diff --git a/docs/product-requirements.md b/docs/product-requirements.md index 0d456f2ae..0eb8864d5 100644 --- a/docs/product-requirements.md +++ b/docs/product-requirements.md @@ -242,7 +242,7 @@ current boundary until that repository adopts one. | `ContextualWisdomLab/keyverse` | `docs/PRD.md` | Production OIDC/JWKS/identity control plane; local demo Keycloak is not Keyverse | | `ContextualWisdomLab/RankWeave` | No standalone PRD; `README.md`, `ARCHITECTURE.md` | Store-agnostic ranking/fusion dependency; caller owns channels and authorization | | `ContextualWisdomLab/ThreadWeave` | `docs/PRD.md` | Deterministic reference-thread assembly dependency; LineageWeave owns records and persistence | -| `ContextualWisdomLab/DiskSage` | No standalone PRD; `docs/superpowers/specs/2026-07-10-disksage-design.md` | Prospective storage-policy boundary; no current runtime integration | +| `ContextualWisdomLab/disksage` (product brand: DiskSage) | No standalone PRD; `docs/superpowers/specs/2026-07-10-disksage-design.md` | Prospective storage-policy boundary; no current runtime integration | | `ContextualWisdomLab/wardnet` | No standalone PRD; `README.md`, `docs/architecture.md` | Prospective gateway/network-policy boundary; no current runtime integration | | `ContextualWisdomLab/naruon` | Scoped `docs/topic-intelligence/PRD.md` only | Owns observed calendar/email projections; LineageWeave owns commitments and combined display | | `ContextualWisdomLab/LineageWeave` | This PRD, with ADRs normative | Evidence BI/orchestration, lineage, semantic projection, API, and UI owner | diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 7704fa748..9a00a3ed0 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -1,7 +1,7 @@ # Product & Technical Gap Baseline -> Dashboard delivery snapshot: 2026-08-26 07:15 KST. Protected `main` was -> `494b54e2245040bcf02b45376f221c37cd437e76`. This local branch is not +> Dashboard delivery snapshot: 2026-08-27 06:38 KST. Protected `main` was +> `ff7431bd1851c03e737808d22c6a2d43968582f9`. This local branch is not > protected-main release evidence. ## Operations Dashboard PRD/TRD traceability @@ -60,14 +60,16 @@ only aggregate, non-identifying evidence to this repository. ### Exact open-PR boundary -At this snapshot there were 11 open PRs and 10 open issues. PRs #660 and #659 -merged to protected `main`; PR #666 remains only non-default-branch stack -composition inside #663. Every remaining open head required refreshed hosted -gates and/or independent review after the base changed. These observations are +At this snapshot there were 41 open PRs and 11 open issues. PR #712 merged only +into #702's non-default branch as `78a14410`; it is part of that combined +candidate and is not protected-`main` delivery. PR #711 still targets #640 and +must wait for its protected upstream dependency before it can be retargeted to +`main`. Every remaining open head required refreshed hosted gates and/or +independent review after the base changed. These observations are not merge readiness. Re-fetch exact heads, unresolved threads, checks, approvals, rulesets, and merge SHA before any lifecycle claim. -> Audit snapshot: 2026-08-26 07:15 KST (refreshed by the autonomous merge +> Audit snapshot: 2026-08-27 06:38 KST (refreshed by the autonomous merge > loop). This repository records synthetic fixtures and aggregate, > non-identifying runtime evidence only. Open PRs and local checks are not > protected-default-branch release evidence. Identifying post identifiers, @@ -76,31 +78,80 @@ approvals, rulesets, and merge SHA before any lifecycle claim. ## 1. Exact-head and governance evidence -The protected default branch was `494b54e2245040bcf02b45376f221c37cd437e76` -when this baseline was refreshed. The live queue contained 11 open PRs and 10 +The protected default branch was `ff7431bd1851c03e737808d22c6a2d43968582f9` +when this baseline was refreshed. The live queue contained 41 open PRs and 11 open issues. The exact-head inventory below supersedes older per-PR snapshots elsewhere in this document; those older rows remain useful historical delivery context only. | PR | Exact observed head | Merge/check state at this snapshot | | ---: | --- | --- | -| #667 | `3bc662d7` | refreshes protected-main and open-queue documentation evidence; base conflict remains to be repaired | -| #663 | `6fd2f701` | combined Project ontology candidate plus #666's non-default-branch removal of sampled region-coverage arithmetic; base conflict remains to be repaired | -| #658 | `f007a5ed` | evidence-honest Global Ask cutoff; hosted checks and independent review required | -| #657 | `2d9b43b7` | TEPP asynchronous lifecycle persistence while unpublished producer work stays unavailable; hosted checks and independent review required | -| #644 | `ed8d97f3` | native frontend surface code splitting; hosted checks and independent review required | -| #643 | `7fb4d18c` | shared token-backed status notice; hosted checks and independent review required | -| #640 | `2d50fa01` | dashboard case metrics and project journeys; base conflict remains to be repaired | -| #639 | `48065ad1` | restores Running action and Compose contracts; hosted checks and independent review required | -| #632 | `29aee18d` | graph-fact provenance, public verification, MCP admission, and k6 evidence; hosted checks and independent review required | -| #631 | `665046dc` (observed parent) | decomposes closed PR #490; this merge refresh advances its head and restarts hosted review evidence | -| #629 | `0138db5f` | provider-work release and bounded landing reads refreshed onto protected `main`; hosted checks and independent review restarted | +| #629 | `b721b0f2` | provider-work release and bounded landing reads; exact-head hosted review remains incomplete | +| #632 | `24262a99` | graph-fact provenance; exact-head hosted review remains incomplete | +| #639 | `2f4b1bff` | Running action and Compose contracts; exact-head hosted review remains incomplete | +| #640 | `ebfe60af` | dashboard case metrics and project journeys; exact-head hosted review remains incomplete | +| #643 | `8767de1b` | shared token-backed status notice; exact-head hosted review remains incomplete | +| #644 | `f53dd28e` | native frontend surface code splitting; exact-head hosted review remains incomplete | +| #657 | `355a5796` | TEPP asynchronous lifecycle consumer; exact-head hosted review remains incomplete | +| #658 | `5f3bc384` | evidence-honest Global Ask cutoff; exact-head hosted review remains incomplete | +| #667 | `e3f8a895` | per-post Ask history and baseline evidence; exact-head hosted review remains incomplete | +| #668 | `234f975b` | evidence-bound project history; exact-head hosted review remains incomplete | +| #672 | `a3e87a89` | persisted semantic evidence nomination; exact-head hosted review remains incomplete | +| #679 | `135dfe7c` | opt-in public-claim envelopes; exact-head hosted review remains incomplete | +| #680 | `b05e3100` | customer-actionable ranking guidance; exact-head hosted review remains incomplete | +| #700 | `1bc99eca` | evidence-bound conversation turns; exact-head hosted review remains incomplete | +| #701 | `cc3351a9` | production-equivalent concurrent-migration fixture; exact-head hosted review remains incomplete and independent approval is absent | +| #702 | `92294223` | source-semantic coverage plus non-default #712 composition; exact-head hosted evidence remains incomplete | +| #704 | `7b9a70ee` | external lineage contract with exact provider-work budget and fail-closed importer repair; exact-head hosted evidence remains incomplete | +| #709 | `8ef4090c` | official DOT/FJA worker-function taxonomy; exact-head hosted review remains incomplete | +| #710 | `27a917ee` | historical snapshot precursor observed before this refresh commit; committing the snapshot necessarily advances the present PR head | +| #711 | `05e5f520` | stacked on #640 and blocked by an unmerged contextual-orchestrator pin; auto-merge remains disabled | +| #713 | `850494c3` | complete source-post Voice-of-X taxonomy; exact-head hosted review remains incomplete | +| #716 | `65e1dcdc` | stacked on #711; operations backfill priority, with unstable hosted evidence and no protected-main claim | +| #717 | `ebb4ef1d` | stacked on #713; evidence-bearing Voice-of-X combinations, with unstable hosted evidence and no protected-main claim | +| #718 | `2723fea3` | stacked on #709; evidence-bound occupational constructs; terminal hosted checks are green but no protected-main claim exists | +| #719 | `6ee2278a` | stacked on #718; source-grounded occupational taxonomy, with no protected-main claim | +| #720 | `dda0531d` | stale-run cancellation workflow; exact-head hosted review remains incomplete | +| #721 | `9214c50f` | stacked on #718; normalized evidence-bound occupational-construct persistence; terminal hosted checks are green but no protected-main claim exists | +| #723 | `316fc190` | stacked on #721; official O*NET 31.0 construct catalog sync; terminal hosted checks are green but no protected-main claim exists | +| #724 | `1d2f8052` | stacked on #719; complete 2018 SOC hierarchy, with unstable hosted evidence and no protected-main claim | +| #726 | `d6a12fbb` | stacked on #723; catalog-bound extraction plus merged #729 review UI; hosted checks are active and no protected-main claim exists | +| #728 | `e52a8272` | stacked on #640; leftover-map explained-share persistence, with unstable hosted evidence and no protected-main claim | +| #731 | `b3b9b360` | stacked on #724; complete O*NET 31.0 