From bd109e66669f95930dbbd08efd640bd614e0a3ce Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 09:20:18 +0900 Subject: [PATCH 01/68] test(docs): expose post-547 commercial authority drift --- test/documentation-live-open-pr-authority.test.ts | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index 6a6e5ccf0..d40f697bb 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -5,13 +5,18 @@ describe("product-technical gap baseline live open-PR authority", () => { it("separates active source lanes from integrated protected history and observation-scoped downstream heads", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); - expect(baseline).toContain("PR #535 exact `e996b509f699c3f942ef81f0ac52b804b783cd19`"); + expect(baseline).toContain("protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`"); + expect(baseline).toContain("PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a`"); + expect(baseline).toContain("PR #558 exact `f2aa8570d952cc0a371da161e651472c080e00ce`"); + expect(baseline).toContain("merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`"); expect(baseline).toContain("merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`"); expect(baseline).toContain("observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305`"); expect(baseline).toContain("live #556 must be re-fetched before integration"); expect(baseline).toContain("issue #555 / PR #556"); + expect(baseline).not.toContain("PR #535 exact `e996b509f699c3f942ef81f0ac52b804b783cd19`"); expect(baseline).not.toContain("PR #535 exact `59205b5ae333a1f2b5e6b2112bf059592ba492c9`"); expect(baseline).not.toContain("PR #535 exact `4ad6907ae9f97b202a32a9b5e170f275ac9129b9`"); expect(baseline).not.toContain("PR #540은 아직 merge authority가 아니다"); + expect(baseline).not.toContain("PR #547은 이 문서와 executable documentation authority contract의 sole writer다"); }); }); From 80473dd42dc50cfa73610fbfbbe6811412ef6d0a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 09:20:32 +0900 Subject: [PATCH 02/68] test(docs): require current active commercial lanes --- ...roduct-technical-gap-current-candidate-contract.test.ts | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index 91d5a1891..a5c6a5df8 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -6,9 +6,11 @@ describe("product technical gap current candidate authority", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); for (const currentTruth of [ - "protected `main@099d7d89a51bca4a2cf7c6b285b50ffadd08d001`", + "protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`", "central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`", - "PR #535 exact `e996b509f699c3f942ef81f0ac52b804b783cd19`", + "PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a`", + "PR #558 exact `f2aa8570d952cc0a371da161e651472c080e00ce`", + "merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`", "merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`", "observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305`", "merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`", @@ -23,6 +25,7 @@ describe("product technical gap current candidate authority", () => { for (const staleTruth of [ "protected `main@d6394b2aa73e6fc57fccdad74ea38ad87f79e7f8`", "protected `main@e6de53a1c2902cddc09e77a58efb82420cd8f5db`", + "PR #535 exact `e996b509f699c3f942ef81f0ac52b804b783cd19`", "PR #535 exact `4ad6907ae9f97b202a32a9b5e170f275ac9129b9`", "PR #542 exact `195fdd70b267332f246d93beb95fa96fabade52e`", "PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`도 protected", From eeab6f7e3a2e38a119639e33a3dcca276b18fa0a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 09:21:40 +0900 Subject: [PATCH 03/68] docs: refresh commercial gap authority after #547 --- docs/product-technical-gap-baseline.md | 71 +++++++++++++++----------- 1 file changed, 41 insertions(+), 30 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e41f7764e..8b0565834 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,15 +2,15 @@ ## Authority and update rule -이 문서는 Noema의 protected truth, active candidate, transient workflow evidence, foreign-owner authority를 분리한다. 저장소 문서나 테스트가 특정 revision의 사실을 기록하더라도 predecessor GREEN, queued/skipped/cancelled run, 오래된 PR base snapshot, scanner/model judgement는 다음 revision의 merge authority로 전용하지 않는다. Open PR의 exact head, live base, required workflow, review thread, central dependency는 mutation·merge·release 직전에 다시 조회한다. +이 문서는 Noema의 protected truth, active candidate, transient workflow evidence와 foreign-owner authority를 분리한다. Open PR exact head, protected base, required workflow, review thread, release와 central dependency는 mutation·merge·release 직전에 다시 읽는다. predecessor GREEN, queued/skipped/cancelled run, 오래된 PR base snapshot과 scanner/model judgement는 다음 revision의 merge authority로 전용하지 않는다. -이 #547 candidate를 current protected tree에 수렴시킨 construction snapshot은 GitHub-verified protected `main@099d7d89a51bca4a2cf7c6b285b50ffadd08d001`이다. 이 SHA를 merge 이후의 evergreen `current main`으로 취급하지 않는다. Current protected source identity는 mutation·merge·release 직전에 live-read한다. Construction snapshot ancestry에는 merged PR #536 exact `4fe6fe84611dfa1d69d8e0712b72b278429524d0`, merged PR #548 exact `fb44888bd571cae61dbfc93c1b46675855fbfc9c`, merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`, merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`, merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`, merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`의 유효 delta가 포함돼 있다. +Current protected source는 GitHub-verified protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`이며 merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`의 documentation-authority delta를 포함한다. Current protected source identity는 mutation·merge·release 직전에 live-read한다. 이 SHA도 future merge 뒤의 evergreen current-main identity로 취급하지 않는다. -#542는 Durable Workflow / Task Execution과 State / Checkpoint의 atomic claim, checkpoint CAS/replay, effect-start/terminal authority, cancellation/recovery 및 retained-provenance validation을 protected source로 만들었다. ADR 0013은 배포된 Durable Object transaction/runtime 증거가 아직 없으므로 `Proposed`를 유지한다. #540은 historical Wrangler/Miniflare/Sharp/Libvips tooling path를 제거하고 pinned `workerd@1.20260625.1` + `esbuild@0.28.1`, canonical lock/license evidence와 patch-validator dependency pruning을 protected source로 만들었다. Source integration은 immutable release rights, NOTICE/attribution, SBOM/provenance publication을 자동으로 증명하지 않는다. +Construction snapshot 이력은 protected `main@099d7d89a51bca4a2cf7c6b285b50ffadd08d001`에서 #547을 수렴시킨 시점을 보존한다. 그 ancestry에는 merged PR #536 exact `4fe6fe84611dfa1d69d8e0712b72b278429524d0`, merged PR #548 exact `fb44888bd571cae61dbfc93c1b46675855fbfc9c`, merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`, merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`, merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`, merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`가 포함돼 있다. Construction snapshot은 역사 증거이며 moving protected head를 고정하는 장치가 아니다. -이 candidate construction 시 관찰한 moving central control-plane snapshot은 central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`다. 이 SHA 역시 foreign owner의 evergreen current head로 간주하지 않고 consumer mutation 직전에 live-read한다. Noema protected runtime의 reviewed immutable consumer pin은 `c9052e607e5f3cc76e73207e7786b21500721b79`이며 runtime authority 표현은 `ALLOWED_WORKFLOW_SHA = c9052e607e5f3cc76e73207e7786b21500721b79`다. Moving central main과 reviewed immutable consumer source identity를 같은 권위로 취급하지 않는다. +이 revision 작성 시 마지막으로 관찰한 moving central control-plane snapshot은 central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`다. Noema protected runtime의 reviewed immutable consumer pin은 `c9052e607e5f3cc76e73207e7786b21500721b79`이며 runtime authority 표현은 `ALLOWED_WORKFLOW_SHA = c9052e607e5f3cc76e73207e7786b21500721b79`다. Moving central main과 reviewed immutable consumer source identity를 같은 권위로 취급하지 않는다. -`docs/product-technical-gap-baseline.md`의 cross-lane source writer는 PR #547 하나다. 다른 feature lane이 과거 baseline blob을 포함하더라도 ordinary/non-force semantic convergence 때 current authority로 승계하지 않는다. +Merged #547은 이전 cross-lane baseline writer였고, 이 successor revision은 #547 protected integration 뒤 생긴 live authority 변화만 이어받는다. 다른 feature lane이 과거 baseline blob을 포함하더라도 ordinary/non-force semantic convergence 때 current authority로 승계하지 않는다. ## Canonical product boundary @@ -18,55 +18,66 @@ Noema Core Domain은 **Agent Runtime**과 **Workflow / Task Execution**이다. * `contextual-orchestrator`는 provider/model discovery, routing, retry/failover, test-time compute와 provider credential을 소유한다. Noema는 released gateway contract와 canonical `orchestrator/free` alias를 소비할 뿐 direct provider SDK, provider key, provider/model/group fallback policy를 소유하지 않는다. `.github`는 organization reusable workflow와 control-plane source를 소유한다. `quarantine-sandbox-runtime`, Wardnet, EgressWeave, AppGuardrail은 isolation/security/outbound truth를 각자 소유한다. Keyverse는 identity backend owner다. `context-graph-contracts`와 `enterprise-architecture-core`는 released/versioned contract로만 연결하며 mutable sibling PR source, copied domain table, cross-service SQL은 runtime truth가 아니다. -Protected lineage의 #550은 PR-scoped supersession cancellation과 work-conserving dispatch를, #553은 automation threat-model documentation contract를, #542는 Durable Object state binding/routing과 durable state-store source를, #540은 current tooling/license source boundary를 통합했다. 이 네 lane은 active merge candidate가 아니다. 특히 #542 source integration은 runtime deployment·compatibility·transaction evidence까지 제조하지 않으며 #540 source integration은 release/publication rights까지 제조하지 않는다. +#550은 PR-scoped supersession cancellation과 work-conserving dispatch를 protected source에 통합했다. #535의 ordinary convergence는 이 protected work-conserving concurrency/admission을 보존한다. #542는 Durable Workflow / Task Execution과 State / Checkpoint의 atomic task claim, checkpoint CAS/replay, effect-start/terminal authority, cancellation/recovery 및 retained-provenance validation을 protected source로 만들었다. ADR 0013은 deployed Durable Object transaction/runtime 증거가 아직 없으므로 `Proposed`를 유지한다. #540은 historical Wrangler/Miniflare/Sharp/Libvips tooling path를 제거하고 pinned `workerd@1.20260625.1` + `esbuild@0.28.1`, canonical lock/license evidence와 patch-validator dependency pruning을 protected source에 통합했다. ## Active candidate convergence — 2026-09-08 KST ### Orchestrator/free consumer — PR #535 -PR #535 exact `e996b509f699c3f942ef81f0ac52b804b783cd19`는 Draft이며 construction snapshot protected main과 diverged 상태다. Hosted CI `34132537891`은 exact checkout과 package-manager setup 뒤 live pull-request base guard에서 실패했다. 이는 stale-ancestry RED다. 해당 head를 rerun하거나 guard를 약화하지 않는다. +PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a`는 Draft다. #547이 protected source가 된 뒤 이전 four-GREEN head를 그대로 전용하지 않고, protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`를 첫 parent, predecessor를 둘째 parent로 하는 ordinary/non-force semantic convergence를 수행했다. Fresh compare는 `behind_by=0`이고 merge-base가 current protected main과 일치한다. -Valid source delta는 merge-base `e6de53a1c2902cddc09e77a58efb82420cd8f5db` 이후 37개 path다. 다음 successor는 mutation 시점의 live protected main에서 시작해 protected work-conserving concurrency/admission, #542 durable workflow/state, `noema-core` Shared Kernel, #540 toolchain/license truth와 actionable failed-check/source-evidence behavior를 보존하면서 strict `orchestrator/free`, request-level ZDR/privacy, `timeout=None`, `max_retries=0`, gateway validation과 direct-provider/fallback rejection delta만 ordinary/non-force semantic convergence해야 한다. +Current exact delta는 strict `orchestrator/free`, request-level ZDR/privacy, reviewer `timeout=None`, `max_retries=0`, gateway validation, direct-provider/fallback rejection과 OpenCode tool-capability allowlisting을 소유한다. Provider/model discovery·routing·credential·retry/failover truth는 contextual-orchestrator owner에 남긴다. 새 source revision에는 application CI, reviewer-ci, required Security와 patch-validator-image의 wholly fresh generation이 생성됐고 마지막 관찰에서는 모두 queued/pending이었다. predecessor GREEN은 transfer하지 않는다. -Historical overlap path는 `.github/workflows/hourly-product-development.yml`, `docs/operations/hourly-product-development.md`, `test/documentation-architecture-contract.test.ts`, `test/helpers/hourly-workflow.ts`, `test/hourly-product-development-final-candidate-cleanup.test.ts`, `test/hourly-product-development-workflow.test.ts`다. Stale candidate의 zero-open-PR/scheduled semantics로 protected work-conserving source를 되돌리지 않는다. 특히 model-bearing proposer는 canonical `orchestrator/free`를 source-pin하고 repository-authored model inference timeout/retry를 두지 않되 current path-isolation/single-flight contract를 보존한다. +Next action은 unchanged exact head의 fresh four-GREEN, clean review authority와 current-base ancestry를 다시 확인한 뒤 normal merge하는 것이다. Check wait은 이 lane만 막는다. -### Exact-claim evidence receipts — issue #555 / PR #556 +### Patch-validator default-branch cache seed — issue #66 / PR #558 + +PR #558 exact `f2aa8570d952cc0a371da161e651472c080e00ce`는 Draft이며 protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6` 위에 ordinary/non-force convergence됐다. Effective diff는 `.github/workflows/patch-validator-image.yml`과 `test/patch-validator-image-build-cache.test.ts`뿐이다. -Observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305`는 live #535가 아닌 과거 feature-base snapshot 위에 있다. `live #556 must be re-fetched before integration`. Hosted CI `34089768682`의 live-base RED와 absent Security evidence 때문에 이 exact head는 non-authorizing이다. #535가 fresh exact-head four-GREEN으로 normally integrate된 뒤에만 protected main과 live #556을 다시 읽고 ordinary/non-force restack/retarget한다. +RCA는 동일한 `type=gha,scope=noema-patch-validator-image` 문자열만으로 sibling PR cache가 공유된다는 가정을 반증했다. 기존 workflow는 PR branch와 manual dispatch에서만 cache를 기록해 sibling PR이 default/base branch cache로 복구할 수 없었고, successive exact-head static Node builds가 반복해서 cold path를 탔다. #558은 protected `main` push에서 image-authority path가 바뀔 때만 full image verification을 실행해 default-branch BuildKit cache를 seed하도록 한다. `workflow_dispatch`, PR-scoped cancellation, stale-head refusal, pinned scanners/toolchain, static runtime checks, no-network/non-root smoke, SBOM/vulnerability receipts와 fail-closed verification은 유지한다. -#556이 소유하는 source contract는 producer-issued evidence receipt, exact repository/head/workflow/run/attempt identity, claim/evidence digest, evidence-kind separation, model-visible `[receipt:]` reference와 pre-publication admission이다. Source receipt는 execution/research authority가 아니다. Remaining boundary는 exact stdout/stderr handoff, trusted research producer, fresh Security 포함 exact-head gates, immutable Noema release, released central `.github#1641` consumer bump와 original corpus RED→GREEN이다. +첫 repaired PR은 default-branch seed가 아직 없으므로 cold build를 지불할 수 있다. Normal #558 merge는 workflow path 자체를 변경하므로 protected merge commit에서 push image run을 한 번 보장한다. 그 run이 protected-main operational acceptance와 cache seed를 모두 실제로 통과하는지 확인하고, 이후 별도 image-authority PR에서 cache restore 및 실제 build duration을 측정하기 전에는 성능 개선을 주장하지 않는다. + +### Exact-claim evidence receipts — issue #555 / PR #556 -### Cross-lane baseline — PR #547 +Observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305`는 현재 #535 feature-base보다 뒤처진 stale stacked head다. `live #556 must be re-fetched before integration`. Historical CI는 live-base guard에서 RED였고 required Security evidence가 없으므로 이 exact head는 non-authorizing이다. -PR #547은 이 문서와 executable documentation authority contract의 sole writer다. 이 revision은 #540을 active candidate로 잘못 남겨 둔 stale baseline을 수리하고 protected integration과 current open lane을 다시 분리한다. #547 자신의 future commit SHA나 merge commit SHA를 evergreen current authority로 문서에 고정하지 않는다. Exact source/head/check/review evidence는 merge 직전에 live-read한다. +#556이 소유하는 valid source contract는 producer-issued evidence receipt, exact repository/head/workflow/run/attempt identity, claim/evidence digest, evidence-kind separation, model-visible `[receipt:]` reference와 pre-publication admission이다. Source receipt는 execution/research authority가 아니다. #535가 normal integrate된 뒤 protected main과 live #556을 다시 읽고, historical baseline/source blob을 복사하지 않은 채 receipt/test/fixture/contract delta만 ordinary/non-force restack/retarget한다. Fresh Security 포함 exact-head gates가 필요하다. + +Remaining boundary는 exact stdout/stderr handoff, trusted research producer, immutable Noema release, released central `.github#1641` consumer bump와 original corpus RED→GREEN이다. ## Protected but incomplete commercial evidence ### Toolchain / inbound license — issue #531 / merged PR #540 -Merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`의 source remediation은 construction snapshot protected lineage에 이미 포함돼 있다. 따라서 더 이상 #540 merge를 buyer gap의 next action으로 요구하지 않는다. 남은 권위는 protected-source package/SBOM/provenance/reproducibility, NOTICE/attribution, actual released-artifact rights와 explicit owner/legal outbound-rights evidence다. Source-only license inventory나 PR-head image check를 release evidence로 승격하지 않는다. +Merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac` source remediation은 protected lineage에 포함돼 있다. 남은 권위는 protected-source package/SBOM/provenance/reproducibility, NOTICE/attribution, actual released-artifact rights와 explicit owner/legal outbound-rights evidence다. Source-only license inventory나 PR-head image check를 release evidence로 승격하지 않는다. ### Durable runtime operation — issue #541 / merged PR #542 Merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`는 durable workflow/state source를 protected lineage에 넣었다. 남은 권위는 실제 deployed Durable Object binding/transaction compatibility, recovery/rollback receipt, immutable release/package/SBOM/provenance/reproducibility다. ADR 0013은 이 evidence가 존재하기 전까지 `Proposed`다. +### Patch-validator publication — issue #66 + +#547 exact head의 current static runtime/image/SBOM/receipt verification은 protected integration 전 terminal success를 얻었지만 PR-head evidence다. Protected-main operational run, immutable image digest publication, signature/attestation, source/workflow/builder provenance, reproducibility, rollback과 activation evidence는 아직 없다. GitHub release collection도 비어 있으므로 source integration을 release로 간주하지 않는다. + ## Current authority table | Lane | Authority | Integration / completion condition | | --- | --- | --- | -| Protected source | live protected `main`; #547 construction snapshot used protected `main@099d7d89a51bca4a2cf7c6b285b50ffadd08d001`; merged #536/#548/#550/#553/#542/#540 | Current exact protected head is live-read before every mutation, merge and release. Construction SHA is historical evidence, not evergreen current-main identity. | -| Central workflow trust | moving central main is live-read; construction snapshot central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`; reviewed Noema consumer pin `c9052e607e5f3cc76e73207e7786b21500721b79` | Moving foreign head and immutable reviewed pin stay distinct. | -| Toolchain/license source | merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac` | Source complete; #531 remains open for protected release/publication/rights evidence. | -| Durable workflow/state source | merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc` | Source complete; #541 remains open for deployed runtime/recovery/release evidence. | -| Orchestrator/free consumer | PR #535 exact `e996b509f699c3f942ef81f0ac52b804b783cd19` | Live-base RED; semantic convergence onto live protected main before fresh four-GREEN. | -| Exact-claim receipts | observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305` | Wait for #535 normal integration, then live-read/restack and fresh Security-inclusive evidence. | -| Cross-lane baseline | PR #547 | Sole writer; docs/contracts change together and require wholly fresh exact-head evidence. | +| Protected source | live protected `main`; current observation protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`; historical #547 construction snapshot protected `main@099d7d89a51bca4a2cf7c6b285b50ffadd08d001` | Exact protected head는 mutation·merge·release 직전에 live-read한다. | +| Central workflow trust | moving central main은 live-read; observed central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`; reviewed Noema pin `c9052e607e5f3cc76e73207e7786b21500721b79` | Moving foreign head와 immutable reviewed pin을 분리한다. | +| Toolchain/license source | merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac` | Source complete; #531은 release/publication/rights evidence 때문에 open이다. | +| Durable workflow/state source | merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc` | Source complete; #541은 deployed runtime/recovery/release evidence 때문에 open이다. | +| Documentation authority | merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6` + this post-integration successor | #547는 protected history다. Moving PR truth는 successor에서 code-current하게 갱신한다. | +| Orchestrator/free consumer | PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a` | Fresh exact-head four-GREEN + clean review + current ancestry 후 normal merge. | +| Patch-validator cache seed | PR #558 exact `f2aa8570d952cc0a371da161e651472c080e00ce` | Fresh four-GREEN 후 normal merge; protected-main push image run과 cache seed를 별도 검증. | +| Exact-claim receipts | observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305` | #535 normal merge 뒤 live-read/restack, fresh Security-inclusive evidence와 immutable release. | ## Evidence semantics and merge rules A PR can be review-clean while non-authorizing. Review thread resolution, CI, reviewer-ci, required Security Scan, image/SBOM/provenance and branch ancestry are separate evidence classes. Every source mutation or restack invalidates predecessor workflow evidence. `queued`, `pending`, `in_progress`, `skipped`, `cancelled`, stale or absent-required evidence is not passing. -Normal merge requires unchanged exact head, independently refreshed live base/head, no valid unresolved review finding, applicable required terminal-success gates and no foreign-owner/protected-contract regression. Concurrent commits or pushes are not called a race merely because they occur. Wrong base/conflict, stale ADR identity, mutable dependency, missing fixture/contract or single-writer violation is repaired by ordinary/non-force convergence rather than force push, destructive rebase or casual Close. +Normal merge requires unchanged exact head, independently refreshed live base/head, no valid unresolved review finding, applicable required terminal-success gates and no foreign-owner/protected-contract regression. Concurrent commits or pushes are not called a race merely because they occur. Wrong base/conflict, stale ADR identity, mutable dependency, missing fixture/contract or single-writer violation is repaired by ordinary/non-force semantic convergence rather than force push, destructive rebase or casual Close. PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge 또는 verified successor가 모든 유효 delta/test/fixture/contract/evidence를 완전히 승계한 경우에만 사라진다. Blocked lane은 자기 lane만 막고 unrelated safe review, owner-path repair, docs-to-code repair와 buyer-gap work는 계속한다. @@ -74,16 +85,16 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge | Priority | Gap | Buyer/operator impact | Current owner | Authoritative completion evidence | Next executable action | | --- | --- | --- | --- | --- | --- | -| P0 | Strict orchestrator/free consumer | Noema가 provider/model routing authority를 복제하면 제품 경계와 운영 책임이 흐려진다. | PR #535 | Live protected main 위 semantic convergence + fresh exact-head CI/reviewer/Security/image + normal merge | #547가 stable protected ancestry를 만들면 stale head를 rerun하지 말고 37-path valid delta와 six protected-overlap path를 semantic union한다. | -| P0 | Exact-claim evidence supply chain | 외부 tool claim이 authenticated producer evidence 없이 reviewer authority로 승격될 수 있다. | issue #555 / PR #556 | #535 merge 후 current-main restack, execution/research producers, immutable release, released central consumer bump, original hosted corpus GREEN | #535 protected integration 전에는 #556을 움직이지 않는다. | -| P0 | Toolchain/license release evidence | Source dependency remediation만으로 구매자에게 실제 배포 artifact 권리와 재현성을 증명할 수 없다. | issue #531 / merged PR #540 | Protected exact release의 package/image/SBOM/provenance/reproducibility/NOTICE/rights evidence | Release-ready protected exact head가 존재할 때만 immutable publication evidence를 만든다. | -| P0 | Reviewer/Maintainer production identity | Source-only controls로 App installation, key custody/rotation, bounded publication authority를 증명할 수 없다. | issues #29 / #227 | Live installation/permissions/key-custody/rotation 및 bounded publication/recovery receipts | 승인된 control-plane preflight를 실행하고 source evidence와 분리 보존한다. | +| P0 | Strict orchestrator/free consumer | Noema가 provider/model routing authority를 복제하면 제품 경계와 운영 책임이 흐려진다. | PR #535 | Fresh exact-head CI/reviewer/Security/image + normal merge | Current exact generation을 관찰하고 실패 시 causal repair; GREEN이면 current-base/review 재검증 후 normal merge. | +| P0 | Exact-claim evidence supply chain | Tool claim이 authenticated producer evidence 없이 reviewer authority로 승격될 수 있다. | issue #555 / PR #556 | #535 merge 후 current-main restack, execution/research producers, immutable release, released central consumer bump, original hosted corpus GREEN | #535 protected integration 전에는 #556을 움직이지 않는다. | +| P0 | Patch-validator operational publication | PR-head image success만으로 protected operation, reusable cache, immutable activation을 증명할 수 없다. | issue #66 / PR #558 | #558 merge + protected-main exact image run/cache seed + immutable image/signature/SBOM/provenance/reproducibility/rollback | #558 exact gates를 통과시키고 normal merge한 뒤 protected-main push run과 cache restore를 실측한다. | +| P0 | Toolchain/license release evidence | Source dependency remediation만으로 실제 배포 artifact 권리와 재현성을 증명할 수 없다. | issue #531 / merged PR #540 | Protected exact release package/image/SBOM/provenance/reproducibility/NOTICE/rights evidence | Release-ready protected exact head가 있을 때만 immutable publication evidence를 만든다. | +| P0 | Reviewer/Maintainer production identity | Source-only controls로 App installation, key custody/rotation, bounded publication authority를 증명할 수 없다. | issues #29 / #227 | Live installation/permissions/key-custody/rotation 및 bounded publication/recovery receipts | 승인된 control-plane preflight에서 source evidence와 분리 보존한다. | | P0 | Governance enforceability | Required workflow source만으로 실제 approval/deletion/rewrite/break-glass 정책을 모두 증명할 수 없다. | issue #27 | Live ruleset/protection audit와 observed required-workflow behavior | protected mutation 직전 live governance를 다시 읽고 owner control에서만 수정한다. | -| P0 | Patch-validator publication | PR-head image success와 protected source만으로 immutable artifact activation을 증명할 수 없다. | issue #66 | Protected-main operational run + immutable image/signature/SBOM/provenance/reproducibility/rollback | Protected exact head에서 operational acceptance를 실행할 수 있는 authorized dispatch surface가 있을 때만 publication을 진행한다. | -| P1 | Durable runtime operation | Source-level durable semantics와 실제 deployed transaction/recovery는 다른 evidence class다. | issue #541 | Deployed Durable Object compatibility + recovery/rollback + immutable release identity | 승인된 runtime deployment evidence가 없으면 ADR 0013 `Proposed`를 유지한다. | +| P1 | Durable runtime operation | Source-level durable semantics와 실제 deployed transaction/recovery는 다른 evidence class다. | issue #541 | Deployed Durable Object compatibility + recovery/rollback + immutable release identity | 승인된 runtime evidence가 없으면 ADR 0013 `Proposed`를 유지한다. | | P1 | Production KPI evidence | Fixture는 reliability, latency, commercial production operation을 입증하지 못한다. | issue #3 | Authenticated retained production KPI window with source/run identity and falsifiable denominator | 승인된 production source가 없으면 fail closed를 유지한다. | | P1 | Acquisition transfer | Apache-2.0 source grant는 contributor ownership, assignment, artifact-transfer rights 자체를 증명하지 않는다. | issue #5 | Exact-release rights metadata, dependency/NOTICE/SBOM, contributor/IP and transfer evidence | Immutable release 이후 acquisition evidence를 해당 권위에서 수집한다. | ## Completion discipline -각 gap은 표의 Authoritative completion evidence가 실제로 존재하고 current source/head에 결합될 때만 닫는다. 문서 존재, synthetic fixture, model judgement, stale workflow result를 완료 증거로 사용하지 않는다. Release-ready exact protected head가 없으면 version/tag/package/SBOM/provenance/rollback을 임의로 제조하지 않는다. +각 gap은 Authoritative completion evidence가 실제로 존재하고 current source/head에 결합될 때만 닫는다. 문서 존재, synthetic fixture, model judgement, stale workflow result를 완료 증거로 사용하지 않는다. Release-ready exact protected head가 없으면 version/tag/package/SBOM/provenance/rollback을 제조하지 않는다. From 6b1e66451c2f9201b448572907768a80f5789ba9 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 09:31:24 +0900 Subject: [PATCH 04/68] test: advance patch-validator candidate authority --- test/documentation-live-open-pr-authority.test.ts | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index d40f697bb..59d46a209 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -7,7 +7,7 @@ describe("product-technical gap baseline live open-PR authority", () => { expect(baseline).toContain("protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`"); expect(baseline).toContain("PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a`"); - expect(baseline).toContain("PR #558 exact `f2aa8570d952cc0a371da161e651472c080e00ce`"); + expect(baseline).toContain("PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`"); expect(baseline).toContain("merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`"); expect(baseline).toContain("merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`"); expect(baseline).toContain("observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305`"); @@ -16,7 +16,8 @@ describe("product-technical gap baseline live open-PR authority", () => { expect(baseline).not.toContain("PR #535 exact `e996b509f699c3f942ef81f0ac52b804b783cd19`"); expect(baseline).not.toContain("PR #535 exact `59205b5ae333a1f2b5e6b2112bf059592ba492c9`"); expect(baseline).not.toContain("PR #535 exact `4ad6907ae9f97b202a32a9b5e170f275ac9129b9`"); + expect(baseline).not.toContain("PR #558 exact `f2aa8570d952cc0a371da161e651472c080e00ce`"); expect(baseline).not.toContain("PR #540은 아직 merge authority가 아니다"); expect(baseline).not.toContain("PR #547은 이 문서와 executable documentation authority contract의 sole writer다"); }); -}); +}); \ No newline at end of file From b7de38bae54dc8e6695fa0c9f2ab7c2f757b7f22 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 09:31:50 +0900 Subject: [PATCH 05/68] test: reject superseded patch-validator candidate --- .../product-technical-gap-current-candidate-contract.test.ts | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index a5c6a5df8..cfd55de72 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -9,7 +9,7 @@ describe("product technical gap current candidate authority", () => { "protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`", "central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`", "PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a`", - "PR #558 exact `f2aa8570d952cc0a371da161e651472c080e00ce`", + "PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`", "merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`", "merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`", "observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305`", @@ -27,6 +27,7 @@ describe("product technical gap current candidate authority", () => { "protected `main@e6de53a1c2902cddc09e77a58efb82420cd8f5db`", "PR #535 exact `e996b509f699c3f942ef81f0ac52b804b783cd19`", "PR #535 exact `4ad6907ae9f97b202a32a9b5e170f275ac9129b9`", + "PR #558 exact `f2aa8570d952cc0a371da161e651472c080e00ce`", "PR #542 exact `195fdd70b267332f246d93beb95fa96fabade52e`", "PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`도 protected", "PR #553 exact `c03d946f52faf65b1f9b75c3c601fed106ffcbd0`", @@ -36,4 +37,4 @@ describe("product technical gap current candidate authority", () => { expect(baseline).not.toContain(staleTruth); } }); -}); +}); \ No newline at end of file From 49ca12da66c2eb1cf103851170cfb5fc74aa705d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 09:33:12 +0900 Subject: [PATCH 06/68] docs: refresh patch-validator exact authority --- docs/product-technical-gap-baseline.md | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 8b0565834..4e7bceaf0 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -26,16 +26,18 @@ Noema Core Domain은 **Agent Runtime**과 **Workflow / Task Execution**이다. * PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a`는 Draft다. #547이 protected source가 된 뒤 이전 four-GREEN head를 그대로 전용하지 않고, protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`를 첫 parent, predecessor를 둘째 parent로 하는 ordinary/non-force semantic convergence를 수행했다. Fresh compare는 `behind_by=0`이고 merge-base가 current protected main과 일치한다. -Current exact delta는 strict `orchestrator/free`, request-level ZDR/privacy, reviewer `timeout=None`, `max_retries=0`, gateway validation, direct-provider/fallback rejection과 OpenCode tool-capability allowlisting을 소유한다. Provider/model discovery·routing·credential·retry/failover truth는 contextual-orchestrator owner에 남긴다. 새 source revision에는 application CI, reviewer-ci, required Security와 patch-validator-image의 wholly fresh generation이 생성됐고 마지막 관찰에서는 모두 queued/pending이었다. predecessor GREEN은 transfer하지 않는다. +Current exact delta는 strict `orchestrator/free`, request-level ZDR/privacy, reviewer `timeout=None`, `max_retries=0`, gateway validation, direct-provider/fallback rejection과 OpenCode tool-capability allowlisting을 소유한다. Provider/model discovery·routing·credential·retry/failover truth는 contextual-orchestrator owner에 남긴다. 마지막 관찰에서 application CI와 reviewer-ci는 terminal success, required Security는 queued, patch-validator-image는 in progress였다. predecessor GREEN은 transfer하지 않는다. Next action은 unchanged exact head의 fresh four-GREEN, clean review authority와 current-base ancestry를 다시 확인한 뒤 normal merge하는 것이다. Check wait은 이 lane만 막는다. ### Patch-validator default-branch cache seed — issue #66 / PR #558 -PR #558 exact `f2aa8570d952cc0a371da161e651472c080e00ce`는 Draft이며 protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6` 위에 ordinary/non-force convergence됐다. Effective diff는 `.github/workflows/patch-validator-image.yml`과 `test/patch-validator-image-build-cache.test.ts`뿐이다. +PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`는 Draft이며 protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6` 위에 ordinary/non-force convergence된 `f2aa8570...`에서 test-only causal repair로 정상 전진했다. Fresh compare는 `behind_by=0`, merge-base exact protected main이며 effective diff는 `.github/workflows/patch-validator-image.yml`, `test/patch-validator-image-build-cache.test.ts`, `test/patch-validator-workflow.test.ts` 세 경로다. RCA는 동일한 `type=gha,scope=noema-patch-validator-image` 문자열만으로 sibling PR cache가 공유된다는 가정을 반증했다. 기존 workflow는 PR branch와 manual dispatch에서만 cache를 기록해 sibling PR이 default/base branch cache로 복구할 수 없었고, successive exact-head static Node builds가 반복해서 cold path를 탔다. #558은 protected `main` push에서 image-authority path가 바뀔 때만 full image verification을 실행해 default-branch BuildKit cache를 seed하도록 한다. `workflow_dispatch`, PR-scoped cancellation, stale-head refusal, pinned scanners/toolchain, static runtime checks, no-network/non-root smoke, SBOM/vulnerability receipts와 fail-closed verification은 유지한다. +Converged predecessor `f2aa8570...`의 hosted CI `34172635652`는 exact checkout/live-base/lockfile/install/typecheck 뒤 release tests에서 현실 RED를 냈다. 원인은 기존 `patch-validator-workflow` contract가 unfiltered `pull_request:`를 검증한다는 명목으로 `workflow_dispatch:`와의 직접 인접성을 요구해, 별도 sibling `push:` trigger를 잘못 거부한 것이었다. Current `2f91bf8...`은 다음 non-empty event line이 같은 YAML indentation의 trigger임을 요구하도록 테스트를 일반화해 unfiltered PR invariant를 유지하면서 protected-main seed trigger를 허용한다. Production workflow·permission·security/publication boundary는 바꾸지 않았다. 새 exact head에는 application CI `34173491056`, reviewer-ci `34173491034`, required Security `34173491124`, patch-validator-image `34173491077`의 wholly fresh generation이 생겼고 마지막 관찰에서는 queued/pending이었다. predecessor GREEN은 transfer하지 않는다. + 첫 repaired PR은 default-branch seed가 아직 없으므로 cold build를 지불할 수 있다. Normal #558 merge는 workflow path 자체를 변경하므로 protected merge commit에서 push image run을 한 번 보장한다. 그 run이 protected-main operational acceptance와 cache seed를 모두 실제로 통과하는지 확인하고, 이후 별도 image-authority PR에서 cache restore 및 실제 build duration을 측정하기 전에는 성능 개선을 주장하지 않는다. ### Exact-claim evidence receipts — issue #555 / PR #556 @@ -70,7 +72,7 @@ Merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`는 durable workf | Durable workflow/state source | merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc` | Source complete; #541은 deployed runtime/recovery/release evidence 때문에 open이다. | | Documentation authority | merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6` + this post-integration successor | #547는 protected history다. Moving PR truth는 successor에서 code-current하게 갱신한다. | | Orchestrator/free consumer | PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a` | Fresh exact-head four-GREEN + clean review + current ancestry 후 normal merge. | -| Patch-validator cache seed | PR #558 exact `f2aa8570d952cc0a371da161e651472c080e00ce` | Fresh four-GREEN 후 normal merge; protected-main push image run과 cache seed를 별도 검증. | +| Patch-validator cache seed | PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295` | Fresh four-GREEN 후 normal merge; protected-main push image run과 cache seed를 별도 검증. | | Exact-claim receipts | observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305` | #535 normal merge 뒤 live-read/restack, fresh Security-inclusive evidence와 immutable release. | ## Evidence semantics and merge rules @@ -97,4 +99,4 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge ## Completion discipline -각 gap은 Authoritative completion evidence가 실제로 존재하고 current source/head에 결합될 때만 닫는다. 문서 존재, synthetic fixture, model judgement, stale workflow result를 완료 증거로 사용하지 않는다. Release-ready exact protected head가 없으면 version/tag/package/SBOM/provenance/rollback을 제조하지 않는다. +각 gap은 Authoritative completion evidence가 실제로 존재하고 current source/head에 결합될 때만 닫는다. 문서 존재, synthetic fixture, model judgement, stale workflow result를 완료 증거로 사용하지 않는다. Release-ready exact protected head가 없으면 version/tag/package/SBOM/provenance/rollback을 제조하지 않는다. \ No newline at end of file From 1430f8b01f1176082d589e1c9e76746b3b517979 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 10:51:00 +0900 Subject: [PATCH 07/68] test: require current #535 commercial authority --- test/documentation-live-open-pr-authority.test.ts | 3 ++- test/product-technical-gap-current-candidate-contract.test.ts | 3 ++- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index 59d46a209..997ae33c8 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -6,13 +6,14 @@ describe("product-technical gap baseline live open-PR authority", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); expect(baseline).toContain("protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`"); - expect(baseline).toContain("PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a`"); + expect(baseline).toContain("PR #535 exact `06ed62fcc5611e9b25ef38b06e87e7521dbf1be1`"); expect(baseline).toContain("PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`"); expect(baseline).toContain("merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`"); expect(baseline).toContain("merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`"); expect(baseline).toContain("observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305`"); expect(baseline).toContain("live #556 must be re-fetched before integration"); expect(baseline).toContain("issue #555 / PR #556"); + expect(baseline).not.toContain("PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a`"); expect(baseline).not.toContain("PR #535 exact `e996b509f699c3f942ef81f0ac52b804b783cd19`"); expect(baseline).not.toContain("PR #535 exact `59205b5ae333a1f2b5e6b2112bf059592ba492c9`"); expect(baseline).not.toContain("PR #535 exact `4ad6907ae9f97b202a32a9b5e170f275ac9129b9`"); diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index cfd55de72..e02390dd6 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -8,7 +8,7 @@ describe("product technical gap current candidate authority", () => { for (const currentTruth of [ "protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`", "central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`", - "PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a`", + "PR #535 exact `06ed62fcc5611e9b25ef38b06e87e7521dbf1be1`", "PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`", "merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`", "merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`", @@ -25,6 +25,7 @@ describe("product technical gap current candidate authority", () => { for (const staleTruth of [ "protected `main@d6394b2aa73e6fc57fccdad74ea38ad87f79e7f8`", "protected `main@e6de53a1c2902cddc09e77a58efb82420cd8f5db`", + "PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a`", "PR #535 exact `e996b509f699c3f942ef81f0ac52b804b783cd19`", "PR #535 exact `4ad6907ae9f97b202a32a9b5e170f275ac9129b9`", "PR #558 exact `f2aa8570d952cc0a371da161e651472c080e00ce`", From 56000ad6a5eea8c60fea3155d56d5267e81ee2a2 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 11:06:28 +0900 Subject: [PATCH 08/68] docs: repair current commercial authority after hosted RED --- docs/product-technical-gap-baseline.md | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 4e7bceaf0..159bf7632 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -24,11 +24,11 @@ Noema Core Domain은 **Agent Runtime**과 **Workflow / Task Execution**이다. * ### Orchestrator/free consumer — PR #535 -PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a`는 Draft다. #547이 protected source가 된 뒤 이전 four-GREEN head를 그대로 전용하지 않고, protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`를 첫 parent, predecessor를 둘째 parent로 하는 ordinary/non-force semantic convergence를 수행했다. Fresh compare는 `behind_by=0`이고 merge-base가 current protected main과 일치한다. +PR #535 exact `06ed62fcc5611e9b25ef38b06e87e7521dbf1be1`는 Draft다. #547이 protected source가 된 뒤 이전 four-GREEN head를 그대로 전용하지 않고 protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`를 첫 parent로 ordinary/non-force semantic convergence한 뒤, hosted CI가 stale procedure 문서의 global-empty-PR admission 가정을 현실 RED로 드러냈다. Test-only `f1bca1b44bc9b1cf5f67c200380aaeed8c67bb2f`의 application CI `34177131397`은 exact checkout, live-base guard, lockfile control, install, typecheck를 통과하고 release tests에서 1 failed / 4140 passed로 실패했다. -Current exact delta는 strict `orchestrator/free`, request-level ZDR/privacy, reviewer `timeout=None`, `max_retries=0`, gateway validation, direct-provider/fallback rejection과 OpenCode tool-capability allowlisting을 소유한다. Provider/model discovery·routing·credential·retry/failover truth는 contextual-orchestrator owner에 남긴다. 마지막 관찰에서 application CI와 reviewer-ci는 terminal success, required Security는 queued, patch-validator-image는 in progress였다. predecessor GREEN은 transfer하지 않는다. +Current `06ed62f...`는 두 procedure 문서만 protected work-conserving admission으로 수리한다. strict `orchestrator/free`, request-level ZDR/privacy, reviewer `timeout=None`, `max_retries=0`, gateway validation, direct-provider/fallback rejection과 OpenCode tool-capability allowlisting을 유지하며 provider/model discovery·routing·credential·retry/failover truth는 contextual-orchestrator owner에 남긴다. Fresh compare는 `behind_by=0`이고 merge-base가 current protected main과 일치한다. -Next action은 unchanged exact head의 fresh four-GREEN, clean review authority와 current-base ancestry를 다시 확인한 뒤 normal merge하는 것이다. Check wait은 이 lane만 막는다. +현재 exact generation은 application CI `34177518778`, reviewer-ci `34177518813`, required Security Scan `34177518804`가 terminal success이고 patch-validator-image `34177518809`가 in progress다. Three GREEN은 four-GREEN이 아니며 predecessor GREEN은 transfer하지 않는다. Next action은 unchanged exact head의 terminal image success, clean fresh review authority와 current-base ancestry를 다시 확인한 뒤 normal merge하는 것이다. ### Patch-validator default-branch cache seed — issue #66 / PR #558 @@ -36,9 +36,9 @@ PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`는 Draft이며 protecte RCA는 동일한 `type=gha,scope=noema-patch-validator-image` 문자열만으로 sibling PR cache가 공유된다는 가정을 반증했다. 기존 workflow는 PR branch와 manual dispatch에서만 cache를 기록해 sibling PR이 default/base branch cache로 복구할 수 없었고, successive exact-head static Node builds가 반복해서 cold path를 탔다. #558은 protected `main` push에서 image-authority path가 바뀔 때만 full image verification을 실행해 default-branch BuildKit cache를 seed하도록 한다. `workflow_dispatch`, PR-scoped cancellation, stale-head refusal, pinned scanners/toolchain, static runtime checks, no-network/non-root smoke, SBOM/vulnerability receipts와 fail-closed verification은 유지한다. -Converged predecessor `f2aa8570...`의 hosted CI `34172635652`는 exact checkout/live-base/lockfile/install/typecheck 뒤 release tests에서 현실 RED를 냈다. 원인은 기존 `patch-validator-workflow` contract가 unfiltered `pull_request:`를 검증한다는 명목으로 `workflow_dispatch:`와의 직접 인접성을 요구해, 별도 sibling `push:` trigger를 잘못 거부한 것이었다. Current `2f91bf8...`은 다음 non-empty event line이 같은 YAML indentation의 trigger임을 요구하도록 테스트를 일반화해 unfiltered PR invariant를 유지하면서 protected-main seed trigger를 허용한다. Production workflow·permission·security/publication boundary는 바꾸지 않았다. 새 exact head에는 application CI `34173491056`, reviewer-ci `34173491034`, required Security `34173491124`, patch-validator-image `34173491077`의 wholly fresh generation이 생겼고 마지막 관찰에서는 queued/pending이었다. predecessor GREEN은 transfer하지 않는다. +Converged predecessor `f2aa8570...`의 hosted CI `34172635652`는 exact checkout/live-base/lockfile/install/typecheck 뒤 release tests에서 현실 RED를 냈다. 원인은 기존 `patch-validator-workflow` contract가 unfiltered `pull_request:`를 검증한다는 명목으로 `workflow_dispatch:`와의 직접 인접성을 요구해 별도 sibling `push:` trigger를 잘못 거부한 것이었다. Current `2f91bf8...`은 다음 non-empty event line이 같은 YAML indentation의 trigger임을 요구하도록 테스트를 일반화해 unfiltered PR invariant를 유지하면서 protected-main seed trigger를 허용한다. Production workflow·permission·security/publication boundary는 바꾸지 않았다. -첫 repaired PR은 default-branch seed가 아직 없으므로 cold build를 지불할 수 있다. Normal #558 merge는 workflow path 자체를 변경하므로 protected merge commit에서 push image run을 한 번 보장한다. 그 run이 protected-main operational acceptance와 cache seed를 모두 실제로 통과하는지 확인하고, 이후 별도 image-authority PR에서 cache restore 및 실제 build duration을 측정하기 전에는 성능 개선을 주장하지 않는다. +현재 exact generation은 application CI `34173491056`, reviewer-ci `34173491034`, required Security Scan `34173491124`가 terminal success이고 patch-validator-image `34173491077`가 in progress다. 첫 repaired PR은 default-branch seed가 아직 없으므로 cold build를 지불할 수 있다. Normal #558 merge는 workflow path 자체를 변경하므로 protected merge commit에서 push image run을 한 번 보장한다. 그 run이 protected-main operational acceptance와 cache seed를 모두 실제로 통과하는지 확인하고, 이후 별도 image-authority PR에서 cache restore 및 실제 build duration을 측정하기 전에는 성능 개선을 주장하지 않는다. ### Exact-claim evidence receipts — issue #555 / PR #556 @@ -71,7 +71,7 @@ Merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`는 durable workf | Toolchain/license source | merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac` | Source complete; #531은 release/publication/rights evidence 때문에 open이다. | | Durable workflow/state source | merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc` | Source complete; #541은 deployed runtime/recovery/release evidence 때문에 open이다. | | Documentation authority | merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6` + this post-integration successor | #547는 protected history다. Moving PR truth는 successor에서 code-current하게 갱신한다. | -| Orchestrator/free consumer | PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a` | Fresh exact-head four-GREEN + clean review + current ancestry 후 normal merge. | +| Orchestrator/free consumer | PR #535 exact `06ed62fcc5611e9b25ef38b06e87e7521dbf1be1` | Fresh exact-head four-GREEN + clean review + current ancestry 후 normal merge. | | Patch-validator cache seed | PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295` | Fresh four-GREEN 후 normal merge; protected-main push image run과 cache seed를 별도 검증. | | Exact-claim receipts | observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305` | #535 normal merge 뒤 live-read/restack, fresh Security-inclusive evidence와 immutable release. | From 75270e641eed3d73dc93c138eed2392980505857 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 11:46:05 +0900 Subject: [PATCH 09/68] test(docs): require live post-558 commercial authority Require the documentation lane to reflect protected #558 integration, the newly converged #535 exact head, and the newly observed #556 stacked head before production baseline text is repaired. --- ...documentation-live-open-pr-authority.test.ts | 14 ++++++-------- ...nical-gap-current-candidate-contract.test.ts | 17 +++++++---------- 2 files changed, 13 insertions(+), 18 deletions(-) diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index 997ae33c8..751b07ba7 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -5,20 +5,18 @@ describe("product-technical gap baseline live open-PR authority", () => { it("separates active source lanes from integrated protected history and observation-scoped downstream heads", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); - expect(baseline).toContain("protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`"); - expect(baseline).toContain("PR #535 exact `06ed62fcc5611e9b25ef38b06e87e7521dbf1be1`"); - expect(baseline).toContain("PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`"); + expect(baseline).toContain("protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd`"); + expect(baseline).toContain("PR #535 exact `551d81da28b0c03ca44deedf60e95125dcceb81b`"); + expect(baseline).toContain("merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`"); expect(baseline).toContain("merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`"); expect(baseline).toContain("merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`"); - expect(baseline).toContain("observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305`"); + expect(baseline).toContain("observed PR #556 exact `9d6d52c1dd4fc88203a832b509f4ec28cef3c68a`"); expect(baseline).toContain("live #556 must be re-fetched before integration"); expect(baseline).toContain("issue #555 / PR #556"); + expect(baseline).not.toContain("PR #535 exact `06ed62fcc5611e9b25ef38b06e87e7521dbf1be1`"); expect(baseline).not.toContain("PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a`"); expect(baseline).not.toContain("PR #535 exact `e996b509f699c3f942ef81f0ac52b804b783cd19`"); - expect(baseline).not.toContain("PR #535 exact `59205b5ae333a1f2b5e6b2112bf059592ba492c9`"); - expect(baseline).not.toContain("PR #535 exact `4ad6907ae9f97b202a32a9b5e170f275ac9129b9`"); expect(baseline).not.toContain("PR #558 exact `f2aa8570d952cc0a371da161e651472c080e00ce`"); - expect(baseline).not.toContain("PR #540은 아직 merge authority가 아니다"); - expect(baseline).not.toContain("PR #547은 이 문서와 executable documentation authority contract의 sole writer다"); + expect(baseline).not.toContain("observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305`"); }); }); \ No newline at end of file diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index e02390dd6..30bdfab17 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -6,13 +6,13 @@ describe("product technical gap current candidate authority", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); for (const currentTruth of [ - "protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`", + "protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd`", "central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`", - "PR #535 exact `06ed62fcc5611e9b25ef38b06e87e7521dbf1be1`", - "PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`", + "PR #535 exact `551d81da28b0c03ca44deedf60e95125dcceb81b`", + "merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`", "merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`", "merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`", - "observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305`", + "observed PR #556 exact `9d6d52c1dd4fc88203a832b509f4ec28cef3c68a`", "merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`", "merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`", "merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`", @@ -23,17 +23,14 @@ describe("product technical gap current candidate authority", () => { expect(baseline).toContain("predecessor GREEN"); for (const staleTruth of [ + "protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`", "protected `main@d6394b2aa73e6fc57fccdad74ea38ad87f79e7f8`", - "protected `main@e6de53a1c2902cddc09e77a58efb82420cd8f5db`", + "PR #535 exact `06ed62fcc5611e9b25ef38b06e87e7521dbf1be1`", "PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a`", "PR #535 exact `e996b509f699c3f942ef81f0ac52b804b783cd19`", - "PR #535 exact `4ad6907ae9f97b202a32a9b5e170f275ac9129b9`", "PR #558 exact `f2aa8570d952cc0a371da161e651472c080e00ce`", - "PR #542 exact `195fdd70b267332f246d93beb95fa96fabade52e`", - "PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`도 protected", - "PR #553 exact `c03d946f52faf65b1f9b75c3c601fed106ffcbd0`", + "observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305`", "PR #540은 아직 merge authority가 아니다", - "patch-validator-image 34155490034", ]) { expect(baseline).not.toContain(staleTruth); } From 3f4b9a107bf30c4c79ed840925e0badec1c28574 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 11:51:39 +0900 Subject: [PATCH 10/68] docs(gap): repair post-558 live commercial authority Bring #559's owned baseline in line with protected #558 integration, exact #535 convergence, and the newly observed #556 stack while preserving canonical owner boundaries and release-evidence discipline. --- docs/product-technical-gap-baseline.md | 84 +++++++++++++------------- 1 file changed, 41 insertions(+), 43 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 159bf7632..167137547 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,78 +2,76 @@ ## Authority and update rule -이 문서는 Noema의 protected truth, active candidate, transient workflow evidence와 foreign-owner authority를 분리한다. Open PR exact head, protected base, required workflow, review thread, release와 central dependency는 mutation·merge·release 직전에 다시 읽는다. predecessor GREEN, queued/skipped/cancelled run, 오래된 PR base snapshot과 scanner/model judgement는 다음 revision의 merge authority로 전용하지 않는다. +이 문서는 protected source, active candidate, transient workflow evidence와 foreign-owner authority를 분리한다. Open PR exact head, protected base, required workflow, review thread, release와 central dependency는 mutation·merge·release 직전에 다시 읽는다. predecessor GREEN, queued/pending/in-progress/skipped/cancelled run, 오래된 PR base snapshot과 scanner/model judgement는 다음 revision의 merge authority로 전용하지 않는다. -Current protected source는 GitHub-verified protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`이며 merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`의 documentation-authority delta를 포함한다. Current protected source identity는 mutation·merge·release 직전에 live-read한다. 