From 3ee5881acea2d17c8d7240287865ba65c5afb570 Mon Sep 17 00:00:00 2001 From: Cristian Tcaci <59696583+Chris0Jeky@users.noreply.github.com> Date: Mon, 21 Sep 2026 23:56:44 +0100 Subject: [PATCH 1/7] docs: reconcile repository direction and v0.3 programme --- .codex/memories/00_ACTIVE.md | 40 +- OUTSTANDING_TASKS.md | 32 +- autodoc/AGENT_INDEX.md | 17 +- docs/IMPLEMENTATION_MASTERPLAN.md | 40 ++ docs/INDEX.md | 9 +- docs/ISSUE_EXECUTION_GUIDE.md | 41 +- docs/REVIVAL_PLAN.md | 35 +- .../2026-09-17-v0.3-release-assessment.md | 8 + ...repository-direction-and-v0.3-programme.md | 334 +++++++++++ docs/releases/V0_3_0_READINESS.md | 554 +++++++++--------- docs/strategy/PRODUCT_DIRECTION.md | 31 +- 11 files changed, 842 insertions(+), 299 deletions(-) create mode 100644 docs/analysis/2026-09-21-repository-direction-and-v0.3-programme.md diff --git a/.codex/memories/00_ACTIVE.md b/.codex/memories/00_ACTIVE.md index ad8f96d406..9b7f4fc795 100644 --- a/.codex/memories/00_ACTIVE.md +++ b/.codex/memories/00_ACTIVE.md @@ -1,6 +1,6 @@ # Active Taskdeck Agent Context -Last updated: 2026-09-11 +Last updated: 2026-09-21 This file is the active-gate pointer for every implementation agent on Taskdeck: Codex reaches it through `AGENTS.md` and `.codex/README.md`, Claude Code through the `CLAUDE.md` orient list (it is not auto-loaded for Claude). It intentionally summarizes routing only; the canonical state remains in `docs/STATUS.md`. @@ -11,6 +11,8 @@ This file is the active-gate pointer for every implementation agent on Taskdeck: - Tier and push/merge authority: `.agent-harness/tier.json` (re-read live; do not infer authority from this summary) - Current shipped state: `docs/STATUS.md` - Active release/wave sequencing: `docs/REVIVAL_PLAN.md` +- Current repository programme brief: `docs/analysis/2026-09-21-repository-direction-and-v0.3-programme.md` +- Live v0.3 gate: `docs/releases/V0_3_0_READINESS.md` - Broader delivery/planning record: `docs/IMPLEMENTATION_MASTERPLAN.md` - Stable invariants: `docs/GOLDEN_PRINCIPLES.md` - Dependency-aware issue execution: `docs/ISSUE_EXECUTION_GUIDE.md` @@ -57,14 +59,34 @@ issue and remote ref before resuming; this pointer does not claim current CI or - Retired, do not resume: `origin/issue-1940/provenance-shortcut@c9135fef3b64da5d6c578bd4d9c76fe4fdb7eb65`. The ref still exists and is not an ancestor of `main`, but the slice it held shipped as PR `#2323` (merge `221aa88c8`), recorded in `docs/STATUS.md`. Recreating a worktree from it would redo landed work. `#1940` stays open for the two MEDIUM residuals named on the issue, not for this branch. -## Lane coordination (2026-09-04) - -- Two implementation lanes run concurrently: `alpha-product-trust` (human work loop: Capture/Inbox, proposals, Review, Board/Paper/Legacy, a11y, product semantics) and `beta-platform-integrity` (runtime, security, delivery, CI, harness). An issue belongs to the lane that owns its primary acceptance outcome, not to whichever layer its files sit in. A programme coordinator session owns issue topology, milestones, Project state, this file, `autodoc/AGENT_INDEX.md` and `docs/releases/V0_3_0_READINESS.md`; it does not implement in a path a lane has leased, and it merges only its own coordination PRs under the ordinary tier gate (`.agent-harness/tier.json` is the authority, not this line). -- Claim before writing: post `[Claude lane claim v2]` on the issue (lane, base SHA, owned paths, shared-path leases, parallel-safe work, status) and `[Claude lane release v2]` with the exact head and result when done. `[Codex lane claim v2]` / `[Codex lane release v2]` are the same protocol with the same fields; search for both forms before claiming, because an existing open PR plus a current claim in either form outranks a new claim. A stale claim is one with no release and no branch activity; the coordinator reconciles it, not the other lane. -- One writer per canonical doc: the lane that merges a slice writes its own bounded `docs/STATUS.md` block and `OUTSTANDING_TASKS.md` tick; cross-lane reconciliation blocks and the readiness view are the coordinator's. Never edit a canonical doc that an open PR already edits without agreeing the order first. -- Control-plane PRs (`.github/workflows/**`, `ci/**`, `scripts/ci/**`, runner or branch-protection paths, and the `ci/policy.v1.json` control paths) merge only after the maintainer's own review plus one fresh-context review (ADR-0066 amendment 2026-09-03). Green is not authority. **SC-10 is closed** (all twelve PRs in that queue merged 2026-09-06), but the 2026-09-06 walkthrough ruling q-1 = A delegated **those twelve named PRs only**; it did not lift the amendment for a new control-plane PR. Practice has diverged three times, on 2026-09-08 (`#2772`, `#2787`) and again on 2026-09-10 (the CI-continuation train), and the divergence is an open human decision: `OUTSTANDING_TASKS.md` J.1, J.2 and J.3. Read J.3 before opening or merging a control-plane PR. A control-plane PR that is parked is recorded on J.2, which is where SC-10's role went when it closed. -- Codex review credits: SC-9 closed 2026-09-06 and the connector was reviewing normally when last observed (2026-09-10). **Read the connector's own comment on your PR rather than this line** - like milestone counts and CI colour, credit state is live GitHub, and this file's preamble says live GitHub outranks it. Standing rules either way: global law 2g, so a clean Codex outcome is the whole review gate for documentation-only or very-low-risk work and other work still gets one fresh-context independent review; and if a usage-limit notice does appear, it is informational, not a finding, and the gate falls back to one fresh-context review per PR. Do not spend a reviewer subagent on the assumption that the connector is unavailable without looking. -- Stacked PRs: a PR whose base is another PR's branch merges into that branch, not `main`. Merge the parent first, always; only after the parent has actually merged, re-target the child with `gh pr edit N --base main`, then confirm the new base via the API before merging it. Never re-target a child whose parent is still open, because that pulls the parent's unmerged commits into the child. Never `--delete-branch` a stacked base PR. +## Current programme routing (2026-09-21) + +- Taskdeck is in v0.3 release convergence. Read the current programme brief and live readiness view + before selecting work. The old alpha/beta lane names are historical coordination aids, not current + ownership authority. +- Live GitHub owns milestone counts, PR state, CI, review and branch ancestry. An open PR inventory is + not an admission list. Select work through the active plan, accepted ADRs, issue dependencies and + current ownership evidence. +- Claim before writing: search both `[Claude lane claim v2]` and `[Codex lane claim v2]`, open PRs, + branches and recent issue comments. An existing current claim or open PR outranks a new claim. +- One writer per canonical doc. The implementation owner writes the bounded shipped-truth update for + its merged slice; programme-wide reconciliation and the release readiness view remain + coordinator-owned. Do not edit a canonical document already touched by an open PR without an + explicit integration order. +- Stacked PRs are dependency graphs. Verify the actual base and parent head through GitHub. Merge the + parent first, refresh/retarget the child only after the parent lands, and rerun exact-head evidence. + Never infer that a mergeable stacked child is independently ready for `main`. +- Any base refresh, merge from `main`, stack collapse, review repair or generated-file change creates + a new exact head. Earlier green CI and review are historical until the current head is qualified. +- Current release-control state: merged foundations `#3156`/`#3167`; open parent `#3295` before + stacked child `#3296`; CI-17 inventory `#3297` before implementation `#3170`; post-merge Windows + timeout reconciliation after `#3162`; remaining `#2335` acceptance after merged `#2838`; corrected + runner work after FIX-FIRST recovery PR `#3261`. +- Control-plane work still follows ADR-0066 and `OUTSTANDING_TASKS.md` section J. Green is evidence, + not merge authority. The September directives are recorded per named wave; they do not silently + settle the standing rule for every future control-plane PR. +- Read the review connector's live result. A usage-limit notice is informational, not a finding. Use + the repository's documented fresh-context fallback when the connector cannot review. ## Start of session diff --git a/OUTSTANDING_TASKS.md b/OUTSTANDING_TASKS.md index ddb1ce6b1b..dac14187de 100644 --- a/OUTSTANDING_TASKS.md +++ b/OUTSTANDING_TASKS.md @@ -9,7 +9,7 @@ 4. **Add new outstanding tasks here** when the maintainer asks you to remember something, or when substantial work is deferred. Keep entries short with a one-line "how" and a link to the GitHub issue/PR that holds the detail. 5. Keep this file lean and scannable. Detail lives in the linked issues, not here. -Last reviewed: 2026-09-19 +Last reviewed: 2026-09-21 - [x] **Ratify the remaining dogfooding decision batch.** ADR-0060 is owned by `#2084`, ADR-0061 by `#1772`, and ADR-0062 by `#2091`. Decide Project timing, multi-board identity, hierarchy boundaries, first item types, custom-field timing, actual-time-tracking fit, and whether `#2012` blocks any future public managed-service path. The private-host/cost/backup decisions are item **CL-1** below. The maintainer had fixed the release targets (v0.2 final 2026-09-01; v0.3 RC 2026-09-04; v0.3 final 2026-09-08 or 2026-09-09) — *superseded 2026-08-30 by RC deck q-6: v0.2.0 shipped 2026-08-29 and v0.3 has no dates, "we ship when the release is ready"* — waived the weekly intake cap only for `#2092`-`#2094`, and deferred general optimistic concurrency to the Stage 2 small-team alpha. Until the remaining choices are ratified, `Board -> Column -> Card` and review-first automation remain authoritative. *(2026-08-29, walkthrough q-1 = A: **dedicated ratification session** — one decision brief per ADR with per-question options is prepared in `docs/analysis/2026-08-29-adr-0060-0062-ratification-briefs.md`.)* *(**Checked off 2026-08-29 (later sitting):** the maintainer ratified all three in-session — q-2 B (ADR-0060 **Accepted**, with scope notes: multi-board identity + hierarchy boundaries go to architecture review `#2187`, prompted cascade allowed for parent archive, compatibility-ladder review `#2188`), q-3 A (ADR-0061 **Accepted as direction only, evidence pending**; three CL-1 values still pending — see CL-1), q-4 A (ADR-0062 **Accepted**, cross-cutting contract amended). Every decision this item named is recorded in the ADRs' "Decisions recorded (2026-08-29)" sections and on `#2084`/`#1772`/`#2091`; the `#2012` interaction is recorded as a hard gate on any public managed-service path. Rule-3 authorization = the in-session replies.)* @@ -159,6 +159,8 @@ Analysis docs: `docs/PROJECT_TRAJECTORY.md` (strengths + path) and `docs/COURSE_ The maintainer directed (2026-08-30) that the repository goes **private for the v0.3.0 release** on a **personal GitHub Pro account** with no Team/Enterprise dependency. Tracker CI-00 `#2324`; executable cutover checklist CI-13 `#2337`; baseline `docs/ci/CI_BASELINE.md`. +**Current execution order (reconciled 2026-09-21):** finish the pre-cutover evidence, mirror/GHCR, storage and runner proofs; make the development repository private; only then register the stable Smart CI gate; run CI-17 with every self-hosted runner unassociated; associate only already-proven runners after that rehearsal. Final tag creation and publication happen later. The detailed order is `docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md` and `#2337`. + - [x] **SC-1 — CI-00 delegated rulings — confirm or overturn (`#2324`).** Nine rulings made under the 2026-08-30 directive (personal-account mode; base-ref control plane; one stable `Smart CI / Required Gate` + branch-current; hosted-by-default execution mode; Linux baseline + Windows contract; tree-SHA landed verifier; shadow-first selection; change-driven nightly with mutation manual; storage first). Overturning any is one reply on `#2324`. *(**Confirmed 2026-09-03, maintainer decision packet SC1, with the private-Pro approval-boundary amendment:** all nine rulings stand; the amendment records that a personal Pro private repository has no organization ruleset or required-workflow boundary, so the approval boundary is the maintainer's own account — hosted-only execution (ruling 4) until CI-04 proves the isolated runners, the read-only `pull_request_target` control plane, and the maintainer's review plus the fresh-context review before any control-plane (T0/T2) or runner change. GitHub's workflow-run approval setting covers fork/outside-contributor runs only and gates **nothing** for a branch an agent pushes to this repository; that same-repo residual (ADR-0066 Decision 8) stays recorded and is closed only by the CI-14 `#2338` organization path. Recorded on `#2324` (with the correction) and in ADR-0066 as amended in PR `#2442`.)* - [x] **SC-2 — artifact storage before cutover (`#2333`, CI-09).** Measured 2026-08-30: **372.1 GB of unexpired artifacts** (359 GB are exported container images from `reusable-container-images.yml` at the default 90-day retention, oldest 2026-06-02) against the 1 GB Pro allowance; GitHub bills private-repository storage per GB-day, so this is the first cost the moment the repository is private. Agent side: retention classes in the workflows (PR on `#2333`) + the dry-run deletion command `node scripts/ci/smart-ci/artifact-cleanup.mjs --name-prefix container-image-artifacts --older-than-days 1` (2026-08-30 scoped dry run: **1,412 PR-lane candidates = 245.9 GB**; 520 artifacts from `main`/tag runs are excluded by design; nothing deleted; deletion needs `--delete --ids-file --confirm-count 1412`). **Human:** authorize the one-time deletion of the expired-by-policy artifacts (destructive; agents do not run it unasked) or record an accepted spend on `#2337`. *(**Executed 2026-09-03 under the maintainer decision packet SC2 = "authorize bounded deletion after a fresh dry run."** Fresh dry run: 1,499 PR-lane `container-image-artifacts` candidates = 263.3 GB (35,640 listed; 554 `main`/tag artifacts excluded by design). First delete pass aborted fail-closed on a 1,499→1,498 drift (one artifact expired in between), re-run with the re-verified count and killed by the host at ≥1,300 deleted with 0 failures; a third fresh dry run found the remaining 114 = 16.0 GB and deleted 114/114, 0 failed. **Total: 1,498 artifacts, about 263.2 GB, removed; zero `main`/tag artifacts touched.** Evidence on `#2333`. The retention classes (PR `#2408`, **merged 2026-09-04 00:47Z**, merge `f5163d3cb`) and the storage ledger remain CI-09 engineering work, not human actions.)* - [x] **SC-3 — plan confirmation and spend ceiling (`#2337` A/B1).** Confirm the account is GitHub Pro, set a monthly Actions spend ceiling + alert, and verify how the Codex GitHub App and Copilot code review are billed on a private repository. *(**Re-ruled 2026-09-03 by the maintainer in-session, superseding the packet's $10/month value: SC-3 is deferred — no paid overage ceiling is set.** The GitHub Pro plan is **confirmed** and its included 3,000 minutes/month are the whole hosted budget, spent on **Linux** jobs only; Windows (x2) and any macOS (x10) legs run locally — the laptop runner once CI-04 `#2328` registers it, agent-run proving checks until then — or carry a local fallback, never hosted overage. GitHub's default $0 spending limit is the effective hard ceiling. **Still the maintainer's:** read the Billing → Spending limits page at cutover step J.7 to confirm the limit is $0 and record it on `#2337`; verify Codex/Copilot billing on a private repository. Recorded on `#2337`, `#2324`, `#2328`, `#2331`, checklist A and ADR-0066.)* *(**Ticked 2026-09-06, 2026-09-06 guided-walkthrough reply q-5 = A, values supplied in-session (`map:v1:e5beef60c3235e76726721636988f12e53ad55368f875b9a64c8ce71ae621b93`):** Billing → Budgets shows a **$0** Actions budget; a GitHub budget caps spend only when its "stop usage when limit is reached" toggle is on, and that toggle was not read in the first pass; **confirmed on in the second pass (2026-09-06, q-22 = A, `map:v1:cfe8e597c6d5bbb5fac7db58f3e09fa8b62dab8f624eb25f77af37ab971c0451`), so the $0 budget is a hard ceiling** and the J.7 residual is closed; the Codex connector bills through the maintainer's OpenAI subscription, its review allowance refreshes on that subscription's daily cycle and it reaches private owned repositories, so no GitHub-side billing applies; Copilot is the Student offer (134/200 included AI credits at read time, additional usage not enabled, $0 budget) and is not relied on. Recorded on `#2337`.)* @@ -200,6 +202,33 @@ The maintainer directed (2026-08-30) that the repository goes **private for the - [ ] **Acknowledge (or direct a revert of any of) the twenty control-plane merges below, and answer J.3 (b) so the next wave has a standing rule.