From 509ea7e9f3e293bf88eb68aed6c1c434630a7c57 Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 12:50:59 +0900 Subject: [PATCH 01/32] docs: refresh live product gap baseline --- docs/product-technical-gap-baseline.md | 73 ++++++++++++-------------- 1 file changed, 34 insertions(+), 39 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 20c0cf5a0..25c767f1c 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Audit snapshot: 2026-08-25 12:07 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 12:47 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -9,38 +9,30 @@ ## 1. Exact-head and governance evidence -The protected default branch was `965c798de5f789db245625e06e03c1563163051f` -when this baseline was refreshed. The live queue contained 24 open PRs and 22 +The protected default branch was `b7714c5520b0e6c7f8e73af9adfc62e7841a0362` +when this baseline was refreshed. The live queue contained 16 open PRs and 21 open issues. The exact-head inventory below supersedes older per-PR snapshots elsewhere in this document; those older rows remain useful historical delivery context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | -| #598 | `63db0854` | reads 5W1H roles/events across a stale summary contract version; exact-head checks and independent review pending | -| #597 | `8e132b5b` | clears stale related-post graph state before opening Customer Master detail in place; auto-merge armed, exact-head checks and independent review pending | -| #596 | `edb24472` | aligns the two orchestrator-backed hierarchy/name-resolution clients with the existing bounded 600-second deep-work window and verifies both defaults; exact-head checks and independent review pending | -| #595 | `9378c04f` | restores the audited no-draft-dimension import door and nullable updated-at fallback orphaned by the prior stack race; result typing repaired, 24 focused tests passed, auto-merge armed | -| #591 | `ea5e72f5` | canonical current-queue baseline; this refresh supersedes the observed head, so checks and review restart | -| #588 | `3a67a802` | reconstruction naming reconciled with current main; auto-merge armed, checks pending | -| #585 | `ffe1290b` | only locally-authored bounded job errors may persist; transport errors remain generic; auto-merge armed, checks restarted | -| #584 | `17068ec3` | current-main ADR collision repaired; auto-merge armed, checks restarted | -| #582 | `3992302f` | batched Ask lineage graph reconciled with current main and the conflict-tail repair; auto-merge armed, checks restarted | -| #581 | `c1b424eb` | concurrent exact-head update observed after event-time Ask reconciliation; checks and review pending | -| #579 | `69c05078` | interaction-map migration and hosted SQL-suppression inventory reconciled; auto-merge armed | -| #564 | `212b55a9` | concurrent exact-head update observed; checks and review pending | -| #563 | `353b7470` | concurrent exact-head update observed after raw-residual identity repair; checks and review pending | -| #539 | `e4dffe63` | concurrent exact-head update observed; checks and review pending | -| #537 | `d5ac65d8` | current-main reconciliation pushed; checks restarted | -| #493 | `e9c63d56` | concurrent exact-head update observed; checks and review pending | -| #490 | `73413d0b` | code-quality findings repaired; current-main reconciliation remains before checks can settle | -| #484 | `fa898bc5` | concurrent exact-head update observed after Allen interval reconciliation; checks and review pending | -| #482 | `b0e737d3` | concurrent exact-head update observed after the corroborated-SKOS reconciliation; exact-head checks and review pending | -| #468 | `a14093a3` | exact Keyverse org/PU scope persists in 3NF job child tables and is intersected with current grants; provider-shape, completeness-gate, role-intersection, and TEPP-contract reviews repaired; current main merged, 52 focused tests passed, auto-merge armed | -| #434 | `ff34c9b6` | stacked on #387; review findings repaired, but the stack remains conflicting until its parent delivery boundary settles | -| #394 | `ec74eedd` | indentation evidence composed with current HTTP response-boundary protections; 56 focused tests passed, auto-merge armed | -| #387 | `462b41fb` | budgeted LLM selection precedes exact-channel weight lookup; persistence evidence uses fast-mlsirm estimates, 37 backend tests plus frontend interaction/lint/build passed; auto-merge armed, stale changes-requested state awaits exact-head rereview | -| #383 | `138eaad4` | reader-safe OTel diagnostics composed with current HTTP response bounds; 76 focused tests passed, auto-merge armed | +| #599 | `205b8a51` | raw-residual cross-share documentation aligned with the implementation; no arbitrary weighting introduced; mergeable, auto-merge armed, exact-head checks/review pending | +| #595 | `153127f0` | audited no-draft import door, nullable updated-at fallback, and event-time import composed on current main; 24 focused tests passed; mergeable, auto-merge armed | +| #588 | `3a67a802` | reconstruction naming branch is conflicting; six unresolved review threads remain | +| #582 | `edca49bb` | batched cited-lineage fetch composed with current main; 37 focused tests passed; mergeable, auto-merge armed | +| #579 | `69c05078` | interaction-map coordinate branch is conflicting; nine unresolved review threads remain | +| #564 | `78afd5b8` | reconstruction naming branch is conflicting; review is required on its exact head | +| #539 | `e4dffe63` | explained-share branch is conflicting and its exact-head check rollup is failing | +| #537 | `d5ac65d8` | unexplained-share branch is conflicting; six unresolved review threads and failing exact-head checks remain | +| #493 | `d2ef6b20` | empty-DAG reasons and explicit double-failure alert composed with current main; focused frontend test, lint/build, and docs tests passed; mergeable, auto-merge armed | +| #490 | `73413d0b` | broad historical workspace branch is conflicting with failing checks; decompose/restack rather than replaying its 931-commit merge wholesale | +| #484 | `5a61c5f7` | Allen interval semantics and deferred FK validation are mergeable; two newly opened review threads require settlement | +| #482 | `b0e737d3` | corroborated SKOS companion branch is conflicting; four unresolved review threads remain | +| #468 | `49f8231a` | exact Keyverse org/PU scope, fast-mlsirm/orchestrator/TEPP boundaries, and event-time import were composed with current main; 46 focused tests passed; mergeable, auto-merge armed | +| #434 | `ff34c9b6` | stacked on #387 and conflicting; checks fail although its review threads are settled | +| #387 | `462b41fb` | channel-evidence branch is conflicting with five unresolved threads, failing checks, and a stale changes-requested decision | +| #383 | `138eaad4` | reader-safe OTel branch is conflicting with six unresolved threads and failing checks | No row above is merge evidence. Immediately before any lifecycle action, re-fetch the head, unresolved threads, formal reviews, rulesets, and same-head @@ -76,12 +68,8 @@ Two systemic gates currently dominate the queue: after ~70 s and `openai-direct/gpt-5.6-luna` after ~5 s. This is an infrastructure failure, not a code finding. The durable repair is ContextualWisdomLab/.github#1263 (executable Azure and cross-provider - fallbacks), whose first push was itself blocked by the same replay guard it - fixes because its prior merge commit reverted ten base-merged paths; that - branch was re-based over current `.github` main restoring the reverted work - (vulnerability-location boundary filtering, internal-warning filter, - requirements lock refresh, changed-path workflow state) while preserving - the PR's own failover changes. + fallbacks). Its exact head is `ab3d7645`, remains open/conflicting, and has + not delivered a control-plane repair to protected `.github` main. 2. **Current-head independent approval.** The org merge scheduler requires `reviewDecision == APPROVED` plus complete Strix evidence on the exact head. Bot review evidence regenerates per push, so any repair push resets @@ -92,6 +80,13 @@ Recent protected-default-branch delivery evidence (squash merges onto | PR | Merged (UTC) | Delivered | | ---: | --- | --- | +| #598 | 2026-08-25 03:32 | 5W1H roles/events remain readable across a stale summary contract version | +| #597 | 2026-08-25 03:32 | related posts open Customer Master detail in place without stale graph state | +| #591 | 2026-08-25 03:32 | prior exact-head product-gap baseline snapshot | +| #584 | 2026-08-25 03:32 | TEPP topic-lineage consumption boundary grounded in cited temporal models | +| #581 | 2026-08-25 03:32 | relative-time Ask filtering bound to event time | +| #596 | 2026-08-25 03:27 | hierarchy/name-resolution deep-work timeouts aligned at 600 seconds | +| #585 | 2026-08-25 03:27 | raw Global Ask transport exceptions replaced by bounded client-safe detail | | #355 | 2026-08-25 02:38 | Naruon calendar projection contract and conformance fixture | | #562 | 2026-08-24 02:05 | parameter-free classic RRF; deleted the last hand-picked fused score | | #561 | 2026-08-24 01:47 | knowledge-graph precedence/hierarchy relation classification and layout order | @@ -115,10 +110,10 @@ never force-push or delete evidence ad hoc. The Grok durable hourly loop and the central thin GitHub Actions caller ContextualWisdomLab/.github#1259 (minute 4, `pr-review-fix-scheduler.yml`) both target this repository. Do not add a LineageWeave-local duplicate -workflow. OpenCode coverage-evidence currently fails pnpm 9.15.9 heads on -`--trust-lockfile` (a pnpm 11.3 flag) and on a synthesized Vitest `--coverage` -flag; ContextualWisdomLab/.github#1258 (`9b5dba9`) is the exact-head repair -and has auto-merge armed pending independent OpenCode / Strix / Noema. +workflow. ContextualWisdomLab/.github#1258 merged at exact head `897819c4` to +repair the pnpm/coverage-evidence workflow; newly created exact PR heads must +still prove the runtime behavior because merged workflow source alone is not +check evidence. Figma design-system boundary (ADR 0002): File ID `1Su3lDRmiZdcUs47t1QwIX`. The sanitized file now contains synthetic Event Lineage desktop (`5:14`) and @@ -163,7 +158,7 @@ evidence across heads. The org merge scheduler merges only when | Gate | Evidence | Durable repair | | --- | --- | --- | -| Strix provider unavailability | `nvidia_nim/nemotron-3-super-120b-a12b` exits ~70 s, `openai-direct/gpt-5.6-luna` exits ~5 s on ~28 unrelated heads ("provider/backend was unavailable") | ContextualWisdomLab/.github#1263 — executable Azure/cross-provider fallbacks; its prior merge commit reverted ten base-merged paths, now restored over current `.github` main | +| Strix provider unavailability | `nvidia_nim/nvidia/nemotron-3-super-120b-a12b` and `openai-direct/gpt-5.6-luna` failed authoritatively across unrelated heads | ContextualWisdomLab/.github#1263 at `ab3d7645` proposes executable Azure/cross-provider fallbacks but remains open/conflicting; repair that branch without weakening the required gate | | ADR 0109 login repair debt | Eight branches cut from the pre-repair base carried the unauthenticated `AdminPanel` + unused-OIDC-helper `tsc -b` failure | Same verified two-line repair applied to #521, #522, #552, #553, #554, #556, #558, #560 during this loop; frontend lint/test/build verified locally | ### 3.1 Workspace root and product surfaces @@ -357,7 +352,7 @@ Process every open PR in ascending number order, considering leverage; for each: check reviews → repair → re-verify Checks → merge → continue. Checks and review latency are never blockers — keep working while they settle. -1. **Unblock Strix org-wide** by landing ContextualWisdomLab/.github#1263 +1. **Unblock Strix org-wide** by reconciling and landing ContextualWisdomLab/.github#1263 (fallbacks executable), then rerun failed strix jobs across the queue. 2. Merge ascending from #258 once each head shows terminal green required checks plus current-head independent approval. The leftover-map ladder From 6bb3a2ebfbba6bc035752119b53beed98dbbd9ef Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 13:06:42 +0900 Subject: [PATCH 02/32] docs: align protected-release queue count --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 25c767f1c..0a2fbf518 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -259,7 +259,7 @@ this file per §3.5 of the prior snapshot). | Gap | Current evidence | Acceptance requirement | | --- | --- | --- | -| Protected release | 24 open PRs at snapshot; the queue is gated mainly by per-head independent approvals and pending hosted checks; #355 landed during this window | Terminal exact-head checks, no unresolved threads, independent exact-head approvals, protected squash-merge SHA | +| Protected release | 16 open PRs at snapshot; the queue is split between mergeable heads awaiting independent review/checks and older conflicting stacks | Terminal exact-head checks, no unresolved threads, independent exact-head approvals, protected squash-merge SHA | | Shared frontend gate | The ADR 0109 login repair is on protected `main`; eight older branches carried the defect and received the same verified repair this loop (#521–#560) | Keep every future branch cut from post-repair bases; re-verify with frontend lint/test/build before push | | Identifying baseline regression | `main` gap file listed real post identifiers; separately, closed #506 and pre-existing public history contain a private runtime source-table identifier, while current `main` and #507 trees are clean | Land this non-identifying rewrite, then coordinate ADR 0001 history remediation with security/privacy owners; do not reproduce the value, force-push, or delete evidence ad hoc | | Authorized-corpus runtime | Repository tests use synthetic fixtures; private records remain outside git | Authenticated runtime validation returning only aggregate, non-identifying evidence | From d3bc3f019ff5a8a957b6137e03640f0947fe6bab Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 13:34:53 +0900 Subject: [PATCH 03/32] docs: refresh exact-head queue after protected merges --- docs/product-technical-gap-baseline.md | 24 ++++++++++++------------ 1 file changed, 12 insertions(+), 12 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 0a2fbf518..37b9cfdfb 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Audit snapshot: 2026-08-25 12:47 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 13:33 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -9,30 +9,29 @@ ## 1. Exact-head and governance evidence -The protected default branch was `b7714c5520b0e6c7f8e73af9adfc62e7841a0362` -when this baseline was refreshed. The live queue contained 16 open PRs and 21 +The protected default branch was `3ac4ff1e7387b8f243cbb0fb20e7ff3ed80f3716` +when this baseline was refreshed. The live queue contained 15 open PRs and 21 open issues. The exact-head inventory below supersedes older per-PR snapshots elsewhere in this document; those older rows remain useful historical delivery context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | -| #599 | `205b8a51` | raw-residual cross-share documentation aligned with the implementation; no arbitrary weighting introduced; mergeable, auto-merge armed, exact-head checks/review pending | +| #600 | `7580bdc9` | this baseline's pre-amendment observed head; mergeable and auto-merge armed, but its exact-head check rollup failed and must be revalidated after this refresh | | #595 | `153127f0` | audited no-draft import door, nullable updated-at fallback, and event-time import composed on current main; 24 focused tests passed; mergeable, auto-merge armed | | #588 | `3a67a802` | reconstruction naming branch is conflicting; six unresolved review threads remain | | #582 | `edca49bb` | batched cited-lineage fetch composed with current main; 37 focused tests passed; mergeable, auto-merge armed | | #579 | `69c05078` | interaction-map coordinate branch is conflicting; nine unresolved review threads remain | -| #564 | `78afd5b8` | reconstruction naming branch is conflicting; review is required on its exact head | +| #564 | `78afd5b8` | reconstruction naming branch is conflicting; exact-head checks fail and review is required | | #539 | `e4dffe63` | explained-share branch is conflicting and its exact-head check rollup is failing | | #537 | `d5ac65d8` | unexplained-share branch is conflicting; six unresolved review threads and failing exact-head checks remain | -| #493 | `d2ef6b20` | empty-DAG reasons and explicit double-failure alert composed with current main; focused frontend test, lint/build, and docs tests passed; mergeable, auto-merge armed | +| #493 | `a7a050ef` | empty-DAG reasons and explicit double-failure alert composed with current main; focused frontend test, lint/build, and docs tests passed; mergeable, auto-merge armed | | #490 | `73413d0b` | broad historical workspace branch is conflicting with failing checks; decompose/restack rather than replaying its 931-commit merge wholesale | -| #484 | `5a61c5f7` | Allen interval semantics and deferred FK validation are mergeable; two newly opened review threads require settlement | -| #482 | `b0e737d3` | corroborated SKOS companion branch is conflicting; four unresolved review threads remain | -| #468 | `49f8231a` | exact Keyverse org/PU scope, fast-mlsirm/orchestrator/TEPP boundaries, and event-time import were composed with current main; 46 focused tests passed; mergeable, auto-merge armed | -| #434 | `ff34c9b6` | stacked on #387 and conflicting; checks fail although its review threads are settled | -| #387 | `462b41fb` | channel-evidence branch is conflicting with five unresolved threads, failing checks, and a stale changes-requested decision | -| #383 | `138eaad4` | reader-safe OTel branch is conflicting with six unresolved threads and failing checks | +| #484 | `c12b3b17` | Allen interval semantics and deferred FK validation are mergeable with no unresolved threads; auto-merge armed | +| #482 | `43bb8ba1` | corroborated SKOS companion is mergeable with no unresolved threads; auto-merge armed | +| #468 | `4f8305a8` | integration boundaries, event-time import, and comparison-response ABAC stripping are composed with current main; no unresolved threads; auto-merge armed | +| #387 | `2620e0ae` | channel evidence plus Ask reconstruction-profile preservation is mergeable with no unresolved threads; the stale formal changes-requested decision still gates merge | +| #383 | `7ff6b945` | reader-safe OTel diagnostics and service-peer-bounded session metadata are mergeable with no unresolved threads; auto-merge armed | No row above is merge evidence. Immediately before any lifecycle action, re-fetch the head, unresolved threads, formal reviews, rulesets, and same-head @@ -80,6 +79,7 @@ Recent protected-default-branch delivery evidence (squash merges onto | PR | Merged (UTC) | Delivered | | ---: | --- | --- | +| #599 | 2026-08-25 04:28 | raw-residual leftover-map cross-share identity aligned without arbitrary weighting | | #598 | 2026-08-25 03:32 | 5W1H roles/events remain readable across a stale summary contract version | | #597 | 2026-08-25 03:32 | related posts open Customer Master detail in place without stale graph state | | #591 | 2026-08-25 03:32 | prior exact-head product-gap baseline snapshot | From 766554e50e5db44fe2aaf82b26cf6f19d8555926 Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 13:39:38 +0900 Subject: [PATCH 04/32] docs: record Strix visibility root repair --- docs/product-technical-gap-baseline.md | 32 +++++++++++++++----------- 1 file changed, 19 insertions(+), 13 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 37b9cfdfb..4694cc88e 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Audit snapshot: 2026-08-25 13:33 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 13:39 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -10,21 +10,18 @@ ## 1. Exact-head and governance evidence The protected default branch was `3ac4ff1e7387b8f243cbb0fb20e7ff3ed80f3716` -when this baseline was refreshed. The live queue contained 15 open PRs and 21 +when this baseline was refreshed. The live queue contained 12 open PRs and 21 open issues. The exact-head inventory below supersedes older per-PR snapshots elsewhere in this document; those older rows remain useful historical delivery context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | -| #600 | `7580bdc9` | this baseline's pre-amendment observed head; mergeable and auto-merge armed, but its exact-head check rollup failed and must be revalidated after this refresh | +| #600 | `ac351100` | this baseline's pre-amendment observed head; auto-merge armed, with exact-head required checks queued | | #595 | `153127f0` | audited no-draft import door, nullable updated-at fallback, and event-time import composed on current main; 24 focused tests passed; mergeable, auto-merge armed | | #588 | `3a67a802` | reconstruction naming branch is conflicting; six unresolved review threads remain | | #582 | `edca49bb` | batched cited-lineage fetch composed with current main; 37 focused tests passed; mergeable, auto-merge armed | | #579 | `69c05078` | interaction-map coordinate branch is conflicting; nine unresolved review threads remain | -| #564 | `78afd5b8` | reconstruction naming branch is conflicting; exact-head checks fail and review is required | -| #539 | `e4dffe63` | explained-share branch is conflicting and its exact-head check rollup is failing | -| #537 | `d5ac65d8` | unexplained-share branch is conflicting; six unresolved review threads and failing exact-head checks remain | | #493 | `a7a050ef` | empty-DAG reasons and explicit double-failure alert composed with current main; focused frontend test, lint/build, and docs tests passed; mergeable, auto-merge armed | | #490 | `73413d0b` | broad historical workspace branch is conflicting with failing checks; decompose/restack rather than replaying its 931-commit merge wholesale | | #484 | `c12b3b17` | Allen interval semantics and deferred FK validation are mergeable with no unresolved threads; auto-merge armed | @@ -58,9 +55,17 @@ protected `main`; the ADR 0109 pattern (`returnUrlFromLocation()` then broken base still carried the defect; the shared repair was applied to each of them during this loop (see §3.1). -Two systemic gates currently dominate the queue: - -1. **Strix provider unavailability (org control plane).