and/or independent review after the base changed. These observations are -not merge readiness. Re-fetch exact heads, unresolved threads, checks, -approvals, rulesets, and merge SHA before any lifecycle claim. - -> Audit snapshot: 2026-08-26 07:15 KST (refreshed by the autonomous merge -> loop). This repository records synthetic fixtures and aggregate, -> non-identifying runtime evidence only. Open PRs and local checks are not -> protected-default-branch release evidence. Identifying post identifiers, -> organization names, and production record keys must never appear in this -> file. - -## 1. Exact-head and governance evidence - -The protected default branch was `494b54e2245040bcf02b45376f221c37cd437e76` -when this baseline was refreshed. The live queue contained 11 open PRs and 10 -open issues. The exact-head inventory below supersedes older per-PR snapshots -elsewhere in this document; those older rows remain useful historical delivery -context only. - -| PR | Exact observed head | Merge/check state at this snapshot | -| ---: | --- | --- | -| #667 | `3bc662d7` | refreshes protected-main and open-queue documentation evidence; base conflict remains to be repaired | -| #663 | `6fd2f701` | combined Project ontology candidate plus #666's non-default-branch removal of sampled region-coverage arithmetic; base conflict remains to be repaired | -| #658 | `f007a5ed` | evidence-honest Global Ask cutoff; hosted checks and independent review required | -| #657 | `2d9b43b7` | TEPP asynchronous lifecycle persistence while unpublished producer work stays unavailable; hosted checks and independent review required | -| #644 | `ed8d97f3` | native frontend surface code splitting; hosted checks and independent review required | -| #643 | `7fb4d18c` | shared token-backed status notice; hosted checks and independent review required | -| #640 | `2d50fa01` | dashboard case metrics and project journeys; base conflict remains to be repaired | -| #639 | `48065ad1` | restores Running action and Compose contracts; hosted checks and independent review required | -| #632 | `29aee18d` | graph-fact provenance, public verification, MCP admission, and k6 evidence; hosted checks and independent review required | -| #631 | `665046dc` (observed parent) | decomposes closed PR #490; this merge refresh advances its head and restarts hosted review evidence | -| #629 | `0138db5f` | provider-work release and bounded landing reads refreshed onto protected `main`; hosted checks and independent review restarted | - -No row above is merge evidence. Immediately before any lifecycle action, -re-fetch the head, unresolved threads, formal reviews, rulesets, and same-head -check conclusions. In particular, queued checks are infrastructure state and -do not transfer evidence from an earlier SHA. - -PR #607 first merged as `61fd631c7bb3c57113fd19763c2c43161eeb2824` -into #606's non-default branch. PR #606 subsequently passed the protected gate, -so the combined TEPP-consumer and operations-dashboard implementation is now -on `main`; the still-open TEPP producer PR #237 keeps end-to-end anchor -acceptance unavailable. - -PR #604 was closed unmerged after its exact OIDC repair was composed into #605; -its green or pending checks are not delivery evidence. PR #482 merged as -protected-main commit `464ff25002044b9d933c8eefd36c8def7ca0ffd8` -with package conflict markers, identifying baseline records, and an OIDC -return-context regression. PR #603 repaired the package/privacy and -analysis-run transaction defects through protected main at `4f53190b`; the -OIDC defect remains delivered until #604 or the composed #605 passes the -protected gate. Protected main is therefore not yet a release candidate. - -PR #592 first merged as `3b3af3b4fe9c439354433a43444e05f37ab24ea3` -into #590's non-default stack base at `2f033ba3`. The complete stack then -passed the protected gate and #590 merged to `main` as -`1d1379fc59d9dac6e9c8bfa4812313e3b9e8f3c8`. - -PR #521 merged through protected `main` as -`3797f063b1a7396972a749aa81f23745acccbee1`; it is release evidence and no -longer part of the open queue. That merge also left a standalone conflict -marker and duplicated stale tail in `CLAUDE.md`; #594 repaired it through -protected `main` as `241be2dddf657f854cb8be54fe11d4ef48d37976`. - -Protected main now contains the ADR 0109 OIDC return restoration from #605, -including fragment preservation and storage fallback. The #606 dashboard -landing must additionally route `?post=` deep links to the Board; that focused -regression is part of the current candidate and is not delivery evidence yet. - -Three systemic gates currently dominate the queue: - -1. **Strix visibility lookup failure (org control plane).** PR #600 exact head - `7580bdc9` failed before scanning because the required-workflow token could - not resolve this public repository after six API retries. The root repair is - ContextualWisdomLab/.github#1320 at `3b9b2380`: ordinary PR, push, and - schedule runs use trusted event visibility; cross-repository dispatch keeps - authoritative public/private/internal visibility; private and internal - repositories remain on private-capable providers. The exact head also - composes the executable fallback contract and classifies bounded NVIDIA - `ServiceUnavailableError` overload evidence as retryable across configured - distinct models without weakening exhaustion or vulnerability fail-close. - A hosted fallback then completed with zero vulnerabilities but was rejected - because the generic warning gate treated Strix's fallback-model banner and - a Hugging Face unauthenticated-download notice as provider failures. The - current head removes only those two exact scanner notices before the - existing general warning and explicit 429/provider failure checks. The - current head also clears a foreign NVIDIA/OpenRouter endpoint before a - direct-OpenAI fallback while retaining an explicitly configured - direct-OpenAI primary endpoint. The prior full quick-gate harness, overload - path, 12 visibility-contract tests, and the focused cross-provider endpoint - contract passed; exact-head hosted revalidation remains pending. It is blocked on - hosted exact-head gates and independent review, so no repaired - protected-main Strix runtime evidence exists yet. -2. **Strix provider unavailability (org control plane).** The central required - Strix scan on .github#1320 failed when NVIDIA returned `Service temporarily - overloaded`; the gate correctly failed closed but did not try its configured - distinct fallbacks because the service-unavailable classifier excluded the - NVIDIA provider. Exact head `3b9b2380` composes that execution repair and the - two exact non-fatal scanner-notice exclusions while keeping - incomplete exhaustion non-passing. This is still an unmerged control-plane - proposal, not protected-main or downstream runtime evidence. -3. **Current-head independent approval.** The org merge scheduler requires - `reviewDecision == APPROVED` plus complete Strix evidence on the exact - head. Bot review evidence regenerates per push, so any repair push resets - the review clock by design; this is expected and not a bypass target. - -Recent protected-default-branch delivery evidence (squash merges onto -`main`, newest first): - -| PR | Merged (UTC) | Delivered | -| ---: | --- | --- | -| #628 | 2026-08-25 12:39 | one-round-trip authorized post filter options without narrowing the complete ABAC-visible set | -| #627 | 2026-08-25 12:35 | preserved valid k6 lifecycle evidence across setup, scenario execution, and teardown | -| #468 | 2026-08-25 08:44 | fast-mlsirm, Keyverse, contextual-orchestrator, and TEPP integration boundaries | -| #493 | 2026-08-25 08:44 | evidence-grounded Event Lineage isolation reasons | -| #600 | 2026-08-25 08:44 | then-current exact-head product/technical baseline | -| #605 | 2026-08-25 08:44 | dialog focus order, evidence readability, and OIDC return-context restoration | -| #608 | 2026-08-25 08:43 | Naruon projection consumed by Workspace Calendar | -| #603 | 2026-08-25 07:24 | short analysis-run transactions, session advisory locking, package-marker/privacy repair, and provider-work lease release | -| #602 | 2026-08-25 07:24 | post-detail modal semantics, Escape close, initial focus, and opener restoration; navigation-refocus edge case continues on #605 | -| #582 | 2026-08-25 07:24 | bounded batched cited-lineage graph fetch | -| #588 | 2026-08-25 07:23 | named two-axis leftover-map reconstruction and raw-residual identity | -| #482 | 2026-08-25 07:03 | corroborated SKOS companion organization chips; regressions subsequently tracked above | -| #601 | 2026-08-25 06:38 | APA 7th PROV-O and PROV-DM references for ADRs 0011 and 0065 | -| #595 | 2026-08-25 04:39 | audited no-draft import door, nullable updated-at fallback, and event-time import | -| #484 | 2026-08-25 04:39 | Allen interval relations with deferred FK validation | -| #383 | 2026-08-25 04:39 | reader-safe OTel diagnostics and service-peer-bounded session metadata | -| #599 | 2026-08-25 04:28 | raw-residual leftover-map cross-share identity aligned without arbitrary weighting | -| #598 | 2026-08-25 03:32 | 5W1H roles/events remain readable across a stale summary contract version | -| #597 | 2026-08-25 03:32 | related posts open Customer Master detail in place without stale graph state | -| #591 | 2026-08-25 03:32 | prior exact-head product-gap baseline snapshot | -| #584 | 2026-08-25 03:32 | TEPP topic-lineage consumption boundary grounded in cited temporal models | -| #581 | 2026-08-25 03:32 | relative-time Ask filtering bound to event time | -| #596 | 2026-08-25 03:27 | hierarchy/name-resolution deep-work timeouts aligned at 600 seconds | -| #585 | 2026-08-25 03:27 | raw Global Ask transport exceptions replaced by bounded client-safe detail | -| #355 | 2026-08-25 02:38 | Naruon calendar projection contract and conformance fixture | -| #562 | 2026-08-24 02:05 | parameter-free classic RRF; deleted the last hand-picked fused score | -| #561 | 2026-08-24 01:47 | knowledge-graph precedence/hierarchy relation classification and layout order | -| #555 | 2026-08-24 01:29 | per-channel score breakdown persisted on `post_lineage_edge.channel_scores` (ADR 0195) | -| #559 | 2026-08-24 01:26 | deleted `DEFAULT_CHANNEL_WEIGHTS` hand-picked fallback | -| #549 | 2026-08-24 00:43 | clamped embedding cosine into `[0, 1]` instead of remapping from `[-1, 1]` (ADR 0190) | -| #548 | 2026-08-24 00:37 | mid-reconstruction provider failure maps to an explicit unavailable state | -| #544 | 2026-08-24 00:27 | fusion weights accepted only via fast-mlsirm estimation | -| #538 | 2026-08-23 23:39 | real embeddings wired into the Event Lineage text channel | - -This documentation is owned by protected `main` again: the #426 stack landed, -so hidden-stack merges (#494, #497, #499, #505, #509 into unprotected parent -branches) are historical context only and no longer gate anything. - -The current protected-`main` and exact #507 trees are clean of the private -runtime source-table identifier present in the closed #506 head and older -public history. Do not reproduce or hint at its value. Historical remediation -requires the ADR 0001 incident process and security/privacy-owner coordination; -never force-push or delete evidence ad hoc. - -The Grok durable hourly loop and the central thin GitHub Actions caller -ContextualWisdomLab/.github#1259 (minute 4, `pr-review-fix-scheduler.yml`) -both target this repository. Do not add a LineageWeave-local duplicate -workflow. ContextualWisdomLab/.github#1258 merged at exact head `897819c4` to -repair the pnpm/coverage-evidence workflow; newly created exact PR heads must -still prove the runtime behavior because merged workflow source alone is not -check evidence. - -Figma design-system boundary (ADR 0002): File ID `1Su3lDRmiZdcUs47t1QwIX`. -The sanitized file now contains synthetic Event Lineage desktop (`5:14`) and -mobile (`5:15`) frames with graph direction, event dates, an inference -boundary, and exact fused-score evidence. Do not copy source-organization -content into this repository. Storybook remains the executable scene and -edge-case inventory for repeated web objects; rendered code-to-Figma parity -still requires same-viewport browser comparison on an exact candidate head. - -## 2. User-visible capability baseline - -Substantially present on protected `main`: - -- PostgreSQL-backed import, normalized provenance, cutoff-aware analysis runs, - source revisions, lineage reconstruction, and explicit unavailable states. -- Authenticated workspace navigation, post detail, localized summaries, 5W1H, - R&R/Keyman, evidence citations, chat, organization hierarchy, and lineage DAG - (`frontend/src/LineageDag.tsx` is on `main`; the old “DAG view missing” - baseline entry is stale). -- Semantic paragraph/list/table/image-region units that preserve the source - representation and provenance instead of flattening it into one body string. -- FJA→I/O-Psychology semantic layer (ADR 0251): the published DOT/FJA - Data/People/Things worker functions (ADR 0232) project into disjoint - cognitive, affective, and behavioral constructs with APA 7th anchors, - SHACL validation, and a deterministic typed read model - (`lineageweave/iopsy_taxonomy.py`); no fitted weight or O*NET/ADR 0248 - crosswalk is asserted (ADR 0145). -- Contextual-orchestrator boundaries for adjudication, extraction, summaries, - chat, embeddings, and VISION; null channels remain unavailable and are - dropped from score fusion. -- W3C PROV-O projection through normalized provenance tables, with the - knowledge graph retained as an explicit navigation projection. -- Keyverse/Keycloak OIDC, RankWeave fusion port, TEPP measurement client, - ThreadWeave tree assembly. - -These statements describe source capability, not authenticated production -corpus acceptance or protected release. - -## 3. Historical open-PR inventory (superseded by §1) - -Heads below are queue evidence captured at snapshot time; recheck SHA, -checks, unresolved threads, and independent approval immediately before any -merge claim. Do not self-approve, force-push, or transfer stale review -evidence across heads. The org merge scheduler merges only when -`reviewDecision == APPROVED` on the exact head and Strix evidence is complete. - -### 3.0 Shared systemic gate - -| Gate | Evidence | Durable repair | -| --- | --- | --- | -| Strix provider unavailability | `nvidia_nim/nvidia/nemotron-3-super-120b-a12b` and `openai-direct/gpt-5.6-luna` failed authoritatively across unrelated heads | ContextualWisdomLab/.github#1263 at `ab3d7645` proposes executable Azure/cross-provider fallbacks but remains open/conflicting; repair that branch without weakening the required gate | -| ADR 0109 login repair debt | Eight branches cut from the pre-repair base carried the unauthenticated `AdminPanel` + unused-OIDC-helper `tsc -b` failure | Same verified two-line repair applied to #521, #522, #552, #553, #554, #556, #558, #560 during this loop; frontend lint/test/build verified locally | - -### 3.1 Workspace root and product surfaces - -| PR | Head | Intent | Notes | -| ---: | --- | --- | --- | -| #258 | `f0b5234d` | Workspace evidence board and source-grounded ontology surface (root stack) | Largest surface; historical CHANGES_REQUESTED is stale relative to current head | -| #349 | `bef4a858` | Bounded ontology and provenance explorer (v2.13.0) | Issue #341 | -| #355 | `2f3f308c` | Naruon event projection contract | Issues #336/#338 | -| #387 | `5ef0f2e6` | Persist and explain Event Lineage channel evidence | Issue #274 | -| #405 | `ec62d9f0` | Persisted image-region locations (v2.12.8) | VISION region provenance | -| #484 | `878c4a87` | Allen interval relations on Event Lineage edges (v2.15.0) | Temporal modeling; Allen (1983) | -| #490 | `d0cad030` | Wire remaining ADR 0133–0137 surfaces | Consolidated product stack incl. Knowledge Graph token repair | -| #493 | `499c8b1b` | Name Event Lineage isolation reasons (v2.16.0) | Honest unavailable/failed states | - -### 3.2 SKOS organization aliases and leftover-map family (stacked) - -| PR | Head | Intent | -| ---: | --- | --- | -| #480 | `f18b421d` | Bind corroborated SKOS org aliases to one catalog row | -| #482 | `c38c08d6` | Corroborated SKOS companion caption on organization chips (v2.14.0) | -| #481 | `32944979` | Persist leftover interaction-map coordinates (v2.12.7) | -| #485 | `dcaa6320` | Leftover pair clicks land on the named Post quality criterion (v2.12.8) | -| #518 | `3117823f` | Name leftover complete-case coverage (v2.12.17) | -| #519 | `31c150c8` | Persist leftover-map axis share on period reports (v2.12.16) | -| #521 | `40677c75` | Leftover pairs on the grouping comparison strip (v2.12.17) | -| #522 | `9be3712e` | Leftover-map distances on two Gabriel axes (v2.12.18) | -| #535 | `1fb5d69a` | Name leftover-map unexplained leftover (v2.12.26) | -| #537 | `9a639554` | Name leftover-map unexplained share (v2.12.27) | -| #539 | `740629d0` | Name leftover-map explained share (v2.12.28) | -| #563 | `740d50f3` | Name leftover-map cross share (v2.12.29) | -| #564 | `ac5de72a` | Name leftover-map reconstruction share (v2.12.30) | - -The leftover-map naming series (#518–#564) is a stacked ladder of honest -leftover-pair labeling increments; merge in ascending order once each exact -head clears gates. - -### 3.3 Repairs and operability - -| PR | Head | Intent | -| ---: | --- | --- | -| #393 | `4ddd3a83` | Detach provider parse error context (honest orchestrator failure) | -| #394 | `cf9505b7` | Preserve source indentation evidence for adjudication | -| #434 | `01d6cca5` | Wire adjudication client into corpus-wide rebuild (issue #289) | -| #541 | `3d93ea9b` | Bootstrap repo-root sys.path in operator scripts | -| #546 | `d210c20c` | Strip Keycloak OIDC callback params from post share links | -| #547 | `fb7fe2db` | Shorten orchestrator healthcheck retry budget | -| #552 | `89000280` | Footer text contrast passes WCAG 1.4.3 AA | -| #553 | `e5152f5c` | `.post-meta` contrast in both themes | -| #554 | `689e42e4` | Event Lineage DAG node marks get a 24×24 px hit target | -| #556 | `21cf9991` | Citation chip grows to a 24px touch target | -| #558 | `91dd1bfc` | Bare loading text exposed as live regions | -| #560 | `59b769e3` | Secondary details/summary toggles sized to `--size-control-min` | - -### 3.4 Integration and measurement boundary - -| PR | Head | Intent | -| ---: | --- | --- | -| #417 | `cb08377c` | TEPP topic-lineage consumption boundary (TRSL-TM + CHRONOS/TDT) ADR | -| #468 | `228f13dd` | Bind fast-mlsirm, Keyverse, orchestrator, and TEPP integration tests | -| #258-family measurement note | — | GRM/GPCM/CAT/FIPC parameter recovery (#451–#454) landed earlier; true-parameter RMSE remains the acceptance bar | - -### 3.5 Documentation - -| PR | Intent | -| ---: | --- | -| #565 | Sync AGENTS.md / CLAUDE.md with accepted ADR boundaries | -| this file | Non-identifying gap baseline refresh (ADR 0001) | - -Closed as superseded during this loop: #368 (baseline rewrite superseded by -this file per §3.5 of the prior snapshot). - -## 4. Open issues (complete live queue; product acceptance remaining on `main`) - -| Issue | User-visible gap | Active PR | -| ---: | --- | --- | -| #79 | Milestone 2: port verified direct-PostgreSQL analysis into the protected architecture | analysis-run registry on `main`; remaining runtime bridge | -| #87 | Milestone 2.1 normalized runtime-analysis schema bridge | related analysis-run work | -| #269 | Authenticated Global Ask MCP browser-safe and admission-bounded | Ask stack | -| #271 | Evidence-honest knowledge-cutoff scope on Global Ask | #658; still open and not protected-main evidence | -| #272 | Verify Global Ask KG/ontology/semantic claims with public SearXNG evidence | #632 preserves internal provenance; public verification acceptance remains open | -| #277 | TEPP: persist accepted receipts, poll completed results, keep measurement authority distinct | #657 consumer lifecycle; executable producer route remains unavailable | -| #280 | Full project-lifecycle history and handover intervals | #640 adds case/project journeys and #663 adds evidence-backed Project exploration; authoritative lifecycle reconciliation remains #284 | -| #284 | Authoritative lifecycle ingestion and idempotent reconciliation | No active delivery PR confirmed | -| #338 | Evidence-bounded email/project lineage contract for Naruon consumption | #704 recreates the provider-side contract on current `main` without arbitrary fusion weights; #343 remains only a non-default-stack merge and #355 is a distinct calendar contract | -| #611 | Decompose closed PR #490 ADR 0133–0137 evidence without transferring stale branch state | #631 supplies the current-main inventory only; focused implementation PRs and tests for every unmet criterion are still required | - -## 5. Open product and technical gaps - -| Gap | Current evidence | Acceptance requirement | -| --- | --- | --- | -| Protected release | 12 open PRs at snapshot, all targeting `main` with normal auto-merge enabled. None has the required independent approval, and running checks on #631/#632/#663 are not treated as blockers for safe work on other PRs. #666's merge into the non-default #663 branch is not protected-main delivery | Terminal exact-head checks, no unresolved threads, two independent approvals including last-push approval, protected squash-merge SHA | -| CI queue release latency | Two Tests runs for already merged PRs occupied the available runner slots while 54 newer runs remained queued. Manual cancellation released the stale work, but the central close workflow was itself queued behind those runs. #634 merged into #631's non-default branch and reuses the repository's existing per-PR concurrency group so a jobless close event can cancel obsolete Tests work before runner allocation; this is not protected-main delivery | Merge #631 through its refreshed protected gate; close a synthetic PR while its Tests run is active and verify the old run becomes cancelled, the close-event jobs remain skipped, and a newer exact-head run starts without manual intervention | -| Evidence-grounded operations workspace | Protected-main #614 delivers governed semantic Ask, live Similar VOC, disjoint pending/failed analysis metrics, full Storybook state inventory, and current desktop/mobile screenshot evidence. Authorized-corpus backfill acceptance remains unavailable | Perform authenticated authorized-corpus acceptance with aggregate evidence and retain fail-closed no-match behavior | -| Shared frontend gate | The ADR 0109 login repair is on protected `main`; eight older branches carried the defect and received the same verified repair this loop (#521–#560) | Keep every future branch cut from post-repair bases; re-verify with frontend lint/test/build before push | -| Identifying baseline regression | `main` gap file listed real post identifiers; separately, closed #506 and pre-existing public history contain a private runtime source-table identifier, while current `main` and #507 trees are clean | Land this non-identifying rewrite, then coordinate ADR 0001 history remediation with security/privacy owners; do not reproduce the value, force-push, or delete evidence ad hoc | -| Authorized-corpus runtime | Repository tests use synthetic fixtures; private records remain outside git | Authenticated runtime validation returning only aggregate, non-identifying evidence | -| Concurrent web responsiveness | ADR 0204 releases pooled transactions during provider work, and the synthetic Compose boundary has an authenticated k6 E2E harness for Ask enqueue, concurrent reads, and job polling. PR #633's measured landing-query and event-loop work merged into open parent #629 rather than protected `main`; its aggregate observation improved 25-VU throughput but did not establish a latency SLO. The current exact #629 also persists each completed relation verification before propagating a later provider failure | Land #629 through its refreshed protected gate, rebuild that exact-head application image, and repeat `make load-http` with declared environment concurrency/window and retained raw distributions/resource configuration; set no SLO until representative capacity evidence is approved | -| Image understanding | Region, OCR, and description work exists across active heads (#405, #419), but current runtime acceptance has not yet proved table-image structure, complete region coverage, or summary/image readiness together | Orchestrator-backed rendered workflow, original/derived asset provenance, region-before-OCR processing, and honest unsupported states; reconcile ADR 0052's image-bearing summary readiness with ADR 0098 before changing sequencing | -| Semantic source rendering | Paragraph, table, list, formula, and indentation work exists across stacks (#394, #427, #448–#450); #515 adds synthetic backend/frontend parity for deterministic rows/cells, footnote boundaries, and encoded scripts | Land the #427 → #515 stack, then gather authenticated browser evidence that list nesting, continuation alignment, and formula units render without authoring-layout artifacts | -| Event and project semantics | #663 is the largest current user-visible gap slice: evidence-backed Project nodes, bounded traversal, cutoff/snapshot fencing, exact-value table parity, and localized graph labels. Focus visibility, label-bound, and temporal test-double regressions are repaired. #666's heuristic removal is composed into this parent but is not separately protected-main evidence. #640 separately adds project journeys without claiming authoritative lifecycle status | Combined #663 must pass exact-head checks and independent approval before protected merge. Aggregate authenticated evidence must still prove distinct projects/events and handover intervals without promoting co-occurrence | -| Voice primary history | Protected `main` `bbb19192` includes ADR 0252 / #761 (migration 0243, GiST primary-period exclusion, `clock_timestamp()` after the source-row lock, API/ontology half-open cutoff SQL). v2.22.1 adds synthetic PostgreSQL integration tests for A → B → A at before/between/after cutoffs, concurrent primary updates, additional-assignment close, and 0237→0243 trigger replay. This is not yet protected-main evidence | Land the live-test slice through the protected gate with independent exact-head APPROVE; close #748 only after that protected delivery | -| Knowledge Graph readability | #659 recreates the token-backed node-type repair on current `main`, including regression coverage; it is open and therefore not protected-main evidence | Merge #659 normally, then verify light/dark contrast, keyboard graph navigation, full labels, and evidence tables in the authenticated rendered surface | -| Source-code lookup UX | Source state/detail codes remain evidence-bearing machine values and current detail presentation is dense | Catalog-backed display labels with raw-code provenance, compact 5W1H/source-detail hierarchy, keyboard access, and no unsupported customer/project binding | -| Calendar / Naruon | #355 delivered the projection contract; v2.17.0 wires operator consumption without forwarding the end-user token. Naruon producer, provider/consumer fixtures, and protected merge remain open (#336) | Verify observed events against the published schema without invented events; keep commitments available when the channel is unwired | -| SKOS organization aliases | Catalog binding and chip caption live on #480 / #482 | One catalog row per corroborated org; companion caption is hint-only until bound | -| Event Lineage evidence | Channel evidence and Allen relations live on #387 / #484 | Persist channel scores, explain them in the popup, never invent a fused score | -| Scientific measurement | Durable accepted TEPP receipts and LineageWeave #614's exact accepted snapshot/cutoff/run/pair-count consumer are protected; TEPP #237 remains open, so no registered producer artifact exists yet. #387 removes inferred/default persistence weights, but several older reconstruction tests still pass hand-authored numeric dictionaries that are not estimator evidence | Land TEPP #237 through its protected gate, then replace remaining reconstruction-test constants with provenance-bearing fast-mlsirm estimates over synthetic fixtures. Retain true-parameter RMSE recovery as the acceptance bar | -| Asynchronous authorization | Protected `main` rebuilds Global Ask worker scope after the bearer token leaves the request; #468 now persists exact Keyverse organization/process-unit scope in 3NF child tables and intersects it with current affiliations | Land #468 through the protected gate; prove a second affiliation and a revoked process unit cannot widen delayed-job evidence | -| Planned-facility intent | Planned-facility relationship intent remains only on closed, unmerged #490; earlier stack-only merges were not protected delivery | Recreate the evidence-backed slice on a current base and land through protected `main` before a release claim | -| Accessibility and responsive UX | #602 delivered base post-detail modal semantics; #605 adds selected-post refocus, collapsed/hidden/inert/CSS-invisible focus exclusion across both modal types, readable evidence separators, focused tests, and desktop/mobile Storybook screenshots | Land #605 through the protected gate, then complete screen-reader and authenticated Playwright acceptance on the exact release head | -| Design tokens and repeated objects | Token extraction started; sanitized Figma Event Lineage desktop/mobile frames exist, while other repeated product surfaces remain incomplete | Tokens in CSS + Storybook stories for board, popup, DAG, Ask, calendar, forms, charts; same-viewport Figma/runtime visual comparison before release | -| Frontend delivery performance | #644 implements a native dynamic-import boundary for conditional workspace surfaces and retains accessible loading/error states; exact-head checks passed but the PR is not protected-main evidence | Merge #644 normally, rebuild the protected-main production bundle, and retain the measured chunk inventory rather than raising the warning limit | -| External integrations | Search, Zotero, calendar, Keyverse, orchestrator, RankWeave, ThreadWeave, TEPP, DiskSage, wardnet | Provider conformance, failure/reconciliation behavior, and provenance-bearing integration evidence | -| Naruon email/project lineage | #704 provides a strict store-agnostic v1 contract, opaque evidence references, observed/inferred truth separation, knowledge-cutoff admission, and explicit unavailable states. Inferred edges require an injected provenance-bearing fast-mlsirm estimate; no local default weight exists | Merge #704 through protected `main`, publish an immutable attested artifact, then enable the Naruon consumer only against that released version and its contract fixtures | -| MSA / modular reuse | LineageWeave must run standalone and as a consumer of org packages | Do not reimplement RankWeave/TEPP/orchestrator/ThreadWeave/Keyverse; fix upstream and PR there | -| Accelerator runtime ownership | ADR 0076/0208 already prohibit local model and mathematical ownership; ADR 0237 now defines MLX as a native orchestrator-side service and TEPP/fast-mlsirm CUDA/OpenCL/CPU profiles as scientific-compute-owner deployments, so LineageWeave Compose remains device-neutral. RankWeave remains the dependency-free Python retrieval-fusion/evaluation owner behind its published contract | TEPP and fast-mlsirm must publish deterministic CPU recovery plus conformance evidence for every advertised CUDA/OpenCL profile; contextual-orchestrator must prove native MLX availability through its provider-neutral health/contract boundary. LineageWeave accepts only versioned, provenance-bearing envelopes and fails closed when the owner is unavailable | -| Product contract authority | The current LineageWeave PRD records exact-case ecosystem authorities. TEPP, fast-mlsirm, keyverse, ThreadWeave, and RankWeave PR #41 have standalone PRDs; RankWeave's remains unmerged. contextual-orchestrator, disksage, and wardnet still rely on product/architecture documents, and naruon has only a scoped Topic Intelligence PRD | Keep ADRs normative, preserve canonical repository case in machine references, land the pending PRDs, and add standalone PRDs in each remaining owning repository before cross-product release claims exceed its documented boundary | -| Release quality | PR #660 is now on protected `main`; its pre-merge full Python suite passed 1,352 tests with 17 skips, but release-wide frontend, Storybook, security, browser, and runtime acceptance remain unproven on one exact protected head | Repository-wide coverage, docstrings, Storybook, security, browser, and release evidence on one exact head | -| PII | Masking would paralyze the product; ADR 0001 forbids identifying artifacts in git | ABAC + authorized runtime; synthetic fixtures in git; no mask-in-place that drops names the operator must read | -| Database | PostgreSQL, 3NF, snake_case ≥ two words, hot-partition and lock policy | No file DBs; read/write split if lock management fails; whitelist every migration | - -### 5.1 Closed PR #490 decomposition (issue #611) - -Protected `main` at `04e6b610` and the three open PRs present during the initial -decomposition were rechecked; the later audit snapshot above includes #631 -itself as the fourth open PR. Protected `main` contains none of PR #490. That PR remains -closed, unmerged branch evidence; its ADR 0133–0137 files are not normative and -its 321-file tree must not be replayed. Current-main code and schema searches -give this delivery matrix: - -| Closed-branch decision | Current-main classification | Smallest remaining delivery | -| --- | --- | --- | -| ADR 0133 source-reference research | Partial foundation: protected `main` has the self-hosted SearXNG relation-verification client and fail-closed configuration, but it verifies an already extracted relation. It has no source-unit/image-region lead, cited-resource retrieval, claim judgment, or normalized research citation workflow | One post-scoped lead-to-citation slice that reuses the self-hosted SearXNG search boundary, adds public-target SSRF/redirect rejection for result retrieval, and judges through contextual-orchestrator with explicit unavailable outcomes | -| ADR 0134 token-backed exception messages | Partial: sanitized next-action failures exist, but no shared token-backed exception component or complete Storybook error inventory exists | Migrate one existing unavailable flow to one shared accessible alert and verify its success, unavailable, and retry states | -| ADR 0135 kind/status-exact analysis actions | Partial: protected `main` has kind-aware start/retry controls plus normative analysis-run, TEPP, cutoff-body, and channel-evidence contracts; it does not contain the closed branch's unified guidance component or its full kind × status interaction inventory | Test the current run-kind/status matrix first, then add only a proven missing state/control pair rather than copying the closed-branch function | -| ADR 0136 per-post Ask history | Partial: `post_chat_result` / `post_chat_citation`, the authorized post Chat API, and its linear exchange history are on protected `main`. Account-and-post-scoped sessions, ordered turns, list/select/new controls, and batched citation reauthorization are not | Define the 3NF account/post session boundary, bounded batch reauthorization, and one authorized list/load/write path before adding the conversation picker | -| ADR 0137 cross-post customer identity | Partial foundation: protected `main` preserves source customer hints and has corporate-catalog unique/miss/tie safeguards, but it has no normalized cross-post customer-identity judgment, supporting-post binding, or corporate-name-history workflow | Add only after external corroboration, orchestrator judgment, TEPP ordering, and unique-catalog fail-close can be verified together; never promote a one-post hint | - -This matrix satisfies only #611's current-main inventory step. Issue #611 -remains open: every unmet criterion above still needs a focused regression test -and exact-head current-main implementation PR before its acceptance criteria -are satisfied. No stale check, review, or implementation is transferred from -#490. - -## 6. UI-UX acceptance inventory (must be defined, reviewed, applied, audited) - -Each item needs a Storybook scene, an edge-case story, and an automated check -before a commercial release claim. Figma File ID `1Su3lDRmiZdcUs47t1QwIX`. - -| Dimension | Current | Gap | -| --- | --- | --- | -| Accessibility | Partial labels/roles on board, popup, login | WCAG 2.2 AA on login, board, popup, Ask, calendar, admin; focus order; live regions | -| Touch & Interaction | Click-first popup and lists | 44px targets, swipe/escape to dismiss popup, no hover-only actions | -| Performance | Board caps and hint render limits exist | Interaction-to-next-paint on board search, DAG, Ask; no N+1 (#358) | -| Style Selection | Korean UI standards merged (#347) | Tokenized light/dark; Anti-Slop-UI density; no decorative noise | -| Layout & Responsive | Desktop popup shell | 402px-class phone layout; stacked GNB; readable DAG | -| Typography & Color | Badge tokens extracted | Contrast on badges, links, error/status; no raw hex in components | -| Animation | Minimal | Reduced-motion; no blocking animation on evidence open | -| Forms & Feedback | Login, Ask, tickets, admin brand | Inline validation, next-action copy, unavailable vs failed distinction | -| Navigation Patterns | Board / customers / calendar / Ask / admin | Deep-link post + OIDC return URL (#426); bookmarkable Ask | -| Charts & Data | Period reports, leftover pairs, Rankings, DAG | Honest empty/unavailable; no invented theta; Storybook chart states | - -## 7. Ecosystem leverage order - -Reuse before rebuild. Consume these ContextualWisdomLab packages in this order -of leverage; open connector PRs there when the defect is upstream: - -1. **contextual-orchestrator** — every LLM/VISION/embedding call (Fugu / Conductor / TRINITY routing). Never a raw provider SDK. -2. **Keyverse** — OIDC issuer, JWKS, tenant principals. -3. **RankWeave** — fused scores and rankings; never invent a fused score or theta. -4. **TEPP** — calibrated measurement; persist receipts; no local reimplementation. -5. **fast-mlsirm** — GRM/GPCM/CAT/FIPC recovery tests (#451–#454) must stay true-parameter RMSE. -6. **ThreadWeave** — tree assembly. -7. **Naruon** — calendar and email/project lineage projection (#336, #338, #355). -8. **DiskSage / wardnet** — storage and network policy as needed. -9. **ContextualWisdomLab/.github** — required review workflows (OpenCode, Strix, Noema) and the LineageWeave hourly caller (#1259). If stacked PRs miss central review or coverage-evidence fails on pnpm 9 (`--trust-lockfile` is pnpm 11.3) or a missing Vitest coverage provider, fix the org workflow (#1258), not a local bypass. - -## 8. Public ontology publication boundary - -- PR #426 publishes fragment-addressable HTML, byte-identical Turtle, - isomorphic JSON-LD and N-Triples, the PROV-O support profile, and a - source-digest manifest from the authoritative ontology. -- Pull requests validate only. Only protected `main` may publish, and the - generated-directory marker, linked-IRI, duplicate-fragment, symlink, and - source-overlap checks fail closed. -- The lowercase knowledge-graph namespace and repository-case support-profile - namespace remain distinct until issue #372 delivers a versioned migration - and compatibility decision; this publication PR rewrites neither identity. -- Until the protected deployment and exact URL checks succeed, the public - ontology endpoint remains unavailable and must not be represented as live. - -## 9. Evidence boundaries - -- Never add a real record, title, name, identifier, screenshot, log, benchmark - artifact, or documentation example to this repository. -- Attendance or co-occurrence is not responsibility, project, customer, or - affiliation evidence. Preserve uncertainty and provenance. -- Missing transport, model capability, accepted envelope, or persistence is - unavailable or failed evidence, never a placeholder result. -- Local green tests, bot statuses, auto-merge, and warning-only checks do not - prove a protected merge. -- Re-fetch base/head SHAs, checks, review threads, approvals, rulesets, and the - merge SHA immediately before any lifecycle claim. -- Do not self-approve. Independent OpenCode / Strix / Noema review is required. -- Do not force-push. Do not treat GitHub Checks duration as a blocker; repair - the failing check instead. -- `COPILOT_GITHUB_TOKEN` is not used. - -## 10. Next acceptance loop (autonomous merge order) - -Process every open PR in ascending number order, considering leverage; for -each: check reviews → repair → re-verify Checks → merge → continue. Checks and -review latency are never blockers — keep working while they settle. - -1. Revalidate Strix after merged ContextualWisdomLab/.github#1320, reconcile - open .github#1263, and land the atomic hourly LineageWeave caller in open - .github#1288 only through their protected gates. -2. Process main-targeted PRs #629, #631, #632, #639, #640, #643, #644, #657, - #658, #659, #660, and #663 only after each exact head shows terminal green - required checks plus current-head independent approval. Treat #666's - non-default-branch merge only as part of #663's combined candidate and - collect all protected evidence on #663's exact head. -3. While hosted checks or independent reviews wait, resume user-visible gaps - from §5 in leverage order: - external semantic verification (#272), Naruon calendar (#355/#336), and - authenticated operations/ontology publication acceptance. Event Lineage - evidence shipped in merged PR #387 and closed issue #274 is not an open gap. -4. Rename remaining `[Buyer Gap]` issue titles to neutral product-object - naming per repository convention (no "Buyer" for internal objects). -5. Keep psychometric tests as true-parameter recovery (RMSE); never fixture - tautologies, invented theta, or hand-authored numeric weights. Remove - weights from tests that do not exercise fusion; fusion tests must consume - provenance-bearing fast-mlsirm estimates over synthetic fixtures. -6. Run frontend lint/test/build/Storybook, backend tests, and authenticated - browser/accessibility checks on the exact candidate release head. -7. Fix only evidence-backed failures and repeat the protected merge gate. -8. Refresh this file each loop with the exact queue state. - -## 11. Spec pointers (derive, do not fork) - -- Product/architecture: `ARCHITECTURE.md`, `AGENTS.md`, `CLAUDE.md` -- Research grounding: ADR 0084, `docs/lineage-bi-research-notes.md` -- Demo identity: ADR 0001 -- Figma boundary: ADR 0002 (File ID `1Su3lDRmiZdcUs47t1QwIX`) -- Orchestrator / paper-grounded models: ADR 0015, ADR 0076 (Fugu, TRINITY, Conductor) -- Ontology / PROV-O / SKOS: ADR 0004, ADR 0011, issue #372 -- Analysis runs / TEPP: ADR 0013–0023, issue #79 / #277 -- Calendar / Naruon: issues #336 / #338, PR #355, operator consumption v2.17.0 -- Ask Agent: issues #269–#272, #358–#363 - -Citations in doctoring and ADRs use APA 7th. Do not invent a heuristic where -the papers leave the decision undecided. - -## 12. Delivery snapshot (2026-08-27) - -Fresh merges on protected `main`, verified from PR lifecycle state and -post-merge reruns (not transferable evidence for later heads): - -| PR | Delivery | Governing ADR / reference | -| ---: | --- | --- | -| #643 | Shared StatusNotice (ADR 0220): success/unavailable/retry states, WorkspaceCalendar auth-unavailable copy, 5-locale i18n; CI Full suite 22m54s green | ADR 0220 | -| #644 | Native workspace surface split: 9 conditionally rendered components as lazy() dynamic imports behind a SurfaceBoundary error boundary; build emits 9 chunks (1.5-37 kB), main bundle 543 kB; 470 frontend tests, tsc, Storybook green | — | -| #762 | Evidence-bound project history (ADR 0243): /api/projects/{key}/history endpoint, project_history.py projection, fetchProjectHistory client, standalone ProjectHistoryTimeline component; supersedes #668 (3-way merge kept only the additive +2279/-0, dropping the branch's 8k shared-file reverts; popup UI hookup deferred as a scoped follow-up) | ADR 0243 | -| #763 | Live-PostgreSQL A→B→A Voice history validation (ADR 0252) proving effective_from/effective_to interval replacement across repeated primary-Voice imports | ADR 0252 | -| #764 | Test-only coverage lift: observability 78%→96%, post_summary 77%→89%, claim_verification 86%→99%; package line coverage 93.5%→95% (484→371 missing); 1651 Python tests green | — | -| #761 | Temporal imported-primary Voice history (ADR 0252): migration 0243 (`effective_to` + GiST primary-period exclusion + synchronize trigger), refined 0237 `least()` effective_from backfill, `effective_from/effective_to` dataclass/export + `coalesce($2,$3)` cutoff predicate. Completes the half-shipped main layer that queried `voice.effective_to` against a missing column. CI Full suite 19m13s green | ADR 0252 | -| #629 | Provider work released before embedding pool bound; landing reads bounded (k6-verified concurrency); merged with strix-only infra timeout (Full suite + all other gates green) | — | -| #750 | Leftover-map unexplained leftover share persisted (`report_leftover_map_unexplained_share`, share `s = U² / R²`) | ADR 0233 | -| #749 | Authorized job-family/job-series import snapshots (`0223_authorized_job_architecture`) | ADR 0263 | -| #759 | ***Promoted** the ONET rating-store stack to `main`: migrations 0222/0223, authenticated rating/rating-sources/rating-occupations endpoints, `OccupationRatingProfile` UI + stories, rating client functions, import scripts, ADR 0252–0263 references. Semgrep SQLi nullified by PL/pgSQL `format(%I/%L)` DDL + documented `nosemgrep`; 1583 Python + 447 frontend tests green | ADR 0257–0263 | -| #747 | Current product and MCP manuals (`docs/manuals/*`, contract tests) | ADR 0118-family | -| #754 | Customer-actionable copy and ADR 0237 accelerator runtime boundary; share/bookmark/verification call sites reworded and ko/zh/ja/vi translations completed after review | ADR 0237 | -| #700 | Source conversation-turn evidence ingestion (`0233_source_conversation_turn_evidence`, choke/adjacency resilience) | ADR 0238 | -| #658 | Optional Global Ask knowledge cutoff honoring `source_post_revision` cover | ADR 0216 | -| #632 | Graph-fact source provenance preserved through MCP streaming + verified psql-parity migration fixture | ADR 0166 | -| #742 | Evidence-bound product-operations relations (stack base) | ADR 0235 | -| #743 | Imported occupation-rating source catalog (stack base) | ADR 0260 | -| #745 | Occupation catalog title filter (stack base) | ADR 0262 | -| #746 | Rating-source occupation selector (stack base) | ADR 0261 | -| #740 | Occupation rating evidence view (stack base) | ADR 0259 | -| #720 | Cancel stale test runs on PR close | — | -| #716 | Prioritized evidence-bound operations backfill | — | -| #711 | Pinned validated structured-workflow runtime | — | -| #704 | Current-main external lineage contract publication | — | - -The ONET rows stacked into base branches (#743/#745/#746/#740/#732) reached -`main` together through the #759 promotion; their per-base merge records are -historical evidence only. The job-architecture artifact ship originally via -#749 is now re-verified on `main` from the promotion. +> Current authority snapshot: 2026-09-14 20:45 KST. +> +> Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`; +> the commit is signature-verified and no protected-main movement was observed in +> the fresh pre-write sweep. This document is a current projection of live +> PR/Issue/check authority, not a replacement for those sources. Historical +> overlays through 2026-09-13 are preserved byte-for-byte in +> [`evidence/product-technical-gap-baseline-history-through-20260913.md`](evidence/product-technical-gap-baseline-history-through-20260913.md). +> When this snapshot and live GitHub state differ, live protected refs, PRs, +> Issues, ADRs and check receipts win. + +## Protected delivery baseline + +No LineageWeave release is admitted from the current protected head. + +- Summary shared-catalog authorization repair #1079 is open, Ready and mergeable + at `c2923950e73c88a9f9fd932332ddd47682da124b` on protected + `main@83eba56149eb802cd63642c507c324c9976ec78e`. Reader materialization is + fail-closed for catalog enrichment; explicit `post_admin` retains the canonical + enrichment path. Exact-head Tests `34815479029`, Security `34815434486`, SAST + `34815434313`, and CodeQL `34815434324` are still non-terminal. Predecessor + receipts do not authorize this head. +- Canonical organization queue observation now has a LineageWeave enrollment + repair in `ContextualWisdomLab/.github#2200`, exact + `c4054eef3fc3cd84c87ea830b2e94d4145aa34e8`, stacked on queue-health owner + #1150. Its focused allowlist contract is GREEN, but the PR is Draft and hosted + acceptance is non-terminal. LineageWeave must not copy queue policy or runner + controls locally. +- Review-sidecar admission/preflight remains owned by + `ContextualWisdomLab/.github#1629`, exact + `db3d648c905d283f03fc16fbc9891ba76edd56b8` on `.github` protected + `main@91be6442906c7b6b4f600272c953699708394327`. The owner source is repaired + but its exact-head acceptance remains pending; provider/model/timeout/retry + policy must not be reimplemented in LineageWeave. + +## Buyer-visible gap register + +| Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | +| --- | --- | --- | --- | +| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Reader path is lookup/reuse-only; explicit admin retains mutation authority. Hosted PostgreSQL + Keycloak + Valkey acceptance is not terminal. | Unchanged-head repository/PostgreSQL, authenticated topology, Security/SAST/CodeQL, Strix/model review and qualifying review evidence, then normal protected merge. | +| Catalog connection leases and summary TOCTOU | #1077 and #1080 | Kept separate from #1079: provider work must not hold long DB leases; post-provider persistence must revalidate authorization/visibility and source revision. | Causal RED→GREEN in each owner lane, short-transaction evidence, current-head tests and protected integration. | +| Governed UI translation delivery | #929 `f898399c5ff9ab89fe440d2e66985860e141620c` and child #932 | PostgreSQL-authoritative versioned ledger is implemented and repository tests are GREEN, but complete reviewed `ko/en/ja/zh/vi/es/de/fr` Customer Master publication is not demonstrated and central Security/CodeQL gates remain non-GREEN. | Complete eight-locale resource publication, authenticated API/browser