이 SHA도 future merge 뒤의 evergreen current-main identity로 취급하지 않는다. +Current protected source는 GitHub-verified protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd`다. 이 protected revision에는 normal #558 merge와 merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`의 patch-validator default-branch cache-seed contract가 포함돼 있다. Current source SHA는 moving observation이며 future merge 뒤 evergreen identity로 취급하지 않는다. -Construction snapshot 이력은 protected `main@099d7d89a51bca4a2cf7c6b285b50ffadd08d001`에서 #547을 수렴시킨 시점을 보존한다. 그 ancestry에는 merged PR #536 exact `4fe6fe84611dfa1d69d8e0712b72b278429524d0`, merged PR #548 exact `fb44888bd571cae61dbfc93c1b46675855fbfc9c`, merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`, merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`, merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`, merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`가 포함돼 있다. Construction snapshot은 역사 증거이며 moving protected head를 고정하는 장치가 아니다. +이 revision 작성 시 moving central control-plane snapshot은 central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`다. Noema runtime의 reviewed immutable central consumer pin은 `c9052e607e5f3cc76e73207e7786b21500721b79`이고 runtime authority 표현은 `ALLOWED_WORKFLOW_SHA = c9052e607e5f3cc76e73207e7786b21500721b79`다. Moving foreign head와 reviewed immutable pin을 같은 권위로 취급하지 않는다. -이 revision 작성 시 마지막으로 관찰한 moving central control-plane snapshot은 central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`다. Noema protected runtime의 reviewed immutable consumer pin은 `c9052e607e5f3cc76e73207e7786b21500721b79`이며 runtime authority 표현은 `ALLOWED_WORKFLOW_SHA = c9052e607e5f3cc76e73207e7786b21500721b79`다. Moving central main과 reviewed immutable consumer source identity를 같은 권위로 취급하지 않는다. +Merged documentation history에는 merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`가 있고, toolchain history에는 merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`, durable workflow/state history에는 merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`, work-conserving concurrency에는 merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`, automation threat-model documentation에는 merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`가 포함돼 있다. 이 SHA들은 protected lineage의 역사 증거이며 open-candidate authority가 아니다. -Merged #547은 이전 cross-lane baseline writer였고, 이 successor revision은 #547 protected integration 뒤 생긴 live authority 변화만 이어받는다. 다른 feature lane이 과거 baseline blob을 포함하더라도 ordinary/non-force semantic convergence 때 current authority로 승계하지 않는다. +#559가 cross-lane commercial baseline과 executable documentation-authority tests를 소유한다. 다른 feature lane에 포함된 과거 baseline blob은 ordinary/non-force convergence 때 current authority로 승계하지 않는다. ## Canonical product boundary Noema Core Domain은 **Agent Runtime**과 **Workflow / Task Execution**이다. **Tool / Capability Boundary**, **State / Checkpoint**, **Isolation Integration**, **Policy / Approval**, **Observability**, **Recovery**는 명시적 bounded context다. Execution identity, side-effect authority, claim/checkpoint CAS, cancellation/recovery invariant는 Noema transaction boundary에 남긴다. -`contextual-orchestrator`는 provider/model discovery, routing, retry/failover, test-time compute와 provider credential을 소유한다. Noema는 released gateway contract와 canonical `orchestrator/free` alias를 소비할 뿐 direct provider SDK, provider key, provider/model/group fallback policy를 소유하지 않는다. `.github`는 organization reusable workflow와 control-plane source를 소유한다. `quarantine-sandbox-runtime`, Wardnet, EgressWeave, AppGuardrail은 isolation/security/outbound truth를 각자 소유한다. Keyverse는 identity backend owner다. `context-graph-contracts`와 `enterprise-architecture-core`는 released/versioned contract로만 연결하며 mutable sibling PR source, copied domain table, cross-service SQL은 runtime truth가 아니다. +`contextual-orchestrator`는 provider/model discovery, routing, retry/failover, test-time compute와 provider credential을 소유한다. Noema는 released gateway contract와 canonical `orchestrator/free` alias를 소비할 뿐 direct provider SDK, provider key, provider/model/group fallback policy를 소유하지 않는다. `.github`는 organization reusable workflow와 control-plane source를 소유한다. `quarantine-sandbox-runtime`, Wardnet, EgressWeave, AppGuardrail은 isolation/security/outbound truth를 각자 소유한다. Keyverse는 identity backend owner다. `context-graph-contracts`와 `enterprise-architecture-core`는 released/versioned contract로만 연결하고 mutable sibling PR source, copied domain table, cross-service SQL을 runtime truth로 사용하지 않는다. -#550은 PR-scoped supersession cancellation과 work-conserving dispatch를 protected source에 통합했다. #535의 ordinary convergence는 이 protected work-conserving concurrency/admission을 보존한다. #542는 Durable Workflow / Task Execution과 State / Checkpoint의 atomic task claim, checkpoint CAS/replay, effect-start/terminal authority, cancellation/recovery 및 retained-provenance validation을 protected source로 만들었다. ADR 0013은 deployed Durable Object transaction/runtime 증거가 아직 없으므로 `Proposed`를 유지한다. #540은 historical Wrangler/Miniflare/Sharp/Libvips tooling path를 제거하고 pinned `workerd@1.20260625.1` + `esbuild@0.28.1`, canonical lock/license evidence와 patch-validator dependency pruning을 protected source에 통합했다. +#550은 PR-scoped supersession cancellation과 work-conserving dispatch를 protected source에 통합했다. #542는 Durable Workflow / Task Execution과 State / Checkpoint의 atomic task claim, checkpoint CAS/replay, effect-start/terminal authority, cancellation/recovery 및 retained-provenance validation을 protected source로 만들었다. ADR 0013은 deployed Durable Object transaction/runtime evidence가 없으므로 `Proposed`를 유지한다. #540은 historical Wrangler/Miniflare/Sharp/Libvips tooling path를 제거하고 pinned `workerd@1.20260625.1` + `esbuild@0.28.1`, canonical lock/license evidence와 patch-validator dependency pruning을 protected source에 통합했다. ## Active candidate convergence — 2026-09-08 KST ### Orchestrator/free consumer — PR #535 -PR #535 exact `06ed62fcc5611e9b25ef38b06e87e7521dbf1be1`는 Draft다. #547이 protected source가 된 뒤 이전 four-GREEN head를 그대로 전용하지 않고 protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`를 첫 parent로 ordinary/non-force semantic convergence한 뒤, hosted CI가 stale procedure 문서의 global-empty-PR admission 가정을 현실 RED로 드러냈다. Test-only `f1bca1b44bc9b1cf5f67c200380aaeed8c67bb2f`의 application CI `34177131397`은 exact checkout, live-base guard, lockfile control, install, typecheck를 통과하고 release tests에서 1 failed / 4140 passed로 실패했다. +PR #535 exact `551d81da28b0c03ca44deedf60e95125dcceb81b`는 Draft다. #558 integration 뒤 branch를 force 없이 ordinary two-parent convergence했고, first parent는 current protected source, second parent는 predecessor `06ed62fcc5611e9b25ef38b06e87e7521dbf1be1`다. Fresh compare는 ahead-only, `behind_by=0`, merge-base exact current protected main이다. -Current `06ed62f...`는 두 procedure 문서만 protected work-conserving admission으로 수리한다. strict `orchestrator/free`, request-level ZDR/privacy, reviewer `timeout=None`, `max_retries=0`, gateway validation, direct-provider/fallback rejection과 OpenCode tool-capability allowlisting을 유지하며 provider/model discovery·routing·credential·retry/failover truth는 contextual-orchestrator owner에 남긴다. Fresh compare는 `behind_by=0`이고 merge-base가 current protected main과 일치한다. +Semantic convergence는 protected #558의 `.github/workflows/patch-validator-image.yml`, `test/patch-validator-image-build-cache.test.ts`, `test/patch-validator-workflow.test.ts`를 보호해 retired FaaS parity build path를 되살리지 않는다. #535의 strict `orchestrator/free`, request-level ZDR/privacy, reviewer `timeout=None`, `max_retries=0`, gateway validation, direct-provider/fallback rejection과 OpenCode tool-capability boundary는 유지한다. Provider/model discovery·routing·credential·retry/failover truth는 contextual-orchestrator owner에 남긴다. -현재 exact generation은 application CI `34177518778`, reviewer-ci `34177518813`, required Security Scan `34177518804`가 terminal success이고 patch-validator-image `34177518809`가 in progress다. Three GREEN은 four-GREEN이 아니며 predecessor GREEN은 transfer하지 않는다. Next action은 unchanged exact head의 terminal image success, clean fresh review authority와 current-base ancestry를 다시 확인한 뒤 normal merge하는 것이다. +이 exact head의 새 generation은 application CI `34181022232`, reviewer-ci `34181022241`, required Security Scan `34181022210`, patch-validator-image `34181022238`이며 현재 queued 상태다. 이전 exact head의 GREEN은 transfer하지 않는다. Next action은 unchanged exact head에서 terminal four-GREEN, fresh clean review authority, unchanged protected ancestry를 다시 확인한 뒤 normal merge하는 것이다. -### Patch-validator default-branch cache seed — issue #66 / PR #558 +### Patch-validator default-branch cache seed — merged #558 / issue #66 -PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`는 Draft이며 protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6` 위에 ordinary/non-force convergence된 `f2aa8570...`에서 test-only causal repair로 정상 전진했다. Fresh compare는 `behind_by=0`, merge-base exact protected main이며 effective diff는 `.github/workflows/patch-validator-image.yml`, `test/patch-validator-image-build-cache.test.ts`, `test/patch-validator-workflow.test.ts` 세 경로다. +Merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`는 protected source에 포함됐다. Protected workflow는 image-authority path가 protected main에서 바뀔 때 full image verification을 실행해 default-branch BuildKit cache seed를 만들 수 있게 하며, `workflow_dispatch`, PR-scoped cancellation, stale-head refusal, pinned scanner/toolchain, static runtime checks, no-network/non-root smoke, SBOM/vulnerability receipts와 fail-closed verification을 유지한다. -RCA는 동일한 `type=gha,scope=noema-patch-validator-image` 문자열만으로 sibling PR cache가 공유된다는 가정을 반증했다. 기존 workflow는 PR branch와 manual dispatch에서만 cache를 기록해 sibling PR이 default/base branch cache로 복구할 수 없었고, successive exact-head static Node builds가 반복해서 cold path를 탔다. #558은 protected `main` push에서 image-authority path가 바뀔 때만 full image verification을 실행해 default-branch BuildKit cache를 seed하도록 한다. `workflow_dispatch`, PR-scoped cancellation, stale-head refusal, pinned scanners/toolchain, static runtime checks, no-network/non-root smoke, SBOM/vulnerability receipts와 fail-closed verification은 유지한다. - -Converged predecessor `f2aa8570...`의 hosted CI `34172635652`는 exact checkout/live-base/lockfile/install/typecheck 뒤 release tests에서 현실 RED를 냈다. 원인은 기존 `patch-validator-workflow` contract가 unfiltered `pull_request:`를 검증한다는 명목으로 `workflow_dispatch:`와의 직접 인접성을 요구해 별도 sibling `push:` trigger를 잘못 거부한 것이었다. Current `2f91bf8...`은 다음 non-empty event line이 같은 YAML indentation의 trigger임을 요구하도록 테스트를 일반화해 unfiltered PR invariant를 유지하면서 protected-main seed trigger를 허용한다. Production workflow·permission·security/publication boundary는 바꾸지 않았다. - -현재 exact generation은 application CI `34173491056`, reviewer-ci `34173491034`, required Security Scan `34173491124`가 terminal success이고 patch-validator-image `34173491077`가 in progress다. 첫 repaired PR은 default-branch seed가 아직 없으므로 cold build를 지불할 수 있다. Normal #558 merge는 workflow path 자체를 변경하므로 protected merge commit에서 push image run을 한 번 보장한다. 그 run이 protected-main operational acceptance와 cache seed를 모두 실제로 통과하는지 확인하고, 이후 별도 image-authority PR에서 cache restore 및 실제 build duration을 측정하기 전에는 성능 개선을 주장하지 않는다. +Source integration 자체는 protected-main push run의 cache hit, immutable image digest publication, signature/attestation, reproducibility 또는 rollback을 자동으로 증명하지 않는다. Issue #66은 실제 protected-main operational evidence와 immutable publication evidence가 생길 때까지 open authority다. ### Exact-claim evidence receipts — issue #555 / PR #556 -Observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305`는 현재 #535 feature-base보다 뒤처진 stale stacked head다. `live #556 must be re-fetched before integration`. Historical CI는 live-base guard에서 RED였고 required Security evidence가 없으므로 이 exact head는 non-authorizing이다. +Observed PR #556 exact `9d6d52c1dd4fc88203a832b509f4ec28cef3c68a`는 Draft다. `live #556 must be re-fetched before integration`. 이 candidate는 legitimate ordinary descendant이지만 predecessor #535 source 위에서 구성됐고, current #535와의 fresh compare는 diverged다. 따라서 current #556 gate 결과를 post-#535 integration authority로 사용하지 않는다. + +#556의 retained contract는 authenticated producer receipt와 `ClaimEvidenceRequirement` publication authority를 분리한다. Raw current-head source receipt는 context authority일 뿐이고, trusted producer가 exact claim/evidence kind와 finding coordinates를 명시적으로 승인하지 않는 한 blocking finding을 권위화하지 못한다. Requirement/receipt mismatch, wrong coordinates, direct model dictionaries, context-to-finding promotion은 deterministic gate와 publisher 전에 fail closed한다. -#556이 소유하는 valid source contract는 producer-issued evidence receipt, exact repository/head/workflow/run/attempt identity, claim/evidence digest, evidence-kind separation, model-visible `[receipt:]` reference와 pre-publication admission이다. Source receipt는 execution/research authority가 아니다. #535가 normal integrate된 뒤 protected main과 live #556을 다시 읽고, historical baseline/source blob을 복사하지 않은 채 receipt/test/fixture/contract delta만 ordinary/non-force restack/retarget한다. Fresh Security 포함 exact-head gates가 필요하다. +#535가 normally integrate된 뒤 resulting protected main과 live #556을 다시 읽고, valid claim-evidence implementation/tests만 ordinary/non-force restack/retarget한다. #559 소유 baseline의 historical blob은 제외하고 `central-review.yml` 등 #535 overlap은 protected semantics와 합성한다. 이후 fresh Security-inclusive exact-head gates와 normal merge가 필요하다. -Remaining boundary는 exact stdout/stderr handoff, trusted research producer, immutable Noema release, released central `.github#1641` consumer bump와 original corpus RED→GREEN이다. +Remaining supply-chain boundary는 exact stdout/stderr handoff, trusted research producer, immutable Noema release, released central `.github#1641` consumer bump와 unchanged original corpus RED→GREEN이다. ## Protected but incomplete commercial evidence -### Toolchain / inbound license — issue #531 / merged PR #540 +### Toolchain and inbound rights — issue #531 / merged #540 -Merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac` source remediation은 protected lineage에 포함돼 있다. 남은 권위는 protected-source package/SBOM/provenance/reproducibility, NOTICE/attribution, actual released-artifact rights와 explicit owner/legal outbound-rights evidence다. Source-only license inventory나 PR-head image check를 release evidence로 승격하지 않는다. +Source remediation은 protected lineage에 있다. 남은 권위는 exact released package/image/SBOM/provenance/reproducibility, NOTICE/attribution, actual artifact rights와 explicit owner/legal outbound-rights evidence다. Source-only license inventory를 release evidence로 승격하지 않는다. -### Durable runtime operation — issue #541 / merged PR #542 +### Durable runtime operation — issue #541 / merged #542 -Merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`는 durable workflow/state source를 protected lineage에 넣었다. 남은 권위는 실제 deployed Durable Object binding/transaction compatibility, recovery/rollback receipt, immutable release/package/SBOM/provenance/reproducibility다. ADR 0013은 이 evidence가 존재하기 전까지 `Proposed`다. +Durable workflow/state source는 protected lineage에 있다. 남은 권위는 deployed Durable Object binding/transaction compatibility, recovery/rollback receipt, immutable release/package/SBOM/provenance/reproducibility다. 이 evidence 전까지 ADR 0013은 `Proposed`다. -### Patch-validator publication — issue #66 +### Governance and production identity -#547 exact head의 current static runtime/image/SBOM/receipt verification은 protected integration 전 terminal success를 얻었지만 PR-head evidence다. Protected-main operational run, immutable image digest publication, signature/attestation, source/workflow/builder provenance, reproducibility, rollback과 activation evidence는 아직 없다. GitHub release collection도 비어 있으므로 source integration을 release로 간주하지 않는다. +Required workflow source만으로 reviewer/maintainer App installation, key custody/rotation, bounded publication authority, ruleset enforcement, break-glass operation을 모두 입증할 수 없다. Live governance와 approved control-plane evidence는 source evidence와 별도로 유지한다. ## Current authority table | Lane | Authority | Integration / completion condition | | --- | --- | --- | -| Protected source | live protected `main`; current observation protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`; historical #547 construction snapshot protected `main@099d7d89a51bca4a2cf7c6b285b50ffadd08d001` | Exact protected head는 mutation·merge·release 직전에 live-read한다. | -| Central workflow trust | moving central main은 live-read; observed central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`; reviewed Noema pin `c9052e607e5f3cc76e73207e7786b21500721b79` | Moving foreign head와 immutable reviewed pin을 분리한다. | -| Toolchain/license source | merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac` | Source complete; #531은 release/publication/rights evidence 때문에 open이다. | -| Durable workflow/state source | merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc` | Source complete; #541은 deployed runtime/recovery/release evidence 때문에 open이다. | -| Documentation authority | merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6` + this post-integration successor | #547는 protected history다. Moving PR truth는 successor에서 code-current하게 갱신한다. | -| Orchestrator/free consumer | PR #535 exact `06ed62fcc5611e9b25ef38b06e87e7521dbf1be1` | Fresh exact-head four-GREEN + clean review + current ancestry 후 normal merge. | -| Patch-validator cache seed | PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295` | Fresh four-GREEN 후 normal merge; protected-main push image run과 cache seed를 별도 검증. | -| Exact-claim receipts | observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305` | #535 normal merge 뒤 live-read/restack, fresh Security-inclusive evidence와 immutable release. | +| Protected source | live protected main; current observation protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd` | mutation·merge·release 직전 exact protected head 재조회 | +| Central workflow trust | central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`; reviewed pin `c9052e607e5f3cc76e73207e7786b21500721b79` | moving head와 immutable reviewed pin 분리 | +| Toolchain/license source | merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac` | source complete; release/publication/rights evidence 미완료 | +| Durable workflow/state source | merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc` | source complete; deployed runtime/recovery/release evidence 미완료 | +| Documentation authority | merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6` + active #559 successor | moving PR/protected truth를 #559에서 code-current 유지 | +| Orchestrator/free consumer | PR #535 exact `551d81da28b0c03ca44deedf60e95125dcceb81b` | fresh four-GREEN + clean review + current ancestry 후 normal merge | +| Patch-validator cache seed | merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295` | protected operational run/cache behavior + immutable image/release evidence | +| Exact-claim receipts | observed PR #556 exact `9d6d52c1dd4fc88203a832b509f4ec28cef3c68a` | #535 merge 후 protected-source restack, fresh Security-inclusive gates, immutable release | ## Evidence semantics and merge rules @@ -87,15 +85,15 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge | Priority | Gap | Buyer/operator impact | Current owner | Authoritative completion evidence | Next executable action | | --- | --- | --- | --- | --- | --- | -| P0 | Strict orchestrator/free consumer | Noema가 provider/model routing authority를 복제하면 제품 경계와 운영 책임이 흐려진다. | PR #535 | Fresh exact-head CI/reviewer/Security/image + normal merge | Current exact generation을 관찰하고 실패 시 causal repair; GREEN이면 current-base/review 재검증 후 normal merge. | -| P0 | Exact-claim evidence supply chain | Tool claim이 authenticated producer evidence 없이 reviewer authority로 승격될 수 있다. | issue #555 / PR #556 | #535 merge 후 current-main restack, execution/research producers, immutable release, released central consumer bump, original hosted corpus GREEN | #535 protected integration 전에는 #556을 움직이지 않는다. | -| P0 | Patch-validator operational publication | PR-head image success만으로 protected operation, reusable cache, immutable activation을 증명할 수 없다. | issue #66 / PR #558 | #558 merge + protected-main exact image run/cache seed + immutable image/signature/SBOM/provenance/reproducibility/rollback | #558 exact gates를 통과시키고 normal merge한 뒤 protected-main push run과 cache restore를 실측한다. | -| P0 | Toolchain/license release evidence | Source dependency remediation만으로 실제 배포 artifact 권리와 재현성을 증명할 수 없다. | issue #531 / merged PR #540 | Protected exact release package/image/SBOM/provenance/reproducibility/NOTICE/rights evidence | Release-ready protected exact head가 있을 때만 immutable publication evidence를 만든다. | -| P0 | Reviewer/Maintainer production identity | Source-only controls로 App installation, key custody/rotation, bounded publication authority를 증명할 수 없다. | issues #29 / #227 | Live installation/permissions/key-custody/rotation 및 bounded publication/recovery receipts | 승인된 control-plane preflight에서 source evidence와 분리 보존한다. | -| P0 | Governance enforceability | Required workflow source만으로 실제 approval/deletion/rewrite/break-glass 정책을 모두 증명할 수 없다. | issue #27 | Live ruleset/protection audit와 observed required-workflow behavior | protected mutation 직전 live governance를 다시 읽고 owner control에서만 수정한다. | -| P1 | Durable runtime operation | Source-level durable semantics와 실제 deployed transaction/recovery는 다른 evidence class다. | issue #541 | Deployed Durable Object compatibility + recovery/rollback + immutable release identity | 승인된 runtime evidence가 없으면 ADR 0013 `Proposed`를 유지한다. | -| P1 | Production KPI evidence | Fixture는 reliability, latency, commercial production operation을 입증하지 못한다. | issue #3 | Authenticated retained production KPI window with source/run identity and falsifiable denominator | 승인된 production source가 없으면 fail closed를 유지한다. | -| P1 | Acquisition transfer | Apache-2.0 source grant는 contributor ownership, assignment, artifact-transfer rights 자체를 증명하지 않는다. | issue #5 | Exact-release rights metadata, dependency/NOTICE/SBOM, contributor/IP and transfer evidence | Immutable release 이후 acquisition evidence를 해당 권위에서 수집한다. | +| P0 | Strict orchestrator/free consumer | Noema가 provider/model routing authority를 복제하면 제품 경계와 운영 책임이 흐려진다. | PR #535 | fresh exact-head CI/reviewer/Security/image + normal merge | current exact generation 실패 시 causal repair; GREEN이면 current-base/review 재검증 후 normal merge | +| P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority로 승격될 수 있다. | issue #555 / PR #556 | #535 merge 후 restack, execution/research producer evidence, normal merge, immutable release, released consumer RED→GREEN | #535 normal integration 후 live #556을 재구성 | +| P0 | Patch-validator operational publication | source merge만으로 reusable cache와 immutable runtime activation을 증명할 수 없다. | issue #66 | protected-main image/cache receipt + immutable image/signature/SBOM/provenance/reproducibility/rollback | protected operational evidence를 exact source에 결합 | +| P0 | Toolchain/license release evidence | source dependency remediation만으로 실제 배포 artifact 권리와 재현성을 증명할 수 없다. | issue #531 | protected exact release package/image/SBOM/provenance/reproducibility/NOTICE/rights | release-ready protected exact head에서만 publication evidence 생성 | +| P0 | Reviewer/Maintainer production identity | source control만으로 App installation, key custody/rotation, bounded publication authority를 증명할 수 없다. | issues #29 / #227 | live installation/permissions/key-custody/rotation + bounded publication/recovery receipt | approved control-plane evidence와 source evidence를 분리 보존 | +| P0 | Governance enforceability | workflow source만으로 approval/deletion/rewrite/break-glass 정책 전체를 증명할 수 없다. | issue #27 | live ruleset/protection audit + observed required-workflow behavior | protected mutation 직전 governance 재조회 | +| P1 | Durable runtime operation | source-level durable semantics와 deployed transaction/recovery는 별도 evidence class다. | issue #541 | deployed compatibility + recovery/rollback + immutable release identity | evidence 전 ADR 0013 `Proposed` 유지 | +| P1 | Production KPI evidence | fixture는 reliability, latency, commercial operation을 입증하지 못한다. | issue #3 | authenticated retained production KPI window with source/run identity and denominator | approved production source가 없으면 fail closed 유지 | +| P1 | Acquisition transfer | Apache-2.0 source grant는 contributor ownership, assignment, artifact-transfer rights 자체를 증명하지 않는다. | issue #5 | exact-release rights metadata, dependency/NOTICE/SBOM, contributor/IP and transfer evidence | immutable release 이후 acquisition evidence 수집 | ## Completion discipline From 94bde819ac79335da7ef01497fc207605f941ce8 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 11:55:51 +0900 Subject: [PATCH 11/68] test(docs): require latest observed #556 authority Advance the documentation contract to the live #556 successor after its hosted release-test RED, while rejecting the superseded observation. Production baseline text follows in the causal repair commit. --- test/documentation-live-open-pr-authority.test.ts | 4 ++-- test/product-technical-gap-current-candidate-contract.test.ts | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index 751b07ba7..ce209ffdc 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -10,13 +10,13 @@ describe("product-technical gap baseline live open-PR authority", () => { expect(baseline).toContain("merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`"); expect(baseline).toContain("merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`"); expect(baseline).toContain("merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`"); - expect(baseline).toContain("observed PR #556 exact `9d6d52c1dd4fc88203a832b509f4ec28cef3c68a`"); + expect(baseline).toContain("observed PR #556 exact `29cb77bb943dcd93d65f959f20f50a0622e0ba4a`"); expect(baseline).toContain("live #556 must be re-fetched before integration"); expect(baseline).toContain("issue #555 / PR #556"); expect(baseline).not.toContain("PR #535 exact `06ed62fcc5611e9b25ef38b06e87e7521dbf1be1`"); expect(baseline).not.toContain("PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a`"); - expect(baseline).not.toContain("PR #535 exact `e996b509f699c3f942ef81f0ac52b804b783cd19`"); expect(baseline).not.toContain("PR #558 exact `f2aa8570d952cc0a371da161e651472c080e00ce`"); + expect(baseline).not.toContain("observed PR #556 exact `9d6d52c1dd4fc88203a832b509f4ec28cef3c68a`"); expect(baseline).not.toContain("observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305`"); }); }); \ No newline at end of file diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index 30bdfab17..422135e58 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -12,7 +12,7 @@ describe("product technical gap current candidate authority", () => { "merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`", "merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`", "merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`", - "observed PR #556 exact `9d6d52c1dd4fc88203a832b509f4ec28cef3c68a`", + "observed PR #556 exact `29cb77bb943dcd93d65f959f20f50a0622e0ba4a`", "merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`", "merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`", "merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`", @@ -27,8 +27,8 @@ describe("product technical gap current candidate authority", () => { "protected `main@d6394b2aa73e6fc57fccdad74ea38ad87f79e7f8`", "PR #535 exact `06ed62fcc5611e9b25ef38b06e87e7521dbf1be1`", "PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a`", - "PR #535 exact `e996b509f699c3f942ef81f0ac52b804b783cd19`", "PR #558 exact `f2aa8570d952cc0a371da161e651472c080e00ce`", + "observed PR #556 exact `9d6d52c1dd4fc88203a832b509f4ec28cef3c68a`", "observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305`", "PR #540은 아직 merge authority가 아니다", ]) { From 095168327a6fd360672fe1b9ee23ffbbc4ded568 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 11:57:04 +0900 Subject: [PATCH 12/68] docs(gap): record live #556 successor and hosted RED Update #559's sole documentation authority to the latest #556 exact head, preserve the observed hosted release-test failure as historical evidence, and keep the downstream stack non-authorizing until #535 reaches protected main. --- docs/product-technical-gap-baseline.md | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 167137547..9ca9104d3 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -28,20 +28,22 @@ PR #535 exact `551d81da28b0c03ca44deedf60e95125dcceb81b`는 Draft다. #558 integ Semantic convergence는 protected #558의 `.github/workflows/patch-validator-image.yml`, `test/patch-validator-image-build-cache.test.ts`, `test/patch-validator-workflow.test.ts`를 보호해 retired FaaS parity build path를 되살리지 않는다. #535의 strict `orchestrator/free`, request-level ZDR/privacy, reviewer `timeout=None`, `max_retries=0`, gateway validation, direct-provider/fallback rejection과 OpenCode tool-capability boundary는 유지한다. Provider/model discovery·routing·credential·retry/failover truth는 contextual-orchestrator owner에 남긴다. -이 exact head의 새 generation은 application CI `34181022232`, reviewer-ci `34181022241`, required Security Scan `34181022210`, patch-validator-image `34181022238`이며 현재 queued 상태다. 이전 exact head의 GREEN은 transfer하지 않는다. Next action은 unchanged exact head에서 terminal four-GREEN, fresh clean review authority, unchanged protected ancestry를 다시 확인한 뒤 normal merge하는 것이다. +이 exact head의 새 generation은 application CI `34181022232`, reviewer-ci `34181022241`, required Security Scan `34181022210`, patch-validator-image `34181022238`이다. 마지막 관찰에서 CI와 reviewer-ci는 terminal success, Security Scan은 queued, image는 in progress다. Two GREEN은 four-GREEN이 아니며 이전 exact head의 GREEN은 transfer하지 않는다. Next action은 unchanged exact head에서 terminal four-GREEN, fresh clean review authority, unchanged protected ancestry를 다시 확인한 뒤 normal merge하는 것이다. ### Patch-validator default-branch cache seed — merged #558 / issue #66 Merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`는 protected source에 포함됐다. Protected workflow는 image-authority path가 protected main에서 바뀔 때 full image verification을 실행해 default-branch BuildKit cache seed를 만들 수 있게 하며, `workflow_dispatch`, PR-scoped cancellation, stale-head refusal, pinned scanner/toolchain, static runtime checks, no-network/non-root smoke, SBOM/vulnerability receipts와 fail-closed verification을 유지한다. -Source integration 자체는 protected-main push run의 cache hit, immutable image digest publication, signature/attestation, reproducibility 또는 rollback을 자동으로 증명하지 않는다. Issue #66은 실제 protected-main operational evidence와 immutable publication evidence가 생길 때까지 open authority다. +Protected-main exact `59ae66d...`의 push `patch-validator-image` run `34179912851`은 실제 GitHub-hosted runner에서 in progress다. `ci 34179912905`와 `reviewer-ci 34179912864`는 terminal success다. Source integration 또는 진행 중 image run 자체는 cache hit, immutable image digest publication, signature/attestation, reproducibility 또는 rollback을 증명하지 않는다. Issue #66은 terminal operational evidence와 immutable publication evidence가 생길 때까지 open authority다. ### Exact-claim evidence receipts — issue #555 / PR #556 -Observed PR #556 exact `9d6d52c1dd4fc88203a832b509f4ec28cef3c68a`는 Draft다. `live #556 must be re-fetched before integration`. 이 candidate는 legitimate ordinary descendant이지만 predecessor #535 source 위에서 구성됐고, current #535와의 fresh compare는 diverged다. 따라서 current #556 gate 결과를 post-#535 integration authority로 사용하지 않는다. +Observed PR #556 exact `29cb77bb943dcd93d65f959f20f50a0622e0ba4a`는 Draft다. `live #556 must be re-fetched before integration`. Predecessor `9d6d52c1dd4fc88203a832b509f4ec28cef3c68a`의 hosted CI `34180062659`는 exact checkout, live-base guard, lockfile control, install, typecheck 뒤 release tests에서 실패했다. Current #556 successor는 해당 documentation-authority invariant를 수리했지만 current #535 `551d81d...`가 아직 protected source가 아니므로 post-#535 integration authority는 아니다. #556의 retained contract는 authenticated producer receipt와 `ClaimEvidenceRequirement` publication authority를 분리한다. Raw current-head source receipt는 context authority일 뿐이고, trusted producer가 exact claim/evidence kind와 finding coordinates를 명시적으로 승인하지 않는 한 blocking finding을 권위화하지 못한다. Requirement/receipt mismatch, wrong coordinates, direct model dictionaries, context-to-finding promotion은 deterministic gate와 publisher 전에 fail closed한다. +Current #556 exact generation은 application CI `34181585090`, reviewer-ci `34181585132`, patch-validator-image `34181585051`이 새로 queued됐고 required Security evidence는 아직 관찰되지 않았다. 이 세 run의 결과와 predecessor evidence를 merge authority로 전용하지 않는다. + #535가 normally integrate된 뒤 resulting protected main과 live #556을 다시 읽고, valid claim-evidence implementation/tests만 ordinary/non-force restack/retarget한다. #559 소유 baseline의 historical blob은 제외하고 `central-review.yml` 등 #535 overlap은 protected semantics와 합성한다. 이후 fresh Security-inclusive exact-head gates와 normal merge가 필요하다. Remaining supply-chain boundary는 exact stdout/stderr handoff, trusted research producer, immutable Noema release, released central `.github#1641` consumer bump와 unchanged original corpus RED→GREEN이다. @@ -71,7 +73,7 @@ Required workflow source만으로 reviewer/maintainer App installation, key cust | Documentation authority | merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6` + active #559 successor | moving PR/protected truth를 #559에서 code-current 유지 | | Orchestrator/free consumer | PR #535 exact `551d81da28b0c03ca44deedf60e95125dcceb81b` | fresh four-GREEN + clean review + current ancestry 후 normal merge | | Patch-validator cache seed | merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295` | protected operational run/cache behavior + immutable image/release evidence | -| Exact-claim receipts | observed PR #556 exact `9d6d52c1dd4fc88203a832b509f4ec28cef3c68a` | #535 merge 후 protected-source restack, fresh Security-inclusive gates, immutable release | +| Exact-claim receipts | observed PR #556 exact `29cb77bb943dcd93d65f959f20f50a0622e0ba4a` | #535 merge 후 protected-source restack, fresh Security-inclusive gates, immutable release | ## Evidence semantics and merge rules From f7c4542321fa9e619cc598db0d4a4c88f848e465 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 12:08:06 +0900 Subject: [PATCH 13/68] test(docs): require current #535 endpoint-repair authority --- test/product-technical-gap-current-candidate-contract.test.ts | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index 422135e58..482356382 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -8,7 +8,7 @@ describe("product technical gap current candidate authority", () => { for (const currentTruth of [ "protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd`", "central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`", - "PR #535 exact `551d81da28b0c03ca44deedf60e95125dcceb81b`", + "PR #535 exact `e0a329916ab71b1009aa62cbab667a737d511223`", "merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`", "merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`", "merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`", @@ -25,6 +25,7 @@ describe("product technical gap current candidate authority", () => { for (const staleTruth of [ "protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`", "protected `main@d6394b2aa73e6fc57fccdad74ea38ad87f79e7f8`", + "PR #535 exact `551d81da28b0c03ca44deedf60e95125dcceb81b`", "PR #535 exact `06ed62fcc5611e9b25ef38b06e87e7521dbf1be1`", "PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a`", "PR #558 exact `f2aa8570d952cc0a371da161e651472c080e00ce`", From 8f5fdeec449adbcd3166877074da8878d575a53c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 12:09:34 +0900 Subject: [PATCH 14/68] docs: track current #535 gateway endpoint repair --- docs/product-technical-gap-baseline.md | 18 ++++++++++-------- 1 file changed, 10 insertions(+), 8 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 9ca9104d3..76c5dad01 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -24,25 +24,27 @@ Noema Core Domain은 **Agent Runtime**과 **Workflow / Task Execution**이다. * ### Orchestrator/free consumer — PR #535 -PR #535 exact `551d81da28b0c03ca44deedf60e95125dcceb81b`는 Draft다. #558 integration 뒤 branch를 force 없이 ordinary two-parent convergence했고, first parent는 current protected source, second parent는 predecessor `06ed62fcc5611e9b25ef38b06e87e7521dbf1be1`다. Fresh compare는 ahead-only, `behind_by=0`, merge-base exact current protected main이다. +PR #535 exact `e0a329916ab71b1009aa62cbab667a737d511223`는 Draft다. #558 integration 뒤 branch를 force 없이 ordinary two-parent convergence했고 current compare는 ahead-only, `behind_by=0`, merge-base exact protected main이다. -Semantic convergence는 protected #558의 `.github/workflows/patch-validator-image.yml`, `test/patch-validator-image-build-cache.test.ts`, `test/patch-validator-workflow.test.ts`를 보호해 retired FaaS parity build path를 되살리지 않는다. #535의 strict `orchestrator/free`, request-level ZDR/privacy, reviewer `timeout=None`, `max_retries=0`, gateway validation, direct-provider/fallback rejection과 OpenCode tool-capability boundary는 유지한다. Provider/model discovery·routing·credential·retry/failover truth는 contextual-orchestrator owner에 남긴다. +Fresh exact-head review에서 JavaScript gateway preflight와 `contracts/orchestrator-gateway.json`이 direct-provider host, URL userinfo/query/fragment, non-`/v1` endpoint를 거부하는 반면 Python reviewer boundary는 임의 HTTPS endpoint를 허용하는 cross-language authority drift가 확인됐다. 그 상태에서는 `orchestrator/free` model alias를 유지하더라도 직접 또는 임의 OpenAI-compatible HTTPS endpoint에 gateway credential을 붙일 수 있었다. -이 exact head의 새 generation은 application CI `34181022232`, reviewer-ci `34181022241`, required Security Scan `34181022210`, patch-validator-image `34181022238`이다. 마지막 관찰에서 CI와 reviewer-ci는 terminal success, Security Scan은 queued, image는 in progress다. Two GREEN은 four-GREEN이 아니며 이전 exact head의 GREEN은 transfer하지 않는다. Next action은 unchanged exact head에서 terminal four-GREEN, fresh clean review authority, unchanged protected ancestry를 다시 확인한 뒤 normal merge하는 것이다. +Test-only `9d67a3cff2700ec2672f78ea05a5e464e7857360`은 contract에 명시된 direct-provider host 여섯 개, URL authority metadata, `/v1` path shape와 정상 gateway endpoint를 executable regression으로 추가했다. 후속 causal repair가 PR-scoped supersession을 일으켜 이 test-only hosted generation은 실행 전에 cancelled됐으므로 hosted RED로 주장하지 않는다. Production `e0a329916ab71b1009aa62cbab667a737d511223`은 `reviewer/noema_reviewer/config.py`에 동일 endpoint invariant를 적용하고 exact `orchestrator/free`, reviewer `timeout=None`, `max_retries=0`, loopback-only HTTP development allowance와 contextual-orchestrator provider/model ownership을 보존한다. + +이 exact head의 wholly fresh generation은 application CI `34182299462`, reviewer-ci `34182299455`, required Security Scan `34182299456`, patch-validator-image `34182299469`이다. 마지막 관찰에서 CI는 pending, 나머지는 queued다. 이전 exact head의 GREEN은 transfer하지 않는다. Next action은 이 unchanged exact head가 실패하면 causal repair하고, terminal four-GREEN이면 fresh clean review authority와 unchanged protected ancestry를 다시 확인한 뒤 normal merge하는 것이다. ### Patch-validator default-branch cache seed — merged #558 / issue #66 Merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`는 protected source에 포함됐다. Protected workflow는 image-authority path가 protected main에서 바뀔 때 full image verification을 실행해 default-branch BuildKit cache seed를 만들 수 있게 하며, `workflow_dispatch`, PR-scoped cancellation, stale-head refusal, pinned scanner/toolchain, static runtime checks, no-network/non-root smoke, SBOM/vulnerability receipts와 fail-closed verification을 유지한다. -Protected-main exact `59ae66d...`의 push `patch-validator-image` run `34179912851`은 실제 GitHub-hosted runner에서 in progress다. `ci 34179912905`와 `reviewer-ci 34179912864`는 terminal success다. Source integration 또는 진행 중 image run 자체는 cache hit, immutable image digest publication, signature/attestation, reproducibility 또는 rollback을 증명하지 않는다. Issue #66은 terminal operational evidence와 immutable publication evidence가 생길 때까지 open authority다. +Protected-main exact `59ae66d...`의 push `patch-validator-image` run `34179912851`은 현재 operational/cache-seed evidence owner다. Source integration 또는 image run 자체는 cache hit, immutable image digest publication, signature/attestation, reproducibility 또는 rollback을 증명하지 않는다. Issue #66은 terminal operational evidence와 immutable publication evidence가 생길 때까지 open authority다. ### Exact-claim evidence receipts — issue #555 / PR #556 -Observed PR #556 exact `29cb77bb943dcd93d65f959f20f50a0622e0ba4a`는 Draft다. `live #556 must be re-fetched before integration`. Predecessor `9d6d52c1dd4fc88203a832b509f4ec28cef3c68a`의 hosted CI `34180062659`는 exact checkout, live-base guard, lockfile control, install, typecheck 뒤 release tests에서 실패했다. Current #556 successor는 해당 documentation-authority invariant를 수리했지만 current #535 `551d81d...`가 아직 protected source가 아니므로 post-#535 integration authority는 아니다. +Observed PR #556 exact `29cb77bb943dcd93d65f959f20f50a0622e0ba4a`는 Draft다. `live #556 must be re-fetched before integration`. Predecessor `9d6d52c1dd4fc88203a832b509f4ec28cef3c68a`의 hosted CI `34180062659`는 exact checkout, live-base guard, lockfile control, install, typecheck 뒤 release tests에서 실패했다. Current #556 successor는 해당 documentation-authority invariant를 수리했지만 current #535 `e0a3299...`가 아직 protected source가 아니므로 post-#535 integration authority는 아니다. #556의 retained contract는 authenticated producer receipt와 `ClaimEvidenceRequirement` publication authority를 분리한다. Raw current-head source receipt는 context authority일 뿐이고, trusted producer가 exact claim/evidence kind와 finding coordinates를 명시적으로 승인하지 않는 한 blocking finding을 권위화하지 못한다. Requirement/receipt mismatch, wrong coordinates, direct model dictionaries, context-to-finding promotion은 deterministic gate와 publisher 전에 fail closed한다. -Current #556 exact generation은 application CI `34181585090`, reviewer-ci `34181585132`, patch-validator-image `34181585051`이 새로 queued됐고 required Security evidence는 아직 관찰되지 않았다. 이 세 run의 결과와 predecessor evidence를 merge authority로 전용하지 않는다. +Current #556 exact generation은 application CI `34181585090`, reviewer-ci `34181585132`, patch-validator-image `34181585051`이며 required Security evidence는 아직 final-integration authority로 관찰되지 않았다. 이 run들과 predecessor evidence를 merge authority로 전용하지 않는다. #535가 normally integrate된 뒤 resulting protected main과 live #556을 다시 읽고, valid claim-evidence implementation/tests만 ordinary/non-force restack/retarget한다. #559 소유 baseline의 historical blob은 제외하고 `central-review.yml` 등 #535 overlap은 protected semantics와 합성한다. 이후 fresh Security-inclusive exact-head gates와 normal merge가 필요하다. @@ -71,7 +73,7 @@ Required workflow source만으로 reviewer/maintainer App installation, key cust | Toolchain/license source | merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac` | source complete; release/publication/rights evidence 미완료 | | Durable workflow/state source | merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc` | source complete; deployed runtime/recovery/release evidence 미완료 | | Documentation authority | merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6` + active #559 successor | moving PR/protected truth를 #559에서 code-current 유지 | -| Orchestrator/free consumer | PR #535 exact `551d81da28b0c03ca44deedf60e95125dcceb81b` | fresh four-GREEN + clean review + current ancestry 후 normal merge | +| Orchestrator/free consumer | PR #535 exact `e0a329916ab71b1009aa62cbab667a737d511223` | fresh four-GREEN + clean review + current ancestry 후 normal merge | | Patch-validator cache seed | merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295` | protected operational run/cache behavior + immutable image/release evidence | | Exact-claim receipts | observed PR #556 exact `29cb77bb943dcd93d65f959f20f50a0622e0ba4a` | #535 merge 후 protected-source restack, fresh Security-inclusive gates, immutable release | @@ -99,4 +101,4 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge ## Completion discipline -각 gap은 Authoritative completion evidence가 실제로 존재하고 current source/head에 결합될 때만 닫는다. 문서 존재, synthetic fixture, model judgement, stale workflow result를 완료 증거로 사용하지 않는다. Release-ready exact protected head가 없으면 version/tag/package/SBOM/provenance/rollback을 제조하지 않는다. \ No newline at end of file +각 gap은 Authoritative completion evidence가 실제로 존재하고 current source/head에 결합될 때만 닫는다. 문서 존재, synthetic fixture, model judgement, stale workflow result를 완료 증거로 사용하지 않는다. Release-ready exact protected head가 없으면 version/tag/package/SBOM/provenance/rollback을 제조하지 않는다. From 06e635ca2d082f7d75107f6acb59755727065705 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 12:13:12 +0900 Subject: [PATCH 15/68] test(docs): require #535 coverage-repair authority --- test/product-technical-gap-current-candidate-contract.test.ts | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index 482356382..e86a8a6d4 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -8,7 +8,7 @@ describe("product technical gap current candidate authority", () => { for (const currentTruth of [ "protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd`", "central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`", - "PR #535 exact `e0a329916ab71b1009aa62cbab667a737d511223`", + "PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`", "merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`", "merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`", "merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`", @@ -25,6 +25,7 @@ describe("product technical gap current candidate authority", () => { for (const staleTruth of [ "protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`", "protected `main@d6394b2aa73e6fc57fccdad74ea38ad87f79e7f8`", + "PR #535 exact `e0a329916ab71b1009aa62cbab667a737d511223`", "PR #535 exact `551d81da28b0c03ca44deedf60e95125dcceb81b`", "PR #535 exact `06ed62fcc5611e9b25ef38b06e87e7521dbf1be1`", "PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a`", From 53be2186cbc25c49027013db98b43898cb7e2a2c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 12:14:08 +0900 Subject: [PATCH 16/68] docs: track #535 coverage-gate repair --- docs/product-technical-gap-baseline.md | 16 +++++++++------- 1 file changed, 9 insertions(+), 7 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 76c5dad01..ca9246f79 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -24,23 +24,25 @@ Noema Core Domain은 **Agent Runtime**과 **Workflow / Task Execution**이다. * ### Orchestrator/free consumer — PR #535 -PR #535 exact `e0a329916ab71b1009aa62cbab667a737d511223`는 Draft다. #558 integration 뒤 branch를 force 없이 ordinary two-parent convergence했고 current compare는 ahead-only, `behind_by=0`, merge-base exact protected main이다. +PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`는 Draft다. #558 integration 뒤 branch를 force 없이 ordinary two-parent convergence했고 current compare는 ahead-only, `behind_by=0`, merge-base exact protected main이다. -Fresh exact-head review에서 JavaScript gateway preflight와 `contracts/orchestrator-gateway.json`이 direct-provider host, URL userinfo/query/fragment, non-`/v1` endpoint를 거부하는 반면 Python reviewer boundary는 임의 HTTPS endpoint를 허용하는 cross-language authority drift가 확인됐다. 그 상태에서는 `orchestrator/free` model alias를 유지하더라도 직접 또는 임의 OpenAI-compatible HTTPS endpoint에 gateway credential을 붙일 수 있었다. +Fresh exact-head review에서 JavaScript gateway preflight와 `contracts/orchestrator-gateway.json`이 direct-provider host, URL userinfo/query/fragment, non-`/v1` endpoint를 거부하는 반면 Python reviewer boundary는 임의 HTTPS endpoint를 허용하는 cross-language authority drift가 확인됐다. 그 상태에서는 `orchestrator/free` model alias를 유지하더라도 직접 provider 또는 malformed OpenAI-compatible HTTPS endpoint에 gateway credential을 붙일 수 있었다. -Test-only `9d67a3cff2700ec2672f78ea05a5e464e7857360`은 contract에 명시된 direct-provider host 여섯 개, URL authority metadata, `/v1` path shape와 정상 gateway endpoint를 executable regression으로 추가했다. 후속 causal repair가 PR-scoped supersession을 일으켜 이 test-only hosted generation은 실행 전에 cancelled됐으므로 hosted RED로 주장하지 않는다. Production `e0a329916ab71b1009aa62cbab667a737d511223`은 `reviewer/noema_reviewer/config.py`에 동일 endpoint invariant를 적용하고 exact `orchestrator/free`, reviewer `timeout=None`, `max_retries=0`, loopback-only HTTP development allowance와 contextual-orchestrator provider/model ownership을 보존한다. +Test-only `9d67a3cff2700ec2672f78ea05a5e464e7857360`은 contract에 명시된 direct-provider host 여섯 개, URL authority metadata, `/v1` path shape와 정상 gateway endpoint를 executable regression으로 추가했다. 후속 causal repair가 PR-scoped supersession을 일으켜 이 test-only hosted generation은 실행 전에 cancelled됐으므로 hosted RED로 주장하지 않는다. Production `e0a329916ab71b1009aa62cbab667a737d511223`은 `reviewer/noema_reviewer/config.py`에 동일 endpoint invariant를 적용하고 exact `orchestrator/free`, reviewer `timeout=None`, `max_retries=0`, loopback-only HTTP development allowance와 contextual-orchestrator provider/model ownership을 보존했다. -이 exact head의 wholly fresh generation은 application CI `34182299462`, reviewer-ci `34182299455`, required Security Scan `34182299456`, patch-validator-image `34182299469`이다. 마지막 관찰에서 CI는 pending, 나머지는 queued다. 이전 exact head의 GREEN은 transfer하지 않는다. Next action은 이 unchanged exact head가 실패하면 causal repair하고, terminal four-GREEN이면 fresh clean review authority와 unchanged protected ancestry를 다시 확인한 뒤 normal merge하는 것이다. +그 exact production head의 reviewer-ci `34182299455` / job `101923650070`에서 631 reviewer tests 자체는 모두 통과했지만 mandatory line+branch coverage가 99.93%로 실패했고, `config.py`의 hostless-URL rejection branch 한 줄이 미실행으로 남았다. Gate를 약화하지 않고 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`에서 `https:///v1` regression 하나를 추가해 해당 fail-closed branch를 직접 실행하도록 수리했다. 이 후속은 production behavior를 바꾸지 않는다. + +`82b20b2...`의 wholly fresh generation은 application CI `34182693606`, reviewer-ci `34182693512`, required Security Scan `34182693575`, patch-validator-image `34182693666`이다. 마지막 관찰에서는 queued/pending 상태다. 이전 exact head의 GREEN 또는 RED 이후 일부 성공 evidence는 transfer하지 않는다. Next action은 unchanged exact head가 실패하면 causal repair하고, terminal four-GREEN이면 fresh clean review authority와 unchanged protected ancestry를 다시 확인한 뒤 normal merge하는 것이다. ### Patch-validator default-branch cache seed — merged #558 / issue #66 Merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`는 protected source에 포함됐다. Protected workflow는 image-authority path가 protected main에서 바뀔 때 full image verification을 실행해 default-branch BuildKit cache seed를 만들 수 있게 하며, `workflow_dispatch`, PR-scoped cancellation, stale-head refusal, pinned scanner/toolchain, static runtime checks, no-network/non-root smoke, SBOM/vulnerability receipts와 fail-closed verification을 유지한다. -Protected-main exact `59ae66d...`의 push `patch-validator-image` run `34179912851`은 현재 operational/cache-seed evidence owner다. Source integration 또는 image run 자체는 cache hit, immutable image digest publication, signature/attestation, reproducibility 또는 rollback을 증명하지 않는다. Issue #66은 terminal operational evidence와 immutable publication evidence가 생길 때까지 open authority다. +Protected-main exact `59ae66d...`의 push `patch-validator-image` run `34179912851`은 현재 operational/cache-seed evidence owner다. 마지막 관찰에서 실제 GitHub-hosted runner의 `Build exact-head patch-validator image` 단계가 in progress이고 이후 static-runtime/smoke/SBOM/vulnerability verification은 아직 pending이다. Source integration 또는 image run 자체는 cache hit, immutable image digest publication, signature/attestation, reproducibility 또는 rollback을 증명하지 않는다. Issue #66은 terminal operational evidence와 immutable publication evidence가 생길 때까지 open authority다. ### Exact-claim evidence receipts — issue #555 / PR #556 -Observed PR #556 exact `29cb77bb943dcd93d65f959f20f50a0622e0ba4a`는 Draft다. `live #556 must be re-fetched before integration`. Predecessor `9d6d52c1dd4fc88203a832b509f4ec28cef3c68a`의 hosted CI `34180062659`는 exact checkout, live-base guard, lockfile control, install, typecheck 뒤 release tests에서 실패했다. Current #556 successor는 해당 documentation-authority invariant를 수리했지만 current #535 `e0a3299...`가 아직 protected source가 아니므로 post-#535 integration authority는 아니다. +Observed PR #556 exact `29cb77bb943dcd93d65f959f20f50a0622e0ba4a`는 Draft다. `live #556 must be re-fetched before integration`. Predecessor `9d6d52c1dd4fc88203a832b509f4ec28cef3c68a`의 hosted CI `34180062659`는 exact checkout, live-base guard, lockfile control, install, typecheck 뒤 release tests에서 실패했다. Current #556 successor는 해당 documentation-authority invariant를 수리했지만 current #535 `82b20b2...