content model, with unstable hosted evidence and no protected-main claim | +| #732 | `7f60aa8e` | stacked on #731; O*NET content-model linkages, with no protected-main claim | +| #733 | `17c554a9` | stacked on #726; authorized occupational-construct ontology navigation, with active hosted evidence and no protected-main claim | +| #734 | `4c3677af` | stacked on #732; O*NET occupation rating store, with no protected-main claim | +| #735 | `e2042093` | stacked pinned O*NET rating importer; no protected-main claim | +| #740 | `e6efa6fe` | stacked occupation evidence UI with stale-request fencing; focused UI tests and screenshots are candidate evidence only | +| #742 | `7e2cef27` | stacked evidence-bound product relations; dirty merge state and no protected-main claim | +| #743 | `8b420ce5` | stacked authenticated occupation selector; no protected-main claim | +| #745 | `c8a702ec` | stacked occupation-selector continuation; dirty merge state and no protected-main claim | +| #746 | `0f3017aa` | stacked O*NET source catalog; no protected-main claim | No row above is merge evidence. Immediately before any lifecycle action, re-fetch the head, unresolved threads, formal reviews, rulesets, and same-head check conclusions. In particular, queued checks are infrastructure state and do not transfer evidence from an earlier SHA. +Cross-PR authority audit at this snapshot found unresolved composition +collisions that must be reconciled after each parent reaches protected `main`: +PR #640 and #713 both carry ADR 0246; PR #714 and stacked #717 both carry ADR +0247; #718 occupies candidate ADR 0248 while its dependent occupational stack +continues through ADR 0254; and #632 and #701 carry different blobs for +migration 0210. The candidate changelog fragments also +span 2.19.0 through 2.22.0 while every pyproject-changing head inspected still +declares 2.18.0. These are candidate-branch conflicts, not authority to pick a +number heuristically. Merge each parent first, retarget its children to +`main`, allocate the next unused ADR/migration/release identity from that live +base, and recollect exact-head evidence. + +Voice-of-X candidates remain bounded by ADR 0246/0251: twelve atomic classes +and extensible compositions retain approved Post evidence, qualified PROV-O +derivation, truth status, and cutoff. A fixed combination enumeration, +B2B2C-only restriction, or substitution of a hidden evidence Post is not an +accepted implementation. Authenticated PostgreSQL API and rendered UI evidence +remain unavailable for any acceptance criterion not proven on that boundary. + PR #607 first merged as `61fd631c7bb3c57113fd19763c2c43161eeb2824` into #606's non-default branch. PR #606 subsequently passed the protected gate, so the combined TEPP-consumer and operations-dashboard implementation is now @@ -352,17 +403,17 @@ this file per §3.5 of the prior snapshot). | #271 | Evidence-honest knowledge-cutoff scope on Global Ask | #658; still open and not protected-main evidence | | #272 | Verify Global Ask KG/ontology/semantic claims with public SearXNG evidence | #632 preserves internal provenance; public verification acceptance remains open | | #277 | TEPP: persist accepted receipts, poll completed results, keep measurement authority distinct | #657 consumer lifecycle; executable producer route remains unavailable | -| #280 | Full project-lifecycle history and handover intervals | #640 adds case/project journeys and #663 adds evidence-backed Project exploration; authoritative lifecycle reconciliation remains #284 | +| #280 | Full project-lifecycle history and handover intervals | #663 delivered evidence-backed Project exploration to protected `main`; #640 adds case/project journeys, while authoritative lifecycle reconciliation remains #284 | | #284 | Authoritative lifecycle ingestion and idempotent reconciliation | No active delivery PR confirmed | | #338 | Evidence-bounded email/project lineage contract for Naruon consumption | Missing on protected `main`; #343 merged only into a non-default stack, while #355 is a distinct calendar-consumer contract and is not delivery evidence for email/project lineage | -| #611 | Decompose closed PR #490 ADR 0133–0137 evidence without transferring stale branch state | #631 supplies the current-main inventory only; focused implementation PRs and tests for every unmet criterion are still required | +| #611 | Decompose closed PR #490 ADR 0133–0137 evidence without transferring stale branch state | #631 delivered the current-main inventory to protected `main`; focused implementation PRs and tests for every unmet criterion are still required | ## 5. Open product and technical gaps | Gap | Current evidence | Acceptance requirement | | --- | --- | --- | -| Protected release | 12 open PRs at