From e8ad53f72dc70bf1cd014e5d08cfe3e11eaddaa7 Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 21:42:07 +0900 Subject: [PATCH 01/21] docs(gaps): decompose closed ADR stack on current main --- docs/product-technical-gap-baseline.md | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 9a65c2eb6..ac7a405c5 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -389,6 +389,25 @@ this file per §3.5 of the prior snapshot). | PII | Masking would paralyze the product; ADR 0001 forbids identifying artifacts in git | ABAC + authorized runtime; synthetic fixtures in git; no mask-in-place that drops names the operator must read | | Database | PostgreSQL, 3NF, snake_case ≥ two words, hot-partition and lock policy | No file DBs; read/write split if lock management fails; whitelist every migration | +### 5.1 Closed PR #490 decomposition (issue #611) + +Protected `main` at `7403a452` has no open PR. PR #490 remains closed, +unmerged branch evidence; its ADR 0133–0137 files are not normative and its +321-file tree must not be replayed. Current-main code and schema searches give +this delivery matrix: + +| Closed-branch decision | Current-main classification | Smallest remaining delivery | +| --- | --- | --- | +| ADR 0133 source-reference research | Missing: no post-scoped research-lead, retrieval, judgment, or citation persistence/read workflow exists | One SSRF-safe SearXNG retrieval slice through contextual-orchestrator, with normalized citations and explicit unavailable outcomes | +| ADR 0134 token-backed exception messages | Partial: sanitized next-action failures exist, but no shared token-backed exception component or complete Storybook error inventory exists | Migrate one existing unavailable flow to one shared accessible alert and verify its success, unavailable, and retry states | +| ADR 0135 kind/status-exact analysis actions | Partial: normative analysis-run, TEPP, cutoff-body, and channel-evidence contracts exist; the closed branch's unified guidance function does not | Audit the current run-kind/status matrix and add only a demonstrably missing combination with one interaction test | +| ADR 0136 per-post Ask history | Missing: persisted post chat exists, but no account-and-post-scoped session/turn contract or conversation picker exists | Define the 3NF account/post session boundary, bounded batch reauthorization, and one authorized list/load/write path before UI work | +| ADR 0137 cross-post customer identity | Missing: no normalized customer-identity judgment, binding, or name-history workflow exists | Add only after external corroboration, orchestrator judgment, TEPP ordering, and unique-catalog fail-close can be verified together; never promote a one-post hint | + +Each missing row requires its own current-main PR and focused regression +evidence. This matrix satisfies the decomposition requirement without +transferring stale checks, reviews, or implementation from #490. + ## 6. UI-UX acceptance inventory (must be defined, reviewed, applied, audited) Each item needs a Storybook scene, an edge-case story, and an automated check From 2bfd1a25c96b1bef137c04935833c71007befd19 Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 21:43:13 +0900 Subject: [PATCH 02/21] docs(gaps): separate Naruon email from calendar evidence --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index ac7a405c5..2c7201932 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -351,7 +351,7 @@ this file per §3.5 of the prior snapshot). | #284 | Authoritative lifecycle ingestion and idempotent reconciliation | No active delivery PR confirmed | | #289 | Activate the optional lineage LLM channel through a bounded asynchronous rebuild | #434 | | #336 | Replace pseudo-CalDAV feed with a Naruon-owned calendar projection | Contract on `main` (#355); operator consume wiring in historical branch `feat/naruon-calendar-buyer-wiring-v2170` | -| #338 | Evidence-bounded email/project lineage contract for Naruon consumption | #355 | +| #338 | Evidence-bounded email/project lineage contract for Naruon consumption | Missing on protected `main`; #343 merged only into a non-default stack, while #355 is a distinct calendar-consumer contract and is not delivery evidence for email/project lineage | | #341 | Heterogeneous ontology and provenance explorer separate from Event Lineage | Protected `main` via #349; issue closed | | #358 | Batch reauthorize persisted post-Ask evidence without N+1 queries | Ask stack | | #359 | Centralize Global Ask session storage access | Ask stack | From 09b6f330eb236edf04f58dc5b5ace9e7ac2d99ee Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 21:45:45 +0900 Subject: [PATCH 03/21] docs(gaps): correct Global Ask cutoff delivery state --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 2c7201932..d1298ef47 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -343,7 +343,7 @@ this file per §3.5 of the prior snapshot). | #79 | Milestone 2: port verified direct-PostgreSQL analysis into the protected architecture | analysis-run registry on `main`; remaining runtime bridge | | #87 | Milestone 2.1 normalized runtime-analysis schema bridge | related analysis-run work | | #269 | Authenticated Global Ask MCP browser-safe and admission-bounded | Ask stack | -| #271 | Evidence-honest knowledge-cutoff scope on Global Ask | Ask stack | +| #271 | Evidence-honest knowledge-cutoff scope on Global Ask | Missing on protected `main`: `GlobalAskRequest` accepts only `question`; #301 merged into a non-default stack and is not release evidence | | #272 | Verify Global Ask KG/ontology/semantic claims with public SearXNG evidence | Ask stack | | #274 | Persist and explain Event Lineage channel evidence | #387 | | #277 | TEPP: persist accepted receipts, poll completed results, keep measurement authority distinct | #468, #417 | From a048adf03b45e9be4304809072edce808e885582 Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 21:48:58 +0900 Subject: [PATCH 04/21] docs(gaps): correct closed ADR decomposition evidence --- docs/product-technical-gap-baseline.md | 49 ++++++++++++++------------ 1 file changed, 26 insertions(+), 23 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index d1298ef47..d403f72e9 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,7 +1,7 @@ # Product & Technical Gap Baseline -> Dashboard delivery snapshot: 2026-08-25 21:34 KST. Protected `main` was -> `d7d5eeb310b055b5e138060cf2dfb929b03090a6`. This local branch is not +> Dashboard delivery snapshot: 2026-08-25 21:47 KST. Protected `main` was +> `7403a4528c4a68a4e2636449b9497d0619c47c82`. This local branch is not > protected-main release evidence. ## Operations Dashboard PRD/TRD traceability @@ -60,18 +60,18 @@ only aggregate, non-identifying evidence to this repository. ### Exact open-PR boundary -At this snapshot there were 3 open PRs and 11 open issues. Exact observed heads -were `#628 d07d212f` (this branch's observed parent), `#627 9e0528a6`, and -`#579 1c209c85`. PR #579 is open; its ADR 0211 reservation is why this branch's -filter-option decision is ADR 0212. PRs #612, #614, #615, #616, and #626 -reached protected `main`; the superseded baseline PR #613 closed without merge -and its PRD was recreated on protected main. The open heads remain blocked on -hosted gates and/or independent review. These +At this snapshot there were 3 open PRs and 10 open issues. Exact observed heads +were `#631 09b6f330` (this branch's observed parent), `#629 3d69ea4f`, and +`#579 f079ff1c`. PR #579 is open; its ADR 0211 reservation is why protected +main's filter-option decision is ADR 0212. PRs #627 and #628 reached protected +`main`; #629 remains an open asynchronous-pool follow-up and is not release +evidence. The open heads remain blocked on hosted gates and/or independent +review. These observations are not merge readiness. Re-fetch exact heads, unresolved threads, checks, approvals, rulesets, and merge SHA before any lifecycle claim. -> Audit snapshot: 2026-08-25 21:34 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 21:47 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -80,17 +80,17 @@ lifecycle claim. ## 1. Exact-head and governance evidence -The protected default branch was `d7d5eeb310b055b5e138060cf2dfb929b03090a6` -when this baseline was refreshed. The live queue contained 3 open PRs and 11 +The protected default branch was `7403a4528c4a68a4e2636449b9497d0619c47c82` +when this baseline was refreshed. The live queue contained 3 open PRs and 10 open issues. The exact-head inventory below supersedes older per-PR snapshots elsewhere in this document; those older rows remain useful historical delivery context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | -| #628 | `d07d212f` (observed parent) | this row is updated by #628 itself, so its exact head advances after the snapshot is encoded; ADR 0212 combines complete ABAC-visible filter options into one database round trip, while hosted gates and independent review remain required | -| #627 | `9e0528a6` | repairs k6 lifecycle evidence preservation; hosted gates remain required | -| #579 | `1c209c85` | persists leftover interaction-map coordinates and owns ADR 0211; hosted gates and independent review remain required | +| #631 | `09b6f330` (observed parent) | decomposes closed PR #490 without replaying it; this row advances when the snapshot correction is committed, and hosted gates plus independent review remain required | +| #629 | `3d69ea4f` | releases the Global Ask pool before embedding-provider work; hosted gates and independent review remain required | +| #579 | `f079ff1c` | persists leftover interaction-map coordinates through the fast-mlsirm owner contract and owns ADR 0211; hosted gates and independent review remain required | No row above is merge evidence. Immediately before any lifecycle action, re-fetch the head, unresolved threads, formal reviews, rulesets, and same-head @@ -357,6 +357,7 @@ this file per §3.5 of the prior snapshot). | #359 | Centralize Global Ask session storage access | Ask stack | | #363 | Continue ontology neighborhoods beyond the bounded source window | Protected `main` via #349; issue closed | | #372 | Reconcile lowercase and repository-case public namespace IRIs | Protected `main` via #616; issue closed, with term-kind hardening on #618 | +| #611 | Decompose closed PR #490 ADR 0133–0137 evidence without transferring stale branch state | #631 supplies the current-main inventory only; focused implementation PRs and tests for every unmet criterion are still required | ## 5. Open product and technical gaps @@ -398,15 +399,17 @@ this delivery matrix: | Closed-branch decision | Current-main classification | Smallest remaining delivery | | --- | --- | --- | -| ADR 0133 source-reference research | Missing: no post-scoped research-lead, retrieval, judgment, or citation persistence/read workflow exists | One SSRF-safe SearXNG retrieval slice through contextual-orchestrator, with normalized citations and explicit unavailable outcomes | +| ADR 0133 source-reference research | Partial foundation: protected `main` has the self-hosted SearXNG relation-verification client and fail-closed configuration, but it verifies an already extracted relation. It has no source-unit/image-region lead, cited-resource retrieval, claim judgment, or normalized research citation workflow | One post-scoped lead-to-citation slice that reuses the self-hosted SearXNG search boundary, adds public-target SSRF/redirect rejection for result retrieval, and judges through contextual-orchestrator with explicit unavailable outcomes | | ADR 0134 token-backed exception messages | Partial: sanitized next-action failures exist, but no shared token-backed exception component or complete Storybook error inventory exists | Migrate one existing unavailable flow to one shared accessible alert and verify its success, unavailable, and retry states | -| ADR 0135 kind/status-exact analysis actions | Partial: normative analysis-run, TEPP, cutoff-body, and channel-evidence contracts exist; the closed branch's unified guidance function does not | Audit the current run-kind/status matrix and add only a demonstrably missing combination with one interaction test | -| ADR 0136 per-post Ask history | Missing: persisted post chat exists, but no account-and-post-scoped session/turn contract or conversation picker exists | Define the 3NF account/post session boundary, bounded batch reauthorization, and one authorized list/load/write path before UI work | -| ADR 0137 cross-post customer identity | Missing: no normalized customer-identity judgment, binding, or name-history workflow exists | Add only after external corroboration, orchestrator judgment, TEPP ordering, and unique-catalog fail-close can be verified together; never promote a one-post hint | - -Each missing row requires its own current-main PR and focused regression -evidence. This matrix satisfies the decomposition requirement without -transferring stale checks, reviews, or implementation