`가 아직 protected source가 아니므로 post-#535 integration authority는 아니다. #556의 retained contract는 authenticated producer receipt와 `ClaimEvidenceRequirement` publication authority를 분리한다. Raw current-head source receipt는 context authority일 뿐이고, trusted producer가 exact claim/evidence kind와 finding coordinates를 명시적으로 승인하지 않는 한 blocking finding을 권위화하지 못한다. Requirement/receipt mismatch, wrong coordinates, direct model dictionaries, context-to-finding promotion은 deterministic gate와 publisher 전에 fail closed한다. @@ -73,7 +75,7 @@ Required workflow source만으로 reviewer/maintainer App installation, key cust | Toolchain/license source | merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac` | source complete; release/publication/rights evidence 미완료 | | Durable workflow/state source | merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc` | source complete; deployed runtime/recovery/release evidence 미완료 | | Documentation authority | merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6` + active #559 successor | moving PR/protected truth를 #559에서 code-current 유지 | -| Orchestrator/free consumer | PR #535 exact `e0a329916ab71b1009aa62cbab667a737d511223` | fresh four-GREEN + clean review + current ancestry 후 normal merge | +| Orchestrator/free consumer | PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491` | fresh four-GREEN + clean review + current ancestry 후 normal merge | | Patch-validator cache seed | merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295` | protected operational run/cache behavior + immutable image/release evidence | | Exact-claim receipts | observed PR #556 exact `29cb77bb943dcd93d65f959f20f50a0622e0ba4a` | #535 merge 후 protected-source restack, fresh Security-inclusive gates, immutable release | From 3a50038783defb3cd381533ec8ea5f767ef8eec5 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 12:16:05 +0900 Subject: [PATCH 17/68] test(docs): require current central control-plane snapshot --- test/product-technical-gap-current-candidate-contract.test.ts | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index e86a8a6d4..52e1fb6b3 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -7,7 +7,7 @@ describe("product technical gap current candidate authority", () => { for (const currentTruth of [ "protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd`", - "central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`", + "central `.github/main@7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db`", "PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`", "merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`", "merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`", @@ -23,6 +23,7 @@ describe("product technical gap current candidate authority", () => { expect(baseline).toContain("predecessor GREEN"); for (const staleTruth of [ + "central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`", "protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`", "protected `main@d6394b2aa73e6fc57fccdad74ea38ad87f79e7f8`", "PR #535 exact `e0a329916ab71b1009aa62cbab667a737d511223`", From 352fe711363662889925f34ef98520192d1866cc Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 12:16:51 +0900 Subject: [PATCH 18/68] docs: refresh central control-plane snapshot --- docs/product-technical-gap-baseline.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index ca9246f79..d55dd5c86 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -6,7 +6,7 @@ Current protected source는 GitHub-verified protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd`다. 이 protected revision에는 normal #558 merge와 merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`의 patch-validator default-branch cache-seed contract가 포함돼 있다. Current source SHA는 moving observation이며 future merge 뒤 evergreen identity로 취급하지 않는다. -이 revision 작성 시 moving central control-plane snapshot은 central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`다. Noema runtime의 reviewed immutable central consumer pin은 `c9052e607e5f3cc76e73207e7786b21500721b79`이고 runtime authority 표현은 `ALLOWED_WORKFLOW_SHA = c9052e607e5f3cc76e73207e7786b21500721b79`다. Moving foreign head와 reviewed immutable pin을 같은 권위로 취급하지 않는다. +이 revision 작성 시 moving central control-plane snapshot은 central `.github/main@7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db`다. 이 revision은 #2028의 CodeQL dispatch evidence lookup/binding repair를 포함한다. Noema runtime의 reviewed immutable central consumer pin은 `c9052e607e5f3cc76e73207e7786b21500721b79`이고 runtime authority 표현은 `ALLOWED_WORKFLOW_SHA = c9052e607e5f3cc76e73207e7786b21500721b79`다. Moving foreign head와 reviewed immutable pin을 같은 권위로 취급하지 않으며, central moving head가 전진했다고 Noema consumer pin을 자동 승격하지 않는다. Merged documentation history에는 merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`가 있고, toolchain history에는 merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`, durable workflow/state history에는 merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`, work-conserving concurrency에는 merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`, automation threat-model documentation에는 merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`가 포함돼 있다. 이 SHA들은 protected lineage의 역사 증거이며 open-candidate authority가 아니다. @@ -32,7 +32,7 @@ Test-only `9d67a3cff2700ec2672f78ea05a5e464e7857360`은 contract에 명시된 di 그 exact production head의 reviewer-ci `34182299455` / job `101923650070`에서 631 reviewer tests 자체는 모두 통과했지만 mandatory line+branch coverage가 99.93%로 실패했고, `config.py`의 hostless-URL rejection branch 한 줄이 미실행으로 남았다. Gate를 약화하지 않고 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`에서 `https:///v1` regression 하나를 추가해 해당 fail-closed branch를 직접 실행하도록 수리했다. 이 후속은 production behavior를 바꾸지 않는다. -`82b20b2...`의 wholly fresh generation은 application CI `34182693606`, reviewer-ci `34182693512`, required Security Scan `34182693575`, patch-validator-image `34182693666`이다. 마지막 관찰에서는 queued/pending 상태다. 이전 exact head의 GREEN 또는 RED 이후 일부 성공 evidence는 transfer하지 않는다. Next action은 unchanged exact head가 실패하면 causal repair하고, terminal four-GREEN이면 fresh clean review authority와 unchanged protected ancestry를 다시 확인한 뒤 normal merge하는 것이다. +`82b20b2...`의 wholly fresh generation은 application CI `34182693606`, reviewer-ci `34182693512`, required Security Scan `34182693575`, patch-validator-image `34182693666`이다. 마지막 관찰에서는 queued 상태다. 이전 exact head의 GREEN 또는 RED 이후 일부 성공 evidence는 transfer하지 않는다. Next action은 unchanged exact head가 실패하면 causal repair하고, terminal four-GREEN이면 fresh clean review authority와 unchanged protected ancestry를 다시 확인한 뒤 normal merge하는 것이다. ### Patch-validator default-branch cache seed — merged #558 / issue #66 @@ -71,10 +71,10 @@ Required workflow source만으로 reviewer/maintainer App installation, key cust | Lane | Authority | Integration / completion condition | | --- | --- | --- | | Protected source | live protected main; current observation protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd` | mutation·merge·release 직전 exact protected head 재조회 | -| Central workflow trust | central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`; reviewed pin `c9052e607e5f3cc76e73207e7786b21500721b79` | moving head와 immutable reviewed pin 분리 | +| Central workflow trust | central `.github/main@7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db`; reviewed pin `c9052e607e5f3cc76e73207e7786b21500721b79` | moving head와 immutable reviewed pin 분리; released/reviewed consumer bump 전 자동 승격 금지 | | Toolchain/license source | merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac` | source complete; release/publication/rights evidence 미완료 | | Durable workflow/state source | merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc` | source complete; deployed runtime/recovery/release evidence 미완료 | -| Documentation authority | merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6` + active #559 successor | moving PR/protected truth를 #559에서 code-current 유지 | +| Documentation authority | merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6` + active #559 successor | moving PR/protected/central truth를 #559에서 code-current 유지 | | Orchestrator/free consumer | PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491` | fresh four-GREEN + clean review + current ancestry 후 normal merge | | Patch-validator cache seed | merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295` | protected operational run/cache behavior + immutable image/release evidence | | Exact-claim receipts | observed PR #556 exact `29cb77bb943dcd93d65f959f20f50a0622e0ba4a` | #535 merge 후 protected-source restack, fresh Security-inclusive gates, immutable release | From 27e18bfea984e14eb38d422db2352119632b9b52 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 13:08:01 +0900 Subject: [PATCH 19/68] test(docs): retire stale commercial authority assertions --- docs/product-technical-gap-baseline.md | 22 ++++++++-------- ...umentation-current-trust-authority.test.ts | 23 +++++++++++------ ...cumentation-live-open-pr-authority.test.ts | 25 +++++++++++++------ ...n-post-trust-integration-authority.test.ts | 15 +++++------ ...ion-workflow-concurrency-authority.test.ts | 3 +-- ...cal-gap-current-candidate-contract.test.ts | 6 +++-- 6 files changed, 56 insertions(+), 38 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index d55dd5c86..e9d7d7cf0 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -10,7 +10,7 @@ Current protected source는 GitHub-verified protected `main@59ae66de96b64c8ce51f Merged documentation history에는 merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`가 있고, toolchain history에는 merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`, durable workflow/state history에는 merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`, work-conserving concurrency에는 merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`, automation threat-model documentation에는 merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`가 포함돼 있다. 이 SHA들은 protected lineage의 역사 증거이며 open-candidate authority가 아니다. -#559가 cross-lane commercial baseline과 executable documentation-authority tests를 소유한다. 다른 feature lane에 포함된 과거 baseline blob은 ordinary/non-force convergence 때 current authority로 승계하지 않는다. +#559가 cross-lane commercial baseline과 executable documentation-authority tests를 소유한다. 다른 feature lane에 포함된 과거 baseline blob은 ordinary/non-force semantic convergence 때 current authority로 승계하지 않는다. ## Canonical product boundary @@ -32,21 +32,21 @@ Test-only `9d67a3cff2700ec2672f78ea05a5e464e7857360`은 contract에 명시된 di 그 exact production head의 reviewer-ci `34182299455` / job `101923650070`에서 631 reviewer tests 자체는 모두 통과했지만 mandatory line+branch coverage가 99.93%로 실패했고, `config.py`의 hostless-URL rejection branch 한 줄이 미실행으로 남았다. Gate를 약화하지 않고 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`에서 `https:///v1` regression 하나를 추가해 해당 fail-closed branch를 직접 실행하도록 수리했다. 이 후속은 production behavior를 바꾸지 않는다. -`82b20b2...`의 wholly fresh generation은 application CI `34182693606`, reviewer-ci `34182693512`, required Security Scan `34182693575`, patch-validator-image `34182693666`이다. 마지막 관찰에서는 queued 상태다. 이전 exact head의 GREEN 또는 RED 이후 일부 성공 evidence는 transfer하지 않는다. Next action은 unchanged exact head가 실패하면 causal repair하고, terminal four-GREEN이면 fresh clean review authority와 unchanged protected ancestry를 다시 확인한 뒤 normal merge하는 것이다. +`82b20b2...`의 wholly fresh generation은 application CI `34182693606` SUCCESS, reviewer-ci `34182693512` SUCCESS, required Security Scan `34182693575` SUCCESS, patch-validator-image `34182693666` IN_PROGRESS다. 세 GREEN만으로 four-GREEN을 주장하지 않으며 image가 terminal-success가 되기 전 normal merge하지 않는다. 이전 exact head의 GREEN 또는 RED 이후 일부 성공 evidence도 transfer하지 않는다. Next action은 unchanged image gate가 terminal-success이면 fresh clean review authority와 unchanged protected ancestry를 다시 확인한 뒤 normal merge하고, 실패하면 그 exact failure를 causal repair하는 것이다. ### Patch-validator default-branch cache seed — merged #558 / issue #66 Merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`는 protected source에 포함됐다. Protected workflow는 image-authority path가 protected main에서 바뀔 때 full image verification을 실행해 default-branch BuildKit cache seed를 만들 수 있게 하며, `workflow_dispatch`, PR-scoped cancellation, stale-head refusal, pinned scanner/toolchain, static runtime checks, no-network/non-root smoke, SBOM/vulnerability receipts와 fail-closed verification을 유지한다. -Protected-main exact `59ae66d...`의 push `patch-validator-image` run `34179912851`은 현재 operational/cache-seed evidence owner다. 마지막 관찰에서 실제 GitHub-hosted runner의 `Build exact-head patch-validator image` 단계가 in progress이고 이후 static-runtime/smoke/SBOM/vulnerability verification은 아직 pending이다. Source integration 또는 image run 자체는 cache hit, immutable image digest publication, signature/attestation, reproducibility 또는 rollback을 증명하지 않는다. Issue #66은 terminal operational evidence와 immutable publication evidence가 생길 때까지 open authority다. +Protected-main exact `59ae66d...`의 push `patch-validator-image` run `34179912851`은 terminal SUCCESS다. 따라서 protected-main operational/cache-seed workflow execution은 실제 완료됐지만, 그 성공만으로 cache hit 성능, immutable image digest publication, signature/attestation, reproducibility 또는 rollback을 증명하지 않는다. Issue #66은 immutable publication evidence가 source/run identity와 결합될 때까지 open authority다. ### Exact-claim evidence receipts — issue #555 / PR #556 -Observed PR #556 exact `29cb77bb943dcd93d65f959f20f50a0622e0ba4a`는 Draft다. `live #556 must be re-fetched before integration`. Predecessor `9d6d52c1dd4fc88203a832b509f4ec28cef3c68a`의 hosted CI `34180062659`는 exact checkout, live-base guard, lockfile control, install, typecheck 뒤 release tests에서 실패했다. Current #556 successor는 해당 documentation-authority invariant를 수리했지만 current #535 `82b20b2...`가 아직 protected source가 아니므로 post-#535 integration authority는 아니다. +Observed PR #556 exact `363d62bc888e7b9555ff56bbce4dadc0a61d4efb`는 Draft이며 base는 PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`다. `live #556 must be re-fetched before integration`. 이 head는 predecessor claim-evidence work와 current #535를 ordinary/non-force two-parent convergence로 보존했지만 #535가 아직 protected source가 아니므로 post-#535 final integration authority는 아니다. #556의 retained contract는 authenticated producer receipt와 `ClaimEvidenceRequirement` publication authority를 분리한다. Raw current-head source receipt는 context authority일 뿐이고, trusted producer가 exact claim/evidence kind와 finding coordinates를 명시적으로 승인하지 않는 한 blocking finding을 권위화하지 못한다. Requirement/receipt mismatch, wrong coordinates, direct model dictionaries, context-to-finding promotion은 deterministic gate와 publisher 전에 fail closed한다. -Current #556 exact generation은 application CI `34181585090`, reviewer-ci `34181585132`, patch-validator-image `34181585051`이며 required Security evidence는 아직 final-integration authority로 관찰되지 않았다. 이 run들과 predecessor evidence를 merge authority로 전용하지 않는다. +Current #556 exact generation은 application CI `34185282259` QUEUED, reviewer-ci `34185282319` QUEUED, patch-validator-image `34185282257` QUEUED이고 required Security Scan은 exact-head run inventory에서 ABSENT다. Protected `AGENTS.md`와 central `.github`의 current `security-scan.yml`은 stacked feature-base PR도 default-branch PR과 같은 Security Scan을 받아야 한다고 명시하므로 이 absence는 exemption이 아니라 owner-path routing defect다. Noema는 central workflow source를 복제하거나 gate를 약화하지 않는다. `.github` governance/required-workflow owner가 dispatch/ruleset application을 확인해야 하며, final restack head에도 Security가 없으면 integration을 fail closed한다. #535가 normally integrate된 뒤 resulting protected main과 live #556을 다시 읽고, valid claim-evidence implementation/tests만 ordinary/non-force restack/retarget한다. #559 소유 baseline의 historical blob은 제외하고 `central-review.yml` 등 #535 overlap은 protected semantics와 합성한다. 이후 fresh Security-inclusive exact-head gates와 normal merge가 필요하다. @@ -76,8 +76,8 @@ Required workflow source만으로 reviewer/maintainer App installation, key cust | Durable workflow/state source | merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc` | source complete; deployed runtime/recovery/release evidence 미완료 | | Documentation authority | merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6` + active #559 successor | moving PR/protected/central truth를 #559에서 code-current 유지 | | Orchestrator/free consumer | PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491` | fresh four-GREEN + clean review + current ancestry 후 normal merge | -| Patch-validator cache seed | merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295` | protected operational run/cache behavior + immutable image/release evidence | -| Exact-claim receipts | observed PR #556 exact `29cb77bb943dcd93d65f959f20f50a0622e0ba4a` | #535 merge 후 protected-source restack, fresh Security-inclusive gates, immutable release | +| Patch-validator cache seed | merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`; protected run `34179912851` SUCCESS | protected operational execution complete; immutable image/release evidence 미완료 | +| Exact-claim receipts | observed PR #556 exact `363d62bc888e7b9555ff56bbce4dadc0a61d4efb` | #535 merge 후 protected-source restack, owner-path Security routing repair, fresh Security-inclusive gates, immutable release | ## Evidence semantics and merge rules @@ -91,9 +91,9 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge | Priority | Gap | Buyer/operator impact | Current owner | Authoritative completion evidence | Next executable action | | --- | --- | --- | --- | --- | --- | -| P0 | Strict orchestrator/free consumer | Noema가 provider/model routing authority를 복제하면 제품 경계와 운영 책임이 흐려진다. | PR #535 | fresh exact-head CI/reviewer/Security/image + normal merge | current exact generation 실패 시 causal repair; GREEN이면 current-base/review 재검증 후 normal merge | -| P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority로 승격될 수 있다. | issue #555 / PR #556 | #535 merge 후 restack, execution/research producer evidence, normal merge, immutable release, released consumer RED→GREEN | #535 normal integration 후 live #556을 재구성 | -| P0 | Patch-validator operational publication | source merge만으로 reusable cache와 immutable runtime activation을 증명할 수 없다. | issue #66 | protected-main image/cache receipt + immutable image/signature/SBOM/provenance/reproducibility/rollback | protected operational evidence를 exact source에 결합 | +| P0 | Strict orchestrator/free consumer | Noema가 provider/model routing authority를 복제하면 제품 경계와 운영 책임이 흐려진다. | PR #535 | fresh exact-head CI/reviewer/Security/image + normal merge | image terminal-success면 current-base/review 재검증 후 normal merge; failure면 exact causal repair | +| P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority로 승격될 수 있다. | issue #555 / PR #556 | #535 merge 후 restack, execution/research producer evidence, Security-inclusive gates, normal merge, immutable release, released consumer RED→GREEN | central Security routing owner-path 확인과 #535 normal integration 후 live #556 재구성 | +| P0 | Patch-validator operational publication | source merge만으로 reusable cache와 immutable runtime activation을 증명할 수 없다. | issue #66 | protected-main image/cache receipt + immutable image/signature/SBOM/provenance/reproducibility/rollback | successful protected run `34179912851`을 immutable publication evidence와 결합 | | P0 | Toolchain/license release evidence | source dependency remediation만으로 실제 배포 artifact 권리와 재현성을 증명할 수 없다. | issue #531 | protected exact release package/image/SBOM/provenance/reproducibility/NOTICE/rights | release-ready protected exact head에서만 publication evidence 생성 | | P0 | Reviewer/Maintainer production identity | source control만으로 App installation, key custody/rotation, bounded publication authority를 증명할 수 없다. | issues #29 / #227 | live installation/permissions/key-custody/rotation + bounded publication/recovery receipt | approved control-plane evidence와 source evidence를 분리 보존 | | P0 | Governance enforceability | workflow source만으로 approval/deletion/rewrite/break-glass 정책 전체를 증명할 수 없다. | issue #27 | live ruleset/protection audit + observed required-workflow behavior | protected mutation 직전 governance 재조회 | @@ -103,4 +103,4 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge ## Completion discipline -각 gap은 Authoritative completion evidence가 실제로 존재하고 current source/head에 결합될 때만 닫는다. 문서 존재, synthetic fixture, model judgement, stale workflow result를 완료 증거로 사용하지 않는다. Release-ready exact protected head가 없으면 version/tag/package/SBOM/provenance/rollback을 제조하지 않는다. +각 gap은 Authoritative completion evidence가 실제로 존재하고 current source/head에 결합될 때만 닫는다. 문서 존재, synthetic fixture, model judgement, stale workflow result를 완료 증거로 사용하지 않는다. Release-ready exact protected head가 없으면 version/tag/package/SBOM/provenance/rollback을 제조하지 않는다. \ No newline at end of file diff --git a/test/documentation-current-trust-authority.test.ts b/test/documentation-current-trust-authority.test.ts index 112bfdc86..ced2853b8 100644 --- a/test/documentation-current-trust-authority.test.ts +++ b/test/documentation-current-trust-authority.test.ts @@ -2,18 +2,25 @@ import { readFileSync } from "node:fs"; import { describe, expect, it } from "vitest"; describe("current protected trust authority documentation", () => { - it("separates construction snapshots, live-read moving heads, and immutable reviewed pins", () => { + it("separates live moving heads from immutable reviewed pins", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); - expect(baseline).toContain("protected `main@099d7d89a51bca4a2cf7c6b285b50ffadd08d001`"); - expect(baseline).toContain("central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`"); + expect(baseline).toContain("protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd`"); + expect(baseline).toContain("central `.github/main@7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db`"); expect(baseline).toContain("`ALLOWED_WORKFLOW_SHA = c9052e607e5f3cc76e73207e7786b21500721b79`"); + expect(baseline).toContain("Current source SHA는 moving observation이며 future merge 뒤 evergreen identity로 취급하지 않는다"); + expect(baseline).toContain("Moving foreign head와 reviewed immutable pin을 같은 권위로 취급하지 않으며"); expect(baseline).toContain("merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`"); expect(baseline).toContain("merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`"); - expect(baseline).toContain("Current protected source identity는 mutation·merge·release 직전에 live-read한다"); - expect(baseline).toContain("Moving central main과 reviewed immutable consumer source identity를 같은 권위로 취급하지 않는다"); - expect(baseline).not.toContain("protected `main@d6394b2aa73e6fc57fccdad74ea38ad87f79e7f8`"); - expect(baseline).not.toContain("protected `main@e6de53a1c2902cddc09e77a58efb82420cd8f5db`"); - expect(baseline).not.toContain("Central workflow authority는 `.github/main@c9052e607e5f3cc76e73207e7786b21500721b79`다."); + + for (const staleAuthority of [ + "protected `main@099d7d89a51bca4a2cf7c6b285b50ffadd08d001`", + "central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`", + "protected `main@d6394b2aa73e6fc57fccdad74ea38ad87f79e7f8`", + "protected `main@e6de53a1c2902cddc09e77a58efb82420cd8f5db`", + "Central workflow authority는 `.github/main@c9052e607e5f3cc76e73207e7786b21500721b79`다.", + ]) { + expect(baseline).not.toContain(staleAuthority); + } }); }); diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index ce209ffdc..d6db89e41 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -6,17 +6,26 @@ describe("product-technical gap baseline live open-PR authority", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); expect(baseline).toContain("protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd`"); - expect(baseline).toContain("PR #535 exact `551d81da28b0c03ca44deedf60e95125dcceb81b`"); + expect(baseline).toContain("PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`"); expect(baseline).toContain("merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`"); expect(baseline).toContain("merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`"); expect(baseline).toContain("merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`"); - expect(baseline).toContain("observed PR #556 exact `29cb77bb943dcd93d65f959f20f50a0622e0ba4a`"); + expect(baseline).toContain("Observed PR #556 exact `363d62bc888e7b9555ff56bbce4dadc0a61d4efb`"); + expect(baseline).toContain("base는 PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`"); expect(baseline).toContain("live #556 must be re-fetched before integration"); + expect(baseline).toContain("required Security Scan은 exact-head run inventory에서 ABSENT"); + expect(baseline).toContain("exemption이 아니라 owner-path routing defect"); expect(baseline).toContain("issue #555 / PR #556"); - expect(baseline).not.toContain("PR #535 exact `06ed62fcc5611e9b25ef38b06e87e7521dbf1be1`"); - expect(baseline).not.toContain("PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a`"); - expect(baseline).not.toContain("PR #558 exact `f2aa8570d952cc0a371da161e651472c080e00ce`"); - expect(baseline).not.toContain("observed PR #556 exact `9d6d52c1dd4fc88203a832b509f4ec28cef3c68a`"); - expect(baseline).not.toContain("observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305`"); + + for (const staleAuthority of [ + "PR #535 exact `551d81da28b0c03ca44deedf60e95125dcceb81b`", + "PR #535 exact `06ed62fcc5611e9b25ef38b06e87e7521dbf1be1`", + "PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a`", + "observed PR #556 exact `29cb77bb943dcd93d65f959f20f50a0622e0ba4a`", + "observed PR #556 exact `9d6d52c1dd4fc88203a832b509f4ec28cef3c68a`", + "observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305`", + ]) { + expect(baseline).not.toContain(staleAuthority); + } }); -}); \ No newline at end of file +}); diff --git a/test/documentation-post-trust-integration-authority.test.ts b/test/documentation-post-trust-integration-authority.test.ts index cdc522528..66742b41b 100644 --- a/test/documentation-post-trust-integration-authority.test.ts +++ b/test/documentation-post-trust-integration-authority.test.ts @@ -2,25 +2,26 @@ import { readFileSync } from "node:fs"; import { describe, expect, it } from "vitest"; describe("post-trust-integration documentation authority", () => { - it("binds commercial-gap construction evidence to protected integrations without freezing moving heads", () => { + it("binds commercial-gap evidence to current protected integrations without freezing moving heads", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); for (const protectedHistory of [ - "protected `main@099d7d89a51bca4a2cf7c6b285b50ffadd08d001`", - "merged PR #536 exact `4fe6fe84611dfa1d69d8e0712b72b278429524d0`", - "merged PR #548 exact `fb44888bd571cae61dbfc93c1b46675855fbfc9c`", + "protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd`", + "merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`", + "merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`", "merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`", "merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`", "merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`", "merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`", - "central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`", + "central `.github/main@7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db`", ]) { expect(baseline).toContain(protectedHistory); } expect(baseline).toContain("ordinary/non-force semantic convergence"); expect(baseline).toContain("predecessor GREEN"); - expect(baseline).toContain("Construction snapshot"); - expect(baseline).not.toContain("protected `main@d6394b2aa73e6fc57fccdad74ea38ad87f79e7f8`"); + expect(baseline).toContain("moving observation"); + expect(baseline).not.toContain("protected `main@099d7d89a51bca4a2cf7c6b285b50ffadd08d001`"); + expect(baseline).not.toContain("central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`"); expect(baseline).not.toContain("PR #542 exact `195fdd70b267332f246d93beb95fa96fabade52e`"); expect(baseline).not.toContain("PR #540은 아직 merge authority가 아니다"); }); diff --git a/test/documentation-workflow-concurrency-authority.test.ts b/test/documentation-workflow-concurrency-authority.test.ts index 84ab938c7..394136fa9 100644 --- a/test/documentation-workflow-concurrency-authority.test.ts +++ b/test/documentation-workflow-concurrency-authority.test.ts @@ -6,9 +6,8 @@ describe("workflow-concurrency documentation authority", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); expect(baseline).toContain("merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`"); - expect(baseline).toContain("#550은 PR-scoped supersession cancellation과 work-conserving dispatch를"); + expect(baseline).toContain("#550은 PR-scoped supersession cancellation과 work-conserving dispatch를 protected source에 통합했다"); expect(baseline).toContain("merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`"); - expect(baseline).toContain("protected work-conserving concurrency/admission"); expect(baseline).toContain("pinned `workerd@1.20260625.1` + `esbuild@0.28.1`"); expect(baseline).not.toContain("PR #540은 아직 merge authority가 아니다"); expect(baseline).not.toContain("patch-validator-image 34155490034"); diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index 52e1fb6b3..7e9de22e9 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -12,7 +12,7 @@ describe("product technical gap current candidate authority", () => { "merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`", "merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`", "merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`", - "observed PR #556 exact `29cb77bb943dcd93d65f959f20f50a0622e0ba4a`", + "Observed PR #556 exact `363d62bc888e7b9555ff56bbce4dadc0a61d4efb`", "merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`", "merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`", "merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`", @@ -21,6 +21,7 @@ describe("product technical gap current candidate authority", () => { } expect(baseline).toContain("live #556 must be re-fetched before integration"); expect(baseline).toContain("predecessor GREEN"); + expect(baseline).toContain("required Security Scan은 exact-head run inventory에서 ABSENT"); for (const staleTruth of [ "central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`", @@ -31,6 +32,7 @@ describe("product technical gap current candidate authority", () => { "PR #535 exact `06ed62fcc5611e9b25ef38b06e87e7521dbf1be1`", "PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a`", "PR #558 exact `f2aa8570d952cc0a371da161e651472c080e00ce`", + "observed PR #556 exact `29cb77bb943dcd93d65f959f20f50a0622e0ba4a`", "observed PR #556 exact `9d6d52c1dd4fc88203a832b509f4ec28cef3c68a`", "observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305`", "PR #540은 아직 merge authority가 아니다", @@ -38,4 +40,4 @@ describe("product technical gap current candidate authority", () => { expect(baseline).not.toContain(staleTruth); } }); -}); \ No newline at end of file +}); From f3fb518c5d9e39d8dbc001c93b69e28046483114 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 14:35:42 +0900 Subject: [PATCH 20/68] docs: refresh protected and claim-evidence authority --- docs/product-technical-gap-baseline.md | 52 ++++++++++++-------------- 1 file changed, 24 insertions(+), 28 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index e9d7d7cf0..422538ad9 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -4,11 +4,11 @@ 이 문서는 protected source, active candidate, transient workflow evidence와 foreign-owner authority를 분리한다. Open PR exact head, protected base, required workflow, review thread, release와 central dependency는 mutation·merge·release 직전에 다시 읽는다. predecessor GREEN, queued/pending/in-progress/skipped/cancelled run, 오래된 PR base snapshot과 scanner/model judgement는 다음 revision의 merge authority로 전용하지 않는다. -Current protected source는 GitHub-verified protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd`다. 이 protected revision에는 normal #558 merge와 merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`의 patch-validator default-branch cache-seed contract가 포함돼 있다. Current source SHA는 moving observation이며 future merge 뒤 evergreen identity로 취급하지 않는다. +Current protected source는 GitHub-verified protected `main@0dbfceb850cda3a016ceb39ae1c8a1a96a9f2ad5`다. 이 protected revision에는 normal #535 merge가 포함돼 있고, merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`의 strict `orchestrator/free` consumer, provider-endpoint fail-closed contract와 reviewer `timeout=None`/`max_retries=0` semantics가 protected source가 됐다. Current source SHA는 moving observation이며 future merge 뒤 evergreen identity로 취급하지 않는다. -이 revision 작성 시 moving central control-plane snapshot은 central `.github/main@7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db`다. 이 revision은 #2028의 CodeQL dispatch evidence lookup/binding repair를 포함한다. Noema runtime의 reviewed immutable central consumer pin은 `c9052e607e5f3cc76e73207e7786b21500721b79`이고 runtime authority 표현은 `ALLOWED_WORKFLOW_SHA = c9052e607e5f3cc76e73207e7786b21500721b79`다. Moving foreign head와 reviewed immutable pin을 같은 권위로 취급하지 않으며, central moving head가 전진했다고 Noema consumer pin을 자동 승격하지 않는다. +이 revision 작성 시 moving central control-plane snapshot은 central `.github/main@7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db`다. Noema runtime의 reviewed immutable central consumer pin은 `c9052e607e5f3cc76e73207e7786b21500721b79`이고 runtime authority 표현은 `ALLOWED_WORKFLOW_SHA = c9052e607e5f3cc76e73207e7786b21500721b79`다. Moving foreign head와 reviewed immutable pin을 같은 권위로 취급하지 않으며, central moving head가 전진했다고 Noema consumer pin을 자동 승격하지 않는다. -Merged documentation history에는 merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`가 있고, toolchain history에는 merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`, durable workflow/state history에는 merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`, work-conserving concurrency에는 merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`, automation threat-model documentation에는 merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`가 포함돼 있다. 이 SHA들은 protected lineage의 역사 증거이며 open-candidate authority가 아니다. +Merged documentation history에는 merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`가 있고, toolchain history에는 merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`, durable workflow/state history에는 merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`, work-conserving concurrency에는 merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`, automation threat-model documentation에는 merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`, patch-validator default-branch cache-seed history에는 merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`가 포함돼 있다. 이 SHA들은 protected lineage의 역사 증거이며 open-candidate authority가 아니다. #559가 cross-lane commercial baseline과 executable documentation-authority tests를 소유한다. 다른 feature lane에 포함된 과거 baseline blob은 ordinary/non-force semantic convergence 때 current authority로 승계하지 않는다. @@ -18,41 +18,37 @@ Noema Core Domain은 **Agent Runtime**과 **Workflow / Task Execution**이다. * `contextual-orchestrator`는 provider/model discovery, routing, retry/failover, test-time compute와 provider credential을 소유한다. Noema는 released gateway contract와 canonical `orchestrator/free` alias를 소비할 뿐 direct provider SDK, provider key, provider/model/group fallback policy를 소유하지 않는다. `.github`는 organization reusable workflow와 control-plane source를 소유한다. `quarantine-sandbox-runtime`, Wardnet, EgressWeave, AppGuardrail은 isolation/security/outbound truth를 각자 소유한다. Keyverse는 identity backend owner다. `context-graph-contracts`와 `enterprise-architecture-core`는 released/versioned contract로만 연결하고 mutable sibling PR source, copied domain table, cross-service SQL을 runtime truth로 사용하지 않는다. -#550은 PR-scoped supersession cancellation과 work-conserving dispatch를 protected source에 통합했다. #542는 Durable Workflow / Task Execution과 State / Checkpoint의 atomic task claim, checkpoint CAS/replay, effect-start/terminal authority, cancellation/recovery 및 retained-provenance validation을 protected source로 만들었다. ADR 0013은 deployed Durable Object transaction/runtime evidence가 없으므로 `Proposed`를 유지한다. #540은 historical Wrangler/Miniflare/Sharp/Libvips tooling path를 제거하고 pinned `workerd@1.20260625.1` + `esbuild@0.28.1`, canonical lock/license evidence와 patch-validator dependency pruning을 protected source에 통합했다. +#550은 PR-scoped supersession cancellation과 work-conserving dispatch를 protected source에 통합했다. #542는 Durable Workflow / Task Execution과 State / Checkpoint의 atomic task claim, checkpoint CAS/replay, effect-start/terminal authority, cancellation/recovery 및 retained-provenance validation을 protected source로 만들었다. ADR 0013은 deployed Durable Object transaction/runtime evidence가 없으므로 `Proposed`를 유지한다. #540은 historical Wrangler/Miniflare/Sharp/Libvips tooling path를 제거하고 pinned `workerd@1.20260625.1` + `esbuild@0.28.1`, canonical lock/license evidence와 patch-validator dependency pruning을 protected source에 통합했다. #535는 repository-selected provider/model authority를 제거하고 canonical `orchestrator/free` alias와 contextual-orchestrator gateway boundary를 protected source에 통합했다. ## Active candidate convergence — 2026-09-08 KST -### Orchestrator/free consumer — PR #535 - -PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`는 Draft다. #558 integration 뒤 branch를 force 없이 ordinary two-parent convergence했고 current compare는 ahead-only, `behind_by=0`, merge-base exact protected main이다. - -Fresh exact-head review에서 JavaScript gateway preflight와 `contracts/orchestrator-gateway.json`이 direct-provider host, URL userinfo/query/fragment, non-`/v1` endpoint를 거부하는 반면 Python reviewer boundary는 임의 HTTPS endpoint를 허용하는 cross-language authority drift가 확인됐다. 그 상태에서는 `orchestrator/free` model alias를 유지하더라도 직접 provider 또는 malformed OpenAI-compatible HTTPS endpoint에 gateway credential을 붙일 수 있었다. +### Exact-claim evidence receipts — issue #555 / PR #556 -Test-only `9d67a3cff2700ec2672f78ea05a5e464e7857360`은 contract에 명시된 direct-provider host 여섯 개, URL authority metadata, `/v1` path shape와 정상 gateway endpoint를 executable regression으로 추가했다. 후속 causal repair가 PR-scoped supersession을 일으켜 이 test-only hosted generation은 실행 전에 cancelled됐으므로 hosted RED로 주장하지 않는다. Production `e0a329916ab71b1009aa62cbab667a737d511223`은 `reviewer/noema_reviewer/config.py`에 동일 endpoint invariant를 적용하고 exact `orchestrator/free`, reviewer `timeout=None`, `max_retries=0`, loopback-only HTTP development allowance와 contextual-orchestrator provider/model ownership을 보존했다. +Observed PR #556 exact `920eb7be0c3f57c5f149328a08beddc13339a338`는 Draft이고 default `main`을 base로 한다. Prerequisite #535는 이미 normal merge돼 protected `main@0dbfceb850cda3a016ceb39ae1c8a1a96a9f2ad5`가 되었으며, #556은 그 protected source 위로 ordinary/non-force restack/retarget됐다. `live #556 must be re-fetched before integration`이며 predecessor head의 gate나 review evidence는 전용하지 않는다. -그 exact production head의 reviewer-ci `34182299455` / job `101923650070`에서 631 reviewer tests 자체는 모두 통과했지만 mandatory line+branch coverage가 99.93%로 실패했고, `config.py`의 hostless-URL rejection branch 한 줄이 미실행으로 남았다. Gate를 약화하지 않고 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`에서 `https:///v1` regression 하나를 추가해 해당 fail-closed branch를 직접 실행하도록 수리했다. 이 후속은 production behavior를 바꾸지 않는다. +#556의 retained contract는 authenticated producer receipt와 `ClaimEvidenceRequirement` publication authority를 분리한다. Raw current-head source receipt는 context authority일 뿐이고, trusted producer가 exact claim/evidence kind와 finding coordinates를 명시적으로 승인하지 않는 한 blocking finding을 권위화하지 못한다. Requirement/receipt mismatch, wrong coordinates, direct model dictionaries, context-to-finding promotion은 deterministic gate와 publisher 전에 fail closed한다. -`82b20b2...`의 wholly fresh generation은 application CI `34182693606` SUCCESS, reviewer-ci `34182693512` SUCCESS, required Security Scan `34182693575` SUCCESS, patch-validator-image `34182693666` IN_PROGRESS다. 세 GREEN만으로 four-GREEN을 주장하지 않으며 image가 terminal-success가 되기 전 normal merge하지 않는다. 이전 exact head의 GREEN 또는 RED 이후 일부 성공 evidence도 transfer하지 않는다. Next action은 unchanged image gate가 terminal-success이면 fresh clean review authority와 unchanged protected ancestry를 다시 확인한 뒤 normal merge하고, 실패하면 그 exact failure를 causal repair하는 것이다. +Fresh source-authority review에서 exported `produce_source_claim_receipt()`가 `claim`과 `source_line_bytes`를 독립적으로 seal하고 서로 같은 의미인지 확인하지 않는 결함이 확인됐다. 기존 producer test는 실제 line `run: cargo generate-lockfile --locked\n`에 대해 paraphrase claim `the workflow invokes cargo generate-lockfile --locked`를 성공적으로 receipt화하고 있었다. 이 상태에서는 producer call이 path/line hash와 별개의 claim digest를 결합해 exact source finding처럼 보이는 권위를 만들 수 있었다. -### Patch-validator default-branch cache seed — merged #558 / issue #66 +Test-only `dbab4cdc150d4973002f8b61173282f7c7542725`는 claim이 exact source line에서 파생돼야 한다는 regression contract를 추가했다. Hosted workflow generation은 materialize됐지만 후속 branch mutation의 정상 `cancel-in-progress`에 의해 test execution 전에 cancelled됐으므로 hosted RED로 주장하지 않는다. Production `440346ee73e60e87915bd3027a774e24d3ac5124`는 artifact 생성 전에 exactly-one-line UTF-8 decoding과 claim equality를 fail closed로 강제했다. Current exact `920eb7be0c3f57c5f149328a08beddc13339a338`은 LF/CRLF/unterminated line, paraphrase mismatch, embedded multi-line bytes와 invalid UTF-8 edge를 추가로 고정한다. -Merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`는 protected source에 포함됐다. Protected workflow는 image-authority path가 protected main에서 바뀔 때 full image verification을 실행해 default-branch BuildKit cache seed를 만들 수 있게 하며, `workflow_dispatch`, PR-scoped cancellation, stale-head refusal, pinned scanner/toolchain, static runtime checks, no-network/non-root smoke, SBOM/vulnerability receipts와 fail-closed verification을 유지한다. +Current #556 exact generation은 application CI `34190991491`, reviewer-ci `34190991526`, required Security Scan `34190991567`, patch-validator-image `34190991473`이다. 이 revision 작성 시 네 lane은 모두 non-terminal이며 absent/queued/pending/in-progress/cancelled evidence는 passing으로 취급하지 않는다. Default `main` retarget 뒤 required Security Scan이 실제 materialize되므로, 이전 stacked-head Security absence는 이 concrete PR의 현재 gate exemption이 아니다. Central `.github#2037`은 future genuinely stacked PR에 대한 별도 owner-path defect로 남긴다. -Protected-main exact `59ae66d...`의 push `patch-validator-image` run `34179912851`은 terminal SUCCESS다. 따라서 protected-main operational/cache-seed workflow execution은 실제 완료됐지만, 그 성공만으로 cache hit 성능, immutable image digest publication, signature/attestation, reproducibility 또는 rollback을 증명하지 않는다. Issue #66은 immutable publication evidence가 source/run identity와 결합될 때까지 open authority다. +Remaining supply-chain boundary는 exact stdout/stderr handoff, trusted research producer, immutable Noema release, released central `.github#1641` consumer bump와 unchanged original/synonym corpus RED→GREEN이다. -### Exact-claim evidence receipts — issue #555 / PR #556 +### Cross-lane documentation authority — PR #559 -Observed PR #556 exact `363d62bc888e7b9555ff56bbce4dadc0a61d4efb`는 Draft이며 base는 PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`다. `live #556 must be re-fetched before integration`. 이 head는 predecessor claim-evidence work와 current #535를 ordinary/non-force two-parent convergence로 보존했지만 #535가 아직 protected source가 아니므로 post-#535 final integration authority는 아니다. +#559는 이 baseline과 다섯 executable documentation-authority tests의 sole writer다. #535 normal integration과 #556 current-head mutation을 반영해 protected source와 active-candidate identity를 다시 수렴시켜야 한다. Feature-lane source, historical #556 baseline blob이나 predecessor gate result를 #559 authority로 전용하지 않는다. #559 자신의 source mutation도 predecessor workflow evidence를 무효화하므로 final exact head에서 fresh CI/reviewer/Security/image가 필요하다. -#556의 retained contract는 authenticated producer receipt와 `ClaimEvidenceRequirement` publication authority를 분리한다. Raw current-head source receipt는 context authority일 뿐이고, trusted producer가 exact claim/evidence kind와 finding coordinates를 명시적으로 승인하지 않는 한 blocking finding을 권위화하지 못한다. Requirement/receipt mismatch, wrong coordinates, direct model dictionaries, context-to-finding promotion은 deterministic gate와 publisher 전에 fail closed한다. +## Protected but incomplete commercial evidence -Current #556 exact generation은 application CI `34185282259` QUEUED, reviewer-ci `34185282319` QUEUED, patch-validator-image `34185282257` QUEUED이고 required Security Scan은 exact-head run inventory에서 ABSENT다. Protected `AGENTS.md`와 central `.github`의 current `security-scan.yml`은 stacked feature-base PR도 default-branch PR과 같은 Security Scan을 받아야 한다고 명시하므로 이 absence는 exemption이 아니라 owner-path routing defect다. Noema는 central workflow source를 복제하거나 gate를 약화하지 않는다. `.github` governance/required-workflow owner가 dispatch/ruleset application을 확인해야 하며, final restack head에도 Security가 없으면 integration을 fail closed한다. +### Orchestrator/free consumer — merged #535 -#535가 normally integrate된 뒤 resulting protected main과 live #556을 다시 읽고, valid claim-evidence implementation/tests만 ordinary/non-force restack/retarget한다. #559 소유 baseline의 historical blob은 제외하고 `central-review.yml` 등 #535 overlap은 protected semantics와 합성한다. 이후 fresh Security-inclusive exact-head gates와 normal merge가 필요하다. +Merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`는 protected `main@0dbfceb850cda3a016ceb39ae1c8a1a96a9f2ad5`에 normal integration됐다. Exact candidate가 application CI/reviewer-ci/required Security/patch-validator-image terminal SUCCESS와 clean review authority를 충족한 뒤 merge됐으며, provider/model routing은 `contextual-orchestrator` owner에 남고 Noema는 `orchestrator/free`와 gateway-only credentials를 소비한다. Source integration 자체는 immutable Noema package/release, SBOM/provenance/reproducibility 또는 downstream consumer activation을 증명하지 않는다. -Remaining supply-chain boundary는 exact stdout/stderr handoff, trusted research producer, immutable Noema release, released central `.github#1641` consumer bump와 unchanged original corpus RED→GREEN이다. +### Patch-validator default-branch cache seed — merged #558 / issue #66 -## Protected but incomplete commercial evidence +Merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`는 protected source에 포함됐다. Protected-main prior push `patch-validator-image` run `34179912851`은 terminal SUCCESS다. 따라서 operational/cache-seed workflow execution은 실제 완료됐지만, 그 성공만으로 cache hit 성능, immutable image digest publication, signature/attestation, reproducibility 또는 rollback을 증명하지 않는다. Issue #66은 immutable publication evidence가 source/run identity와 결합될 때까지 open authority다. ### Toolchain and inbound rights — issue #531 / merged #540 @@ -70,14 +66,14 @@ Required workflow source만으로 reviewer/maintainer App installation, key cust | Lane | Authority | Integration / completion condition | | --- | --- | --- | -| Protected source | live protected main; current observation protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd` | mutation·merge·release 직전 exact protected head 재조회 | +| Protected source | live protected main; current observation protected `main@0dbfceb850cda3a016ceb39ae1c8a1a96a9f2ad5` | mutation·merge·release 직전 exact protected head 재조회 | | Central workflow trust | central `.github/main@7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db`; reviewed pin `c9052e607e5f3cc76e73207e7786b21500721b79` | moving head와 immutable reviewed pin 분리; released/reviewed consumer bump 전 자동 승격 금지 | | Toolchain/license source | merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac` | source complete; release/publication/rights evidence 미완료 | | Durable workflow/state source | merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc` | source complete; deployed runtime/recovery/release evidence 미완료 | | Documentation authority | merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6` + active #559 successor | moving PR/protected/central truth를 #559에서 code-current 유지 | -| Orchestrator/free consumer | PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491` | fresh four-GREEN + clean review + current ancestry 후 normal merge | +| Orchestrator/free consumer | merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491` | protected source complete; immutable Noema release와 released consumer evidence 미완료 | | Patch-validator cache seed | merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`; protected run `34179912851` SUCCESS | protected operational execution complete; immutable image/release evidence 미완료 | -| Exact-claim receipts | observed PR #556 exact `363d62bc888e7b9555ff56bbce4dadc0a61d4efb` | #535 merge 후 protected-source restack, owner-path Security routing repair, fresh Security-inclusive gates, immutable release | +| Exact-claim receipts | observed PR #556 exact `920eb7be0c3f57c5f149328a08beddc13339a338` | fresh Security-inclusive exact-head gates, clean review, normal merge, execution/research producer evidence, immutable release | ## Evidence semantics and merge rules @@ -91,8 +87,8 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge | Priority | Gap | Buyer/operator impact | Current owner | Authoritative completion evidence | Next executable action | | --- | --- | --- | --- | --- | --- | -| P0 | Strict orchestrator/free consumer | Noema가 provider/model routing authority를 복제하면 제품 경계와 운영 책임이 흐려진다. | PR #535 | fresh exact-head CI/reviewer/Security/image + normal merge | image terminal-success면 current-base/review 재검증 후 normal merge; failure면 exact causal repair | -| P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority로 승격될 수 있다. | issue #555 / PR #556 | #535 merge 후 restack, execution/research producer evidence, Security-inclusive gates, normal merge, immutable release, released consumer RED→GREEN | central Security routing owner-path 확인과 #535 normal integration 후 live #556 재구성 | +| P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority로 승격되거나 source claim이 cited line과 분리되면 blocking review가 잘못 권위화될 수 있다. | issue #555 / PR #556 | exact source-claim binding + execution/research producer evidence + fresh gates + normal merge + immutable release + released consumer RED→GREEN | exact `920eb7be...` gates/review 확인; failure면 causal repair, four-GREEN이면 normal merge | +| P0 | Strict orchestrator/free consumer release | Source는 protected됐지만 immutable released package와 central consumer activation이 없으면 commercial integration contract가 완결되지 않는다. | merged #535 + release lane | protected exact release/tag/package/SBOM/provenance/reproducibility + released consumer | release-ready protected head에서만 immutable publication evidence 생성 | | P0 | Patch-validator operational publication | source merge만으로 reusable cache와 immutable runtime activation을 증명할 수 없다. | issue #66 | protected-main image/cache receipt + immutable image/signature/SBOM/provenance/reproducibility/rollback | successful protected run `34179912851`을 immutable publication evidence와 결합 | | P0 | Toolchain/license release evidence | source dependency remediation만으로 실제 배포 artifact 권리와 재현성을 증명할 수 없다. | issue #531 | protected exact release package/image/SBOM/provenance/reproducibility/NOTICE/rights | release-ready protected exact head에서만 publication evidence 생성 | | P0 | Reviewer/Maintainer production identity | source control만으로 App installation, key custody/rotation, bounded publication authority를 증명할 수 없다. | issues #29 / #227 | live installation/permissions/key-custody/rotation + bounded publication/recovery receipt | approved control-plane evidence와 source evidence를 분리 보존 | @@ -103,4 +99,4 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge ## Completion discipline -각 gap은 Authoritative completion evidence가 실제로 존재하고 current source/head에 결합될 때만 닫는다. 문서 존재, synthetic fixture, model judgement, stale workflow result를 완료 증거로 사용하지 않는다. Release-ready exact protected head가 없으면 version/tag/package/SBOM/provenance/rollback을 제조하지 않는다. \ No newline at end of file +각 gap은 Authoritative completion evidence가 실제로 존재하고 current source/head에 결합될 때만 닫는다. 