diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e41f7764e..b5b70b621 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,88 +2,82 @@ ## Authority and update rule -이 문서는 Noema의 protected truth, active candidate, transient workflow evidence, foreign-owner authority를 분리한다. 저장소 문서나 테스트가 특정 revision의 사실을 기록하더라도 predecessor GREEN, queued/skipped/cancelled run, 오래된 PR base snapshot, scanner/model judgement는 다음 revision의 merge authority로 전용하지 않는다. Open PR의 exact head, live base, required workflow, review thread, central dependency는 mutation·merge·release 직전에 다시 조회한다. +이 문서는 protected source, active candidate, transient workflow evidence와 foreign-owner authority를 분리한다. Open PR exact head, protected base, required workflow, review thread, release와 central dependency는 mutation·merge·release 직전에 다시 읽는다. predecessor GREEN, queued/pending/in-progress/skipped/cancelled run, 오래된 PR base snapshot과 scanner/model judgement는 다음 revision의 merge authority로 전용하지 않는다. queued는 GREEN이 아니다. -이 #547 candidate를 current protected tree에 수렴시킨 construction snapshot은 GitHub-verified protected `main@099d7d89a51bca4a2cf7c6b285b50ffadd08d001`이다. 이 SHA를 merge 이후의 evergreen `current main`으로 취급하지 않는다. Current protected source identity는 mutation·merge·release 직전에 live-read한다. Construction snapshot ancestry에는 merged PR #536 exact `4fe6fe84611dfa1d69d8e0712b72b278429524d0`, merged PR #548 exact `fb44888bd571cae61dbfc93c1b46675855fbfc9c`, merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`, merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`, merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`, merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`의 유효 delta가 포함돼 있다. +Current protected source는 GitHub-verified protected `main@e3aa77c3f678336c548440f355f988345b0ba976`다. Current source SHA는 moving observation이며 future merge 뒤 evergreen identity로 취급하지 않는다. 이 protected revision에는 merged PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`의 producer-authenticated exact-claim evidence admission과 non-vacuous reviewer publication contract, 그리고 merged PR #560 exact `5aab7c098f3478069127f34e398326415ec599a4`의 fail-closed external-extension Tool / Capability admission contract가 포함돼 있다. -#542는 Durable Workflow / Task Execution과 State / Checkpoint의 atomic claim, checkpoint CAS/replay, effect-start/terminal authority, cancellation/recovery 및 retained-provenance validation을 protected source로 만들었다. ADR 0013은 배포된 Durable Object transaction/runtime 증거가 아직 없으므로 `Proposed`를 유지한다. #540은 historical Wrangler/Miniflare/Sharp/Libvips tooling path를 제거하고 pinned `workerd@1.20260625.1` + `esbuild@0.28.1`, canonical lock/license evidence와 patch-validator dependency pruning을 protected source로 만들었다. Source integration은 immutable release rights, NOTICE/attribution, SBOM/provenance publication을 자동으로 증명하지 않는다. +Moving central control-plane snapshot은 central `.github/main@7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db`다. Noema runtime의 reviewed immutable central consumer pin은 `c9052e607e5f3cc76e73207e7786b21500721b79`이고 runtime authority 표현은 `ALLOWED_WORKFLOW_SHA = c9052e607e5f3cc76e73207e7786b21500721b79`다. Moving foreign head와 reviewed immutable pin을 같은 권위로 취급하지 않으며 central moving head가 전진했다고 consumer pin을 자동 승격하지 않는다. -이 candidate construction 시 관찰한 moving central control-plane snapshot은 central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`다. 이 SHA 역시 foreign owner의 evergreen current head로 간주하지 않고 consumer mutation 직전에 live-read한다. Noema protected runtime의 reviewed immutable consumer pin은 `c9052e607e5f3cc76e73207e7786b21500721b79`이며 runtime authority 표현은 `ALLOWED_WORKFLOW_SHA = c9052e607e5f3cc76e73207e7786b21500721b79`다. Moving central main과 reviewed immutable consumer source identity를 같은 권위로 취급하지 않는다. +Protected history에는 merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`, merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`, merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`, merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`, merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`, merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`, merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`, merged PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`, merged PR #560 exact `5aab7c098f3478069127f34e398326415ec599a4`가 포함돼 있다. 이 SHA들은 역사 증거이지 open-candidate authority가 아니다. -`docs/product-technical-gap-baseline.md`의 cross-lane source writer는 PR #547 하나다. 다른 feature lane이 과거 baseline blob을 포함하더라도 ordinary/non-force semantic convergence 때 current authority로 승계하지 않는다. +#559가 `docs/product-technical-gap-baseline.md`와 executable documentation-authority tests의 sole writer다. 다른 feature lane의 과거 baseline blob은 ordinary/non-force semantic convergence 때 current authority로 승계하지 않는다. ## Canonical product boundary -Noema Core Domain은 **Agent Runtime**과 **Workflow / Task Execution**이다. **Tool / Capability Boundary**, **State / Checkpoint**, **Isolation Integration**, **Policy / Approval**, **Observability**, **Recovery**는 명시적 bounded context다. Execution identity, side-effect authority, claim/checkpoint CAS, cancellation/recovery invariant는 Noema transaction boundary에 남긴다. +Noema Core Domain은 Agent Runtime과 Workflow / Task Execution이다. Tool / Capability Boundary, State / Checkpoint, Isolation Integration, Policy / Approval, Observability, Recovery는 명시적 bounded context다. Execution identity, side-effect authority, claim/checkpoint CAS, cancellation/recovery invariant와 Noema-owned product/role/time approval issuance는 Noema 경계에 남긴다. -`contextual-orchestrator`는 provider/model discovery, routing, retry/failover, test-time compute와 provider credential을 소유한다. Noema는 released gateway contract와 