normal/loading/empty/error/permission/responsive states, keyboard/focus/screen-reader, CJK/text expansion/font fallback, current security/governance receipts. | +| MCP buyer-path latency | #1009 `4fff982a96b0ad6e791aa8c463925388d036f08f` | Modern/legacy protocol repair is Draft. Recorded modern submit/read and legacy read measurements remain far above the repository `p95 <= 20 ms` acceptance contract; CodeQL is also non-GREEN. | Representative uncontended cold/realistic measurements without sample removal or artificial warm-up, profile owned query/I/O/runtime bottlenecks, Rust-first hot-path repair where causal, then exact-head gates. | +| Release identity and immutable publication | #961 `3bdec0504a65e63f44bd49ba15de37182a1672cc` / #1056 | Candidate aligns runtime/package/frontend at 2.28.0 and has repository/Security/SAST GREEN, but Required CodeQL and independent review remain incomplete. Protected main still carries the pre-repair runtime identity. | Built/installed version proof, normal protected merge, immutable tag/package/release, SBOM/provenance, reproducibility and rollback evidence bound to one exact protected SHA. | +| Material Customer Master / lineage UI | #929/#932 plus the live Customer Master and lineage presentation owner PRs | Translation authority, authorization repairs, responsive/a11y states and browser evidence are distributed across their existing owner lanes; no competing inline translation or authorization implementation is permitted. | Converged owner prerequisites plus current-head normal/loading/empty/error/permission/responsive, pointer/touch/keyboard/focus/screen-reader, deterministic identity/layout and applicable performance evidence. | + +## Evidence and ownership rules + +A queued, skipped, COMMENTED, rate-limited, status-only, predecessor-head or +source-neutral result is not GREEN evidence for a moved current head. Valid +findings are repaired in their canonical owner lane and consumed through released +contracts/ACLs; domain truth is not copied across repositories. + +For database paths, external/model work must execute outside long-lived explicit +transactions and locks. Persistence reacquires the shortest necessary lease, +revalidates authorization/version state, and uses idempotent/UPSERT semantics +where the domain contract requires them. + +For material UI, repository/unit evidence does not replace rendered buyer-path +acceptance. Normal/loading/empty/error/permission/responsive behavior, +pointer/touch/keyboard/focus, accessibility, locale expansion/font fallback and +applicable p95 evidence remain part of release acceptance. + +## Historical evidence + +The former append-only baseline, including every dated overlay through +2026-09-13 20:27 KST, is preserved unchanged at +[`docs/evidence/product-technical-gap-baseline-history-through-20260913.md`](evidence/product-technical-gap-baseline-history-through-20260913.md). +It is provenance, not current authority. Future refreshes should update this +current projection and preserve superseded snapshots without presenting old +runtime/check state as live. From dbc167a128c1416cf2d7dd9c48167344323efe06 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 14 Sep 2026 23:12:56 +0900 Subject: [PATCH 053/276] docs(gaps): refresh exact-head acceptance evidence --- docs/product-technical-gap-baseline.md | 29 ++++++++++++++++++-------- 1 file changed, 20 insertions(+), 9 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index ef583a23b..9eb42e0d9 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-14 20:45 KST. +> Current authority snapshot: 2026-09-14 23:12 KST. > > Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`; > the commit is signature-verified and no protected-main movement was observed in @@ -19,15 +19,20 @@ No LineageWeave release is admitted from the current protected head. at `c2923950e73c88a9f9fd932332ddd47682da124b` on protected `main@83eba56149eb802cd63642c507c324c9976ec78e`. Reader materialization is fail-closed for catalog enrichment; explicit `post_admin` retains the canonical - enrichment path. Exact-head Tests `34815479029`, Security `34815434486`, SAST - `34815434313`, and CodeQL `34815434324` are still non-terminal. Predecessor - receipts do not authorize this head. -- Canonical organization queue observation now has a LineageWeave enrollment - repair in `ContextualWisdomLab/.github#2200`, exact + enrichment path. Exact-head Tests `34815479029` are now GREEN: Frontend + `103885140448`, Full suite `103885140559`, and authenticated PostgreSQL + + Keycloak + Valkey Summary authorization integration `103885140632` all passed + on this unchanged head. SAST `34815434313` is also GREEN, and GitHub Advanced + Security CodeQL/Semgrep changed-source checks report no new alerts. Remaining + fail-closed gates are Security `34815434486` (`trivy-fs` and `scorecard` + unassigned), authoritative CodeQL PR `34815434324`, and current-head + Strix/Noema/OpenCode review jobs. +- Canonical organization queue observation has a LineageWeave enrollment repair + in `ContextualWisdomLab/.github#2200`, exact `c4054eef3fc3cd84c87ea830b2e94d4145aa34e8`, stacked on queue-health owner #1150. Its focused allowlist contract is GREEN, but the PR is Draft and hosted - acceptance is non-terminal. LineageWeave must not copy queue policy or runner - controls locally. + Security/SAST/CodeQL acceptance remains queued. LineageWeave must not copy + queue policy or runner controls locally. - Review-sidecar admission/preflight remains owned by `ContextualWisdomLab/.github#1629`, exact `db3d648c905d283f03fc16fbc9891ba76edd56b8` on `.github` protected @@ -39,7 +44,7 @@ No LineageWeave release is admitted from the current protected head. | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | -| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Reader path is lookup/reuse-only; explicit admin retains mutation authority. Hosted PostgreSQL + Keycloak + Valkey acceptance is not terminal. | Unchanged-head repository/PostgreSQL, authenticated topology, Security/SAST/CodeQL, Strix/model review and qualifying review evidence, then normal protected merge. | +| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Reader path is lookup/reuse-only; explicit admin retains mutation authority. Full PostgreSQL and authenticated PostgreSQL + Keycloak + Valkey materialization/fallback regressions are GREEN on the unchanged head; SAST is GREEN; GHAS CodeQL/Semgrep report no new changed-source alerts. | Finish Security and authoritative Required CodeQL, obtain exact-head Strix/OpenCode/Noema and qualifying review evidence, then normal protected merge. | | Catalog connection leases and summary TOCTOU | #1077 and #1080 | Kept separate from #1079: provider work must not hold long DB leases; post-provider persistence must revalidate authorization/visibility and source revision. | Causal RED→GREEN in each owner lane, short-transaction evidence, current-head tests and protected integration. | | Governed UI translation delivery | #929 `f898399c5ff9ab89fe440d2e66985860e141620c` and child #932 | PostgreSQL-authoritative versioned ledger is implemented and repository tests are GREEN, but complete reviewed `ko/en/ja/zh/vi/es/de/fr` Customer Master publication is not demonstrated and central Security/CodeQL gates remain non-GREEN. | Complete eight-locale resource publication, authenticated API/browser normal/loading/empty/error/permission/responsive states, keyboard/focus/screen-reader, CJK/text expansion/font fallback, current security/governance receipts. | | MCP buyer-path latency | #1009 `4fff982a96b0ad6e791aa8c463925388d036f08f` | Modern/legacy protocol repair is Draft. Recorded modern submit/read and legacy read measurements remain far above the repository `p95 <= 20 ms` acceptance contract; CodeQL is also non-GREEN. | Representative uncontended cold/realistic measurements without sample removal or artificial warm-up, profile owned query/I/O/runtime bottlenecks, Rust-first hot-path repair where causal, then exact-head gates. | @@ -53,6 +58,12 @@ source-neutral result is not GREEN evidence for a moved current head. Valid findings are repaired in their canonical owner lane and consumed through released contracts/ACLs; domain truth is not copied across repositories. +The #1079 same-head transition from pre-checkout queue to successful Frontend, +full PostgreSQL and authenticated integration execution is positive owner-path +evidence: runner admission latency must not be converted into leaf source churn, +manual reruns, selector changes or synthetic passing status. Remaining queued +jobs are still incomplete evidence and stay fail-closed. + For database paths, external/model work must execute outside long-lived explicit transactions and locks. Persistence reacquires the shortest necessary lease, revalidates authorization/version state, and uses idempotent/UPSERT semantics From 678c194c8b553a0c1d1765011a81c3e1cdd809f8 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 14 Sep 2026 23:54:36 +0900 Subject: [PATCH 054/276] docs(gaps): record review-sidecar prerequisite RED --- docs/product-technical-gap-baseline.md | 39 +++++++++++++++++--------- 1 file changed, 25 insertions(+), 14 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 9eb42e0d9..e24e35386 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-14 23:12 KST. +> Current authority snapshot: 2026-09-14 23:55 KST. > > Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`; > the commit is signature-verified and no protected-main movement was observed in @@ -19,26 +19,37 @@ No LineageWeave release is admitted from the current protected head. at `c2923950e73c88a9f9fd932332ddd47682da124b` on protected `main@83eba56149eb802cd63642c507c324c9976ec78e`. Reader materialization is fail-closed for catalog enrichment; explicit `post_admin` retains the canonical - enrichment path. Exact-head Tests `34815479029` are now GREEN: Frontend + enrichment path. Exact-head Tests `34815479029` are GREEN: Frontend `103885140448`, Full suite `103885140559`, and authenticated PostgreSQL + Keycloak + Valkey Summary authorization integration `103885140632` all passed on this unchanged head. SAST `34815434313` is also GREEN, and GitHub Advanced Security CodeQL/Semgrep changed-source checks report no new alerts. Remaining - fail-closed gates are Security `34815434486` (`trivy-fs` and `scorecard` - unassigned), authoritative CodeQL PR `34815434324`, and current-head - Strix/Noema/OpenCode review jobs. -- Canonical organization queue observation has a LineageWeave enrollment repair - in `ContextualWisdomLab/.github#2200`, exact - `c4054eef3fc3cd84c87ea830b2e94d4145aa34e8`, stacked on queue-health owner - #1150. Its focused allowlist contract is GREEN, but the PR is Draft and hosted - Security/SAST/CodeQL acceptance remains queued. LineageWeave must not copy - queue policy or runner controls locally. + fail-closed gates are Security `34815434486`, authoritative CodeQL PR + `34815434324`, and current-head Strix/Noema/OpenCode review jobs. +- Canonical organization queue observation remains owned by + `ContextualWisdomLab/.github#1150`, exact + `42bb922f03bf75aed1bc1931d9fbaf04a5433e20`. On that unchanged owner head, + SAST `34831634664` and Agent Review Runtime Quality CI `34831634694` are now + terminal GREEN; Python Security `34831634654`, Security Scan `34831634718`, and + CodeQL PR `34831634674` remain queued/nonterminal. LineageWeave enrollment child + `.github#2200` remains Draft at exact + `c4054eef3fc3cd84c87ea830b2e94d4145aa34e8`, stacked directly on #1150; its + focused allowlist contract is GREEN while its own hosted Security/SAST/CodeQL + acceptance remains queued. LineageWeave must not copy queue policy or runner + controls locally. - Review-sidecar admission/preflight remains owned by `ContextualWisdomLab/.github#1629`, exact `db3d648c905d283f03fc16fbc9891ba76edd56b8` on `.github` protected - `main@91be6442906c7b6b4f600272c953699708394327`. The owner source is repaired - but its exact-head acceptance remains pending; provider/model/timeout/retry - policy must not be reimplemented in LineageWeave. + `main@91be6442906c7b6b4f600272c953699708394327`. Its provider-default source + contract is repaired, but exact-head Runtime Quality `34826203993` is a real + hosted RED: review-repair pytest collection ran without the Noema document + dependency and eleven Noema-related modules failed import because + `defusedxml` was absent. Canonical prerequisite `.github#2170`, exact + `c346b8324fa23e23d4007799d26ad3a8ac6ae4c3`, owns that dependency-install + predicate and is Ready with fresh exact-head acceptance still in progress or + queued. Correct order is #2170 normal protected integration, then ordinary + non-force #1629 reconciliation and fresh acceptance. Provider/model/timeout/ + retry policy must not be reimplemented in LineageWeave. ## Buyer-visible gap register From ed6e06d0676b80aadb51b2331e2487dede1364a9 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Mon, 14 Sep 2026 23:57:18 +0900 Subject: [PATCH 055/276] docs(gaps): record prerequisite exact-head GREEN --- docs/product-technical-gap-baseline.md | 14 ++++++++------ 1 file changed, 8 insertions(+), 6 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e24e35386..2d1beb1b6 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-14 23:55 KST. +> Current authority snapshot: 2026-09-14 23:57 KST. > > Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`; > the commit is signature-verified and no protected-main movement was observed in @@ -29,7 +29,7 @@ No LineageWeave release is admitted from the current protected head. - Canonical organization queue observation remains owned by `ContextualWisdomLab/.github#1150`, exact `42bb922f03bf75aed1bc1931d9fbaf04a5433e20`. On that unchanged owner head, - SAST `34831634664` and Agent Review Runtime Quality CI `34831634694` are now + SAST `34831634664` and Agent Review Runtime Quality CI `34831634694` are terminal GREEN; Python Security `34831634654`, Security Scan `34831634718`, and CodeQL PR `34831634674` remain queued/nonterminal. LineageWeave enrollment child `.github#2200` remains Draft at exact @@ -46,10 +46,12 @@ No LineageWeave release is admitted from the current protected head. dependency and eleven Noema-related modules failed import because `defusedxml` was absent. Canonical prerequisite `.github#2170`, exact `c346b8324fa23e23d4007799d26ad3a8ac6ae4c3`, owns that dependency-install - predicate and is Ready with fresh exact-head acceptance still in progress or - queued. Correct order is #2170 normal protected integration, then ordinary - non-force #1629 reconciliation and fresh acceptance. Provider/model/timeout/ - retry policy must not be reimplemented in LineageWeave. + predicate and is Ready. On that unchanged exact head, Agent Review Runtime + Quality CI `34826735972` and SAST `34826735939` are GREEN; Security + `34826736000`, Python Security `34826735889`, and CodeQL PR `34826735991` + remain queued. Correct order is #2170 normal protected integration, then + ordinary non-force #1629 reconciliation and fresh acceptance. Provider/model/ + timeout/retry policy must not be reimplemented in LineageWeave. ## Buyer-visible gap register From deff9aedc75c26feb33fc597bdc0eab2bba0dde3 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 01:48:58 +0900 Subject: [PATCH 056/276] docs(gaps): refresh current gate evidence --- docs/product-technical-gap-baseline.md | 35 +++++++++++++++----------- 1 file changed, 21 insertions(+), 14 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 2d1beb1b6..53e6506d5 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-14 23:57 KST. +> Current authority snapshot: 2026-09-15 01:44 KST. > > Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`; > the commit is signature-verified and no protected-main movement was observed in @@ -23,9 +23,14 @@ No LineageWeave release is admitted from the current protected head. `103885140448`, Full suite `103885140559`, and authenticated PostgreSQL + Keycloak + Valkey Summary authorization integration `103885140632` all passed on this unchanged head. SAST `34815434313` is also GREEN, and GitHub Advanced - Security CodeQL/Semgrep changed-source checks report no new alerts. Remaining - fail-closed gates are Security `34815434486`, authoritative CodeQL PR - `34815434324`, and current-head Strix/Noema/OpenCode review jobs. + Security CodeQL/Semgrep changed-source checks report no new alerts. Security + `trivy-fs` `104054627552` is now GREEN, while Security `scorecard` + `103964168871` remains queued. Required CodeQL language detection + `103965453105` is GREEN and compatibility-analysis jobs are materialized but + queued (`python` `104055427775`, `javascript-typescript` `104055427725`). + Current-head Strix `103970045852`, Noema `103965387845`, and OpenCode admission + `103974955239` remain queued, and no qualifying independent APPROVED review + exists. - Canonical organization queue observation remains owned by `ContextualWisdomLab/.github#1150`, exact `42bb922f03bf75aed1bc1931d9fbaf04a5433e20`. On that unchanged owner head, @@ -47,17 +52,18 @@ No LineageWeave release is admitted from the current protected head. `defusedxml` was absent. Canonical prerequisite `.github#2170`, exact `c346b8324fa23e23d4007799d26ad3a8ac6ae4c3`, owns that dependency-install predicate and is Ready. On that unchanged exact head, Agent Review Runtime - Quality CI `34826735972` and SAST `34826735939` are GREEN; Security - `34826736000`, Python Security `34826735889`, and CodeQL PR `34826735991` - remain queued. Correct order is #2170 normal protected integration, then - ordinary non-force #1629 reconciliation and fresh acceptance. Provider/model/ - timeout/retry policy must not be reimplemented in LineageWeave. + Quality CI `34826735972`, SAST `34826735939`, gitleaks, and Required CodeQL + language detection are GREEN. Required CodeQL compatibility analyses, Security + `trivy-fs`/`scorecard`, Python Security `Bandit`/`pip-audit`, and current-head + review jobs remain queued. Correct order is #2170 normal protected integration, + then ordinary non-force #1629 reconciliation and fresh acceptance. Provider/ + model/timeout/retry policy must not be reimplemented in LineageWeave. ## Buyer-visible gap register | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | -| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Reader path is lookup/reuse-only; explicit admin retains mutation authority. Full PostgreSQL and authenticated PostgreSQL + Keycloak + Valkey materialization/fallback regressions are GREEN on the unchanged head; SAST is GREEN; GHAS CodeQL/Semgrep report no new changed-source alerts. | Finish Security and authoritative Required CodeQL, obtain exact-head Strix/OpenCode/Noema and qualifying review evidence, then normal protected merge. | +| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Reader path is lookup/reuse-only; explicit admin retains mutation authority. Full PostgreSQL and authenticated PostgreSQL + Keycloak + Valkey materialization/fallback regressions are GREEN on the unchanged head; SAST and Security trivy-fs are GREEN; GHAS CodeQL/Semgrep report no new changed-source alerts; Required CodeQL language detection is GREEN. | Finish Security scorecard and Required CodeQL compatibility analyses, obtain exact-head Strix/OpenCode/Noema and qualifying approval evidence, then normal protected merge. | | Catalog connection leases and summary TOCTOU | #1077 and #1080 | Kept separate from #1079: provider work must not hold long DB leases; post-provider persistence must revalidate authorization/visibility and source revision. | Causal RED→GREEN in each owner lane, short-transaction evidence, current-head tests and protected integration. | | Governed UI translation delivery | #929 `f898399c5ff9ab89fe440d2e66985860e141620c` and child #932 | PostgreSQL-authoritative versioned ledger is implemented and repository tests are GREEN, but complete reviewed `ko/en/ja/zh/vi/es/de/fr` Customer Master publication is not demonstrated and central Security/CodeQL gates remain non-GREEN. | Complete eight-locale resource publication, authenticated API/browser normal/loading/empty/error/permission/responsive states, keyboard/focus/screen-reader, CJK/text expansion/font fallback, current security/governance receipts. | | MCP buyer-path latency | #1009 `4fff982a96b0ad6e791aa8c463925388d036f08f` | Modern/legacy protocol repair is Draft. Recorded modern submit/read and legacy read measurements remain far above the repository `p95 <= 20 ms` acceptance contract; CodeQL is also non-GREEN. | Representative uncontended cold/realistic measurements without sample removal or artificial warm-up, profile owned query/I/O/runtime bottlenecks, Rust-first hot-path repair where causal, then exact-head gates. | @@ -72,10 +78,11 @@ findings are repaired in their canonical owner lane and consumed through release contracts/ACLs; domain truth is not copied across repositories. The #1079 same-head transition from pre-checkout queue to successful Frontend, -full PostgreSQL and authenticated integration execution is positive owner-path -evidence: runner admission latency must not be converted into leaf source churn, -manual reruns, selector changes or synthetic passing status. Remaining queued -jobs are still incomplete evidence and stay fail-closed. +full PostgreSQL, authenticated integration, trivy-fs, and CodeQL language-detect +execution is positive owner-path evidence: runner admission latency must not be +converted into leaf source churn, manual reruns, selector changes or synthetic +passing status. Remaining queued jobs are still incomplete evidence and stay +fail-closed. For database paths, external/model work must execute outside long-lived explicit transactions and locks. Persistence reacquires the shortest necessary lease, From 3dc9330e0dfc00475b9535ad741accf8a4585cc7 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 01:51:46 +0900 Subject: [PATCH 057/276] docs(gaps): record exact-head security green --- docs/product-technical-gap-baseline.md | 32 +++++++++++++------------- 1 file changed, 16 insertions(+), 16 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 53e6506d5..e64dde8d3 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-15 01:44 KST. +> Current authority snapshot: 2026-09-15 01:47 KST. > > Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`; > the commit is signature-verified and no protected-main movement was observed in @@ -22,15 +22,15 @@ No LineageWeave release is admitted from the current protected head. enrichment path. Exact-head Tests `34815479029` are GREEN: Frontend `103885140448`, Full suite `103885140559`, and authenticated PostgreSQL + Keycloak + Valkey Summary authorization integration `103885140632` all passed - on this unchanged head. SAST `34815434313` is also GREEN, and GitHub Advanced - Security CodeQL/Semgrep changed-source checks report no new alerts. Security - `trivy-fs` `104054627552` is now GREEN, while Security `scorecard` - `103964168871` remains queued. Required CodeQL language detection - `103965453105` is GREEN and compatibility-analysis jobs are materialized but - queued (`python` `104055427775`, `javascript-typescript` `104055427725`). - Current-head Strix `103970045852`, Noema `103965387845`, and OpenCode admission - `103974955239` remain queued, and no qualifying independent APPROVED review - exists. + on this unchanged head. SAST `34815434313` is GREEN. Required Security Scan + `34815434486` is now terminal GREEN, including `trivy-fs` `103964168812` and + `scorecard` `103964168871`; GitHub Advanced Security CodeQL, Trivy, Scorecard, + and Semgrep changed-source checks report no new alerts. Required CodeQL language + detection `103965453105` is GREEN and compatibility-analysis jobs are + materialized but queued (`python` `104064547176`, `javascript-typescript` + `104064547154`, `actions` `104064547137`). Current-head Strix `103970045852`, + Noema `103965387845`, and OpenCode admission `103974955239` remain queued, and + no qualifying independent APPROVED review exists. - Canonical organization queue observation remains owned by `ContextualWisdomLab/.github#1150`, exact `42bb922f03bf75aed1bc1931d9fbaf04a5433e20`. On that unchanged owner head, @@ -63,7 +63,7 @@ No LineageWeave release is admitted from the current protected head. | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | -| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Reader path is lookup/reuse-only; explicit admin retains mutation authority. Full PostgreSQL and authenticated PostgreSQL + Keycloak + Valkey materialization/fallback regressions are GREEN on the unchanged head; SAST and Security trivy-fs are GREEN; GHAS CodeQL/Semgrep report no new changed-source alerts; Required CodeQL language detection is GREEN. | Finish Security scorecard and Required CodeQL compatibility analyses, obtain exact-head Strix/OpenCode/Noema and qualifying approval evidence, then normal protected merge. | +| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Reader path is lookup/reuse-only; explicit admin retains mutation authority. Full PostgreSQL and authenticated PostgreSQL + Keycloak + Valkey materialization/fallback regressions, SAST, and Required Security Scan are GREEN on the unchanged head; GHAS CodeQL/Trivy/Scorecard/Semgrep report no new changed-source alerts; Required CodeQL language detection is GREEN. | Finish Required CodeQL compatibility analyses, obtain exact-head Strix/OpenCode/Noema and qualifying approval evidence, then normal protected merge. | | Catalog connection leases and summary TOCTOU | #1077 and #1080 | Kept separate from #1079: provider work must not hold long DB leases; post-provider persistence must revalidate authorization/visibility and source revision. | Causal RED→GREEN in each owner lane, short-transaction evidence, current-head tests and protected integration. | | Governed UI translation delivery | #929 `f898399c5ff9ab89fe440d2e66985860e141620c` and child #932 | PostgreSQL-authoritative versioned ledger is implemented and repository tests are GREEN, but complete reviewed `ko/en/ja/zh/vi/es/de/fr` Customer Master publication is not demonstrated and central Security/CodeQL gates remain non-GREEN. | Complete eight-locale resource publication, authenticated API/browser normal/loading/empty/error/permission/responsive states, keyboard/focus/screen-reader, CJK/text expansion/font fallback, current security/governance receipts. | | MCP buyer-path latency | #1009 `4fff982a96b0ad6e791aa8c463925388d036f08f` | Modern/legacy protocol repair is Draft. Recorded modern submit/read and legacy read measurements remain far above the repository `p95 <= 20 ms` acceptance contract; CodeQL is also non-GREEN. | Representative uncontended cold/realistic measurements without sample removal or artificial warm-up, profile owned query/I/O/runtime bottlenecks, Rust-first hot-path repair where causal, then exact-head gates. | @@ -78,11 +78,11 @@ findings are repaired in their canonical owner lane and consumed through release contracts/ACLs; domain truth is not copied across repositories. The #1079 same-head transition from pre-checkout queue to successful Frontend, -full PostgreSQL, authenticated integration, trivy-fs, and CodeQL language-detect -execution is positive owner-path evidence: runner admission latency must not be -converted into leaf source churn, manual reruns, selector changes or synthetic -passing status. Remaining queued jobs are still incomplete evidence and stay -fail-closed. +full PostgreSQL, authenticated integration, Security Scan, and CodeQL +language-detect execution is positive owner-path evidence: runner admission +latency must not be converted into leaf source churn, manual reruns, selector +changes or synthetic passing status. Remaining queued jobs are still incomplete +evidence and stay fail-closed. For database paths, external/model work must execute outside long-lived explicit transactions and locks. Persistence reacquires the shortest necessary lease, From 0b9ded38af1180aef856fd4fbc8d0efb80e00438 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 02:50:33 +0900 Subject: [PATCH 058/276] docs(gaps): refresh live review execution evidence --- docs/product-technical-gap-baseline.md | 48 +++++++++++++++----------- 1 file changed, 27 insertions(+), 21 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e64dde8d3..c84a61806 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-15 01:47 KST. +> Current authority snapshot: 2026-09-15 02:47 KST. > > Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`; > the commit is signature-verified and no protected-main movement was observed in @@ -23,14 +23,20 @@ No LineageWeave release is admitted from the current protected head. `103885140448`, Full suite `103885140559`, and authenticated PostgreSQL + Keycloak + Valkey Summary authorization integration `103885140632` all passed on this unchanged head. SAST `34815434313` is GREEN. Required Security Scan - `34815434486` is now terminal GREEN, including `trivy-fs` `103964168812` and + `34815434486` is terminal GREEN, including `trivy-fs` `103964168812` and `scorecard` `103964168871`; GitHub Advanced Security CodeQL, Trivy, Scorecard, and Semgrep changed-source checks report no new alerts. Required CodeQL language - detection `103965453105` is GREEN and compatibility-analysis jobs are - materialized but queued (`python` `104064547176`, `javascript-typescript` - `104064547154`, `actions` `104064547137`). Current-head Strix `103970045852`, - Noema `103965387845`, and OpenCode admission `103974955239` remain queued, and - no qualifying independent APPROVED review exists. + detection `103965453105` is GREEN while compatibility analyses remain queued + without a runner (`python` `104064547176`, `javascript-typescript` + `104064547154`, `actions` `104064547137`). OpenCode exact-head admission + `103974955239` is now GREEN; its `opencode-review` `104070870170`, + `coverage-evidence` `104070870162`, and `coverage-source-tree` `104070870386` + jobs remain queued without a runner. Strix `103970045852` and Noema + `103965387845` have both received GitHub-hosted runners and are now actively + executing on the unchanged exact head: Strix reached `Run Strix (quick)` after + successful sidecar provisioning/install, while Noema is provisioning its + contextual-orchestrator review sidecar. Neither is terminal review evidence, + and no qualifying independent APPROVED review exists. - Canonical organization queue observation remains owned by `ContextualWisdomLab/.github#1150`, exact `42bb922f03bf75aed1bc1931d9fbaf04a5433e20`. On that unchanged owner head, @@ -51,19 +57,18 @@ No LineageWeave release is admitted from the current protected head. dependency and eleven Noema-related modules failed import because `defusedxml` was absent. Canonical prerequisite `.github#2170`, exact `c346b8324fa23e23d4007799d26ad3a8ac6ae4c3`, owns that dependency-install - predicate and is Ready. On that unchanged exact head, Agent Review Runtime - Quality CI `34826735972`, SAST `34826735939`, gitleaks, and Required CodeQL - language detection are GREEN. Required CodeQL compatibility analyses, Security - `trivy-fs`/`scorecard`, Python Security `Bandit`/`pip-audit`, and current-head - review jobs remain queued. Correct order is #2170 normal protected integration, - then ordinary non-force #1629 reconciliation and fresh acceptance. Provider/ - model/timeout/retry policy must not be reimplemented in LineageWeave. + predicate and is Ready/mergeable. On that unchanged exact head, Agent Review + Runtime Quality CI `34826735972` and SAST `34826735939` are GREEN; Security + `34826736000`, Python Security `34826735889`, and CodeQL `34826735991` remain + queued. Correct order is #2170 normal protected integration, then ordinary + non-force #1629 reconciliation and fresh acceptance. Provider/model/timeout/ + retry policy must not be reimplemented in LineageWeave. ## Buyer-visible gap register | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | -| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Reader path is lookup/reuse-only; explicit admin retains mutation authority. Full PostgreSQL and authenticated PostgreSQL + Keycloak + Valkey materialization/fallback regressions, SAST, and Required Security Scan are GREEN on the unchanged head; GHAS CodeQL/Trivy/Scorecard/Semgrep report no new changed-source alerts; Required CodeQL language detection is GREEN. | Finish Required CodeQL compatibility analyses, obtain exact-head Strix/OpenCode/Noema and qualifying approval evidence, then normal protected merge. | +| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Reader path is lookup/reuse-only; explicit admin retains mutation authority. Full PostgreSQL and authenticated PostgreSQL + Keycloak + Valkey materialization/fallback regressions, SAST, and Required Security Scan are GREEN on the unchanged head; GHAS CodeQL/Trivy/Scorecard/Semgrep report no new changed-source alerts; Required CodeQL language detection and OpenCode current-head admission are GREEN; Strix and Noema have entered actual exact-head execution. | Finish Required CodeQL compatibility analyses and OpenCode review/coverage jobs, obtain terminal exact-head Strix/Noema and qualifying approval evidence, then normal protected merge. | | Catalog connection leases and summary TOCTOU | #1077 and #1080 | Kept separate from #1079: provider work must not hold long DB leases; post-provider persistence must revalidate authorization/visibility and source revision. | Causal RED→GREEN in each owner lane, short-transaction evidence, current-head tests and protected integration. | | Governed UI translation delivery | #929 `f898399c5ff9ab89fe440d2e66985860e141620c` and child #932 | PostgreSQL-authoritative versioned ledger is implemented and repository tests are GREEN, but complete reviewed `ko/en/ja/zh/vi/es/de/fr` Customer Master publication is not demonstrated and central Security/CodeQL gates remain non-GREEN. | Complete eight-locale resource publication, authenticated API/browser normal/loading/empty/error/permission/responsive states, keyboard/focus/screen-reader, CJK/text expansion/font fallback, current security/governance receipts. | | MCP buyer-path latency | #1009 `4fff982a96b0ad6e791aa8c463925388d036f08f` | Modern/legacy protocol repair is Draft. Recorded modern submit/read and legacy read measurements remain far above the repository `p95 <= 20 ms` acceptance contract; CodeQL is also non-GREEN. | Representative uncontended cold/realistic measurements without sample removal or artificial warm-up, profile owned query/I/O/runtime bottlenecks, Rust-first hot-path repair where causal, then exact-head gates. | @@ -77,12 +82,13 @@ source-neutral result is not GREEN evidence for a moved current head. Valid findings are repaired in their canonical owner lane and consumed through released contracts/ACLs; domain truth is not copied across repositories. -The #1079 same-head transition from pre-checkout queue to successful Frontend, -full PostgreSQL, authenticated integration, Security Scan, and CodeQL -language-detect execution is positive owner-path evidence: runner admission -latency must not be converted into leaf source churn, manual reruns, selector -changes or synthetic passing status. Remaining queued jobs are still incomplete -evidence and stay fail-closed. +The #1079 same-head progression from pre-checkout queue to successful repository, +authenticated integration, Security, CodeQL language-detect and OpenCode-admission +execution—and now actual Strix/Noema runner allocation—remains positive owner-path +evidence: runner admission latency must not be converted into leaf source churn, +manual reruns, selector changes or synthetic passing status. In-progress and +queued final review/compatibility jobs are still incomplete evidence and stay +fail-closed. For database paths, external/model work must execute outside long-lived explicit transactions and locks. Persistence reacquires the shortest necessary lease, From 0b0146a7ec563fb29fcf3ebecfa054aea41d1611 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 04:48:27 +0900 Subject: [PATCH 059/276] docs(gaps): record exact-head full-diff review evidence --- docs/product-technical-gap-baseline.md | 27 ++++++++++++++++---------- 1 file changed, 17 insertions(+), 10 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index c84a61806..14e183a2a 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-15 02:47 KST. +> Current authority snapshot: 2026-09-15 04:46 KST. > > Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`; > the commit is signature-verified and no protected-main movement was observed in @@ -29,14 +29,18 @@ No LineageWeave release is admitted from the current protected head. detection `103965453105` is GREEN while compatibility analyses remain queued without a runner (`python` `104064547176`, `javascript-typescript` `104064547154`, `actions` `104064547137`). OpenCode exact-head admission - `103974955239` is now GREEN; its `opencode-review` `104070870170`, + `103974955239` is GREEN; its `opencode-review` `104070870170`, `coverage-evidence` `104070870162`, and `coverage-source-tree` `104070870386` jobs remain queued without a runner. Strix `103970045852` and Noema - `103965387845` have both received GitHub-hosted runners and are now actively - executing on the unchanged exact head: Strix reached `Run Strix (quick)` after + `103965387845` have both received GitHub-hosted runners and are actively + executing on the unchanged exact head: Strix is in `Run Strix (quick)` after successful sidecar provisioning/install, while Noema is provisioning its - contextual-orchestrator review sidecar. Neither is terminal review evidence, - and no qualifying independent APPROVED review exists. + contextual-orchestrator review sidecar. Neither is terminal review evidence. + CodeRabbit has now completed an independent full base-to-head review of all 13 + changed files from protected main through exact `c2923950e...`, reported no + actionable comments and `Merge Risk: Minimal`, and both inline threads remain + resolved. That full-diff result is useful review evidence but is not a submitted + `APPROVED` review, so a qualifying independent approval is still absent. - Canonical organization queue observation remains owned by `ContextualWisdomLab/.github#1150`, exact `42bb922f03bf75aed1bc1931d9fbaf04a5433e20`. On that unchanged owner head, @@ -68,7 +72,7 @@ No LineageWeave release is admitted from the current protected head. | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | -| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Reader path is lookup/reuse-only; explicit admin retains mutation authority. Full PostgreSQL and authenticated PostgreSQL + Keycloak + Valkey materialization/fallback regressions, SAST, and Required Security Scan are GREEN on the unchanged head; GHAS CodeQL/Trivy/Scorecard/Semgrep report no new changed-source alerts; Required CodeQL language detection and OpenCode current-head admission are GREEN; Strix and Noema have entered actual exact-head execution. | Finish Required CodeQL compatibility analyses and OpenCode review/coverage jobs, obtain terminal exact-head Strix/Noema and qualifying approval evidence, then normal protected merge. | +| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Reader path is lookup/reuse-only; explicit admin retains mutation authority. Full PostgreSQL and authenticated PostgreSQL + Keycloak + Valkey materialization/fallback regressions, SAST, and Required Security Scan are GREEN on the unchanged head; GHAS CodeQL/Trivy/Scorecard/Semgrep report no new changed-source alerts; Required CodeQL language detection and OpenCode current-head admission are GREEN; CodeRabbit full base-to-head review reports no actionable comments and Minimal merge risk; Strix and Noema are in actual exact-head execution. | Finish Required CodeQL compatibility analyses and OpenCode review/coverage jobs, obtain terminal exact-head Strix/Noema and a qualifying submitted approval, then normal protected merge. | | Catalog connection leases and summary TOCTOU | #1077 and #1080 | Kept separate from #1079: provider work must not hold long DB leases; post-provider persistence must revalidate authorization/visibility and source revision. | Causal RED→GREEN in each owner lane, short-transaction evidence, current-head tests and protected integration. | | Governed UI translation delivery | #929 `f898399c5ff9ab89fe440d2e66985860e141620c` and child #932 | PostgreSQL-authoritative versioned ledger is implemented and repository tests are GREEN, but complete reviewed `ko/en/ja/zh/vi/es/de/fr` Customer Master publication is not demonstrated and central Security/CodeQL gates remain non-GREEN. | Complete eight-locale resource publication, authenticated API/browser normal/loading/empty/error/permission/responsive states, keyboard/focus/screen-reader, CJK/text expansion/font fallback, current security/governance receipts. | | MCP buyer-path latency | #1009 `4fff982a96b0ad6e791aa8c463925388d036f08f` | Modern/legacy protocol repair is Draft. Recorded modern submit/read and legacy read measurements remain far above the repository `p95 <= 20 ms` acceptance contract; CodeQL is also non-GREEN. | Representative uncontended cold/realistic measurements without sample removal or artificial warm-up, profile owned query/I/O/runtime bottlenecks, Rust-first hot-path repair where causal, then exact-head gates. | @@ -78,9 +82,12 @@ No LineageWeave release is admitted from the current protected head. ## Evidence and ownership rules A queued, skipped, COMMENTED, rate-limited, status-only, predecessor-head or -source-neutral result is not GREEN evidence for a moved current head. Valid -findings are repaired in their canonical owner lane and consumed through released -contracts/ACLs; domain truth is not copied across repositories. +source-neutral result is not GREEN evidence for a moved current head. An exact-head +full-diff review with no actionable findings is positive independent review +coverage, but it is not equivalent to a submitted `APPROVED` review when approval +is an explicit merge gate. Valid findings are repaired in their canonical owner +lane and consumed through released contracts/ACLs; domain truth is not copied +across repositories. The #1079 same-head progression from pre-checkout queue to successful repository, authenticated integration, Security, CodeQL language-detect and OpenCode-admission From 105a2a257104a85dcd37dc124a7762f551da8c66 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 05:47:10 +0900 Subject: [PATCH 060/276] docs(gaps): refresh central prerequisite evidence --- docs/product-technical-gap-baseline.md | 18 +++++++++++------- 1 file changed, 11 insertions(+), 7 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 14e183a2a..44fa7c824 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-15 04:46 KST. +> Current authority snapshot: 2026-09-15 05:43 KST. > > Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`; > the commit is signature-verified and no protected-main movement was observed in @@ -36,7 +36,7 @@ No LineageWeave release is admitted from the current protected head. executing on the unchanged exact head: Strix is in `Run Strix (quick)` after successful sidecar provisioning/install, while Noema is provisioning its contextual-orchestrator review sidecar. Neither is terminal review evidence. - CodeRabbit has now completed an independent full base-to-head review of all 13 + CodeRabbit has completed an independent full base-to-head review of all 13 changed files from protected main through exact `c2923950e...`, reported no actionable comments and `Merge Risk: Minimal`, and both inline threads remain resolved. That full-diff result is useful review evidence but is not a submitted @@ -50,8 +50,8 @@ No LineageWeave release is admitted from the current protected head. `.github#2200` remains Draft at exact `c4054eef3fc3cd84c87ea830b2e94d4145aa34e8`, stacked directly on #1150; its focused allowlist contract is GREEN while its own hosted Security/SAST/CodeQL - acceptance remains queued. LineageWeave must not copy queue policy or runner - controls locally. + acceptance remains nonterminal. LineageWeave must not copy queue policy or + runner controls locally. - Review-sidecar admission/preflight remains owned by `ContextualWisdomLab/.github#1629`, exact `db3d648c905d283f03fc16fbc9891ba76edd56b8` on `.github` protected @@ -62,9 +62,13 @@ No LineageWeave release is admitted from the current protected head. `defusedxml` was absent. Canonical prerequisite `.github#2170`, exact `c346b8324fa23e23d4007799d26ad3a8ac6ae4c3`, owns that dependency-install predicate and is Ready/mergeable. On that unchanged exact head, Agent Review - Runtime Quality CI `34826735972` and SAST `34826735939` are GREEN; Security - `34826736000`, Python Security `34826735889`, and CodeQL `34826735991` remain - queued. Correct order is #2170 normal protected integration, then ordinary + Runtime Quality CI `34826735972`, SAST `34826735939`, Python Security + `34826735889`, and Security Scan `34826736000` are GREEN. CodeQL PR + `34826735991` remains nonterminal: language detection `103958511197` is GREEN, + while Python `104055129249` and Actions `104055129294` remain queued without a + runner. The only submitted `APPROVED` review still binds predecessor + `ae0f2f57...`, not exact `c346b832...`, so exact-head approval is also still + required. Correct order is #2170 normal protected integration, then ordinary non-force #1629 reconciliation and fresh acceptance. Provider/model/timeout/ retry policy must not be reimplemented in LineageWeave. From 7c4f24a0d4822946931c8a9443eb680e24f1815b Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 06:51:19 +0900 Subject: [PATCH 061/276] docs(gaps): record exact-head review prerequisite approval --- docs/product-technical-gap-baseline.md | 13 +++++++------ 1 file changed, 7 insertions(+), 6 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 44fa7c824..8b12d899e 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-15 05:43 KST. +> Current authority snapshot: 2026-09-15 06:48 KST. > > Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`; > the commit is signature-verified and no protected-main movement was observed in @@ -66,11 +66,12 @@ No LineageWeave release is admitted from the current protected head. `34826735889`, and Security Scan `34826736000` are GREEN. CodeQL PR `34826735991` remains nonterminal: language detection `103958511197` is GREEN, while Python `104055129249` and Actions `104055129294` remain queued without a - runner. The only submitted `APPROVED` review still binds predecessor - `ae0f2f57...`, not exact `c346b832...`, so exact-head approval is also still - required. Correct order is #2170 normal protected integration, then ordinary - non-force #1629 reconciliation and fresh acceptance. Provider/model/timeout/ - retry policy must not be reimplemented in LineageWeave. + runner. A fresh Noema review submitted at 2026-09-14T21:09:40Z now APPROVES + exact `c346b832...`; predecessor approval remains historical only. #2170 is + therefore merge-blocked only by those two CodeQL matrix jobs. Correct order is + #2170 normal protected integration, then ordinary non-force #1629 reconciliation + and fresh acceptance. Provider/model/timeout/retry policy must not be + reimplemented in LineageWeave. ## Buyer-visible gap register From c0f0e270dde3322935b9296fc87962135c71bf5f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 06:53:56 +0900 Subject: [PATCH 062/276] docs(gaps): correct current required-gate inventory --- docs/product-technical-gap-baseline.md | 32 +++++++++++++++----------- 1 file changed, 19 insertions(+), 13 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 8b12d899e..9ac47520c 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-15 06:48 KST. +> Current authority snapshot: 2026-09-15 06:53 KST. > > Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`; > the commit is signature-verified and no protected-main movement was observed in @@ -63,15 +63,19 @@ No LineageWeave release is admitted from the current protected head. `c346b8324fa23e23d4007799d26ad3a8ac6ae4c3`, owns that dependency-install predicate and is Ready/mergeable. On that unchanged exact head, Agent Review Runtime Quality CI `34826735972`, SAST `34826735939`, Python Security - `34826735889`, and Security Scan `34826736000` are GREEN. CodeQL PR - `34826735991` remains nonterminal: language detection `103958511197` is GREEN, - while Python `104055129249` and Actions `104055129294` remain queued without a - runner. A fresh Noema review submitted at 2026-09-14T21:09:40Z now APPROVES - exact `c346b832...`; predecessor approval remains historical only. #2170 is - therefore merge-blocked only by those two CodeQL matrix jobs. Correct order is - #2170 normal protected integration, then ordinary non-force #1629 reconciliation - and fresh acceptance. Provider/model/timeout/retry policy must not be - reimplemented in LineageWeave. + `34826735889`, Security Scan `34826736000`, Noema `104012246592`, Strix + `104017621732`, Required OpenCode bootstrap `103920511286`, and CodeQL language + detection `103958511197` are GREEN. A fresh Noema review submitted at + 2026-09-14T21:09:40Z APPROVES exact `c346b832...