문서 존재, synthetic fixture, model judgement, stale workflow result를 완료 증거로 사용하지 않는다. Release-ready exact protected head가 없으면 version/tag/package/SBOM/provenance/rollback을 제조하지 않는다. From adc90385c9e2869b1b4252cf6634ee7d0b329ae5 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 14:36:55 +0900 Subject: [PATCH 21/68] test(docs): track protected #535 integration --- test/documentation-current-trust-authority.test.ts | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/test/documentation-current-trust-authority.test.ts b/test/documentation-current-trust-authority.test.ts index ced2853b8..ca444eacc 100644 --- a/test/documentation-current-trust-authority.test.ts +++ b/test/documentation-current-trust-authority.test.ts @@ -5,15 +5,17 @@ describe("current protected trust authority documentation", () => { it("separates live moving heads from immutable reviewed pins", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); - expect(baseline).toContain("protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd`"); + expect(baseline).toContain("protected `main@0dbfceb850cda3a016ceb39ae1c8a1a96a9f2ad5`"); expect(baseline).toContain("central `.github/main@7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db`"); expect(baseline).toContain("`ALLOWED_WORKFLOW_SHA = c9052e607e5f3cc76e73207e7786b21500721b79`"); expect(baseline).toContain("Current source SHA는 moving observation이며 future merge 뒤 evergreen identity로 취급하지 않는다"); expect(baseline).toContain("Moving foreign head와 reviewed immutable pin을 같은 권위로 취급하지 않으며"); + expect(baseline).toContain("merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`"); expect(baseline).toContain("merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`"); expect(baseline).toContain("merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`"); for (const staleAuthority of [ + "protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd`", "protected `main@099d7d89a51bca4a2cf7c6b285b50ffadd08d001`", "central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`", "protected `main@d6394b2aa73e6fc57fccdad74ea38ad87f79e7f8`", From bab98b4f1545596ccafef72d7eaf932a6b62e7b4 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 14:37:06 +0900 Subject: [PATCH 22/68] test(docs): track current claim-evidence head --- ...cumentation-live-open-pr-authority.test.ts | 20 +++++++++---------- 1 file changed, 10 insertions(+), 10 deletions(-) diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index d6db89e41..0e668e143 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -2,28 +2,28 @@ import { readFileSync } from "node:fs"; import { describe, expect, it } from "vitest"; describe("product-technical gap baseline live open-PR authority", () => { - it("separates active source lanes from integrated protected history and observation-scoped downstream heads", () => { + it("separates integrated protected history from the current claim-evidence candidate", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); - expect(baseline).toContain("protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd`"); - expect(baseline).toContain("PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`"); + expect(baseline).toContain("protected `main@0dbfceb850cda3a016ceb39ae1c8a1a96a9f2ad5`"); + expect(baseline).toContain("merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`"); expect(baseline).toContain("merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`"); expect(baseline).toContain("merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`"); expect(baseline).toContain("merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`"); - expect(baseline).toContain("Observed PR #556 exact `363d62bc888e7b9555ff56bbce4dadc0a61d4efb`"); - expect(baseline).toContain("base는 PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`"); + expect(baseline).toContain("Observed PR #556 exact `920eb7be0c3f57c5f149328a08beddc13339a338`"); + expect(baseline).toContain("default `main`을 base로 한다"); expect(baseline).toContain("live #556 must be re-fetched before integration"); - expect(baseline).toContain("required Security Scan은 exact-head run inventory에서 ABSENT"); - expect(baseline).toContain("exemption이 아니라 owner-path routing defect"); + expect(baseline).toContain("Test-only `dbab4cdc150d4973002f8b61173282f7c7542725`"); + expect(baseline).toContain("Production `440346ee73e60e87915bd3027a774e24d3ac5124`"); + expect(baseline).toContain("required Security Scan `34190991567`"); expect(baseline).toContain("issue #555 / PR #556"); for (const staleAuthority of [ - "PR #535 exact `551d81da28b0c03ca44deedf60e95125dcceb81b`", - "PR #535 exact `06ed62fcc5611e9b25ef38b06e87e7521dbf1be1`", - "PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a`", + "Observed PR #556 exact `363d62bc888e7b9555ff56bbce4dadc0a61d4efb`", "observed PR #556 exact `29cb77bb943dcd93d65f959f20f50a0622e0ba4a`", "observed PR #556 exact `9d6d52c1dd4fc88203a832b509f4ec28cef3c68a`", "observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305`", + "required Security Scan은 exact-head run inventory에서 ABSENT", ]) { expect(baseline).not.toContain(staleAuthority); } From d159e248438297018854f1c422d40556b221329a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 14:37:16 +0900 Subject: [PATCH 23/68] test(docs): bind post-535 protected authority --- test/documentation-post-trust-integration-authority.test.ts | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/test/documentation-post-trust-integration-authority.test.ts b/test/documentation-post-trust-integration-authority.test.ts index 66742b41b..d9074eef8 100644 --- a/test/documentation-post-trust-integration-authority.test.ts +++ b/test/documentation-post-trust-integration-authority.test.ts @@ -6,7 +6,8 @@ describe("post-trust-integration documentation authority", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); for (const protectedHistory of [ - "protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd`", + "protected `main@0dbfceb850cda3a016ceb39ae1c8a1a96a9f2ad5`", + "merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`", "merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`", "merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`", "merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`", @@ -20,6 +21,7 @@ describe("post-trust-integration documentation authority", () => { expect(baseline).toContain("ordinary/non-force semantic convergence"); expect(baseline).toContain("predecessor GREEN"); expect(baseline).toContain("moving observation"); + expect(baseline).not.toContain("protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd`"); expect(baseline).not.toContain("protected `main@099d7d89a51bca4a2cf7c6b285b50ffadd08d001`"); expect(baseline).not.toContain("central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`"); expect(baseline).not.toContain("PR #542 exact `195fdd70b267332f246d93beb95fa96fabade52e`"); From da179c9d368c1c3a6e8161f4197a68c14be29b38 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 14:37:28 +0900 Subject: [PATCH 24/68] test(docs): refresh current candidate contract --- ...nical-gap-current-candidate-contract.test.ts | 17 ++++++++--------- 1 file changed, 8 insertions(+), 9 deletions(-) diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index 7e9de22e9..5ae4a7f4a 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -6,13 +6,13 @@ describe("product technical gap current candidate authority", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); for (const currentTruth of [ - "protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd`", + "protected `main@0dbfceb850cda3a016ceb39ae1c8a1a96a9f2ad5`", "central `.github/main@7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db`", - "PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`", + "merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`", "merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`", "merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`", "merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`", - "Observed PR #556 exact `363d62bc888e7b9555ff56bbce4dadc0a61d4efb`", + "Observed PR #556 exact `920eb7be0c3f57c5f149328a08beddc13339a338`", "merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`", "merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`", "merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`", @@ -21,20 +21,19 @@ describe("product technical gap current candidate authority", () => { } expect(baseline).toContain("live #556 must be re-fetched before integration"); expect(baseline).toContain("predecessor GREEN"); - expect(baseline).toContain("required Security Scan은 exact-head run inventory에서 ABSENT"); + expect(baseline).toContain("required Security Scan `34190991567`"); + expect(baseline).toContain("Source receipt production now additionally enforces claim-to-line byte identity"); for (const staleTruth of [ + "protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd`", "central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`", "protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`", "protected `main@d6394b2aa73e6fc57fccdad74ea38ad87f79e7f8`", - "PR #535 exact `e0a329916ab71b1009aa62cbab667a737d511223`", - "PR #535 exact `551d81da28b0c03ca44deedf60e95125dcceb81b`", - "PR #535 exact `06ed62fcc5611e9b25ef38b06e87e7521dbf1be1`", - "PR #535 exact `6739f0ab58e81dc56ea1485a5dea0f39e1cdfd3a`", - "PR #558 exact `f2aa8570d952cc0a371da161e651472c080e00ce`", + "Observed PR #556 exact `363d62bc888e7b9555ff56bbce4dadc0a61d4efb`", "observed PR #556 exact `29cb77bb943dcd93d65f959f20f50a0622e0ba4a`", "observed PR #556 exact `9d6d52c1dd4fc88203a832b509f4ec28cef3c68a`", "observed PR #556 exact `fecb03d9c632f90f290f921c1d6e90ce86ca5305`", + "required Security Scan은 exact-head run inventory에서 ABSENT", "PR #540은 아직 merge authority가 아니다", ]) { expect(baseline).not.toContain(staleTruth); From 08c16e5a79cdf1c3e23e952de874efd656270222 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 14:37:44 +0900 Subject: [PATCH 25/68] test(docs): align claim-binding authority wording --- test/product-technical-gap-current-candidate-contract.test.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index 5ae4a7f4a..13948f300 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -22,7 +22,7 @@ describe("product technical gap current candidate authority", () => { expect(baseline).toContain("live #556 must be re-fetched before integration"); expect(baseline).toContain("predecessor GREEN"); expect(baseline).toContain("required Security Scan `34190991567`"); - expect(baseline).toContain("Source receipt production now additionally enforces claim-to-line byte identity"); + expect(baseline).toContain("claim equality를 fail closed로 강제했다"); for (const staleTruth of [ "protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd`", From 44d2050804ef1d167b2170dcf6fc31657900b9f6 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 15:08:44 +0900 Subject: [PATCH 26/68] docs: refresh claim-evidence candidate authority --- docs/product-technical-gap-baseline.md | 16 ++++++++++------ .../documentation-live-open-pr-authority.test.ts | 8 ++++++-- ...hnical-gap-current-candidate-contract.test.ts | 7 +++++-- 3 files changed, 21 insertions(+), 10 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 422538ad9..b8de772c7 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -24,21 +24,25 @@ Noema Core Domain은 **Agent Runtime**과 **Workflow / Task Execution**이다. * ### Exact-claim evidence receipts — issue #555 / PR #556 -Observed PR #556 exact `920eb7be0c3f57c5f149328a08beddc13339a338`는 Draft이고 default `main`을 base로 한다. Prerequisite #535는 이미 normal merge돼 protected `main@0dbfceb850cda3a016ceb39ae1c8a1a96a9f2ad5`가 되었으며, #556은 그 protected source 위로 ordinary/non-force restack/retarget됐다. `live #556 must be re-fetched before integration`이며 predecessor head의 gate나 review evidence는 전용하지 않는다. +Observed PR #556 exact `809ccb78bfdf8f9785d4c74ab834159961cce6e9`는 Draft이고 default `main`을 base로 한다. Prerequisite #535는 이미 normal merge돼 protected `main@0dbfceb850cda3a016ceb39ae1c8a1a96a9f2ad5`가 되었으며, #556은 그 protected source 위로 ordinary/non-force restack/retarget됐다. `live #556 must be re-fetched before integration`이며 predecessor head의 gate나 review evidence는 전용하지 않는다. #556의 retained contract는 authenticated producer receipt와 `ClaimEvidenceRequirement` publication authority를 분리한다. Raw current-head source receipt는 context authority일 뿐이고, trusted producer가 exact claim/evidence kind와 finding coordinates를 명시적으로 승인하지 않는 한 blocking finding을 권위화하지 못한다. Requirement/receipt mismatch, wrong coordinates, direct model dictionaries, context-to-finding promotion은 deterministic gate와 publisher 전에 fail closed한다. Fresh source-authority review에서 exported `produce_source_claim_receipt()`가 `claim`과 `source_line_bytes`를 독립적으로 seal하고 서로 같은 의미인지 확인하지 않는 결함이 확인됐다. 기존 producer test는 실제 line `run: cargo generate-lockfile --locked\n`에 대해 paraphrase claim `the workflow invokes cargo generate-lockfile --locked`를 성공적으로 receipt화하고 있었다. 이 상태에서는 producer call이 path/line hash와 별개의 claim digest를 결합해 exact source finding처럼 보이는 권위를 만들 수 있었다. -Test-only `dbab4cdc150d4973002f8b61173282f7c7542725`는 claim이 exact source line에서 파생돼야 한다는 regression contract를 추가했다. Hosted workflow generation은 materialize됐지만 후속 branch mutation의 정상 `cancel-in-progress`에 의해 test execution 전에 cancelled됐으므로 hosted RED로 주장하지 않는다. Production `440346ee73e60e87915bd3027a774e24d3ac5124`는 artifact 생성 전에 exactly-one-line UTF-8 decoding과 claim equality를 fail closed로 강제했다. Current exact `920eb7be0c3f57c5f149328a08beddc13339a338`은 LF/CRLF/unterminated line, paraphrase mismatch, embedded multi-line bytes와 invalid UTF-8 edge를 추가로 고정한다. +Test-only `dbab4cdc150d4973002f8b61173282f7c7542725`는 claim이 exact source line에서 파생돼야 한다는 regression contract를 추가했다. Hosted workflow generation은 materialize됐지만 후속 branch mutation의 정상 `cancel-in-progress`에 의해 test execution 전에 cancelled됐으므로 hosted RED로 주장하지 않는다. Production `440346ee73e60e87915bd3027a774e24d3ac5124`는 artifact 생성 전에 exactly-one-line UTF-8 decoding과 claim equality를 fail closed로 강제했다. Edge-coverage exact `920eb7be0c3f57c5f149328a08beddc13339a338`은 LF/CRLF/unterminated line, paraphrase mismatch, embedded multi-line bytes와 invalid UTF-8 edge를 추가로 고정했다. -Current #556 exact generation은 application CI `34190991491`, reviewer-ci `34190991526`, required Security Scan `34190991567`, patch-validator-image `34190991473`이다. 이 revision 작성 시 네 lane은 모두 non-terminal이며 absent/queued/pending/in-progress/cancelled evidence는 passing으로 취급하지 않는다. Default `main` retarget 뒤 required Security Scan이 실제 materialize되므로, 이전 stacked-head Security absence는 이 concrete PR의 현재 gate exemption이 아니다. Central `.github#2037`은 future genuinely stacked PR에 대한 별도 owner-path defect로 남긴다. +Exact `920eb7be...`는 이후 실제 hosted reviewer-ci RED를 만들었다. Run `34190991526`, job `101948849348`에서 exact checkout, noema-core 100% line+branch coverage와 100% docstring gate는 통과했지만 reviewer suite가 **1 failed / 721 passed**로 종료됐다. 전체 reviewer coverage는 100%였다. 실패는 `test_caller_owned_kind_prevents_source_receipt_from_authorizing_execution`의 `_source_bundle()`이 production exact-line invariant 도입 뒤에도 runtime paraphrase `CLAIM`을 `b"cargo generate-lockfile --locked\n"`와 결합하던 stale fixture였다. Production invariant를 약화하지 않았다. + +Causal test repair `1cd8db5a94ed420bed8b52be0d3b3354f9fc86ab`은 source receipt의 claim을 exact decoded line `cargo generate-lockfile --locked`로 맞추면서도 caller-owned `EvidenceKind.EXECUTION` 요구와 source receipt 사이의 kind-mismatch 거부를 그대로 검증한다. Fresh review는 이어 `reviewer/tests/test_claim_evidence_publication_boundary.py`의 unused `claim_evidence_runtime` import를 유효 finding으로 보고했고, no-behavior-change repair `809ccb78bfdf8f9785d4c74ab834159961cce6e9`에서 그 import만 제거했다. 해당 review thread는 새 exact head에서 resolved/outdated가 됐다. + +Current #556 exact generation은 application CI `34193084836`, reviewer-ci `34193084831`, required Security Scan `34193084827`, patch-validator-image `34193084840`이다. 이 revision 작성 시 CI/reviewer/Security는 queued, image는 pending이며 predecessor evidence는 passing으로 전용하지 않는다. Default `main` retarget 뒤 required Security Scan이 실제 materialize되므로, 이전 stacked-head Security absence는 이 concrete PR의 현재 gate exemption이 아니다. Central `.github#2037`은 future genuinely stacked PR에 대한 별도 owner-path defect로 남긴다. Remaining supply-chain boundary는 exact stdout/stderr handoff, trusted research producer, immutable Noema release, released central `.github#1641` consumer bump와 unchanged original/synonym corpus RED→GREEN이다. ### Cross-lane documentation authority — PR #559 -#559는 이 baseline과 다섯 executable documentation-authority tests의 sole writer다. #535 normal integration과 #556 current-head mutation을 반영해 protected source와 active-candidate identity를 다시 수렴시켜야 한다. Feature-lane source, historical #556 baseline blob이나 predecessor gate result를 #559 authority로 전용하지 않는다. #559 자신의 source mutation도 predecessor workflow evidence를 무효화하므로 final exact head에서 fresh CI/reviewer/Security/image가 필요하다. +#559는 이 baseline과 다섯 executable documentation-authority tests의 sole writer다. #535 normal integration과 #556 current-head mutation을 반영해 protected source와 active-candidate identity를 다시 수렴시킨다. Feature-lane source, historical #556 baseline blob이나 predecessor gate result를 #559 authority로 전용하지 않는다. #559 자신의 source mutation도 predecessor workflow evidence를 무효화하므로 final exact head에서 fresh CI/reviewer/Security/image가 필요하다. ## Protected but incomplete commercial evidence @@ -73,7 +77,7 @@ Required workflow source만으로 reviewer/maintainer App installation, key cust | Documentation authority | merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6` + active #559 successor | moving PR/protected/central truth를 #559에서 code-current 유지 | | Orchestrator/free consumer | merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491` | protected source complete; immutable Noema release와 released consumer evidence 미완료 | | Patch-validator cache seed | merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`; protected run `34179912851` SUCCESS | protected operational execution complete; immutable image/release evidence 미완료 | -| Exact-claim receipts | observed PR #556 exact `920eb7be0c3f57c5f149328a08beddc13339a338` | fresh Security-inclusive exact-head gates, clean review, normal merge, execution/research producer evidence, immutable release | +| Exact-claim receipts | observed PR #556 exact `809ccb78bfdf8f9785d4c74ab834159961cce6e9` | fresh Security-inclusive exact-head gates, clean review, normal merge, execution/research producer evidence, immutable release | ## Evidence semantics and merge rules @@ -87,7 +91,7 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge | Priority | Gap | Buyer/operator impact | Current owner | Authoritative completion evidence | Next executable action | | --- | --- | --- | --- | --- | --- | -| P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority로 승격되거나 source claim이 cited line과 분리되면 blocking review가 잘못 권위화될 수 있다. | issue #555 / PR #556 | exact source-claim binding + execution/research producer evidence + fresh gates + normal merge + immutable release + released consumer RED→GREEN | exact `920eb7be...` gates/review 확인; failure면 causal repair, four-GREEN이면 normal merge | +| P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority로 승격되거나 source claim이 cited line과 분리되면 blocking review가 잘못 권위화될 수 있다. | issue #555 / PR #556 | exact source-claim binding + execution/research producer evidence + fresh gates + normal merge + immutable release + released consumer RED→GREEN | exact `809ccb78...` gates/review 확인; failure면 causal repair, four-GREEN이면 normal merge | | P0 | Strict orchestrator/free consumer release | Source는 protected됐지만 immutable released package와 central consumer activation이 없으면 commercial integration contract가 완결되지 않는다. | merged #535 + release lane | protected exact release/tag/package/SBOM/provenance/reproducibility + released consumer | release-ready protected head에서만 immutable publication evidence 생성 | | P0 | Patch-validator operational publication | source merge만으로 reusable cache와 immutable runtime activation을 증명할 수 없다. | issue #66 | protected-main image/cache receipt + immutable image/signature/SBOM/provenance/reproducibility/rollback | successful protected run `34179912851`을 immutable publication evidence와 결합 | | P0 | Toolchain/license release evidence | source dependency remediation만으로 실제 배포 artifact 권리와 재현성을 증명할 수 없다. | issue #531 | protected exact release package/image/SBOM/provenance/reproducibility/NOTICE/rights | release-ready protected exact head에서만 publication evidence 생성 | diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index 0e668e143..4ce10e96f 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -10,15 +10,19 @@ describe("product-technical gap baseline live open-PR authority", () => { expect(baseline).toContain("merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`"); expect(baseline).toContain("merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`"); expect(baseline).toContain("merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`"); - expect(baseline).toContain("Observed PR #556 exact `920eb7be0c3f57c5f149328a08beddc13339a338`"); + expect(baseline).toContain("Observed PR #556 exact `809ccb78bfdf8f9785d4c74ab834159961cce6e9`"); expect(baseline).toContain("default `main`을 base로 한다"); expect(baseline).toContain("live #556 must be re-fetched before integration"); expect(baseline).toContain("Test-only `dbab4cdc150d4973002f8b61173282f7c7542725`"); expect(baseline).toContain("Production `440346ee73e60e87915bd3027a774e24d3ac5124`"); - expect(baseline).toContain("required Security Scan `34190991567`"); + expect(baseline).toContain("reviewer-ci RED"); + expect(baseline).toContain("run `34190991526`"); + expect(baseline).toContain("`1cd8db5a94ed420bed8b52be0d3b3354f9fc86ab`"); + expect(baseline).toContain("required Security Scan `34193084827`"); expect(baseline).toContain("issue #555 / PR #556"); for (const staleAuthority of [ + "Observed PR #556 exact `920eb7be0c3f57c5f149328a08beddc13339a338`", "Observed PR #556 exact `363d62bc888e7b9555ff56bbce4dadc0a61d4efb`", "observed PR #556 exact `29cb77bb943dcd93d65f959f20f50a0622e0ba4a`", "observed PR #556 exact `9d6d52c1dd4fc88203a832b509f4ec28cef3c68a`", diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index 13948f300..c4884290f 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -12,7 +12,7 @@ describe("product technical gap current candidate authority", () => { "merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`", "merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`", "merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`", - "Observed PR #556 exact `920eb7be0c3f57c5f149328a08beddc13339a338`", + "Observed PR #556 exact `809ccb78bfdf8f9785d4c74ab834159961cce6e9`", "merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`", "merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`", "merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`", @@ -21,14 +21,17 @@ describe("product technical gap current candidate authority", () => { } expect(baseline).toContain("live #556 must be re-fetched before integration"); expect(baseline).toContain("predecessor GREEN"); - expect(baseline).toContain("required Security Scan `34190991567`"); + expect(baseline).toContain("required Security Scan `34193084827`"); expect(baseline).toContain("claim equality를 fail closed로 강제했다"); + expect(baseline).toContain("reviewer-ci RED"); + expect(baseline).toContain("1 failed / 721 passed"); for (const staleTruth of [ "protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd`", "central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`", "protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`", "protected `main@d6394b2aa73e6fc57fccdad74ea38ad87f79e7f8`", + "Observed PR #556 exact `920eb7be0c3f57c5f149328a08beddc13339a338`", "Observed PR #556 exact `363d62bc888e7b9555ff56bbce4dadc0a61d4efb`", "observed PR #556 exact `29cb77bb943dcd93d65f959f20f50a0622e0ba4a`", "observed PR #556 exact `9d6d52c1dd4fc88203a832b509f4ec28cef3c68a`", From 9c14c4e2e5d7fb0d51e0510ea3489d42ba4df0e8 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 16:03:26 +0900 Subject: [PATCH 27/68] test(docs): match hosted run authority casing --- test/documentation-live-open-pr-authority.test.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index 4ce10e96f..d3f6acc0e 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -16,7 +16,7 @@ describe("product-technical gap baseline live open-PR authority", () => { expect(baseline).toContain("Test-only `dbab4cdc150d4973002f8b61173282f7c7542725`"); expect(baseline).toContain("Production `440346ee73e60e87915bd3027a774e24d3ac5124`"); expect(baseline).toContain("reviewer-ci RED"); - expect(baseline).toContain("run `34190991526`"); + expect(baseline).toContain("Run `34190991526`"); expect(baseline).toContain("`1cd8db5a94ed420bed8b52be0d3b3354f9fc86ab`"); expect(baseline).toContain("required Security Scan `34193084827`"); expect(baseline).toContain("issue #555 / PR #556"); From 3f122035a99f8d9ebdda5d5ee15700aedaf0106c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 16:11:59 +0900 Subject: [PATCH 28/68] docs: refresh live Noema commercial authority --- docs/product-technical-gap-baseline.md | 40 +++++++++++++++----------- 1 file changed, 23 insertions(+), 17 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b8de772c7..af9e63124 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -24,35 +24,43 @@ Noema Core Domain은 **Agent Runtime**과 **Workflow / Task Execution**이다. * ### Exact-claim evidence receipts — issue #555 / PR #556 -Observed PR #556 exact `809ccb78bfdf8f9785d4c74ab834159961cce6e9`는 Draft이고 default `main`을 base로 한다. Prerequisite #535는 이미 normal merge돼 protected `main@0dbfceb850cda3a016ceb39ae1c8a1a96a9f2ad5`가 되었으며, #556은 그 protected source 위로 ordinary/non-force restack/retarget됐다. `live #556 must be re-fetched before integration`이며 predecessor head의 gate나 review evidence는 전용하지 않는다. +Observed PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`는 Draft이고 default `main`을 base로 한다. Prerequisite #535는 이미 normal merge돼 protected `main@0dbfceb850cda3a016ceb39ae1c8a1a96a9f2ad5`가 되었으며, #556은 그 protected source 위의 ahead-only candidate다. `live #556 must be re-fetched before integration`이며 predecessor head의 gate나 review evidence는 전용하지 않는다. #556의 retained contract는 authenticated producer receipt와 `ClaimEvidenceRequirement` publication authority를 분리한다. Raw current-head source receipt는 context authority일 뿐이고, trusted producer가 exact claim/evidence kind와 finding coordinates를 명시적으로 승인하지 않는 한 blocking finding을 권위화하지 못한다. Requirement/receipt mismatch, wrong coordinates, direct model dictionaries, context-to-finding promotion은 deterministic gate와 publisher 전에 fail closed한다. -Fresh source-authority review에서 exported `produce_source_claim_receipt()`가 `claim`과 `source_line_bytes`를 독립적으로 seal하고 서로 같은 의미인지 확인하지 않는 결함이 확인됐다. 기존 producer test는 실제 line `run: cargo generate-lockfile --locked\n`에 대해 paraphrase claim `the workflow invokes cargo generate-lockfile --locked`를 성공적으로 receipt화하고 있었다. 이 상태에서는 producer call이 path/line hash와 별개의 claim digest를 결합해 exact source finding처럼 보이는 권위를 만들 수 있었다. +Test-only `dbab4cdc150d4973002f8b61173282f7c7542725`는 claim이 exact source line에서 파생돼야 한다는 regression contract를 추가했다. Hosted workflow generation은 후속 mutation의 정상 `cancel-in-progress`로 test execution 전에 cancelled돼 hosted RED로 주장하지 않는다. Production `440346ee73e60e87915bd3027a774e24d3ac5124`는 exactly-one-line UTF-8 decoding과 claim equality를 fail closed로 강제했다. Edge head `920eb7be0c3f57c5f149328a08beddc13339a338`은 LF/CRLF/unterminated line, paraphrase mismatch, embedded multi-line bytes와 invalid UTF-8 edge를 고정했다. -Test-only `dbab4cdc150d4973002f8b61173282f7c7542725`는 claim이 exact source line에서 파생돼야 한다는 regression contract를 추가했다. Hosted workflow generation은 materialize됐지만 후속 branch mutation의 정상 `cancel-in-progress`에 의해 test execution 전에 cancelled됐으므로 hosted RED로 주장하지 않는다. Production `440346ee73e60e87915bd3027a774e24d3ac5124`는 artifact 생성 전에 exactly-one-line UTF-8 decoding과 claim equality를 fail closed로 강제했다. Edge-coverage exact `920eb7be0c3f57c5f149328a08beddc13339a338`은 LF/CRLF/unterminated line, paraphrase mismatch, embedded multi-line bytes와 invalid UTF-8 edge를 추가로 고정했다. +Exact `920eb7be...`는 실제 hosted reviewer-ci RED를 만들었다. Run `34190991526`, job `101948849348`에서 exact checkout, noema-core 100% line+branch coverage와 100% docstring gate는 통과했지만 reviewer suite가 **1 failed / 721 passed**로 종료됐다. 실패는 stale `_source_bundle()` fixture가 exact source bytes와 runtime paraphrase를 계속 결합하던 데 있었고, causal test repair `1cd8db5a94ed420bed8b52be0d3b3354f9fc86ab`은 source claim을 exact decoded line으로 맞추면서 source-vs-execution kind mismatch rejection을 보존했다. 후속 `809ccb78bfdf8f9785d4c74ab834159961cce6e9`은 review에서 확인된 unused import만 제거했다. -Exact `920eb7be...`는 이후 실제 hosted reviewer-ci RED를 만들었다. Run `34190991526`, job `101948849348`에서 exact checkout, noema-core 100% line+branch coverage와 100% docstring gate는 통과했지만 reviewer suite가 **1 failed / 721 passed**로 종료됐다. 전체 reviewer coverage는 100%였다. 실패는 `test_caller_owned_kind_prevents_source_receipt_from_authorizing_execution`의 `_source_bundle()`이 production exact-line invariant 도입 뒤에도 runtime paraphrase `CLAIM`을 `b"cargo generate-lockfile --locked\n"`와 결합하던 stale fixture였다. Production invariant를 약화하지 않았다. +그 뒤 publisher boundary review는 finding-free `request_changes`/`blocked` model verdict가 receipt admission을 건너뛴 채 GitHub non-approval로 게시될 수 있는 vacuous-oracle bypass를 찾았다. RED `6629f07e2c7bd35698331d8966b7cbe35204a808`은 실제 PydanticAI agent→CLI publisher seam에서 두 non-approval 상태를 재현하고, GREEN `4c2153702972e8d5c0f077ac79cc68cbf6da4bfb`은 model non-approval에 producer-authenticated finding을 필수화했다. Current exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`은 CHANGELOG authority까지 포함한다. -Causal test repair `1cd8db5a94ed420bed8b52be0d3b3354f9fc86ab`은 source receipt의 claim을 exact decoded line `cargo generate-lockfile --locked`로 맞추면서도 caller-owned `EvidenceKind.EXECUTION` 요구와 source receipt 사이의 kind-mismatch 거부를 그대로 검증한다. Fresh review는 이어 `reviewer/tests/test_claim_evidence_publication_boundary.py`의 unused `claim_evidence_runtime` import를 유효 finding으로 보고했고, no-behavior-change repair `809ccb78bfdf8f9785d4c74ab834159961cce6e9`에서 그 import만 제거했다. 해당 review thread는 새 exact head에서 resolved/outdated가 됐다. +Current #556 exact generation은 application CI `34197596549`, reviewer-ci `34197596588`, required Security Scan `34197596536`, patch-validator-image `34197596517`이다. 이 revision 작성 시 네 lane 모두 queued이며 predecessor `809ccb78...`의 CI/reviewer/Security success는 current merge authority가 아니다. Default `main` retarget 뒤 required Security Scan이 materialize되므로 absent/queued/skipped/cancelled/failed Security를 passing으로 취급하지 않는다. -Current #556 exact generation은 application CI `34193084836`, reviewer-ci `34193084831`, required Security Scan `34193084827`, patch-validator-image `34193084840`이다. 이 revision 작성 시 CI/reviewer/Security는 queued, image는 pending이며 predecessor evidence는 passing으로 전용하지 않는다. Default `main` retarget 뒤 required Security Scan이 실제 materialize되므로, 이전 stacked-head Security absence는 이 concrete PR의 현재 gate exemption이 아니다. Central `.github#2037`은 future genuinely stacked PR에 대한 별도 owner-path defect로 남긴다. +Remaining supply-chain boundary는 exact stdout/stderr producer, trusted research producer, immutable Noema release, released central `.github#1641` consumer bump와 unchanged original/synonym corpus RED→GREEN이다. -Remaining supply-chain boundary는 exact stdout/stderr handoff, trusted research producer, immutable Noema release, released central `.github#1641` consumer bump와 unchanged original/synonym corpus RED→GREEN이다. +### External extension admission — issue #545 / PR #560 + +Observed PR #560 test-only exact `58f8bbadd6a4a3863d642883e40f4753f6dc291f`는 Draft이고 default `main`을 base로 한다. 이 lane은 Tool / Capability Boundary만 소유하며 plugin source, provider routing, quarantine/security/outbound implementation을 Noema로 복제하지 않는다. ADR 0015는 `Proposed`이고 local ACL/test double은 `context-graph-contracts`의 immutable shared artifact contract가 나오기 전의 fail-closed boundary다. + +Initial exact `e23d9ef941f453720ddc1456c7bc208e9434a7b2`의 hosted application CI run `34195202961`, job `101961294823`은 exact checkout, live-base, lockfile, install, typecheck를 통과한 뒤 repository-wide public API documentation gate에서 실패했다. 새 external-extension module의 12 public exported type/interface가 meaningful adjacent JSDoc을 충족하지 못한 현실 RED였다. Production behavior나 gate를 약화하지 않고 `469efe70b673a2c58d93e1944721216e167afc9b`에서 해당 public contracts에 의미 있는 JSDoc을 추가했다. + +그 후 invocation-time source-integrity review에서 admission이 pin한 catalog identity 여섯 필드 중 live invocation이 `artifact_sha256`와 `upstream_commit_sha` 두 필드만 재검증하는 결함을 확인했다. `external_extension_id`, `upstream_repository`, `upstream_path`, `marketplace_entry_sha256`가 admission 뒤 바뀌어도 silent drift가 가능하므로 “catalog drift cannot silently update an admitted extension” invariant가 불완전하다. Test-only exact `58f8bbadd6a4a3863d642883e40f4753f6dc291f`은 네 누락 identity drift를 hostile regression으로 추가했다. Current runs은 application CI `34197933796`, reviewer-ci `34197933756`, required Security Scan `34197933827`, patch-validator-image `34197933767`이며 이 revision 작성 시 모두 queued다. Hosted RED가 materialize되기 전 production fix를 덮어쓰지 않는다. ### Cross-lane documentation authority — PR #559 -#559는 이 baseline과 다섯 executable documentation-authority tests의 sole writer다. #535 normal integration과 #556 current-head mutation을 반영해 protected source와 active-candidate identity를 다시 수렴시킨다. Feature-lane source, historical #556 baseline blob이나 predecessor gate result를 #559 authority로 전용하지 않는다. #559 자신의 source mutation도 predecessor workflow evidence를 무효화하므로 final exact head에서 fresh CI/reviewer/Security/image가 필요하다. +#559는 이 baseline과 다섯 executable documentation-authority tests의 sole writer다. Exact predecessor `44d2050804ef1d167b2170dcf6fc31657900b9f6`의 application CI `34193418411`은 release tests에서 1건 실패했다. Baseline은 문장 시작의 `Run \`34190991526\``을 올바르게 기록했지만 executable test가 lowercase `run` exact substring을 요구한 docs/test casing mismatch였다. Gate를 느슨하게 하거나 baseline을 부자연스럽게 바꾸지 않고 `9c14c4e2e5d7fb0d51e0510ea3489d42ba4df0e8`에서 test oracle을 실제 문장 casing에 맞췄다. + +이 revision은 이후 #556의 `860714c...` 전진과 새 #560 Tool Capability lane을 반영한다. Feature-lane source, historical #556 baseline blob, predecessor gate result를 #559 authority로 전용하지 않는다. #559 자신의 source mutation도 predecessor workflow evidence를 무효화하므로 final exact head에서 fresh CI/reviewer/Security/image가 필요하다. ## Protected but incomplete commercial evidence ### Orchestrator/free consumer — merged #535 -Merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`는 protected `main@0dbfceb850cda3a016ceb39ae1c8a1a96a9f2ad5`에 normal integration됐다. Exact candidate가 application CI/reviewer-ci/required Security/patch-validator-image terminal SUCCESS와 clean review authority를 충족한 뒤 merge됐으며, provider/model routing은 `contextual-orchestrator` owner에 남고 Noema는 `orchestrator/free`와 gateway-only credentials를 소비한다. Source integration 자체는 immutable Noema package/release, SBOM/provenance/reproducibility 또는 downstream consumer activation을 증명하지 않는다. +Merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`는 protected `main@0dbfceb850cda3a016ceb39ae1c8a1a96a9f2ad5`에 normal integration됐다. Provider/model routing은 `contextual-orchestrator` owner에 남고 Noema는 `orchestrator/free`와 gateway-only credentials를 소비한다. Source integration 자체는 immutable Noema package/release, SBOM/provenance/reproducibility 또는 downstream consumer activation을 증명하지 않는다. ### Patch-validator default-branch cache seed — merged #558 / issue #66 -Merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`는 protected source에 포함됐다. Protected-main prior push `patch-validator-image` run `34179912851`은 terminal SUCCESS다. 따라서 operational/cache-seed workflow execution은 실제 완료됐지만, 그 성공만으로 cache hit 성능, immutable image digest publication, signature/attestation, reproducibility 또는 rollback을 증명하지 않는다. Issue #66은 immutable publication evidence가 source/run identity와 결합될 때까지 open authority다. +Merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`는 protected source에 포함됐다. Protected-main prior push `patch-validator-image` run `34179912851`은 terminal SUCCESS다. 그 성공만으로 cache hit 성능, immutable image digest publication, signature/attestation, reproducibility 또는 rollback을 증명하지 않는다. ### Toolchain and inbound rights — issue #531 / merged #540 @@ -62,10 +70,6 @@ Source remediation은 protected lineage에 있다. 남은 권위는 exact releas Durable workflow/state source는 protected lineage에 있다. 남은 권위는 deployed Durable Object binding/transaction compatibility, recovery/rollback receipt, immutable release/package/SBOM/provenance/reproducibility다. 이 evidence 전까지 ADR 0013은 `Proposed`다. -### Governance and production identity - -Required workflow source만으로 reviewer/maintainer App installation, key custody/rotation, bounded publication authority, ruleset enforcement, break-glass operation을 모두 입증할 수 없다. Live governance와 approved control-plane evidence는 source evidence와 별도로 유지한다. - ## Current authority table | Lane | Authority | Integration / completion condition | @@ -77,7 +81,8 @@ Required workflow source만으로 reviewer/maintainer App installation, key cust | Documentation authority | merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6` + active #559 successor | moving PR/protected/central truth를 #559에서 code-current 유지 | | Orchestrator/free consumer | merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491` | protected source complete; immutable Noema release와 released consumer evidence 미완료 | | Patch-validator cache seed | merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`; protected run `34179912851` SUCCESS | protected operational execution complete; immutable image/release evidence 미완료 | -| Exact-claim receipts | observed PR #556 exact `809ccb78bfdf8f9785d4c74ab834159961cce6e9` | fresh Security-inclusive exact-head gates, clean review, normal merge, execution/research producer evidence, immutable release | +| Exact-claim receipts | observed PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c` | fresh Security-inclusive exact-head gates, clean review, normal merge, execution/research producer evidence, immutable release | +| External extension admission | observed PR #560 test-only exact `58f8bbadd6a4a3863d642883e40f4753f6dc291f` | hosted drift RED, full pinned-catalog revalidation, 100% tests/docs, fresh gates, normal merge; shared immutable owner contract remains external prerequisite | ## Evidence semantics and merge rules @@ -87,11 +92,12 @@ Normal merge requires unchanged exact head, independently refreshed live base/he PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge 또는 verified successor가 모든 유효 delta/test/fixture/contract/evidence를 완전히 승계한 경우에만 사라진다. Blocked lane은 자기 lane만 막고 unrelated safe review, owner-path repair, docs-to-code repair와 buyer-gap work는 계속한다. -## Buyer and operator gaps +## Commercial gap register | Priority | Gap | Buyer/operator impact | Current owner | Authoritative completion evidence | Next executable action | | --- | --- | --- | --- | --- | --- | -| P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority로 승격되거나 source claim이 cited line과 분리되면 blocking review가 잘못 권위화될 수 있다. | issue #555 / PR #556 | exact source-claim binding + execution/research producer evidence + fresh gates + normal merge + immutable release + released consumer RED→GREEN | exact `809ccb78...` gates/review 확인; failure면 causal repair, four-GREEN이면 normal merge | +| P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority로 승격되면 blocking review가 잘못 권위화될 수 있다. | issue #555 / PR #556 | source-claim binding + non-vacuous producer findings + execution/research producer evidence + fresh gates + normal merge + immutable release + released consumer RED→GREEN | exact `860714c...` gates/review 확인; failure면 causal repair, four-GREEN이면 normal merge | +| P0 | External extension capability admission | third-party plugin metadata·prompt·hook를 runtime authority로 오인하면 제품 경계와 고객 데이터가 확장 코드에 노출될 수 있다. | issue #545 / PR #560 | immutable source identity + independent scan receipts + full live catalog drift rejection + no undeclared capability + fresh gates + normal merge + immutable shared-contract consumption | test-only `58f8bba...` hosted RED 확인 후 minimal full-identity revalidation | | P0 | Strict orchestrator/free consumer release | Source는 protected됐지만 immutable released package와 central consumer activation이 없으면 commercial integration contract가 완결되지 않는다. | merged #535 + release lane | protected exact release/tag/package/SBOM/provenance/reproducibility + released consumer | release-ready protected head에서만 immutable publication evidence 생성 | | P0 | Patch-validator operational publication | source merge만으로 reusable cache와 immutable runtime activation을 증명할 수 없다. | issue #66 | protected-main image/cache receipt + immutable image/signature/SBOM/provenance/reproducibility/rollback | successful protected run `34179912851`을 immutable publication evidence와 결합 | | P0 | Toolchain/license release evidence | source dependency remediation만으로 실제 배포 artifact 권리와 재현성을 증명할 수 없다. | issue #531 | protected exact release package/image/SBOM/provenance/reproducibility/NOTICE/rights | release-ready protected exact head에서만 publication evidence 생성 | From aec88cc45fe1c7762026c6659d7d908d1b0e85c7 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 16:12:19 +0900 Subject: [PATCH 29/68] test(docs): track current Noema feature authority --- test/documentation-live-open-pr-authority.test.ts | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index d3f6acc0e..cbf51dd66 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -2,7 +2,7 @@ import { readFileSync } from "node:fs"; import { describe, expect, it } from "vitest"; describe("product-technical gap baseline live open-PR authority", () => { - it("separates integrated protected history from the current claim-evidence candidate", () => { + it("separates integrated protected history from current feature candidates", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); expect(baseline).toContain("protected `main@0dbfceb850cda3a016ceb39ae1c8a1a96a9f2ad5`"); @@ -10,7 +10,8 @@ describe("product-technical gap baseline live open-PR authority", () => { expect(baseline).toContain("merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`"); expect(baseline).toContain("merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`"); expect(baseline).toContain("merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`"); - expect(baseline).toContain("Observed PR #556 exact `809ccb78bfdf8f9785d4c74ab834159961cce6e9`"); + expect(baseline).toContain("Observed PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`"); + expect(baseline).toContain("Observed PR #560 test-only exact `58f8bbadd6a4a3863d642883e40f4753f6dc291f`"); expect(baseline).toContain("default `main`을 base로 한다"); expect(baseline).toContain("live #556 must be re-fetched before integration"); expect(baseline).toContain("Test-only `dbab4cdc150d4973002f8b61173282f7c7542725`"); @@ -18,10 +19,13 @@ describe("product-technical gap baseline live open-PR authority", () => { expect(baseline).toContain("reviewer-ci RED"); expect(baseline).toContain("Run `34190991526`"); expect(baseline).toContain("`1cd8db5a94ed420bed8b52be0d3b3354f9fc86ab`"); - expect(baseline).toContain("required Security Scan `34193084827`"); + expect(baseline).toContain("required Security Scan `34197596536`"); expect(baseline).toContain("issue #555 / PR #556"); + expect(baseline).toContain("issue #545 / PR #560"); + expect(baseline).toContain("application CI `34197933796`"); for (const staleAuthority of [ + "Observed PR #556 exact `809ccb78bfdf8f9785d4c74ab834159961cce6e9`", "Observed PR #556 exact `920eb7be0c3f57c5f149328a08beddc13339a338`", "Observed PR #556 exact `363d62bc888e7b9555ff56bbce4dadc0a61d4efb`", "observed PR #556 exact `29cb77bb943dcd93d65f959f20f50a0622e0ba4a`", From 16e006c605b5ff28858a9ab4c29154e8b800c8e2 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 16:12:38 +0900 Subject: [PATCH 30/68] test(docs): bind commercial gap to live feature heads --- ...oduct-technical-gap-current-candidate-contract.test.ts | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index c4884290f..7050410e1 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -12,7 +12,8 @@ describe("product technical gap current candidate authority", () => { "merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`", "merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`", "merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`", - "Observed PR #556 exact `809ccb78bfdf8f9785d4c74ab834159961cce6e9`", + "Observed PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`", + "Observed PR #560 test-only exact `58f8bbadd6a4a3863d642883e40f4753f6dc291f`", "merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`", "merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`", "merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`", @@ -21,16 +22,19 @@ describe("product technical gap current candidate authority", () => { } expect(baseline).toContain("live #556 must be re-fetched before integration"); expect(baseline).toContain("predecessor GREEN"); - expect(baseline).toContain("required Security Scan `34193084827`"); + expect(baseline).toContain("required Security Scan `34197596536`"); expect(baseline).toContain("claim equality를 fail closed로 강제했다"); expect(baseline).toContain("reviewer-ci RED"); expect(baseline).toContain("1 failed / 721 passed"); + expect(baseline).toContain("catalog drift cannot silently update an admitted extension"); + expect(baseline).toContain("application CI `34197933796`"); for (const staleTruth of [ "protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd`", "central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`", "protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`", "protected `main@d6394b2aa73e6fc57fccdad74ea38ad87f79e7f8`", + "Observed PR #556 exact `809ccb78bfdf8f9785d4c74ab834159961cce6e9`", "Observed PR #556 exact `920eb7be0c3f57c5f149328a08beddc13339a338`", "Observed PR #556 exact `363d62bc888e7b9555ff56bbce4dadc0a61d4efb`", "observed PR #556 exact `29cb77bb943dcd93d65f959f20f50a0622e0ba4a`", From e86592848162e68e7001e8acb54bd2973ac6bb40 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 17:34:31 +0900 Subject: [PATCH 31/68] test(docs): require settled external-extension authority --- test/documentation-live-open-pr-authority.test.ts | 6 ++++-- ...product-technical-gap-current-candidate-contract.test.ts | 6 ++++-- 2 files changed, 8 insertions(+), 4 deletions(-) diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index cbf51dd66..d67f0f5af 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -11,7 +11,7 @@ describe("product-technical gap baseline live open-PR authority", () => { expect(baseline).toContain("merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`"); expect(baseline).toContain("merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`"); expect(baseline).toContain("Observed PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`"); - expect(baseline).toContain("Observed PR #560 test-only exact `58f8bbadd6a4a3863d642883e40f4753f6dc291f`"); + expect(baseline).toContain("Observed PR #560 exact `81bff2f61ab6c323845116acd9622334f9dcfadd`"); expect(baseline).toContain("default `main`을 base로 한다"); expect(baseline).toContain("live #556 must be re-fetched before integration"); expect(baseline).toContain("Test-only `dbab4cdc150d4973002f8b61173282f7c7542725`"); @@ -22,9 +22,11 @@ describe("product-technical gap baseline live open-PR authority", () => { expect(baseline).toContain("required Security Scan `34197596536`"); expect(baseline).toContain("issue #555 / PR #556"); expect(baseline).toContain("issue #545 / PR #560"); - expect(baseline).toContain("application CI `34197933796`"); + expect(baseline).toContain("application CI `34204455463`"); + expect(baseline).toContain("module-private runtime authority"); for (const staleAuthority of [ + "Observed PR #560 test-only exact `58f8bbadd6a4a3863d642883e40f4753f6dc291f`", "Observed PR #556 exact `809ccb78bfdf8f9785d4c74ab834159961cce6e9`", "Observed PR #556 exact `920eb7be0c3f57c5f149328a08beddc13339a338`", "Observed PR #556 exact `363d62bc888e7b9555ff56bbce4dadc0a61d4efb`", diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index 7050410e1..55bbb34f2 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -13,7 +13,7 @@ describe("product technical gap current candidate authority", () => { "merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`", "merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`", "Observed PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`", - "Observed PR #560 test-only exact `58f8bbadd6a4a3863d642883e40f4753f6dc291f`", + "Observed PR #560 exact `81bff2f61ab6c323845116acd9622334f9dcfadd`", "merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`", "merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`", "merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`", @@ -27,13 +27,15 @@ describe("product technical gap current candidate authority", () => { expect(baseline).toContain("reviewer-ci RED"); expect(baseline).toContain("1 failed / 721 passed"); expect(baseline).toContain("catalog drift cannot silently update an admitted extension"); - expect(baseline).toContain("application CI `34197933796`"); + expect(baseline).toContain("application CI `34204455463`"); + expect(baseline).toContain("module-private runtime authority"); for (const staleTruth of [ "protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd`", "central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`", "protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`", "protected `main@d6394b2aa73e6fc57fccdad74ea38ad87f79e7f8`", + "Observed PR #560 test-only exact `58f8bbadd6a4a3863d642883e40f4753f6dc291f`", "Observed PR #556 exact `809ccb78bfdf8f9785d4c74ab834159961cce6e9`", "Observed PR #556 exact `920eb7be0c3f57c5f149328a08beddc13339a338`", "Observed PR #556 exact `363d62bc888e7b9555ff56bbce4dadc0a61d4efb`", From 595f1f78413ecf934d5fc4476c31dd2e44d43186 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 17:38:44 +0900 Subject: [PATCH 32/68] docs: converge commercial gap to current plugin admission --- docs/product-technical-gap-baseline.md | 24 ++++++++++++++++-------- 1 file changed, 16 insertions(+), 8 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index af9e63124..f3bbb72a7 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -34,23 +34,31 @@ Exact `920eb7be...`는 실제 hosted reviewer-ci RED를 만들었다. Run `34190 그 뒤 publisher boundary review는 finding-free `request_changes`/`blocked` model verdict가 receipt admission을 건너뛴 채 GitHub non-approval로 게시될 수 있는 vacuous-oracle bypass를 찾았다. RED `6629f07e2c7bd35698331d8966b7cbe35204a808`은 실제 PydanticAI agent→CLI publisher seam에서 두 non-approval 상태를 재현하고, GREEN `4c2153702972e8d5c0f077ac79cc68cbf6da4bfb`은 model non-approval에 producer-authenticated finding을 필수화했다. Current exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`은 CHANGELOG authority까지 포함한다. -Current #556 exact generation은 application CI `34197596549`, reviewer-ci `34197596588`, required Security Scan `34197596536`, patch-validator-image `34197596517`이다. 이 revision 작성 시 네 lane 모두 queued이며 predecessor `809ccb78...`의 CI/reviewer/Security success는 current merge authority가 아니다. Default `main` retarget 뒤 required Security Scan이 materialize되므로 absent/queued/skipped/cancelled/failed Security를 passing으로 취급하지 않는다. +Current #556 exact generation은 application CI `34197596549`, reviewer-ci `34197596588`, required Security Scan `34197596536`, patch-validator-image `34197596517`이다. 이 revision 작성 시 application CI, reviewer-ci, required Security는 terminal SUCCESS이고 patch-validator-image만 `in_progress`다. 따라서 3-GREEN이지 four-GREEN이 아니며 image lane이 terminal success가 되기 전 normal merge authority는 없다. Default `main` retarget 뒤 required Security Scan이 materialize되므로 absent/queued/skipped/cancelled/failed Security를 passing으로 취급하지 않는다. Remaining supply-chain boundary는 exact stdout/stderr producer, trusted research producer, immutable Noema release, released central `.github#1641` consumer bump와 unchanged original/synonym corpus RED→GREEN이다. ### External extension admission — issue #545 / PR #560 -Observed PR #560 test-only exact `58f8bbadd6a4a3863d642883e40f4753f6dc291f`는 Draft이고 default `main`을 base로 한다. 이 lane은 Tool / Capability Boundary만 소유하며 plugin source, provider routing, quarantine/security/outbound implementation을 Noema로 복제하지 않는다. ADR 0015는 `Proposed`이고 local ACL/test double은 `context-graph-contracts`의 immutable shared artifact contract가 나오기 전의 fail-closed boundary다. +Observed PR #560 exact `81bff2f61ab6c323845116acd9622334f9dcfadd`는 Draft이고 default `main`을 base로 한다. 이 lane은 Tool / Capability Boundary만 소유하며 plugin source, provider routing, quarantine/security/outbound implementation을 Noema로 복제하지 않는다. ADR 0015는 `Proposed`이고 local ACL/test double은 `context-graph-contracts`의 immutable shared artifact contract가 나오기 전의 fail-closed boundary다. Initial exact `e23d9ef941f453720ddc1456c7bc208e9434a7b2`의 hosted application CI run `34195202961`, job `101961294823`은 exact checkout, live-base, lockfile, install, typecheck를 통과한 뒤 repository-wide public API documentation gate에서 실패했다. 새 external-extension module의 12 public exported type/interface가 meaningful adjacent JSDoc을 충족하지 못한 현실 RED였다. Production behavior나 gate를 약화하지 않고 `469efe70b673a2c58d93e1944721216e167afc9b`에서 해당 public contracts에 의미 있는 JSDoc을 추가했다. -그 후 invocation-time source-integrity review에서 admission이 pin한 catalog identity 여섯 필드 중 live invocation이 `artifact_sha256`와 `upstream_commit_sha` 두 필드만 재검증하는 결함을 확인했다. `external_extension_id`, `upstream_repository`, `upstream_path`, `marketplace_entry_sha256`가 admission 뒤 바뀌어도 silent drift가 가능하므로 “catalog drift cannot silently update an admitted extension” invariant가 불완전하다. Test-only exact `58f8bbadd6a4a3863d642883e40f4753f6dc291f`은 네 누락 identity drift를 hostile regression으로 추가했다. Current runs은 application CI `34197933796`, reviewer-ci `34197933756`, required Security Scan `34197933827`, patch-validator-image `34197933767`이며 이 revision 작성 시 모두 queued다. Hosted RED가 materialize되기 전 production fix를 덮어쓰지 않는다. +Invocation-time source-integrity review에서는 admission이 pin한 catalog identity 여섯 필드 중 일부만 재검증돼 “catalog drift cannot silently update an admitted extension” invariant가 불완전한 것을 찾았다. Test-only exact `58f8bbadd6a4a3863d642883e40f4753f6dc291f`의 application CI `34197933796`, job `101969766167`은 exact checkout, live-base, lockfile, install, typecheck 뒤 release tests에서 **4 / 4167 failed**의 실제 hosted RED를 만들었다. `6b7b5d64d28a46464c854c74ac33ac1b01a888f2`는 drift fixture만 바로잡았고, production `572aa5919210b511e58d70e809dbefc60196ada7`는 activation scope/time을 재검증하면서 live catalog를 extension id/repository/commit/path/artifact/marketplace digest 전체 six-field identity에 묶었다. + +그 뒤 public invocation이 structurally constructible activation을 authority로 믿는 결함을 test-only `2987e8625fb0964eb119a4be337280b49588e8bc`가 재현했고 application CI `34199961782`에서 실제 hosted RED가 관찰됐다. 또 exported `AdmittedExternalExtension` fabrication이 AppGuardrail/quarantine receipt admission을 건너뛸 수 있어 test-only `632c77b9db9f39662f78087b3b4eca45b46cf9d9`가 activation boundary를 고정했다. Ordinary descendant `f9be6fbecd566d197caa7317bc99de4b931573d1`은 admitted-extension provenance를 module-private runtime authority로 결합했다. + +Fresh review는 field-identical activation clone과 invocation-receipt replay clone, invocation 시점의 AppGuardrail/quarantine receipt revocation TOCTOU를 추가로 찾았다. Test-only `3b072f8f9c07959187006fa926812bbc713aff99`은 activation clone을, test-only parent `0323a3c67767b5e137de6b754a8173c51d709c21`은 owner receipt revocation과 retained replay clone을 고정했다. Current production `81bff2f61ab6c323845116acd9622334f9dcfadd`는 admitted extension, activation, invocation receipt의 issuance provenance를 module-private runtime authority로 인증하고, invocation 때 AppGuardrail/quarantine receipts를 다시 resolve해 artifact/isolation-policy/producer-owner binding을 재검증한다. Scope/time 및 six-field catalog identity fail-closed 검증은 유지한다. + +Current #560 exact generation은 application CI `34204455463`, reviewer-ci `34204455676`, required Security Scan `34204455766`, patch-validator-image `34204455409`다. 이 revision 작성 시 네 lane 모두 queued이며 predecessor local 34-pass/owned production 100%/typecheck evidence를 hosted GREEN으로 승격하지 않는다. 두 substantive review thread는 production repair를 기록했지만 exact-head hosted verification 전까지 intentionally unresolved 상태라 merge authority가 아니다. + +Shared completion boundary는 immutable `context-graph-contracts` external-capability contract, live AppGuardrail/quarantine owner evidence, bounded pilot evidence, exact-head four-GREEN, clean review authority와 normal merge다. Noema가 mutable sibling ref나 foreign scanner/isolation/egress implementation을 복제해 completion을 제조하지 않는다. ### Cross-lane documentation authority — PR #559 -#559는 이 baseline과 다섯 executable documentation-authority tests의 sole writer다. Exact predecessor `44d2050804ef1d167b2170dcf6fc31657900b9f6`의 application CI `34193418411`은 release tests에서 1건 실패했다. Baseline은 문장 시작의 `Run \`34190991526\``을 올바르게 기록했지만 executable test가 lowercase `run` exact substring을 요구한 docs/test casing mismatch였다. Gate를 느슨하게 하거나 baseline을 부자연스럽게 바꾸지 않고 `9c14c4e2e5d7fb0d51e0510ea3489d42ba4df0e8`에서 test oracle을 실제 문장 casing에 맞췄다. +#559는 이 baseline과 다섯 executable documentation-authority tests의 sole writer다. Exact predecessor `44d2050804ef1d167b2170dcf6fc31657900b9f6`의 application CI `34193418411`은 release tests에서 1건 실패했다. Baseline은 문장 시작의 `Run `34190991526``을 올바르게 기록했지만 executable test가 lowercase `run` exact substring을 요구한 docs/test casing mismatch였다. Gate를 느슨하게 하거나 baseline을 부자연스럽게 바꾸지 않고 `9c14c4e2e5d7fb0d51e0510ea3489d42ba4df0e8`에서 test oracle을 실제 문장 casing에 맞췄다. -이 revision은 이후 #556의 `860714c...` 전진과 새 #560 Tool Capability lane을 반영한다. Feature-lane source, historical #556 baseline blob, predecessor gate result를 #559 authority로 전용하지 않는다. #559 자신의 source mutation도 predecessor workflow evidence를 무효화하므로 final exact head에서 fresh CI/reviewer/Security/image가 필요하다. +#560이 `81bff2f...` production repair까지 전진하면서 #559 exact `16e006c605b5ff28858a9ab4c29154e8b800c8e2`의 baseline/oracle은 stale authority가 됐다. Test-only `e86592848162e68e7001e8acb54bd2973ac6bb40`은 current #560 exact와 current run generation을 먼저 요구한다. 