canonical `orchestrator/free` alias를 소비할 뿐 direct provider SDK, provider key, provider/model/group fallback policy를 소유하지 않는다. `.github`는 organization reusable workflow와 control-plane source를 소유한다. `quarantine-sandbox-runtime`, Wardnet, EgressWeave, AppGuardrail은 isolation/security/outbound truth를 각자 소유한다. Keyverse는 identity backend owner다. `context-graph-contracts`와 `enterprise-architecture-core`는 released/versioned contract로만 연결하며 mutable sibling PR source, copied domain table, cross-service SQL은 runtime truth가 아니다. +`contextual-orchestrator`는 provider/model discovery, routing, retry/failover, test-time compute와 provider credential을 소유한다. Noema는 released gateway contract와 canonical `orchestrator/free` alias를 소비하며 direct provider SDK, provider key, provider/model/group fallback policy를 소유하지 않는다. `.github`는 organization reusable workflow/control-plane source다. Keyverse는 identity backend다. `quarantine-sandbox-runtime`, Wardnet, EgressWeave, AppGuardrail은 각자의 isolation/security/outbound/scanning truth를 소유한다. Noema는 그 owner evidence를 reference/pin으로 소비할 뿐 foreign implementation이나 domain table을 복제하지 않는다. Cross-service SQL과 mutable sibling PR dependency는 금지한다. -Protected lineage의 #550은 PR-scoped supersession cancellation과 work-conserving dispatch를, #553은 automation threat-model documentation contract를, #542는 Durable Object state binding/routing과 durable state-store source를, #540은 current tooling/license source boundary를 통합했다. 이 네 lane은 active merge candidate가 아니다. 특히 #542 source integration은 runtime deployment·compatibility·transaction evidence까지 제조하지 않으며 #540 source integration은 release/publication rights까지 제조하지 않는다. +Baseline의 요구·설계·데이터·경계 authority는 `docs/PRD.md`, `docs/TRD.md`, `docs/UML.md`, `docs/ERD.md`, `docs/CONTEXT_MAP.md`다. 이 register는 그 문서와 ADR을 대체하지 않고 current Gap/Action/Status를 exact source·PR·workflow evidence에 결합한다. ADR 0015는 protected source에 포함됐지만 상태는 `Proposed`이며 durable lifecycle persistence, immutable shared-contract consumption, live pilot와 release evidence가 남아 있다. -## Active candidate convergence — 2026-09-08 KST +## Integrated exact-claim evidence — issue #555 / merged PR #556 -### Orchestrator/free consumer — PR #535 +PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`는 unchanged exact-head application CI `34197596549`, reviewer-ci `34197596588`, required Security Scan `34197596536`, patch-validator-image `34197596517` terminal SUCCESS와 clean review authority를 충족한 뒤 normal merge됐다. Resulting protected merge는 GitHub-verified `36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`이다. -PR #535 exact `e996b509f699c3f942ef81f0ac52b804b783cd19`는 Draft이며 construction snapshot protected main과 diverged 상태다. Hosted CI `34132537891`은 exact checkout과 package-manager setup 뒤 live pull-request base guard에서 실패했다. 이는 stale-ancestry RED다. 해당 head를 rerun하거나 guard를 약화하지 않는다. +Protected source는 raw source receipt를 context authority로만 취급하고, `ClaimEvidenceRequirement`와 producer-authenticated receipt의 kind/identity/coordinates/digest가 일치해야 finding/publication authority가 되도록 한다. `produce_source_claim_receipt()`는 exactly-one-line UTF-8 source bytes와 claim equality를 요구하며 paraphrase, embedded multiline, invalid UTF-8을 거부한다. Model `request_changes`/`blocked`는 producer-authenticated finding 없이 publication될 수 없다. Source integration은 execution stdout/stderr producer, research producer, immutable release, released central consumer까지 자동으로 증명하지 않는다. -Valid source delta는 merge-base `e6de53a1c2902cddc09e77a58efb82420cd8f5db` 이후 37개 path다. 다음 successor는 mutation 시점의 live protected main에서 시작해 protected work-conserving concurrency/admission, #542 durable workflow/state, `noema-core` Shared Kernel, #540 toolchain/license truth와 actionable failed-check/source-evidence behavior를 보존하면서 strict `orchestrator/free`, request-level ZDR/privacy, `timeout=None`, `max_retries=0`, gateway validation과 direct-provider/fallback rejection delta만 ordinary/non-force semantic convergence해야 한다. +## Integrated external-extension admission — issue #545 / merged PR #560 -Historical overlap path는 `.github/workflows/hourly-product-development.yml`, `docs/operations/hourly-product-development.md`, `test/documentation-architecture-contract.test.ts`, `test/helpers/hourly-workflow.ts`, `test/hourly-product-development-final-candidate-cleanup.test.ts`, `test/hourly-product-development-workflow.test.ts`다. Stale candidate의 zero-open-PR/scheduled semantics로 protected work-conserving source를 되돌리지 않는다. 특히 model-bearing proposer는 canonical `orchestrator/free`를 source-pin하고 repository-authored model inference timeout/retry를 두지 않되 current path-isolation/single-flight contract를 보존한다. +PR #560 exact `5aab7c098f3478069127f34e398326415ec599a4`는 unchanged exact-head application CI `34289599257`, reviewer-ci `34289599291`, required Security Scan `34289599289`, patch-validator-image `34289599248` terminal SUCCESS와 fresh clean review authority를 충족한 뒤 normal merge됐다. Resulting protected merge는 GitHub-verified `e3aa77c3f678336c548440f355f988345b0ba976`다. #559는 그 protected merge를 ordinary/non-force merge-parent로 받아 documentation authority를 수렴하며 predecessor GREEN을 재사용하지 않는다. -### Exact-claim evidence receipts — issue #555 / PR #556 +Earlier Policy / Approval RED `7ca9aebee6f92053913c0bbc665c8de77650891f`의 hosted application CI `34206149899`, job `101995980303`은 valid catalog/AppGuardrail/quarantine evidence만으로 descriptor가 active/product/role grant를 self-broaden할 수 없음을 고정했다. Subsequent production source separates source/catalog/scanner authority from Noema Policy / Approval issuance, keeps the source-issued grant at a pilot ceiling, seals admission/activation/receipt provenance, revalidates the full six-field catalog identity and live scanner