** The central required +Three systemic gates currently dominate the queue: + +1. **Strix visibility lookup failure (org control plane).** PR #600 exact head + `7580bdc9` failed before scanning because the required-workflow token could + not resolve this public repository after six API retries. The root repair is + ContextualWisdomLab/.github#1320 at `335f3870`: ordinary PR, push, and + schedule runs use trusted event visibility; cross-repository dispatch keeps + bounded API validation; private and internal repositories remain on + private-capable providers. It is open with auto-merge armed, so no repaired + Strix runtime evidence exists yet. +2. **Strix provider unavailability (org control plane).** The central required Strix scan fails across ~28 unrelated LineageWeave PRs with "could not complete authoritative vulnerability analysis because its provider/backend was unavailable": `nvidia_nim/nvidia/nemotron-3-super-120b-a12b` exits @@ -69,7 +74,7 @@ Two systemic gates currently dominate the queue: ContextualWisdomLab/.github#1263 (executable Azure and cross-provider fallbacks). Its exact head is `ab3d7645`, remains open/conflicting, and has not delivered a control-plane repair to protected `.github` main. -2. **Current-head independent approval.** The org merge scheduler requires +3. **Current-head independent approval.** The org merge scheduler requires `reviewDecision == APPROVED` plus complete Strix evidence on the exact head. Bot review evidence regenerates per push, so any repair push resets the review clock by design; this is expected and not a bypass target. @@ -259,7 +264,7 @@ this file per §3.5 of the prior snapshot). | Gap | Current evidence | Acceptance requirement | | --- | --- | --- | -| Protected release | 16 open PRs at snapshot; the queue is split between mergeable heads awaiting independent review/checks and older conflicting stacks | Terminal exact-head checks, no unresolved threads, independent exact-head approvals, protected squash-merge SHA | +| Protected release | 12 open PRs at snapshot; the queue is split between mergeable heads awaiting independent review/checks and older conflicting stacks | Terminal exact-head checks, no unresolved threads, independent exact-head approvals, protected squash-merge SHA | | Shared frontend gate | The ADR 0109 login repair is on protected `main`; eight older branches carried the defect and received the same verified repair this loop (#521–#560) | Keep every future branch cut from post-repair bases; re-verify with frontend lint/test/build before push | | Identifying baseline regression | `main` gap file listed real post identifiers; separately, closed #506 and pre-existing public history contain a private runtime source-table identifier, while current `main` and #507 trees are clean | Land this non-identifying rewrite, then coordinate ADR 0001 history remediation with security/privacy owners; do not reproduce the value, force-push, or delete evidence ad hoc | | Authorized-corpus runtime | Repository tests use synthetic fixtures; private records remain outside git | Authenticated runtime validation returning only aggregate, non-identifying evidence | @@ -352,8 +357,9 @@ Process every open PR in ascending number order, considering leverage; for each: check reviews → repair → re-verify Checks → merge → continue. Checks and review latency are never blockers — keep working while they settle. -1. **Unblock Strix org-wide** by reconciling and landing ContextualWisdomLab/.github#1263 - (fallbacks executable), then rerun failed strix jobs across the queue. +1. **Unblock Strix org-wide** by landing ContextualWisdomLab/.github#1320 + (trusted event visibility), then reconciling ContextualWisdomLab/.github#1263 + (fallbacks executable), and rerun failed Strix jobs across the queue. 2. Merge ascending from #258 once each head shows terminal green required checks plus current-head independent approval. The leftover-map ladder (#518–#564) merges in ascending order. From fb825b974e260faad1743ec1c8633d5e027a6523 Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 13:41:02 +0900 Subject: [PATCH 05/32] docs: bind Strix repair to reviewed head --- docs/product-technical-gap-baseline.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 4694cc88e..a9f9e1c49 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Audit snapshot: 2026-08-25 13:39 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 13:42 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -17,7 +17,7 @@ context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | -| #600 | `ac351100` | this baseline's pre-amendment observed head; auto-merge armed, with exact-head required checks queued | +| #600 | `6982bf4e` | this baseline's pre-amendment observed head; auto-merge armed, with exact-head required checks queued | | #595 | `153127f0` | audited no-draft import door, nullable updated-at fallback, and event-time import composed on current main; 24 focused tests passed; mergeable, auto-merge armed | | #588 | `3a67a802` | reconstruction naming branch is conflicting; six unresolved review threads remain | | #582 | `edca49bb` | batched cited-lineage fetch composed with current main; 37 focused tests passed; mergeable, auto-merge armed | @@ -60,7 +60,7 @@ Three systemic gates currently dominate the queue: 1. **Strix visibility lookup failure (org control plane).** PR #600 exact head `7580bdc9` failed before scanning because the required-workflow token could not resolve this public repository after six API retries. The root repair is - ContextualWisdomLab/.github#1320 at `335f3870`: ordinary PR, push, and + ContextualWisdomLab/.github#1320 at `de7c8344`: ordinary PR, push, and schedule runs use trusted event visibility; cross-repository dispatch keeps bounded API validation; private and internal repositories remain on private-capable providers. It is open with auto-merge armed, so no repaired From 3e7de6707bd12a33e9e8bd78fa0e885b8473080b Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 13:43:47 +0900 Subject: [PATCH 06/32] docs: record PR 588 review reconciliation --- docs/product-technical-gap-baseline.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index a9f9e1c49..0596b6998 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Audit snapshot: 2026-08-25 13:42 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 13:46 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -17,9 +17,9 @@ context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | -| #600 | `6982bf4e` | this baseline's pre-amendment observed head; auto-merge armed, with exact-head required checks queued | +| #600 | `fb825b97` | this baseline's pre-amendment observed head; auto-merge armed, with exact-head required checks queued | | #595 | `153127f0` | audited no-draft import door, nullable updated-at fallback, and event-time import composed on current main; 24 focused tests passed; mergeable, auto-merge armed | -| #588 | `3a67a802` | reconstruction naming branch is conflicting; six unresolved review threads remain | +| #588 | `e4234bce` | ADR 0182/0201 context reconciled and all six review threads resolved; the later leftover-map ladder still conflicts with current main and needs semantic composition | | #582 | `edca49bb` | batched cited-lineage fetch composed with current main; 37 focused tests passed; mergeable, auto-merge armed | | #579 | `69c05078` | interaction-map coordinate branch is conflicting; nine unresolved review threads remain | | #493 | `a7a050ef` | empty-DAG reasons and explicit double-failure alert composed with current main; focused frontend test, lint/build, and docs tests passed; mergeable, auto-merge armed | From df645d3a0ff8d927172b7b51cac6d96e7c4b2785 Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 14:03:44 +0900 Subject: [PATCH 07/32] docs: refresh exact-head queue after protected deliveries --- docs/product-technical-gap-baseline.md | 31 +++++++++++++------------- 1 file changed, 16 insertions(+), 15 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 0596b6998..6e5f1efe4 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Audit snapshot: 2026-08-25 13:46 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 14:01 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -9,26 +9,24 @@ ## 1. Exact-head and governance evidence -The protected default branch was `3ac4ff1e7387b8f243cbb0fb20e7ff3ed80f3716` -when this baseline was refreshed. The live queue contained 12 open PRs and 21 +The protected default branch was `c168ad0016de9aa42a7a6f4136972e80121ef981` +when this baseline was refreshed. The live queue contained 10 open PRs and 20 open issues. The exact-head inventory below supersedes older per-PR snapshots elsewhere in this document; those older rows remain useful historical delivery context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | -| #600 | `fb825b97` | this baseline's pre-amendment observed head; auto-merge armed, with exact-head required checks queued | -| #595 | `153127f0` | audited no-draft import door, nullable updated-at fallback, and event-time import composed on current main; 24 focused tests passed; mergeable, auto-merge armed | -| #588 | `e4234bce` | ADR 0182/0201 context reconciled and all six review threads resolved; the later leftover-map ladder still conflicts with current main and needs semantic composition | -| #582 | `edca49bb` | batched cited-lineage fetch composed with current main; 37 focused tests passed; mergeable, auto-merge armed | +| #601 | `5ce88969` | PROV-O ADR APA 7th references are mergeable; exact-head checks and independent review remain pending | +| #600 | `3e7de670` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | +| #588 | `6185f2ae` | raw-residual reconstruction, rank-zero identity, API presence, and comparison-strip contracts reconciled with current main; focused backend/frontend/schema checks passed; auto-merge armed | +| #582 | `edca49bb` | batched cited-lineage fetch previously passed 37 focused tests but now conflicts with advanced main; restack semantically before re-arming | | #579 | `69c05078` | interaction-map coordinate branch is conflicting; nine unresolved review threads remain | -| #493 | `a7a050ef` | empty-DAG reasons and explicit double-failure alert composed with current main; focused frontend test, lint/build, and docs tests passed; mergeable, auto-merge armed | +| #493 | `a7a050ef` | empty-DAG reasons and explicit double-failure alert previously passed focused frontend/lint/build/docs checks but now conflicts with advanced main | | #490 | `73413d0b` | broad historical workspace branch is conflicting with failing checks; decompose/restack rather than replaying its 931-commit merge wholesale | -| #484 | `c12b3b17` | Allen interval semantics and deferred FK validation are mergeable with no unresolved threads; auto-merge armed | -| #482 | `43bb8ba1` | corroborated SKOS companion is mergeable with no unresolved threads; auto-merge armed | -| #468 | `4f8305a8` | integration boundaries, event-time import, and comparison-response ABAC stripping are composed with current main; no unresolved threads; auto-merge armed | -| #387 | `2620e0ae` | channel evidence plus Ask reconstruction-profile preservation is mergeable with no unresolved threads; the stale formal changes-requested decision still gates merge | -| #383 | `7ff6b945` | reader-safe OTel diagnostics and service-peer-bounded session metadata are mergeable with no unresolved threads; auto-merge armed | +| #482 | `43bb8ba1` | corroborated SKOS companion has no unresolved threads but conflicts with advanced main | +| #468 | `4f8305a8` | integration boundaries, event-time import, and comparison-response ABAC stripping have no unresolved threads but conflict with advanced main | +| #387 | `2620e0ae` | channel evidence plus Ask reconstruction-profile preservation conflicts with advanced main; two new threads and the stale formal changes-requested decision require settlement | No row above is merge evidence. Immediately before any lifecycle action, re-fetch the head, unresolved threads, formal reviews, rulesets, and same-head @@ -60,10 +58,10 @@ Three systemic gates currently dominate the queue: 1. **Strix visibility lookup failure (org control plane).** PR #600 exact head `7580bdc9` failed before scanning because the required-workflow token could not resolve this public repository after six API retries. The root repair is - ContextualWisdomLab/.github#1320 at `de7c8344`: ordinary PR, push, and + ContextualWisdomLab/.github#1320 at `e704343d`: ordinary PR, push, and schedule runs use trusted event visibility; cross-repository dispatch keeps bounded API validation; private and internal repositories remain on - private-capable providers. It is open with auto-merge armed, so no repaired + private-capable providers. It is mergeable with auto-merge armed, so no repaired Strix runtime evidence exists yet. 2. **Strix provider unavailability (org control plane).** The central required Strix scan fails across ~28 unrelated LineageWeave PRs with "could not @@ -84,6 +82,9 @@ Recent protected-default-branch delivery evidence (squash merges onto | PR | Merged (UTC) | Delivered | | ---: | --- | --- | +| #595 | 2026-08-25 04:39 | audited no-draft import door, nullable updated-at fallback, and event-time import | +| #484 | 2026-08-25 04:39 | Allen interval relations with deferred FK validation | +| #383 | 2026-08-25 04:39 | reader-safe OTel diagnostics and service-peer-bounded session metadata | | #599 | 2026-08-25 04:28 | raw-residual leftover-map cross-share identity aligned without arbitrary weighting | | #598 | 2026-08-25 03:32 | 5W1H roles/events remain readable across a stale summary contract version | | #597 | 2026-08-25 03:32 | related posts open Customer Master detail in place without stale graph state | From 7559aaef8770f813dd80ecb725a7df6e16487045 Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 14:18:21 +0900 Subject: [PATCH 08/32] docs: refresh exact-head control-plane evidence --- docs/product-technical-gap-baseline.md | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 6e5f1efe4..461ea8646 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Audit snapshot: 2026-08-25 14:01 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 14:18 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -18,7 +18,7 @@ context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | | #601 | `5ce88969` | PROV-O ADR APA 7th references are mergeable; exact-head checks and independent review remain pending | -| #600 | `3e7de670` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | +| #600 | `df645d3a` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | | #588 | `6185f2ae` | raw-residual reconstruction, rank-zero identity, API presence, and comparison-strip contracts reconciled with current main; focused backend/frontend/schema checks passed; auto-merge armed | | #582 | `edca49bb` | batched cited-lineage fetch previously passed 37 focused tests but now conflicts with advanced main; restack semantically before re-arming | | #579 | `69c05078` | interaction-map coordinate branch is conflicting; nine unresolved review threads remain | @@ -58,11 +58,14 @@ Three systemic gates currently dominate the queue: 1. **Strix visibility lookup failure (org control plane).** PR #600 exact head `7580bdc9` failed before scanning because the required-workflow token could not resolve this public repository after six API retries. The root repair is - ContextualWisdomLab/.github#1320 at `e704343d`: ordinary PR, push, and + ContextualWisdomLab/.github#1320 at `92bb94c5`: ordinary PR, push, and schedule runs use trusted event visibility; cross-repository dispatch keeps bounded API validation; private and internal repositories remain on - private-capable providers. It is mergeable with auto-merge armed, so no repaired - Strix runtime evidence exists yet. + private-capable providers. The exact head also composes the previously + separate executable fallback-contract repair; 1,406 central tests, the + full Strix quick gate, actionlint, shell syntax, and diff checks passed + locally. It is blocked on hosted exact-head gates and independent review, + so no repaired protected-main Strix runtime evidence exists yet. 2. **Strix provider unavailability (org control plane).** The central required Strix scan fails across ~28 unrelated LineageWeave PRs with "could not complete authoritative vulnerability analysis because its provider/backend From 0ff088236b1b43af40f5de73f5be89c98b678a05 Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 14:20:49 +0900 Subject: [PATCH 09/32] docs: record PR 579 exact-head repair --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 461ea8646..c80742d5c 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Audit snapshot: 2026-08-25 14:18 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 14:25 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -21,7 +21,7 @@ context only. | #600 | `df645d3a` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | | #588 | `6185f2ae` | raw-residual reconstruction, rank-zero identity, API presence, and comparison-strip contracts reconciled with current main; focused backend/frontend/schema checks passed; auto-merge armed | | #582 | `edca49bb` | batched cited-lineage fetch previously passed 37 focused tests but now conflicts with advanced main; restack semantically before re-arming | -| #579 | `69c05078` | interaction-map coordinate branch is conflicting; nine unresolved review threads remain | +| #579 | `08554951` | interaction-map coordinate branch is conflicting; ADR 0202 traceability was repaired, 20 focused documentation/schema checks passed, and all review threads are resolved; semantic composition with current main remains | | #493 | `a7a050ef` | empty-DAG reasons and explicit double-failure alert previously passed focused frontend/lint/build/docs checks but now conflicts with advanced main | | #490 | `73413d0b` | broad historical workspace branch is conflicting with failing checks; decompose/restack rather than replaying its 931-commit merge wholesale | | #482 | `43bb8ba1` | corroborated SKOS companion has no unresolved threads but conflicts with advanced main | From ef30e8d5b021e77380c81aaff8fefd74ba059e3c Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 14:23:02 +0900 Subject: [PATCH 10/32] docs: record PR 582 semantic composition --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index c80742d5c..233e6e635 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Audit snapshot: 2026-08-25 14:25 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 14:32 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -20,7 +20,7 @@ context only. | #601 | `5ce88969` | PROV-O ADR APA 7th references are mergeable; exact-head checks and independent review remain pending | | #600 | `df645d3a` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | | #588 | `6185f2ae` | raw-residual reconstruction, rank-zero identity, API presence, and comparison-strip contracts reconciled with current main; focused backend/frontend/schema checks passed; auto-merge armed | -| #582 | `edca49bb` | batched cited-lineage fetch previously passed 37 focused tests but now conflicts with advanced main; restack semantically before re-arming | +| #582 | `cab04063` | batched cited-lineage fetch was semantically composed with current main while retaining ADR 0161 interval relations; 27 focused lineage/documentation checks passed, no review threads remain, and auto-merge is armed pending hosted checks and independent review | | #579 | `08554951` | interaction-map coordinate branch is conflicting; ADR 0202 traceability was repaired, 20 focused documentation/schema checks passed, and all review threads are resolved; semantic composition with current main remains | | #493 | `a7a050ef` | empty-DAG reasons and explicit double-failure alert previously passed focused frontend/lint/build/docs checks but now conflicts with advanced main | | #490 | `73413d0b` | broad historical workspace branch is conflicting with failing checks; decompose/restack rather than replaying its 931-commit merge wholesale | From dc7798c01e26b833060310d9f2adc4559aed00b9 Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 14:26:07 +0900 Subject: [PATCH 11/32] docs: refresh exact-head queue contracts --- docs/product-technical-gap-baseline.