`; predecessor approval remains + historical only. Full current required-check inventory is still nonterminal: + CodeQL Python `104055129249`, CodeQL Actions `104055129294`, Required OpenCode + `coverage-evidence` `104142936003`, Required OpenCode `opencode-review` + `104142935844`, and latest `scan-pr-queue` `104154156265` remain queued. Earlier + `scan-pr-queue` `103920512039` success is superseded as current evidence by the + newer queued attempt and is not promoted over it. Correct order is #2170 normal + protected integration only after all current required gates are terminal GREEN, + then ordinary non-force #1629 reconciliation and fresh acceptance. Provider/ + model/timeout/retry policy must not be reimplemented in LineageWeave. ## Buyer-visible gap register @@ -90,9 +94,11 @@ A queued, skipped, COMMENTED, rate-limited, status-only, predecessor-head or source-neutral result is not GREEN evidence for a moved current head. An exact-head full-diff review with no actionable findings is positive independent review coverage, but it is not equivalent to a submitted `APPROVED` review when approval -is an explicit merge gate. Valid findings are repaired in their canonical owner -lane and consumed through released contracts/ACLs; domain truth is not copied -across repositories. +is an explicit merge gate. A newer queued attempt also supersedes an older success +for current-attempt evidence; old success is not promoted over a newer nonterminal +required run. Valid findings are repaired in their canonical owner lane and +consumed through released contracts/ACLs; domain truth is not copied across +repositories. The #1079 same-head progression from pre-checkout queue to successful repository, authenticated integration, Security, CodeQL language-detect and OpenCode-admission From 5462b3f33c634d445b6b17e264c7fb2e02cc6a30 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 08:50:43 +0900 Subject: [PATCH 063/276] docs(gaps): record terminal review runtime evidence --- docs/product-technical-gap-baseline.md | 150 +++++++++++++------------ 1 file changed, 77 insertions(+), 73 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 9ac47520c..afc24a744 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-15 06:53 KST. +> Current authority snapshot: 2026-09-15 08:43 KST. > > Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`; > the commit is signature-verified and no protected-main movement was observed in @@ -15,75 +15,81 @@ No LineageWeave release is admitted from the current protected head. -- Summary shared-catalog authorization repair #1079 is open, Ready and mergeable - at `c2923950e73c88a9f9fd932332ddd47682da124b` on protected +- Summary shared-catalog authorization repair #1079 remains open and Ready at + exact `c2923950e73c88a9f9fd932332ddd47682da124b` on protected `main@83eba56149eb802cd63642c507c324c9976ec78e`. Reader materialization is - fail-closed for catalog enrichment; explicit `post_admin` retains the canonical - enrichment path. Exact-head Tests `34815479029` are GREEN: Frontend + fail-closed for shared-catalog enrichment; explicit `post_admin` retains the + canonical enrichment path. Exact-head Tests `34815479029` are GREEN: Frontend `103885140448`, Full suite `103885140559`, and authenticated PostgreSQL + - Keycloak + Valkey Summary authorization integration `103885140632` all passed - on this unchanged head. SAST `34815434313` is GREEN. Required Security Scan - `34815434486` is terminal GREEN, including `trivy-fs` `103964168812` and - `scorecard` `103964168871`; GitHub Advanced Security CodeQL, Trivy, Scorecard, - and Semgrep changed-source checks report no new alerts. Required CodeQL language - detection `103965453105` is GREEN while compatibility analyses remain queued - without a runner (`python` `104064547176`, `javascript-typescript` - `104064547154`, `actions` `104064547137`). OpenCode exact-head admission - `103974955239` is GREEN; its `opencode-review` `104070870170`, - `coverage-evidence` `104070870162`, and `coverage-source-tree` `104070870386` - jobs remain queued without a runner. Strix `103970045852` and Noema - `103965387845` have both received GitHub-hosted runners and are actively - executing on the unchanged exact head: Strix is in `Run Strix (quick)` after - successful sidecar provisioning/install, while Noema is provisioning its - contextual-orchestrator review sidecar. Neither is terminal review evidence. - CodeRabbit has completed an independent full base-to-head review of all 13 - changed files from protected main through exact `c2923950e...`, reported no - actionable comments and `Merge Risk: Minimal`, and both inline threads remain - resolved. That full-diff result is useful review evidence but is not a submitted - `APPROVED` review, so a qualifying independent approval is still absent. + Keycloak + Valkey Summary authorization integration `103885140632` all passed. + SAST `34815434313` and Required Security Scan `34815434486` are GREEN; changed- + source GHAS CodeQL, Trivy, Scorecard and Semgrep report no new alerts. +- Required CodeQL language detection `103965453105` is GREEN. Compatibility + receivers Python `104064547176`, JavaScript/TypeScript `104064547154`, and + Actions `104064547137` are now terminal FAIL-CLOSED after reading an absent + current-head producer verdict; they are not product-analysis failures. The + coordinator `Dispatch current-head CodeQL scan` `104180256379` is queued with + no runner. Canonical bootstrap/cutover ownership remains `.github#2106 -> + #2040`; LineageWeave must not manufacture a wake commit or duplicate that + control plane. +- Required OpenCode coverage is partly terminal GREEN: `coverage-source-tree` + `104070870386` and `coverage-evidence` `104070870162` succeeded on exact + `c2923950e...`. `opencode-review` `104070870170` successfully dispatched a + current-head request, then correctly failed because no authenticated + `opencode-agent` `APPROVED`/`CHANGES_REQUESTED` verdict had materialized on the + exact head. The central dispatch path owns the eventual verdict/rerun. +- Required Strix `103970045852` is terminal FAILURE but not a LineageWeave + security finding. Trusted-source validation, contextual-orchestrator sidecar + provisioning and Strix installation succeeded. Artifact `strix-reports` + `10371857268` (digest + `sha256:b0d69ccbdf5b4fa52c99e118a9d76e6d4251d34d7deb9341131b9ce8270dd13b`) + contains a terminal report/SARIF with zero findings, while concurrent sub-agent + requests received explicit CO `503 concurrency_limit_exceeded` / `too many + concurrent orchestration runs`. The Strix gate correctly refused to promote a + partial provider execution to GREEN. CO deliberately rejects saturated inference + rather than queueing it; the repair therefore belongs to canonical review-runtime + admission/backpressure, not to a leaf provider/model override or gate weakening. + Fresh consumer evidence is recorded on `.github#2139/#2140`. +- Required Noema `103965387845` is terminal CANCELLED and likewise is not a + product finding. Exact-head admission, credential selection, GitHub App token, + current-head validation and visibility checks succeeded. `Provision contextual- + orchestrator review sidecar` started at `2026-09-14T16:50:39Z`, logged the + sidecar starting at `16:52:41Z`, never emitted readiness, and GitHub cancelled + the operation at `22:51:33Z` after about six hours; no model-verdict step ran. + This is startup/provisioning occupancy evidence, not an elapsed-model-time + verdict. `.github#1629` retains sidecar admission/preflight ownership and + `.github#2139/#2140` retain progress/idle/runner-reclamation semantics. +- CodeRabbit completed an independent full protected-base-to-exact-head review of + all 13 changed files with no actionable comments and `Merge Risk: Minimal`; both + inline threads are resolved. This is positive independent review coverage but + not a submitted qualifying `APPROVED` review. - Canonical organization queue observation remains owned by - `ContextualWisdomLab/.github#1150`, exact - `42bb922f03bf75aed1bc1931d9fbaf04a5433e20`. On that unchanged owner head, - SAST `34831634664` and Agent Review Runtime Quality CI `34831634694` are - terminal GREEN; Python Security `34831634654`, Security Scan `34831634718`, and - CodeQL PR `34831634674` remain queued/nonterminal. LineageWeave enrollment child - `.github#2200` remains Draft at exact - `c4054eef3fc3cd84c87ea830b2e94d4145aa34e8`, stacked directly on #1150; its - focused allowlist contract is GREEN while its own hosted Security/SAST/CodeQL - acceptance remains nonterminal. LineageWeave must not copy queue policy or - runner controls locally. -- Review-sidecar admission/preflight remains owned by - `ContextualWisdomLab/.github#1629`, exact - `db3d648c905d283f03fc16fbc9891ba76edd56b8` on `.github` protected + `ContextualWisdomLab/.github#1150` with LineageWeave enrollment child + `.github#2200`; LineageWeave does not copy queue policy or runner controls. +- Review-sidecar admission/preflight remains owned by `.github#1629`, exact + `db3d648c905d283f03fc16fbc9891ba76edd56b8`, on `.github` protected `main@91be6442906c7b6b4f600272c953699708394327`. Its provider-default source - contract is repaired, but exact-head Runtime Quality `34826203993` is a real - hosted RED: review-repair pytest collection ran without the Noema document - dependency and eleven Noema-related modules failed import because - `defusedxml` was absent. Canonical prerequisite `.github#2170`, exact - `c346b8324fa23e23d4007799d26ad3a8ac6ae4c3`, owns that dependency-install - predicate and is Ready/mergeable. On that unchanged exact head, Agent Review - Runtime Quality CI `34826735972`, SAST `34826735939`, Python Security - `34826735889`, Security Scan `34826736000`, Noema `104012246592`, Strix - `104017621732`, Required OpenCode bootstrap `103920511286`, and CodeQL language - detection `103958511197` are GREEN. A fresh Noema review submitted at - 2026-09-14T21:09:40Z APPROVES exact `c346b832...`; predecessor approval remains - historical only. Full current required-check inventory is still nonterminal: - CodeQL Python `104055129249`, CodeQL Actions `104055129294`, Required OpenCode - `coverage-evidence` `104142936003`, Required OpenCode `opencode-review` - `104142935844`, and latest `scan-pr-queue` `104154156265` remain queued. Earlier - `scan-pr-queue` `103920512039` success is superseded as current evidence by the - newer queued attempt and is not promoted over it. Correct order is #2170 normal - protected integration only after all current required gates are terminal GREEN, - then ordinary non-force #1629 reconciliation and fresh acceptance. Provider/ - model/timeout/retry policy must not be reimplemented in LineageWeave. + contract is repaired but its exact-head Runtime Quality RED is blocked by the + missing Noema document dependency during review-repair collection. Canonical + prerequisite `.github#2170`, exact + `c346b8324fa23e23d4007799d26ad3a8ac6ae4c3`, owns that dependency predicate and + remains Ready/mergeable with Runtime Quality, SAST, Python Security, Security, + Noema, Strix, OpenCode bootstrap and CodeQL language detection GREEN plus a + current-head Noema APPROVED review. Its current CodeQL receivers are fail-closed + pending coordinator `104179015295`; latest `scan-pr-queue` `104154156265`, + `coverage-evidence` `104142936003` and `opencode-review` `104142935844` remain + nonterminal. Correct sequencing stays #2170 normal protected integration -> + ordinary/non-force #1629 reconciliation -> fresh #1629 acceptance. Final + provider admission/routing/TTC remains owned by released contextual-orchestrator, + not central CI or LineageWeave. ## Buyer-visible gap register | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | -| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Reader path is lookup/reuse-only; explicit admin retains mutation authority. Full PostgreSQL and authenticated PostgreSQL + Keycloak + Valkey materialization/fallback regressions, SAST, and Required Security Scan are GREEN on the unchanged head; GHAS CodeQL/Trivy/Scorecard/Semgrep report no new changed-source alerts; Required CodeQL language detection and OpenCode current-head admission are GREEN; CodeRabbit full base-to-head review reports no actionable comments and Minimal merge risk; Strix and Noema are in actual exact-head execution. | Finish Required CodeQL compatibility analyses and OpenCode review/coverage jobs, obtain terminal exact-head Strix/Noema and a qualifying submitted approval, then normal protected merge. | -| Catalog connection leases and summary TOCTOU | #1077 and #1080 | Kept separate from #1079: provider work must not hold long DB leases; post-provider persistence must revalidate authorization/visibility and source revision. | Causal RED→GREEN in each owner lane, short-transaction evidence, current-head tests and protected integration. | -| Governed UI translation delivery | #929 `f898399c5ff9ab89fe440d2e66985860e141620c` and child #932 | PostgreSQL-authoritative versioned ledger is implemented and repository tests are GREEN, but complete reviewed `ko/en/ja/zh/vi/es/de/fr` Customer Master publication is not demonstrated and central Security/CodeQL gates remain non-GREEN. | Complete eight-locale resource publication, authenticated API/browser normal/loading/empty/error/permission/responsive states, keyboard/focus/screen-reader, CJK/text expansion/font fallback, current security/governance receipts. | +| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Reader path is lookup/reuse-only; explicit admin retains mutation authority. Full PostgreSQL and authenticated PostgreSQL + Keycloak + Valkey materialization/fallback regressions, SAST and Required Security are GREEN. CodeRabbit full-diff review is clean. OpenCode coverage tree/evidence are GREEN. Strix produced zero SARIF findings but failed closed on CO saturation; Noema never reached a verdict because sidecar provisioning occupied the runner until cancellation. | Finish current-head CodeQL producer/compatibility acceptance, obtain authenticated OpenCode verdict, repair/revalidate Strix and Noema through canonical owner lanes, obtain qualifying submitted approval, then normal protected merge. | +| Catalog connection leases and summary TOCTOU | #1077 and #1080 | Kept separate from #1079: provider work must not hold long DB leases; post-provider persistence must revalidate authorization/visibility and source revision. | Causal RED->GREEN in each owner lane, short-transaction evidence, current-head tests and protected integration. | +| Governed UI translation delivery | #929 `f898399c5ff9ab89fe440d2e66985860e141620c` and child #932 | PostgreSQL-authoritative versioned ledger is implemented and repository tests are GREEN, but complete reviewed `ko/en/ja/zh/vi/es/de/fr` Customer Master publication is not demonstrated and central Security/CodeQL gates remain non-GREEN. | Complete eight-locale resource publication, authenticated API/browser normal/loading/empty/error/permission/responsive states, keyboard/focus/screen-reader, CJK/text expansion/font fallback and current security/governance receipts. | | MCP buyer-path latency | #1009 `4fff982a96b0ad6e791aa8c463925388d036f08f` | Modern/legacy protocol repair is Draft. Recorded modern submit/read and legacy read measurements remain far above the repository `p95 <= 20 ms` acceptance contract; CodeQL is also non-GREEN. | Representative uncontended cold/realistic measurements without sample removal or artificial warm-up, profile owned query/I/O/runtime bottlenecks, Rust-first hot-path repair where causal, then exact-head gates. | | Release identity and immutable publication | #961 `3bdec0504a65e63f44bd49ba15de37182a1672cc` / #1056 | Candidate aligns runtime/package/frontend at 2.28.0 and has repository/Security/SAST GREEN, but Required CodeQL and independent review remain incomplete. Protected main still carries the pre-repair runtime identity. | Built/installed version proof, normal protected merge, immutable tag/package/release, SBOM/provenance, reproducibility and rollback evidence bound to one exact protected SHA. | | Material Customer Master / lineage UI | #929/#932 plus the live Customer Master and lineage presentation owner PRs | Translation authority, authorization repairs, responsive/a11y states and browser evidence are distributed across their existing owner lanes; no competing inline translation or authorization implementation is permitted. | Converged owner prerequisites plus current-head normal/loading/empty/error/permission/responsive, pointer/touch/keyboard/focus/screen-reader, deterministic identity/layout and applicable performance evidence. | @@ -94,19 +100,17 @@ A queued, skipped, COMMENTED, rate-limited, status-only, predecessor-head or source-neutral result is not GREEN evidence for a moved current head. An exact-head full-diff review with no actionable findings is positive independent review coverage, but it is not equivalent to a submitted `APPROVED` review when approval -is an explicit merge gate. A newer queued attempt also supersedes an older success -for current-attempt evidence; old success is not promoted over a newer nonterminal -required run. Valid findings are repaired in their canonical owner lane and -consumed through released contracts/ACLs; domain truth is not copied across -repositories. +is an explicit merge gate. A compatibility receiver that fails because its +current-head producer has not yet materialized is fail-closed control-plane +evidence, not a source-analysis failure. A clean SARIF/report from a review scan +whose provider execution was incomplete is likewise not promoted to GREEN. -The #1079 same-head progression from pre-checkout queue to successful repository, -authenticated integration, Security, CodeQL language-detect and OpenCode-admission -execution—and now actual Strix/Noema runner allocation—remains positive owner-path -evidence: runner admission latency must not be converted into leaf source churn, -manual reruns, selector changes or synthetic passing status. In-progress and -queued final review/compatibility jobs are still incomplete evidence and stay -fail-closed. +Valid findings are repaired in their canonical owner lane and consumed through +released contracts/ACLs; domain truth is not copied across repositories. In +particular, CO's explicit `concurrency_limit_exceeded` overload contract must not +be weakened from a LineageWeave leaf. Review callers must respect the released +capacity/admission boundary, while progress/idle/runner-reclamation semantics stay +separate from total model elapsed time. For database paths, external/model work must execute outside long-lived explicit transactions and locks. Persistence reacquires the shortest necessary lease, From 2d820a5cf7766a0271cf0ece0c36c5c9e78c4362 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 09:54:19 +0900 Subject: [PATCH 064/276] docs(gaps): record current-main ADR occupancy reconstruction --- docs/product-technical-gap-baseline.md | 27 +++++++++++++++++++------- 1 file changed, 20 insertions(+), 7 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index afc24a744..f766f849f 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-15 08:43 KST. +> Current authority snapshot: 2026-09-15 09:53 KST. > > Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`; > the commit is signature-verified and no protected-main movement was observed in @@ -26,10 +26,10 @@ No LineageWeave release is admitted from the current protected head. source GHAS CodeQL, Trivy, Scorecard and Semgrep report no new alerts. - Required CodeQL language detection `103965453105` is GREEN. Compatibility receivers Python `104064547176`, JavaScript/TypeScript `104064547154`, and - Actions `104064547137` are now terminal FAIL-CLOSED after reading an absent + Actions `104064547137` are terminal FAIL-CLOSED after reading an absent current-head producer verdict; they are not product-analysis failures. The - coordinator `Dispatch current-head CodeQL scan` `104180256379` is queued with - no runner. Canonical bootstrap/cutover ownership remains `.github#2106 -> + coordinator `Dispatch current-head CodeQL scan` `104180256379` remains queued + with no runner. Canonical bootstrap/cutover ownership remains `.github#2106 -> #2040`; LineageWeave must not manufacture a wake commit or duplicate that control plane. - Required OpenCode coverage is partly terminal GREEN: `coverage-source-tree` @@ -49,7 +49,12 @@ No LineageWeave release is admitted from the current protected head. partial provider execution to GREEN. CO deliberately rejects saturated inference rather than queueing it; the repair therefore belongs to canonical review-runtime admission/backpressure, not to a leaf provider/model override or gate weakening. - Fresh consumer evidence is recorded on `.github#2139/#2140`. + Fresh consumer evidence remains on `.github#2139`. The decision-record lane + `.github#2140` was found stale/non-mergeable against current protected `.github` + `main@91be6442906c7b6b4f600272c953699708394327`; current-main reconstruction + `.github#2207` now carries the same ADR blob (`1c133061cccb6bca9c3552cb8bdbca43b17d19f1`) + plus the original changelog evidence via the repository's existing `CHANGELOG.d/` + convention. #2140 remains open/Draft until complete succession is proved. - Required Noema `103965387845` is terminal CANCELLED and likewise is not a product finding. Exact-head admission, credential selection, GitHub App token, current-head validation and visibility checks succeeded. `Provision contextual- @@ -58,7 +63,9 @@ No LineageWeave release is admitted from the current protected head. the operation at `22:51:33Z` after about six hours; no model-verdict step ran. This is startup/provisioning occupancy evidence, not an elapsed-model-time verdict. `.github#1629` retains sidecar admission/preflight ownership and - `.github#2139/#2140` retain progress/idle/runner-reclamation semantics. + `.github#2139` retains progress/idle/runner-reclamation evidence. Proposed + ADR-0030 authority is being reconstructed on current protected `.github` main + in Draft `.github#2207`; no total elapsed model deadline is introduced. - CodeRabbit completed an independent full protected-base-to-exact-head review of all 13 changed files with no actionable comments and `Merge Risk: Minimal`; both inline threads are resolved. This is positive independent review coverage but @@ -87,7 +94,7 @@ No LineageWeave release is admitted from the current protected head. | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | -| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Reader path is lookup/reuse-only; explicit admin retains mutation authority. Full PostgreSQL and authenticated PostgreSQL + Keycloak + Valkey materialization/fallback regressions, SAST and Required Security are GREEN. CodeRabbit full-diff review is clean. OpenCode coverage tree/evidence are GREEN. Strix produced zero SARIF findings but failed closed on CO saturation; Noema never reached a verdict because sidecar provisioning occupied the runner until cancellation. | Finish current-head CodeQL producer/compatibility acceptance, obtain authenticated OpenCode verdict, repair/revalidate Strix and Noema through canonical owner lanes, obtain qualifying submitted approval, then normal protected merge. | +| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Reader path is lookup/reuse-only; explicit admin retains mutation authority. Full PostgreSQL and authenticated PostgreSQL + Keycloak + Valkey materialization/fallback regressions, SAST and Required Security are GREEN. CodeRabbit full-diff review is clean. OpenCode coverage tree/evidence are GREEN. Strix produced zero SARIF findings but failed closed on CO saturation; Noema never reached a verdict because sidecar provisioning occupied the runner until cancellation. Canonical occupancy decision evidence is on `.github#2139`, with stale `.github#2140` reconstructed as current-main Draft `.github#2207`. | Finish current-head CodeQL producer/compatibility acceptance, obtain authenticated OpenCode verdict, repair/revalidate Strix and Noema through canonical owner lanes, prove the #2140 -> #2207 decision-record succession, obtain qualifying submitted approval, then normal protected merge. | | Catalog connection leases and summary TOCTOU | #1077 and #1080 | Kept separate from #1079: provider work must not hold long DB leases; post-provider persistence must revalidate authorization/visibility and source revision. | Causal RED->GREEN in each owner lane, short-transaction evidence, current-head tests and protected integration. | | Governed UI translation delivery | #929 `f898399c5ff9ab89fe440d2e66985860e141620c` and child #932 | PostgreSQL-authoritative versioned ledger is implemented and repository tests are GREEN, but complete reviewed `ko/en/ja/zh/vi/es/de/fr` Customer Master publication is not demonstrated and central Security/CodeQL gates remain non-GREEN. | Complete eight-locale resource publication, authenticated API/browser normal/loading/empty/error/permission/responsive states, keyboard/focus/screen-reader, CJK/text expansion/font fallback and current security/governance receipts. | | MCP buyer-path latency | #1009 `4fff982a96b0ad6e791aa8c463925388d036f08f` | Modern/legacy protocol repair is Draft. Recorded modern submit/read and legacy read measurements remain far above the repository `p95 <= 20 ms` acceptance contract; CodeQL is also non-GREEN. | Representative uncontended cold/realistic measurements without sample removal or artificial warm-up, profile owned query/I/O/runtime bottlenecks, Rust-first hot-path repair where causal, then exact-head gates. | @@ -105,6 +112,12 @@ current-head producer has not yet materialized is fail-closed control-plane evidence, not a source-analysis failure. A clean SARIF/report from a review scan whose provider execution was incomplete is likewise not promoted to GREEN. +A stale/conflicted owner PR is not silently force-rebased and is not closed merely +because a replacement exists. Reconstruction is acceptable only from the current +protected owner base with every still-valid decision/test/fixture/contract/evidence +delta carried forward and independently revalidated. `.github#2207` is therefore a +candidate successor to #2140, not yet proof that #2140 may close. + Valid findings are repaired in their canonical owner lane and consumed through released contracts/ACLs; domain truth is not copied across repositories. In particular, CO's explicit `concurrency_limit_exceeded` overload contract must not From f761b9dd7e54e71227091ab8de85bfedfec5f2f0 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 10:51:01 +0900 Subject: [PATCH 065/276] docs(gaps): refresh central review gate settlement --- docs/product-technical-gap-baseline.md | 28 +++++++++++++++++--------- 1 file changed, 19 insertions(+), 9 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index f766f849f..f90b6af81 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-15 09:53 KST. +> Current authority snapshot: 2026-09-15 10:50 KST. > > Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`; > the commit is signature-verified and no protected-main movement was observed in @@ -81,14 +81,24 @@ No LineageWeave release is admitted from the current protected head. prerequisite `.github#2170`, exact `c346b8324fa23e23d4007799d26ad3a8ac6ae4c3`, owns that dependency predicate and remains Ready/mergeable with Runtime Quality, SAST, Python Security, Security, - Noema, Strix, OpenCode bootstrap and CodeQL language detection GREEN plus a - current-head Noema APPROVED review. Its current CodeQL receivers are fail-closed - pending coordinator `104179015295`; latest `scan-pr-queue` `104154156265`, - `coverage-evidence` `104142936003` and `opencode-review` `104142935844` remain - nonterminal. Correct sequencing stays #2170 normal protected integration -> - ordinary/non-force #1629 reconciliation -> fresh #1629 acceptance. Final - provider admission/routing/TTC remains owned by released contextual-orchestrator, - not central CI or LineageWeave. + Noema, Strix, OpenCode bootstrap, `coverage-source-tree`, `coverage-evidence`, + latest `scan-pr-queue`, and CodeQL language detection GREEN plus a current-head + Noema APPROVED review. Its CodeQL Actions/Python compatibility receivers are + fail-closed and coordinator `104179015295` remains queued with no runner. + Required OpenCode `opencode-review` `104142935844` is terminal FAILURE after + dispatch succeeded because no authenticated exact-head OpenCode verdict existed; + the sibling coverage jobs are GREEN, so this is review publication/settlement + evidence rather than a coverage or #2170 source failure. Correct sequencing + stays #2170 normal protected integration -> ordinary/non-force #1629 + reconciliation -> fresh #1629 acceptance. Final provider + admission/routing/TTC remains owned by released contextual-orchestrator, not + central CI or LineageWeave. +- `.github#2207` remains a Draft reconstruction of stale/non-mergeable #2140 on + current protected `.github/main`; exact head is + `36a6755a5b699d8f43269805b6fccd5c5d75eae5`. Current-head + `required-workflow-bootstrap` `104210566507` and `admit-current-head` + `104210566437` remain queued and there is no submitted review, so complete + succession is not yet proven and #2140 must remain open. ## Buyer-visible gap register From f811085a7d5333ecc9372035c3c474ba2bbd40e1 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 11:48:53 +0900 Subject: [PATCH 066/276] docs(gaps): record canonical CodeQL dispatch progress --- docs/product-technical-gap-baseline.md | 45 +++++++++++++++++--------- 1 file changed, 30 insertions(+), 15 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index f90b6af81..38bc9dea5 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-15 10:50 KST. +> Current authority snapshot: 2026-09-15 11:49 KST. > > Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`; > the commit is signature-verified and no protected-main movement was observed in @@ -28,10 +28,17 @@ No LineageWeave release is admitted from the current protected head. receivers Python `104064547176`, JavaScript/TypeScript `104064547154`, and Actions `104064547137` are terminal FAIL-CLOSED after reading an absent current-head producer verdict; they are not product-analysis failures. The - coordinator `Dispatch current-head CodeQL scan` `104180256379` remains queued - with no runner. Canonical bootstrap/cutover ownership remains `.github#2106 -> - #2040`; LineageWeave must not manufacture a wake commit or duplicate that - control plane. + coordinator `Dispatch current-head CodeQL scan` `104180256379` has now run on a + hosted runner and completed GREEN after validating live head/base, binding all + three receiver job ids, obtaining GitHub OIDC plus the repository-scoped app + token, and dispatching the exact actions/javascript-typescript/python matrix. + Canonical producer run `.github` `34922377994` now exists for exact + LineageWeave #1079 and its `validate-dispatch` job `104233131441` is queued. + The current boundary is producer validation/execution, authenticated + `codeql-dispatch/` terminal verdict publication, and fresh + compatibility settlement. Canonical bootstrap/cutover ownership remains + `.github#2106 -> #2040`; LineageWeave must not manufacture a wake commit or + duplicate that control plane. - Required OpenCode coverage is partly terminal GREEN: `coverage-source-tree` `104070870386` and `coverage-evidence` `104070870162` succeeded on exact `c2923950e...`. `opencode-review` `104070870170` successfully dispatched a @@ -82,15 +89,17 @@ No LineageWeave release is admitted from the current protected head. `c346b8324fa23e23d4007799d26ad3a8ac6ae4c3`, owns that dependency predicate and remains Ready/mergeable with Runtime Quality, SAST, Python Security, Security, Noema, Strix, OpenCode bootstrap, `coverage-source-tree`, `coverage-evidence`, - latest `scan-pr-queue`, and CodeQL language detection GREEN plus a current-head - Noema APPROVED review. Its CodeQL Actions/Python compatibility receivers are - fail-closed and coordinator `104179015295` remains queued with no runner. - Required OpenCode `opencode-review` `104142935844` is terminal FAILURE after - dispatch succeeded because no authenticated exact-head OpenCode verdict existed; - the sibling coverage jobs are GREEN, so this is review publication/settlement - evidence rather than a coverage or #2170 source failure. Correct sequencing - stays #2170 normal protected integration -> ordinary/non-force #1629 - reconciliation -> fresh #1629 acceptance. Final provider + latest `scan-pr-queue`, CodeQL language detection, and CodeQL coordinator GREEN + plus a current-head Noema APPROVED review. Its coordinator `104179015295` + completed the exact current-head dispatch and created canonical producer run + `34921233636`; that run's `validate-dispatch` job `104229618015` is queued. + Actions/Python compatibility receivers remain prior fail-closed evidence until + producer verdict settlement. Required OpenCode `opencode-review` `104142935844` + is terminal FAILURE after dispatch succeeded because no authenticated exact-head + OpenCode verdict existed; the sibling coverage jobs are GREEN, so this is review + publication/settlement evidence rather than a coverage or #2170 source failure. + Correct sequencing stays #2170 normal protected integration -> ordinary/non-force + #1629 reconciliation -> fresh #1629 acceptance. Final provider admission/routing/TTC remains owned by released contextual-orchestrator, not central CI or LineageWeave. - `.github#2207` remains a Draft reconstruction of stale/non-mergeable #2140 on @@ -104,7 +113,7 @@ No LineageWeave release is admitted from the current protected head. | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | -| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Reader path is lookup/reuse-only; explicit admin retains mutation authority. Full PostgreSQL and authenticated PostgreSQL + Keycloak + Valkey materialization/fallback regressions, SAST and Required Security are GREEN. CodeRabbit full-diff review is clean. OpenCode coverage tree/evidence are GREEN. Strix produced zero SARIF findings but failed closed on CO saturation; Noema never reached a verdict because sidecar provisioning occupied the runner until cancellation. Canonical occupancy decision evidence is on `.github#2139`, with stale `.github#2140` reconstructed as current-main Draft `.github#2207`. | Finish current-head CodeQL producer/compatibility acceptance, obtain authenticated OpenCode verdict, repair/revalidate Strix and Noema through canonical owner lanes, prove the #2140 -> #2207 decision-record succession, obtain qualifying submitted approval, then normal protected merge. | +| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Reader path is lookup/reuse-only; explicit admin retains mutation authority. Full PostgreSQL and authenticated PostgreSQL + Keycloak + Valkey materialization/fallback regressions, SAST and Required Security are GREEN. CodeRabbit full-diff review is clean. OpenCode coverage tree/evidence are GREEN. Strix produced zero SARIF findings but failed closed on CO saturation; Noema never reached a verdict because sidecar provisioning occupied the runner until cancellation. CodeQL coordinator has completed the exact-head canonical dispatch; producer run `34922377994` is now queued at validation. Canonical occupancy decision evidence is on `.github#2139`, with stale `.github#2140` reconstructed as current-main Draft `.github#2207`. | Finish current-head CodeQL producer/compatibility acceptance, obtain authenticated OpenCode verdict, repair/revalidate Strix and Noema through canonical owner lanes, prove the #2140 -> #2207 decision-record succession, obtain qualifying submitted approval, then normal protected merge. | | Catalog connection leases and summary TOCTOU | #1077 and #1080 | Kept separate from #1079: provider work must not hold long DB leases; post-provider persistence must revalidate authorization/visibility and source revision. | Causal RED->GREEN in each owner lane, short-transaction evidence, current-head tests and protected integration. | | Governed UI translation delivery | #929 `f898399c5ff9ab89fe440d2e66985860e141620c` and child #932 | PostgreSQL-authoritative versioned ledger is implemented and repository tests are GREEN, but complete reviewed `ko/en/ja/zh/vi/es/de/fr` Customer Master publication is not demonstrated and central Security/CodeQL gates remain non-GREEN. | Complete eight-locale resource publication, authenticated API/browser normal/loading/empty/error/permission/responsive states, keyboard/focus/screen-reader, CJK/text expansion/font fallback and current security/governance receipts. | | MCP buyer-path latency | #1009 `4fff982a96b0ad6e791aa8c463925388d036f08f` | Modern/legacy protocol repair is Draft. Recorded modern submit/read and legacy read measurements remain far above the repository `p95 <= 20 ms` acceptance contract; CodeQL is also non-GREEN. | Representative uncontended cold/realistic measurements without sample removal or artificial warm-up, profile owned query/I/O/runtime bottlenecks, Rust-first hot-path repair where causal, then exact-head gates. | @@ -122,6 +131,12 @@ current-head producer has not yet materialized is fail-closed control-plane evidence, not a source-analysis failure. A clean SARIF/report from a review scan whose provider execution was incomplete is likewise not promoted to GREEN. +A successful dispatch coordinator proves only validated exact-head handoff to the +canonical producer. It does not transfer producer acceptance: the resulting +repository-dispatch run must validate its payload, execute the detected-language +matrix, publish authenticated terminal verdicts, and drive fresh receiver +settlement on the same exact consumer head before CodeQL is GREEN. + A stale/conflicted owner PR is not silently force-rebased and is not closed merely because a replacement exists. Reconstruction is acceptable only from the current protected owner base with every still-valid decision/test/fixture/contract/evidence From 51e687521ef1dd776effa99750b6870451389415 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 12:56:10 +0900 Subject: [PATCH 067/276] docs(gaps): record reconstructed comparison post repair --- docs/product-technical-gap-baseline.md | 20 +++++++++++++++++--- 1 file changed, 17 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 38bc9dea5..29880977e 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-15 11:49 KST. +> Current authority snapshot: 2026-09-15 12:55 KST. > > Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`; > the commit is signature-verified and no protected-main movement was observed in @@ -106,14 +106,28 @@ No LineageWeave release is admitted from the current protected head. current protected `.github/main`; exact head is `36a6755a5b699d8f43269805b6fccd5c5d75eae5`. Current-head `required-workflow-bootstrap` `104210566507` and `admit-current-head` - `104210566437` remain queued and there is no submitted review, so complete - succession is not yet proven and #2140 must remain open. + `104210566437` remain queued. A manual CodeRabbit full review has now been + triggered against exact protected base/head and is processing the two docs-only + changed files; there is still no submitted review, so complete succession is not + yet proven and #2140 must remain open. +- Draft #1034 has advanced from its intentional comparison-post coordinate RED to + exact `49d02bfc232a2979a57cdadcc7dc379042348c29`. The branch retains the realistic + contract in `tests/test_grouping_comparison_graphic_post_person_coordinate_contract.py` + and now carries the minimum production repair: `leftoverMapComparePlotPostBadge` + accepts only persisted finite person `ξ` coordinates, comparison post actions + have a distinct accessible name, invalid coordinates omit the coordinate, and + report post naming remains separate. No criterion `ζ`, geometry, distance, rank, + or measurement output is used to infer person coordinates. Fresh repository Tests + run `34926728363` has materialized on this exact head and both Frontend and Full + suite jobs are still pre-runner queued. A manual exact-head CodeRabbit full review + is also requested; no predecessor validation receipt transfers. ## Buyer-visible gap register | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | | Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Reader path is lookup/reuse-only; explicit admin retains mutation authority. Full PostgreSQL and authenticated PostgreSQL + Keycloak + Valkey materialization/fallback regressions, SAST and Required Security are GREEN. CodeRabbit full-diff review is clean. OpenCode coverage tree/evidence are GREEN. Strix produced zero SARIF findings but failed closed on CO saturation; Noema never reached a verdict because sidecar provisioning occupied the runner until cancellation. CodeQL coordinator has completed the exact-head canonical dispatch; producer run `34922377994` is now queued at validation. Canonical occupancy decision evidence is on `.github#2139`, with stale `.github#2140` reconstructed as current-main Draft `.github#2207`. | Finish current-head CodeQL producer/compatibility acceptance, obtain authenticated OpenCode verdict, repair/revalidate Strix and Noema through canonical owner lanes, prove the #2140 -> #2207 decision-record succession, obtain qualifying submitted approval, then normal protected merge. | +| Comparison leftover-map post-marker identity | #1034 `49d02bfc232a2979a57cdadcc7dc379042348c29` | The reconstructed realistic RED now has a minimal production implementation: comparison marker action text is derived only from persisted finite person axes through `leftoverMapComparePlotPostBadge`; report-marker action identity remains separate, and invalid person coordinates fail closed without borrowing criterion axes. Exact-head repository Tests and independent full review are newly materialized/requested and nonterminal. | Exact-head focused/static contract, frontend lint/tests/build, full repository/PostgreSQL validation, rendered keyboard/focus/a11y evidence, applicable Security/SAST/CodeQL/model review, qualifying approval, then ordinary parent-stack convergence/integration. | | Catalog connection leases and summary TOCTOU | #1077 and #1080 | Kept separate from #1079: provider work must not hold long DB leases; post-provider persistence must revalidate authorization/visibility and source revision. | Causal RED->GREEN in each owner lane, short-transaction evidence, current-head tests and protected integration. | | Governed UI translation delivery | #929 `f898399c5ff9ab89fe440d2e66985860e141620c` and child #932 | PostgreSQL-authoritative versioned ledger is implemented and repository tests are GREEN, but complete reviewed `ko/en/ja/zh/vi/es/de/fr` Customer Master publication is not demonstrated and central Security/CodeQL gates remain non-GREEN. | Complete eight-locale resource publication, authenticated API/browser normal/loading/empty/error/permission/responsive states, keyboard/focus/screen-reader, CJK/text expansion/font fallback and current security/governance receipts. | | MCP buyer-path latency | #1009 `4fff982a96b0ad6e791aa8c463925388d036f08f` | Modern/legacy protocol repair is Draft. Recorded modern submit/read and legacy read measurements remain far above the repository `p95 <= 20 ms` acceptance contract; CodeQL is also non-GREEN. | Representative uncontended cold/realistic measurements without sample removal or artificial warm-up, profile owned query/I/O/runtime bottlenecks, Rust-first hot-path repair where causal, then exact-head gates. | From 04c09198cae2b9642768d31dd61cc832b2086e0e Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 14:03:35 +0900 Subject: [PATCH 068/276] docs(gaps): record criterion coordinate stack convergence --- docs/product-technical-gap-baseline.md | 95 +++++++++++++++----------- 1 file changed, 56 insertions(+), 39 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 29880977e..ce65b6c65 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-15 12:55 KST. +> Current authority snapshot: 2026-09-15 13:48 KST. > > Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`; > the commit is signature-verified and no protected-main movement was observed in @@ -28,17 +28,16 @@ No LineageWeave release is admitted from the current protected head. receivers Python `104064547176`, JavaScript/TypeScript `104064547154`, and Actions `104064547137` are terminal FAIL-CLOSED after reading an absent current-head producer verdict; they are not product-analysis failures. The - coordinator `Dispatch current-head CodeQL scan` `104180256379` has now run on a - hosted runner and completed GREEN after validating live head/base, binding all - three receiver job ids, obtaining GitHub OIDC plus the repository-scoped app - token, and dispatching the exact actions/javascript-typescript/python matrix. - Canonical producer run `.github` `34922377994` now exists for exact - LineageWeave #1079 and its `validate-dispatch` job `104233131441` is queued. - The current boundary is producer validation/execution, authenticated - `codeql-dispatch/` terminal verdict publication, and fresh - compatibility settlement. Canonical bootstrap/cutover ownership remains - `.github#2106 -> #2040`; LineageWeave must not manufacture a wake commit or - duplicate that control plane. + coordinator `Dispatch current-head CodeQL scan` `104180256379` completed GREEN + after validating live head/base, binding all three receiver job ids, obtaining + GitHub OIDC plus the repository-scoped app token, and dispatching the exact + actions/javascript-typescript/python matrix. Canonical producer run `.github` + `34922377994` exists for exact LineageWeave #1079 and its `validate-dispatch` + job `104233131441` remains nonterminal. The current boundary is producer + validation/execution, authenticated `codeql-dispatch/` terminal + verdict publication, and fresh compatibility settlement. Canonical + bootstrap/cutover ownership remains `.github#2106 -> #2040`; LineageWeave must + not manufacture a wake commit or duplicate that control plane. - Required OpenCode coverage is partly terminal GREEN: `coverage-source-tree` `104070870386` and `coverage-evidence` `104070870162` succeeded on exact `c2923950e...`. `opencode-review` `104070870170` successfully dispatched a @@ -92,42 +91,54 @@ No LineageWeave release is admitted from the current protected head. latest `scan-pr-queue`, CodeQL language detection, and CodeQL coordinator GREEN plus a current-head Noema APPROVED review. Its coordinator `104179015295` completed the exact current-head dispatch and created canonical producer run - `34921233636`; that run's `validate-dispatch` job `104229618015` is queued. - Actions/Python compatibility receivers remain prior fail-closed evidence until - producer verdict settlement. Required OpenCode `opencode-review` `104142935844` - is terminal FAILURE after dispatch succeeded because no authenticated exact-head - OpenCode verdict existed; the sibling coverage jobs are GREEN, so this is review - publication/settlement evidence rather than a coverage or #2170 source failure. - Correct sequencing stays #2170 normal protected integration -> ordinary/non-force - #1629 reconciliation -> fresh #1629 acceptance. Final provider - admission/routing/TTC remains owned by released contextual-orchestrator, not - central CI or LineageWeave. + `34921233636`; that run's `validate-dispatch` job `104229618015` remains + nonterminal. Actions/Python compatibility receivers remain prior fail-closed + evidence until producer verdict settlement. Required OpenCode `opencode-review` + `104142935844` is terminal FAILURE after dispatch succeeded because no + authenticated exact-head OpenCode verdict existed; the sibling coverage jobs are + GREEN, so this is review publication/settlement evidence rather than a coverage + or #2170 source failure. Correct sequencing stays #2170 normal protected + integration -> ordinary/non-force #1629 reconciliation -> fresh #1629 + acceptance. Final provider admission/routing/TTC remains owned by released + contextual-orchestrator, not central CI or LineageWeave. - `.github#2207` remains a Draft reconstruction of stale/non-mergeable #2140 on current protected `.github/main`; exact head is `36a6755a5b699d8f43269805b6fccd5c5d75eae5`. Current-head `required-workflow-bootstrap` `104210566507` and `admit-current-head` - `104210566437` remain queued. A manual CodeRabbit full review has now been - triggered against exact protected base/head and is processing the two docs-only - changed files; there is still no submitted review, so complete succession is not - yet proven and #2140 must remain open. -- Draft #1034 has advanced from its intentional comparison-post coordinate RED to - exact `49d02bfc232a2979a57cdadcc7dc379042348c29`. The branch retains the realistic - contract in `tests/test_grouping_comparison_graphic_post_person_coordinate_contract.py` - and now carries the minimum production repair: `leftoverMapComparePlotPostBadge` - accepts only persisted finite person `ξ` coordinates, comparison post actions - have a distinct accessible name, invalid coordinates omit the coordinate, and - report post naming remains separate. No criterion `ζ`, geometry, distance, rank, - or measurement output is used to infer person coordinates. Fresh repository Tests - run `34926728363` has materialized on this exact head and both Frontend and Full - suite jobs are still pre-runner queued. A manual exact-head CodeRabbit full review - is also requested; no predecessor validation receipt transfers. + `104210566437` remain nonterminal. A manual CodeRabbit full review has been + triggered against exact protected base/head; complete succession is not yet + proven and #2140 must remain open. +- Draft #876 is now exact `d8b7f420bfb651f535c1b378b3d33ea71a6683a2`. + Its realistic report-criterion RED has a minimum production repair: + `leftoverMapPlotCriterionBadge` derives accessible criterion ζ only from the + marker's persisted item-axis pair via `formatLeftoverMapCoordinatePair`, + preserves finite zero coordinates, and fails closed to the generic criterion + name when the pair is unusable. Person ξ, geometry, distance, rank, coverage, + and neighboring evidence are not used to infer ζ. Exact-head Tests run + `34930586337` is newly materialized and nonterminal; an exact-head CodeRabbit + full-diff review is requested. No predecessor receipt transfers. +- Descendant Draft #1033 has been non-force converged onto repaired #876 and is + exact `1b3ce95e7b3850f4dd48ff883bc6c2da83319321`. Its own comparison-criterion + RED is also causally repaired: `leftoverMapComparePlotCriterionBadge` uses the + same persisted item-axis formatting boundary but a distinct comparison action, + while report criterion naming remains on the report helper. Exact-head Tests + run `34930915311` is nonterminal and an exact-head full-diff review is requested. +- Descendant Draft #1034 has been non-force converged onto repaired #1033 and is + exact `9aecd5559865885639f1c7c08cca77e8fd8a1581`. It preserves both inherited + criterion ζ repairs plus its local comparison-post ξ repair. Comparison post + actions derive ξ only from persisted finite person axes through + `leftoverMapComparePlotPostBadge`; invalid person coordinates fail closed to + the coordinate-omitted action and no criterion ζ or measurement output infers + ξ. Exact-head Tests run `34931115271` is newly materialized and nonterminal; + an exact-head full-diff review is requested. The stack remains Draft in order + #876 -> #1033 -> #1034 until current-head evidence settles. ## Buyer-visible gap register | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | -| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Reader path is lookup/reuse-only; explicit admin retains mutation authority. Full PostgreSQL and authenticated PostgreSQL + Keycloak + Valkey materialization/fallback regressions, SAST and Required Security are GREEN. CodeRabbit full-diff review is clean. OpenCode coverage tree/evidence are GREEN. Strix produced zero SARIF findings but failed closed on CO saturation; Noema never reached a verdict because sidecar provisioning occupied the runner until cancellation. CodeQL coordinator has completed the exact-head canonical dispatch; producer run `34922377994` is now queued at validation. Canonical occupancy decision evidence is on `.github#2139`, with stale `.github#2140` reconstructed as current-main Draft `.github#2207`. | Finish current-head CodeQL producer/compatibility acceptance, obtain authenticated OpenCode verdict, repair/revalidate Strix and Noema through canonical owner lanes, prove the #2140 -> #2207 decision-record succession, obtain qualifying submitted approval, then normal protected merge. | -| Comparison leftover-map post-marker identity | #1034 `49d02bfc232a2979a57cdadcc7dc379042348c29` | The reconstructed realistic RED now has a minimal production implementation: comparison marker action text is derived only from persisted finite person axes through `leftoverMapComparePlotPostBadge`; report-marker action identity remains separate, and invalid person coordinates fail closed without borrowing criterion axes. Exact-head repository Tests and independent full review are newly materialized/requested and nonterminal. | Exact-head focused/static contract, frontend lint/tests/build, full repository/PostgreSQL validation, rendered keyboard/focus/a11y evidence, applicable Security/SAST/CodeQL/model review, qualifying approval, then ordinary parent-stack convergence/integration. | +| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Reader path is lookup/reuse-only; explicit admin retains mutation authority. Full PostgreSQL and authenticated PostgreSQL + Keycloak + Valkey materialization/fallback regressions, SAST and Required Security are GREEN. CodeRabbit full-diff review is clean. OpenCode coverage tree/evidence are GREEN. Strix produced zero SARIF findings but failed closed on CO saturation; Noema never reached a verdict because sidecar provisioning occupied the runner until cancellation. CodeQL coordinator has completed the exact-head canonical dispatch; producer run `34922377994` is now at producer validation. Canonical occupancy decision evidence is on `.github#2139`, with stale `.github#2140` reconstructed as current-main Draft `.github#2207`. | Finish current-head CodeQL producer/compatibility acceptance, obtain authenticated OpenCode verdict, repair/revalidate Strix and Noema through canonical owner lanes, prove the #2140 -> #2207 decision-record succession, obtain qualifying submitted approval, then normal protected merge. | +| Report/comparison leftover-map marker identity | #876 `d8b7f420...