receipts, and rejects impossible pre-activation invocation chronology. -Observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305`는 live #535가 아닌 과거 feature-base snapshot 위에 있다. `live #556 must be re-fetched before integration`. Hosted CI `34089768682`의 live-base RED와 absent Security evidence 때문에 이 exact head는 non-authorizing이다. #535가 fresh exact-head four-GREEN으로 normally integrate된 뒤에만 protected main과 live #556을 다시 읽고 ordinary/non-force restack/retarget한다. +Fresh hostile-input RED `f30f67328efbcd0b8bed7ac89f7c64c40528ea44` / hosted application CI `34218780676`, job `102036728526` proved that a revoked descriptor-list Proxy could leak a raw JavaScript exception through public admission. Production `802b0bff0f32c170ada328b04e87e0db43ee7cd4` normalized that public boundary without weakening descriptor/list/capability validation. -#556이 소유하는 source contract는 producer-issued evidence receipt, exact repository/head/workflow/run/attempt identity, claim/evidence digest, evidence-kind separation, model-visible `[receipt:]` reference와 pre-publication admission이다. Source receipt는 execution/research authority가 아니다. Remaining boundary는 exact stdout/stderr handoff, trusted research producer, fresh Security 포함 exact-head gates, immutable Noema release, released central `.github#1641` consumer bump와 original corpus RED→GREEN이다. +Runtime-current authority RED `4be371ec08b852f4d00829ba5aa6936df6564b5e`의 Hosted application CI `34221586992`, job `102045717213`은 caller event timestamp를 backdate해 실제 만료 뒤 권한을 계속 행사할 수 있던 결함을 재현했다. Production `2b50b35b7bdbb834f571dfcae50dceb05766244c`는 activation/invocation 때 Noema runtime wall clock이 descriptor와 독립 Policy / Approval validity window 모두 안에 있도록 요구한다. `83e3130f1894e879769e014c76e28ffc982a2063`은 pre-window edge를 고정했고 `f8703e6628961d380df59e4e90b600ebad215c11`은 ADR 0015에 event-time과 current-time authority를 분리했다. -### Cross-lane baseline — PR #547 +Replay semantic RED `cb8ad638875b761aea70aba78a480bd5031c4d7d`는 동일 invocation identity가 다른 instruction/observed-content semantics를 요청해도 retained receipt가 허용하던 결함을 증명했다. Production `9c7ae13f7053fa368fd778c3909c4428d1bdf28e`는 replay를 complete normalized invocation envelope에 결합했다. Refactor `03c2a6949a858043c6f7412a9ee724de63deaae2` 뒤 vacuous해진 core-conflict oracle은 `83ee8e9b54be7ea59cfa11fe03e4ad0c6414950c`에서 direct core coverage로 복구됐다. -PR #547은 이 문서와 executable documentation authority contract의 sole writer다. 이 revision은 #540을 active candidate로 잘못 남겨 둔 stale baseline을 수리하고 protected integration과 current open lane을 다시 분리한다. #547 자신의 future commit SHA나 merge commit SHA를 evergreen current authority로 문서에 고정하지 않는다. Exact source/head/check/review evidence는 merge 직전에 live-read한다. +Unbound core-receipt RED `5a50a9bcfe12f3938b30e4a3cb15af8d30134391`는 internal core가 발행한 authentic receipt가 public wrapper의 invocation-envelope authority 없이 넘어갈 수 있음을 증명했다. Production `cbb64def35bad02024076c1db74e9da4739ae736`은 public binding이 없는 retained receipt를 fail closed한다. Activation-time revocation RED `8ff77d9b6428a2c09f2c72bf3b05fdb989e35843`와 production `8251d4bcd2c81dd13d252a576b55dc21e66db9c4`는 admission 뒤 policy drift/revocation을 새 activation 발행 전에 다시 읽도록 했다. -## Protected but incomplete commercial evidence +Invocation-authority substitution RED `abcd1fea4b28b826826fed6b23296b59ceda98ca`는 structurally compatible caller-supplied authority가 admission-bound live authority를 대체할 수 있음을 증명했다. Production `f8814b8fd7b66f40335df85c6aadab12aa760bc1`는 invocation에 admission 당시 결합한 동일 authority instance를 요구한다. `1acbf2f464cbfb0c5ad6e3991ecc9b04f17fb895`는 same-authority catalog/scan drift를 유지했고 `feed68db0ac0404607a292ed2686bf47e5e2be22`는 운영/rollback owner 경계를 갱신했다. Hosted application CI `34230994573`, job `102076920357`이 4,190 passed / 10 failed로 드러낸 stale fixture는 `532cfaadf655d3158434db8a1c3a985a33ad3a9f`, `ab2baeda9665df96753a03f1242455efe0662e41`, `273aa711d1c7611fadab9346944891548b30919a`에서 same-authority intent를 유지하면서 mutable test cache를 제거했다. -### Toolchain / inbound license — issue #531 / merged PR #540 +Exact-admission provenance RED `0a32ee0a88378931a07b7e3b61cc31e3b494a7ab`는 source admission A에서 발행한 authentic activation이 동일 trusted authority가 source B로 이동한 뒤에도 artifact/product/role/policy/time이 맞으면 B를 authorize할 수 있던 결함을 재현했다. Hosted application CI `34235691056`, job `102092675348`은 exact checkout/live-base/lockfile/install/typecheck 뒤 release tests에서 실패했다. Test-only `49115306b4abf7656f7fd136de8a3ff0c5a1968b`은 retained activation replay와 public invocation-receipt replay까지 확장했다. Canonical production `225a04ec2c833e9068e79ad7b70f3f5d8f6d934a`는 core의 activation/receipt provenance를 process-global set에서 exact `AdmittedExternalExtension`-bound map으로 옮겼고, `2e843825cc31a316a5834db3d355e8e4a18ca028`은 public wrapper에 잠시 중복됐던 binding kernel을 제거해 exact-admission activation/receipt authority를 core 한 곳에 남겼다. 같은 conformance invariant는 `context-graph-contracts#27`에 foreign-owner requirement로 넘겼고 mutable issue/branch를 Noema runtime dependency로 소비하지 않는다. -Merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`의 source remediation은 construction snapshot protected lineage에 이미 포함돼 있다. 따라서 더 이상 #540 merge를 buyer gap의 next action으로 요구하지 않는다. 