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 233e6e635..e67937fe2 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Audit snapshot: 2026-08-25 14:32 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 14:42 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -17,16 +17,16 @@ context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | -| #601 | `5ce88969` | PROV-O ADR APA 7th references are mergeable; exact-head checks and independent review remain pending | -| #600 | `df645d3a` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | -| #588 | `6185f2ae` | raw-residual reconstruction, rank-zero identity, API presence, and comparison-strip contracts reconciled with current main; focused backend/frontend/schema checks passed; auto-merge armed | +| #601 | `5ce88969` | draft PROV-O ADR APA 7th references are mergeable and checks are progressing, but the PR's explicit owner contract says not to mark Ready or merge | +| #600 | `ef30e8d5` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | +| #588 | `6185f2ae` | raw-residual reconstruction, rank-zero identity, API presence, and comparison-strip contracts reconciled with current main; focused backend/frontend/schema checks passed, all review threads are resolved, and auto-merge is armed | | #582 | `cab04063` | batched cited-lineage fetch was semantically composed with current main while retaining ADR 0161 interval relations; 27 focused lineage/documentation checks passed, no review threads remain, and auto-merge is armed pending hosted checks and independent review | | #579 | `08554951` | interaction-map coordinate branch is conflicting; ADR 0202 traceability was repaired, 20 focused documentation/schema checks passed, and all review threads are resolved; semantic composition with current main remains | | #493 | `a7a050ef` | empty-DAG reasons and explicit double-failure alert previously passed focused frontend/lint/build/docs checks but now conflicts with advanced main | | #490 | `73413d0b` | broad historical workspace branch is conflicting with failing checks; decompose/restack rather than replaying its 931-commit merge wholesale | | #482 | `43bb8ba1` | corroborated SKOS companion has no unresolved threads but conflicts with advanced main | | #468 | `4f8305a8` | integration boundaries, event-time import, and comparison-response ABAC stripping have no unresolved threads but conflict with advanced main | -| #387 | `2620e0ae` | channel evidence plus Ask reconstruction-profile preservation conflicts with advanced main; two new threads and the stale formal changes-requested decision require settlement | +| #387 | `3fab1f6a` | channel evidence plus Ask reconstruction-profile preservation is mergeable with no unresolved threads; only changes-requested decisions from obsolete heads remain, so auto-merge is armed pending current-head checks and independent re-review | No row above is merge evidence. Immediately before any lifecycle action, re-fetch the head, unresolved threads, formal reviews, rulesets, and same-head From ddec7c8e24e0cb8459f3f9311ed20f05023cd984 Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 14:36:42 +0900 Subject: [PATCH 12/32] docs: record PR 493 semantic composition --- docs/product-technical-gap-baseline.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e67937fe2..7b085e625 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Audit snapshot: 2026-08-25 14:42 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 15:01 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -18,11 +18,11 @@ context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | | #601 | `5ce88969` | draft PROV-O ADR APA 7th references are mergeable and checks are progressing, but the PR's explicit owner contract says not to mark Ready or merge | -| #600 | `ef30e8d5` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | +| #600 | `dc7798c0` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | | #588 | `6185f2ae` | raw-residual reconstruction, rank-zero identity, API presence, and comparison-strip contracts reconciled with current main; focused backend/frontend/schema checks passed, all review threads are resolved, and auto-merge is armed | | #582 | `cab04063` | batched cited-lineage fetch was semantically composed with current main while retaining ADR 0161 interval relations; 27 focused lineage/documentation checks passed, no review threads remain, and auto-merge is armed pending hosted checks and independent review | | #579 | `08554951` | interaction-map coordinate branch is conflicting; ADR 0202 traceability was repaired, 20 focused documentation/schema checks passed, and all review threads are resolved; semantic composition with current main remains | -| #493 | `a7a050ef` | empty-DAG reasons and explicit double-failure alert previously passed focused frontend/lint/build/docs checks but now conflicts with advanced main | +| #493 | `8b4fa4fb` | ADR 0143 empty-DAG reasons were semantically composed with ADR 0161 interval labels; 32 focused backend/docs checks, frontend lint, isolated timeout diagnostics, and production build passed; auto-merge is armed pending hosted exact-head gates and independent review | | #490 | `73413d0b` | broad historical workspace branch is conflicting with failing checks; decompose/restack rather than replaying its 931-commit merge wholesale | | #482 | `43bb8ba1` | corroborated SKOS companion has no unresolved threads but conflicts with advanced main | | #468 | `4f8305a8` | integration boundaries, event-time import, and comparison-response ABAC stripping have no unresolved threads but conflict with advanced main | From bc86ad7e5d8cae1fffa1f9ef8a31b7f2e7cd3092 Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 14:42:39 +0900 Subject: [PATCH 13/32] docs: reconcile complete live issue queue --- docs/product-technical-gap-baseline.md | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 7b085e625..b5e585d34 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Audit snapshot: 2026-08-25 15:01 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 14:41 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -18,11 +18,11 @@ context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | | #601 | `5ce88969` | draft PROV-O ADR APA 7th references are mergeable and checks are progressing, but the PR's explicit owner contract says not to mark Ready or merge | -| #600 | `dc7798c0` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | +| #600 | `ddec7c8e` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | | #588 | `6185f2ae` | raw-residual reconstruction, rank-zero identity, API presence, and comparison-strip contracts reconciled with current main; focused backend/frontend/schema checks passed, all review threads are resolved, and auto-merge is armed | | #582 | `cab04063` | batched cited-lineage fetch was semantically composed with current main while retaining ADR 0161 interval relations; 27 focused lineage/documentation checks passed, no review threads remain, and auto-merge is armed pending hosted checks and independent review | | #579 | `08554951` | interaction-map coordinate branch is conflicting; ADR 0202 traceability was repaired, 20 focused documentation/schema checks passed, and all review threads are resolved; semantic composition with current main remains | -| #493 | `8b4fa4fb` | ADR 0143 empty-DAG reasons were semantically composed with ADR 0161 interval labels; 32 focused backend/docs checks, frontend lint, isolated timeout diagnostics, and production build passed; auto-merge is armed pending hosted exact-head gates and independent review | +| #493 | `ff960f3a` | ADR 0143 empty-DAG reasons were stacked on #387 channel evidence while retaining ADR 0161 interval labels; 36 focused backend checks, 175 focused frontend checks, lint, production/Storybook builds, and desktop/mobile rendered screenshots passed; no review threads remain and auto-merge is armed pending hosted exact-head gates and independent review | | #490 | `73413d0b` | broad historical workspace branch is conflicting with failing checks; decompose/restack rather than replaying its 931-commit merge wholesale | | #482 | `43bb8ba1` | corroborated SKOS companion has no unresolved threads but conflicts with advanced main | | #468 | `4f8305a8` | integration boundaries, event-time import, and comparison-response ABAC stripping have no unresolved threads but conflict with advanced main | @@ -240,7 +240,7 @@ head clears gates. Closed as superseded during this loop: #368 (baseline rewrite superseded by this file per §3.5 of the prior snapshot). -## 4. Open issues (product acceptance remaining on `main`) +## 4. Open issues (complete live queue; product acceptance remaining on `main`) | Issue | User-visible gap | Active PR | | ---: | --- | --- | @@ -259,10 +259,11 @@ this file per §3.5 of the prior snapshot). | #341 | Heterogeneous ontology and provenance explorer separate from Event Lineage | #349 | | #358 | Batch reauthorize persisted post-Ask evidence without N+1 queries | Ask stack | | #359 | Centralize Global Ask session storage access | Ask stack | -| #361 | Preserve server diagnostics behind generic orchestrator 503 responses | #383 | | #362 | Roll back rejected Global Ask turn atomically instead of poisoning the session | Ask stack | | #363 | Continue ontology neighborhoods beyond the bounded source window | Ask / ontology | | #372 | Reconcile lowercase and repository-case public namespace IRIs | #426 Pages stack; #492 is merged into that branch, not protected `main` | +| #566 | Release the run-start outbox transaction before adjudication provider latency | No active delivery PR confirmed | +| #568 | Batch cited-post lineage fetch and bound merged Global Ask graph payload | #582 | ## 5. Open product and technical gaps From 979e7fc2f0c332cbc8f23a7395b3b53699da4fbe Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 14:46:34 +0900 Subject: [PATCH 14/32] docs: record PR 482 visual exact-head audit --- docs/product-technical-gap-baseline.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 7b085e625..6f6c47448 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Audit snapshot: 2026-08-25 15:01 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 15:10 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -18,13 +18,13 @@ context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | | #601 | `5ce88969` | draft PROV-O ADR APA 7th references are mergeable and checks are progressing, but the PR's explicit owner contract says not to mark Ready or merge | -| #600 | `dc7798c0` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | +| #600 | `ddec7c8e` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | | #588 | `6185f2ae` | raw-residual reconstruction, rank-zero identity, API presence, and comparison-strip contracts reconciled with current main; focused backend/frontend/schema checks passed, all review threads are resolved, and auto-merge is armed | | #582 | `cab04063` | batched cited-lineage fetch was semantically composed with current main while retaining ADR 0161 interval relations; 27 focused lineage/documentation checks passed, no review threads remain, and auto-merge is armed pending hosted checks and independent review | | #579 | `08554951` | interaction-map coordinate branch is conflicting; ADR 0202 traceability was repaired, 20 focused documentation/schema checks passed, and all review threads are resolved; semantic composition with current main remains | | #493 | `8b4fa4fb` | ADR 0143 empty-DAG reasons were semantically composed with ADR 0161 interval labels; 32 focused backend/docs checks, frontend lint, isolated timeout diagnostics, and production build passed; auto-merge is armed pending hosted exact-head gates and independent review | | #490 | `73413d0b` | broad historical workspace branch is conflicting with failing checks; decompose/restack rather than replaying its 931-commit merge wholesale | -| #482 | `43bb8ba1` | corroborated SKOS companion has no unresolved threads but conflicts with advanced main | +| #482 | `6b9084b9` | ADR 0170 organization-alias captions were composed with current main; 44 backend/docs and 93 frontend tests, lint, app/Storybook builds, plus desktop/mobile rendered screenshot audits passed; auto-merge is armed pending hosted exact-head gates and independent review | | #468 | `4f8305a8` | integration boundaries, event-time import, and comparison-response ABAC stripping have no unresolved threads but conflict with advanced main | | #387 | `3fab1f6a` | channel evidence plus Ask reconstruction-profile preservation is mergeable with no unresolved threads; only changes-requested decisions from obsolete heads remain, so auto-merge is armed pending current-head checks and independent re-review | From 928512e4a55ade8635150b3116fc9b179bd3a600 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 25 Aug 2026 15:20:32 +0900 Subject: [PATCH 15/32] docs: record post dialog accessibility gap delivery --- docs/product-technical-gap-baseline.md | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 57cb04bba..8344ae2b4 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Audit snapshot: 2026-08-25 15:10 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 15:18 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -10,15 +10,16 @@ ## 1. Exact-head and governance evidence The protected default branch was `c168ad0016de9aa42a7a6f4136972e80121ef981` -when this baseline was refreshed. The live queue contained 10 open PRs and 20 +when this baseline was refreshed. The live queue contained 11 open PRs and 20 open issues. The exact-head inventory below supersedes older per-PR snapshots elsewhere in this document; those older rows remain useful historical delivery context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | +| #602 | `b286d883` | Post-detail modal semantics, focus containment/restoration, and Escape close are mergeable; focused tests, lint, production build, and authenticated desktop/mobile rendering passed locally, while exact-head hosted checks and independent review remain pending; auto-merge is armed | | #601 | `5ce88969` | draft PROV-O ADR APA 7th references are mergeable and checks are progressing, but the PR's explicit owner contract says not to mark Ready or merge | -| #600 | `bc86ad7e` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | +| #600 | `a4117f52` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | | #588 | `6185f2ae` | raw-residual reconstruction, rank-zero identity, API presence, and comparison-strip contracts reconciled with current main; focused backend/frontend/schema checks passed, all review threads are resolved, and auto-merge is armed | | #582 | `cab04063` | batched cited-lineage fetch was semantically composed with current main while retaining ADR 0161 interval relations; 27 focused lineage/documentation checks passed, no review threads remain, and auto-merge is armed pending hosted checks and independent review | | #579 | `08554951` | interaction-map coordinate branch is conflicting; ADR 0202 traceability was repaired, 20 focused documentation/schema checks passed, and all review threads are resolved; semantic composition with current main remains | @@ -284,7 +285,7 @@ this file per §3.5 of the prior snapshot). | Scientific measurement | Durable accepted TEPP receipts and fail-closed production weighting are protected (`main`); #468 binds fast-mlsirm/Keyverse/orchestrator/TEPP integration tests and now fails closed on upstream probability-axis drift. #387 removes inferred/default persistence weights and converts its 3/4-channel evidence tests to fast-mlsirm estimates, but several older reconstruction tests still pass hand-authored numeric weight dictionaries; those constants are not estimator evidence | Continue replacing remaining reconstruction-test constants with provenance-bearing fast-mlsirm estimates over synthetic fixtures; tests unrelated to fusion must bypass weighting entirely, as #484 does. Land #387/#468/#417 through the standard gate and retain true-parameter RMSE recovery as the acceptance bar | | Asynchronous authorization | Protected `main` rebuilds Global Ask worker scope after the bearer token leaves the request; #468 now persists exact Keyverse organization/process-unit scope in 3NF child tables and intersects it with current affiliations | Land #468 through the protected gate; prove a second affiliation and a revoked process unit cannot widen delayed-job evidence | | Planned-facility intent | Planned-facility relationship intent rides on open #490 (`d0cad030`), whose earlier stack-only merges were not protected delivery | Settle #490 exact-head checks plus independent approval, then land through protected `main` before a release claim | -| Accessibility and responsive UX | Unit coverage exists for major surfaces; Storybook inventory incomplete | Keyboard, screen-reader, mobile, and authenticated Playwright acceptance on the exact release head | +| Accessibility and responsive UX | Unit coverage exists for major surfaces; #602 closes the ADR 0153 post-detail dialog semantics/focus follow-up and has authenticated desktop/mobile rendered evidence, but it is not protected-main delivery; Storybook inventory remains incomplete | Land #602 through the protected gate, then complete keyboard, screen-reader, mobile, and authenticated Playwright acceptance on the exact release head | | Design tokens and repeated objects | Token extraction started; sanitized Figma Event Lineage desktop/mobile frames exist, while other repeated product surfaces remain incomplete | Tokens in CSS + Storybook stories for board, popup, DAG, Ask, calendar, forms, charts; same-viewport Figma/runtime visual comparison before release | | External integrations | Search, Zotero, calendar, Keyverse, orchestrator, RankWeave, ThreadWeave, TEPP, disksage, wardnet | Provider conformance, failure/reconciliation behavior, and provenance-bearing integration evidence | | MSA / modular reuse | LineageWeave must run standalone and as a consumer of org packages | Do not reimplement RankWeave/TEPP/orchestrator/ThreadWeave/Keyverse; fix upstream and PR there | From b0a448bf1e492d993e7eb103472c01f11a7a3474 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 25 Aug 2026 15:22:24 +0900 Subject: [PATCH 16/32] docs: refresh exact open PR heads --- docs/product-technical-gap-baseline.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 8344ae2b4..50bbdea9a 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Audit snapshot: 2026-08-25 15:18 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 15:21 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -19,11 +19,11 @@ context only. | ---: | --- | --- | | #602 | `b286d883` | Post-detail modal semantics, focus containment/restoration, and Escape close are mergeable; focused tests, lint, production build, and authenticated desktop/mobile rendering passed locally, while exact-head hosted checks and independent review remain pending; auto-merge is armed | | #601 | `5ce88969` | draft PROV-O ADR APA 7th references are mergeable and checks are progressing, but the PR's explicit owner contract says not to mark Ready or merge | -| #600 | `a4117f52` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | +| #600 | `928512e4` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | | #588 | `6185f2ae` | raw-residual reconstruction, rank-zero identity, API presence, and comparison-strip contracts reconciled with current main; focused backend/frontend/schema checks passed, all review threads are resolved, and auto-merge is armed | | #582 | `cab04063` | batched cited-lineage fetch was semantically composed with current main while retaining ADR 0161 interval relations; 27 focused lineage/documentation checks passed, no review threads remain, and auto-merge is armed pending hosted checks and independent review | | #579 | `08554951` | interaction-map coordinate branch is conflicting; ADR 0202 traceability was repaired, 20 focused documentation/schema checks passed, and all review threads are resolved; semantic composition with current main remains | -| #493 | `ff960f3a` | ADR 0143 empty-DAG reasons were stacked on #387 channel evidence while retaining ADR 0161 interval labels; 36 focused backend checks, 175 focused frontend checks, lint, production/Storybook builds, and desktop/mobile rendered screenshots passed; no review threads remain and auto-merge is armed pending hosted exact-head gates and independent review | +| #493 | `6fbc8660` | ADR 0143 empty-DAG reasons were stacked on #387 channel evidence while retaining ADR 0161 interval labels; 36 focused backend checks, 175 focused frontend checks, lint, production/Storybook builds, and desktop/mobile rendered screenshots passed; no review threads remain and auto-merge is armed pending hosted exact-head gates and independent review | | #490 | `73413d0b` | broad historical workspace branch is conflicting with failing checks; decompose/restack rather than replaying its 931-commit merge wholesale | | #482 | `6b9084b9` | ADR 0170 organization-alias captions were composed with current main; 44 backend/docs and 93 frontend tests, lint, app/Storybook builds, plus desktop/mobile rendered screenshot audits passed; auto-merge is armed pending hosted exact-head gates and independent review | | #468 | `4f8305a8` | integration boundaries, event-time import, and comparison-response ABAC stripping have no unresolved threads but conflict with advanced main | From 60b3f7a63d1025864619a6d98567186432c371fe Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 25 Aug 2026 15:34:19 +0900 Subject: [PATCH 17/32] docs: refresh dialog PR exact head --- docs/product-technical-gap-baseline.