from #490. +| ADR 0135 kind/status-exact analysis actions | Partial: protected `main` has kind-aware start/retry controls plus normative analysis-run, TEPP, cutoff-body, and channel-evidence contracts; it does not contain the closed branch's unified guidance component or its full kind × status interaction inventory | Test the current run-kind/status matrix first, then add only a proven missing state/control pair rather than copying the closed-branch function | +| ADR 0136 per-post Ask history | Partial: `post_chat_result` / `post_chat_citation`, the authorized post Chat API, and its linear exchange history are on protected `main`. Account-and-post-scoped sessions, ordered turns, list/select/new controls, and batched citation reauthorization are not | Define the 3NF account/post session boundary, bounded batch reauthorization, and one authorized list/load/write path before adding the conversation picker | +| ADR 0137 cross-post customer identity | Partial foundation: protected `main` preserves source customer hints and has corporate-catalog unique/miss/tie safeguards, but it has no normalized cross-post customer-identity judgment, supporting-post binding, or corporate-name-history workflow | Add only after external corroboration, orchestrator judgment, TEPP ordering, and unique-catalog fail-close can be verified together; never promote a one-post hint | + +This matrix satisfies only #611's current-main inventory step. Issue #611 +remains open: every unmet criterion above still needs a focused regression test +and exact-head current-main implementation PR before its acceptance criteria +are satisfied. No stale check, review, or implementation is transferred from +#490. ## 6. UI-UX acceptance inventory (must be defined, reviewed, applied, audited) From 67edfc091848b0120787b6fe414b95dabbf6a73f Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 21:51:39 +0900 Subject: [PATCH 05/21] docs(gaps): refresh exact open heads --- docs/product-technical-gap-baseline.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index d403f72e9..119e627ea 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,6 +1,6 @@ # Product & Technical Gap Baseline -> Dashboard delivery snapshot: 2026-08-25 21:47 KST. Protected `main` was +> Dashboard delivery snapshot: 2026-08-25 21:51 KST. Protected `main` was > `7403a4528c4a68a4e2636449b9497d0619c47c82`. This local branch is not > protected-main release evidence. @@ -61,7 +61,7 @@ only aggregate, non-identifying evidence to this repository. ### Exact open-PR boundary At this snapshot there were 3 open PRs and 10 open issues. Exact observed heads -were `#631 09b6f330` (this branch's observed parent), `#629 3d69ea4f`, and +were `#631 a048adf0` (this branch's observed parent), `#629 8797605b`, and `#579 f079ff1c`. PR #579 is open; its ADR 0211 reservation is why protected main's filter-option decision is ADR 0212. PRs #627 and #628 reached protected `main`; #629 remains an open asynchronous-pool follow-up and is not release @@ -71,7 +71,7 @@ observations are not merge readiness. Re-fetch exact heads, unresolved threads, checks, approvals, rulesets, and merge SHA before any lifecycle claim. -> Audit snapshot: 2026-08-25 21:47 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 21:51 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -88,8 +88,8 @@ context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | -| #631 | `09b6f330` (observed parent) | decomposes closed PR #490 without replaying it; this row advances when the snapshot correction is committed, and hosted gates plus independent review remain required | -| #629 | `3d69ea4f` | releases the Global Ask pool before embedding-provider work; hosted gates and independent review remain required | +| #631 | `a048adf0` (observed parent) | decomposes closed PR #490 without replaying it; this row advances when the snapshot correction is committed, and hosted gates plus independent review remain required | +| #629 | `8797605b` | releases the Global Ask pool before embedding-provider work; hosted gates and independent review remain required | | #579 | `f079ff1c` | persists leftover interaction-map coordinates through the fast-mlsirm owner contract and owns ADR 0211; hosted gates and independent review remain required | No row above is merge evidence. Immediately before any lifecycle action, From e0afb20ea70ce67d9708e6480c92967bc1ddd350 Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 21:54:06 +0900 Subject: [PATCH 06/21] docs(gaps): reconcile active protected-release queue --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 119e627ea..28a0b593b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -353,7 +353,7 @@ this file per §3.5 of the prior snapshot). | #336 | Replace pseudo-CalDAV feed with a Naruon-owned calendar projection | Contract on `main` (#355); operator consume wiring in historical branch `feat/naruon-calendar-buyer-wiring-v2170` | | #338 | Evidence-bounded email/project lineage contract for Naruon consumption | Missing on protected `main`; #343 merged only into a non-default stack, while #355 is a distinct calendar-consumer contract and is not delivery evidence for email/project lineage | | #341 | Heterogeneous ontology and provenance explorer separate from Event Lineage | Protected `main` via #349; issue closed | -| #358 | Batch reauthorize persisted post-Ask evidence without N+1 queries | Ask stack | +| #358 | Batch reauthorize persisted post-Ask evidence without N+1 queries | Closed as obsolete: protected `main` has no persisted project-history Ask exchange path to reauthorize; any future ADR 0136 session delivery must include bounded batch reauthorization | | #359 | Centralize Global Ask session storage access | Ask stack | | #363 | Continue ontology neighborhoods beyond the bounded source window | Protected `main` via #349; issue closed | | #372 | Reconcile lowercase and repository-case public namespace IRIs | Protected `main` via #616; issue closed, with term-kind hardening on #618 | @@ -363,7 +363,7 @@ this file per §3.5 of the prior snapshot). | Gap | Current evidence | Acceptance requirement | | --- | --- | --- | -| Protected release | 3 open PRs at snapshot: #627 and #628 are current-main performance follow-ups, while reopened #579 retains hosted and independent-review gates | Terminal exact-head checks, no unresolved threads, independent exact-head approvals, protected squash-merge SHA | +| Protected release | 3 open PRs at snapshot: #631 is this current-main decomposition, #629 is the asynchronous pool follow-up, and reopened #579 consumes the fast-mlsirm interaction-map contract; all retain hosted and independent-review gates | Terminal exact-head checks, no unresolved threads, independent exact-head approvals, protected squash-merge SHA | | Evidence-grounded operations workspace | Protected-main #614 delivers governed semantic Ask, live Similar VOC, disjoint pending/failed analysis metrics, full Storybook state inventory, and current desktop/mobile screenshot evidence. Authorized-corpus backfill acceptance remains unavailable | Perform authenticated authorized-corpus acceptance with aggregate evidence and retain fail-closed no-match behavior | | Shared frontend gate | The ADR 0109 login repair is on protected `main`; eight older branches carried the defect and received the same verified repair this loop (#521–#560) | Keep every future branch cut from post-repair bases; re-verify with frontend lint/test/build before push | | Identifying baseline regression | `main` gap file listed real post identifiers; separately, closed #506 and pre-existing public history contain a private runtime source-table identifier, while current `main` and #507 trees are clean | Land this non-identifying rewrite, then coordinate ADR 0001 history remediation with security/privacy owners; do not reproduce the value, force-push, or delete evidence ad hoc | From 80cbfb52a3f5e4af93c9b604d872883cc1ef786b Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 21:56:06 +0900 Subject: [PATCH 07/21] docs(gaps): record protected performance deliveries --- docs/product-technical-gap-baseline.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 28a0b593b..81321127d 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -170,6 +170,8 @@ Recent protected-default-branch delivery evidence (squash merges onto | PR | Merged (UTC) | Delivered | | ---: | --- | --- | +| #628 | 2026-08-25 12:39 | one-round-trip authorized post filter options without narrowing the complete ABAC-visible set | +| #627 | 2026-08-25 12:35 | preserved valid k6 lifecycle evidence across setup, scenario execution, and teardown | | #468 | 2026-08-25 08:44 | fast-mlsirm, Keyverse, contextual-orchestrator, and TEPP integration boundaries | | #493 | 2026-08-25 08:44 | evidence-grounded Event Lineage isolation reasons | | #600 | 2026-08-25 08:44 | then-current exact-head product/technical baseline | From ffc1f5a959c14ce0ed36b831290e7a9b8315a5b8 Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 21:57:35 +0900 Subject: [PATCH 08/21] docs(gaps): keep issue inventory live-only --- docs/product-technical-gap-baseline.md | 7 ------- 1 file changed, 7 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 81321127d..4fb7c904a 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -351,14 +351,7 @@ this file per §3.5 of the prior snapshot). | #277 | TEPP: persist accepted receipts, poll completed results, keep measurement authority distinct | #468, #417 | | #280 | Full project-lifecycle history and handover intervals | Tracked with issue #284; no active delivery PR confirmed | | #284 | Authoritative lifecycle ingestion and idempotent reconciliation | No active delivery PR confirmed | -| #289 | Activate the optional lineage LLM channel through a bounded asynchronous rebuild | #434 | -| #336 | Replace pseudo-CalDAV feed with a Naruon-owned calendar projection | Contract on `main` (#355); operator consume wiring in historical branch `feat/naruon-calendar-buyer-wiring-v2170` | | #338 | Evidence-bounded email/project lineage contract for Naruon consumption | Missing on protected `main`; #343 merged only into a non-default stack, while #355 is a distinct calendar-consumer contract and is not delivery evidence for email/project lineage | -| #341 | Heterogeneous ontology and provenance explorer separate from Event Lineage | Protected `main` via #349; issue closed | -| #358 | Batch reauthorize persisted post-Ask evidence without N+1 queries | Closed as obsolete: protected `main` has no persisted project-history Ask exchange path to reauthorize; any future ADR 0136 session delivery must include bounded batch reauthorization | -| #359 | Centralize Global Ask session storage access | Ask stack | -| #363 | Continue ontology neighborhoods beyond the bounded source window | Protected `main` via #349; issue closed | -| #372 | Reconcile lowercase and repository-case public namespace IRIs | Protected `main` via #616; issue closed, with term-kind hardening on #618 | | #611 | Decompose closed PR #490 ADR 0133–0137 evidence without transferring stale branch state | #631 supplies the current-main inventory only; focused implementation PRs and tests for every unmet criterion are still required | ## 5. Open product and technical gaps From 99ec6007f6c8e5f88559d315ad00847932002cfc Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 21:58:03 +0900 Subject: [PATCH 09/21] docs(gaps): scope live issue ledger exactly --- docs/product-technical-gap-baseline.md | 22 +++++++++++----------- 1 file changed, 11 insertions(+), 11 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 4fb7c904a..345f77c92 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,7 +1,7 @@ # Product & Technical Gap Baseline -> Dashboard delivery snapshot: 2026-08-25 21:51 KST. Protected `main` was -> `7403a4528c4a68a4e2636449b9497d0619c47c82`. This local branch is not +> Dashboard delivery snapshot: 2026-08-25 21:57 KST. Protected `main` was +> `04e6b610655d0db91d5f7ba9486bdda1440e0b19`. This local branch is not > protected-main release evidence. ## Operations Dashboard PRD/TRD traceability @@ -61,7 +61,7 @@ only aggregate, non-identifying evidence to this repository. ### Exact open-PR boundary At this snapshot there were 3 open PRs and 10 open issues. Exact observed heads -were `#631 a048adf0` (this branch's observed parent), `#629 8797605b`, and +were `#631 ffc1f5a9` (this branch's observed parent), `#629 fee4d76a`, and `#579 f079ff1c`. PR #579 is open; its ADR 0211 reservation is why protected main's filter-option decision is ADR 0212. PRs #627 and #628 reached protected `main`; #629 remains an open asynchronous-pool follow-up and is not release @@ -71,7 +71,7 @@ observations are not merge readiness. Re-fetch exact heads, unresolved threads, checks, approvals, rulesets, and merge SHA before any lifecycle claim. -> Audit snapshot: 2026-08-25 21:51 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 21:57 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -80,7 +80,7 @@ lifecycle claim. ## 1. Exact-head and governance evidence -The protected default branch was `7403a4528c4a68a4e2636449b9497d0619c47c82` +The protected default branch was `04e6b610655d0db91d5f7ba9486bdda1440e0b19` when this baseline was refreshed. The live queue contained 3 open PRs and 10 open issues. The exact-head inventory below supersedes older per-PR snapshots elsewhere in this document; those older rows remain useful historical delivery @@ -88,8 +88,8 @@ context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | -| #631 | `a048adf0` (observed parent) | decomposes closed PR #490 without replaying it; this row advances when the snapshot correction is committed, and hosted gates plus independent review remain required | -| #629 | `8797605b` | releases the Global Ask pool before embedding-provider work; hosted gates and independent review remain required | +| #631 | `ffc1f5a9` (observed parent) | decomposes closed PR #490 without replaying it; this row advances when the snapshot correction is committed, and hosted gates plus independent review remain required | +| #629 | `fee4d76a` | releases the Global Ask pool before embedding-provider work; hosted gates and independent review remain required | | #579 | `f079ff1c` | persists leftover interaction-map coordinates through the fast-mlsirm owner contract and owns ADR 0211; hosted gates and independent review remain required | No row above is merge evidence. Immediately before any lifecycle action, @@ -387,10 +387,10 @@ this file per §3.5 of the prior snapshot). ### 5.1 Closed PR #490 decomposition (issue #611) -Protected `main` at `7403a452` has no open PR. PR #490 remains closed, -unmerged branch evidence; its ADR 0133–0137 files are not normative and its -321-file tree must not be replayed. Current-main code and schema searches give -this delivery matrix: +Protected `main` at `04e6b610` and the three-PR live queue were rechecked for +this decomposition. PR #490 remains closed, unmerged branch evidence; its ADR +0133–0137 files are not normative and its 321-file tree must not be replayed. +Current-main code and schema searches give this delivery matrix: | Closed-branch decision | Current-main classification | Smallest remaining delivery | | --- | --- | --- | From ece39baeeb58f518e4d15a75e31d129164e08420 Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 21:59:00 +0900 Subject: [PATCH 10/21] docs(gaps): separate main content from live queue --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 4fb7c904a..109dc9139 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -387,7 +387,7 @@ this file per §3.5 of the prior snapshot). ### 5.1 Closed PR #490 decomposition (issue #611) -Protected `main` at `7403a452` has no open PR. PR #490 remains closed, +Protected `main` at `7403a452` contains none of PR #490. That PR remains closed, unmerged branch evidence; its ADR 0133–0137 files are not normative and its 321-file tree must not be replayed. Current-main code and schema searches give this delivery matrix: From 42206e1142d1f0918d6df663ce3fed0db142407c Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 22:18:39 +0900 Subject: [PATCH 11/21] docs(gaps): refresh four-PR delivery boundary --- docs/product-technical-gap-baseline.md | 19 ++++++++++--------- 1 file changed, 10 insertions(+), 9 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 30f1a7425..763cbdeab 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -60,9 +60,9 @@ only aggregate, non-identifying evidence to this repository. ### Exact open-PR boundary -At this snapshot there were 3 open PRs and 10 open issues. Exact observed heads -were `#631 ffc1f5a9` (this branch's observed parent), `#629 fee4d76a`, and -`#579 f079ff1c`. PR #579 is open; its ADR 0211 reservation is why protected +At this snapshot there were 4 open PRs and 10 open issues. Exact observed heads +were `#632 476d761d`, `#631 7a641cb1` (this branch's observed parent), +`#629 49675283`, and `#579 762ad6de`. PR #579 is open; its ADR 0211 reservation is why protected main's filter-option decision is ADR 0212. PRs #627 and #628 reached protected `main`; #629 remains an open asynchronous-pool follow-up and is not release evidence. The open heads remain blocked on hosted gates and/or independent @@ -71,7 +71,7 @@ observations are not merge readiness. Re-fetch exact heads, unresolved threads, checks, approvals, rulesets, and merge SHA before any lifecycle claim. -> Audit snapshot: 2026-08-25 21:57 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 22:17 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -81,16 +81,17 @@ lifecycle claim. ## 1. Exact-head and governance evidence The protected default branch was `04e6b610655d0db91d5f7ba9486bdda1440e0b19` -when this baseline was refreshed. The live queue contained 3 open PRs and 10 +when this baseline was refreshed. The live queue contained 4 open PRs and 10 open issues. The exact-head inventory below supersedes older per-PR snapshots elsewhere in this document; those older rows remain useful historical delivery context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | -| #631 | `ffc1f5a9` (observed parent) | decomposes closed PR #490 without replaying it; this row advances when the snapshot correction is committed, and hosted gates plus independent review remain required | -| #629 | `fee4d76a` | releases the Global Ask pool before embedding-provider work; hosted gates and independent review remain required | -| #579 | `f079ff1c` | persists leftover interaction-map coordinates through the fast-mlsirm owner contract and owns ADR 0211; hosted gates and independent review remain required | +| #632 | `476d761d` | preserves the source-post provenance of ontology-annotated prompt facts; hosted gates and independent review remain required | +| #631 | `7a641cb1` (observed parent) | decomposes closed PR #490 without replaying it; this row advances when the snapshot correction is committed, and hosted gates plus independent review remain required | +| #629 | `49675283` | releases the Global Ask pool before embedding-provider work and records repaired replay/load evidence; hosted gates and independent review remain required | +| #579 | `762ad6de` | persists leftover interaction-map coordinates through the fast-mlsirm owner contract and owns ADR 0211; hosted gates and independent review remain required | No row above is merge evidence. Immediately before any lifecycle action, re-fetch the head, unresolved threads, formal reviews, rulesets, and same-head @@ -358,7 +359,7 @@ this file per §3.5 of the prior snapshot). | Gap | Current evidence | Acceptance requirement | | --- | --- | --- | -| Protected release | 3 open PRs at snapshot: #631 is this current-main decomposition, #629 is the asynchronous pool follow-up, and reopened #579 consumes the fast-mlsirm interaction-map contract; all retain hosted and independent-review gates | Terminal exact-head checks, no unresolved threads, independent exact-head approvals, protected squash-merge SHA | +| Protected release | 4 open PRs at snapshot: #632 preserves graph-fact provenance, #631 is this current-main decomposition, #629 is the asynchronous pool follow-up, and reopened #579 consumes the fast-mlsirm interaction-map contract; all retain hosted and independent-review gates | Terminal exact-head checks, no unresolved threads, independent exact-head approvals, protected squash-merge SHA | | Evidence-grounded operations workspace | Protected-main #614 delivers governed semantic Ask, live Similar VOC, disjoint pending/failed analysis metrics, full Storybook state inventory, and current desktop/mobile screenshot evidence. Authorized-corpus backfill acceptance remains unavailable | Perform authenticated authorized-corpus acceptance with aggregate evidence and retain fail-closed no-match behavior | | Shared frontend gate | The ADR 0109 login repair is on protected `main`; eight older branches carried the defect and received the same verified repair this loop (#521–#560) | Keep every future branch cut from post-repair bases; re-verify with frontend lint/test/build before push | | Identifying baseline regression | `main` gap file listed real post identifiers; separately, closed #506 and pre-existing public history contain a private runtime source-table identifier, while current `main` and #507 trees are clean | Land this non-identifying rewrite, then coordinate ADR 0001 history remediation with security/privacy owners; do not reproduce the value, force-push, or delete evidence ad hoc | From 1034c4db5f61bd00450aadcdea2911c44c1d90ba Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 22:21:49 +0900 Subject: [PATCH 12/21] docs(gaps): keep live issue queue exact --- docs/product-technical-gap-baseline.md | 1 - 1 file changed, 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 763cbdeab..3f7ab1167 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -348,7 +348,6 @@ this file per §3.5 of the prior snapshot). | #269 | Authenticated Global Ask MCP browser-safe and admission-bounded | Ask stack | | #271 | Evidence-honest knowledge-cutoff scope on Global Ask | Missing on protected `main`: `GlobalAskRequest` accepts only `question`; #301 merged into a non-default stack and is not release evidence | | #272 | Verify Global Ask KG/ontology/semantic claims with public SearXNG evidence | Ask stack | -| #274 | Persist and explain Event Lineage channel evidence | #387 | | #277 | TEPP: persist accepted receipts, poll completed results, keep measurement authority distinct | #468, #417 | | #280 | Full project-lifecycle history and handover intervals | Tracked with issue #284; no active delivery PR confirmed | | #284 | Authoritative lifecycle ingestion and idempotent reconciliation | No active delivery PR confirmed | From 62deb34a6ebe884a0057602f3a5428ff2fcb947c Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 22:23:55 +0900 Subject: [PATCH 13/21] docs(gaps): distinguish decomposition snapshot --- docs/product-technical-gap-baseline.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 3f7ab1167..fcb1bd31b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -387,8 +387,9 @@ this file per §3.5 of the prior snapshot). ### 5.1 Closed PR #490 decomposition (issue #611) -Protected `main` at `04e6b610` and the three-PR live queue were rechecked for -this decomposition; protected `main` contains none of PR #490. That PR remains +Protected `main` at `04e6b610` and the three open PRs present during the initial +decomposition were rechecked; the later audit snapshot above includes #631 +itself as the fourth open PR. Protected `main` contains none of PR #490. That PR remains closed, unmerged branch evidence; its ADR 0133–0137 files are not normative and its 321-file tree must not be replayed. Current-main code and schema searches give this delivery matrix: From e248b0a84ffe4b6d1b1a61e6eb0dacb31b1c7305 Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 22:25:39 +0900 Subject: [PATCH 14/21] docs(gaps): refresh reviewed PR heads --- docs/product-technical-gap-baseline.md | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index fcb1bd31b..c73288c5e 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -61,8 +61,8 @@ only aggregate, non-identifying evidence to this repository. ### Exact open-PR boundary At this snapshot there were 4 open PRs and 10 open issues. Exact observed heads -were `#632 476d761d`, `#631 7a641cb1` (this branch's observed parent), -`#629 49675283`, and `#579 762ad6de`. PR #579 is open; its ADR 0211 reservation is why protected +were `#632 c5193532`, `#631 62deb34a` (this branch's observed parent), +`#629 49675283`, and `#579 45769b0d`. PR #579 is open; its ADR 0211 reservation is why protected main's filter-option decision is ADR 0212. PRs #627 and #628 reached protected `main`; #629 remains an open asynchronous-pool follow-up and is not release evidence. The open heads remain blocked on hosted gates and/or independent @@ -71,7 +71,7 @@ observations are not merge readiness. Re-fetch exact heads, unresolved threads, checks, approvals, rulesets, and merge SHA before any lifecycle claim. -> Audit snapshot: 2026-08-25 22:17 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 22:25 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -88,10 +88,10 @@ context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | -| #632 | `476d761d` | preserves the source-post provenance of ontology-annotated prompt facts; hosted gates and independent review remain required | -| #631 | `7a641cb1` (observed parent) | decomposes closed PR #490 without replaying it; this row advances when the snapshot correction is committed, and hosted gates plus independent review remain required | +| #632 | `c5193532` | preserves the source-post provenance of ontology-annotated prompt facts; hosted gates and independent review remain required | +| #631 | `62deb34a` (observed parent) | decomposes closed PR #490 without replaying it; this row advances when the snapshot correction is committed, and