남은 권위는 protected-source package/SBOM/provenance/reproducibility, NOTICE/attribution, actual released-artifact rights와 explicit owner/legal outbound-rights evidence다. Source-only license inventory나 PR-head image check를 release evidence로 승격하지 않는다. +Plaintext replay-retention RED `3f41d94af1454926b65b1801004fe245098742b0`는 public replay WeakMap이 reversible `JSON.stringify(normalizedRequest)`를 receipt lifetime 동안 보유해 instruction, observed content, rejected secret/product/hidden-reasoning inputs의 수명을 불필요하게 늘리던 결함을 고정했다. Hosted application CI `34237704683`, job `102099615873`은 exact checkout/live-base/lockfile/install/release typecheck 뒤 release tests에서 실패했다. Production `79182c7be196c42fb94450cae9a7857ae67b5434`는 retained replay identity를 versioned/domain-separated SHA-256 digest로 바꾸고 every semantic field, key-order independence, fixed-width/no-plaintext regression을 추가했다. ADR `ac6b6c088f034a8778bdc8a859f7157223883b8d`는 process-local WeakMap lifetime, restart fail-closed, explicit digest-version migration과 FIPS 180-4 authority를 기록하며 `Proposed`를 유지한다. -### Durable runtime operation — issue #541 / merged PR #542 +그 뒤 live security finding `5586918828`은 repository-owned TypeScript SHA-256 padding/schedule/rounds가 Tool / Capability bounded context에 불필요한 security-critical primitive ownership을 추가한다는 결함을 분리했다. Test-only `b50b43065098609118991e0b0b0b4936725c2899`은 platform `crypto.subtle.digest` 또는 independently maintained/audited exact-pinned provider를 요구하고 local `SHA256_INITIAL`, `SHA256_ROUND`, `sha256Hex` ownership을 금지했다. Hosted application CI `34240985563`, job `102111324942`은 exact checkout, live-base guard, lockfile control, install과 release typecheck를 통과한 뒤 release tests에서 terminal FAILURE가 되어 reality RED를 확정했다. 같은 generation의 reviewer-ci `34240985515`와 required Security Scan `34240985513`은 SUCCESS였고 image `34240985555`는 successor generation 때문에 CANCELLED되어 GREEN으로 전용하지 않는다. -Merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`는 durable workflow/state source를 protected lineage에 넣었다. 남은 권위는 실제 deployed Durable Object binding/transaction compatibility, recovery/rollback receipt, immutable release/package/SBOM/provenance/reproducibility다. ADR 0013은 이 evidence가 존재하기 전까지 `Proposed`다. +Production `80292ed53943c61aa9d282ed18024b0f98f4cb1f`는 home-grown hash primitive를 제거하고 replay digest를 Worker Web Crypto `crypto.subtle.digest("SHA-256", ...)`에 위임했다. `396514c8f5183324e6c8d0a16d7a5d339b2cbb72`는 digest가 성공하기 전 accepted receipt를 public authority로 publish하지 않도록 success/replay path를 비동기로 만들고 digest-provider failure를 fail closed한다. `d1af4d703bd4c67b8be26d0c105d2a4ed0d4575a`는 standard SHA-256 short/padding-boundary/multi-block/long-message vectors를, `210bc59b17933b908aa20b1de1a160b07672b687`, `90bf018cbb2ea803adb02cd8e98010288f2c8201`, `a220003532901350b1ac9fc81079c7145dbf2b6f`, `26634f181f9c29e875bdd57ab5bc046b109fd91b`는 affected replay/invocation/policy tests가 async publication contract를 실제로 await하도록 수렴시켰다. ADR `62d4ea3f6a7227e66b072e914a0711587ad22279`는 SHA-256 primitive ownership을 Worker runtime에 두고 Noema가 domain/version canonicalization, replay-state lifecycle과 fail-closed interpretation만 소유하도록 기록하며 ADR 0015는 계속 `Proposed`다. -## Current authority table +Final #560 source generation `5aab7c098f3478069127f34e398326415ec599a4`는 all-four terminal SUCCESS를 충족했고 clean review 뒤 normal merge됐다. Source integration은 local fail-closed admission contract를 protected history로 승격하지만 durable append-only lifecycle evidence, immutable shared contract, AppGuardrail/quarantine/EgressWeave live operation, production pilot, release와 buyer completion까지 자동으로 증명하지 않는다. -| Lane | Authority | Integration / completion condition | -| --- | --- | --- | -| Protected source | live protected `main`; #547 construction snapshot used protected `main@099d7d89a51bca4a2cf7c6b285b50ffadd08d001`; merged #536/#548/#550/#553/#542/#540 | Current exact protected head is live-read before every mutation, merge and release. Construction SHA is historical evidence, not evergreen current-main identity. | -| Central workflow trust | moving central main is live-read; construction snapshot central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`; reviewed Noema consumer pin `c9052e607e5f3cc76e73207e7786b21500721b79` | Moving foreign head and immutable reviewed pin stay distinct. | -| Toolchain/license source | merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac` | Source complete; #531 remains open for protected release/publication/rights evidence. | -| Durable workflow/state source | merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc` | Source complete; #541 remains open for deployed runtime/recovery/release evidence. | -| Orchestrator/free consumer | PR #535 exact `e996b509f699c3f942ef81f0ac52b804b783cd19` | Live-base RED; semantic convergence onto live protected main before fresh four-GREEN. | -| Exact-claim receipts | observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305` | Wait for #535 normal integration, then live-read/restack and fresh Security-inclusive evidence. | -| Cross-lane baseline | PR #547 | Sole writer; docs/contracts change together and require wholly fresh exact-head evidence. | +AppGuardrail/quarantine receipts는 scanner/provenance evidence이지 Noema approval이 아니다. EgressWeave/quarantine references는 outbound/isolation operation의 대체물이 아니다. Anthropic marketplace review는 discovery evidence이지 CWL product authority가 아니다. `context-graph-contracts#27`이 immutable shared external-capability contract를 release하기 전까지 이 local port는 fail-closed ACL/test double이며 live plugin installation 또는 buyer completion을 주장하지 않는다. `context-graph-contracts#27`과 `appguardrail#1099`의 owner evidence를 Noema가 합성하지 않는다. -## Evidence semantics and merge rules +## Evidence and merge rules -A PR can be review-clean while non-authorizing. Review thread resolution, CI, reviewer-ci, required Security Scan, image/SBOM/provenance and branch ancestry are separate evidence classes. Every source mutation or restack invalidates predecessor workflow evidence. `queued`, `pending`, `in_progress`, `skipped`, `cancelled`, stale or absent-required evidence is not passing. +Review resolution, CI, reviewer-ci, required Security, image/SBOM/provenance, branch