후속 production documentation repair는 이 baseline만 code-current하게 맞추며 feature-lane source나 predecessor gate를 전용하지 않는다. Test-only predecessor가 branch advancement 때문에 실행 전에 취소되거나 queued로 남으면 hosted RED로 주장하지 않는다. ## Protected but incomplete commercial evidence @@ -82,7 +90,7 @@ Durable workflow/state source는 protected lineage에 있다. 남은 권위는 d | Orchestrator/free consumer | merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491` | protected source complete; immutable Noema release와 released consumer evidence 미완료 | | Patch-validator cache seed | merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`; protected run `34179912851` SUCCESS | protected operational execution complete; immutable image/release evidence 미완료 | | Exact-claim receipts | observed PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c` | fresh Security-inclusive exact-head gates, clean review, normal merge, execution/research producer evidence, immutable release | -| External extension admission | observed PR #560 test-only exact `58f8bbadd6a4a3863d642883e40f4753f6dc291f` | hosted drift RED, full pinned-catalog revalidation, 100% tests/docs, fresh gates, normal merge; shared immutable owner contract remains external prerequisite | +| External extension admission | observed PR #560 exact `81bff2f61ab6c323845116acd9622334f9dcfadd` | fresh exact-head gates, resolved valid review findings, normal merge; immutable shared owner contract and live owner receipts remain external prerequisites | ## Evidence semantics and merge rules @@ -96,8 +104,8 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge | Priority | Gap | Buyer/operator impact | Current owner | Authoritative completion evidence | Next executable action | | --- | --- | --- | --- | --- | --- | -| P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority로 승격되면 blocking review가 잘못 권위화될 수 있다. | issue #555 / PR #556 | source-claim binding + non-vacuous producer findings + execution/research producer evidence + fresh gates + normal merge + immutable release + released consumer RED→GREEN | exact `860714c...` gates/review 확인; failure면 causal repair, four-GREEN이면 normal merge | -| P0 | External extension capability admission | third-party plugin metadata·prompt·hook를 runtime authority로 오인하면 제품 경계와 고객 데이터가 확장 코드에 노출될 수 있다. | issue #545 / PR #560 | immutable source identity + independent scan receipts + full live catalog drift rejection + no undeclared capability + fresh gates + normal merge + immutable shared-contract consumption | test-only `58f8bba...` hosted RED 확인 후 minimal full-identity revalidation | +| P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority로 승격되면 blocking review가 잘못 권위화될 수 있다. | issue #555 / PR #556 | source-claim binding + non-vacuous producer findings + execution/research producer evidence + fresh gates + normal merge + immutable release + released consumer RED→GREEN | exact `860714c...` image/review 확인; four-GREEN이면 protected ancestry 재조회 후 normal merge | +| P0 | External extension capability admission | third-party plugin metadata·prompt·hook를 runtime authority로 오인하면 제품 경계와 고객 데이터가 확장 코드에 노출될 수 있다. | issue #545 / PR #560 | immutable source identity + independent scan receipts + full live catalog/receipt revalidation + authenticated issuance provenance + no undeclared capability + fresh gates + clean review + normal merge + immutable shared-contract consumption | exact `81bff2f...` hosted gates 확인; failure면 causal repair, four-GREEN 뒤 valid open threads resolve 여부 재검증 | | P0 | Strict orchestrator/free consumer release | Source는 protected됐지만 immutable released package와 central consumer activation이 없으면 commercial integration contract가 완결되지 않는다. | merged #535 + release lane | protected exact release/tag/package/SBOM/provenance/reproducibility + released consumer | release-ready protected head에서만 immutable publication evidence 생성 | | P0 | Patch-validator operational publication | source merge만으로 reusable cache와 immutable runtime activation을 증명할 수 없다. | issue #66 | protected-main image/cache receipt + immutable image/signature/SBOM/provenance/reproducibility/rollback | successful protected run `34179912851`을 immutable publication evidence와 결합 | | P0 | Toolchain/license release evidence | source dependency remediation만으로 실제 배포 artifact 권리와 재현성을 증명할 수 없다. | issue #531 | protected exact release package/image/SBOM/provenance/reproducibility/NOTICE/rights | release-ready protected exact head에서만 publication evidence 생성 | From e5bcc305bf6f3f40033a015c5f8087ec62025ce1 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 17:48:27 +0900 Subject: [PATCH 33/68] test(docs): track active policy-approval RED --- test/documentation-live-open-pr-authority.test.ts | 8 +++++--- ...oduct-technical-gap-current-candidate-contract.test.ts | 8 +++++--- 2 files changed, 10 insertions(+), 6 deletions(-) diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index d67f0f5af..c016a93db 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -11,7 +11,8 @@ describe("product-technical gap baseline live open-PR authority", () => { expect(baseline).toContain("merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`"); expect(baseline).toContain("merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`"); expect(baseline).toContain("Observed PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`"); - expect(baseline).toContain("Observed PR #560 exact `81bff2f61ab6c323845116acd9622334f9dcfadd`"); + expect(baseline).toContain("Observed PR #560 test-only exact `7ca9aebee6f92053913c0bbc665c8de77650891f`"); + expect(baseline).toContain("Production predecessor #560 exact `81bff2f61ab6c323845116acd9622334f9dcfadd`"); expect(baseline).toContain("default `main`을 base로 한다"); expect(baseline).toContain("live #556 must be re-fetched before integration"); expect(baseline).toContain("Test-only `dbab4cdc150d4973002f8b61173282f7c7542725`"); @@ -22,11 +23,12 @@ describe("product-technical gap baseline live open-PR authority", () => { expect(baseline).toContain("required Security Scan `34197596536`"); expect(baseline).toContain("issue #555 / PR #556"); expect(baseline).toContain("issue #545 / PR #560"); - expect(baseline).toContain("application CI `34204455463`"); - expect(baseline).toContain("module-private runtime authority"); + expect(baseline).toContain("application CI `34206149899`"); + expect(baseline).toContain("Policy / Approval issuance"); for (const staleAuthority of [ "Observed PR #560 test-only exact `58f8bbadd6a4a3863d642883e40f4753f6dc291f`", + "Observed PR #560 exact `81bff2f61ab6c323845116acd9622334f9dcfadd`", "Observed PR #556 exact `809ccb78bfdf8f9785d4c74ab834159961cce6e9`", "Observed PR #556 exact `920eb7be0c3f57c5f149328a08beddc13339a338`", "Observed PR #556 exact `363d62bc888e7b9555ff56bbce4dadc0a61d4efb`", diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index 55bbb34f2..2ecf70577 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -13,7 +13,8 @@ describe("product technical gap current candidate authority", () => { "merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`", "merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`", "Observed PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`", - "Observed PR #560 exact `81bff2f61ab6c323845116acd9622334f9dcfadd`", + "Observed PR #560 test-only exact `7ca9aebee6f92053913c0bbc665c8de77650891f`", + "Production predecessor #560 exact `81bff2f61ab6c323845116acd9622334f9dcfadd`", "merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`", "merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`", "merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`", @@ -27,8 +28,8 @@ describe("product technical gap current candidate authority", () => { expect(baseline).toContain("reviewer-ci RED"); expect(baseline).toContain("1 failed / 721 passed"); expect(baseline).toContain("catalog drift cannot silently update an admitted extension"); - expect(baseline).toContain("application CI `34204455463`"); - expect(baseline).toContain("module-private runtime authority"); + expect(baseline).toContain("application CI `34206149899`"); + expect(baseline).toContain("Policy / Approval issuance"); for (const staleTruth of [ "protected `main@59ae66de96b64c8ce51f0030a624815a08dbefdd`", @@ -36,6 +37,7 @@ describe("product technical gap current candidate authority", () => { "protected `main@699489cdbb8de3404154d9a3d6022c692ce85fd6`", "protected `main@d6394b2aa73e6fc57fccdad74ea38ad87f79e7f8`", "Observed PR #560 test-only exact `58f8bbadd6a4a3863d642883e40f4753f6dc291f`", + "Observed PR #560 exact `81bff2f61ab6c323845116acd9622334f9dcfadd`", "Observed PR #556 exact `809ccb78bfdf8f9785d4c74ab834159961cce6e9`", "Observed PR #556 exact `920eb7be0c3f57c5f149328a08beddc13339a338`", "Observed PR #556 exact `363d62bc888e7b9555ff56bbce4dadc0a61d4efb`", From 6046c66ec41c9ebf73c0a2986e88905bbf12d9cc Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 17:50:45 +0900 Subject: [PATCH 34/68] docs: bind commercial gap to policy-approval RED --- docs/product-technical-gap-baseline.md | 104 ++++++++++--------------- 1 file changed, 39 insertions(+), 65 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index f3bbb72a7..0676f79b9 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -4,99 +4,73 @@ 이 문서는 protected source, active candidate, transient workflow evidence와 foreign-owner authority를 분리한다. Open PR exact head, protected base, required workflow, review thread, release와 central dependency는 mutation·merge·release 직전에 다시 읽는다. predecessor GREEN, queued/pending/in-progress/skipped/cancelled run, 오래된 PR base snapshot과 scanner/model judgement는 다음 revision의 merge authority로 전용하지 않는다. -Current protected source는 GitHub-verified protected `main@0dbfceb850cda3a016ceb39ae1c8a1a96a9f2ad5`다. 이 protected revision에는 normal #535 merge가 포함돼 있고, merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`의 strict `orchestrator/free` consumer, provider-endpoint fail-closed contract와 reviewer `timeout=None`/`max_retries=0` semantics가 protected source가 됐다. Current source SHA는 moving observation이며 future merge 뒤 evergreen identity로 취급하지 않는다. +Current protected source는 GitHub-verified protected `main@0dbfceb850cda3a016ceb39ae1c8a1a96a9f2ad5`다. Current source SHA는 moving observation이며 future merge 뒤 evergreen identity로 취급하지 않는다. 이 protected revision에는 merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`의 strict `orchestrator/free` consumer와 provider-endpoint fail-closed contract가 포함돼 있다. 이 revision 작성 시 moving central control-plane snapshot은 central `.github/main@7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db`다. Noema runtime의 reviewed immutable central consumer pin은 `c9052e607e5f3cc76e73207e7786b21500721b79`이고 runtime authority 표현은 `ALLOWED_WORKFLOW_SHA = c9052e607e5f3cc76e73207e7786b21500721b79`다. Moving foreign head와 reviewed immutable pin을 같은 권위로 취급하지 않으며, central moving head가 전진했다고 Noema consumer pin을 자동 승격하지 않는다. -Merged documentation history에는 merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`가 있고, toolchain history에는 merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`, durable workflow/state history에는 merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`, work-conserving concurrency에는 merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`, automation threat-model documentation에는 merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`, patch-validator default-branch cache-seed history에는 merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`가 포함돼 있다. 이 SHA들은 protected lineage의 역사 증거이며 open-candidate authority가 아니다. +Protected history에는 merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`, merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`, merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`, merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`, merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`, merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`가 포함돼 있다. 이 SHA들은 역사 증거이지 open-candidate authority가 아니다. -#559가 cross-lane commercial baseline과 executable documentation-authority tests를 소유한다. 다른 feature lane에 포함된 과거 baseline blob은 ordinary/non-force semantic convergence 때 current authority로 승계하지 않는다. +#559가 `docs/product-technical-gap-baseline.md`와 executable documentation-authority tests의 sole writer다. 다른 feature lane의 과거 baseline blob은 ordinary/non-force semantic convergence 때 current authority로 승계하지 않는다. ## Canonical product boundary Noema Core Domain은 **Agent Runtime**과 **Workflow / Task Execution**이다. **Tool / Capability Boundary**, **State / Checkpoint**, **Isolation Integration**, **Policy / Approval**, **Observability**, **Recovery**는 명시적 bounded context다. Execution identity, side-effect authority, claim/checkpoint CAS, cancellation/recovery invariant는 Noema transaction boundary에 남긴다. -`contextual-orchestrator`는 provider/model discovery, routing, retry/failover, test-time compute와 provider credential을 소유한다. Noema는 released gateway contract와 canonical `orchestrator/free` alias를 소비할 뿐 direct provider SDK, provider key, provider/model/group fallback policy를 소유하지 않는다. `.github`는 organization reusable workflow와 control-plane source를 소유한다. `quarantine-sandbox-runtime`, Wardnet, EgressWeave, AppGuardrail은 isolation/security/outbound truth를 각자 소유한다. Keyverse는 identity backend owner다. `context-graph-contracts`와 `enterprise-architecture-core`는 released/versioned contract로만 연결하고 mutable sibling PR source, copied domain table, cross-service SQL을 runtime truth로 사용하지 않는다. +`contextual-orchestrator`는 provider/model discovery, routing, retry/failover, test-time compute와 provider credential을 소유한다. Noema는 released gateway contract와 canonical `orchestrator/free` alias를 소비할 뿐 direct provider SDK, provider key, provider/model/group fallback policy를 소유하지 않는다. `.github`는 organization reusable workflow/control-plane source, Keyverse는 identity backend, `quarantine-sandbox-runtime`·Wardnet·EgressWeave·AppGuardrail은 각자의 isolation/security/outbound truth를 소유한다. `context-graph-contracts`와 `enterprise-architecture-core`는 released/versioned contract로만 연결하며 mutable sibling PR source, copied domain table, cross-service SQL을 runtime truth로 쓰지 않는다. -#550은 PR-scoped supersession cancellation과 work-conserving dispatch를 protected source에 통합했다. #542는 Durable Workflow / Task Execution과 State / Checkpoint의 atomic task claim, checkpoint CAS/replay, effect-start/terminal authority, cancellation/recovery 및 retained-provenance validation을 protected source로 만들었다. ADR 0013은 deployed Durable Object transaction/runtime evidence가 없으므로 `Proposed`를 유지한다. #540은 historical Wrangler/Miniflare/Sharp/Libvips tooling path를 제거하고 pinned `workerd@1.20260625.1` + `esbuild@0.28.1`, canonical lock/license evidence와 patch-validator dependency pruning을 protected source에 통합했다. #535는 repository-selected provider/model authority를 제거하고 canonical `orchestrator/free` alias와 contextual-orchestrator gateway boundary를 protected source에 통합했다. +#550은 PR-scoped supersession cancellation과 work-conserving dispatch를 protected source에 통합했다. #542는 Durable Workflow / Task Execution과 State / Checkpoint의 atomic task claim, checkpoint CAS/replay, effect-start/terminal authority, cancellation/recovery와 retained-provenance validation을 protected source로 만들었다. ADR 0013은 deployed Durable Object transaction/runtime evidence가 없으므로 `Proposed`다. #540은 historical Wrangler/Miniflare/Sharp/Libvips tooling path를 제거하고 pinned `workerd@1.20260625.1` + `esbuild@0.28.1`과 canonical lock/license evidence를 protected source에 통합했다. ## Active candidate convergence — 2026-09-08 KST ### Exact-claim evidence receipts — issue #555 / PR #556 -Observed PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`는 Draft이고 default `main`을 base로 한다. Prerequisite #535는 이미 normal merge돼 protected `main@0dbfceb850cda3a016ceb39ae1c8a1a96a9f2ad5`가 되었으며, #556은 그 protected source 위의 ahead-only candidate다. `live #556 must be re-fetched before integration`이며 predecessor head의 gate나 review evidence는 전용하지 않는다. +Observed PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`는 Draft이고 default `main`을 base로 한다. Prerequisite #535는 protected source에 정상 통합됐고 #556은 그 위의 ahead-only candidate다. `live #556 must be re-fetched before integration`이며 predecessor head의 workflow/review evidence를 current authority로 전용하지 않는다. -#556의 retained contract는 authenticated producer receipt와 `ClaimEvidenceRequirement` publication authority를 분리한다. Raw current-head source receipt는 context authority일 뿐이고, trusted producer가 exact claim/evidence kind와 finding coordinates를 명시적으로 승인하지 않는 한 blocking finding을 권위화하지 못한다. Requirement/receipt mismatch, wrong coordinates, direct model dictionaries, context-to-finding promotion은 deterministic gate와 publisher 전에 fail closed한다. +#556은 authenticated producer receipt와 `ClaimEvidenceRequirement` publication authority를 분리한다. Raw source receipt는 context authority일 뿐이고 requirement/receipt mismatch, wrong coordinates, direct model dictionaries, context-to-finding promotion은 deterministic gate와 publisher 전에 fail closed한다. -Test-only `dbab4cdc150d4973002f8b61173282f7c7542725`는 claim이 exact source line에서 파생돼야 한다는 regression contract를 추가했다. Hosted workflow generation은 후속 mutation의 정상 `cancel-in-progress`로 test execution 전에 cancelled돼 hosted RED로 주장하지 않는다. Production `440346ee73e60e87915bd3027a774e24d3ac5124`는 exactly-one-line UTF-8 decoding과 claim equality를 fail closed로 강제했다. Edge head `920eb7be0c3f57c5f149328a08beddc13339a338`은 LF/CRLF/unterminated line, paraphrase mismatch, embedded multi-line bytes와 invalid UTF-8 edge를 고정했다. +Test-only `dbab4cdc150d4973002f8b61173282f7c7542725`는 claim이 exact source line에서 파생돼야 한다는 regression contract를 추가했다. Production `440346ee73e60e87915bd3027a774e24d3ac5124`는 exactly-one-line UTF-8 decoding과 claim equality를 fail closed로 강제했다. Edge exact `920eb7be0c3f57c5f149328a08beddc13339a338`의 hosted reviewer-ci RED는 Run `34190991526`, job `101948849348`에서 **1 failed / 721 passed**로 종료됐고, stale fixture만 고친 causal repair는 `1cd8db5a94ed420bed8b52be0d3b3354f9fc86ab`이다. 후속 publisher boundary는 finding-free non-approval을 거부하도록 보강됐다. -Exact `920eb7be...`는 실제 hosted reviewer-ci RED를 만들었다. Run `34190991526`, job `101948849348`에서 exact checkout, noema-core 100% line+branch coverage와 100% docstring gate는 통과했지만 reviewer suite가 **1 failed / 721 passed**로 종료됐다. 실패는 stale `_source_bundle()` fixture가 exact source bytes와 runtime paraphrase를 계속 결합하던 데 있었고, causal test repair `1cd8db5a94ed420bed8b52be0d3b3354f9fc86ab`은 source claim을 exact decoded line으로 맞추면서 source-vs-execution kind mismatch rejection을 보존했다. 후속 `809ccb78bfdf8f9785d4c74ab834159961cce6e9`은 review에서 확인된 unused import만 제거했다. - -그 뒤 publisher boundary review는 finding-free `request_changes`/`blocked` model verdict가 receipt admission을 건너뛴 채 GitHub non-approval로 게시될 수 있는 vacuous-oracle bypass를 찾았다. RED `6629f07e2c7bd35698331d8966b7cbe35204a808`은 실제 PydanticAI agent→CLI publisher seam에서 두 non-approval 상태를 재현하고, GREEN `4c2153702972e8d5c0f077ac79cc68cbf6da4bfb`은 model non-approval에 producer-authenticated finding을 필수화했다. Current exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`은 CHANGELOG authority까지 포함한다. - -Current #556 exact generation은 application CI `34197596549`, reviewer-ci `34197596588`, required Security Scan `34197596536`, patch-validator-image `34197596517`이다. 이 revision 작성 시 application CI, reviewer-ci, required Security는 terminal SUCCESS이고 patch-validator-image만 `in_progress`다. 따라서 3-GREEN이지 four-GREEN이 아니며 image lane이 terminal success가 되기 전 normal merge authority는 없다. Default `main` retarget 뒤 required Security Scan이 materialize되므로 absent/queued/skipped/cancelled/failed Security를 passing으로 취급하지 않는다. - -Remaining supply-chain boundary는 exact stdout/stderr producer, trusted research producer, immutable Noema release, released central `.github#1641` consumer bump와 unchanged original/synonym corpus RED→GREEN이다. +Current #556 generation은 application CI `34197596549`, reviewer-ci `34197596588`, required Security Scan `34197596536`, patch-validator-image `34197596517`이다. Fresh read에서 CI/reviewer/Security는 terminal SUCCESS이고 image만 in progress라 3-GREEN이지 four-GREEN이 아니다. Exact stdout/stderr producer, trusted research producer, immutable Noema release, released central consumer와 unchanged original/synonym corpus RED→GREEN은 별도 completion evidence다. ### External extension admission — issue #545 / PR #560 -Observed PR #560 exact `81bff2f61ab6c323845116acd9622334f9dcfadd`는 Draft이고 default `main`을 base로 한다. 이 lane은 Tool / Capability Boundary만 소유하며 plugin source, provider routing, quarantine/security/outbound implementation을 Noema로 복제하지 않는다. ADR 0015는 `Proposed`이고 local ACL/test double은 `context-graph-contracts`의 immutable shared artifact contract가 나오기 전의 fail-closed boundary다. - -Initial exact `e23d9ef941f453720ddc1456c7bc208e9434a7b2`의 hosted application CI run `34195202961`, job `101961294823`은 exact checkout, live-base, lockfile, install, typecheck를 통과한 뒤 repository-wide public API documentation gate에서 실패했다. 새 external-extension module의 12 public exported type/interface가 meaningful adjacent JSDoc을 충족하지 못한 현실 RED였다. Production behavior나 gate를 약화하지 않고 `469efe70b673a2c58d93e1944721216e167afc9b`에서 해당 public contracts에 의미 있는 JSDoc을 추가했다. +Observed PR #560 test-only exact `7ca9aebee6f92053913c0bbc665c8de77650891f`는 Draft이고 default `main`을 base로 한다. Production predecessor #560 exact `81bff2f61ab6c323845116acd9622334f9dcfadd`는 Tool / Capability source identity, runtime-issued admission/activation/invocation receipt provenance, live AppGuardrail/quarantine receipt re-resolution을 구현한 마지막 production tree다. ADR 0015는 계속 `Proposed`다. -Invocation-time source-integrity review에서는 admission이 pin한 catalog identity 여섯 필드 중 일부만 재검증돼 “catalog drift cannot silently update an admitted extension” invariant가 불완전한 것을 찾았다. Test-only exact `58f8bbadd6a4a3863d642883e40f4753f6dc291f`의 application CI `34197933796`, job `101969766167`은 exact checkout, live-base, lockfile, install, typecheck 뒤 release tests에서 **4 / 4167 failed**의 실제 hosted RED를 만들었다. `6b7b5d64d28a46464c854c74ac33ac1b01a888f2`는 drift fixture만 바로잡았고, production `572aa5919210b511e58d70e809dbefc60196ada7`는 activation scope/time을 재검증하면서 live catalog를 extension id/repository/commit/path/artifact/marketplace digest 전체 six-field identity에 묶었다. +이 lane의 기존 실제 RED에는 missing public-doc gate, catalog identity drift, forged activation, fabricated admitted object, field-identical activation/receipt clone과 owner-receipt revocation TOCTOU가 있다. 특히 test-only `58f8bbadd6a4a3863d642883e40f4753f6dc291f`의 hosted application CI `34197933796`은 4 / 4167 release-test failures를 만들었고, 후속 production은 six-field identity를 재검증해 `catalog drift cannot silently update an admitted extension` invariant를 완성했다. Production predecessor의 focused local evidence는 34 passed, owned production 100%, typecheck/diff-check GREEN이었지만 hosted four-GREEN을 뜻하지 않는다. -그 뒤 public invocation이 structurally constructible activation을 authority로 믿는 결함을 test-only `2987e8625fb0964eb119a4be337280b49588e8bc`가 재현했고 application CI `34199961782`에서 실제 hosted RED가 관찰됐다. 또 exported `AdmittedExternalExtension` fabrication이 AppGuardrail/quarantine receipt admission을 건너뛸 수 있어 test-only `632c77b9db9f39662f78087b3b4eca45b46cf9d9`가 activation boundary를 고정했다. Ordinary descendant `f9be6fbecd566d197caa7317bc99de4b931573d1`은 admitted-extension provenance를 module-private runtime authority로 결합했다. +#### Current Policy / Approval issuance RED -Fresh review는 field-identical activation clone과 invocation-receipt replay clone, invocation 시점의 AppGuardrail/quarantine receipt revocation TOCTOU를 추가로 찾았다. Test-only `3b072f8f9c07959187006fa926812bbc713aff99`은 activation clone을, test-only parent `0323a3c67767b5e137de6b754a8173c51d709c21`은 owner receipt revocation과 retained replay clone을 고정했다. Current production `81bff2f61ab6c323845116acd9622334f9dcfadd`는 admitted extension, activation, invocation receipt의 issuance provenance를 module-private runtime authority로 인증하고, invocation 때 AppGuardrail/quarantine receipts를 다시 resolve해 artifact/isolation-policy/producer-owner binding을 재검증한다. Scope/time 및 six-field catalog identity fail-closed 검증은 유지한다. +Fresh source review는 `ExternalExtensionAuthority`가 source/catalog identity와 AppGuardrail/quarantine scan receipt만 신뢰하고, `approval_status`, `allowed_product_repositories`, `allowed_execution_roles`, validity와 policy scope는 untrusted descriptor에서 그대로 받는 결함을 찾았다. Module-private WeakSet은 객체가 admission 함수를 통과했다는 사실만 증명하며 product grant 내용이 Noema Policy / Approval owner에게서 발급됐다는 사실은 증명하지 않는다. -Current #560 exact generation은 application CI `34204455463`, reviewer-ci `34204455676`, required Security Scan `34204455766`, patch-validator-image `34204455409`다. 이 revision 작성 시 네 lane 모두 queued이며 predecessor local 34-pass/owned production 100%/typecheck evidence를 hosted GREEN으로 승격하지 않는다. 두 substantive review thread는 production repair를 기록했지만 exact-head hosted verification 전까지 intentionally unresolved 상태라 merge authority가 아니다. +Current test-only `7ca9aebee6f92053913c0bbc665c8de77650891f`의 `test/external-extension-policy-authority.test.ts`는 exact source/catalog/scan pins를 고정한 채 product/role/status만 self-broaden하고, independently trusted Policy / Approval issuance가 없으면 admission이 fail closed해야 한다고 요구한다. Current generation은 application CI `34206149899`, reviewer-ci `34206149930`, required Security Scan `34206149849`, patch-validator-image `34206149861`이며 fresh read에서 모두 queued라 hosted RED를 아직 주장하지 않는다. -Shared completion boundary는 immutable `context-graph-contracts` external-capability contract, live AppGuardrail/quarantine owner evidence, bounded pilot evidence, exact-head four-GREEN, clean review authority와 normal merge다. Noema가 mutable sibling ref나 foreign scanner/isolation/egress implementation을 복제해 completion을 제조하지 않는다. +Minimum causal fix는 product/role/status/validity/policy grant를 별도의 pinned Noema Policy / Approval authority 또는 receipt에 결합하는 것이다. Anthropic catalog, AppGuardrail/quarantine scan receipts, `Readonly`/freeze, in-process object provenance를 product-approval truth로 과승격하지 않는다. Provider routing은 contextual-orchestrator, scanner/isolation/egress는 각 canonical owner에 남긴다. ### Cross-lane documentation authority — PR #559 -#559는 이 baseline과 다섯 executable documentation-authority tests의 sole writer다. Exact predecessor `44d2050804ef1d167b2170dcf6fc31657900b9f6`의 application CI `34193418411`은 release tests에서 1건 실패했다. Baseline은 문장 시작의 `Run `34190991526``을 올바르게 기록했지만 executable test가 lowercase `run` exact substring을 요구한 docs/test casing mismatch였다. Gate를 느슨하게 하거나 baseline을 부자연스럽게 바꾸지 않고 `9c14c4e2e5d7fb0d51e0510ea3489d42ba4df0e8`에서 test oracle을 실제 문장 casing에 맞췄다. - -#560이 `81bff2f...` production repair까지 전진하면서 #559 exact `16e006c605b5ff28858a9ab4c29154e8b800c8e2`의 baseline/oracle은 stale authority가 됐다. Test-only `e86592848162e68e7001e8acb54bd2973ac6bb40`은 current #560 exact와 current run generation을 먼저 요구한다. 후속 production documentation repair는 이 baseline만 code-current하게 맞추며 feature-lane source나 predecessor gate를 전용하지 않는다. Test-only predecessor가 branch advancement 때문에 실행 전에 취소되거나 queued로 남으면 hosted RED로 주장하지 않는다. - -## Protected but incomplete commercial evidence - -### Orchestrator/free consumer — merged #535 - -Merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`는 protected `main@0dbfceb850cda3a016ceb39ae1c8a1a96a9f2ad5`에 normal integration됐다. Provider/model routing은 `contextual-orchestrator` owner에 남고 Noema는 `orchestrator/free`와 gateway-only credentials를 소비한다. Source integration 자체는 immutable Noema package/release, SBOM/provenance/reproducibility 또는 downstream consumer activation을 증명하지 않는다. - -### Patch-validator default-branch cache seed — merged #558 / issue #66 - -Merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`는 protected source에 포함됐다. Protected-main prior push `patch-validator-image` run `34179912851`은 terminal SUCCESS다. 그 성공만으로 cache hit 성능, immutable image digest publication, signature/attestation, reproducibility 또는 rollback을 증명하지 않는다. - -### Toolchain and inbound rights — issue #531 / merged #540 - -Source remediation은 protected lineage에 있다. 남은 권위는 exact released package/image/SBOM/provenance/reproducibility, NOTICE/attribution, actual artifact rights와 explicit owner/legal outbound-rights evidence다. Source-only license inventory를 release evidence로 승격하지 않는다. - -### Durable runtime operation — issue #541 / merged #542 +#559는 baseline과 다섯 executable documentation-authority tests만 소유한다. Earlier exact `44d2050804ef1d167b2170dcf6fc31657900b9f6`의 application CI `34193418411`은 문장 casing을 과도하게 고정한 test oracle 때문에 release tests 1건이 실패했고 `9c14c4e2e5d7fb0d51e0510ea3489d42ba4df0e8`이 그 oracle만 수리했다. -Durable workflow/state source는 protected lineage에 있다. 남은 권위는 deployed Durable Object binding/transaction compatibility, recovery/rollback receipt, immutable release/package/SBOM/provenance/reproducibility다. 이 evidence 전까지 ADR 0013은 `Proposed`다. +#560이 production `81bff2f...`로 전진했을 때 #559는 `e86592848162e68e7001e8acb54bd2973ac6bb40` test-only → `595f1f78413ecf934d5fc4476c31dd2e44d43186` production documentation convergence를 수행했다. 이후 #560에서 새 Policy / Approval RED가 발견돼 test-only `e5bcc305bf6f3f40033a015c5f8087ec62025ce1`이 active exact `7ca9aeb...`를 다시 executable authority로 요구한다. 이 문서 revision은 그 active RED를 code-current하게 반영한다. Feature source와 predecessor gate는 #559로 복사하지 않는다. ## Current authority table | Lane | Authority | Integration / completion condition | | --- | --- | --- | -| Protected source | live protected main; current observation protected `main@0dbfceb850cda3a016ceb39ae1c8a1a96a9f2ad5` | mutation·merge·release 직전 exact protected head 재조회 | -| Central workflow trust | central `.github/main@7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db`; reviewed pin `c9052e607e5f3cc76e73207e7786b21500721b79` | moving head와 immutable reviewed pin 분리; released/reviewed consumer bump 전 자동 승격 금지 | -| Toolchain/license source | merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac` | source complete; release/publication/rights evidence 미완료 | -| Durable workflow/state source | merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc` | source complete; deployed runtime/recovery/release evidence 미완료 | -| Documentation authority | merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6` + active #559 successor | moving PR/protected/central truth를 #559에서 code-current 유지 | -| Orchestrator/free consumer | merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491` | protected source complete; immutable Noema release와 released consumer evidence 미완료 | -| Patch-validator cache seed | merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`; protected run `34179912851` SUCCESS | protected operational execution complete; immutable image/release evidence 미완료 | -| Exact-claim receipts | observed PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c` | fresh Security-inclusive exact-head gates, clean review, normal merge, execution/research producer evidence, immutable release | -| External extension admission | observed PR #560 exact `81bff2f61ab6c323845116acd9622334f9dcfadd` | fresh exact-head gates, resolved valid review findings, normal merge; immutable shared owner contract and live owner receipts remain external prerequisites | +| Protected source | protected `main@0dbfceb850cda3a016ceb39ae1c8a1a96a9f2ad5` | mutation·merge·release 직전 exact protected head 재조회 | +| Central workflow trust | central `.github/main@7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db`; reviewed pin `c9052e607e5f3cc76e73207e7786b21500721b79` | moving head와 immutable reviewed pin 분리 | +| Toolchain/license source | merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac` | release/publication/rights evidence 미완료 | +| Durable workflow/state source | merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc` | deployed runtime/recovery/release evidence 미완료 | +| Documentation authority | merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6` + active #559 successor | moving PR/protected/central truth code-current 유지 | +| Orchestrator/free consumer | merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491` | immutable Noema release + released consumer evidence 미완료 | +| Patch-validator cache seed | merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`; protected run `34179912851` SUCCESS | immutable image/release evidence 미완료 | +| Exact-claim receipts | observed PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c` | image terminal success + clean review + normal merge + execution/research producer + immutable release | +| External extension admission | observed PR #560 test-only exact `7ca9aebee6f92053913c0bbc665c8de77650891f`; production predecessor `81bff2f61ab6c323845116acd9622334f9dcfadd` | Policy / Approval RED→minimum fix→fresh four-GREEN→clean review→normal merge; immutable shared owner/live pilot evidence remains separate | ## Evidence semantics and merge rules -A PR can be review-clean while non-authorizing. Review thread resolution, CI, reviewer-ci, required Security Scan, image/SBOM/provenance and branch ancestry are separate evidence classes. Every source mutation or restack invalidates predecessor workflow evidence. `queued`, `pending`, `in_progress`, `skipped`, `cancelled`, stale or absent-required evidence is not passing. +A PR can be review-clean while non-authorizing. Review resolution, CI, reviewer-ci, required Security, image/SBOM/provenance, branch ancestry와 release는 separate evidence classes다. Every source mutation/restack invalidates predecessor workflow evidence. `queued`, `pending`, `in_progress`, `skipped`, `cancelled`, stale 또는 absent-required evidence는 passing이 아니다. -Normal merge requires unchanged exact head, independently refreshed live base/head, no valid unresolved review finding, applicable required terminal-success gates and no foreign-owner/protected-contract regression. Concurrent commits or pushes are not called a race merely because they occur. Wrong base/conflict, stale ADR identity, mutable dependency, missing fixture/contract or single-writer violation is repaired by ordinary/non-force semantic convergence rather than force push, destructive rebase or casual Close. +Normal merge requires unchanged exact head, independently refreshed live base/head, no valid unresolved review finding, applicable required terminal-success gates and no foreign-owner/protected-contract regression. Concurrent commits나 pushes 자체를 race로 단정하지 않는다. Wrong base/conflict, stale ADR, mutable dependency, missing fixture/contract, single-writer 위반은 force push나 destructive rebase가 아니라 ordinary/non-force semantic convergence로 수리한다. PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge 또는 verified successor가 모든 유효 delta/test/fixture/contract/evidence를 완전히 승계한 경우에만 사라진다. Blocked lane은 자기 lane만 막고 unrelated safe review, owner-path repair, docs-to-code repair와 buyer-gap work는 계속한다. @@ -104,17 +78,17 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge | Priority | Gap | Buyer/operator impact | Current owner | Authoritative completion evidence | Next executable action | | --- | --- | --- | --- | --- | --- | -| P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority로 승격되면 blocking review가 잘못 권위화될 수 있다. | issue #555 / PR #556 | source-claim binding + non-vacuous producer findings + execution/research producer evidence + fresh gates + normal merge + immutable release + released consumer RED→GREEN | exact `860714c...` image/review 확인; four-GREEN이면 protected ancestry 재조회 후 normal merge | -| P0 | External extension capability admission | third-party plugin metadata·prompt·hook를 runtime authority로 오인하면 제품 경계와 고객 데이터가 확장 코드에 노출될 수 있다. | issue #545 / PR #560 | immutable source identity + independent scan receipts + full live catalog/receipt revalidation + authenticated issuance provenance + no undeclared capability + fresh gates + clean review + normal merge + immutable shared-contract consumption | exact `81bff2f...` hosted gates 확인; failure면 causal repair, four-GREEN 뒤 valid open threads resolve 여부 재검증 | -| P0 | Strict orchestrator/free consumer release | Source는 protected됐지만 immutable released package와 central consumer activation이 없으면 commercial integration contract가 완결되지 않는다. | merged #535 + release lane | protected exact release/tag/package/SBOM/provenance/reproducibility + released consumer | release-ready protected head에서만 immutable publication evidence 생성 | -| P0 | Patch-validator operational publication | source merge만으로 reusable cache와 immutable runtime activation을 증명할 수 없다. | issue #66 | protected-main image/cache receipt + immutable image/signature/SBOM/provenance/reproducibility/rollback | successful protected run `34179912851`을 immutable publication evidence와 결합 | -| P0 | Toolchain/license release evidence | source dependency remediation만으로 실제 배포 artifact 권리와 재현성을 증명할 수 없다. | issue #531 | protected exact release package/image/SBOM/provenance/reproducibility/NOTICE/rights | release-ready protected exact head에서만 publication evidence 생성 | -| P0 | Reviewer/Maintainer production identity | source control만으로 App installation, key custody/rotation, bounded publication authority를 증명할 수 없다. | issues #29 / #227 | live installation/permissions/key-custody/rotation + bounded publication/recovery receipt | approved control-plane evidence와 source evidence를 분리 보존 | -| P0 | Governance enforceability | workflow source만으로 approval/deletion/rewrite/break-glass 정책 전체를 증명할 수 없다. | issue #27 | live ruleset/protection audit + observed required-workflow behavior | protected mutation 직전 governance 재조회 | -| P1 | Durable runtime operation | source-level durable semantics와 deployed transaction/recovery는 별도 evidence class다. | issue #541 | deployed compatibility + recovery/rollback + immutable release identity | evidence 전 ADR 0013 `Proposed` 유지 | -| P1 | Production KPI evidence | fixture는 reliability, latency, commercial operation을 입증하지 못한다. | issue #3 | authenticated retained production KPI window with source/run identity and denominator | approved production source가 없으면 fail closed 유지 | -| P1 | Acquisition transfer | Apache-2.0 source grant는 contributor ownership, assignment, artifact-transfer rights 자체를 증명하지 않는다. | issue #5 | exact-release rights metadata, dependency/NOTICE/SBOM, contributor/IP and transfer evidence | immutable release 이후 acquisition evidence 수집 | +| P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority가 될 수 있다. | issue #555 / PR #556 | source binding + non-vacuous findings + producer evidence + fresh gates + normal merge + immutable release + released consumer RED→GREEN | exact `860714c...` image/review 재조회; four-GREEN이면 protected ancestry 확인 후 normal merge | +| P0 | External extension capability admission | third-party plugin metadata/prompt/hook 또는 self-asserted product grant가 runtime authority가 될 수 있다. | issue #545 / PR #560 | immutable source + independent scan + independently issued Policy / Approval grant + live revalidation + no undeclared capability + fresh gates/review + normal merge + immutable shared contract | exact `7ca9aeb...` hosted RED 확인 후 minimum Policy / Approval issuance binding | +| P0 | Strict orchestrator/free consumer release | Source 통합만으로 immutable consumer activation을 증명할 수 없다. | merged #535 + release lane | exact release/tag/package/SBOM/provenance/reproducibility + released consumer | release-ready protected head에서만 publication | +| P0 | Patch-validator operational publication | source merge와 한 번의 image run만으로 reusable immutable runtime을 증명할 수 없다. | issue #66 | protected execution + immutable image/signature/SBOM/provenance/reproducibility/rollback | immutable publication evidence와 결합 | +| P0 | Toolchain/license release evidence | source dependency remediation만으로 배포 artifact 권리/재현성을 증명할 수 없다. | issue #531 | package/image/SBOM/provenance/reproducibility/NOTICE/rights | release-ready exact head에서만 생성 | +| P0 | Reviewer/Maintainer production identity | source control만으로 App installation, key custody/rotation, bounded publication authority를 증명할 수 없다. | issues #29 / #227 | live installation/permissions/key-custody/rotation + publication/recovery receipt | control-plane evidence와 source evidence 분리 | +| P0 | Governance enforceability | workflow source만으로 approval/deletion/rewrite/break-glass 정책 전체를 증명할 수 없다. | issue #27 | live ruleset/protection audit + observed required-workflow behavior | protected mutation 직전 재조회 | +| P1 | Durable runtime operation | source-level durable semantics와 deployed transaction/recovery는 별도 evidence다. | issue #541 | deployed compatibility + recovery/rollback + immutable release | ADR 0013 Proposed 유지 | +| P1 | Production KPI evidence | fixture는 reliability, latency, commercial operation을 입증하지 못한다. | issue #3 | authenticated retained KPI window + source/run identity + denominator | approved production source 없으면 fail closed | +| P1 | Acquisition transfer | Apache-2.0 source grant는 contributor ownership/assignment/artifact-transfer rights 자체를 증명하지 않는다. | issue #5 | exact-release rights metadata + NOTICE/SBOM + contributor/IP transfer evidence | immutable release 이후 수집 | ## Completion discipline -각 gap은 Authoritative completion evidence가 실제로 존재하고 current source/head에 결합될 때만 닫는다. 문서 존재, synthetic fixture, model judgement, stale workflow result를 완료 증거로 사용하지 않는다. Release-ready exact protected head가 없으면 version/tag/package/SBOM/provenance/rollback을 제조하지 않는다. +각 gap은 authoritative completion evidence가 실제로 존재하고 current source/head에 결합될 때만 닫는다. 문서 존재, synthetic fixture, model judgement, stale workflow result를 완료 증거로 사용하지 않는다. Release-ready exact protected head가 없으면 version/tag/package/SBOM/provenance/rollback을 제조하지 않는다. From 104a41306e0ba59335f5f35896b4a7b01a926047 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 18:43:25 +0900 Subject: [PATCH 35/68] docs: restore durable commercial gap owners --- docs/product-technical-gap-baseline.md | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 6ca1358a1..60a6fdbdc 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -26,11 +26,11 @@ Protected source는 raw source receipt를 context authority로만 취급하고, ## Active external-extension candidate — issue #545 / PR #560 -Observed PR #560 exact `935b99e1704b5a9966057a886dc60640d6bda5e2`는 Draft이며 protected `main`을 base로 한다. #556 merge 뒤 이 candidate는 ordinary/non-force restack이 필요하므로 live ancestry를 다시 읽기 전 merge authority가 아니다. Current generation은 application CI `34209618966`, reviewer-ci `34209619032`, required Security Scan `34209618973`, patch-validator-image `34209619260`이며 모두 queued다. queued는 GREEN이 아니다. +Observed PR #560 exact `669a45ab8a3a31727b361ada7f750e492a9ee166`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. #556 merge 뒤 current writer는 feature head와 protected main을 두 parent로 갖는 ordinary/non-force semantic restack을 수행했고, `.github`와 `reviewer` protected owner source를 그대로 승계했다. Current generation은 application CI `34211077535`, reviewer-ci `34211077488`, required Security Scan `34211077614`, patch-validator-image `34211077464`이며 모두 non-terminal이다. predecessor 결과는 이 exact head의 merge authority가 아니다. Earlier test-only exact `7ca9aebee6f92053913c0bbc665c8de77650891f`의 hosted application CI `34206149899`, job `101995980303`은 exact checkout, live-base guard, lockfile control, install, typecheck를 통과한 뒤 release tests에서 실패했다. 이 RED는 valid catalog/AppGuardrail/quarantine evidence가 있어도 descriptor가 `approval_status`, product repository, execution role을 self-broaden하면 별도 Noema Policy / Approval issuance 없이는 admission이 거부돼야 한다는 결함을 증명했다. -Production `c6e91dbe8b452e067d30890aae993b04b7cd814c`는 source/catalog/scanner authority와 Noema Policy / Approval issuance를 분리했다. Public Tool / Capability adapter는 maximum approval status, allowed product repositories, allowed execution roles, validity interval, isolation/egress references와 activation-policy version을 독립 grant에 결합한다. Unknown extension에는 implicit grant가 없다. Activation은 issued policy version을 인용해야 하며 invocation은 policy를 다시 resolve해 revocation/drift를 fail closed한다. Current exact `935b99e...`는 hostile/edge tests와 ADR 0015 `Proposed` decision까지 code-current하게 포함한다. +Production `c6e91dbe8b452e067d30890aae993b04b7cd814c`는 source/catalog/scanner authority와 Noema Policy / Approval issuance를 분리했다. Public Tool / Capability adapter는 maximum approval status, allowed product repositories, allowed execution roles, validity interval, isolation/egress references와 activation-policy version을 독립 grant에 결합한다. Unknown extension에는 implicit grant가 없다. Activation은 issued policy version을 인용해야 하며 invocation은 policy를 다시 resolve해 revocation/drift를 fail closed한다. Current exact `669a45a...`는 hostile/edge tests와 ADR 0015 `Proposed` decision을 보존한 채 protected #556 source를 ordinary/non-force로 승계한다. AppGuardrail/quarantine receipts는 scanner/provenance evidence이지 Noema approval이 아니다. EgressWeave/quarantine references는 outbound/isolation operation의 대체물이 아니다. Anthropic marketplace review는 discovery evidence이지 CWL product authority가 아니다. `context-graph-contracts`가 immutable shared external-capability contract를 release하기 전까지 이 local port는 fail-closed ACL/test double이며 live plugin installation 또는 buyer completion을 주장하지 않는다. @@ -47,9 +47,13 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge | Priority | Gap | Buyer/operator impact | Current owner | Authoritative completion evidence | Next executable action | | --- | --- | --- | --- | --- | --- | | P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority가 될 위험 | protected #556 + release/consumer lanes | protected source + execution/research producer + immutable Noema release + released central consumer corpus RED→GREEN | release/producer evidence를 별도 lane에서 완성 | -| P0 | External extension capability admission | third-party plugin metadata 또는 self-asserted product grant가 runtime authority가 될 위험 | issue #545 / PR #560 | immutable source + independent scan + Noema-issued Policy / Approval grant + live revalidation + fresh four-GREEN + normal merge + immutable shared contract/live pilot evidence | #556 protected merge를 ordinary/non-force로 restack한 뒤 exact-head gates 재검증 | +| P0 | External extension capability admission | third-party plugin metadata 또는 self-asserted product grant가 runtime authority가 될 위험 | issue #545 / PR #560 | immutable source + independent scan + Noema-issued Policy / Approval grant + live revalidation + fresh four-GREEN + normal merge + immutable shared contract/live pilot evidence | restacked exact head의 semantic union과 fresh gates를 재검증 | +| P0 | Protected-main governance closure | required Security workflow만으로 PR/review/history/deletion/bypass 통제를 증명했다고 오인할 위험 | issue #27 | fresh live ruleset + required PR/review/conversation/history/deletion controls + independent bypass/break-glass evidence + protected-source governance receipt | source가 만들 수 없는 organization/admin control은 issue #27에서 독립 검증 | | P0 | Strict orchestrator/free consumer release | source 통합만으로 immutable consumer activation을 증명할 수 없음 | merged #535 + release lane | version/tag/package/SBOM/provenance/reproducibility/rollback + released consumer | release-ready protected head에서만 publication | | P0 | Patch-validator operational publication | source/image CI success만으로 reusable immutable runtime을 증명할 수 없음 | issue #66 | protected execution + immutable image/signature/SBOM/provenance/reproducibility/rollback | immutable publication evidence와 결합 | +| P0 | Authentic production KPI evidence | fixture·synthetic 또는 source-level KPI 검증이 실제 운영 성능을 대체할 위험 | issue #3 | authenticated production-window records + strict provenance + buyer-relevant KPI gate | 실제 production evidence 없이는 readiness를 승격하지 않음 | +| P0 | Acquisition coordination | source/docs 완료를 buyer·legal·transfer readiness로 잘못 승격할 위험 | issue #5 | exact protected revision + applicable release/deployment/operational/buyer/legal evidence family | 남은 evidence family를 owner별로 수렴하고 source claim과 분리 | +| P0 | External Maintainer/Reviewer App identity | source capability-file 계약이 실제 App 설치·키 custody·rotation·권한·reviewer identity를 대체할 위험 | issues #29 / #227 | live installation + key custody/rotation + repository permission + eligible reviewer/publication identity evidence | 외부 App authority는 해당 issue owner에서 독립 검증 | | P0 | Durable workflow/state production evidence | source Durable Object logic이 실제 deployed transaction/recovery를 증명하지 않음 | merged #542 / ADR 0013 | deployment compatibility + recovery/rollback receipt + immutable release | deployed runtime evidence 확보 전 ADR 0013 `Proposed` 유지 | ## Release boundary From 9a664104067a0411a8038efe8ba7a8e588fe36d5 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 18:51:32 +0900 Subject: [PATCH 36/68] docs: align external-extension authority after restack --- docs/product-technical-gap-baseline.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 60a6fdbdc..cbdbb4ccb 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,7 +2,7 @@ ## Authority and update rule -이 문서는 protected source, active candidate, transient workflow evidence와 foreign-owner authority를 분리한다. Open PR exact head, protected base, required workflow, review thread, release와 central dependency는 mutation·merge·release 직전에 다시 읽는다. predecessor GREEN, queued/pending/in-progress/skipped/cancelled run, 오래된 PR base snapshot과 scanner/model judgement는 다음 revision의 merge authority로 전용하지 않는다. +이 문서는 protected source, active candidate, transient workflow evidence와 foreign-owner authority를 분리한다. Open PR exact head, protected base, required workflow, review thread, release와 central dependency는 mutation·merge·release 직전에 다시 읽는다. predecessor GREEN, queued/pending/in-progress/skipped/cancelled run, 오래된 PR base snapshot과 scanner/model judgement는 다음 revision의 merge authority로 전용하지 않는다. queued는 GREEN이 아니다. Current protected source는 GitHub-verified protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`다. Current source SHA는 moving observation이며 future merge 뒤 evergreen identity로 취급하지 않는다. 이 protected revision에는 merged PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`의 producer-authenticated exact-claim evidence admission과 non-vacuous reviewer publication contract가 포함돼 있다. @@ -26,11 +26,11 @@ Protected source는 raw source receipt를 context authority로만 취급하고, ## Active external-extension candidate — issue #545 / PR #560 -Observed PR #560 exact `669a45ab8a3a31727b361ada7f750e492a9ee166`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. #556 merge 뒤 current writer는 feature head와 protected main을 두 parent로 갖는 ordinary/non-force semantic restack을 수행했고, `.github`와 `reviewer` protected owner source를 그대로 승계했다. Current generation은 application CI `34211077535`, reviewer-ci `34211077488`, required Security Scan `34211077614`, patch-validator-image `34211077464`이며 모두 non-terminal이다. predecessor 결과는 이 exact head의 merge authority가 아니다. +Observed PR #560 exact `68f28439edfd92394723ebc1248a6b2e9a957d44`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. #556 merge 뒤 current writer는 feature head와 protected main을 두 parent로 갖는 ordinary/non-force semantic restack을 수행했고, `.github`와 `reviewer` protected owner source를 그대로 승계했다. Restack 때 겹친 `CHANGELOG.md`에서는 protected #556 entry와 #560 Tool / Capability entry의 semantic union을 복구했으며, predecessor `669a45a...` 대비 해당 repair는 exactly one addition / zero deletion이다. Current generation은 application CI `34212097312`, reviewer-ci `34212097422`, required Security Scan `34212097303`, patch-validator-image `34212097392`이며 모두 queued다. predecessor 결과는 이 exact head의 merge authority가 아니다. Earlier test-only exact `7ca9aebee6f92053913c0bbc665c8de77650891f`의 hosted application CI `34206149899`, job `101995980303`은 exact checkout, live-base guard, lockfile control, install, typecheck를 통과한 뒤 release tests에서 실패했다. 이 RED는 valid catalog/AppGuardrail/quarantine evidence가 있어도 descriptor가 `approval_status`, product repository, execution role을 self-broaden하면 별도 Noema Policy / Approval issuance 없이는 admission이 거부돼야 한다는 결함을 증명했다. -Production `c6e91dbe8b452e067d30890aae993b04b7cd814c`는 source/catalog/scanner authority와 Noema Policy / Approval issuance를 분리했다. Public Tool / Capability adapter는 maximum approval status, allowed product repositories, allowed execution roles, validity interval, isolation/egress references와 activation-policy version을 독립 grant에 결합한다. Unknown extension에는 implicit grant가 없다. Activation은 issued policy version을 인용해야 하며 invocation은 policy를 다시 resolve해 revocation/drift를 fail closed한다. Current exact `669a45a...`는 hostile/edge tests와 ADR 0015 `Proposed` decision을 보존한 채 protected #556 source를 ordinary/non-force로 승계한다. +Production `c6e91dbe8b452e067d30890aae993b04b7cd814c`는 source/catalog/scanner authority와 Noema Policy / Approval issuance를 분리했다. Public Tool / Capability adapter는 maximum approval status, allowed product repositories, allowed execution roles, validity interval, isolation/egress references와 activation-policy version을 독립 grant에 결합한다. Unknown extension에는 implicit grant가 없다. Activation은 issued policy version을 인용해야 하며 invocation은 policy를 다시 resolve해 revocation/drift를 fail closed한다. Current exact `68f2843...