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 50bbdea9a..2d3a38124 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Audit snapshot: 2026-08-25 15:21 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 15:33 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -17,9 +17,9 @@ context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | -| #602 | `b286d883` | Post-detail modal semantics, focus containment/restoration, and Escape close are mergeable; focused tests, lint, production build, and authenticated desktop/mobile rendering passed locally, while exact-head hosted checks and independent review remain pending; auto-merge is armed | +| #602 | `36f05476` | Post-detail modal semantics, focus containment/restoration, and Escape close are mergeable; the valid rerender focus-steal review was repaired with a mount-only focus lifecycle and regression test, all threads are resolved, and auto-merge remains armed pending exact-head hosted checks and independent review | | #601 | `5ce88969` | draft PROV-O ADR APA 7th references are mergeable and checks are progressing, but the PR's explicit owner contract says not to mark Ready or merge | -| #600 | `928512e4` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | +| #600 | `b0a448bf` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | | #588 | `6185f2ae` | raw-residual reconstruction, rank-zero identity, API presence, and comparison-strip contracts reconciled with current main; focused backend/frontend/schema checks passed, all review threads are resolved, and auto-merge is armed | | #582 | `cab04063` | batched cited-lineage fetch was semantically composed with current main while retaining ADR 0161 interval relations; 27 focused lineage/documentation checks passed, no review threads remain, and auto-merge is armed pending hosted checks and independent review | | #579 | `08554951` | interaction-map coordinate branch is conflicting; ADR 0202 traceability was repaired, 20 focused documentation/schema checks passed, and all review threads are resolved; semantic composition with current main remains | From 5289362040fac3bbccbf98844a42e69e5fdb3096 Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 15:35:19 +0900 Subject: [PATCH 18/32] docs: refresh remediated exact PR heads --- docs/product-technical-gap-baseline.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 50bbdea9a..629ba7fb0 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Audit snapshot: 2026-08-25 15:21 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 15:33 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -17,12 +17,12 @@ context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | -| #602 | `b286d883` | Post-detail modal semantics, focus containment/restoration, and Escape close are mergeable; focused tests, lint, production build, and authenticated desktop/mobile rendering passed locally, while exact-head hosted checks and independent review remain pending; auto-merge is armed | +| #602 | `36f05476` | Post-detail modal semantics, focus containment/restoration, and Escape close are mergeable; exact-head review repaired rerender-driven focus theft and added its regression test; focused tests, lint, production build, and authenticated desktop/mobile rendering passed locally; all threads are resolved and auto-merge is armed pending hosted checks and independent review | | #601 | `5ce88969` | draft PROV-O ADR APA 7th references are mergeable and checks are progressing, but the PR's explicit owner contract says not to mark Ready or merge | -| #600 | `928512e4` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | +| #600 | `b0a448bf` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | | #588 | `6185f2ae` | raw-residual reconstruction, rank-zero identity, API presence, and comparison-strip contracts reconciled with current main; focused backend/frontend/schema checks passed, all review threads are resolved, and auto-merge is armed | | #582 | `cab04063` | batched cited-lineage fetch was semantically composed with current main while retaining ADR 0161 interval relations; 27 focused lineage/documentation checks passed, no review threads remain, and auto-merge is armed pending hosted checks and independent review | -| #579 | `08554951` | interaction-map coordinate branch is conflicting; ADR 0202 traceability was repaired, 20 focused documentation/schema checks passed, and all review threads are resolved; semantic composition with current main remains | +| #579 | `bfefe98e` | interaction-map coordinates were semantically composed with current main's cross-share and interval work; the ADR 0168/0202 collision was repaired, all threads are resolved, 69 focused scientific/schema checks plus the focused live API contract passed, and 163 frontend tests, lint, app/Storybook builds, and desktop/mobile rendered audits passed; auto-merge is armed pending hosted checks and independent review | | #493 | `6fbc8660` | ADR 0143 empty-DAG reasons were stacked on #387 channel evidence while retaining ADR 0161 interval labels; 36 focused backend checks, 175 focused frontend checks, lint, production/Storybook builds, and desktop/mobile rendered screenshots passed; no review threads remain and auto-merge is armed pending hosted exact-head gates and independent review | | #490 | `73413d0b` | broad historical workspace branch is conflicting with failing checks; decompose/restack rather than replaying its 931-commit merge wholesale | | #482 | `6b9084b9` | ADR 0170 organization-alias captions were composed with current main; 44 backend/docs and 93 frontend tests, lint, app/Storybook builds, plus desktop/mobile rendered screenshot audits passed; auto-merge is armed pending hosted exact-head gates and independent review | From 5ff2cf772821fb666f4838ba6bf7c4eb9eeef495 Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 15:44:19 +0900 Subject: [PATCH 19/32] docs: record Strix overload fallback repair --- docs/product-technical-gap-baseline.md | 35 +++++++++++++------------- 1 file changed, 18 insertions(+), 17 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 29653e95d..8983482e6 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Audit snapshot: 2026-08-25 15:33 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 15:43 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -19,7 +19,7 @@ context only. | ---: | --- | --- | | #602 | `36f05476` | Post-detail modal semantics, focus containment/restoration, and Escape close are mergeable; the valid rerender focus-steal review was repaired with a mount-only focus lifecycle and regression test, all threads are resolved, and auto-merge remains armed pending exact-head hosted checks and independent review | | #601 | `5ce88969` | draft PROV-O ADR APA 7th references are mergeable and checks are progressing, but the PR's explicit owner contract says not to mark Ready or merge | -| #600 | `b0a448bf` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | +| #600 | `cb5eff38` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | | #588 | `6185f2ae` | raw-residual reconstruction, rank-zero identity, API presence, and comparison-strip contracts reconciled with current main; focused backend/frontend/schema checks passed, all review threads are resolved, and auto-merge is armed | | #582 | `cab04063` | batched cited-lineage fetch was semantically composed with current main while retaining ADR 0161 interval relations; 27 focused lineage/documentation checks passed, no review threads remain, and auto-merge is armed pending hosted checks and independent review | | #579 | `bfefe98e` | interaction-map coordinates were semantically composed with current main's cross-share and interval work; the ADR 0168/0202 collision was repaired, all threads are resolved, 69 focused scientific/schema checks plus the focused live API contract passed, and 163 frontend tests, lint, app/Storybook builds, and desktop/mobile rendered audits passed; auto-merge is armed pending hosted checks and independent review | @@ -59,23 +59,24 @@ Three systemic gates currently dominate the queue: 1. **Strix visibility lookup failure (org control plane).** PR #600 exact head `7580bdc9` failed before scanning because the required-workflow token could not resolve this public repository after six API retries. The root repair is - ContextualWisdomLab/.github#1320 at `92bb94c5`: ordinary PR, push, and + ContextualWisdomLab/.github#1320 at `5f00b765`: ordinary PR, push, and schedule runs use trusted event visibility; cross-repository dispatch keeps - bounded API validation; private and internal repositories remain on - private-capable providers. The exact head also composes the previously - separate executable fallback-contract repair; 1,406 central tests, the - full Strix quick gate, actionlint, shell syntax, and diff checks passed - locally. It is blocked on hosted exact-head gates and independent review, - so no repaired protected-main Strix runtime evidence exists yet. + authoritative public/private/internal visibility; private and internal + repositories remain on private-capable providers. The exact head also + composes the executable fallback contract and classifies bounded NVIDIA + `ServiceUnavailableError` overload evidence as retryable across configured + distinct models without weakening exhaustion or vulnerability fail-close. + The full Strix quick-gate harness passed, and the composed head passed the + overload path plus 12 visibility-contract tests. It remains blocked on + hosted exact-head gates and independent review, so no repaired + protected-main Strix runtime evidence exists yet. 2. **Strix provider unavailability (org control plane).** The central required - Strix scan fails across ~28 unrelated LineageWeave PRs with "could not - complete authoritative vulnerability analysis because its provider/backend - was unavailable": `nvidia_nim/nvidia/nemotron-3-super-120b-a12b` exits - after ~70 s and `openai-direct/gpt-5.6-luna` after ~5 s. This is an - infrastructure failure, not a code finding. The durable repair is - ContextualWisdomLab/.github#1263 (executable Azure and cross-provider - fallbacks). Its exact head is `ab3d7645`, remains open/conflicting, and has - not delivered a control-plane repair to protected `.github` main. + Strix scan on .github#1320 failed when NVIDIA returned `Service temporarily + overloaded`; the gate correctly failed closed but did not try its configured + distinct fallbacks because the service-unavailable classifier excluded the + NVIDIA provider. Exact head `5f00b765` repairs that execution path and keeps + incomplete exhaustion non-passing. This is still an unmerged control-plane + proposal, not protected-main or downstream runtime evidence. 3. **Current-head independent approval.** The org merge scheduler requires `reviewDecision == APPROVED` plus complete Strix evidence on the exact head. Bot review evidence regenerates per push, so any repair push resets From 1cb63dae6d44e58f2616fabaeb7206c263aa307f Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 15:46:21 +0900 Subject: [PATCH 20/32] docs: record reconciled integration head --- docs/product-technical-gap-baseline.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 8983482e6..b913b1366 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Audit snapshot: 2026-08-25 15:43 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 15:45 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -19,14 +19,14 @@ context only. | ---: | --- | --- | | #602 | `36f05476` | Post-detail modal semantics, focus containment/restoration, and Escape close are mergeable; the valid rerender focus-steal review was repaired with a mount-only focus lifecycle and regression test, all threads are resolved, and auto-merge remains armed pending exact-head hosted checks and independent review | | #601 | `5ce88969` | draft PROV-O ADR APA 7th references are mergeable and checks are progressing, but the PR's explicit owner contract says not to mark Ready or merge | -| #600 | `cb5eff38` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | +| #600 | `5ff2cf77` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | | #588 | `6185f2ae` | raw-residual reconstruction, rank-zero identity, API presence, and comparison-strip contracts reconciled with current main; focused backend/frontend/schema checks passed, all review threads are resolved, and auto-merge is armed | | #582 | `cab04063` | batched cited-lineage fetch was semantically composed with current main while retaining ADR 0161 interval relations; 27 focused lineage/documentation checks passed, no review threads remain, and auto-merge is armed pending hosted checks and independent review | | #579 | `bfefe98e` | interaction-map coordinates were semantically composed with current main's cross-share and interval work; the ADR 0168/0202 collision was repaired, all threads are resolved, 69 focused scientific/schema checks plus the focused live API contract passed, and 163 frontend tests, lint, app/Storybook builds, and desktop/mobile rendered audits passed; auto-merge is armed pending hosted checks and independent review | | #493 | `6fbc8660` | ADR 0143 empty-DAG reasons were stacked on #387 channel evidence while retaining ADR 0161 interval labels; 36 focused backend checks, 175 focused frontend checks, lint, production/Storybook builds, and desktop/mobile rendered screenshots passed; no review threads remain and auto-merge is armed pending hosted exact-head gates and independent review | | #490 | `73413d0b` | broad historical workspace branch is conflicting with failing checks; decompose/restack rather than replaying its 931-commit merge wholesale | | #482 | `6b9084b9` | ADR 0170 organization-alias captions were composed with current main; 44 backend/docs and 93 frontend tests, lint, app/Storybook builds, plus desktop/mobile rendered screenshot audits passed; auto-merge is armed pending hosted exact-head gates and independent review | -| #468 | `4f8305a8` | integration boundaries, event-time import, and comparison-response ABAC stripping have no unresolved threads but conflict with advanced main | +| #468 | `a1952e5e` | fast-mlsirm v0.8.0, exact Keyverse scope, orchestrator, and TEPP boundaries were composed with current main; TEPP contract/auth headers and telemetry-safe startup were retained, 74 focused integration tests plus 37 TEPP/start/config tests and the live authorization-scope contract passed, no review threads remain, and auto-merge is armed pending hosted exact-head gates and independent review | | #387 | `3fab1f6a` | channel evidence plus Ask reconstruction-profile preservation is mergeable with no unresolved threads; only changes-requested decisions from obsolete heads remain, so auto-merge is armed pending current-head checks and independent re-review | No row above is merge evidence. Immediately before any lifecycle action, From ae6e8cbccae2769537aa3092674f26c673d9848f Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 15:50:25 +0900 Subject: [PATCH 21/32] docs: record protected PROV references delivery --- docs/product-technical-gap-baseline.md | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b913b1366..8b4f3c93d 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Audit snapshot: 2026-08-25 15:45 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 15:49 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -9,17 +9,16 @@ ## 1. Exact-head and governance evidence -The protected default branch was `c168ad0016de9aa42a7a6f4136972e80121ef981` -when this baseline was refreshed. The live queue contained 11 open PRs and 20 +The protected default branch was `ea71d9ca9adda1c4c8f82ed295d2202a8a2f5c1f` +when this baseline was refreshed. The live queue contained 10 open PRs and 20 open issues. The exact-head inventory below supersedes older per-PR snapshots elsewhere in this document; those older rows remain useful historical delivery context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | -| #602 | `36f05476` | Post-detail modal semantics, focus containment/restoration, and Escape close are mergeable; the valid rerender focus-steal review was repaired with a mount-only focus lifecycle and regression test, all threads are resolved, and auto-merge remains armed pending exact-head hosted checks and independent review | -| #601 | `5ce88969` | draft PROV-O ADR APA 7th references are mergeable and checks are progressing, but the PR's explicit owner contract says not to mark Ready or merge | -| #600 | `5ff2cf77` | this baseline's pre-amendment observed head; mergeable with review/check evidence pending | +| #602 | `a1e4dc8f` | Post-detail modal semantics, focus containment/restoration, and Escape close are composed with current main; the valid rerender focus-steal review was repaired with a mount-only focus lifecycle and regression test, all threads are resolved, and auto-merge remains armed pending exact-head hosted checks and independent review | +| #600 | `1cb63dae` | this baseline's pre-amendment observed head; composed with current main and awaiting exact-head review/check evidence | | #588 | `6185f2ae` | raw-residual reconstruction, rank-zero identity, API presence, and comparison-strip contracts reconciled with current main; focused backend/frontend/schema checks passed, all review threads are resolved, and auto-merge is armed | | #582 | `cab04063` | batched cited-lineage fetch was semantically composed with current main while retaining ADR 0161 interval relations; 27 focused lineage/documentation checks passed, no review threads remain, and auto-merge is armed pending hosted checks and independent review | | #579 | `bfefe98e` | interaction-map coordinates were semantically composed with current main's cross-share and interval work; the ADR 0168/0202 collision was repaired, all threads are resolved, 69 focused scientific/schema checks plus the focused live API contract passed, and 163 frontend tests, lint, app/Storybook builds, and desktop/mobile rendered audits passed; auto-merge is armed pending hosted checks and independent review | @@ -87,6 +86,7 @@ Recent protected-default-branch delivery evidence (squash merges onto | PR | Merged (UTC) | Delivered | | ---: | --- | --- | +| #601 | 2026-08-25 06:38 | APA 7th PROV-O and PROV-DM references for ADRs 0011 and 0065 | | #595 | 2026-08-25 04:39 | audited no-draft import door, nullable updated-at fallback, and event-time import | | #484 | 2026-08-25 04:39 | Allen interval relations with deferred FK validation | | #383 | 2026-08-25 04:39 | reader-safe OTel diagnostics and service-peer-bounded session metadata | From 023a02cac69800503a5fb30ad2bed20cf5cc16c5 Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 15:53:57 +0900 Subject: [PATCH 22/32] docs: refresh current-main PR heads --- docs/product-technical-gap-baseline.md | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 8b4f3c93d..ca748d9a7 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Audit snapshot: 2026-08-25 15:49 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 15:52 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -18,15 +18,15 @@ context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | | #602 | `a1e4dc8f` | Post-detail modal semantics, focus containment/restoration, and Escape close are composed with current main; the valid rerender focus-steal review was repaired with a mount-only focus lifecycle and regression test, all threads are resolved, and auto-merge remains armed pending exact-head hosted checks and independent review | -| #600 | `1cb63dae` | this baseline's pre-amendment observed head; composed with current main and awaiting exact-head review/check evidence | -| #588 | `6185f2ae` | raw-residual reconstruction, rank-zero identity, API presence, and comparison-strip contracts reconciled with current main; focused backend/frontend/schema checks passed, all review threads are resolved, and auto-merge is armed | -| #582 | `cab04063` | batched cited-lineage fetch was semantically composed with current main while retaining ADR 0161 interval relations; 27 focused lineage/documentation checks passed, no review threads remain, and auto-merge is armed pending hosted checks and independent review | -| #579 | `bfefe98e` | interaction-map coordinates were semantically composed with current main's cross-share and interval work; the ADR 0168/0202 collision was repaired, all threads are resolved, 69 focused scientific/schema checks plus the focused live API contract passed, and 163 frontend tests, lint, app/Storybook builds, and desktop/mobile rendered audits passed; auto-merge is armed pending hosted checks and independent review | -| #493 | `6fbc8660` | ADR 0143 empty-DAG reasons were stacked on #387 channel evidence while retaining ADR 0161 interval labels; 36 focused backend checks, 175 focused frontend checks, lint, production/Storybook builds, and desktop/mobile rendered screenshots passed; no review threads remain and auto-merge is armed pending hosted exact-head gates and independent review | +| #600 | `ae6e8cbc` | this baseline's pre-amendment observed head; composed with current main and awaiting exact-head review/check evidence | +| #588 | `e9b29f11` | raw-residual reconstruction, rank-zero identity, API presence, and comparison-strip contracts are composed with current main; focused backend/frontend/schema checks passed, all review threads are resolved, and auto-merge is armed | +| #582 | `d7cf4072` | batched cited-lineage fetch is composed with current main while retaining ADR 0161 interval relations; 27 focused lineage/documentation checks passed, no review threads remain, and auto-merge is armed pending hosted checks and independent review | +| #579 | `dac509f9` | interaction-map coordinates are composed with current main's cross-share and interval work; the ADR 