ancestry, release는 separate evidence classes다. Every source mutation/restack invalidates predecessor workflow evidence. `queued`, `pending`, `in_progress`, `skipped`, `cancelled`, stale 또는 absent-required evidence는 passing이 아니다. -Normal merge requires unchanged exact head, independently refreshed live base/head, no valid unresolved review finding, applicable required terminal-success gates and no foreign-owner/protected-contract regression. Concurrent commits or pushes are not called a race merely because they occur. Wrong base/conflict, stale ADR identity, mutable dependency, missing fixture/contract or single-writer violation is repaired by ordinary/non-force convergence rather than force push, destructive rebase or casual Close. +#559 predecessor exact `f4807d71ae815a5d79a08ef35628d72bb4ad34b9`의 application CI `34241457271`, job `102112384672`은 exact checkout, live-base guard, lockfile control, install과 release typecheck를 통과한 뒤 release tests에서 terminal FAILURE였다. 원인은 executable documentation-authority test가 이미 바뀐 baseline의 runtime-current RED 문구와 Web Crypto repair lineage를 따라오지 못한 stale expectation이었다. #559는 feature source를 복사하지 않고 이 baseline과 해당 documentation contract만 ordinary/non-force로 함께 수리한다. #560 integration 뒤에는 protected `main@e3aa77c3f678336c548440f355f988345b0ba976`를 ordinary merge-parent로 받아 reconverge했고, 그 뒤 source mutation은 새 exact-head generation만 merge authority가 된다. + +Normal merge requires unchanged exact head, independently refreshed live base/head, no valid unresolved review finding, applicable required terminal-success gates and no foreign-owner/protected-contract regression. Concurrent commits나 pushes 자체를 race로 단정하지 않는다. Wrong base/conflict, stale ADR, mutable dependency, missing fixture/contract, single-writer 위반은 force push나 destructive rebase가 아니라 ordinary/non-force semantic convergence로 수리한다. PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge 또는 verified successor가 모든 유효 delta/test/fixture/contract/evidence를 완전히 승계한 경우에만 사라진다. Blocked lane은 자기 lane만 막고 unrelated safe review, owner-path repair, docs-to-code repair와 buyer-gap work는 계속한다. -## Buyer and operator gaps +## Commercial gap register -| Priority | Gap | Buyer/operator impact | Current owner | Authoritative completion evidence | Next executable action | -| --- | --- | --- | --- | --- | --- | -| P0 | Strict orchestrator/free consumer | Noema가 provider/model routing authority를 복제하면 제품 경계와 운영 책임이 흐려진다. | PR #535 | Live protected main 위 semantic convergence + fresh exact-head CI/reviewer/Security/image + normal merge | #547가 stable protected ancestry를 만들면 stale head를 rerun하지 말고 37-path valid delta와 six protected-overlap path를 semantic union한다. | -| P0 | Exact-claim evidence supply chain | 외부 tool claim이 authenticated producer evidence 없이 reviewer authority로 승격될 수 있다. | issue #555 / PR #556 | #535 merge 후 current-main restack, execution/research producers, immutable release, released central consumer bump, original hosted corpus GREEN | #535 protected integration 전에는 #556을 움직이지 않는다. | -| P0 | Toolchain/license release evidence | Source dependency remediation만으로 구매자에게 실제 배포 artifact 권리와 재현성을 증명할 수 없다. | issue #531 / merged PR #540 | Protected exact release의 package/image/SBOM/provenance/reproducibility/NOTICE/rights evidence | Release-ready protected exact head가 존재할 때만 immutable publication evidence를 만든다. | -| P0 | Reviewer/Maintainer production identity | Source-only controls로 App installation, key custody/rotation, bounded publication authority를 증명할 수 없다. | issues #29 / #227 | Live installation/permissions/key-custody/rotation 및 bounded publication/recovery receipts | 승인된 control-plane preflight를 실행하고 source evidence와 분리 보존한다. | -| P0 | Governance enforceability | Required workflow source만으로 실제 approval/deletion/rewrite/break-glass 정책을 모두 증명할 수 없다. | issue #27 | Live ruleset/protection audit와 observed required-workflow behavior | protected mutation 직전 live governance를 다시 읽고 owner control에서만 수정한다. | -| P0 | Patch-validator publication | PR-head image success와 protected source만으로 immutable artifact activation을 증명할 수 없다. | issue #66 | Protected-main operational run + immutable image/signature/SBOM/provenance/reproducibility/rollback | Protected exact head에서 operational acceptance를 실행할 수 있는 authorized dispatch surface가 있을 때만 publication을 진행한다. | -| P1 | Durable runtime operation | Source-level durable semantics와 실제 deployed transaction/recovery는 다른 evidence class다. | issue #541 | Deployed Durable Object compatibility + recovery/rollback + immutable release identity | 승인된 runtime deployment evidence가 없으면 ADR 0013 `Proposed`를 유지한다. | -| P1 | Production KPI evidence | Fixture는 reliability, latency, commercial production operation을 입증하지 못한다. | issue #3 | Authenticated retained production KPI window with source/run identity and falsifiable denominator | 승인된 production source가 없으면 fail closed를 유지한다. | -| P1 | Acquisition transfer | Apache-2.0 source grant는 contributor ownership, assignment, artifact-transfer rights 자체를 증명하지 않는다. | issue #5 | Exact-release rights metadata, dependency/NOTICE/SBOM, contributor/IP and transfer evidence | Immutable release 이후 acquisition evidence를 해당 권위에서 수집한다. | +| Priority | Gap | Buyer/operator impact | Current owner | Status | Authoritative completion evidence | Next executable action | +| --- | --- | --- | --- | --- | --- | --- | +| P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority가 될 위험 | protected #556 + release/consumer lanes | Source integrated; producer/release/consumer open | protected source + execution/research producer + immutable Noema release + released central consumer corpus RED→GREEN | release/producer evidence를 별도 lane에서 완성 | +| P0 | External