diff --git a/ARCHITECTURE.md b/ARCHITECTURE.md index fd8904c..b6f4460 100644 --- a/ARCHITECTURE.md +++ b/ARCHITECTURE.md @@ -33,8 +33,36 @@ Core invariants: ## Current implementation The active MVP is a React/Vite browser workspace. State is in memory and there is no production persistence or publication backend. The browser can download and restore the exact deterministic schema-v1 JSON draft containing normalized operator-authored facts and readiness finding codes. Restore treats the local file as untrusted input, admits only the closed schema and catalog, and recomputes derived readiness evidence before atomically replacing workspace state. This local portability boundary is not publication, persistence, backup, or legal approval. The seven PRD steps are routed to distinct editing surfaces. The collection taxonomy is metadata only. `src/policy.ts` owns deterministic collection-selection/no-collection/mode/purpose/path, non-collection authoring-completeness findings, and schema-v1 validation/reconstruction; `src/App.tsx` owns browser orchestration, bounded local file selection, explicit no-collection and transfer-status capture, warning-to-source navigation, stale dependent-fact invalidation, and deterministic preview rendering. `src/AuthoringFocusController.tsx` is a browser interaction adapter: after explicit rail, previous/next, or review-warning navigation changes the active editing surface, it moves programmatic focus to that surface's heading without changing domain state, intercepting ordinary field interaction, or overriding the separate preview-focus shortcut. +The separate `src/policy-review-report.ts` read projection creates the local minimal TXT review summary via `createPolicyReviewText`. It consumes `createPolicyExport` for canonical service identity/state/ordered codes, `getCompletedSteps` for seven responsibility states, and `getReview` for recommendation labels; it is not a second readiness engine or aggregate. Each code keeps one row, with `단계 미상` fallback instead of data loss. Detailed path/purpose, retention, recipient/country and contact values are excluded; service identity remains disclosure-bearing. JSON quoting plus visible Unicode line/direction-control escaping applies at this TXT boundary, without claiming HTML/Markdown sanitization. + +`App.tsx` owns the fixed-name `policyweave-review.txt` browser download, pending-import disable/handler guard, bounded failure feedback and next-task object-URL cleanup after allocation. Download initiation changes feedback only, not authored facts, navigation or readiness. Presentation `report_format: v1` is independent of fact `schema_version: 1` and neither is a publication revision. [ADR-0006](docs/ADR-0006-local-review-summary.md) records the choice; [local layered proposal/review evidence](docs/evidence/mixed-agents-review-summary.md) records the development workflow, not runtime product AI, heterogeneous-model verification or an approval receipt. No new network, storage, dependency or legal-rule boundary is introduced. + +PRD `US-SESSION-01` exposes, rather than changes, that memory boundary. Shared `SessionNotice` is a static paragraph after the section heading and before inputs in all three editor component types, yielding one notice in each active step. It explains no automatic saving, reload/tab-close loss and the existing JSON export path without new live/focus ownership, a global layout row, browser storage, beforeunload or persistence adapter. Header/preview `앱 버전 0.1.0` is separate from fact `schema_version: 1`, report `report_format: v1` and any future publication revision. Import's existing polite pending status and semantic lock retain their own ownership; the notice neither alters facts/readiness nor certifies file storage. JSON carries admitted normalized facts, not a complete raw-input backup; TXT is a review projection, not a restore source. [The session evidence record](docs/evidence/session-notice-20261005.md) separates layered development, bounded TDD observations and unfinished current-candidate gates from historical receipts. + Authoring completeness is deliberately separate from legal sufficiency. Current readiness rules prove that product-defined fact responsibilities were explicitly addressed; they do not assert that a policy complies with law. Source/effective-date-bound legal validation belongs to the Legal Source Registry -> Review & Publication boundary. +## Canonical URL portability successor — 2026-10-05 candidate + +Historical checkpoint note: the 03:18 KST pending/frozen-TXT statements below describe that checkpoint, not the later delivered URL slice. At 03:30 KST, an independently compiled retained predecessor/candidate comparison confirmed exact TXT bytes for eight previously admissible cases; rejected-URL output is intentionally excluded from that compatibility claim. The later [URL evidence](docs/evidence/url-portability-20261005.md) and PR #26 published head `1e662c2f08d4e156b9280ef434bc876c0c77b283` record completed local gates and whole-source review, not hosted acceptance or release. The subsequent [mobile-title evidence](docs/evidence/mobile-document-title-20261005.md) separately records a fullgate NONPASS and observation repair; it must not inherit the predecessor's runtime clearance. + +The Policy Fact Authoring export boundary derives URL evidence from admitted normalized facts, not discarded raw diagnostics. `createPolicyExport` withholds a rejected URL as `null` and computes `service_url` against that admitted absence. The editor's raw `getDraftReview` still emits `service_url_format`; both remain incomplete and owned by step 1. The two views serve different correction/portability responsibilities and do not mutate one another. A JSON restore reconstructs only admitted facts and must recompute identical ordered codes/readiness; historical `null` + format evidence remains rejected, not grandfathered or migrated. + +The TXT read projection supplies that same canonical URL (or empty sentinel) to the unchanged public `formatReviewFinding` helper. Thus canonical `service_url` has its step-1 label, while raw helper calls retain raw format lookup and unresolved-code fallback. One row per exported code, ordering, non-URL findings, completion and recommendation authority remain intact. This is not a second readiness engine or a raw-input backup. Fact schema 1/report format v1 are unchanged; prior blank/valid JSON/TXT byte preservation requires frozen-fixture verification. Initially pending, the JSON blank/valid direct-export and restore/re-export comparisons plus withheld strict denial are parent-reported confirmed at 03:18 KST; frozen TXT comparison remains unverified. + +[The dated successor evidence](docs/evidence/url-portability-20261005.md) binds Layer1 proposals/runtime RED, summary-fed Layer2 conditional reviews and parent aggregation separately from intermediate focused GREEN and unfinished current full/browser/whole-prior-PR-union review/hosted acceptance. Parent 03:18 KST successor reports 65 focused cases plus lint/build against the owned source/test freeze, still not full-suite acceptance. No persistence, UI, autosave, network or legal-source boundary is changed; separate cancellation/stream and centralized workflow owners are not overlaid. + +## Mobile document-title presentation boundary — 2026-10-05 candidate + +PRD `US-MOBILE-TITLE-01` places the mobile header's existing document-name text on a normal-flow wrapping row. The implementation candidate is limited to the `.document-name` rule inside `max-width: 720px`; `App.tsx` retains the exact service-name projection, policy suffix and DOM order. Title layout has no fact, readiness, focus, download, importer or persistence authority. Natural header-height growth is intentional, while existing visible sibling controls must remain readable and nonoverlapping. Default/short-name nonmobile layout is a preservation boundary; global long-name/preview reflow is not included. [The dated evidence](docs/evidence/mobile-document-title-20261005.md) separates current diagnostics and planning from uncompleted implementation and final acceptance. Existing ADR-0005/0006 contracts are unchanged; no new architecture or legal decision is introduced. + +## Mobile import-feedback presentation boundary — 2026-10-05 candidate + +PRD `US-IMPORT-FEEDBACK-01` repairs mobile exposure of the existing `.save-state` polite region through stylesheet presentation only. A normal-flow wrapping row exposes pending and idle copy without new App state, DOM/live owner, import authority or persistence adapter. Fieldset busy and existing import/authoring/TXT locks remain; busy must not defer the live region through its ancestors. Static SessionNotice remains outside live ownership. Status has no fact/readiness/file-storage authority. Default/short-name nonmobile layout and the existing mobile title rule are preservation boundaries. [Dated evidence](docs/evidence/mobile-import-feedback-20261005.md) distinguishes baseline diagnostics and layered planning from incomplete repository TDD/final acceptance. ADR-0005/0006, separate cancellation/stream work and hosted integration gates are unchanged; no new legal or architecture decision is introduced. + +## Screen preview reading-width boundary — 2026-10-05 candidate + +PRD `US-PREVIEW-REFLOW-01` is a screen-presentation convenience contract for existing deterministic fact text. Direct paper h2/p and table th/td share a scoped wrapping declaration; warning controls, fixed clause headings and print media are excluded. It adds no facts, readiness engine, state owner, focus/live region, file format or persistence authority. Existing horizontal access was demonstrated, so the candidate is not lost-data recovery. Natural vertical growth/scrolling remains valid. [Dated evidence](docs/evidence/preview-text-reflow-20261005.md) distinguishes actual diagnostic access and layered planning from pending repository TDD and final acceptance. ADR-0005/0006 normalized portability/minimal TXT boundaries remain unchanged; no new legal or hosted architecture decision is introduced. + ## Persistence boundary (Proposed schema; CI-only runtime) ADR-0003 and `db/migrations/0001_policy_revision.sql` propose the first PostgreSQL contract. The 3NF write model uses `policy_revision` as aggregate root; `service_profile`, `collection_item`, `processing_purpose`, and `retention_rule` are revision-owned facts. `(tenant_account_id, revision_number)` identifies a version, while `(policy_revision_id, collection_item_key)` is the item-level UPSERT/idempotency key. Deferred database constraints lock the owning revision row, reject collection items under explicit no-collection, and reject retention-rule/status contradictions at transaction commit. diff --git a/CHANGELOG.md b/CHANGELOG.md index 512f36f..cc7d1b4 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,6 +5,8 @@ All notable product changes are recorded here. PolicyWeave is pre-release; entri ## Unreleased ### Added +- Candidate `US-SESSION-01` static memory-only notice before input on every authoring step: no automatic saving, reload/tab-close loss, and existing JSON export for portability. One shared paragraph covers all three editor types without live/focus ownership or a global layout change; existing pending-import feedback/locks remain. No autosave, browser storage, beforeunload, network, dependency or schema/legal-rule change. [The 2026-10-05 evidence record](docs/evidence/session-notice-20261005.md) preserves parent-reported focused TDD/build observations separately from historic suite totals and unfinished current-candidate browser/full-suite/hosted/approval gates; this is not a passing or release receipt. +- Local minimal TXT review summary on the candidate branch: `createPolicyReviewText` reuses canonical export state/service identity/ordered finding codes, existing seven-step completion and recommendation derivation; `검토 요약 다운로드` starts `policyweave-review.txt` (`text/plain;charset=utf-8`) without network or source-state changes. It omits detailed operational/contact facts, distinguishes report-format v1 from facts-schema v1, retains unknown findings and escapes dynamic line/direction controls. Import-time disable/handler guard, contained preparation/activation failures and deferred object-URL reclamation preserve the local boundary. ADR-0006 and the layered MoA-inspired decision record record completed local full-suite/browser successor evidence separately from unresolved visual inspection, exact-head hosted CI and qualifying approval; this entry is not a release or passing receipt. - Fail-closed local schema-v1 draft restore with exact object-shape, canonical-string, collection-catalog, closed-status, contradiction, and derived-evidence validation. Files above 1 MiB are rejected before parsing, invalid files preserve the current workspace, and accepted facts are reconstructed without trusting file-supplied readiness or finding claims. The import and authoring controls are disabled only while a selected file is read and validated, then re-enabled on success or failure so accepted restore cannot overwrite concurrent edits; the visible import control exposes its disabled state and the existing live status region announces `JSON 초안 확인 중` during that interval. The native authoring `fieldset` remains a semantic grid item rather than using `display: contents`. Its local-file control retains a visible high-contrast keyboard focus indicator and 44 px target. The return path performs no network request and does not claim cross-version migration, persistence, backup, publication, or legal approval. - Runtime categorical-status admission regression matrix: 64 invalid-input cases, all 16 valid collection/retention/transfer combinations and disabled-item isolation. The matrix verifies stable owning findings, incomplete readiness, null export of unsupported statuses, source non-mutation and deterministic valid projections; ADR-0004 binds its hosted RED and bounded local verification without claiming a released external interoperability or cross-version migration contract. - Executable npm manifest/lock/license contracts and an exact-head CycloneDX SBOM artifact. Every direct declaration must equal its reviewed lock resolution, the lock root must match the manifest, and every locked package must retain machine-readable license metadata. @@ -23,6 +25,14 @@ All notable product changes are recorded here. PolicyWeave is pre-release; entri - Playwright/axe browser evidence harness covering desktop, tablet, and mobile rendering; horizontal overflow; keyboard activation and focus transfer; explicit no-collection progression; retention-status transitions and stale-period invalidation; effective 200% browser-zoom reflow from the desktop profile; serious/critical automated accessibility findings; real-browser JSON download events with mouse, keyboard, and touch activation; fixed filename; JSON MIME; byte-stable repeated exports; review-ready payload semantics; success and preparation/activation-error object-URL cleanup; and exact-head screenshot artifacts. ### Changed + +Historical status note: the dated session/URL pending and frozen-TXT phrases in earlier entries below preserve their original checkpoints. The [URL successor evidence](docs/evidence/url-portability-20261005.md) supplies later completed local gates/source review; a retained-source comparison at 03:30 KST confirmed eight previously admissible TXT cases byte-for-byte, excluding changed rejected-URL output. Those results accompanied published PR #26 head `1e662c2f08d4e156b9280ef434bc876c0c77b283`, not a release. The [mobile-title successor](docs/evidence/mobile-document-title-20261005.md) has its own later fullgate NONPASS/observer-repair boundary; earlier PASS totals do not clear it. + +- Screen preview text-reflow candidate (`US-PREVIEW-REFLOW-01`): selects a new bounded reading-width convenience contract for paper fact headings/paragraphs/table cells, with screen-only wrapping and unchanged warning controls/print media. Native diagnosis confirms existing scroll access, not lost facts; long-token table/prose horizontal movement motivates the improvement. [Dated evidence](docs/evidence/preview-text-reflow-20261005.md) records actual repository RED/GREEN, complete source review and local workload recovery (unit/UI 230; browser 225 passed plus 12 existing skips). Original timeout/flaky history and the recovery supervisor's exit 1 from its immediate port probe remain separate from zero-exit workload commands and a later successful strict bind. No causal timeout repair, hosted/qualifying approval, integration, release, AT or physical-print acceptance is claimed. App/domain/white-space/schema/dependency/CI/legal/persistence contracts remain unchanged. +- Mobile import-feedback candidate (`US-IMPORT-FEEDBACK-01`): reuse the existing polite `.save-state` as a normal-flow wrapping mobile row rather than hiding it with the app version. Pending and idle copy become readable intentionally; neither implies saved work. Existing fieldset/import/TXT locks, static SessionNotice, App state, strict restore and file formats are preserved. [Dated evidence](docs/evidence/mobile-import-feedback-20261005.md) records baseline native mobile invisibility/AX absence and full-proposal cross-review separately from pending repository TDD and final gates. No extra live owner, cancellation, persistence, dependency or CI change; no completed repair, AT/WCAG approval or release claim. +- Mobile document-title reflow candidate (`US-MOBILE-TITLE-01`): a bounded CSS-only wrapping row is selected to replace silent 190 px clipping in the mobile header, while preserving the full input/text/suffix, DOM order, native controls and domain contracts. Independent current-browser measurements reproduce long-title clipping at 320/390 px despite zero document overflow; default controls pass. [The dated evidence](docs/evidence/mobile-document-title-20261005.md) distinguishes these diagnostics and full-proposal cross-reviews from pending repository TDD, implementation/full-suite/visual/source-review gates. Nonmobile extreme names, preview/rail, AT and hosted approval remain separate; this entry is not a completed repair or release receipt. +- Candidate canonical URL normalized-portability successor: JSON finding derivation follows the admitted URL after redaction (`null` → `service_url`), while live/raw `service_url_format` correction guidance stays unchanged. TXT formats those same canonical codes using admitted URL facts; its public raw helper and unresolved-code fallback are unchanged. Schema 1/report v1 and strict restore recomputation remain exact; old inconsistent null+format exports stay rejected without exception or migration. Blank/valid prior bytes must remain unchanged, with frozen-fixture verification initially pending. Parent 03:18 KST successor reports retained-source blank/valid JSON fixture direct-export and restore/re-export byte equality, withheld strict denial, and 65 focused passes plus lint/build (freeze manifest); frozen TXT comparison and full-suite acceptance remain unverified. [The 2026-10-05 successor evidence](docs/evidence/url-portability-20261005.md) preserves Layer1 RED and parent native 2-RED/3-control → 5-GREEN plus related 35-pass/lint/build observations as intermediate, not final-source acceptance. Current full/browser/whole-union review/hosted/approval gates remain pending. No UI/autosave/network/legal-rule change or release is claimed. +- Header and preview version labels now identify `앱 버전 0.1.0`, removing the unsupported `임시저장` claim. Application version is not JSON schema v1, TXT report format v1, a publication revision or proof of stored work. Existing JSON restore remains explicit and validated; reload/restore tests characterize that behavior rather than introduce automatic recovery. - Collection mode, retention status and both transfer statuses now require exact confirmed vocabulary at runtime in review and schema-v1 export. Truthy unknown values no longer complete steps or escape as confirmed facts; they preserve the existing owning finding and export as `null`. Valid positive/negative attestations, dependent details and independent completed responsibilities are preserved without coercion. - The active product-gap ledger separates current PR #1 integration truth from the former stack's historical receipts. The preceding ledger is retained byte-for-byte under `docs/evidence/product-gap-history-through-20260909.md`; no valid historical evidence is dropped or reused as current acceptance. - All direct npm packages now use exact reviewed versions. React and Lucide remain runtime dependencies; TypeScript, Vite, and the React Vite plugin are correctly classified with the test/build toolchain in `devDependencies`, and npm regenerated the lock graph so transitive development scope is accurate. diff --git a/README.md b/README.md index 24dccec..63299ca 100644 --- a/README.md +++ b/README.md @@ -31,6 +31,12 @@ PolicyWeave는 범용 법률 문구를 임의로 채우는 생성기가 아닙 선택한 수집 항목에는 수집 경로와 처리 목적을 별도로 기록할 수 있습니다. 필수 사실이 없거나 처리 목적이 비어 있으면 검토본이 이를 숨기지 않고 차단 또는 검토 경고로 드러내며, 경고에서 원인이 있는 입력 단계로 돌아갈 수 있습니다. 작성 내용은 실시간 검토본에 반영되고 모바일·키보드 사용도 고려합니다. 현재 schema-v1 JSON 초안은 로컬로 내보내고, 정확한 검증과 준비 상태 재계산을 통과한 경우에만 다시 열 수 있습니다. +### 로컬 최소 검토 요약 + +미리보기의 `검토 요약 다운로드`는 미완료 초안에서도 `policyweave-review.txt`를 로컬로 내려받기 시작합니다. TXT에는 정규화된 서비스 이름/허용 URL, 제품 정의 준비 상태, 7단계 완료 상태, 순서를 보존한 필수 확인 코드와 권장 항목이 담깁니다. 처리 목적·수집 경로 값, 보유 기간, 제공/이전 수령자·국가, 담당자 연락처와 전체 사실은 담지 않습니다. 서비스 식별정보는 남을 수 있으므로 파일 보관·전달 범위를 직접 확인하세요. + +같은 입력은 같은 TXT를 만들며 타임스탬프를 추가하지 않습니다. 검토 요약 형식 v1과 사실 스키마 v1은 발행 버전이나 승인 표시가 아닙니다. TXT는 JSON 초안 복원 파일·공개 정책·법률 자문·저장 완료 증거를 대체하지 않습니다. JSON 확인 중에는 버튼이 잠기며, 실패하면 현재 작성 상태를 유지하고 재시도를 안내합니다. 현재 후보의 전체 검증과 독립 승인 상태는 [로컬 증거 기록](docs/evidence/mixed-agents-review-summary.md)에서 별도로 구분합니다. + ## 빠른 시작 현재 제품은 소스로 평가하는 초기 개발 버전입니다. 패키지 메타데이터 `0.1.0`은 게시된 릴리스를 뜻하지 않습니다. 