0168/0202 collision was repaired, all threads are resolved, 69 focused scientific/schema checks plus the focused live API contract passed, and 163 frontend tests, lint, app/Storybook builds, and desktop/mobile rendered audits passed; auto-merge is armed pending hosted checks and independent review | +| #493 | `415890a9` | ADR 0143 empty-DAG reasons are composed with current main and #387 channel evidence while retaining ADR 0161 interval labels; 36 focused backend checks, 175 focused frontend checks, lint, production/Storybook builds, and desktop/mobile rendered screenshots passed; no review threads remain and auto-merge is armed pending hosted exact-head gates and independent review | | #490 | `73413d0b` | broad historical workspace branch is conflicting with failing checks; decompose/restack rather than replaying its 931-commit merge wholesale | -| #482 | `6b9084b9` | ADR 0170 organization-alias captions were composed with current main; 44 backend/docs and 93 frontend tests, lint, app/Storybook builds, plus desktop/mobile rendered screenshot audits passed; auto-merge is armed pending hosted exact-head gates and independent review | -| #468 | `a1952e5e` | fast-mlsirm v0.8.0, exact Keyverse scope, orchestrator, and TEPP boundaries were composed with current main; TEPP contract/auth headers and telemetry-safe startup were retained, 74 focused integration tests plus 37 TEPP/start/config tests and the live authorization-scope contract passed, no review threads remain, and auto-merge is armed pending hosted exact-head gates and independent review | -| #387 | `3fab1f6a` | channel evidence plus Ask reconstruction-profile preservation is mergeable with no unresolved threads; only changes-requested decisions from obsolete heads remain, so auto-merge is armed pending current-head checks and independent re-review | +| #482 | `35f5b0fb` | ADR 0170 organization-alias captions are composed with current main; 44 backend/docs and 93 frontend tests, lint, app/Storybook builds, plus desktop/mobile rendered screenshot audits passed; auto-merge is armed pending hosted exact-head gates and independent review | +| #468 | `0f15d1bd` | fast-mlsirm v0.8.0, exact Keyverse scope, orchestrator, and TEPP boundaries are composed with current main; TEPP contract/auth headers and telemetry-safe startup were retained, 74 focused integration tests plus 37 TEPP/start/config tests and the live authorization-scope contract passed, no review threads remain, and auto-merge is armed pending hosted exact-head gates and independent review | +| #387 | `728125c1` | channel evidence plus Ask reconstruction-profile preservation is composed with current main and has no unresolved threads; only changes-requested decisions from obsolete heads remain, so auto-merge is armed pending current-head checks and independent re-review | No row above is merge evidence. Immediately before any lifecycle action, re-fetch the head, unresolved threads, formal reviews, rulesets, and same-head From 5bc7897f3770ea601fdc1ae284e98e75efc339f5 Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 16:15:11 +0900 Subject: [PATCH 23/32] fix: release pool during analysis provider work --- ...analysis-run-short-transaction-delivery.md | 9 + backend/app/analysis_run_start.py | 443 +++++++++--------- backend/app/analysis_run_worker.py | 41 +- backend/app/main.py | 34 +- ...analysis-run-short-transaction-delivery.md | 65 +++ docs/adr/README.md | 1 + .../POSTGRESQL_CONCURRENCY_REFERENCES.md | 15 + tests/test_analysis_run_start.py | 107 ++++- tests/test_analysis_run_worker.py | 17 +- 9 files changed, 473 insertions(+), 259 deletions(-) create mode 100644 CHANGELOG.d/analysis-run-short-transaction-delivery.md create mode 100644 docs/adr/0204-analysis-run-short-transaction-delivery.md create mode 100644 docs/doctoring/POSTGRESQL_CONCURRENCY_REFERENCES.md diff --git a/CHANGELOG.d/analysis-run-short-transaction-delivery.md b/CHANGELOG.d/analysis-run-short-transaction-delivery.md new file mode 100644 index 000000000..4dd2d5bd5 --- /dev/null +++ b/CHANGELOG.d/analysis-run-short-transaction-delivery.md @@ -0,0 +1,9 @@ +# Unreleased — Analysis-run provider work releases the database pool + +## Fixed + +- Analysis-run delivery now commits its claim before ThreadWeave adjudication + or TEPP transport, releases the pooled connection while that work runs, and + persists the complete outcome in a second short transaction. PostgreSQL + session advisory locks serialize the HTTP and worker paths without an + invented lease timeout. diff --git a/backend/app/analysis_run_start.py b/backend/app/analysis_run_start.py index 54a50f733..94a7f2264 100644 --- a/backend/app/analysis_run_start.py +++ b/backend/app/analysis_run_start.py @@ -2,15 +2,18 @@ ADR 0021 reconstructs lineage. ADR 0022 starts TEPP through ``tepp_client`` only. ADR 0023 enqueues that work on a durable outbox -so a crash after Running does not lose the item. Period-report stays +so a crash after Running does not lose the item. ADR 0204 keeps provider +work outside database transactions and pool leases. Period-report stays another path. Neither start invents a theta or a calibrated report score. """ from __future__ import annotations +import asyncio import hashlib import json +from dataclasses import dataclass from datetime import datetime, timezone from typing import Any from uuid import UUID @@ -83,6 +86,29 @@ def judge(self, candidate_label: str, record_label: str) -> float: raise _AdjudicationProviderError(str(exc)) from exc +@dataclass(frozen=True) +class _DeliveryPlan: + """Frozen provider input materialized by the short claim transaction.""" + + work_kind_code: str + started_at: datetime + locked: dict[str, Any] + records: tuple[Any, ...] = () + weights: dict[str, float] | None = None + + +@dataclass(frozen=True) +class _DeliveryOutcome: + """Provider result ready for one short atomic persistence transaction.""" + + work_kind_code: str + started_at: datetime + edges: tuple[Edge, ...] = () + status_code: str = _SUCCEEDED + failure_code: str = "" + envelope: dict[str, Any] | None = None + + def reconstruction_result_digest(edges: list[Edge]) -> str: """SHA-256 of the ordered parent choices. Never hashes a post body.""" material = json.dumps( @@ -704,8 +730,9 @@ async def enqueue_pending_analysis_run( async def deliver_queued_analysis_run( - conn: asyncpg.Connection, + pool: asyncpg.Pool, *, + database_url: str, analysis_run_id: str, account_id: str, affiliated_entity_ids: list[str], @@ -713,28 +740,86 @@ async def deliver_queued_analysis_run( adjudication_client: AdjudicationClient | None = None, valkey_stream_entry_id: str | None = None, ) -> dict[str, Any]: - """Claim the outbox row and finish ThreadWeave or TEPP. + """Claim, compute without a pool slot, then atomically persist delivery. A delivered row replays the stored result. Missing work is 409. TEPP stays Failed when the transport is missing or the envelope is - not persistable. No theta is invented. + not persistable. A dedicated PostgreSQL session owns the run-level + advisory lock; it carries no transaction and is not a pool slot. """ try: UUID(analysis_run_id) except ValueError as exc: raise AnalysisRunStartError(404, "This analysis run is not visible.") from exc + lock_conn = await asyncpg.connect(database_url) + try: + acquired = await lock_conn.fetchval( + "select pg_try_advisory_lock(hashtextextended($1, 0))", + f"lineageweave:analysis-run:{analysis_run_id}", + ) + if not acquired: + async with pool.acquire() as conn: + current = await _visible_or_404( + conn, analysis_run_id, account_id, affiliated_entity_ids + ) + if current["status_code"] == _SUCCEEDED: + return current + raise AnalysisRunStartError( + 409, + "Open this run. Delivery is already running; refresh to read its result.", + ) + + async with pool.acquire() as conn: + async with conn.transaction(): + plan_or_result = await _claim_delivery_plan( + conn, + analysis_run_id=analysis_run_id, + account_id=account_id, + affiliated_entity_ids=affiliated_entity_ids, + adjudication_client=adjudication_client, + valkey_stream_entry_id=valkey_stream_entry_id, + ) + if isinstance(plan_or_result, dict): + return plan_or_result + + outcome = await asyncio.to_thread( + _execute_delivery_plan, + plan_or_result, + tepp_client or TeppClient(), + adjudication_client, + ) + async with pool.acquire() as conn: + async with conn.transaction(): + return await _persist_delivery_outcome( + conn, + analysis_run_id=analysis_run_id, + account_id=account_id, + affiliated_entity_ids=affiliated_entity_ids, + outcome=outcome, + valkey_stream_entry_id=valkey_stream_entry_id, + ) + finally: + await lock_conn.close() + + +async def _claim_delivery_plan( + conn: asyncpg.Connection, + *, + analysis_run_id: str, + account_id: str, + affiliated_entity_ids: list[str], + adjudication_client: AdjudicationClient | None, + valkey_stream_entry_id: str | None, +) -> _DeliveryPlan | dict[str, Any]: + """Commit the claim and materialize immutable provider input.""" current = await fetch_visible_analysis_run( - conn, - analysis_run_id, - account_id, - affiliated_entity_ids, + conn, analysis_run_id, account_id, affiliated_entity_ids ) if current is None: raise AnalysisRunStartError(404, "This analysis run is not visible.") if current["status_code"] == _SUCCEEDED: return current - outbox = await conn.fetchrow( """ select outbox.analysis_run_id, outbox.work_kind_code, @@ -762,156 +847,173 @@ async def deliver_queued_analysis_run( return await _visible_or_404( conn, analysis_run_id, account_id, affiliated_entity_ids ) - now = datetime.now(timezone.utc) - try: - if not latest_outbox_delivery_is_claimed(latest): + started_at = datetime.now(timezone.utc) + if not latest_outbox_delivery_is_claimed(latest): + try: await _append_outbox_delivery( conn, analysis_run_id, await _next_outbox_delivery_ordinal(conn, analysis_run_id), "analysis_outbox_claimed", - now, + started_at, valkey_stream_entry_id, ) - if outbox["work_kind_code"] == _TEPP_KIND: - await _deliver_tepp_measurement( - conn, - analysis_run_id=analysis_run_id, - locked=outbox, - tepp_client=tepp_client or TeppClient(), - ) - elif outbox["work_kind_code"] == _TOPIC_LINEAGE_KIND: - await _deliver_topic_lineage_measurement( - conn, - analysis_run_id=analysis_run_id, - locked=outbox, - tepp_client=tepp_client or TeppClient(), - ) - else: - await _deliver_lineage_reconstruction( - conn, - analysis_run_id=analysis_run_id, - locked=outbox, - affiliated_entity_ids=affiliated_entity_ids, - adjudication_client=adjudication_client, + except asyncpg.UniqueViolationError as exc: + raise start_write_conflict_error() from exc + locked = dict(outbox) + if outbox["work_kind_code"] != _LINEAGE_KIND: + return _DeliveryPlan(str(outbox["work_kind_code"]), started_at, locked) + + member_rows = await _snapshot_member_posts( + conn, outbox["analysis_source_snapshot_id"] + ) + rows = member_rows or await _cutoff_source_posts( + conn, + corporate_entity_id=outbox["corporate_entity_id"], + knowledge_cutoff=outbox["knowledge_cutoff"], + affiliated_entity_ids=affiliated_entity_ids, + ) + active_channels = {"temporal", "secondary_key", "text"} + if adjudication_client is not None and getattr(adjudication_client, "available", False): + active_channels.add("llm") + weights = await load_estimated_channel_weights(conn, active_channels) + if weights is None: + raise AnalysisRunStartError( + 503, + "Channel weights are not estimated yet for this run's active " + f"channels ({', '.join(sorted(active_channels))}). Run " + "scripts/estimate_channel_weights.py, then start this run again.", + ) + return _DeliveryPlan( + _LINEAGE_KIND, + started_at, + locked, + tuple(records_from_source_posts(rows)), + dict(weights), + ) + + +def _execute_delivery_plan( + plan: _DeliveryPlan, + tepp_client: TeppClient, + adjudication_client: AdjudicationClient | None, +) -> _DeliveryOutcome: + """Run provider or reconstruction work with no database resource.""" + if plan.work_kind_code == _LINEAGE_KIND: + guarded_client = ( + _ProviderBoundaryAdjudication(adjudication_client) + if plan.weights is not None and "llm" in plan.weights + else adjudication_client + ) + try: + edges = lineage_edge_specs( + list(plan.records), llm=guarded_client, weights=plan.weights or {} ) - finished = datetime.now(timezone.utc) - if finished < now: - finished = now - await _append_outbox_delivery( - conn, - analysis_run_id, - await _next_outbox_delivery_ordinal(conn, analysis_run_id), - "analysis_outbox_delivered", - finished, - valkey_stream_entry_id, + except _AdjudicationProviderError as exc: + raise AnalysisRunStartError( + 503, + "The adjudication provider failed mid-reconstruction; nothing " + "was persisted. Check the contextual-orchestrator transport, " + "then start this run again.", + ) from exc + return _DeliveryOutcome(plan.work_kind_code, plan.started_at, tuple(edges)) + + request_factory = ( + topic_lineage_run_request + if plan.work_kind_code == _TOPIC_LINEAGE_KIND + else tepp_run_request + ) + request = request_factory( + idempotency_key=str(plan.locked["idempotency_key"]), + snapshot_sha256=str(plan.locked["snapshot_sha256"]), + knowledge_cutoff=plan.locked["knowledge_cutoff"], + corporate_entity_id=str(plan.locked["corporate_entity_id"]), + ) + if plan.work_kind_code == _TOPIC_LINEAGE_KIND: + status_code, failure_code, envelope = topic_lineage_submit_outcome( + tepp_client, request ) - except asyncpg.UniqueViolationError as exc: - raise start_write_conflict_error() from exc - return await _visible_or_404( - conn, analysis_run_id, account_id, affiliated_entity_ids + else: + status_code, failure_code, envelope = _tepp_submission(tepp_client, request) + return _DeliveryOutcome( + plan.work_kind_code, + plan.started_at, + status_code=status_code, + failure_code=failure_code, + envelope=envelope, ) -async def start_pending_analysis_run( +async def _persist_delivery_outcome( conn: asyncpg.Connection, *, analysis_run_id: str, account_id: str, affiliated_entity_ids: list[str], - tepp_client: TeppClient | None = None, - adjudication_client: AdjudicationClient | None = None, - valkey_stream_entry_id: str | None = None, + outcome: _DeliveryOutcome, + valkey_stream_entry_id: str | None, ) -> dict[str, Any]: - """Enqueue then deliver on one connection. - - The HTTP start path commits the outbox before this delivery so a - crash leaves Running plus a durable work item. Callers that wrap - both steps in one transaction keep the older all-or-nothing - behavior. - """ - queued = await enqueue_pending_analysis_run( - conn, - analysis_run_id=analysis_run_id, - account_id=account_id, - affiliated_entity_ids=affiliated_entity_ids, + """Persist one complete outcome and delivered event atomically.""" + outbox = await conn.fetchrow( + "select analysis_run_id from analysis_run_outbox where analysis_run_id = $1 for update", + analysis_run_id, ) - if queued["status_code"] == _SUCCEEDED: - return queued - return await deliver_queued_analysis_run( + if outbox is None: + raise AnalysisRunStartError(409, "Open this run. Its queued work no longer exists.") + latest = await _latest_outbox_delivery(conn, analysis_run_id) + if latest_outbox_delivery_is_delivered(latest): + return await _visible_or_404( + conn, analysis_run_id, account_id, affiliated_entity_ids + ) + finished = max(datetime.now(timezone.utc), outcome.started_at) + status_code = outcome.status_code + failure_code = outcome.failure_code + if outcome.work_kind_code == _LINEAGE_KIND: + await _persist_lineage_reconstruction( + conn, analysis_run_id=analysis_run_id, edges=outcome.edges, finished=finished + ) + elif outcome.status_code == _SUCCEEDED and outcome.envelope is not None: + persist = ( + _persist_topic_lineage_result + if outcome.work_kind_code == _TOPIC_LINEAGE_KIND + else _persist_tepp_result + ) + if not await persist( + conn, analysis_run_id=analysis_run_id, envelope=outcome.envelope + ): + status_code = _FAILED + failure_code = "tepp_result_not_persisted" + if outcome.work_kind_code != _LINEAGE_KIND: + await _append_status( + conn, + analysis_run_id, + await _next_status_ordinal(conn, analysis_run_id), + status_code, + finished, + failure_code, + ) + await _append_outbox_delivery( conn, - analysis_run_id=analysis_run_id, - account_id=account_id, - affiliated_entity_ids=affiliated_entity_ids, - tepp_client=tepp_client, - adjudication_client=adjudication_client, - valkey_stream_entry_id=valkey_stream_entry_id, + analysis_run_id, + await _next_outbox_delivery_ordinal(conn, analysis_run_id), + "analysis_outbox_delivered", + finished, + valkey_stream_entry_id, + ) + return await _visible_or_404( + conn, analysis_run_id, account_id, affiliated_entity_ids ) -async def _deliver_lineage_reconstruction( +async def _persist_lineage_reconstruction( conn: asyncpg.Connection, *, analysis_run_id: str, - locked: asyncpg.Record, - affiliated_entity_ids: list[str], - adjudication_client: AdjudicationClient | None = None, + edges: tuple[Edge, ...], + finished: datetime, ) -> None: - """Persist ThreadWeave parent choices for the frozen bag.""" - now = datetime.now(timezone.utc) - member_rows = await _snapshot_member_posts( - conn, - locked["analysis_source_snapshot_id"], - ) - if member_rows: - rows = member_rows - else: - rows = await _cutoff_source_posts( - conn, - corporate_entity_id=locked["corporate_entity_id"], - knowledge_cutoff=locked["knowledge_cutoff"], - affiliated_entity_ids=affiliated_entity_ids, - ) - # ADR 0200 point 1: weights are measurement output only -- the - # activated fast-mlsirm set matching this run's active channels - # (four when the adjudication client is available, three - # deterministic otherwise). A missing set fails the start with a - # next-action message instead of reconstructing on constants. - active_channels = {"temporal", "secondary_key", "text"} - if adjudication_client is not None and getattr(adjudication_client, "available", False): - active_channels = active_channels | {"llm"} - weights = await load_estimated_channel_weights(conn, active_channels) - if weights is None: - raise AnalysisRunStartError( - 503, - "Channel weights are not estimated yet for this run's active " - f"channels ({', '.join(sorted(active_channels))}). Run " - "scripts/estimate_channel_weights.py, then start this run again.", - ) - # The provider boundary is exactly llm.judge() -- wrapping the whole - # pipeline would disguise a reconstruction code bug as a retryable - # provider outage. The enclosing transaction rolls back either way, - # so no partial graph persists (issue #289 RED 4/6). - guarded_client = ( - _ProviderBoundaryAdjudication(adjudication_client) - if "llm" in active_channels - else adjudication_client - ) - try: - edges = lineage_edge_specs( - records_from_source_posts(rows), llm=guarded_client, weights=weights - ) - except _AdjudicationProviderError as exc: - raise AnalysisRunStartError( - 503, - "The adjudication provider failed mid-reconstruction; nothing " - "was persisted. Check the contextual-orchestrator transport, " - "then start this run again.", - ) from exc + """Persist complete ThreadWeave parent choices in the completion transaction.""" digest = reconstruction_result_digest(edges) - finished = datetime.now(timezone.utc) - if finished < now: - finished = now await conn.execute( """ insert into analysis_run_reconstruction @@ -943,82 +1045,3 @@ async def _deliver_lineage_reconstruction( _SUCCEEDED, finished, ) - - -async def _deliver_tepp_measurement( - conn: asyncpg.Connection, - *, - analysis_run_id: str, - locked: asyncpg.Record, - tepp_client: TeppClient, -) -> None: - """Submit the frozen snapshot through ``tepp_client``. Never persist a theta.""" - now = datetime.now(timezone.utc) - request = tepp_run_request( - idempotency_key=str(locked["idempotency_key"]), - snapshot_sha256=str(locked["snapshot_sha256"]), - knowledge_cutoff=locked["knowledge_cutoff"], - corporate_entity_id=str(locked["corporate_entity_id"]), - ) - status_code, failure_code, envelope = _tepp_submission(tepp_client, request) - if status_code == _SUCCEEDED and envelope is not None: - if not await _persist_tepp_result( - conn, - analysis_run_id=analysis_run_id, - envelope=envelope, - ): - status_code = _FAILED - failure_code = "tepp_result_not_persisted" - finished = datetime.now(timezone.utc) - if finished < now: - finished = now - await _append_status( - conn, - analysis_run_id, - await _next_status_ordinal(conn, analysis_run_id), - status_code, - finished, - failure_code, - ) - - -async def _deliver_topic_lineage_measurement( - conn: asyncpg.Connection, - *, - analysis_run_id: str, - locked: asyncpg.Record, - tepp_client: TeppClient, -) -> None: - """Submit the frozen snapshot through ``tepp_client`` for topic-lineage. - - Mirrors :func:`_deliver_tepp_measurement` (ADR 0022) with the - topic-lineage model contract (ADR 0132). Never persists a locally - computed topic identity or CHRONOS/TDT event prediction. - """ - now = datetime.now(timezone.utc) - request = topic_lineage_run_request( - idempotency_key=str(locked["idempotency_key"]), - snapshot_sha256=str(locked["snapshot_sha256"]), - knowledge_cutoff=locked["knowledge_cutoff"], - corporate_entity_id=str(locked["corporate_entity_id"]), - ) - status_code, failure_code, envelope = topic_lineage_submit_outcome(tepp_client, request) - if status_code == _SUCCEEDED and envelope is not None: - if not await _persist_topic_lineage_result( - conn, - analysis_run_id=analysis_run_id, - envelope=envelope, - ): - status_code = _FAILED - failure_code = "tepp_result_not_persisted" - finished = datetime.now(timezone.utc) - if finished < now: - finished = now - await _append_status( - conn, - analysis_run_id, - await _next_status_ordinal(conn, analysis_run_id), - status_code, - finished, - failure_code, - ) diff --git a/backend/app/analysis_run_worker.py b/backend/app/analysis_run_worker.py index 4f3d76ead..5a6109b16 100644 --- a/backend/app/analysis_run_worker.py +++ b/backend/app/analysis_run_worker.py @@ -30,6 +30,7 @@ async def consume_analysis_run_stream_once( client: redis.Redis, pool: asyncpg.Pool, *, + database_url: str, last_id: str, tepp_client: TeppClient, adjudication_client: AdjudicationClient, @@ -78,25 +79,25 @@ async def consume_analysis_run_stream_once( # once the operator resolves the named next action. try: async with pool.acquire() as conn: - async with conn.transaction(): - owner = await conn.fetchrow( - """ - select requested_by_account_id - from analysis_run - where analysis_run_id = $1::uuid - """, - analysis_run_id, - ) - if owner is not None: - await deliver_queued_analysis_run( - conn, - analysis_run_id=analysis_run_id, - account_id=str(owner["requested_by_account_id"]), - affiliated_entity_ids=[], - tepp_client=tepp_client, - adjudication_client=adjudication_client, - valkey_stream_entry_id=str(entry_id), - ) + owner = await conn.fetchrow( + """ + select requested_by_account_id + from analysis_run + where analysis_run_id = $1::uuid + """, + analysis_run_id, + ) + if owner is not None: + await deliver_queued_analysis_run( + pool, + database_url=database_url, + analysis_run_id=analysis_run_id, + account_id=str(owner["requested_by_account_id"]), + affiliated_entity_ids=[], + tepp_client=tepp_client, + adjudication_client=adjudication_client, + valkey_stream_entry_id=str(entry_id), + ) except AnalysisRunCreateError as exc: _worker_logger.warning( "analysis-run %s delivery refused (%s): %s", @@ -112,6 +113,7 @@ async def run_analysis_run_worker( client: redis.Redis, pool: asyncpg.Pool, *, + database_url: str, tepp_client: TeppClient, adjudication_client: AdjudicationClient, ) -> None: @@ -123,6 +125,7 @@ async def run_analysis_run_worker( client, pool, last_id=last_id, + database_url=database_url, tepp_client=tepp_client, adjudication_client=adjudication_client, ) diff --git a/backend/app/main.py b/backend/app/main.py index d233ca315..0e98548af 100644 --- a/backend/app/main.py +++ b/backend/app/main.py @@ -240,6 +240,7 @@ async def lifespan(app: FastAPI): run_analysis_run_worker( valkey, pool, + database_url=settings.database_url, tepp_client=configured_tepp_client( settings.tepp_transport_url, settings.tepp_api_key, @@ -3320,23 +3321,22 @@ async def start_analysis_run( work_kind_code=str(queued.get("run_kind_code") or ""), request_sha256=request_digest, ) - async with pool.acquire() as conn: - async with conn.transaction(): - try: - started = await deliver_queued_analysis_run( - conn, - analysis_run_id=analysis_run_id, - account_id=account.user_account_id, - affiliated_entity_ids=list(account.corporate_entity_ids), - tepp_client=configured_tepp_client( - settings.tepp_transport_url, - settings.tepp_api_key, - ), - adjudication_client=_adjudication_client(), - valkey_stream_entry_id=stream_id, - ) - except AnalysisRunStartError as exc: - raise HTTPException(exc.status_code, exc.detail) from exc + try: + started = await deliver_queued_analysis_run( + pool, + database_url=settings.database_url, + analysis_run_id=analysis_run_id, + account_id=account.user_account_id, + affiliated_entity_ids=list(account.corporate_entity_ids), + tepp_client=configured_tepp_client( + settings.tepp_transport_url, + settings.tepp_api_key, + ), + adjudication_client=_adjudication_client(), + valkey_stream_entry_id=stream_id, + ) + except AnalysisRunStartError as exc: + raise HTTPException(exc.status_code, exc.detail) from exc return started diff --git a/docs/adr/0204-analysis-run-short-transaction-delivery.md b/docs/adr/0204-analysis-run-short-transaction-delivery.md new file mode 100644 index 000000000..8b94e6017 --- /dev/null +++ b/docs/adr/0204-analysis-run-short-transaction-delivery.md @@ -0,0 +1,65 @@ +# ADR 0204 — Analysis-run delivery releases pooled connections during provider work + +**Decision status:** Accepted +**Date:** 2026-08-25 +**Related:** [0023](0023-analysis-run-outbox.md), issue [#566](https://github.com/ContextualWisdomLab/LineageWeave/issues/566) + +## Context + +Analysis-run delivery currently locks `analysis_run_outbox` inside a database +transaction and retains that transaction and its pooled connection while +ThreadWeave adjudication or TEPP transport waits on an external provider. A +large frozen snapshot can therefore occupy a row lock and scarce pool slot for +minutes. Moving the synchronous provider work to another thread frees the event +loop but does not release either database resource. + +The claim must remain exclusive across the HTTP start path and the background +worker. A time-based application lease would require an unsupported expiry +constant and could admit a second writer while a valid deep provider run is +still executing. + +## Decision + +1. A delivery owns a PostgreSQL **session-level advisory lock** derived by + PostgreSQL from the immutable analysis-run UUID. `pg_try_advisory_lock` + fails immediately when another delivery owns the run. PostgreSQL releases + the lock automatically if the dedicated lock session disconnects, including + an ungraceful worker failure. No guessed lease duration or heartbeat ratio + is introduced. +2. The advisory-lock session is opened outside the application pool and does + not run the product reads or writes. It carries no open transaction while a + provider executes. One active analysis run therefore consumes no pooled + connection during provider latency. +3. A first short pooled transaction validates visibility, locks the outbox row, + appends the immutable claim event, and materializes the frozen provider + input. It commits before any adjudication or TEPP call. +4. Provider computation runs with no pooled connection and no open database + transaction. Lineage uses only fast-mlsirm-estimated active-channel weights; + TEPP remains the sole calibrated-measurement transport. No weight, theta, + retry interval, or lease duration is invented locally. +5. A second short pooled transaction locks the outbox row again and atomically + persists the complete result, terminal status, and delivered event. A + provider failure leaves Running plus the durable claimed outbox item for an + explicit retry; it cannot leave a partial graph or calibrated result. +6. If the advisory lock is already held, delivery returns a conflict that tells + the caller to open the running analysis. It does not wait while retaining an + HTTP request or pool slot. + +## Consequences + +- Provider latency no longer expands a database transaction or starves the + application pool. +- PostgreSQL session cleanup supplies crash recovery without a rule-of-thumb + timeout. +- The dedicated advisory-lock session is bounded to one per concurrently + executing analysis run and is visible in `pg_locks` for operations audit. +- Result persistence remains all-or-nothing in one short transaction. + +## References + +PostgreSQL Global Development Group. (2026a). *PostgreSQL 18.6 documentation: +13.3 explicit locking*. https://www.postgresql.org/docs/18/explicit-locking.html + +PostgreSQL Global Development Group. (2026b). *PostgreSQL 18.6 documentation: +9.28 system administration functions*. +https://www.postgresql.org/docs/18/functions-admin.html diff --git a/docs/adr/README.md b/docs/adr/README.md index 0af8db2cd..d1444fce7 100644 --- a/docs/adr/README.md +++ b/docs/adr/README.md @@ -16,6 +16,7 @@ decision from them. | [`ONTOLOGY_NAMESPACE_INVENTORY.md`](../doctoring/ONTOLOGY_NAMESPACE_INVENTORY.md) | [0157](0157-public-ontology-namespace-identity.md) | | [`image-content-schema.md`](../image-content-schema.md) | [0066](0066-position-preserving-image-content.md) | | [`storybook-inventory.md`](../storybook-inventory.md) | [0118](0118-uiux-standard-guide-v3-design-overhaul.md), [0184](0184-ontology-provenance-explorer.md) | +| [`POSTGRESQL_CONCURRENCY_REFERENCES.md`](../doctoring/POSTGRESQL_CONCURRENCY_REFERENCES.md) | [0204](0204-analysis-run-short-transaction-delivery.md) | [0011](0011-prov-o-standard-relations.md) and [0065](0065-prov-o-provenance-boundary.md) cite the dated W3C PROV-O and PROV-DM Recommendations (https://www.w3.org/TR/2013/REC-prov-o-20130430/ and https://www.w3.org/TR/2013/REC-prov-dm-20130430/). diff --git a/docs/doctoring/POSTGRESQL_CONCURRENCY_REFERENCES.md b/docs/doctoring/POSTGRESQL_CONCURRENCY_REFERENCES.md new file mode 100644 index 000000000..06d073dbd --- /dev/null +++ b/docs/doctoring/POSTGRESQL_CONCURRENCY_REFERENCES.md @@ -0,0 +1,15 @@ +# PostgreSQL concurrency references + +Supporting research register for ADR 0204. ADR 0204 is normative. + +PostgreSQL Global Development Group. (2026a). *PostgreSQL 18.6 documentation: +13.3 explicit locking*. https://www.postgresql.org/docs/18/explicit-locking.html + +PostgreSQL Global Development Group. (2026b). *PostgreSQL 18.6 documentation: +9.28 system administration functions*. +https://www.postgresql.org/docs/18/functions-admin.html + +Adopted facts: session-level advisory locks survive transaction commit, are +released explicitly or when their session ends, are observable through +`pg_locks`, and `pg_try_advisory_lock` returns immediately when ownership is +unavailable. These properties replace an application-defined lease timeout. diff --git a/tests/test_analysis_run_start.py b/tests/test_analysis_run_start.py index c084ddda6..6c39ee54e 100644 --- a/tests/test_analysis_run_start.py +++ b/tests/test_analysis_run_start.py @@ -1,9 +1,11 @@ """Start-reconstruction contracts: digest, freeze, 422/409, designed tree.""" from datetime import datetime, timezone +from functools import lru_cache import pytest +from backend.app import analysis_run_start from backend.app.analysis_run_ingestion import reconstructed_edge_is_visible from backend.app.analysis_run_start import ( AnalysisRunStartError, @@ -18,20 +20,107 @@ topic_lineage_submit_outcome, ) from backend.app.lineage_ingestion import records_from_source_posts +from lineageweave.channel_weight_estimation import estimate_fixture_channel_weights from lineageweave.fixtures import sample_records from lineageweave.http_client import HttpClientError from lineageweave.lineage_persistence import lineage_edge_specs from lineageweave.tepp_client import AnalysisRunRequest, TeppClient, TeppNotAvailable -# Synthetic unit-test fusion weights (org policy allows synthetic data -# in unit tests); product paths load persisted fast-mlsirm estimates -# and fail closed otherwise (ADR 0200 point 1). -_SYNTHETIC_WEIGHTS = {"temporal": 0.5, "secondary_key": 0.34, "text": 0.16} +@lru_cache(maxsize=1) +def _estimated_fixture_weights() -> dict[str, float]: + """Return the fast-mlsirm estimate or fail the test closed.""" + estimate = estimate_fixture_channel_weights() + assert estimate is not None + return estimate.weights + + +@pytest.mark.anyio +async def test_delivery_releases_pool_during_provider_work_and_closes_run_lock(monkeypatch): + """ADR 0204: provider latency owns neither a transaction nor a pool slot.""" + active_pool_leases = 0 + + class Transaction: + async def __aenter__(self): + return self + + async def __aexit__(self, *_args): + return False + + class Connection: + def transaction(self): + return Transaction() + + class Acquire: + async def __aenter__(self): + nonlocal active_pool_leases + active_pool_leases += 1 + return Connection() + + async def __aexit__(self, *_args): + nonlocal active_pool_leases + active_pool_leases -= 1 + return False + + class Pool: + def acquire(self): + return Acquire() + + class LockConnection: + closed = False + + async def fetchval(self, query, lock_key): + assert "pg_try_advisory_lock" in query + assert lock_key.endswith("00000000-0000-0000-0000-000000000001") + return True + + async def close(self): + self.closed = True + + lock_connection = LockConnection() + plan = analysis_run_start._DeliveryPlan( + "analysis_run_tepp", + datetime(2026, 8, 25, tzinfo=timezone.utc), + {}, + ) + + async def fake_claim(*_args, **_kwargs): + assert active_pool_leases == 1 + return plan + + def fake_execute(*_args): + assert active_pool_leases == 0 + return analysis_run_start._DeliveryOutcome( + "analysis_run_tepp", plan.started_at, status_code="analysis_status_failed" + ) + + async def fake_persist(*_args, **_kwargs): + assert active_pool_leases == 1 + return {"status_code": "analysis_status_failed"} + + async def fake_connect(_database_url): + return lock_connection + + monkeypatch.setattr(analysis_run_start.asyncpg, "connect", fake_connect) + monkeypatch.setattr(analysis_run_start, "_claim_delivery_plan", fake_claim) + monkeypatch.setattr(analysis_run_start, "_execute_delivery_plan", fake_execute) + monkeypatch.setattr(analysis_run_start, "_persist_delivery_outcome", fake_persist) + + result = await analysis_run_start.deliver_queued_analysis_run( + Pool(), + database_url="postgresql://synthetic", + analysis_run_id="00000000-0000-0000-0000-000000000001", + account_id="synthetic-account", + affiliated_entity_ids=[], + ) + + assert result == {"status_code": "analysis_status_failed"} + assert active_pool_leases == 0 + assert lock_connection.closed def test_reconstruction_digest_is_stable_and_ignores_edge_order() -> None: """The same parent choices hash the same way regardless of insert order.""" - edges = lineage_edge_specs(sample_records(), weights=_SYNTHETIC_WEIGHTS) + edges = lineage_edge_specs(sample_records(), weights=_estimated_fixture_weights()) reversed_edges = list(reversed(edges)) assert reconstruction_result_digest(edges) == reconstruction_result_digest(reversed_edges) assert reconstruction_result_digest([]) == reconstruction_result_digest([]) @@ -45,7 +134,8 @@ def test_start_uses_the_same_parent_choices_as_library_reconstruct() -> None: branch point for the revised quote and the delivery question. A start that dropped an edge or invented a parent would fail this check. """ - edges = lineage_edge_specs(sample_records(), weights=_SYNTHETIC_WEIGHTS) + weights = _estimated_fixture_weights() + edges = lineage_edge_specs(sample_records(), weights=weights) children = {edge.child_id for edge in edges if edge.parent_id == "rec-002"} assert children >= {"rec-003", "rec-004"} assert all(0.0 <= edge.fused_score <= 1.0 for edge in edges) @@ -66,11 +156,12 @@ def test_start_wiring_recovers_a100_from_source_post_rows() -> None: } for record in sample_records() ] - edges = lineage_edge_specs(records_from_source_posts(rows), weights=_SYNTHETIC_WEIGHTS) + weights = _estimated_fixture_weights() + edges = lineage_edge_specs(records_from_source_posts(rows), weights=weights) children = {edge.child_id for edge in edges if edge.parent_id == "rec-002"} assert children >= {"rec-003", "rec-004"} assert reconstruction_result_digest(edges) == reconstruction_result_digest( - lineage_edge_specs(sample_records(), weights=_SYNTHETIC_WEIGHTS) + lineage_edge_specs(sample_records(), weights=weights) ) diff --git a/tests/test_analysis_run_worker.py b/tests/test_analysis_run_worker.py index 847f72e3b..8dcbb500a 100644 --- a/tests/test_analysis_run_worker.py +++ b/tests/test_analysis_run_worker.py @@ -79,6 +79,7 @@ async def test_idle_worker_reads_do_not_emit_empty_spans(monkeypatch): _IdleValkey(), _Pool(), last_id="0-0", + database_url="postgresql://synthetic", tepp_client=TeppClient(), adjudication_client=NullAdjudicationClient(), ) == "0-0" @@ -123,6 +124,7 @@ async def xread(self, _streams, *, count, block): FailingValkey(), _Pool(), last_id="0-0", + database_url="postgresql://synthetic", tepp_client=TeppClient(), adjudication_client=NullAdjudicationClient(), ) @@ -179,6 +181,7 @@ async def no_sleep(*_args): await analysis_run_worker.run_analysis_run_worker( RecoveringAnalysisValkey(), _Pool(), + database_url="postgresql://synthetic", tepp_client=TeppClient(), adjudication_client=NullAdjudicationClient(), ) @@ -240,16 +243,19 @@ async def xread(self, _streams, *, count, block): async def test_consumer_forwards_valid_event_and_skips_malformed_event(monkeypatch): calls = [] - async def fake_deliver(conn, **kwargs): - del conn + pool = _Pool() + + async def fake_deliver(delivery_pool, **kwargs): + assert delivery_pool is pool calls.append(kwargs) monkeypatch.setattr(analysis_run_worker, "deliver_queued_analysis_run", fake_deliver) last_id = await analysis_run_worker.consume_analysis_run_stream_once( _Valkey(), - _Pool(), + pool, last_id="0-0", + database_url="postgresql://synthetic", tepp_client=TeppClient(), adjudication_client=NullAdjudicationClient(), ) @@ -258,6 +264,7 @@ async def fake_deliver(conn, **kwargs): assert calls == [ { "analysis_run_id": "00000000-0000-0000-0000-000000000001", + "database_url": "postgresql://synthetic", "account_id": "synthetic-account", "affiliated_entity_ids": [], "tepp_client": calls[0]["tepp_client"], @@ -290,8 +297,7 @@ async def test_one_refused_delivery_does_not_end_the_worker(monkeypatch): """ delivered = [] - async def fake_deliver(conn, **kwargs): - del conn + async def fake_deliver(_pool, **kwargs): if kwargs["analysis_run_id"].endswith("1"): raise AnalysisRunStartError( 503, "Channel weights are not estimated yet." @@ -304,6 +310,7 @@ async def fake_deliver(conn, **kwargs): _TwoRunsValkey(), _Pool(), last_id="0-0", + database_url="postgresql://synthetic", tepp_client=TeppClient(), adjudication_client=NullAdjudicationClient(), ) From 49c8e00622fd081c15a1067340bfb3eac49b3713 Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 16:15:54 +0900 Subject: [PATCH 24/32] fix: remove merged package metadata markers --- CHANGELOG.d/analysis-run-short-transaction-delivery.md | 2 ++ frontend/package.json | 4 ---- uv.lock | 4 ---- 3 files changed, 2 insertions(+), 8 deletions(-) diff --git a/CHANGELOG.d/analysis-run-short-transaction-delivery.md b/CHANGELOG.d/analysis-run-short-transaction-delivery.md index 4dd2d5bd5..c44459200 100644 --- a/CHANGELOG.d/analysis-run-short-transaction-delivery.md +++ b/CHANGELOG.d/analysis-run-short-transaction-delivery.md @@ -7,3 +7,5 @@ persists the complete outcome in a second short transaction. PostgreSQL session advisory locks serialize the HTTP and worker paths without an invented lease timeout. +- Removed conflict markers accidentally delivered in the Python and frontend + package-version metadata, restoring deterministic dependency and UI builds. diff --git a/frontend/package.json b/frontend/package.json index b3ab3a502..2a95c3a22 100644 --- a/frontend/package.json +++ b/frontend/package.json @@ -1,11 +1,7 @@ { "name": "frontend", "private": true, -<<<<<<< HEAD "version": "2.15.1", -======= - "version": "2.14.0", ->>>>>>> 5ef5bf66 (feat: show corroborated SKOS companion on organization chips) "type": "module", "scripts": { "dev": "vite", diff --git a/uv.lock b/uv.lock index fbba5bd5a..87668cd4a 100644 --- a/uv.lock +++ b/uv.lock @@ -597,11 +597,7 @@ wheels = [ [[package]] name = "lineageweave" -<<<<<<< HEAD version = "2.15.1" -======= -version = "2.14.0" ->>>>>>> 5ef5bf66 (feat: show corroborated SKOS companion on organization chips) source = { editable = "." } dependencies = [ { name = "certifi" }, From 2b4d74b86aa6a160c2488bb9420804087c14645e Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 16:18:58 +0900 Subject: [PATCH 25/32] docs: restore aggregate product gap baseline --- docs/product-technical-gap-baseline.md | 416 +++++++++++++++++++++++-- 1 file changed, 392 insertions(+), 24 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 21d0f28de..20c0cf5a0 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,26 +1,394 @@ # Product & Technical Gap Baseline -## 1. Known Parsing & Frontend Display Gaps -- **Footnote Parsing**: `post=00505695-3e61-1fd1-83c5-263f88a9e77a` fails to recognize footnotes (li/oi level errors). -- **Table Parsing**: `post=00505695-3e61-1fd1-80c6-86bb61c8ddc5` completely fails at parsing tables. -- **Indentation**: Incorrect indentation rendering in `post=00505695-7571-1fd1-83c3-d521b187ad5b` and `post=00505695-3e61-1fd1-83c0-497b3c1c455e`. -- **Image/Table OCR**: `post=00505695-7571-1fd1-83dd-3d22a61a5734` fails text recognition for tables inside images, markdown parsing fails, and image OCR description is too shallow for Ontology & Semantics. -- **Math/Superscripts**: `post=00505695-9612-1fe1-83a7-e30153323f25` fails to parse superscripts like m^3 properly. Needs strict Ontology grammar for math formulas. -- **Missing UI Elements**: DAG (Directed Acyclic Graph) view is currently missing from the frontend for `post=00505695-7571-1fd1-83c5-895ed333cdbc`. - -## 2. LLM Extraction & Knowledge Graph Gaps -- **Multiple Project Extraction**: (Resolved) LLM prompt updated to request key_events as objects with project_name, separating events correctly. -- **5W1H Missing**: (Resolved) LLM prompt updated to explicitly request 5W1H evidence items in the JSON output array. -- **R&R and Keyman Missing**: (Resolved) LLM prompt updated to explicitly instruct using actual stated names rather than collective titles. -- **Entity Resolution / Searxng**: Abbreviations like "한전" and "한국전력" are not mapped properly using Searxng and KG corroboration. Buyer chips now show a unique corroborated SKOS companion for the synthetic `DC` / `Demo Corp` pair (ADR 0170); that does not close live unresolved abbreviations. -- **Meso-level Team Mapping**: (Resolved) Checked extraction logic; `team` mapping logic is present and correct, but LLM needed better explicit instruction which is covered by R&R resolution. -- **Base64 Image Omni-modal**: Current text-only embedding fails on images. Omni-modal LLM processing is required for images to capture layout, font size, colors, and spatial meaning. - -## 3. General Architecture Gaps -- **DB Architecture**: Ensure PostgreSQL is strictly used (no file DBs), 3rd normal form is maintained, and Hot Partitions are handled. DB locks must be managed (or use read/write replicas). -- **Zotero Integration**: Papers and standards referenced by TEPP must be synced via Local Zotero API (http://localhost:23119/api/) and cited using APA 7th edition in docstrings. -- **Testing**: We need actual testing of Psychometrics (Fast-MLSIRM parameter calibration, RMSE of estimates, Fixed-Item Parameter Calibration, CAT) against synthetic/demo data. -- **Security & Compliance**: PII masking cannot break the system. Need SOC 2 and CSAP compliance alternatives to blind PII masking. -- **LLM Orchestration**: Ensure ALL LLM calls route through `contextual-orchestrator` utilizing API keys (BYTEZ, NVIDIA, OPENROUTER, OPENAI) with auto model discovery and optimal reasoning effort allocation (Fugu/Conductor/TRINITY research). - -*This document is continuously updated by the hourly automated agent loop.