** On 2026-09-18 the maintainer directed, in-session, "keep working through the PRs (open and draft), deal with them end-to-end, ensure they're correct, and ultimately merge them". A coordinator plus five worker sessions then took 76 open PRs to merge (72 merged, 2 closed as duplicates, 2 still gating at the time of this row). Each PR got one fresh-context adversarial review by a worker that was not its author, exact-head green `ci-required` and a three-minute aging window; Codex review credits were exhausted for the whole wave, so the connector reviewed none of them. Twenty of the merges touch `ci/policy.v1.json` control paths and were merged under that directive rather than the ADR-0066 per-PR maintainer review, each with a disclosure comment on its thread: `#3167` (`fd1381be9`, landed-verifier decision core; residuals on `#3227`), `#3140` (`328dbfd01`), `#3139` (`531c7a0a9`), `#3154` (`50b4c989f`), `#3149` (`ae1d25010`), `#3143` (`bcb446965`, adds a PowerShell step to the required Windows API Integration job), `#3156` (`409291f79`), `#3162` (`eb8174977`, `--blame-hang`/`--diag` on API integration), `#2931` (`3ae88426a`, mutation smoke; two defects fixed that its own fixtures masked), `#3212` (`92000c9e3`), `#3213` (`ae649062b`), `#3196` (`af8d2f6b9`), `#3168` (`8dce5f60a`), `#3169` (`a259f16f3`), `#3113` (`ceacb43a8`), `#3111` (`f4aeb2b72`, release-container contract; declined MEDIUM on `#3244`), `#2838` (`32e2374ef`, `persist-credentials: false` on all 48 checkout steps and Pages permission scoping; this lifts the J.3 park), `#3171` (`3dcb05de4`), `#3190` (`3f2b53772`) and `#3130` (`2a73b7473`, GitHub Pages static demo mode; `pages-frontend.yml` gains `VITE_DEMO_MODE`; residual on `#3246`). Counting honestly with J.1 to J.3: **thirty-six** control-plane merges are now awaiting a reply across the four rows. Two things happened during the wave that the standing rule should weigh: the required `API Integration (windows-latest)` job hit its 45-minute ceiling three times with zero test failures under runner contention (recorded on `#3158`), and the required `Frontend Unit` bundle-size gate was found to be measuring a test-mode rebuild about 20% larger than the shipped bundle (fixed by `#3243`, not control-plane). Follow-up issues opened by the wave: `#3227`, `#3228`, `#3229`, `#3237`, `#3241`, `#3242`, `#3244`, `#3245`, `#3246`, `#3247`, `#3248`, `#3249`. +### J.5. Current v0.3 release-control checkpoint (2026-09-21) + +This row consolidates the human actions that remain after the merged release-assessment pass and the +September 18-21 implementation wave. It does not replace the detailed evidence and order on `#2337`, +`#2439`, `#3170`, or the private-cutover checklist. Historical parked wording in J.3 is not current: +`#2838`, `#3156`, `#3162`, and `#3167` are recorded as merged in J.4. + +- [ ] Record the standing review/merge rule for **new** ADR-0066 control-plane PRs after the named + September directives. J.3(b) remains unanswered; do not infer a permanent waiver from a completed + wave. +- [ ] Review the current landed-verifier and CI-17 stacks in dependency order: parent `#3295` before + stacked child `#3296`, and non-activating inventory `#3297` before the actual `#3170` rehearsal + control. Automated green evidence is not the human approval. +- [ ] Approve or reject the corrected current-main runner-bootstrap slice after the FIX-FIRST nested + reparse-point gap recorded on recovery PR `#3261` is closed. Do not register a runner from that + stale branch. +- [ ] Authorize the exact current storage deletion set from `#2333`; a count or old inventory is not + authorization. +- [ ] Create `Chris0Jeky/taskdeck-release`, disable mirror Actions, create the narrowly scoped + publishing credential, and make release GHCR packages public before repository privacy, as owned + by `#2439`/`#2337`. +- [ ] Execute the visibility, required-check, branch-policy and runner-association sequence on + `#2337`: privacy first, then stable gate registration, CI-17 with runners unassociated, then only + already-proven runner association. +- [ ] Approve the frozen final commit, real `v0.3.0` tag, private Release, public mirror publication, + anonymous verification and announcement in that order. + ## K. v0.3 residual decision batch (2026-09-05, from the alpha lane's read-only audit of 15 milestone issues) — human actions Source: the alpha lane audited 15 open v0.3 issues on 2026-09-04 against `main` `61e94f672` to `8c511205d`, each audit adversarially re-verified read-only, and handed the coordinator the gates that need a maintainer answer. Everything agent-decidable from the same audit is already queued on the lanes without a ruling (#2215, #2214, #1307 batch-approve parity, #2007 AC5+AC6, #1968 Legacy-truthful shortcut map, #2009 contrast-guard pins, #1284 view-level regression, #1961 board-store dedupe, #2501 MEDIUM-2). Answer by letter on the issue named in each item, or in one reply here; each audit item says what the answer unblocks and names a proposed default, which is the direction the agents would recommend, not authorization to act while the item is unanswered (D-12 was ruled in-session on 2026-09-05 and is closed). Nothing below is built, closed, moved or re-titled until its letter is recorded here or on the issue (D-12 was ruled in-session on 2026-09-05; D-1 to D-11 and D-13 to D-15 were ruled in-session on 2026-09-06 through the guided walkthrough, each row carrying its letters). @@ -224,6 +253,7 @@ Source: the alpha lane audited 15 open v0.3 issues on 2026-09-04 against `main` ## Changelog +- 2026-09-21 (repository direction and release-programme reconciliation): **Added §J.5; no item checked.** Consolidated the still-human release-control actions after the September 18-21 wave, preserved J.3(b) as open, named the active Smart CI/CI-17 dependency order, and restated that privacy, package visibility, branch protection, credentials, runner association and final publication remain explicit human actions. `Last reviewed` bumped to 2026-09-21. - 2026-09-19 (PR recovery wave closeout): **One new `[ ]`: §J.4.** No item was checked. Twenty control-plane PRs merged 2026-09-18/19 under the maintainer's in-session directive to work every open PR to merge, disclosed per PR on-thread and listed on the row with merge SHAs; `#2838`'s J.3 park is lifted by that directive, and J.3 (b) is still unanswered. `Last reviewed` bumped to 2026-09-19. - 2026-09-10 (coordination reconciliation pass): **One new `[ ]`: §J.3.** No item was checked. Twelve control-plane PRs merged outside the ADR-0066 per-PR review: the eight-PR CI-continuation train (`#2863`, `#2864`, `#2865`, `#2867`, `#2868`, `#2869`, `#2871`, `#2878`) on 2026-09-10 against the R4 gate the seven `ci/continuation-*` bodies declared, plus `#2832`, `#2834` (both 2026-09-09), `#2858` and `#2866` (both 2026-09-10), found by sweeping every merge since 2026-09-08 against all 36 `ci/policy.v1.json` control paths rather than by following the train. `#2866` is a different failure mode: a product PR that touched `scripts/deploy/**`, which `ci/policy.v1.json` does declare, but for which `.claude/rules/ci-control.md` never loaded, because its three globs reached only 10 of the 36 declared entries. What is verified is that the rules region did not fire, not what the authoring agent knew. PR `#2925` widens that frontmatter to all 36. Their tracker is CI-12 `#2336`, which records the session as maintainer-requested and, at 02:40:20Z, "the maintainer's 2026-09-10 request to finish implementation, merging, testing and CI improvements" - so the row asks whether that request supplied the per-PR review the amendment wants, and separately asks for the standing rule for the *next* control-plane PR. The row also records the train's quality: one confirmed HIGH (a trusted verifier bypassed through a Windows directory junction) was fixed in `cdc6d8e9f` at 09:49:14Z and is an ancestor of `#2871`'s 10:23:22Z merge, so the gap is procedural, not a shipped known defect. Measured, not inferred: merge SHAs and times from the API, control-path scope from each PR file list against `ci/policy.v1.json`, the fix ordering by `git merge-base --is-ancestor`, and 7/7 on `export.test.mjs` at current `main`. Outside this file the same pass corrected `.codex/memories/00_ACTIVE.md`, which had been telling both lanes since 2026-09-04 that Codex review credits were exhausted (they are not) and that control-plane PRs park under SC-10 (SC-10 closed 2026-09-06; parking is J.2's now). `Last reviewed` bumped to 2026-09-10. - 2026-09-07 (device-verification pass, PR `#2768`): **Rule 3 relaxed, one `[x]`, one new row.** *Rule 3* now permits an agent to check an item off when completion is fairly clearly established, not only when the maintainer explicitly says so — maintainer directive given in-session ("tasks can be marked as completed if it's inferred fairly clearly that it has been completed"); a related PR merely being opened still is not completion, and human decisions/approvals are still never inferred (global law 5). **Checked off** on the same directive ("Make the key as completed as well"): *Set `Llm__OpenAi__ApiKey` on the second dev machine* — the OneDrive/Middlesex laptop now carries the key and all three live-provider gates at User scope, the `gpt-4o-mini` model pin is gone from every scope, and a live OpenAI call succeeded twice (`?probe=true` returned `verificationStatus: "verified"`, `isMock: false`, 2777 ms; the **Verify LLM** button turned the banner green at 1488 ms on `gpt-5.6-luna`). **Added:** *rotate the OpenAI key* — the verification proves the value reported as byte-identical to a previously exposed key is live and accepting requests, which makes rotation urgent; agents cannot perform it. **Left open:** the frontend-suite row — both 2026-08-20 blockers (unhydrated `.env`, Node below the pin) are cleared and the suite executes (377 files, 5976 passing), but the broad proving command has still never exited 0 here: it exits 1 under worker-startup contention, and with the API stopped it wedges entirely on `ECONNREFUSED :5000` because `src/api/versionApi.ts` fetches `GET /health/live` over real axios. Two P1 Codex findings on `#2768` (agent self-check-off; calling an exit-1 run green) were both confirmed and fixed before the rule change landed. diff --git a/autodoc/AGENT_INDEX.md b/autodoc/AGENT_INDEX.md index 143f736234..e2c13e4967 100644 --- a/autodoc/AGENT_INDEX.md +++ b/autodoc/AGENT_INDEX.md @@ -1,14 +1,6 @@ # Agent Index - Taskdeck (seam map) -Last-Verified: 2026-09-18 (Grok adapter routing only: `.grok/` plus Claude-compat skill loading; seam -table not re-measured). Prior: 2026-09-10 (orient-section file sizes and the region-rule list re-measured 2026-09-10 against `main` `a1f797913`; private audio-answer row verified with SQLite/API/component/Chromium tests; PWA/offline row re-verified 2026-09-05 in a real Chromium under `#2639`; the frontend, -transcript, Smart CI and docs rows re-verified 2026-09-03 against `main` `d629129f3`; Context Fabric -verified 2026-08-30 after CF-01 `#2255`; -agent-inventory routing verified 2026-08-18; MCP/container and map-reduce seams remain verified -2026-08-02; the rest retain the 2026-07-13 exploration). Re-verify when a seam moves; treat a stamp -older than ~90 days as stale (a wrong map misroutes — worse than no map). **Any edit to this file -bumps the stamp**, including one that only adds a row: an unbumped stamp claims verification the edit -did not do. +Last-Verified: 2026-09-21 (orientation, current programme routing, documentation authority, and Smart CI/release-control pointers re-measured against `main` `f001dd921`; implementation seam rows retain their own earlier evidence unless stated). Re-verify when a seam moves; treat a stamp older than ~90 days as stale. **Any edit to this file bumps the stamp.** This is the repo's seam map — a fast orientation layer for coding agents. It points to interfaces, invariants, and verification commands; it does not duplicate implementation. @@ -27,8 +19,7 @@ It is the Taskdeck equivalent of the harness `AGENT_MAP.md` (grandfathered name) `docs/IMPLEMENTATION_MASTERPLAN.md` (about 2,360 lines — also section-read only, never bulk-read). Both counts are approximate on purpose: they are there to tell you the file is too big to bulk-read, not to be exact. Human-action file: `OUTSTANDING_TASKS.md`. - Strategy spine: `docs/strategy/PRODUCT_DIRECTION.md` → `docs/REVIVAL_PLAN.md`. Decisions: - `docs/decisions/INDEX.md`. + Strategy spine: `docs/strategy/PRODUCT_DIRECTION.md` -> `docs/REVIVAL_PLAN.md`. Current programme: `docs/analysis/2026-09-21-repository-direction-and-v0.3-programme.md`. Live v0.3 gate: `docs/releases/V0_3_0_READINESS.md`. Decisions: `docs/decisions/INDEX.md`. Dated assessments are evidence, not current authority. - Contract: `AGENTS.md`. Invariants: `docs/GOLDEN_PRINCIPLES.md`. Skills: `.claude/skills/` (canonical; Claude and Grok via compatibility) and `.codex/skills/` (Codex adapter). There is no `.grok/skills/`. @@ -57,8 +48,8 @@ It is the Taskdeck equivalent of the harness `AGENT_MAP.md` (grandfathered name) | Frontend workspace | `frontend/taskdeck-web/src/`: `router`, `views`, `store/board*`, `composables/`, `api/http.ts`, `components/ui` (18 `Td*`) | Review-first UI gating; per-board SignalR (`useBoardRealtime.ts`), not global; `boardStore` is a facade over `store/board/*`; all HTTP through `api/http.ts` | `npm run typecheck`, `npm run build`, `npx vitest --run` (OOM-prone: `--maxWorkers=2`/targeted), Playwright (see `frontend/taskdeck-web/CLAUDE.md`). **`vitest --run` is not full coverage:** `vitest.config.ts:15` excludes `tests/pwa-generated-worker.spec.ts`, so a `vite.config.ts` workbox or `src/pwa/**` change is unproven until you also run `npm run test:pwa-generated-worker` (it builds first). See the PWA row. | | PWA / offline / cache boundary | `frontend/taskdeck-web/vite.config.ts` (the `runtimeCaching` block), `frontend/taskdeck-web/src/pwa/` (`runtimeCachePolicy.ts`, `legacyApiCache.ts`, `legacyApiCacheWorker.ts`, `staleBundleRecovery.ts`), `frontend/taskdeck-web/public/api-cache-cleanup.js`, `backend/src/Taskdeck.Api/Middleware/ApiCacheControlMiddleware.cs`; behaviour contract `docs/platform/PWA_OFFLINE_BEHAVIOR.md` | **No runtime cache may ever admit an API response** (`#2350`, PR `#2381`; `#2411`): the service worker is network-only for the API and `ApiCacheControlMiddleware` stamps `no-store, private` server-side, so neither the worker nor the browser cache holds identity-bound data. Only two Workbox `runtimeCaching` handlers exist: `StaleWhileRevalidate` for lazy `it`/`es` locale chunks and `CacheFirst` for assets under `/assets/` and `/icons/`. The build normalizes `VITE_API_BASE_URL`; shared build-time factories create full-URL regular expressions that exclude both the default `/api` path and the configured API base before admitting build-owned paths. That includes a base nested under an emitted directory such as `/assets/api`; malformed or ambiguous configuration produces a match-nothing predicate. **The boundary is configuration-aware but not origin-anchored:** the matchers allow any HTTP or HTTPS authority and the static cache accepts statuses `[0, 200]`, so an opaque third-party response under a matching static path can be admitted; default and configured API paths remain excluded. A pre-`#2350` installation still runs a NetworkFirst worker that repopulates the authenticated cache, so retirement is not left to the `registerType: 'prompt'` update banner: the page probes the controlling worker over a `MessageChannel`, treats silence as pre-`#2350`, then follows the replacement through `updatefound`/`statechange` to `installed` before messaging skip-waiting, because `registration.update()` resolves inside Install so a read taken *at the moment it resolves* finds `waiting` still null. The separate up-front `registration.waiting` read at `legacyApiCacheWorker.ts:191` is deliberate, covering a replacement already waiting because the user dismissed the update banner - **do not delete it**. The whole migration is **fail-closed** and gates identity: failure clears credentials (`router/index.ts:390`) and blocks session establishment (`sessionStore.ts:71-73,188-191`), bounded by `RETIREMENT_DEADLINE_MS = 12_000`. `public/api-cache-cleanup.js` sweeps twice: once at script evaluation (one-time, guarded by the `taskdeck-pwa-cache-policy-v2` marker) and once unconditionally inside `event.waitUntil` on `activate`, which is what covers an entry the old worker admits during install. That `waitUntil` holds the worker in `activating` so nothing is **served** from a half-swept cache, but it does **not** abort activation on error (the spec aborts only on a rejected *install*) and page script reading `CacheStorage` can still observe the pre-sweep state until the worker reaches `activated`. **`#2639` re-measured 2026-09-05:** the claim that the `activate` listener never fires because `vite-plugin-pwa` emits `importScripts` inside its async AMD factory does **not** reproduce in Chromium 151 - the listener fires on first install, on the skip-waiting migration and after a CDP-forced worker restart. The ordering is unspecified rather than broken, and `vite.config.ts` now hoists that call to offset 0 of `dist/sw.js` (`src/pwa/hoistWorkerImportScripts.ts`, build fails if it cannot) so it stops depending on microtask scheduling | `src/pwa/runtimeCachePolicy.ts` owns both the testable pathname predicates and the build-time factories imported by `vite.config.ts`. Workbox serializes the returned `RegExp` objects into `sw.js`, so the generated worker has no free identifiers. `tests/runtime-cache-policy-parity.spec.ts` pins the config-to-factory relationship; run it for any predicate change. Then `npx vitest --run --maxWorkers=2 src/tests/pwa/` and `src/tests/router/startupCacheBoundary.spec.ts`; **`npm run test:pwa-generated-worker`** for the generated worker, which `vitest.config.ts:15` excludes from the default run; `ApiCacheControlApiTests`; E2E `tests/e2e/pwa-api-cache.spec.ts` plus `tests/e2e/pwa-proof-strict.spec.ts` (both gated on `TASKDECK_E2E_PWA_PREVIEW=1` and run through `playwright.pwa-proof.config.ts`, which has no `webServer`: start the backend and a `vite preview` of a production build yourself) | | Agent runtime & MCP | `Application` (`AutomationPolicyEngine`), **MCP surface in `Api`** (`Program.cs` `--mcp` branch, `Api/Mcp/*`), `.codex/config.toml`, `.mcp.json`, `.grok/config.toml` (permissions only — no MCP servers), `docs/MCP_TOOLING_GUIDE.md` | Policy evaluated before execute; egress/telemetry guards; tool registry; Docker MCP gateway is user-scope only | security tests, MCP inventory/egress tests | -| Agent tooling / CI / docs | `.claude/`, `.codex/`, `.grok/` (README + permissions; Grok loads `.claude/skills/`), `scripts/github/Invoke-TaskdeckReadOnlyInventory.ps1`, `scripts/agent_hooks/` (manual ledger projection only), `.github/workflows/` (`ci-required.yml` = the required CI evidence; `smart-ci-shadow.yml` = the shadow planner + observation-mode gate, **landed** and now running `Smart CI / Plan`, `Smart CI / Planner Self-Test` and `Smart CI / Required Gate` on every PR), `ci/policy.v1.json` + `scripts/ci/smart-ci/` (planner `plan.mjs` and gate evaluator `evaluate-gate.mjs` from CI-02, plus the CLIs `measure-ci-estate.mjs`, `recall-report.mjs`, `action-pins.mjs`, `artifact-cleanup.mjs` and `resolve-merge-ref.mjs` (`#2401`, PR `#2404`); map `docs/ci/SMART_CI.md`, tracker CI-00 `#2324`), `scripts/check-*.mjs` | Delegated shell-backed inventory enters through the opt-in read-only argv wrapper; direct Git/GitHub mutation stays coordinator-owned; review and merge disposition come from live authority plus the canonical global pipeline; no Taskdeck-owned runtime hooks or local command-deny list; Smart CI is in **shadow mode** — the planner and gate change no job selection until the recall report (CI-02 `#2326`) and the gate is registered only by the maintainer (CI-03 `#2327`); CI-control paths (`.github/**`, `ci/**`, `scripts/ci/**`) are R4/T2 and qualify hosted-only, never on a self-hosted runner; the repository goes private for v0.3.0 by maintainer action only (CI-13 `#2337`) and no self-hosted runner is attached while it is public | `powershell -NoProfile -ExecutionPolicy Bypass -File scripts/github/Invoke-TaskdeckReadOnlyInventory.ps1 -SelfTest`; failure-ledger synchronization unittest, settings/tier parsing, worktree helper suite when touched, then docs gates (see `scripts/agent_hooks/CLAUDE.md`); `node --test scripts/ci/smart-ci/*.test.mjs` when `ci/**` or `scripts/ci/smart-ci/**` change | -| Docs & planning | `docs/STATUS.md`, `docs/IMPLEMENTATION_MASTERPLAN.md`, `docs/ISSUE_EXECUTION_GUIDE.md`, `docs/TESTING_GUIDE.md` | STATUS is source of truth for shipped reality; keep governance line intact | `node scripts/check-docs-governance.mjs`, `node scripts/check-golden-principles.mjs`, `node scripts/check-doc-links.mjs` | +| Agent tooling / CI / docs | `.claude/`, `.codex/`, `.grok/` (README + permissions; Grok loads `.claude/skills/`), `scripts/github/Invoke-TaskdeckReadOnlyInventory.ps1`, `scripts/agent_hooks/` (manual ledger projection only), `.github/workflows/` (`ci-required.yml` = the required CI evidence; `smart-ci-shadow.yml` = the shadow planner + observation-mode gate, **landed** and now running `Smart CI / Plan`, `Smart CI / Planner Self-Test` and `Smart CI / Required Gate` on every PR), `ci/policy.v1.json` + `scripts/ci/smart-ci/` (planner `plan.mjs` and gate evaluator `evaluate-gate.mjs` from CI-02, plus the CLIs `measure-ci-estate.mjs`, `recall-report.mjs`, `action-pins.mjs`, `artifact-cleanup.mjs` and `resolve-merge-ref.mjs` (`#2401`, PR `#2404`); map `docs/ci/SMART_CI.md`, tracker CI-00 `#2324`), `scripts/check-*.mjs` | Delegated shell-backed inventory enters through the opt-in read-only argv wrapper; direct Git/GitHub mutation stays coordinator-owned; review and merge disposition come from live authority plus the canonical global pipeline; no Taskdeck-owned runtime hooks or local command-deny list; Smart CI is in **shadow mode** - the planner and gate change no job selection until the recall report (CI-02 `#2326`) and the gate is registered only by the maintainer (CI-03 `#2327`); CI-control paths (`.github/**`, `ci/**`, `scripts/ci/**`) are R4/T2 and qualify hosted-only, never on a self-hosted runner; the repository goes private for v0.3.0 by maintainer action only (CI-13 `#2337`); CI-17 `#3170` must first prove a fail-closed Linux-only rehearsal across the workflow graph, and no self-hosted runner is associated until that post-privacy rehearsal passes | `powershell -NoProfile -ExecutionPolicy Bypass -File scripts/github/Invoke-TaskdeckReadOnlyInventory.ps1 -SelfTest`; failure-ledger synchronization unittest, settings/tier parsing, worktree helper suite when touched, then docs gates (see `scripts/agent_hooks/CLAUDE.md`); `node --test scripts/ci/smart-ci/*.test.mjs` when `ci/**` or `scripts/ci/smart-ci/**` change | +| Docs & planning | `docs/STATUS.md`, `docs/analysis/2026-09-21-repository-direction-and-v0.3-programme.md`, `docs/releases/V0_3_0_READINESS.md`, `docs/IMPLEMENTATION_MASTERPLAN.md`, `docs/ISSUE_EXECUTION_GUIDE.md`, `docs/TESTING_GUIDE.md` | STATUS is source of truth for shipped reality; keep governance line intact | `node scripts/check-docs-governance.mjs`, `node scripts/check-golden-principles.mjs`, `node scripts/check-doc-links.mjs` | ## Interface-On-Top Convention diff --git a/docs/IMPLEMENTATION_MASTERPLAN.md b/docs/IMPLEMENTATION_MASTERPLAN.md index 9cc8f6b6bb..a7cd53aa49 100644 --- a/docs/IMPLEMENTATION_MASTERPLAN.md +++ b/docs/IMPLEMENTATION_MASTERPLAN.md @@ -1,5 +1,45 @@ # Taskdeck Implementation Masterplan +## Current programme integration (2026-09-21) + +Taskdeck is in v0.3 release convergence. The product ladder remains unchanged; the current work is +making the existing Accountable Agents + Downloadable Beta claim trustworthy under concurrency, +credential/session replacement, private-repository CI, exact-tag release qualification and public +source/package continuity. + +Current engineering direction: + +- bind asynchronous completion to explicit route, session, credential, request-generation and object + owners; +- separate durable commits from post-commit best-effort tails; +- read one authoritative snapshot or versioned evidence set per decision; +- distinguish unavailable data from authoritative empty state; +- bind CI receipts and release evidence to repository, workflow, event, head/tree, policy and + unexpired artifact identities; +- finish release-control dependencies before broadening v0.4 scope. + +Current release-control order: + +1. finish admitted exact-identity correctness stacks without widening into adjacent refactoring; +2. landed receipt foundations are merged in `#3156` and `#3167`; qualify active parent `#3295` + before stacked child `#3296`, then add authoritative collector/workflow integration; +3. qualify non-activating CI-17 inventory `#3297`, then implement trusted rehearsal control `#3170`; +4. close release prerequisites: post-merge Windows timeout evidence and `#2378`/`#2588`, remaining + `#2335`/CodeQL acceptance after merged `#2838`, storage `#2333`, nightly/exact-tag qualification + `#2334`, corrected current-main runner preparation for `#2328`, and mirror/GHCR continuity + `#2439`; +5. reconcile the milestone through `#2235`, preserving explicit residual rulings; +6. execute the human cutover `#2337`; +7. freeze the final head, create and qualify the real tag, publish the private Release, mirror it + publicly, verify anonymously, and announce. + +The current rationale, admission policy and full dependency map are in +[`docs/analysis/2026-09-21-repository-direction-and-v0.3-programme.md`](analysis/2026-09-21-repository-direction-and-v0.3-programme.md). +The live release gate is [`docs/releases/V0_3_0_READINESS.md`](releases/V0_3_0_READINESS.md). Entries +below remain delivery history or narrower implementation notes; they do not override this current +programme order or live GitHub. + + Last Updated: 2026-09-19 ## GitHub Pages static demo (2026-09-17) diff --git a/docs/INDEX.md b/docs/INDEX.md index ed1108c76c..891da7afa3 100644 --- a/docs/INDEX.md +++ b/docs/INDEX.md @@ -53,7 +53,7 @@ Stable reference material belongs in topical subfolders. - Regular product user: - `START_HERE.md` -> `manual/02_home_and_today.md` -> `manual/03_projects_and_cards.md` -> `manual/08_recipes.md` - Maintainer or planner: - - `strategy/PRODUCT_DIRECTION.md` -> `STATUS.md` -> `REVIVAL_PLAN.md` -> `IMPLEMENTATION_MASTERPLAN.md` -> `ISSUE_EXECUTION_GUIDE.md` -> `TESTING_GUIDE.md` + - `strategy/PRODUCT_DIRECTION.md` -> `STATUS.md` -> `analysis/2026-09-21-repository-direction-and-v0.3-programme.md` -> `REVIVAL_PLAN.md` -> `releases/V0_3_0_READINESS.md` -> `IMPLEMENTATION_MASTERPLAN.md` -> `ISSUE_EXECUTION_GUIDE.md` -> `TESTING_GUIDE.md` - active execution order: the revival **phases** in `REVIVAL_PLAN.md` (truth + safety → transcript engine → open-beta launch → checkpoint). *Historical:* the archive-pivot waves (2026-06-13→2026-07-10, superseded by ADR-0044 but retained as the checkpoint fallback), `PROJECT_TRAJECTORY.md`/`COURSE_CORRECTION.md` (2026-07-02 analysis pair), root `taskdeck-12-week-roadmap-v4.md`, tracker `#972` - Contributor or agent: - `STATUS.md` -> `IMPLEMENTATION_MASTERPLAN.md` -> `GOLDEN_PRINCIPLES.md` -> `ISSUE_EXECUTION_GUIDE.md` -> `MCP_TOOLING_GUIDE.md` -> `../autodoc/AGENT_INDEX.md` -> `agentic/SKILL_REGISTRY.md` @@ -80,8 +80,7 @@ Stable reference material belongs in topical subfolders. - `platform/` - Provider, import-adapter, and starter-pack platform or reference docs. - `releases/` - - Release-facing material: `releases/V0_3_0_READINESS.md` (the standing v0.3.0 gate view: clauses, - technical blockers, human gates, trackers, and the milestone residuals awaiting a re-ruling), the + - Release-facing material: `releases/V0_3_0_READINESS.md` (the current standing v0.3.0 gate view: live snapshot boundary, critical path, issue routing, human gates, and definition of done), the packaged Windows quick start, and per-tag notes under `releases/notes/`. - `security/` - Active security and abuse-protection policies or baselines. @@ -95,6 +94,8 @@ Stable reference material belongs in topical subfolders. - Shared agent question, failure, guide-update, tool-parity, and skill-registry protocols. This is a contributor/agent operating layer, not product truth. - `analysis/` - Dated reconciliation notes, audits, and planning snapshots. Non-authoritative unless promoted. + - includes `analysis/2026-09-21-repository-direction-and-v0.3-programme.md` for the current repository-wide convergence thesis, release-control dependency map, admission rules, and human-decision boundary. It is a dated executive brief; live GitHub and the canonical strategy/readiness documents outrank its changing facts. + - includes `analysis/2026-09-17-v0.3-release-assessment.md` as the historical release-owner snapshot that established the safe cutover order. - includes `analysis/2026-03-07_mvp-expansion-reconciliation-tracker.md` for ongoing promotion of `docs/InReview/MVP_EXPANSION/` into canonical docs and backlog guidance. - includes `analysis/2026-03-07_mvp-expansion-gap-map.md` for the dated doc and issue reconciliation baseline. - includes `analysis/2026-03-07_mvp-expansion-source-coverage-audit.md` for the full file-by-file and snippet-by-snippet audit of what from `MVP_EXPANSION/` is promoted, deferred, or carried into later-wave issue scope. @@ -120,6 +121,8 @@ Stable reference material belongs in topical subfolders. ## Working Notes +- `analysis/2026-09-21-repository-direction-and-v0.3-programme.md` + - Current programme brief for v0.3 convergence, exact-identity correctness, release-control sequencing, and admission boundaries. - `analysis/2026-03-07_mvp-expansion-reconciliation-tracker.md` - Canonical continuity log for the MVP expansion reconciliation. - `analysis/2026-03-07_mvp-expansion-source-coverage-audit.md` diff --git a/docs/ISSUE_EXECUTION_GUIDE.md b/docs/ISSUE_EXECUTION_GUIDE.md index 3254576dee..f9878f52c9 100644 --- a/docs/ISSUE_EXECUTION_GUIDE.md +++ b/docs/ISSUE_EXECUTION_GUIDE.md @@ -1,11 +1,13 @@ # Issue Execution Guide -Last Updated: 2026-08-23 +Last Updated: 2026-09-21 Scope: How agents execute the GitHub issue backlog safely, in dependency order, and with explicit priority, status, and milestone discipline. **Active sequence:** the ratified REVIVAL wave in `docs/REVIVAL_PLAN.md` (direction: -`docs/strategy/PRODUCT_DIRECTION.md`). ADR-0051 permits an authorized coordinator to admit an +`docs/strategy/PRODUCT_DIRECTION.md`), with current repository and v0.3 routing in +`docs/analysis/2026-09-21-repository-direction-and-v0.3-programme.md` and +`docs/releases/V0_3_0_READINESS.md`. ADR-0051 permits an authorized coordinator to admit an acceptance-ready existing issue without a maintainer-request gate, within the caps below. New tables, endpoints, mutation paths, connector types, top-level views, security posture, and other architectural surprises still require `REVIVAL_PLAN.md` §7 or a later Accepted ADR/plan amendment. @@ -49,6 +51,37 @@ labels mark issues agents must not convert into implementation or infer complete 7. Use the project `No Status` view (`no:status`) and assign `Now` or `Next` before active work, respecting the four-`Now`/eight-`Next` caps. +## Programme routing, ownership, and stacked work (Required) + +Before selecting or continuing an issue: + +1. Refresh live issue, milestone, PR, branch, checks, review threads, Project status and recent + commits. A dated document never proves live ownership or readiness. +2. Search both lane-claim marker families, open PRs and remote branches. Do not duplicate a current + implementation because its claim format differs. +3. Determine the primary acceptance owner. File location alone does not decide whether work belongs + to product trust, platform integrity, release control or documentation reconciliation. +4. For a stacked PR, record the parent PR, actual base branch and required landing order. A child + based on an open parent is not independently mergeable to `main` even when GitHub reports it + conflict-free. +5. Treat CI/review as exact-head evidence. Rebase, base merge, retarget, review repair, generated + file update or parent refresh invalidates the old qualification claim. +6. Check canonical-document ownership before editing `STATUS`, the masterplan, readiness, + `OUTSTANDING_TASKS`, this guide, or the agent index. Agree an integration order with any open PR + already touching the file. +7. For control-plane work, read ADR-0066 plus `OUTSTANDING_TASKS.md` section J. Green checks do not + grant merge authority. +8. For v0.3 work, prefer the release critical path. Future-horizon work remains valid backlog but + does not displace an unfinished release dependency merely because it is easier. + +Current named dependency examples are deliberately pointers, not permanent inventory: + +- landed verification: merged foundations `#3156` and `#3167`, open parent `#3295`, stacked child + `#3296`, then collector and workflow integration; +- private rehearsal: workflow inventory `#3297`, then CI-17 implementation `#3170`; +- runner recovery: PR `#3261` is FIX-FIRST evidence and must be ported minimally rather than merged + wholesale. + ## Project Status Workflow (Required) - Move issue to `Now` only when active implementation starts and all dependencies are complete. @@ -71,11 +104,11 @@ labels mark issues agents must not convert into implementation or infer complete 3. Add/update tests for behavior changes. 4. Run required verification commands. 5. Update docs (`STATUS`/`IMPLEMENTATION_MASTERPLAN`/test docs) if reality changed. -6. Open PR with linked issue and risk notes. +6. Open PR with linked issue, dependency/stack notes, exact base/head identity, and risk notes. 7. Enter the canonical global laws and `review-and-ship` pipeline; this guide adds no local reviewer-count, severity, convergence, or merge rule. 8. Move project item to `Review`. -9. After merge, move item to `Done` and post final verification summary. +9. After merge, move item to `Done` and post the merge SHA, exact-head verification, residuals, and final disposition. ## WIP Discipline diff --git a/docs/REVIVAL_PLAN.md b/docs/REVIVAL_PLAN.md index 3be4727d40..a6a80a888e 100644 --- a/docs/REVIVAL_PLAN.md +++ b/docs/REVIVAL_PLAN.md @@ -1,6 +1,6 @@ # Taskdeck Revival Plan — Free Open Beta → Commercial Horizon -Last Updated: 2026-09-11 +Last Updated: 2026-09-21 **Status:** Active execution plan (maintainer-decided 2026-07-10, **ADR-0044**; supersedes the archive pivot). Product identity, direction, and the release-theme ladder are owned by `docs/strategy/PRODUCT_DIRECTION.md` (2026-08-23); this plan owns wave sequencing, the issue map, and ship gates. **Authority:** the ratified REVIVAL/GEN waves and ADR-0051's bounded autonomous-admission lane are the only intake paths. Existing tracked backlog may be promoted under §5 without another owner decision; new product surface remains allowed only where §7 or a later Accepted ADR/plan amendment grants it. @@ -47,7 +47,7 @@ The beta is **free and wide open** — its job is adoption, feedback, and exposu | **v0.1 "First Light"** | **SHIPPED 2026-08-19 (tag `v0.1.0`) + 2026-08-21 (`v0.1.1`, Windows).** Phase 1 complete: honest surfaces, safe public defaults, exercised release pipeline, welcoming README/onboarding | §6 ship gate (delivered except (i) dogfooding days — running since 2026-08-22 and re-scoped 2026-08-27 to the #1271 standing tracker, no longer release-gating — and the §6 beta threat model + one-time ACL/TOCTOU re-triage, still outstanding on #1311) | | **v0.1.2** | **SHIPPED 2026-08-25 (tag at `9766edbb5`).** Honest-Windows-Beta correction: the `#1876` double-click/startup fix plus the Priority I tranche | q-3 gate satisfied: maintainer accepted the release deck in-session 2026-08-24 (`#1947`); milestone groomed to zero open and closed, residuals re-milestoned to v0.2 | | **v0.2 "Coherent Context-to-Action Loop"** | **SHIPPED 2026-08-29 (tag at `48c05e1dc`).