아직 GitHub 릴리스가 없으므로 검토 중인 소스와 배포 가능한 제품을 구분해 사용하세요. @@ -111,6 +117,7 @@ PolicyWeave는 개인정보처리방침을 만들기 위해 불필요한 실제 - [아키텍처](ARCHITECTURE.md) — 제품 책임과 기술 경계 - [ADR-0001: Policy as Data](docs/ADR-0001-policy-as-data.md) — 핵심 설계 결정 - [ADR-0005: 로컬 schema-v1 초안 복원](docs/ADR-0005-local-draft-restore.md) — 신뢰하지 않는 로컬 파일의 fail-closed 복원 결정 +- [ADR-0006: 로컬 최소 TXT 검토 요약](docs/ADR-0006-local-review-summary.md) — 출력 최소화와 다운로드 실패 경계 - [제품·기술 Gap baseline](docs/product-technical-gap-baseline.md) — 아직 닫히지 않은 상용화 Gap과 완료 증거 - [공개 문서 홈](docs/index.md) — 저장소 문서 탐색 시작점 - [변경 이력](CHANGELOG.md) diff --git a/docs/ADR-0005-local-draft-restore.md b/docs/ADR-0005-local-draft-restore.md index ca551ed..a5a6829 100644 --- a/docs/ADR-0005-local-draft-restore.md +++ b/docs/ADR-0005-local-draft-restore.md @@ -37,7 +37,7 @@ After reconstruction, PolicyWeave runs `createPolicyExport` again. Imported `doc ## User, operations, and failure scenes -- An operator exports an incomplete draft, later selects that file, and resumes with the same unresolved findings. Blank values do not become negative attestations. +- An operator exports an incomplete draft, later selects that file, and resumes with the same unresolved findings recomputed from admitted normalized facts, not every discarded raw diagnostic. Blank values do not become negative attestations. - A complete no-collection draft restores with zero blockers only when every independent retention, transfer, service, and contact fact still satisfies current rules. - A manipulated file that changes only `document_state` to `review_ready` is rejected and the current workspace remains unchanged. - A file with an unknown collection key, duplicate key, mismatched label, non-canonical string/URL, uppercase status, extra property, or contradictory no-collection state is rejected with bounded user guidance rather than partially applied. @@ -56,6 +56,28 @@ Pending-feedback test-only commit `3e2eba61e7e4f02c5ac8b3f9ee23895d515a37b3` the Semantic-fieldset test-only commit `52d252a2c0c46b12c6cecdebd3dcc67940322bde` reproduced the remaining accessibility risk by failing while `.editing-lock` used `display: contents`. Implementation `9d540895569ab945a087bed99c7d4906b82ae532` keeps the native disabled/`aria-busy` fieldset as the middle grid item, resets only its user-agent box, and gives the contained editing panel the grid item's height so bounded scrolling remains available. Focused style/import validation passed 10/10 locally; hosted browser and assistive-technology evidence remain separate gates. +## Session-boundary clarification — 2026-10-05 + +PRD `US-SESSION-01` adds truthful notice of this ADR's existing memory-only portability boundary; it does not revise schema admission, persistence or restore authority. The active editor shows one static paragraph after its heading and before inputs, explaining no automatic saving, reload/tab-close loss and existing JSON export. Header/preview `앱 버전 0.1.0` replaces the unsupported temporary-save label and is independent of JSON `schema_version: 1` and TXT `report_format: v1`. The notice does not replace the import live region, become a focus target, add beforeunload/browser storage or change the semantic input lock. + +A valid native JSON download → reload-empty → explicit import journey characterizes existing behavior; it does not establish automatic recovery or a new feature. JSON carries only admitted normalized facts: rejected URLs, inactive/discarded details and every raw input are not guaranteed round-trip backup content. A failed import preserves current state; success retains validated replacement and step-1 navigation. Download initiation is not completed storage, and TXT is not a restore artifact. Existing cancellation/stream work remains separately owned, not implied by this clarification. + +[The session evidence record](evidence/session-notice-20261005.md) retains parent-reported focused TDD/build observations separately from direct source inspection, all historic receipts above and unfinished current full/browser/hosted/independent-approval gates. This ADR remains Proposed; no new CI pass, protected integration, release or legal conclusion is asserted. + +## Canonical URL evidence clarification — 2026-10-05 successor candidate + +"Same unresolved findings" applies to admitted normalized facts and their exact recomputed evidence. It does not promise a full raw-input backup or recovery of discarded diagnostics. The live editor keeps `service_url_format` for nonblank rejected URL correction; JSON withholds the rejected URL as `null` and derives canonical `service_url`. Restore reconstructs the empty sentinel, remains incomplete and retains service-information step-1 ownership. The canonical TXT projection uses the same URL/code boundary; TXT is still not a restore artifact. + +`schema_version: 1`, exact object/catalog/status validation, reconstruction and ordered finding/readiness equality remain unchanged. Historical producer-inconsistent `null` + `service_url_format` files remain rejected, with no grandfathering, dual-code exception, trusted file evidence, automatic repair or migration. Existing blank/valid JSON/TXT bytes must be preserved, but frozen predecessor-fixture verification was pending at the initial checkpoint. Parent 03:18 KST successor confirms retained-source blank/valid JSON direct-export and restore/re-export byte equality plus withheld strict denial; frozen TXT comparison remains unverified. The producer repair is not a schema revision; any future schema revision still requires explicit migration/loss/compatibility treatment. + +[The successor evidence](evidence/url-portability-20261005.md) preserves independent Layer1 proposals and frozen native RED, summary-fed Layer2 conditional reviews, parent synthesis and intermediate native 2-RED/3-control → 5-GREEN plus related 35-pass/lint/build observations. Current full/browser, whole prior-PR union independent review and hosted/qualifying-approval gates are pending. Parent 03:18 KST successor reports 65 focused cases plus lint/build against the owned source/test freeze, still not full-suite acceptance. This ADR remains Proposed; no protected shipment or legal conclusion is asserted, and separate PR #25 cancellation/stream ownership is unchanged. + +## Mobile pending-feedback clarification — 2026-10-05 candidate + +PRD `US-IMPORT-FEEDBACK-01` selects a CSS-only mobile exposure repair for this ADR's existing polite status. Pending `JSON 초안 확인 중` and idle `브라우저 작업 중` reuse the same region and App state; idle is not saved work or continuing validation. Fieldset busy remains separate from the live region and its ancestors. No duplicate live output, static-notice promotion, new lock/cancellation, schema change, raw-backup promise or persistence authority is introduced. + +[The dated evidence](evidence/mobile-import-feedback-20261005.md) records actual mobile invisibility despite working native lock/release, conditional full-proposal cross-reviews and required repository TDD/final gates. Valid replacement/step-1 behavior, invalid/read-failure preservation, oversize rejection before read and exact file bytes remain acceptance boundaries. AX exposure is not actual AT speech. This clarification does not complete current hosted/approval gates or alter Proposed status and separate PR #25 ownership. + ## Consequences and follow-up -PolicyWeave now owns a deterministic local export/restore round trip for schema-v1. This closes the missing current-version return path, not version migration. Any schema-v2 work must define explicit migration, loss reporting, compatibility fixtures, and rollback behavior. DB-backed versioned ko/en/ja/zh/vi/es/de/fr resources remain a separate owner contract; schema-v1 catalog-label identity must not be relaxed by embedding a full translation catalog in the browser. +PolicyWeave owns a deterministic local export/restore round trip for admitted normalized schema-v1 facts with consistent recomputed evidence, not every historical producer-inconsistent file or discarded raw value. This closes the missing current-version return path, not version migration. Any schema-v2 work must define explicit migration, loss reporting, compatibility fixtures, and rollback behavior. DB-backed versioned ko/en/ja/zh/vi/es/de/fr resources remain a separate owner contract; schema-v1 catalog-label identity must not be relaxed by embedding a full translation catalog in the browser. diff --git a/docs/ADR-0006-local-review-summary.md b/docs/ADR-0006-local-review-summary.md new file mode 100644 index 0000000..2acd014 --- /dev/null +++ b/docs/ADR-0006-local-review-summary.md @@ -0,0 +1,54 @@ +# ADR-0006: Local minimal TXT review summary + +- Status: Proposed +- Date: 2026-10-03 +- Owner: Review & Publication / Policy Fact Authoring +- Scope: `src/policy-review-report.ts`, `src/App.tsx`, PRD `US-REVIEW-01` +- Candidate base: `60fd7fb`, branch `feat-mixed-agents-prd`; no implementation commit or exact-head hosted PASS receipt is asserted here. +- Evidence: [local layered proposal, cross-review and verification record](evidence/mixed-agents-review-summary.md) + +## Problem and alternatives + +Operators need a portable view of missing responsibilities and current product-defined readiness, but exporting another full-facts document expands disclosure and duplicates the existing JSON portability boundary. A summary must not invent facts, claim legal approval, or diverge from the existing domain findings. + +1. **Full-facts Markdown**: the independent product proposal included normalized seven-step facts and findings. Deferred for this slice because it duplicates JSON, exposes contact and operational details, and adds Markdown/HTML output obligations. +2. **Minimal TXT**: the independent technical proposal limits output to canonical service identity, existing readiness/completion, blocker codes and recommendation labels. Selected after a second cross-review layer and parent aggregation, subject to all P1 controls below. +3. **PDF/HTML/hosted report or AI-generated assessment**: out of scope; no renderer dependency, new network surface, model runtime or legal rule is justified for a local deterministic summary. + +## Decision + +A separate pure `createPolicyReviewText` read projection consumes `createPolicyExport` for schema version, `document_state`, normalized service identity and ordered `review_finding_codes`; `getCompletedSteps` supplies seven-step completion and `getReview(...).recommended` supplies recommendation labels. No new readiness rule or source-of-truth store is introduced. + +- Emit one blocker row for each exported code, in exact order, without deduplication or suppression. `formatReviewFinding` decorates codes resolvable against its supplied facts with existing owning-step/label semantics; an unresolved code stays visible as a quoted `단계 미상` row. The report must supply canonical URL facts so its canonical URL code is resolvable. +- Preserve collection contradiction's incomplete steps 2 and 3 even when the selected item has otherwise complete details. Recommendations never become blockers or proof of legal sufficiency. +- Include canonical service name/allowed URL only as authored identity values. Do not expose raw rejected credential/query/fragment URLs. Exclude path/purpose values, retention periods, recipient/country values, contact values and full fact objects. Identity and catalog/finding labels can still disclose context; the result is not guaranteed anonymous. +- JSON quote every dynamic string and visibly escape C1 controls (`U+0080–U+009F`), `U+061C`, `U+200E–U+200F`, `U+2028–U+202E` and `U+2066–U+2069`. This is line/direction-control handling for TXT, not universal HTML/Markdown sanitization. +- Emit deterministic text without timestamps or nonces. `report_format: v1` is presentation format, `schema_version: 1` is the existing fact contract, and neither is a publication or approval version. + +`DocumentPreview` exposes `검토 요약 다운로드`. Browser orchestration uses `policyweave-review.txt`, MIME `text/plain;charset=utf-8`, Blob and an object URL. The button is disabled during pending JSON import and `exportReview` independently guards that interval. Blob, URL allocation, anchor construction/configuration and click failures are contained with generic retry feedback, without exception text. An allocated URL is reclaimed on the next task after either success or activation failure, not synchronously before deferred browser consumption. + +Success announces download initiation, not file storage completion. Success and failure may change feedback only; items, facts, attestations, active step, readiness and completion remain unchanged. Browser cancellation, persistence, publication and approval are not established by starting a download. + +## Verification and acceptance + +PRD `US-REVIEW-01` defines user acceptance. `src/policy-review-report.test.ts` traces initial/incomplete and complete projections, exact ordered finding identity/cardinality, owning labels, recommendation separation, contradictory completion, hostile string encoding, detail omission and unknown fallback. `src/policy-review-ui.test.tsx` traces browser-adapter behavior. Required domain cases also include unsupported categorical values and unsafe URL non-disclosure; required UI/browser cases include full workspace preservation, import lock, fixed filename/MIME, deterministic bytes, mouse/keyboard/touch activation, preparation/activation exceptions and delayed cleanup. + +These are requirements/assertion traces, not blanket passing receipts. The evidence document preserves initial failures, bounded local successor passes and toolchain caveats separately. The parent completed local lint/tests/build and browser regressions; visual screenshot inspection remains unresolved. Exact-current-head organization workflows, resolved threads and qualifying independent approval remain unverified gates. No hosted release is claimed. + +## Canonical URL composition clarification — 2026-10-05 successor candidate + +Historical checkpoint note: the frozen-TXT/pending clauses below describe the 03:18 KST handoff. A separate 03:30 KST retained predecessor/candidate compilation confirmed eight previously admissible TXT cases with exact byte equality; intentionally changed rejected-URL output is excluded. Later [URL evidence](evidence/url-portability-20261005.md) records the completed local source/runtime gates associated with published PR #26 head `1e662c2f08d4e156b9280ef434bc876c0c77b283`, not protected integration or release. This ADR stays Proposed. The [mobile-title successor evidence](evidence/mobile-document-title-20261005.md) separately retains its later fullgate NONPASS and observer-repair requirements; that candidate does not inherit the earlier runtime PASS. + +The report is a canonical export projection, not a record of every raw editor diagnostic. After a rejected URL is withheld as `null`, JSON/TXT use `service_url` and the step-1 `서비스 URL` label; live raw `getDraftReview` still uses `service_url_format` and `서비스 URL 형식`. `createPolicyReviewText` supplies the exported URL (or empty sentinel) to `formatReviewFinding`. The public helper itself is unchanged: a raw format-code/raw-invalid-fact call still has format ownership; a code not resolvable against supplied facts stays visible via fallback. Canonical `service_url` must not misleadingly fall back to `단계 미상`. Other ordered codes, one-row cardinality, seven-step completion, recommendations and text escaping remain unchanged. + +Fact `schema_version: 1` and presentation `report_format: v1` are unchanged. Strict JSON restore recomputation remains exact and historical null+format exports stay rejected, without compatibility exception or migration. Blank/valid prior JSON/TXT bytes must be unchanged; frozen predecessor-fixture byte verification was initially pending, distinct from current-function deterministic output. Parent 03:18 KST confirms retained-source blank/valid JSON direct-export and restore/re-export equality and withheld strict denial; frozen TXT comparison remains unverified. No raw backup, UI/autosave/network/legal-rule change is introduced. + +[The successor evidence](evidence/url-portability-20261005.md) binds the Layer1 runtime/contract proposals, summary-fed Layer2 conditional reviews and parent synthesis separately from intermediate parent native 2 RED + 3 controls then 5 GREEN and related 35-case/lint/build reports. Earlier local full/browser receipts above remain historical; current successor full/browser/whole prior-PR union review/hosted/qualifying approval gates remain pending. Parent 03:18 KST successor reports 65 focused cases plus lint/build against the owned source/test freeze, still not full-suite acceptance. This Proposed ADR and planning agreement are not final implementation or release approval. + +## Screen presentation clarification — 2026-10-05 candidate + +PRD `US-PREVIEW-REFLOW-01` selects screen-only wrapping of existing paper fact text as a bounded reading-width convenience contract. It does not broaden this ADR's minimal TXT contents or change `createPolicyReviewText`, escaping, code ordering, report v1, fixed filename/MIME or pending handler guard. Same-state native JSON/TXT byte preservation remains required; diagnostic before/after pairs are not production-successor acceptance. The candidate leaves warning buttons and print media outside its new rule and does not claim physical printing or AT acceptance. [Dated evidence](evidence/preview-text-reflow-20261005.md) keeps current repository/final gates pending separately from historical receipts. This ADR remains Proposed; no new legal, schema or publication authority is introduced. + +## Consequences + +TXT aids review without duplicating the entire fact export; JSON remains the current-version restore artifact. Future summary format changes require reviewed presentation compatibility, while fact-schema migration remains ADR-0005's separate contract. Hosted review/publication still requires tenant authorization, immutable revision/audit, encryption and source/rule evidence. The MoA-inspired development workflow does not add product AI or satisfy GitHub independent approval. diff --git a/docs/PRD.md b/docs/PRD.md index ec84015..b593629 100644 --- a/docs/PRD.md +++ b/docs/PRD.md @@ -17,7 +17,7 @@ PolicyWeave는 법률 문장을 임의로 창작하는 도구가 아니다. 운 - 개인정보를 수집하지 않는 경우의 명시적 운영자 확인과 수집 항목 사실의 상호배타성 - 개인정보 보유 여부의 명시적 `보유함`/`보유하지 않음` 확인; `보유함`일 때만 보유 기간 요구 - 제3자 제공과 국외 이전의 명시적 `있음`/`없음` 확인; `있음`일 때만 종속 상세 사실 요구 -- 공개 전 검토 요약과 버전 정보 +- 공개 전 로컬 최소 TXT 검토 요약과 별도 형식/사실 스키마 버전 정보(공개·승인·저장 완료의 증거 아님) - 정적 공개 URL 발행 계약(후속 백엔드에서 구현) - 버전이 명시된 JSON으로 현재 정책 사실과 검토 상태를 로컬 내보내기 @@ -28,6 +28,90 @@ PolicyWeave는 법률 문장을 임의로 창작하는 도구가 아니다. 운 - 검증이 실패하면 현재 작업공간을 보존하며, 1 MiB를 초과한 파일은 파싱 전에 거부한다. - 복원 경로는 브라우저 로컬에 한정하고 네트워크 전송·공개·호스팅 영속화를 주장하지 않는다. +## US-PORTABILITY-01: 정규화된 URL 사실의 로컬 이동성 — 2026-10-05 후속 후보 + +1. 원시 작성값이 비어 있지 않지만 허용 URL이 아니면 live `getDraftReview`는 기존 `service_url_format` 수정 안내를 유지한다. 다운로드는 원시 작성값·완료 판정을 변경하지 않는다. +2. JSON은 허용된 정규화 사실의 이동성 파일이다. 거부된 URL은 계속 `service_url: null`로 제외하고, 내보낸 발견사항은 그 제외 이후의 사실에서 `service_url`로 계산한다. `incomplete`와 서비스 정보 1단계 책임을 유지하며 자격정보·query·fragment를 다른 목적지로 고쳐 쓰거나 파일에 남기지 않는다. +3. TXT는 같은 canonical JSON 코드의 순서·개수와 URL의 1단계 `서비스 URL` 라벨을 유지한다. live 원시 형식 진단을 보존하는 파일은 아니다. 공개 helper `formatReviewFinding`의 원시 사실 해석은 그대로이고, 보고서 호출이 정규화 URL 사실을 전달한다. `단계 미상`은 그 helper가 주어진 사실에서 해석하지 못한 코드의 보존 경계이며 canonical URL 코드가 그 경계로 빠져서는 안 된다. +4. `schema_version: 1`과 `report_format: v1`, 정확한 객체/카탈로그/상태 검증, 재계산 후 ordered 코드·readiness 일치 검증은 변경하지 않는다. 과거 `null` URL + `service_url_format` 파일은 여전히 거부한다. 호환성 예외·자동 수정·migration을 도입하지 않는다. +5. 빈 URL·유효 URL의 기존 JSON/TXT 바이트는 유지해야 한다. 후속 함수 round trip과 과거 frozen fixture 간 바이트 비교는 서로 다른 증거이며, 초기 문서 checkpoint에서는 frozen fixture 검증이 미완료였다. 03:18 KST 후속 parent 보고와 freeze manifest는 실제 보존된 선행 소스로 생성한 blank/valid JSON fixture의 direct export·restore/re-export byte equality 및 withheld fixture의 strict denial을 확인한다. 이는 TXT frozen 바이트 비교나 전체 suite 완료를 뜻하지 않는다. 거부된 원시 URL/폐기된 상세값/원시 진단 전체의 백업은 보장하지 않는다. +6. 실제 JSON 다운로드 → 새로고침 후 빈 상태 → 명시적 파일 복원 → byte-equal 재내보내기, TXT 라벨·순서·비밀값 비노출, 원시 상태 불변, 조작된 코드/readiness 거부를 현재 소스에 묶어 확인해야 한다. 현재 전체 suite·실제 브라우저·이전 PR 전체 union 독립 검토·exact-head hosted/승인 게이트는 미완료이며 집중 GREEN만으로 수락하지 않는다. + +[후속 결정·증거 범위](evidence/url-portability-20261005.md). 이는 기존 정규화 사실 계약의 producer 일관성 수정 후보이지 새 법률 규칙, 네트워크/자동 저장 기능 또는 출시 증거가 아니다. + +## US-REVIEW-01: 로컬 최소 검토 요약 + +운영자로서 현재 작성 상태와 다음 확인 책임을 책임자와 검토하기 위해, 전체 처리 상세를 다시 복제하지 않는 로컬 TXT 요약을 다운로드하고 싶다. + +### 수락조건 + +1. 미완료 상태에서도 미리보기의 `검토 요약 다운로드`로 `policyweave-review.txt`를 내려받기 시작할 수 있다. MIME은 `text/plain;charset=utf-8`이며 네트워크 요청·새 저장소·외부 렌더러를 추가하지 않는다. +2. 요약은 기존 JSON 내보내기의 `document_state`, 정규화된 서비스 이름/허용 URL과 순서가 같은 차단 코드, 기존 완료 판정의 7단계 상태, 기존 권장 검토 항목을 보여 준다. 차단 코드마다 정확히 한 행을 유지하며 알 수 없는 코드는 버리지 않고 `단계 미상`으로 남긴다. 수집 모순은 수집 항목과 처리 목적 단계의 미완료 판정을 그대로 보존한다. +3. 수집 경로·처리 목적 값, 보유 기간, 제공/이전 수령자·국가, 담당자 이름·이메일 및 전체 사실 객체는 포함하지 않는다. 서비스 식별정보는 포함될 수 있으므로 보관·전달 범위를 운영자가 확인한다. 이는 익명화된 파일이라는 보장이 아니다. +4. 같은 입력은 같은 TXT를 만든다. 타임스탬프·nonce·발행 버전을 생성하지 않으며 `report_format: v1`과 `schema_version: 1`을 구분한다. 동적 문자열은 JSON 인용하고 줄/문단 구분자와 bidi 제어문자를 가시적으로 이스케이프한다. HTML/Markdown 안전성을 주장하지 않는다. +5. JSON 읽기/검증 중에는 버튼을 비활성화하고 핸들러에서도 거부한다. 다운로드 준비·활성화 실패는 일반적인 재시도 안내로 처리하며 예외 원문을 표시하지 않는다. URL 할당에 성공하면 성공/실패 모두에서 다음 task에 회수한다. +6. 성공 안내는 `다운로드를 시작했습니다`이며 파일 저장 완료를 주장하지 않는다. 성공/실패 모두 작성 사실·선택 항목·명시적 확인·현재 단계·완료 판정을 변경하지 않는다. +7. 요약은 제품 정의 입력 완결성의 표현일 뿐 법률 자문·준법 보장·승인·발행·자동 저장의 증거가 아니다. TXT는 JSON 복원 파일이나 공개 개인정보처리방침을 대체하지 않는다. + +결정과 검증 범위: [ADR-0006](ADR-0006-local-review-summary.md), [로컬 MoA/검증 기록](evidence/mixed-agents-review-summary.md). 현재 후보의 실제 브라우저·전체 suite·exact-head CI·독립 승인 증거는 별도 게이트이며 이 수락조건의 기재만으로 통과하지 않는다. + +## US-SESSION-01: 메모리 전용 작성과 보관 경계 안내 + +운영자로서 작성 내용이 자동 저장되지 않는다는 사실을 입력 전에 알고, 보관이 필요하면 기존 JSON 내보내기와 검증된 가져오기 경로를 선택하고 싶다. + +### 수락조건 + +1. 상단과 미리보기는 `앱 버전 0.1.0`으로 표시하고 `임시저장`·자동 저장·저장 완료를 주장하지 않는다. 앱 버전은 JSON `schema_version: 1`, TXT `report_format: v1`, 승인·발행 버전과 별개다. +2. 모든 7단계의 작성면에서 `.section-head` 다음, 첫 입력 전에 동일한 정적 안내를 정확히 하나 제공한다: `자동 저장되지 않습니다. 새로고침하거나 탭을 닫으면 작성 내용이 사라집니다. 보관하려면 JSON 내보내기를 사용하세요.` +3. 안내는 일반 문서 흐름에 남아 320 px 모바일에서도 숨겨지거나 가로로 잘리지 않아야 한다. 상단 `.version`·`.save-state`의 모바일 숨김 여부에 의존하지 않는다. 반복 live 알림, alert/status 역할 또는 별도 포커스 대상으로 만들지 않는다. +4. 편집, 단계 이동, 가져오기 대기·성공·실패와 JSON/TXT 다운로드 성공·실패 후에도 안내를 유지한다. 기존 가져오기 live 상태 `JSON 초안 확인 중` / `브라우저 작업 중`과 입력 잠금은 보존한다. 안내가 사실·선택·명시적 확인·완료/readiness 판정·내보내기 바이트를 바꾸지 않는다. 정상 가져오기의 검증 후 상태 교체와 첫 단계 이동은 기존 동작이다. +5. 유효한 schema-v1 파일의 실제 다운로드 → 새로고침 후 빈 작업공간 → 명시적 파일 가져오기 경로를 브라우저에서 확인한다. 이는 기존 메모리 소실/JSON 복원 동작의 특성화이며 새 자동 복원 기능이 아니다. JSON은 정규화·검증된 사실의 이동성 파일이지 잘못된 URL, 비활성/폐기된 원시 입력 전체를 보존하는 백업이 아니다. TXT는 복원 파일이 아니며 다운로드 시작은 파일 보관 완료를 증명하지 않는다. +6. 자동 저장, localStorage/sessionStorage/IndexedDB, beforeunload, 네트워크 영속화, 새 의존성 또는 스키마/법률 규칙을 추가하지 않는다. 저장·승인·준법·공개 완료를 안내로 추론하지 않는다. + +결정·MoA/TDD 및 검증 범위: [2026-10-05 세션 안내 증거](evidence/session-notice-20261005.md), [ADR-0005](ADR-0005-local-draft-restore.md). 소스 assertion·집중 로컬 실행·선행 suite·현재 후보의 전체/실제 브라우저·hosted CI·독립 승인 증거는 서로 대체하지 않는다. + +## US-MOBILE-TITLE-01: 모바일 문서 이름의 줄바꿈 + +운영자로서 긴 서비스 이름을 입력해도 현재 문서의 이름과 `개인정보처리방침` 접미사를 모바일 상단에서 읽고 싶다. + +### 수락조건 + +1. 모바일 규칙이 적용되는 320·390·720 px에서 기본 이름, 짧은 한글, 고정된 긴 한글·혼합 문자열·공백 없는 ASCII 시험값의 상단 문서 이름을 일반 흐름의 줄바꿈으로 표시한다. 이는 검증 cohort이며 새로운 입력 길이 제한이 아니다. +2. 입력값·문서 이름 전체 문자열·접미사·DOM 순서를 보존한다. 자동 절단, 새 정규화, 접미사 숨김, `title` 또는 말줄임표만으로 전체 이름 확인을 대체하지 않는다. +3. 실제 양수 크기의 텍스트 줄들이 문서 이름 상자 안에 포함되고, 가로로 모바일 viewport를 넘거나 인접 상단 요소와 겹치지 않아야 한다. 자연스러운 높이 증가와 세로 스크롤을 허용하며 모든 줄의 초기 viewport 높이 내 동시 표시를 요구하지 않는다. +4. brand·작성 상태·JSON 가져오기/내보내기 문구와 컨트롤을 보존한다. 721·820·1280 px의 기본·짧은 이름은 변경 전 비모바일 스타일·배치를 유지한다. 비모바일 극장문·미리보기의 전체 장문 처리는 이 모바일 제목 수락 범위 밖이다. +5. 사실·완료/readiness·7단계 이동·키보드 focus·세션 안내·native JSON/TXT·strict import를 바꾸지 않는다. 동일 입력 상태에서 측정·이동 전후 보존을 비교한다. 이름 입력 자체가 정상적으로 바꾸는 발견사항을 불변으로 요구하지 않는다. + +[모바일 제목의 결정·검증 기록](evidence/mobile-document-title-20261005.md)은 독립 실측, 계획 교차 검토, 저장소 RED, 구현 GREEN, 시각 확인과 최종 gate를 구분한다. 현재 수락조건의 기재는 구현·접근성 전체·hosted 승인·출시 증거가 아니다. + +## US-IMPORT-FEEDBACK-01: 모바일 JSON 가져오기 상태 안내 + +운영자로서 JSON 초안을 읽고 검증하는 동안 입력이 잠긴 이유를 모바일에서도 기존 상태 안내로 확인하고 싶다. + +### 수락조건 + +1. 320·390·720 px에서 기존 `.save-state`의 `JSON 초안 확인 중`을 숨기지 않고 일반 흐름의 줄바꿈 행으로 표시한다. 종료 후 기존 `브라우저 작업 중`도 표시한다. 이 평상시 문구는 저장 완료나 계속되는 가져오기를 뜻하지 않는다. 앱 버전의 모바일 숨김은 유지한다. +2. 기존 문구·DOM 순서를 유지하고 상단 `.save-state`의 기존 `aria-live="polite"` 영역을 그대로 재사용한다. 기존 footer 결과 안내는 변경하지 않고 새 live 영역을 추가하지 않는다. 현재 텍스트는 해당 영역의 실제 Chromium AX 자손 경로에서 노출되어야 한다. 영역이나 유효 조상에 busy를 부여하지 않고, 정적 세션 안내를 live/status/alert로 바꾸지 않는다. 실제 보조기술 발화는 별도 검증이다. +3. 상태 텍스트 줄은 양수 크기로 가로 viewport와 실제 clipping 경계 안에 남고, 상단의 제목·가져오기/내보내기 컨트롤과 겹치지 않는다. rail은 상단 아래에서 시작한다. 자연스러운 상단 높이 증가와 세로 스크롤을 허용한다. 721·820·1280 px의 같은 기본/짧은 이름 입력은 기존 비모바일 배치를 유지한다. +4. 기존 fieldset busy, 작성 입력·파일 선택·TXT 잠금을 유지한다. rail·JSON 내보내기까지 새로 잠그지 않는다. 유효 파일은 검증 후 상태 교체·첫 단계 이동·입력 초기화·잠금 해제와 같은 파일의 byte-equal 재내보내기를 유지한다. 잘못된 JSON/schema와 읽기 실패는 오류 안내 외의 기존 원시 작성값·현재 단계·검토 상태를 보존한다. 1 MiB 초과 파일은 읽기 전에 거부한다. +5. App 상태, strict importer, 사실 스키마, 7단계, JSON/TXT 바이트 계약, 메모리 전용 경계를 바꾸지 않는다. 새 알림 영역·footer 재사용·취소·자동 저장·의존성·CI 정책을 추가하지 않는다. + +[결정·증거 기록](evidence/mobile-import-feedback-20261005.md)은 baseline 실측, 저장소 RED/GREEN, 현재 최종 gate를 구분한다. 이 수락조건은 구현 완료·AT/WCAG 수락·hosted 승인·출시 증거가 아니다. + +## US-PREVIEW-REFLOW-01: 장문 사실의 화면 미리보기 줄바꿈 + +운영자로서 고정된 장문 시험 cohort의 검토본 제목·본문·목적 표를 현재 paper 읽기 폭 안에서 줄바꿈으로 검토하고 싶다. 원래 사실·검토본 접미사·경고 책임을 유지하며 자연 높이 증가와 내부/문서 세로 스크롤을 허용한다. + +### 수락조건 + +1. 화면의 `.paper > h2`, `.paper > p`, `.paper th`, `.paper td`에 한정해 긴 토큰을 줄바꿈한다. 고정 ASCII cohort는 320·390·720·721·820·1280·1440 px, 한글·혼합 문자열은 대표 320·820 px에서 검증한다. 이는 시험 범위이며 모든 문자열·글꼴·기기의 가독성 보장이 아니다. +2. 입력값·현재 투영 문자열·`(검토본)` 접미사·표 행과 카탈로그/상태 문구를 유지한다. 셀 텍스트는 셀의 실제 읽기 폭 안에, 표는 paper content-box 안에 남고 가로 왕복 없이 해당 사실을 검토할 수 있어야 한다. 문서 전체 overflow 0이나 문자열 존재만으로 수락하지 않는다. +3. 아래 fold에 있는 줄을 실패로 보지 않는다. 실제 document/preview 세로 스크롤 경로에서 대상의 처음·끝을 확인하고, hidden/clip/투명 텍스트·표 팽창·인접 텍스트 겹침에 민감한 검사를 둔다. 기존 preview의 auto 스크롤과 높이 상한은 유지한다. +4. 기본/짧은 입력의 선행·후속 실제 배치와 기존 경고 버튼·header/status/notice·7단계·키보드 heading focus·입력 잠금·완료/readiness를 보존한다. 같은 상태의 native JSON/TXT 바이트와 strict restore를 유지한다. 원시 입력과 정규화 JSON을 같은 문자열이라고 가정하지 않는다. +5. 변경은 screen에 한정하고 print에는 새 줄바꿈 규칙을 적용하지 않는다. print-media 비교는 실제 인쇄·pagination 승인과 별개다. 새 white-space·입력 길이 제한·사실 정규화·절단·숨김·App 상태·live 영역·스키마·의존성·CI 정책을 추가하지 않는다. + +기존 가로 스크롤로 사실에 도달할 수 있음은 이미 확인됐다. 이 이야기는 유실 복구나 현행 스크롤 계약 위반 수리가 아닌 **새 화면 읽기 편의 계약**이다. [결정·증거 기록](evidence/preview-text-reflow-20261005.md)은 실제 저장소 RED/GREEN, 전체 소스 검토와 현 소스의 로컬 실행 225개 통과·기존 제외 12개를 기록한다. 최초 실행의 실패·재시도 이력과 후속 실행 감독기의 즉시 포트 검사 실패도 보존한다. 