extension lifecycle evidence | third-party plugin metadata, self-asserted grant, stale/cross-admission activation, backdated event time, divergent replay 또는 restart 뒤 process-local authority가 runtime truth로 오인될 위험 | merged #560 + issue #561 | Admission source integrated; ADR 0015 Proposed; durable lifecycle/restart evidence open | immutable source + independent scan + Noema-issued Policy / Approval + admission-bound authority + append-only versioned lifecycle stream + CAS/idempotency/restart/rollback proof + immutable shared contract/live pilot | #561에서 Noema State / Checkpoint 경계의 append-only lifecycle evidence를 구현하고 foreign owner truth는 immutable ref/digest로만 보존 | +| P0 | Protected-main governance closure | required Security workflow만으로 PR/review/history/deletion/bypass 통제를 증명했다고 오인할 위험 | issue #27 | Open; external control evidence absent | fresh live ruleset + required PR/review/conversation/history/deletion controls + independent bypass/break-glass evidence + protected-source governance receipt | source가 만들 수 없는 organization/admin control은 issue #27에서 독립 검증 | +| P0 | Strict orchestrator/free consumer release | source 통합만으로 immutable consumer activation을 증명할 수 없음 | merged #535 + release lane | Source integrated; release/consumer open | version/tag/package/SBOM/provenance/reproducibility/rollback + released consumer | release-ready protected head에서만 publication | +| P0 | Patch-validator operational publication | source/image CI success만으로 reusable immutable runtime을 증명할 수 없음 | issue #66 | Open; publication evidence absent | protected execution + immutable image/signature/SBOM/provenance/reproducibility/rollback | explicit BuildKit cache-reuse evidence와 protected execution receipt를 확보하고 elapsed time만으로 cache hit/miss를 추정하지 않음 | +| P0 | Authentic production KPI evidence | fixture·synthetic 또는 source-level KPI 검증이 실제 운영 성능을 대체할 위험 | issue #3 | Open; production window absent | authenticated production-window records + strict provenance + buyer-relevant KPI gate | 실제 production evidence 없이는 readiness를 승격하지 않음 | +| P0 | Acquisition coordination | source/docs 완료를 buyer·legal·transfer readiness로 잘못 승격할 위험 | issue #5 | Open; evidence families incomplete | exact protected revision + applicable release/deployment/operational/buyer/legal evidence family | 남은 evidence family를 owner별로 수렴하고 source claim과 분리 | +| P0 | External Maintainer/Reviewer App identity | source capability-file 계약이 실제 App 설치·키 custody·rotation·권한·reviewer identity를 대체할 위험 | issues #29 / #227 | Open; live identity evidence absent | live installation + key custody/rotation + repository permission + eligible reviewer/publication identity evidence | 외부 App authority는 해당 issue owner에서 독립 검증 | +| P0 | Durable workflow/state production evidence | source Durable Object logic이 실제 deployed transaction/recovery를 증명하지 않음 | merged #542 / ADR 0013 | Source integrated; ADR 0013 Proposed | deployment compatibility + recovery/rollback receipt + immutable release | deployed runtime evidence 확보 전 ADR 0013 `Proposed` 유지 | -## Completion discipline +## Release boundary -각 gap은 표의 Authoritative completion evidence가 실제로 존재하고 current source/head에 결합될 때만 닫는다. 문서 존재, synthetic fixture, model judgement, stale workflow result를 완료 증거로 사용하지 않는다. Release-ready exact protected head가 없으면 version/tag/package/SBOM/provenance/rollback을 임의로 제조하지 않는다. +GitHub release collection에 immutable Noema release가 실제 존재하기 전 version/tag/package/SBOM/provenance/reproducibility/rollback completion을 주장하지 않는다. Release-ready exact protected head에서만 publication하고, consumer는 released/versioned contract만 bump한다. diff --git a/test/documentation-architecture-contract.test.ts b/test/documentation-architecture-contract.test.ts index 9baf45415..51f4692f3 100644 --- a/test/documentation-architecture-contract.test.ts +++ b/test/documentation-architecture-contract.test.ts @@ -79,8 +79,17 @@ describe("authoritative Noema documentation graph", () => { expect(productGap).toContain(owner); } expect(productGap).toContain( - "| Priority | Gap | Buyer/operator impact | Current owner | Authoritative completion evidence | Next executable action |", + "| Priority | Gap | Buyer/operator impact | Current owner | Status | Authoritative completion evidence | Next executable action |", ); + for (const authorityDocument of [ + "docs/PRD.md", + "docs/TRD.md", + "docs/UML.md", + "docs/ERD.md", + "docs/CONTEXT_MAP.md", + ]) { + expect(productGap).toContain(`\`${authorityDocument}\``); + } expect(productGap).toContain("issues #29 / #227"); for (const staleOwner of ["PR #407", "PR #67", "Active PR #426"]) { expect(gapAudit).not.toContain(staleOwner); diff --git a/test/documentation-current-trust-authority.test.ts b/test/documentation-current-trust-authority.test.ts index 112bfdc86..cc504d16c 100644 --- a/test/documentation-current-trust-authority.test.ts +++ b/test/documentation-current-trust-authority.test.ts @@ -2,18 +2,16 @@ import { readFileSync } from "node:fs"; import { describe, expect, it } from "vitest"; describe("current protected trust authority documentation", () => { - it("separates construction snapshots, live-read moving heads, and immutable reviewed pins", () => { + it("separates current protected source, moving central head, and immutable pin", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); - expect(baseline).toContain("protected `main@099d7d89a51bca4a2cf7c6b285b50ffadd08d001`"); - expect(baseline).toContain("central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`"); + expect(baseline).toContain("protected `main@e3aa77c3f678336c548440f355f988345b0ba976`"); + expect(baseline).toContain("central `.github/main@7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db`"); expect(baseline).toContain("`ALLOWED_WORKFLOW_SHA = c9052e607e5f3cc76e73207e7786b21500721b79`"); - expect(baseline).toContain("merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`"); - expect(baseline).toContain("merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`"); - expect(baseline).toContain("Current protected source identity는 mutation·merge·release 직전에 live-read한다"); - expect(baseline).toContain("Moving central main과 reviewed immutable consumer source identity를 같은 권위로 취급하지 않는다"); - expect(baseline).not.toContain("protected `main@d6394b2aa73e6fc57fccdad74ea38ad87f79e7f8`"); - expect(baseline).not.toContain("protected `main@e6de53a1c2902cddc09e77a58efb82420cd8f5db`"); - expect(baseline).not.toContain("Central workflow authority는 `.github/main@c9052e607e5f3cc76e73207e7786b21500721b79`다."); + expect(baseline).toContain("Current source SHA는 moving observation이며 future merge 뒤 evergreen identity로 취급하지 않는다"); + expect(baseline).toContain("Moving foreign head와 reviewed immutable pin을 같은 권위로 취급하지 않으며"); + expect(baseline).toContain("merged PR #560 exact `5aab7c098f3478069127f34e398326415ec599a4`"); + expect(baseline).not.toContain("protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`다"); + expect(baseline).not.toContain("central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`"); }); }); diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index 6a6e5ccf0..43f7001af 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -1,17 +1,23 @@ import { readFileSync } from "node:fs"; import { describe, expect, it } from "vitest"; -describe("product-technical gap baseline live open-PR authority", () => { - it("separates active source lanes from integrated protected history and observation-scoped downstream heads", () => { +describe("product-technical gap baseline live source authority", () => { + it("treats #560 as integrated protected history without promoting downstream completion", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); - expect(baseline).toContain("PR #535 exact `e996b509f699c3f942ef81f0ac52b804b783cd19`"); - expect(baseline).toContain("merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`"); - expect(baseline).toContain("observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305`"); - expect(baseline).toContain("live #556 must be re-fetched before integration"); - expect(baseline).toContain("issue #555 / PR #556"); - expect(baseline).not.toContain("PR #535 exact `59205b5ae333a1f2b5e6b2112bf059592ba492c9`"); - expect(baseline).not.toContain("PR #535 exact `4ad6907ae9f97b202a32a9b5e170f275ac9129b9`"); - expect(baseline).not.toContain("PR #540은 아직 merge authority가 아니다"); + expect(baseline).toContain("Integrated external-extension admission — issue #545 / merged PR #560"); + expect(baseline).toContain("PR #560 exact `5aab7c098f3478069127f34e398326415ec599a4`"); + expect(baseline).toContain("Resulting protected merge는 GitHub-verified `e3aa77c3f678336c548440f355f988345b0ba976`"); + expect(baseline).toContain("application CI `34289599257`"); + expect(baseline).toContain("patch-validator-image `34289599248`"); + expect(baseline).toContain("Policy / Approval issuance"); + expect(baseline).toContain("Runtime-current authority RED `4be371ec08b852f4d00829ba5aa6936df6564b5e`"); + expect(baseline).toContain("Replay semantic RED `cb8ad638875b761aea70aba78a480bd5031c4d7d`"); + expect(baseline).toContain("Exact-admission provenance RED `0a32ee0a88378931a07b7e3b61cc31e3b494a7ab`"); + expect(baseline).toContain("Worker Web Crypto `crypto.subtle.digest(\"SHA-256\", ...)`"); + expect(baseline).toContain("durable append-only lifecycle evidence"); + expect(baseline).toContain("ordinary/non-force"); + expect(baseline).not.toContain("## Active external-extension candidate"); + expect(baseline).not.toContain("PR #560의 ADR 0015는 candidate-only"); }); }); diff --git a/test/documentation-post-trust-integration-authority.test.ts b/test/documentation-post-trust-integration-authority.test.ts index cdc522528..ad5455007 100644 --- a/test/documentation-post-trust-integration-authority.test.ts +++ b/test/documentation-post-trust-integration-authority.test.ts @@ -2,26 +2,24 @@ import { readFileSync } from "node:fs"; import { describe, expect, it } from "vitest"; describe("post-trust-integration documentation authority", () => { - it("binds commercial-gap construction evidence to protected integrations without freezing moving heads", () => { + it("binds commercial gaps to protected integrations without freezing moving heads", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); - for (const protectedHistory of [ - "protected `main@099d7d89a51bca4a2cf7c6b285b50ffadd08d001`", - "merged PR #536 exact `4fe6fe84611dfa1d69d8e0712b72b278429524d0`", - "merged PR #548 exact `fb44888bd571cae61dbfc93c1b46675855fbfc9c`", + for (const integrated of [ + "merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`", + "merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`", + "merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`", + "merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`", "merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`", "merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`", - "merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`", - "merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`", - "central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`", + "merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`", + "merged PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`", + "merged PR #560 exact `5aab7c098f3478069127f34e398326415ec599a4`", ]) { - expect(baseline).toContain(protectedHistory); + expect(baseline).toContain(integrated); } - expect(baseline).toContain("ordinary/non-force