`는 hostile/edge tests와 ADR 0015 `Proposed` decision을 보존한 채 protected #556 source와 CHANGELOG semantic union을 ordinary/non-force로 승계한다. AppGuardrail/quarantine receipts는 scanner/provenance evidence이지 Noema approval이 아니다. EgressWeave/quarantine references는 outbound/isolation operation의 대체물이 아니다. Anthropic marketplace review는 discovery evidence이지 CWL product authority가 아니다. `context-graph-contracts`가 immutable shared external-capability contract를 release하기 전까지 이 local port는 fail-closed ACL/test double이며 live plugin installation 또는 buyer completion을 주장하지 않는다. From 2b7aee24fc119ab06c8abe7a6224a1f78815b423 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 18:51:51 +0900 Subject: [PATCH 37/68] test: bind documentation authority to restacked #560 --- test/documentation-live-open-pr-authority.test.ts | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index 773715de0..608c9c64b 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -6,12 +6,14 @@ describe("product-technical gap baseline live open-PR authority", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); expect(baseline).toContain("Resulting protected merge는 GitHub-verified `36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`"); - expect(baseline).toContain("Observed PR #560 exact `935b99e1704b5a9966057a886dc60640d6bda5e2`"); - expect(baseline).toContain("application CI `34209618966`"); + expect(baseline).toContain("Observed PR #560 exact `68f28439edfd92394723ebc1248a6b2e9a957d44`"); + expect(baseline).toContain("application CI `34212097312`"); expect(baseline).toContain("Policy / Approval issuance"); expect(baseline).toContain("Production `c6e91dbe8b452e067d30890aae993b04b7cd814c`"); - expect(baseline).toContain("ordinary/non-force restack"); + expect(baseline).toContain("ordinary/non-force semantic restack"); + expect(baseline).toContain("CHANGELOG semantic union"); expect(baseline).not.toContain("Observed PR #556 exact"); - expect(baseline).not.toContain("Observed PR #560 test-only exact `7ca9aebee6f92053913c0bbc665c8de77650891f`"); + expect(baseline).not.toContain("Observed PR #560 exact `935b99e1704b5a9966057a886dc60640d6bda5e2`"); + expect(baseline).not.toContain("application CI `34209618966`"); }); }); From f68a06985c9a0d4195d7825bae3efcf312bc59f7 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 19:03:16 +0900 Subject: [PATCH 38/68] test(d(docs): require complete gap authority schema --- test/documentation-architecture-contract.test.ts | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/test/documentation-architecture-contract.test.ts b/test/documentation-architecture-contract.test.ts index 9baf45415..51f4692f3 100644 --- a/test/documentation-architecture-contract.test.ts +++ b/test/documentation-architecture-contract.test.ts @@ -79,8 +79,17 @@ describe("authoritative Noema documentation graph", () => { expect(productGap).toContain(owner); } expect(productGap).toContain( - "| Priority | Gap | Buyer/operator impact | Current owner | Authoritative completion evidence | Next executable action |", + "| Priority | Gap | Buyer/operator impact | Current owner | Status | Authoritative completion evidence | Next executable action |", ); + for (const authorityDocument of [ + "docs/PRD.md", + "docs/TRD.md", + "docs/UML.md", + "docs/ERD.md", + "docs/CONTEXT_MAP.md", + ]) { + expect(productGap).toContain(`\`${authorityDocument}\``); + } expect(productGap).toContain("issues #29 / #227"); for (const staleOwner of ["PR #407", "PR #67", "Active PR #426"]) { expect(gapAudit).not.toContain(staleOwner); From dee8e8df7d4668e2d11254f5970f3b08dd2f7b47 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 19:03:18 +0900 Subject: [PATCH 39/68] docs: bind gap status to architecture authorities --- docs/product-technical-gap-baseline.md | 24 +++++++++++++----------- 1 file changed, 13 insertions(+), 11 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index cbdbb4ccb..2c738fc96 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -18,6 +18,8 @@ Noema Core Domain은 Agent Runtime과 Workflow / Task Execution이다. Tool / Ca `contextual-orchestrator`는 provider/model discovery, routing, retry/failover, test-time compute와 provider credential을 소유한다. Noema는 released gateway contract와 canonical `orchestrator/free` alias를 소비하며 direct provider SDK, provider key, provider/model/group fallback policy를 소유하지 않는다. `.github`는 organization reusable workflow/control-plane source다. Keyverse는 identity backend다. `quarantine-sandbox-runtime`, Wardnet, EgressWeave, AppGuardrail은 각자의 isolation/security/outbound/scanning truth를 소유한다. Noema는 그 owner evidence를 reference/pin으로 소비할 뿐 foreign implementation이나 domain table을 복제하지 않는다. Cross-service SQL과 mutable sibling PR dependency는 금지한다. +Baseline의 요구·설계·데이터·경계 authority는 `docs/PRD.md`, `docs/TRD.md`, `docs/UML.md`, `docs/ERD.md`, `docs/CONTEXT_MAP.md`다. 이 register는 그 문서와 ADR을 대체하지 않고 current Gap/Action/Status를 exact source·PR·workflow evidence에 결합한다. PR #560의 ADR 0015는 candidate-only `Proposed`이며 protected ADR authority로 승격하지 않는다. + ## Integrated exact-claim evidence — issue #555 / merged PR #556 PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`는 unchanged exact-head application CI `34197596549`, reviewer-ci `34197596588`, required Security Scan `34197596536`, patch-validator-image `34197596517` terminal SUCCESS와 clean review authority를 충족한 뒤 normal merge됐다. Resulting protected merge는 GitHub-verified `36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`이다. @@ -44,17 +46,17 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge ## Commercial gap register -| Priority | Gap | Buyer/operator impact | Current owner | Authoritative completion evidence | Next executable action | -| --- | --- | --- | --- | --- | --- | -| P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority가 될 위험 | protected #556 + release/consumer lanes | protected source + execution/research producer + immutable Noema release + released central consumer corpus RED→GREEN | release/producer evidence를 별도 lane에서 완성 | -| P0 | External extension capability admission | third-party plugin metadata 또는 self-asserted product grant가 runtime authority가 될 위험 | issue #545 / PR #560 | immutable source + independent scan + Noema-issued Policy / Approval grant + live revalidation + fresh four-GREEN + normal merge + immutable shared contract/live pilot evidence | restacked exact head의 semantic union과 fresh gates를 재검증 | -| P0 | Protected-main governance closure | required Security workflow만으로 PR/review/history/deletion/bypass 통제를 증명했다고 오인할 위험 | issue #27 | fresh live ruleset + required PR/review/conversation/history/deletion controls + independent bypass/break-glass evidence + protected-source governance receipt | source가 만들 수 없는 organization/admin control은 issue #27에서 독립 검증 | -| P0 | Strict orchestrator/free consumer release | source 통합만으로 immutable consumer activation을 증명할 수 없음 | merged #535 + release lane | version/tag/package/SBOM/provenance/reproducibility/rollback + released consumer | release-ready protected head에서만 publication | -| P0 | Patch-validator operational publication | source/image CI success만으로 reusable immutable runtime을 증명할 수 없음 | issue #66 | protected execution + immutable image/signature/SBOM/provenance/reproducibility/rollback | immutable publication evidence와 결합 | -| P0 | Authentic production KPI evidence | fixture·synthetic 또는 source-level KPI 검증이 실제 운영 성능을 대체할 위험 | issue #3 | authenticated production-window records + strict provenance + buyer-relevant KPI gate | 실제 production evidence 없이는 readiness를 승격하지 않음 | -| P0 | Acquisition coordination | source/docs 완료를 buyer·legal·transfer readiness로 잘못 승격할 위험 | issue #5 | exact protected revision + applicable release/deployment/operational/buyer/legal evidence family | 남은 evidence family를 owner별로 수렴하고 source claim과 분리 | -| P0 | External Maintainer/Reviewer App identity | source capability-file 계약이 실제 App 설치·키 custody·rotation·권한·reviewer identity를 대체할 위험 | issues #29 / #227 | live installation + key custody/rotation + repository permission + eligible reviewer/publication identity evidence | 외부 App authority는 해당 issue owner에서 독립 검증 | -| P0 | Durable workflow/state production evidence | source Durable Object logic이 실제 deployed transaction/recovery를 증명하지 않음 | merged #542 / ADR 0013 | deployment compatibility + recovery/rollback receipt + immutable release | deployed runtime evidence 확보 전 ADR 0013 `Proposed` 유지 | +| Priority | Gap | Buyer/operator impact | Current owner | Status | Authoritative completion evidence | Next executable action | +| --- | --- | --- | --- | --- | --- | --- | +| P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority가 될 위험 | protected #556 + release/consumer lanes | Source integrated; producer/release/consumer open | protected source + execution/research producer + immutable Noema release + released central consumer corpus RED→GREEN | release/producer evidence를 별도 lane에서 완성 | +| P0 | External extension capability admission | third-party plugin metadata 또는 self-asserted product grant가 runtime authority가 될 위험 | issue #545 / PR #560 | Draft; ADR 0015 Proposed | immutable source + independent scan + Noema-issued Policy / Approval grant + live revalidation + fresh four-GREEN + normal merge + immutable shared contract/live pilot evidence | restacked exact head의 semantic union과 fresh gates를 재검증 | +| P0 | Protected-main governance closure | required Security workflow만으로 PR/review/history/deletion/bypass 통제를 증명했다고 오인할 위험 | issue #27 | Open; external control evidence absent | fresh live ruleset + required PR/review/conversation/history/deletion controls + independent bypass/break-glass evidence + protected-source governance receipt | source가 만들 수 없는 organization/admin control은 issue #27에서 독립 검증 | +| P0 | Strict orchestrator/free consumer release | source 통합만으로 immutable consumer activation을 증명할 수 없음 | merged #535 + release lane | Source integrated; release/consumer open | version/tag/package/SBOM/provenance/reproducibility/rollback + released consumer | release-ready protected head에서만 publication | +| P0 | Patch-validator operational publication | source/image CI success만으로 reusable immutable runtime을 증명할 수 없음 | issue #66 | Open; publication evidence absent | protected execution + immutable image/signature/SBOM/provenance/reproducibility/rollback | immutable publication evidence와 결합 | +| P0 | Authentic production KPI evidence | fixture·synthetic 또는 source-level KPI 검증이 실제 운영 성능을 대체할 위험 | issue #3 | Open; production window absent | authenticated production-window records + strict provenance + buyer-relevant KPI gate | 실제 production evidence 없이는 readiness를 승격하지 않음 | +| P0 | Acquisition coordination | source/docs 완료를 buyer·legal·transfer readiness로 잘못 승격할 위험 | issue #5 | Open; evidence families incomplete | exact protected revision + applicable release/deployment/operational/buyer/legal evidence family | 남은 evidence family를 owner별로 수렴하고 source claim과 분리 | +| P0 | External Maintainer/Reviewer App identity | source capability-file 계약이 실제 App 설치·키 custody·rotation·권한·reviewer identity를 대체할 위험 | issues #29 / #227 | Open; live identity evidence absent | live installation + key custody/rotation + repository permission + eligible reviewer/publication identity evidence | 외부 App authority는 해당 issue owner에서 독립 검증 | +| P0 | Durable workflow/state production evidence | source Durable Object logic이 실제 deployed transaction/recovery를 증명하지 않음 | merged #542 / ADR 0013 | Source integrated; ADR 0013 Proposed | deployment compatibility + recovery/rollback receipt + immutable release | deployed runtime evidence 확보 전 ADR 0013 `Proposed` 유지 | ## Release boundary From 418c7d11c8345cbbf7dc5afdd32f4e8601548332 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 19:08:00 +0900 Subject: [PATCH 40/68] test(docs): reject stale tool-capability candidate --- test/documentation-live-open-pr-authority.test.ts | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index 608c9c64b..5f0dcf9a1 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -6,13 +6,14 @@ describe("product-technical gap baseline live open-PR authority", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); expect(baseline).toContain("Resulting protected merge는 GitHub-verified `36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`"); - expect(baseline).toContain("Observed PR #560 exact `68f28439edfd92394723ebc1248a6b2e9a957d44`"); - expect(baseline).toContain("application CI `34212097312`"); + expect(baseline).toContain("Observed PR #560 exact `83a54b699e9b5678b6f41125f57cb36fc5ce9597`"); + expect(baseline).toContain("application CI `34213481992`"); expect(baseline).toContain("Policy / Approval issuance"); expect(baseline).toContain("Production `c6e91dbe8b452e067d30890aae993b04b7cd814c`"); expect(baseline).toContain("ordinary/non-force semantic restack"); expect(baseline).toContain("CHANGELOG semantic union"); expect(baseline).not.toContain("Observed PR #556 exact"); + expect(baseline).not.toContain("Observed PR #560 exact `68f28439edfd92394723ebc1248a6b2e9a957d44`"); expect(baseline).not.toContain("Observed PR #560 exact `935b99e1704b5a9966057a886dc60640d6bda5e2`"); expect(baseline).not.toContain("application CI `34209618966`"); }); From 6f7a0ce04cda753dd9cac530200f701f925141d6 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 19:08:01 +0900 Subject: [PATCH 41/68] docs: refresh current tool-capability evidence --- docs/product-technical-gap-baseline.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 2c738fc96..1c0626876 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -28,11 +28,11 @@ Protected source는 raw source receipt를 context authority로만 취급하고, ## Active external-extension candidate — issue #545 / PR #560 -Observed PR #560 exact `68f28439edfd92394723ebc1248a6b2e9a957d44`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. #556 merge 뒤 current writer는 feature head와 protected main을 두 parent로 갖는 ordinary/non-force semantic restack을 수행했고, `.github`와 `reviewer` protected owner source를 그대로 승계했다. Restack 때 겹친 `CHANGELOG.md`에서는 protected #556 entry와 #560 Tool / Capability entry의 semantic union을 복구했으며, predecessor `669a45a...` 대비 해당 repair는 exactly one addition / zero deletion이다. Current generation은 application CI `34212097312`, reviewer-ci `34212097422`, required Security Scan `34212097303`, patch-validator-image `34212097392`이며 모두 queued다. predecessor 결과는 이 exact head의 merge authority가 아니다. +Observed PR #560 exact `83a54b699e9b5678b6f41125f57cb36fc5ce9597`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. #556 merge 뒤 current writer는 feature head와 protected main을 두 parent로 갖는 ordinary/non-force semantic restack을 수행했고, `.github`와 `reviewer` protected owner source를 그대로 승계했다. Restack 때 겹친 `CHANGELOG.md`에서는 protected #556 entry와 #560 Tool / Capability entry의 semantic union을 복구했으며, predecessor `669a45a...` 대비 `68f2843...` repair는 exactly one addition / zero deletion이다. Current generation은 application CI `34213481992`, reviewer-ci `34213481836`, required Security Scan `34213481938`, patch-validator-image `34213481766`이며 모두 queued다. predecessor 결과는 이 exact head의 merge authority가 아니다. Earlier test-only exact `7ca9aebee6f92053913c0bbc665c8de77650891f`의 hosted application CI `34206149899`, job `101995980303`은 exact checkout, live-base guard, lockfile control, install, typecheck를 통과한 뒤 release tests에서 실패했다. 이 RED는 valid catalog/AppGuardrail/quarantine evidence가 있어도 descriptor가 `approval_status`, product repository, execution role을 self-broaden하면 별도 Noema Policy / Approval issuance 없이는 admission이 거부돼야 한다는 결함을 증명했다. -Production `c6e91dbe8b452e067d30890aae993b04b7cd814c`는 source/catalog/scanner authority와 Noema Policy / Approval issuance를 분리했다. Public Tool / Capability adapter는 maximum approval status, allowed product repositories, allowed execution roles, validity interval, isolation/egress references와 activation-policy version을 독립 grant에 결합한다. Unknown extension에는 implicit grant가 없다. Activation은 issued policy version을 인용해야 하며 invocation은 policy를 다시 resolve해 revocation/drift를 fail closed한다. Current exact `68f2843...`는 hostile/edge tests와 ADR 0015 `Proposed` decision을 보존한 채 protected #556 source와 CHANGELOG semantic union을 ordinary/non-force로 승계한다. +Production `c6e91dbe8b452e067d30890aae993b04b7cd814c`는 source/catalog/scanner authority와 Noema Policy / Approval issuance를 분리했다. Public Tool / Capability adapter는 maximum approval status, allowed product repositories, allowed execution roles, validity interval, isolation/egress references와 activation-policy version을 독립 grant에 결합한다. Unknown extension에는 implicit grant가 없다. Activation은 issued policy version을 인용해야 하며 invocation은 policy를 다시 resolve해 revocation/drift를 fail closed한다. RED `2096510...`은 hostile public activation/invocation envelope의 property read가 domain error 밖으로 새는 경계를 고정했고 current exact `83a54b6...`는 이를 canonical fail-closed rejection으로 normalize한다. 이 exact는 ADR 0015 `Proposed`와 protected #556 source 및 CHANGELOG semantic union을 보존한다. AppGuardrail/quarantine receipts는 scanner/provenance evidence이지 Noema approval이 아니다. EgressWeave/quarantine references는 outbound/isolation operation의 대체물이 아니다. Anthropic marketplace review는 discovery evidence이지 CWL product authority가 아니다. `context-graph-contracts`가 immutable shared external-capability contract를 release하기 전까지 이 local port는 fail-closed ACL/test double이며 live plugin installation 또는 buyer completion을 주장하지 않는다. From e9f9cb32334c055b3149eee69a8f83a4e3de3855 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 19:32:04 +0900 Subject: [PATCH 42/68] docs: refresh active extension authority --- docs/product-technical-gap-baseline.md | 4 ++-- test/documentation-live-open-pr-authority.test.ts | 5 +++-- 2 files changed, 5 insertions(+), 4 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 1c0626876..eb7bf26ac 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -28,11 +28,11 @@ Protected source는 raw source receipt를 context authority로만 취급하고, ## Active external-extension candidate — issue #545 / PR #560 -Observed PR #560 exact `83a54b699e9b5678b6f41125f57cb36fc5ce9597`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. #556 merge 뒤 current writer는 feature head와 protected main을 두 parent로 갖는 ordinary/non-force semantic restack을 수행했고, `.github`와 `reviewer` protected owner source를 그대로 승계했다. Restack 때 겹친 `CHANGELOG.md`에서는 protected #556 entry와 #560 Tool / Capability entry의 semantic union을 복구했으며, predecessor `669a45a...` 대비 `68f2843...` repair는 exactly one addition / zero deletion이다. Current generation은 application CI `34213481992`, reviewer-ci `34213481836`, required Security Scan `34213481938`, patch-validator-image `34213481766`이며 모두 queued다. predecessor 결과는 이 exact head의 merge authority가 아니다. +Observed PR #560 exact `cdcc06365d907dd623aa3535d432061c50bdf3c6`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. #556 merge 뒤 current writer는 feature head와 protected main을 두 parent로 갖는 ordinary/non-force semantic restack을 수행했고, `.github`와 `reviewer` protected owner source를 그대로 승계했다. Restack 때 겹친 `CHANGELOG.md`에서는 protected #556 entry와 #560 Tool / Capability entry의 semantic union을 복구했으며, predecessor `669a45a...` 대비 `68f2843...` repair는 exactly one addition / zero deletion이다. Current generation은 application CI `34215229734`, reviewer-ci `34215229769`, required Security Scan `34215229728`, patch-validator-image `34215229773`이며 모두 non-terminal이다. predecessor 결과는 이 exact head의 merge authority가 아니다. Earlier test-only exact `7ca9aebee6f92053913c0bbc665c8de77650891f`의 hosted application CI `34206149899`, job `101995980303`은 exact checkout, live-base guard, lockfile control, install, typecheck를 통과한 뒤 release tests에서 실패했다. 이 RED는 valid catalog/AppGuardrail/quarantine evidence가 있어도 descriptor가 `approval_status`, product repository, execution role을 self-broaden하면 별도 Noema Policy / Approval issuance 없이는 admission이 거부돼야 한다는 결함을 증명했다. -Production `c6e91dbe8b452e067d30890aae993b04b7cd814c`는 source/catalog/scanner authority와 Noema Policy / Approval issuance를 분리했다. Public Tool / Capability adapter는 maximum approval status, allowed product repositories, allowed execution roles, validity interval, isolation/egress references와 activation-policy version을 독립 grant에 결합한다. Unknown extension에는 implicit grant가 없다. Activation은 issued policy version을 인용해야 하며 invocation은 policy를 다시 resolve해 revocation/drift를 fail closed한다. RED `2096510...`은 hostile public activation/invocation envelope의 property read가 domain error 밖으로 새는 경계를 고정했고 current exact `83a54b6...`는 이를 canonical fail-closed rejection으로 normalize한다. 이 exact는 ADR 0015 `Proposed`와 protected #556 source 및 CHANGELOG semantic union을 보존한다. +Production `c6e91dbe8b452e067d30890aae993b04b7cd814c`는 source/catalog/scanner authority와 Noema Policy / Approval issuance를 분리했다. Public Tool / Capability adapter는 maximum approval status, allowed product repositories, allowed execution roles, validity interval, isolation/egress references와 activation-policy version을 독립 grant에 결합한다. Unknown extension에는 implicit grant가 없다. Activation은 issued policy version을 인용해야 하며 invocation은 policy를 다시 resolve해 revocation/drift를 fail closed한다. RED `2096510...`은 hostile public activation/invocation envelope의 property read가 domain error 밖으로 새는 경계를 고정했고 `83a54b6...`는 이를 canonical fail-closed rejection으로 normalize한다. Subsequent RED `0dd7956...`는 source-issued pilot grant가 active authority로 오용되는 경계를 고정했다. Production `2f7ff5a...`는 default ceiling을 `approved_for_pilot`로 낮췄고, current exact `cdcc063...`는 active-path fixtures에 명시적인 `TrustedExtensionPolicyApproval`을 공급하면서 그 production 경계를 유지한다. 이 exact는 ADR 0015 `Proposed`와 protected #556 source 및 CHANGELOG semantic union을 보존한다. AppGuardrail/quarantine receipts는 scanner/provenance evidence이지 Noema approval이 아니다. EgressWeave/quarantine references는 outbound/isolation operation의 대체물이 아니다. Anthropic marketplace review는 discovery evidence이지 CWL product authority가 아니다. `context-graph-contracts`가 immutable shared external-capability contract를 release하기 전까지 이 local port는 fail-closed ACL/test double이며 live plugin installation 또는 buyer completion을 주장하지 않는다. diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index 5f0dcf9a1..6085ba1aa 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -6,8 +6,8 @@ describe("product-technical gap baseline live open-PR authority", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); expect(baseline).toContain("Resulting protected merge는 GitHub-verified `36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`"); - expect(baseline).toContain("Observed PR #560 exact `83a54b699e9b5678b6f41125f57cb36fc5ce9597`"); - expect(baseline).toContain("application CI `34213481992`"); + expect(baseline).toContain("Observed PR #560 exact `cdcc06365d907dd623aa3535d432061c50bdf3c6`"); + expect(baseline).toContain("application CI `34215229734`"); expect(baseline).toContain("Policy / Approval issuance"); expect(baseline).toContain("Production `c6e91dbe8b452e067d30890aae993b04b7cd814c`"); expect(baseline).toContain("ordinary/non-force semantic restack"); @@ -15,6 +15,7 @@ describe("product-technical gap baseline live open-PR authority", () => { expect(baseline).not.toContain("Observed PR #556 exact"); expect(baseline).not.toContain("Observed PR #560 exact `68f28439edfd92394723ebc1248a6b2e9a957d44`"); expect(baseline).not.toContain("Observed PR #560 exact `935b99e1704b5a9966057a886dc60640d6bda5e2`"); + expect(baseline).not.toContain("Observed PR #560 exact `83a54b699e9b5678b6f41125f57cb36fc5ce9597`"); expect(baseline).not.toContain("application CI `34209618966`"); }); }); From 173b411a633311874d3dca3e5d7e1dd1a3ce2bc5 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 19:43:00 +0900 Subject: [PATCH 43/68] docs: bind extension event chronology evidence --- docs/product-technical-gap-baseline.md | 4 ++-- test/documentation-live-open-pr-authority.test.ts | 5 +++-- 2 files changed, 5 insertions(+), 4 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index eb7bf26ac..cf8dad29d 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -28,11 +28,11 @@ Protected source는 raw source receipt를 context authority로만 취급하고, ## Active external-extension candidate — issue #545 / PR #560 -Observed PR #560 exact `cdcc06365d907dd623aa3535d432061c50bdf3c6`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. #556 merge 뒤 current writer는 feature head와 protected main을 두 parent로 갖는 ordinary/non-force semantic restack을 수행했고, `.github`와 `reviewer` protected owner source를 그대로 승계했다. Restack 때 겹친 `CHANGELOG.md`에서는 protected #556 entry와 #560 Tool / Capability entry의 semantic union을 복구했으며, predecessor `669a45a...` 대비 `68f2843...` repair는 exactly one addition / zero deletion이다. Current generation은 application CI `34215229734`, reviewer-ci `34215229769`, required Security Scan `34215229728`, patch-validator-image `34215229773`이며 모두 non-terminal이다. predecessor 결과는 이 exact head의 merge authority가 아니다. +Observed PR #560 exact `37dd2c0d197b780661f1ce5b43b243711791b3c5`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. #556 merge 뒤 current writer는 feature head와 protected main을 두 parent로 갖는 ordinary/non-force semantic restack을 수행했고, `.github`와 `reviewer` protected owner source를 그대로 승계했다. Restack 때 겹친 `CHANGELOG.md`에서는 protected #556 entry와 #560 Tool / Capability entry의 semantic union을 복구했으며, predecessor `669a45a...` 대비 `68f2843...` repair는 exactly one addition / zero deletion이다. Current generation은 application CI `34216555624`, reviewer-ci `34216555679`, required Security Scan `34216555618`, patch-validator-image `34216555664`이며 모두 queued다. predecessor 결과는 이 exact head의 merge authority가 아니다. Earlier test-only exact `7ca9aebee6f92053913c0bbc665c8de77650891f`의 hosted application CI `34206149899`, job `101995980303`은 exact checkout, live-base guard, lockfile control, install, typecheck를 통과한 뒤 release tests에서 실패했다. 이 RED는 valid catalog/AppGuardrail/quarantine evidence가 있어도 descriptor가 `approval_status`, product repository, execution role을 self-broaden하면 별도 Noema Policy / Approval issuance 없이는 admission이 거부돼야 한다는 결함을 증명했다. -Production `c6e91dbe8b452e067d30890aae993b04b7cd814c`는 source/catalog/scanner authority와 Noema Policy / Approval issuance를 분리했다. Public Tool / Capability adapter는 maximum approval status, allowed product repositories, allowed execution roles, validity interval, isolation/egress references와 activation-policy version을 독립 grant에 결합한다. Unknown extension에는 implicit grant가 없다. Activation은 issued policy version을 인용해야 하며 invocation은 policy를 다시 resolve해 revocation/drift를 fail closed한다. RED `2096510...`은 hostile public activation/invocation envelope의 property read가 domain error 밖으로 새는 경계를 고정했고 `83a54b6...`는 이를 canonical fail-closed rejection으로 normalize한다. Subsequent RED `0dd7956...`는 source-issued pilot grant가 active authority로 오용되는 경계를 고정했다. Production `2f7ff5a...`는 default ceiling을 `approved_for_pilot`로 낮췄고, current exact `cdcc063...`는 active-path fixtures에 명시적인 `TrustedExtensionPolicyApproval`을 공급하면서 그 production 경계를 유지한다. 이 exact는 ADR 0015 `Proposed`와 protected #556 source 및 CHANGELOG semantic union을 보존한다. +Production `c6e91dbe8b452e067d30890aae993b04b7cd814c`는 source/catalog/scanner authority와 Noema Policy / Approval issuance를 분리했다. Public Tool / Capability adapter는 maximum approval status, allowed product repositories, allowed execution roles, validity interval, isolation/egress references와 activation-policy version을 독립 grant에 결합한다. Unknown extension에는 implicit grant가 없다. Activation은 issued policy version을 인용해야 하며 invocation은 policy를 다시 resolve해 revocation/drift를 fail closed한다. RED `2096510...`은 hostile public activation/invocation envelope의 property read가 domain error 밖으로 새는 경계를 고정했고 `83a54b6...`는 이를 canonical fail-closed rejection으로 normalize한다. Subsequent RED `0dd7956...`는 source-issued pilot grant가 active authority로 오용되는 경계를 고정했다. Production `2f7ff5a...`는 default ceiling을 `approved_for_pilot`로 낮췄고, `cdcc063...`는 active-path fixtures에 명시적인 `TrustedExtensionPolicyApproval`을 공급하면서 그 production 경계를 유지한다. Causal RED `9711e3f...`는 invocation이 issued activation보다 이를 수 있던 event-order 결함을 고정했고 current exact `37dd2c0...`는 descriptor-window error precedence를 유지한 채 그 불가능한 순서를 거부한다. 이 exact는 ADR 0015 `Proposed`와 protected #556 source 및 CHANGELOG semantic union을 보존한다. AppGuardrail/quarantine receipts는 scanner/provenance evidence이지 Noema approval이 아니다. EgressWeave/quarantine references는 outbound/isolation operation의 대체물이 아니다. Anthropic marketplace review는 discovery evidence이지 CWL product authority가 아니다. `context-graph-contracts`가 immutable shared external-capability contract를 release하기 전까지 이 local port는 fail-closed ACL/test double이며 live plugin installation 또는 buyer completion을 주장하지 않는다. diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index 6085ba1aa..5737fa0e2 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -6,8 +6,8 @@ describe("product-technical gap baseline live open-PR authority", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); expect(baseline).toContain("Resulting protected merge는 GitHub-verified `36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`"); - expect(baseline).toContain("Observed PR #560 exact `cdcc06365d907dd623aa3535d432061c50bdf3c6`"); - expect(baseline).toContain("application CI `34215229734`"); + expect(baseline).toContain("Observed PR #560 exact `37dd2c0d197b780661f1ce5b43b243711791b3c5`"); + expect(baseline).toContain("application CI `34216555624`"); expect(baseline).toContain("Policy / Approval issuance"); expect(baseline).toContain("Production `c6e91dbe8b452e067d30890aae993b04b7cd814c`"); expect(baseline).toContain("ordinary/non-force semantic restack"); @@ -16,6 +16,7 @@ describe("product-technical gap baseline live open-PR authority", () => { expect(baseline).not.toContain("Observed PR #560 exact `68f28439edfd92394723ebc1248a6b2e9a957d44`"); expect(baseline).not.toContain("Observed PR #560 exact `935b99e1704b5a9966057a886dc60640d6bda5e2`"); expect(baseline).not.toContain("Observed PR #560 exact `83a54b699e9b5678b6f41125f57cb36fc5ce9597`"); + expect(baseline).not.toContain("Observed PR #560 exact `cdcc06365d907dd623aa3535d432061c50bdf3c6`"); expect(baseline).not.toContain("application CI `34209618966`"); }); }); From 1386077a2836efc57c8745ca86cca38be3c63c0e Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 19:48:09 +0900 Subject: [PATCH 44/68] docs: refresh extension chronology authority --- docs/product-technical-gap-baseline.md | 4 ++-- test/documentation-live-open-pr-authority.test.ts | 5 +++-- 2 files changed, 5 insertions(+), 4 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index cf8dad29d..75980775a 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -28,11 +28,11 @@ Protected source는 raw source receipt를 context authority로만 취급하고, ## Active external-extension candidate — issue #545 / PR #560 -Observed PR #560 exact `37dd2c0d197b780661f1ce5b43b243711791b3c5`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. #556 merge 뒤 current writer는 feature head와 protected main을 두 parent로 갖는 ordinary/non-force semantic restack을 수행했고, `.github`와 `reviewer` protected owner source를 그대로 승계했다. Restack 때 겹친 `CHANGELOG.md`에서는 protected #556 entry와 #560 Tool / Capability entry의 semantic union을 복구했으며, predecessor `669a45a...` 대비 `68f2843...` repair는 exactly one addition / zero deletion이다. Current generation은 application CI `34216555624`, reviewer-ci `34216555679`, required Security Scan `34216555618`, patch-validator-image `34216555664`이며 모두 queued다. predecessor 결과는 이 exact head의 merge authority가 아니다. +Observed PR #560 exact `281a9dbd5080fb3c0c52ac079a8f3957c3f8e443`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. #556 merge 뒤 current writer는 feature head와 protected main을 두 parent로 갖는 ordinary/non-force semantic restack을 수행했고, `.github`와 `reviewer` protected owner source를 그대로 승계했다. Restack 때 겹친 `CHANGELOG.md`에서는 protected #556 entry와 #560 Tool / Capability entry의 semantic union을 복구했으며, predecessor `669a45a...` 대비 `68f2843...` repair는 exactly one addition / zero deletion이다. Current generation은 application CI `34217233912`, reviewer-ci `34217233938`, required Security Scan `34217233921`, patch-validator-image `34217233913`이며 모두 queued/pending이다. predecessor 결과는 이 exact head의 merge authority가 아니다. Earlier test-only exact `7ca9aebee6f92053913c0bbc665c8de77650891f`의 hosted application CI `34206149899`, job `101995980303`은 exact checkout, live-base guard, lockfile control, install, typecheck를 통과한 뒤 release tests에서 실패했다. 이 RED는 valid catalog/AppGuardrail/quarantine evidence가 있어도 descriptor가 `approval_status`, product repository, execution role을 self-broaden하면 별도 Noema Policy / Approval issuance 없이는 admission이 거부돼야 한다는 결함을 증명했다. -Production `c6e91dbe8b452e067d30890aae993b04b7cd814c`는 source/catalog/scanner authority와 Noema Policy / Approval issuance를 분리했다. Public Tool / Capability adapter는 maximum approval status, allowed product repositories, allowed execution roles, validity interval, isolation/egress references와 activation-policy version을 독립 grant에 결합한다. Unknown extension에는 implicit grant가 없다. Activation은 issued policy version을 인용해야 하며 invocation은 policy를 다시 resolve해 revocation/drift를 fail closed한다. RED `2096510...`은 hostile public activation/invocation envelope의 property read가 domain error 밖으로 새는 경계를 고정했고 `83a54b6...`는 이를 canonical fail-closed rejection으로 normalize한다. Subsequent RED `0dd7956...`는 source-issued pilot grant가 active authority로 오용되는 경계를 고정했다. Production `2f7ff5a...`는 default ceiling을 `approved_for_pilot`로 낮췄고, `cdcc063...`는 active-path fixtures에 명시적인 `TrustedExtensionPolicyApproval`을 공급하면서 그 production 경계를 유지한다. Causal RED `9711e3f...`는 invocation이 issued activation보다 이를 수 있던 event-order 결함을 고정했고 current exact `37dd2c0...`는 descriptor-window error precedence를 유지한 채 그 불가능한 순서를 거부한다. 이 exact는 ADR 0015 `Proposed`와 protected #556 source 및 CHANGELOG semantic union을 보존한다. +Production `c6e91dbe8b452e067d30890aae993b04b7cd814c`는 source/catalog/scanner authority와 Noema Policy / Approval issuance를 분리했다. Public Tool / Capability adapter는 maximum approval status, allowed product repositories, allowed execution roles, validity interval, isolation/egress references와 activation-policy version을 독립 grant에 결합한다. Unknown extension에는 implicit grant가 없다. Activation은 issued policy version을 인용해야 하며 invocation은 policy를 다시 resolve해 revocation/drift를 fail closed한다. RED `2096510...`은 hostile public activation/invocation envelope의 property read가 domain error 밖으로 새는 경계를 고정했고 `83a54b6...`는 이를 canonical fail-closed rejection으로 normalize한다. Subsequent RED `0dd7956...`는 source-issued pilot grant가 active authority로 오용되는 경계를 고정했다. Production `2f7ff5a...`는 default ceiling을 `approved_for_pilot`로 낮췄고, `cdcc063...`는 active-path fixtures에 명시적인 `TrustedExtensionPolicyApproval`을 공급하면서 그 production 경계를 유지한다. Causal RED `9711e3f...`는 invocation이 issued activation보다 이를 수 있던 event-order 결함을 고정했고 `37dd2c0...`는 descriptor-window error precedence를 유지한 채 그 불가능한 순서를 거부하고 current exact `281a9dbd...`는 동일 invariant를 ADR 0015, CHANGELOG, Test Strategy와 Traceability에 기록한다. 이 exact는 ADR 0015 `Proposed`와 protected #556 source 및 CHANGELOG semantic union을 보존한다. AppGuardrail/quarantine receipts는 scanner/provenance evidence이지 Noema approval이 아니다. EgressWeave/quarantine references는 outbound/isolation operation의 대체물이 아니다. Anthropic marketplace review는 discovery evidence이지 CWL product authority가 아니다. `context-graph-contracts`가 immutable shared external-capability contract를 release하기 전까지 이 local port는 fail-closed ACL/test double이며 live plugin installation 또는 buyer completion을 주장하지 않는다. diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index 5737fa0e2..e758c09e3 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -6,8 +6,8 @@ describe("product-technical gap baseline live open-PR authority", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); expect(baseline).toContain("Resulting protected merge는 GitHub-verified `36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`"); - expect(baseline).toContain("Observed PR #560 exact `37dd2c0d197b780661f1ce5b43b243711791b3c5`"); - expect(baseline).toContain("application CI `34216555624`"); + expect(baseline).toContain("Observed PR #560 exact `281a9dbd5080fb3c0c52ac079a8f3957c3f8e443`"); + expect(baseline).toContain("application CI `34217233912`"); expect(baseline).toContain("Policy / Approval issuance"); expect(baseline).toContain("Production `c6e91dbe8b452e067d30890aae993b04b7cd814c`"); expect(baseline).toContain("ordinary/non-force semantic restack"); @@ -17,6 +17,7 @@ describe("product-technical gap baseline live open-PR authority", () => { expect(baseline).not.toContain("Observed PR #560 exact `935b99e1704b5a9966057a886dc60640d6bda5e2`"); expect(baseline).not.toContain("Observed PR #560 exact `83a54b699e9b5678b6f41125f57cb36fc5ce9597`"); expect(baseline).not.toContain("Observed PR #560 exact `cdcc06365d907dd623aa3535d432061c50bdf3c6`"); + expect(baseline).not.toContain("Observed PR #560 exact `37dd2c0d197b780661f1ce5b43b243711791b3c5`"); expect(baseline).not.toContain("application CI `34209618966`"); }); }); From 8875421990e3e2f33a6193c19d68e4e26a72b06e Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 20:13:44 +0900 Subject: [PATCH 45/68] docs: bind gap baseline to hostile admission repair --- docs/product-technical-gap-baseline.md | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 75980775a..73eae8695 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -28,13 +28,17 @@ Protected source는 raw source receipt를 context authority로만 취급하고, ## Active external-extension candidate — issue #545 / PR #560 -Observed PR #560 exact `281a9dbd5080fb3c0c52ac079a8f3957c3f8e443`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. #556 merge 뒤 current writer는 feature head와 protected main을 두 parent로 갖는 ordinary/non-force semantic restack을 수행했고, `.github`와 `reviewer` protected owner source를 그대로 승계했다. Restack 때 겹친 `CHANGELOG.md`에서는 protected #556 entry와 #560 Tool / Capability entry의 semantic union을 복구했으며, predecessor `669a45a...` 대비 `68f2843...` repair는 exactly one addition / zero deletion이다. Current generation은 application CI `34217233912`, reviewer-ci `34217233938`, required Security Scan `34217233921`, patch-validator-image `34217233913`이며 모두 queued/pending이다. predecessor 결과는 이 exact head의 merge authority가 아니다. +Observed PR #560 exact `802b0bff0f32c170ada328b04e87e0db43ee7cd4`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. Compare authority는 `behind_by=0`, merge base exact protected main이다. #556 merge 뒤 feature lane은 protected `.github`와 `reviewer` owner source를 그대로 승계하고 `docs/product-technical-gap-baseline.md`는 #559에 남겨 두었다. Earlier ordinary/non-force restack의 `CHANGELOG.md` overlap도 protected #556 entry와 #560 Tool / Capability entry의 semantic union을 보존한다. Earlier test-only exact `7ca9aebee6f92053913c0bbc665c8de77650891f`의 hosted application CI `34206149899`, job `101995980303`은 exact checkout, live-base guard, lockfile control, install, typecheck를 통과한 뒤 release tests에서 실패했다. 이 RED는 valid catalog/AppGuardrail/quarantine evidence가 있어도 descriptor가 `approval_status`, product repository, execution role을 self-broaden하면 별도 Noema Policy / Approval issuance 없이는 admission이 거부돼야 한다는 결함을 증명했다. -Production `c6e91dbe8b452e067d30890aae993b04b7cd814c`는 source/catalog/scanner authority와 Noema Policy / Approval issuance를 분리했다. Public Tool / Capability adapter는 maximum approval status, allowed product repositories, allowed execution roles, validity interval, isolation/egress references와 activation-policy version을 독립 grant에 결합한다. Unknown extension에는 implicit grant가 없다. Activation은 issued policy version을 인용해야 하며 invocation은 policy를 다시 resolve해 revocation/drift를 fail closed한다. RED `2096510...`은 hostile public activation/invocation envelope의 property read가 domain error 밖으로 새는 경계를 고정했고 `83a54b6...`는 이를 canonical fail-closed rejection으로 normalize한다. Subsequent RED `0dd7956...`는 source-issued pilot grant가 active authority로 오용되는 경계를 고정했다. Production `2f7ff5a...`는 default ceiling을 `approved_for_pilot`로 낮췄고, `cdcc063...`는 active-path fixtures에 명시적인 `TrustedExtensionPolicyApproval`을 공급하면서 그 production 경계를 유지한다. Causal RED `9711e3f...`는 invocation이 issued activation보다 이를 수 있던 event-order 결함을 고정했고 `37dd2c0...`는 descriptor-window error precedence를 유지한 채 그 불가능한 순서를 거부하고 current exact `281a9dbd...`는 동일 invariant를 ADR 0015, CHANGELOG, Test Strategy와 Traceability에 기록한다. 이 exact는 ADR 0015 `Proposed`와 protected #556 source 및 CHANGELOG semantic union을 보존한다. +Production `c6e91dbe8b452e067d30890aae993b04b7cd814c`는 source/catalog/scanner authority와 Noema Policy / Approval issuance를 분리했다. Public Tool / Capability adapter는 maximum approval status, allowed product repositories, allowed execution roles, validity interval, isolation/egress references와 activation-policy version을 독립 grant에 결합한다. Unknown extension에는 implicit grant가 없다. Activation은 issued policy version을 인용해야 하며 invocation은 policy를 다시 resolve해 revocation/drift를 fail closed한다. RED `2096510...`은 hostile public activation/invocation envelope의 property read가 domain error 밖으로 새는 경계를 고정했고 `83a54b6...`는 이를 canonical fail-closed rejection으로 normalize한다. Subsequent RED `0dd7956...`는 source-issued pilot grant가 active authority로 오용되는 경계를 고정했다. Production `2f7ff5a...`는 default ceiling을 `approved_for_pilot`로 낮췄고, `cdcc063...`는 active-path fixtures에 명시적인 `TrustedExtensionPolicyApproval`을 공급하면서 그 production 경계를 유지한다. Causal RED `9711e3f...`는 invocation이 issued activation보다 이를 수 있던 event-order 결함을 고정했고 `37dd2c0...`는 descriptor-window error precedence를 유지한 채 그 불가능한 순서를 거부한다. -AppGuardrail/quarantine receipts는 scanner/provenance evidence이지 Noema approval이 아니다. EgressWeave/quarantine references는 outbound/isolation operation의 대체물이 아니다. Anthropic marketplace review는 discovery evidence이지 CWL product authority가 아니다. `context-graph-contracts`가 immutable shared external-capability contract를 release하기 전까지 이 local port는 fail-closed ACL/test double이며 live plugin installation 또는 buyer completion을 주장하지 않는다. +Fresh public admission-boundary review then found that a revoked Proxy supplied as a descriptor capability list could make `Array.isArray()` throw a raw JavaScript `TypeError` before the bounded Tool / Capability error contract. Test-only exact `f30f67328efbcd0b8bed7ac89f7c64c40528ea44` added a revoked `required_network_capabilities` Proxy. Hosted application CI `34218780676`, job `102036728526` passed exact checkout, live-base guard, lockfile control, install and release typecheck, then failed at release tests: this is the real hostile-case RED. Production `802b0bff0f32c170ada328b04e87e0db43ee7cd4` adds only the missing public admission seam normalization: existing `ExternalExtensionAdmissionError` is rethrown and other hostile exceptions become `admission request could not be read safely`; descriptor/list/capability validation is not weakened. + +Current exact-head generation is application CI `34219296338`, reviewer-ci `34219296283`, required Security Scan `34219296330`, and patch-validator-image `34219296355`. These runs are revision-local and predecessor GREEN does not transfer; queued/pending/in-progress status is not merge authority. ADR 0015 remains `Proposed`. + +AppGuardrail/quarantine receipts는 scanner/provenance evidence이지 Noema approval이 아니다. EgressWeave/quarantine references는 outbound/isolation operation의 대체물이 아니다. Anthropic marketplace review는 discovery evidence이지 CWL product authority가 아니다. `context-graph-contracts#27`이 immutable shared external-capability contract를 release하기 전까지 이 local port는 fail-closed ACL/test double이며 live plugin installation 또는 buyer completion을 주장하지 않는다. `context-graph-contracts#27`과 `appguardrail#1099`는 모두 open이고 해당 owner evidence를 Noema가 합성하지 않는다. ## Evidence and merge rules @@ -49,7 +53,7 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge | Priority | Gap | Buyer/operator impact | Current owner | Status | Authoritative completion evidence | Next executable action | | --- | --- | --- | --- | --- | --- | --- | | P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority가 될 위험 | protected #556 + release/consumer lanes | Source integrated; producer/release/consumer open | protected source + execution/research producer + immutable Noema release + released central consumer corpus RED→GREEN | release/producer evidence를 별도 lane에서 완성 | -| P0 | External extension capability admission | third-party plugin metadata 또는 self-asserted product grant가 runtime authority가 될 위험 | issue #545 / PR #560 | Draft; ADR 0015 Proposed | immutable source + independent scan + Noema-issued Policy / Approval grant + live revalidation + fresh four-GREEN + normal merge + immutable shared contract/live pilot evidence | restacked exact head의 semantic union과 fresh gates를 재검증 | +| P0 | External extension capability admission | third-party plugin metadata 또는 self-asserted/hostile product grant가 runtime authority가 될 위험 | issue #545 / PR #560 | Draft; ADR 0015 Proposed; public admission hostile RED repaired, exact-head gates open | immutable source + independent scan + Noema-issued Policy / Approval grant + public hostile-input normalization + live revalidation + fresh four-GREEN + normal merge + immutable shared contract/live pilot evidence | `802b0bf...` unchanged-head gates와 fresh review를 검증하고 실패 시 해당 causal lane 즉시 수리 | | P0 | Protected-main governance closure | required Security workflow만으로 PR/review/history/deletion/bypass 통제를 증명했다고 오인할 위험 | issue #27 | Open; external control evidence absent | fresh live ruleset + required PR/review/conversation/history/deletion controls + independent bypass/break-glass evidence + protected-source governance receipt | source가 만들 수 없는 organization/admin control은 issue #27에서 독립 검증 | | P0 | Strict orchestrator/free consumer release | source 통합만으로 immutable consumer activation을 증명할 수 없음 | merged #535 + release lane | Source integrated; release/consumer open | version/tag/package/SBOM/provenance/reproducibility/rollback + released consumer | release-ready protected head에서만 publication | | P0 | Patch-validator operational publication | source/image CI success만으로 reusable immutable runtime을 증명할 수 없음 | issue #66 | Open; publication evidence absent | protected execution + immutable image/signature/SBOM/provenance/reproducibility/rollback | immutable publication evidence와 결합 | From d4e7e4b66bd087a0f51ed5b0e1cbe1851b395f42 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 20:14:01 +0900 Subject: [PATCH 46/68] test(docs): bind live candidate to admission repair --- test/documentation-live-open-pr-authority.test.ts | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index e758c09e3..1d73969c1 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -6,18 +6,21 @@ describe("product-technical gap baseline live open-PR authority", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); expect(baseline).toContain("Resulting protected merge는 GitHub-verified `36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`"); - expect(baseline).toContain("Observed PR #560 exact `281a9dbd5080fb3c0c52ac079a8f3957c3f8e443`"); - expect(baseline).toContain("application CI `34217233912`"); + expect(baseline).toContain("Observed PR #560 exact `802b0bff0f32c170ada328b04e87e0db43ee7cd4`"); + expect(baseline).toContain("Hosted application CI `34218780676`, job `102036728526`"); + expect(baseline).toContain("application CI `34219296338`"); expect(baseline).toContain("Policy / Approval issuance"); expect(baseline).toContain("Production `c6e91dbe8b452e067d30890aae993b04b7cd814c`"); - expect(baseline).toContain("ordinary/non-force semantic restack"); - expect(baseline).toContain("CHANGELOG semantic union"); + expect(baseline).toContain("public admission seam normalization"); + expect(baseline).toContain("ordinary/non-force restack"); + expect(baseline).toContain("CHANGELOG"); expect(baseline).not.toContain("Observed PR #556 exact"); expect(baseline).not.toContain("Observed PR #560 exact `68f28439edfd92394723ebc1248a6b2e9a957d44`"); expect(baseline).not.toContain("Observed PR #560 exact `935b99e1704b5a9966057a886dc60640d6bda5e2`"); expect(baseline).not.toContain("Observed PR #560 exact `83a54b699e9b5678b6f41125f57cb36fc5ce9597`"); expect(baseline).not.toContain("Observed PR #560 exact `cdcc06365d907dd623aa3535d432061c50bdf3c6`"); expect(baseline).not.toContain("Observed PR #560 exact `37dd2c0d197b780661f1ce5b43b243711791b3c5`"); + expect(baseline).not.toContain("Observed PR #560 exact `281a9dbd5080fb3c0c52ac079a8f3957c3f8e443`"); expect(baseline).not.toContain("application CI `34209618966`"); }); }); From 8341cab95d4fef1f0504fa3b908aaffe4555f41e Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 20:22:01 +0900 Subject: [PATCH 47/68] test(docs): preserve candidate ADR authority wording --- test/product-technical-gap-current-candidate-contract.test.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index 3da101cb9..779b8e17c 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -10,7 +10,7 @@ describe("product-technical gap current candidate contract", () => { expect(baseline).toContain("hosted application CI `34206149899`, job `101995980303`"); expect(baseline).toContain("source/catalog/scanner authority와 Noema Policy / Approval issuance를 분리했다"); expect(baseline).toContain("Unknown extension에는 implicit grant가 없다"); - expect(baseline).toContain("ADR 0015 `Proposed`"); + expect(baseline).toContain("PR #560의 ADR 0015는 candidate-only `Proposed`"); expect(baseline).toContain("context-graph-contracts"); expect(baseline).toContain("live plugin installation 또는 buyer completion을 주장하지 않는다"); expect(baseline).toContain("immutable Noema release"); From b65eb4ad3da97c0206a96aa933070209c9dd8ead Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 20:49:16 +0900 Subject: [PATCH 48/68] docs: refresh external-extension runtime-time authority --- docs/product-technical-gap-baseline.md | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 73eae8695..4f0c3852a 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -14,7 +14,7 @@ Protected history에는 merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe ## Canonical product boundary -Noema Core Domain은 Agent Runtime과 Workflow / Task Execution이다. Tool / Capability Boundary, State / Checkpoint, Isolation Integration, Policy / Approval, Observability, Recovery는 명시적 bounded context다. Execution identity, side-effect authority, claim/checkpoint CAS, cancellation/recovery invariant와 Noema-owned product/role approval issuance는 Noema 경계에 남긴다. +Noema Core Domain은 Agent Runtime과 Workflow / Task Execution이다. Tool / Capability Boundary, State / Checkpoint, Isolation Integration, Policy / Approval, Observability, Recovery는 명시적 bounded context다. Execution identity, side-effect authority, claim/checkpoint CAS, cancellation/recovery invariant와 Noema-owned product/role/time approval issuance는 Noema 경계에 남긴다. `contextual-orchestrator`는 provider/model discovery, routing, retry/failover, test-time compute와 provider credential을 소유한다. Noema는 released gateway contract와 canonical `orchestrator/free` alias를 소비하며 direct provider SDK, provider key, provider/model/group fallback policy를 소유하지 않는다. `.github`는 organization reusable workflow/control-plane source다. Keyverse는 identity backend다. `quarantine-sandbox-runtime`, Wardnet, EgressWeave, AppGuardrail은 각자의 isolation/security/outbound/scanning truth를 소유한다. Noema는 그 owner evidence를 reference/pin으로 소비할 뿐 foreign implementation이나 domain table을 복제하지 않는다. Cross-service SQL과 mutable sibling PR dependency는 금지한다. @@ -28,17 +28,17 @@ Protected source는 raw source receipt를 context authority로만 취급하고, ## Active external-extension candidate — issue #545 / PR #560 -Observed PR #560 exact `802b0bff0f32c170ada328b04e87e0db43ee7cd4`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. Compare authority는 `behind_by=0`, merge base exact protected main이다. #556 merge 뒤 feature lane은 protected `.github`와 `reviewer` owner source를 그대로 승계하고 `docs/product-technical-gap-baseline.md`는 #559에 남겨 두었다. Earlier ordinary/non-force restack의 `CHANGELOG.md` overlap도 protected #556 entry와 #560 Tool / Capability entry의 semantic union을 보존한다. +Observed PR #560 exact `f8703e6628961d380df59e4e90b600ebad215c11`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. Compare authority는 `behind_by=0`, merge base exact protected main이다. #556 merge 뒤 feature lane은 protected `.github`와 `reviewer` owner source를 그대로 승계하고 `docs/product-technical-gap-baseline.md`는 #559에 남겨 두었다. Ordinary/non-force history를 유지하며 force push나 destructive rebase를 쓰지 않는다. -Earlier test-only exact `7ca9aebee6f92053913c0bbc665c8de77650891f`의 hosted application CI `34206149899`, job `101995980303`은 exact checkout, live-base guard, lockfile control, install, typecheck를 통과한 뒤 release tests에서 실패했다. 이 RED는 valid catalog/AppGuardrail/quarantine evidence가 있어도 descriptor가 `approval_status`, product repository, execution role을 self-broaden하면 별도 Noema Policy / Approval issuance 없이는 admission이 거부돼야 한다는 결함을 증명했다. +Earlier Policy / Approval RED `7ca9aebee6f92053913c0bbc665c8de77650891f`의 hosted application CI `34206149899`, job `101995980303`은 valid catalog/AppGuardrail/quarantine evidence만으로 descriptor가 active/product/role grant를 self-broaden할 수 없음을 고정했다. Subsequent production source separates source/catalog/scanner authority from Noema Policy / Approval issuance, keeps the source-issued grant at a pilot ceiling, seals admission/activation/receipt provenance, revalidates the full six-field catalog identity and live scanner receipts, and rejects impossible pre-activation invocation chronology. -Production `c6e91dbe8b452e067d30890aae993b04b7cd814c`는 source/catalog/scanner authority와 Noema Policy / Approval issuance를 분리했다. Public Tool / Capability adapter는 maximum approval status, allowed product repositories, allowed execution roles, validity interval, isolation/egress references와 activation-policy version을 독립 grant에 결합한다. Unknown extension에는 implicit grant가 없다. Activation은 issued policy version을 인용해야 하며 invocation은 policy를 다시 resolve해 revocation/drift를 fail closed한다. RED `2096510...`은 hostile public activation/invocation envelope의 property read가 domain error 밖으로 새는 경계를 고정했고 `83a54b6...`는 이를 canonical fail-closed rejection으로 normalize한다. Subsequent RED `0dd7956...`는 source-issued pilot grant가 active authority로 오용되는 경계를 고정했다. Production `2f7ff5a...`는 default ceiling을 `approved_for_pilot`로 낮췄고, `cdcc063...`는 active-path fixtures에 명시적인 `TrustedExtensionPolicyApproval`을 공급하면서 그 production 경계를 유지한다. Causal RED `9711e3f...`는 invocation이 issued activation보다 이를 수 있던 event-order 결함을 고정했고 `37dd2c0...