* +> Audit snapshot: 2026-08-25 12:07 KST (refreshed by the autonomous merge +> loop). This repository records synthetic fixtures and aggregate, +> non-identifying runtime evidence only. Open PRs and local checks are not +> protected-default-branch release evidence. Identifying post identifiers, +> organization names, and production record keys must never appear in this +> file. + +## 1. Exact-head and governance evidence + +The protected default branch was `965c798de5f789db245625e06e03c1563163051f` +when this baseline was refreshed. The live queue contained 24 open PRs and 22 +open issues. The exact-head inventory below supersedes older per-PR snapshots +elsewhere in this document; those older rows remain useful historical delivery +context only. + +| PR | Exact observed head | Merge/check state at this snapshot | +| ---: | --- | --- | +| #598 | `63db0854` | reads 5W1H roles/events across a stale summary contract version; exact-head checks and independent review pending | +| #597 | `8e132b5b` | clears stale related-post graph state before opening Customer Master detail in place; auto-merge armed, exact-head checks and independent review pending | +| #596 | `edb24472` | aligns the two orchestrator-backed hierarchy/name-resolution clients with the existing bounded 600-second deep-work window and verifies both defaults; exact-head checks and independent review pending | +| #595 | `9378c04f` | restores the audited no-draft-dimension import door and nullable updated-at fallback orphaned by the prior stack race; result typing repaired, 24 focused tests passed, auto-merge armed | +| #591 | `ea5e72f5` | canonical current-queue baseline; this refresh supersedes the observed head, so checks and review restart | +| #588 | `3a67a802` | reconstruction naming reconciled with current main; auto-merge armed, checks pending | +| #585 | `ffe1290b` | only locally-authored bounded job errors may persist; transport errors remain generic; auto-merge armed, checks restarted | +| #584 | `17068ec3` | current-main ADR collision repaired; auto-merge armed, checks restarted | +| #582 | `3992302f` | batched Ask lineage graph reconciled with current main and the conflict-tail repair; auto-merge armed, checks restarted | +| #581 | `c1b424eb` | concurrent exact-head update observed after event-time Ask reconciliation; checks and review pending | +| #579 | `69c05078` | interaction-map migration and hosted SQL-suppression inventory reconciled; auto-merge armed | +| #564 | `212b55a9` | concurrent exact-head update observed; checks and review pending | +| #563 | `353b7470` | concurrent exact-head update observed after raw-residual identity repair; checks and review pending | +| #539 | `e4dffe63` | concurrent exact-head update observed; checks and review pending | +| #537 | `d5ac65d8` | current-main reconciliation pushed; checks restarted | +| #493 | `e9c63d56` | concurrent exact-head update observed; checks and review pending | +| #490 | `73413d0b` | code-quality findings repaired; current-main reconciliation remains before checks can settle | +| #484 | `fa898bc5` | concurrent exact-head update observed after Allen interval reconciliation; checks and review pending | +| #482 | `b0e737d3` | concurrent exact-head update observed after the corroborated-SKOS reconciliation; exact-head checks and review pending | +| #468 | `a14093a3` | exact Keyverse org/PU scope persists in 3NF job child tables and is intersected with current grants; provider-shape, completeness-gate, role-intersection, and TEPP-contract reviews repaired; current main merged, 52 focused tests passed, auto-merge armed | +| #434 | `ff34c9b6` | stacked on #387; review findings repaired, but the stack remains conflicting until its parent delivery boundary settles | +| #394 | `ec74eedd` | indentation evidence composed with current HTTP response-boundary protections; 56 focused tests passed, auto-merge armed | +| #387 | `462b41fb` | budgeted LLM selection precedes exact-channel weight lookup; persistence evidence uses fast-mlsirm estimates, 37 backend tests plus frontend interaction/lint/build passed; auto-merge armed, stale changes-requested state awaits exact-head rereview | +| #383 | `138eaad4` | reader-safe OTel diagnostics composed with current HTTP response bounds; 76 focused tests passed, auto-merge armed | + +No row above is merge evidence. Immediately before any lifecycle action, +re-fetch the head, unresolved threads, formal reviews, rulesets, and same-head +check conclusions. In particular, queued checks are infrastructure state and +do not transfer evidence from an earlier SHA. + +PR #592 first merged as `3b3af3b4fe9c439354433a43444e05f37ab24ea3` +into #590's non-default stack base at `2f033ba3`. The complete stack then +passed the protected gate and #590 merged to `main` as +`1d1379fc59d9dac6e9c8bfa4812313e3b9e8f3c8`. + +PR #521 merged through protected `main` as +`3797f063b1a7396972a749aa81f23745acccbee1`; it is release evidence and no +longer part of the open queue. That merge also left a standalone conflict +marker and duplicated stale tail in `CLAUDE.md`; #594 repaired it through +protected `main` as `241be2dddf657f854cb8be54fe11d4ef48d37976`. + +The former protected-`main` login defect (unauthenticated `AdminPanel` render +plus unused OIDC return-url helpers failing `tsc -b`) is repaired on +protected `main`; the ADR 0109 pattern (`returnUrlFromLocation()` then +`rememberOidcReturnUrl()` before `signinRedirect`, and an authenticated-only +`accessToken` narrowing before `AdminPanel`) is present at +`frontend/src/App.tsx` on the current head. Eight branches cut from the older +broken base still carried the defect; the shared repair was applied to each of +them during this loop (see §3.1). + +Two systemic gates currently dominate the queue: + +1. **Strix provider unavailability (org control plane).** The central required + Strix scan fails across ~28 unrelated LineageWeave PRs with "could not + complete authoritative vulnerability analysis because its provider/backend + was unavailable": `nvidia_nim/nvidia/nemotron-3-super-120b-a12b` exits + after ~70 s and `openai-direct/gpt-5.6-luna` after ~5 s. This is an + infrastructure failure, not a code finding. The durable repair is + ContextualWisdomLab/.github#1263 (executable Azure and cross-provider + fallbacks), whose first push was itself blocked by the same replay guard it + fixes because its prior merge commit reverted ten base-merged paths; that + branch was re-based over current `.github` main restoring the reverted work + (vulnerability-location boundary filtering, internal-warning filter, + requirements lock refresh, changed-path workflow state) while preserving + the PR's own failover changes. +2. **Current-head independent approval.** The org merge scheduler requires + `reviewDecision == APPROVED` plus complete Strix evidence on the exact + head. Bot review evidence regenerates per push, so any repair push resets + the review clock by design; this is expected and not a bypass target. + +Recent protected-default-branch delivery evidence (squash merges onto +`main`, newest first): + +| PR | Merged (UTC) | Delivered | +| ---: | --- | --- | +| #355 | 2026-08-25 02:38 | Naruon calendar projection contract and conformance fixture | +| #562 | 2026-08-24 02:05 | parameter-free classic RRF; deleted the last hand-picked fused score | +| #561 | 2026-08-24 01:47 | knowledge-graph precedence/hierarchy relation classification and layout order | +| #555 | 2026-08-24 01:29 | per-channel score breakdown persisted on `post_lineage_edge.channel_scores` (ADR 0195) | +| #559 | 2026-08-24 01:26 | deleted `DEFAULT_CHANNEL_WEIGHTS` hand-picked fallback | +| #549 | 2026-08-24 00:43 | clamped embedding cosine into `[0, 1]` instead of remapping from `[-1, 1]` (ADR 0190) | +| #548 | 2026-08-24 00:37 | mid-reconstruction provider failure maps to an explicit unavailable state | +| #544 | 2026-08-24 00:27 | fusion weights accepted only via fast-mlsirm estimation | +| #538 | 2026-08-23 23:39 | real embeddings wired into the Event Lineage text channel | + +This documentation is owned by protected `main` again: the #426 stack landed, +so hidden-stack merges (#494, #497, #499, #505, #509 into unprotected parent +branches) are historical context only and no longer gate anything. + +The current protected-`main` and exact #507 trees are clean of the private +runtime source-table identifier present in the closed #506 head and older +public history. Do not reproduce or hint at its value. Historical remediation +requires the ADR 0001 incident process and security/privacy-owner coordination; +never force-push or delete evidence ad hoc. + +The Grok durable hourly loop and the central thin GitHub Actions caller +ContextualWisdomLab/.github#1259 (minute 4, `pr-review-fix-scheduler.yml`) +both target this repository. Do not add a LineageWeave-local duplicate +workflow. OpenCode coverage-evidence currently fails pnpm 9.15.9 heads on +`--trust-lockfile` (a pnpm 11.3 flag) and on a synthesized Vitest `--coverage` +flag; ContextualWisdomLab/.github#1258 (`9b5dba9`) is the exact-head repair +and has auto-merge armed pending independent OpenCode / Strix / Noema. + +Figma design-system boundary (ADR 0002): File ID `1Su3lDRmiZdcUs47t1QwIX`. +The sanitized file now contains synthetic Event Lineage desktop (`5:14`) and +mobile (`5:15`) frames with graph direction, event dates, an inference +boundary, and exact fused-score evidence. Do not copy source-organization +content into this repository. Storybook remains the executable scene and +edge-case inventory for repeated web objects; rendered code-to-Figma parity +still requires same-viewport browser comparison on an exact candidate head. + +## 2. User-visible capability baseline + +Substantially present on protected `main`: + +- PostgreSQL-backed import, normalized provenance, cutoff-aware analysis runs, + source revisions, lineage reconstruction, and explicit unavailable states. +- Authenticated workspace navigation, post detail, localized summaries, 5W1H, + R&R/Keyman, evidence citations, chat, organization hierarchy, and lineage DAG + (`frontend/src/LineageDag.tsx` is on `main`; the old “DAG view missing” + baseline entry is stale). +- Semantic paragraph/list/table/image-region units that preserve the source + representation and provenance instead of flattening it into one body string. +- Contextual-orchestrator boundaries for adjudication, extraction, summaries, + chat, embeddings, and VISION; null channels remain unavailable and are + dropped from score fusion. +- W3C PROV-O projection through normalized provenance tables, with the + knowledge graph retained as an explicit navigation projection. +- Keyverse/Keycloak OIDC, RankWeave fusion port, TEPP measurement client, + ThreadWeave tree assembly. + +These statements describe source capability, not authenticated production +corpus acceptance or protected release. + +## 3. Historical open-PR inventory (superseded by §1) + +Heads below are queue evidence captured at snapshot time; recheck SHA, +checks, unresolved threads, and independent approval immediately before any +merge claim. Do not self-approve, force-push, or transfer stale review +evidence across heads. The org merge scheduler merges only when +`reviewDecision == APPROVED` on the exact head and Strix evidence is complete. + +### 3.0 Shared systemic gate + +| Gate | Evidence | Durable repair | +| --- | --- | --- | +| Strix provider unavailability | `nvidia_nim/nemotron-3-super-120b-a12b` exits ~70 s, `openai-direct/gpt-5.6-luna` exits ~5 s on ~28 unrelated heads ("provider/backend was unavailable") | ContextualWisdomLab/.github#1263 — executable Azure/cross-provider fallbacks; its prior merge commit reverted ten base-merged paths, now restored over current `.github` main | +| ADR 0109 login repair debt | Eight branches cut from the pre-repair base carried the unauthenticated `AdminPanel` + unused-OIDC-helper `tsc -b` failure | Same verified two-line repair applied to #521, #522, #552, #553, #554, #556, #558, #560 during this loop; frontend lint/test/build verified locally | + +### 3.1 Workspace root and product surfaces + +| PR | Head | Intent | Notes | +| ---: | --- | --- | --- | +| #258 | `f0b5234d` | Workspace evidence board and source-grounded ontology surface (root stack) | Largest surface; historical CHANGES_REQUESTED is stale relative to current head | +| #349 | `bef4a858` | Bounded ontology and provenance explorer (v2.13.0) | Issue #341 | +| #355 | `2f3f308c` | Naruon event projection contract | Issues #336/#338 | +| #387 | `5ef0f2e6` | Persist and explain Event Lineage channel evidence | Issue #274 | +| #405 | `ec62d9f0` | Persisted image-region locations (v2.12.8) | VISION region provenance | +| #484 | `878c4a87` | Allen interval relations on Event Lineage edges (v2.15.0) | Temporal modeling; Allen (1983) | +| #490 | `d0cad030` | Wire remaining ADR 0133–0137 surfaces | Consolidated product stack incl. Knowledge Graph token repair | +| #493 | `499c8b1b` | Name Event Lineage isolation reasons (v2.16.0) | Honest unavailable/failed states | + +### 3.2 SKOS organization aliases and leftover-map family (stacked) + +| PR | Head | Intent | +| ---: | --- | --- | +| #480 | `f18b421d` | Bind corroborated SKOS org aliases to one catalog row | +| #482 | `c38c08d6` | Corroborated SKOS companion caption on organization chips (v2.14.0) | +| #481 | `32944979` | Persist leftover interaction-map coordinates (v2.12.7) | +| #485 | `dcaa6320` | Leftover pair clicks land on the named Post quality criterion (v2.12.8) | +| #518 | `3117823f` | Name leftover complete-case coverage (v2.12.17) | +| #519 | `31c150c8` | Persist leftover-map axis share on period reports (v2.12.16) | +| #521 | `40677c75` | Leftover pairs on the grouping comparison strip (v2.12.17) | +| #522 | `9be3712e` | Leftover-map distances on two Gabriel axes (v2.12.18) | +| #535 | `1fb5d69a` | Name leftover-map unexplained leftover (v2.12.26) | +| #537 | `9a639554` | Name leftover-map unexplained share (v2.12.27) | +| #539 | `740629d0` | Name leftover-map explained share (v2.12.28) | +| #563 | `740d50f3` | Name leftover-map cross share (v2.12.29) | +| #564 | `ac5de72a` | Name leftover-map reconstruction share (v2.12.30) | + +The leftover-map naming series (#518–#564) is a stacked ladder of honest +leftover-pair labeling increments; merge in ascending order once each exact +head clears gates. + +### 3.3 Repairs and operability + +| PR | Head | Intent | +| ---: | --- | --- | +| #393 | `4ddd3a83` | Detach provider parse error context (honest orchestrator failure) | +| #394 | `cf9505b7` | Preserve source indentation evidence for adjudication | +| #434 | `01d6cca5` | Wire adjudication client into corpus-wide rebuild (issue #289) | +| #541 | `3d93ea9b` | Bootstrap repo-root sys.path in operator scripts | +| #546 | `d210c20c` | Strip Keycloak OIDC callback params from post share links | +| #547 | `fb7fe2db` | Shorten orchestrator healthcheck retry budget | +| #552 | `89000280` | Footer text contrast passes WCAG 1.4.3 AA | +| #553 | `e5152f5c` | `.post-meta` contrast in both themes | +| #554 | `689e42e4` | Event Lineage DAG node marks get a 24×24 px hit target | +| #556 | `21cf9991` | Citation chip grows to a 24px touch target | +| #558 | `91dd1bfc` | Bare loading text exposed as live regions | +| #560 | `59b769e3` | Secondary details/summary toggles sized to `--size-control-min` | + +### 3.4 Integration and measurement boundary + +| PR | Head | Intent | +| ---: | --- | --- | +| #417 | `cb08377c` | TEPP topic-lineage consumption boundary (TRSL-TM + CHRONOS/TDT) ADR | +| #468 | `228f13dd` | Bind fast-mlsirm, Keyverse, orchestrator, and TEPP integration tests | +| #258-family measurement note | — | GRM/GPCM/CAT/FIPC parameter recovery (#451–#454) landed earlier; true-parameter RMSE remains the acceptance bar | + +### 3.5 Documentation + +| PR | Intent | +| ---: | --- | +| #565 | Sync AGENTS.md / CLAUDE.md with accepted ADR boundaries | +| this file | Non-identifying gap baseline refresh (ADR 0001) | + +Closed as superseded during this loop: #368 (baseline rewrite superseded by +this file per §3.5 of the prior snapshot). + +## 4. Open issues (product acceptance remaining on `main`) + +| Issue | User-visible gap | Active PR | +| ---: | --- | --- | +| #79 | Milestone 2: port verified direct-PostgreSQL analysis into the protected architecture | analysis-run registry on `main`; remaining runtime bridge | +| #87 | Milestone 2.1 normalized runtime-analysis schema bridge | related analysis-run work | +| #269 | Authenticated Global Ask MCP browser-safe and admission-bounded | Ask stack | +| #271 | Evidence-honest knowledge-cutoff scope on Global Ask | Ask stack | +| #272 | Verify Global Ask KG/ontology/semantic claims with public SearXNG evidence | Ask stack | +| #274 | Persist and explain Event Lineage channel evidence | #387 | +| #277 | TEPP: persist accepted receipts, poll completed results, keep measurement authority distinct | #468, #417 | +| #280 | Full project-lifecycle history and handover intervals | Tracked with issue #284; no active delivery PR confirmed | +| #284 | Authoritative lifecycle ingestion and idempotent reconciliation | No active delivery PR confirmed | +| #289 | Activate the optional lineage LLM channel through a bounded asynchronous rebuild | #434 | +| #336 | Replace pseudo-CalDAV feed with a Naruon-owned calendar projection | #355 | +| #338 | Evidence-bounded email/project lineage contract for Naruon consumption | #355 | +| #341 | Heterogeneous ontology and provenance explorer separate from Event Lineage | #349 | +| #358 | Batch reauthorize persisted post-Ask evidence without N+1 queries | Ask stack | +| #359 | Centralize Global Ask session storage access | Ask stack | +| #361 | Preserve server diagnostics behind generic orchestrator 503 responses | #383 | +| #362 | Roll back rejected Global Ask turn atomically instead of poisoning the session | Ask stack | +| #363 | Continue ontology neighborhoods beyond the bounded source window | Ask / ontology | +| #372 | Reconcile lowercase and repository-case public namespace IRIs | #426 Pages stack; #492 is merged into that branch, not protected `main` | + +## 5. Open product and technical gaps + +| Gap | Current evidence | Acceptance requirement | +| --- | --- | --- | +| Protected release | 24 open PRs at snapshot; the queue is gated mainly by per-head independent approvals and pending hosted checks; #355 landed during this window | Terminal exact-head checks, no unresolved threads, independent exact-head approvals, protected squash-merge SHA | +| Shared frontend gate | The ADR 0109 login repair is on protected `main`; eight older branches carried the defect and received the same verified repair this loop (#521–#560) | Keep every future branch cut from post-repair bases; re-verify with frontend lint/test/build before push | +| Identifying baseline regression | `main` gap file listed real post identifiers; separately, closed #506 and pre-existing public history contain a private runtime source-table identifier, while current `main` and #507 trees are clean | Land this non-identifying rewrite, then coordinate ADR 0001 history remediation with security/privacy owners; do not reproduce the value, force-push, or delete evidence ad hoc | +| Authorized-corpus runtime | Repository tests use synthetic fixtures; private records remain outside git | Authenticated runtime validation returning only aggregate, non-identifying evidence | +| Image understanding | Region, OCR, and description work exists across active heads (#405, #419), but current runtime acceptance has not yet proved table-image structure, complete region coverage, or summary/image readiness together | Orchestrator-backed rendered workflow, original/derived asset provenance, region-before-OCR processing, and honest unsupported states; reconcile ADR 0052's image-bearing summary readiness with ADR 0098 before changing sequencing | +| Semantic source rendering | Paragraph, table, list, formula, and indentation work exists across stacks (#394, #427, #448–#450); #515 adds synthetic backend/frontend parity for