별도 후속 포트 바인딩 성공은 감독기 exit 1을 덮어쓰지 않으며, 이 로컬 실행 결과는 원인 수리·hosted 검사·qualifying approval·병합·출시를 뜻하지 않는다. + ## 비목표 - 법률 자문 또는 준법 보장 diff --git a/docs/TRD.md b/docs/TRD.md index 802a72c..c29737c 100644 --- a/docs/TRD.md +++ b/docs/TRD.md @@ -41,9 +41,57 @@ The separation between collection and retention follows the PIPC Standard Person - Hosted web endpoints, when introduced, use non-blocking/asynchronous handling and require realistic k6 tests before a p95 <=20 ms page/API claim is recorded. - Production does not depend on synthetic demo data. +## Local minimal TXT review summary + +`src/policy-review-report.ts` owns the pure `createPolicyReviewText` projection; it does not own readiness rules. `createPolicyExport` supplies canonical service identity, `document_state`, schema version and ordered finding codes; `getCompletedSteps` supplies all seven responsibility states; `getReview(...).recommended` supplies recommendation labels. `formatReviewFinding` maps existing codes to owning steps/labels without dropping or reordering codes. Unknown codes retain one quoted row with `단계 미상`. Collection contradiction must retain the domain's incomplete steps 2 and 3, even when item details are otherwise complete. + +The output is a local review aid, not the full JSON portability payload. It excludes collection-path and purpose values, retention periods, recipient/country details, contact values and the full facts object. Service identity can still identify an operator; omission of details is not anonymization. Unsafe credential/query/fragment URLs stay withheld by the existing export admission contract, never printed raw. Dynamic strings are JSON quoted with visible escaping for C1 controls, Unicode line/paragraph separators and bidi controls; this is a TXT boundary, not an HTML/Markdown encoder. No time, nonce, publication revision or runtime LLM is introduced. `report_format: v1` versions presentation independently of `schema_version: 1` facts. + +`DocumentPreview` exposes `검토 요약 다운로드`; `exportReview` is both visibly disabled and handler-guarded during import. It uses fixed filename `policyweave-review.txt` and MIME `text/plain;charset=utf-8`, contains Blob/object-URL/anchor/activation exceptions with generic retry copy, and schedules object-URL reclamation on the next task whenever allocation succeeded. Successful activation announces download initiation, not completed storage. Neither outcome changes authoring facts, selected items, attestations, current step or derived completion/readiness. No network, renderer dependency, persistence, legal rule or cancellation contract is added. + +Acceptance: PRD `US-REVIEW-01`; decision: [ADR-0006](ADR-0006-local-review-summary.md). Domain/UI/browser assertions must cover ordered blocker cardinality, unknown fallback, recommendation separation, contradiction ownership, hostile strings, unsafe URL non-disclosure, deterministic bytes, pending-import lock, complete workspace preservation and preparation/activation failure cleanup. [The local evidence record](evidence/mixed-agents-review-summary.md) preserves earlier bounded observations, completed local full-suite/browser successor evidence, and unresolved visual inspection, exact-head hosted and qualifying-approval gates. + +## Mobile import-feedback presentation candidate + +PRD `US-IMPORT-FEEDBACK-01` reuses the existing `.save-state` polite region. At `max-width: 720px`, hide only `.version` and present status as a full-width normal-flow wrapping row. Pending `JSON 초안 확인 중` and idle `브라우저 작업 중` are both intentionally visible; idle is not a save or ongoing-import claim. App text/state/DOM order, mobile title rule, strict restore and file formats retain their ownership. Busy stays on the authoring fieldset, never on the live region or its effective ancestors. Static SessionNotice stays non-live. + +Native acceptance binds the existing backend DOM identity to nonignored polite AX ownership and actual descendant text, not global text/attribute matches. Rendered line/clipping/viewport/nonoverlap and rail positioning are separate requirements; natural vertical scrolling is valid. Validate 320/390/720 mobile states and actual same-input predecessor/successor preservation at 721/820/1280. Valid, invalid JSON/schema, read rejection and oversize-before-read are distinct controls. Existing fieldset/import/TXT locks stay; rail/JSON export are not newly locked. Explicit native held-fixture timing is not natural latency or actual AT speech. [The dated evidence](evidence/mobile-import-feedback-20261005.md) separates current diagnostics/plan from repository TDD and pending final gates. No App/domain/storage/dependency/config/CI/legal-rule change is admitted. + +## Memory-only authoring notice + +PRD `US-SESSION-01` makes the existing memory-only contract visible before input. `src/App.tsx` renders shared `SessionNotice` as a normal paragraph immediately after the section heading in `FactStep`, `CollectionForm` and `PurposeForm`; the active editor contains exactly one notice across all seven steps. Copy: `자동 저장되지 않습니다. 새로고침하거나 탭을 닫으면 작성 내용이 사라집니다. 보관하려면 JSON 내보내기를 사용하세요.` It is neither a live announcement nor an alert/status/focus target. It does not introduce a global workspace row or change the workspace height calculation; mobile acceptance must prove readable, non-hidden normal-flow text at 320 px rather than rely on header metadata that existing CSS hides. + +Header and preview label `앱 버전 0.1.0` identifies the application only, independently of JSON `schema_version: 1` and TXT `report_format: v1`. The notice has no state or persistence authority. Existing pending-import fieldset/input locks and polite `JSON 초안 확인 중` / `브라우저 작업 중` feedback remain unchanged. Import success retains the existing validated replacement/step-1 transition; failures and export outcomes must not gain fact/readiness mutations or saved-state claims. Normalized JSON portability does not preserve every rejected, inactive or discarded raw value; TXT cannot restore a draft. No autosave, browser storage, beforeunload, network, dependency, schema or legal-rule change is admitted. + +`src/initial-workspace.test.tsx` traces version semantics, one notice per step, input ordering and static semantics; existing import/export regressions support preservation. Real-browser acceptance additionally requires notice persistence across editing/import/export outcomes, narrow-mobile readability and native download → reload-empty → explicit validated restore. The last journey characterizes existing behavior, not a new restore mechanism. [The dated evidence record](evidence/session-notice-20261005.md) distinguishes parent-reported bounded TDD from directly inspected source and pending successor gates; predecessor totals are not this candidate's passing certificate. + ## Local draft portability The JSON file is a draft portability artifact, not a publication receipt, immutable revision, legal approval, or persistence backup. It may be exported while incomplete so operators can inspect and transfer their authored work without converting blanks into `none`. The schema-v1 return path reconstructs facts from admitted fields and recomputes readiness/findings rather than trusting file claims. Invalid files leave current browser state unchanged; authoring is locked only for the bounded read/validation interval so accepted restore cannot discard edits made during that interval. Contract changes require a new schema version, explicit migration/loss behavior, and compatibility evidence; the current fixed filename avoids using customer-controlled text as a filesystem name. Preparation/activation-error recovery does not establish cancellation of an in-progress browser transfer. +## Canonical URL portability successor — 2026-10-05 candidate + +Historical checkpoint note: the 03:18 KST frozen-TXT/pending execution clauses below retain their original observation time. A separate 03:30 KST retained-source compilation compared eight previously admissible predecessor/candidate TXT outputs exactly equal; rejected-URL output intentionally changes and is not covered by that claim. The later [URL evidence](evidence/url-portability-20261005.md) records completed local verification and complete source review associated with published PR #26 head `1e662c2f08d4e156b9280ef434bc876c0c77b283`. Hosted execution/approval and release remain separate. The subsequent [mobile-title fullgate NONPASS and repair](evidence/mobile-document-title-20261005.md) require new candidate-bound acceptance, not reuse of those predecessor passes. + +`createPolicyExport` normalizes the service URL once and derives exported draft findings from a copy whose `serviceUrl` is that admitted URL or the empty sentinel for `null`. Live/raw `getDraftReview` remains unchanged: a nonblank rejected URL yields `service_url_format` for correction; canonical JSON after withholding it yields `service_url`, remains `incomplete`, and retains step-1 ownership. Neither download changes raw facts or completion. Withholding is not destination rewriting or preservation of rejected input provenance. + +`createPolicyReviewText` uses the same exported URL in the facts supplied to `formatReviewFinding`, so each canonical JSON code has exactly one TXT row in the same order and a withheld URL has the step-1 `서비스 URL` label. The public helper itself retains raw-facts behavior, including `service_url_format` lookup. Its `단계 미상` fallback preserves codes not resolvable against the supplied facts; it is not a canonical URL-label substitute and does not promise that arbitrary known-code/raw-fact mismatches are resolvable. Other findings, seven-step completion, recommendations and escaping retain their existing authority. + +The closed schema shape and `schema_version: 1`, TXT `report_format: v1`, importer validation and exact ordered-code/readiness recomputation comparison are unchanged. Old producer-inconsistent `service_url: null` + `service_url_format` files remain rejected, with no dual-code compatibility exception, trusted evidence, silent correction or migration. This producer-consistency repair clarifies the existing normalized-fact contract rather than adding a schema field/version; a future schema change still requires the version/migration/loss contract above. Blank/valid prior JSON/TXT bytes must remain unchanged; frozen predecessor-fixture verification was pending at the initial documentation checkpoint, not inferred from current-function repeat/round-trip equality. At 03:18 KST the parent reports actual retained-source blank/valid JSON fixture equality for both direct export and restore/re-export, and strict denial of the withheld fixture; frozen TXT comparison remains unverified. + +[The source-bounded successor evidence](evidence/url-portability-20261005.md) separates the frozen Layer1 RED, summary-fed conditional Layer2 reviews, parent-reported five-case GREEN and related 35-case/lint/build intermediate observations from pending current full/browser/whole-union review/hosted gates. Parent 03:18 KST successor reports 65 focused cases plus lint/build against the owned source/test freeze, still not full-suite acceptance. No UI, autosave, dependency, network or legal-source/rule change is part of this slice; PR #25 cancellation/stream and central workflow ownership remain separate. + +## Mobile document-title reflow candidate + +PRD `US-MOBILE-TITLE-01` changes only the mobile `.document-name` presentation rule at `max-width: 720px`. The existing service-name text and policy suffix remain a deterministic, non-interactive projection. A full-width normal-flow row can grow and wrap without input truncation or domain mutation; unchanged color/font/focus tokens and native file controls retain their ownership. + +Native acceptance requires exact input/text, nonempty positive text-line rectangles contained within the title box, scroll/client dimensions, horizontal viewport containment, visible sibling text and nonoverlap, and sensitivity to clipping, hidden-title and overlap counterexamples. Document-level zero overflow alone cannot prove a child title is readable. Use 320/390/720 px fixed cohorts, including default/short-name controls; compare unchanged default/short-name nonmobile geometry/style at 721/820/1280 px with the actual predecessor. Natural vertical scrolling is valid. Global extreme-name/preview behavior, screen-reader and blanket WCAG acceptance remain separate. [The evidence record](evidence/mobile-document-title-20261005.md) binds diagnostics, repository RED, minimal CSS GREEN, screenshots and final gates separately; a proposed test or CSS declaration is not passing execution evidence. No timeout/retry/skip/config/dependency/schema change is part of this candidate. + +## Screen-only preview text reflow candidate + +PRD `US-PREVIEW-REFLOW-01` adds a bounded reading-width convenience contract, not recovery of lost facts. Existing preview horizontal scroll is a verified access path. The selected stylesheet addition uses `@media screen` and one `overflow-wrap: anywhere` declaration shared by `.paper > h2`, `.paper > p`, `.paper th` and `.paper td`; the narrower selector's effect requires actual repository RED/GREEN. Existing warning span/b/button, fixed clause h3, header/status and print-media styles are outside the new rule. No white-space, table-layout, App/domain or format change is admitted. + +Acceptance measures positive text fragments against cell content bounds, table against paper content bounds and preview-local horizontal bounds. Below-fold text and natural vertical scrolling are valid; distinguish actual document/preview owners from hidden/clip ancestry. Default/short paired geometry and fixed ASCII cases span 320/390/720/721/820/1280/1440, with representative Korean/mixed cases at 320/820. Exact text/suffix, catalog/row identity, mounted raw controls, warnings/focus, seven responsibilities and canonical native JSON/TXT bytes must be preserved. Print emulation is not physical printing or pagination acceptance; no new AT/print/WCAG claim follows. [Dated evidence](evidence/preview-text-reflow-20261005.md) preserves diagnostic positives and setup failures separately from pending current repository/full-source/hosted gates. Existing dependency/configuration/test budgets and other-owner contracts stay unchanged. + ## Hosted persistence/publication entry criteria Before network persistence lands, define a versioned policy-data schema, migration policy, 3NF relational model, per-item UPSERT/idempotency rules, immutable publication receipt, supersession/rollback semantics, tenant/purpose authorization, audit evidence, encryption/key management, retention/deletion behavior, and backup/restore testing. Use two-or-more-word semantic persistence object names in `snake_case` by default. The revision model must preserve explicit no-collection and explicit retention status independently; `none` must not be materialized from collection absence, and an inapplicable/non-retained state must not carry a live `retention_rule` value. diff --git a/docs/evidence/mixed-agents-review-summary.md b/docs/evidence/mixed-agents-review-summary.md new file mode 100644 index 0000000..06f690b --- /dev/null +++ b/docs/evidence/mixed-agents-review-summary.md @@ -0,0 +1,79 @@ +# Local minimal review summary — layered-agent and evidence record + +Date: 2026-10-03 (KST). Repository: PolicyWeave. Candidate base: `60fd7fb`; branch: `feat-mixed-agents-prd`. This record describes a branch-local development decision and bounded observations, not a release, hosted approval or final-head passing certificate. + +## Methodology source + +The verified primary source is Wang, J., Wang, J., Athiwaratkun, B., Zhang, C., & Zou, J. (2024, June 7), *Mixture-of-Agents Enhances Large Language Model Capabilities*, arXiv:2406.04692v1, DOI `10.48550/arXiv.2406.04692`; arXiv metadata/abstract retrieved 2026-10-03. Its layered pattern passes prior-layer agent outputs to the next layer as auxiliary information.[1] The source is methodology metadata only: no benchmark score, performance benefit or reproduction claim is adopted for PolicyWeave. + +This task used a **MoA-inspired development workflow**: independent proposals → both reviewers receive prior proposals plus the parent aggregate → final parent aggregation. It was not merely two parallel implementation assignments. Role independence is not verified model heterogeneity; it is not a runtime product-AI feature. + +## Local receipt chain + +These local receipts were inspected for manifest status and task/log metadata. They are execution-provenance pointers, not portable CI artifacts or qualifying GitHub approvals. Do not copy raw transcripts into the repository: they can contain private local context. Only bounded summaries and identifiers are recorded here. + +| Stage | Local receipt | Observed decision/input | +| --- | --- | --- | +| Layer 1, independent proposals | `~/.hermes/cache/delegation/live/deleg_6398a30f/manifest.json`, `task-0.log`, `task-1.log`; two tasks completed | Product: whole-plan full-facts Markdown with seven-step facts/findings/version. Technical: whole-plan minimal TXT with canonical readiness/identity and no detailed operational/contact values. Both were read-only proposal tasks. | +| Layer 2, cross-review | `~/.hermes/cache/delegation/live/deleg_2296ff9a/manifest.json`, `task-0.log`, `task-1.log`; two tasks completed | Both kickoff contexts supplied both Layer-1 plans plus parent integrated TXT plan. Both returned conditional acceptance with output-encoding, cardinality/ownership, failure/lifetime and state-preservation controls rather than unconditional implementation approval. | +| Parent aggregation | This bounded decision record and [ADR-0006](../ADR-0006-local-review-summary.md) | Minimal TXT selected; full-facts Markdown deferred; all P1 conditions retained as implementation/test contracts. Parent synthesis is not an additional independent approval receipt. | + +Both inspected manifests have `model: null` and `provider: null`. Delegation used same/inherited model configuration; returned metadata does not establish distinct resolved model identities. **Heterogeneous model/provider execution is unverified.** Do not describe role-separated fanout as a verified mixed-model ensemble, claim the paper's benchmark benefits, or count model review as protected-branch independent approval. + +## Aggregated controls and implementation trace + +| Control from cross-review | Contract/trace | Acceptance boundary | +| --- | --- | --- | +| TXT minimum rather than full-facts duplication | `createPolicyReviewText`, PRD `US-REVIEW-01`, ADR-0006 | Identity, state, seven-step status, codes/labels and recommendations only; detailed path/purpose/contact/retention/recipient/country values omitted. Identity remains disclosure-bearing. | +| Every exported blocker has one row in order | `createPolicyExport(...).review_finding_codes` → `formatReviewFinding` | No filtering/deduplication; quoted unknown-code `단계 미상` fallback; count must equal row cardinality. | +| Preserve code ownership and contradiction semantics | `getDraftReview`, collection-code mapping, `getCompletedSteps` | Collection mode/path map to step 2, purpose to step 3; collection contradiction keeps both steps incomplete. | +| Visible control escaping, not plain stringify alone | TXT quoting boundary and hostile-string domain assertions | JSON quoting plus C1/Unicode line/paragraph/bidi escaping for all dynamic strings, including labels/codes/unknown fallback. No HTML/Markdown-safety claim. | +| Do not leak invalid raw URL | Canonical `createPolicyExport` service profile | Credentials/query/fragment stay withheld; error feedback does not include exception/raw fact text. | +| Bounded browser lifetime/failures | `DocumentPreview`, `exportReview`, UI/browser contracts | Fixed filename/MIME; import disable plus handler guard; Blob/URL/anchor/click exception containment; next-task reclamation after successful allocation on success or activation failure. | +| Preserve the complete workspace | Pure domain projection; download feedback only | Facts/items/attestations/current step/readiness/completion unchanged after success/failure; no automatic save or hidden restore. | +| Honest version and success wording | `report_format: v1`, `schema_version: 1`, initiated-download feedback | No timestamp/nonce/publication version; initiation is not completed storage, legal review, approval, persistence or publication. | + +No new network, renderer dependency, legal source/rule or hosted product runtime was introduced by this choice. The historic source/legal/gap ledger is preserved and not promoted to current-head evidence. + +## Earlier documentation-slice observations — historical local status + +This documentation slice directly inspected the implementation/test source and the two proposal-layer manifests/log metadata. It did not run the parent's feature suite or remote GitHub gates. The following test/toolchain observations were supplied by the parent handoff and are labeled as bounded reports, not independently re-executed results: + +- Initial domain RED: the focused test failed because `createPolicyReviewText` did not exist. An initial focused GREEN was then reported. It does not certify the later expanded domain matrix or final tree. +- Initial UI RED: the download button was absent. An initial focused UI pass was reported; a later local run timed out. Timeout is **unknown**, not PASS, and no full-suite count is asserted. +- The first `npm ci` installed production dependencies only; a later development install stalled. The parent copied identical-lock-version dependencies from an existing sibling tree into this owned local tree via `ditto`, and the local UI harness needed `NODE_ENV=test`. This is a task-specific executor caveat, not a universal README setup requirement or clean-install attestation; no dependency/workflow edit is authorized by it. + +| Gate | Status at the earlier documentation slice | Needed evidence | +| --- | --- | --- | +| Expanded current-tree domain/UI regressions | Unverified here; assertion source is not a runner receipt | Actual completed output bound to final candidate source/test tree, including hostile controls, fallback/cardinality, unsupported statuses, unsafe URLs and full-state preservation | +| Full lint/test/build | Pending/unverified | Completed real commands on the final candidate; no fabricated totals or timeout-as-pass | +| Native-browser TXT workflow | Forthcoming/pending | Real download events/bytes/MIME, repeated bytes, activation modes, import lock and failure cleanup; jsdom is supporting evidence only | +| Exact-head hosted verification/security | Unverified | Fresh source/head/base/checkout/run/artifact identity and terminal required checks; no stale, cancelled, skipped or predecessor receipt | +| Independent approval/resolved threads | Unresolved | Qualifying current approval and zero unresolved required threads under live protections; no administrative bypass | +| Issue #12 dependency review | Unresolved, parent reports HTTP 403 | Canonical owner-side repair/terminal workflow and distribution/license acceptance; summary feature does not close the issue | +| Hosted publication/release | Not implemented/claimed | Separate security, immutable review/publication and release contracts; TXT is not publication | + +Docs-slice execution on the local working tree: `git diff --check` completed without whitespace errors; `node --test tests/local_preview_contract.mjs` passed its six existing documentation/local-preview configuration contracts; relative-link checking found no missing targets across the ten owned documentation files; strict citation-ledger verification accepted the methodology source reference. These are bounded documentation/configuration checks, not feature-suite, browser, hosted CI or approval evidence. + +Parent-reported remote observations: Draft PR #1 at `60fd7fb5c3177984a993102742bb16e36a909e2d`; separate Draft PR #25 at `af8c0da17cdfb4786867f4e85401dbbb811b581e`, owning import cancellation/stream work. This feature does not duplicate that work. No workflow-run cancellation was performed or requested. These observations require fresh live inspection before commit/push/integration. This docs task performs no commit or push. + +## Parent-executed successor verification + +The following supersedes the pending **local execution** observations above, not hosted or approval gates. The parent executed these commands on the current uncommitted candidate and will bind final file hashes in a separate local verification receipt: + +- Full Vitest: 193/193 across 18 files, exit 0, with `NODE_ENV=test`, Node 26.7.0 and one worker. This includes 11 report-domain and seven report-UI cases. +- ESLint: exit 0. Existing documentation/local-preview contracts: 6/6, exit 0. Production TypeScript/Vite build: exit 0. +- New browser journey: initial desktop/tablet/mobile runs failed the 48 px touch-height assertion (actual 38 px); `.review-download` was repaired to 48 px. The same three cases then passed on rebuilt product bytes. +- Full Playwright: 39 collected, 27 passed, 12 existing profile-scoped skips, exit 0. This is not 39 executed passes or a full accessibility audit. +- The initial TS2571 in the test's anchor instance access was corrected with an explicit `HTMLAnchorElement` cast; the failed build was not cleared by the succeeding lint command's exit 0. +- Visual screenshot inspection remains unresolved: the first analysis call ended with an upstream stream error and the second with a quota 429. Screenshots exist; DOM/touch/no-overflow checks do not replace their visual inspection. + +Exact-current-head hosted checks, qualifying approval, protected integration, clean-install acceptance, legal/distribution obligations and publication remain unresolved. Independent whole-delta local review subsequently found no blocking security or logic defect and independently repeated 193 unit/UI, lint/build, six pretest and three new browser passes against byte-matching source. It suggested documentation-status reconciliation and stronger handler/native-browser instrumentation. This is not a counted GitHub approval. + +## Successor boundary verification + +[The 2026-10-04 successor](review-summary-successor-20261004.md) records clean-install recovery, another actual proposal/cross-review layer, native browser boundary coverage