` -> #1033 `1b3ce95...` -> #1034 `9aecd555...` | The report criterion ζ, comparison criterion ζ, and comparison post ξ contracts now each have minimum causal production implementations. ζ is derived only from persisted item axes; comparison ξ is derived only from persisted person axes; report/comparison accessible names remain distinct and invalid pairs fail closed without cross-axis inference. Descendants were converged non-force after each parent moved. Fresh exact-head Tests and independent full reviews are materialized/requested and nonterminal. | Settle exact-head focused/static contracts, frontend lint/tests/build, full repository/PostgreSQL validation, rendered keyboard/focus/a11y evidence, applicable Security/SAST/CodeQL/model review, qualifying approvals, then integrate in parent order without dropping descendant deltas. | | Catalog connection leases and summary TOCTOU | #1077 and #1080 | Kept separate from #1079: provider work must not hold long DB leases; post-provider persistence must revalidate authorization/visibility and source revision. | Causal RED->GREEN in each owner lane, short-transaction evidence, current-head tests and protected integration. | | Governed UI translation delivery | #929 `f898399c5ff9ab89fe440d2e66985860e141620c` and child #932 | PostgreSQL-authoritative versioned ledger is implemented and repository tests are GREEN, but complete reviewed `ko/en/ja/zh/vi/es/de/fr` Customer Master publication is not demonstrated and central Security/CodeQL gates remain non-GREEN. | Complete eight-locale resource publication, authenticated API/browser normal/loading/empty/error/permission/responsive states, keyboard/focus/screen-reader, CJK/text expansion/font fallback and current security/governance receipts. | | MCP buyer-path latency | #1009 `4fff982a96b0ad6e791aa8c463925388d036f08f` | Modern/legacy protocol repair is Draft. Recorded modern submit/read and legacy read measurements remain far above the repository `p95 <= 20 ms` acceptance contract; CodeQL is also non-GREEN. | Representative uncontended cold/realistic measurements without sample removal or artificial warm-up, profile owned query/I/O/runtime bottlenecks, Rust-first hot-path repair where causal, then exact-head gates. | @@ -151,6 +162,12 @@ repository-dispatch run must validate its payload, execute the detected-language matrix, publish authenticated terminal verdicts, and drive fresh receiver settlement on the same exact consumer head before CodeQL is GREEN. +A moved parent immediately invalidates descendant ancestry assumptions. Descendant +repair is non-force: read the intervening delta, preserve still-valid +contract/test/product evidence, then merge/reconstruct/retarget onto the moved +parent without rewriting shared history. Parent GREEN evidence never transfers to +that newly moved descendant head. + A stale/conflicted owner PR is not silently force-rebased and is not closed merely because a replacement exists. Reconstruction is acceptable only from the current protected owner base with every still-valid decision/test/fixture/contract/evidence From c01c94122d09320d38670d69db8595563343897d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 16:58:43 +0900 Subject: [PATCH 069/276] docs(gaps): record current leftover-map stack convergence --- docs/product-technical-gap-baseline.md | 306 +++++++++++-------------- 1 file changed, 133 insertions(+), 173 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index ce65b6c65..b70daa5de 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,190 +1,151 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-15 13:48 KST. +> Current authority snapshot: 2026-09-15. > -> Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`; -> the commit is signature-verified and no protected-main movement was observed in -> the fresh pre-write sweep. This document is a current projection of live -> PR/Issue/check authority, not a replacement for those sources. Historical -> overlays through 2026-09-13 are preserved byte-for-byte in +> Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`. +> This file is a current projection of live PR/Issue/check authority, not a +> substitute for those sources. Historical overlays through 2026-09-13 are +> preserved in > [`evidence/product-technical-gap-baseline-history-through-20260913.md`](evidence/product-technical-gap-baseline-history-through-20260913.md). -> When this snapshot and live GitHub state differ, live protected refs, PRs, -> Issues, ADRs and check receipts win. +> When this projection differs from live GitHub state, protected refs, PRs, +> Issues, ADRs and exact-head check receipts win. ## Protected delivery baseline No LineageWeave release is admitted from the current protected head. -- Summary shared-catalog authorization repair #1079 remains open and Ready at - exact `c2923950e73c88a9f9fd932332ddd47682da124b` on protected - `main@83eba56149eb802cd63642c507c324c9976ec78e`. Reader materialization is - fail-closed for shared-catalog enrichment; explicit `post_admin` retains the - canonical enrichment path. Exact-head Tests `34815479029` are GREEN: Frontend - `103885140448`, Full suite `103885140559`, and authenticated PostgreSQL + - Keycloak + Valkey Summary authorization integration `103885140632` all passed. - SAST `34815434313` and Required Security Scan `34815434486` are GREEN; changed- - source GHAS CodeQL, Trivy, Scorecard and Semgrep report no new alerts. -- Required CodeQL language detection `103965453105` is GREEN. Compatibility - receivers Python `104064547176`, JavaScript/TypeScript `104064547154`, and - Actions `104064547137` are terminal FAIL-CLOSED after reading an absent - current-head producer verdict; they are not product-analysis failures. The - coordinator `Dispatch current-head CodeQL scan` `104180256379` completed GREEN - after validating live head/base, binding all three receiver job ids, obtaining - GitHub OIDC plus the repository-scoped app token, and dispatching the exact - actions/javascript-typescript/python matrix. Canonical producer run `.github` - `34922377994` exists for exact LineageWeave #1079 and its `validate-dispatch` - job `104233131441` remains nonterminal. The current boundary is producer - validation/execution, authenticated `codeql-dispatch/` terminal - verdict publication, and fresh compatibility settlement. Canonical - bootstrap/cutover ownership remains `.github#2106 -> #2040`; LineageWeave must - not manufacture a wake commit or duplicate that control plane. -- Required OpenCode coverage is partly terminal GREEN: `coverage-source-tree` - `104070870386` and `coverage-evidence` `104070870162` succeeded on exact - `c2923950e...`. `opencode-review` `104070870170` successfully dispatched a - current-head request, then correctly failed because no authenticated - `opencode-agent` `APPROVED`/`CHANGES_REQUESTED` verdict had materialized on the - exact head. The central dispatch path owns the eventual verdict/rerun. -- Required Strix `103970045852` is terminal FAILURE but not a LineageWeave - security finding. Trusted-source validation, contextual-orchestrator sidecar - provisioning and Strix installation succeeded. Artifact `strix-reports` - `10371857268` (digest - `sha256:b0d69ccbdf5b4fa52c99e118a9d76e6d4251d34d7deb9341131b9ce8270dd13b`) - contains a terminal report/SARIF with zero findings, while concurrent sub-agent - requests received explicit CO `503 concurrency_limit_exceeded` / `too many - concurrent orchestration runs`. The Strix gate correctly refused to promote a - partial provider execution to GREEN. CO deliberately rejects saturated inference - rather than queueing it; the repair therefore belongs to canonical review-runtime - admission/backpressure, not to a leaf provider/model override or gate weakening. - Fresh consumer evidence remains on `.github#2139`. The decision-record lane - `.github#2140` was found stale/non-mergeable against current protected `.github` - `main@91be6442906c7b6b4f600272c953699708394327`; current-main reconstruction - `.github#2207` now carries the same ADR blob (`1c133061cccb6bca9c3552cb8bdbca43b17d19f1`) - plus the original changelog evidence via the repository's existing `CHANGELOG.d/` - convention. #2140 remains open/Draft until complete succession is proved. -- Required Noema `103965387845` is terminal CANCELLED and likewise is not a - product finding. Exact-head admission, credential selection, GitHub App token, - current-head validation and visibility checks succeeded. `Provision contextual- - orchestrator review sidecar` started at `2026-09-14T16:50:39Z`, logged the - sidecar starting at `16:52:41Z`, never emitted readiness, and GitHub cancelled - the operation at `22:51:33Z` after about six hours; no model-verdict step ran. - This is startup/provisioning occupancy evidence, not an elapsed-model-time - verdict. `.github#1629` retains sidecar admission/preflight ownership and - `.github#2139` retains progress/idle/runner-reclamation evidence. Proposed - ADR-0030 authority is being reconstructed on current protected `.github` main - in Draft `.github#2207`; no total elapsed model deadline is introduced. -- CodeRabbit completed an independent full protected-base-to-exact-head review of - all 13 changed files with no actionable comments and `Merge Risk: Minimal`; both - inline threads are resolved. This is positive independent review coverage but - not a submitted qualifying `APPROVED` review. -- Canonical organization queue observation remains owned by - `ContextualWisdomLab/.github#1150` with LineageWeave enrollment child - `.github#2200`; LineageWeave does not copy queue policy or runner controls. -- Review-sidecar admission/preflight remains owned by `.github#1629`, exact - `db3d648c905d283f03fc16fbc9891ba76edd56b8`, on `.github` protected - `main@91be6442906c7b6b4f600272c953699708394327`. Its provider-default source - contract is repaired but its exact-head Runtime Quality RED is blocked by the - missing Noema document dependency during review-repair collection. Canonical - prerequisite `.github#2170`, exact - `c346b8324fa23e23d4007799d26ad3a8ac6ae4c3`, owns that dependency predicate and - remains Ready/mergeable with Runtime Quality, SAST, Python Security, Security, - Noema, Strix, OpenCode bootstrap, `coverage-source-tree`, `coverage-evidence`, - latest `scan-pr-queue`, CodeQL language detection, and CodeQL coordinator GREEN - plus a current-head Noema APPROVED review. Its coordinator `104179015295` - completed the exact current-head dispatch and created canonical producer run - `34921233636`; that run's `validate-dispatch` job `104229618015` remains - nonterminal. Actions/Python compatibility receivers remain prior fail-closed - evidence until producer verdict settlement. Required OpenCode `opencode-review` - `104142935844` is terminal FAILURE after dispatch succeeded because no - authenticated exact-head OpenCode verdict existed; the sibling coverage jobs are - GREEN, so this is review publication/settlement evidence rather than a coverage - or #2170 source failure. Correct sequencing stays #2170 normal protected - integration -> ordinary/non-force #1629 reconciliation -> fresh #1629 - acceptance. Final provider admission/routing/TTC remains owned by released - contextual-orchestrator, not central CI or LineageWeave. -- `.github#2207` remains a Draft reconstruction of stale/non-mergeable #2140 on - current protected `.github/main`; exact head is - `36a6755a5b699d8f43269805b6fccd5c5d75eae5`. Current-head - `required-workflow-bootstrap` `104210566507` and `admit-current-head` - `104210566437` remain nonterminal. A manual CodeRabbit full review has been - triggered against exact protected base/head; complete succession is not yet - proven and #2140 must remain open. -- Draft #876 is now exact `d8b7f420bfb651f535c1b378b3d33ea71a6683a2`. - Its realistic report-criterion RED has a minimum production repair: - `leftoverMapPlotCriterionBadge` derives accessible criterion ζ only from the - marker's persisted item-axis pair via `formatLeftoverMapCoordinatePair`, - preserves finite zero coordinates, and fails closed to the generic criterion - name when the pair is unusable. Person ξ, geometry, distance, rank, coverage, - and neighboring evidence are not used to infer ζ. Exact-head Tests run - `34930586337` is newly materialized and nonterminal; an exact-head CodeRabbit - full-diff review is requested. No predecessor receipt transfers. -- Descendant Draft #1033 has been non-force converged onto repaired #876 and is - exact `1b3ce95e7b3850f4dd48ff883bc6c2da83319321`. Its own comparison-criterion - RED is also causally repaired: `leftoverMapComparePlotCriterionBadge` uses the - same persisted item-axis formatting boundary but a distinct comparison action, - while report criterion naming remains on the report helper. Exact-head Tests - run `34930915311` is nonterminal and an exact-head full-diff review is requested. -- Descendant Draft #1034 has been non-force converged onto repaired #1033 and is - exact `9aecd5559865885639f1c7c08cca77e8fd8a1581`. It preserves both inherited - criterion ζ repairs plus its local comparison-post ξ repair. Comparison post - actions derive ξ only from persisted finite person axes through - `leftoverMapComparePlotPostBadge`; invalid person coordinates fail closed to - the coordinate-omitted action and no criterion ζ or measurement output infers - ξ. Exact-head Tests run `34931115271` is newly materialized and nonterminal; - an exact-head full-diff review is requested. The stack remains Draft in order - #876 -> #1033 -> #1034 until current-head evidence settles. +### Summary shared-catalog authorization + +#1079 remains open, Ready and mechanically mergeable at exact +`c2923950e73c88a9f9fd932332ddd47682da124b` on protected +`main@83eba56149eb802cd63642c507c324c9976ec78e`. Reader materialization is +fail-closed for shared Customer Master catalog enrichment and explicit +`post_admin` retains the canonical create/upsert path. Exact-head repository, +authenticated PostgreSQL + Keycloak + Valkey integration, SAST and Required +Security evidence are GREEN. CodeRabbit's protected-base-to-head full-diff +review reported no actionable findings, but that is not a submitted qualifying +`APPROVED` review. + +Required CodeQL remains fail-closed, not source-failed. Compatibility receivers +failed after finding no authenticated current-head producer verdict. Coordinator +`104180256379` completed the exact consumer-head dispatch successfully and created +canonical `.github` producer run `34922377994`; that producer is still queued at +the current sweep. Producer validation/execution, authenticated terminal verdict +publication and fresh compatibility settlement remain required. The CodeQL +control plane stays owned by the canonical `.github` lane. + +OpenCode source-tree and coverage evidence are GREEN, while `opencode-review` +failed closed because no authenticated exact-head review verdict had materialized. +Strix produced zero findings but correctly failed closed after contextual- +orchestrator rejected concurrent sub-agent work with explicit +`concurrency_limit_exceeded`; incomplete provider execution is not GREEN. Noema +never reached a model verdict because contextual-orchestrator sidecar provisioning +occupied the runner until cancellation. These are canonical review-runtime / +provider-admission problems, not authorization-source findings in LineageWeave. + +Foundation prerequisite `.github#2170` remains open/Ready/mergeable at exact +`c346b8324fa23e23d4007799d26ad3a8ac6ae4c3` on protected +`.github/main@91be6442906c7b6b4f600272c953699708394327`. Runtime Quality, SAST, +Python Security, Security, Noema, Strix, OpenCode bootstrap, OpenCode source-tree +and coverage evidence, latest queue scan, CodeQL language detection and the +CodeQL coordinator are GREEN, and a current-head Noema `APPROVED` review exists. +Canonical producer run `34921233636` is still at producer validation; OpenCode +review publication is also unsettled. Required ordering therefore remains +`.github#2170` normal protected integration -> ordinary/non-force `.github#1629` +reconciliation -> fresh #1629 acceptance. LineageWeave must not copy dependency +predicates, queue policy, provider/model routing, fallback or timeout semantics. + +The stale `.github#2140` decision-record lane remains open while current-main Draft +successor `.github#2207` is independently revalidated. A replacement branch is +not complete succession by itself. + +### Leftover-map identity and evidence stack + +Parent #875 moved to exact +`b220dcb8d73f6bdc926c5d8cb1ae3f47df05100c` on current #874 +`2b49e327b02a2b9f8b1449ae4b5a68648849e227`. The moved parent was not treated +as a race or rewritten. Direct children were read, their local deltas preserved, +and their ancestry converged through ordinary non-force two-parent commits. + +#876 is now exact `2c12c30b54ca1cbb74a9ec8829dcb68314ccee6d` on current #875. +Semantic convergence PR #1081 was normally recognized as merged at that commit; +it was not simply closed. The branch preserves the report-criterion ζ contract: +`leftoverMapPlotCriterionBadge` consumes only persisted finite item axes, keeps +finite zero coordinates, fails closed for unusable pairs and does not infer ζ +from person ξ, geometry, distance, rank, coverage or neighboring evidence. It +also inherits #875's independent persisted comparison-axis singular evidence. +Fresh exact-head Tests run `34943676800` is queued. Predecessor validation does +not transfer. + +#1033 is now exact `d69b339f71a5a3bca9fb84aae663e2aae0eda739` on current #876. +It preserves the report criterion boundary and adds the distinct comparison- +criterion ζ boundary through `leftoverMapComparePlotCriterionBadge`, again using +only persisted item axes. Comparison naming composes existing localized labels; +no competing static translation authority is introduced. Fresh exact-head Tests +run `34943827063` is queued. Historical #878 remains open as a delta carrier +until complete verified succession is demonstrated. + +#1034 is now exact `4078f769dde0b4503325d37d61761967f137482e` on current #1033. +It preserves both criterion ζ boundaries and its comparison-post ξ repair. +`leftoverMapComparePlotPostBadge` consumes persisted finite person axes only; +criterion ζ, singular evidence, geometry, distance, rank and coverage do not +infer ξ. Fresh exact-head Tests run `34943967157` is queued. No open PR directly +targeted the #1034 branch in the current sweep. Historical #879 remains open until +complete verified succession is demonstrated. + +Sibling #877 is now exact `cbb28027cfe0ea72651cb5bb03d809801ecc8068` on current #875. +Its one-file executable comparison-origin-tick RED was deliberately preserved +while ancestry converged. Fresh exact-head Tests run `34944016757` is queued. +The branch stays Draft until the local RED has a causal source repair and fresh +acceptance; ancestry movement is not permission to manufacture GREEN evidence. + +The product stack therefore remains Draft and ordered. #876 -> #1033 -> #1034 +must settle current-head evidence before promotion, while #877 follows its own +sibling lane. No descendant inherits parent or predecessor validation receipts. ## Buyer-visible gap register | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | -| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Reader path is lookup/reuse-only; explicit admin retains mutation authority. Full PostgreSQL and authenticated PostgreSQL + Keycloak + Valkey materialization/fallback regressions, SAST and Required Security are GREEN. CodeRabbit full-diff review is clean. OpenCode coverage tree/evidence are GREEN. Strix produced zero SARIF findings but failed closed on CO saturation; Noema never reached a verdict because sidecar provisioning occupied the runner until cancellation. CodeQL coordinator has completed the exact-head canonical dispatch; producer run `34922377994` is now at producer validation. Canonical occupancy decision evidence is on `.github#2139`, with stale `.github#2140` reconstructed as current-main Draft `.github#2207`. | Finish current-head CodeQL producer/compatibility acceptance, obtain authenticated OpenCode verdict, repair/revalidate Strix and Noema through canonical owner lanes, prove the #2140 -> #2207 decision-record succession, obtain qualifying submitted approval, then normal protected merge. | -| Report/comparison leftover-map marker identity | #876 `d8b7f420...` -> #1033 `1b3ce95...` -> #1034 `9aecd555...` | The report criterion ζ, comparison criterion ζ, and comparison post ξ contracts now each have minimum causal production implementations. ζ is derived only from persisted item axes; comparison ξ is derived only from persisted person axes; report/comparison accessible names remain distinct and invalid pairs fail closed without cross-axis inference. Descendants were converged non-force after each parent moved. Fresh exact-head Tests and independent full reviews are materialized/requested and nonterminal. | Settle exact-head focused/static contracts, frontend lint/tests/build, full repository/PostgreSQL validation, rendered keyboard/focus/a11y evidence, applicable Security/SAST/CodeQL/model review, qualifying approvals, then integrate in parent order without dropping descendant deltas. | -| Catalog connection leases and summary TOCTOU | #1077 and #1080 | Kept separate from #1079: provider work must not hold long DB leases; post-provider persistence must revalidate authorization/visibility and source revision. | Causal RED->GREEN in each owner lane, short-transaction evidence, current-head tests and protected integration. | -| Governed UI translation delivery | #929 `f898399c5ff9ab89fe440d2e66985860e141620c` and child #932 | PostgreSQL-authoritative versioned ledger is implemented and repository tests are GREEN, but complete reviewed `ko/en/ja/zh/vi/es/de/fr` Customer Master publication is not demonstrated and central Security/CodeQL gates remain non-GREEN. | Complete eight-locale resource publication, authenticated API/browser normal/loading/empty/error/permission/responsive states, keyboard/focus/screen-reader, CJK/text expansion/font fallback and current security/governance receipts. | -| MCP buyer-path latency | #1009 `4fff982a96b0ad6e791aa8c463925388d036f08f` | Modern/legacy protocol repair is Draft. Recorded modern submit/read and legacy read measurements remain far above the repository `p95 <= 20 ms` acceptance contract; CodeQL is also non-GREEN. | Representative uncontended cold/realistic measurements without sample removal or artificial warm-up, profile owned query/I/O/runtime bottlenecks, Rust-first hot-path repair where causal, then exact-head gates. | -| Release identity and immutable publication | #961 `3bdec0504a65e63f44bd49ba15de37182a1672cc` / #1056 | Candidate aligns runtime/package/frontend at 2.28.0 and has repository/Security/SAST GREEN, but Required CodeQL and independent review remain incomplete. Protected main still carries the pre-repair runtime identity. | Built/installed version proof, normal protected merge, immutable tag/package/release, SBOM/provenance, reproducibility and rollback evidence bound to one exact protected SHA. | -| Material Customer Master / lineage UI | #929/#932 plus the live Customer Master and lineage presentation owner PRs | Translation authority, authorization repairs, responsive/a11y states and browser evidence are distributed across their existing owner lanes; no competing inline translation or authorization implementation is permitted. | Converged owner prerequisites plus current-head normal/loading/empty/error/permission/responsive, pointer/touch/keyboard/focus/screen-reader, deterministic identity/layout and applicable performance evidence. | +| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Authorization repair and repository/security tests are GREEN; independent full-diff review is clean. CodeQL producer, OpenCode verdict, Strix/Noema complete review evidence and qualifying approval remain unsettled. | Finish canonical current-head CodeQL settlement, authenticated OpenCode verdict, Strix/Noema owner-path repair/revalidation, qualifying approval and normal protected merge. | +| Report/comparison leftover-map marker identity | #876 `2c12c30...` -> #1033 `d69b339...` -> #1034 `4078f769...` | Report criterion ζ, comparison criterion ζ and comparison post ξ causal implementations are preserved after current-parent non-force convergence. Fresh exact-head Tests are newly queued; historical #878/#879 carriers remain open. | Settle focused/static contracts, frontend lint/tests/build, full repository/PostgreSQL validation, rendered keyboard/focus/a11y evidence, applicable Security/SAST/CodeQL/model review and qualifying approvals; integrate in parent order. | +| Comparison origin tick identity | #877 `cbb28027...` | Current #875 ancestry is converged while the executable origin-tick contract remains intentional RED. | Implement the minimum causal source repair, prove exact-head RED -> GREEN, then complete the ordinary security/browser/review gates. | +| Catalog connection leases and summary TOCTOU | #1077 and #1080 | Kept separate from #1079; external/provider work must not hold long database leases and post-provider persistence must revalidate authorization/visibility/source revision. | Causal RED -> GREEN in each owner lane, short-transaction evidence, current-head tests and protected integration. | +| Governed UI translation delivery | #929 and child #932 | Governed versioned translation-ledger work remains in its canonical owner lane; the leftover-map stack consumes existing localized labels instead of adding a competing store. | Complete reviewed `ko/en/ja/zh/vi/es/de/fr` resources and rendered normal/loading/empty/error/permission/responsive, keyboard/focus/screen-reader, CJK expansion and font-fallback evidence. | +| MCP buyer-path latency | #1009 | Existing measurements remain above the repository `p95 <= 20 ms` acceptance contract. | Representative uncontended measurements, causal query/I/O/runtime profiling, Rust-first hot-path repair where warranted and exact-head gates. | +| Release identity and immutable publication | #961 / #1056 | Candidate release identity work remains Draft; protected main is not release-ready. | Built/installed version proof, normal protected merge, immutable tag/package/release, SBOM/provenance, reproducibility and rollback evidence on one protected SHA. | ## Evidence and ownership rules -A queued, skipped, COMMENTED, rate-limited, status-only, predecessor-head or -source-neutral result is not GREEN evidence for a moved current head. An exact-head -full-diff review with no actionable findings is positive independent review -coverage, but it is not equivalent to a submitted `APPROVED` review when approval -is an explicit merge gate. A compatibility receiver that fails because its -current-head producer has not yet materialized is fail-closed control-plane -evidence, not a source-analysis failure. A clean SARIF/report from a review scan -whose provider execution was incomplete is likewise not promoted to GREEN. - -A successful dispatch coordinator proves only validated exact-head handoff to the -canonical producer. It does not transfer producer acceptance: the resulting -repository-dispatch run must validate its payload, execute the detected-language -matrix, publish authenticated terminal verdicts, and drive fresh receiver -settlement on the same exact consumer head before CodeQL is GREEN. - -A moved parent immediately invalidates descendant ancestry assumptions. Descendant -repair is non-force: read the intervening delta, preserve still-valid -contract/test/product evidence, then merge/reconstruct/retarget onto the moved -parent without rewriting shared history. Parent GREEN evidence never transfers to -that newly moved descendant head. - -A stale/conflicted owner PR is not silently force-rebased and is not closed merely -because a replacement exists. Reconstruction is acceptable only from the current -protected owner base with every still-valid decision/test/fixture/contract/evidence -delta carried forward and independently revalidated. `.github#2207` is therefore a -candidate successor to #2140, not yet proof that #2140 may close. - -Valid findings are repaired in their canonical owner lane and consumed through -released contracts/ACLs; domain truth is not copied across repositories. In -particular, CO's explicit `concurrency_limit_exceeded` overload contract must not -be weakened from a LineageWeave leaf. Review callers must respect the released -capacity/admission boundary, while progress/idle/runner-reclamation semantics stay -separate from total model elapsed time. - -For database paths, external/model work must execute outside long-lived explicit +Queued, skipped, COMMENTED, rate-limited, status-only, predecessor-head or source- +neutral results are not GREEN evidence for a moved head. An exact-head full-diff +review with no actionable finding is positive independent review coverage but is +not equivalent to a submitted `APPROVED` review when approval is a gate. + +A successful dispatch coordinator proves only exact-head handoff to the canonical +producer. It does not transfer producer acceptance. The producer must validate +its payload, execute the detected-language matrix, publish authenticated terminal +verdicts and drive fresh consumer settlement on the same exact head. + +A moved parent invalidates descendant ancestry assumptions immediately. Repair is +non-force: inspect the intervening delta, preserve valid contract/test/product +evidence, then merge/reconstruct/retarget onto the moved parent without rewriting +shared history. Parent GREEN evidence does not transfer to the resulting descendant. + +A stale or conflicted PR is not force-rebased or closed merely because a successor +exists. Closure requires complete verified succession of every valid product, +test, fixture, contract and evidence delta, or another explicitly allowed close +condition. + +Canonical domain truth stays with its owner. LineageWeave consumes released +contracts/ACLs and does not copy contextual-orchestrator admission/routing, +central CI queue policy, psychometrics implementations, ranking, scheduling or +other owner functionality. + +For database paths, external/model work occurs outside long-lived explicit transactions and locks. Persistence reacquires the shortest necessary lease, -revalidates authorization/version state, and uses idempotent/UPSERT semantics -where the domain contract requires them. +revalidates authorization/version state and uses idempotent/UPSERT semantics when +the domain contract requires them. For material UI, repository/unit evidence does not replace rendered buyer-path acceptance. Normal/loading/empty/error/permission/responsive behavior, @@ -193,9 +154,8 @@ applicable p95 evidence remain part of release acceptance. ## Historical evidence -The former append-only baseline, including every dated overlay through -2026-09-13 20:27 KST, is preserved unchanged at +The former append-only baseline, including dated overlays through 2026-09-13, is +preserved unchanged at [`docs/evidence/product-technical-gap-baseline-history-through-20260913.md`](evidence/product-technical-gap-baseline-history-through-20260913.md). It is provenance, not current authority. Future refreshes should update this -current projection and preserve superseded snapshots without presenting old -runtime/check state as live. +projection rather than presenting superseded runtime/check state as live. From cf5454a8dce6d83183cfbeb12a36cea42051cf3f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 17:59:41 +0900 Subject: [PATCH 070/276] docs(gaps): record non-force leftover-map convergence --- docs/product-technical-gap-baseline.md | 78 +++++++++++++------------- 1 file changed, 39 insertions(+), 39 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b70daa5de..80df8c032 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -61,43 +61,43 @@ not complete succession by itself. ### Leftover-map identity and evidence stack -Parent #875 moved to exact -`b220dcb8d73f6bdc926c5d8cb1ae3f47df05100c` on current #874 -`2b49e327b02a2b9f8b1449ae4b5a68648849e227`. The moved parent was not treated -as a race or rewritten. Direct children were read, their local deltas preserved, -and their ancestry converged through ordinary non-force two-parent commits. - -#876 is now exact `2c12c30b54ca1cbb74a9ec8829dcb68314ccee6d` on current #875. -Semantic convergence PR #1081 was normally recognized as merged at that commit; -it was not simply closed. The branch preserves the report-criterion ζ contract: -`leftoverMapPlotCriterionBadge` consumes only persisted finite item axes, keeps -finite zero coordinates, fails closed for unusable pairs and does not infer ζ -from person ξ, geometry, distance, rank, coverage or neighboring evidence. It -also inherits #875's independent persisted comparison-axis singular evidence. -Fresh exact-head Tests run `34943676800` is queued. Predecessor validation does -not transfer. - -#1033 is now exact `d69b339f71a5a3bca9fb84aae663e2aae0eda739` on current #876. -It preserves the report criterion boundary and adds the distinct comparison- -criterion ζ boundary through `leftoverMapComparePlotCriterionBadge`, again using -only persisted item axes. Comparison naming composes existing localized labels; -no competing static translation authority is introduced. Fresh exact-head Tests -run `34943827063` is queued. Historical #878 remains open as a delta carrier -until complete verified succession is demonstrated. - -#1034 is now exact `4078f769dde0b4503325d37d61761967f137482e` on current #1033. -It preserves both criterion ζ boundaries and its comparison-post ξ repair. -`leftoverMapComparePlotPostBadge` consumes persisted finite person axes only; -criterion ζ, singular evidence, geometry, distance, rank and coverage do not -infer ξ. Fresh exact-head Tests run `34943967157` is queued. No open PR directly -targeted the #1034 branch in the current sweep. Historical #879 remains open until -complete verified succession is demonstrated. - -Sibling #877 is now exact `cbb28027cfe0ea72651cb5bb03d809801ecc8068` on current #875. -Its one-file executable comparison-origin-tick RED was deliberately preserved -while ancestry converged. Fresh exact-head Tests run `34944016757` is queued. -The branch stays Draft until the local RED has a causal source repair and fresh -acceptance; ancestry movement is not permission to manufacture GREEN evidence. +Parent #875 is exact `9303d67219071d76b59d4b85a49dac11023dcab1` on its current +base `eb051da92758e7bf84138e034b2049868c0fb487`. Its moved ancestry was read and +adopted without force-push or destructive rebase. Latest Tests attempts on this +exact head include queued run `34947735003`; newer Draft-policy attempts were +skipped and therefore are not GREEN evidence. + +#876 is exact `f461f5023cdd658b4b37813a8bb3df6ee06dde72` on current #875. +It preserves the report-criterion ζ contract: `leftoverMapPlotCriterionBadge` +consumes only persisted finite item axes, keeps finite zero coordinates, fails +closed for unusable pairs and does not infer ζ from person ξ, geometry, distance, +rank, coverage or neighboring evidence. Current-head Tests run `34947822715` +remains queued; newer Draft-policy run `34949321710` was skipped. Predecessor +validation does not transfer. + +#1033 is now exact `84b927f37471e3969f071520875eb40e5576877c` on current #876. +A semantic two-parent, non-force merge adopted the moved #876 ancestry while +preserving only the intended three-file comparison-criterion delta. Convergence +PR #1084 is normally recognized as merged at this exact commit. The comparison +ζ helper consumes only persisted finite item axes and keeps report criterion +behavior separate. Fresh exact-head Tests run `34949322503` is queued; no prior +receipt transfers. + +#1034 is now exact `708e435d4c975696f4f78a5e9b81969b5895f31e` on current #1033. +A second semantic two-parent, non-force merge preserved the comparison-post ξ +delta while adopting the converged report/comparison criterion and singular-axis +foundation. `leftoverMapComparePlotPostBadge` consumes persisted finite person axes +only; criterion ζ, singular/share evidence, geometry, distance, rank and coverage +do not infer ξ. Fresh exact-head Tests run `34949510341` is queued. Historical +#879 remains open until complete verified succession is demonstrated. + +Sibling #877 is now exact `73f8bf898a8eafc162850dae0b8dbc4955760fdb` on current #875. +A semantic two-parent, non-force merge adopted current #875 while preserving the +three-file comparison-origin-tick repair. Convergence PR #1083 is normally +recognized as merged at this exact commit. Origin identity is exact canonical +formatted zero; share and σ are projected independently and never define origin. +Fresh exact-head Tests run `34949897498` is queued. The branch remains Draft until +its current-head rendered and repository evidence settles. The product stack therefore remains Draft and ordered. #876 -> #1033 -> #1034 must settle current-head evidence before promotion, while #877 follows its own @@ -108,8 +108,8 @@ sibling lane. No descendant inherits parent or predecessor validation receipts. | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | | Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Authorization repair and repository/security tests are GREEN; independent full-diff review is clean. CodeQL producer, OpenCode verdict, Strix/Noema complete review evidence and qualifying approval remain unsettled. | Finish canonical current-head CodeQL settlement, authenticated OpenCode verdict, Strix/Noema owner-path repair/revalidation, qualifying approval and normal protected merge. | -| Report/comparison leftover-map marker identity | #876 `2c12c30...` -> #1033 `d69b339...` -> #1034 `4078f769...` | Report criterion ζ, comparison criterion ζ and comparison post ξ causal implementations are preserved after current-parent non-force convergence. Fresh exact-head Tests are newly queued; historical #878/#879 carriers remain open. | Settle focused/static contracts, frontend lint/tests/build, full repository/PostgreSQL validation, rendered keyboard/focus/a11y evidence, applicable Security/SAST/CodeQL/model review and qualifying approvals; integrate in parent order. | -| Comparison origin tick identity | #877 `cbb28027...` | Current #875 ancestry is converged while the executable origin-tick contract remains intentional RED. | Implement the minimum causal source repair, prove exact-head RED -> GREEN, then complete the ordinary security/browser/review gates. | +| Report/comparison leftover-map marker identity | #876 `f461f502...` -> #1033 `84b927f3...` -> #1034 `708e435d...` | Report criterion ζ, comparison criterion ζ and comparison post ξ causal implementations are preserved after semantic current-parent non-force convergence. Fresh exact-head Tests are queued; historical #878/#879 carriers remain open. | Settle focused/static contracts, frontend lint/tests/build, full repository/PostgreSQL validation, rendered keyboard/focus/a11y evidence, applicable Security/SAST/CodeQL/model review and qualifying approvals; integrate in parent order. | +| Comparison origin tick identity | #877 `73f8bf89...` | Causal production repair is preserved after semantic convergence onto current #875. Exact formatted zero defines origin; share and σ remain independent. Fresh Tests `34949897498` is queued. | Prove current-head executable contract and frontend build/tests, rendered keyboard/focus/a11y/i18n evidence, applicable security/model review and qualifying approval before promotion. | | Catalog connection leases and summary TOCTOU | #1077 and #1080 | Kept separate from #1079; external/provider work must not hold long database leases and post-provider persistence must revalidate authorization/visibility/source revision. | Causal RED -> GREEN in each owner lane, short-transaction evidence, current-head tests and protected integration. | | Governed UI translation delivery | #929 and child #932 | Governed versioned translation-ledger work remains in its canonical owner lane; the leftover-map stack consumes existing localized labels instead of adding a competing store. | Complete reviewed `ko/en/ja/zh/vi/es/de/fr` resources and rendered normal/loading/empty/error/permission/responsive, keyboard/focus/screen-reader, CJK expansion and font-fallback evidence. | | MCP buyer-path latency | #1009 | Existing measurements remain above the repository `p95 <= 20 ms` acceptance contract. | Representative uncontended measurements, causal query/I/O/runtime profiling, Rust-first hot-path repair where warranted and exact-head gates. | From f999eef7e176cada9e6a072d818477957df06c93 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 19:04:16 +0900 Subject: [PATCH 071/276] docs(gaps): record comparison-axis repair and stack convergence --- docs/product-technical-gap-baseline.md | 206 +++++++++++-------------- 1 file changed, 88 insertions(+), 118 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 80df8c032..11f11ff22 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,14 +1,12 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-15. +> Current authority snapshot: 2026-09-15 19:04 KST. > -> Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e`. -> This file is a current projection of live PR/Issue/check authority, not a -> substitute for those sources. Historical overlays through 2026-09-13 are -> preserved in +> Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e` at this projection. +> This file summarizes live PR/Issue/check authority; protected refs, PRs, Issues, +> ADRs and exact-head receipts remain authoritative. Historical overlays through +> 2026-09-13 are preserved in > [`evidence/product-technical-gap-baseline-history-through-20260913.md`](evidence/product-technical-gap-baseline-history-through-20260913.md). -> When this projection differs from live GitHub state, protected refs, PRs, -> Issues, ADRs and exact-head check receipts win. ## Protected delivery baseline @@ -16,121 +14,96 @@ No LineageWeave release is admitted from the current protected head. ### Summary shared-catalog authorization -#1079 remains open, Ready and mechanically mergeable at exact +#1079 remains open and Ready at exact `c2923950e73c88a9f9fd932332ddd47682da124b` on protected -`main@83eba56149eb802cd63642c507c324c9976ec78e`. Reader materialization is -fail-closed for shared Customer Master catalog enrichment and explicit -`post_admin` retains the canonical create/upsert path. Exact-head repository, -authenticated PostgreSQL + Keycloak + Valkey integration, SAST and Required -Security evidence are GREEN. CodeRabbit's protected-base-to-head full-diff -review reported no actionable findings, but that is not a submitted qualifying -`APPROVED` review. - -Required CodeQL remains fail-closed, not source-failed. Compatibility receivers -failed after finding no authenticated current-head producer verdict. Coordinator -`104180256379` completed the exact consumer-head dispatch successfully and created -canonical `.github` producer run `34922377994`; that producer is still queued at -the current sweep. Producer validation/execution, authenticated terminal verdict -publication and fresh compatibility settlement remain required. The CodeQL -control plane stays owned by the canonical `.github` lane. - -OpenCode source-tree and coverage evidence are GREEN, while `opencode-review` -failed closed because no authenticated exact-head review verdict had materialized. -Strix produced zero findings but correctly failed closed after contextual- -orchestrator rejected concurrent sub-agent work with explicit -`concurrency_limit_exceeded`; incomplete provider execution is not GREEN. Noema -never reached a model verdict because contextual-orchestrator sidecar provisioning -occupied the runner until cancellation. These are canonical review-runtime / -provider-admission problems, not authorization-source findings in LineageWeave. - -Foundation prerequisite `.github#2170` remains open/Ready/mergeable at exact -`c346b8324fa23e23d4007799d26ad3a8ac6ae4c3` on protected -`.github/main@91be6442906c7b6b4f600272c953699708394327`. Runtime Quality, SAST, -Python Security, Security, Noema, Strix, OpenCode bootstrap, OpenCode source-tree -and coverage evidence, latest queue scan, CodeQL language detection and the -CodeQL coordinator are GREEN, and a current-head Noema `APPROVED` review exists. -Canonical producer run `34921233636` is still at producer validation; OpenCode -review publication is also unsettled. Required ordering therefore remains -`.github#2170` normal protected integration -> ordinary/non-force `.github#1629` -reconciliation -> fresh #1629 acceptance. LineageWeave must not copy dependency -predicates, queue policy, provider/model routing, fallback or timeout semantics. - -The stale `.github#2140` decision-record lane remains open while current-main Draft -successor `.github#2207` is independently revalidated. A replacement branch is -not complete succession by itself. - -### Leftover-map identity and evidence stack - -Parent #875 is exact `9303d67219071d76b59d4b85a49dac11023dcab1` on its current -base `eb051da92758e7bf84138e034b2049868c0fb487`. Its moved ancestry was read and -adopted without force-push or destructive rebase. Latest Tests attempts on this -exact head include queued run `34947735003`; newer Draft-policy attempts were -skipped and therefore are not GREEN evidence. - -#876 is exact `f461f5023cdd658b4b37813a8bb3df6ee06dde72` on current #875. -It preserves the report-criterion ζ contract: `leftoverMapPlotCriterionBadge` -consumes only persisted finite item axes, keeps finite zero coordinates, fails -closed for unusable pairs and does not infer ζ from person ξ, geometry, distance, -rank, coverage or neighboring evidence. Current-head Tests run `34947822715` -remains queued; newer Draft-policy run `34949321710` was skipped. Predecessor -validation does not transfer. - -#1033 is now exact `84b927f37471e3969f071520875eb40e5576877c` on current #876. -A semantic two-parent, non-force merge adopted the moved #876 ancestry while -preserving only the intended three-file comparison-criterion delta. Convergence -PR #1084 is normally recognized as merged at this exact commit. The comparison -ζ helper consumes only persisted finite item axes and keeps report criterion -behavior separate. Fresh exact-head Tests run `34949322503` is queued; no prior -receipt transfers. - -#1034 is now exact `708e435d4c975696f4f78a5e9b81969b5895f31e` on current #1033. -A second semantic two-parent, non-force merge preserved the comparison-post ξ -delta while adopting the converged report/comparison criterion and singular-axis -foundation. `leftoverMapComparePlotPostBadge` consumes persisted finite person axes -only; criterion ζ, singular/share evidence, geometry, distance, rank and coverage -do not infer ξ. Fresh exact-head Tests run `34949510341` is queued. Historical -#879 remains open until complete verified succession is demonstrated. - -Sibling #877 is now exact `73f8bf898a8eafc162850dae0b8dbc4955760fdb` on current #875. -A semantic two-parent, non-force merge adopted current #875 while preserving the -three-file comparison-origin-tick repair. Convergence PR #1083 is normally -recognized as merged at this exact commit. Origin identity is exact canonical -formatted zero; share and σ are projected independently and never define origin. -Fresh exact-head Tests run `34949897498` is queued. The branch remains Draft until -its current-head rendered and repository evidence settles. - -The product stack therefore remains Draft and ordered. #876 -> #1033 -> #1034 -must settle current-head evidence before promotion, while #877 follows its own -sibling lane. No descendant inherits parent or predecessor validation receipts. +`main@83eba56149eb802cd63642c507c324c9976ec78e`. Its reader materialization path +is fail-closed for shared Customer Master catalog enrichment, while explicit +`post_admin` retains the canonical create/upsert path. Repository, authenticated +PostgreSQL + Keycloak + Valkey, SAST and Required Security evidence are GREEN. + +Required CodeQL remains a canonical control-plane wait rather than a LineageWeave +source failure. Coordinator `104180256379` dispatched `.github` producer run +`34922377994`, which remains nonterminal. OpenCode source-tree/coverage evidence +is GREEN but the authenticated exact-head review verdict is unsettled. Strix +failed closed after contextual-orchestrator returned +`concurrency_limit_exceeded`; Noema was cancelled during sidecar provisioning +before a model verdict. LineageWeave must not copy provider routing, queue, +timeout, retry or credential policy to work around those owner paths. + +Foundation `.github#2170` and its `.github#1629` reconciliation remain ordered +prerequisites for the central review/runtime path. Historical `.github#2140` +remains open while current-main successor `.github#2207` is independently +validated; successor creation alone is not complete succession. + +### Leftover-map singular/share and marker-identity stack + +A fresh review found a real product RED in #867. Its executable contract required +comparison-graphic axis evidence to expose independent persisted `σ` and share +states through `leftoverMapComparePlotAxisBadge`, but the production helper was +missing. Exact #867 `6d5562411904ca1e945898fa70c2aad7eaed10f7` +now contains the causal repair: empty/share-only/σ-only/combined states are +composed from persisted values only; finite `σ=0` survives; no square root, +normalization, clamping or cross-inference is introduced. Fresh Tests run +`34954789975` is queued, so this is not yet GREEN release evidence. + +Because #867 moved, every active descendant was immediately converged by ordinary +two-parent, non-force commits. The current linear ancestry is: + +`#867 6d556241... -> #868 6c7897e9... -> #869 49637c03... -> +#870 6162dbdf... -> #871 2834dd5a... -> #872 beb425a2... -> +#873 7cae3683... -> #874 7dac5923... -> #875 73665d07...