snapshot, all targeting `main` with normal auto-merge enabled. None has the required independent approval, and running checks on #631/#632/#663 are not treated as blockers for safe work on other PRs. #666's merge into the non-default #663 branch is not protected-main delivery | Terminal exact-head checks, no unresolved threads, two independent approvals including last-push approval, protected squash-merge SHA | -| CI queue release latency | Two Tests runs for already merged PRs occupied the available runner slots while 54 newer runs remained queued. Manual cancellation released the stale work, but the central close workflow was itself queued behind those runs. #634 merged into #631's non-default branch and reuses the repository's existing per-PR concurrency group so a jobless close event can cancel obsolete Tests work before runner allocation; this is not protected-main delivery | Merge #631 through its refreshed protected gate; close a synthetic PR while its Tests run is active and verify the old run becomes cancelled, the close-event jobs remain skipped, and a newer exact-head run starts without manual intervention | +| Protected release | 41 open PRs at snapshot. Twenty-one target `main`; twenty are stacked on unmerged candidates. None of the occupational stack is protected-main delivery. #712's merge into non-default #702 is composition, not protected-main delivery. Queued checks remain infrastructure state and do not block safe work on other PRs. Active ruleset 18156473 currently requires one approval, dismissal on push, approval for unattributed changes, resolved threads, and seven central workflows; it does not currently enable the separate last-push-approval flag | Terminal exact-head checks, no unresolved threads, one eligible independent current-head approval, and a protected squash-merge SHA under the re-fetched active rules | +| CI queue release latency | Two Tests runs for already merged PRs occupied the available runner slots while 54 newer runs remained queued. Manual cancellation released the stale work, but the central close workflow was itself queued behind those runs. #631 delivered #634's reuse of the repository's existing per-PR concurrency group to protected `main`, so a jobless close event can cancel obsolete Tests work before runner allocation | Close a synthetic PR while its Tests run is active and verify the old run becomes cancelled, the close-event jobs remain skipped, and a newer exact-head run starts without manual intervention | | Evidence-grounded operations workspace | Protected-main #614 delivers governed semantic Ask, live Similar VOC, disjoint pending/failed analysis metrics, full Storybook state inventory, and current desktop/mobile screenshot evidence. Authorized-corpus backfill acceptance remains unavailable | Perform authenticated authorized-corpus acceptance with aggregate evidence and retain fail-closed no-match behavior | | Shared frontend gate | The ADR 0109 login repair is on protected `main`; eight older branches carried the defect and received the same verified repair this loop (#521–#560) | Keep every future branch cut from post-repair bases; re-verify with frontend lint/test/build before push | | Identifying baseline regression | `main` gap file listed real post identifiers; separately, closed #506 and pre-existing public history contain a private runtime source-table identifier, while current `main` and #507 trees are clean | Land this non-identifying rewrite, then coordinate ADR 0001 history remediation with security/privacy owners; do not reproduce the value, force-push, or delete evidence ad hoc | @@ -370,8 +421,10 @@ this file per §3.5 of the prior snapshot). | Concurrent web responsiveness | ADR 0204 releases pooled transactions during provider work, and the synthetic Compose boundary has an authenticated k6 E2E harness for Ask enqueue, concurrent reads, and job polling. PR #633's measured landing-query and event-loop work merged into open parent #629 rather than protected `main`; its aggregate observation improved 25-VU throughput but did not establish a latency SLO. The current exact #629 also persists each completed relation verification before propagating a later provider failure | Land #629 through its refreshed protected gate, rebuild that exact-head application image, and repeat `make load-http` with declared environment concurrency/window and retained raw distributions/resource configuration; set no SLO until representative capacity evidence is approved | | Image understanding | Region, OCR, and description work exists across active heads (#405, #419), but current runtime acceptance has not yet proved table-image structure, complete region coverage, or summary/image readiness together | Orchestrator-backed rendered workflow, original/derived