** Milestone 0 open / 15 closed; the transcript loop acceptance is recorded in `docs/STATUS.md`; the maintainer accepted the release deck in-session (q-1 B, `#1947`) and the agent cut the tag under that ruling | a real 45-min transcript → reviewable, evidence-linked, typed action items; capture fields never silently dropped; release checks green | -| **v0.3 "Accountable Agents + Downloadable Beta"** | **`v0.3.0-rc.1` SHIPPED 2026-08-30 (prerelease, tag at `9d2ea3c7c`)**; final **when ready — no dates** (maintainer ruling 2026-08-30, RC deck q-6). Phase 3 packages MCP with scoped keys, Review liveness, honest degradation, the double-click start, the trusted private-instance proof (#1772 Stage 1) and the maintainer-pulled fix queue; the **hosted, install-free open beta moved to v0.4** (deck note 3); **the repository goes private for the v0.3.0 release** on the personal GitHub Pro account (maintainer directive 2026-08-30 — ADR-0066 Smart CI Fabric, tracker CI-00 #2324) | RC checks green on the exact head; milestone closed or explicitly re-ruled; launch kit drafted (#2242); `main` green; **the CI-13 #2337 cutover performed by the maintainer** (private repository with `Smart CI / Required Gate` enforced). Standing per-clause state, and the split between blockers, human gates, trackers and milestone residuals, is `docs/releases/V0_3_0_READINESS.md` | +| **v0.3 "Accountable Agents + Downloadable Beta"** | **`v0.3.0-rc.1` SHIPPED 2026-08-30 (prerelease, tag at `9d2ea3c7c`)**; final **when ready, no dates**. Phase 3 packages MCP with scoped keys, Review liveness, honest degradation, the double-click start, the trusted private-instance proof (#1772 Stage 1) and the retained fix queue; the hosted, install-free open beta stays in v0.4. The development repository becomes private for `v0.3.0` under ADR-0066, with public source/releases through `Chris0Jeky/taskdeck-release` and public GHCR (`#2439`), plus the CI-17 Linux-only rehearsal (`#3170`) before runner association. | Exact frozen-head checks; every milestone issue closed, moved or explicitly retained; storage/least-privilege/nightly/mirror/runner prerequisites complete; CI-13 `#2337` executed in the canonical order; the real tag qualified; private Release mirrored and anonymously verified before announcement. Current state: `docs/releases/V0_3_0_READINESS.md`. | | **v0.4 "Hosted Open Beta + Work Model + Fabric Foundation"** | The install-free hosted open beta (#2243: ADR-0061 stages → open registration under the beta threat model), the work-model slices #2087/#2089/#2092/#2093 (q-3 B), opt-in analytics (#1308 Option B), refactoring (#2236) and performance (#2237) passes, the behaviour-preserving Context Fabric foundation (Phase 5 slices 1–3 + storage seam: CF-01/02/03/05/06/07, CF-23), and the Worker Protocol host CF-04 (slice 5, not behaviour-preserving — it launches supervised sidecars) because the ADR-0048 worker #1429 is its first sidecar. The former "Every Artefact" content (GEN-03/04/06) moved into Phase 5; GEN-07/08/11 stay with (GEN-12 `#1326` closed 2026-09-03: stay one application) #1327 | a stranger registers and runs the loop; every legacy capture reads back byte-identically through `ICaptureStore`; the transcript golden path is unchanged behind the capability runner | | **v0.5 "Speak, Type, Paste, or Drop"** | Phase 5 payoff: candidates (CF-08), context resolver (CF-09), the voice vertical (CF-12/13/14/16), Universal Capture (CF-20), capture-centred review + presentation profiles (CF-21), GEN-03 #1317 as a registered vision processor | a voice note → time-anchored transcript → reviewable proposal → approve → apply → the audio range plays from Review; no board required to capture or understand | | **v0.6 "Under Your Rules"** | Phase 5 policy families: processing profiles + router v1 + receipts (CF-10), cache (CF-11), cloud STT + benchmark (CF-15), OCR sidecar (CF-18), meeting bundle (CF-17), runtime outcome metrics + dashboard (CF-24B; the corpus CF-24A lands in v0.5), first delegated-authority class (CF-22, own gate; stretch, not a release blocker) | a *Private* profile never egresses; a route receipt explains every processor choice; CF-22 ships only after its evidence bar | @@ -65,6 +65,37 @@ The 2026-08-26 reconciliation is recorded in `docs/analysis/2026-08-26-v012-dogf ADR-0060 and ADR-0062 are Accepted and ADR-0061 is Accepted as direction only, evidence pending (maintainer rulings of 2026-08-29, recorded in each ADR). The shipped `Board -> Column -> Card` model and proposal-first automation contract remain unchanged until the work-model slices (`#2087`, `#2092`, `#2093` — moved to v0.4 on 2026-08-30, q-3 B; `#2240` is the v0.3 sub-slice) land under those rulings; ADR-0060 stages 4–5 remain gated on an ADR amendment, and the private shared instance stays gated on the pending CL-1 values and the Stage 1 prerequisites tracked on `#1772` (`#1777` stays parked). +### Current programme sequence (2026-09-21) + +The v0.3 lane is now a convergence and release-control programme. The detailed current map is the +[2026-09-21 repository direction and v0.3 programme brief](analysis/2026-09-21-repository-direction-and-v0.3-programme.md), +with the live gate view in [`releases/V0_3_0_READINESS.md`](releases/V0_3_0_READINESS.md). + +Sequence: + +1. **Finish exact-identity correctness work already admitted to v0.3.** Complete owned stacks around + request/session/credential generations, authoritative snapshots, durable commit boundaries, + honest unavailable states, and release receipts. Do not turn the theme into unlimited adjacent + refactoring. +2. **Finish Smart CI proof.** Treat merged `#3156` and `#3167` as landed foundations; qualify + parent `#3295` before stacked child `#3296`, then add authoritative collection/workflow + integration and rebuild the observation evidence. +3. **Finish CI-17.** Qualify the non-activating workflow inventory in `#3297`, then implement the + trusted, fail-closed Linux-only rehearsal owned by `#3170`. +4. **Close release prerequisites.** Reconcile post-merge Windows timeout evidence after `#3162`, + finish the remaining `#2335`/CodeQL acceptance after merged `#2838`, and complete storage + (`#2333`), nightly/exact-tag qualification (`#2334`), runner proof (`#2328`), and mirror/GHCR + continuity (`#2439`). +5. **Reconcile all open milestone issues.** Close on evidence, split real residuals, or record an + explicit maintainer ruling. Preserve `#2315`'s existing residual ruling unless changed. +6. **Execute the human cutover.** Follow `docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md`: public GHCR, + privacy, stable gate registration, CI-17 rehearsal, then runner association. +7. **Freeze and release.** Rehearse the final head, prove the publication hold, create `v0.3.0`, + qualify the exact tag, publish privately, mirror publicly, verify anonymously, then announce. + +v0.4 and later work remains authorized by the ladder and accepted ADRs, but it is not the default +admission source while release-critical v0.3 dependencies remain unfinished. + ### Current work-model sequence (2026-09-12) This note supersedes the historical assignment timing and unimplemented-parent wording above. diff --git a/docs/analysis/2026-09-17-v0.3-release-assessment.md b/docs/analysis/2026-09-17-v0.3-release-assessment.md index baf9e169da..7534b55dec 100644 --- a/docs/analysis/2026-09-17-v0.3-release-assessment.md +++ b/docs/analysis/2026-09-17-v0.3-release-assessment.md @@ -1,5 +1,13 @@ # v0.3 release assessment - 2026-09-17 +> **Historical snapshot.** This assessment records the 2026-09-17 measurement and the decisions that +> produced the safe cutover order. For current counts, active PR stacks and programme sequencing, +> use the +> [2026-09-21 repository direction and v0.3 programme brief](2026-09-21-repository-direction-and-v0.3-programme.md) +> and the live [`v0.3.0` readiness view](../releases/V0_3_0_READINESS.md). Do not update the snapshot +> tables below to look current; preserve them as dated evidence. + + This is a dated decision-support snapshot for the final `v0.3.0` release. It does not replace [`V0_3_0_READINESS.md`](../releases/V0_3_0_READINESS.md), the executable cutover checklist, issue records, or live GitHub state. Newer maintainer rulings and live evidence take precedence. diff --git a/docs/analysis/2026-09-21-repository-direction-and-v0.3-programme.md b/docs/analysis/2026-09-21-repository-direction-and-v0.3-programme.md new file mode 100644 index 0000000000..a2b9a279bb --- /dev/null +++ b/docs/analysis/2026-09-21-repository-direction-and-v0.3-programme.md @@ -0,0 +1,334 @@ +# Repository direction and v0.3 programme - 2026-09-21 + +This is a dated programme brief. It reconciles live GitHub state, the merged 2026-09-17 release +assessment, the current repository snapshot, and the engineering work that landed or opened between +2026-09-18 and 2026-09-21. + +It does not replace the canonical sources: + +- shipped reality: [`docs/STATUS.md`](../STATUS.md); +- product identity and release ladder: + [`docs/strategy/PRODUCT_DIRECTION.md`](../strategy/PRODUCT_DIRECTION.md); +- execution authority and phase sequencing: [`docs/REVIVAL_PLAN.md`](../REVIVAL_PLAN.md); +- live v0.3 gate view: [`docs/releases/V0_3_0_READINESS.md`](../releases/V0_3_0_READINESS.md); +- private-cutover execution: + [`docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md`](../ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md); +- human-only actions: [`OUTSTANDING_TASKS.md`](../../OUTSTANDING_TASKS.md). + +Live GitHub outranks every count, PR state, CI result, and branch reference in this file. + +## Executive position + +Taskdeck is in **release convergence**, not feature discovery. + +The product direction has not changed: + +- v0.3 is **Accountable Agents + Downloadable Beta**; +- v0.4 is the hosted beta and work-model/Fabric-foundation horizon; +- broader Context Fabric, delegated-authority, scale, and commercial work remain later horizons. + +The repository has, however, changed materially since the 2026-09-17 assessment. A large correctness +wave moved the dominant engineering risk away from isolated feature gaps and toward one shared +question: + +> Can every asynchronous result, mutation, receipt, and release decision be proven to belong to the +> route, session, credential, object identity, transaction, policy, and exact source revision that +> initiated it? + +Recent work repeatedly answers that question at different seams. The programme should now treat +those answers as one convergence discipline rather than as unrelated bug fixes. + +## Snapshot + +Measured on 2026-09-21 against live GitHub and `main` +`f001dd92149dd3dc807f48691772f2ac2cd3f1f5`. + +| Signal | Current reading | Programme meaning | +| --- | --- | --- | +| v0.3 milestone | 104 closed, 30 open, 134 total | 77.6% closed by issue count; this is throughput, not release readiness | +| Open split | 16 `ci`, 5 `dogfooding`, 9 other | Release-control and retained product acceptance remain intertwined | +| Priority I | 10 open v0.3 issues | The release still has explicit trust/blocker work | +| Distribution | `v0.3.0-rc.1` remains the latest v0.3 release artifact | Packaging is proven at RC level; final release control is not | +| Repository | Public | The accepted private-development cutover has not happened | +| Required checks | Three security contexts | `Smart CI / Required Gate` is not yet registered in branch protection | +| Final tag | Not created | Final-head and exact-tag qualification remain future actions | + +**Release verdict:** no-go for `v0.3.0` today. The downloadable beta exists, but the final trust, +cutover, evidence, and publication chain is incomplete. + +## The current engineering thesis + +### 1. Bind every completion to an owner + +The September 18-21 wave repeatedly found that a late response could settle into a newer context: +route changes, card switches, credential replacement, token rotation, board replacement, retry, +realtime reconnection, and overlapping store reads. + +The durable rule is: + +- capture an explicit owner when work starts; +- invalidate or supersede that owner when route, session, credential, request generation, or object + identity changes; +- re-check ownership immediately before publishing state; +- do not let an older completion clear loading, error, or recovery state owned by newer work. + +Examples include the HTTP/session boundary, board and metrics stores, notification and audit reads, +realtime rejoin recovery, feature-flag route gates, and queue/store request ownership. + +### 2. Separate durable commit from post-commit tails + +A committed change must not later be rewritten as failed because a notification, linked-record +reconciliation, cleanup, or caller cancellation failed after commit. Conversely, a pre-commit +failure must not publish effects that can outlive rollback. + +This requires an explicit durable boundary: + +- transaction-owned effects before commit; +- deferred or best-effort work after commit; +- uncancelled cleanup where cancellation can no longer reverse durability; +- receipts that describe the committed result, not the last adapter call. + +### 3. Read one authoritative snapshot per decision + +Rollups, expiry, related evidence, and reconciliation cannot safely combine independent reads from +different instants. Where a decision spans related records, use one bounded snapshot or one +explicitly versioned evidence set, then mutate or report against that same identity. + +### 4. Distinguish empty from unavailable + +Taskdeck's trust model applies to reads as well as writes. A failed or pending read must not render as +an authoritative empty state. Recovery must remain visible and retryable without discarding cached +truth or drafts. + +### 5. Treat CI evidence as a product trust boundary + +A green-looking receipt is useful only when it is bound to: + +- the correct repository; +- authoritative workflow and run metadata; +- the exact head, merge tree, policy and configuration identity; +- selected lanes that actually ran and completed successfully; +- an unexpired artifact produced by the expected event and workflow. + +Missing, stale, ambiguous, malformed, cross-repository, non-enforcing, or `wouldFail` evidence must +select full qualification. + +## Current v0.3 workstreams and release sequence + +The A-J sections below group ownership and acceptance workstreams; their letters are not execution +priority. The controlling release sequence is: + +1. finish admitted exact-identity correctness stacks without widening into adjacent refactoring; +2. finish Smart CI proof and authoritative landed-evidence integration; +3. implement and prove CI-17 after its non-activating inventory prerequisite; +4. close Windows, least-privilege, storage, nightly, runner, and mirror/GHCR prerequisites; +5. reconcile every open milestone issue on the resulting evidence, while doing obvious close-on- + evidence updates continuously rather than waiting for a final batch; +6. execute the human private-repository cutover in the canonical checklist order; +7. freeze, tag, qualify, publish privately, mirror publicly, verify anonymously, then announce. + +Exact-head CI, review, stack ancestry, control-plane authority, and maintainer gates still apply. + +### A. Reconcile retained release scope + +Owners: milestone 4, `#2235`, and the maintainer decision record. + +- Give every open issue one release disposition: **SHIP**, **CLOSE ON EVIDENCE**, + **EXPLICIT RESIDUAL**, **DEFER**, or **HUMAN GATE**. +- Preserve `#2315` as the already-ruled non-blocking residual unless the maintainer changes that + ruling. +- Do not bulk-close issues because their original acceptance appears old. Re-read delivery comments, + merged PRs, current source, and surviving residuals. +- Admit new v0.3 scope only for a release-critical regression or an explicit maintainer ruling. + +### B. Finish Smart CI receipt and landed-verifier proof + +Owners: `#2326`, `#2327`, `#2508`, `#3227`, and CI-00 `#2324`. + +Landed foundations and current implementation stack: + +1. PR `#3156` merged on 2026-09-19 and delivered the merge-base receipt residuals. `#2508` + remains open for final issue reconciliation, not because that PR still needs qualification. +2. PR `#3167` merged on 2026-09-18 and delivered the pure landed-verifier decision core. `#3227` + records the planner-only shadow-receipt gap that must remain full qualification. +3. Open parent PR `#3295` strengthens repository-bound, enforce-mode receipt qualification. +4. Open child PR `#3296` is stacked on `#3295` and hardens the CLI and denial outputs. +5. Authoritative PR association, artifact collection, workflow integration, and the bounded + main-versus-full routing decision still require their own current-main integration slice. + +Safe sequencing rules: + +- merge or otherwise resolve the parent before retargeting a stacked child; +- re-run exact-head checks after any base refresh or stack collapse; +- do not remove the existing full `push: main` path until the collector/integration and observation + evidence are accepted; +- do not register the stable required context while the repository remains public. + +### C. Build the CI-17 Linux-only rehearsal control + +Owners: `#3170`, CI-13 `#2337`, and runner boundary `#2328`. + +`#3297` is the current non-activating prerequisite. It inventories Windows-capable jobs and reusable +workflow call edges. It does **not** implement trusted mode propagation, authorization, suppression, +non-vacuous evidence, or the cutover rehearsal. + +The implementation after that inventory must: + +- derive the mode from trusted protected-base control code; +- cover required, called, and reusable workflows transitively; +- suppress every private hosted Windows job during the rehearsal; +- preserve Linux, security, governance, receipt, and control-plane evidence; +- fail closed if coverage is incomplete, inconsistent, bypassed, or newly drifted; +- emit an auditable receipt; +- prove R0, R2, R4, normal merge, nightly, and no-publish release scenarios before runner association. + +### D. Reconcile Windows qualification after the bounded timeout landed + +Owners: `#2378` and `#2588`; delivered timeout evidence: closed `#3158` and merged PR `#3162`. + +PR `#3162` merged on 2026-09-19 with the calibrated 45-minute outer bound, 20-minute per-test hang +watchdog, process-tree termination, mini-dump support, and partial-results evidence path. Later +45-minute ceiling occurrences under runner contention are recorded in `OUTSTANDING_TASKS.md` J.4 and +on `#3158`; they are post-merge evidence, not proof that the timeout implementation is still absent. +Classify that evidence causally, then close, consolidate, or explicitly retain the older launcher and +runner-speed residuals. Rerunning without preserving the original failure is not closure. + +### E. Reconcile landed least privilege and the remaining control-plane decision + +Owners: `#2335` and `OUTSTANDING_TASKS.md` section J; delivered implementation: merged PR `#2838`. + +- Full-SHA action pinning and `sha_pinning_required: true` are already complete. +- PR `#2838` merged on 2026-09-19, delivering