`. + +No child was force-pushed or destructively rebased, and no predecessor receipt +transfers to a moved exact head. #868-#875 remain Draft because each retains its +own local tick/share/singular contract and requires fresh exact-head repository, +security, rendered accessibility and independent-review evidence before +promotion. + +The current report/comparison marker stack below #875 is: + +- #876 exact `4290b153db2ea50e78e3b2c4f5e4f37488688644`: report criterion `ζ` + consumes only persisted finite item-axis coordinates and fails closed for + unusable pairs. +- #1033 exact `2fb586e408114770e0a054b663002190439d5a5b`: comparison criterion `ζ` + preserves the #876 boundary on the current repaired ancestry. +- #1034 exact `603e255bc11146495617c44ea7a329233be284e8`: comparison post `ξ` + consumes only persisted finite person-axis coordinates. Fresh Tests run + `34955527799` is queued. +- sibling #877 exact `2d859c90cf74c3a011e25b295d7a50a631007bdb`: comparison origin-tick + identity remains exact canonical formatted zero; share and `σ` are independent, + and the repaired comparison-axis badge is preserved. Fresh Tests run + `34955402329` is queued. + +Historical #878/#879 remain open as delta carriers. Their full stale trees are not +replayed over repaired ancestry; #1033/#1034 are the current reconstruction +successors. They may close only after every valid product/test/fixture/contract/ +evidence delta is demonstrably inherited and verified. ## Buyer-visible gap register | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | -| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950e73c88a9f9fd932332ddd47682da124b` | Authorization repair and repository/security tests are GREEN; independent full-diff review is clean. CodeQL producer, OpenCode verdict, Strix/Noema complete review evidence and qualifying approval remain unsettled. | Finish canonical current-head CodeQL settlement, authenticated OpenCode verdict, Strix/Noema owner-path repair/revalidation, qualifying approval and normal protected merge. | -| Report/comparison leftover-map marker identity | #876 `f461f502...` -> #1033 `84b927f3...` -> #1034 `708e435d...` | Report criterion ζ, comparison criterion ζ and comparison post ξ causal implementations are preserved after semantic current-parent non-force convergence. Fresh exact-head Tests are queued; historical #878/#879 carriers remain open. | Settle focused/static contracts, frontend lint/tests/build, full repository/PostgreSQL validation, rendered keyboard/focus/a11y evidence, applicable Security/SAST/CodeQL/model review and qualifying approvals; integrate in parent order. | -| Comparison origin tick identity | #877 `73f8bf89...` | Causal production repair is preserved after semantic convergence onto current #875. Exact formatted zero defines origin; share and σ remain independent. Fresh Tests `34949897498` is queued. | Prove current-head executable contract and frontend build/tests, rendered keyboard/focus/a11y/i18n evidence, applicable security/model review and qualifying approval before promotion. | +| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950...` | Authorization repair plus repository/security evidence are GREEN; central CodeQL/model-review settlement is not complete. | Canonical CodeQL producer/receiver settlement, authenticated OpenCode verdict, Strix/Noema owner-path revalidation, qualifying approval and normal protected merge. | +| Comparison-graphic axis σ/share identity | #867 `6d556241...` | Missing production composition helper was repaired causally; fresh Tests `34954789975` is queued. | Focused contract + frontend/full repository tests, rendered a11y/i18n evidence, applicable Security/SAST/CodeQL/model review and qualifying approval. | +| Singular/share tick stack | #868 `6c7897e9...` -> #875 `73665d07...` | All descendants contain the repaired #867 foundation through ordinary non-force merge ancestry; PR bases now point to current parents. | Settle each local RED and fresh exact-head repository/security/browser-a11y/performance/review evidence in parent order. | +| Report/comparison marker identity | #876 `4290b153...` -> #1033 `2fb586e4...` -> #1034 `603e255b...` | ζ/ζ/ξ causal boundaries are preserved on current repaired ancestry; #1034 Tests are queued. Historical #878/#879 remain open delta carriers. | Focused/static contracts, frontend build/tests, full repository/PostgreSQL validation, rendered keyboard/focus/a11y evidence, applicable security/model review and qualifying approvals. | +| Comparison origin tick identity | #877 `2d859c90...` | Exact-zero origin rule and independent share/σ composition survive current-parent convergence; Tests are queued. | Current-head executable contract, frontend build/tests, rendered keyboard/focus/a11y/i18n, applicable security/model review and qualifying approval. | | Catalog connection leases and summary TOCTOU | #1077 and #1080 | Kept separate from #1079; external/provider work must not hold long database leases and post-provider persistence must revalidate authorization/visibility/source revision. | Causal RED -> GREEN in each owner lane, short-transaction evidence, current-head tests and protected integration. | -| Governed UI translation delivery | #929 and child #932 | Governed versioned translation-ledger work remains in its canonical owner lane; the leftover-map stack consumes existing localized labels instead of adding a competing store. | Complete reviewed `ko/en/ja/zh/vi/es/de/fr` resources and rendered normal/loading/empty/error/permission/responsive, keyboard/focus/screen-reader, CJK expansion and font-fallback evidence. | +| Governed UI translation delivery | #929 and child #932 | Governed versioned translation-ledger work remains in its canonical owner lane; leftover-map work consumes localized labels rather than adding a competing store. | Reviewed `ko/en/ja/zh/vi/es/de/fr` resources plus rendered normal/loading/empty/error/permission/responsive, keyboard/focus/screen-reader, CJK expansion and font-fallback evidence. | | MCP buyer-path latency | #1009 | Existing measurements remain above the repository `p95 <= 20 ms` acceptance contract. | Representative uncontended measurements, causal query/I/O/runtime profiling, Rust-first hot-path repair where warranted and exact-head gates. | | Release identity and immutable publication | #961 / #1056 | Candidate release identity work remains Draft; protected main is not release-ready. | Built/installed version proof, normal protected merge, immutable tag/package/release, SBOM/provenance, reproducibility and rollback evidence on one protected SHA. | ## Evidence and ownership rules -Queued, skipped, COMMENTED, rate-limited, status-only, predecessor-head or source- -neutral results are not GREEN evidence for a moved head. An exact-head full-diff -review with no actionable finding is positive independent review coverage but is -not equivalent to a submitted `APPROVED` review when approval is a gate. - -A successful dispatch coordinator proves only exact-head handoff to the canonical -producer. It does not transfer producer acceptance. The producer must validate -its payload, execute the detected-language matrix, publish authenticated terminal -verdicts and drive fresh consumer settlement on the same exact head. +Queued, skipped, COMMENTED, rate-limited, status-only, predecessor-head or +source-neutral results are not GREEN evidence for a moved head. A successful +dispatch coordinator proves exact-head handoff only; authenticated producer +execution and consumer settlement must still complete on that same head. A moved parent invalidates descendant ancestry assumptions immediately. Repair is -non-force: inspect the intervening delta, preserve valid contract/test/product +non-force: inspect intervening deltas, preserve valid product/contract/test evidence, then merge/reconstruct/retarget onto the moved parent without rewriting -shared history. Parent GREEN evidence does not transfer to the resulting descendant. +shared history. Parent GREEN evidence never transfers to the resulting child. A stale or conflicted PR is not force-rebased or closed merely because a successor exists. Closure requires complete verified succession of every valid product, @@ -142,20 +115,17 @@ contracts/ACLs and does not copy contextual-orchestrator admission/routing, central CI queue policy, psychometrics implementations, ranking, scheduling or other owner functionality. -For database paths, external/model work occurs outside long-lived explicit -transactions and locks. Persistence reacquires the shortest necessary lease, -revalidates authorization/version state and uses idempotent/UPSERT semantics when -the domain contract requires them. +External/model work stays outside long-lived explicit database transactions and +locks. Persistence reacquires the shortest necessary lease, revalidates +authorization/version state and uses idempotent/UPSERT semantics where required. -For material UI, repository/unit evidence does not replace rendered buyer-path -acceptance. Normal/loading/empty/error/permission/responsive behavior, +Material UI requires rendered buyer-path acceptance in addition to unit/repository +evidence: normal/loading/empty/error/permission/responsive behavior, pointer/touch/keyboard/focus, accessibility, locale expansion/font fallback and -applicable p95 evidence remain part of release acceptance. +applicable p95 evidence. ## Historical evidence -The former append-only baseline, including dated overlays through 2026-09-13, is -preserved unchanged at +The former append-only baseline through 2026-09-13 remains unchanged at [`docs/evidence/product-technical-gap-baseline-history-through-20260913.md`](evidence/product-technical-gap-baseline-history-through-20260913.md). -It is provenance, not current authority. Future refreshes should update this -projection rather than presenting superseded runtime/check state as live. +It is provenance, not current authority. From 09c7e3837fcb349d4e06a9020419ff54b827bb51 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 21:04:04 +0900 Subject: [PATCH 072/276] docs(gaps): record graphic badge repair and descendant convergence --- docs/product-technical-gap-baseline.md | 117 +++++++++++++------------ 1 file changed, 60 insertions(+), 57 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 11f11ff22..c284e6ea3 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-15 19:04 KST. +> Current authority snapshot: 2026-09-15 21:03 KST. > > Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e` at this projection. > This file summarizes live PR/Issue/check authority; protected refs, PRs, Issues, @@ -14,21 +14,13 @@ No LineageWeave release is admitted from the current protected head. ### Summary shared-catalog authorization -#1079 remains open and Ready at exact -`c2923950e73c88a9f9fd932332ddd47682da124b` on protected -`main@83eba56149eb802cd63642c507c324c9976ec78e`. Its reader materialization path -is fail-closed for shared Customer Master catalog enrichment, while explicit -`post_admin` retains the canonical create/upsert path. Repository, authenticated -PostgreSQL + Keycloak + Valkey, SAST and Required Security evidence are GREEN. - -Required CodeQL remains a canonical control-plane wait rather than a LineageWeave -source failure. Coordinator `104180256379` dispatched `.github` producer run -`34922377994`, which remains nonterminal. OpenCode source-tree/coverage evidence -is GREEN but the authenticated exact-head review verdict is unsettled. Strix -failed closed after contextual-orchestrator returned -`concurrency_limit_exceeded`; Noema was cancelled during sidecar provisioning -before a model verdict. LineageWeave must not copy provider routing, queue, -timeout, retry or credential policy to work around those owner paths. +#1079 remains open at exact `c2923950e73c88a9f9fd932332ddd47682da124b` +on protected `main@83eba56149eb802cd63642c507c324c9976ec78e`. Its reader +materialization path remains fail-closed for shared Customer Master catalog +enrichment, while explicit `post_admin` retains the canonical create/upsert +path. Central CodeQL/OpenCode/Strix/Noema settlement is still owned outside this +product stack; LineageWeave must not copy provider routing, queue, timeout, retry +or credential policy to work around those owner paths. Foundation `.github#2170` and its `.github#1629` reconciliation remain ordered prerequisites for the central review/runtime path. Historical `.github#2140` @@ -37,42 +29,52 @@ validated; successor creation alone is not complete succession. ### Leftover-map singular/share and marker-identity stack -A fresh review found a real product RED in #867. Its executable contract required -comparison-graphic axis evidence to expose independent persisted `σ` and share -states through `leftoverMapComparePlotAxisBadge`, but the production helper was -missing. Exact #867 `6d5562411904ca1e945898fa70c2aad7eaed10f7` -now contains the causal repair: empty/share-only/σ-only/combined states are -composed from persisted values only; finite `σ=0` survives; no square root, -normalization, clamping or cross-inference is introduced. Fresh Tests run -`34954789975` is queued, so this is not yet GREEN release evidence. - -Because #867 moved, every active descendant was immediately converged by ordinary -two-parent, non-force commits. The current linear ancestry is: - -`#867 6d556241... -> #868 6c7897e9... -> #869 49637c03... -> -#870 6162dbdf... -> #871 2834dd5a... -> #872 beb425a2... -> -#873 7cae3683... -> #874 7dac5923... -> #875 73665d07...`. - -No child was force-pushed or destructively rebased, and no predecessor receipt -transfers to a moved exact head. #868-#875 remain Draft because each retains its -own local tick/share/singular contract and requires fresh exact-head repository, -security, rendered accessibility and independent-review evidence before -promotion. +A current-head review on #867 found that the newly introduced +`leftoverMapComparePlotAxisBadge` helper was not actually wired to the comparison +graphic. The component still mapped axis evidence through +`leftoverMapCompareAxisBadge`, which is comparison-strip copy. A realistic source +contract was first added at `e4670959cca60a94bc0ebf54a503f3b4d38d535d` to +require graphic-specific wiring, making the predecessor implementation RED. +Production head `9e9e38dab1120585d41cb4f2ee81778689b0256a` then switched +`LeftoverMapPlot` to `leftoverMapComparePlotAxisBadge` and documented the touched +production helpers. The graphic and strip surfaces therefore keep distinct copy +while both consume only persisted finite singular/share evidence. + +Fresh #867 Tests are not GREEN yet: run `34965610236` is queued, a newer attempt +was cancelled, and another attempt was skipped. Neither cancellation nor skip is +acceptance evidence. + +Because #867 moved, the active descendant stack was reconverged immediately by +normal merge PRs, without force-push or destructive rebase. The current linear +ancestry is: + +`#867 9e9e38da... -> #868 933d4627... -> #869 26b9ce48... -> +#870 4d7e6404... -> #871 ddcba830... -> #872 ea26581b... -> +#873 bc03c627... -> #874 c5abdfc2... -> #875 4e90d973...`. + +Convergence PRs #1085 through #1092 were normally merged in parent order. No +predecessor validation receipt transfers to any moved exact head. #868-#875 stay +Draft because each retains its own local tick/share/singular contract and still +requires fresh exact-head repository, security, rendered accessibility and +independent-review evidence before promotion. The current report/comparison marker stack below #875 is: -- #876 exact `4290b153db2ea50e78e3b2c4f5e4f37488688644`: report criterion `ζ` +- #876 exact `a9cefd596d0a4eb94281eccbadd1b24ce3ff6a1f`: report criterion `ζ` consumes only persisted finite item-axis coordinates and fails closed for - unusable pairs. -- #1033 exact `2fb586e408114770e0a054b663002190439d5a5b`: comparison criterion `ζ` - preserves the #876 boundary on the current repaired ancestry. -- #1034 exact `603e255bc11146495617c44ea7a329233be284e8`: comparison post `ξ` - consumes only persisted finite person-axis coordinates. Fresh Tests run - `34955527799` is queued. -- sibling #877 exact `2d859c90cf74c3a011e25b295d7a50a631007bdb`: comparison origin-tick - identity remains exact canonical formatted zero; share and `σ` are independent, - and the repaired comparison-axis badge is preserved. Fresh Tests run - `34955402329` is queued. + unusable pairs. It adopted #875 through normal convergence PR #1093. +- #1033 exact `549db716caf71f3581bfa8cd96768212665feb6b`: comparison criterion `ζ` + preserves the #876 boundary after normal convergence PR #1094. +- #1034 exact `0171755fc42dd30842a0245eb13430981426bd10`: comparison post `ξ` + consumes only persisted finite person-axis coordinates after normal convergence + PR #1095. Fresh Tests run `34966164590` is queued. +- sibling #877 exact `a0a2b6f7fa3a5b905e31a7fae21a26dcc1aead5d`: comparison origin-tick + identity remains exact canonical formatted zero. Because #877 and #867 both + touch `LeftoverMapPlot`, the parent change required semantic conflict repair: + the graphic-specific axis-badge wiring and executable wiring contract were + applied without removing the origin-tick delta, then a two-parent non-force + merge commit completed convergence PR #1096. Fresh Tests run `34966416325` is + queued. Historical #878/#879 remain open as delta carriers. Their full stale trees are not replayed over repaired ancestry; #1033/#1034 are the current reconstruction @@ -83,11 +85,11 @@ evidence delta is demonstrably inherited and verified. | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | -| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950...` | Authorization repair plus repository/security evidence are GREEN; central CodeQL/model-review settlement is not complete. | Canonical CodeQL producer/receiver settlement, authenticated OpenCode verdict, Strix/Noema owner-path revalidation, qualifying approval and normal protected merge. | -| Comparison-graphic axis σ/share identity | #867 `6d556241...` | Missing production composition helper was repaired causally; fresh Tests `34954789975` is queued. | Focused contract + frontend/full repository tests, rendered a11y/i18n evidence, applicable Security/SAST/CodeQL/model review and qualifying approval. | -| Singular/share tick stack | #868 `6c7897e9...` -> #875 `73665d07...` | All descendants contain the repaired #867 foundation through ordinary non-force merge ancestry; PR bases now point to current parents. | Settle each local RED and fresh exact-head repository/security/browser-a11y/performance/review evidence in parent order. | -| Report/comparison marker identity | #876 `4290b153...` -> #1033 `2fb586e4...` -> #1034 `603e255b...` | ζ/ζ/ξ causal boundaries are preserved on current repaired ancestry; #1034 Tests are queued. Historical #878/#879 remain open delta carriers. | Focused/static contracts, frontend build/tests, full repository/PostgreSQL validation, rendered keyboard/focus/a11y evidence, applicable security/model review and qualifying approvals. | -| Comparison origin tick identity | #877 `2d859c90...` | Exact-zero origin rule and independent share/σ composition survive current-parent convergence; Tests are queued. | Current-head executable contract, frontend build/tests, rendered keyboard/focus/a11y/i18n, applicable security/model review and qualifying approval. | +| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950...` | Authorization repair remains isolated from central review-runtime owner logic. | Canonical CodeQL producer/receiver settlement, authenticated OpenCode verdict, Strix/Noema owner-path revalidation, qualifying approval and normal protected merge. | +| Comparison-graphic axis σ/share identity | #867 `9e9e38da...` | Review finding reproduced by source contract, production now uses graphic-specific helper rather than strip helper; current Tests are queued/skipped/cancelled, not GREEN. | Focused contract + frontend/full repository tests, rendered a11y/i18n evidence, applicable Security/SAST/CodeQL/model review and qualifying approval. | +| Singular/share tick stack | #868 `933d4627...` -> #875 `4e90d973...` | Descendants contain repaired #867 foundation through normal non-force merge ancestry and PR authority now names current parents/heads. | Settle each local RED and fresh exact-head repository/security/browser-a11y/performance/review evidence in parent order. | +| Report/comparison marker identity | #876 `a9cefd59...` -> #1033 `549db716...` -> #1034 `0171755f...` | ζ/ζ/ξ boundaries are preserved on repaired ancestry; #1034 Tests `34966164590` are queued. Historical #878/#879 remain open delta carriers. | Focused contracts, frontend build/tests, full repository/PostgreSQL validation, rendered keyboard/focus/a11y evidence, applicable security/model review and qualifying approvals. | +| Comparison origin tick identity | #877 `a0a2b6f7...` | Semantic conflict repair preserves exact-zero origin, independent share/σ composition, graphic-specific axis badge copy and its executable wiring contract; Tests `34966416325` are queued. | Current-head executable contract, frontend build/tests, rendered keyboard/focus/a11y/i18n, applicable security/model review and qualifying approval. | | Catalog connection leases and summary TOCTOU | #1077 and #1080 | Kept separate from #1079; external/provider work must not hold long database leases and post-provider persistence must revalidate authorization/visibility/source revision. | Causal RED -> GREEN in each owner lane, short-transaction evidence, current-head tests and protected integration. | | Governed UI translation delivery | #929 and child #932 | Governed versioned translation-ledger work remains in its canonical owner lane; leftover-map work consumes localized labels rather than adding a competing store. | Reviewed `ko/en/ja/zh/vi/es/de/fr` resources plus rendered normal/loading/empty/error/permission/responsive, keyboard/focus/screen-reader, CJK expansion and font-fallback evidence. | | MCP buyer-path latency | #1009 | Existing measurements remain above the repository `p95 <= 20 ms` acceptance contract. | Representative uncontended measurements, causal query/I/O/runtime profiling, Rust-first hot-path repair where warranted and exact-head gates. | @@ -95,10 +97,11 @@ evidence delta is demonstrably inherited and verified. ## Evidence and ownership rules -Queued, skipped, COMMENTED, rate-limited, status-only, predecessor-head or -source-neutral results are not GREEN evidence for a moved head. A successful -dispatch coordinator proves exact-head handoff only; authenticated producer -execution and consumer settlement must still complete on that same head. +Queued, skipped, COMMENTED, cancelled, rate-limited, status-only, +predecessor-head or source-neutral results are not GREEN evidence for a moved +head. A successful dispatch coordinator proves exact-head handoff only; +authenticated producer execution and consumer settlement must still complete on +that same head. A moved parent invalidates descendant ancestry assumptions immediately. Repair is non-force: inspect intervening deltas, preserve valid product/contract/test From 6a36c32751660902547e2595d5d35ffd46de5e7d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 21:29:55 +0900 Subject: [PATCH 073/276] docs(product): refresh live gap authority after owner and stack repairs --- docs/product-technical-gap-baseline.md | 127 ++++++++++++++----------- 1 file changed, 73 insertions(+), 54 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index c284e6ea3..90cb823f2 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-15 21:03 KST. +> Current authority snapshot: 2026-09-15 21:29 KST. > > Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e` at this projection. > This file summarizes live PR/Issue/check authority; protected refs, PRs, Issues, @@ -23,58 +23,77 @@ product stack; LineageWeave must not copy provider routing, queue, timeout, retr or credential policy to work around those owner paths. Foundation `.github#2170` and its `.github#1629` reconciliation remain ordered -prerequisites for the central review/runtime path. Historical `.github#2140` -remains open while current-main successor `.github#2207` is independently -validated; successor creation alone is not complete succession. +prerequisites for the central review/runtime path. On #2170 exact +`c346b8324fa23e23d4007799d26ad3a8ac6ae4c3`, canonical CodeQL producer run +`34921233636` has passed `validate-dispatch` (`104229618015` SUCCESS) and is now +waiting in the actual scan job `104230163129`; coordinator success alone is not +analysis acceptance. + +Historical `.github#2140` remains open while current-main successor `.github#2207` +is independently validated. #2207 moved to exact +`9b34e64e772a8c77ab5c049accfba5cb2ae5de0d` after a valid CodeRabbit finding was +repaired in ADR-0030: the no-interruption guarantee for active streaming is now +explicitly scoped to the external job boundary, while a job ceiling or separately +classified runner-reclamation event may terminate the request without becoming a +model-failure verdict or route-ranking signal. A second review suggestion to +replace `012beaac` was rejected after verification because #2137 uses that value as +the target vendored contextual-orchestrator revision. Fresh #2207 Security/SAST/ +CodeQL/Python Security evidence belongs to the new head; no receipt from +`36a6755...` transfers. Successor creation or one review repair is still not +complete succession, so #2140 stays open. ### Leftover-map singular/share and marker-identity stack -A current-head review on #867 found that the newly introduced -`leftoverMapComparePlotAxisBadge` helper was not actually wired to the comparison -graphic. The component still mapped axis evidence through -`leftoverMapCompareAxisBadge`, which is comparison-strip copy. A realistic source -contract was first added at `e4670959cca60a94bc0ebf54a503f3b4d38d535d` to -require graphic-specific wiring, making the predecessor implementation RED. -Production head `9e9e38dab1120585d41cb4f2ee81778689b0256a` then switched -`LeftoverMapPlot` to `leftoverMapComparePlotAxisBadge` and documented the touched -production helpers. The graphic and strip surfaces therefore keep distinct copy -while both consume only persisted finite singular/share evidence. - -Fresh #867 Tests are not GREEN yet: run `34965610236` is queued, a newer attempt -was cancelled, and another attempt was skipped. Neither cancellation nor skip is -acceptance evidence. - -Because #867 moved, the active descendant stack was reconverged immediately by -normal merge PRs, without force-push or destructive rebase. The current linear -ancestry is: - -`#867 9e9e38da... -> #868 933d4627... -> #869 26b9ce48... -> -#870 4d7e6404... -> #871 ddcba830... -> #872 ea26581b... -> -#873 bc03c627... -> #874 c5abdfc2... -> #875 4e90d973...`. - -Convergence PRs #1085 through #1092 were normally merged in parent order. No -predecessor validation receipt transfers to any moved exact head. #868-#875 stay -Draft because each retains its own local tick/share/singular contract and still -requires fresh exact-head repository, security, rendered accessibility and -independent-review evidence before promotion. - -The current report/comparison marker stack below #875 is: - -- #876 exact `a9cefd596d0a4eb94281eccbadd1b24ce3ff6a1f`: report criterion `ζ` +#867's production repair remains the foundation: `LeftoverMapPlot` uses +`leftoverMapComparePlotAxisBadge` for comparison-graphic captions, while the +comparison strip retains `leftoverMapCompareAxisBadge`. Both helpers consume only +persisted finite singular/share evidence and keep the two measurements independent. + +The #867 branch then advanced non-destructively from `9e9e38da...` to exact +`a81297680bf1b0536227db41fd9596ee42519c0e`. The intervening delta was inspected +rather than treated as a race: it changes only +`frontend/src/leftoverMapAxisBadge.test.ts` (+53/-0) and adds direct Vitest coverage +for the graphic helper's empty, share-only, singular-only (including finite +`σ=0`), and combined states. It does not change production semantics. Current +#867 Tests include queued run `34967080332`; cancelled/skipped sibling attempts are +not acceptance evidence. + +Because that parent movement invalidated descendant ancestry assumptions, the +active linear stack was adopted/converged without force-push or destructive +rebase. The current exact ancestry is: + +`#867 a8129768... -> #868 d39343ab... -> #869 732ad3b6... -> +#870 fb1eb3cd... -> #871 78ce9469... -> #872 fc9bf9db... -> +#873 c8a5063c... -> #874 f2377692... -> #875 758da1e8...`. + +The moved #868-#875 heads keep their own tick/share/singular product deltas while +inheriting the exact #867 executable test blob. Their PR authorities now name the +current parent/head pairs. No predecessor validation receipt transfers, and all +remain Draft pending fresh exact-head repository/security/rendered-accessibility/ +performance/review evidence. + +The current report/comparison marker stack below #875 was also repaired in the +same turn rather than left conflicted: + +- #876 exact `347962092b5887580fce6d2d708d9ae7c950c2a2`: report criterion `ζ` consumes only persisted finite item-axis coordinates and fails closed for - unusable pairs. It adopted #875 through normal convergence PR #1093. -- #1033 exact `549db716caf71f3581bfa8cd96768212665feb6b`: comparison criterion `ζ` - preserves the #876 boundary after normal convergence PR #1094. -- #1034 exact `0171755fc42dd30842a0245eb13430981426bd10`: comparison post `ξ` - consumes only persisted finite person-axis coordinates after normal convergence - PR #1095. Fresh Tests run `34966164590` is queued. -- sibling #877 exact `a0a2b6f7fa3a5b905e31a7fae21a26dcc1aead5d`: comparison origin-tick - identity remains exact canonical formatted zero. Because #877 and #867 both - touch `LeftoverMapPlot`, the parent change required semantic conflict repair: - the graphic-specific axis-badge wiring and executable wiring contract were - applied without removing the origin-tick delta, then a two-parent non-force - merge commit completed convergence PR #1096. Fresh Tests run `34966416325` is - queued. + unusable pairs. The prior criterion product/test delta is preserved while the + exact upstream Vitest blob is inherited. Fresh Tests run `34968725267` is queued. +- #1033 exact `ccf077cf503b4ce3169e44186a07b74ee30ec7f0`: comparison criterion `ζ` + preserves the #876 boundary after semantic non-force convergence. Fresh Tests + run `34968819345` is queued. +- #1034 exact `b9dec94a21e47b9ceeb30a3074b6978d17b00958`: comparison post `ξ` + consumes only persisted finite person-axis coordinates. Fresh Tests run + `34968872059` is queued. +- sibling #877 exact `ba9101f59743de37f999c3ccf5e0ad0a1a26980d`: comparison origin-tick + identity remains exact canonical formatted zero while share/σ remain independent. + Fresh Tests run `34968764771` is pending. + +For #876/#877/#1033/#1034 the only upstream semantic movement was the executable +`leftoverMapAxisBadge.test.ts` coverage. Their local product/test files did not +overlap that delta, so convergence used explicit two-parent commits and copied the +exact upstream blob into the child tree before a non-force branch fast-forward. +No child product delta was replaced or force-rebased. Historical #878/#879 remain open as delta carriers. Their full stale trees are not replayed over repaired ancestry; #1033/#1034 are the current reconstruction @@ -85,11 +104,11 @@ evidence delta is demonstrably inherited and verified. | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | -| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950...` | Authorization repair remains isolated from central review-runtime owner logic. | Canonical CodeQL producer/receiver settlement, authenticated OpenCode verdict, Strix/Noema owner-path revalidation, qualifying approval and normal protected merge. | -| Comparison-graphic axis σ/share identity | #867 `9e9e38da...` | Review finding reproduced by source contract, production now uses graphic-specific helper rather than strip helper; current Tests are queued/skipped/cancelled, not GREEN. | Focused contract + frontend/full repository tests, rendered a11y/i18n evidence, applicable Security/SAST/CodeQL/model review and qualifying approval. | -| Singular/share tick stack | #868 `933d4627...` -> #875 `4e90d973...` | Descendants contain repaired #867 foundation through normal non-force merge ancestry and PR authority now names current parents/heads. | Settle each local RED and fresh exact-head repository/security/browser-a11y/performance/review evidence in parent order. | -| Report/comparison marker identity | #876 `a9cefd59...` -> #1033 `549db716...` -> #1034 `0171755f...` | ζ/ζ/ξ boundaries are preserved on repaired ancestry; #1034 Tests `34966164590` are queued. Historical #878/#879 remain open delta carriers. | Focused contracts, frontend build/tests, full repository/PostgreSQL validation, rendered keyboard/focus/a11y evidence, applicable security/model review and qualifying approvals. | -| Comparison origin tick identity | #877 `a0a2b6f7...` | Semantic conflict repair preserves exact-zero origin, independent share/σ composition, graphic-specific axis badge copy and its executable wiring contract; Tests `34966416325` are queued. | Current-head executable contract, frontend build/tests, rendered keyboard/focus/a11y/i18n, applicable security/model review and qualifying approval. | +| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950...` | Authorization repair remains isolated from central review-runtime owner logic. `.github#2170` producer validation is GREEN but its actual CodeQL scan remains queued; `.github#2207` moved after a verified ADR repair and requires entirely fresh evidence. | Canonical CodeQL producer/receiver settlement, authenticated OpenCode verdict, Strix/Noema owner-path revalidation, qualifying approval and normal protected merge. | +| Comparison-graphic axis σ/share identity | #867 `a8129768...` | Production uses graphic-specific helper rather than strip helper; direct Vitest state coverage now exercises empty/share-only/σ-only/combined states. Current Tests run `34967080332` is queued, not GREEN. | Focused contract + frontend/full repository tests, rendered a11y/i18n evidence, applicable Security/SAST/CodeQL/model review and qualifying approval. | +| Singular/share tick stack | #868 `d39343ab...` -> #875 `758da1e8...` | Descendants contain repaired #867 foundation plus the executable helper-state tests through non-force ancestry; PR authority names current parents/heads. | Settle each local RED and fresh exact-head repository/security/browser-a11y/performance/review evidence in parent order. | +| Report/comparison marker identity | #876 `34796209...` -> #1033 `ccf077cf...` -> #1034 `b9dec94a...` | ζ/ζ/ξ boundaries are preserved after current-parent convergence; new Tests `34968725267`, `34968819345`, `34968872059` are queued. Historical #878/#879 remain open delta carriers. | Focused contracts, frontend build/tests, full repository/PostgreSQL validation, rendered keyboard/focus/a11y evidence, applicable security/model review and qualifying approvals. | +| Comparison origin tick identity | #877 `ba9101f5...` | Exact-zero origin and independent share/σ composition are preserved while the upstream executable badge-state tests are inherited; Tests `34968764771` is pending. | Current-head executable contract, frontend build/tests, rendered keyboard/focus/a11y/i18n, applicable security/model review and qualifying approval. | | Catalog connection leases and summary TOCTOU | #1077 and #1080 | Kept separate from #1079; external/provider work must not hold long database leases and post-provider persistence must revalidate authorization/visibility/source revision. | Causal RED -> GREEN in each owner lane, short-transaction evidence, current-head tests and protected integration. | | Governed UI translation delivery | #929 and child #932 | Governed versioned translation-ledger work remains in its canonical owner lane; leftover-map work consumes localized labels rather than adding a competing store. | Reviewed `ko/en/ja/zh/vi/es/de/fr` resources plus rendered normal/loading/empty/error/permission/responsive, keyboard/focus/screen-reader, CJK expansion and font-fallback evidence. | | MCP buyer-path latency | #1009 | Existing measurements remain above the repository `p95 <= 20 ms` acceptance contract. | Representative uncontended measurements, causal query/I/O/runtime profiling, Rust-first hot-path repair where warranted and exact-head gates. | From ccb5d68353ce41ee7928bbee44ca95c9bd6d0da3 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 21:33:45 +0900 Subject: [PATCH 074/276] docs(product): refresh owner ADR authority after review repair --- docs/product-technical-gap-baseline.md | 29 ++++++++++++++------------ 1 file changed, 16 insertions(+), 13 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 90cb823f2..5ac180bc6 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-15 21:29 KST. +> Current authority snapshot: 2026-09-15 21:34 KST. > > Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e` at this projection. > This file summarizes live PR/Issue/check authority; protected refs, PRs, Issues, @@ -30,17 +30,20 @@ waiting in the actual scan job `104230163129`; coordinator success alone is not analysis acceptance. Historical `.github#2140` remains open while current-main successor `.github#2207` -is independently validated. #2207 moved to exact -`9b34e64e772a8c77ab5c049accfba5cb2ae5de0d` after a valid CodeRabbit finding was -repaired in ADR-0030: the no-interruption guarantee for active streaming is now -explicitly scoped to the external job boundary, while a job ceiling or separately -classified runner-reclamation event may terminate the request without becoming a -model-failure verdict or route-ranking signal. A second review suggestion to -replace `012beaac` was rejected after verification because #2137 uses that value as -the target vendored contextual-orchestrator revision. Fresh #2207 Security/SAST/ -CodeQL/Python Security evidence belongs to the new head; no receipt from -`36a6755...` transfers. Successor creation or one review repair is still not -complete succession, so #2140 stays open. +is independently validated. #2207 is now exact +`2d61a668a0d7f0f4bb51c7805945db15e81f0bec` after two rounds of verified review +repair. Active streaming is protected from the idle-socket bound only within the +external job boundary; a job ceiling or separately classified runner-reclamation +event may still terminate the request without becoming a model-failure verdict or +route-ranking signal. First-response-byte silence is now classified only as a +transport-level no-progress observation: it does not prove provider/model failure +or distinguish long time-to-first-byte from transport stall, and occupancy expiry +must not penalise, circuit-break, or rank the route. The changelog carries the same +boundary. A separate review suggestion to replace `012beaac` was rejected after +verification because #2137 uses that value as the target vendored +contextual-orchestrator revision. All receipts from earlier #2207 heads are +historical; successor existence or repaired prose is not complete succession, so +#2140 stays open. ### Leftover-map singular/share and marker-identity stack @@ -104,7 +107,7 @@ evidence delta is demonstrably inherited and verified. | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | -| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950...` | Authorization repair remains isolated from central review-runtime owner logic. `.github#2170` producer validation is GREEN but its actual CodeQL scan remains queued; `.github#2207` moved after a verified ADR repair and requires entirely fresh evidence. | Canonical CodeQL producer/receiver settlement, authenticated OpenCode verdict, Strix/Noema owner-path revalidation, qualifying approval and normal protected merge. | +| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950...` | Authorization repair remains isolated from central review-runtime owner logic. `.github#2170` producer validation is GREEN but its actual CodeQL scan remains queued; `.github#2207` is now `2d61a668...` after verified ADR/changelog semantic repairs and requires entirely fresh evidence. | Canonical CodeQL producer/receiver settlement, authenticated OpenCode verdict, Strix/Noema owner-path revalidation, qualifying approval and normal protected merge. | | Comparison-graphic axis σ/share identity | #867 `a8129768...` | Production uses graphic-specific helper rather than strip helper; direct Vitest state coverage now exercises empty/share-only/σ-only/combined states. Current Tests run `34967080332` is queued, not GREEN. | Focused contract + frontend/full repository tests, rendered a11y/i18n evidence, applicable Security/SAST/CodeQL/model review and qualifying approval. | | Singular/share tick stack | #868 `d39343ab...` -> #875 `758da1e8...` | Descendants contain repaired #867 foundation plus the executable helper-state tests through non-force ancestry; PR authority names current parents/heads. | Settle each local RED and fresh exact-head repository/security/browser-a11y/performance/review evidence in parent order. | | Report/comparison marker identity | #876 `34796209...` -> #1033 `ccf077cf...` -> #1034 `b9dec94a...` | ζ/ζ/ξ boundaries are preserved after current-parent convergence; new Tests `34968725267`, `34968819345`, `34968872059` are queued. Historical #878/#879 remain open delta carriers. | Focused contracts, frontend build/tests, full repository/PostgreSQL validation, rendered keyboard/focus/a11y evidence, applicable security/model review and qualifying approvals. | From 84465061cd479f1de7336a23b0ab1f29a9ddc94a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 21:56:06 +0900 Subject: [PATCH 075/276] docs(gaps): record owner-boundary descendant convergence --- docs/product-technical-gap-baseline.md | 35 ++++++++++++++++++++++++-- 1 file changed, 33 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 5ac180bc6..29121f79d 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-15 21:34 KST. +> Current authority snapshot: 2026-09-15 21:54 KST. > > Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e` at this projection. > This file summarizes live PR/Issue/check authority; protected refs, PRs, Issues, @@ -45,6 +45,36 @@ contextual-orchestrator revision. All receipts from earlier #2207 heads are historical; successor existence or repaired prose is not complete succession, so #2140 stays open. +### Owner-boundary and governed measurement stack + +#899 is the canonical LineageWeave consumer-boundary foundation at exact +`d331d1f6b05d39385a652be6dbb8f279871a2e2e` on protected +`main@83eba56149eb802cd63642c507c324c9976ec78e`. Its latest parent delta is a +single `docs/ubiquitous-language.md` Markdown/trailing-whitespace cleanup; the +contextual-orchestrator ownership semantics remain unchanged. #966 has already +converged onto that exact parent at `1be24cd923b89a64f41d05bea8534b552e1ee7bc`. + +#902 was still based on predecessor #899 `e5711282...` and GitHub reported it +non-mergeable after the parent moved. The parent delta and #902 both touched the +ubiquitous-language file, so the repair did not choose one side wholesale. Two-parent +non-force convergence `8b5cc45dbb2d6ef7bb3b49a10c33cdfb93b483cc` +retains #899's current Markdown structure and #902's substantive 2PLM +intended-use/recovery-contract wording. Fresh compare now has merge-base exactly +`d331d1f6...`, `behind_by=0`, with the same seven measurement-policy files; #902 is +open / Draft / mergeable / clean. Exact-head Tests `34971343143` is terminal +`skipped` under Draft admission, so it is not product GREEN. Status contexts from +CodeRabbit/Devin are not substituted for a qualifying submitted approval. + +#915 depended on the moved #902 and also owned the same ubiquitous-language file. +Two-parent non-force convergence `6540acebbb3ecef4736ebeefa6c0c4486b002b79` +retains the newly converged #902 glossary formatting/2PLM wording plus #915's +dynamic-evaluation vocabulary and adjudication boundary. Fresh compare has +merge-base exactly `8b5cc45...`, `behind_by=0`, and the same 12 dynamic-evaluation +files; #915 is open / Draft / mergeable / clean. Exact-head Tests `34971580315` is +terminal `skipped` under Draft admission, and no qualifying current-head submitted +approval is claimed. No open PR currently targets #915's head branch, so this +ancestry movement has no further active descendant to converge in that lane. + ### Leftover-map singular/share and marker-identity stack #867's production repair remains the foundation: `LeftoverMapPlot` uses @@ -108,6 +138,7 @@ evidence delta is demonstrably inherited and verified. | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | | Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950...` | Authorization repair remains isolated from central review-runtime owner logic. `.github#2170` producer validation is GREEN but its actual CodeQL scan remains queued; `.github#2207` is now `2d61a668...` after verified ADR/changelog semantic repairs and requires entirely fresh evidence. | Canonical CodeQL producer/receiver settlement, authenticated OpenCode verdict, Strix/Noema owner-path revalidation, qualifying approval and normal protected merge. | +| Contextual-orchestrator consumer boundary and governed measurement/evaluation lineage | #899 `d331d1f6...` -> #902 `8b5cc45d...` -> #915 `6540aceb...`; #966 `1be24cd9...` is a separate #899 descendant | #902 and #915 were both repaired non-force after current-parent movement, including semantic overlap in `docs/ubiquitous-language.md`; both are now clean/mergeable Drafts. Their exact-head Tests are Draft-skipped, not GREEN. | #899 normal integration first, then fresh full repository/security/governance evidence and qualifying independent approvals on unchanged #902/#915 descendant heads; no predecessor receipt transfer. | | Comparison-graphic axis σ/share identity | #867 `a8129768...` | Production uses graphic-specific helper rather than strip helper; direct Vitest state coverage now exercises empty/share-only/σ-only/combined states. Current Tests run `34967080332` is queued, not GREEN. | Focused contract + frontend/full repository tests, rendered a11y/i18n evidence, applicable Security/SAST/CodeQL/model review and qualifying approval. | | Singular/share tick stack | #868 `d39343ab...` -> #875 `758da1e8...` | Descendants contain repaired #867 foundation plus the executable helper-state tests through non-force ancestry; PR authority names current parents/heads. | Settle each local RED and fresh exact-head repository/security/browser-a11y/performance/review evidence in parent order. | | Report/comparison marker identity | #876 `34796209...` -> #1033 `ccf077cf...` -> #1034 `b9dec94a...` | ζ/ζ/ξ boundaries are preserved after current-parent convergence; new Tests `34968725267`, `34968819345`, `34968872059` are queued. Historical #878/#879 remain open delta carriers. | Focused contracts, frontend build/tests, full repository/PostgreSQL validation, rendered keyboard/focus/a11y evidence, applicable security/model review and qualifying approvals. | @@ -153,4 +184,4 @@ applicable p95 evidence. The former append-only baseline through 2026-09-13 remains unchanged at [`docs/evidence/product-technical-gap-baseline-history-through-20260913.md`](evidence/product-technical-gap-baseline-history-through-20260913.md). -It is provenance, not current authority. +It is provenance, not current authority. \ No newline at end of file From 430d333a94c03014fc9d575d7dd07379c5865cf5 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 22:04:41 +0900 Subject: [PATCH 076/276] docs(gaps): include bounded-operator descendant convergence --- docs/product-technical-gap-baseline.md | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 29121f79d..686ad99db 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-15 21:54 KST. +> Current authority snapshot: 2026-09-15 22:04 KST. > > Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e` at this projection. > This file summarizes live PR/Issue/check authority; protected refs, PRs, Issues, @@ -75,6 +75,15 @@ terminal `skipped` under Draft admission, and no qualifying current-head submitt approval is claimed. No open PR currently targets #915's head branch, so this ancestry movement has no further active descendant to converge in that lane. +#919 was the remaining direct #899 child one commit behind `d331d1f6...`. Its 14 +bounded-operator/test/ADR/changelog files are disjoint from #899's intervening +glossary-only delta. Two-parent non-force convergence +`53dca4bda5dee5d1f4dceb75ea3c53d85bbc8e62` adopts the exact current parent +glossary blob while preserving all local #919 deltas. Fresh compare now has +merge-base exactly `d331d1f6...`, `behind_by=0`, and the same 14 local files; #919 +is open / Draft / mergeable. Exact-head Tests `34972516997` is terminal `skipped` +under Draft admission, not GREEN. No open PR currently targets #919's branch. + ### Leftover-map singular/share and marker-identity stack #867's production repair remains the foundation: `LeftoverMapPlot` uses @@ -138,7 +147,7 @@ evidence delta is demonstrably inherited and verified. | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | | Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950...