hosted gates plus independent review remain required | | #629 | `49675283` | releases the Global Ask pool before embedding-provider work and records repaired replay/load evidence; hosted gates and independent review remain required | -| #579 | `762ad6de` | persists leftover interaction-map coordinates through the fast-mlsirm owner contract and owns ADR 0211; hosted gates and independent review remain required | +| #579 | `45769b0d` | persists leftover interaction-map coordinates through the fast-mlsirm owner contract and fails coverage closed with rejected maps; hosted gates and independent review remain required | No row above is merge evidence. Immediately before any lifecycle action, re-fetch the head, unresolved threads, formal reviews, rulesets, and same-head From 2c8157ac24b70437febd74785e581193e1136d44 Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 22:30:33 +0900 Subject: [PATCH 15/21] docs(gaps): remove shipped lineage gap from loop --- docs/product-technical-gap-baseline.md | 25 ++++++++++++++----------- 1 file changed, 14 insertions(+), 11 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index c73288c5e..5f876ea58 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -478,23 +478,26 @@ Process every open PR in ascending number order, considering leverage; for each: check reviews → repair → re-verify Checks → merge → continue. Checks and review latency are never blockers — keep working while they settle. -1. Revalidate Strix after protected ContextualWisdomLab/.github#1320, reconcile - .github#1263, and land the atomic hourly LineageWeave caller in .github#1288. -2. Merge #387 and #618–#621 only after each exact head shows terminal - green required checks plus current-head independent approval. +1. Revalidate Strix after merged ContextualWisdomLab/.github#1320, reconcile + open .github#1263, and land the atomic hourly LineageWeave caller in open + .github#1288 only through their protected gates. +2. Process open LineageWeave PRs #579, #629, #631, and #632 only after each + exact head shows terminal green required checks plus current-head + independent approval. 3. After the queue drains, resume user-visible gaps from §5 in leverage order: - Event Lineage evidence (#387/#274), Naruon calendar (#355/#336), and - authenticated operations/ontology publication acceptance. -5. Rename remaining `[Buyer Gap]` issue titles to neutral product-object + external semantic verification (#272), Naruon calendar (#355/#336), and + authenticated operations/ontology publication acceptance. Event Lineage + evidence shipped in merged PR #387 and closed issue #274 is not an open gap. +4. Rename remaining `[Buyer Gap]` issue titles to neutral product-object naming per repository convention (no "Buyer" for internal objects). -6. Keep psychometric tests as true-parameter recovery (RMSE); never fixture +5. Keep psychometric tests as true-parameter recovery (RMSE); never fixture tautologies, invented theta, or hand-authored numeric weights. Remove weights from tests that do not exercise fusion; fusion tests must consume provenance-bearing fast-mlsirm estimates over synthetic fixtures. -7. Run frontend lint/test/build/Storybook, backend tests, and authenticated +6. Run frontend lint/test/build/Storybook, backend tests, and authenticated browser/accessibility checks on the exact candidate release head. -8. Fix only evidence-backed failures and repeat the protected merge gate. -9. Refresh this file each loop with the exact queue state. +7. Fix only evidence-backed failures and repeat the protected merge gate. +8. Refresh this file each loop with the exact queue state. ## 11. Spec pointers (derive, do not fork) From 24dbce046cde8cabe4951e0b74c0076e4ac112ad Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 25 Aug 2026 06:34:42 -0700 Subject: [PATCH 16/21] fix(ci): cancel tests when pull requests close (#634) * fix(ci): cancel tests when pull requests close * docs(gaps): track stale CI runner work --------- Co-authored-by: seonghobae --- .github/workflows/tests.yml | 3 +++ docs/product-technical-gap-baseline.md | 20 ++++++++++++-------- tests/test_tests_workflow_contract.py | 15 +++++++++++++++ 3 files changed, 30 insertions(+), 8 deletions(-) create mode 100644 tests/test_tests_workflow_contract.py diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index 1cad1f17c..5f96edc07 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -4,6 +4,7 @@ on: push: branches: [main] pull_request: + types: [opened, synchronize, reopened, closed] permissions: contents: read @@ -15,6 +16,7 @@ concurrency: jobs: pytest: name: Full test suite + if: github.event_name != 'pull_request' || github.event.action != 'closed' runs-on: ubuntu-latest services: postgres: @@ -60,6 +62,7 @@ jobs: frontend: name: Frontend lint, test, build + if: github.event_name != 'pull_request' || github.event.action != 'closed' runs-on: ubuntu-latest steps: - name: Checkout repository diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 5f876ea58..b4812f984 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -60,9 +60,10 @@ only aggregate, non-identifying evidence to this repository. ### Exact open-PR boundary -At this snapshot there were 4 open PRs and 10 open issues. Exact observed heads -were `#632 c5193532`, `#631 62deb34a` (this branch's observed parent), -`#629 49675283`, and `#579 45769b0d`. PR #579 is open; its ADR 0211 reservation is why protected +At this snapshot there were 6 open PRs and 10 open issues. Exact observed heads +were `#634 14083a14` (this branch's observed parent), `#633 741b01c3`, +`#632 7381c9ec`, `#631 e248b0a8`, `#629 49675283`, and `#579 45769b0d`. +PR #579 is open; its ADR 0211 reservation is why protected main's filter-option decision is ADR 0212. PRs #627 and #628 reached protected `main`; #629 remains an open asynchronous-pool follow-up and is not release evidence. The open heads remain blocked on hosted gates and/or independent @@ -71,7 +72,7 @@ observations are not merge readiness. Re-fetch exact heads, unresolved threads, checks, approvals, rulesets, and merge SHA before any lifecycle claim. -> Audit snapshot: 2026-08-25 22:25 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 22:30 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -81,15 +82,17 @@ lifecycle claim. ## 1. Exact-head and governance evidence The protected default branch was `04e6b610655d0db91d5f7ba9486bdda1440e0b19` -when this baseline was refreshed. The live queue contained 4 open PRs and 10 +when this baseline was refreshed. The live queue contained 6 open PRs and 10 open issues. The exact-head inventory below supersedes older per-PR snapshots elsewhere in this document; those older rows remain useful historical delivery context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | -| #632 | `c5193532` | preserves the source-post provenance of ontology-annotated prompt facts; hosted gates and independent review remain required | -| #631 | `62deb34a` (observed parent) | decomposes closed PR #490 without replaying it; this row advances when the snapshot correction is committed, and hosted gates plus independent review remain required | +| #634 | `14083a14` (observed parent) | makes the existing Tests concurrency group cancel obsolete work when a PR closes; it is stacked on #631 and requires parent-first delivery plus exact-head gates | +| #633 | `741b01c3` | keeps authenticated web reads responsive under measured concurrent load; hosted gates and independent review remain required | +| #632 | `7381c9ec` | preserves the source-post provenance of ontology-annotated prompt facts; hosted gates and independent review remain required | +| #631 | `e248b0a8` | decomposes closed PR #490 without replaying it; hosted gates and independent review remain required | | #629 | `49675283` | releases the Global Ask pool before embedding-provider work and records repaired replay/load evidence; hosted gates and independent review remain required | | #579 | `45769b0d` | persists leftover interaction-map coordinates through the fast-mlsirm owner contract and fails coverage closed with rejected maps; hosted gates and independent review remain required | @@ -358,7 +361,8 @@ this file per §3.5 of the prior snapshot). | Gap | Current evidence | Acceptance requirement | | --- | --- | --- | -| Protected release | 4 open PRs at snapshot: #632 preserves graph-fact provenance, #631 is this current-main decomposition, #629 is the asynchronous pool follow-up, and reopened #579 consumes the fast-mlsirm interaction-map contract; all retain hosted and independent-review gates | Terminal exact-head checks, no unresolved threads, independent exact-head approvals, protected squash-merge SHA | +| Protected release | 6 open PRs at snapshot: #634 repairs stale-run cancellation, #633 follows measured web-read contention, #632 preserves graph-fact provenance, #631 is the current-main decomposition, #629 is the asynchronous pool follow-up, and reopened #579 consumes the fast-mlsirm interaction-map contract; all retain hosted and independent-review gates | Parent-first delivery for #634; terminal exact-head checks, no unresolved threads, two independent approvals including last-push approval, protected squash-merge SHA | +| CI queue release latency | Two Tests runs for already merged PRs occupied the available runner slots while 54 newer runs remained queued. Manual cancellation released the stale work, but the central close workflow was itself queued behind those runs. #634 reuses the repository's existing per-PR concurrency group and emits a jobless close event so GitHub can cancel obsolete Tests work before runner allocation | Merge #631 then retarget and merge #634; close a synthetic PR while its Tests run is active and verify the old run becomes cancelled, the close-event jobs remain skipped, and a newer exact-head run starts without manual intervention | | Evidence-grounded operations workspace | Protected-main #614 delivers governed semantic Ask, live Similar VOC, disjoint pending/failed analysis metrics, full Storybook state inventory, and current desktop/mobile screenshot evidence. Authorized-corpus backfill acceptance remains unavailable | Perform authenticated authorized-corpus acceptance with aggregate evidence and retain fail-closed no-match behavior | | Shared frontend gate | The ADR 0109 login repair is on protected `main`; eight older branches carried the defect and received the same verified repair this loop (#521–#560) | Keep every future branch cut from post-repair bases; re-verify with frontend lint/test/build before push | | Identifying baseline regression | `main` gap file listed real post identifiers; separately, closed #506 and pre-existing public history contain a private runtime source-table identifier, while current `main` and #507 trees are clean | Land this non-identifying rewrite, then coordinate ADR 0001 history remediation with security/privacy owners; do not reproduce the value, force-push, or delete evidence ad hoc | diff --git a/tests/test_tests_workflow_contract.py b/tests/test_tests_workflow_contract.py new file mode 100644 index 000000000..2fd145b0e --- /dev/null +++ b/tests/test_tests_workflow_contract.py @@ -0,0 +1,15 @@ +"""Regression contracts for the repository test workflow.""" + +from pathlib import Path + + +def test_pr_close_cancels_obsolete_test_runs_without_starting_jobs() -> None: + """A close event must cancel the same-PR run while scheduling no test work.""" + workflow = ( + Path(__file__).resolve().parents[1] / ".github/workflows/tests.yml" + ).read_text(encoding="utf-8") + + assert "types: [opened, synchronize, reopened, closed]" in workflow + assert "group: tests-${{ github.ref }}" in workflow + assert "cancel-in-progress: true" in workflow + assert workflow.count("github.event.action != 'closed'") == 2 From 0386b0e332766d48f594726271a564c69b5e520a Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 22:37:22 +0900 Subject: [PATCH 17/21] docs(gaps): record stacked CI delivery --- docs/product-technical-gap-baseline.md | 21 ++++++++++----------- 1 file changed, 10 insertions(+), 11 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b4812f984..29dce821e 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -60,9 +60,9 @@ only aggregate, non-identifying evidence to this repository. ### Exact open-PR boundary -At this snapshot there were 6 open PRs and 10 open issues. Exact observed heads -were `#634 14083a14` (this branch's observed parent), `#633 741b01c3`, -`#632 7381c9ec`, `#631 e248b0a8`, `#629 49675283`, and `#579 45769b0d`. +At this snapshot there were 5 open PRs and 10 open issues. Exact observed heads +were `#633 66d0f524`, `#632 a60c5b4f`, `#631 24dbce04` (this branch's +observed parent), `#629 49675283`, and `#579 45769b0d`. PR #579 is open; its ADR 0211 reservation is why protected main's filter-option decision is ADR 0212. PRs #627 and #628 reached protected `main`; #629 remains an open asynchronous-pool follow-up and is not release @@ -72,7 +72,7 @@ observations are not merge readiness. Re-fetch exact heads, unresolved threads, checks, approvals, rulesets, and merge SHA before any lifecycle claim. -> Audit snapshot: 2026-08-25 22:30 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 22:36 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -82,17 +82,16 @@ lifecycle claim. ## 1. Exact-head and governance evidence The protected default branch was `04e6b610655d0db91d5f7ba9486bdda1440e0b19` -when this baseline was refreshed. The live queue contained 6 open PRs and 10 +when this baseline was refreshed. The live queue contained 5 open PRs and 10 open issues. The exact-head inventory below supersedes older per-PR snapshots elsewhere in this document; those older rows remain useful historical delivery context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | -| #634 | `14083a14` (observed parent) | makes the existing Tests concurrency group cancel obsolete work when a PR closes; it is stacked on #631 and requires parent-first delivery plus exact-head gates | -| #633 | `741b01c3` | keeps authenticated web reads responsive under measured concurrent load; hosted gates and independent review remain required | -| #632 | `7381c9ec` | preserves the source-post provenance of ontology-annotated prompt facts; hosted gates and independent review remain required | -| #631 | `e248b0a8` | decomposes closed PR #490 without replaying it; hosted gates and independent review remain required | +| #633 | `66d0f524` | is stacked on #629 and keeps authenticated web reads responsive under measured concurrent load; merge the parent first, then retarget and reverify | +| #632 | `a60c5b4f` | preserves the source-post provenance of ontology-annotated prompt facts; hosted gates and independent review remain required | +| #631 | `24dbce04` (observed parent) | decomposes closed PR #490 and now contains #634's non-default-branch CI cancellation merge; hosted gates and independent review remain required | | #629 | `49675283` | releases the Global Ask pool before embedding-provider work and records repaired replay/load evidence; hosted gates and independent review remain required | | #579 | `45769b0d` | persists leftover interaction-map coordinates through the fast-mlsirm owner contract and fails coverage closed with rejected maps; hosted gates and independent review remain required | @@ -361,8 +360,8 @@ this file per §3.5 of the prior snapshot). | Gap | Current evidence | Acceptance requirement | | --- | --- | --- | -| Protected release | 6 open PRs at snapshot: #634 repairs stale-run cancellation, #633 follows measured web-read contention, #632 preserves graph-fact provenance, #631 is the current-main decomposition, #629 is the asynchronous pool follow-up, and reopened #579 consumes the fast-mlsirm interaction-map contract; all retain hosted and independent-review gates | Parent-first delivery for #634; terminal exact-head checks, no unresolved threads, two independent approvals including last-push approval, protected squash-merge SHA | -| CI queue release latency | Two Tests runs for already merged PRs occupied the available runner slots while 54 newer runs remained queued. Manual cancellation released the stale work, but the central close workflow was itself queued behind those runs. #634 reuses the repository's existing per-PR concurrency group and emits a jobless close event so GitHub can cancel obsolete Tests work before runner allocation | Merge #631 then retarget and merge #634; close a synthetic PR while its Tests run is active and verify the old run becomes cancelled, the close-event jobs remain skipped, and a newer exact-head run starts without manual intervention | +| Protected release | 5 open PRs at snapshot: #633 is stacked on #629 for measured web-read contention, #632 preserves graph-fact provenance, #631 combines current-main decomposition with #634's CI fix, #629 is the asynchronous pool follow-up, and reopened #579 consumes the fast-mlsirm interaction-map contract; all retain hosted and independent-review gates | Merge #629 before retargeting #633; terminal exact-head checks, no unresolved threads, two independent approvals including last-push approval, protected squash-merge SHA | +| CI queue release latency | Two Tests runs for already merged PRs occupied the available runner slots while 54 newer runs remained queued. Manual cancellation released the stale work, but the central close workflow was itself queued behind those runs. #634 merged into #631's non-default branch and reuses the repository's existing per-PR concurrency group so a jobless close event can cancel obsolete Tests work before runner allocation; this is not protected-main delivery | Merge #631 through its refreshed protected gate; close a synthetic PR while its Tests run is active and verify the old run becomes cancelled, the close-event jobs remain skipped, and a newer exact-head run starts without manual intervention | | Evidence-grounded operations workspace | Protected-main #614 delivers governed semantic Ask, live Similar VOC, disjoint pending/failed analysis metrics, full Storybook state inventory, and current desktop/mobile screenshot evidence. Authorized-corpus backfill acceptance remains unavailable | Perform authenticated authorized-corpus acceptance with aggregate evidence and retain fail-closed no-match behavior | | Shared frontend gate | The ADR 0109 login repair is on protected `main`; eight older branches carried the defect and received the same verified repair this loop (#521–#560) | Keep every future branch cut from post-repair bases; re-verify with frontend lint/test/build before push | | Identifying baseline regression | `main` gap file listed real post identifiers; separately, closed #506 and pre-existing public history contain a private runtime source-table identifier, while current `main` and #507 trees are clean | Land this non-identifying rewrite, then coordinate ADR 0001 history remediation with security/privacy owners; do not reproduce the value, force-push, or delete evidence ad hoc | From edbf6f9325a831eb805f1214b5e654b8fbf5da6e Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 22:42:34 +0900 Subject: [PATCH 18/21] docs(gaps): record composed performance stack --- docs/product-technical-gap-baseline.md | 17 ++++++++--------- 1 file changed, 8 insertions(+), 9 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 29dce821e..0ca84f110 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -60,9 +60,9 @@ only aggregate, non-identifying evidence to this repository. ### Exact open-PR boundary -At this snapshot there were 5 open PRs and 10 open issues. Exact observed heads -were `#633 66d0f524`, `#632 a60c5b4f`, `#631 24dbce04` (this branch's -observed parent), `#629 49675283`, and `#579 45769b0d`. +At this snapshot there were 4 open PRs and 10 open issues. Exact observed heads +were `#632 a60c5b4f`, `#631 0386b0e3` (this branch's observed parent), +`#629 143a6a3f`, and `#579 45769b0d`. PR #579 is open; its ADR 0211 reservation is why protected main's filter-option decision is ADR 0212. PRs #627 and #628 reached protected `main`; #629 remains an open asynchronous-pool follow-up and is not release @@ -72,7 +72,7 @@ observations are not merge readiness. Re-fetch exact heads, unresolved threads, checks, approvals, rulesets, and merge SHA before any lifecycle claim. -> Audit snapshot: 2026-08-25 22:36 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 22:41 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -82,17 +82,16 @@ lifecycle claim. ## 1. Exact-head and governance evidence The protected default branch was `04e6b610655d0db91d5f7ba9486bdda1440e0b19` -when this baseline was refreshed. The live queue contained 5 open PRs and 10 +when this baseline was refreshed. The live queue contained 4 open PRs and 10 open issues. The exact-head inventory below supersedes older per-PR snapshots elsewhere in this document; those older rows remain useful historical delivery context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | -| #633 | `66d0f524` | is stacked on #629 and keeps authenticated web reads responsive under measured concurrent load; merge the parent first, then retarget and reverify | | #632 | `a60c5b4f` | preserves the source-post provenance of ontology-annotated prompt facts; hosted gates and independent review remain required | -| #631 | `24dbce04` (observed parent) | decomposes closed PR #490 and now contains #634's non-default-branch CI cancellation merge; hosted gates and independent review remain required | -| #629 | `49675283` | releases the Global Ask pool before embedding-provider work and records repaired replay/load evidence; hosted gates and independent review remain required | +| #631 | `0386b0e3` (observed parent) | decomposes closed PR #490 and contains #634's non-default-branch CI cancellation merge; hosted gates and independent review remain required | +| #629 | `143a6a3f` | now contains #633's measured web-read responsiveness work and its incremental relation-verification repair in addition to the pool-release slice; hosted gates and independent review remain required | | #579 | `45769b0d` | persists leftover interaction-map coordinates through the fast-mlsirm owner contract and fails coverage closed with rejected maps; hosted gates and independent review remain required | No row above is merge evidence. Immediately before any lifecycle action, @@ -360,7 +359,7 @@ this file per §3.5 of the prior snapshot). | Gap | Current evidence | Acceptance requirement | | --- | --- | --- | -| Protected release | 5 open PRs at snapshot: #633 is stacked on #629 for measured web-read contention, #632 preserves graph-fact provenance, #631 combines current-main decomposition with #634's CI fix, #629 is the asynchronous pool follow-up, and reopened #579 consumes the fast-mlsirm interaction-map contract; all retain hosted and independent-review gates | Merge #629 before retargeting #633; terminal exact-head checks, no unresolved threads, two independent approvals including last-push approval, protected squash-merge SHA | +| Protected release | 4 open PRs at snapshot: #632 preserves graph-fact provenance, #631 combines current-main decomposition with #634's CI fix, #629 now combines the asynchronous pool and measured web-read slices from #633, and reopened #579 consumes the fast-mlsirm interaction-map contract; all retain hosted and independent-review gates | Terminal exact-head checks, no unresolved threads, two independent approvals including last-push approval, protected squash-merge SHA | | CI queue release latency | Two Tests runs for already merged PRs occupied the available runner slots while 54 newer runs remained queued. Manual cancellation released the stale work, but the central close workflow was itself queued behind those runs. #634 merged into #631's non-default branch and reuses the repository's existing per-PR concurrency group so a jobless close event can cancel obsolete Tests work before runner allocation; this is not protected-main delivery | Merge #631 through its refreshed protected gate; close a synthetic PR while its Tests run is active and verify the old run becomes cancelled, the close-event jobs remain skipped, and a newer exact-head run starts without manual intervention | | Evidence-grounded operations workspace | Protected-main #614 delivers governed semantic Ask, live Similar VOC, disjoint pending/failed analysis metrics, full Storybook state inventory, and current desktop/mobile screenshot evidence. Authorized-corpus backfill acceptance remains unavailable | Perform authenticated authorized-corpus acceptance with aggregate evidence and retain fail-closed no-match behavior | | Shared frontend gate | The ADR 0109 login repair is on protected `main`; eight older branches carried the defect and received the same verified repair this loop (#521–#560) | Keep every future branch cut from post-repair bases; re-verify with frontend lint/test/build before push | From 1c7a25f93d6fae62bb6de9f844952450cf37c90b Mon Sep 17 00:00:00 2001 From: seonghobae Date: Tue, 25 Aug 2026 22:44:08 +0900 Subject: [PATCH 19/21] docs(gaps): refresh exact protected queue evidence --- docs/product-technical-gap-baseline.md | 21 ++++++++++----------- 1 file changed, 10 insertions(+), 11 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 29dce821e..48fa70c3e 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -60,9 +60,9 @@ only aggregate, non-identifying evidence to this repository. ### Exact open-PR boundary -At this snapshot there were 5 open PRs and 10 open issues. Exact observed heads -were `#633 66d0f524`, `#632 a60c5b4f`, `#631 24dbce04` (this branch's -observed parent), `#629 49675283`, and `#579 45769b0d`. +At this snapshot there were 4 open PRs and 10 open issues. Exact observed heads +were `#632 fb6aa44d`, `#631 0386b0e3` (this branch's observed parent), +`#629 143a6a3f`, and `#579 45769b0d`. PR #579 is open; its ADR 0211 reservation is why protected