deterministic rows/cells, footnote boundaries, and encoded scripts | Land the #427 → #515 stack, then gather authenticated browser evidence that list nesting, continuation alignment, and formula units render without authoring-layout artifacts | +| Event and project semantics | Multi-project mentions, project-bound actions, 5W1H, requester/processor, and semantic relations exist in ADR 0036/0052/0100/0111/0129 and active stacks | Aggregate authenticated evidence must show distinct projects and events, explicit requester/processor and real R&R, normalized relative time, and product/entity relations without promoting attendance or co-occurrence | +| Knowledge Graph readability | The black evidence-node root cause is an undefined-token fallback; the design-token repair and long-label/evidence-table coverage are present on #490, not protected `main` | Deliver the token repair through protected `main`, then verify light/dark contrast, keyboard graph navigation, full labels, and evidence tables in the authenticated rendered surface | +| Source-code lookup UX | Source state/detail codes remain evidence-bearing machine values and current detail presentation is dense | Catalog-backed display labels with raw-code provenance, compact 5W1H/source-detail hierarchy, keyboard access, and no unsupported customer/project binding | +| Calendar / Naruon | #355 delivered the Naruon-owned projection contract and conformance fixture to protected `main`; live consumer acceptance is not yet evidenced | Verify Naruon consumption against the published schema and issues #336/#338 without invented events | +| SKOS organization aliases | Catalog binding and chip caption live on #480 / #482 | One catalog row per corroborated org; companion caption is hint-only until bound | +| Event Lineage evidence | Channel evidence and Allen relations live on #387 / #484 | Persist channel scores, explain them in the popup, never invent a fused score | +| Scientific measurement | Durable accepted TEPP receipts and fail-closed production weighting are protected (`main`); #468 binds fast-mlsirm/Keyverse/orchestrator/TEPP integration tests and now fails closed on upstream probability-axis drift. #387 removes inferred/default persistence weights and converts its 3/4-channel evidence tests to fast-mlsirm estimates, but several older reconstruction tests still pass hand-authored numeric weight dictionaries; those constants are not estimator evidence | Continue replacing remaining reconstruction-test constants with provenance-bearing fast-mlsirm estimates over synthetic fixtures; tests unrelated to fusion must bypass weighting entirely, as #484 does. Land #387/#468/#417 through the standard gate and retain true-parameter RMSE recovery as the acceptance bar | +| Asynchronous authorization | Protected `main` rebuilds Global Ask worker scope after the bearer token leaves the request; #468 now persists exact Keyverse organization/process-unit scope in 3NF child tables and intersects it with current affiliations | Land #468 through the protected gate; prove a second affiliation and a revoked process unit cannot widen delayed-job evidence | +| Planned-facility intent | Planned-facility relationship intent rides on open #490 (`d0cad030`), whose earlier stack-only merges were not protected delivery | Settle #490 exact-head checks plus independent approval, then land through protected `main` before a release claim | +| Accessibility and responsive UX | Unit coverage exists for major surfaces; Storybook inventory incomplete | Keyboard, screen-reader, mobile, and authenticated Playwright acceptance on the exact release head | +| Design tokens and repeated objects | Token extraction started; sanitized Figma Event Lineage desktop/mobile frames exist, while other repeated product surfaces remain incomplete | Tokens in CSS + Storybook stories for board, popup, DAG, Ask, calendar, forms, charts; same-viewport Figma/runtime visual comparison before release | +| External integrations | Search, Zotero, calendar, Keyverse, orchestrator, RankWeave, ThreadWeave, TEPP, disksage, wardnet | Provider conformance, failure/reconciliation behavior, and provenance-bearing integration evidence | +| MSA / modular reuse | LineageWeave must run standalone and as a consumer of org packages | Do not reimplement RankWeave/TEPP/orchestrator/ThreadWeave/Keyverse; fix upstream and PR there | +| Release quality | Local focused/full suites have passed on individual PR heads | Repository-wide coverage, docstrings, Storybook, security, browser, and release evidence on one exact head | +| PII | Masking would paralyze the product; ADR 0001 forbids identifying artifacts in git | ABAC + authorized runtime; synthetic fixtures in git; no mask-in-place that drops names the operator must read | +| Database | PostgreSQL, 3NF, snake_case ≥ two words, hot-partition and lock policy | No file DBs; read/write split if lock management fails; whitelist every migration | + +## 6. UI-UX acceptance inventory (must be defined, reviewed, applied, audited) + +Each item needs a Storybook scene, an edge-case story, and an automated check +before a commercial release claim. Figma File ID `1Su3lDRmiZdcUs47t1QwIX`. + +| Dimension | Current | Gap | +| --- | --- | --- | +| Accessibility | Partial labels/roles on board, popup, login | WCAG 2.2 AA on login, board, popup, Ask, calendar, admin; focus order; live regions | +| Touch & Interaction | Click-first popup and lists | 44px targets, swipe/escape to dismiss popup, no hover-only actions | +| Performance | Board caps and hint render limits exist | Interaction-to-next-paint on board search, DAG, Ask; no N+1 (#358) | +| Style Selection | Korean UI standards merged (#347) | Tokenized light/dark; Anti-Slop-UI density; no decorative noise | +| Layout & Responsive | Desktop popup shell | 402px-class phone layout; stacked GNB; readable DAG | +| Typography & Color | Badge tokens extracted | Contrast on badges, links, error/status; no raw hex in components | +| Animation | Minimal | Reduced-motion; no blocking animation on evidence open | +| Forms & Feedback | Login, Ask, tickets, admin brand | Inline validation, next-action copy, unavailable vs failed distinction | +| Navigation Patterns | Board / customers / calendar / Ask / admin | Deep-link post + OIDC return URL (#426); bookmarkable Ask | +| Charts & Data | Period reports, leftover pairs, Rankings, DAG | Honest empty/unavailable; no invented theta; Storybook chart states | + +## 7. Ecosystem leverage order + +Reuse before rebuild. Consume these ContextualWisdomLab packages in this order +of leverage; open connector PRs there when the defect is upstream: + +1. **contextual-orchestrator** — every LLM/VISION/embedding call (Fugu / Conductor / TRINITY routing). Never a raw provider SDK. +2. **Keyverse** — OIDC issuer, JWKS, tenant principals. +3. **RankWeave** — fused scores and rankings; never invent a fused score or theta. +4. **TEPP** — calibrated measurement; persist receipts; no local reimplementation. +5. **fast-mlsirm** — GRM/GPCM/CAT/FIPC recovery tests (#451–#454) must stay true-parameter RMSE. +6. **ThreadWeave** — tree assembly. +7. **Naruon** — calendar and email/project lineage projection (#336, #338, #355). +8. **disksage / wardnet** — storage and network policy as needed. +9. **ContextualWisdomLab/.github** — required review workflows (OpenCode, Strix, Noema) and the LineageWeave hourly caller (#1259). If stacked PRs miss central review or coverage-evidence fails on pnpm 9 (`--trust-lockfile` is pnpm 11.3) or a missing Vitest coverage provider, fix the org workflow (#1258), not a local bypass. + +## 8. Public ontology publication boundary + +- PR #426 publishes fragment-addressable HTML, byte-identical Turtle, + isomorphic JSON-LD and N-Triples, the PROV-O support profile, and a + source-digest manifest from the authoritative ontology. +- Pull requests validate only. Only protected `main` may publish, and the + generated-directory marker, linked-IRI, duplicate-fragment, symlink, and + source-overlap checks fail closed. +- The lowercase knowledge-graph namespace and repository-case support-profile + namespace remain distinct until issue #372 delivers a versioned migration + and compatibility decision; this publication PR rewrites neither identity. +- Until the protected deployment and exact URL checks succeed, the public + ontology endpoint remains unavailable and must not be represented as live. + +## 9. Evidence boundaries + +- Never add a real record, title, name, identifier, screenshot, log, benchmark + artifact, or documentation example to this repository. +- Attendance or co-occurrence is not responsibility, project, customer, or + affiliation evidence. Preserve uncertainty and provenance. +- Missing transport, model capability, accepted envelope, or persistence is + unavailable or failed evidence, never a placeholder result. +- Local green tests, bot statuses, auto-merge, and warning-only checks do not + prove a protected merge. +- Re-fetch base/head SHAs, checks, review threads, approvals, rulesets, and the + merge SHA immediately before any lifecycle claim. +- Do not self-approve. Independent OpenCode / Strix / Noema review is required. +- Do not force-push. Do not treat GitHub Checks duration as a blocker; repair + the failing check instead. +- `COPILOT_GITHUB_TOKEN` is not used. + +## 10. Next acceptance loop (autonomous merge order) + +Process every open PR in ascending number order, considering leverage; for +each: check reviews → repair → re-verify Checks → merge → continue. Checks and +review latency are never blockers — keep working while they settle. + +1. **Unblock Strix org-wide** by landing ContextualWisdomLab/.github#1263 + (fallbacks executable), then rerun failed strix jobs across the queue. +2. Merge ascending from #258 once each head shows terminal green required + checks plus current-head independent approval. The leftover-map ladder + (#518–#564) merges in ascending order. +3. Keep the shared ADR 0109 repair verified on #521–#560 heads (done this + loop; frontend lint/test/build passed locally before each push). +4. After PRs drain below a handful, resume buyer-visible gaps from §5 in + leverage order: Event Lineage evidence (#387/#274), Naruon calendar + (#355/#336), SKOS aliases (#480/#482), ontology explorer (#349/#341). +5. Rename remaining `[Buyer Gap]` issue titles to neutral product-object + naming per repository convention (no "Buyer" for internal objects). +6. Keep psychometric tests as true-parameter recovery (RMSE); never fixture + tautologies, invented theta, or hand-authored numeric weights. Remove + weights from tests that do not exercise fusion; fusion tests must consume + provenance-bearing fast-mlsirm estimates over synthetic fixtures. +7. Run frontend lint/test/build/Storybook, backend tests, and authenticated + browser/accessibility checks on the exact candidate release head. +8. Fix only evidence-backed failures and repeat the protected merge gate. +9. Refresh this file each loop with the exact queue state. + +## 11. Spec pointers (derive, do not fork) + +- Product/architecture: `ARCHITECTURE.md`, `AGENTS.md`, `CLAUDE.md` +- Research grounding: ADR 0084, `docs/lineage-bi-research-notes.md` +- Demo identity: ADR 0001 +- Figma boundary: ADR 0002 (File ID `1Su3lDRmiZdcUs47t1QwIX`) +- Orchestrator / paper-grounded models: ADR 0015, ADR 0076 (Fugu, TRINITY, Conductor) +- Ontology / PROV-O / SKOS: ADR 0004, ADR 0011, issue #372 +- Analysis runs / TEPP: ADR 0013–0023, issue #79 / #277 +- Calendar / Naruon: issues #336 / #338, PR #355 +- Ask Agent: issues #269–#272, #358–#363 + +Citations in doctoring and ADRs use APA 7th. Do not invent a heuristic where +the papers leave the decision undecided. From f60cff01a5db85e0db0847865986c23bb879f74d Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 16:23:31 +0900 Subject: [PATCH 26/32] docs: record protected-main release regression --- docs/product-technical-gap-baseline.md | 23 +++++++++++++++-------- 1 file changed, 15 insertions(+), 8 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index ca748d9a7..78b4d0685 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Audit snapshot: 2026-08-25 15:52 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 16:22 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -9,7 +9,7 @@ ## 1. Exact-head and governance evidence -The protected default branch was `ea71d9ca9adda1c4c8f82ed295d2202a8a2f5c1f` +The protected default branch was `464ff25002044b9d933c8eefd36c8def7ca0ffd8` when this baseline was refreshed. The live queue contained 10 open PRs and 20 open issues. The exact-head inventory below supersedes older per-PR snapshots elsewhere in this document; those older rows remain useful historical delivery @@ -17,14 +17,14 @@ context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | +| #603 | `2b4d74b8` | releases pooled connections and transactions during analysis-run provider work using PostgreSQL session advisory locks and two short transactions; also removes package-metadata conflict markers and identifying baseline records delivered by #482; 67 analysis-run tests and the aggregate documentation-hygiene contract passed, auto-merge is armed pending exact-head hosted checks and independent review | | #602 | `a1e4dc8f` | Post-detail modal semantics, focus containment/restoration, and Escape close are composed with current main; the valid rerender focus-steal review was repaired with a mount-only focus lifecycle and regression test, all threads are resolved, and auto-merge remains armed pending exact-head hosted checks and independent review | -| #600 | `ae6e8cbc` | this baseline's pre-amendment observed head; composed with current main and awaiting exact-head review/check evidence | -| #588 | `e9b29f11` | raw-residual reconstruction, rank-zero identity, API presence, and comparison-strip contracts are composed with current main; focused backend/frontend/schema checks passed, all review threads are resolved, and auto-merge is armed | -| #582 | `d7cf4072` | batched cited-lineage fetch is composed with current main while retaining ADR 0161 interval relations; 27 focused lineage/documentation checks passed, no review threads remain, and auto-merge is armed pending hosted checks and independent review | -| #579 | `dac509f9` | interaction-map coordinates are composed with current main's cross-share and interval work; the ADR 0168/0202 collision was repaired, all threads are resolved, 69 focused scientific/schema checks plus the focused live API contract passed, and 163 frontend tests, lint, app/Storybook builds, and desktop/mobile rendered audits passed; auto-merge is armed pending hosted checks and independent review | -| #493 | `415890a9` | ADR 0143 empty-DAG reasons are composed with current main and #387 channel evidence while retaining ADR 0161 interval labels; 36 focused backend checks, 175 focused frontend checks, lint, production/Storybook builds, and desktop/mobile rendered screenshots passed; no review threads remain and auto-merge is armed pending hosted exact-head gates and independent review | +| #600 | `51f8b4c0` | this baseline's pre-amendment stack head, composed on #603 so protected main's package-marker/privacy regression cannot return; awaiting exact-head review/check evidence | +| #588 | `c33e777e` | raw-residual reconstruction, rank-zero identity, API presence, and comparison-strip contracts are composed with current main; the concurrent exact-head update resets hosted evidence, while auto-merge remains armed | +| #582 | `63dd0d06` | batched cited-lineage fetch is composed with current main while retaining ADR 0161 interval relations; the concurrent exact-head update resets hosted evidence, while auto-merge remains armed | +| #579 | `96b8896a` | interaction-map coordinates preserve the scientific/schema/UI contracts, but the concurrent exact head is currently dirty against main and must be composed again before hosted gates can settle | +| #493 | `2ce959cb` | ADR 0143 empty-DAG reasons preserve channel and interval evidence, but the concurrent exact head is currently dirty against main and must be composed again before hosted gates can settle | | #490 | `73413d0b` | broad historical workspace branch is conflicting with failing checks; decompose/restack rather than replaying its 931-commit merge wholesale | -| #482 | `35f5b0fb` | ADR 0170 organization-alias captions are composed with current main; 44 backend/docs and 93 frontend tests, lint, app/Storybook builds, plus desktop/mobile rendered screenshot audits passed; auto-merge is armed pending hosted exact-head gates and independent review | | #468 | `0f15d1bd` | fast-mlsirm v0.8.0, exact Keyverse scope, orchestrator, and TEPP boundaries are composed with current main; TEPP contract/auth headers and telemetry-safe startup were retained, 74 focused integration tests plus 37 TEPP/start/config tests and the live authorization-scope contract passed, no review threads remain, and auto-merge is armed pending hosted exact-head gates and independent review | | #387 | `728125c1` | channel evidence plus Ask reconstruction-profile preservation is composed with current main and has no unresolved threads; only changes-requested decisions from obsolete heads remain, so auto-merge is armed pending current-head checks and independent re-review | @@ -33,6 +33,13 @@ re-fetch the head, unresolved threads, formal reviews, rulesets, and same-head check conclusions. In particular, queued checks are infrastructure state and do not transfer evidence from an earlier SHA. +PR #482 merged as protected-main commit `464ff25002044b9d933c8eefd36c8def7ca0ffd8`, +but that tree contains unresolved conflict markers in `uv.lock` and +`frontend/package.json` and replaced this aggregate baseline with identifying +runtime post keys. Those are delivered regressions, not merely branch gaps; +#603 contains the root repair and privacy regression test evidence. Until #603 +lands, protected main is not releaseable. + PR #592 first merged as `3b3af3b4fe9c439354433a43444e05f37ab24ea3` into #590's non-default stack base at `2f033ba3`. The complete stack then passed the protected gate and #590 merged to `main` as From 236569f9e12dc52b86d3db5ddf97009cacaeb4de Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 17:01:53 +0900 Subject: [PATCH 27/32] docs: record modal focus review repair --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 70825f168..01f43e9cf 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -17,7 +17,7 @@ context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | -| #605 | `caaa9d3d` | exact-main follow-up for post-navigation refocus, visibility-aware modal focus order, readable evidence separators, and validated OIDC return context; 10 component tests, 3 focused app tests, lint/build/Storybook, and 1440×900 plus 390×844 screenshot audits passed; auto-merge awaits hosted gates and independent review | +| #605 | `1098f6ba` | exact-main follow-up for post-navigation refocus, visibility-aware modal focus order including native disclosure summaries, readable evidence separators, and validated OIDC return context; 12 shared/component tests, focused app tests, lint/build/Storybook, and 1440×900 plus 390×844 screenshot audits passed; auto-merge awaits hosted gates and independent review | | #604 | `063d7257` | independently restores the protected-main OIDC return-context/build regression; auto-merge awaits hosted gates and independent review, and overlap with #605 must be composed without dropping either focus/evidence repair | | #600 | `f60cff01` | this baseline's pre-amendment head; the current refresh composes protected main and supersedes the queue snapshot, so exact-head checks and review restart | | #579 | `acd44dfe` | interaction-map coordinates now compose protected main, return no false axes or criteria-only map, preserve the validated OIDC return path, and retain successful backend/frontend/build plus desktop/mobile Storybook evidence; auto-merge awaits hosted gates and independent review | From f1b4ff625e74907bbbb08195c58c8f5431f7bd99 Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 17:16:47 +0900 Subject: [PATCH 28/32] fix(frontend): wire ADR 0109 return-url helpers into the login button The login button computed returnUrl manually (window.location.pathname + window.location.search), which drops the URL hash fragment and never calls rememberOidcReturnUrl. Two defects followed: tsc -b fails on the now-unused returnUrlFromLocation / rememberOidcReturnUrl imports (build-breaking), and the sessionStorage/ localStorage fallback that restoreOidcReturnUrl (main.tsx) depends on when the OIDC state round-trip is dropped was never populated. Both are exercised by the existing App.test.tsx assertion and were already failing before this change. Call returnUrlFromLocation() (includes the hash, strips callback params) and rememberOidcReturnUrl() before signinRedirect, restoring the ADR 0109 pattern this repository's own docs already describe as present. Pre-existing on protected main, independent of this PR's own changes; found while verifying this merge and confirmed by a clean build of origin/main alone. Co-Authored-By: Claude Sonnet 5 --- frontend/src/App.tsx | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/frontend/src/App.tsx b/frontend/src/App.tsx index 640262baf..767b157f2 100644 --- a/frontend/src/App.tsx +++ b/frontend/src/App.tsx @@ -4968,7 +4968,8 @@ export default function App({ showLabPanels = false }: { showLabPanels?: boolean