and independent handler-guard mutation evidence. Original failures and prior totals above remain historical; they are not replaced with successor results. + +## Sources + +[1] https://arxiv.org/abs/2406.04692 — *Mixture-of-Agents Enhances Large Language Model Capabilities*; primary arXiv metadata/abstract, retrieved 2026-10-03. diff --git a/docs/evidence/mobile-document-title-20261005.md b/docs/evidence/mobile-document-title-20261005.md new file mode 100644 index 0000000..4733e9e --- /dev/null +++ b/docs/evidence/mobile-document-title-20261005.md @@ -0,0 +1,91 @@ +# Mobile document-title reflow — 2026-10-05 candidate + +## Scope and current baseline + +PRD `US-MOBILE-TITLE-01` selects one mobile presentation defect against published PR #26 head `1e662c2f08d4e156b9280ef434bc876c0c77b283`, based on `develop@60fd7fb5c3177984a993102742bb16e36a909e2d`. `App.tsx` renders the exact service-name input (or existing default) plus `개인정보처리방침`; the mobile stylesheet limits that text to 190 px with `overflow:hidden; white-space:nowrap`. The proposed repair changes only that mobile title rule, not input values, DOM order, projection authority, seven steps, focus, import/download, schema, dependencies, workflows or persistence. Existing ADR-0005/0006 decisions remain unchanged; no new legal rule or source verification is introduced. + +At the 05:28 KST parent admission, all thirteen frozen source/config/spec hashes still matched the published baseline and the worktree was clean. The owned loopback preview served a fresh parent build at `127.0.0.1:4173`, process `proc_463b978170af`; independent observations verified HTTP 200 and JS/CSS identity. Later documentation additions are parent-owned and do not constitute production repair or a final execution gate. + +## Layer1 actual browser diagnostics + +`deleg_e21285ca` obtained two independent whole proposals without sharing either with the other. Both used installed Playwright Chromium against the current build at 320/390 px with synthetic service names only: + +| Observation | Proposal A | Proposal B | +| --- | --- | --- | +| Default title | Two containment controls pass | Two containment controls pass | +| Long name | Mixed Korean/ASCII fixture: 190 px visible box vs about 586 px rendered text, two failing containment observations | Unspaced ASCII fixture: 190 px visible box vs about 653 px rendered text, two failing containment observations | +| Document horizontal overflow | Zero despite title clipping | Zero despite title clipping | +| Diagnostic exit | Zero because script collects failing observations | One from intended failed containment assertions, not setup/timeout | +| Other controls | Rail has intentional horizontal scroll; access failure unmeasured | One 320 px URL-warning Enter-to-heading path passes; not all warnings/AT | + +The four title rows in B's retained packet are accompanied by a separate keyboard-control row; total row count five is not five title cases. No repository regression RED, product GREEN or full suite was executed by these proposal agents. Initial unavailable-server reads remain setup observations, not product failures. + +A parent screenshot inspection of actual B `320-long.png` sees the truncated `SyntheticMobileDocume` and no policy suffix, while both JSON control labels are readable. The full original string and clipping cause come from the actual input/text/geometry packet, not the screenshot alone. These observations do not establish blanket accessibility, all rail navigation or nonmobile long-name acceptance. + +Parent retained thirteen Layer1 files (A six, B seven) and verified copied byte hashes in the local report root. Two retention-helper errors remain excluded evidence: an early copy-loop checked B before copying it, and a later count assertion assumed four total B rows rather than four title rows plus keyboard control. The latter shell's final diff-check masked its failed Python exit; corrected categorized retention used explicit success chaining. These were evidence-retention harness failures, not browser/product regressions or a reason to rerun the already completed observations. + +## Full-proposal cross-review and parent aggregation + +`deleg_5bb51706` supplied EACH Layer2 reviewer BOTH FULL prior proposal texts. Each reviewer explicitly reported reading them and relevant source/tests; both conditionally accepted the same title-only mobile wrapping plan. This differs from the summary-fed historical session/URL layers: full-text transfer is evidenced here, while same/inherited models still do not prove heterogeneous-provider execution, benchmark benefits or runtime product AI. + +Parent aggregate selects a full-width normal-flow title row inside `max-width:720px`, preserving exact text/suffix with wrapping and horizontal containment. `max-width:100%` is preferred to unrestricted width; properties must be confirmed by actual rendered geometry, not accepted by declaration. Header height can grow and natural vertical scrolling remains valid. Name length restrictions, raw-value truncation/normalization, hidden suffix, title/ellipsis alone, global overflow hiding, rail/preview/focus redesign and added disclosure controls are rejected for this slice. + +The new native oracle must combine exact input/text, nonempty positive text-line rectangles, per-line title-box containment, scroll/client dimensions, horizontal viewport containment, visible sibling text and pairwise nonoverlap. Otherwise-valid old-width/nowrap clipping, fixed-height clipping, hidden title and sibling-overlap controls must prove sensitivity without replacing intended failure reasons. Hidden file-input and child-icon geometry are not sibling-overlap targets. Same-input measurement/navigation preservation must not incorrectly require unchanged findings after entering a new valid service name. + +## Implementation and verification handoff — pending + +Sole writer `deleg_15fd1d56` owns ONLY the existing mobile `.document-name` rule in `src/styles.css` and new `tests/e2e/mobile-document-title.spec.ts`. First obtain an actual repository containment assertion RED against untouched CSS; only then perform the minimal repair and rerun the same assertion. Existing ordinary case/assertion deadlines, retries and skips stay unchanged. The parent owns documentation, final gates and publication; no child server restart, commit or push is authorized. + +Fixed cohorts cover 320/390/720 px default/short/long Korean, mixed and unspaced ASCII names; actual predecessor/successor default/short-name geometry/style at 721/820/1280 px forms the nonmobile preservation boundary. Nonmobile extreme names and preview reflow remain separate gaps rather than being hidden or falsely claimed solved. + +At this dated documentation checkpoint, repository RED/GREEN, sensitivity controls, nonmobile comparison, final screenshots, current complete unit/lint/build/native-browser run and whole-candidate source review are **pending**. The previous published URL slice's passing local receipts cannot certify these new bytes. `npm test` includes local-preview pretests; direct Vitest alone is not the complete gate. Final configured browser execution must use a fresh build and settled server ownership; profile skips, flaky/timeout runs and producer errors must remain separately disclosed. No new standalone-contract automatic npm/CI integration is asserted. + +## Settled implementation handoff — 2026-10-05 05:43 KST + +The sole writer completed repository TDD before production change: untouched CSS produced two intended B-fixture failures at 320/390 px, exit 1, with `document-name:line-containment`, `horizontal-viewport` and `scroll-width`; default controls passed and no setup/timeout error was reported. The only production change replaces the mobile title rule with `display:block; flex-basis:100%; min-width:0; max-width:100%; white-space:normal; overflow-wrap:anywhere; overflow:visible`. Parent independently compared the full CSS against its published predecessor and found all other bytes unchanged. + +The same initial two tests then passed (5.1 seconds). The settled expanded spec passed nineteen cases (40.5 seconds), exit 0, no skips, against the existing owned preview with CI unset. Fixed mixed/short-Korean/long-Korean cohorts at 320/390/720, B at 720 and same-input navigation/URL-warning keyboard return were included. Fixture-owned sensitivity controls separately required the causal `line-containment`, `scroll-height`, `invisible` and `overlap:document-name:status` fields; exact inline styles and the baseline measurement were restored between them. These intended-negative controls are oracle evidence, not extra product REDs. Focused lint and explicit Node/DOM TypeScript checks exited 0. + +Actual independent before/after native observations at 721/820/1280 px with default/short names compare six whole-header geometry/style rows exactly equal. The permanent spec's injected legacy mobile rule is supporting media-scope isolation evidence, not by itself an actual predecessor build comparison. Neither observation asserts nonmobile horizontal-fit or extreme-name acceptance. + +Settled SHA-256: CSS `c98107ae06987c784fb0daa547728228d42dca7a77cbe451b32b07b202eb7aa6`; new browser spec `7de891c7f359e20e3c8624fda3dc201247b7453fb68d201a9b3ecbe59822195b`. Parent verified these hashes and all four actual causal-field packets, retained 177 evidence files with hash equality and all 43 screenshots. The parent npm-test gate separately completed six pretests and 230 unit/UI cases across nineteen files, exit 0; selected src/manifest/config hashes matched before/after and still match the settled candidate. This does not yet certify the complete browser candidate. + +Parent inspected the actual settled 320 px B-title screenshot: every service-name character and the policy suffix are visible over wrapped lines, with readable, nonoverlapping status/import/export text. The single-line service-name input scrolls its long value and is not claimed to show the entire value simultaneously. Visual evidence is bounded to the inspected capture, not all screenshots or AT acceptance. After writer settlement, the parent stopped only its owned preview and confirmed port release by a successful strict 4173 bind. The next fresh configured CI=1 full browser gate and complete independent source review are pending; earlier pending checkpoints above remain dated history. + +## Complete candidate NONPASS and observer RCA — 2026-10-05 06:06–06:14 KST + +The parent chain `proc_814d127267d0` completed **exit 1**, not acceptance: standalone snapshot checks 78 passed, handler guard positive/intended-negative checks passed, lint/build passed, then all 156 configured browser cases reconciled to 141 first-pass passes, one terminal failure, two flaky cases that passed on configured retry, and twelve existing profile-scoped skips (17.0 minutes). The terminal failure was the mobile known-collection URL native round trip; the desktop/mobile no-collection URL cases were flaky. No timeout, retry policy or skip was changed. All 36 launch-source hashes still matched at exit; strict port 4173 bind confirmed server release. Parent retained a hash inventory of 965 actual browser artifacts in `mobile-title-fullgate-nonpass.json`. These totals must not be combined with the focused nineteen-case receipt into a passing full gate. + +Independent complete source review `deleg_b72f0947` read all 36 base-to-worktree paths and returned no blocking security/logic finding. Parent verified the exact complete inventory digest `2f507554eb60837beb9ada4fc9563c481bfe3b138adcdbabcc6d3d985a2af5b3`. This source verdict does not clear runtime NONPASS. Its nonblocking suggestions are retained: the permanent title suite lacks an explicit empty/default-name 720 px assertion (320/390 defaults and 721 nonmobile default are covered), and some older canonical status summaries should be labeled historical checkpoints. No missing cohort is claimed executed. This additive evidence section changes the documentation snapshot after that source review; earlier approval is not automatically transferred to unread bytes. + +Read-only RCA `deleg_afc4a0ad` inspected three retained traces and verified their embedded URL spec matched the unchanged source. The 30-second timeout precedes the final native-file-text assertion. After timeout, teardown restored native descriptors while some body work continued: known retry import began at 31.022 seconds after restoration at 30.160 seconds, and no-collection import began at 32.105 seconds after restoration at 30.490 seconds. Times are relative to each browser fixture's return, not the exact test-body start. Actual native calls after restoration were no longer observed; the audit arrays themselves were not deleted. Initial known import preceded teardown and retained one file-text event, but its case was still timed out. Thus empty late file-text/create/click/revoke observations do not establish absent native operations or valid observed download evidence. + +Parent independently verified the original and both restored JSON files in four failed trace folders: all present re-exports were byte-identical to their actual originals and retained canonical `service_url` evidence. The RCA separately verified nine files against receipts. These completed bytes do not clear the timing failure. CPU/host contention, CSS influence and the underlying reason for time exhaustion remain unproved. The measured four seven-step survey spans sum to approximately 11.688/13.178/12.552 seconds in the three inspected runs, making reduced read-only observation round trips a testable efficiency candidate, not a proven environmental diagnosis. + +Sole successor writer `deleg_da991152` owns only URL-spec helper/lifecycle definitions and a new standalone observation contract. It must first reproduce post-restoration false admission with active positive controls, preserve native descriptor cleanup and reject inactive audit evidence, then separately demonstrate native-equivalent seven-step raw-control observations before reducing their round trips. All original test bodies, native saved-file paths/bytes, step ownership, assertions, ordinary deadlines and production/mobile-title code remain unchanged. No blind rerun or earlier source-PASS transfer is admitted. The new contract is not automatically part of npm test/CI. Repair, renewed focused/full execution and fresh whole-candidate review remain pending. + +Parent additionally inspected retained focused 390 px ASCII and 320 px Korean title screenshots; together with the prior 320 px ASCII capture, all three show readable complete title/suffix and nonoverlapping status/JSON labels. These limited visual observations do not repair the URL fullgate failure or establish all-screen/AT conformance. + +## Guard-only successor settlement — 2026-10-05 06:27 KST + +Writer `deleg_da991152` settled only explicit observer-lifetime admission and the source-bound standalone contract. The corrected actual Chromium RED against the predecessor helper failed with `Missing expected rejection` in post-restore, held-read cleanup and pagehide controls, while active native read/download and receiver controls passed. The repaired helper then passed five controls (six Node tests including the parent), exit 0, no skips/cancellation; its owned context/browser closed. Earlier invalid-receiver harness timeout and the initial TypeScript config refusal remain excluded, retained setup errors rather than behavioral RED. Focused lint/syntax/corrected TypeScript checks completed exit 0. + +Settled URL spec SHA-256 is `8eb9c4249dfa01f677974321ece2495522c4e7bf1458c238563917644f78ba1b`; standalone contract is `d810061864b430df4f827e42327ae7866fbf773c689d9e31c8488bffbecf8cc3`. Parent verified both, retained 23 actual helper artifacts with byte hashes and independently confirmed the entire original URL test-body suffix remained identical (`85bbd16ef5173e3e4c92329c4c214878a3f5ce14f5d27e1e2d7c78877bfcb630`). Native download/seed/survey/step semantics and original polling limits remain unchanged. The standalone contract is not in npm test/CI. + +**Survey batching was not implemented or verified; cost-comparison controls executed: zero.** Guard GREEN rejects inactive evidence but does not prove completion inside the case deadline. Parent started a fresh successor command with the actual standalone contract, lint/build and all eighteen native URL cases across configured profiles (`proc_1e96ad6b9ea8`), with ordinary deadlines/retries and fresh server ownership. Its result and renewed final whole-candidate acceptance remain pending. The prior fullgate NONPASS, all original failure evidence and source-review snapshot remain preserved rather than overwritten. + +## Completed successor local acceptance — 2026-10-05 06:44 KST + +The guard-only focused parent command `proc_1e96ad6b9ea8` completed exit 0: five actual Chromium helper controls (six Node tests including parent), lint/build and all eighteen native URL cases passed (3.6 minutes), with no skips/failures/flaky/retries reported. All 37 frozen candidate hashes matched at completion; strict port 4173 bind confirmed release and the parent retained 304 actual artifact hashes. The new standalone observation contract remains outside npm test/CI. + +The subsequent fresh-build configured whole-browser command `proc_310dd730ad3f` also completed **exit 0**. Its 156 collected cases reconcile to **144 passed plus twelve existing profile-scoped skips**, no terminal failure, flaky result or retry reported (8.7 minutes). No case/assertion budget, retry policy or scoped skip changed. Parent verified all 37 frozen candidate hashes and the selected source hashes from the six-pretest/230-unit gate, confirmed port release with a strict bind, and retained 895 actual browser-file hashes. These artifact counts are not case counts or hosted uploads. Earlier standalone snapshot 78-check and handler guard positive/intended-negative receipts remain bound to unchanged sources; they are not silently added to npm/CI discovery. + +Fresh independent whole-source reviewer `deleg_4ccc1722` read all 37 changed paths, returned no blocking security/logic finding, and matched the complete parent-verified inventory digest `a3b16d8bdcf5a52ab063bbea6bb5a1bb336da6236b2a0f365af9a23052ade31e`. Its nonblocking limits remain: the title spec has no explicit empty/default-name case at 720 px, and the standalone contract does not prove cleanup across context-creation/route-setup or context-close failure. Those paths are not claimed verified. The native exact-base reconstruction confirmed all 81 regular repository-file bytes with the live index unchanged. This additive terminal section requires a separate bounded documentation recheck; the earlier reviewer cannot approve unseen bytes. + +All earlier fullgate NONPASS, retries, setup errors, rejected observation states and source-review checkpoints above remain retained history. Guard-only integrity repair plus a successful successor run does **not** identify the underlying cause of earlier time exhaustion or establish universal timing stability. Survey batching and cost-comparison controls remain unimplemented/unexecuted. Local source/runtime acceptance is not a qualifying GitHub approval, current hosted PASS, protected merge, publication or release. At this terminal documentation handoff the successor is still uncommitted and unpushed; those external transitions require fresh remote-parent verification and actual readback. + +## Ownership and release limits + +PR #25 continues to own import stream/cancellation; central `.github` PR #2565 owns Runner migration. Current exact-head PR #26 `verify` failed before test execution with the observed billing-lock annotation; Issue #12 remains open for authoritative Dependency Review and protected integration evidence. Local execution/review cannot substitute for actual current hosted checks, qualifying GitHub approval, resolved threads, ordinary protected integration or release. No merge, ready toggle, workflow rerun, issue closure, storage, legal sufficiency or universal WCAG/AT acceptance is claimed. + +Local parent receipts/proposals/byte inventories are in `/`, a placeholder for the historical owner-local location, not a public link or new execution record: `loop28-next-slice-baseline.json`, `mobile-title-layer1-a.md`, `mobile-title-layer1-evidence/binding.json`, and `mobile-title-parent-aggregate.md`. These are local evidence, not hosted uploads. diff --git a/docs/evidence/mobile-import-feedback-20261005.md b/docs/evidence/mobile-import-feedback-20261005.md new file mode 100644 index 0000000..ad9ba74 --- /dev/null +++ b/docs/evidence/mobile-import-feedback-20261005.md @@ -0,0 +1,54 @@ +# Mobile import feedback — 2026-10-05 candidate + +## Scope and current acceptance state + +Published baseline: PR #26 head `a51669c91f579f94019ae1714554eb74db5a9366`. PRD `US-IMPORT-FEEDBACK-01` selects one presentation defect: the existing polite `.save-state` region is hidden at mobile widths by `display: none`, while the existing import/authoring lock works. The candidate is limited to the mobile stylesheet and a new native-browser regression. No App/domain, file format, readiness, persistence, dependency, CI or legal-rule change is admitted. + +This checkpoint records inspected baseline diagnostics and a selected plan, **not completed repository TDD or implementation acceptance**. The assigned writer must first reproduce an intended failure with native pending prerequisites established, then repair CSS and pass the same oracle. Current full-suite, visual, whole-source-review, exact-head hosted and qualifying-approval gates remain separate and incomplete. Historical failures and predecessor receipts are not overwritten by a later focused pass. + +## Layered investigation and decision + +- Layer1 `deleg_13b81e43`: two independent full proposals, each grounded in native saved-file import probes. A measured 320/390 px; B measured 320/390/820 px. Mobile pending text was hidden with a zero-size box, no rendered text rectangles and no nonignored pending AX text; B's 820 px control exposed it. Busy/disabled prerequisites and subsequent release worked. Five saved/re-export pairs were byte-equal within their own journeys. A's 927-byte fixture and B's 914-byte fixture differ and are not cross-fixture equality claims. +- Parent retained 21 artifacts in the task report's `import-feedback-layer1-evidence/` directory and inspected B's 320 px screenshot. That image establishes absence of visible pending copy, not input semantics, AX relationships or actual assistive-technology speech. +- Layer2 `deleg_4d2d5f46`: each reviewer read **both full proposals** and current source. Both conditionally accepted reuse of the existing region, subject to geometry, live-owner AX identity, native failure controls and preservation gates. Conditional plan agreement is not implementation approval. +- Parent aggregate: reduce the mobile hidden selector to `.version`; retain existing `.save-state` flex display and give it a full-width normal-flow wrapping row with zero minimum width/left margin, bounded width and ordinary wrapping. Preserve the existing title rule, App state/text/DOM order and polite region. Idle `브라우저 작업 중` becomes visible intentionally; it means neither saved work nor a continuing import. + +Roles and transferred full texts are evidenced; heterogeneous model/provider identity is not verified. This is a development workflow, not runtime product AI, a benchmark result or qualifying GitHub approval. + +## Required native acceptance + +The 320/390 px tracer must use a real download, actual saved path, explicit selection and an exact-name one-shot held native `File.text` result. The hold changes result-delivery timing/Promise identity for that fixture; it does not measure natural read latency. Unrelated calls retain native receiver/arguments/results. Settle held work and restore original descriptors in cleanup, including inherited lookup when removing an own-property shadow. Observation must remain active when evidence is admitted; post-cleanup empty logs are not evidence of no read or storage. + +Before visual/AX assertions, establish native pending read, busy fieldset and disabled import/authoring/TXT controls. Rail and JSON export are not newly locked. Measure nonempty positive text-line rectangles, effective visibility/clipping, horizontal containment, visible sibling nonoverlap and rail below the header; natural vertical scrolling is allowed. Bind AX to the existing region's backend DOM identity and follow actual child paths to current text, including ignored-node flattening. Require nonignored polite live ownership without effective busy ancestry. Global string matches or DOM attributes alone do not prove exposure. Static SessionNotice stays non-live and outside that ownership. + +Cover valid native release and byte-equal re-export, invalid JSON/schema preservation, explicit read rejection and files larger