` | Authorization repair remains isolated from central review-runtime owner logic. `.github#2170` producer validation is GREEN but its actual CodeQL scan remains queued; `.github#2207` is now `2d61a668...` after verified ADR/changelog semantic repairs and requires entirely fresh evidence. | Canonical CodeQL producer/receiver settlement, authenticated OpenCode verdict, Strix/Noema owner-path revalidation, qualifying approval and normal protected merge. | -| Contextual-orchestrator consumer boundary and governed measurement/evaluation lineage | #899 `d331d1f6...` -> #902 `8b5cc45d...` -> #915 `6540aceb...`; #966 `1be24cd9...` is a separate #899 descendant | #902 and #915 were both repaired non-force after current-parent movement, including semantic overlap in `docs/ubiquitous-language.md`; both are now clean/mergeable Drafts. Their exact-head Tests are Draft-skipped, not GREEN. | #899 normal integration first, then fresh full repository/security/governance evidence and qualifying independent approvals on unchanged #902/#915 descendant heads; no predecessor receipt transfer. | +| Contextual-orchestrator consumer boundary and governed measurement/evaluation/operator lineage | #899 `d331d1f6...`; children #902 `8b5cc45d...` -> #915 `6540aceb...`, #919 `53dca4bd...`, and #966 `1be24cd9...` | #902/#915 semantic glossary overlap and disjoint #919 operator delta were converged non-force onto the exact current parent. All are now mergeable Drafts. #902/#915/#919 exact-head Tests are Draft-skipped, not GREEN. | #899 normal integration first, then fresh full repository/security/governance evidence and qualifying independent approvals on unchanged descendant heads; no predecessor receipt transfer. | | Comparison-graphic axis σ/share identity | #867 `a8129768...` | Production uses graphic-specific helper rather than strip helper; direct Vitest state coverage now exercises empty/share-only/σ-only/combined states. Current Tests run `34967080332` is queued, not GREEN. | Focused contract + frontend/full repository tests, rendered a11y/i18n evidence, applicable Security/SAST/CodeQL/model review and qualifying approval. | | Singular/share tick stack | #868 `d39343ab...` -> #875 `758da1e8...` | Descendants contain repaired #867 foundation plus the executable helper-state tests through non-force ancestry; PR authority names current parents/heads. | Settle each local RED and fresh exact-head repository/security/browser-a11y/performance/review evidence in parent order. | | Report/comparison marker identity | #876 `34796209...` -> #1033 `ccf077cf...` -> #1034 `b9dec94a...` | ζ/ζ/ξ boundaries are preserved after current-parent convergence; new Tests `34968725267`, `34968819345`, `34968872059` are queued. Historical #878/#879 remain open delta carriers. | Focused contracts, frontend build/tests, full repository/PostgreSQL validation, rendered keyboard/focus/a11y evidence, applicable security/model review and qualifying approvals. | From e20e92c67c9fcf0525fd7fb417587bf069c39331 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 22:56:58 +0900 Subject: [PATCH 077/276] docs(gaps): record PostgreSQL timeout compatibility repair --- docs/product-technical-gap-baseline.md | 37 +++++++++++++++++++++++--- 1 file changed, 33 insertions(+), 4 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 686ad99db..c59ceb5bb 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-15 22:04 KST. +> Current authority snapshot: 2026-09-15 22:44 KST. > > Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e` at this projection. > This file summarizes live PR/Issue/check authority; protected refs, PRs, Issues, @@ -45,6 +45,33 @@ contextual-orchestrator revision. All receipts from earlier #2207 heads are historical; successor existence or repaired prose is not complete succession, so #2140 stays open. +### Commercial-safe synchronous PostgreSQL boundary + +#911 is now exact `6030b295aadc3ee76dc4d27f5713273f35888325`, open / Draft / +mergeable on protected `main@83eba56149eb802cd63642c507c324c9976ec78e`. +Fresh review found that the pg8000 compatibility adapter had changed libpq +`connect_timeout` semantics while migrating the synchronous seed/admin/schema +boundary away from `psycopg2-binary`: URI values were accepted as arbitrary +floats and every non-positive value was rejected. The PostgreSQL/libpq contract +uses decimal-integer URI text and treats zero or negative values as an indefinite +wait. RED `326a97d89b3642fae392857218e4274bd456a8c0` now covers both DSN and +keyword no-deadline sentinels plus rejection of non-integer URI text; causal +repair `b7838e40d6a200b8b9474cd03fcd52046c80bd6b` omits pg8000's timeout +argument for the no-deadline sentinel and restores integer URI parsing. Changelog +commit `6030b295aadc3ee76dc4d27f5713273f35888325` makes that behavior explicit. +The TLS/SQLSTATE/runtime ownership boundaries are unchanged; runtime persistence +remains `asyncpg`. + +No prior #911 receipt transfers to this changed source head. Exact-head Tests +`34977841241`, PROV-O `34977841500`, and Ontology Pages `34977841059` are +Draft-skipped, not GREEN. Security `34977841173`, SAST Semgrep `34977841093`, +and CodeQL PR `34977841115` are fresh queued runs. A fresh exact-head CodeRabbit +review was requested; no qualifying independent exact-head APPROVE exists. The +central terminal CodeQL publication path remains owned by `.github#1929`, while +the public-repository Dependency Review HTTP-403/support incident remains owned +by `.github#810`; LineageWeave must not fabricate statuses or substitute weaker +local scanners for those required gates. + ### Owner-boundary and governed measurement stack #899 is the canonical LineageWeave consumer-boundary foundation at exact @@ -139,18 +166,20 @@ No child product delta was replaced or force-rebased. Historical #878/#879 remain open as delta carriers. Their full stale trees are not replayed over repaired ancestry; #1033/#1034 are the current reconstruction -successors. They may close only after every valid product/test/fixture/contract/ -evidence delta is demonstrably inherited and verified. +successors at `ccf077cf...` and `b9dec94a...`. Their PR authorities now point to +those current successors. They may close only after every valid +product/test/fixture/contract/evidence delta is demonstrably inherited and verified. ## Buyer-visible gap register | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | | Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950...` | Authorization repair remains isolated from central review-runtime owner logic. `.github#2170` producer validation is GREEN but its actual CodeQL scan remains queued; `.github#2207` is now `2d61a668...` after verified ADR/changelog semantic repairs and requires entirely fresh evidence. | Canonical CodeQL producer/receiver settlement, authenticated OpenCode verdict, Strix/Noema owner-path revalidation, qualifying approval and normal protected merge. | +| Commercial-safe synchronous PostgreSQL tooling must preserve libpq connection semantics | #910 / #911 `6030b295...` | Test-first timeout compatibility repair preserves zero/negative no-deadline sentinels and decimal-integer URI parsing while keeping runtime on asyncpg. Exact-head repository Tests/PROV-O/Ontology are Draft-skipped; Security/SAST/CodeQL are queued; no exact-head APPROVE exists. | Fresh exact-head repository/security/CodeQL/model-review evidence, canonical Dependency Review support/availability settlement, qualifying independent approval, ADR 0366 remaining Proposed until normal integration. | | Contextual-orchestrator consumer boundary and governed measurement/evaluation/operator lineage | #899 `d331d1f6...`; children #902 `8b5cc45d...` -> #915 `6540aceb...`, #919 `53dca4bd...`, and #966 `1be24cd9...` | #902/#915 semantic glossary overlap and disjoint #919 operator delta were converged non-force onto the exact current parent. All are now mergeable Drafts. #902/#915/#919 exact-head Tests are Draft-skipped, not GREEN. | #899 normal integration first, then fresh full repository/security/governance evidence and qualifying independent approvals on unchanged descendant heads; no predecessor receipt transfer. | | Comparison-graphic axis σ/share identity | #867 `a8129768...` | Production uses graphic-specific helper rather than strip helper; direct Vitest state coverage now exercises empty/share-only/σ-only/combined states. Current Tests run `34967080332` is queued, not GREEN. | Focused contract + frontend/full repository tests, rendered a11y/i18n evidence, applicable Security/SAST/CodeQL/model review and qualifying approval. | | Singular/share tick stack | #868 `d39343ab...` -> #875 `758da1e8...` | Descendants contain repaired #867 foundation plus the executable helper-state tests through non-force ancestry; PR authority names current parents/heads. | Settle each local RED and fresh exact-head repository/security/browser-a11y/performance/review evidence in parent order. | -| Report/comparison marker identity | #876 `34796209...` -> #1033 `ccf077cf...` -> #1034 `b9dec94a...` | ζ/ζ/ξ boundaries are preserved after current-parent convergence; new Tests `34968725267`, `34968819345`, `34968872059` are queued. Historical #878/#879 remain open delta carriers. | Focused contracts, frontend build/tests, full repository/PostgreSQL validation, rendered keyboard/focus/a11y evidence, applicable security/model review and qualifying approvals. | +| Report/comparison marker identity | #876 `34796209...` -> #1033 `ccf077cf...` -> #1034 `b9dec94a...` | ζ/ζ/ξ boundaries are preserved after current-parent convergence; new Tests `34968725267`, `34968819345`, `34968872059` are queued. Historical #878/#879 remain open delta carriers with current successor authority repaired. | Focused contracts, frontend build/tests, full repository/PostgreSQL validation, rendered keyboard/focus/a11y evidence, applicable security/model review and qualifying approvals. | | Comparison origin tick identity | #877 `ba9101f5...` | Exact-zero origin and independent share/σ composition are preserved while the upstream executable badge-state tests are inherited; Tests `34968764771` is pending. | Current-head executable contract, frontend build/tests, rendered keyboard/focus/a11y/i18n, applicable security/model review and qualifying approval. | | Catalog connection leases and summary TOCTOU | #1077 and #1080 | Kept separate from #1079; external/provider work must not hold long database leases and post-provider persistence must revalidate authorization/visibility/source revision. | Causal RED -> GREEN in each owner lane, short-transaction evidence, current-head tests and protected integration. | | Governed UI translation delivery | #929 and child #932 | Governed versioned translation-ledger work remains in its canonical owner lane; leftover-map work consumes localized labels rather than adding a competing store. | Reviewed `ko/en/ja/zh/vi/es/de/fr` resources plus rendered normal/loading/empty/error/permission/responsive, keyboard/focus/screen-reader, CJK expansion and font-fallback evidence. | From 78e56920300dd0e6a3173c0fcf4d91a90d4b4211 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 23:00:03 +0900 Subject: [PATCH 078/276] docs(gaps): record exact-head PostgreSQL validation admission --- docs/product-technical-gap-baseline.md | 25 +++++++++++++++---------- 1 file changed, 15 insertions(+), 10 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index c59ceb5bb..224044f39 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -62,15 +62,20 @@ commit `6030b295aadc3ee76dc4d27f5713273f35888325` makes that behavior explicit. The TLS/SQLSTATE/runtime ownership boundaries are unchanged; runtime persistence remains `asyncpg`. -No prior #911 receipt transfers to this changed source head. Exact-head Tests -`34977841241`, PROV-O `34977841500`, and Ontology Pages `34977841059` are -Draft-skipped, not GREEN. Security `34977841173`, SAST Semgrep `34977841093`, -and CodeQL PR `34977841115` are fresh queued runs. A fresh exact-head CodeRabbit -review was requested; no qualifying independent exact-head APPROVE exists. The -central terminal CodeQL publication path remains owned by `.github#1929`, while -the public-repository Dependency Review HTTP-403/support incident remains owned -by `.github#810`; LineageWeave must not fabricate statuses or substitute weaker -local scanners for those required gates. +No prior #911 receipt transfers to this changed source head. Its initial Draft +event skipped Tests `34977841241`, PROV-O `34977841500`, and Ontology Pages +`34977841059`, so the unchanged head was deliberately admitted Ready only long +enough to register real exact-head validation and was immediately returned to +Draft. Tests `34978508294`, PROV-O `34978508011`, and Ontology Pages +`34978508135` are now queued. Security `34977841173`, SAST Semgrep +`34977841093`, and CodeQL PR `34977841115` remain queued. The fresh CodeRabbit +request covers the `6030b295...` change range but is rate-limited before a new +actionable review; CodeRabbit/Devin status contexts are not submitted approvals. +No qualifying independent exact-head APPROVE exists. The central terminal CodeQL +publication path remains owned by `.github#1929`, while the public-repository +Dependency Review HTTP-403/support incident remains owned by `.github#810`; +LineageWeave must not fabricate statuses or substitute weaker local scanners for +those required gates. ### Owner-boundary and governed measurement stack @@ -175,7 +180,7 @@ product/test/fixture/contract/evidence delta is demonstrably inherited and verif | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | | Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950...` | Authorization repair remains isolated from central review-runtime owner logic. `.github#2170` producer validation is GREEN but its actual CodeQL scan remains queued; `.github#2207` is now `2d61a668...` after verified ADR/changelog semantic repairs and requires entirely fresh evidence. | Canonical CodeQL producer/receiver settlement, authenticated OpenCode verdict, Strix/Noema owner-path revalidation, qualifying approval and normal protected merge. | -| Commercial-safe synchronous PostgreSQL tooling must preserve libpq connection semantics | #910 / #911 `6030b295...` | Test-first timeout compatibility repair preserves zero/negative no-deadline sentinels and decimal-integer URI parsing while keeping runtime on asyncpg. Exact-head repository Tests/PROV-O/Ontology are Draft-skipped; Security/SAST/CodeQL are queued; no exact-head APPROVE exists. | Fresh exact-head repository/security/CodeQL/model-review evidence, canonical Dependency Review support/availability settlement, qualifying independent approval, ADR 0366 remaining Proposed until normal integration. | +| Commercial-safe synchronous PostgreSQL tooling must preserve libpq connection semantics | #910 / #911 `6030b295...` | Test-first timeout compatibility repair preserves zero/negative no-deadline sentinels and decimal-integer URI parsing while keeping runtime on asyncpg. The unchanged source head has been re-admitted for real current-head Tests/PROV-O/Ontology, all now queued; Security/SAST/CodeQL also remain queued. Fresh CodeRabbit review is rate-limited and no exact-head APPROVE exists. | Exact-head repository/security/CodeQL/model-review GREEN, canonical Dependency Review support/availability settlement, qualifying independent approval, ADR 0366 remaining Proposed until normal integration. | | Contextual-orchestrator consumer boundary and governed measurement/evaluation/operator lineage | #899 `d331d1f6...`; children #902 `8b5cc45d...` -> #915 `6540aceb...`, #919 `53dca4bd...`, and #966 `1be24cd9...` | #902/#915 semantic glossary overlap and disjoint #919 operator delta were converged non-force onto the exact current parent. All are now mergeable Drafts. #902/#915/#919 exact-head Tests are Draft-skipped, not GREEN. | #899 normal integration first, then fresh full repository/security/governance evidence and qualifying independent approvals on unchanged descendant heads; no predecessor receipt transfer. | | Comparison-graphic axis σ/share identity | #867 `a8129768...` | Production uses graphic-specific helper rather than strip helper; direct Vitest state coverage now exercises empty/share-only/σ-only/combined states. Current Tests run `34967080332` is queued, not GREEN. | Focused contract + frontend/full repository tests, rendered a11y/i18n evidence, applicable Security/SAST/CodeQL/model review and qualifying approval. | | Singular/share tick stack | #868 `d39343ab...` -> #875 `758da1e8...` | Descendants contain repaired #867 foundation plus the executable helper-state tests through non-force ancestry; PR authority names current parents/heads. | Settle each local RED and fresh exact-head repository/security/browser-a11y/performance/review evidence in parent order. | From b3e8665dd66eb8766951bf45355340cef6e5b64b Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 15 Sep 2026 23:03:04 +0900 Subject: [PATCH 079/276] docs(gaps): keep PostgreSQL validation admission current --- docs/product-technical-gap-baseline.md | 56 +++++++++++++------------- 1 file changed, 29 insertions(+), 27 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 224044f39..bf8e65713 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -47,35 +47,37 @@ historical; successor existence or repaired prose is not complete succession, so ### Commercial-safe synchronous PostgreSQL boundary -#911 is now exact `6030b295aadc3ee76dc4d27f5713273f35888325`, open / Draft / +#911 is exact `6030b295aadc3ee76dc4d27f5713273f35888325`, open / Ready / mergeable on protected `main@83eba56149eb802cd63642c507c324c9976ec78e`. -Fresh review found that the pg8000 compatibility adapter had changed libpq -`connect_timeout` semantics while migrating the synchronous seed/admin/schema -boundary away from `psycopg2-binary`: URI values were accepted as arbitrary -floats and every non-positive value was rejected. The PostgreSQL/libpq contract -uses decimal-integer URI text and treats zero or negative values as an indefinite -wait. RED `326a97d89b3642fae392857218e4274bd456a8c0` now covers both DSN and -keyword no-deadline sentinels plus rejection of non-integer URI text; causal -repair `b7838e40d6a200b8b9474cd03fcd52046c80bd6b` omits pg8000's timeout -argument for the no-deadline sentinel and restores integer URI parsing. Changelog -commit `6030b295aadc3ee76dc4d27f5713273f35888325` makes that behavior explicit. -The TLS/SQLSTATE/runtime ownership boundaries are unchanged; runtime persistence +Ready is validation admission only, not merge readiness. Fresh review found that +the pg8000 compatibility adapter had changed libpq `connect_timeout` semantics +while migrating the synchronous seed/admin/schema boundary away from +`psycopg2-binary`: URI values were accepted as arbitrary floats and every +non-positive value was rejected. The PostgreSQL/libpq contract uses decimal- +integer URI text and treats zero or negative values as an indefinite wait. RED +`326a97d89b3642fae392857218e4274bd456a8c0` covers both DSN and keyword +no-deadline sentinels plus rejection of non-integer URI text; causal repair +`b7838e40d6a200b8b9474cd03fcd52046c80bd6b` omits pg8000's timeout argument +for the no-deadline sentinel and restores integer URI parsing. Changelog commit +`6030b295aadc3ee76dc4d27f5713273f35888325` makes that behavior explicit. The +TLS/SQLSTATE/runtime ownership boundaries are unchanged; runtime persistence remains `asyncpg`. -No prior #911 receipt transfers to this changed source head. Its initial Draft -event skipped Tests `34977841241`, PROV-O `34977841500`, and Ontology Pages -`34977841059`, so the unchanged head was deliberately admitted Ready only long -enough to register real exact-head validation and was immediately returned to -Draft. Tests `34978508294`, PROV-O `34978508011`, and Ontology Pages -`34978508135` are now queued. Security `34977841173`, SAST Semgrep -`34977841093`, and CodeQL PR `34977841115` remain queued. The fresh CodeRabbit -request covers the `6030b295...` change range but is rate-limited before a new -actionable review; CodeRabbit/Devin status contexts are not submitted approvals. -No qualifying independent exact-head APPROVE exists. The central terminal CodeQL -publication path remains owned by `.github#1929`, while the public-repository -Dependency Review HTTP-403/support incident remains owned by `.github#810`; -LineageWeave must not fabricate statuses or substitute weaker local scanners for -those required gates. +No prior #911 receipt transfers to this changed source head. The initial Draft +event skipped repository-local validation. A first attempt to admit the unchanged +head Ready and immediately return it to Draft proved the admission behavior rather +than producing GREEN: runs `34978508294` / `34978508011` / `34978508135` were +cancelled when Draft was restored, followed by new skipped Draft runs. Therefore +the exact head is intentionally left Ready until its validations settle. Tests +`34978833151`, PROV-O `34978832987`, and Ontology Pages `34978833063` are queued; +Security `34977841173`, SAST Semgrep `34977841093`, and CodeQL PR `34977841115` +remain queued. The fresh CodeRabbit request covers the `6030b295...` change range +but is rate-limited before a new actionable review; CodeRabbit/Devin status +contexts are not submitted approvals. No qualifying independent exact-head +APPROVE exists. The central terminal CodeQL publication path remains owned by +`.github#1929`, while the public-repository Dependency Review HTTP-403/support +incident remains owned by `.github#810`; LineageWeave must not fabricate statuses +or substitute weaker local scanners for those required gates. ### Owner-boundary and governed measurement stack @@ -180,7 +182,7 @@ product/test/fixture/contract/evidence delta is demonstrably inherited and verif | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | | Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950...` | Authorization repair remains isolated from central review-runtime owner logic. `.github#2170` producer validation is GREEN but its actual CodeQL scan remains queued; `.github#2207` is now `2d61a668...` after verified ADR/changelog semantic repairs and requires entirely fresh evidence. | Canonical CodeQL producer/receiver settlement, authenticated OpenCode verdict, Strix/Noema owner-path revalidation, qualifying approval and normal protected merge. | -| Commercial-safe synchronous PostgreSQL tooling must preserve libpq connection semantics | #910 / #911 `6030b295...` | Test-first timeout compatibility repair preserves zero/negative no-deadline sentinels and decimal-integer URI parsing while keeping runtime on asyncpg. The unchanged source head has been re-admitted for real current-head Tests/PROV-O/Ontology, all now queued; Security/SAST/CodeQL also remain queued. Fresh CodeRabbit review is rate-limited and no exact-head APPROVE exists. | Exact-head repository/security/CodeQL/model-review GREEN, canonical Dependency Review support/availability settlement, qualifying independent approval, ADR 0366 remaining Proposed until normal integration. | +| Commercial-safe synchronous PostgreSQL tooling must preserve libpq connection semantics | #910 / #911 `6030b295...` | Test-first timeout compatibility repair preserves zero/negative no-deadline sentinels and decimal-integer URI parsing while keeping runtime on asyncpg. The exact source head is validation-admitted Ready because returning it to Draft cancelled repository-local runs; Tests/PROV-O/Ontology plus Security/SAST/CodeQL are queued. Fresh CodeRabbit review is rate-limited and no exact-head APPROVE exists. | Exact-head repository/security/CodeQL/model-review GREEN, canonical Dependency Review support/availability settlement, qualifying independent approval, ADR 0366 remaining Proposed until normal integration. | | Contextual-orchestrator consumer boundary and governed measurement/evaluation/operator lineage | #899 `d331d1f6...`; children #902 `8b5cc45d...` -> #915 `6540aceb...`, #919 `53dca4bd...`, and #966 `1be24cd9...` | #902/#915 semantic glossary overlap and disjoint #919 operator delta were converged non-force onto the exact current parent. All are now mergeable Drafts. #902/#915/#919 exact-head Tests are Draft-skipped, not GREEN. | #899 normal integration first, then fresh full repository/security/governance evidence and qualifying independent approvals on unchanged descendant heads; no predecessor receipt transfer. | | Comparison-graphic axis σ/share identity | #867 `a8129768...` | Production uses graphic-specific helper rather than strip helper; direct Vitest state coverage now exercises empty/share-only/σ-only/combined states. Current Tests run `34967080332` is queued, not GREEN. | Focused contract + frontend/full repository tests, rendered a11y/i18n evidence, applicable Security/SAST/CodeQL/model review and qualifying approval. | | Singular/share tick stack | #868 `d39343ab...` -> #875 `758da1e8...` | Descendants contain repaired #867 foundation plus the executable helper-state tests through non-force ancestry; PR authority names current parents/heads. | Settle each local RED and fresh exact-head repository/security/browser-a11y/performance/review evidence in parent order. | From ad9c1275a14e1e9be8dbfa872d62ceb5101e52e7 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 16 Sep 2026 00:09:17 +0900 Subject: [PATCH 080/276] docs(gaps): record report-axis missingness repair and current stack --- docs/product-technical-gap-baseline.md | 263 ++++++------------------- 1 file changed, 64 insertions(+), 199 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index bf8e65713..76d7af0da 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,232 +1,97 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-15 22:44 KST. +> Current authority snapshot: 2026-09-15. > > Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e` at this projection. -> This file summarizes live PR/Issue/check authority; protected refs, PRs, Issues, -> ADRs and exact-head receipts remain authoritative. Historical overlays through -> 2026-09-13 are preserved in +> Protected refs, live PRs/Issues, ADRs, and exact-head receipts remain authoritative. +> Historical overlays through 2026-09-13 are preserved in > [`evidence/product-technical-gap-baseline-history-through-20260913.md`](evidence/product-technical-gap-baseline-history-through-20260913.md). ## Protected delivery baseline -No LineageWeave release is admitted from the current protected head. +No LineageWeave release is admitted from the current protected head. A moved parent invalidates descendant acceptance evidence; branch convergence never transfers predecessor receipts. ### Summary shared-catalog authorization -#1079 remains open at exact `c2923950e73c88a9f9fd932332ddd47682da124b` -on protected `main@83eba56149eb802cd63642c507c324c9976ec78e`. Its reader -materialization path remains fail-closed for shared Customer Master catalog -enrichment, while explicit `post_admin` retains the canonical create/upsert -path. Central CodeQL/OpenCode/Strix/Noema settlement is still owned outside this -product stack; LineageWeave must not copy provider routing, queue, timeout, retry -or credential policy to work around those owner paths. - -Foundation `.github#2170` and its `.github#1629` reconciliation remain ordered -prerequisites for the central review/runtime path. On #2170 exact -`c346b8324fa23e23d4007799d26ad3a8ac6ae4c3`, canonical CodeQL producer run -`34921233636` has passed `validate-dispatch` (`104229618015` SUCCESS) and is now -waiting in the actual scan job `104230163129`; coordinator success alone is not -analysis acceptance. - -Historical `.github#2140` remains open while current-main successor `.github#2207` -is independently validated. #2207 is now exact -`2d61a668a0d7f0f4bb51c7805945db15e81f0bec` after two rounds of verified review -repair. Active streaming is protected from the idle-socket bound only within the -external job boundary; a job ceiling or separately classified runner-reclamation -event may still terminate the request without becoming a model-failure verdict or -route-ranking signal. First-response-byte silence is now classified only as a -transport-level no-progress observation: it does not prove provider/model failure -or distinguish long time-to-first-byte from transport stall, and occupancy expiry -must not penalise, circuit-break, or rank the route. The changelog carries the same -boundary. A separate review suggestion to replace `012beaac` was rejected after -verification because #2137 uses that value as the target vendored -contextual-orchestrator revision. All receipts from earlier #2207 heads are -historical; successor existence or repaired prose is not complete succession, so -#2140 stays open. +#1079 remains open / Ready / mergeable at exact `c2923950e73c88a9f9fd932332ddd47682da124b` on protected `main@83eba56149eb802cd63642c507c324c9976ec78e`. Reader summary materialization remains fail-closed for shared Customer Master catalog mutation while explicit `post_admin` retains canonical create/upsert authority. Its product repository/security tests are GREEN, but canonical review-runtime settlement is not complete. + +Required CodeQL has passed language detection, coordinator dispatch, and canonical producer `validate-dispatch`; actual JavaScript/TypeScript, Python, and Actions scan jobs remain queued without runners. OpenCode source/evidence coverage is GREEN but no authenticated exact-head verdict has materialized. Strix produced a zero-finding artifact but refused GREEN when contextual-orchestrator returned bounded concurrency overload. Noema was cancelled after review-sidecar provisioning never became ready; no model verdict ran. These are canonical `.github`/contextual-orchestrator owner-path conditions, not reasons to copy queue, provider, timeout, retry, credential, or status logic into LineageWeave. + +Foundation order remains `.github#2170 normal integration -> ordinary/non-force .github#1629 reconciliation -> fresh #1629 acceptance`. Historical `.github#2140` stays open while current-main successor `.github#2207` exact `2d61a668a0d7f0f4bb51c7805945db15e81f0bec` obtains fresh current-head checks and independent review. First-byte silence is only a transport-level no-progress observation; occupancy release does not become a provider/model penalty, circuit-break, or route-ranking signal. ### Commercial-safe synchronous PostgreSQL boundary -#911 is exact `6030b295aadc3ee76dc4d27f5713273f35888325`, open / Ready / -mergeable on protected `main@83eba56149eb802cd63642c507c324c9976ec78e`. -Ready is validation admission only, not merge readiness. Fresh review found that -the pg8000 compatibility adapter had changed libpq `connect_timeout` semantics -while migrating the synchronous seed/admin/schema boundary away from -`psycopg2-binary`: URI values were accepted as arbitrary floats and every -non-positive value was rejected. The PostgreSQL/libpq contract uses decimal- -integer URI text and treats zero or negative values as an indefinite wait. RED -`326a97d89b3642fae392857218e4274bd456a8c0` covers both DSN and keyword -no-deadline sentinels plus rejection of non-integer URI text; causal repair -`b7838e40d6a200b8b9474cd03fcd52046c80bd6b` omits pg8000's timeout argument -for the no-deadline sentinel and restores integer URI parsing. Changelog commit -`6030b295aadc3ee76dc4d27f5713273f35888325` makes that behavior explicit. The -TLS/SQLSTATE/runtime ownership boundaries are unchanged; runtime persistence -remains `asyncpg`. - -No prior #911 receipt transfers to this changed source head. The initial Draft -event skipped repository-local validation. A first attempt to admit the unchanged -head Ready and immediately return it to Draft proved the admission behavior rather -than producing GREEN: runs `34978508294` / `34978508011` / `34978508135` were -cancelled when Draft was restored, followed by new skipped Draft runs. Therefore -the exact head is intentionally left Ready until its validations settle. Tests -`34978833151`, PROV-O `34978832987`, and Ontology Pages `34978833063` are queued; -Security `34977841173`, SAST Semgrep `34977841093`, and CodeQL PR `34977841115` -remain queued. The fresh CodeRabbit request covers the `6030b295...` change range -but is rate-limited before a new actionable review; CodeRabbit/Devin status -contexts are not submitted approvals. No qualifying independent exact-head -APPROVE exists. The central terminal CodeQL publication path remains owned by -`.github#1929`, while the public-repository Dependency Review HTTP-403/support -incident remains owned by `.github#810`; LineageWeave must not fabricate statuses -or substitute weaker local scanners for those required gates. +#911 remains exact `6030b295aadc3ee76dc4d27f5713273f35888325`, open / Ready / mergeable. Ready is validation admission only. RED `326a97d89b3642fae392857218e4274bd456a8c0` captures libpq-compatible `connect_timeout` behavior: URI values are decimal integers and zero/negative values are no-deadline sentinels. Causal repair `b7838e40d6a200b8b9474cd03fcd52046c80bd6b` restores those semantics at the pg8000 synchronous compatibility boundary; runtime persistence remains `asyncpg`. Changelog commit `6030b295...` is code-current. + +Exact-head Tests `34978833151`, PROV-O `34978832987`, Ontology Pages `34978833063`, Security `34977841173`, SAST `34977841093`, and CodeQL `34977841115` remain queued. A skipped/cancelled Draft run is not GREEN evidence, and no qualifying exact-head independent approval exists. ### Owner-boundary and governed measurement stack -#899 is the canonical LineageWeave consumer-boundary foundation at exact -`d331d1f6b05d39385a652be6dbb8f279871a2e2e` on protected -`main@83eba56149eb802cd63642c507c324c9976ec78e`. Its latest parent delta is a -single `docs/ubiquitous-language.md` Markdown/trailing-whitespace cleanup; the -contextual-orchestrator ownership semantics remain unchanged. #966 has already -converged onto that exact parent at `1be24cd923b89a64f41d05bea8534b552e1ee7bc`. - -#902 was still based on predecessor #899 `e5711282...` and GitHub reported it -non-mergeable after the parent moved. The parent delta and #902 both touched the -ubiquitous-language file, so the repair did not choose one side wholesale. Two-parent -non-force convergence `8b5cc45dbb2d6ef7bb3b49a10c33cdfb93b483cc` -retains #899's current Markdown structure and #902's substantive 2PLM -intended-use/recovery-contract wording. Fresh compare now has merge-base exactly -`d331d1f6...`, `behind_by=0`, with the same seven measurement-policy files; #902 is -open / Draft / mergeable / clean. Exact-head Tests `34971343143` is terminal -`skipped` under Draft admission, so it is not product GREEN. Status contexts from -CodeRabbit/Devin are not substituted for a qualifying submitted approval. - -#915 depended on the moved #902 and also owned the same ubiquitous-language file. -Two-parent non-force convergence `6540acebbb3ecef4736ebeefa6c0c4486b002b79` -retains the newly converged #902 glossary formatting/2PLM wording plus #915's -dynamic-evaluation vocabulary and adjudication boundary. Fresh compare has -merge-base exactly `8b5cc45...`, `behind_by=0`, and the same 12 dynamic-evaluation -files; #915 is open / Draft / mergeable / clean. Exact-head Tests `34971580315` is -terminal `skipped` under Draft admission, and no qualifying current-head submitted -approval is claimed. No open PR currently targets #915's head branch, so this -ancestry movement has no further active descendant to converge in that lane. - -#919 was the remaining direct #899 child one commit behind `d331d1f6...`. Its 14 -bounded-operator/test/ADR/changelog files are disjoint from #899's intervening -glossary-only delta. Two-parent non-force convergence -`53dca4bda5dee5d1f4dceb75ea3c53d85bbc8e62` adopts the exact current parent -glossary blob while preserving all local #919 deltas. Fresh compare now has -merge-base exactly `d331d1f6...`, `behind_by=0`, and the same 14 local files; #919 -is open / Draft / mergeable. Exact-head Tests `34972516997` is terminal `skipped` -under Draft admission, not GREEN. No open PR currently targets #919's branch. - -### Leftover-map singular/share and marker-identity stack - -#867's production repair remains the foundation: `LeftoverMapPlot` uses -`leftoverMapComparePlotAxisBadge` for comparison-graphic captions, while the -comparison strip retains `leftoverMapCompareAxisBadge`. Both helpers consume only -persisted finite singular/share evidence and keep the two measurements independent. - -The #867 branch then advanced non-destructively from `9e9e38da...` to exact -`a81297680bf1b0536227db41fd9596ee42519c0e`. The intervening delta was inspected -rather than treated as a race: it changes only -`frontend/src/leftoverMapAxisBadge.test.ts` (+53/-0) and adds direct Vitest coverage -for the graphic helper's empty, share-only, singular-only (including finite -`σ=0`), and combined states. It does not change production semantics. Current -#867 Tests include queued run `34967080332`; cancelled/skipped sibling attempts are -not acceptance evidence. - -Because that parent movement invalidated descendant ancestry assumptions, the -active linear stack was adopted/converged without force-push or destructive -rebase. The current exact ancestry is: - -`#867 a8129768... -> #868 d39343ab... -> #869 732ad3b6... -> -#870 fb1eb3cd... -> #871 78ce9469... -> #872 fc9bf9db... -> -#873 c8a5063c... -> #874 f2377692... -> #875 758da1e8...`. - -The moved #868-#875 heads keep their own tick/share/singular product deltas while -inheriting the exact #867 executable test blob. Their PR authorities now name the -current parent/head pairs. No predecessor validation receipt transfers, and all -remain Draft pending fresh exact-head repository/security/rendered-accessibility/ -performance/review evidence. - -The current report/comparison marker stack below #875 was also repaired in the -same turn rather than left conflicted: - -- #876 exact `347962092b5887580fce6d2d708d9ae7c950c2a2`: report criterion `ζ` - consumes only persisted finite item-axis coordinates and fails closed for - unusable pairs. The prior criterion product/test delta is preserved while the - exact upstream Vitest blob is inherited. Fresh Tests run `34968725267` is queued. -- #1033 exact `ccf077cf503b4ce3169e44186a07b74ee30ec7f0`: comparison criterion `ζ` - preserves the #876 boundary after semantic non-force convergence. Fresh Tests - run `34968819345` is queued. -- #1034 exact `b9dec94a21e47b9ceeb30a3074b6978d17b00958`: comparison post `ξ` - consumes only persisted finite person-axis coordinates. Fresh Tests run - `34968872059` is queued. -- sibling #877 exact `ba9101f59743de37f999c3ccf5e0ad0a1a26980d`: comparison origin-tick - identity remains exact canonical formatted zero while share/σ remain independent. - Fresh Tests run `34968764771` is pending. - -For #876/#877/#1033/#1034 the only upstream semantic movement was the executable -`leftoverMapAxisBadge.test.ts` coverage. Their local product/test files did not -overlap that delta, so convergence used explicit two-parent commits and copied the -exact upstream blob into the child tree before a non-force branch fast-forward. -No child product delta was replaced or force-rebased. - -Historical #878/#879 remain open as delta carriers. Their full stale trees are not -replayed over repaired ancestry; #1033/#1034 are the current reconstruction -successors at `ccf077cf...` and `b9dec94a...`. Their PR authorities now point to -those current successors. They may close only after every valid -product/test/fixture/contract/evidence delta is demonstrably inherited and verified. +#899 remains the contextual-orchestrator consumer-boundary foundation at exact `d331d1f6b05d39385a652be6dbb8f279871a2e2e`. Its converged descendants remain #902 `8b5cc45dbb2d6ef7bb3b49a10c33cdfb93b483cc` -> #915 `6540acebbb3ecef4736ebeefa6c0c4486b002b79`, #919 `53dca4bda5dee5d1f4dceb75ea3c53d85bbc8e62`, and #966 `1be24cd923b89a64f41d05bea8534b552e1ee7bc`. Draft-skipped Tests are not product GREEN. Canonical model/provider behavior stays in contextual-orchestrator; measurement truth stays with its canonical owners. + +### Leftover-map report-axis missingness repair + +Fresh review of #866 found a buyer-visible composition defect that its existing helper contract did not exercise end-to-end. The helper described independent persisted σ/share states, but the report rendering path still consumed coupled primitives. With a valid persisted σ and missing/non-finite share, `leftoverMapAxisBadgeShare` could synthesize `NaN%` and the report template could not preserve σ cleanly without share. + +The repair is test-first and local to LineageWeave presentation composition: + +- RED `7c570b484b4298fbd0a699003f05980aee6235e8` adds a report-path contract for independent σ/share evidence. +- Production repair `3422a234a5bfe885040000492f3a2f901c769c88` makes `leftoverMapAxisBadgeShare` delegate finite validation to the existing plot-axis share formatter and return an optional suffix. Missing/non-finite share now becomes `""`, not `NaN%`; finite `0%` remains explicit. +- Vitest strengthening `2efcf06184dcee7815233465fcd9efa32d65aabe` covers finite/zero/missing/non-finite share plus combined, share-only, singular-only (`σ=0` included), and empty helper states. +- Final exact #866 head is `c267657779dce655e6a7a604e93a9799d395cc2f`; exact-head Tests `34984661983` is queued, not GREEN. + +The repair does not infer σ from share or share from σ, does not change SQL, and does not move psychometric/domain truth into LineageWeave. + +### Current non-force leftover-map ancestry + +The #866 movement made the active descendant stack stale. Each child delta was inspected before convergence. Where the child did not modify the repaired helper/contract files, the child tree was preserved and the repaired blobs were adopted through explicit two-parent commits; #867's concurrent test-only comparison-graphic state matrix was semantically combined rather than overwritten. No force-push or destructive rebase was used. + +Current exact linear ancestry: + +`#866 c2676577... -> #867 b70c2a39... -> #868 b25a4d17... -> #869 7c26ba9f... -> #870 f3a4ee56... -> #871 0427b933... -> #872 2193ddf4... -> #873 c80e4e60... -> #874 d4afa56f... -> #875 ef6b5423...` + +All of #866-#875 are open / Draft / mergeable after convergence. Their local singular/share/tick product contracts remain distinct. No predecessor validation receipt transfers. + +Below #875 the current marker/origin topology is: + +- #876 `fd855ab45626b272e594b3d486edc817ff09aa18`: report criterion `ζ` consumes only persisted finite item-axis coordinates and fails closed for unusable pairs. +- #1033 `8a8f4c6ba52712c6376682458ed7ee85ea8c0e44`: comparison criterion `ζ` preserves the same item-coordinate boundary with distinct comparison naming. +- #1034 `9946cb4f38e2d1852558158a6f59e7278d5e4917`: comparison post `ξ` consumes only persisted finite person-axis coordinates; criterion `ζ`, geometry, distance, rank, coverage, singular/share evidence do not infer `ξ`. +- sibling #877 `cd645e4a3eb275d37475987b1b838a76fe18c70e`: comparison origin-tick identity remains canonical formatted zero while share and σ stay independent. + +#876/#877/#1033/#1034 are open / Draft / mergeable after semantic non-force convergence. No open descendants remain below #1034 or #877. Historical #878/#879 remain open delta carriers; their stale full trees are not replayed. Current succession authority is #876 `fd855ab...` -> #1033 `8a8f4c6b...` -> #1034 `9946cb4f...`. They may close only after every valid product/test/fixture/contract/evidence delta is demonstrably inherited and verified. ## Buyer-visible gap register | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | -| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950...` | Authorization repair remains isolated from central review-runtime owner logic. `.github#2170` producer validation is GREEN but its actual CodeQL scan remains queued; `.github#2207` is now `2d61a668...` after verified ADR/changelog semantic repairs and requires entirely fresh evidence. | Canonical CodeQL producer/receiver settlement, authenticated OpenCode verdict, Strix/Noema owner-path revalidation, qualifying approval and normal protected merge. | -| Commercial-safe synchronous PostgreSQL tooling must preserve libpq connection semantics | #910 / #911 `6030b295...` | Test-first timeout compatibility repair preserves zero/negative no-deadline sentinels and decimal-integer URI parsing while keeping runtime on asyncpg. The exact source head is validation-admitted Ready because returning it to Draft cancelled repository-local runs; Tests/PROV-O/Ontology plus Security/SAST/CodeQL are queued. Fresh CodeRabbit review is rate-limited and no exact-head APPROVE exists. | Exact-head repository/security/CodeQL/model-review GREEN, canonical Dependency Review support/availability settlement, qualifying independent approval, ADR 0366 remaining Proposed until normal integration. | -| Contextual-orchestrator consumer boundary and governed measurement/evaluation/operator lineage | #899 `d331d1f6...`; children #902 `8b5cc45d...` -> #915 `6540aceb...`, #919 `53dca4bd...`, and #966 `1be24cd9...` | #902/#915 semantic glossary overlap and disjoint #919 operator delta were converged non-force onto the exact current parent. All are now mergeable Drafts. #902/#915/#919 exact-head Tests are Draft-skipped, not GREEN. | #899 normal integration first, then fresh full repository/security/governance evidence and qualifying independent approvals on unchanged descendant heads; no predecessor receipt transfer. | -| Comparison-graphic axis σ/share identity | #867 `a8129768...` | Production uses graphic-specific helper rather than strip helper; direct Vitest state coverage now exercises empty/share-only/σ-only/combined states. Current Tests run `34967080332` is queued, not GREEN. | Focused contract + frontend/full repository tests, rendered a11y/i18n evidence, applicable Security/SAST/CodeQL/model review and qualifying approval. | -| Singular/share tick stack | #868 `d39343ab...` -> #875 `758da1e8...` | Descendants contain repaired #867 foundation plus the executable helper-state tests through non-force ancestry; PR authority names current parents/heads. | Settle each local RED and fresh exact-head repository/security/browser-a11y/performance/review evidence in parent order. | -| Report/comparison marker identity | #876 `34796209...` -> #1033 `ccf077cf...` -> #1034 `b9dec94a...` | ζ/ζ/ξ boundaries are preserved after current-parent convergence; new Tests `34968725267`, `34968819345`, `34968872059` are queued. Historical #878/#879 remain open delta carriers with current successor authority repaired. | Focused contracts, frontend build/tests, full repository/PostgreSQL validation, rendered keyboard/focus/a11y evidence, applicable security/model review and qualifying approvals. | -| Comparison origin tick identity | #877 `ba9101f5...` | Exact-zero origin and independent share/σ composition are preserved while the upstream executable badge-state tests are inherited; Tests `34968764771` is pending. | Current-head executable contract, frontend build/tests, rendered keyboard/focus/a11y/i18n, applicable security/model review and qualifying approval. | -| Catalog connection leases and summary TOCTOU | #1077 and #1080 | Kept separate from #1079; external/provider work must not hold long database leases and post-provider persistence must revalidate authorization/visibility/source revision. | Causal RED -> GREEN in each owner lane, short-transaction evidence, current-head tests and protected integration. | -| Governed UI translation delivery | #929 and child #932 | Governed versioned translation-ledger work remains in its canonical owner lane; leftover-map work consumes localized labels rather than adding a competing store. | Reviewed `ko/en/ja/zh/vi/es/de/fr` resources plus rendered normal/loading/empty/error/permission/responsive, keyboard/focus/screen-reader, CJK expansion and font-fallback evidence. | -| MCP buyer-path latency | #1009 | Existing measurements remain above the repository `p95 <= 20 ms` acceptance contract. | Representative uncontended measurements, causal query/I/O/runtime profiling, Rust-first hot-path repair where warranted and exact-head gates. | -| Release identity and immutable publication | #961 / #1056 | Candidate release identity work remains Draft; protected main is not release-ready. | Built/installed version proof, normal protected merge, immutable tag/package/release, SBOM/provenance, reproducibility and rollback evidence on one protected SHA. | +| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950...` | Product repository/security tests GREEN; canonical CodeQL actual scan, OpenCode verdict, complete Strix/Noema evidence and qualifying approval remain unsettled. | Owner-path terminal evidence, qualifying approval, normal protected merge. | +| Commercial-safe synchronous PostgreSQL tooling must preserve libpq connection semantics | #910 / #911 `6030b295...` | Test-first timeout compatibility repair is code-current; all current validation/security/CodeQL runs remain queued. | Exact-head GREEN plus qualifying independent approval; no Draft-skipped receipt substitution. | +| Contextual-orchestrator consumer boundary and governed measurement/evaluation/operator lineage | #899 `d331d1f6...`; #902 `8b5cc45d...` -> #915 `6540aceb...`; #919 `53dca4bd...`; #966 `1be24cd9...` | Descendants are non-force converged and mergeable Drafts. | Parent integration followed by fresh full repository/security/governance evidence and qualifying approvals. | +| Report-axis σ/share missingness | #866 `c2676577...` | RED -> causal production repair -> Vitest/contract strengthening complete locally; missing/non-finite share no longer synthesizes `NaN%`; exact-head Tests `34984661983` queued. | Exact-head frontend/full tests, rendered normal/empty/error/permission/responsive and keyboard/focus/a11y/i18n evidence, security/model review, qualifying approval. | +| Comparison-graphic axis σ/share identity | #867 `b70c2a39...` | Graphic-specific helper preserved; concurrent direct state-matrix tests adopted together with #866 repair. | Fresh exact-head repository/rendered/security/review evidence. | +| Singular/share tick stack | #868 `b25a4d17...` -> #875 `ef6b5423...` | All descendants semantically converged onto current parent chain without force-push; local tick/share/singular deltas preserved. | Settle each local RED and fresh exact-head repository/security/browser-a11y/performance/review evidence in parent order. | +| Report/comparison marker identity | #876 `fd855ab...` -> #1033 `8a8f4c6b...` -> #1034 `9946cb4f...