main's filter-option decision is ADR 0212. PRs #627 and #628 reached protected `main`; #629 remains an open asynchronous-pool follow-up and is not release @@ -72,7 +72,7 @@ observations are not merge readiness. Re-fetch exact heads, unresolved threads, checks, approvals, rulesets, and merge SHA before any lifecycle claim. -> Audit snapshot: 2026-08-25 22:36 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-25 22:43 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -82,17 +82,16 @@ lifecycle claim. ## 1. Exact-head and governance evidence The protected default branch was `04e6b610655d0db91d5f7ba9486bdda1440e0b19` -when this baseline was refreshed. The live queue contained 5 open PRs and 10 +when this baseline was refreshed. The live queue contained 4 open PRs and 10 open issues. The exact-head inventory below supersedes older per-PR snapshots elsewhere in this document; those older rows remain useful historical delivery context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | -| #633 | `66d0f524` | is stacked on #629 and keeps authenticated web reads responsive under measured concurrent load; merge the parent first, then retarget and reverify | -| #632 | `a60c5b4f` | preserves the source-post provenance of ontology-annotated prompt facts; hosted gates and independent review remain required | -| #631 | `24dbce04` (observed parent) | decomposes closed PR #490 and now contains #634's non-default-branch CI cancellation merge; hosted gates and independent review remain required | -| #629 | `49675283` | releases the Global Ask pool before embedding-provider work and records repaired replay/load evidence; hosted gates and independent review remain required | +| #632 | `fb6aa44d` | preserves graph-fact evidence provenance and drops unauthorized post endpoints before label hydration; hosted gates and independent review remain required | +| #631 | `0386b0e3` (observed parent) | decomposes closed PR #490 and now contains #634's non-default-branch CI cancellation merge; hosted gates and independent review remain required | +| #629 | `143a6a3f` | combines the asynchronous embedding-pool and measured web-read work after #633's non-default-branch merge, then preserves each completed relation verification before a later provider failure; hosted gates and independent review remain required | | #579 | `45769b0d` | persists leftover interaction-map coordinates through the fast-mlsirm owner contract and fails coverage closed with rejected maps; hosted gates and independent review remain required | No row above is merge evidence. Immediately before any lifecycle action, @@ -360,13 +359,13 @@ this file per §3.5 of the prior snapshot). | Gap | Current evidence | Acceptance requirement | | --- | --- | --- | -| Protected release | 5 open PRs at snapshot: #633 is stacked on #629 for measured web-read contention, #632 preserves graph-fact provenance, #631 combines current-main decomposition with #634's CI fix, #629 is the asynchronous pool follow-up, and reopened #579 consumes the fast-mlsirm interaction-map contract; all retain hosted and independent-review gates | Merge #629 before retargeting #633; terminal exact-head checks, no unresolved threads, two independent approvals including last-push approval, protected squash-merge SHA | +| Protected release | 4 open PRs at snapshot: #632 preserves graph-fact provenance and endpoint authorization, #631 combines current-main decomposition with #634's CI fix, #629 combines the asynchronous pool and measured concurrency stacks, and reopened #579 consumes the fast-mlsirm interaction-map contract; all retain hosted and independent-review gates | Terminal exact-head checks, no unresolved threads, two independent approvals including last-push approval, protected squash-merge SHA | | CI queue release latency | Two Tests runs for already merged PRs occupied the available runner slots while 54 newer runs remained queued. Manual cancellation released the stale work, but the central close workflow was itself queued behind those runs. #634 merged into #631's non-default branch and reuses the repository's existing per-PR concurrency group so a jobless close event can cancel obsolete Tests work before runner allocation; this is not protected-main delivery | Merge #631 through its refreshed protected gate; close a synthetic PR while its Tests run is active and verify the old run becomes cancelled, the close-event jobs remain skipped, and a newer exact-head run starts without manual intervention | | Evidence-grounded operations workspace | Protected-main #614 delivers governed semantic Ask, live Similar VOC, disjoint pending/failed analysis metrics, full Storybook state inventory, and current desktop/mobile screenshot evidence. Authorized-corpus backfill acceptance remains unavailable | Perform authenticated authorized-corpus acceptance with aggregate evidence and retain fail-closed no-match behavior | | Shared frontend gate | The ADR 0109 login repair is on protected `main`; eight older branches carried the defect and received the same verified repair this loop (#521–#560) | Keep every future branch cut from post-repair bases; re-verify with frontend lint/test/build before push | | Identifying baseline regression | `main` gap file listed real post identifiers; separately, closed #506 and pre-existing public history contain a private runtime source-table identifier, while current `main` and #507 trees are clean | Land this non-identifying rewrite, then coordinate ADR 0001 history remediation with security/privacy owners; do not reproduce the value, force-push, or delete evidence ad hoc | | Authorized-corpus runtime | Repository tests use synthetic fixtures; private records remain outside git | Authenticated runtime validation returning only aggregate, non-identifying evidence | -| Concurrent web responsiveness | ADR 0204 releases pooled transactions during provider work, and the synthetic Compose boundary has an authenticated k6 E2E harness for Ask enqueue, concurrent reads, and job polling. An older-image local observation found repeated post-filter queries while `/api/posts` exceeded 30 seconds; ADR 0212 combines two authorized filter-option queries into one round trip without narrowing ABAC-visible options. The observation is not exact-head evidence or a product guarantee, and no physical scan reduction is claimed without an exact-head plan | Rebuild an exact-head application image, run `make load-http` with declared environment concurrency/window, and retain raw distributions and resource configuration. Compare the post-list database plan and latency with ADR 0212 while preserving the complete authorized filter set; set no SLO until representative capacity evidence is approved | +| Concurrent web responsiveness | ADR 0204 releases pooled transactions during provider work, and the synthetic Compose boundary has an authenticated k6 E2E harness for Ask enqueue, concurrent reads, and job polling. PR #633's measured landing-query and event-loop work merged into open parent #629 rather than protected `main`; its aggregate observation improved 25-VU throughput but did not establish a latency SLO. The current exact #629 also persists each completed relation verification before propagating a later provider failure | Land #629 through its refreshed protected gate, rebuild that exact-head application image, and repeat `make load-http` with declared environment concurrency/window and retained raw distributions/resource configuration; set no SLO until representative capacity evidence is approved | | Image understanding | Region, OCR, and description work exists across active heads (#405, #419), but current runtime acceptance has not yet proved table-image structure, complete region coverage, or summary/image readiness together | Orchestrator-backed rendered workflow, original/derived asset provenance, region-before-OCR processing, and honest unsupported states; reconcile ADR 0052's image-bearing summary readiness with ADR 0098 before changing sequencing | | Semantic source rendering | Paragraph, table, list, formula, and indentation work exists across stacks (#394, #427, #448–#450); #515 adds synthetic backend/frontend parity for deterministic rows/cells, footnote boundaries, and encoded scripts | Land the #427 → #515 stack, then gather authenticated browser evidence that list nesting, continuation alignment, and formula units render without authoring-layout artifacts | | Event and project semantics | Multi-project mentions, project-bound actions, 5W1H, requester/processor, and semantic relations exist in ADR 0036/0052/0100/0111/0129 and active stacks | Aggregate authenticated evidence must show distinct projects and events, explicit requester/processor and real R&R, normalized relative time, and product/entity relations without promoting attendance or co-occurrence | From 4cf0f088cf1dcb412163a75515c19a8c7ae88625 Mon Sep 17 00:00:00 2001 From: Codex Date: Wed, 26 Aug 2026 06:13:37 +0900 Subject: [PATCH 20/21] docs(gaps): refresh exact protected queue --- docs/product-technical-gap-baseline.md | 64 +++++++++++++++----------- 1 file changed, 37 insertions(+), 27 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 48fa70c3e..acf35951f 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -60,19 +60,17 @@ only aggregate, non-identifying evidence to this repository. ### Exact open-PR boundary -At this snapshot there were 4 open PRs and 10 open issues. Exact observed heads -were `#632 fb6aa44d`, `#631 0386b0e3` (this branch's observed parent), -`#629 143a6a3f`, and `#579 45769b0d`. -PR #579 is open; its ADR 0211 reservation is why protected -main's filter-option decision is ADR 0212. PRs #627 and #628 reached protected -`main`; #629 remains an open asynchronous-pool follow-up and is not release -evidence. The open heads remain blocked on hosted gates and/or independent -review. These +At this snapshot there were 13 open PRs and 10 open issues. Exact observed +heads are recorded in section 1. PR #666 is stacked on #663 and therefore +cannot be retargeted or treated as protected-main evidence until #663 first +passes the protected gate. Every open head remains blocked on hosted gates +and/or independent review; normal auto-merge is enabled on each main-targeted +PR. These observations are not merge readiness. Re-fetch exact heads, unresolved threads, checks, approvals, rulesets, and merge SHA before any lifecycle claim. -> Audit snapshot: 2026-08-25 22:43 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-26 07:31 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -82,17 +80,26 @@ lifecycle claim. ## 1. Exact-head and governance evidence The protected default branch was `04e6b610655d0db91d5f7ba9486bdda1440e0b19` -when this baseline was refreshed. The live queue contained 4 open PRs and 10 +when this baseline was refreshed. The live queue contained 13 open PRs and 10 open issues. The exact-head inventory below supersedes older per-PR snapshots elsewhere in this document; those older rows remain useful historical delivery context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | -| #632 | `fb6aa44d` | preserves graph-fact evidence provenance and drops unauthorized post endpoints before label hydration; hosted gates and independent review remain required | -| #631 | `0386b0e3` (observed parent) | decomposes closed PR #490 and now contains #634's non-default-branch CI cancellation merge; hosted gates and independent review remain required | -| #629 | `143a6a3f` | combines the asynchronous embedding-pool and measured web-read work after #633's non-default-branch merge, then preserves each completed relation verification before a later provider failure; hosted gates and independent review remain required | -| #579 | `45769b0d` | persists leftover interaction-map coordinates through the fast-mlsirm owner contract and fails coverage closed with rejected maps; hosted gates and independent review remain required | +| #666 | `f369ca0b` | stacked repair removes sampled region-coverage arithmetic; parent #663 must merge first, then this PR must be retargeted to `main` and re-prove every gate | +| #663 | `2488f0f0` | largest current buyer-facing slice: evidence-backed Project nodes in the bounded ontology explorer; all review threads resolved, some checks running, independent review required, auto-merge enabled | +| #660 | `24fda085` | restores backend runtime/integration contracts; exact-head checks passed, independent review required, auto-merge enabled | +| #659 | `0739b9d7` | token-backed ontology node readability; exact-head checks passed, independent review required, auto-merge enabled | +| #658 | `fe830b0a` | evidence-honest Global Ask knowledge cutoff; exact-head checks passed, independent review required, auto-merge enabled | +| #657 | `64f48679` | TEPP asynchronous lifecycle persistence while unpublished producer work stays unavailable; exact-head checks passed, independent review required, auto-merge enabled | +| #644 | `d9ff9980` | native frontend surface code splitting; exact-head checks passed, independent review required, auto-merge enabled | +| #643 | `0a1f8ec1` | shared token-backed status notice; exact-head checks passed, independent review required, auto-merge enabled | +| #640 | `2d50fa01` | dashboard case metrics and project journeys; exact-head checks passed, independent review required, auto-merge enabled | +| #639 | `aee02dca` | restores Running action and Compose contracts; exact-head checks passed, independent review required, auto-merge enabled | +| #632 | `702adf2d` | preserves graph-fact source provenance; some checks running, independent review required, auto-merge enabled | +| #631 | `c0022c97` (observed parent) | decomposes closed PR #490 and refreshes the exact queue; exact-head checks passed before this documentation update, independent review required, auto-merge enabled | +| #629 | `4b4d6707` | releases provider work and bounds landing reads; exact-head checks passed, independent review required, auto-merge enabled | No row above is merge evidence. Immediately before any lifecycle action, re-fetch the head, unresolved threads, formal reviews, rulesets, and same-head @@ -347,10 +354,10 @@ this file per §3.5 of the prior snapshot). | #79 | Milestone 2: port verified direct-PostgreSQL analysis into the protected architecture | analysis-run registry on `main`; remaining runtime bridge | | #87 | Milestone 2.1 normalized runtime-analysis schema bridge | related analysis-run work | | #269 | Authenticated Global Ask MCP browser-safe and admission-bounded | Ask stack | -| #271 | Evidence-honest knowledge-cutoff scope on Global Ask | Missing on protected `main`: `GlobalAskRequest` accepts only `question`; #301 merged into a non-default stack and is not release evidence | -| #272 | Verify Global Ask KG/ontology/semantic claims with public SearXNG evidence | Ask stack | -| #277 | TEPP: persist accepted receipts, poll completed results, keep measurement authority distinct | #468, #417 | -| #280 | Full project-lifecycle history and handover intervals | Tracked with issue #284; no active delivery PR confirmed | +| #271 | Evidence-honest knowledge-cutoff scope on Global Ask | #658; still open and not protected-main evidence | +| #272 | Verify Global Ask KG/ontology/semantic claims with public SearXNG evidence | #632 preserves internal provenance; public verification acceptance remains open | +| #277 | TEPP: persist accepted receipts, poll completed results, keep measurement authority distinct | #657 consumer lifecycle; executable producer route remains unavailable | +| #280 | Full project-lifecycle history and handover intervals | #640 adds case/project journeys and #663 adds evidence-backed Project exploration; authoritative lifecycle reconciliation remains #284 | | #284 | Authoritative lifecycle ingestion and idempotent reconciliation | No active delivery PR confirmed | | #338 | Evidence-bounded email/project lineage contract for Naruon consumption | Missing on protected `main`; #343 merged only into a non-default stack, while #355 is a distinct calendar-consumer contract and is not delivery evidence for email/project lineage | | #611 | Decompose closed PR #490 ADR 0133–0137 evidence without transferring stale branch state | #631 supplies the current-main inventory only; focused implementation PRs and tests for every unmet criterion are still required | @@ -359,7 +366,7 @@ this file per §3.5 of the prior snapshot). | Gap | Current evidence | Acceptance requirement | | --- | --- | --- | -| Protected release | 4 open PRs at snapshot: #632 preserves graph-fact provenance and endpoint authorization, #631 combines current-main decomposition with #634's CI fix, #629 combines the asynchronous pool and measured concurrency stacks, and reopened #579 consumes the fast-mlsirm interaction-map contract; all retain hosted and independent-review gates | Terminal exact-head checks, no unresolved threads, two independent approvals including last-push approval, protected squash-merge SHA | +| Protected release | 13 open PRs at snapshot. Twelve target `main` with normal auto-merge enabled; stacked #666 targets #663. None has the required independent approval, and running checks on #632/#663/#666 are not treated as blockers for safe work on other PRs | Terminal exact-head checks, no unresolved threads, two independent approvals including last-push approval, protected squash-merge SHA | | CI queue release latency | Two Tests runs for already merged PRs occupied the available runner slots while 54 newer runs remained queued. Manual cancellation released the stale work, but the central close workflow was itself queued behind those runs. #634 merged into #631's non-default branch and reuses the repository's existing per-PR concurrency group so a jobless close event can cancel obsolete Tests work before runner allocation; this is not protected-main delivery | Merge #631 through its refreshed protected gate; close a synthetic PR while its Tests run is active and verify the old run becomes cancelled, the close-event jobs remain skipped, and a newer exact-head run starts without manual intervention | | Evidence-grounded operations workspace | Protected-main #614 delivers governed semantic Ask, live Similar VOC, disjoint pending/failed analysis metrics, full Storybook state inventory, and current desktop/mobile screenshot evidence. Authorized-corpus backfill acceptance remains unavailable | Perform authenticated authorized-corpus acceptance with aggregate evidence and retain fail-closed no-match behavior | | Shared frontend gate | The ADR 0109 login repair is on protected `main`; eight older branches carried the defect and received the same verified repair this loop (#521–#560) | Keep every future branch cut from post-repair bases; re-verify with frontend lint/test/build before push | @@ -368,8 +375,8 @@ this file per §3.5 of the prior snapshot). | Concurrent web responsiveness | ADR 0204 releases pooled transactions during provider work, and the synthetic Compose boundary has an authenticated k6 E2E harness for Ask enqueue, concurrent reads, and job polling. PR #633's measured landing-query and event-loop work merged into open parent #629 rather than protected `main`; its aggregate observation improved 25-VU throughput but did not establish a latency SLO. The current exact #629 also persists each completed relation verification before propagating a later provider failure | Land #629 through its refreshed protected gate, rebuild that exact-head application image, and repeat `make load-http` with declared environment concurrency/window and retained raw distributions/resource configuration; set no SLO until representative capacity evidence is approved | | Image understanding | Region, OCR, and description work exists across active heads (#405, #419), but current runtime acceptance has not yet proved table-image structure, complete region coverage, or summary/image readiness together | Orchestrator-backed rendered workflow, original/derived asset provenance, region-before-OCR processing, and honest unsupported states; reconcile ADR 0052's image-bearing summary readiness with ADR 0098 before changing sequencing | | Semantic source rendering | Paragraph, table, list, formula, and indentation work exists across stacks (#394, #427, #448–#450); #515 adds synthetic backend/frontend parity for deterministic rows/cells, footnote boundaries, and encoded scripts | Land the #427 → #515 stack, then gather authenticated browser evidence that list nesting, continuation alignment, and formula units render without authoring-layout artifacts | -| Event and project semantics | Multi-project mentions, project-bound actions, 5W1H, requester/processor, and semantic relations exist in ADR 0036/0052/0100/0111/0129 and active stacks | Aggregate authenticated evidence must show distinct projects and events, explicit requester/processor and real R&R, normalized relative time, and product/entity relations without promoting attendance or co-occurrence | -| Knowledge Graph readability | The black evidence-node root cause is an undefined-token fallback; the design-token repair and long-label/evidence-table coverage remain only on closed, unmerged #490, not protected `main` | Recreate the token repair on a current base and deliver it through protected `main`, then verify light/dark contrast, keyboard graph navigation, full labels, and evidence tables in the authenticated rendered surface | +| Event and project semantics | #663 is the largest current user-visible gap slice: evidence-backed Project nodes, bounded traversal, cutoff/snapshot fencing, exact-value table parity, and localized graph labels. Focus visibility and label-bound review defects are repaired with regressions. It remains unmerged; #640 separately adds project journeys without claiming authoritative lifecycle status | Parent #663 must pass exact-head checks and independent approval before protected merge; only then retarget #666 to `main`. Aggregate authenticated evidence must still prove distinct projects/events and handover intervals without promoting co-occurrence | +| Knowledge Graph readability | #659 recreates the token-backed node-type repair on current `main`, including regression coverage; it is open and therefore not protected-main evidence | Merge #659 normally, then verify light/dark contrast, keyboard graph navigation, full labels, and evidence tables in the authenticated rendered surface | | Source-code lookup UX | Source state/detail codes remain evidence-bearing machine values and current detail presentation is dense | Catalog-backed display labels with raw-code provenance, compact 5W1H/source-detail hierarchy, keyboard access, and no unsupported customer/project binding | | Calendar / Naruon | #355 delivered the projection contract; v2.17.0 wires operator consumption without forwarding the end-user token. Naruon producer, provider/consumer fixtures, and protected merge remain open (#336) | Verify observed events against the published schema without invented events; keep commitments available when the channel is unwired | | SKOS organization aliases | Catalog binding and chip caption live on #480 / #482 | One catalog row per corroborated org; companion caption is hint-only until bound | @@ -379,10 +386,10 @@ this file per §3.5 of the prior snapshot). | Planned-facility intent | Planned-facility relationship intent remains only on closed, unmerged #490; earlier stack-only merges were not protected delivery | Recreate the evidence-backed slice on a current base and land through protected `main` before a release claim | | Accessibility and responsive UX | #602 delivered base post-detail modal semantics; #605 adds selected-post refocus, collapsed/hidden/inert/CSS-invisible focus exclusion across both modal types, readable evidence separators, focused tests, and desktop/mobile Storybook screenshots | Land #605 through the protected gate, then complete screen-reader and authenticated Playwright acceptance on the exact release head | | Design tokens and repeated objects | Token extraction started; sanitized Figma Event Lineage desktop/mobile frames exist, while other repeated product surfaces remain incomplete | Tokens in CSS + Storybook stories for board, popup, DAG, Ask, calendar, forms, charts; same-viewport Figma/runtime visual comparison before release | -| Frontend delivery performance | A current production build succeeds but emits Vite's >500 kB chunk warning (`539.27 kB` minified); raising the warning limit would conceal rather than reduce delivery cost | Measure module contribution on an exact head, split one real route/surface boundary with native dynamic import, then prove the warning is absent and loading/error states remain accessible | +| Frontend delivery performance | #644 implements a native dynamic-import boundary for conditional workspace surfaces and retains accessible loading/error states; exact-head checks passed but the PR is not protected-main evidence | Merge #644 normally, rebuild the protected-main production bundle, and retain the measured chunk inventory rather than raising the warning limit | | External integrations | Search, Zotero, calendar, Keyverse, orchestrator, RankWeave, ThreadWeave, TEPP, DiskSage, wardnet | Provider conformance, failure/reconciliation behavior, and provenance-bearing integration evidence | | MSA / modular reuse | LineageWeave must run standalone and as a consumer of org packages | Do not reimplement RankWeave/TEPP/orchestrator/ThreadWeave/Keyverse; fix upstream and PR there | -| Product contract authority | This branch recreates the first LineageWeave PRD after superseded #613 closed without merge and records an exact-case ecosystem authority register; TEPP, fast-mlsirm, keyverse, and ThreadWeave have standalone PRDs, while contextual-orchestrator, RankWeave, DiskSage, and wardnet currently rely on product-planning/architecture documents and naruon has only a scoped Topic Intelligence PRD | Land the LineageWeave PRD, keep ADRs normative, and add standalone PRDs in each owning repository before making cross-product release claims beyond its documented boundary | +| Product contract authority | The current LineageWeave PRD and linked ecosystem authorities were re-read before this loop. Remote canonical names are `LineageWeave`, `RankWeave`, `ThreadWeave`, `TEPP`, and lowercase `disksage`; `DiskSage` is a product brand/local-directory spelling, not the canonical GitHub repository name. contextual-orchestrator and RankWeave still rely on product/architecture authority rather than standalone PRDs | Keep ADRs normative, preserve remote canonical repository case in machine references, and add standalone PRDs in each owning repository before cross-product release claims exceed its documented boundary | | Release quality | Local focused/full suites have passed on individual PR heads | Repository-wide coverage, docstrings, Storybook, security, browser, and release evidence on one exact head | | PII | Masking would paralyze the product; ADR 0001 forbids identifying artifacts in git | ABAC + authorized runtime; synthetic fixtures in git; no mask-in-place that drops names the operator must read | | Database | PostgreSQL, 3NF, snake_case ≥ two words, hot-partition and lock policy | No file DBs; read/write split if lock management fails; whitelist every migration | @@ -483,10 +490,13 @@ review latency are never blockers — keep working while they settle. 