than 1 MiB rejected before read (zero read calls; no forced pending duration). Capture preservation baselines after test inputs are entered; compare mounted raw controls/current step/preview/ordered findings/readiness separately from normalized JSON. Success intentionally replaces validated facts and returns to step 1; expected error feedback changes on failure. Check 720 px mobile idle/pending/default/long-title states and compare actual predecessor/successor default/short-name geometry and style at 721/820/1280 px. Causal counterexamples must reject hidden/clipped/overlapping/empty text, incorrect AX text and busy ancestry without changing otherwise-valid prerequisites. + +## Boundaries and remaining gates + +Repository-discovered browser tests must keep the ordinary 30-second case and 5-second assertion budgets, existing retries/skips/configuration and dependencies. No new cancellation, timeout, footer alert, duplicate live region or state owner is part of this repair. Current lint, unit/pretests, build, existing standalone observer/guard contracts, configured native suite, source-bound artifact verification, screenshot inspection and independent whole-candidate review are required before publication claims. + +Actual VoiceOver speech, human OS chooser use, natural file-read performance and blanket WCAG conformance are not established by Chromium AX/geometry. PR #25 import-stream/cancellation ownership, Issue #12, centralized Runner migration, hosted execution, protected integration and release remain separate. No hosted persistence or legal-source revalidation is implied. + +## Settled focused checkpoint — 2026-10-05 07:26–07:29 KST + +Implementation writer `deleg_ae3d0819` has stopped editing. Parent verified `src/styles.css` SHA-256 `278b2588e369523b49476e47449cc9ad5587c48d156b6fa8b34ec988b3ff71bf` and new `tests/e2e/import-feedback.spec.ts` SHA-256 `b2629de02fd245a845a310a5afa030ac68154ef8c6cfe9b8b4249e6e2b1ea039`. Reversing exactly the admitted hide/status-row replacement reproduces the baseline CSS bytes; the existing mobile title rule and all other CSS are unchanged. App/domain/configuration/dependencies were not edited. + +Parent read actual retained logs: official unchanged-CSS 320/390 pending cases failed only the visual/AX oracle with `hidden`, `empty-line`, `wrong-AX`; three nonmobile controls passed. The same initial five-case spec passed after minimum CSS and a successful build. Expanded first run retained 13 passes and one failed busy-ancestor sensitivity: CDP emitted numeric `1`, which the observer initially treated only as boolean true. The final observer recognizes true/1/'true'; the final focused desktop-Chromium lane passed all 15 cases in 1.5 minutes, with focused ESLint and strict TypeScript exits 0 reported in the settled manifest. This is not full configured-browser acceptance. + +Parent retained and hash-verified 301 evidence files, including 31 screenshots, and independently compared nine native byte pairs: three saved/re-export journeys and six previous/preserved failure journeys. An initial parent verifier wrongly grouped the saved import fixture with the distinct current-workspace file and exited 1; only pair selection was corrected, without source/artifact changes. Six nonmobile idle/pending captured visual-data pairs at 721/820/1280 are reported identical, not a comparison of every computed style. Descriptor restoration is reported exact in 14 receipts. Normal current status AX text occurs once under the bound polite owner without busy ancestry. Parent inspected the actual 320 px pending capture: status, title and JSON controls are readable/nonoverlapping; rail begins below the header. Intentional horizontally scrolling rail edges are not a newly proven defect. + +The unit run under inherited `NODE_ENV=production` exited 1 with 192 passes and 38 UI setup failures (`React.act is not a function`). The same sources under process-local `NODE_ENV=test` passed six pretests and all 230 unit/UI cases in 19 files; parent verified actual log and all 26 source hashes unchanged. The original environment failure remains retained and is not product RED. No production or dependency repair was required. + +Remaining evidence limits are explicit: new raw-control snapshots observe mounted step 4 only, not unmounted seven-step values; existing broader regressions must complement them. Pagehide is a dispatched lifecycle-event control, not destroyed-frame/navigation acceptance. AX-hidden sensitivity is not an independently wrong exposed-text probe. Unrelated native Promise/throw/argument identity and a second one-shot read were not independently exercised. The 720 normal case uses a short current name, not a separate empty/default cohort. Additional boundary cases are existing-behavior first-GREEN characterizations, not extra production REDs. Required acceptance above is retained; these limits are not silently promoted to completed coverage. Current complete native suite, whole-source review, hosted execution/approval and release remain incomplete. + +## Terminal local acceptance — 2026-10-05 07:43 KST + +Parent completed source-bound verification before this additive documentation update. `npm test` under process-local `NODE_ENV=test` passed six pretests and all 230 unit/UI cases in 19 files. The final gate `proc_99073e5a8fd1` exited 0: existing standalone snapshot/URL-observation/summary-handler contracts, repository lint, fresh production build and configured `CI=1` browser suite all exited 0. Browser collection was 201 cases: **189 passed and 12 existing profile-scoped skips**, 8.2 minutes, with no failure/flaky/retry reported. Existing case/assertion budgets, retry policy, skips, dependencies and configuration were unchanged. Standalone contracts were executed explicitly by the parent and are not newly admitted to npm test or CI. + +Parent verified all 39 frozen candidate hashes and six gate-log hashes after terminal exit, plus strict bind availability on port 4173. Browser evidence inventory contains 1,231 actual files. Actual served HTML/JS/CSS matched the fresh build bytes. A private Git index/object reconstruction reproduced all 83 candidate blobs from base `60fd7fb5c3177984a993102742bb16e36a909e2d` plus its full-index patch, with apply check 0, complete byte equality and unchanged live index. Native evidence was additionally audited: 301 focused artifacts retained/hash-equal, six predecessor/successor nonmobile visual-data comparisons equal, 14 descriptor restoration receipts exact, and 25 positive backend-identity-bound AX measurements with one matching actual descendant text (six intentional negative controls kept separate). Parent inspected 320/390 pending and 720 long-title screenshots; these support visible text, not actual AT speech. + +Independent reviewer `deleg_00a2110b` read the whole 39-path base-to-candidate union and returned **PASS, no blocking security/logic/oracle or unsupported completion finding**. Parent matched manifest SHA `f035262f0ef149f423f28bd316e63097042c4d9dc1ad4cbb5400b942afed41df` and compact sorted files-map digest `792b4ee3d713228322f4164027da49ce87d39d85e0210805f87c94af1a3f39d3` against the actual reviewed bytes. The reviewer did not execute tests or provide qualifying GitHub approval. Earlier document-only `deleg_1c4fa6b5` PASS covered its original eight-document snapshot, not later checkpoint additions. + +Nonblocking follow-ups remain explicit: nested-finally descriptor recovery if a settlement poll fails; a permanent predecessor-equality/default-name lane; child-level partial text visibility controls; independently exercised native Promise/throw/second-read identity. PRD now clarifies that reuse concerns the existing header `.save-state`, not the separate unchanged footer polite output. This PRD wording clarification and terminal evidence append are documentation-only successor changes; reviewed runtime/test bytes remain unchanged and require bounded final-document review. Existing earlier failure receipts and all stated coverage limits remain preserved. Exact-head hosted checks, qualifying independent approval, protected integration and release are still separate and **not passed by these local results**. No merge, runner adoption or legal/AT certification is claimed. + +Related contracts: [PRD](../PRD.md), [TRD](../TRD.md), [ADR-0005](../ADR-0005-local-draft-restore.md), [memory-only session](session-notice-20261005.md), [mobile title and observer history](mobile-document-title-20261005.md). diff --git a/docs/evidence/preview-text-reflow-20261005.md b/docs/evidence/preview-text-reflow-20261005.md new file mode 100644 index 0000000..d8baec5 --- /dev/null +++ b/docs/evidence/preview-text-reflow-20261005.md @@ -0,0 +1,70 @@ +# Preview text reflow — 2026-10-05 candidate + +## Product decision, not lost-fact recovery + +Published baseline: PR #26 head `2ff4fc6819578fbfadd27ebbdaa22ae97647ea5c`. Parent admits PRD `US-PREVIEW-REFLOW-01` as a new bounded screen-reading convenience contract: fixed long-text cohorts can be reviewed within the paper reading width without horizontal panning. Existing native horizontal scroll access is valid and positively observed; this slice does **not** repair demonstrated permanent clipping, lost facts or failed warning navigation. Natural height growth, document scrolling and the existing bounded preview's vertical scrolling remain valid. + +The selected candidate is one screen-only wrapping declaration scoped to `.paper > h2`, `.paper > p`, `.paper th` and `.paper td`. Direct fact-text ownership excludes the existing warning span/b/button and fixed clause h3; whole-paper inheritance was rejected to avoid changing those controls. This narrower scope was not executed in Layer1 and must prove its effect through repository TDD. `@media screen` avoids adding a print layout rule; print-media style/geometry comparisons are not printer pagination acceptance. No App/domain, white-space, table-layout, input truncation, schema, dependency, CI, legal rule, persistence or cancellation change is admitted. + +## Actual layered investigation + +Layer1 `deleg_e9d59cb0` produced two independent full plans. A's 127-line proposal SHA-256 is `c8f6f2405fd05fda5f323203a06160fbe6d91daa2e3fecd08d070a318afae84f`; B's 128-line proposal is `6dbff28ccab703cfaf1d797df832889dac4f61a706719546f2cc16d209fec255`. A recommends reducing the measured reading burden; B recommends honest none unless the parent explicitly adopts a new convenience contract. This difference is product judgment, not measurement contradiction. + +- A records 72 diagnostic snapshots at 320/390/820/1280 px and six complete scroll-union title/purpose/contact targets at 320/820, with every observed character reached. Its ASCII fixture required up to 4,180 px horizontal movement. Five-position samples initially missed intermediate characters; those are not permanent unreachability evidence. Whole-paper `anywhere` diagnostic overlays removed preview-local ASCII overflow at four widths; `break-word` left table expansion. That overlay is not the narrower production candidate or repository GREEN. +- B records 20 default/short/mixed/ASCII/short-header-with-long-other-facts journeys and eight corrected endpoint-scroll observations. All 20 warning actions focused the owning heading within the viewport. Short-header controls separate preview-local prose/table expansion from unrelated extreme nonmobile header overflow. Endpoint reachability is not identical to A's complete character-union proof. +- Parent retained 142 actual artifacts and verified all available artifact/source hashes plus 44 native JSON/TXT before/after byte pairs (A 4, B 40). Different A321-character/B236-character fixtures are not cross-fixture equality. Parent compared A short-input captured paper/preview/text-fragment geometry before/after overlay at four widths; values were identical. These are diagnostic preservation observations, not successor acceptance. +- B's initial locator exit 2 and wrong-viewport scroll exit 0 are preserved/excluded. Corrected diagnostic exit 1 measures own-box overflow, not a repository regression RED. A's diagnostic scripts exited 0. Both investigations exceeded the requested time target and ended without repository or server changes. + +Each Layer2 reviewer in `deleg_cafb0a0e` read **both full proposals**, confirmed their hashes and conditionally accepted a new paper-reading contract with narrow text ownership. One reviewer independently rehashed the retained inventory and compared byte pairs; the other explicitly did not claim that full audit. Parent aggregation chose the new contract after considering honest none. Conditional plan agreement is not implementation approval. Role-separated same/inherited-model work does not prove heterogeneous-provider execution, runtime product AI or benchmark benefit. + +Parent inspected the actual 320 px short-header/long-other-facts screenshot: prose and table extend rightward at rest. The 820 px diagnostic overlay contact capture shows wrapping without visible overlap; its purpose table is outside the capture. Images alone prove neither permanent loss nor actual AT speech. + +## Required repository tracer and preservation + +First tracer: actual public input at 320 px, short service name, one enabled catalog item with confirmed mode/path, short-purpose positive then one unbroken 321-character ASCII purpose. Admit exact input/cell text and table row/catalog/status ownership before measuring. The intended RED must be the new paper/text/table horizontal containment requirement with unchanged CSS, not setup, locator or timeout failure. Emit actual measurements and screenshot before assertion; only afterward apply the minimum rule, build and replay the identical initial test/oracle to GREEN. + +Require positive text rectangles within cell content bounds, table within paper content bounds and local preview horizontal bounds; local scroll/client equality is supporting evidence, not a replacement. Below-fold vertical text is not failure: use the actual document/preview owner to reveal first/last source ranges, preserve normal auto scrolling and reject hidden/clip/invisible intermediate content. Sensitivity controls cover nowrap, expanded table, horizontal/vertical clipping, invisibility and real sibling overlap, with normal below-fold positives and unconditional cleanup. + +Capture predecessor/successor default/short geometry at 320/390/720/721/820/1280/1440, fixed long ASCII cohorts and representative Korean/mixed states. A >1300 control covers the three-column surface affected by the new rule. Print emulation remains distinct from real printing. Exact raw mounted controls/current step, completion/readiness, ordered warnings, text/suffix, existing header/status/notice/locks and native JSON/TXT bytes must remain unchanged. Canonical JSON normalization and TXT omission of detailed facts remain existing contracts; neither proves every unmounted raw value. Newline characterization, if exercised through an admitted native file, must not add `pre-wrap` or silently promise a new display contract. + +## Current checkpoint / remaining gates + +At this documentation checkpoint, the implementation writer owns only stylesheet addition and a new native regression. Repository official RED/GREEN, final focused evidence, current whole-unit/lint/build/configured browser gates, visual inspection of the wrapped purpose table, independent whole-base-to-candidate source review and publication are not yet established. Prior unit230/browser189+12-scoped-skip results belong to the published predecessor. No test budgets, retry/skip policy or configuration may be weakened. + +Hosted exact-head checks, qualifying approval, protected integration, release, actual AT speech, human mobile scrolling, all Unicode/glyph behavior and printer pagination remain separate. Central Runner ownership, Issue #12 and PR #25 cancellation/stream work are not closed or bypassed. No legal source/rule or retrieval date is changed or revalidated. + +## Settled focused checkpoint — 2026-10-05 08:49–08:51 KST + +Writer `deleg_3ccde714` has stopped editing. Parent verified stylesheet SHA `69860559bcfd2a6b7e503c4690200ccd425c92ead1fffd195c421a8aa25230a6` and new native spec SHA `45d9c10972404d0a7d5402eaa88e964a74d2455d86604382f9a38181e8453fa5`. Removing exactly the added screen-media block reproduces published CSS bytes. App/domain/configuration/dependencies and existing browser specs remain unchanged. + +Parent read the actual official RED log: a short positive passed, then the 321-character purpose produced `table-paper-content-x` and text-paper containment failures. Initial test SHA `ddc29acb4d2eb45a1d376ba2fa37aaca32aba8939a2241f86c14914bafc5a954` matches both RED and initial GREEN bindings. Expanded desktop-focused execution reports 12 passes in 38.6 seconds. Focused lint/TypeScript passed; the original locator setup failure and TypeScript invocation correction remain separate from RED. A redundant replay after an explicit production rebuild was interrupted by its external 90-second observer at case 8; it is incomplete and is not a second passing run. The earlier complete focused result and unchanged final spec/assets remain distinct evidence. Current full configured native acceptance is still required. + +Parent retained and hash-verified 79 evidence files (78 declared artifact hashes plus the inventory file). There are **20 equality comparisons, not 20 native file pairs**: fourteen default/short screen geometry/state JSON captures, three print-emulated geometry/state captures, two native JSON comparisons (short export and restored export) and one native TXT comparison. Every corresponding baseline/successor byte comparison is exact. This corrects the writer's compact combined wording without changing any source or artifacts. Long-fixture native JSON/TXT predecessor pairs were not exercised. Native filenames and short saved-path restore/re-export were observed; runtime MIME and AX were not newly measured by this spec. + +Parent inspected the actual 320px ASCII purpose-table capture: all three columns, headers and wrapped text are visible without horizontal clipping or overlap. Source bytes are separately checked; the image does not prove exact repeated-character preservation or AT speech. Parent independently fetched current served/dist assets: JavaScript SHA `5abc9fdeeaaccb5c11b80a93c6c46b0e5e3b426bddcdd9c04da35f3793f45a56` is byte-identical to the published baseline despite its changed filename; CSS differs. Both the initial build's recorded inherited environment and final explicit build use production mode. + +The focused spec exercises purpose/retention, URL and mobile title long-text cohorts, first/last source-character vertical reachability and geometry sensitivity. It does not independently prove every intermediate character's visibility, every transfer/contact long combination, imported newline behavior, narrower hidden-clip variants, actual printer pagination or AT speech. Screen-only selector exclusion is checked with print-media captures, not physical printing. Existing broader seven-step/import/focus regressions must complement the new spec. Parent unit verification completed six pretests and 230 cases in 19 files under process-local test mode with all 26 source hashes unchanged; it excludes the previously unsettled browser spec. Final full native suite, complete accumulated-source review, exact-head hosted checks/approval and publication remain pending at this checkpoint. Prior failures and limits are preserved rather than promoted by focused GREEN. + +## Whole-candidate review and original runtime NONPASS — 2026-10-05 + +Independent reviewer `deleg_4f02e5b1` read all 41 base-to-candidate paths and verified the manifest before and after inspection. Manifest SHA-256 is `5e46496408d1ff4b5a5a1aad6dfd5a97d08cdd85c2631e38df757b92626364e5`; files-map digest is `d93448a5a26cbb4b51738d711c3355c61284f6f382bb05994dcb10ec14ddfcff`. The verdict is COMPLETE SOURCE PASS with no blocking finding, not runtime acceptance, hosted evidence or qualifying approval. Nonblocking limits remain: hidden descendants/clip-path/intermediate-line or within-cell overlap sensitivity; predecessor equality runs only in the explicit green receipt phase; long-native pairs, imported newline and all transfer/contact combinations are unmeasured. Optional served-build evidence was not independently inspected by this reviewer. + +The original full configured run collected 237 cases and ended EXIT1 after 18.4 minutes: 223 passed, one tablet URL known-collection failure, one tablet session JSON case passed only after its configured retry (flaky), and 12 existing profile-scoped skips. Three standalone contracts, lint and production build exited zero, but do not clear that browser NONPASS. Parent verified all 41 source hashes and original log hashes, and retained 1,359 artifact files with a hash inventory. The terminal strict-port probe failed; a separate fresh strict bind later succeeded. Neither observation is rewritten. + +Read-only RCA `deleg_1df87ddf` joined test/browser source stacks and monotonic timing. The first session attempt crossed its 30-second deadline during the restored survey's seventh public rail activation, not after a completed body. Cleanup restored native wrappers while the body continued. The retained restored observations and 1,215-byte native JSON pair are equal, but their final assertions ran after the deadline and cannot certify that attempt or complete active-observer coverage. The eventual retry PASS remains flaky history. + +Read-only RCA `deleg_e1bf4da1` verified both URL trace/spec bindings and 24 retained artifacts. The first attempt exhausted the same deadline in the pre-reload audit; its active observation returned zero after timeout. The retry exhausted the deadline after the first restored download's native-path assertion, within the subsequent saved-file processing interval. Cleanup overlapped later body operations; the final audit correctly rejected the inactive observer. The existing active guard executed and was not removed or bypassed. The retained original and two restored JSON files are each 1,209 bytes and byte-equal, but the retry's later equality assertions do not pass the timed-out case. These traces do not establish CSS causality, host contention or the specific cost that exhausted the budget. + +One unchanged-source focused diagnostic subsequently ran exactly those two tablet cases with the original 30-second case, 5-second assertion and CI retry policies. It exited zero with two passes in 38.7 seconds and no reported retry/flaky result. Parent verified source and built-asset hashes, 36 diagnostic files, native byte equality, and active URL body receipts before cleanup and after restore. This is a selected-case recovery observation, not a causal repair or full-suite acceptance. The original NONPASS remains immutable. A single separate whole recovery is in progress at this draft checkpoint; no final result is implied here. + +## Complete local workload recovery and separate supervisor boundary — 2026-10-05 09:46 KST + +The separate unchanged-source recovery completed all seven commands with exit zero: six npm pretests and 230 unit/UI cases in 19 files; the three standalone snapshot/URL-observer/summary-guard contracts; lint; a fresh production build; and the complete configured browser cohort. The browser collected 237 cases and reports **225 passed, 12 existing profile-scoped skips, no reported failures or flaky results**, in 11.0 minutes. CI mode, workers=1, the 30-second browser-case/5-second assertion defaults, configured retry and existing skip policy were retained. Standalone contracts remain separately executed local evidence, not newly wired npm/hosted gates. + +The supervisor `proc_26a37c58f9ec` nevertheless exited **1** because its immediate post-run strict-port probe failed. Its saved terminal receipt records workload exit 0 and `port_4173_released: false`; the returned supervisor exit and saved workload status must not be conflated. Parent preserved both, then independently performed a fresh strict bind successfully at 09:46 KST. No listener was killed and no original receipt was rewritten. This later resource observation complements the completed workload, but does not turn the original supervisor exit into zero or establish the cause of the transient bind failure. + +Parent verified all 41 source hashes, all seven log hashes, 237 unique reported case identities and 1,336 recovery artifact hashes. The browser log SHA-256 is `07fea411bf8cdf766ccbfa684e6a7060c27173102e2ceeda6d9ed3746863eef4`. The recovery server's actual HTML/JavaScript/CSS matched fresh dist bytes. JavaScript SHA remains `5abc9fdeeaaccb5c11b80a93c6c46b0e5e3b426bddcdd9c04da35f3793f45a56`, CSS SHA `d474556bfc7941bf28613d8e4768584c8180027eb7938b156a3db68b8f13bd88`. All 1,359 original failed-run artifact hashes remain unchanged. This is complete current-source local workload recovery, not a causal