checkout `persist-credentials: false` coverage and + Pages permission scoping. Do not describe that implementation as parked or awaiting rebase. +- Remaining `#2335` work is acceptance reconciliation, hosted-only control-path proof where still + unproved, an explicit CodeQL posture, and the maintainer's post-hoc/standing control-plane ruling. +- Green CI is qualification evidence, not merge authority. + +### F. Make private storage sustainable at the settled budget + +Owner: `#2333`. + +- Refresh the identity-bound cleanup dry run. +- Preserve release, provenance, and required audit evidence. +- Obtain maintainer authorization for the exact current deletion set. +- Execute only that set and record requested/deleted/skipped/failed/not-found outcomes. +- Remeasure artifacts and caches under the settled `$0` posture. + +### G. Complete nightly and exact-tag release qualification + +Owner: `#2334`. + +- Accept the nightly observation window and weekly full sweep. +- Keep mutation manual unless ADR-0052 is explicitly amended. +- Prove the frozen final head through the trusted Linux-only no-publish path. +- Create the real tag only after the publication hold is proven. +- Qualify hosted Linux/control work and isolated Windows release work against the same tag, commit, + policy, checksums, provenance, and release contract. + +### H. Operationalise the public mirror and GHCR continuity + +Owner: `#2439`. + +- Create `Chris0Jeky/taskdeck-release` with mirror Actions disabled. +- Use a fine-grained credential scoped only to the mirror contents boundary. +- Make release GHCR packages explicitly public before repository privacy and verify anonymous access + both before and after the flip. +- Stage and verify source and byte-identical release assets before public mirror publication. +- Publish the private Release before the mirror consumes it. + +### I. Prove runners before association + +Owner: `#2328`. + +The recovered branch surfaced in PR `#3261` is evidence, not an integration candidate. It is stale and +has a FIX-FIRST nested reparse-point gap. Port only a corrected minimal slice onto current `main`, +prove Linux and Windows cleanup boundaries with real filesystem fixtures, and keep registration a +human action after the CI-17 rehearsal. + +### J. Execute the human cutover + +Owner: `#2337` and the maintainer. + +The accepted order remains: + +1. freeze merges and capture settings/rollback values; +2. complete storage, mirror, GHCR, runner, Smart CI, and CI-17 prerequisites; +3. make GHCR public and verify it anonymously; +4. change the development repository to private; +5. only then register `Smart CI / Required Gate` and apply the recorded branch policy; +6. run the Linux-only private rehearsal with every self-hosted runner unassociated; +7. stop on any hosted Windows scheduling, bypass, missing evidence, or ambiguous result; +8. associate only already-proven runners; +9. freeze the final head, qualify the real tag, publish privately, mirror publicly, verify + anonymously, then announce. + +## Product-work admission during convergence + +The correctness wave is valuable and should continue when it closes a retained defect, trust gap, or +release claim. It must not become an unlimited parallel product programme. + +Use these rules: + +1. **Release-control first.** A release-critical control-path or evidence dependency outranks an + unrelated product improvement. +2. **Finish owned stacks.** Do not start a neighbouring store or review seam while its parent stack is + still unqualified unless paths and state ownership are truly independent. +3. **No v0.4 pull-forward by convenience.** A future-horizon issue needs its accepted plan/ADR and + should not displace retained v0.3 work merely because it is easier. +4. **Hard defects remain admissible.** Security, data integrity, authorization, false-success, + cross-session state, or durable-commit defects may pre-empt the queue when evidence supports the + severity. +5. **Docs follow truth.** Update `STATUS.md` only for merged shipped behavior. Update this programme, + readiness, or planning material for direction and sequencing changes. + +## Human decisions still open + +The repository contains implementation-ready work, but these decisions/actions remain human-owned: + +- final per-issue v0.3 disposition; +- the standing review/merge rule for new control-plane PRs after the September directives; +- CLI trust posture for `#1131`; +- MCP runtime hash-approval posture for `#1309`; +- CodeQL posture for `#2335`; +- the remaining private-instance choices and execution for `#1772`; +- exact storage deletion authorization for `#2333`; +- mirror repository and credential creation for `#2439`; +- repository visibility, required-check, branch-policy, and runner-association actions for `#2337`; +- final tag, private Release, mirror publication, and public announcement authorization. + +## Definition of v0.3.0 done + +The final release is ready only when: + +- every milestone issue is closed, moved, or covered by an explicit recorded residual; +- the frozen final head is green under the final required-check configuration; +- authoritative landed verification and full escalation are proven; +- Smart CI observation and recall thresholds are accepted; +- private artifact/cache posture fits the settled budget; +- runner isolation, cleanup, offline, override, reset, and revocation are proven before association; +- CI-17 proves zero private hosted Windows work with non-vacuous Linux/control/security evidence; +- GHCR remains anonymously available across the privacy change; +- the real tag is rebuilt and qualified after it exists; +- Linux/control and isolated-Windows evidence bind one immutable release identity; +- publication cannot occur before the post-tag hold is released; +- the private Release is the source for the staged public mirror; +- anonymous verification passes for source, assets, checksums, provenance, links, GHCR, and downloads; +- shipped notes and known limitations match reality; +- announcement follows verification, never precedes it. + +## Immediate next actions + +1. Finish admitted exact-identity correctness stacks around request/session/credential ownership, + authoritative snapshots, durable commit boundaries, and honest unavailable states without + expanding into unrelated refactoring. +2. Treat merged `#3156` and `#3167` as landed foundations; qualify parent `#3295` before stacked + child `#3296`, add authoritative collector/workflow integration, then reconcile `#2508` and + `#3227` on evidence. +3. Finish exact-head evidence and maintainer review for `#3297`, then implement the actual `#3170` + control rather than treating inventory as completion. +4. Close the remaining prerequisites: reconcile the post-merge 45-minute Windows timeout evidence + and `#2378`/`#2588`; settle remaining `#2335`/CodeQL acceptance after merged `#2838`; refresh + storage; port corrected runner work from `#3261`; and complete nightly plus mirror/GHCR proof. +5. Reconcile all 30 open v0.3 issues without bulk closure, preserving `#2315` unless re-ruled. +6. Execute the private cutover in the canonical checklist order. +7. Freeze, tag, qualify, publish privately, mirror publicly, verify anonymously, and announce. diff --git a/docs/releases/V0_3_0_READINESS.md b/docs/releases/V0_3_0_READINESS.md index cf4e6c6ca2..572616b657 100644 --- a/docs/releases/V0_3_0_READINESS.md +++ b/docs/releases/V0_3_0_READINESS.md @@ -1,267 +1,291 @@ # v0.3.0 release readiness -Last Updated: 2026-09-11. This file is refreshed in parts, not all at once; the table in section 1 says when each part was last measured and against what. - -**What this file is.** A standing view of what actually stands between `main` and the final `v0.3.0` -tag, so the open v0.3 milestone count is never mistaken for the blocker count. It classifies work into -gate clauses, technical blockers, human gates, trackers and milestone residuals. - -**What this file is not.** It is not shipped reality (`docs/STATUS.md`), not the plan -(`docs/REVIVAL_PLAN.md`), and not a go/no-go. The release decision is the maintainer's; ADR-0051 and -`.agent-harness/tier.json` cover only the mechanics once a ruling exists. Live GitHub outranks the -issue numbers below. - -## 1. The gate - -The five clauses are `docs/REVIVAL_PLAN.md` §3, the v0.3 row. Per-clause provenance, which is what tells a coordinator what still needs re-measuring: - -| Part | Last measured | Against | -|---|---|---| -| Clause 2 and the section 5 split | 2026-09-10 | `main` `a1f797913` | -| Clause 4 (`main` green) | 2026-09-10 | `CI` run `34494959248` at `a1f797913` | -| Clause 5's branch-protection read | 2026-09-10 | live branch protection on `main` | -| Section 3, the human-gate table | rows re-read 2026-09-10; the rest 2026-09-05 04:00Z | `main` `a1f797913` for the SC-9 and SC-10 rows, `42d3007f0` for the others | -| Section 2, the clause-5 chain | preface re-measured 2026-09-10 and updated 2026-09-11; the numbered narrative below it 2026-09-04 | `main` `a1f797913` for the preface; live GitHub and current `main` for the 2026-09-11 update | -| Clauses 1 and 3 | 2026-09-03 | not re-measured since | -| Section 4, trackers | 2026-09-05 | not re-measured since | - - -| # | Gate clause | State | What it waits on | -|---|---|---|---| -| 1 | RC checks green on the exact head | Not yet applicable | Measured at the final tag head, not before | -| 2 | Milestone closed or explicitly re-ruled | **Not met.** **32 open**, re-measured 2026-09-10 against `main` `a1f797913`, down from the 44 recorded on 2026-09-05. Today's split is 17 `ci` / 5 `dogfooding` / 10 other; section 5 lists all three. **Ruled 2026-09-03: nothing else is re-ruled out.** Two issues have since been re-ruled out of the v0.3 count: `#1972` to v0.5 with CF-21 (the 2026-09-03 exception) and `#2240` to v0.4 with `#2093` on the 2026-09-06 walkthrough (q-6 B, `decision` label discharged). A third ruling, D-8 on 2026-09-06, left `#2315` **in** the milestone but out of the blocker set. The per-issue movement between the two measurements is not reconstructed here; the 2026-09-05 history it replaced is in this file's git history | Every open issue closing on evidence, sections 2 to 5 below | -| 3 | Launch kit drafted (`#2242`) | **Met.** `#2242` closed | Nothing | -| 4 | `main` green | **Green at the tip `a1f797913`** (`CI` run `34494959248`, completed 2026-09-10T15:55:39Z, 17 jobs success and 1 skipped). Re-measured 2026-09-10; this is a tip reading, not a claim that every intermediate head was green. Three of the eight most recent `main` runs were `cancelled` by the workflow's own concurrency group as the next merge landed (`46ac59930`, `43f918050`, `63e639cb2`), so a green tip run still only exists when the merge queue drains. `#2582` (closed 2026-09-06) does **not** remove that: it guarantees the in-progress `main` run completes and that the tip runs, not a run per landed commit, so *pending* intermediate runs are still superseded during a wave. These three are that surviving mode, not a regression of the fix | `#2378`, and section 2 | -| 5 | CI-13 `#2337` cutover by the maintainer, private repository with `Smart CI / Required Gate` enforced | **Not met.** Branch protection re-read live 2026-09-10: `main` still requires exactly the three security contexts (`Dependency Security / Dependency Security Signals`, `SAST Scan / SAST Scan (Semgrep)`, `Secret Scan / Gitleaks Scan`), with `strict: false`, `enforce_admins: false` and `required_approving_review_count: 0`. Unchanged since 2026-09-05 | Section 3, and the section 2 chain below it | - -Clause 2 does not by itself require every open issue to close. "Explicitly re-ruled" means each one -either closes on evidence or carries a recorded decision moving it out of v0.3. **The maintainer ruled -on 2026-09-03 that the un-gated issues do not move, with one exception: `#1972` goes to v0.5 with -CF-21 `#2274`, which is the only thing that can close it. v0.3.0 tags only when the whole milestone is -closed.** Section 5 records the split that ruling was made over. Issues seeded onto the milestone -after the ruling inherit it unless their seeding says otherwise. - -## 2. Technical blockers on the gate - -These are the issues whose state a Codex lane can change and that a gate clause actually depends on. -Everything else in the milestone is section 4 or section 5. - -**Re-measured 2026-09-10 against `main` `a1f797913`; the numbered narrative below it is the 2026-09-04 measurement, kept because its evidence is still the record of how the chain got here.** Four things have moved, and the first makes the list below misleading if read as current: - -- **`#2506` merged on 2026-09-06 (`79d7efdb7`).** Item 1 names it as "the first open blocker on clause 5"; it is not open. It landed as the first step of the SC-10 chain the maintainer delegated that morning. -- **The `planner-error` class it was meant to close is still live.** It is now tracked as `#2562`, with three observed triggers rather than one: a stacked PR whose base is another PR's branch; a retained merge ref whose parent is the old base after a retarget (the lane's 2026-09-10 note on `#2897`); and a plain unstacked PR whose base simply moved under it between branch creation and the gate run, observed today on `#2925` (run `34509907288`, `CONTROL_BASE` `b3edd1ee1`, a merge that landed about twenty minutes earlier). The third needs no unusual setup at all, so this is not a stacked-PR-only defect and `#2562` has been retitled to say so. -- **The recall report exists and reads not-ready.** The beta lane published one on `#2336` at 2026-09-10T02:57:50Z over the 2026-09-09 to 2026-09-10 window: **usable merged PRs 7 of 42 against a floor of 20**, usable revision/attempt observations 9 of 88, failed lanes observed 3, **missed 3, recall 0.0%**, ready for selection **no**. So SC-4's condition fails on two counts at once — the sample is far below the floor, and recall on the sample it does have is zero. -- **The landed-commit verifier still does not exist.** There is no such module under `scripts/ci/smart-ci/`, which holds `plan.mjs`, `evaluate-gate.mjs`, `resolve-merge-ref.mjs`, `recall-report.mjs`, `nightly-coordinator.mjs`, `nightly-baseline.mjs`, `action-pins.mjs`, `artifact-cleanup.mjs`, `measure-ci-estate.mjs` and the `continuation/` tree. The three `landed` mentions in the tree are in tests and `ci-required.yml`, not an implementation. - -**What that leaves as genuinely takeable now.** `#2327`'s two halves are different shapes and only one is implementable: the landed verifier is code nobody has written, while the observation window is evidence that restarted on 2026-09-06 (a false red at 19:34Z retracted that morning's clean tally) and cannot rebuild until `#2562` is fixed. **The window itself can close while the repository is public; what waits for SC-6 is registering `Smart CI / Required Gate` in branch protection**, because while the repository is public a fork's `pull_request` run can create a job with the gate's name and protection would accept that spoofed context. `OUTSTANDING_TASKS.md` SC-4 draws exactly that line, and the checklist keeps them as separate §C items. A lane taking `#2327` should take the verifier and leave the window to accumulate. `#2562` is the other takeable item and it taxes every PR opened while `main` is busy — superseded by the 2026-09-11 update below, which found a PR on it. - -**Also measured 2026-09-10, on the cutover sections this chain depends on** (evidence on `#2337`, `#2335`, `#2327` and `#2334`; `docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md` is the CI region's and was not edited): §G is four-of-five done, leaving `persist-credentials: false` — PR `#2838`'s entire scope — as its only open non-maintainer item; §C's planner side is green locally at 512/512; §H's nightly coordinator exists and is wired but `ci-nightly.yml` states in its own words that the job is observation only and every deep job remains unconditional, so **selective execution is not shipped**. - -**Updated 2026-09-11 against live GitHub.** Three things moved since the preface above, and the first two point at the same unanswered question: - -- **`#2562` now has a PR, and that PR is parked.** `#2987` "Fail closed on retained Smart CI merge refs" (open, head `5d62bf104`, `Closes #2562`) validates each retained merge ref against the authenticated named base tip and fails closed on head mismatches, unreadable base refs, compare failures and unrelated parents. So `#2562` is no longer takeable work. The **landed-commit verifier is now the only unclaimed half of this chain** and it still does not exist: `scripts/ci/smart-ci/` was re-listed on 2026-09-11 and holds no such module. -- **Three control-plane PRs are parked on the same answer, `OUTSTANDING_TASKS.md` §J.3 (b).** `#2987` (its own body names the ADR-0066 maintainer review as a merge gate), `#2838` (`#2335` checkout-credential persistence and Pages permission scoping, head `f076baab1`) and `#2931` (frontend mutation activation smoke guard, head `0e367fb3a`, which also edits `.github/workflows/mutation-testing.yml`) are all open, and all three are control-plane by `ci/policy.v1.json`. Until §J.3 (b) is answered the ADR-0066 amendment stands as written, so none of them merges on agent authority. That keeps `#2838` as the only open non-maintainer item in cutover §G, and it now also keeps the fix for the defect that broke SC-4's observation window sitting in a queue. **§J.3 (b) is the bottleneck on this chain, not lane capacity.** -- **The reviewed queue landed, and none of it is control-plane.** Sixteen PRs merged on 2026-09-11 between 00:02:15Z and 16:53:17Z: `#2951`, `#2938`, `#2955`, `#2959`, `#2961`, `#2964`, `#2970`, `#2971`, `#2972`, `#2973`, `#2975`, `#2976`, `#2983`, `#2985`, `#2986` and `#2988`. Each one's file list was swept against all 36 `ci/policy.v1.json` control paths — the same method that found §J.3's twelve — and **zero files matched**, so the §J.3 disclosure list does not grow and nothing in the queue moved this chain. Clause 2's open count was **not** re-derived by this update; section 1's 32 is still the 2026-09-10 measurement and several of these merges close v0.4 work rather than v0.3 issues. - -**The clause-5 chain, in order.