` | ζ/ζ/ξ boundaries preserved after current-parent convergence; historical #878/#879 remain open delta carriers. | Focused contracts, frontend/full repository/PostgreSQL validation, rendered keyboard/focus/a11y evidence, security/model review and qualifying approvals. | +| Comparison origin tick identity | #877 `cd645e4a...` | Exact-zero origin and independent share/σ composition preserved after convergence; no open descendant remains. | Current-head executable/frontend/rendered/security evidence and qualifying approval. | +| Catalog connection leases and summary TOCTOU | #1077 and #1080 | Kept separate from #1079; external/provider work must not hold long DB leases and persistence must revalidate authority/revision. | Causal RED -> GREEN in each owner lane, short-transaction evidence, current-head tests and protected integration. | +| Governed UI translation delivery | #929 and child #932 | Versioned translation-ledger work remains in its canonical owner lane; leftover-map consumes localized labels rather than creating a competing store. | `ko/en/ja/zh/vi/es/de/fr` plus rendered normal/loading/empty/error/permission/responsive, keyboard/focus/screen-reader, CJK expansion/font fallback evidence. | +| MCP buyer-path latency | #1009 | Existing evidence remains subject to repository `p95 <= 20 ms` acceptance. | Representative uncontended measurements, causal query/I/O/runtime profiling and Rust-first hot-path repair where warranted. | +| Release identity and immutable publication | #961 / #1056 | Protected main is not release-ready. | Built/installed version proof, normal protected merge, immutable tag/package/release, SBOM/provenance, reproducibility and rollback evidence on one protected SHA. | ## Evidence and ownership rules -Queued, skipped, COMMENTED, cancelled, rate-limited, status-only, -predecessor-head or source-neutral results are not GREEN evidence for a moved -head. A successful dispatch coordinator proves exact-head handoff only; -authenticated producer execution and consumer settlement must still complete on -that same head. +Queued, skipped, COMMENTED, cancelled, rate-limited, status-only, predecessor-head, or source-neutral results are not GREEN evidence for a moved head. A successful dispatch coordinator proves handoff only; authenticated producer execution and consumer settlement must still complete on that same head. -A moved parent invalidates descendant ancestry assumptions immediately. Repair is -non-force: inspect intervening deltas, preserve valid product/contract/test -evidence, then merge/reconstruct/retarget onto the moved parent without rewriting -shared history. Parent GREEN evidence never transfers to the resulting child. +A moved parent invalidates descendant ancestry assumptions immediately. Repair is non-force: inspect intervening deltas, preserve valid product/contract/test evidence, then merge/reconstruct/retarget onto the moved parent without rewriting shared history. Parent GREEN evidence never transfers to the resulting child. -A stale or conflicted PR is not force-rebased or closed merely because a successor -exists. Closure requires complete verified succession of every valid product, -test, fixture, contract and evidence delta, or another explicitly allowed close -condition. +A stale or conflicted PR is not force-rebased or closed merely because a successor exists. Closure requires complete verified succession of every valid product, test, fixture, contract and evidence delta, or another explicitly allowed close condition. -Canonical domain truth stays with its owner. LineageWeave consumes released -contracts/ACLs and does not copy contextual-orchestrator admission/routing, -central CI queue policy, psychometrics implementations, ranking, scheduling or -other owner functionality. +Canonical domain truth stays with its owner. LineageWeave consumes released contracts/ACLs and does not copy contextual-orchestrator admission/routing, central CI queue policy, psychometrics implementations, ranking, scheduling, or other owner functionality. -External/model work stays outside long-lived explicit database transactions and -locks. Persistence reacquires the shortest necessary lease, revalidates -authorization/version state and uses idempotent/UPSERT semantics where required. +External/model work stays outside long-lived explicit database transactions and locks. Persistence reacquires the shortest necessary lease, revalidates authorization/version state and uses idempotent/UPSERT semantics where required. -Material UI requires rendered buyer-path acceptance in addition to unit/repository -evidence: normal/loading/empty/error/permission/responsive behavior, -pointer/touch/keyboard/focus, accessibility, locale expansion/font fallback and -applicable p95 evidence. +Material UI requires rendered buyer-path acceptance in addition to unit/repository evidence: normal/loading/empty/error/permission/responsive behavior, pointer/touch/keyboard/focus, accessibility, locale expansion/font fallback and applicable p95 evidence. ## Historical evidence -The former append-only baseline through 2026-09-13 remains unchanged at -[`docs/evidence/product-technical-gap-baseline-history-through-20260913.md`](evidence/product-technical-gap-baseline-history-through-20260913.md). -It is provenance, not current authority. \ No newline at end of file +The former append-only baseline through 2026-09-13 remains unchanged at [`docs/evidence/product-technical-gap-baseline-history-through-20260913.md`](evidence/product-technical-gap-baseline-history-through-20260913.md). It is provenance, not current authority. From 8af96128a2f37a48ce40e49ad86280e54f81852c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 16 Sep 2026 02:03:23 +0900 Subject: [PATCH 081/276] docs(gaps): record live report-axis RED and descendant convergence --- docs/product-technical-gap-baseline.md | 98 +++++++++++--------------- 1 file changed, 42 insertions(+), 56 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 76d7af0da..3e3d36b62 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,97 +1,83 @@ # Product & Technical Gap Baseline -> Current authority snapshot: 2026-09-15. +> Current authority snapshot: 2026-09-16. > -> Protected `main` is `83eba56149eb802cd63642c507c324c9976ec78e` at this projection. -> Protected refs, live PRs/Issues, ADRs, and exact-head receipts remain authoritative. -> Historical overlays through 2026-09-13 are preserved in -> [`evidence/product-technical-gap-baseline-history-through-20260913.md`](evidence/product-technical-gap-baseline-history-through-20260913.md). +> Protected `main` observed at `83eba56149eb802cd63642c507c324c9976ec78e`. +> Protected refs, live PRs/Issues, ADRs, exact heads and exact-head receipts are authoritative. +> Historical overlays through 2026-09-13 remain in +> [`docs/evidence/product-technical-gap-baseline-history-through-20260913.md`](evidence/product-technical-gap-baseline-history-through-20260913.md). ## Protected delivery baseline -No LineageWeave release is admitted from the current protected head. A moved parent invalidates descendant acceptance evidence; branch convergence never transfers predecessor receipts. +No LineageWeave release is admitted from the current protected head. A moved parent invalidates descendant acceptance evidence. A semantic/non-force convergence preserves valid deltas but never transfers predecessor validation receipts. ### Summary shared-catalog authorization -#1079 remains open / Ready / mergeable at exact `c2923950e73c88a9f9fd932332ddd47682da124b` on protected `main@83eba56149eb802cd63642c507c324c9976ec78e`. Reader summary materialization remains fail-closed for shared Customer Master catalog mutation while explicit `post_admin` retains canonical create/upsert authority. Its product repository/security tests are GREEN, but canonical review-runtime settlement is not complete. - -Required CodeQL has passed language detection, coordinator dispatch, and canonical producer `validate-dispatch`; actual JavaScript/TypeScript, Python, and Actions scan jobs remain queued without runners. OpenCode source/evidence coverage is GREEN but no authenticated exact-head verdict has materialized. Strix produced a zero-finding artifact but refused GREEN when contextual-orchestrator returned bounded concurrency overload. Noema was cancelled after review-sidecar provisioning never became ready; no model verdict ran. These are canonical `.github`/contextual-orchestrator owner-path conditions, not reasons to copy queue, provider, timeout, retry, credential, or status logic into LineageWeave. - -Foundation order remains `.github#2170 normal integration -> ordinary/non-force .github#1629 reconciliation -> fresh #1629 acceptance`. Historical `.github#2140` stays open while current-main successor `.github#2207` exact `2d61a668a0d7f0f4bb51c7805945db15e81f0bec` obtains fresh current-head checks and independent review. First-byte silence is only a transport-level no-progress observation; occupancy release does not become a provider/model penalty, circuit-break, or route-ranking signal. +#1079 remains the Customer Master/shared-catalog authorization candidate at exact `c2923950e73c88a9f9fd932332ddd47682da124b`. Product repository/security evidence exists, but canonical CodeQL actual scans, authenticated OpenCode verdict, complete Strix/Noema owner-path settlement and qualifying independent approval remain outstanding. Canonical review/runtime queue, provider, timeout, retry and credential behavior stays in `.github` and contextual-orchestrator; LineageWeave does not copy it. ### Commercial-safe synchronous PostgreSQL boundary -#911 remains exact `6030b295aadc3ee76dc4d27f5713273f35888325`, open / Ready / mergeable. Ready is validation admission only. RED `326a97d89b3642fae392857218e4274bd456a8c0` captures libpq-compatible `connect_timeout` behavior: URI values are decimal integers and zero/negative values are no-deadline sentinels. Causal repair `b7838e40d6a200b8b9474cd03fcd52046c80bd6b` restores those semantics at the pg8000 synchronous compatibility boundary; runtime persistence remains `asyncpg`. Changelog commit `6030b295...` is code-current. - -Exact-head Tests `34978833151`, PROV-O `34978832987`, Ontology Pages `34978833063`, Security `34977841173`, SAST `34977841093`, and CodeQL `34977841115` remain queued. A skipped/cancelled Draft run is not GREEN evidence, and no qualifying exact-head independent approval exists. +#911 remains exact `6030b295aadc3ee76dc4d27f5713273f35888325`. Its test-first pg8000 compatibility repair preserves libpq-style integer `connect_timeout` semantics and treats non-positive values as no-deadline sentinels. Runtime persistence remains `asyncpg`. Ready state is validation admission, not merge acceptance; current-head repository/security/CodeQL evidence and qualifying independent approval are still required. ### Owner-boundary and governed measurement stack -#899 remains the contextual-orchestrator consumer-boundary foundation at exact `d331d1f6b05d39385a652be6dbb8f279871a2e2e`. Its converged descendants remain #902 `8b5cc45dbb2d6ef7bb3b49a10c33cdfb93b483cc` -> #915 `6540acebbb3ecef4736ebeefa6c0c4486b002b79`, #919 `53dca4bda5dee5d1f4dceb75ea3c53d85bbc8e62`, and #966 `1be24cd923b89a64f41d05bea8534b552e1ee7bc`. Draft-skipped Tests are not product GREEN. Canonical model/provider behavior stays in contextual-orchestrator; measurement truth stays with its canonical owners. +#899 remains the contextual-orchestrator consumer-boundary foundation at `d331d1f6b05d39385a652be6dbb8f279871a2e2e`. Descendant evaluation/measurement lanes remain separate from LineageWeave domain truth. Provider/model/routing behavior stays in contextual-orchestrator; psychometric truth stays in its canonical owners. -### Leftover-map report-axis missingness repair +## Active leftover-map foundation finding -Fresh review of #866 found a buyer-visible composition defect that its existing helper contract did not exercise end-to-end. The helper described independent persisted σ/share states, but the report rendering path still consumed coupled primitives. With a valid persisted σ and missing/non-finite share, `leftoverMapAxisBadgeShare` could synthesize `NaN%` and the report template could not preserve σ cleanly without share. +Fresh review of #866 found that the four-state report-axis projection exists but the buyer path still bypasses it. -The repair is test-first and local to LineageWeave presentation composition: +Current #866 exact head is `35f4b07fd91a01ce14c31059fa4d46ad3a9ca5a2`, based on #865 `0728f56ba66f16783685c84d9d3aa034eea9f143`. The helper `leftoverMapAxisBadge(axis)` already distinguishes combined, singular-only, share-only and empty evidence, preserves finite `σ=0`, and fails closed for unusable values. The live `frontend/src/App.tsx`, however, still composes `leftoverMapAxisBadgeSingular` and `leftoverMapAxisBadgeShare` directly. When neither persisted datum is usable, the report can still emit a badge shell instead of omitting evidence. -- RED `7c570b484b4298fbd0a699003f05980aee6235e8` adds a report-path contract for independent σ/share evidence. -- Production repair `3422a234a5bfe885040000492f3a2f901c769c88` makes `leftoverMapAxisBadgeShare` delegate finite validation to the existing plot-axis share formatter and return an optional suffix. Missing/non-finite share now becomes `""`, not `NaN%`; finite `0%` remains explicit. -- Vitest strengthening `2efcf06184dcee7815233465fcd9efa32d65aabe` covers finite/zero/missing/non-finite share plus combined, share-only, singular-only (`σ=0` included), and empty helper states. -- Final exact #866 head is `c267657779dce655e6a7a604e93a9799d395cc2f`; exact-head Tests `34984661983` is queued, not GREEN. +`tests/test_leftover_axis_report_singular_only_contract.py` is the current executable RED. It requires the report path to call `leftoverMapAxisBadge(axis)`, render only non-null projections, and stop importing the two primitive helpers. The minimal causal production fix is confined to `App.tsx`; it does not alter SQL, persistence, psychometric estimation or a canonical-owner contract. -The repair does not infer σ from share or share from σ, does not change SQL, and does not move psychometric/domain truth into LineageWeave. +One-shot run `34997230462` is queued on auxiliary exact `c39342a735f484b8895f65eee7b2b43de8634cff`. It verifies the RED before applying the two exact buyer-path substitutions and focused GREEN contract. Queued is not GREEN. If #866 moves, every descendant must converge again from the resulting exact head. -### Current non-force leftover-map ancestry +## Current non-force ancestry -The #866 movement made the active descendant stack stale. Each child delta was inspected before convergence. Where the child did not modify the repaired helper/contract files, the child tree was preserved and the repaired blobs were adopted through explicit two-parent commits; #867's concurrent test-only comparison-graphic state matrix was semantically combined rather than overwritten. No force-push or destructive rebase was used. +#867 currently sits at `8e76dc8dd5f9cc357622df0e8ebdb9a8a033a8c7`. Its own comparison-axis badge product delta remains intact, and it has already adopted #866's current comparison-tick executable contract. Its PR base snapshot is still the predecessor #866 head, because the compatible `LeftoverMapPlot.tsx` source composition and two-parent ancestry have not yet executed. One-shot convergence run `34997608532` is queued on auxiliary exact `9d491fa744bf38df4fa1df07050f57a6b5fa97ff`; the first attempt failed before job admission because the generated workflow YAML contained an unindented multiline Python literal, and that RCA was repaired rather than blindly rerun. -Current exact linear ancestry: +The descendant stack was immediately converged non-force onto the current #867 head so no child remains pointed at the older `8ba406...` parent. These exact heads preserve each lane's distinct product/test delta: -`#866 c2676577... -> #867 b70c2a39... -> #868 b25a4d17... -> #869 7c26ba9f... -> #870 f3a4ee56... -> #871 0427b933... -> #872 2193ddf4... -> #873 c80e4e60... -> #874 d4afa56f... -> #875 ef6b5423...` +`#867 8e76dc8d... -> #868 b71b0451... -> #869 2d8f8c31... -> #870 1bc75aac... -> #871 b7b9ad82... -> #872 f3d1df48... -> #873 59fa0966... -> #874 da862b35... -> #875 05ca9a16...` -All of #866-#875 are open / Draft / mergeable after convergence. Their local singular/share/tick product contracts remain distinct. No predecessor validation receipt transfers. +Below #875, current exact topology is: -Below #875 the current marker/origin topology is: +- #876 `5dd5152d4772fc337995675a73c68facfaa14a95`: report criterion `ζ`, persisted finite item-axis pair only. +- #1033 `cce3c6d0fe1bca7b121d3218b1909ec6e8878ea1`: comparison criterion `ζ`, same item-coordinate boundary with distinct comparison identity. +- #1034 `d2e0eb630044f81bb23e201d25ff0580e7d6d7d9`: comparison post `ξ`, persisted finite person-axis pair only. +- sibling #877 `23c0988d7698b777053e8588a70075f4bcdb8157`: origin tick identity is canonical formatted zero; share and σ remain independent. -- #876 `fd855ab45626b272e594b3d486edc817ff09aa18`: report criterion `ζ` consumes only persisted finite item-axis coordinates and fails closed for unusable pairs. -- #1033 `8a8f4c6ba52712c6376682458ed7ee85ea8c0e44`: comparison criterion `ζ` preserves the same item-coordinate boundary with distinct comparison naming. -- #1034 `9946cb4f38e2d1852558158a6f59e7278d5e4917`: comparison post `ξ` consumes only persisted finite person-axis coordinates; criterion `ζ`, geometry, distance, rank, coverage, singular/share evidence do not infer `ξ`. -- sibling #877 `cd645e4a3eb275d37475987b1b838a76fe18c70e`: comparison origin-tick identity remains canonical formatted zero while share and σ stay independent. +All are open Drafts and currently mergeable after their latest ordinary two-parent convergence. This does **not** mean the stack is settled: when #867 acquires #866's source/ancestry delta, and when #866 later acquires the causal `App.tsx` repair, the full descendant chain must converge again. No current descendant receipt can be treated as acceptance for those future heads. -#876/#877/#1033/#1034 are open / Draft / mergeable after semantic non-force convergence. No open descendants remain below #1034 or #877. Historical #878/#879 remain open delta carriers; their stale full trees are not replayed. Current succession authority is #876 `fd855ab...` -> #1033 `8a8f4c6b...` -> #1034 `9946cb4f...`. They may close only after every valid product/test/fixture/contract/evidence delta is demonstrably inherited and verified. +Historical #878/#879 remain open delta/evidence carriers. They are not closed merely because #876/#1033/#1034 reconstruct their intended product contracts; closure still requires complete verified succession of every valid product, test, fixture, contract and evidence delta. ## Buyer-visible gap register | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | -| Summary reads must not mutate Customer Master shared catalogs | #1078 / #1079 `c2923950...` | Product repository/security tests GREEN; canonical CodeQL actual scan, OpenCode verdict, complete Strix/Noema evidence and qualifying approval remain unsettled. | Owner-path terminal evidence, qualifying approval, normal protected merge. | -| Commercial-safe synchronous PostgreSQL tooling must preserve libpq connection semantics | #910 / #911 `6030b295...` | Test-first timeout compatibility repair is code-current; all current validation/security/CodeQL runs remain queued. | Exact-head GREEN plus qualifying independent approval; no Draft-skipped receipt substitution. | -| Contextual-orchestrator consumer boundary and governed measurement/evaluation/operator lineage | #899 `d331d1f6...`; #902 `8b5cc45d...` -> #915 `6540aceb...`; #919 `53dca4bd...`; #966 `1be24cd9...` | Descendants are non-force converged and mergeable Drafts. | Parent integration followed by fresh full repository/security/governance evidence and qualifying approvals. | -| Report-axis σ/share missingness | #866 `c2676577...` | RED -> causal production repair -> Vitest/contract strengthening complete locally; missing/non-finite share no longer synthesizes `NaN%`; exact-head Tests `34984661983` queued. | Exact-head frontend/full tests, rendered normal/empty/error/permission/responsive and keyboard/focus/a11y/i18n evidence, security/model review, qualifying approval. | -| Comparison-graphic axis σ/share identity | #867 `b70c2a39...` | Graphic-specific helper preserved; concurrent direct state-matrix tests adopted together with #866 repair. | Fresh exact-head repository/rendered/security/review evidence. | -| Singular/share tick stack | #868 `b25a4d17...` -> #875 `ef6b5423...` | All descendants semantically converged onto current parent chain without force-push; local tick/share/singular deltas preserved. | Settle each local RED and fresh exact-head repository/security/browser-a11y/performance/review evidence in parent order. | -| Report/comparison marker identity | #876 `fd855ab...` -> #1033 `8a8f4c6b...` -> #1034 `9946cb4f...` | ζ/ζ/ξ boundaries preserved after current-parent convergence; historical #878/#879 remain open delta carriers. | Focused contracts, frontend/full repository/PostgreSQL validation, rendered keyboard/focus/a11y evidence, security/model review and qualifying approvals. | -| Comparison origin tick identity | #877 `cd645e4a...` | Exact-zero origin and independent share/σ composition preserved after convergence; no open descendant remains. | Current-head executable/frontend/rendered/security evidence and qualifying approval. | -| Catalog connection leases and summary TOCTOU | #1077 and #1080 | Kept separate from #1079; external/provider work must not hold long DB leases and persistence must revalidate authority/revision. | Causal RED -> GREEN in each owner lane, short-transaction evidence, current-head tests and protected integration. | -| Governed UI translation delivery | #929 and child #932 | Versioned translation-ledger work remains in its canonical owner lane; leftover-map consumes localized labels rather than creating a competing store. | `ko/en/ja/zh/vi/es/de/fr` plus rendered normal/loading/empty/error/permission/responsive, keyboard/focus/screen-reader, CJK expansion/font fallback evidence. | -| MCP buyer-path latency | #1009 | Existing evidence remains subject to repository `p95 <= 20 ms` acceptance. | Representative uncontended measurements, causal query/I/O/runtime profiling and Rust-first hot-path repair where warranted. | -| Release identity and immutable publication | #961 / #1056 | Protected main is not release-ready. | Built/installed version proof, normal protected merge, immutable tag/package/release, SBOM/provenance, reproducibility and rollback evidence on one protected SHA. | +| Summary reads must not mutate Customer Master shared catalogs | #1079 `c2923950...` | Product repository/security evidence exists; central model/review settlement is incomplete. | Canonical owner-path terminal evidence, qualifying approval, normal protected merge. | +| Commercial-safe synchronous PostgreSQL tooling | #911 `6030b295...` | Test-first timeout compatibility repair is code-current. | Exact-head repository/security/CodeQL GREEN and qualifying approval. | +| Report-axis σ/share missingness | #866 `35f4b07...` | Four-state helper and executable RED exist; live buyer path still bypasses projection. Repair run `34997230462` queued. | Causal `App.tsx` GREEN, fresh frontend/full/rendered/a11y/i18n/security evidence and qualifying approval. | +| Comparison-graphic axis σ/share identity | #867 `8e76dc8...` | Product/helper contract retained; parent executable tick contract adopted. Source/ancestry convergence run `34997608532` queued. | Exact parent convergence, then fresh repository/rendered/security/review evidence. | +| Singular/share tick stack | #868 `b71b045...` -> #875 `05ca9a16...` | Child deltas preserved through ordinary two-parent convergence onto current #867 test head. | Re-converge after #867/#866 move; fresh exact-head repository/browser/security/performance/review evidence in parent order. | +| Report/comparison marker identity | #876 `5dd5152d...` -> #1033 `cce3c6d0...` -> #1034 `d2e0eb63...` | ζ/ζ/ξ owner boundaries preserved after latest convergence. | Re-converge on foundation movement; focused/full/rendered/security evidence and qualifying approvals. | +| Comparison origin identity | #877 `23c0988d...` | Exact-zero origin and independent share/σ composition preserved. | Re-converge on foundation movement; executable/rendered/a11y/i18n/security evidence and qualifying approval. | +| Catalog connection leases and summary TOCTOU | #1077 / #1080 | Separate owner lanes; external/model work must not hold long DB leases. | Causal RED→GREEN, short-transaction evidence and protected integration. | +| Governed UI translation delivery | #929 / #932 | Versioned translation-ledger work remains in its canonical owner lane. | `ko/en/ja/zh/vi/es/de/fr`, normal/loading/empty/error/permission/responsive, keyboard/focus/screen-reader, CJK expansion/font fallback. | +| MCP buyer-path latency | #1009 | Repository target remains p95 ≤ 20 ms where applicable. | Representative measurements and causal profiling; Rust-first hot-path repair if warranted. | +| Release identity and immutable publication | #961 / #1056 | Protected main is not release-ready. | One protected SHA with version/CHANGELOG/tag/package/release, SBOM/provenance, reproducibility and rollback evidence. | ## Evidence and ownership rules -Queued, skipped, COMMENTED, cancelled, rate-limited, status-only, predecessor-head, or source-neutral results are not GREEN evidence for a moved head. A successful dispatch coordinator proves handoff only; authenticated producer execution and consumer settlement must still complete on that same head. - -A moved parent invalidates descendant ancestry assumptions immediately. Repair is non-force: inspect intervening deltas, preserve valid product/contract/test evidence, then merge/reconstruct/retarget onto the moved parent without rewriting shared history. Parent GREEN evidence never transfers to the resulting child. - -A stale or conflicted PR is not force-rebased or closed merely because a successor exists. Closure requires complete verified succession of every valid product, test, fixture, contract and evidence delta, or another explicitly allowed close condition. +Queued, skipped, COMMENTED, cancelled, rate-limited, status-only, predecessor-head or source-neutral results are not GREEN evidence for a moved head. A successful dispatcher or coordinator proves handoff only; producer execution and consumer settlement must complete on the same exact head. -Canonical domain truth stays with its owner. LineageWeave consumes released contracts/ACLs and does not copy contextual-orchestrator admission/routing, central CI queue policy, psychometrics implementations, ranking, scheduling, or other owner functionality. +A moved parent invalidates descendant ancestry immediately. Repair is ordinary/non-force: inspect intervening deltas, preserve valid product/test/fixture/contract evidence, then create a semantic two-parent convergence or safe reconstruction. Force-push, destructive rebase and receipt inheritance are not acceptable substitutes. -External/model work stays outside long-lived explicit database transactions and locks. Persistence reacquires the shortest necessary lease, revalidates authorization/version state and uses idempotent/UPSERT semantics where required. +A conflicted or stale PR is repaired, not closed by convenience. Closure requires normal merge, complete verified successor inheritance, user direction, no valid delta, or another explicitly permitted condition. -Material UI requires rendered buyer-path acceptance in addition to unit/repository evidence: normal/loading/empty/error/permission/responsive behavior, pointer/touch/keyboard/focus, accessibility, locale expansion/font fallback and applicable p95 evidence. +Canonical domain truth stays with its owner. LineageWeave consumes released contracts/ACLs and does not copy contextual-orchestrator routing/admission, central CI queue policy, psychometrics implementations, ranking, scheduling or other owner functionality. -## Historical evidence +External/model work stays outside long-lived explicit database transactions and locks. Persistence reacquires the shortest necessary lease, revalidates authorization/version state, and uses idempotent/UPSERT semantics where required. -The former append-only baseline through 2026-09-13 remains unchanged at [`docs/evidence/product-technical-gap-baseline-history-through-20260913.md`](evidence/product-technical-gap-baseline-history-through-20260913.md). It is provenance, not current authority. +Material UI acceptance requires rendered buyer-path evidence in addition to unit/repository checks: normal/loading/empty/error/permission/responsive states, pointer/touch/keyboard/focus, accessibility, locale expansion/font fallback and applicable performance evidence. From 74f9cfd0ea7b89afe3f4427589670f6b3b258d2b Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 16 Sep 2026 02:52:30 +0900 Subject: [PATCH 082/276] docs(gaps): repair live leftover-map ancestry authority --- docs/product-technical-gap-baseline.md | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 3e3d36b62..21871e9a3 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -25,6 +25,8 @@ No LineageWeave release is admitted from the current protected head. A moved par ## Active leftover-map foundation finding +A fresh authority sweep found that the Git ancestry had already been converged by ordinary two-parent commits while several PR bodies still advertised predecessor SHAs. The live precondition chain is now recorded consistently as `#859 2550e8d8... -> #860 2084d534... -> #861 59ae392c... -> #862 f0588b94... -> #863 bac8d3a5... -> #865 0728f56b... -> #866 35f4b07f...`. The #860/#861/#862/#863/#865 PR authorities were repaired without changing their source refs, and no validation receipt was transferred by that metadata repair. + Fresh review of #866 found that the four-state report-axis projection exists but the buyer path still bypasses it. Current #866 exact head is `35f4b07fd91a01ce14c31059fa4d46ad3a9ca5a2`, based on #865 `0728f56ba66f16783685c84d9d3aa034eea9f143`. The helper `leftoverMapAxisBadge(axis)` already distinguishes combined, singular-only, share-only and empty evidence, preserves finite `σ=0`, and fails closed for unusable values. The live `frontend/src/App.tsx`, however, still composes `leftoverMapAxisBadgeSingular` and `leftoverMapAxisBadgeShare` directly. When neither persisted datum is usable, the report can still emit a badge shell instead of omitting evidence. @@ -50,7 +52,7 @@ Below #875, current exact topology is: All are open Drafts and currently mergeable after their latest ordinary two-parent convergence. This does **not** mean the stack is settled: when #867 acquires #866's source/ancestry delta, and when #866 later acquires the causal `App.tsx` repair, the full descendant chain must converge again. No current descendant receipt can be treated as acceptance for those future heads. -Historical #878/#879 remain open delta/evidence carriers. They are not closed merely because #876/#1033/#1034 reconstruct their intended product contracts; closure still requires complete verified succession of every valid product, test, fixture, contract and evidence delta. +Historical #878/#879 remain open delta/evidence carriers. Their succession authority is current with #876 `5dd5152d...`, #1033 `cce3c6d0...`, and #1034 `d2e0eb63...`; they are not closed merely because those reconstructed successors preserve the intended product contracts. Closure still requires complete verified succession of every valid product, test, fixture, contract and evidence delta. ## Buyer-visible gap register @@ -80,4 +82,4 @@ Canonical domain truth stays with its owner. LineageWeave consumes released cont External/model work stays outside long-lived explicit database transactions and locks. Persistence reacquires the shortest necessary lease, revalidates authorization/version state, and uses idempotent/UPSERT semantics where required. -Material UI acceptance requires rendered buyer-path evidence in addition to unit/repository checks: normal/loading/empty/error/permission/responsive states, pointer/touch/keyboard/focus, accessibility, locale expansion/font fallback and applicable performance evidence. +Material UI acceptance requires rendered buyer-path evidence in addition to unit/repository checks: normal/loading/empty/error/permission/responsive states, pointer/touch/keyboard/focus, accessibility, locale expansion/font fallback and applicable performance evidence. \ No newline at end of file From 0cd2d492a8fa85fbb91bea1232678006b73d6027 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 16 Sep 2026 04:52:57 +0900 Subject: [PATCH 083/276] docs(gaps): refresh exact-head validation evidence --- docs/product-technical-gap-baseline.md | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 21871e9a3..88cfe416b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -17,7 +17,7 @@ No LineageWeave release is admitted from the current protected head. A moved par ### Commercial-safe synchronous PostgreSQL boundary -#911 remains exact `6030b295aadc3ee76dc4d27f5713273f35888325`. Its test-first pg8000 compatibility repair preserves libpq-style integer `connect_timeout` semantics and treats non-positive values as no-deadline sentinels. Runtime persistence remains `asyncpg`. Ready state is validation admission, not merge acceptance; current-head repository/security/CodeQL evidence and qualifying independent approval are still required. +#911 remains exact `6030b295aadc3ee76dc4d27f5713273f35888325`. Its test-first pg8000 compatibility repair preserves libpq-style integer `connect_timeout` semantics and treats non-positive values as no-deadline sentinels. Runtime persistence remains `asyncpg`. Exact-head Tests `34978833151`, PROV-O `34978832987`, Ontology Pages `34978833063`, and SAST `34977841093` are terminal GREEN. Security `34977841173` and CodeQL PR `34977841115` remain queued, and there is still no qualifying independent exact-head `APPROVED` review. Ready state is validation admission, not merge acceptance. ### Owner-boundary and governed measurement stack @@ -39,6 +39,8 @@ One-shot run `34997230462` is queued on auxiliary exact `c39342a735f484b8895f65e #867 currently sits at `8e76dc8dd5f9cc357622df0e8ebdb9a8a033a8c7`. Its own comparison-axis badge product delta remains intact, and it has already adopted #866's current comparison-tick executable contract. Its PR base snapshot is still the predecessor #866 head, because the compatible `LeftoverMapPlot.tsx` source composition and two-parent ancestry have not yet executed. One-shot convergence run `34997608532` is queued on auxiliary exact `9d491fa744bf38df4fa1df07050f57a6b5fa97ff`; the first attempt failed before job admission because the generated workflow YAML contained an unindented multiline Python literal, and that RCA was repaired rather than blindly rerun. +#1110 is the explicit #866→#867 conflict/evidence carrier. It is now open / Draft, not Ready: GitHub may report the carrier mechanically mergeable, but that is not successor convergence evidence. Keep it open until the ordinary two-parent successor exists on #867 and its valid delta/tests are verified; if #866 advances from the pending `App.tsx` repair, that movement must be converged as well before promotion. + The descendant stack was immediately converged non-force onto the current #867 head so no child remains pointed at the older `8ba406...` parent. These exact heads preserve each lane's distinct product/test delta: `#867 8e76dc8d... -> #868 b71b0451... -> #869 2d8f8c31... -> #870 1bc75aac... -> #871 b7b9ad82... -> #872 f3d1df48... -> #873 59fa0966... -> #874 da862b35... -> #875 05ca9a16...` @@ -59,9 +61,9 @@ Historical #878/#879 remain open delta/evidence carriers. Their succession autho | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | | Summary reads must not mutate Customer Master shared catalogs | #1079 `c2923950...` | Product repository/security evidence exists; central model/review settlement is incomplete. | Canonical owner-path terminal evidence, qualifying approval, normal protected merge. | -| Commercial-safe synchronous PostgreSQL tooling | #911 `6030b295...` | Test-first timeout compatibility repair is code-current. | Exact-head repository/security/CodeQL GREEN and qualifying approval. | +| Commercial-safe synchronous PostgreSQL tooling | #911 `6030b295...` | Exact-head Tests/PROV-O/Ontology/SAST are GREEN after the timeout compatibility repair. | Security and CodeQL terminal GREEN plus qualifying independent exact-head approval. | | Report-axis σ/share missingness | #866 `35f4b07...` | Four-state helper and executable RED exist; live buyer path still bypasses projection. Repair run `34997230462` queued. | Causal `App.tsx` GREEN, fresh frontend/full/rendered/a11y/i18n/security evidence and qualifying approval. | -| Comparison-graphic axis σ/share identity | #867 `8e76dc8...` | Product/helper contract retained; parent executable tick contract adopted. Source/ancestry convergence run `34997608532` queued. | Exact parent convergence, then fresh repository/rendered/security/review evidence. | +| Comparison-graphic axis σ/share identity | #867 `8e76dc8...` | Product/helper contract retained; parent executable tick contract adopted. Source/ancestry convergence run `34997608532` queued; #1110 is Draft conflict/evidence carrier. | Exact parent convergence, then fresh repository/rendered/security/review evidence. | | Singular/share tick stack | #868 `b71b045...` -> #875 `05ca9a16...` | Child deltas preserved through ordinary two-parent convergence onto current #867 test head. | Re-converge after #867/#866 move; fresh exact-head repository/browser/security/performance/review evidence in parent order. | | Report/comparison marker identity | #876 `5dd5152d...` -> #1033 `cce3c6d0...` -> #1034 `d2e0eb63...` | ζ/ζ/ξ owner boundaries preserved after latest convergence. | Re-converge on foundation movement; focused/full/rendered/security evidence and qualifying approvals. | | Comparison origin identity | #877 `23c0988d...` | Exact-zero origin and independent share/σ composition preserved. | Re-converge on foundation movement; executable/rendered/a11y/i18n/security evidence and qualifying approval. | From a37e66bf57ccdb47b120cf9e2821cfb78f11685e Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 16 Sep 2026 05:22:47 +0900 Subject: [PATCH 084/276] docs(gaps): refresh leftover-map convergence and repair RCA --- docs/product-technical-gap-baseline.md | 44 ++++++++++++-------------- 1 file changed, 20 insertions(+), 24 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 88cfe416b..52def8f02 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -25,36 +25,32 @@ No LineageWeave release is admitted from the current protected head. A moved par ## Active leftover-map foundation finding -A fresh authority sweep found that the Git ancestry had already been converged by ordinary two-parent commits while several PR bodies still advertised predecessor SHAs. The live precondition chain is now recorded consistently as `#859 2550e8d8... -> #860 2084d534... -> #861 59ae392c... -> #862 f0588b94... -> #863 bac8d3a5... -> #865 0728f56b... -> #866 35f4b07f...`. The #860/#861/#862/#863/#865 PR authorities were repaired without changing their source refs, and no validation receipt was transferred by that metadata repair. +#866 remains the active report-axis buyer-path RED at exact `35f4b07fd91a01ce14c31059fa4d46ad3a9ca5a2`, based on #865 `0728f56ba66f16783685c84d9d3aa034eea9f143`. The helper `leftoverMapAxisBadge(axis)` already distinguishes combined, singular-only, share-only and empty evidence, preserves finite `σ=0`, and fails closed for unusable values. The live `frontend/src/App.tsx`, however, still composes `leftoverMapAxisBadgeSingular` and `leftoverMapAxisBadgeShare` directly. When neither persisted datum is usable, the report can still emit a badge shell instead of omitting evidence. -Fresh review of #866 found that the four-state report-axis projection exists but the buyer path still bypasses it. +`tests/test_leftover_axis_report_singular_only_contract.py` remains the executable RED. It requires the report path to call `leftoverMapAxisBadge(axis)`, render only non-null projections, and stop importing the two primitive helpers. The minimal causal production fix remains confined to `App.tsx`; it does not alter SQL, persistence, psychometric estimation or a canonical-owner contract. -Current #866 exact head is `35f4b07fd91a01ce14c31059fa4d46ad3a9ca5a2`, based on #865 `0728f56ba66f16783685c84d9d3aa034eea9f143`. The helper `leftoverMapAxisBadge(axis)` already distinguishes combined, singular-only, share-only and empty evidence, preserves finite `σ=0`, and fails closed for unusable values. The live `frontend/src/App.tsx`, however, still composes `leftoverMapAxisBadgeSingular` and `leftoverMapAxisBadgeShare` directly. When neither persisted datum is usable, the report can still emit a badge shell instead of omitting evidence. - -`tests/test_leftover_axis_report_singular_only_contract.py` is the current executable RED. It requires the report path to call `leftoverMapAxisBadge(axis)`, render only non-null projections, and stop importing the two primitive helpers. The minimal causal production fix is confined to `App.tsx`; it does not alter SQL, persistence, psychometric estimation or a canonical-owner contract. - -One-shot run `34997230462` is queued on auxiliary exact `c39342a735f484b8895f65eee7b2b43de8634cff`. It verifies the RED before applying the two exact buyer-path substitutions and focused GREEN contract. Queued is not GREEN. If #866 moves, every descendant must converge again from the resulting exact head. +One-shot run `34997230462` eventually received a GitHub-hosted runner. It verified the exact RED head successfully, then failed in `Apply minimal causal fix` because the automation literal for the import block contained indentation that the real source does not contain. GREEN, commit and push steps were skipped. This is an automation-code RCA, not a product verdict. The workflow was repaired at auxiliary exact `468571288ba8ef45065c188c8d3a28ff2105cf7e` using line-joined exact source blocks and the current checkout action; replacement run `35016883619` is queued. Queued is not GREEN. Once #866 moves, every descendant must converge again from the resulting exact head. ## Current non-force ancestry -#867 currently sits at `8e76dc8dd5f9cc357622df0e8ebdb9a8a033a8c7`. Its own comparison-axis badge product delta remains intact, and it has already adopted #866's current comparison-tick executable contract. Its PR base snapshot is still the predecessor #866 head, because the compatible `LeftoverMapPlot.tsx` source composition and two-parent ancestry have not yet executed. One-shot convergence run `34997608532` is queued on auxiliary exact `9d491fa744bf38df4fa1df07050f57a6b5fa97ff`; the first attempt failed before job admission because the generated workflow YAML contained an unindented multiline Python literal, and that RCA was repaired rather than blindly rerun. +The previously stale #866→#867 parent convergence completed successfully in run `34997608532`. #867 is now exact `1d5e0d7aa86ab4d45e9834c5630ae2d9374f46ec`, directly based on current #866 `35f4b07fd91a01ce14c31059fa4d46ad3a9ca5a2`; its comparison-axis σ/share product delta remains intact. This convergence does not pre-adopt the still-pending #866 `App.tsx` repair and transfers no validation receipts. -#1110 is the explicit #866→#867 conflict/evidence carrier. It is now open / Draft, not Ready: GitHub may report the carrier mechanically mergeable, but that is not successor convergence evidence. Keep it open until the ordinary two-parent successor exists on #867 and its valid delta/tests are verified; if #866 advances from the pending `App.tsx` repair, that movement must be converged as well before promotion. +The live descendant chain is: -The descendant stack was immediately converged non-force onto the current #867 head so no child remains pointed at the older `8ba406...` parent. These exact heads preserve each lane's distinct product/test delta: - -`#867 8e76dc8d... -> #868 b71b0451... -> #869 2d8f8c31... -> #870 1bc75aac... -> #871 b7b9ad82... -> #872 f3d1df48... -> #873 59fa0966... -> #874 da862b35... -> #875 05ca9a16...` +`#867 1d5e0d7a... -> #868 de64a973... -> #869 dc3b9fc4... -> #870 0b6a21a0... -> #871 4448ffd1... -> #872 167f63f5... -> #873 41a755cc... -> #874 e75f5ff4... -> #875 8bfc9511...` Below #875, current exact topology is: -- #876 `5dd5152d4772fc337995675a73c68facfaa14a95`: report criterion `ζ`, persisted finite item-axis pair only. -- #1033 `cce3c6d0fe1bca7b121d3218b1909ec6e8878ea1`: comparison criterion `ζ`, same item-coordinate boundary with distinct comparison identity. -- #1034 `d2e0eb630044f81bb23e201d25ff0580e7d6d7d9`: comparison post `ξ`, persisted finite person-axis pair only. -- sibling #877 `23c0988d7698b777053e8588a70075f4bcdb8157`: origin tick identity is canonical formatted zero; share and σ remain independent. +- #876 `6a1c46546fc6b74564af8f7834a17ca6275a5e21`: report criterion `ζ`, persisted finite item-axis pair only. +- #1033 `a29e2979ff85aaee30ad906e577aafdc8dd8e5c2`: comparison criterion `ζ`, same item-coordinate boundary with distinct comparison identity. +- #1034 `f2982aba2e6e15969aa980d4d42b44f822f20ecf`: comparison post `ξ`, persisted finite person-axis pair only. +- sibling #877 `a61db0aa7870f287689b3b1a47f5b8be740ebb72`: canonical formatted-zero origin identity with independent share/σ composition. + +#877 exposed a real executable-contract drift during convergence. Production already routed comparison tick accessibility copy through `leftoverMapPlotTickText` and `leftoverMapComparePlotTickAxisBadge`, preserving exact-origin/share/σ evidence, while `tests/test_grouping_comparison_graphic_tick_contract.py` still required the obsolete inline comparison-label ternary and prohibited the comparison tick template. The test was repaired at `8503b0f03d54ce0995e20e9c0149f097b5240e57`, then current #875 was adopted through ordinary two-parent commit `a61db0aa7870f287689b3b1a47f5b8be740ebb72`. Temporary convergence PR #1114 is therefore normally merged, not simply closed. Fresh #877 Tests run `35018582871` is nonterminal; no predecessor receipt transfers. -All are open Drafts and currently mergeable after their latest ordinary two-parent convergence. This does **not** mean the stack is settled: when #867 acquires #866's source/ancestry delta, and when #866 later acquires the causal `App.tsx` repair, the full descendant chain must converge again. No current descendant receipt can be treated as acceptance for those future heads. +All current product lanes remain Draft. They are converged only to the current #866 foundation. When #866 acquires the causal `App.tsx` repair, the full descendant chain must converge again. No current descendant receipt can be treated as acceptance for those future heads. -Historical #878/#879 remain open delta/evidence carriers. Their succession authority is current with #876 `5dd5152d...`, #1033 `cce3c6d0...`, and #1034 `d2e0eb63...`; they are not closed merely because those reconstructed successors preserve the intended product contracts. Closure still requires complete verified succession of every valid product, test, fixture, contract and evidence delta. +Historical #878/#879 remain open delta/evidence carriers. Their succession authority is current with #876 `6a1c4654...`, #1033 `a29e2979...`, and #1034 `f2982aba...`; they are not closed merely because reconstructed successors preserve the intended product contracts. Closure still requires complete verified succession of every valid product, test, fixture, contract and evidence delta. ## Buyer-visible gap register @@ -62,11 +58,11 @@ Historical #878/#879 remain open delta/evidence carriers. Their succession autho | --- | --- | --- | --- | | Summary reads must not mutate Customer Master shared catalogs | #1079 `c2923950...` | Product repository/security evidence exists; central model/review settlement is incomplete. | Canonical owner-path terminal evidence, qualifying approval, normal protected merge. | | Commercial-safe synchronous PostgreSQL tooling | #911 `6030b295...` | Exact-head Tests/PROV-O/Ontology/SAST are GREEN after the timeout compatibility repair. | Security and CodeQL terminal GREEN plus qualifying independent exact-head approval. | -| Report-axis σ/share missingness | #866 `35f4b07...` | Four-state helper and executable RED exist; live buyer path still bypasses projection. Repair run `34997230462` queued. | Causal `App.tsx` GREEN, fresh frontend/full/rendered/a11y/i18n/security evidence and qualifying approval. | -| Comparison-graphic axis σ/share identity | #867 `8e76dc8...` | Product/helper contract retained; parent executable tick contract adopted. Source/ancestry convergence run `34997608532` queued; #1110 is Draft conflict/evidence carrier. | Exact parent convergence, then fresh repository/rendered/security/review evidence. | -| Singular/share tick stack | #868 `b71b045...` -> #875 `05ca9a16...` | Child deltas preserved through ordinary two-parent convergence onto current #867 test head. | Re-converge after #867/#866 move; fresh exact-head repository/browser/security/performance/review evidence in parent order. | -| Report/comparison marker identity | #876 `5dd5152d...` -> #1033 `cce3c6d0...` -> #1034 `d2e0eb63...` | ζ/ζ/ξ owner boundaries preserved after latest convergence. | Re-converge on foundation movement; focused/full/rendered/security evidence and qualifying approvals. | -| Comparison origin identity | #877 `23c0988d...` | Exact-zero origin and independent share/σ composition preserved. | Re-converge on foundation movement; executable/rendered/a11y/i18n/security evidence and qualifying approval. | +| Report-axis σ/share missingness | #866 `35f4b07...` | Four-state helper and executable RED exist. First repair run confirmed RED then failed in source-application automation; repaired run `35016883619` is queued. | Causal `App.tsx` GREEN, fresh frontend/full/rendered/a11y/i18n/security evidence and qualifying approval. | +| Comparison-graphic axis σ/share identity | #867 `1d5e0d7...` | Product/helper contract retained and current #866 ancestry is converged. | Re-converge after #866 moves, then fresh repository/rendered/security/review evidence. | +| Singular/share tick stack | #868 `de64a973...` -> #875 `8bfc9511...