repair of historical timeouts, proof of deterministic latency, hosted checks, qualifying approval, integration or release. + +The parent is now adding this documentation-only checkpoint after runtime settlement. The earlier 41-path source verdict covers the frozen implementation/test bytes; any changed document bytes need their own final review before publication. Long-native predecessor pairs, newline, every intermediate glyph/hidden descendant, all transfer/contact combinations, AT speech and physical printer pagination remain unmeasured. PR #25, Issue #12 and the central Runner migration retain separate ownership and acceptance gates. + +Related: [PRD](../PRD.md), [TRD](../TRD.md), [architecture](../../ARCHITECTURE.md), [gap ledger](../product-technical-gap-baseline.md), [ADR-0005](../ADR-0005-local-draft-restore.md), [ADR-0006](../ADR-0006-local-review-summary.md). diff --git a/docs/evidence/review-summary-successor-20261004.md b/docs/evidence/review-summary-successor-20261004.md new file mode 100644 index 0000000..1b7e0df --- /dev/null +++ b/docs/evidence/review-summary-successor-20261004.md @@ -0,0 +1,34 @@ +# Review summary verification and delivery successor — 2026-10-04 + +Repository: PolicyWeave. Source base: `60fd7fb5c3177984a993102742bb16e36a909e2d`. Branch: `feat-mixed-agents-prd`. This is a successor to [the original layered-agent evidence](mixed-agents-review-summary.md), not retrospective replacement of its failures or receipts. + +## Existing work preserved and current authority + +The parent verified that all 16 original candidate files still match the previous patch receipt. A fresh read on 2026-10-04 finds parent Draft PR #1 (`develop` → `main`) unchanged at the source base above, and separate Draft PR #25 (`agent/import-cancellation` → `develop`) at `af8c0da17cdfb4786867f4e85401dbbb811b581e`. The summary work does not duplicate import cancellation/stream ownership. Issue #12 is open; the root candidate's Dependency Review failure, missing OpenCode approval evidence and cancelled Noema verdict remain non-passing. No required workflow rerun, run cancellation, protection change, synthetic status or Issue closure was performed. + +## Second layered development decision + +The primary methodology reference remains Wang et al., *Mixture-of-Agents Enhances Large Language Model Capabilities*, arXiv:2406.04692 (2024-06-07). Its prior-layer-output pattern informed the development workflow; no benchmark benefit is claimed. + +- Layer 1 (`deleg_773be568`): two independent whole plans proposed finishing `US-REVIEW-01` rather than inventing another feature. The product plan prioritized handler guard, native download boundaries, import recovery and observable state preservation. The technical plan distinguished immediately passing existing-behavior tests from production RED→GREEN and proposed isolated mutation evidence for the handler guard. +- Layer 2 (`deleg_7e249da4`): both reviewers received both plans and the parent aggregate. They retained the minimum scope, required original native-method calls and explicit fixture labels, rejected JSON-only claims of full raw-state preservation, and required fresh owned-server/build identity rather than stale preview reuse. +- Parent aggregate: add acceptance contracts and isolated guard controls, then exercise the final candidate and submit an ordinary Draft PR targeting `develop`. No new product API, React internal access, legal rule, hosted store, dependency or runtime model is authorized by this decision. + +Delegated model/provider identities are not verified heterogeneous. Role separation and shared prior-layer proposals are development provenance, not GitHub approval. + +## Clean installation recovery + +A previously dependency-empty owned directory at `/policyweave-clean-install-20261004` (a placeholder for the historical installation scratch location, not a public link or new execution record) ran `NODE_ENV=development npm ci --include=dev --no-audit --no-fund --prefer-offline --fetch-retries=0 --fetch-timeout=20000`: exit 0, 243 packages added. Lock bytes match the candidate. npm reported an allow-scripts warning for `fsevents@2.3.3`; no install-script approval or policy change was performed. This is installed-toolchain evidence, not a fresh vulnerability scan or cross-platform guarantee. + +The preserved candidate was materialized with its verified patch and exercised using those clean-installed dependencies: six pretests, 193 Vitest cases across 18 files, lint and production build completed with exit 0 (`proc_d1d5cc33cf18`). Those totals describe the predecessor source snapshot only; later contract additions require fresh final-candidate execution. + +## Visual observation, not whole-product acceptance + +The original mobile screenshot was successfully inspected on 2026-10-04 after the prior upstream-drop and quota-429 failures. The summary-download label/border is fully shown and readable without neighboring overlap. The header title and part of the horizontal step list are visually cut off at the right. This is a bounded historical screenshot observation, not a current-successor visual audit, full-screen completeness, native zoom, screen-reader or WCAG conformance. Those remaining visual conditions are not dismissed by document-level no-overflow assertions. + +## Executed acceptance contracts — completed parent full gate + +- `tests/e2e/review-summary-boundaries.spec.ts`: native Blob MIME, original URL allocation/activation/deferred-reclaim observation, real downloaded bytes, fixture-owned pending reads and read/validation failure recovery, plus observable state preservation. Positive/negative instrumentation is explicit; passing newly added assertions characterize existing behavior unless a genuine source defect is reproduced. +- `tests/review_summary_guard_contract.mjs`: isolated source copy with only button disabling removed must reject pending-import downloads through real React UI events; an additional guard-removal mutation must fail the intended allocation assertion. The live source remains unchanged. Fixture collection errors or timeouts are not accepted as mutation detection. + +The browser-contract owner completed 24/24 cases across desktop/tablet/mobile, zero skips, failures, flakes or retries. The spec uses a disclosed 60-second local survey budget without changing global config/retries; earlier descriptor/locator errors and default-30-second survey failures are retained as harness observations, not product RED. Original browser primitives are called by the positive observers. The guard owner completed one outer Node contract: enabled-button positive exit 0 and guard-removal negative exit 1 specifically at `HANDLER_GUARD_PENDING_IMPORT_ALLOCATION`, with live hashes unchanged and owned groups settled. This standalone guard contract is not wired into npm test or CI. Parent final-candidate verification completed as `proc_b1bea28186dc`: six pretests; 193/193 Vitest cases across 18 files; lint and production build; the standalone guard contract (positive 0, intended mutation negative 1); and full Chromium suite 63 collected, 51 passed, 12 existing profile-scoped skips, exit 0. `CI=1` forbids reuse of a pre-existing preview server; rebuilt product bytes were exercised. The 24 new boundary cases retain their disclosed 60-second survey budget. Unmounted/discarded stale facts not exposed by public controls/export remain outside observable preservation proof. Shell initialization reported `can't change option: zle`; it did not prevent the commands, and the warning is not suppressed. A new Draft PR is delivery/review admission, not parent integration, current-head CI success, qualifying approval, publication or release. Issue #12 and PR #25 keep their own exit contracts. diff --git a/docs/evidence/session-notice-20261005.md b/docs/evidence/session-notice-20261005.md new file mode 100644 index 0000000..3117920 --- /dev/null +++ b/docs/evidence/session-notice-20261005.md @@ -0,0 +1,86 @@ +# Memory-only editing notice — US-SESSION-01 evidence + +Date: 2026-10-05 (KST). Repository: PolicyWeave. Source base: `ee12e3fddefec1c4038e6da333019e3455e6a50f`; parent identifies this as Draft consumer PR #26. This record documents an uncommitted session-notice candidate, not release, current-head CI success or qualifying approval. This documentation owner edits only the seven assigned existing documents and this new record; no production change, commit, push or workflow operation is performed here. + +## Decision and acceptance boundary + +The existing workspace uses React memory, while the predecessor header claimed `버전 0.1.0 (임시저장)`. Existing mobile CSS hides `.version` and `.save-state`, so changing header copy alone cannot deliver the loss warning. PRD [US-SESSION-01](../PRD.md) selects a shared static paragraph in `FactStep`, `CollectionForm` and `PurposeForm`, after `.section-head` and before the first input, exactly once per active editor across all seven steps: + +> 자동 저장되지 않습니다. 새로고침하거나 탭을 닫으면 작성 내용이 사라집니다. 보관하려면 JSON 내보내기를 사용하세요. + +Header and preview identify `앱 버전 0.1.0`, separate from JSON `schema_version: 1`, TXT `report_format: v1` and future publication revisions. The paragraph owns no state, live announcement, alert/status role or focus target. Existing import's native fieldset/input lock and polite `JSON 초안 확인 중` / `브라우저 작업 중` remain under `isImporting`. It does not add a global row or alter workspace height arithmetic, browser storage, autosave, beforeunload, network, dependencies, schema or legal rules. + +Notice persistence is required during editing, navigation, import pending/success/failure and JSON/TXT export success/failure. Its presence must not change facts, selected items, attestations, completion/readiness or exported bytes. Accepted import still performs its existing validated state replacement and step-1 navigation. Native valid-JSON download → reload-empty → explicit restore characterizes existing memory/portability behavior, not new automatic recovery. JSON is admitted normalized facts, not every rejected/inactive/discarded raw value's backup; TXT is not a restore file. Download initiation is not storage completion. Mobile 320 px readable normal-flow placement and actual browser outcomes require runner evidence, not jsdom or copy inspection alone. + +## Methodology source and actual layered provenance + +Wang, J., Wang, J., Athiwaratkun, B., Zhang, C., & Zou, J. (2024, June 7), *Mixture-of-Agents Enhances Large Language Model Capabilities*, arXiv:2406.04692v1, DOI `10.48550/arXiv.2406.04692`, is the primary methodology source. Version-v1 metadata and abstract were retrieved on 2026-10-05; the abstract specifies prior-layer outputs as auxiliary inputs for each next-layer agent.[1] Only that development pattern is adopted; no benchmark score, speed/quality improvement, runtime product AI or paper reproduction is claimed. + +The documentation owner directly read both local manifests and their four task logs. Raw transcripts are not copied into this repository: local receipts are provenance pointers, not portable CI artifacts or GitHub approvals. + +| Stage | Local receipt | Directly observed scope | +| --- | --- | --- | +| Layer 1, independent whole proposals | `~/.hermes/cache/delegation/live/deleg_3fdbd3a9/manifest.json`, `task-0.log`, `task-1.log`; two tasks completed, 2026-10-05 01:20:33–01:26:07 KST | Product A and Technical B independently chose truthful session/save wording and existing JSON portability. Both identified the hidden mobile metadata gap; neither implemented production changes. | +| Layer 2, cross-review | `~/.hermes/cache/delegation/live/deleg_77762cef/manifest.json`, `task-0.log`, `task-1.log`; two tasks completed, 01:29:53–01:35:21 KST | Kickoffs supplied summaries of both Layer-1 plans and the parent aggregate. Reviewers conditionally retained shared editor-local placement, static semantics, import feedback, version separation and native restore/preservation checks. One reviewer explicitly reported not finding full proposal text. Full verbatim prior-output transfer is therefore not established. | +| Parent synthesis | Parent handoff and current source, traced in PRD/TRD/architecture | Retain warning before inputs in the three editor types, reject header-only/global-banner fixes, retain failure/data/mobile acceptance and no new storage. This is synthesis, not an additional independent approval. | + +Both manifests contain `model: null` and `provider: null`; same/inherited configuration does not establish resolved heterogeneous identities. This is a **MoA-inspired, summary-fed development workflow**, not a verified heterogeneous ensemble or complete reproduction of the paper's all-output transfer. Conditional planning review does not approve the final implementation. + +## Direct source inspection snapshot + +At 2026-10-05 01:51:26 KST, the documentation owner recorded these SHA-256 hashes from actual local bytes. They identify inspection, not the execution bytes of earlier parent tests or a frozen final successor. Other owners are still adding tests. + +| Source | SHA-256 | Observed trace | +| --- | --- | --- | +| `src/App.tsx` | `d846002aea63583d7bec553776ba293ebf843989eb0df4397af2eccd98295068` | Shared `SessionNotice`, three placements, header/preview app labels, unchanged pending-import feedback owner | +| `src/initial-workspace.test.tsx` | `4d0713d41e7f19d63009aa631d54762c415c0fd4db894503c2499f266d107bc2` | One notice across each of seven steps, input ordering, no live/alert/tabindex and unchanged initial zero completion; explicit header/preview labels | +| `src/styles.css` | `b8f434878d5a0b819196c837101a3faac628f2c94096f931b70466a8df955943` | Existing header mobile hiding, not modified by notice implementation | +| `src/policy.ts` | `e351c81b74d97c46f9179997b660dfaf7411c774b3aa1c56e4fbb2c707e7adfd` | Existing fact/readiness/export/restore authority; no notice-owned domain change | +| `src/policy-review-report.ts` | `0e22b3823c63b2c1f8287e7aa884436d76446882e906612ba4e0daf942488f1a` | Existing TXT projection/version, not a restore mechanism | + +Assertion source is not execution evidence. Public control properties plus normalized exports can support observable preservation but cannot certify unmounted/discarded hidden raw facts. Existing unsafe-URL normalization/admission limits are not repaired or waived by the notice. + +## Parent-reported bounded TDD observations + +The parent handoff supplies the following local observations. This documentation owner did not independently re-execute them, inspect their full command logs, or bind their execution to the snapshot hashes above. They must not be promoted to CI/full-suite evidence or summed with later totals. + +| Slice | Reported observation | Evidence boundary | +| --- | --- | --- | +| Temporary-save claim RED | One intended failure / three passes observed, then outer 60-second timeout; rerun completed exit 1 | Original timeout retained as incomplete execution, not PASS; completed rerun is intended RED only | +| Missing notice RED | Initial run reported two failures / three passes, exit 1; null-check improved to identify the intended missing step-1 notice | Harness/null access is not counted as an independent product defect; intended absence is the regression target | +| Header label GREEN | Focused one pass / four selection skips | Selected-case evidence, not four additional passes or full suite | +| Static notice GREEN | Focused five cases passed | Bounded local report only; not native mobile/layout acceptance | +| Preview label RED→GREEN | New intended one failure / four selection skips, then five cases passed and build passed | Version slice and bounded local build; no final-source full gate inferred | + +New existing-behavior reload/restore and failure-preservation characterization may be first-GREEN. Do not manufacture behavioral RED from a locator/setup error, host contention, timeout or previously implemented restore behavior. + +## Historic receipts retained, successor gates not inferred + +[The original summary evidence](mixed-agents-review-summary.md) and [2026-10-04 successor](review-summary-successor-20261004.md) remain unchanged. Their completed 193 unit/UI and 51 browser passes with 12 scoped skips belong to predecessor work, not US-SESSION-01. Earlier harness failures, native-browser survey-budget disclosures, clean-install warning, screenshot limitations and unresolved integration obligations remain intact. + +| Gate | State at this documentation handoff | Required before broader acceptance | +| --- | --- | --- | +| Current full unit/UI, lint and build | Pending here; parent-reported focused/build observations above only | Completed canonical commands with source/test identities and exit status; no stale totals | +| Session native-browser/mobile successor | Underway in another owner lane; no completed result claimed here | 320 px readable/non-hidden notice, edit/import/export persistence, public-state/version preservation, valid native download/reload/restore, actual downloads/failure cleanup and final build identity | +| Visual/assistive-technology acceptance | Not established | Inspect current rendered screenshots separately from no-overflow assertions; native zoom/screen-reader evidence remains separate | +| Exact-head hosted required checks | Unverified here | Fresh repository/PR/source head/base/checkout/run/job/artifact identity and terminal live required workflows | +| Qualifying independent approval and threads | Unresolved here | Final whole-candidate review, current qualifying approval and resolved required threads; no bypass | +| Protected integration/publication/release | Not performed or claimed | Ordinary governed integration and independent hosted/publication/security contracts | + +Parent reports Draft PR #26 as consumer, separate Draft PR #25 owning import-stream/cancellation, and central `.github` migration work (PR #2565, Draft `ab0c8659`) with an older consumer billing failure. These are attributed handoff observations, not remote re-fetches or integrated-ready evidence. No workflow edit/rerun/cancellation, gate relaxation, PR #25 modification or legal-source refresh belongs to this notice/documentation slice. Work can proceed locally while owner-side CI gates remain unresolved. + +## Documentation-slice verification + +Direct execution in this slice: `git diff --check` completed exit 0; `node --test tests/local_preview_contract.mjs` completed six passes, zero failures/skips, exit 0; relative-link checking found zero missing targets in the eight owned documents. Strict citation-ledger verification with evidence passed for the one external methodology reference. Every pre-existing line in the seven edited documents remains present, and the three historical evidence files linked above (including the archived product-gap ledger) are byte-equal to HEAD. These are documentation/configuration and preservation checks, not feature-suite, browser, hosted CI or approval evidence. + +The first arXiv `web_extract` attempt timed out after 120 seconds with no content. A real `web.run` open of the exact v1 page then returned its metadata/abstract, supporting the bounded methodology attribution; no result was inferred from the failed extraction. A broad scratch-file listing also encountered a dangling symlink after the local delegation receipts had been read; narrowing to relevant top-level directories completed. Neither retrieval/listing error is a product-test outcome. + +## Parent-executed successor receipts — 2026-10-05 + +The documentation handoff table above records an earlier state. The parent subsequently verified all 290 retained browser-artifact hashes and the browser owner's end-source hashes against the current candidate. The new spec's completed desktop run passed six cases; its three-profile run passed 18 cases, zero skips/flakes/failures, on the ordinary 30-second case budget. Two earlier 2-pass/4-fail locator-timeout runs remain excluded harness evidence, not product RED. Current 320 px step-1 screenshot inspection found the notice fully readable across three lines without clipping or overlap; that bounded image observation does not establish whole-product visual/AT acceptance. + +Parent final unit/config gate `proc_bdc56c716167` completed exit 0: six pretests, 195 unit/UI cases across 18 files, lint, build and independent handler-guard contract (enabled-button positive exit 0, guard-removal intended assertion exit 1). Parent production/test bytes were frozen before that run. Full accumulated browser suite `proc_2e469ba14328` completed exit 0 against rebuilt bytes and a new owned server (`CI=1`): 81 collected, 69 passed, 12 existing profile-scoped skips. The new session cases are included, not added a second time to this total. The subsequent whole-candidate source review (`deleg_70f729f1`) found no blocking security or logic defect across the complete develop-to-candidate union: 24 paths including both new files. Its evidence snapshot preceded this terminal-browser receipt append; production/test hashes are unchanged, and the append reports only parent-executed results. This local source verdict does not replace runtime gates, hosted checks, qualifying GitHub approval or release. + +## Sources + +[1] https://arxiv.org/abs/2406.04692v1 — *Mixture-of-Agents Enhances Large Language Model Capabilities*; primary version-v1 metadata/abstract, retrieved 2026-10-05. diff --git a/docs/evidence/url-portability-20261005.md b/docs/evidence/url-portability-20261005.md new file mode 100644 index 0000000..5711eda --- /dev/null +++ b/docs/evidence/url-portability-20261005.md @@ -0,0 +1,106 @@ +# Canonical URL normalized-portability successor — 2026-10-05 + +## Authority and scope + +Documentation handoff for the uncommitted successor based on session-notice HEAD `2117734f1956b7200bd8b396066e33f800e18436`. This is a bounded contract/evidence record, not final implementation approval, current full-suite/browser PASS, hosted CI PASS, protected integration, publication or legal sufficiency. The documentation owner read the canonical documents and actual producer/formatter/import comparison, the Layer1 report/results/commands and parent native RED logs. GREEN/lint/build, fixed-fixture execution and Layer2 outcomes below are parent-reported, not newly executed by this documentation owner. + +Canonical contracts: [PRD US-PORTABILITY-01](../PRD.md), [TRD](../TRD.md), [architecture](../../ARCHITECTURE.md), [ADR-0005](../ADR-0005-local-draft-restore.md), [ADR-0006](../ADR-0006-local-review-summary.md), [gap ledger](../product-technical-gap-baseline.md), [traceability](../research-traceability.md). Existing [session receipts](session-notice-20261005.md) and [TXT development receipts](mixed-agents-review-summary.md), plus all earlier dated canonical lines/receipts, are retained; their passing totals do not certify this successor. + +## Selected existing-contract clarification + +- **Live/raw correction:** a nonblank rejected authoring URL still yields `service_url_format` through unchanged `getDraftReview`; it remains a step-1 blocker. Download must not change raw facts, selected items, attestations, completion or navigation. +- **Canonical JSON after redaction:** normalize the URL once in `createPolicyExport`, withhold rejected input as `service_url: null`, and derive exported URL evidence from that admitted URL or the empty sentinel. Null yields `service_url`, not discarded format provenance. Incomplete status and step-1 ownership remain. No raw credential/query/fragment input, placeholder destination or stripped/repaired destination is admitted. +- **Canonical TXT composition:** `createPolicyReviewText` formats the exact exported code list with the same admitted URL in its supplied facts. A withheld URL has exactly one `service_url` row labelled `1단계 "서비스 정보" | "서비스 URL"`, in canonical JSON order; it must not become `단계 미상`. Non-URL findings, completion, recommendations and escaping retain existing authority. +- **Public helper scope:** `formatReviewFinding` itself is unchanged. Raw `service_url_format` with raw invalid URL facts still resolves to the format label. Its fallback preserves codes not resolvable against the facts supplied by its caller (including genuinely unknown codes); it is not a universal known-code lookup independent of facts. The composed canonical report must pass the correct URL facts rather than broaden or suppress fallback. +- **Closed boundary unchanged:** fact `schema_version: 1`, TXT `report_format: v1`, exact schema/catalog/status validation, reconstruction and ordered-code/readiness recomputation comparison remain unchanged. Old producer-inconsistent null+`service_url_format` files remain rejected. There is no dual-code admission, grandfathering, trusted findings, compatibility exception, silent repair or migration. +- **Compatibility obligation, not completed receipt:** blank/valid prior JSON/TXT bytes must remain unchanged. Current-function repeat/round-trip equality and frozen