** Clause 5 needs `Smart CI / Required Gate` enforced. Branch protection -on `main` today requires exactly three contexts, all security: `Dependency Security / Dependency -Security Signals`, `SAST Scan / SAST Scan (Semgrep)`, `Secret Scan / Gitleaks Scan`. Registering the -Smart CI gate is human action SC-4, and SC-4's own condition is at least 20 PRs of observation without -a false red. What stands between here and that condition: - -0. **`#2401` is fixed and closed** (PR `#2440`, merge `a09d986c0`), which unblocks the count rather - than completing it. It had produced two false reds the same day: `#2408` (run `33736889079`, - 09:05Z) and `#2421` (run `33754458696`, 12:18Z) both failed `Smart CI / Required Gate` on - `base-sha-mismatch` plus `trust-mismatch` after `main` moved under a queued - `pull_request_target` event, not on branch content. The cause was in `plan.mjs`: - `requirePullRequestMergeBinding` ran *before* the `--base-sha` override was applied, so a - fail-closed planner escalation built its `errorPlan` from the stale event base and the - event-derived trust level. The fix moves that check after the override. **The SC-4 window still - has to accumulate**: 20 PRs of observation without a false red is a forward-looking count that - starts from a clean planner, and `a09d986c0` did not leave one — a second, differently shaped - planner defect produced five more false reds on 2026-09-04 (item 1). The clock restarts when that - fix lands, not here. -1. **PR `#2506` is the first open blocker on clause 5** (OPEN, `MERGEABLE` / `CLEAN` when measured - 2026-09-04). Five shadow false reds of one shape landed on 2026-09-04 and are recorded on `#2327`: - PR `#2485` twice (runs `33831258567` and `33833016055`), `#2496` (run `33832960392`), `#2515` - (run `33839324377`) and `#2500` (head `f9d851bc1`). Every receipt read `planner-error` — - *pull-request planning requires merge SHA and tree SHA from the same fetched merge ref* — plus - `trust-mismatch`. The cause is not `#2401`'s ordering bug. - `.github/workflows/smart-ci-shadow.yml` pins `CONTROL_BASE` to the workflow's `github.sha`, the - base tip at dispatch, and `resolveMergeRef` rejects any observation whose first parent differs - from it (`mismatchReason` in `scripts/ci/smart-ci/resolve-merge-ref.mjs`). GitHub regenerates - `refs/pull/N/merge` against whatever the base branch points at now, so a push to `main` between - dispatch and the resolver's fetch mismatches permanently, fails closed with no merge-SHA outputs, - and the fail-closed `errorPlan` then re-derives trust from the event. `#2506` accepts a first - parent that is the live protected base tip. Until it merges the reds are excluded from the SC-4 - count by the `#2327` citation, and the observation window cannot start. -2. **`#2327`** (CI-03, Priority I) owns the stable gate contract, branch-current behaviour, the - landed-commit verifier and event topology. Its own residuals are recorded on the issue; the - verifier does not exist yet and cancellation provenance cannot yet separate a manual cancel from a - concurrency supersede, and `#2508` adds a further CI-03 residual seeded from `#2506`'s review. `#2562` sits in the same chain: the planner resolves `CONTROL_BASE` to `main`'s tip, so every stacked PR fails the shadow gate with `planner-error`; an unpublished branch already carries its fix shape and overlaps `#2506` (note on `#2326`). - With `#2401` closed, this is the first open *issue* in the chain, behind PR `#2506`. -3. **`#2326`** (CI-02, Priority I) remains an observation gate. Selective execution is not shipped and - must not be described as shipped or authorized before its evidence conditions are met. - -**The cutover checklist is also a clause-5 prerequisite, and it is wider than the chain above.** -`OUTSTANDING_TASKS.md` SC-6 permits the visibility change only after sections A to J of -`docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md` are complete. Those sections name their owners, so every -one of them is gate work: - -| Section | Owner | State | -|---|---|---| -| A. Decisions (maintainer) | `#2324`, `#2337` | Human, section 3 | -| B. Measure before changing | CI-01 `#2325`, CI-09 `#2333` | `#2325` closed; `#2333` open | -| C. Planner and gate | CI-02 `#2326`, CI-03 `#2327` | Both open, above | -| D. Event topology | CI-03 `#2327` | Open, above | -| E. Test right-sizing | CI-05 `#2329`, CI-07 `#2331`, CI-08 `#2332` | All three open | -| F. Runners | CI-04 `#2328` | Open. **Mostly agent work**, see below | -| G. Supply chain | CI-11 `#2335` | Open, hands off to SC-5 | -| H. Nightly and release | CI-10 `#2334` | Open, v0.3 since 2026-09-03 (Q1 ruled A), Priority I | -| I. Rehearsal while still public | CI-13 `#2337` (checklist header) | Open, evidence recorded on `#2337` | -| J. Public distribution preparation | CI-16 `#2439` | Open; provision and verify before the mirror rehearsal | - -**Section F is not a human gate, despite SC-7.** Its four boxes are isolated VMs, no host mounts or -personal credentials with one job per host, a tested hosted override and offline-runner behaviour, -and tested workspace/Docker/cache cleanup with a documented VM reset and revocation path. All of that -is agent-preparable and must happen *before* cutover. Only the registration tokens and the GitHub -association are human, and those are SC-7, which runs *after*. Treating `#2328` as wholly human would -send required pre-cutover engineering out of the technical queue and let SC-6 look ready while -section F is unbuilt. - -**Section H is a prerequisite in full (Q1 on `#2337`, ruled A by the maintainer 2026-09-03).** CI-10 -`#2334` moved from v0.4 to v0.3 and is a release blocker: the nightly coordinator with its honest -no-change receipt and weekly sweep, mutation kept manual, and the pre-cutover release contract plus -public/no-publish rehearsals all land before cutover. Exact-tag qualification and publication remain -in section L after privacy and runner association. The agent's recommendation to split the section -(keep nightly consolidation on v0.4, carve out release qualification) was declined. `#2334` depends on CI-01 (closed), -CI-03 `#2327` and CI-05 `#2329`, both already v0.3, so nothing else moves milestone; its scope also -triages `#1210` and `#2180`, which carry no milestone. - -**Hosted minutes are a fixed budget, not a spend line (SC-3 re-ruled 2026-09-03).** The packet's -$10/month overage ceiling is deferred. GitHub Pro is confirmed; its included 3,000 minutes/month fund -Linux hosted jobs only, and Windows (x2) or macOS (x10) legs run locally (the laptop runner via CI-04 -`#2328`, agent-run proving checks until then) or carry a local fallback. That sizes CI-07 `#2331` and -the section E Windows contract: the retained full Windows suite is local-runner work, not hosted. - -**Clause-4 risks.** Three open intermittent reds can take `main` red without a code defect. None is -a product defect; all four are noise in clause 4 and in the SC-4 observation window. -**`#2489` closed** 2026-09-04 on PR `#2566` (merge `ea3e39e7d`): the notification paging test now pins -the query shape instead of a 2 s wall-clock bound. Three shapes were seeded from that night's reds in its -place (`#2588`, `#2561` and `#2572`, the last since closed), and a fourth, `#2691`, on 2026-09-05. (**`#2572`**, the fixed 300 ms `WorkerResilienceTests` delay, was one of them for three hours: -seeded from PR `#2522`'s run and closed on PR `#2592`, merge `4bf4a2e55`, which waits on worker progress -instead.) **`#2588`** is the Linux one: the dev-up `Node helper: TERM closes an active frontend -connection` case reds ubuntu Frontend Unit (seen on the alpha lane's docs-only PR `#2586`, and on 2026-09-05 on the docs-only PR `#2641`, run `33944370096`; both re-proven green on one rerun). -**`#2561`** is the Windows launcher one: dev-up `Stop-LoadedStack` retains PID state when -the pre-kill identity probe reads Unknown, a 3 s assertion failure, not the `#2378` timeout class (seen -once, PR `#2542` run `33850321779`). -**`#2691`** closed on 2026-09-07 after PR #2716 replaced the cancellation timing race with an extractor-entry handshake. The current regression is `ArtefactExtractionServiceTests.ExtractAsync_ShouldPropagateCallerCancellationAfterExtractorEntryWithoutRecording`. Four later required Windows Backend Unit jobs passed (runs `34162770894`, `34162836227`, `34162817370`, and `34163031267`); the issue records the exact heads and jobs. This bounded observation supersedes the earlier rerun-only checkpoint from run `33941869440`. -**`#2378`** (Priority I) is the Windows Frontend Unit launcher timeout. PR `#2427` (merge `7d8deef12`) removed that leg from the required E2E prerequisites, so its timeout can no longer leave `E2E Smoke` skipped; the launcher timeout itself is still open. It fired at least five more times on 2026-09-05 (PR `#2575` twice, PR `#2616`, PR `#2619`, and `main` itself at `1e234a011`; `spawnSync powershell.exe ETIMEDOUT` at about 20 s on four different cases, on diffs that could not have caused it), each recorded on the issue and, on PRs, re-proven with one rerun, never more. During the D-12 sweep the same afternoon it fired twice more: PR `#2654` (run `33948799223`, the launcher-suite step cancelled at the 25 minute job ceiling) and PR `#2626` (run `33969725867`, the launcher-suite step failing at 7 minutes), both re-proven green on one rerun. -The earlier pair named here is closed: **`#2425`** (Windows worktree helper scenario 28, the forced -5s timeout landing in the checkout phase) closed 2026-09-04 on PR `#2447` (merge `550f195ce`), and -**`#2399`** (Windows batch command-shape sample contamination) closed the same day on PR `#2454` -(merge `65abe3e2f`). - -## 3. Human gates - -**Row states re-checked against `OUTSTANDING_TASKS.md` §J on 2026-09-10.** Six of the eleven SC rows -read as open here while their §J row was already `[x]`: SC-1, SC-3, SC-5, SC-9, SC-10 and SC-11. All six -are corrected below, and a D-9 row is added for `#1940`. The still-open gates are **SC-4** (register the stable gate), **SC-6** (visibility) and -**SC-7** (register the runners), and their order is SC-6 before SC-4 before the CI-17 private-mode, -Linux-only rehearsal with runners still unassociated, then SC-7. §J is the authority for these -states; this table is a view of it. - -Clause 5 is entirely human. The named items live in `OUTSTANDING_TASKS.md` and map to issues: - -| Item | Issue | Nature | -|---|---|---| -| SC-1 confirm or overturn the nine CI-00 delegated rulings | `#2324` | **Closed 2026-09-03**: confirmed with the private-Pro approval-boundary amendment | -| SC-2 authorize the one-time artifact deletion, or accept the spend | `#2333`, `#2337` | **Executed 2026-09-03**: 1,498 PR-lane artifacts deleted, evidence on `#2333` | -| SC-3 confirm the plan and set a spend ceiling | `#2337` | **Closed 2026-09-06** (q-22 = A). The $0 Actions budget's "stop usage when limit is reached" toggle was read as on, making it a hard ceiling and closing the J.7 residual; Codex bills through the maintainer's OpenAI subscription with no GitHub-side billing, and Copilot is the Student offer and is not relied on | -| SC-4 register the stable gate in branch protection | `#2327`, `#2337` | Blocked by section 2 | -| SC-5 flip `sha_pinning_required` after CI-11 | `#2335` | **Closed 2026-09-06**: the maintainer ran the corrected command and `gh api repos/Chris0Jeky/Taskdeck/actions/permissions` reads back `sha_pinning_required: true`. `#2335` itself stays open for its non-maintainer criteria | -| SC-6 change repository visibility to private | `#2337` | The release-defining action | -| SC-7 register the isolated runners after cutover | `#2328`, `#2337` | Post-cutover | -| SC-8 public-asset and launch-kit decision | `#2337`, `#2242` | **Ruled 2026-09-03**, see below | -| SC-9 top up Codex review credits or accept the fresh-context fallback | `#2337` | **Closed 2026-09-06** (walkthrough q-4 = A). The connector was reviewing normally when last observed, 2026-09-10 | -| SC-10 review the queued control-plane PRs (ADR-0066 amendment 2026-09-03) | `#2324`, `#2331` | **Closed 2026-09-06**, all twelve merged under the q-1 = A delegation. That delegation covered those twelve named PRs only; the amendment still binds a new control-plane PR. **SC-10's row closing did not close its follow-through**: §J.1 and §J.2 are open human-action rows for the `#2772` and `#2787` post-hoc merges, §J.2 also holds parked `#2838`, and §J.3 carries the 2026-09-08 to 2026-09-10 disclosure plus the open question of whether the gate should stand at all. Read all three before treating this row's "Closed" as the end of it | -| SC-11 enable `delete_branch_on_merge`, then decide the one-time merged-branch sweep | none | **Closed 2026-09-06**: sweep executed, setting flipped by the maintainer and read back `true` | -| D-9 (b) request-edit fields and (c) defer durations | `#1940` | Open, parked for a written ruling. This is the whole remainder of `#1940`: its three acceptance criteria are checked and implemented on `main` `06bd4d18e`, so nothing in it is implementable until (b) and (c) are ruled. Section 5 counts it here, not against the Priority I implementation load | - -**SC-8 is answered.** The maintainer ruled on 2026-09-03: a **private development repository plus a -public release and source mirror**. Development, CI, issues and the control plane go private for -v0.3.0; Releases, checksums and provenance, and the GPL-3.0-only source stay public through a mirror, -with GitHub Pages still publishing from the private repository. CI-16 `#2439` implements it and -serves checklist section J, which puts it inside the SC-6 A-to-J prerequisite set. The launch kit and -any `awesome-selfhosted` wording point at the mirror, not the private repository. - -`#1772` (private shared instance) carries human decision CL-1 and is the one non-CI human-gated issue -still on the milestone. RT-1/2/3 (signing), BEN-1 and DIST-1 are in `OUTSTANDING_TASKS.md` but are not -v0.3.0 gate items: the 2026-08-29 q-5 ruling is that signing gates no release *before* v0.3.x, and -v0.2.0 shipped unsigned. That defers signing past v0.3.0, not past the maintenance line; the release -programme still targets it at the first v0.3.x release. - -**The 2026-09-03 decision packet landed in PR `#2442` (merge `c37d90b81`) and its follow-up `#2444`,** -which own `OUTSTANDING_TASKS.md`, the checklist annotations and the ADRs for that packet. Its SC-3 -value (a $10/month ceiling) was superseded the same day by the deferral recorded in section 2 above. -This file does not restate those records or check off their tracker boxes; it reads them. - -## 4. Trackers - -Trackers do not close by doing work; they close when their children do, or by a ruling. - -- **`#2324`** CI-00, the Smart CI Fabric and private-repository decision tracker (ADR-0066). -- **`#2235`** v0.3 spring cleaning. This is the reconciliation pass that clause 2 depends on, and this - readiness file is one of its outputs. - -## 5. Where the 32 open issues actually sit - -Clause 2's content is deciding which of these ship inside v0.3.0 and which are re-ruled out, and that -split is a maintainer ruling, not an agent decision. The useful thing this section does is separate -the ones that already have a gate clause behind them from the ones that do not. Re-measured 2026-09-10 -against `main` `a1f797913`, replacing the 2026-09-05 count of 44: - -- **5 carry `dogfooding`**, the product-polish family seeded from real use: `#2009`, `#2004`, `#1999`, - `#1949`, `#1940`. Three of the five are Priority I (`#2004`, `#1949`, `#1940`), but **`#1940` is not - implementable work**: all three of its acceptance criteria are checked and its 2026-09-09 - reconciliation records them implemented on `main` `06bd4d18e`. What holds it open is §K D-9 (b) - request-edit fields and (c) defer durations, parked for a written ruling, plus two non-blocking - `#1968` usability residuals. Section 3 carries it as a D-9 row; count it there, not against the - Priority I implementation load. Five left this group - since 2026-09-05, all closed on evidence: `#2141` (09-06), `#1984` (09-07), `#2007` (09-09), - `#1968` (09-09), `#2090` (09-09). -- **17 carry `ci`**, and almost none of them are residuals: - - the clause-5 chain `#2327` and `#2326`, with the CI-03 residual `#2508`; - - the stacked-base planner defect `#2562`; - - the cutover-checklist owners `#2333` (B), `#2329`, `#2331`, `#2332` (E), `#2335` (G) and `#2334` - (H, moved in from v0.4 on the 2026-09-03 Q1 ruling); - - the tracker `#2324` and the two human gates `#2337` and `#2328`; - - the public mirror `#2439` (SC-8 ruling); - - the clause-4 intermittent reds `#2378`, `#2561` and `#2588`. - Four left this group since 2026-09-05, which is what reconciles 21 to 17: `#2504` closed - 2026-09-06, `#2582` closed 2026-09-06, `#2250` closed 2026-09-07 and `#2691` closed 2026-09-07. -- **10 carry neither**: `#2499`, `#2391`, `#2315`, `#2235`, `#2215`, `#2214`, `#1772`, `#1309`, - `#1307`, `#1131`. `#1772` is the human gate in section 3; `#2235` is the spring-cleaning tracker; - `#2315` is counted here but D-8 on 2026-09-06 ruled it ships as a tracked residual and leaves the - v0.3.0 blocker set, which is exactly clause 2's "explicitly re-ruled" branch, so it is **discharged - from clause 2** and its closure is not a release prerequisite; the rest are review residuals and revival slices with no - gate clause behind them. - -**Priority I across the whole milestone (9):** `#2378`, `#2337`, `#2334`, `#2327`, `#2326`, `#2324`, -`#2004`, `#1949`, `#1940`. **Carrying `human-action` (3):** `#2337`, `#2328`, `#1772`, all in section 3. - -This is a count and a classification. It is not a claim that the issues which closed between the -two measurements each closed correctly; each one's evidence is on its own issue and in the -`docs/STATUS.md` blocks for that range. - -## 6. Keeping this current - -Refresh at each coordination cycle, from live state and not from this file: - -1. Re-read the v0.3 row of `docs/REVIVAL_PLAN.md` for the gate clauses. -2. Re-read branch protection for the required contexts. Do not infer that the Smart CI gate is - enforced from a green check. -3. Re-read `docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md` sections A to J and their named owners. SC-6 - makes that whole list clause-5 work, so an issue moving in or out of it changes this file. -4. Re-count the milestone and re-check the section 2 chain. -5. Move anything that becomes shipped reality into `docs/STATUS.md`, not into this file. +Last Updated: 2026-09-21 + +This is the standing operational view of what separates current `main` from the final `v0.3.0` +release. Live GitHub outranks every count, PR state, branch reference, and CI result in this file. + +For the current programme rationale and engineering themes, read the +[2026-09-21 repository direction and v0.3 programme brief](../analysis/2026-09-21-repository-direction-and-v0.3-programme.md). +The [2026-09-17 release assessment](../analysis/2026-09-17-v0.3-release-assessment.md) remains a +historical decision snapshot. The executable human sequence lives in the +[private-repository cutover checklist](../ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md). + +## 1. Current verdict + +**No-go for the final tag.