`는 descriptor-window error precedence를 유지한 채 그 불가능한 순서를 거부한다. +Fresh hostile-input RED `f30f67328efbcd0b8bed7ac89f7c64c40528ea44` / hosted application CI `34218780676`, job `102036728526` proved that a revoked descriptor-list Proxy could leak a raw JavaScript exception through public admission. Production `802b0bff0f32c170ada328b04e87e0db43ee7cd4` normalized that public boundary without weakening descriptor/list/capability validation. -Fresh public admission-boundary review then found that a revoked Proxy supplied as a descriptor capability list could make `Array.isArray()` throw a raw JavaScript `TypeError` before the bounded Tool / Capability error contract. Test-only exact `f30f67328efbcd0b8bed7ac89f7c64c40528ea44` added a revoked `required_network_capabilities` Proxy. Hosted application CI `34218780676`, job `102036728526` passed exact checkout, live-base guard, lockfile control, install and release typecheck, then failed at release tests: this is the real hostile-case RED. Production `802b0bff0f32c170ada328b04e87e0db43ee7cd4` adds only the missing public admission seam normalization: existing `ExternalExtensionAdmissionError` is rethrown and other hostile exceptions become `admission request could not be read safely`; descriptor/list/capability validation is not weakened. +Fresh Tool / Capability review then found a distinct expiry-authority gap: `activated_at` and `invoked_at` are caller event timestamps, so comparing the validity window only against those fields allowed a caller to backdate an operation after actual expiry. Test-only exact `4be371ec08b852f4d00829ba5aa6936df6564b5e` advances the runtime clock beyond `valid_to` while retaining an in-window event timestamp. Hosted application CI `34221586992`, job `102045717213` passed exact checkout, live-base guard, lockfile control, install and release typecheck, then failed at release tests: this is the current causal RED. Production `2b50b35b7bdbb834f571dfcae50dceb05766244c` requires the Noema runtime wall clock to remain inside both the admitted descriptor and independently issued Policy / Approval validity windows for activation and invocation. Exact `83e3130f1894e879769e014c76e28ffc982a2063` covers the pre-window edge; current exact `f8703e6628961d380df59e4e90b600ebad215c11` records the authority distinction in ADR 0015, which remains `Proposed`. -Current exact-head generation is application CI `34219296338`, reviewer-ci `34219296283`, required Security Scan `34219296330`, and patch-validator-image `34219296355`. These runs are revision-local and predecessor GREEN does not transfer; queued/pending/in-progress status is not merge authority. ADR 0015 remains `Proposed`. +Current exact-head generation is application CI `34222306594`, reviewer-ci `34222306710`, required Security Scan `34222306581`, and patch-validator-image `34222306823`. These runs are revision-local and predecessor GREEN does not transfer; queued/pending/in-progress status is not merge authority. -AppGuardrail/quarantine receipts는 scanner/provenance evidence이지 Noema approval이 아니다. EgressWeave/quarantine references는 outbound/isolation operation의 대체물이 아니다. Anthropic marketplace review는 discovery evidence이지 CWL product authority가 아니다. `context-graph-contracts#27`이 immutable shared external-capability contract를 release하기 전까지 이 local port는 fail-closed ACL/test double이며 live plugin installation 또는 buyer completion을 주장하지 않는다. `context-graph-contracts#27`과 `appguardrail#1099`는 모두 open이고 해당 owner evidence를 Noema가 합성하지 않는다. +AppGuardrail/quarantine receipts는 scanner/provenance evidence이지 Noema approval이 아니다. EgressWeave/quarantine references는 outbound/isolation operation의 대체물이 아니다. Anthropic marketplace review는 discovery evidence이지 CWL product authority가 아니다. `context-graph-contracts#27`이 immutable shared external-capability contract를 release하기 전까지 이 local port는 fail-closed ACL/test double이며 live plugin installation 또는 buyer completion을 주장하지 않는다. `context-graph-contracts#27`과 `appguardrail#1099`의 owner evidence를 Noema가 합성하지 않는다. ## Evidence and merge rules @@ -53,7 +53,7 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge | Priority | Gap | Buyer/operator impact | Current owner | Status | Authoritative completion evidence | Next executable action | | --- | --- | --- | --- | --- | --- | --- | | P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority가 될 위험 | protected #556 + release/consumer lanes | Source integrated; producer/release/consumer open | protected source + execution/research producer + immutable Noema release + released central consumer corpus RED→GREEN | release/producer evidence를 별도 lane에서 완성 | -| P0 | External extension capability admission | third-party plugin metadata 또는 self-asserted/hostile product grant가 runtime authority가 될 위험 | issue #545 / PR #560 | Draft; ADR 0015 Proposed; public admission hostile RED repaired, exact-head gates open | immutable source + independent scan + Noema-issued Policy / Approval grant + public hostile-input normalization + live revalidation + fresh four-GREEN + normal merge + immutable shared contract/live pilot evidence | `802b0bf...` unchanged-head gates와 fresh review를 검증하고 실패 시 해당 causal lane 즉시 수리 | +| P0 | External extension capability admission | third-party plugin metadata, self-asserted grant 또는 backdated event time이 runtime authority가 될 위험 | issue #545 / PR #560 | Draft; ADR 0015 Proposed; runtime-clock RED repaired, exact-head gates open | immutable source + independent scan + Noema-issued Policy / Approval grant + public hostile-input normalization + runtime-current expiry enforcement + live revalidation + fresh four-GREEN + normal merge + immutable shared contract/live pilot evidence | `f8703e6...` unchanged-head gates와 fresh review를 검증하고 실패 시 해당 causal lane 즉시 수리 | | P0 | Protected-main governance closure | required Security workflow만으로 PR/review/history/deletion/bypass 통제를 증명했다고 오인할 위험 | issue #27 | Open; external control evidence absent | fresh live ruleset + required PR/review/conversation/history/deletion controls + independent bypass/break-glass evidence + protected-source governance receipt | source가 만들 수 없는 organization/admin control은 issue #27에서 독립 검증 | | P0 | Strict orchestrator/free consumer release | source 통합만으로 immutable consumer activation을 증명할 수 없음 | merged #535 + release lane | Source integrated; release/consumer open | version/tag/package/SBOM/provenance/reproducibility/rollback + released consumer | release-ready protected head에서만 publication | | P0 | Patch-validator operational publication | source/image CI success만으로 reusable immutable runtime을 증명할 수 없음 | issue #66 | Open; publication evidence absent | protected execution + immutable image/signature/SBOM/provenance/reproducibility/rollback | immutable publication evidence와 결합 | From 6a689619815dddf0cd0a60b5123787541a464e90 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 20:49:30 +0900 Subject: [PATCH 49/68] test(docs): bind current runtime-time candidate authority --- ...oduct-technical-gap-current-candidate-contract.test.ts | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index 779b8e17c..d78875d8a 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -6,10 +6,10 @@ describe("product-technical gap current candidate contract", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); expect(baseline).toContain("issue #545 / PR #560"); - expect(baseline).toContain("Earlier test-only exact `7ca9aebee6f92053913c0bbc665c8de77650891f`"); - expect(baseline).toContain("hosted application CI `34206149899`, job `101995980303`"); - expect(baseline).toContain("source/catalog/scanner authority와 Noema Policy / Approval issuance를 분리했다"); - expect(baseline).toContain("Unknown extension에는 implicit grant가 없다"); + expect(baseline).toContain("Test-only exact `4be371ec08b852f4d00829ba5aa6936df6564b5e`"); + expect(baseline).toContain("Hosted application CI `34221586992`, job `102045717213`"); + expect(baseline).toContain("Noema Policy / Approval issuance"); + expect(baseline).toContain("runtime wall clock"); expect(baseline).toContain("PR #560의 ADR 0015는 candidate-only `Proposed`"); expect(baseline).toContain("context-graph-contracts"); expect(baseline).toContain("live plugin installation 또는 buyer completion을 주장하지 않는다"); From 1a9522bcf87a29361ba2e46582bd6fbbb49c9b4c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 20:49:48 +0900 Subject: [PATCH 50/68] test(docs): refresh live external-extension candidate authority --- ...cumentation-live-open-pr-authority.test.ts | 22 +++++++------------ 1 file changed, 8 insertions(+), 14 deletions(-) diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index 1d73969c1..b0c5c0426 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -6,21 +6,15 @@ describe("product-technical gap baseline live open-PR authority", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); expect(baseline).toContain("Resulting protected merge는 GitHub-verified `36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`"); - expect(baseline).toContain("Observed PR #560 exact `802b0bff0f32c170ada328b04e87e0db43ee7cd4`"); - expect(baseline).toContain("Hosted application CI `34218780676`, job `102036728526`"); - expect(baseline).toContain("application CI `34219296338`"); + expect(baseline).toContain("Observed PR #560 exact `f8703e6628961d380df59e4e90b600ebad215c11`"); + expect(baseline).toContain("Hosted application CI `34221586992`, job `102045717213`"); + expect(baseline).toContain("application CI `34222306594`"); expect(baseline).toContain("Policy / Approval issuance"); - expect(baseline).toContain("Production `c6e91dbe8b452e067d30890aae993b04b7cd814c`"); - expect(baseline).toContain("public admission seam normalization"); - expect(baseline).toContain("ordinary/non-force restack"); - expect(baseline).toContain("CHANGELOG"); + expect(baseline).toContain("Production `2b50b35b7bdbb834f571dfcae50dceb05766244c`"); + expect(baseline).toContain("runtime wall clock"); + expect(baseline).toContain("ordinary/non-force"); expect(baseline).not.toContain("Observed PR #556 exact"); - expect(baseline).not.toContain("Observed PR #560 exact `68f28439edfd92394723ebc1248a6b2e9a957d44`"); - expect(baseline).not.toContain("Observed PR #560 exact `935b99e1704b5a9966057a886dc60640d6bda5e2`"); - expect(baseline).not.toContain("Observed PR #560 exact `83a54b699e9b5678b6f41125f57cb36fc5ce9597`"); - expect(baseline).not.toContain("Observed PR #560 exact `cdcc06365d907dd623aa3535d432061c50bdf3c6`"); - expect(baseline).not.toContain("Observed PR #560 exact `37dd2c0d197b780661f1ce5b43b243711791b3c5`"); - expect(baseline).not.toContain("Observed PR #560 exact `281a9dbd5080fb3c0c52ac079a8f3957c3f8e443`"); - expect(baseline).not.toContain("application CI `34209618966`"); + expect(baseline).not.toContain("Observed PR #560 exact `802b0bff0f32c170ada328b04e87e0db43ee7cd4`"); + expect(baseline).not.toContain("application CI `34219296338`"); }); }); From e13419f2f22e74eef903fc4013109f16deaccd4a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 21:24:54 +0900 Subject: [PATCH 51/68] docs: bind gap authority to invocation replay repair --- docs/product-technical-gap-baseline.md | 10 ++++++---- test/documentation-live-open-pr-authority.test.ts | 7 +++++-- ...ct-technical-gap-current-candidate-contract.test.ts | 2 ++ 3 files changed, 13 insertions(+), 6 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 4f0c3852a..6ca54790b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -28,15 +28,17 @@ Protected source는 raw source receipt를 context authority로만 취급하고, ## Active external-extension candidate — issue #545 / PR #560 -Observed PR #560 exact `f8703e6628961d380df59e4e90b600ebad215c11`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. Compare authority는 `behind_by=0`, merge base exact protected main이다. #556 merge 뒤 feature lane은 protected `.github`와 `reviewer` owner source를 그대로 승계하고 `docs/product-technical-gap-baseline.md`는 #559에 남겨 두었다. Ordinary/non-force history를 유지하며 force push나 destructive rebase를 쓰지 않는다. +Observed PR #560 exact `83ee8e9b54be7ea59cfa11fe03e4ad0c6414950c`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. Compare authority는 `behind_by=0`, merge base exact protected main이다. #556 merge 뒤 feature lane은 protected `.github`와 `reviewer` owner source를 그대로 승계하고 `docs/product-technical-gap-baseline.md`는 #559에 남겨 두었다. Ordinary/non-force history를 유지하며 force push나 destructive rebase를 쓰지 않는다. Earlier Policy / Approval RED `7ca9aebee6f92053913c0bbc665c8de77650891f`의 hosted application CI `34206149899`, job `101995980303`은 valid catalog/AppGuardrail/quarantine evidence만으로 descriptor가 active/product/role grant를 self-broaden할 수 없음을 고정했다. Subsequent production source separates source/catalog/scanner authority from Noema Policy / Approval issuance, keeps the source-issued grant at a pilot ceiling, seals admission/activation/receipt provenance, revalidates the full six-field catalog identity and live scanner receipts, and rejects impossible pre-activation invocation chronology. Fresh hostile-input RED `f30f67328efbcd0b8bed7ac89f7c64c40528ea44` / hosted application CI `34218780676`, job `102036728526` proved that a revoked descriptor-list Proxy could leak a raw JavaScript exception through public admission. Production `802b0bff0f32c170ada328b04e87e0db43ee7cd4` normalized that public boundary without weakening descriptor/list/capability validation. -Fresh Tool / Capability review then found a distinct expiry-authority gap: `activated_at` and `invoked_at` are caller event timestamps, so comparing the validity window only against those fields allowed a caller to backdate an operation after actual expiry. Test-only exact `4be371ec08b852f4d00829ba5aa6936df6564b5e` advances the runtime clock beyond `valid_to` while retaining an in-window event timestamp. Hosted application CI `34221586992`, job `102045717213` passed exact checkout, live-base guard, lockfile control, install and release typecheck, then failed at release tests: this is the current causal RED. Production `2b50b35b7bdbb834f571dfcae50dceb05766244c` requires the Noema runtime wall clock to remain inside both the admitted descriptor and independently issued Policy / Approval validity windows for activation and invocation. Exact `83e3130f1894e879769e014c76e28ffc982a2063` covers the pre-window edge; current exact `f8703e6628961d380df59e4e90b600ebad215c11` records the authority distinction in ADR 0015, which remains `Proposed`. +Fresh Tool / Capability review then found a distinct expiry-authority gap: `activated_at` and `invoked_at` are caller event timestamps, so comparing the validity window only against those fields allowed a caller to backdate an operation after actual expiry. Test-only exact `4be371ec08b852f4d00829ba5aa6936df6564b5e` advances the runtime clock beyond `valid_to` while retaining an in-window event timestamp. Hosted application CI `34221586992`, job `102045717213` passed exact checkout, live-base guard, lockfile control, install and release typecheck, then failed at release tests: this is the current causal RED. Production `2b50b35b7bdbb834f571dfcae50dceb05766244c` requires the Noema runtime wall clock to remain inside both the admitted descriptor and independently issued Policy / Approval validity windows for activation and invocation. Exact `83e3130f1894e879769e014c76e28ffc982a2063` covers the pre-window edge; `f8703e6628961d380df59e4e90b600ebad215c11` records the authority distinction in ADR 0015, which remains `Proposed`. -Current exact-head generation is application CI `34222306594`, reviewer-ci `34222306710`, required Security Scan `34222306581`, and patch-validator-image `34222306823`. These runs are revision-local and predecessor GREEN does not transfer; queued/pending/in-progress status is not merge authority. +Test-only replay RED `cb8ad638875b761aea70aba78a480bd5031c4d7d` then proved that a retained receipt omitted instruction and observed-content semantics, allowing the same invocation identity to request different work. Production `9c7ae13f7053fa368fd778c3909c4428d1bdf28e` binds replay to the exact normalized invocation envelope. Refactor `03c2a6949a858043c6f7412a9ee724de63deaae2` made the public check GREEN but rendered the internal conflicting-receipt oracle unexecuted; Coverage repair `83ee8e9b54be7ea59cfa11fe03e4ad0c6414950c` restores that core assertion without changing production behavior. + +Current exact-head generation is application CI `34225184459`, reviewer-ci `34225184096`, required Security Scan `34225184081`, and patch-validator-image `34225184104`. These runs are revision-local and predecessor GREEN does not transfer; queued/pending/in-progress status is not merge authority. AppGuardrail/quarantine receipts는 scanner/provenance evidence이지 Noema approval이 아니다. EgressWeave/quarantine references는 outbound/isolation operation의 대체물이 아니다. Anthropic marketplace review는 discovery evidence이지 CWL product authority가 아니다. `context-graph-contracts#27`이 immutable shared external-capability contract를 release하기 전까지 이 local port는 fail-closed ACL/test double이며 live plugin installation 또는 buyer completion을 주장하지 않는다. `context-graph-contracts#27`과 `appguardrail#1099`의 owner evidence를 Noema가 합성하지 않는다. @@ -53,7 +55,7 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge | Priority | Gap | Buyer/operator impact | Current owner | Status | Authoritative completion evidence | Next executable action | | --- | --- | --- | --- | --- | --- | --- | | P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority가 될 위험 | protected #556 + release/consumer lanes | Source integrated; producer/release/consumer open | protected source + execution/research producer + immutable Noema release + released central consumer corpus RED→GREEN | release/producer evidence를 별도 lane에서 완성 | -| P0 | External extension capability admission | third-party plugin metadata, self-asserted grant 또는 backdated event time이 runtime authority가 될 위험 | issue #545 / PR #560 | Draft; ADR 0015 Proposed; runtime-clock RED repaired, exact-head gates open | immutable source + independent scan + Noema-issued Policy / Approval grant + public hostile-input normalization + runtime-current expiry enforcement + live revalidation + fresh four-GREEN + normal merge + immutable shared contract/live pilot evidence | `f8703e6...` unchanged-head gates와 fresh review를 검증하고 실패 시 해당 causal lane 즉시 수리 | +| P0 | External extension capability admission | third-party plugin metadata, self-asserted grant, backdated event time 또는 divergent replay가 runtime authority가 될 위험 | issue #545 / PR #560 | Draft; ADR 0015 Proposed; runtime-clock/replay RED repaired, exact-head gates open | immutable source + independent scan + Noema-issued Policy / Approval grant + public hostile-input normalization + runtime-current expiry enforcement + request-bound idempotency + live revalidation + fresh four-GREEN + normal merge + immutable shared contract/live pilot evidence | `83ee8e9...` unchanged-head gates와 fresh review를 검증하고 실패 시 해당 causal lane 즉시 수리 | | P0 | Protected-main governance closure | required Security workflow만으로 PR/review/history/deletion/bypass 통제를 증명했다고 오인할 위험 | issue #27 | Open; external control evidence absent | fresh live ruleset + required PR/review/conversation/history/deletion controls + independent bypass/break-glass evidence + protected-source governance receipt | source가 만들 수 없는 organization/admin control은 issue #27에서 독립 검증 | | P0 | Strict orchestrator/free consumer release | source 통합만으로 immutable consumer activation을 증명할 수 없음 | merged #535 + release lane | Source integrated; release/consumer open | version/tag/package/SBOM/provenance/reproducibility/rollback + released consumer | release-ready protected head에서만 publication | | P0 | Patch-validator operational publication | source/image CI success만으로 reusable immutable runtime을 증명할 수 없음 | issue #66 | Open; publication evidence absent | protected execution + immutable image/signature/SBOM/provenance/reproducibility/rollback | immutable publication evidence와 결합 | diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index b0c5c0426..1e8e15c39 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -6,12 +6,15 @@ describe("product-technical gap baseline live open-PR authority", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); expect(baseline).toContain("Resulting protected merge는 GitHub-verified `36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`"); - expect(baseline).toContain("Observed PR #560 exact `f8703e6628961d380df59e4e90b600ebad215c11`"); + expect(baseline).toContain("Observed PR #560 exact `83ee8e9b54be7ea59cfa11fe03e4ad0c6414950c`"); expect(baseline).toContain("Hosted application CI `34221586992`, job `102045717213`"); - expect(baseline).toContain("application CI `34222306594`"); + expect(baseline).toContain("application CI `34225184459`"); expect(baseline).toContain("Policy / Approval issuance"); expect(baseline).toContain("Production `2b50b35b7bdbb834f571dfcae50dceb05766244c`"); expect(baseline).toContain("runtime wall clock"); + expect(baseline).toContain("Test-only replay RED `cb8ad638875b761aea70aba78a480bd5031c4d7d`"); + expect(baseline).toContain("Production `9c7ae13f7053fa368fd778c3909c4428d1bdf28e`"); + expect(baseline).toContain("Coverage repair `83ee8e9b54be7ea59cfa11fe03e4ad0c6414950c`"); expect(baseline).toContain("ordinary/non-force"); expect(baseline).not.toContain("Observed PR #556 exact"); expect(baseline).not.toContain("Observed PR #560 exact `802b0bff0f32c170ada328b04e87e0db43ee7cd4`"); diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index d78875d8a..289fbbaa8 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -10,6 +10,8 @@ describe("product-technical gap current candidate contract", () => { expect(baseline).toContain("Hosted application CI `34221586992`, job `102045717213`"); expect(baseline).toContain("Noema Policy / Approval issuance"); expect(baseline).toContain("runtime wall clock"); + expect(baseline).toContain("same invocation identity"); + expect(baseline).toContain("normalized invocation envelope"); expect(baseline).toContain("PR #560의 ADR 0015는 candidate-only `Proposed`"); expect(baseline).toContain("context-graph-contracts"); expect(baseline).toContain("live plugin installation 또는 buyer completion을 주장하지 않는다"); From 4e5dabd9e74eade1d415d1efe7808a8fecc17b97 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 21:38:45 +0900 Subject: [PATCH 52/68] docs: converge on public replay authority repair --- docs/product-technical-gap-baseline.md | 8 +++++--- test/documentation-live-open-pr-authority.test.ts | 8 ++++++-- ...oduct-technical-gap-current-candidate-contract.test.ts | 2 ++ 3 files changed, 13 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 6ca54790b..70a8b6bc0 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -28,7 +28,7 @@ Protected source는 raw source receipt를 context authority로만 취급하고, ## Active external-extension candidate — issue #545 / PR #560 -Observed PR #560 exact `83ee8e9b54be7ea59cfa11fe03e4ad0c6414950c`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. Compare authority는 `behind_by=0`, merge base exact protected main이다. #556 merge 뒤 feature lane은 protected `.github`와 `reviewer` owner source를 그대로 승계하고 `docs/product-technical-gap-baseline.md`는 #559에 남겨 두었다. Ordinary/non-force history를 유지하며 force push나 destructive rebase를 쓰지 않는다. +Observed PR #560 exact `cbb64def35bad02024076c1db74e9da4739ae736`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. Compare authority는 `behind_by=0`, merge base exact protected main이다. #556 merge 뒤 feature lane은 protected `.github`와 `reviewer` owner source를 그대로 승계하고 `docs/product-technical-gap-baseline.md`는 #559에 남겨 두었다. Ordinary/non-force history를 유지하며 force push나 destructive rebase를 쓰지 않는다. Earlier Policy / Approval RED `7ca9aebee6f92053913c0bbc665c8de77650891f`의 hosted application CI `34206149899`, job `101995980303`은 valid catalog/AppGuardrail/quarantine evidence만으로 descriptor가 active/product/role grant를 self-broaden할 수 없음을 고정했다. Subsequent production source separates source/catalog/scanner authority from Noema Policy / Approval issuance, keeps the source-issued grant at a pilot ceiling, seals admission/activation/receipt provenance, revalidates the full six-field catalog identity and live scanner receipts, and rejects impossible pre-activation invocation chronology. @@ -38,7 +38,9 @@ Fresh Tool / Capability review then found a distinct expiry-authority gap: `acti Test-only replay RED `cb8ad638875b761aea70aba78a480bd5031c4d7d` then proved that a retained receipt omitted instruction and observed-content semantics, allowing the same invocation identity to request different work. Production `9c7ae13f7053fa368fd778c3909c4428d1bdf28e` binds replay to the exact normalized invocation envelope. Refactor `03c2a6949a858043c6f7412a9ee724de63deaae2` made the public check GREEN but rendered the internal conflicting-receipt oracle unexecuted; Coverage repair `83ee8e9b54be7ea59cfa11fe03e4ad0c6414950c` restores that core assertion without changing production behavior. -Current exact-head generation is application CI `34225184459`, reviewer-ci `34225184096`, required Security Scan `34225184081`, and patch-validator-image `34225184104`. These runs are revision-local and predecessor GREEN does not transfer; queued/pending/in-progress status is not merge authority. +Unbound core-receipt RED `5a50a9bcfe12f3938b30e4a3cb15af8d30134391` then proved that an authentic receipt issued through the internal core could cross the public wrapper without public invocation-envelope authority. The missing `WeakMap` binding let the core receipt authority stand in for semantic replay authority and accept different instruction text under the same invocation identity. Production `cbb64def35bad02024076c1db74e9da4739ae736` fails closed when the retained receipt lacks that public binding, while direct core and public boundary assertions keep both authority checks executable. + +Current exact-head generation is application CI `34226928021`, reviewer-ci `34226928282`, required Security Scan `34226928120`, and patch-validator-image `34226928090`. These runs are revision-local and predecessor GREEN does not transfer; queued/pending/in-progress status is not merge authority. AppGuardrail/quarantine receipts는 scanner/provenance evidence이지 Noema approval이 아니다. EgressWeave/quarantine references는 outbound/isolation operation의 대체물이 아니다. Anthropic marketplace review는 discovery evidence이지 CWL product authority가 아니다. `context-graph-contracts#27`이 immutable shared external-capability contract를 release하기 전까지 이 local port는 fail-closed ACL/test double이며 live plugin installation 또는 buyer completion을 주장하지 않는다. `context-graph-contracts#27`과 `appguardrail#1099`의 owner evidence를 Noema가 합성하지 않는다. @@ -55,7 +57,7 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge | Priority | Gap | Buyer/operator impact | Current owner | Status | Authoritative completion evidence | Next executable action | | --- | --- | --- | --- | --- | --- | --- | | P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority가 될 위험 | protected #556 + release/consumer lanes | Source integrated; producer/release/consumer open | protected source + execution/research producer + immutable Noema release + released central consumer corpus RED→GREEN | release/producer evidence를 별도 lane에서 완성 | -| P0 | External extension capability admission | third-party plugin metadata, self-asserted grant, backdated event time 또는 divergent replay가 runtime authority가 될 위험 | issue #545 / PR #560 | Draft; ADR 0015 Proposed; runtime-clock/replay RED repaired, exact-head gates open | immutable source + independent scan + Noema-issued Policy / Approval grant + public hostile-input normalization + runtime-current expiry enforcement + request-bound idempotency + live revalidation + fresh four-GREEN + normal merge + immutable shared contract/live pilot evidence | `83ee8e9...` unchanged-head gates와 fresh review를 검증하고 실패 시 해당 causal lane 즉시 수리 | +| P0 | External extension capability admission | third-party plugin metadata, self-asserted grant, backdated event time, divergent replay 또는 core/public authority confusion이 runtime authority가 될 위험 | issue #545 / PR #560 | Draft; ADR 0015 Proposed; runtime-clock/replay/boundary RED repaired, exact-head gates open | immutable source + independent scan + Noema-issued Policy / Approval grant + public hostile-input normalization + runtime-current expiry enforcement + request-bound idempotency + public invocation-envelope authority + live revalidation + fresh four-GREEN + normal merge + immutable shared contract/live pilot evidence | `cbb64de...` unchanged-head gates와 fresh review를 검증하고 실패 시 해당 causal lane 즉시 수리 | | P0 | Protected-main governance closure | required Security workflow만으로 PR/review/history/deletion/bypass 통제를 증명했다고 오인할 위험 | issue #27 | Open; external control evidence absent | fresh live ruleset + required PR/review/conversation/history/deletion controls + independent bypass/break-glass evidence + protected-source governance receipt | source가 만들 수 없는 organization/admin control은 issue #27에서 독립 검증 | | P0 | Strict orchestrator/free consumer release | source 통합만으로 immutable consumer activation을 증명할 수 없음 | merged #535 + release lane | Source integrated; release/consumer open | version/tag/package/SBOM/provenance/reproducibility/rollback + released consumer | release-ready protected head에서만 publication | | P0 | Patch-validator operational publication | source/image CI success만으로 reusable immutable runtime을 증명할 수 없음 | issue #66 | Open; publication evidence absent | protected execution + immutable image/signature/SBOM/provenance/reproducibility/rollback | immutable publication evidence와 결합 | diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index 1e8e15c39..2aef9192c 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -6,18 +6,22 @@ describe("product-technical gap baseline live open-PR authority", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); expect(baseline).toContain("Resulting protected merge는 GitHub-verified `36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`"); - expect(baseline).toContain("Observed PR #560 exact `83ee8e9b54be7ea59cfa11fe03e4ad0c6414950c`"); + expect(baseline).toContain("Observed PR #560 exact `cbb64def35bad02024076c1db74e9da4739ae736`"); expect(baseline).toContain("Hosted application CI `34221586992`, job `102045717213`"); - expect(baseline).toContain("application CI `34225184459`"); + expect(baseline).toContain("application CI `34226928021`"); expect(baseline).toContain("Policy / Approval issuance"); expect(baseline).toContain("Production `2b50b35b7bdbb834f571dfcae50dceb05766244c`"); expect(baseline).toContain("runtime wall clock"); expect(baseline).toContain("Test-only replay RED `cb8ad638875b761aea70aba78a480bd5031c4d7d`"); expect(baseline).toContain("Production `9c7ae13f7053fa368fd778c3909c4428d1bdf28e`"); expect(baseline).toContain("Coverage repair `83ee8e9b54be7ea59cfa11fe03e4ad0c6414950c`"); + expect(baseline).toContain("Unbound core-receipt RED `5a50a9bcfe12f3938b30e4a3cb15af8d30134391`"); + expect(baseline).toContain("Production `cbb64def35bad02024076c1db74e9da4739ae736`"); + expect(baseline).toContain("public invocation-envelope authority"); expect(baseline).toContain("ordinary/non-force"); expect(baseline).not.toContain("Observed PR #556 exact"); expect(baseline).not.toContain("Observed PR #560 exact `802b0bff0f32c170ada328b04e87e0db43ee7cd4`"); expect(baseline).not.toContain("application CI `34219296338`"); + expect(baseline).not.toContain("Observed PR #560 exact `83ee8e9b54be7ea59cfa11fe03e4ad0c6414950c`"); }); }); diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index 289fbbaa8..a601f589a 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -12,6 +12,8 @@ describe("product-technical gap current candidate contract", () => { expect(baseline).toContain("runtime wall clock"); expect(baseline).toContain("same invocation identity"); expect(baseline).toContain("normalized invocation envelope"); + expect(baseline).toContain("core receipt authority"); + expect(baseline).toContain("public invocation-envelope authority"); expect(baseline).toContain("PR #560의 ADR 0015는 candidate-only `Proposed`"); expect(baseline).toContain("context-graph-contracts"); expect(baseline).toContain("live plugin installation 또는 buyer completion을 주장하지 않는다"); From e085d7252570d40b2616214e09b1336dcb186f75 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 21:50:19 +0900 Subject: [PATCH 53/68] docs: converge on activation revocation repair --- docs/product-technical-gap-baseline.md | 8 +++++--- test/documentation-live-open-pr-authority.test.ts | 8 ++++++-- ...oduct-technical-gap-current-candidate-contract.test.ts | 2 ++ 3 files changed, 13 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 70a8b6bc0..75971fd91 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -28,7 +28,7 @@ Protected source는 raw source receipt를 context authority로만 취급하고, ## Active external-extension candidate — issue #545 / PR #560 -Observed PR #560 exact `cbb64def35bad02024076c1db74e9da4739ae736`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. Compare authority는 `behind_by=0`, merge base exact protected main이다. #556 merge 뒤 feature lane은 protected `.github`와 `reviewer` owner source를 그대로 승계하고 `docs/product-technical-gap-baseline.md`는 #559에 남겨 두었다. Ordinary/non-force history를 유지하며 force push나 destructive rebase를 쓰지 않는다. +Observed PR #560 exact `8251d4bcd2c81dd13d252a576b55dc21e66db9c4`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. Compare authority는 `behind_by=0`, merge base exact protected main이다. #556 merge 뒤 feature lane은 protected `.github`와 `reviewer` owner source를 그대로 승계하고 `docs/product-technical-gap-baseline.md`는 #559에 남겨 두었다. Ordinary/non-force history를 유지하며 force push나 destructive rebase를 쓰지 않는다. Earlier Policy / Approval RED `7ca9aebee6f92053913c0bbc665c8de77650891f`의 hosted application CI `34206149899`, job `101995980303`은 valid catalog/AppGuardrail/quarantine evidence만으로 descriptor가 active/product/role grant를 self-broaden할 수 없음을 고정했다. Subsequent production source separates source/catalog/scanner authority from Noema Policy / Approval issuance, keeps the source-issued grant at a pilot ceiling, seals admission/activation/receipt provenance, revalidates the full six-field catalog identity and live scanner receipts, and rejects impossible pre-activation invocation chronology. @@ -40,7 +40,9 @@ Test-only replay RED `cb8ad638875b761aea70aba78a480bd5031c4d7d` then proved that Unbound core-receipt RED `5a50a9bcfe12f3938b30e4a3cb15af8d30134391` then proved that an authentic receipt issued through the internal core could cross the public wrapper without public invocation-envelope authority. The missing `WeakMap` binding let the core receipt authority stand in for semantic replay authority and accept different instruction text under the same invocation identity. Production `cbb64def35bad02024076c1db74e9da4739ae736` fails closed when the retained receipt lacks that public binding, while direct core and public boundary assertions keep both authority checks executable. -Current exact-head generation is application CI `34226928021`, reviewer-ci `34226928282`, required Security Scan `34226928120`, and patch-validator-image `34226928090`. These runs are revision-local and predecessor GREEN does not transfer; queued/pending/in-progress status is not merge authority. +Activation-time revocation RED `8ff77d9b6428a2c09f2c72bf3b05fdb989e35843` then proved that policy drift and revocation after admission were not re-read before issuing an activation; the stale admission snapshot could therefore issue a new activation even though invocation would fail later. Production `8251d4bcd2c81dd13d252a576b55dc21e66db9c4` binds the issuing authority with the admitted snapshot and re-resolves it before issuing an activation, rejecting both live-scope drift and revocation. + +Current exact-head generation is application CI `34228085116`, reviewer-ci `34228085142`, required Security Scan `34228085293`, and patch-validator-image `34228085478`. These runs are revision-local and predecessor GREEN does not transfer; queued/pending/in-progress status is not merge authority. AppGuardrail/quarantine receipts는 scanner/provenance evidence이지 Noema approval이 아니다. EgressWeave/quarantine references는 outbound/isolation operation의 대체물이 아니다. Anthropic marketplace review는 discovery evidence이지 CWL product authority가 아니다. `context-graph-contracts#27`이 immutable shared external-capability contract를 release하기 전까지 이 local port는 fail-closed ACL/test double이며 live plugin installation 또는 buyer completion을 주장하지 않는다. `context-graph-contracts#27`과 `appguardrail#1099`의 owner evidence를 Noema가 합성하지 않는다. @@ -57,7 +59,7 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge | Priority | Gap | Buyer/operator impact | Current owner | Status | Authoritative completion evidence | Next executable action | | --- | --- | --- | --- | --- | --- | --- | | P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority가 될 위험 | protected #556 + release/consumer lanes | Source integrated; producer/release/consumer open | protected source + execution/research producer + immutable Noema release + released central consumer corpus RED→GREEN | release/producer evidence를 별도 lane에서 완성 | -| P0 | External extension capability admission | third-party plugin metadata, self-asserted grant, backdated event time, divergent replay 또는 core/public authority confusion이 runtime authority가 될 위험 | issue #545 / PR #560 | Draft; ADR 0015 Proposed; runtime-clock/replay/boundary RED repaired, exact-head gates open | immutable source + independent scan + Noema-issued Policy / Approval grant + public hostile-input normalization + runtime-current expiry enforcement + request-bound idempotency + public invocation-envelope authority + live revalidation + fresh four-GREEN + normal merge + immutable shared contract/live pilot evidence | `cbb64de...` unchanged-head gates와 fresh review를 검증하고 실패 시 해당 causal lane 즉시 수리 | +| P0 | External extension capability admission | third-party plugin metadata, self-asserted grant, stale activation grant, backdated event time, divergent replay 또는 core/public authority confusion이 runtime authority가 될 위험 | issue #545 / PR #560 | Draft; ADR 0015 Proposed; runtime-clock/replay/boundary RED repaired, exact-head gates open | immutable source + independent scan + Noema-issued Policy / Approval grant + activation-time revocation check + public hostile-input normalization + runtime-current expiry enforcement + request-bound idempotency + public invocation-envelope authority + live revalidation + fresh four-GREEN + normal merge + immutable shared contract/live pilot evidence | `8251d4b...` unchanged-head gates와 fresh review를 검증하고 실패 시 해당 causal lane 즉시 수리 | | P0 | Protected-main governance closure | required Security workflow만으로 PR/review/history/deletion/bypass 통제를 증명했다고 오인할 위험 | issue #27 | Open; external control evidence absent | fresh live ruleset + required PR/review/conversation/history/deletion controls + independent bypass/break-glass evidence + protected-source governance receipt | source가 만들 수 없는 organization/admin control은 issue #27에서 독립 검증 | | P0 | Strict orchestrator/free consumer release | source 통합만으로 immutable consumer activation을 증명할 수 없음 | merged #535 + release lane | Source integrated; release/consumer open | version/tag/package/SBOM/provenance/reproducibility/rollback + released consumer | release-ready protected head에서만 publication | | P0 | Patch-validator operational publication | source/image CI success만으로 reusable immutable runtime을 증명할 수 없음 | issue #66 | Open; publication evidence absent | protected execution + immutable image/signature/SBOM/provenance/reproducibility/rollback | immutable publication evidence와 결합 | diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index 2aef9192c..01f05174b 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -6,9 +6,9 @@ describe("product-technical gap baseline live open-PR authority", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); expect(baseline).toContain("Resulting protected merge는 GitHub-verified `36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`"); - expect(baseline).toContain("Observed PR #560 exact `cbb64def35bad02024076c1db74e9da4739ae736`"); + expect(baseline).toContain("Observed PR #560 exact `8251d4bcd2c81dd13d252a576b55dc21e66db9c4`"); expect(baseline).toContain("Hosted application CI `34221586992`, job `102045717213`"); - expect(baseline).toContain("application CI `34226928021`"); + expect(baseline).toContain("application CI `34228085116`"); expect(baseline).toContain("Policy / Approval issuance"); expect(baseline).toContain("Production `2b50b35b7bdbb834f571dfcae50dceb05766244c`"); expect(baseline).toContain("runtime wall clock"); @@ -18,10 +18,14 @@ describe("product-technical gap baseline live open-PR authority", () => { expect(baseline).toContain("Unbound core-receipt RED `5a50a9bcfe12f3938b30e4a3cb15af8d30134391`"); expect(baseline).toContain("Production `cbb64def35bad02024076c1db74e9da4739ae736`"); expect(baseline).toContain("public invocation-envelope authority"); + expect(baseline).toContain("Activation-time revocation RED `8ff77d9b6428a2c09f2c72bf3b05fdb989e35843`"); + expect(baseline).toContain("Production `8251d4bcd2c81dd13d252a576b55dc21e66db9c4`"); + expect(baseline).toContain("before issuing an activation"); expect(baseline).toContain("ordinary/non-force"); expect(baseline).not.toContain("Observed PR #556 exact"); expect(baseline).not.toContain("Observed PR #560 exact `802b0bff0f32c170ada328b04e87e0db43ee7cd4`"); expect(baseline).not.toContain("application CI `34219296338`"); expect(baseline).not.toContain("Observed PR #560 exact `83ee8e9b54be7ea59cfa11fe03e4ad0c6414950c`"); + expect(baseline).not.toContain("Observed PR #560 exact `cbb64def35bad02024076c1db74e9da4739ae736`"); }); }); diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index a601f589a..c4ac391a1 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -14,6 +14,8 @@ describe("product-technical gap current candidate contract", () => { expect(baseline).toContain("normalized invocation envelope"); expect(baseline).toContain("core receipt authority"); expect(baseline).toContain("public invocation-envelope authority"); + expect(baseline).toContain("policy drift and revocation"); + expect(baseline).toContain("before issuing an activation"); expect(baseline).toContain("PR #560의 ADR 0015는 candidate-only `Proposed`"); expect(baseline).toContain("context-graph-contracts"); expect(baseline).toContain("live plugin installation 또는 buyer completion을 주장하지 않는다"); From 9bbbb23ac6d4ca1ef198de45756c9396c0b31de1 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 23:00:59 +0900 Subject: [PATCH 54/68] docs: converge on admission-bound invocation authority --- docs/product-technical-gap-baseline.md | 10 +++++++--- test/documentation-live-open-pr-authority.test.ts | 9 +++++++-- ...ct-technical-gap-current-candidate-contract.test.ts | 1 + 3 files changed, 15 insertions(+), 5 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 75971fd91..d09f6373b 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -28,7 +28,7 @@ Protected source는 raw source receipt를 context authority로만 취급하고, ## Active external-extension candidate — issue #545 / PR #560 -Observed PR #560 exact `8251d4bcd2c81dd13d252a576b55dc21e66db9c4`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. Compare authority는 `behind_by=0`, merge base exact protected main이다. #556 merge 뒤 feature lane은 protected `.github`와 `reviewer` owner source를 그대로 승계하고 `docs/product-technical-gap-baseline.md`는 #559에 남겨 두었다. Ordinary/non-force history를 유지하며 force push나 destructive rebase를 쓰지 않는다. +Observed PR #560 exact `273aa711d1c7611fadab9346944891548b30919a`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. Compare authority는 `behind_by=0`, merge base exact protected main이다. #556 merge 뒤 feature lane은 protected `.github`와 `reviewer` owner source를 그대로 승계하고 `docs/product-technical-gap-baseline.md`는 #559에 남겨 두었다. Ordinary/non-force history를 유지하며 force push나 destructive rebase를 쓰지 않는다. Earlier Policy / Approval RED `7ca9aebee6f92053913c0bbc665c8de77650891f`의 hosted application CI `34206149899`, job `101995980303`은 valid catalog/AppGuardrail/quarantine evidence만으로 descriptor가 active/product/role grant를 self-broaden할 수 없음을 고정했다. Subsequent production source separates source/catalog/scanner authority from Noema Policy / Approval issuance, keeps the source-issued grant at a pilot ceiling, seals admission/activation/receipt provenance, revalidates the full six-field catalog identity and live scanner receipts, and rejects impossible pre-activation invocation chronology. @@ -42,7 +42,11 @@ Unbound core-receipt RED `5a50a9bcfe12f3938b30e4a3cb15af8d30134391` then proved Activation-time revocation RED `8ff77d9b6428a2c09f2c72bf3b05fdb989e35843` then proved that policy drift and revocation after admission were not re-read before issuing an activation; the stale admission snapshot could therefore issue a new activation even though invocation would fail later. Production `8251d4bcd2c81dd13d252a576b55dc21e66db9c4` binds the issuing authority with the admitted snapshot and re-resolves it before issuing an activation, rejecting both live-scope drift and revocation. -Current exact-head generation is application CI `34228085116`, reviewer-ci `34228085142`, required Security Scan `34228085293`, and patch-validator-image `34228085478`. These runs are revision-local and predecessor GREEN does not transfer; queued/pending/in-progress status is not merge authority. +Invocation-authority substitution RED `abcd1fea4b28b826826fed6b23296b59ceda98ca` then proved that a structurally matching caller-supplied port could replace the authority bound at admission. Production `f8814b8fd7b66f40335df85c6aadab12aa760bc1` requires the same admission-bound authority instance and performs live policy/catalog/scan mediation through it. `1acbf2f464cbfb0c5ad6e3991ecc9b04f17fb895` preserves genuine same-authority drift/revocation coverage; `feed68db0ac0404607a292ed2686bf47e5e2be22` records the operational boundary and rollback ownership. + +Application CI `34230994573`, job `102076920357` then reached 4,190 passed / 10 failed because older fixtures supplied a second authority after admission. Test repairs `532cfaadf655d3158434db8a1c3a985a33ad3a9f` and `ab2baeda9665df96753a03f1242455efe0662e41` carried the valid same-authority intent, while exact `273aa711d1c7611fadab9346944891548b30919a` removes the hidden mutable `lastAdmissionAuthority` cache and makes every successful invocation fixture reuse its admission authority explicitly. The eight focused external-extension files pass 57 tests with 415/415 statements, 276/276 branches, 59/59 functions, and 387/387 lines covered; typecheck and diff-check are GREEN. + +Current exact-head generation is application CI `34235257622`, reviewer-ci `34235257483`, required Security Scan `34235257642`, and patch-validator-image `34235257516`. These runs are revision-local and predecessor GREEN does not transfer; queued/pending/in-progress status is not merge authority. AppGuardrail/quarantine receipts는 scanner/provenance evidence이지 Noema approval이 아니다. EgressWeave/quarantine references는 outbound/isolation operation의 대체물이 아니다. Anthropic marketplace review는 discovery evidence이지 CWL product authority가 아니다. `context-graph-contracts#27`이 immutable shared external-capability contract를 release하기 전까지 이 local port는 fail-closed ACL/test double이며 live plugin installation 또는 buyer completion을 주장하지 않는다. `context-graph-contracts#27`과 `appguardrail#1099`의 owner evidence를 Noema가 합성하지 않는다. @@ -59,7 +63,7 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge | Priority | Gap | Buyer/operator impact | Current owner | Status | Authoritative completion evidence | Next executable action | | --- | --- | --- | --- | --- | --- | --- | | P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority가 될 위험 | protected #556 + release/consumer lanes | Source integrated; producer/release/consumer open | protected source + execution/research producer + immutable Noema release + released central consumer corpus RED→GREEN | release/producer evidence를 별도 lane에서 완성 | -| P0 | External extension capability admission | third-party plugin metadata, self-asserted grant, stale activation grant, backdated event time, divergent replay 또는 core/public authority confusion이 runtime authority가 될 위험 | issue #545 / PR #560 | Draft; ADR 0015 Proposed; runtime-clock/replay/boundary RED repaired, exact-head gates open | immutable source + independent scan + Noema-issued Policy / Approval grant + activation-time revocation check + public hostile-input normalization + runtime-current expiry enforcement + request-bound idempotency + public invocation-envelope authority + live revalidation + fresh four-GREEN + normal merge + immutable shared contract/live pilot evidence | `8251d4b...` unchanged-head gates와 fresh review를 검증하고 실패 시 해당 causal lane 즉시 수리 | +| P0 | External extension capability admission | third-party plugin metadata, self-asserted grant, stale activation grant, backdated event time, divergent replay 또는 core/public/port authority confusion이 runtime authority가 될 위험 | issue #545 / PR #560 | Draft; ADR 0015 Proposed; runtime-clock/replay/complete-mediation RED repaired, exact-head gates open | immutable source + independent scan + Noema-issued Policy / Approval grant + admission-bound live authority + activation-time revocation check + public hostile-input normalization + runtime-current expiry enforcement + request-bound idempotency + public invocation-envelope authority + live revalidation + fresh four-GREEN + normal merge + immutable shared contract/live pilot evidence | `273aa711...` unchanged-head gates와 fresh review를 검증하고 실패 시 해당 causal lane 즉시 수리 | | P0 | Protected-main governance closure | required Security workflow만으로 PR/review/history/deletion/bypass 통제를 증명했다고 오인할 위험 | issue #27 | Open; external control evidence absent | fresh live ruleset + required PR/review/conversation/history/deletion controls + independent bypass/break-glass evidence + protected-source governance receipt | source가 만들 수 없는 organization/admin control은 issue #27에서 독립 검증 | | P0 | Strict orchestrator/free consumer release | source 통합만으로 immutable consumer activation을 증명할 수 없음 | merged #535 + release lane | Source integrated; release/consumer open | version/tag/package/SBOM/provenance/reproducibility/rollback + released consumer | release-ready protected head에서만 publication | | P0 | Patch-validator operational publication | source/image CI success만으로 reusable immutable runtime을 증명할 수 없음 | issue #66 | Open; publication evidence absent | protected execution + immutable image/signature/SBOM/provenance/reproducibility/rollback | immutable publication evidence와 결합 | diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index 01f05174b..dacfd0433 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -6,9 +6,9 @@ describe("product-technical gap baseline live open-PR authority", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); expect(baseline).toContain("Resulting protected merge는 GitHub-verified `36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`"); - expect(baseline).toContain("Observed PR #560 exact `8251d4bcd2c81dd13d252a576b55dc21e66db9c4`"); + expect(baseline).toContain("Observed PR #560 exact `273aa711d1c7611fadab9346944891548b30919a`"); expect(baseline).toContain("Hosted application CI `34221586992`, job `102045717213`"); - expect(baseline).toContain("application CI `34228085116`"); + expect(baseline).toContain("application CI `34235257622`"); expect(baseline).toContain("Policy / Approval issuance"); expect(baseline).toContain("Production `2b50b35b7bdbb834f571dfcae50dceb05766244c`"); expect(baseline).toContain("runtime wall clock"); @@ -21,11 +21,16 @@ describe("product-technical gap baseline live open-PR authority", () => { expect(baseline).toContain("Activation-time revocation RED `8ff77d9b6428a2c09f2c72bf3b05fdb989e35843`"); expect(baseline).toContain("Production `8251d4bcd2c81dd13d252a576b55dc21e66db9c4`"); expect(baseline).toContain("before issuing an activation"); + expect(baseline).toContain("Invocation-authority substitution RED `abcd1fea4b28b826826fed6b23296b59ceda98ca`"); + expect(baseline).toContain("Production `f8814b8fd7b66f40335df85c6aadab12aa760bc1`"); + expect(baseline).toContain("same admission-bound authority instance"); + expect(baseline).toContain("hidden mutable `lastAdmissionAuthority` cache"); expect(baseline).toContain("ordinary/non-force"); expect(baseline).not.toContain("Observed PR #556 exact"); expect(baseline).not.toContain("Observed PR #560 exact `802b0bff0f32c170ada328b04e87e0db43ee7cd4`"); expect(baseline).not.toContain("application CI `34219296338`"); expect(baseline).not.toContain("Observed PR #560 exact `83ee8e9b54be7ea59cfa11fe03e4ad0c6414950c`"); expect(baseline).not.toContain("Observed PR #560 exact `cbb64def35bad02024076c1db74e9da4739ae736`"); + expect(baseline).not.toContain("Observed PR #560 exact `8251d4bcd2c81dd13d252a576b55dc21e66db9c4`"); }); }); diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index c4ac391a1..4b7abff4a 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -16,6 +16,7 @@ describe("product-technical gap current candidate contract", () => { expect(baseline).toContain("public invocation-envelope authority"); expect(baseline).toContain("policy drift and revocation"); expect(baseline).toContain("before issuing an activation"); + expect(baseline).toContain("admission-bound live authority"); expect(baseline).toContain("PR #560의 ADR 0015는 candidate-only `Proposed`"); expect(baseline).toContain("context-graph-contracts"); expect(baseline).toContain("live plugin installation 또는 buyer completion을 주장하지 않는다"); From 95c44bc54b4970f02792917bf54d3ccbfba82ac3 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 23:18:03 +0900 Subject: [PATCH 55/68] docs: bind commercial gap to exact admission provenance --- docs/product-technical-gap-baseline.md | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index d09f6373b..d18f444e3 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -28,7 +28,7 @@ Protected source는 raw source receipt를 context authority로만 취급하고, ## Active external-extension candidate — issue #545 / PR #560 -Observed PR #560 exact `273aa711d1c7611fadab9346944891548b30919a`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. Compare authority는 `behind_by=0`, merge base exact protected main이다. #556 merge 뒤 feature lane은 protected `.github`와 `reviewer` owner source를 그대로 승계하고 `docs/product-technical-gap-baseline.md`는 #559에 남겨 두었다. Ordinary/non-force history를 유지하며 force push나 destructive rebase를 쓰지 않는다. +Observed PR #560 exact `84a93a2ffcd539df0deb96a9037a31fa863bdcaf`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. Compare authority는 `behind_by=0`, merge base exact protected main이다. #556 merge 뒤 feature lane은 protected `.github`와 `reviewer` owner source를 그대로 승계하고 `docs/product-technical-gap-baseline.md`는 #559에 남겨 두었다. Ordinary/non-force history를 유지하며 force push나 destructive rebase를 쓰지 않는다. Earlier Policy / Approval RED `7ca9aebee6f92053913c0bbc665c8de77650891f`의 hosted application CI `34206149899`, job `101995980303`은 valid catalog/AppGuardrail/quarantine evidence만으로 descriptor가 active/product/role grant를 self-broaden할 수 없음을 고정했다. Subsequent production source separates source/catalog/scanner authority from Noema Policy / Approval issuance, keeps the source-issued grant at a pilot ceiling, seals admission/activation/receipt provenance, revalidates the full six-field catalog identity and live scanner receipts, and rejects impossible pre-activation invocation chronology. @@ -44,9 +44,11 @@ Activation-time revocation RED `8ff77d9b6428a2c09f2c72bf3b05fdb989e35843` then p Invocation-authority substitution RED `abcd1fea4b28b826826fed6b23296b59ceda98ca` then proved that a structurally matching caller-supplied port could replace the authority bound at admission. Production `f8814b8fd7b66f40335df85c6aadab12aa760bc1` requires the same admission-bound authority instance and performs live policy/catalog/scan mediation through it. `1acbf2f464cbfb0c5ad6e3991ecc9b04f17fb895` preserves genuine same-authority drift/revocation coverage; `feed68db0ac0404607a292ed2686bf47e5e2be22` records the operational boundary and rollback ownership. -Application CI `34230994573`, job `102076920357` then reached 4,190 passed / 10 failed because older fixtures supplied a second authority after admission. Test repairs `532cfaadf655d3158434db8a1c3a985a33ad3a9f` and `ab2baeda9665df96753a03f1242455efe0662e41` carried the valid same-authority intent, while exact `273aa711d1c7611fadab9346944891548b30919a` removes the hidden mutable `lastAdmissionAuthority` cache and makes every successful invocation fixture reuse its admission authority explicitly. The eight focused external-extension files pass 57 tests with 415/415 statements, 276/276 branches, 59/59 functions, and 387/387 lines covered; typecheck and diff-check are GREEN. +Application CI `34230994573`, job `102076920357` then reached 4,190 passed / 10 failed because older fixtures supplied a second authority after admission. Test repairs `532cfaadf655d3158434db8a1c3a985a33ad3a9f` and `ab2baeda9665df96753a03f1242455efe0662e41` carried the valid same-authority intent, while exact `273aa711d1c7611fadab9346944891548b30919a` removes the hidden mutable `lastAdmissionAuthority` cache and makes every successful invocation fixture reuse its admission authority explicitly. -Current exact-head generation is application CI `34235257622`, reviewer-ci `34235257483`, required Security Scan `34235257642`, and patch-validator-image `34235257516`. These runs are revision-local and predecessor GREEN does not transfer; queued/pending/in-progress status is not merge authority. +Exact-admission provenance RED `0a32ee0a88378931a07b7e3b61cc31e3b494a7ab` then proved that an authentic activation issued for source admission A could be reused for source admission B when the same trusted authority moved to B and artifact/product/role/policy/time fields still matched. Hosted application CI `34235691056`, job `102092675348` passed exact checkout, live-base guard, lockfile control, install and release typecheck, then failed in release tests. Test-only `49115306b4abf7656f7fd136de8a3ff0c5a1968b` extends the same contract to retained activation replay and public invocation-receipt replay. Production `84a93a2ffcd539df0deb96a9037a31fa863bdcaf` binds issued/replayed activations and public invocation receipts to the exact `AdmittedExternalExtension`, while retaining admission-bound live authority, runtime-current expiry and request-envelope replay checks. The same invariant has been handed to `context-graph-contracts#27` as a future released conformance requirement; Noema does not consume that mutable issue as runtime authority. + +Current exact-head generation is application CI `34236657166`, reviewer-ci `34236657218`, required Security Scan `34236657219`, and patch-validator-image `34236657149`. These runs are revision-local and predecessor GREEN does not transfer; queued/pending/in-progress status is not merge authority. AppGuardrail/quarantine receipts는 scanner/provenance evidence이지 Noema approval이 아니다. EgressWeave/quarantine references는 outbound/isolation operation의 대체물이 아니다. Anthropic marketplace review는 discovery evidence이지 CWL product authority가 아니다. `context-graph-contracts#27`이 immutable shared external-capability contract를 release하기 전까지 이 local port는 fail-closed ACL/test double이며 live plugin installation 또는 buyer completion을 주장하지 않는다. `context-graph-contracts#27`과 `appguardrail#1099`의 owner evidence를 Noema가 합성하지 않는다. @@ -63,7 +65,7 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge | Priority | Gap | Buyer/operator impact | Current owner | Status | Authoritative completion evidence | Next executable action | | --- | --- | --- | --- | --- | --- | --- | | P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority가 될 위험 | protected #556 + release/consumer lanes | Source integrated; producer/release/consumer open | protected source + execution/research producer + immutable Noema release + released central consumer corpus RED→GREEN | release/producer evidence를 별도 lane에서 완성 | -| P0 | External extension capability admission | third-party plugin metadata, self-asserted grant, stale activation grant, backdated event time, divergent replay 또는 core/public/port authority confusion이 runtime authority가 될 위험 | issue #545 / PR #560 | Draft; ADR 0015 Proposed; runtime-clock/replay/complete-mediation RED repaired, exact-head gates open | immutable source + independent scan + Noema-issued Policy / Approval grant + admission-bound live authority + activation-time revocation check + public hostile-input normalization + runtime-current expiry enforcement + request-bound idempotency + public invocation-envelope authority + live revalidation + fresh four-GREEN + normal merge + immutable shared contract/live pilot evidence | `273aa711...