predecessor-fixture byte comparison are distinct; frozen-fixture verification was pending at the initial handoff checkpoint. Parent 03:18 KST successor reports retained-source blank/valid JSON direct-export and restore/re-export byte equality and withheld strict denial; frozen TXT comparison remains unverified. This artifact carries admitted normalized facts, not every rejected/inactive/discarded raw value or raw diagnostic. ADR-0005's “same unresolved findings” is qualified accordingly. + +No application version, UI, autosave/browser storage, import comparison, dependency, network source, legal rule/source/effective-date/template decision is changed by this documentation slice. PR #25 cancellation/stream and centralized `.github` workflow work remain separate ownership. Existing legal retrievals remain historical; none is revalidated here. + +## Layered proposals and conditional aggregation + +The local primary source root is ``, a placeholder for the historical owner-local location outside the repository, not a public link or new execution record; paths below are bounded local receipt identities, not shipped artifacts or external citations. + +1. **Layer1 A — `deleg_c6e76446` task0:** `portability-layer1-evidence/REPORT.md`, `results.json`, `vitest-results.json` and `commands.json` bind actual-function investigation at the frozen HEAD. Installed TypeScript compiled a byte-identical actual policy module, not copied predicates/mocks. Thirty URL executions across fresh-incomplete and otherwise-ready no-collection contexts produced 18 invalid own-export rejections and 12 blank/valid accepted byte-equal re-exports. Python inspection of the copied results confirms 30 rows; its summary states 18/12. The frozen Vitest run exited 1: 31 pass / 18 intended fail, including 19 passing prior tests. The rejection was exact finding mismatch after null reconstructed as blank. Diagnostic recalculation from sanitized facts isolates the cause; it is not an importer exemption or implementation. +2. **Layer1 B — `deleg_c6e76446` task1:** `portability-proposals-and-parent-plan.md` preserves the independent source/contract proposal summary: normalized-fact portability rather than raw backup, canonical null→missing evidence, strict historical rejection, and composed TXT ownership risk. This documentation owner inspected that summary, not a full raw transcript; only A supplied executed runtime evidence. +3. **Layer2 — `deleg_ae7b7ece`, two cross-reviewers:** the parent reports both returned conditional PASS requiring all controls. They received both Layer1 **summaries** and the parent aggregate, not verified full raw proposal transcripts. Required controls include independent expected ordered codes; omissions/extras/reorder/duplicates/substitutions and forged readiness rejection; rejected/normalized/encoded valid URL variants; nullable/status and non-URL controls; raw-state immutability; repeat bytes; canonical TXT ownership/cardinality; historical inconsistent-file rejection and blank/valid frozen fixtures; current browser/full/whole-union review. This handoff has no standalone full Layer2 transcript/hash and does not invent one. +4. **Parent aggregation:** `portability-proposals-and-parent-plan.md` selects the minimal producer/consumer normalization while retaining strict importer/schema and raw correction guidance. All conditions remain acceptance obligations. Parent conditional planning synthesis is not whole-source final review approval. + +This is role-separated, independent-proposal, MoA-inspired development with same/inherited model execution; heterogeneous model/provider identity is unverified. It does not demonstrate full-output-transfer reproduction, benchmark benefit, runtime product AI or qualifying GitHub approval. Methodology context is only the previously cited research in [traceability](../research-traceability.md) and the [prior session record](session-notice-20261005.md); no new external research claim or retrieval is added. + +Layer1's tracked bytes stayed unchanged; its scratch dependency symlink allowed ignored Vite metadata writes and a later concurrent untracked-test change made a subsequent status-preservation assertion fail. This is frozen source-bounded runtime evidence, not a strict zero-filesystem-write claim, native-browser journey or final candidate acceptance. + +## TDD observations and pending gates + +| Observation | Bound and status | +| --- | --- | +| Parent initial native RED | `portability-red-20261005/red.log` / `receipt.json`: own invalid-URL JSON restore mismatch; blank/valid controls. Preserved, not passing. | +| Independent canonical-code assertion | `portability-red-20261005/canonical-code-red.log`: 2026-10-05 03:01:42 KST, 1 intended failure / 2 controls; expected `service_url`, actual raw `service_url_format`. | +| Composed JSON/TXT native RED | `portability-red-20261005/json-txt-red.log` and `json-txt-red-receipt.json`: 03:04:30 KST, exit 1, 2 intended failures / 3 controls across 5 tests; canonical code and TXT step-1 label failed before production edits. | +| Parent minimal repair / GREEN | Parent reports those 5 cases GREEN, then related 35 cases and lint/build passed by 03:10 KST. These are intermediate observations, not this documentation owner's replay or final-source full gate. Native test source has since expanded; the earlier count is not certified against its later hash. | +| Parent 03:18 KST focused successor | Parent reports 65 focused passes and lint/build against the owned source/test slice; `portability-parent-freeze.json` (03:19:46 KST / 2026-10-04 18:19:46 UTC) binds hashes, 65 cases, lint/build exits 0 and unchanged importer. The production repair remains unchanged since 03:07 KST; App/import/schema/report version untouched. This is not a full suite. Tests cover 10 rejected URL variants, 6 blank/valid canonical controls, 9 nullable cases, mixed ordered five blockers/non-URL format, five tampered-code forms and direct raw helper/unknown fallback. | +| Parent fixed JSON fixture successor | Actual retained compiled `2117734` policy source (`e351…`) generated fixed predecessor fixtures. Parent confirms blank/valid direct export and restore/re-export byte equality and withheld strict denial. Fixture hashes and exact assertion source were inspected by this documentation owner, not replayed here. Frozen TXT comparison remains unverified. | +| Remaining local acceptance | Current full suite/lint/build and actual download→reload-empty→file restore→byte-equal re-export; raw editor/state preservation; secret-free ordered TXT; current whole prior-PR union independent source review. Parent reports whole-unit run ongoing at 03:22 KST and separately owns necessary existing `tests/e2e/review-summary.spec.ts` canonical unsafe-TXT expectation reconciliation, not a production change. Pending at bounded documentation handoff; parent will append actual successor receipts rather than reuse earlier totals. | +| Remaining governed acceptance | Exact-current-head required hosted/security workflows, resolved threads and qualifying independent approval. Parent reports prior exact CI `37220990288` failed before execution due to billing and central `.github` Draft PR #2565 `ab0c865` remains separately owned. Neither is passing/protected shipment; not re-fetched by this documentation owner. | + +Test-source presence, local proposals, intermediate GREEN, predecessor browser receipts and central workflow status cannot substitute for these gates. Hosted persistence/publication, manual assistive-technology/native-zoom and legal requirement mappings remain separate open work. + +## Parent-executed successor receipts — 2026-10-05 + +The earlier handoff tables remain dated observations. Parent subsequently bound completed `proc_bd7b3b8fad7b` exit 0 to unchanged nine frozen source/test/fixture paths: 230 Vitest cases across 19 files, six pretests and the standalone handler guard (normal positive exit 0, intended guard-removal failure exit 1). The importer function body, App, CSS, dependencies, browser config and CI workflow remain byte-equal to published `2117734`. Necessary existing browser TXT assertions were separately reconciled to canonical missing-URL labels while retaining raw input and live-format checks; their complete browser gate is not implied by the unit result. + +Parent compiled the actual `2117734` and candidate policy/report sources in exclusive scratch and compared eight previously admissible TXT scenes. All eight output byte sequences matched, including blank/valid/canonicalized URLs, non-URL format findings and collection/conditional blockers. An initial diagnostic compiler-option failure (exit 2) is retained; only scratch compilation mode was corrected. This bounded compatibility result does not include invalid-URL output whose code intentionally changes or claim general external interoperability. + +The browser owner completed 18 distinct native cases across desktop/tablet/mobile on ordinary 30-second budgets, zero failed/skipped/retried, source/spec launch/end/current hashes matching. Parent independently verified 525 retained artifact hashes, 18 unique final cases, and the released port with a successful strict bind; evidence is retained outside the repo under `url-browser-evidence/`. Actual saved-file import after reload and repeated pretty-JSON re-download bytes (including newline) match. Historical inconsistent-file denial, blank/valid acceptance, raw live format guidance, canonical TXT ownership and pending locks are covered. This is first-GREEN browser characterization of the earlier test-first repair, not a new behavioral RED. The child runner's post-desktop strict-bind errno 48 caused an outer exit 1 despite six passing desktop cases; that discrepancy is retained, only remaining-profile launcher cleanup was corrected, and final waits/cleanup succeeded. The parent's first artifact-verifier shell quoting failure (exit 2 before Python ran) is also excluded; the script-based verifier succeeded without browser replay. + +The original full accumulated browser process `proc_918dd118e28a` settled exit 1: 99 collected, 76 passed, eight failed, three flaky (retry success), twelve existing scoped skips, 29.8 minutes. Lint/build preceding it passed. Eight terminal failures were session-notice timeouts; one of the three flaky cases was a URL round trip. Its post-deadline observer mismatch is retained rather than cleared by its retry. The preceding whole develop-to-candidate review `deleg_949511d7` passed all 33 paths, and parent verified its entire inventory digest; that source-only verdict did not clear this runtime NONPASS or approve later changes. + +A separate read-only trace investigation (`deleg_e090ae93`) found successful notice checks repeatedly consumed the deadline, with no observed missing-notice or unexpected-value failure. Timing sums are instrumentation measurements, not proof of CPU contention or an exclusive cost attribution. A scratch-only successor (`deleg_466fc8c9`) replaced only the notice helper's repeated observations with one read-only snapshot per poll. Parent adopted the exact verified candidate and proved all preceding/following test bytes unchanged. Every seven-step survey, native interaction, import/export, byte/state preservation, geometry, screenshot and observer assertion remains; case deadlines are still 30 seconds, assertion budget five seconds, retry/configuration unchanged. Chromium visibility follows the inspected pinned Playwright predicate, not opacity or viewport intersection. + +The retained synthetic Chromium workload inspected by parent contains 53 checks: 26 malformed-record denials, one actual five-second polling denial, 22 visibility-parity controls, three valid single-observation records and one normalized-text positive. Original-helper observation-count RED, counter/closure harness failures and the initial parent receipt-path error remain separate from product behavior. These synthetic controls do not prove application acceptance. Parent's actual-product focused successor `proc_8090e761c494` completed exit 0 after lint/build: all 18 session cases passed with no retry/skips reported, on the original budgets. Current full accumulated successor and fresh complete source review are still required; the earlier 33-path verdict is not transferred to the changed helper. + +The subsequent configured whole-browser run `proc_0b08d8009129` settled exit 0: 99 collected, 83 first-attempt passes, four flaky retry successes, twelve existing scoped skips, zero terminal failures, 11.5 minutes. Parent verified all 33 candidate file hashes and port release. This passing configured command is not retry-free stability and does not clear source-review rejection. + +Fresh whole-union review `deleg_53414f5e` returned NONPASS for two measurement-helper equivalence defects: `textContent` omits input-button values and open-shadow text which original Playwright full-text assertions include; document-only CSS inventory misses open-shadow duplicate matches which original Playwright locators count. The helper's claim that original `toHaveText` uses `textContent` was incorrect. The 53 retained synthetic controls lacked these classes; their earlier GREEN and the configured browser PASS remain bounded historical evidence, not proof of complete adversarial equivalence. No production URL defect was identified by this review. The rejected helper and verdict are retained outside the repo; a separate sole writer must first reproduce the counterexamples with actual Chromium, then repair only test observation semantics and add permanent source-bound regression controls. Further source review and actual-product gates are required before publication. + +A separate sole-writer repair (`deleg_d4c71d77`) then reproduced the two reviewer counterexamples with actual installed Chromium: original Playwright assertions rejected temporary-save input values and open-shadow notice duplicates while the rejected snapshot admitted them. The retained RED command exited 1. The successor uses full-text semantics for all former text assertions and shadow-piercing inventories with descendant matching across shadow hosts; original document-only semantic/order queries and visibility predicates stay unchanged. Parent verified the complete prefix/suffix outside the helper byte-for-byte and the settled helper/contract hashes against writer receipts. + +The new standalone `tests/session_notice_snapshot_contract.mjs` extracts and transpiles the actual three helper declarations from the repository spec; its text oracle is extracted from the hash-bound installed Playwright injected source, and its selector/visibility oracle uses native locators. Writer GREEN exited 0 with 78 passed, zero failed/skipped, including cross-host positives, shadow duplicates, input/open-shadow text, excluded script/style/noscript and 22 visibility controls. Initial TypeScript invocation and a corrected native-semantic fixture expectation remain preserved, not product RED. Writer lint and corrected targeted TypeScript checks passed. The contract is explicitly standalone, not included by npm test or CI. These source-bound synthetic results do not clear the prior review rejection without fresh complete review and actual-product gates; no deadline/configuration or production changes were made for this repair. + +Parent final repaired-candidate gate `proc_2a5d7f679db6` completed exit 0: the source-bound standalone contract passed 78 checks with no failures/skips, followed by lint/build and a fresh complete browser run. All 99 collected browser cases reconciled to 87 passes and twelve existing profile-scoped skips; no failure, flaky result or retry was reported in this run (2.9 minutes). Ordinary case/assertion budgets and configured retry policy were unchanged. Parent verified all 34 candidate file hashes against the launch snapshot, confirmed port release with a strict bind, and retained a hash inventory of 574 actual browser evidence files. These artifact counts are not case counts or hosted uploads. The earlier 230-unit/19-file, six-pretest and standalone handler-guard results remain bound to unchanged production/domain-test/fixture bytes. All earlier failures, rejected helper versions and flaky runs above remain historical evidence; one successful successor does not prove universal timing stability. + +The fresh complete source review `deleg_7b80ad77` is still pending at this terminal-runtime receipt. This additive documentation paragraph does not approve its own content or transfer any earlier reviewer verdict to unseen bytes. No successor commit, push, qualifying GitHub approval, merge or release is asserted here. + +Neither local evidence nor planning reviews substitute for exact-head hosted checks, qualifying approval, resolved threads, protected integration or release. + +## SHA-256 source and receipt bindings + +Frozen baseline `src/policy.ts`: `e351c81b74d97c46f9179997b660dfaf7411c774b3aa1c56e4fbb2c707e7adfd`; baseline report source from parent RED receipt: `0e22b3823c63b2c1f8287e7aa884436d76446882e906612ba4e0daf942488f1a`; five-case RED test: `d7adbcba40c8bfb657549eb1fca173fe71fb227391a38cd49a7fc0cce1bc270d`. + +| Local receipt relative to source root | SHA-256 inspected | +| --- | --- | +| `portability-proposals-and-parent-plan.md` | `ce5d1cf4f83c487b584e5327478f95760ccda498b4ff3322282820a3fc03a282` | +| `portability-layer1-evidence/REPORT.md` | `d6ecdb49cfc021970b7b241c636e2553cae103a4ef1279288956907390b5206a` | +| `portability-layer1-evidence/results.json` | `c63b02a62f3e1cb9100edd02d5650abad5943e6b3b8199bdf15fb90eda18e9a4` | +| `portability-layer1-evidence/vitest-results.json` | `fc03a1ee266ce7056f98973c7f294caf970b7b56e047959c0a3627a6ab23b3e4` | +| `portability-layer1-evidence/commands.json` | `74b40e94603252a617088d980b456ce6226dec6666c9c83f64a443e4e8f77474` | +| `portability-red-20261005/json-txt-red-receipt.json` | `f606ccc73f0539048f8af9e77cddb943a8d9597eb3c3dfecbad602751859210b` | +| `portability-red-20261005/json-txt-red.log` | `79f37b878f4695a7c1c4cdb3f00f1b8557b1085575d28b8fb4398a3baed07eda` | +| `portability-red-20261005/canonical-code-red.log` | `4d7a4d1824888635278e238078c33d58ac696c12759b30e010cbd758fde0dc00` | + +Successor production source inspected (not certified final): [policy.ts](../../src/policy.ts) `210ea40beabef8cb191d9f417ea88d4b2bdb143f044014d899191cd26375e8c2`; [report](../../src/policy-review-report.ts) `f0819fcafa3fef1965478a80c85e29f209a86ef4a198f09886d9cd3e1f8a8d27`; [expanded native test](../../src/policy-portability.test.ts) initially inspected at `36a54429b4df0db102c0020574df4e4c344f7b6ca5865d9eb408a4d0c626ca69`, subsequently frozen by the parent at `852d9bf9166a0eb81aad3492a80b5d4e6904c6873138ce969f03f84ca24639be`. Parent owns these sources; this documentation task did not edit them. A changed hash requires renewed source-bound execution, not recycling the earlier five-case receipt. + +Parent freeze receipt `portability-parent-freeze.json` SHA-256: `4c65d7c00cde8102dba9a3060920e61928a3307f432785aa940a4a6153b4b9f5`. Fixed JSON fixture hashes: [blank](../../tests/fixtures/policy-v1-predecessor-blank.json) `f3fcca2186508a6864d1faf814377997d3b23e1db4b50ceee95a3fa80de05d76`; [valid](../../tests/fixtures/policy-v1-predecessor-valid.json) `0633d76ea48a5b8af289414d13feff8d189acdc0093dedf33b6ad494eeb5dd3e`; [withheld](../../tests/fixtures/policy-v1-predecessor-withheld.json) `353123483750fb345f6443577d6d16a183e66e48bb92cb053fd6e026b11bd7f2`. + +| Canonical document at handoff | SHA-256 | +| --- | --- | +| `docs/PRD.md` | `53a18d78dfc0214d906a4b2e88b9ba52bbadba1cd6aef4331d67415b550e7533` | +| `docs/TRD.md` | `b1b2968585707c32a2661105325b00b4a68cd574852ae84c07d6504a6b79aace` | +| `ARCHITECTURE.md` | `9816583344bb2efaf26023e09cffdfb178e5710c664e425a9719fc882442e09f` | +| `CHANGELOG.md` | `2318da36ba85a3ea0c80ea7d4035f423b0ade0eb551fcdf9e043c23feb17e251` | +| `docs/product-technical-gap-baseline.md` | `5e184e1e93b523cc9a259b771682d42e641c0eed504ec03018a2db6b92fa9f8a` | +| `docs/research-traceability.md` | `4812e05becb8c3112c66e4d935c98dd083ccee55dcec981f0a60570752280018` | +| `docs/ADR-0005-local-draft-restore.md` | `ddddad27da286a8885c75f40e268169db69af1ad7490e2615e127e3364955d80` | +| `docs/ADR-0006-local-review-summary.md` | `f08da933cdcd4c814cb524ff8b81391c6a32c33eb58817a3ee2a17cb78f13f77` | + +This evidence file's own digest is returned in the documentation handoff rather than recursively embedded here. Only the eight named canonical docs and this new evidence document are owned by this task; no commit/push or other-owner edit is authorized. diff --git a/docs/index.md b/docs/index.md index 8e52c95..55ea859 100644 --- a/docs/index.md +++ b/docs/index.md @@ -13,6 +13,9 @@ PolicyWeave is a local-first privacy-policy fact-authoring workspace for web and - [ADR 0003](ADR-0003-policy-revision-persistence.md) — the Proposed PostgreSQL revision identity, 3NF fact, consistency, and item-level UPSERT contract. - [ADR 0004](ADR-0004-runtime-status-admission.md) — the Proposed closed-vocabulary runtime admission decision for categorical policy facts. - [ADR 0005](ADR-0005-local-draft-restore.md) — the Proposed fail-closed schema-v1 local draft restore decision. +- [ADR 0006](ADR-0006-local-review-summary.md) — the Proposed local minimal TXT review-summary decision, distinct from JSON portability and publication. +- [Local layered-agent evidence](evidence/mixed-agents-review-summary.md) — MoA-inspired proposals/cross-review/aggregation, model-provenance limits and unverified integration gates. +- [Review-summary verification successor](evidence/review-summary-successor-20261004.md) — clean-install recovery, second proposal/cross-review layer, native-boundary and isolated-guard receipts, with local/hosted limits. - [Proposed policy revision ERD](ERD.md) — the normalized persistence relationships and transaction invariants represented by migration `0001`. - [Research and legal traceability](research-traceability.md) — authoritative-source, effective-date, and implementation/test traceability for legal and policy decisions. - [Product and technical gap baseline](product-technical-gap-baseline.md) — current commercialization gaps and evidence status. diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 95b108c..16df764 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -10,6 +10,84 @@ Fresh inspection still finds protected `main@52f4fd6bb68f870d0519cf11dd471573a2f A check receipt must bind repository, PR, source head, base, actual checkout SHA, run/attempt/job and artifact identity. An associated PR run that checks out a synthetic merge commit is integration evidence, not automatically a literal head checkout. Re-fetch final candidate evidence after every head or base movement. No queued, skipped, cancelled, predecessor or comment-only result constitutes approval or passing required Checks. Ready is review admission, not merge authorization. +## Local minimal review-summary candidate — 2026-10-03 + +The branch-local delta based on `60fd7fb` implements PRD `US-REVIEW-01`, not hosted approval/publication. [ADR-0006](ADR-0006-local-review-summary.md) chooses minimal TXT over full-facts Markdown. [The local evidence record](evidence/mixed-agents-review-summary.md) preserves two independent proposals, a second layer where both receive both proposals and the parent aggregate, and final conditional aggregation. Role-separated same/inherited-model delegation is not verified heterogeneous-model execution. + +This bounded section does not supersede the dated historical receipts below. Parent-observed live state places Draft PR #1 at `60fd7fb5c3177984a993102742bb16e36a909e2d` and separate Draft PR #25 at `af8c0da17cdfb4786867f4e85401dbbb811b581e`, owning import cancellation/stream work. This summary feature neither duplicates that work nor cancels workflow runs. Issue #12 remains open: Dependency Review HTTP 403 and qualifying independent approval remain unresolved. Re-fetch remote head/base/checks before integration; no new exact-head hosted receipt is asserted here. + +| Gap | Candidate delta | Evidence still required | +| --- | --- | --- | +| Portable review aid | Minimal deterministic `policyweave-review.txt`; canonical identity/state/ordered blocker rows, seven-step completion, separate recommendations; no detailed operational/contact facts | Clean-installed baseline test/lint/build recovered. Parent successor gate: 193 unit/UI passes, six pretests, lint/build, isolated guard positive/negative and 51 browser passes with 12 existing scoped skips; 24 new native-boundary cases are included. Historical mobile summary control visually readable; header/step clipping and broader visual/AT acceptance remain open | +| Legal/publication authority | Existing product-readiness expressions only; report-format v1 and facts-schema v1 are not an approval/publication version | Versioned legal-source/rule mappings, authenticated review and immutable publication remain open | +| Integration assurance | Original independent