** + +Measured on 2026-09-21 against live GitHub and `main` +`f001dd92149dd3dc807f48691772f2ac2cd3f1f5`: + +| Signal | Current state | +| --- | --- | +| v0.3 milestone | 104 closed, 30 open, 134 total: 77.6% closed | +| Open issue split | 16 `ci`, 5 `dogfooding`, 9 other | +| Priority I | 10 open v0.3 issues | +| Distribution | `v0.3.0-rc.1` exists with Windows archive, checksum, and provenance | +| Repository visibility | Public | +| Required `main` contexts | Dependency Security, Semgrep SAST, and Gitleaks Secret Scan | +| Stable Smart CI gate | Not registered in branch protection | +| Final `v0.3.0` tag | Not created | + +The RC proves that Taskdeck can be packaged. It does not prove the final private-development, +least-privilege, exact-tag, mirror, runner, storage, or release-publication contract. + +Issue closure percentage is a throughput measure, not a release-readiness percentage. One unresolved +trust gate can block the tag; an issue with an explicit residual ruling can remain open without doing +so. + +## 2. Formal release gates + +| Gate | State | Required outcome | +| --- | --- | --- | +| Exact final candidate green | Pending | Freeze one head, prove the no-publish path, create `v0.3.0`, and qualify that exact tag | +| Milestone closed or explicitly ruled | Not met | Close, move, or explicitly retain every open issue; preserve the recorded `#2315` residual unless re-ruled | +| Launch material | Drafted | Replace provisional/private URLs with verified public mirror and GHCR destinations | +| Frozen `main` head green | Must be re-proved | Historical or superseded green runs do not qualify the eventual release head | +| Private cutover and gate enforcement | Not met | Complete preconditions, flip private, register the gate, pass CI-17, then associate runners | +| Public distribution continuity | Not met | Prove public GHCR and the staged private-Release-to-public-mirror handoff | + +## 3. Critical workstreams and release sequence + +The numbered subsections group ownership and acceptance workstreams; they are not a linear priority +list. The controlling sequence is: + +1. finish admitted exact-identity correctness stacks; +2. finish Smart CI proof and authoritative landed-evidence integration; +3. implement and prove CI-17; +4. close Windows, least-privilege, storage, nightly, runner, and mirror/GHCR prerequisites; +5. reconcile every milestone issue on the resulting evidence, while applying obvious close-on- + evidence updates continuously; +6. execute the human cutover; +7. freeze, tag, qualify, publish privately, mirror publicly, verify anonymously, then announce. + +### 3.1 Release-scope reconciliation + +Owners: milestone 4, `#2235`, and the maintainer. + +Every open issue needs one current disposition: + +- **SHIP**: required acceptance remains in v0.3; +- **CLOSE ON EVIDENCE**: delivered acceptance is reconciled and any real residual is split; +- **EXPLICIT RESIDUAL**: remains open under a recorded non-blocking ruling; +- **DEFER**: moved with a reason and destination milestone; +- **HUMAN GATE**: agent preparation is complete and an explicit maintainer action remains. + +Do not infer closure from an old checkbox, title, or merged sibling PR. Do not bulk-close the +milestone. + +### 3.2 Smart CI planner, receipts, and landed verification + +Owners: `#2326`, `#2327`, `#2508`, `#3227`, and tracker `#2324`. + +Landed foundations and current implementation chain: + +1. PR `#3156` merged on 2026-09-19 and delivered the merge-base receipt residuals; `#2508` remains + open for issue reconciliation rather than implementation qualification. +2. PR `#3167` merged on 2026-09-18 and delivered the pure landed-verifier decision core; `#3227` + records the planner-only shadow-receipt gap. +3. Open parent PR `#3295`: enforce-mode, selected-lane, and repository-bound receipt proof. +4. Open child PR `#3296`: stacked on `#3295`; CLI and output-denial hardening. +5. Still required: authoritative PR association, repository-scoped collection, artifact retrieval, + workflow integration, and the bounded-versus-full main routing contract. + +Acceptance remains: + +- at least 20 usable merged-PR observations after the last relevant planner fix; +- zero false reds in the accepted window; +- full recall for every lane family proposed for selection; +- bounded normal-merge verification; +- full hosted escalation for direct/bypass push, missing/expired/ambiguous evidence, moved base, + invalid receipt, collector failure, or policy mismatch. + +Do not register `Smart CI / Required Gate` while the development repository is public. + +### 3.3 CI-17 private-cutover rehearsal + +Owner: `#3170`; prerequisite work includes PR `#3297`; human execution owner is `#2337`. + +PR `#3297` inventories runner jobs and reusable-workflow call edges. It is a non-activating +prerequisite, not the rehearsal mechanism or security boundary. + +The final CI-17 implementation must: + +- derive rehearsal mode from trusted protected-base code; +- cover required, called, and reusable workflows transitively; +- suppress all private hosted Windows work before runner association; +- preserve non-vacuous Linux, security, governance, receipt, and control-plane evidence; +- detect unsupported, missing, ambiguous, or drifted coverage and fail closed; +- emit an exact-identity receipt; +- prove R0, R2, R4, normal merge, nightly, and no-publish release scenarios. + +The cutover stops if any hosted Windows job is scheduled, any expected evidence is absent, or the +mode can be selected or weakened by untrusted head code. + +### 3.4 Windows qualification reliability + +Owners: `#2378` and `#2588`; delivered timeout evidence: closed `#3158` and merged PR `#3162`. + +- PR `#3162` merged on 2026-09-19 with the calibrated outer timeout, per-test hang detection, + process-tree termination, mini-dump support, and partial-results upload. +- Post-merge 45-minute ceiling occurrences under runner contention remain evidence to classify, not + proof that the timeout contract is missing. +- Existing launcher/runner timing issues close only on causal repair, a proven superseding contract, + or an explicit residual decision. Same-head reruns cannot erase the original failure. + +### 3.5 Least privilege and hosted control proof + +Owner: `#2335`; delivered implementation: merged PR `#2838`. + +`sha_pinning_required: true` is already enabled. PR `#2838` merged on 2026-09-19 with checkout +credential-persistence coverage and Pages permission scoping. Remaining work is to reconcile the +issue's acceptance, retain hosted-only control-path proof, record the maintainer's control-plane +ruling, and choose an explicit CodeQL posture. + +### 3.6 Storage under the settled `$0` posture + +Owner: `#2333`. + +1. Refresh the identity-bound inventory and cleanup dry run. +2. Preserve release, provenance, and required audit evidence. +3. Obtain authorization for the exact current deletion set. +4. Execute only that set. +5. Record requested, deleted, skipped, failed, and not-found outcomes. +6. Remeasure unexpired artifacts and caches. +7. Prove the private posture is sustainable without paid overage. + +### 3.7 Nightly, weekly, and exact-tag qualification + +Owner: `#2334`. + +- Accept the change-driven nightly observation window. +- Prove the weekly full Linux, Windows, browser, security, container, and performance sweep. +- Keep mutation manual unless ADR-0052 changes. +- Prove the frozen head through the CI-17 Linux-only no-publish path. +- Prove a draft-only publication hold before tag creation. +- Create the real tag, then qualify hosted Linux/control work and isolated Windows release work + against one immutable identity. + +### 3.8 Public mirror and package continuity + +Owner: `#2439`. + +The accepted mirror is `Chris0Jeky/taskdeck-release` with mirror Actions disabled. Required work: + +- create the repository and narrowly scoped credential; +- implement the private-side fail-closed exporter/publisher; +- exclude private control-plane and agent-instruction material; +- make release GHCR packages explicitly public before privacy; +- verify anonymous GHCR access before and after the flip; +- publish the private Release first; +- stage and re-download/verify the mirror source and byte-identical assets before making them public; +- move public install, support, security, licensing, telemetry, and launch links to verified public + destinations. + +### 3.9 Runner isolation and association + +Owner: `#2328`. + +Prove isolated VMs, no host mounts or personal credentials, one job per host, read-only ordinary +tokens, cleanup, offline behavior, hosted override, reset, detachment, revocation, and incident +response before GitHub association. + +PR `#3261` is a stale recovery branch with a blocking nested reparse-point gap. Port a corrected, +minimal current-main slice; do not merge the branch wholesale. + +### 3.10 Human cutover and release + +Owner: `#2337` and the maintainer. + +Canonical order: + +1. pause merges and capture settings plus rollback values; +2. complete sections A-J of the cutover checklist; +3. make GHCR public and verify anonymously; +4. change the development repository to private; +5. register `Smart CI / Required Gate` and retained security contexts; +6. apply the evidence-based strict/admin/break-glass policy; +7. run the CI-17 Linux-only rehearsal with all self-hosted runners unassociated; +8. associate only already-proven runners and prove the separate Windows/self-hosted contract; +9. freeze one final head and repeat the no-publish rehearsal; +10. activate the publication hold and create `v0.3.0`; +11. qualify the exact tag on approved hosted Linux/control and isolated Windows release lanes; +12. publish the private Release; +13. stage, verify, and publish the public mirror; +14. verify source, assets, checksums, provenance, links, GHCR, and downloads anonymously; +15. announce only after every public identity and access check matches. + +## 4. Open milestone routing + +This is a routing aid, not a substitute for live issue bodies or final maintainer dispositions. + +### CI and release-control issues + +`#2324`, `#2326`, `#2327`, `#2328`, `#2329`, `#2331`, `#2332`, `#2333`, `#2334`, `#2335`, +`#2337`, `#2378`, `#2439`, `#2508`, `#2588`, `#3170`. + +### Product, trust, acceptance, and residual issues + +`#1131`, `#1307`, `#1309`, `#1772`, `#1940`, `#1949`, `#1999`, `#2004`, `#2009`, `#2214`, +`#2315`, `#2499`. + +### Final documentation and launch closeout + +`#2235`, `#2391`. + +`#2315` retains its explicit non-blocking residual ruling. Every other issue must close, move, or +receive its own recorded ruling before final release. + +## 5. Human decisions and actions + +Do not infer completion of any item in this section. + +- Final per-issue milestone disposition. +- CLI local-admin versus claims-first posture for `#1131`. +- MCP runtime hash-approval posture for `#1309`. +- Branch-current strictness, administrator enforcement, and break-glass after Smart CI evidence. +- CodeQL posture for `#2335`. +- Remaining private-instance choices and execution for `#1772`. +- Exact storage deletion authorization for `#2333`. +- Mirror repository and credential creation for `#2439`. +- Repository privacy, required-check, branch-policy, and runner-association actions for `#2337`. +- Frozen release commit, final tag, private Release, mirror publication, and announcement. + +## 6. Definition of done + +`v0.3.0` is ready only when: + +- every milestone issue is closed, moved, or covered by an explicit residual ruling; +- no release-critical PR is parked behind an unrecorded decision; +- the exact frozen head is green under the final required-check configuration; +- landed verification and full escalation are proven with authoritative evidence; +- Smart CI observation and recall thresholds are accepted; +- artifact/cache posture fits the settled private budget; +- runner isolation and recovery are proven before association; +- CI-17 schedules zero private hosted Windows work and preserves all expected evidence; +- GHCR is anonymously accessible before and after privacy; +- the real tag is rebuilt and qualified after it exists; +- hosted Linux/control and isolated-Windows evidence bind one tag, commit, policy, checksums, + provenance, and release contract; +- the release workflow cannot publish before the hold is released; +- the private Release contains the exact qualified body and assets; +- the public mirror republishes corresponding source and byte-identical assets through staged + verification; +- anonymous verification passes; +- archive, container, MCP proposal flow, install, update, upgrade, and supported backup claims are + consumer-smoked; +- documentation and known limitations match shipped reality; +- announcement happens last. + +## 7. Keeping this current + +When release state changes: + +1. Re-read the live milestone, open issue bodies, open PR bases, branch protection, releases, and + exact-head checks. +2. Update this file only for programme state, gates, or sequencing. +3. Update `docs/STATUS.md` only for merged shipped behavior. +4. Update `docs/IMPLEMENTATION_MASTERPLAN.md` for durable delivery history and execution changes. +5. Update the cutover checklist and `#2337` together if the human sequence changes. +6. Preserve dated assessments as historical evidence rather than rewriting their snapshots. +7. Record destructive or settings actions only after exact read-back evidence exists. diff --git a/docs/strategy/PRODUCT_DIRECTION.md b/docs/strategy/PRODUCT_DIRECTION.md index 0b7e4c278f..2fda05f03b 100644 --- a/docs/strategy/PRODUCT_DIRECTION.md +++ b/docs/strategy/PRODUCT_DIRECTION.md @@ -1,6 +1,6 @@ # Taskdeck Product Direction -Last Updated: 2026-09-11 +Last Updated: 2026-09-21 **Status: ACTIVE — the canonical current strategy document.** **Authority:** this file owns the product identity, direction, and release-theme ladder. The active @@ -106,7 +106,7 @@ an Accepted ADR today, the ADR wins. |---|---|---|---| | **v0.1.x** | **Honest Windows Beta** | v0.1.0, v0.1.1, and v0.1.2 are shipped facts (v0.1.2 tagged 2026-08-25 at `9766edbb5` under the maintainer's accepted release deck; milestone closed, residuals re-milestoned to v0.2). Windows stays the only supported desktop claim through v0.1.x; macOS is the next platform proof. | COMMITTED | | **v0.2** | **Coherent Context-to-Action Loop** | **v0.2.0 shipped 2026-08-29** (tag at `48c05e1dc`; milestone closed 0/15 under the maintainer's accepted release deck, `#1947`). The **theme** was the former "Transcript Engine" scope (LLM transcript triage, durable transcripts, evidence spans) widened to one coherent loop: capture integrity, grounded chat that always yields a proposal or an explicit inability, evidence/inference inspection and correction, review legibility, guided daily journey, and a victory/progress export candidate. **What actually shipped:** capture integrity (no silently dropped fields), evidence/inference inspection and correction, review legibility, the guided daily journey, a victory/progress export candidate, and — of the chat theme — the **honesty slice only** (`#2074`: an unbound session now says it cannot act instead of answering with prose that reads like completed work). **Not shipped, carried forward:** the grounding half of that theme — `#2004` stays open, and `docs/STATUS.md` records that a bound session can still end an actionable turn in silent prose, so "always yields a proposal or an explicit inability" is the destination, not the delivered state. Carried-forward residuals live on their issues (`#2141`, `#2142`, `#2004`, `#1940`, `#2130`, `#2185`, `#2192`–`#2195`), not in this row. | COMMITTED (shipped) | -| **v0.3** | **Accountable Agents + Downloadable Beta** | The REVIVAL Phase-3 downloadable release (Windows ZIP + self-host container): packaged MCP with scoped credentials and attribution, Review liveness, honest triage degradation, a double-click start that survives leftover provider settings, the trusted private-instance proof (#1772 Stage 1), and the fix/improvement queue the maintainer pulled into the milestone on 2026-08-30. **`v0.3.0-rc.1` shipped 2026-08-30** as a GitHub pre-release (tag at `9d2ea3c7c`); final ships when ready, no fixed date (RC deck q-6). **The repository goes private for the v0.3.0 release** on the maintainer's personal GitHub Pro account (maintainer directive 2026-08-30; ADR-0066, tracker CI-00 `#2324`, human gate CI-13 `#2337`) — CI is re-planned as the Smart CI Fabric so verification stays rigorous inside the Pro allowance, and the launch kit's public-source assumptions (`#2242`) are re-decided on CI-13. | COMMITTED | +| **v0.3** | **Accountable Agents + Downloadable Beta** | The REVIVAL Phase-3 downloadable