asset provenance, region-before-OCR processing, and honest unsupported states; reconcile ADR 0052's image-bearing summary readiness with ADR 0098 before changing sequencing | | Semantic source rendering | Paragraph, table, list, formula, and indentation work exists across stacks (#394, #427, #448–#450); #515 adds synthetic backend/frontend parity for deterministic rows/cells, footnote boundaries, and encoded scripts | Land the #427 → #515 stack, then gather authenticated browser evidence that list nesting, continuation alignment, and formula units render without authoring-layout artifacts | -| Event and project semantics | #663 is the largest current user-visible gap slice: evidence-backed Project nodes, bounded traversal, cutoff/snapshot fencing, exact-value table parity, and localized graph labels. Focus visibility, label-bound, and temporal test-double regressions are repaired. #666's heuristic removal is composed into this parent but is not separately protected-main evidence. #640 separately adds project journeys without claiming authoritative lifecycle status | Combined #663 must pass exact-head checks and independent approval before protected merge. Aggregate authenticated evidence must still prove distinct projects/events and handover intervals without promoting co-occurrence | -| Knowledge Graph readability | #659 recreates the token-backed node-type repair on current `main`, including regression coverage; it is open and therefore not protected-main evidence | Merge #659 normally, then verify light/dark contrast, keyboard graph navigation, full labels, and evidence tables in the authenticated rendered surface | +| Event and project semantics | #663 delivered evidence-backed Project nodes, bounded traversal, cutoff/snapshot fencing, exact-value table parity, localized graph labels, and #666's heuristic removal to protected `main` as `faff7a32`. #640 separately proposes project journeys without claiming authoritative lifecycle status | Aggregate authenticated evidence must still prove distinct projects/events and handover intervals without promoting co-occurrence; #640 remains candidate-only until protected merge | +| Official worker-function vocabulary (2026-08-27 03:58 KST snapshot) | Protected `main` has no addressable DOT/FJA Data/People/Things vocabulary. PR #709 exact head `8ef4090c` carries candidate ADR 0232 and adds the 24 complete official definitions, domains, and ordinal rank positions as SKOS concepts plus deterministic fail-closed reads. Commit `91f342f4` removed the unsupported term-level Fleishman/O*NET facet crosswalk; the current head preserves the authoritative DOT definitions as `skos:definition` without manufacturing stronger semantics | Land candidate ADR 0232 and its implementation together through normal protected gates, publish the deterministic ontology artifact from `main`, and require an authoritative exact crosswalk before adding any ability, skill, work-style, or behavioral mapping | +| Occupational construct evidence (2026-08-27 03:58 KST snapshot) | The #718 → #721 → #723 → #726 → #733 stack defines evidence-bound cognitive, affective, and behavioral constructs, normalized assertion provenance, the pinned official O*NET 31.0 catalog, contextual-orchestrator extraction, Post-detail review, and authorized ontology navigation. Exact heads are `2723fea3`, `9214c50f`, `30ddc8fd`, `6249ba0e`, and `7965fe67`; #729 merged only into #726 and is candidate composition, not protected-main delivery. Parent checks through #723 are terminal green; #726 and #733 have fresh hosted evidence in progress. Local synthetic tests, Storybook builds, and inspected desktop/mobile screenshots are candidate evidence only. No authenticated aggregate runtime acceptance or protected-main delivery exists | Merge #709 first, then retarget and revalidate each child in stack order. Prove official catalog sync, completed-empty versus unavailable extraction, current-digest stale-evidence fencing, ABAC-filtered exact evidence, historical-cutoff unavailability, and rendered keyboard/mobile ontology behavior on one protected release head. Keep affect/performance constructs unavailable unless an authoritative catalog entry and source span support them; add no heuristic projection or numeric weight | +| Knowledge Graph readability | Protected `main` includes #659's token-backed node-type repair and regression coverage | Verify light/dark contrast, keyboard graph navigation, full labels, and evidence tables in the authenticated rendered surface | | Source-code lookup UX | Source state/detail codes remain evidence-bearing machine values and current detail presentation is dense | Catalog-backed display labels with raw-code provenance, compact 5W1H/source-detail hierarchy, keyboard