` | Child deltas preserved through ordinary non-force convergence on current #867. | Re-converge after #866 moves; fresh exact-head repository/browser/security/performance/review evidence in parent order. | +| Report/comparison marker identity | #876 `6a1c4654...` -> #1033 `a29e2979...` -> #1034 `f2982aba...` | ζ/ζ/ξ owner boundaries preserved on current ancestry. | Re-converge on foundation movement; focused/full/rendered/security evidence and qualifying approvals. | +| Comparison origin identity | #877 `a61db0aa...` | Stale executable tick contract repaired at `8503b0f0...`; normal convergence PR #1114 merged at `a61db0aa...`; fresh Tests nonterminal. | Current-head executable/rendered/a11y/i18n/security evidence and qualifying approval; re-converge on foundation movement. | | Catalog connection leases and summary TOCTOU | #1077 / #1080 | Separate owner lanes; external/model work must not hold long DB leases. | Causal RED→GREEN, short-transaction evidence and protected integration. | | Governed UI translation delivery | #929 / #932 | Versioned translation-ledger work remains in its canonical owner lane. | `ko/en/ja/zh/vi/es/de/fr`, normal/loading/empty/error/permission/responsive, keyboard/focus/screen-reader, CJK expansion/font fallback. | | MCP buyer-path latency | #1009 | Repository target remains p95 ≤ 20 ms where applicable. | Representative measurements and causal profiling; Rust-first hot-path repair if warranted. | @@ -84,4 +80,4 @@ Canonical domain truth stays with its owner. LineageWeave consumes released cont External/model work stays outside long-lived explicit database transactions and locks. Persistence reacquires the shortest necessary lease, revalidates authorization/version state, and uses idempotent/UPSERT semantics where required. -Material UI acceptance requires rendered buyer-path evidence in addition to unit/repository checks: normal/loading/empty/error/permission/responsive states, pointer/touch/keyboard/focus, accessibility, locale expansion/font fallback and applicable performance evidence. \ No newline at end of file +Material UI acceptance requires rendered buyer-path evidence in addition to unit/repository checks: normal/loading/empty/error/permission/responsive states, pointer/touch/keyboard/focus, accessibility, locale expansion/font fallback and applicable performance evidence. From b8060d00636da67e4d97dd0c266175157e87549a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 16 Sep 2026 05:27:34 +0900 Subject: [PATCH 085/276] docs(gaps): record comparison tick i18n RED --- docs/product-technical-gap-baseline.md | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 52def8f02..d91ca74b0 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -44,9 +44,13 @@ Below #875, current exact topology is: - #876 `6a1c46546fc6b74564af8f7834a17ca6275a5e21`: report criterion `ζ`, persisted finite item-axis pair only. - #1033 `a29e2979ff85aaee30ad906e577aafdc8dd8e5c2`: comparison criterion `ζ`, same item-coordinate boundary with distinct comparison identity. - #1034 `f2982aba2e6e15969aa980d4d42b44f822f20ecf`: comparison post `ξ`, persisted finite person-axis pair only. -- sibling #877 `a61db0aa7870f287689b3b1a47f5b8be740ebb72`: canonical formatted-zero origin identity with independent share/σ composition. +- sibling #877 `ef776547c3422904f3d1e5119037fad6fb63d3f0`: canonical formatted-zero origin identity with independent share/σ composition, plus a current executable i18n RED. -#877 exposed a real executable-contract drift during convergence. Production already routed comparison tick accessibility copy through `leftoverMapPlotTickText` and `leftoverMapComparePlotTickAxisBadge`, preserving exact-origin/share/σ evidence, while `tests/test_grouping_comparison_graphic_tick_contract.py` still required the obsolete inline comparison-label ternary and prohibited the comparison tick template. The test was repaired at `8503b0f03d54ce0995e20e9c0149f097b5240e57`, then current #875 was adopted through ordinary two-parent commit `a61db0aa7870f287689b3b1a47f5b8be740ebb72`. Temporary convergence PR #1114 is therefore normally merged, not simply closed. Fresh #877 Tests run `35018582871` is nonterminal; no predecessor receipt transfers. +#877 first exposed a real executable-contract drift during convergence. Production already routed comparison tick accessibility copy through `leftoverMapPlotTickText` and `leftoverMapComparePlotTickAxisBadge`, preserving exact-origin/share/σ evidence, while `tests/test_grouping_comparison_graphic_tick_contract.py` still required the obsolete inline comparison-label ternary and prohibited the comparison tick template. The test was repaired at `8503b0f03d54ce0995e20e9c0149f097b5240e57`, then current #875 was adopted through ordinary two-parent commit `a61db0aa7870f287689b3b1a47f5b8be740ebb72`. Temporary convergence PR #1114 is therefore normally merged, not simply closed. + +A fresh unresolved review finding on #877 was then verified against current source rather than accepted blindly. The eight comparison regular/origin tick accessibility templates are defined and passed directly to `tf`, but none is present in the current ko/zh/ja/vi translation catalogs. Existing ordinary leftover-axis tick keys are translated, so the comparison templates fall back to untranslated template strings in non-English accessibility names. This is a current product/a11y/i18n defect, not a cosmetic review note. + +Executable RED `tests/test_grouping_comparison_graphic_tick_i18n_contract.py` was added at exact #877 head `ef776547c3422904f3d1e5119037fad6fb63d3f0`. It requires all eight comparison templates in each of the four currently implemented non-English catalogs and verifies every required placeholder is preserved. One-shot run `35019486346` is queued to add the 32 catalog entries and run the focused i18n/tick/origin contracts. The earlier Tests run `35018582871` belongs to predecessor `a61db0aa...` and is no longer acceptance evidence. The broader es/de/fr locale expansion remains governed by the translation-ledger owner lane; #877 only repairs the locales this frontend currently implements. All current product lanes remain Draft. They are converged only to the current #866 foundation. When #866 acquires the causal `App.tsx` repair, the full descendant chain must converge again. No current descendant receipt can be treated as acceptance for those future heads. @@ -62,7 +66,7 @@ Historical #878/#879 remain open delta/evidence carriers. Their succession autho | Comparison-graphic axis σ/share identity | #867 `1d5e0d7...` | Product/helper contract retained and current #866 ancestry is converged. | Re-converge after #866 moves, then fresh repository/rendered/security/review evidence. | | Singular/share tick stack | #868 `de64a973...` -> #875 `8bfc9511...` | Child deltas preserved through ordinary non-force convergence on current #867. | Re-converge after #866 moves; fresh exact-head repository/browser/security/performance/review evidence in parent order. | | Report/comparison marker identity | #876 `6a1c4654...` -> #1033 `a29e2979...` -> #1034 `f2982aba...` | ζ/ζ/ξ owner boundaries preserved on current ancestry. | Re-converge on foundation movement; focused/full/rendered/security evidence and qualifying approvals. | -| Comparison origin identity | #877 `a61db0aa...` | Stale executable tick contract repaired at `8503b0f0...`; normal convergence PR #1114 merged at `a61db0aa...`; fresh Tests nonterminal. | Current-head executable/rendered/a11y/i18n/security evidence and qualifying approval; re-converge on foundation movement. | +| Comparison origin/a11y identity | #877 `ef776547...` | Stale tick-structure contract repaired and #1114 normally merged; new RED proves eight comparison accessibility templates are absent from ko/zh/ja/vi catalogs. Repair run `35019486346` queued. | Current-head i18n GREEN, fresh executable/rendered/a11y/security evidence and qualifying approval; re-converge on foundation movement. | | Catalog connection leases and summary TOCTOU | #1077 / #1080 | Separate owner lanes; external/model work must not hold long DB leases. | Causal RED→GREEN, short-transaction evidence and protected integration. | | Governed UI translation delivery | #929 / #932 | Versioned translation-ledger work remains in its canonical owner lane. | `ko/en/ja/zh/vi/es/de/fr`, normal/loading/empty/error/permission/responsive, keyboard/focus/screen-reader, CJK expansion/font fallback. | | MCP buyer-path latency | #1009 | Repository target remains p95 ≤ 20 ms where applicable. | Representative measurements and causal profiling; Rust-first hot-path repair if warranted. | From a92be67b361deb73a12153efbc3c0981fc32590e Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 16 Sep 2026 05:46:46 +0900 Subject: [PATCH 086/276] docs(gaps): refresh measurement descendant authority --- docs/product-technical-gap-baseline.md | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index d91ca74b0..c375e913f 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -23,13 +23,19 @@ No LineageWeave release is admitted from the current protected head. A moved par #899 remains the contextual-orchestrator consumer-boundary foundation at `d331d1f6b05d39385a652be6dbb8f279871a2e2e`. Descendant evaluation/measurement lanes remain separate from LineageWeave domain truth. Provider/model/routing behavior stays in contextual-orchestrator; psychometric truth stays in its canonical owners. +#902 is exact `e6e6fed13e8f9273772708167156f7ad16017df4` on #899. Its current causal delta is documentation/changelog-only: it narrows an overstated DRAFT/PILOT scoreless claim to the lifecycle contract the LineageWeave policy object actually enforces. LineageWeave owns the governed rubric/version/lifecycle/activation and observation-policy vocabulary; numerical IRT kernels remain in fast-mlsirm, temporal/event/multilevel measurement semantics in TEPP, and provider/judge execution in contextual-orchestrator. Current-head Tests `35016400830` are terminal `skipped` under Draft admission and are not product GREEN. + +#915 was immediately converged after that parent movement. It is exact `e2cbacb775744c14103c3d3043b78ba5ff9bc7e2`, directly based on #902 `e6e6fed13e8f9273772708167156f7ad16017df4`, by an ordinary two-parent convergence preserving the dynamic-evaluation lineage delta. No fresh workflow run is registered for this exact head; predecessor skipped evidence does not transfer. Its projection keeps criterion, observation, adjudication, calibration, promotion, linking and supersession provenance distinct without absorbing contextual-orchestrator execution, fast-mlsirm psychometrics, or TEPP temporal truth. + +#966 is mechanically mergeable and Draft at actual Git head `1be24cd923b89a64f41d05bea8534b552e1ee7bc` on current #899 `d331d1f6b05d39385a652be6dbb8f279871a2e2e`. The long-form PR body still opens with an older `e5711282...` / `24a3007...` historical snapshot, so authority correction comment `5687847837` records the live base/head without moving source or inheriting checks. This naming lane must not restore provider aliases or copy contextual-orchestrator source. + ## Active leftover-map foundation finding #866 remains the active report-axis buyer-path RED at exact `35f4b07fd91a01ce14c31059fa4d46ad3a9ca5a2`, based on #865 `0728f56ba66f16783685c84d9d3aa034eea9f143`. The helper `leftoverMapAxisBadge(axis)` already distinguishes combined, singular-only, share-only and empty evidence, preserves finite `σ=0`, and fails closed for unusable values. The live `frontend/src/App.tsx`, however, still composes `leftoverMapAxisBadgeSingular` and `leftoverMapAxisBadgeShare` directly. When neither persisted datum is usable, the report can still emit a badge shell instead of omitting evidence. `tests/test_leftover_axis_report_singular_only_contract.py` remains the executable RED. It requires the report path to call `leftoverMapAxisBadge(axis)`, render only non-null projections, and stop importing the two primitive helpers. The minimal causal production fix remains confined to `App.tsx`; it does not alter SQL, persistence, psychometric estimation or a canonical-owner contract. -One-shot run `34997230462` eventually received a GitHub-hosted runner. It verified the exact RED head successfully, then failed in `Apply minimal causal fix` because the automation literal for the import block contained indentation that the real source does not contain. GREEN, commit and push steps were skipped. This is an automation-code RCA, not a product verdict. The workflow was repaired at auxiliary exact `468571288ba8ef45065c188c8d3a28ff2105cf7e` using line-joined exact source blocks and the current checkout action; replacement run `35016883619` is queued. Queued is not GREEN. Once #866 moves, every descendant must converge again from the resulting exact head. +One-shot run `34997230462` eventually received a GitHub-hosted runner. It verified the exact RED head successfully, then failed in `Apply minimal causal fix` because the automation literal for the import block contained indentation that the real source does not contain. GREEN, commit and push steps were skipped. This is an automation-code RCA, not a product verdict. The workflow was repaired at auxiliary exact `468571288ba8ef45065c188c8d3a28ff2105cf7e` using line-joined exact source blocks and the current checkout action; replacement run `35016883619` is still queued. Queued is not GREEN. Once #866 moves, every descendant must converge again from the resulting exact head. ## Current non-force ancestry @@ -50,7 +56,7 @@ Below #875, current exact topology is: A fresh unresolved review finding on #877 was then verified against current source rather than accepted blindly. The eight comparison regular/origin tick accessibility templates are defined and passed directly to `tf`, but none is present in the current ko/zh/ja/vi translation catalogs. Existing ordinary leftover-axis tick keys are translated, so the comparison templates fall back to untranslated template strings in non-English accessibility names. This is a current product/a11y/i18n defect, not a cosmetic review note. -Executable RED `tests/test_grouping_comparison_graphic_tick_i18n_contract.py` was added at exact #877 head `ef776547c3422904f3d1e5119037fad6fb63d3f0`. It requires all eight comparison templates in each of the four currently implemented non-English catalogs and verifies every required placeholder is preserved. One-shot run `35019486346` is queued to add the 32 catalog entries and run the focused i18n/tick/origin contracts. The earlier Tests run `35018582871` belongs to predecessor `a61db0aa...` and is no longer acceptance evidence. The broader es/de/fr locale expansion remains governed by the translation-ledger owner lane; #877 only repairs the locales this frontend currently implements. +Executable RED `tests/test_grouping_comparison_graphic_tick_i18n_contract.py` was added at exact #877 head `ef776547c3422904f3d1e5119037fad6fb63d3f0`. It requires all eight comparison templates in each of the four currently implemented non-English catalogs and verifies every required placeholder is preserved. One-shot run `35019486346` is still queued to add the 32 catalog entries and run the focused i18n/tick/origin contracts. The earlier Tests run `35018582871` belongs to predecessor `a61db0aa...` and is no longer acceptance evidence. The broader es/de/fr locale expansion remains governed by the translation-ledger owner lane; #877 only repairs the locales this frontend currently implements. All current product lanes remain Draft. They are converged only to the current #866 foundation. When #866 acquires the causal `App.tsx` repair, the full descendant chain must converge again. No current descendant receipt can be treated as acceptance for those future heads. @@ -62,6 +68,9 @@ Historical #878/#879 remain open delta/evidence carriers. Their succession autho | --- | --- | --- | --- | | Summary reads must not mutate Customer Master shared catalogs | #1079 `c2923950...` | Product repository/security evidence exists; central model/review settlement is incomplete. | Canonical owner-path terminal evidence, qualifying approval, normal protected merge. | | Commercial-safe synchronous PostgreSQL tooling | #911 `6030b295...` | Exact-head Tests/PROV-O/Ontology/SAST are GREEN after the timeout compatibility repair. | Security and CodeQL terminal GREEN plus qualifying independent exact-head approval. | +| Dichotomous measurement-policy boundary | #902 `e6e6fed1...` | Causal docs/changelog repair matches the implemented DRAFT/PILOT/PUBLISHED lifecycle contract; parent #899 is exact. Draft Tests are skipped, not GREEN. | Normal prerequisite integration, fresh repository/security/governance evidence and qualifying exact-head approval. | +| Dynamic-evaluation provenance projection | #915 `e2cbacb7...` | Ordinary two-parent convergence adopts current #902 while preserving the 12-file dynamic-evaluation delta and owner boundaries. | Fresh current-head required checks, released-owner integration evidence and qualifying approval after prerequisites. | +| Semantic operator/API naming continuation | #966 `1be24cd9...` | Actual Git base/head are current with #899; stale opening body snapshot is explicitly superseded by authority comment `5687847837`. | Keep Draft; fresh exact-head hosted evidence and independent review after #899 integration/reconvergence. | | Report-axis σ/share missingness | #866 `35f4b07...` | Four-state helper and executable RED exist. First repair run confirmed RED then failed in source-application automation; repaired run `35016883619` is queued. | Causal `App.tsx` GREEN, fresh frontend/full/rendered/a11y/i18n/security evidence and qualifying approval. | | Comparison-graphic axis σ/share identity | #867 `1d5e0d7...` | Product/helper contract retained and current #866 ancestry is converged. | Re-converge after #866 moves, then fresh repository/rendered/security/review evidence. | | Singular/share tick stack | #868 `de64a973...` -> #875 `8bfc9511...` | Child deltas preserved through ordinary non-force convergence on current #867. | Re-converge after #866 moves; fresh exact-head repository/browser/security/performance/review evidence in parent order. | From 4da102068d0fc3d577a0c29fcb06d95c3bad35a6 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 16 Sep 2026 07:51:28 +0900 Subject: [PATCH 087/276] docs(gaps): record fail-closed dependency review and queue differential --- docs/product-technical-gap-baseline.md | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index c375e913f..412c2789b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -17,7 +17,7 @@ No LineageWeave release is admitted from the current protected head. A moved par ### Commercial-safe synchronous PostgreSQL boundary -#911 remains exact `6030b295aadc3ee76dc4d27f5713273f35888325`. Its test-first pg8000 compatibility repair preserves libpq-style integer `connect_timeout` semantics and treats non-positive values as no-deadline sentinels. Runtime persistence remains `asyncpg`. Exact-head Tests `34978833151`, PROV-O `34978832987`, Ontology Pages `34978833063`, and SAST `34977841093` are terminal GREEN. Security `34977841173` and CodeQL PR `34977841115` remain queued, and there is still no qualifying independent exact-head `APPROVED` review. Ready state is validation admission, not merge acceptance. +#911 remains exact `6030b295aadc3ee76dc4d27f5713273f35888325`. Its test-first pg8000 compatibility repair preserves libpq-style integer `connect_timeout` semantics and treats non-positive values as no-deadline sentinels. Runtime persistence remains `asyncpg`. Exact-head Tests `34978833151`, PROV-O `34978832987`, Ontology Pages `34978833063`, and SAST `34977841093` are terminal GREEN. Security `34977841173` is now terminal `failure`: changed-scope, OSV, Trivy and Scorecard completed successfully, while dependency-review job `104497459473` passed exact checkout/verification, failed `Check dependency review support`, and skipped the pinned Dependency Review action. That is the intended fail-closed shape of the still-open canonical `.github#810` availability/configuration incident, not evidence of a new pg8000/libpq source regression. Fresh downstream owner evidence is recorded in `.github#810` comment `5689139333`. CodeQL PR `34977841115` remains queued, and there is still no qualifying independent exact-head `APPROVED` review. Ready state is validation admission, not merge acceptance. ### Owner-boundary and governed measurement stack @@ -35,7 +35,7 @@ No LineageWeave release is admitted from the current protected head. A moved par `tests/test_leftover_axis_report_singular_only_contract.py` remains the executable RED. It requires the report path to call `leftoverMapAxisBadge(axis)`, render only non-null projections, and stop importing the two primitive helpers. The minimal causal production fix remains confined to `App.tsx`; it does not alter SQL, persistence, psychometric estimation or a canonical-owner contract. -One-shot run `34997230462` eventually received a GitHub-hosted runner. It verified the exact RED head successfully, then failed in `Apply minimal causal fix` because the automation literal for the import block contained indentation that the real source does not contain. GREEN, commit and push steps were skipped. This is an automation-code RCA, not a product verdict. The workflow was repaired at auxiliary exact `468571288ba8ef45065c188c8d3a28ff2105cf7e` using line-joined exact source blocks and the current checkout action; replacement run `35016883619` is still queued. Queued is not GREEN. Once #866 moves, every descendant must converge again from the resulting exact head. +One-shot run `34997230462` eventually received a GitHub-hosted runner. It verified the exact RED head successfully, then failed in `Apply minimal causal fix` because the automation literal for the import block contained indentation that the real source does not contain. GREEN, commit and push steps were skipped. This is an automation-code RCA, not a product verdict. The workflow was repaired at auxiliary exact `468571288ba8ef45065c188c8d3a28ff2105cf7e` using line-joined exact source blocks and the current checkout action; replacement run `35016883619` / job `104542432409` remains pre-runner queued on `ubuntu-latest` with `runner_id=0` and `steps=[]`. Queued is not GREEN. Same-repository #911 required Security jobs did acquire concrete `ubuntu-24.04` runners during the overlapping interval, so this is not an absolute LineageWeave-wide hosted-runner blackout; it does not by itself distinguish label, concurrency/admission, priority, capacity partitioning, or another owner-plane cause. That narrowed diagnosis is recorded in canonical `.github#712` comment `5689143076`. Once #866 moves, every descendant must converge again from the resulting exact head. ## Current non-force ancestry @@ -56,7 +56,7 @@ Below #875, current exact topology is: A fresh unresolved review finding on #877 was then verified against current source rather than accepted blindly. The eight comparison regular/origin tick accessibility templates are defined and passed directly to `tf`, but none is present in the current ko/zh/ja/vi translation catalogs. Existing ordinary leftover-axis tick keys are translated, so the comparison templates fall back to untranslated template strings in non-English accessibility names. This is a current product/a11y/i18n defect, not a cosmetic review note. -Executable RED `tests/test_grouping_comparison_graphic_tick_i18n_contract.py` was added at exact #877 head `ef776547c3422904f3d1e5119037fad6fb63d3f0`. It requires all eight comparison templates in each of the four currently implemented non-English catalogs and verifies every required placeholder is preserved. One-shot run `35019486346` is still queued to add the 32 catalog entries and run the focused i18n/tick/origin contracts. The earlier Tests run `35018582871` belongs to predecessor `a61db0aa...` and is no longer acceptance evidence. The broader es/de/fr locale expansion remains governed by the translation-ledger owner lane; #877 only repairs the locales this frontend currently implements. +Executable RED `tests/test_grouping_comparison_graphic_tick_i18n_contract.py` was added at exact #877 head `ef776547c3422904f3d1e5119037fad6fb63d3f0`. It requires all eight comparison templates in each of the four currently implemented non-English catalogs and verifies every required placeholder is preserved. One-shot run `35019486346` / job `104551325828` remains pre-runner queued on `ubuntu-latest` with `runner_id=0` and `steps=[]` to add the 32 catalog entries and run the focused i18n/tick/origin contracts. The earlier Tests run `35018582871` belongs to predecessor `a61db0aa...` and is no longer acceptance evidence. The broader es/de/fr locale expansion remains governed by the translation-ledger owner lane; #877 only repairs the locales this frontend currently implements. All current product lanes remain Draft. They are converged only to the current #866 foundation. When #866 acquires the causal `App.tsx` repair, the full descendant chain must converge again. No current descendant receipt can be treated as acceptance for those future heads. @@ -67,15 +67,15 @@ Historical #878/#879 remain open delta/evidence carriers. Their succession autho | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | | Summary reads must not mutate Customer Master shared catalogs | #1079 `c2923950...` | Product repository/security evidence exists; central model/review settlement is incomplete. | Canonical owner-path terminal evidence, qualifying approval, normal protected merge. | -| Commercial-safe synchronous PostgreSQL tooling | #911 `6030b295...` | Exact-head Tests/PROV-O/Ontology/SAST are GREEN after the timeout compatibility repair. | Security and CodeQL terminal GREEN plus qualifying independent exact-head approval. | +| Commercial-safe synchronous PostgreSQL tooling | #911 `6030b295...` | Exact-head Tests/PROV-O/Ontology/SAST are GREEN. Security is terminal fail-closed because canonical Dependency Review support could not be established; independent Security jobs are green. | `.github#810` owner repair followed by authoritative exact-head Security GREEN, CodeQL terminal GREEN, and qualifying independent exact-head approval. | | Dichotomous measurement-policy boundary | #902 `e6e6fed1...` | Causal docs/changelog repair matches the implemented DRAFT/PILOT/PUBLISHED lifecycle contract; parent #899 is exact. Draft Tests are skipped, not GREEN. | Normal prerequisite integration, fresh repository/security/governance evidence and qualifying exact-head approval. | | Dynamic-evaluation provenance projection | #915 `e2cbacb7...` | Ordinary two-parent convergence adopts current #902 while preserving the 12-file dynamic-evaluation delta and owner boundaries. | Fresh current-head required checks, released-owner integration evidence and qualifying approval after prerequisites. | | Semantic operator/API naming continuation | #966 `1be24cd9...` | Actual Git base/head are current with #899; stale opening body snapshot is explicitly superseded by authority comment `5687847837`. | Keep Draft; fresh exact-head hosted evidence and independent review after #899 integration/reconvergence. | -| Report-axis σ/share missingness | #866 `35f4b07...` | Four-state helper and executable RED exist. First repair run confirmed RED then failed in source-application automation; repaired run `35016883619` is queued. | Causal `App.tsx` GREEN, fresh frontend/full/rendered/a11y/i18n/security evidence and qualifying approval. | +| Report-axis σ/share missingness | #866 `35f4b07...` | Four-state helper and executable RED exist. First repair run confirmed RED then failed in source-application automation; repaired run `35016883619` remains pre-runner queued. | Causal `App.tsx` GREEN, fresh frontend/full/rendered/a11y/i18n/security evidence and qualifying approval. | | Comparison-graphic axis σ/share identity | #867 `1d5e0d7...` | Product/helper contract retained and current #866 ancestry is converged. | Re-converge after #866 moves, then fresh repository/rendered/security/review evidence. | | Singular/share tick stack | #868 `de64a973...` -> #875 `8bfc9511...` | Child deltas preserved through ordinary non-force convergence on current #867. | Re-converge after #866 moves; fresh exact-head repository/browser/security/performance/review evidence in parent order. | | Report/comparison marker identity | #876 `6a1c4654...` -> #1033 `a29e2979...` -> #1034 `f2982aba...` | ζ/ζ/ξ owner boundaries preserved on current ancestry. | Re-converge on foundation movement; focused/full/rendered/security evidence and qualifying approvals. | -| Comparison origin/a11y identity | #877 `ef776547...` | Stale tick-structure contract repaired and #1114 normally merged; new RED proves eight comparison accessibility templates are absent from ko/zh/ja/vi catalogs. Repair run `35019486346` queued. | Current-head i18n GREEN, fresh executable/rendered/a11y/security evidence and qualifying approval; re-converge on foundation movement. | +| Comparison origin/a11y identity | #877 `ef776547...` | Stale tick-structure contract repaired and #1114 normally merged; new RED proves eight comparison accessibility templates are absent from ko/zh/ja/vi catalogs. Repair run `35019486346` remains pre-runner queued. | Current-head i18n GREEN, fresh executable/rendered/a11y/security evidence and qualifying approval; re-converge on foundation movement. | | Catalog connection leases and summary TOCTOU | #1077 / #1080 | Separate owner lanes; external/model work must not hold long DB leases. | Causal RED→GREEN, short-transaction evidence and protected integration. | | Governed UI translation delivery | #929 / #932 | Versioned translation-ledger work remains in its canonical owner lane. | `ko/en/ja/zh/vi/es/de/fr`, normal/loading/empty/error/permission/responsive, keyboard/focus/screen-reader, CJK expansion/font fallback. | | MCP buyer-path latency | #1009 | Repository target remains p95 ≤ 20 ms where applicable. | Representative measurements and causal profiling; Rust-first hot-path repair if warranted. | From 51d92db1286fb36259eb3502680729c8905cd2a1 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 16 Sep 2026 08:02:12 +0900 Subject: [PATCH 088/276] docs(gaps): record CodeQL owner repairs and parser finding --- docs/product-technical-gap-baseline.md | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 412c2789b..b046288ab 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -13,7 +13,7 @@ No LineageWeave release is admitted from the current protected head. A moved par ### Summary shared-catalog authorization -#1079 remains the Customer Master/shared-catalog authorization candidate at exact `c2923950e73c88a9f9fd932332ddd47682da124b`. Product repository/security evidence exists, but canonical CodeQL actual scans, authenticated OpenCode verdict, complete Strix/Noema owner-path settlement and qualifying independent approval remain outstanding. Canonical review/runtime queue, provider, timeout, retry and credential behavior stays in `.github` and contextual-orchestrator; LineageWeave does not copy it. +#1079 remains the Customer Master/shared-catalog authorization candidate at exact `c2923950e73c88a9f9fd932332ddd47682da124b`. Product Tests/SAST/Security are terminal GREEN, but required CodeQL is legitimately RED. Canonical producer run `34922377994` has now completed all actual scans: JavaScript/TypeScript and Python analyses succeeded, then the Medium+ SARIF gates failed; Actions produced no retained product finding. The findings are repository-baseline files outside #1079's 13-file authorization delta, so they are owner work rather than new summary-catalog authorization regressions. Python findings are owned by #974; frontend parser findings are owned by #983. Authority correction is recorded on #1079 as comment `5689248387`. Authenticated OpenCode verdict, complete Strix/Noema owner-path settlement and qualifying independent approval also remain outstanding. Canonical review/runtime queue, provider, timeout, retry and credential behavior stays in `.github` and contextual-orchestrator; LineageWeave does not copy it. ### Commercial-safe synchronous PostgreSQL boundary @@ -29,6 +29,14 @@ No LineageWeave release is admitted from the current protected head. A moved par #966 is mechanically mergeable and Draft at actual Git head `1be24cd923b89a64f41d05bea8534b552e1ee7bc` on current #899 `d331d1f6b05d39385a652be6dbb8f279871a2e2e`. The long-form PR body still opens with an older `e5711282...` / `24a3007...` historical snapshot, so authority correction comment `5687847837` records the live base/head without moving source or inheriting checks. This naming lane must not restore provider aliases or copy contextual-orchestrator source. +### CodeQL baseline security ownership + +Canonical producer `34922377994` preserved three immutable SARIF artifacts. Python artifact `10398012754` exposed `py/insecure-protocol` in `lineageweave/http_client.py` and `py/polynomial-redos` in `lineageweave/post_chat.py`; both files belong to active #974 rather than #1079. #974 carried the TLS finding through executable RED `9177894c19339de137aed5fb71dcad9c6a725ec2` and causal fix `0ac8bd5dd85321d84d69782f72aab56e47e33b8b`, explicitly setting a TLS 1.2 minimum while retaining certifi chain and hostname verification. It then carried the user-input regex finding through RED `216e4e3c41161f49b65c48128e8c178790222e3d` and causal fix `6911954363888d1e2d523ebbcf68f68d7217752a`, replacing the end-anchored punctuation regex with linear whitespace normalization plus `.rstrip("?.!")`. These are source-level causal repairs, not current-head CodeQL GREEN; #974 remains Draft and needs fresh exact-head validation. + +#979 was immediately non-force converged after each #974 movement and is now exact `2431fa8cde5927ca9e6afeb2652ff8b01f3f0a85` directly on #974 `6911954363888d1e2d523ebbcf68f68d7217752a`. Its claim-generation/queue/schema delta remains distinct, the parent security files are adopted unchanged, and predecessor receipts do not transfer. There are no open descendants below #979 at this snapshot. + +JavaScript artifact `10398331800` exposed four `js/incomplete-multi-character-sanitization` findings in `frontend/src/postBodyDisplay.ts`. #983 already owns that parser/rendering boundary; owner evidence is recorded in comment `5689242771`. The current React rendering path outputs text nodes and explicit ``/`` elements rather than `dangerouslySetInnerHTML`, so the SARIF alone does not establish exploitable browser XSS. The regex-as-sanitizer boundary is still a valid hard-gate robustness defect: #983 must add adversarial nested/repeated/encoded-script REDs and replace that boundary with one deterministic parser/tokenizer without breaking scientific script, OOXML indentation/footnote, embedded-image or table semantics. Query suppression or gate weakening is not accepted. + ## Active leftover-map foundation finding #866 remains the active report-axis buyer-path RED at exact `35f4b07fd91a01ce14c31059fa4d46ad3a9ca5a2`, based on #865 `0728f56ba66f16783685c84d9d3aa034eea9f143`. The helper `leftoverMapAxisBadge(axis)` already distinguishes combined, singular-only, share-only and empty evidence, preserves finite `σ=0`, and fails closed for unusable values. The live `frontend/src/App.tsx`, however, still composes `leftoverMapAxisBadgeSingular` and `leftoverMapAxisBadgeShare` directly. When neither persisted datum is usable, the report can still emit a badge shell instead of omitting evidence. @@ -66,8 +74,10 @@ Historical #878/#879 remain open delta/evidence carriers. Their succession autho | Gap | Canonical owner / exact candidate | Current evidence | Acceptance still required | | --- | --- | --- | --- | -| Summary reads must not mutate Customer Master shared catalogs | #1079 `c2923950...` | Product repository/security evidence exists; central model/review settlement is incomplete. | Canonical owner-path terminal evidence, qualifying approval, normal protected merge. | +| Summary reads must not mutate Customer Master shared catalogs | #1079 `c2923950...` | Product Tests/SAST/Security are GREEN. Canonical CodeQL actual scans are terminal RED on repository-baseline Python/JS findings outside #1079's diff; owner repairs are in #974/#983 lanes. | Owner repairs integrated/reconverged, fresh exact-head canonical CodeQL GREEN/compatibility settlement, OpenCode/Strix/Noema settlement, qualifying approval, normal protected merge. | | Commercial-safe synchronous PostgreSQL tooling | #911 `6030b295...` | Exact-head Tests/PROV-O/Ontology/SAST are GREEN. Security is terminal fail-closed because canonical Dependency Review support could not be established; independent Security jobs are green. | `.github#810` owner repair followed by authoritative exact-head Security GREEN, CodeQL terminal GREEN, and qualifying independent exact-head approval. | +| Ask HTTP/chat security baseline | #974 `69119543...` -> #979 `2431fa8c...` | CodeQL-derived TLS and polynomial-ReDoS REDs have test-first causal source fixes; child is immediately non-force converged. No current-head GREEN is inherited. | Fresh exact-head Tests/SAST/Security/CodeQL, provider-boundary regression evidence and qualifying approval before parent-first integration. | +| Post-body parser hardening | #983 `60d2f780...` | Four JS CodeQL multi-character-sanitization findings are assigned to the existing parser/rendering owner; React text sink lowers exploit claim but not the hard-gate defect. | Adversarial parser REDs, deterministic tokenizer/parser causal repair, rendered sup/sub/OOXML/image/table regressions, fresh CodeQL GREEN, descendants converged. | | Dichotomous measurement-policy boundary | #902 `e6e6fed1...` | Causal docs/changelog repair matches the implemented DRAFT/PILOT/PUBLISHED lifecycle contract; parent #899 is exact. Draft Tests are skipped, not GREEN. | Normal prerequisite integration, fresh repository/security/governance evidence and qualifying exact-head approval. | | Dynamic-evaluation provenance projection | #915 `e2cbacb7...` | Ordinary two-parent convergence adopts current #902 while preserving the 12-file dynamic-evaluation delta and owner boundaries. | Fresh current-head required checks, released-owner integration evidence and qualifying approval after prerequisites. | | Semantic operator/API naming continuation | #966 `1be24cd9...` | Actual Git base/head are current with #899; stale opening body snapshot is explicitly superseded by authority comment `5687847837`. | Keep Draft; fresh exact-head hosted evidence and independent review after #899 integration/reconvergence. | From 6c0892936ef170a1a479a474f6aa2650a14edc52 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 16 Sep 2026 08:04:16 +0900 Subject: [PATCH 089/276] docs(gaps): admit exact-head validation for CodeQL repairs --- docs/product-technical-gap-baseline.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b046288ab..515572794 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -31,7 +31,7 @@ No LineageWeave release is admitted from the current protected head. A moved par ### CodeQL baseline security ownership -Canonical producer `34922377994` preserved three immutable SARIF artifacts. Python artifact `10398012754` exposed `py/insecure-protocol` in `lineageweave/http_client.py` and `py/polynomial-redos` in `lineageweave/post_chat.py`; both files belong to active #974 rather than #1079. #974 carried the TLS finding through executable RED `9177894c19339de137aed5fb71dcad9c6a725ec2` and causal fix `0ac8bd5dd85321d84d69782f72aab56e47e33b8b`, explicitly setting a TLS 1.2 minimum while retaining certifi chain and hostname verification. It then carried the user-input regex finding through RED `216e4e3c41161f49b65c48128e8c178790222e3d` and causal fix `6911954363888d1e2d523ebbcf68f68d7217752a`, replacing the end-anchored punctuation regex with linear whitespace normalization plus `.rstrip("?.!")`. These are source-level causal repairs, not current-head CodeQL GREEN; #974 remains Draft and needs fresh exact-head validation. +Canonical producer `34922377994` preserved three immutable SARIF artifacts. Python artifact `10398012754` exposed `py/insecure-protocol` in `lineageweave/http_client.py` and `py/polynomial-redos` in `lineageweave/post_chat.py`; both files belong to active #974 rather than #1079. #974 carried the TLS finding through executable RED `9177894c19339de137aed5fb71dcad9c6a725ec2` and causal fix `0ac8bd5dd85321d84d69782f72aab56e47e33b8b`, explicitly setting a TLS 1.2 minimum while retaining certifi chain and hostname verification. It then carried the user-input regex finding through RED `216e4e3c41161f49b65c48128e8c178790222e3d` and causal fix `6911954363888d1e2d523ebbcf68f68d7217752a`, replacing the end-anchored punctuation regex with linear whitespace normalization plus `.rstrip("?.!")`. These are source-level causal repairs, not current-head GREEN. #974 is Ready for validation admission only: Tests `35033878120`, CodeQL PR `35033619584`, SAST `35033619322`, and Security `35033619472` are all queued on the exact repaired head; earlier Tests `35033619342` was a Draft-event skip and is not acceptance. #979 was immediately non-force converged after each #974 movement and is now exact `2431fa8cde5927ca9e6afeb2652ff8b01f3f0a85` directly on #974 `6911954363888d1e2d523ebbcf68f68d7217752a`. Its claim-generation/queue/schema delta remains distinct, the parent security files are adopted unchanged, and predecessor receipts do not transfer. There are no open descendants below #979 at this snapshot. @@ -66,7 +66,7 @@ A fresh unresolved review finding on #877 was then verified against current sour Executable RED `tests/test_grouping_comparison_graphic_tick_i18n_contract.py` was added at exact #877 head `ef776547c3422904f3d1e5119037fad6fb63d3f0`. It requires all eight comparison templates in each of the four currently implemented non-English catalogs and verifies every required placeholder is preserved. One-shot run `35019486346` / job `104551325828` remains pre-runner queued on `ubuntu-latest` with `runner_id=0` and `steps=[]` to add the 32 catalog entries and run the focused i18n/tick/origin contracts. The earlier Tests run `35018582871` belongs to predecessor `a61db0aa...` and is no longer acceptance evidence. The broader es/de/fr locale expansion remains governed by the translation-ledger owner lane; #877 only repairs the locales this frontend currently implements. -All current product lanes remain Draft. They are converged only to the current #866 foundation. When #866 acquires the causal `App.tsx` repair, the full descendant chain must converge again. No current descendant receipt can be treated as acceptance for those future heads. +All current product lanes remain Draft except lanes explicitly promoted only for validation admission. They are converged only to their stated current foundations. When #866 acquires the causal `App.tsx` repair, the full leftover-map descendant chain must converge again. No current descendant receipt can be treated as acceptance for future heads. Historical #878/#879 remain open delta/evidence carriers. Their succession authority is current with #876 `6a1c4654...`, #1033 `a29e2979...`, and #1034 `f2982aba...`; they are not closed merely because reconstructed successors preserve the intended product contracts. Closure still requires complete verified succession of every valid product, test, fixture, contract and evidence delta. @@ -76,7 +76,7 @@ Historical #878/#879 remain open delta/evidence carriers. Their succession autho | --- | --- | --- | --- | | Summary reads must not mutate Customer Master shared catalogs | #1079 `c2923950...` | Product Tests/SAST/Security are GREEN. Canonical CodeQL actual scans are terminal RED on repository-baseline Python/JS findings outside #1079's diff; owner repairs are in #974/#983 lanes. | Owner repairs integrated/reconverged, fresh exact-head canonical CodeQL GREEN/compatibility settlement, OpenCode/Strix/Noema settlement, qualifying approval, normal protected merge. | | Commercial-safe synchronous PostgreSQL tooling | #911 `6030b295...` | Exact-head Tests/PROV-O/Ontology/SAST are GREEN. Security is terminal fail-closed because canonical Dependency Review support could not be established; independent Security jobs are green. | `.github#810` owner repair followed by authoritative exact-head Security GREEN, CodeQL terminal GREEN, and qualifying independent exact-head approval. | -| Ask HTTP/chat security baseline | #974 `69119543...` -> #979 `2431fa8c...` | CodeQL-derived TLS and polynomial-ReDoS REDs have test-first causal source fixes; child is immediately non-force converged. No current-head GREEN is inherited. | Fresh exact-head Tests/SAST/Security/CodeQL, provider-boundary regression evidence and qualifying approval before parent-first integration. | +| Ask HTTP/chat security baseline | #974 `69119543...` -> #979 `2431fa8c...` | CodeQL-derived TLS and polynomial-ReDoS REDs have test-first causal source fixes; child is immediately non-force converged. #974 current Tests/SAST/Security/CodeQL runs are queued after validation admission; no GREEN is inherited. | Fresh exact-head Tests/SAST/Security/CodeQL GREEN, provider-boundary regression evidence and qualifying approval before parent-first integration. | | Post-body parser hardening | #983 `60d2f780...` | Four JS CodeQL multi-character-sanitization findings are assigned to the existing parser/rendering owner; React text sink lowers exploit claim but not the hard-gate defect. | Adversarial parser REDs, deterministic tokenizer/parser causal repair, rendered sup/sub/OOXML/image/table regressions, fresh CodeQL GREEN, descendants converged. | | Dichotomous measurement-policy boundary | #902 `e6e6fed1...` | Causal docs/changelog repair matches the implemented DRAFT/PILOT/PUBLISHED lifecycle contract; parent #899 is exact. Draft Tests are skipped, not GREEN. | Normal prerequisite integration, fresh repository/security/governance evidence and qualifying exact-head approval. | | Dynamic-evaluation provenance projection | #915 `e2cbacb7...` | Ordinary two-parent convergence adopts current #902 while preserving the 12-file dynamic-evaluation delta and owner boundaries. | Fresh current-head required checks, released-owner integration evidence and qualifying approval after prerequisites. | From fccf18a87d5fec75bfc5dbad5aeea9105f1c5c3b Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 16 Sep 2026 08:58:03 +0900 Subject: [PATCH 090/276] docs(gaps): record post-body CodeQL repair and convergence --- docs/product-technical-gap-baseline.md | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 515572794..8b718107d 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -13,7 +13,7 @@ No LineageWeave release is admitted from the current protected head. A moved par ### Summary shared-catalog authorization -#1079 remains the Customer Master/shared-catalog authorization candidate at exact `c2923950e73c88a9f9fd932332ddd47682da124b`. Product Tests/SAST/Security are terminal GREEN, but required CodeQL is legitimately RED. Canonical producer run `34922377994` has now completed all actual scans: JavaScript/TypeScript and Python analyses succeeded, then the Medium+ SARIF gates failed; Actions produced no retained product finding. The findings are repository-baseline files outside #1079's 13-file authorization delta, so they are owner work rather than new summary-catalog authorization regressions. Python findings are owned by #974; frontend parser findings are owned by #983. Authority correction is recorded on #1079 as comment `5689248387`. Authenticated OpenCode verdict, complete Strix/Noema owner-path settlement and qualifying independent approval also remain outstanding. Canonical review/runtime queue, provider, timeout, retry and credential behavior stays in `.github` and contextual-orchestrator; LineageWeave does not copy it. +#1079 remains the Customer Master/shared-catalog authorization candidate at exact `c2923950e73c88a9f9fd932332ddd47682da124b`. Product Tests/SAST/Security are terminal GREEN, but required CodeQL is legitimately RED. Canonical producer run `34922377994` has now completed all actual scans: JavaScript/TypeScript and Python analyses succeeded, then the Medium+ SARIF gates failed; Actions produced no retained product finding. The findings are repository-baseline files outside #1079's 13-file authorization delta, so they are owner work rather than new summary-catalog authorization regressions. Python findings are owned by #974; frontend parser findings are owned and now source-repaired on #983 exact `a91e3724978e95f0902b3e77df91f50f7baf3599`, pending fresh exact-head acceptance evidence. Authority correction is recorded on #1079 as comments `5689248387` and `5689804039`. Authenticated OpenCode verdict, complete Strix/Noema owner-path settlement and qualifying independent approval also remain outstanding. Canonical review/runtime queue, provider, timeout, retry and credential behavior stays in `.github` and contextual-orchestrator; LineageWeave does not copy it. ### Commercial-safe synchronous PostgreSQL boundary @@ -35,7 +35,9 @@ Canonical producer `34922377994` preserved three immutable SARIF artifacts. Pyth #979 was immediately non-force converged after each #974 movement and is now exact `2431fa8cde5927ca9e6afeb2652ff8b01f3f0a85` directly on #974 `6911954363888d1e2d523ebbcf68f68d7217752a`. Its claim-generation/queue/schema delta remains distinct, the parent security files are adopted unchanged, and predecessor receipts do not transfer. There are no open descendants below #979 at this snapshot. -JavaScript artifact `10398331800` exposed four `js/incomplete-multi-character-sanitization` findings in `frontend/src/postBodyDisplay.ts`. #983 already owns that parser/rendering boundary; owner evidence is recorded in comment `5689242771`. The current React rendering path outputs text nodes and explicit ``/`` elements rather than `dangerouslySetInnerHTML`, so the SARIF alone does not establish exploitable browser XSS. The regex-as-sanitizer boundary is still a valid hard-gate robustness defect: #983 must add adversarial nested/repeated/encoded-script REDs and replace that boundary with one deterministic parser/tokenizer without breaking scientific script, OOXML indentation/footnote, embedded-image or table semantics. Query suppression or gate weakening is not accepted. +JavaScript artifact `10398331800` exposed four `js/incomplete-multi-character-sanitization` findings in `frontend/src/postBodyDisplay.ts`, at the tag-rewrite path in `markFootnoteTags`, both nested sup/sub cleanup sites, and the final tag-removal path. #983 owns that parser/rendering boundary. RED commit `ec126f7babb73269c0d4cbf0e7b9a7b4c8ca0a80` adds `frontend/src/postBodyDisplay.security.test.ts` and reproduces two concrete defects: removing an adjacent anchor can synthesize a `