release (Windows ZIP + self-host container): packaged MCP with scoped credentials and attribution, Review liveness, honest triage degradation, a double-click start that survives leftover provider settings, the trusted private-instance proof (#1772 Stage 1), and the retained fix/improvement queue. **`v0.3.0-rc.1` shipped 2026-08-30** as a GitHub pre-release (tag at `9d2ea3c7c`); final ships when ready, no fixed date. **The development repository goes private for `v0.3.0`** on the maintainer's personal GitHub Pro account under ADR-0066 and CI-13 `#2337`. Public source and release continuity use the approved `Chris0Jeky/taskdeck-release` mirror and public GHCR path (`#2439`). Before runner association, CI-17 `#3170` must prove a fail-closed Linux-only private rehearsal across the workflow graph. | COMMITTED | | **v0.4** | **Hosted Open Beta + Work Model + Fabric Foundation** | The *actual* open beta: Taskdeck reachable from anywhere with no download or install (maintainer direction 2026-08-30, umbrella `#2243`; ADR-0061 stages → open registration under the beta threat model, `#1653`, `#1992`, opt-in analytics `#1308`), the work-model slices (`#2087` `#2089` `#2092` `#2093`), refactoring `#2236` and performance `#2237` passes, **the behaviour-preserving Context Fabric foundation** (ADR-0065 slices 1–3 + the storage seam: CF-01/02/03/05/06/07 `#2255`–`#2257`, `#2259`–`#2261`, CF-23 `#2276`), and the Worker Protocol host CF-04 `#2258` (slice 5, the one non-behaviour-preserving item) because the ADR-0048 extraction worker `#1429` is its first sidecar. The former "Every Artefact" third (GEN-03/04/06) moved into the Context Fabric issues; `#1327` stays the GEN tracker for GEN-07/08/11/12. Renamed 2026-08-30 under the CF-00 delegation (ruling 2). Runs under four internal gates (A Fabric persistence · B processor containment · C trusted hosted instance · D public hosted beta), public registration last; milestone membership alone makes no child a release blocker (external audit 2026-08-30, implemented the same day). | LEANING (hosted beta COMMITTED 2026-08-30; foundation placement confirmed 2026-08-30 with gates) | | **v0.5** | **Speak, Type, Paste, or Drop** | The Context Fabric payoff: persisted semantic candidates (CF-08), the boardless context resolver shared with chat (CF-09), the voice vertical (audio source CF-12, lightweight local STT spike CF-13, WhisperX sidecar CF-14, voice-note UX with audio evidence playback CF-16), Universal Capture (CF-20, absorbing GEN-06 `#1320`), capture-centred review + receipts + Flow/Guided/Control presentation profiles (CF-21), and GEN-03 `#1317` as one registered vision processor. Ships when the first vertical (voice note → time-anchored transcript → reviewable proposal → approve → apply → playback) is live-verified and one speech route is genuinely accessible to an ordinary user (CF-13 one-click / downloaded-on-enable / bundled, or a consented managed route — the manually configured WhisperX environment is a dogfooding route, not the public promise); no dates. | LEANING | | **v0.6** | **Under Your Rules** | Processing profiles Private/Balanced/Strict/Expert + router v1 + route receipts (CF-10), result cache + selective escalation (CF-11), one cloud speech adapter + benchmark harness (CF-15), local OCR sidecar (CF-18), the meeting understanding bundle (CF-17), the runtime outcome metrics + dashboard (CF-24B; the corpus CF-24A `#2319` lands in v0.5), and the **first** delegated-authority slice (CF-22 — ADR-0057's create-card-under-Assist class; stretch, not a release blocker, behind its own risk-based evidence gate). | LEANING | @@ -122,6 +122,33 @@ no due dates). Git tags and releases are historical artifacts, never edited to m The wave map and dependency order for v0.4–v0.6 live on tracker CF-00 `#2254` and in `docs/architecture/CONTEXT_FABRIC.md`. +### Current delivery focus (2026-09-21) + +The release-theme ladder is unchanged. The current programme is **v0.3 release convergence**, not +an early start on the v0.4 hosted-beta promise. + +Between 2026-09-18 and 2026-09-21 the repository exposed a repeated correctness theme across HTTP, +stores, realtime, review, metrics, audit, feature flags, proposal execution, expiry and CI: late work +must settle only into the route, session, credential, request generation, object identity, +transaction, policy and exact source revision that initiated it. The same period also split the +remaining release-control work into explicit receipt, collector, CI-17 inventory/rehearsal, runner, +storage, least-privilege, mirror and exact-tag slices. + +This does not redefine the product. It is the work required to make the existing v0.3 promise +credible: + +- finish retained trust and correctness defects rather than broaden the surface; +- make CI and release evidence exact-identity and fail-closed; +- prove the private-development cutover without private hosted Windows execution; +- preserve public source, packages and release assets through the mirror; +- qualify the real tag before publishing or announcing it. + +The current programme map and admission rules are in the +[2026-09-21 repository direction and v0.3 programme brief](../analysis/2026-09-21-repository-direction-and-v0.3-programme.md). +The operational gate view is +[`docs/releases/V0_3_0_READINESS.md`](../releases/V0_3_0_READINESS.md). Future-horizon work remains +valid direction, but it does not displace release-critical v0.3 work by convenience. + ### Work-model delivery implications (2026-09-11) **SHIPPED:** true card archive/restore, Task/Epic/Spike and same-board hierarchy now extend From aabee109af2550ae37a463aeb85afec4e8c86e86 Mon Sep 17 00:00:00 2001 From: Cristian Tcaci <59696583+Chris0Jeky@users.noreply.github.com> Date: Tue, 22 Sep 2026 00:00:35 +0100 Subject: [PATCH 2/7] chore: add review-fix patch chunk 00 --- .github/docs-reviewfix.part-00 | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) create mode 100644 .github/docs-reviewfix.part-00 diff --git a/.github/docs-reviewfix.part-00 b/.github/docs-reviewfix.part-00 new file mode 100644 index 0000000000..734f285d08 --- /dev/null +++ b/.github/docs-reviewfix.part-00 @@ -0,0 +1,25 @@ +diff --git a/docs/STATUS.md b/docs/STATUS.md +index e9c828d..713e713 100644 +--- a/docs/STATUS.md ++++ b/docs/STATUS.md +@@ -1,9 +1,19 @@ + # Taskdeck Status (Source of Truth) + +-Last Updated: 2026-09-20 ++Last Updated: 2026-09-21 + + GitHub Pages (`https://chris0jeky.github.io/Taskdeck/`) now runs as a static demo: empty `VITE_API_BASE_URL` plus `VITE_DEMO_MODE=true`, runtime Pages+loopback detection, and an axios demo adapter so review, chat, and card parent/assignee reads never call `localhost:5000`. Home and Review share the same one pending demo proposal. Local Vite with `.env` still uses the real local API. This is not a hosted backend; that remains later work. Detection: `frontend/taskdeck-web/src/utils/apiBaseUrl.ts`. Operator notes: `docs/product/DEMO_PLAYBOOK.md`. + ++## CI least-privilege delivery checkpoint (#2335) ++ ++PR `#2838` merged on 2026-09-19 as `32e2374ef`. It delivered ++`persist-credentials: false` on all 48 checkout steps and scoped Pages write/OIDC permissions to the ++deployment boundary. Full-SHA action pinning and `sha_pinning_required: true` were already complete. ++This supersedes the 2026-09-10 historical block below that described `#2838` as parked and its ++checkout-credential work as open. Remaining `#2335` work is operational rather than a replay of the ++merged patch: retain/reconcile hosted-only control-path evidence, record the standing maintainer ++review rule for new control-plane PRs, and choose the v0.3 CodeQL posture. ++ + ## Local checklist bootstrap no longer holds an LLM quota slot (#1431 L3) + + A deterministic checklist-bootstrap chat turn never reaches a provider, but `ChatService` used to From a4d8d2c9163dee46fa56b8d510a8ca5e5d6b017e Mon Sep 17 00:00:00 2001 From: Cristian Tcaci <59696583+Chris0Jeky@users.noreply.github.com> Date: Tue, 22 Sep 2026 00:00:47 +0100 Subject: [PATCH 3/7] chore: add review-fix patch chunk 01 --- .github/docs-reviewfix.part-01 | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) create mode 100644 .github/docs-reviewfix.part-01 diff --git a/.github/docs-reviewfix.part-01 b/.github/docs-reviewfix.part-01 new file mode 100644 index 0000000000..2866c3b279 --- /dev/null +++ b/.github/docs-reviewfix.part-01 @@ -0,0 +1,22 @@ +diff --git a/docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md b/docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md +index f1a1538..56582bc 100644 +--- a/docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md ++++ b/docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md +@@ -115,10 +115,12 @@ actions. Never infer a human action from repository state or an issue comment. + - [x] Every external `uses:` is pinned to a full commit SHA and the pin inventory guard is green. + - [x] `sha_pinning_required: true` is enabled and read back from GitHub. + - [ ] Default workflow tokens are read-only; every elevated job is justified and scoped. +-- [ ] `persist-credentials: false` is present wherever a checkout does not need push credentials. ++- [x] `persist-credentials: false` is present wherever a checkout does not need push credentials; ++ merged PR `#2838` delivered the 48-step inventory and Pages permission scoping. + - [ ] No `pull_request_target` path checks out or executes untrusted head code. +-- [ ] CI-control changes have a hosted-only trust fixture. +-- [ ] PR `#2838` is current-head qualified and passes the ADR-0066/J.3 maintainer gate. ++- [ ] CI-control changes have a hosted-only trust fixture and the current evidence is reconciled. ++- [x] PR `#2838` is merged; do not replay or re-park its delivered checkout/Pages patch. ++- [ ] The maintainer records the standing review/merge rule for new ADR-0066 control-plane PRs. + - [ ] CodeQL is re-enabled in an approved lane or the current scanner posture and residual are recorded. + + ## H. Pre-cutover nightly and release contract (CI-10 `#2334`) +diff --git a/OUTSTANDING_TASKS.md b/OUTSTANDING_TASKS.md +index dac1418..de3047d 100644 From fd3a9377fabdf23ebfc396e3910a2102e51f7094 Mon Sep 17 00:00:00 2001 From: Cristian Tcaci <59696583+Chris0Jeky@users.noreply.github.com> Date: Tue, 22 Sep 2026 00:01:08 +0100 Subject: [PATCH 4/7] chore: add review-fix patch chunk 02 --- .github/docs-reviewfix.part-02 | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) create mode 100644 .github/docs-reviewfix.part-02 diff --git a/.github/docs-reviewfix.part-02 b/.github/docs-reviewfix.part-02 new file mode 100644 index 0000000000..f4956cee37 --- /dev/null +++ b/.github/docs-reviewfix.part-02 @@ -0,0 +1,24 @@ +--- a/OUTSTANDING_TASKS.md ++++ b/OUTSTANDING_TASKS.md +@@ -212,6 +212,9 @@ September 18-21 implementation wave. It does not replace the detailed evidence a + - [ ] Record the standing review/merge rule for **new** ADR-0066 control-plane PRs after the named + September directives. J.3(b) remains unanswered; do not infer a permanent waiver from a completed + wave. ++- [ ] Choose and record the v0.3 CodeQL posture for `#2335`: re-enable CodeQL in an approved hosted ++ lane, or retain the current scanners with an explicit reason and residual. The merged `#2838` ++ least-privilege patch does not decide this. + - [ ] Review the current landed-verifier and CI-17 stacks in dependency order: parent `#3295` before + stacked child `#3296`, and non-activating inventory `#3297` before the actual `#3170` rehearsal + control. Automated green evidence is not the human approval. +diff --git a/docs/REVIVAL_PLAN.md b/docs/REVIVAL_PLAN.md +index a6a80a8..6a464d3 100644 +--- a/docs/REVIVAL_PLAN.md ++++ b/docs/REVIVAL_PLAN.md +@@ -82,10 +82,11 @@ Sequence: + integration and rebuild the observation evidence. + 3. **Finish CI-17.** Qualify the non-activating workflow inventory in `#3297`, then implement the + trusted, fail-closed Linux-only rehearsal owned by `#3170`. +-4. **Close release prerequisites.** Reconcile post-merge Windows timeout evidence after `#3162`, +- finish the remaining `#2335`/CodeQL acceptance after merged `#2838`, and complete storage +- (`#2333`), nightly/exact-tag qualification (`#2334`), runner proof (`#2328`), and mirror/GHCR +- continuity (`#2439`). From a8c9d7328ccc6977097b8ada2c6b7851bf8e2575 Mon Sep 17 00:00:00 2001 From: Cristian Tcaci <59696583+Chris0Jeky@users.noreply.github.com> Date: Tue, 22 Sep 2026 00:01:26 +0100 Subject: [PATCH 5/7] chore: add review-fix patch chunk 03 --- .github/docs-reviewfix.part-03 | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) create mode 100644 .github/docs-reviewfix.part-03 diff --git a/.github/docs-reviewfix.part-03 b/.github/docs-reviewfix.part-03 new file mode 100644 index 0000000000..7160328b4f --- /dev/null +++ b/.github/docs-reviewfix.part-03 @@ -0,0 +1,19 @@ ++4. **Close pre-cutover release prerequisites.** Reconcile post-merge Windows timeout evidence ++ after `#3162`, finish the remaining `#2335`/CodeQL acceptance after merged `#2838`, and complete ++ storage (`#2333`), the nightly/release contract plus no-publish rehearsal (`#2334`), runner proof ++ (`#2328`), and mirror/GHCR continuity (`#2439`). Real-tag creation and exact-tag qualification ++ remain step 7, after privacy and the runner decision. + 5. **Reconcile all open milestone issues.** Close on evidence, split real residuals, or record an + explicit maintainer ruling. Preserve `#2315`'s existing residual ruling unless changed. + 6. **Execute the human cutover.** Follow `docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md`: public GHCR, +diff --git a/docs/analysis/2026-09-21-repository-direction-and-v0.3-programme.md b/docs/analysis/2026-09-21-repository-direction-and-v0.3-programme.md +index a2b9a27..0930382 100644 +--- a/docs/analysis/2026-09-21-repository-direction-and-v0.3-programme.md ++++ b/docs/analysis/2026-09-21-repository-direction-and-v0.3-programme.md +@@ -121,7 +121,8 @@ priority. The controlling release sequence is: + 1. finish admitted exact-identity correctness stacks without widening into adjacent refactoring; + 2. finish Smart CI proof and authoritative landed-evidence integration; + 3. implement and prove CI-17 after its non-activating inventory prerequisite; +-4. close Windows, least-privilege, storage, nightly, runner, and mirror/GHCR prerequisites; ++4. close Windows, least-privilege, storage, pre-cutover nightly/release-contract, runner, and ++ mirror/GHCR prerequisites; From a981bc478939f88fd8e088838db8845b88fed461 Mon Sep 17 00:00:00 2001 From: Cristian Tcaci <59696583+Chris0Jeky@users.noreply.github.com> Date: Tue, 22 Sep 2026 00:01:36 +0100 Subject: [PATCH 6/7] chore: add review-fix patch chunk 04 --- .github/docs-reviewfix.part-04 | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) create mode 100644 .github/docs-reviewfix.part-04 diff --git a/.github/docs-reviewfix.part-04 b/.github/docs-reviewfix.part-04 new file mode 100644 index 0000000000..2e9f3b1b7b --- /dev/null +++ b/.github/docs-reviewfix.part-04 @@ -0,0 +1,25 @@ + 5. reconcile every open milestone issue on the resulting evidence, while doing obvious close-on- + evidence updates continuously rather than waiting for a final batch; + 6. execute the human private-repository cutover in the canonical checklist order; +diff --git a/docs/releases/V0_3_0_READINESS.md b/docs/releases/V0_3_0_READINESS.md +index 572616b..0069a01 100644 +--- a/docs/releases/V0_3_0_READINESS.md ++++ b/docs/releases/V0_3_0_READINESS.md +@@ -55,7 +55,8 @@ list. The controlling sequence is: + 1. finish admitted exact-identity correctness stacks; + 2. finish Smart CI proof and authoritative landed-evidence integration; + 3. implement and prove CI-17; +-4. close Windows, least-privilege, storage, nightly, runner, and mirror/GHCR prerequisites; ++4. close Windows, least-privilege, storage, pre-cutover nightly/release-contract, runner, and ++ mirror/GHCR prerequisites; + 5. reconcile every milestone issue on the resulting evidence, while applying obvious close-on- + evidence updates continuously; + 6. execute the human cutover; +diff --git a/docs/IMPLEMENTATION_MASTERPLAN.md b/docs/IMPLEMENTATION_MASTERPLAN.md +index a7cd53a..c6b860b 100644 +--- a/docs/IMPLEMENTATION_MASTERPLAN.md ++++ b/docs/IMPLEMENTATION_MASTERPLAN.md +@@ -24,10 +24,11 @@ Current release-control order: + 2. landed receipt foundations are merged in `#3156` and `#3167`; qualify active parent `#3295` + before stacked child `#3296`, then add authoritative collector/workflow integration; + 3. qualify non-activating CI-17 inventory `#3297`, then implement trusted rehearsal control `#3170`; From 94180660a624a983f9da8a49d4e4fd53c155d54e Mon Sep 17 00:00:00 2001 From: Cristian Tcaci <59696583+Chris0Jeky@users.noreply.github.com> Date: Tue, 22 Sep 2026 00:01:48 +0100 Subject: [PATCH 7/7] chore: add review-fix patch chunk 05 --- .github/docs-reviewfix.part-05 | 12 ++++++++++++ 1 file changed, 12 insertions(+) create mode 100644 .github/docs-reviewfix.part-05 diff --git a/.github/docs-reviewfix.part-05 b/.github/docs-reviewfix.part-05 new file mode 100644 index 0000000000..b9ac0c79b8 --- /dev/null +++ b/.github/docs-reviewfix.part-05 @@ -0,0 +1,12 @@ +-4. close release prerequisites: post-merge Windows timeout evidence and `#2378`/`#2588`, remaining +- `#2335`/CodeQL acceptance after merged `#2838`, storage `#2333`, nightly/exact-tag qualification +- `#2334`, corrected current-main runner preparation for `#2328`, and mirror/GHCR continuity +- `#2439`; ++4. close pre-cutover release prerequisites: post-merge Windows timeout evidence and ++ `#2378`/`#2588`, remaining `#2335`/CodeQL acceptance after merged `#2838`, storage `#2333`, the ++ nightly/release contract plus no-publish rehearsal for `#2334`, corrected current-main runner ++ preparation for `#2328`, and mirror/GHCR continuity `#2439`; real-tag creation and exact-tag ++ qualification remain step 7; + 5. reconcile the milestone through `#2235`, preserving explicit residual rulings; + 6. execute the human cutover `#2337`; + 7. freeze the final head, create and qualify the real tag, publish the private Release, mirror it