access, and no unsupported customer/project binding | | Calendar / Naruon | #355 delivered the projection contract; v2.17.0 wires operator consumption without forwarding the end-user token. Naruon producer, provider/consumer fixtures, and protected merge remain open (#336) | Verify observed events against the published schema without invented events; keep commitments available when the channel is unwired | | SKOS organization aliases | Catalog binding and chip caption live on #480 / #482 | One catalog row per corroborated org; companion caption is hint-only until bound | @@ -400,7 +453,7 @@ give this delivery matrix: | Closed-branch decision | Current-main classification | Smallest remaining delivery | | --- | --- | --- | -| ADR 0133 source-reference research | Partial foundation: protected `main` has the self-hosted SearXNG relation-verification client and fail-closed configuration, but it verifies an already extracted relation. It has no source-unit/image-region lead, cited-resource retrieval, claim judgment, or normalized research citation workflow | One post-scoped lead-to-citation slice that reuses the self-hosted SearXNG search boundary, adds public-target SSRF/redirect rejection for result retrieval, and judges through contextual-orchestrator with explicit unavailable outcomes | +| ADR 0133 source-reference research | Protected `main` still has only the SearXNG relation-verification foundation. PR #714 exact head `76a602c8` at the 2026-08-27 03:58 KST snapshot is the candidate post-scoped source-unit/image-region workflow through contextual-orchestrator; its focused 46-test regression set passed locally, including preservation of the last determinate citation across a transient unavailable re-check and deterministic source-order reads | Complete exact-head hosted checks, independent approval, protected merge, and authenticated synthetic E2E acceptance; until then the buyer-visible capability remains unavailable on protected `main` | | ADR 0134 token-backed exception messages | Partial: sanitized next-action failures exist, but no shared token-backed exception component or complete Storybook error inventory exists | Migrate one existing unavailable flow to one shared accessible alert and verify its success, unavailable, and retry states | | ADR 0135 kind/status-exact analysis actions | Partial: protected `main` has kind-aware start/retry controls plus normative analysis-run, TEPP, cutoff-body, and channel-evidence contracts; it does not contain the closed branch's unified guidance component or its full kind × status interaction inventory | Test the current run-kind/status matrix first, then add only a proven missing state/control pair rather than copying the closed-branch function | | ADR 0136 per-post Ask history | Partial: `post_chat_result` / `post_chat_citation`, the authorized post Chat API, and its linear exchange history are on protected `main`. Account-and-post-scoped sessions, ordered turns, list/select/new controls, and batched citation reauthorization are not | Define the 3NF account/post session boundary, bounded batch reauthorization, and one authorized list/load/write path before adding the conversation picker | @@ -485,11 +538,17 @@ review latency are never blockers — keep working while they settle. 1. Revalidate Strix after merged ContextualWisdomLab/.github#1320, reconcile open .github#1263, and land the atomic hourly LineageWeave caller in open .github#1288 only through their protected gates. -2. Process main-targeted PRs #629, #631, #632, #639, #640, #643, #644, #657, - #658, #659, #660, and #663 only after each exact head shows terminal green - required checks plus current-head independent approval. Treat #666's - non-default-branch merge only as part of #663's combined candidate and - collect all protected evidence on #663's exact head. +2. Process main-targeted PRs #629, #632, #639, #640, #643, #644, #657, + #658, #667, #668, #672, #679, #680, #700, #701, #702, #704, #709, #710, + #713, #714, and #720 only after each exact head shows terminal green required + checks plus current-head independent approval. Treat #712's + non-default-branch merge only as part of #702's combined candidate. Merge + #640 before retargeting #711, then merge #711 before retargeting #716. + Likewise merge #713 before retargeting #717. Merge the occupational stack + in dependency order #709 → #718 → #721 → #723 → #726 → #733; separately + preserve #718 → #719 → #724 → #731 → #732 → #734. Retarget #728 only after #640. + Reconcile ADR/migration/release identities and refresh all + exact-head evidence after every retarget. 3. While hosted checks or independent reviews wait, resume user-visible gaps from §5 in leverage order: external semantic verification (#272), Naruon calendar (#355/#336), and