semantic convergence"); expect(baseline).toContain("predecessor GREEN"); - expect(baseline).toContain("Construction snapshot"); - expect(baseline).not.toContain("protected `main@d6394b2aa73e6fc57fccdad74ea38ad87f79e7f8`"); - expect(baseline).not.toContain("PR #542 exact `195fdd70b267332f246d93beb95fa96fabade52e`"); - expect(baseline).not.toContain("PR #540은 아직 merge authority가 아니다"); + expect(baseline).toContain("ordinary/non-force semantic convergence"); + expect(baseline).toContain("queued는 GREEN이 아니다"); }); }); diff --git a/test/documentation-workflow-concurrency-authority.test.ts b/test/documentation-workflow-concurrency-authority.test.ts index 84ab938c7..04cd7c05e 100644 --- a/test/documentation-workflow-concurrency-authority.test.ts +++ b/test/documentation-workflow-concurrency-authority.test.ts @@ -1,16 +1,16 @@ import { readFileSync } from "node:fs"; import { describe, expect, it } from "vitest"; -describe("workflow-concurrency documentation authority", () => { - it("treats #550 and #540 as integrated protected history", () => { +describe("documentation workflow and concurrency authority", () => { + it("keeps nonterminal checks and concurrent branch movement non-authorizing", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); - expect(baseline).toContain("merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`"); - expect(baseline).toContain("#550은 PR-scoped supersession cancellation과 work-conserving dispatch를"); - expect(baseline).toContain("merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`"); - expect(baseline).toContain("protected work-conserving concurrency/admission"); - expect(baseline).toContain("pinned `workerd@1.20260625.1` + `esbuild@0.28.1`"); - expect(baseline).not.toContain("PR #540은 아직 merge authority가 아니다"); - expect(baseline).not.toContain("patch-validator-image 34155490034"); + for (const state of ["queued", "pending", "in_progress", "skipped", "cancelled"]) { + expect(baseline).toContain(state); + } + expect(baseline).toContain("Every source mutation/restack invalidates predecessor workflow evidence"); + expect(baseline).toContain("Concurrent commits나 pushes 자체를 race로 단정하지 않는다"); + expect(baseline).toContain("force push나 destructive rebase가 아니라 ordinary/non-force semantic convergence"); + expect(baseline).toContain("Blocked lane은 자기 lane만 막고 unrelated safe review"); }); }); diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index 91d5a1891..824a15f2c 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -1,36 +1,28 @@ import { readFileSync } from "node:fs"; import { describe, expect, it } from "vitest"; -describe("product technical gap current candidate authority", () => { - it("tracks protected truth and separates active candidates from integrated history", () => { +describe("product-technical gap current authority", () => { + it("records integrated external-extension admission and the durable lifecycle successor without overclaiming completion", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); - for (const currentTruth of [ - "protected `main@099d7d89a51bca4a2cf7c6b285b50ffadd08d001`", - "central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`", - "PR #535 exact `e996b509f699c3f942ef81f0ac52b804b783cd19`", - "merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`", - "observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305`", - "merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`", - "merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`", - "merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`", - ]) { - expect(baseline).toContain(currentTruth); - } - expect(baseline).toContain("live #556 must be re-fetched before integration"); - expect(baseline).toContain("predecessor GREEN"); - - for (const staleTruth of [ - "protected `main@d6394b2aa73e6fc57fccdad74ea38ad87f79e7f8`", - "protected `main@e6de53a1c2902cddc09e77a58efb82420cd8f5db`", - "PR #535 exact `4ad6907ae9f97b202a32a9b5e170f275ac9129b9`", - "PR #542 exact `195fdd70b267332f246d93beb95fa96fabade52e`", - "PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`도 protected", - "PR #553 exact `c03d946f52faf65b1f9b75c3c601fed106ffcbd0`", - "PR #540은 아직 merge authority가 아니다", - "patch-validator-image 34155490034", - ]) { - expect(baseline).not.toContain(staleTruth); - } + expect(baseline).toContain("issue #545 / merged PR #560"); + expect(baseline).toContain("Runtime-current authority RED `4be371ec08b852f4d00829ba5aa6936df6564b5e`"); + expect(baseline).toContain("Noema Policy / Approval issuance"); + expect(baseline).toContain("runtime wall clock"); + expect(baseline).toContain("Replay semantic RED `cb8ad638875b761aea70aba78a480bd5031c4d7d`"); + expect(baseline).toContain("normalized invocation envelope"); + expect(baseline).toContain("Unbound core-receipt RED `5a50a9bcfe12f3938b30e4a3cb15af8d30134391`"); + expect(baseline).toContain("public binding이 없는 retained receipt를 fail closed"); + expect(baseline).toContain("policy drift/revocation"); + expect(baseline).toContain("admission-bound live authority"); + expect(baseline).toContain("Exact-admission provenance RED"); + expect(baseline).toContain("Plaintext replay-retention RED"); + expect(baseline).toContain("Worker Web Crypto"); + expect(baseline).toContain("ADR 0015는 protected source에 포함됐지만 상태는 `Proposed`"); + expect(baseline).toContain("merged #560 + issue #561"); + expect(baseline).toContain("append-only versioned lifecycle stream"); + expect(baseline).toContain("context-graph-contracts"); + expect(baseline).toContain("live plugin installation 또는 buyer completion을 주장하지 않는다"); + expect(baseline).toContain("immutable Noema release"); }); });