whole-delta local review found no blocking defect. Successor parent gate completed lint/build, 193 Vitest and 51 browser passes with 12 scoped skips; successor independent review pending | Current exact-head hosted workflows, resolved threads and qualifying GitHub approval remain open. Empty-directory npm ci added 243 packages and exercised the predecessor snapshot; fsevents allow-scripts warning is retained, not silently approved. | +| Mixed-agent provenance | Layered proposals → shared prior outputs/cross-review → parent aggregation receipts exist locally | Heterogeneous model/provider identity is unverified; no benchmark or runtime product-AI claim | + +## Memory-only session-notice candidate — 2026-10-05 + +PRD `US-SESSION-01` reconciles unsupported temporary-save wording with the existing React-memory contract. The uncommitted delta is based on `ee12e3fddefec1c4038e6da333019e3455e6a50f`: shared static notice after each section heading and before inputs across all seven steps, plus explicit app-version labels in header/preview. No automatic storage, unload prompt, dependency, schema, readiness or legal rule is added. JSON is normalized fact portability, not every raw input's backup; TXT cannot restore work. Existing pending-import live status and lock remain. + +[The dated evidence record](evidence/session-notice-20261005.md) binds direct source/proposal inspection separately from parent-reported RED→GREEN observations: initial outer timeout is retained as non-passing; completed intended REDs, focused five-case GREEN and local build are bounded reports, not a final-head full gate. Historic 193-unit / 51-browser / 12-scoped-skip totals above remain predecessor receipts and are not promoted to the session candidate. Current full suite and actual browser successor are pending in this documentation handoff; no new CI pass is asserted. + +| Gap | Candidate contract | Remaining evidence | +| --- | --- | --- | +| Truthful session boundary | One static notice per active editor; app version distinct from fact/report versions; no save claim | Current native browser notice persistence across edit/import/export outcomes; readable normal-flow 320 px text and no clipping; reload-empty / explicit validated restore; current lint/test/build | +| Integration and ownership | Parent reports Draft consumer PR #26 and separate import-stream/cancellation PR #25; centralized CI migration remains owner work, not duplicated here | Fresh head/base/checkouts and terminal live required checks, resolved threads and qualifying independent approval. Parent-reported old billing failure/central migration is not integrated-ready evidence; do not bypass gates or alter PR #25 | +| Evidence provenance | Two independent whole proposals followed by summary-fed cross-review and parent synthesis | Same/inherited model identity is unverified heterogeneous; one reviewer explicitly lacked full prior proposal text. Conditional planning agreement is not final implementation approval | + +This dated addition preserves all earlier receipts, including the older PR #1 observations; it does not re-fetch or silently relabel them as current remote truth. Source/test assertion presence and local planning do not close legal, accessibility, hosted persistence/publication or Issue #12 gates. + +## Canonical URL portability successor candidate — 2026-10-05 + +Based on published session-notice HEAD `2117734f1956b7200bd8b396066e33f800e18436`, this bounded successor repairs producer evidence after URL withholding, not strict schema admission. Live raw rejected URLs still produce `service_url_format`; canonical JSON/TXT use `service_url` for the admitted `null`, retain incomplete step-1 ownership and never retain or rewrite rejected URLs. Schema 1/report v1 and exact importer recomputation stay unchanged. Old null+format producer files remain rejected: no compatibility exception or migration, and no full raw-input/diagnostic backup promise. + +[The dated successor record](evidence/url-portability-20261005.md) distinguishes two Layer1 independent proposals (including the actual frozen-source 30-case matrix: 18 rejected own exports / 12 positive round trips) from two summary-fed Layer2 conditional reviews and parent synthesis. Roles were independent; same/inherited model execution is not verified heterogeneous-model/provider execution. Planning conditions are not final implementation approval. + +| Gap | Candidate contract / bounded observation | Remaining evidence | +| --- | --- | --- | +| Normalized URL portability | JSON derives findings after URL admission; TXT supplies admitted URL to unchanged raw helper, preserving ordered one-row-per-code and step-1 label | Current native download/reload/file restore/re-export; invalid variants and all nullable controls; raw-state preservation and secret-free JSON/TXT | +| Compatibility boundary | Strict ordered-code/readiness recomputation; old null+format rejected; existing blank/valid bytes must not change | Initial checkpoint pending; parent 03:18 KST confirms retained-source blank/valid JSON fixture direct/export-restore byte equality and withheld strict denial. Frozen TXT comparison remains unverified; no migration or raw-backup acceptance | +| TDD and integration assurance | Parent native JSON/TXT 2 intended RED + 3 controls, then 5 GREEN; related 35-case pass and lint/build reported at 03:10 KST are intermediate. Parent 03:18 KST successor: 65 focused cases plus lint/build against the owned freeze; still not a full suite | Current full suite/browser, independent whole prior-PR union review, exact-head required hosted checks, resolved threads and qualifying approval; no final PASS | +| Ownership and provenance | No UI/autosave/network/dependency/legal-source/rule change; PR #25 stream/cancellation and central workflow owners unchanged | Parent-reported exact CI `37220990288` billing failure before job execution and central `.github` Draft PR #2565 `ab0c865` are not passing or protected shipment; fresh remote evidence remains owner work | + +All historical sections and receipts remain dated evidence, not this candidate's final gate. No hosted persistence/publication, legal sufficiency or protected integration is asserted. + +## Mobile document-title successor candidate — 2026-10-05 + +Based on published PR #26 head `1e662c2f08d4e156b9280ef434bc876c0c77b283`, PRD `US-MOBILE-TITLE-01` selects one presentation gap: the mobile header silently clips a long service-name projection and policy suffix at 190 px. Independent current-browser measurements at 320/390 px show text widths approximately 586/653 px while document overflow is zero; default-name controls pass. One measured URL-warning keyboard path is normal, and intentional horizontal rail scrolling is not admitted as a defect. These actual observations supersede neither dated earlier receipts nor separate hosted gates. + +| Gap | Bounded candidate | Required successor evidence | +| --- | --- | --- | +| Mobile header title | Normal-flow full-width wrapping row, exact service input/text/suffix and visible sibling controls; mobile CSS rule only | Repository containment RED before production edit, same oracle GREEN, fixed 320/390/720 cohorts, sensitivity controls, screenshots and current full gate | +| Preservation | No App/domain/focus/import/download/storage/CI/dependency/legal rule change; default/short nonmobile layout retained | Actual predecessor/successor comparison at 721/820/1280, existing seven-step/native/focus regressions and final whole-candidate review | +| Evidence authority | Two independent whole plans followed by two reviewers receiving both full texts and parent aggregation | Conditional planning is not implementation approval; heterogeneous-model identity unverified; [dated evidence](evidence/mobile-document-title-20261005.md) retains execution classes separately | + +Nonmobile extreme names, preview/rail text, AT/manual accessibility and protected integration remain open. Natural vertical scrolling is allowed; there is no input length restriction or blanket all-name/all-screen readability promise. Central Runner PR #2565, separate PR #25 and Issue #12 ownership/gates remain unchanged; no migration adoption, approval, merge or release follows from local evidence. + +## Mobile import-feedback successor candidate — 2026-10-05 + +Published baseline is PR #26 head `a51669c91f579f94019ae1714554eb74db5a9366`. Independent native probes reproduce hidden pending `.save-state` text at 320/390 px while existing busy/disabled prerequisites and byte-equal valid release work; 820 px is a positive exposure control. [Dated evidence](evidence/mobile-import-feedback-20261005.md) records five within-journey byte-equal pairs, not cross-fixture equality or actual AT speech. Each Layer2 reviewer read both complete proposals; role separation is not verified heterogeneous-model identity. + +| Gap | Selected bounded repair | Required successor evidence | +| --- | --- | --- | +| Mobile pending reason | Existing polite region visible as wrapping row; idle copy also intentionally visible | Actual repository intended visual/AX RED then same GREEN; live-owner identity/descendant paths, line/clipping/nonoverlap and rail geometry; 720 boundary and 721/820/1280 preservation | +| Existing restore ownership | No App/domain/format change; fieldset/import/TXT locks, static notice and validated state replacement retained | Native saved-path byte equality, invalid JSON/schema/read-rejection preservation, oversize before-read zero calls, cleanup descriptors and current seven-step/TXT regressions | +| Candidate acceptance | CSS-only production scope; no duplicate live/status, busy ancestry or new storage/config/dependency | Current lint/test/build, configured native suite, visual inspection and independent whole-source review; exact-head hosted checks/threads/qualifying approval separate | + +Implementation and final gates remain incomplete at this checkpoint. Historical receipts remain dated. PR #25, central Runner ownership and Issue #12 are not closed or bypassed by this candidate. + +## Screen preview reflow convenience candidate — 2026-10-05 + +Published baseline is PR #26 head `2ff4fc6819578fbfadd27ebbdaa22ae97647ea5c`. Current preview scrolling reaches tested facts and warnings navigate normally; no permanent fact loss or broken warning path was demonstrated. Parent admits `US-PREVIEW-REFLOW-01` as a new bounded screen-reading contract to reduce measured long-token horizontal movement up to 4,180 px and purpose-table expansion. [Dated evidence](evidence/preview-text-reflow-20261005.md) retains independent proposals, errors/excluded viewport results, actual reachability and 44 within-journey native byte pairs; these are not successor acceptance. + +| Gap | Selected bounded candidate | Required successor evidence | +| --- | --- | --- | +| Long-fact reading burden | Screen-only direct h2/p and table th/td wrapping; existing valid scroll path acknowledged | Official new-contract table/text containment RED before CSS, identical oracle GREEN, local content bounds and scroll-aware sensitivity | +| Presentation preservation | Exact facts/suffix/rows, warning controls/header/status, existing vertical scroll and print-rule exclusion | Default/short predecessor comparison at seven fixed widths including 1440, print-emulated scope, native bytes/restore and existing seven-step/focus/lock regressions | +| Evidence authority | Both cross-reviewers read both full plans; conditional agreement, no heterogeneous-model proof | Current lint/test/build/configured browser, wrapped-table visual inspection and independent whole-candidate review; exact-head hosted/approval separate | + +The screen-only repository implementation has actual RED/GREEN, complete 41-path source review and unchanged-source local workload recovery: pretests 6, unit/UI 230, browser 225 passed with 12 existing profile-scoped skips, plus separately executed contracts/lint/build. The original browser failure/flaky history remains retained. All recovery workload commands exited zero, but the supervisor exited 1 on its immediate strict-port check; a separate later strict bind succeeded without rewriting that result. Final documentation review and publication remain pending; hosted checks, qualifying approval, integration and release are not established by this local evidence. No global overflow hiding, text truncation, new fact normalization, legal rule, hosted adapter or dependency/CI change is admitted. PR #25, central Runner ownership and Issue #12 remain separate. + ## Runtime status admission repair [ADR-0004](ADR-0004-runtime-status-admission.md) implements the existing PRD/TRD/ADR-0002 explicit-fact requirement in `src/policy.ts`. Review, completed-step derivation and schema-v1 export no longer treat truthy unknown collection/retention/transfer status values as operator confirmations. Only exact existing members are accepted; unsupported statuses retain their owning finding and export as `null`, without coercion, inferred `no`/`none` or source mutation. diff --git a/docs/research-traceability.md b/docs/research-traceability.md index fefba7f..c7bbac5 100644 --- a/docs/research-traceability.md +++ b/docs/research-traceability.md @@ -53,5 +53,47 @@ World Wide Web Consortium. (2025). *Understanding Success Criterion 2.4.7: Focus 5. LLM output, if later used to explain or propose wording, is never an authoritative legal source and cannot change review/publication state. 6. Collection absence is not evidence of absence of other processing acts such as storage or retention; applicability decisions require their own explicit source fact unless an authoritative rule proves a dependency. +## Local review-summary trace — 2026-10-03 + +PRD `US-REVIEW-01` and [ADR-0006](ADR-0006-local-review-summary.md) add only a deterministic local TXT expression of the existing product-readiness contracts. `createPolicyReviewText` consumes `createPolicyExport`, `getCompletedSteps` and `getReview`; the report/domain and UI regression files trace ordered blocker identity, recommendations, seven-step ownership, text escaping, identity admission and download failure/state-preservation boundaries. Test source is not passing execution evidence; [the local evidence record](evidence/mixed-agents-review-summary.md) labels earlier bounded observations separately from completed local full-suite/browser successor evidence and unresolved visual inspection, exact-head hosted and qualifying-approval gates. + +No legal source, effective-date snapshot, legal rule, template authority or legal-sufficiency conclusion is changed by this feature. The legal register and dated retrievals above remain historical evidence, not revalidated current law. TXT omission of contact and detailed operational facts is a product disclosure-minimization choice, not a legal anonymization decision. + +The development workflow is MoA-inspired: independent proposals, a second layer receiving both prior proposals plus the parent aggregate, then parent aggregation. The methodology source metadata is Wang et al. (2024), *Mixture-of-Agents Enhances Large Language Model Capabilities*, arXiv:2406.04692 v1 (June 7, 2024); its retrieved source citation and local delegation receipt identifiers are recorded in the evidence document. This is not a runtime LLM feature, verified heterogeneous-model ensemble, benchmark reproduction or substitute for independent GitHub approval. + +## Memory-only session-notice trace — 2026-10-05 + +PRD `US-SESSION-01` exposes the existing memory-only boundary through `SessionNotice` in `FactStep`, `CollectionForm` and `PurposeForm`; `src/initial-workspace.test.tsx` traces all-step placement/static semantics and explicit app-version wording. Existing import and export contracts retain pending feedback, validation, derived evidence and failure-state ownership. [The dated evidence record](evidence/session-notice-20261005.md) preserves directly inspected sources and local delegation manifests, parent-reported bounded RED→GREEN/build observations, historic suite receipts and pending current browser/full/hosted/approval gates separately. Test source alone is not execution evidence. + +Wang et al. (2024), *Mixture-of-Agents Enhances Large Language Model Capabilities*, arXiv:2406.04692v1 (June 7, 2024), supplies methodology only: prior-layer outputs inform next-layer agents. Version-v1 metadata/abstract was retrieved again on 2026-10-05; source and exact scope are in the evidence record. Here two independent whole proposals were followed by reviewers receiving summaries plus the parent aggregate; one reviewer reported not finding full proposal text. This is MoA-inspired, not verified full-output-transfer reproduction, heterogeneous-model execution, runtime product AI, benchmark benefit or qualifying GitHub approval. + +No law, source effective date, template authority or legal-sufficiency rule is changed or revalidated by session copy. The legal register and dated retrievals above remain historical. Guidance to export JSON is a product portability choice, not a legal retention/backup guarantee. + +## Canonical URL normalized-portability trace — 2026-10-05 + +PRD `US-PORTABILITY-01` and [the source-bounded evidence](evidence/url-portability-20261005.md) trace an existing normalized-fact producer consistency repair. `createPolicyExport` derives URL evidence after admission/redaction; `createPolicyReviewText` passes that admitted URL to the unchanged `formatReviewFinding` helper. Live raw `service_url_format` remains correction guidance; canonical null URL uses `service_url` and step-1 ownership. [ADR-0005](ADR-0005-local-draft-restore.md) keeps exact schema-v1 reconstruction/recomputation and rejects historical null+format evidence without compatibility exception or migration; [ADR-0006](ADR-0006-local-review-summary.md) preserves ordered TXT cardinality/labels and helper fallback scope. This is admitted-fact portability, not full raw-input/diagnostic backup. + +Two Layer1 independent proposals were followed by two Layer2 reviewers receiving both proposal summaries and parent aggregation, not verified full raw transcripts; parent reports both reviews conditional on all controls. Same/inherited model execution and unverified heterogeneous provider identity are stated honestly. The MoA-inspired methodology uses the prior cited research only; no new external retrieval, benchmark inference, runtime product AI or qualifying GitHub approval is claimed. Frozen-source runtime RED (30 URL cases, 18 own-export rejections and 12 positives), parent native 2 RED + 3 controls then 5 GREEN and related 35/lint/build intermediate signals remain dated intermediate receipts. At 03:18 KST the parent reports 65 focused passes/lint/build and actual retained-source blank/valid JSON fixture direct-export and restore/re-export equality plus withheld strict denial; frozen TXT bytes and current full/browser/whole-union review/hosted acceptance remain unverified. + +No law, effective-date snapshot, template authority, legal source, network source or legal-sufficiency rule is added, changed or revalidated. The register and dated retrievals above remain historical evidence; normalized URL withholding is an existing product admission/disclosure boundary, not a new legal rule. + +## Mobile document-title trace — 2026-10-05 candidate + +PRD `US-MOBILE-TITLE-01` and [the dated evidence](evidence/mobile-document-title-20261005.md) bind a product-UX reflow decision to the current `App.tsx` title projection and mobile stylesheet, not a new law, template or compliance rule. Two independent whole proposals include actual long-name/default controls; each of two next-layer reviewers received both full proposals and conditionally accepted one mobile-title-only plan. This full-proposal transfer is distinct from the summary-fed historical layers above; same/inherited-model roles still do not establish heterogeneous-model execution, benchmark benefit or qualifying GitHub approval. + +The proposed native regression compares exact input/text, rendered line geometry and visible sibling layout; clipping, hidden-title and overlap sensitivity and nonmobile preservation remain acceptance requirements. Diagnostics, repository RED, candidate GREEN, visual inspection and final gates are separate evidence classes. No legal register, retrieval/effective date, authoritative-source mapping, readiness rule or ADR-0005/0006 contract is changed or revalidated. Native geometry and screenshots must not be promoted to universal WCAG/AT conformance. + +## Mobile import-feedback trace — 2026-10-05 candidate + +PRD `US-IMPORT-FEEDBACK-01` and [dated evidence](evidence/mobile-import-feedback-20261005.md) trace existing import-status presentation in `App.tsx` to mobile stylesheet exposure and proposed native-browser regression. Two independent full proposals include actual saved-file/held-read observations; each next-layer reviewer read both full texts. Parent aggregation selects one existing-region mobile row. Full-output transfer and role separation do not prove heterogeneous-model execution, benchmark benefit, runtime product AI or qualifying GitHub approval. + +Native geometry and a backend-identity-bound Chromium AX descendant path establish distinct visual/tree exposure properties, not actual screen-reader speech or blanket WCAG compliance. Static memory-only notice, fieldset busy, strict schema-v1 authority and file formats remain unchanged. Baseline diagnostics, repository intended RED, same-oracle GREEN and final gates are separate evidence classes. No new external retrieval, legal register/effective date, template or readiness rule is added or revalidated; historical legal citations remain historical. + +## Screen preview reflow trace — 2026-10-05 candidate + +PRD `US-PREVIEW-REFLOW-01` and [dated evidence](evidence/preview-text-reflow-20261005.md) trace a new bounded screen-reading convenience decision, not a legal rule or repair of proved fact loss. Existing App plain-text projection and scroll access remain authoritative; one screen-only stylesheet declaration targets direct fact headings/paragraphs and table cells without extending to warning controls or print media. Both Layer2 reviewers read both complete Layer1 proposals and conditionally accepted narrow ownership. Role separation does not prove heterogeneous-provider execution, runtime AI, benchmark benefit or qualifying GitHub approval. + +Actual diagnostic reachability/native bytes, new-contract repository RED/GREEN, candidate full gates and complete source review remain separate. Geometry and print emulation do not certify human meaning readability, AT speech, WCAG or physical printing/pagination. No legal register, retrieval/effective date, template or readiness rule is added or revalidated. ADR-0005/0006 normalized-fact portability/minimal TXT boundaries remain unchanged and historical legal citations remain historical. + ## Current gap The seven-step workspace now captures the product's intended fact categories, including independent explicit retention applicability, but retention-period/legal-basis detail, third-party provision, international transfer, contact/controller information, and legal-basis review still need requirement-level mappings to the authoritative register, deterministic validation, and regression fixtures before PolicyWeave can claim those steps are legally complete. CSS-level focus contrast and deterministic step-focus transfer now have executable regression contracts, but real-browser accessibility evidence remains required before claiming WCAG conformance. diff --git a/src/App.tsx b/src/App.tsx index 1cb28a3..2b832ac 100644 --- a/src/App.tsx +++ b/src/App.tsx @@ -1,5 +1,6 @@ import { ChangeEvent, useMemo, useState } from 'react' import { AlertTriangle, Check, ChevronDown, ExternalLink, FileText, Link, Save, Upload } from 'lucide-react' +import { createPolicyReviewText } from './policy-review-report' import { createPolicyExport, DraftFacts, getCompletedSteps, getDraftReview, getReview, initialFacts, initialItems, isWebServiceUrl, PolicyItem, restorePolicyExport, steps } from './policy' type FactField = { @@ -38,6 +39,11 @@ function StepActions({ current, setCurrent }: { current: number; setCurrent: (st } +/** Explains the browser-memory boundary before operator input without adding a live announcement. */ +function SessionNotice() { + return

자동 저장되지 않습니다. 새로고침하거나 탭을 닫으면 작성 내용이 사라집니다. 보관하려면 JSON 내보내기를 사용하세요.

+} + /** Renders a scalar-fact authoring step backed by the current draft facts. */ function FactStep({ current, title, description, fields, facts, setFacts, setCurrent }: { current: number @@ -64,6 +70,7 @@ function FactStep({ current, title, description, fields, facts, setFacts, setCur } return

{current}. {title}

{description}

+
사실 기반 입력운영 중인 서비스와 계약·처리 흐름에서 확인한 사실만 입력하세요. 확인되지 않은 내용은 비워 두고 검토 대상으로 남깁니다.

확인 정보

{fields.filter((field) => !field.visibleWhen || facts[field.visibleWhen.key] === field.visibleWhen.equals).map((field) =>