1. Revalidate Strix after merged ContextualWisdomLab/.github#1320, reconcile open .github#1263, and land the atomic hourly LineageWeave caller in open .github#1288 only through their protected gates. -2. Process open LineageWeave PRs #579, #629, #631, and #632 only after each - exact head shows terminal green required checks plus current-head - independent approval. -3. After the queue drains, resume user-visible gaps from §5 in leverage order: +2. Process main-targeted PRs #629, #631, #632, #639, #640, #643, #644, #657, + #658, #659, #660, and #663 only after each exact head shows terminal green + required checks plus current-head independent approval. Merge parent #663 + before retargeting stacked child #666 to `main`; collect new exact-head + evidence after the retarget. +3. While hosted checks or independent reviews wait, resume user-visible gaps + from §5 in leverage order: external semantic verification (#272), Naruon calendar (#355/#336), and authenticated operations/ontology publication acceptance. Event Lineage evidence shipped in merged PR #387 and closed issue #274 is not an open gap. From 1d9ac82591bb4b0962d55523cbd421e007dd84d1 Mon Sep 17 00:00:00 2001 From: Codex Date: Wed, 26 Aug 2026 06:27:10 +0900 Subject: [PATCH 21/21] docs(gaps): record stacked child composition --- docs/product-technical-gap-baseline.md | 24 ++++++++++++------------ 1 file changed, 12 insertions(+), 12 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index acf35951f..0e5312b3d 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -60,10 +60,11 @@ only aggregate, non-identifying evidence to this repository. ### Exact open-PR boundary -At this snapshot there were 13 open PRs and 10 open issues. Exact observed -heads are recorded in section 1. PR #666 is stacked on #663 and therefore -cannot be retargeted or treated as protected-main evidence until #663 first -passes the protected gate. Every open head remains blocked on hosted gates +At this snapshot there were 12 open PRs and 10 open issues. Exact observed +heads are recorded in section 1. PR #666 was merged into #663's non-default +branch before the parent reached protected `main`; its checks and merge commit +are stack composition evidence only, while #663 now carries the combined +candidate. Every open head remains blocked on hosted gates and/or independent review; normal auto-merge is enabled on each main-targeted PR. These observations are not merge readiness. Re-fetch exact heads, @@ -80,15 +81,14 @@ lifecycle claim. ## 1. Exact-head and governance evidence The protected default branch was `04e6b610655d0db91d5f7ba9486bdda1440e0b19` -when this baseline was refreshed. The live queue contained 13 open PRs and 10 +when this baseline was refreshed. The live queue contained 12 open PRs and 10 open issues. The exact-head inventory below supersedes older per-PR snapshots elsewhere in this document; those older rows remain useful historical delivery context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | -| #666 | `f369ca0b` | stacked repair removes sampled region-coverage arithmetic; parent #663 must merge first, then this PR must be retargeted to `main` and re-prove every gate | -| #663 | `2488f0f0` | largest current buyer-facing slice: evidence-backed Project nodes in the bounded ontology explorer; all review threads resolved, some checks running, independent review required, auto-merge enabled | +| #663 | `db11629e` | combined parent candidate: evidence-backed Project nodes plus #666's non-default-branch removal of sampled region-coverage arithmetic; checks are running, independent review required, auto-merge enabled | | #660 | `24fda085` | restores backend runtime/integration contracts; exact-head checks passed, independent review required, auto-merge enabled | | #659 | `0739b9d7` | token-backed ontology node readability; exact-head checks passed, independent review required, auto-merge enabled | | #658 | `fe830b0a` | evidence-honest Global Ask knowledge cutoff; exact-head checks passed, independent review required, auto-merge enabled | @@ -366,7 +366,7 @@ this file per §3.5 of the prior snapshot). | Gap | Current evidence | Acceptance requirement | | --- | --- | --- | -| Protected release | 13 open PRs at snapshot. Twelve target `main` with normal auto-merge enabled; stacked #666 targets #663. None has the required independent approval, and running checks on #632/#663/#666 are not treated as blockers for safe work on other PRs | Terminal exact-head checks, no unresolved threads, two independent approvals including last-push approval, protected squash-merge SHA | +| Protected release | 12 open PRs at snapshot, all targeting `main` with normal auto-merge enabled. None has the required independent approval, and running checks on #631/#632/#663 are not treated as blockers for safe work on other PRs. #666's merge into the non-default #663 branch is not protected-main delivery | Terminal exact-head checks, no unresolved threads, two independent approvals including last-push approval, protected squash-merge SHA | | CI queue release latency | Two Tests runs for already merged PRs occupied the available runner slots while 54 newer runs remained queued. Manual cancellation released the stale work, but the central close workflow was itself queued behind those runs. #634 merged into #631's non-default branch and reuses the repository's existing per-PR concurrency group so a jobless close event can cancel obsolete Tests work before runner allocation; this is not protected-main delivery | Merge #631 through its refreshed protected gate; close a synthetic PR while its Tests run is active and verify the old run becomes cancelled, the close-event jobs remain skipped, and a newer exact-head run starts without manual intervention | | Evidence-grounded operations workspace | Protected-main #614 delivers governed semantic Ask, live Similar VOC, disjoint pending/failed analysis metrics, full Storybook state inventory, and current desktop/mobile screenshot evidence. Authorized-corpus backfill acceptance remains unavailable | Perform authenticated authorized-corpus acceptance with aggregate evidence and retain fail-closed no-match behavior | | Shared frontend gate | The ADR 0109 login repair is on protected `main`; eight older branches carried the defect and received the same verified repair this loop (#521–#560) | Keep every future branch cut from post-repair bases; re-verify with frontend lint/test/build before push | @@ -375,7 +375,7 @@ this file per §3.5 of the prior snapshot). | Concurrent web responsiveness | ADR 0204 releases pooled transactions during provider work, and the synthetic Compose boundary has an authenticated k6 E2E harness for Ask enqueue, concurrent reads, and job polling. PR #633's measured landing-query and event-loop work merged into open parent #629 rather than protected `main`; its aggregate observation improved 25-VU throughput but did not establish a latency SLO. The current exact #629 also persists each completed relation verification before propagating a later provider failure | Land #629 through its refreshed protected gate, rebuild that exact-head application image, and repeat `make load-http` with declared environment concurrency/window and retained raw distributions/resource configuration; set no SLO until representative capacity evidence is approved | | Image understanding | Region, OCR, and description work exists across active heads (#405, #419), but current runtime acceptance has not yet proved table-image structure, complete region coverage, or summary/image readiness together | Orchestrator-backed rendered workflow, original/derived asset provenance, region-before-OCR processing, and honest unsupported states; reconcile ADR 0052's image-bearing summary readiness with ADR 0098 before changing sequencing | | Semantic source rendering | Paragraph, table, list, formula, and indentation work exists across stacks (#394, #427, #448–#450); #515 adds synthetic backend/frontend parity for deterministic rows/cells, footnote boundaries, and encoded scripts | Land the #427 → #515 stack, then gather authenticated browser evidence that list nesting, continuation alignment, and formula units render without authoring-layout artifacts | -| Event and project semantics | #663 is the largest current user-visible gap slice: evidence-backed Project nodes, bounded traversal, cutoff/snapshot fencing, exact-value table parity, and localized graph labels. Focus visibility and label-bound review defects are repaired with regressions. It remains unmerged; #640 separately adds project journeys without claiming authoritative lifecycle status | Parent #663 must pass exact-head checks and independent approval before protected merge; only then retarget #666 to `main`. Aggregate authenticated evidence must still prove distinct projects/events and handover intervals without promoting co-occurrence | +| Event and project semantics | #663 is the largest current user-visible gap slice: evidence-backed Project nodes, bounded traversal, cutoff/snapshot fencing, exact-value table parity, and localized graph labels. Focus visibility, label-bound, and temporal test-double regressions are repaired. #666's heuristic removal is composed into this parent but is not separately protected-main evidence. #640 separately adds project journeys without claiming authoritative lifecycle status | Combined #663 must pass exact-head checks and independent approval before protected merge. Aggregate authenticated evidence must still prove distinct projects/events and handover intervals without promoting co-occurrence | | Knowledge Graph readability | #659 recreates the token-backed node-type repair on current `main`, including regression coverage; it is open and therefore not protected-main evidence | Merge #659 normally, then verify light/dark contrast, keyboard graph navigation, full labels, and evidence tables in the authenticated rendered surface | | Source-code lookup UX | Source state/detail codes remain evidence-bearing machine values and current detail presentation is dense | Catalog-backed display labels with raw-code provenance, compact 5W1H/source-detail hierarchy, keyboard access, and no unsupported customer/project binding | | Calendar / Naruon | #355 delivered the projection contract; v2.17.0 wires operator consumption without forwarding the end-user token. Naruon producer, provider/consumer fixtures, and protected merge remain open (#336) | Verify observed events against the published schema without invented events; keep commitments available when the channel is unwired | @@ -492,9 +492,9 @@ review latency are never blockers — keep working while they settle. .github#1288 only through their protected gates. 2. Process main-targeted PRs #629, #631, #632, #639, #640, #643, #644, #657, #658, #659, #660, and #663 only after each exact head shows terminal green - required checks plus current-head independent approval. Merge parent #663 - before retargeting stacked child #666 to `main`; collect new exact-head - evidence after the retarget. + required checks plus current-head independent approval. Treat #666's + non-default-branch merge only as part of #663's combined candidate and + collect all protected evidence on #663's exact head. 3. While hosted checks or independent reviews wait, resume user-visible gaps from §5 in leverage order: external semantic verification (#272), Naruon calendar (#355/#336), and