` unchanged-head gates와 fresh review를 검증하고 실패 시 해당 causal lane 즉시 수리 | +| P0 | External extension capability admission | third-party plugin metadata, self-asserted grant, stale/cross-admission activation, backdated event time, divergent replay 또는 core/public/port authority confusion이 runtime authority가 될 위험 | issue #545 / PR #560 | Draft; ADR 0015 Proposed; runtime-clock/replay/complete-mediation/exact-admission RED repaired, exact-head gates open | immutable source + independent scan + Noema-issued Policy / Approval grant + admission-bound live authority + exact-admission activation/receipt authority + activation-time revocation check + public hostile-input normalization + runtime-current expiry enforcement + request-bound idempotency + public invocation-envelope authority + live revalidation + fresh four-GREEN + normal merge + immutable shared contract/live pilot evidence | `84a93a2f...` unchanged-head gates와 fresh review를 검증하고 실패 시 해당 causal lane 즉시 수리 | | P0 | Protected-main governance closure | required Security workflow만으로 PR/review/history/deletion/bypass 통제를 증명했다고 오인할 위험 | issue #27 | Open; external control evidence absent | fresh live ruleset + required PR/review/conversation/history/deletion controls + independent bypass/break-glass evidence + protected-source governance receipt | source가 만들 수 없는 organization/admin control은 issue #27에서 독립 검증 | | P0 | Strict orchestrator/free consumer release | source 통합만으로 immutable consumer activation을 증명할 수 없음 | merged #535 + release lane | Source integrated; release/consumer open | version/tag/package/SBOM/provenance/reproducibility/rollback + released consumer | release-ready protected head에서만 publication | | P0 | Patch-validator operational publication | source/image CI success만으로 reusable immutable runtime을 증명할 수 없음 | issue #66 | Open; publication evidence absent | protected execution + immutable image/signature/SBOM/provenance/reproducibility/rollback | immutable publication evidence와 결합 | From 458d82670e4e40fb695c2978474424cb5bc26ded Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 23:18:29 +0900 Subject: [PATCH 56/68] test(docs): require exact-admission candidate authority --- test/documentation-live-open-pr-authority.test.ts | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index dacfd0433..cccf7a372 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -6,9 +6,9 @@ describe("product-technical gap baseline live open-PR authority", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); expect(baseline).toContain("Resulting protected merge는 GitHub-verified `36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`"); - expect(baseline).toContain("Observed PR #560 exact `273aa711d1c7611fadab9346944891548b30919a`"); + expect(baseline).toContain("Observed PR #560 exact `84a93a2ffcd539df0deb96a9037a31fa863bdcaf`"); expect(baseline).toContain("Hosted application CI `34221586992`, job `102045717213`"); - expect(baseline).toContain("application CI `34235257622`"); + expect(baseline).toContain("application CI `34236657166`"); expect(baseline).toContain("Policy / Approval issuance"); expect(baseline).toContain("Production `2b50b35b7bdbb834f571dfcae50dceb05766244c`"); expect(baseline).toContain("runtime wall clock"); @@ -25,6 +25,11 @@ describe("product-technical gap baseline live open-PR authority", () => { expect(baseline).toContain("Production `f8814b8fd7b66f40335df85c6aadab12aa760bc1`"); expect(baseline).toContain("same admission-bound authority instance"); expect(baseline).toContain("hidden mutable `lastAdmissionAuthority` cache"); + expect(baseline).toContain("Exact-admission provenance RED `0a32ee0a88378931a07b7e3b61cc31e3b494a7ab`"); + expect(baseline).toContain("Hosted application CI `34235691056`, job `102092675348`"); + expect(baseline).toContain("Test-only `49115306b4abf7656f7fd136de8a3ff0c5a1968b`"); + expect(baseline).toContain("Production `84a93a2ffcd539df0deb96a9037a31fa863bdcaf`"); + expect(baseline).toContain("exact `AdmittedExternalExtension`"); expect(baseline).toContain("ordinary/non-force"); expect(baseline).not.toContain("Observed PR #556 exact"); expect(baseline).not.toContain("Observed PR #560 exact `802b0bff0f32c170ada328b04e87e0db43ee7cd4`"); @@ -32,5 +37,6 @@ describe("product-technical gap baseline live open-PR authority", () => { expect(baseline).not.toContain("Observed PR #560 exact `83ee8e9b54be7ea59cfa11fe03e4ad0c6414950c`"); expect(baseline).not.toContain("Observed PR #560 exact `cbb64def35bad02024076c1db74e9da4739ae736`"); expect(baseline).not.toContain("Observed PR #560 exact `8251d4bcd2c81dd13d252a576b55dc21e66db9c4`"); + expect(baseline).not.toContain("Observed PR #560 exact `273aa711d1c7611fadab9346944891548b30919a`"); }); }); From 4b6f4f4e64644bb9d06ad16027f9a8f2cb136ca8 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 23:18:42 +0900 Subject: [PATCH 57/68] test(docs): bind candidate contract to exact admission --- test/product-technical-gap-current-candidate-contract.test.ts | 2 ++ 1 file changed, 2 insertions(+) diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index 4b7abff4a..ed1f92b65 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -17,6 +17,8 @@ describe("product-technical gap current candidate contract", () => { expect(baseline).toContain("policy drift and revocation"); expect(baseline).toContain("before issuing an activation"); expect(baseline).toContain("admission-bound live authority"); + expect(baseline).toContain("Exact-admission provenance RED"); + expect(baseline).toContain("exact-admission activation/receipt authority"); expect(baseline).toContain("PR #560의 ADR 0015는 candidate-only `Proposed`"); expect(baseline).toContain("context-graph-contracts"); expect(baseline).toContain("live plugin installation 또는 buyer completion을 주장하지 않는다"); From f4807d71ae815a5d79a08ef35628d72bb4ad34b9 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Tue, 8 Sep 2026 23:55:44 +0900 Subject: [PATCH 58/68] docs: track crypto-provider RED authority --- docs/product-technical-gap-baseline.md | 22 ++++++++++------------ 1 file changed, 10 insertions(+), 12 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index d18f444e3..09be19373 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -28,27 +28,25 @@ Protected source는 raw source receipt를 context authority로만 취급하고, ## Active external-extension candidate — issue #545 / PR #560 -Observed PR #560 exact `84a93a2ffcd539df0deb96a9037a31fa863bdcaf`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. Compare authority는 `behind_by=0`, merge base exact protected main이다. #556 merge 뒤 feature lane은 protected `.github`와 `reviewer` owner source를 그대로 승계하고 `docs/product-technical-gap-baseline.md`는 #559에 남겨 두었다. Ordinary/non-force history를 유지하며 force push나 destructive rebase를 쓰지 않는다. +Observed PR #560 exact `b50b43065098609118991e0b0b0b4936725c2899`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. 이 exact head는 cryptographic-provider finding을 현실 RED로 만들기 위한 test-only revision이다. Compare authority는 protected main ancestry를 유지하며 ordinary/non-force history만 사용한다. #556 merge 뒤 feature lane은 protected `.github`와 `reviewer` owner source를 그대로 승계하고 `docs/product-technical-gap-baseline.md`는 #559에 남겨 두었다. Earlier Policy / Approval RED `7ca9aebee6f92053913c0bbc665c8de77650891f`의 hosted application CI `34206149899`, job `101995980303`은 valid catalog/AppGuardrail/quarantine evidence만으로 descriptor가 active/product/role grant를 self-broaden할 수 없음을 고정했다. Subsequent production source separates source/catalog/scanner authority from Noema Policy / Approval issuance, keeps the source-issued grant at a pilot ceiling, seals admission/activation/receipt provenance, revalidates the full six-field catalog identity and live scanner receipts, and rejects impossible pre-activation invocation chronology. Fresh hostile-input RED `f30f67328efbcd0b8bed7ac89f7c64c40528ea44` / hosted application CI `34218780676`, job `102036728526` proved that a revoked descriptor-list Proxy could leak a raw JavaScript exception through public admission. Production `802b0bff0f32c170ada328b04e87e0db43ee7cd4` normalized that public boundary without weakening descriptor/list/capability validation. -Fresh Tool / Capability review then found a distinct expiry-authority gap: `activated_at` and `invoked_at` are caller event timestamps, so comparing the validity window only against those fields allowed a caller to backdate an operation after actual expiry. Test-only exact `4be371ec08b852f4d00829ba5aa6936df6564b5e` advances the runtime clock beyond `valid_to` while retaining an in-window event timestamp. Hosted application CI `34221586992`, job `102045717213` passed exact checkout, live-base guard, lockfile control, install and release typecheck, then failed at release tests: this is the current causal RED. Production `2b50b35b7bdbb834f571dfcae50dceb05766244c` requires the Noema runtime wall clock to remain inside both the admitted descriptor and independently issued Policy / Approval validity windows for activation and invocation. Exact `83e3130f1894e879769e014c76e28ffc982a2063` covers the pre-window edge; `f8703e6628961d380df59e4e90b600ebad215c11` records the authority distinction in ADR 0015, which remains `Proposed`. +Runtime-current authority RED `4be371ec08b852f4d00829ba5aa6936df6564b5e`의 hosted application CI `34221586992`, job `102045717213`은 caller event timestamp를 backdate해 실제 만료 뒤 권한을 계속 행사할 수 있던 결함을 재현했다. Production `2b50b35b7bdbb834f571dfcae50dceb05766244c`는 activation/invocation 때 Noema runtime wall clock이 descriptor와 독립 Policy / Approval validity window 모두 안에 있도록 요구한다. `83e3130f1894e879769e014c76e28ffc982a2063`은 pre-window edge를 고정했고 `f8703e6628961d380df59e4e90b600ebad215c11`은 ADR 0015에 event-time과 current-time authority를 분리했다. -Test-only replay RED `cb8ad638875b761aea70aba78a480bd5031c4d7d` then proved that a retained receipt omitted instruction and observed-content semantics, allowing the same invocation identity to request different work. Production `9c7ae13f7053fa368fd778c3909c4428d1bdf28e` binds replay to the exact normalized invocation envelope. Refactor `03c2a6949a858043c6f7412a9ee724de63deaae2` made the public check GREEN but rendered the internal conflicting-receipt oracle unexecuted; Coverage repair `83ee8e9b54be7ea59cfa11fe03e4ad0c6414950c` restores that core assertion without changing production behavior. +Replay semantic RED `cb8ad638875b761aea70aba78a480bd5031c4d7d`는 동일 invocation identity가 다른 instruction/observed-content semantics를 요청해도 retained receipt가 허용하던 결함을 증명했다. Production `9c7ae13f7053fa368fd778c3909c4428d1bdf28e`는 replay를 complete normalized invocation envelope에 결합했다. Refactor `03c2a6949a858043c6f7412a9ee724de63deaae2` 뒤 vacuous해진 core-conflict oracle은 `83ee8e9b54be7ea59cfa11fe03e4ad0c6414950c`에서 direct core coverage로 복구됐다. -Unbound core-receipt RED `5a50a9bcfe12f3938b30e4a3cb15af8d30134391` then proved that an authentic receipt issued through the internal core could cross the public wrapper without public invocation-envelope authority. The missing `WeakMap` binding let the core receipt authority stand in for semantic replay authority and accept different instruction text under the same invocation identity. Production `cbb64def35bad02024076c1db74e9da4739ae736` fails closed when the retained receipt lacks that public binding, while direct core and public boundary assertions keep both authority checks executable. +Unbound core-receipt RED `5a50a9bcfe12f3938b30e4a3cb15af8d30134391`는 internal core가 발행한 authentic receipt가 public wrapper의 invocation-envelope authority 없이 넘어갈 수 있음을 증명했다. Production `cbb64def35bad02024076c1db74e9da4739ae736`은 public binding이 없는 retained receipt를 fail closed한다. Activation-time revocation RED `8ff77d9b6428a2c09f2c72bf3b05fdb989e35843`와 production `8251d4bcd2c81dd13d252a576b55dc21e66db9c4`는 admission 뒤 policy drift/revocation을 새 activation 발행 전에 다시 읽도록 했다. -Activation-time revocation RED `8ff77d9b6428a2c09f2c72bf3b05fdb989e35843` then proved that policy drift and revocation after admission were not re-read before issuing an activation; the stale admission snapshot could therefore issue a new activation even though invocation would fail later. Production `8251d4bcd2c81dd13d252a576b55dc21e66db9c4` binds the issuing authority with the admitted snapshot and re-resolves it before issuing an activation, rejecting both live-scope drift and revocation. +Invocation-authority substitution RED `abcd1fea4b28b826826fed6b23296b59ceda98ca`는 structurally compatible caller-supplied authority가 admission-bound authority를 대체할 수 있음을 증명했다. Production `f8814b8fd7b66f40335df85c6aadab12aa760bc1`는 invocation에 admission 당시 결합한 동일 authority instance를 요구한다. `1acbf2f464cbfb0c5ad6e3991ecc9b04f17fb895`는 same-authority catalog/scan drift를 유지했고 `feed68db0ac0404607a292ed2686bf47e5e2be22`는 운영/rollback owner 경계를 갱신했다. Hosted application CI `34230994573`, job `102076920357`이 4,190 passed / 10 failed로 드러낸 stale fixture는 `532cfaadf655d3158434db8a1c3a985a33ad3a9f`, `ab2baeda9665df96753a03f1242455efe0662e41`, `273aa711d1c7611fadab9346944891548b30919a`에서 same-authority intent를 유지하면서 mutable test cache를 제거했다. -Invocation-authority substitution RED `abcd1fea4b28b826826fed6b23296b59ceda98ca` then proved that a structurally matching caller-supplied port could replace the authority bound at admission. Production `f8814b8fd7b66f40335df85c6aadab12aa760bc1` requires the same admission-bound authority instance and performs live policy/catalog/scan mediation through it. `1acbf2f464cbfb0c5ad6e3991ecc9b04f17fb895` preserves genuine same-authority drift/revocation coverage; `feed68db0ac0404607a292ed2686bf47e5e2be22` records the operational boundary and rollback ownership. +Exact-admission provenance RED `0a32ee0a88378931a07b7e3b61cc31e3b494a7ab`는 source admission A에서 발행한 authentic activation이 동일 trusted authority가 source B로 이동한 뒤에도 artifact/product/role/policy/time이 맞으면 B를 authorize할 수 있던 결함을 재현했다. Hosted application CI `34235691056`, job `102092675348`은 exact checkout/live-base/lockfile/install/typecheck 뒤 release tests에서 실패했다. Test-only `49115306b4abf7656f7fd136de8a3ff0c5a1968b`은 retained activation replay와 public invocation-receipt replay까지 확장했다. Canonical production `225a04ec2c833e9068e79ad7b70f3f5d8f6d934a`는 core의 activation/receipt provenance를 process-global set에서 exact `AdmittedExternalExtension`-bound map으로 옮겼고, `2e843825cc31a316a5834db3d355e8e4a18ca028`은 public wrapper에 잠시 중복됐던 binding kernel을 제거해 exact-admission authority를 core 한 곳에 남겼다. 같은 conformance invariant는 `context-graph-contracts#27`에 foreign-owner requirement로 넘겼고 mutable issue/branch를 Noema runtime dependency로 소비하지 않는다. -Application CI `34230994573`, job `102076920357` then reached 4,190 passed / 10 failed because older fixtures supplied a second authority after admission. Test repairs `532cfaadf655d3158434db8a1c3a985a33ad3a9f` and `ab2baeda9665df96753a03f1242455efe0662e41` carried the valid same-authority intent, while exact `273aa711d1c7611fadab9346944891548b30919a` removes the hidden mutable `lastAdmissionAuthority` cache and makes every successful invocation fixture reuse its admission authority explicitly. +Plaintext replay-retention RED `3f41d94af1454926b65b1801004fe245098742b0`는 public replay WeakMap이 reversible `JSON.stringify(normalizedRequest)`를 receipt lifetime 동안 보유해 instruction, observed content, rejected secret/product/hidden-reasoning inputs의 수명을 불필요하게 늘리던 결함을 고정했다. Hosted application CI `34237704683`, job `102099615873`은 exact checkout/live-base/lockfile/install/release typecheck 뒤 release tests에서 실패했다. Production `79182c7be196c42fb94450cae9a7857ae67b5434`는 retained replay identity를 versioned/domain-separated SHA-256 digest로 바꾸고 every semantic field, key-order independence, fixed-width/no-plaintext regression을 추가했다. ADR `ac6b6c088f034a8778bdc8a859f7157223883b8d`는 process-local WeakMap lifetime, restart fail-closed, explicit digest-version migration과 FIPS 180-4 authority를 기록하며 `Proposed`를 유지한다. -Exact-admission provenance RED `0a32ee0a88378931a07b7e3b61cc31e3b494a7ab` then proved that an authentic activation issued for source admission A could be reused for source admission B when the same trusted authority moved to B and artifact/product/role/policy/time fields still matched. Hosted application CI `34235691056`, job `102092675348` passed exact checkout, live-base guard, lockfile control, install and release typecheck, then failed in release tests. Test-only `49115306b4abf7656f7fd136de8a3ff0c5a1968b` extends the same contract to retained activation replay and public invocation-receipt replay. Production `84a93a2ffcd539df0deb96a9037a31fa863bdcaf` binds issued/replayed activations and public invocation receipts to the exact `AdmittedExternalExtension`, while retaining admission-bound live authority, runtime-current expiry and request-envelope replay checks. The same invariant has been handed to `context-graph-contracts#27` as a future released conformance requirement; Noema does not consume that mutable issue as runtime authority. - -Current exact-head generation is application CI `34236657166`, reviewer-ci `34236657218`, required Security Scan `34236657219`, and patch-validator-image `34236657149`. These runs are revision-local and predecessor GREEN does not transfer; queued/pending/in-progress status is not merge authority. +그 뒤 live security finding `5586918828`은 `ac6b6c0...`이 SHA-256 padding/schedule/rounds를 repository-owned TypeScript로 직접 구현한 점을 새 merge blocker로 분리했다. 방향인 digest-only retention은 유효하지만 새 security-critical primitive를 단일 local vector로 정당화할 수 없으므로 platform Web Crypto 또는 independently maintained/audited immutable implementation이 필요하다. Current test-only exact `b50b43065098609118991e0b0b0b4936725c2899`은 platform `crypto.subtle.digest` 또는 exact-pinned `@noble/hashes@2.4.0` 중 하나를 요구하고 `SHA256_INITIAL`, `SHA256_ROUND`, local `sha256Hex` ownership을 금지한다. Current generation은 application CI `34240985563`, reviewer-ci `34240985515`, required Security Scan `34240985513`, patch-validator-image `34240985555`이며 모두 아직 nonterminal이다. Hosted RED가 실제 발생하기 전에는 production provider repair를 주장하지 않는다. AppGuardrail/quarantine receipts는 scanner/provenance evidence이지 Noema approval이 아니다. EgressWeave/quarantine references는 outbound/isolation operation의 대체물이 아니다. Anthropic marketplace review는 discovery evidence이지 CWL product authority가 아니다. `context-graph-contracts#27`이 immutable shared external-capability contract를 release하기 전까지 이 local port는 fail-closed ACL/test double이며 live plugin installation 또는 buyer completion을 주장하지 않는다. `context-graph-contracts#27`과 `appguardrail#1099`의 owner evidence를 Noema가 합성하지 않는다. @@ -65,10 +63,10 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge | Priority | Gap | Buyer/operator impact | Current owner | Status | Authoritative completion evidence | Next executable action | | --- | --- | --- | --- | --- | --- | --- | | P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority가 될 위험 | protected #556 + release/consumer lanes | Source integrated; producer/release/consumer open | protected source + execution/research producer + immutable Noema release + released central consumer corpus RED→GREEN | release/producer evidence를 별도 lane에서 완성 | -| P0 | External extension capability admission | third-party plugin metadata, self-asserted grant, stale/cross-admission activation, backdated event time, divergent replay 또는 core/public/port authority confusion이 runtime authority가 될 위험 | issue #545 / PR #560 | Draft; ADR 0015 Proposed; runtime-clock/replay/complete-mediation/exact-admission RED repaired, exact-head gates open | immutable source + independent scan + Noema-issued Policy / Approval grant + admission-bound live authority + exact-admission activation/receipt authority + activation-time revocation check + public hostile-input normalization + runtime-current expiry enforcement + request-bound idempotency + public invocation-envelope authority + live revalidation + fresh four-GREEN + normal merge + immutable shared contract/live pilot evidence | `84a93a2f...` unchanged-head gates와 fresh review를 검증하고 실패 시 해당 causal lane 즉시 수리 | +| P0 | External extension capability admission | third-party plugin metadata, self-asserted grant, stale/cross-admission activation, backdated event time, divergent replay, plaintext replay retention 또는 home-grown crypto가 runtime authority가 될 위험 | issue #545 / PR #560 | Draft; ADR 0015 Proposed; runtime/replay/complete-mediation/exact-admission/plaintext RED repaired; crypto-provider RED candidate queued | immutable source + independent scan + Noema-issued Policy / Approval + admission-bound live authority + exact-admission activation/receipt authority + runtime-current expiry + digest-only replay + platform/audited SHA-256 + NIST conformance + fresh four-GREEN + normal merge + immutable shared contract/live pilot | `b50b4306...` hosted RED를 보존한 뒤 최소 provider repair→fresh unchanged-head gates | | P0 | Protected-main governance closure | required Security workflow만으로 PR/review/history/deletion/bypass 통제를 증명했다고 오인할 위험 | issue #27 | Open; external control evidence absent | fresh live ruleset + required PR/review/conversation/history/deletion controls + independent bypass/break-glass evidence + protected-source governance receipt | source가 만들 수 없는 organization/admin control은 issue #27에서 독립 검증 | | P0 | Strict orchestrator/free consumer release | source 통합만으로 immutable consumer activation을 증명할 수 없음 | merged #535 + release lane | Source integrated; release/consumer open | version/tag/package/SBOM/provenance/reproducibility/rollback + released consumer | release-ready protected head에서만 publication | -| P0 | Patch-validator operational publication | source/image CI success만으로 reusable immutable runtime을 증명할 수 없음 | issue #66 | Open; publication evidence absent | protected execution + immutable image/signature/SBOM/provenance/reproducibility/rollback | immutable publication evidence와 결합 | +| P0 | Patch-validator operational publication | source/image CI success만으로 reusable immutable runtime을 증명할 수 없음 | issue #66 | Open; publication evidence absent | protected execution + immutable image/signature/SBOM/provenance/reproducibility/rollback | merged #556의 1h59m24s build를 cache-hit/miss로 추정하지 말고 explicit BuildKit cache-reuse evidence를 추가 | | P0 | Authentic production KPI evidence | fixture·synthetic 또는 source-level KPI 검증이 실제 운영 성능을 대체할 위험 | issue #3 | Open; production window absent | authenticated production-window records + strict provenance + buyer-relevant KPI gate | 실제 production evidence 없이는 readiness를 승격하지 않음 | | P0 | Acquisition coordination | source/docs 완료를 buyer·legal·transfer readiness로 잘못 승격할 위험 | issue #5 | Open; evidence families incomplete | exact protected revision + applicable release/deployment/operational/buyer/legal evidence family | 남은 evidence family를 owner별로 수렴하고 source claim과 분리 | | P0 | External Maintainer/Reviewer App identity | source capability-file 계약이 실제 App 설치·키 custody·rotation·권한·reviewer identity를 대체할 위험 | issues #29 / #227 | Open; live identity evidence absent | live installation + key custody/rotation + repository permission + eligible reviewer/publication identity evidence | 외부 App authority는 해당 issue owner에서 독립 검증 | From a1929bbb07aed28f9bb85cccdddc17cbf1414f85 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 00:34:42 +0900 Subject: [PATCH 59/68] test(docs): bind external-extension authority to Web Crypto repair --- ...hnical-gap-current-candidate-contract.test.ts | 16 ++++++++++------ 1 file changed, 10 insertions(+), 6 deletions(-) diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index ed1f92b65..41a993777 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -6,19 +6,23 @@ describe("product-technical gap current candidate contract", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); expect(baseline).toContain("issue #545 / PR #560"); - expect(baseline).toContain("Test-only exact `4be371ec08b852f4d00829ba5aa6936df6564b5e`"); + expect(baseline).toContain("Runtime-current authority RED `4be371ec08b852f4d00829ba5aa6936df6564b5e`"); expect(baseline).toContain("Hosted application CI `34221586992`, job `102045717213`"); expect(baseline).toContain("Noema Policy / Approval issuance"); expect(baseline).toContain("runtime wall clock"); - expect(baseline).toContain("same invocation identity"); + expect(baseline).toContain("Replay semantic RED `cb8ad638875b761aea70aba78a480bd5031c4d7d`"); expect(baseline).toContain("normalized invocation envelope"); - expect(baseline).toContain("core receipt authority"); + expect(baseline).toContain("Unbound core-receipt RED `5a50a9bcfe12f3938b30e4a3cb15af8d30134391`"); expect(baseline).toContain("public invocation-envelope authority"); - expect(baseline).toContain("policy drift and revocation"); - expect(baseline).toContain("before issuing an activation"); + expect(baseline).toContain("policy drift/revocation"); expect(baseline).toContain("admission-bound live authority"); expect(baseline).toContain("Exact-admission provenance RED"); - expect(baseline).toContain("exact-admission activation/receipt authority"); + expect(baseline).toContain("Plaintext replay-retention RED"); + expect(baseline).toContain("`b50b43065098609118991e0b0b0b4936725c2899`"); + expect(baseline).toContain("`34240985563`, job `102111324942`"); + expect(baseline).toContain("Worker Web Crypto"); + expect(baseline).toContain("`80292ed53943c61aa9d282ed18024b0f98f4cb1f`"); + expect(baseline).toContain("`396514c8f5183324e6c8d0a16d7a5d339b2cbb72`"); expect(baseline).toContain("PR #560의 ADR 0015는 candidate-only `Proposed`"); expect(baseline).toContain("context-graph-contracts"); expect(baseline).toContain("live plugin installation 또는 buyer completion을 주장하지 않는다"); From ec5b17673078ee070feea22fd89739d97577c72a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 00:36:03 +0900 Subject: [PATCH 60/68] docs: converge external-extension Web Crypto authority --- docs/product-technical-gap-baseline.md | 18 ++++++++++++------ 1 file changed, 12 insertions(+), 6 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 09be19373..5d83ac180 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -28,25 +28,29 @@ Protected source는 raw source receipt를 context authority로만 취급하고, ## Active external-extension candidate — issue #545 / PR #560 -Observed PR #560 exact `b50b43065098609118991e0b0b0b4936725c2899`는 Draft이며 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`을 base로 한다. 이 exact head는 cryptographic-provider finding을 현실 RED로 만들기 위한 test-only revision이다. Compare authority는 protected main ancestry를 유지하며 ordinary/non-force history만 사용한다. #556 merge 뒤 feature lane은 protected `.github`와 `reviewer` owner source를 그대로 승계하고 `docs/product-technical-gap-baseline.md`는 #559에 남겨 두었다. +이 문서를 수렴시킬 때 관찰한 PR #560 exact는 `26634f181f9c29e875bdd57ab5bc046b109fd91b`이며 Draft, base는 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`이다. 이 SHA는 moving observation이지 future merge authority가 아니다. Feature lane은 protected `.github`와 `reviewer` owner source를 그대로 승계하고 `docs/product-technical-gap-baseline.md`는 #559에 남겨 둔다. Ordinary/non-force history를 유지하며 force push나 destructive rebase를 쓰지 않는다. Earlier Policy / Approval RED `7ca9aebee6f92053913c0bbc665c8de77650891f`의 hosted application CI `34206149899`, job `101995980303`은 valid catalog/AppGuardrail/quarantine evidence만으로 descriptor가 active/product/role grant를 self-broaden할 수 없음을 고정했다. Subsequent production source separates source/catalog/scanner authority from Noema Policy / Approval issuance, keeps the source-issued grant at a pilot ceiling, seals admission/activation/receipt provenance, revalidates the full six-field catalog identity and live scanner receipts, and rejects impossible pre-activation invocation chronology. Fresh hostile-input RED `f30f67328efbcd0b8bed7ac89f7c64c40528ea44` / hosted application CI `34218780676`, job `102036728526` proved that a revoked descriptor-list Proxy could leak a raw JavaScript exception through public admission. Production `802b0bff0f32c170ada328b04e87e0db43ee7cd4` normalized that public boundary without weakening descriptor/list/capability validation. -Runtime-current authority RED `4be371ec08b852f4d00829ba5aa6936df6564b5e`의 hosted application CI `34221586992`, job `102045717213`은 caller event timestamp를 backdate해 실제 만료 뒤 권한을 계속 행사할 수 있던 결함을 재현했다. Production `2b50b35b7bdbb834f571dfcae50dceb05766244c`는 activation/invocation 때 Noema runtime wall clock이 descriptor와 독립 Policy / Approval validity window 모두 안에 있도록 요구한다. `83e3130f1894e879769e014c76e28ffc982a2063`은 pre-window edge를 고정했고 `f8703e6628961d380df59e4e90b600ebad215c11`은 ADR 0015에 event-time과 current-time authority를 분리했다. +Runtime-current authority RED `4be371ec08b852f4d00829ba5aa6936df6564b5e`의 Hosted application CI `34221586992`, job `102045717213`은 caller event timestamp를 backdate해 실제 만료 뒤 권한을 계속 행사할 수 있던 결함을 재현했다. Production `2b50b35b7bdbb834f571dfcae50dceb05766244c`는 activation/invocation 때 Noema runtime wall clock이 descriptor와 독립 Policy / Approval validity window 모두 안에 있도록 요구한다. `83e3130f1894e879769e014c76e28ffc982a2063`은 pre-window edge를 고정했고 `f8703e6628961d380df59e4e90b600ebad215c11`은 ADR 0015에 event-time과 current-time authority를 분리했다. Replay semantic RED `cb8ad638875b761aea70aba78a480bd5031c4d7d`는 동일 invocation identity가 다른 instruction/observed-content semantics를 요청해도 retained receipt가 허용하던 결함을 증명했다. Production `9c7ae13f7053fa368fd778c3909c4428d1bdf28e`는 replay를 complete normalized invocation envelope에 결합했다. Refactor `03c2a6949a858043c6f7412a9ee724de63deaae2` 뒤 vacuous해진 core-conflict oracle은 `83ee8e9b54be7ea59cfa11fe03e4ad0c6414950c`에서 direct core coverage로 복구됐다. Unbound core-receipt RED `5a50a9bcfe12f3938b30e4a3cb15af8d30134391`는 internal core가 발행한 authentic receipt가 public wrapper의 invocation-envelope authority 없이 넘어갈 수 있음을 증명했다. Production `cbb64def35bad02024076c1db74e9da4739ae736`은 public binding이 없는 retained receipt를 fail closed한다. Activation-time revocation RED `8ff77d9b6428a2c09f2c72bf3b05fdb989e35843`와 production `8251d4bcd2c81dd13d252a576b55dc21e66db9c4`는 admission 뒤 policy drift/revocation을 새 activation 발행 전에 다시 읽도록 했다. -Invocation-authority substitution RED `abcd1fea4b28b826826fed6b23296b59ceda98ca`는 structurally compatible caller-supplied authority가 admission-bound authority를 대체할 수 있음을 증명했다. Production `f8814b8fd7b66f40335df85c6aadab12aa760bc1`는 invocation에 admission 당시 결합한 동일 authority instance를 요구한다. `1acbf2f464cbfb0c5ad6e3991ecc9b04f17fb895`는 same-authority catalog/scan drift를 유지했고 `feed68db0ac0404607a292ed2686bf47e5e2be22`는 운영/rollback owner 경계를 갱신했다. Hosted application CI `34230994573`, job `102076920357`이 4,190 passed / 10 failed로 드러낸 stale fixture는 `532cfaadf655d3158434db8a1c3a985a33ad3a9f`, `ab2baeda9665df96753a03f1242455efe0662e41`, `273aa711d1c7611fadab9346944891548b30919a`에서 same-authority intent를 유지하면서 mutable test cache를 제거했다. +Invocation-authority substitution RED `abcd1fea4b28b826826fed6b23296b59ceda98ca`는 structurally compatible caller-supplied authority가 admission-bound live authority를 대체할 수 있음을 증명했다. Production `f8814b8fd7b66f40335df85c6aadab12aa760bc1`는 invocation에 admission 당시 결합한 동일 authority instance를 요구한다. `1acbf2f464cbfb0c5ad6e3991ecc9b04f17fb895`는 same-authority catalog/scan drift를 유지했고 `feed68db0ac0404607a292ed2686bf47e5e2be22`는 운영/rollback owner 경계를 갱신했다. Hosted application CI `34230994573`, job `102076920357`이 4,190 passed / 10 failed로 드러낸 stale fixture는 `532cfaadf655d3158434db8a1c3a985a33ad3a9f`, `ab2baeda9665df96753a03f1242455efe0662e41`, `273aa711d1c7611fadab9346944891548b30919a`에서 same-authority intent를 유지하면서 mutable test cache를 제거했다. -Exact-admission provenance RED `0a32ee0a88378931a07b7e3b61cc31e3b494a7ab`는 source admission A에서 발행한 authentic activation이 동일 trusted authority가 source B로 이동한 뒤에도 artifact/product/role/policy/time이 맞으면 B를 authorize할 수 있던 결함을 재현했다. Hosted application CI `34235691056`, job `102092675348`은 exact checkout/live-base/lockfile/install/typecheck 뒤 release tests에서 실패했다. Test-only `49115306b4abf7656f7fd136de8a3ff0c5a1968b`은 retained activation replay와 public invocation-receipt replay까지 확장했다. Canonical production `225a04ec2c833e9068e79ad7b70f3f5d8f6d934a`는 core의 activation/receipt provenance를 process-global set에서 exact `AdmittedExternalExtension`-bound map으로 옮겼고, `2e843825cc31a316a5834db3d355e8e4a18ca028`은 public wrapper에 잠시 중복됐던 binding kernel을 제거해 exact-admission authority를 core 한 곳에 남겼다. 같은 conformance invariant는 `context-graph-contracts#27`에 foreign-owner requirement로 넘겼고 mutable issue/branch를 Noema runtime dependency로 소비하지 않는다. +Exact-admission provenance RED `0a32ee0a88378931a07b7e3b61cc31e3b494a7ab`는 source admission A에서 발행한 authentic activation이 동일 trusted authority가 source B로 이동한 뒤에도 artifact/product/role/policy/time이 맞으면 B를 authorize할 수 있던 결함을 재현했다. Hosted application CI `34235691056`, job `102092675348`은 exact checkout/live-base/lockfile/install/typecheck 뒤 release tests에서 실패했다. Test-only `49115306b4abf7656f7fd136de8a3ff0c5a1968b`은 retained activation replay와 public invocation-receipt replay까지 확장했다. Canonical production `225a04ec2c833e9068e79ad7b70f3f5d8f6d934a`는 core의 activation/receipt provenance를 process-global set에서 exact `AdmittedExternalExtension`-bound map으로 옮겼고, `2e843825cc31a316a5834db3d355e8e4a18ca028`은 public wrapper에 잠시 중복됐던 binding kernel을 제거해 exact-admission activation/receipt authority를 core 한 곳에 남겼다. 같은 conformance invariant는 `context-graph-contracts#27`에 foreign-owner requirement로 넘겼고 mutable issue/branch를 Noema runtime dependency로 소비하지 않는다. Plaintext replay-retention RED `3f41d94af1454926b65b1801004fe245098742b0`는 public replay WeakMap이 reversible `JSON.stringify(normalizedRequest)`를 receipt lifetime 동안 보유해 instruction, observed content, rejected secret/product/hidden-reasoning inputs의 수명을 불필요하게 늘리던 결함을 고정했다. Hosted application CI `34237704683`, job `102099615873`은 exact checkout/live-base/lockfile/install/release typecheck 뒤 release tests에서 실패했다. Production `79182c7be196c42fb94450cae9a7857ae67b5434`는 retained replay identity를 versioned/domain-separated SHA-256 digest로 바꾸고 every semantic field, key-order independence, fixed-width/no-plaintext regression을 추가했다. ADR `ac6b6c088f034a8778bdc8a859f7157223883b8d`는 process-local WeakMap lifetime, restart fail-closed, explicit digest-version migration과 FIPS 180-4 authority를 기록하며 `Proposed`를 유지한다. -그 뒤 live security finding `5586918828`은 `ac6b6c0...`이 SHA-256 padding/schedule/rounds를 repository-owned TypeScript로 직접 구현한 점을 새 merge blocker로 분리했다. 방향인 digest-only retention은 유효하지만 새 security-critical primitive를 단일 local vector로 정당화할 수 없으므로 platform Web Crypto 또는 independently maintained/audited immutable implementation이 필요하다. Current test-only exact `b50b43065098609118991e0b0b0b4936725c2899`은 platform `crypto.subtle.digest` 또는 exact-pinned `@noble/hashes@2.4.0` 중 하나를 요구하고 `SHA256_INITIAL`, `SHA256_ROUND`, local `sha256Hex` ownership을 금지한다. Current generation은 application CI `34240985563`, reviewer-ci `34240985515`, required Security Scan `34240985513`, patch-validator-image `34240985555`이며 모두 아직 nonterminal이다. Hosted RED가 실제 발생하기 전에는 production provider repair를 주장하지 않는다. +그 뒤 live security finding `5586918828`은 repository-owned TypeScript SHA-256 padding/schedule/rounds가 Tool / Capability bounded context에 불필요한 security-critical primitive ownership을 추가한다는 결함을 분리했다. Test-only `b50b43065098609118991e0b0b0b4936725c2899`은 platform `crypto.subtle.digest` 또는 independently maintained/audited exact-pinned provider를 요구하고 local `SHA256_INITIAL`, `SHA256_ROUND`, `sha256Hex` ownership을 금지했다. Hosted application CI `34240985563`, job `102111324942`은 exact checkout, live-base guard, lockfile control, install과 release typecheck를 통과한 뒤 release tests에서 terminal FAILURE가 되어 reality RED를 확정했다. 같은 generation의 reviewer-ci `34240985515`와 required Security Scan `34240985513`은 SUCCESS였고 image `34240985555`는 successor generation 때문에 CANCELLED되어 GREEN으로 전용하지 않는다. + +Production `80292ed53943c61aa9d282ed18024b0f98f4cb1f`는 home-grown hash primitive를 제거하고 replay digest를 Worker Web Crypto `crypto.subtle.digest("SHA-256", ...)`에 위임했다. `396514c8f5183324e6c8d0a16d7a5d339b2cbb72`는 digest가 성공하기 전 accepted receipt를 public authority로 publish하지 않도록 success/replay path를 비동기로 만들고 digest-provider failure를 fail closed한다. `d1af4d703bd4c67b8be26d0c105d2a4ed0d4575a`는 standard SHA-256 short/padding-boundary/multi-block/long-message vectors를, `210bc59b17933b908aa20b1de1a160b07672b687`, `90bf018cbb2ea803adb02cd8e98010288f2c8201`, `a220003532901350b1ac9fc81079c7145dbf2b6f`, `26634f181f9c29e875bdd57ab5bc046b109fd91b`는 affected replay/invocation/policy tests가 async publication contract를 실제로 await하도록 수렴시켰다. ADR `62d4ea3f6a7227e66b072e914a0711587ad22279`는 SHA-256 primitive ownership을 Worker runtime에 두고 Noema가 domain/version canonicalization, replay-state lifecycle과 fail-closed interpretation만 소유하도록 기록하며 ADR 0015는 계속 `Proposed`다. + +이 baseline 수렴 시 #560 exact `26634f181f9c29e875bdd57ab5bc046b109fd91b`의 fresh generation은 application CI `34245484363`, reviewer-ci `34245484297`, required Security Scan `34245484413`, patch-validator-image `34245484369`이며 모두 queued/nonterminal이었다. Predecessor의 GREEN이나 RED를 현재 exact merge authority로 전용하지 않는다. AppGuardrail/quarantine receipts는 scanner/provenance evidence이지 Noema approval이 아니다. EgressWeave/quarantine references는 outbound/isolation operation의 대체물이 아니다. Anthropic marketplace review는 discovery evidence이지 CWL product authority가 아니다. `context-graph-contracts#27`이 immutable shared external-capability contract를 release하기 전까지 이 local port는 fail-closed ACL/test double이며 live plugin installation 또는 buyer completion을 주장하지 않는다. `context-graph-contracts#27`과 `appguardrail#1099`의 owner evidence를 Noema가 합성하지 않는다. @@ -54,6 +58,8 @@ AppGuardrail/quarantine receipts는 scanner/provenance evidence이지 Noema appr Review resolution, CI, reviewer-ci, required Security, image/SBOM/provenance, branch ancestry, release는 separate evidence classes다. Every source mutation/restack invalidates predecessor workflow evidence. `queued`, `pending`, `in_progress`, `skipped`, `cancelled`, stale 또는 absent-required evidence는 passing이 아니다. +#559 exact `f4807d71ae815a5d79a08ef35628d72bb4ad34b9`의 application CI `34241457271`, job `102112384672`은 exact checkout, live-base guard, lockfile control, install과 release typecheck를 통과한 뒤 release tests에서 terminal FAILURE였다. 원인은 executable documentation-authority test가 이미 바뀐 baseline의 runtime-current RED 문구와 Web Crypto repair lineage를 따라오지 못한 stale expectation이었다. #559는 feature source를 복사하지 않고 이 baseline과 해당 documentation contract만 ordinary/non-force로 함께 수리한다. 이 수리 뒤에는 새 exact-head generation만 merge authority가 된다. + Normal merge requires unchanged exact head, independently refreshed live base/head, no valid unresolved review finding, applicable required terminal-success gates and no foreign-owner/protected-contract regression. Concurrent commits나 pushes 자체를 race로 단정하지 않는다. Wrong base/conflict, stale ADR, mutable dependency, missing fixture/contract, single-writer 위반은 force push나 destructive rebase가 아니라 ordinary/non-force semantic convergence로 수리한다. PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge 또는 verified successor가 모든 유효 delta/test/fixture/contract/evidence를 완전히 승계한 경우에만 사라진다. Blocked lane은 자기 lane만 막고 unrelated safe review, owner-path repair, docs-to-code repair와 buyer-gap work는 계속한다. @@ -63,7 +69,7 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge | Priority | Gap | Buyer/operator impact | Current owner | Status | Authoritative completion evidence | Next executable action | | --- | --- | --- | --- | --- | --- | --- | | P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority가 될 위험 | protected #556 + release/consumer lanes | Source integrated; producer/release/consumer open | protected source + execution/research producer + immutable Noema release + released central consumer corpus RED→GREEN | release/producer evidence를 별도 lane에서 완성 | -| P0 | External extension capability admission | third-party plugin metadata, self-asserted grant, stale/cross-admission activation, backdated event time, divergent replay, plaintext replay retention 또는 home-grown crypto가 runtime authority가 될 위험 | issue #545 / PR #560 | Draft; ADR 0015 Proposed; runtime/replay/complete-mediation/exact-admission/plaintext RED repaired; crypto-provider RED candidate queued | immutable source + independent scan + Noema-issued Policy / Approval + admission-bound live authority + exact-admission activation/receipt authority + runtime-current expiry + digest-only replay + platform/audited SHA-256 + NIST conformance + fresh four-GREEN + normal merge + immutable shared contract/live pilot | `b50b4306...` hosted RED를 보존한 뒤 최소 provider repair→fresh unchanged-head gates | +| P0 | External extension capability admission | third-party plugin metadata, self-asserted grant, stale/cross-admission activation, backdated event time, divergent replay, plaintext replay retention 또는 repository-owned crypto가 runtime authority가 될 위험 | issue #545 / PR #560 | Draft; ADR 0015 Proposed; runtime/replay/complete-mediation/exact-admission/plaintext/crypto-provider RED repaired in source; current exact gates nonterminal | immutable source + independent scan + Noema-issued Policy / Approval + admission-bound live authority + exact-admission activation/receipt authority + runtime-current expiry + digest-only replay + platform Web Crypto + NIST conformance + fresh four-GREEN + normal merge + immutable shared contract/live pilot | unchanged current exact four-GREEN과 clean review 확인 후 normal merge; 이후 #559를 resulting protected main에 ordinary/non-force 수렴 | | P0 | Protected-main governance closure | required Security workflow만으로 PR/review/history/deletion/bypass 통제를 증명했다고 오인할 위험 | issue #27 | Open; external control evidence absent | fresh live ruleset + required PR/review/conversation/history/deletion controls + independent bypass/break-glass evidence + protected-source governance receipt | source가 만들 수 없는 organization/admin control은 issue #27에서 독립 검증 | | P0 | Strict orchestrator/free consumer release | source 통합만으로 immutable consumer activation을 증명할 수 없음 | merged #535 + release lane | Source integrated; release/consumer open | version/tag/package/SBOM/provenance/reproducibility/rollback + released consumer | release-ready protected head에서만 publication | | P0 | Patch-validator operational publication | source/image CI success만으로 reusable immutable runtime을 증명할 수 없음 | issue #66 | Open; publication evidence absent | protected execution + immutable image/signature/SBOM/provenance/reproducibility/rollback | merged #556의 1h59m24s build를 cache-hit/miss로 추정하지 말고 explicit BuildKit cache-reuse evidence를 추가 | From fd71701ae915bfdeed3140dbd55868e49f5bf1ac Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 00:41:38 +0900 Subject: [PATCH 61/68] test(docs): follow current external-extension authority --- ...cumentation-live-open-pr-authority.test.ts | 23 +++++++++++-------- 1 file changed, 13 insertions(+), 10 deletions(-) diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index cccf7a372..eea8ff4ef 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -6,30 +6,33 @@ describe("product-technical gap baseline live open-PR authority", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); expect(baseline).toContain("Resulting protected merge는 GitHub-verified `36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`"); - expect(baseline).toContain("Observed PR #560 exact `84a93a2ffcd539df0deb96a9037a31fa863bdcaf`"); + expect(baseline).toContain("이 문서를 수렴시킬 때 관찰한 PR #560 exact는 `26634f181f9c29e875bdd57ab5bc046b109fd91b`"); expect(baseline).toContain("Hosted application CI `34221586992`, job `102045717213`"); - expect(baseline).toContain("application CI `34236657166`"); expect(baseline).toContain("Policy / Approval issuance"); expect(baseline).toContain("Production `2b50b35b7bdbb834f571dfcae50dceb05766244c`"); expect(baseline).toContain("runtime wall clock"); - expect(baseline).toContain("Test-only replay RED `cb8ad638875b761aea70aba78a480bd5031c4d7d`"); + expect(baseline).toContain("Replay semantic RED `cb8ad638875b761aea70aba78a480bd5031c4d7d`"); expect(baseline).toContain("Production `9c7ae13f7053fa368fd778c3909c4428d1bdf28e`"); - expect(baseline).toContain("Coverage repair `83ee8e9b54be7ea59cfa11fe03e4ad0c6414950c`"); + expect(baseline).toContain("core-conflict oracle은 `83ee8e9b54be7ea59cfa11fe03e4ad0c6414950c`"); expect(baseline).toContain("Unbound core-receipt RED `5a50a9bcfe12f3938b30e4a3cb15af8d30134391`"); expect(baseline).toContain("Production `cbb64def35bad02024076c1db74e9da4739ae736`"); - expect(baseline).toContain("public invocation-envelope authority"); + expect(baseline).toContain("public binding이 없는 retained receipt를 fail closed"); expect(baseline).toContain("Activation-time revocation RED `8ff77d9b6428a2c09f2c72bf3b05fdb989e35843`"); expect(baseline).toContain("Production `8251d4bcd2c81dd13d252a576b55dc21e66db9c4`"); - expect(baseline).toContain("before issuing an activation"); + expect(baseline).toContain("새 activation 발행 전에 다시 읽도록 했다"); expect(baseline).toContain("Invocation-authority substitution RED `abcd1fea4b28b826826fed6b23296b59ceda98ca`"); expect(baseline).toContain("Production `f8814b8fd7b66f40335df85c6aadab12aa760bc1`"); - expect(baseline).toContain("same admission-bound authority instance"); - expect(baseline).toContain("hidden mutable `lastAdmissionAuthority` cache"); + expect(baseline).toContain("동일 authority instance"); + expect(baseline).toContain("mutable test cache를 제거했다"); expect(baseline).toContain("Exact-admission provenance RED `0a32ee0a88378931a07b7e3b61cc31e3b494a7ab`"); expect(baseline).toContain("Hosted application CI `34235691056`, job `102092675348`"); expect(baseline).toContain("Test-only `49115306b4abf7656f7fd136de8a3ff0c5a1968b`"); - expect(baseline).toContain("Production `84a93a2ffcd539df0deb96a9037a31fa863bdcaf`"); - expect(baseline).toContain("exact `AdmittedExternalExtension`"); + expect(baseline).toContain("Canonical production `225a04ec2c833e9068e79ad7b70f3f5d8f6d934a`"); + expect(baseline).toContain("exact `AdmittedExternalExtension`-bound map"); + expect(baseline).toContain("Plaintext replay-retention RED `3f41d94af1454926b65b1801004fe245098742b0`"); + expect(baseline).toContain("Test-only `b50b43065098609118991e0b0b0b4936725c2899`"); + expect(baseline).toContain("Worker Web Crypto `crypto.subtle.digest(\"SHA-256\", ...)`"); + expect(baseline).toContain("application CI `34245484363`"); expect(baseline).toContain("ordinary/non-force"); expect(baseline).not.toContain("Observed PR #556 exact"); expect(baseline).not.toContain("Observed PR #560 exact `802b0bff0f32c170ada328b04e87e0db43ee7cd4`"); From 60d33799b7df2e42f75e796f68aca7be62dd4bf7 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 00:42:03 +0900 Subject: [PATCH 62/68] test(docs): assert public receipt binding authority --- test/product-technical-gap-current-candidate-contract.test.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index 41a993777..c59b381f7 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -13,7 +13,7 @@ describe("product-technical gap current candidate contract", () => { expect(baseline).toContain("Replay semantic RED `cb8ad638875b761aea70aba78a480bd5031c4d7d`"); expect(baseline).toContain("normalized invocation envelope"); expect(baseline).toContain("Unbound core-receipt RED `5a50a9bcfe12f3938b30e4a3cb15af8d30134391`"); - expect(baseline).toContain("public invocation-envelope authority"); + expect(baseline).toContain("public binding이 없는 retained receipt를 fail closed"); expect(baseline).toContain("policy drift/revocation"); expect(baseline).toContain("admission-bound live authority"); expect(baseline).toContain("Exact-admission provenance RED"); From 686f11b0755abec0b7cc7cf5bbec479e60857c76 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 00:46:19 +0900 Subject: [PATCH 63/68] test(docs): match activation revocation authority wording --- test/documentation-live-open-pr-authority.test.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index eea8ff4ef..12c55e965 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -18,7 +18,7 @@ describe("product-technical gap baseline live open-PR authority", () => { expect(baseline).toContain("Production `cbb64def35bad02024076c1db74e9da4739ae736`"); expect(baseline).toContain("public binding이 없는 retained receipt를 fail closed"); expect(baseline).toContain("Activation-time revocation RED `8ff77d9b6428a2c09f2c72bf3b05fdb989e35843`"); - expect(baseline).toContain("Production `8251d4bcd2c81dd13d252a576b55dc21e66db9c4`"); + expect(baseline).toContain("production `8251d4bcd2c81dd13d252a576b55dc21e66db9c4`"); expect(baseline).toContain("새 activation 발행 전에 다시 읽도록 했다"); expect(baseline).toContain("Invocation-authority substitution RED `abcd1fea4b28b826826fed6b23296b59ceda98ca`"); expect(baseline).toContain("Production `f8814b8fd7b66f40335df85c6aadab12aa760bc1`"); From 448b0439c61707dd2ca559e49b4a7d68daaefeea Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 10:12:42 +0900 Subject: [PATCH 64/68] docs: converge baseline after #560 protected integration --- docs/product-technical-gap-baseline.md | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 5d83ac180..b5b70b621 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -4,11 +4,11 @@ 이 문서는 protected source, active candidate, transient workflow evidence와 foreign-owner authority를 분리한다. Open PR exact head, protected base, required workflow, review thread, release와 central dependency는 mutation·merge·release 직전에 다시 읽는다. predecessor GREEN, queued/pending/in-progress/skipped/cancelled run, 오래된 PR base snapshot과 scanner/model judgement는 다음 revision의 merge authority로 전용하지 않는다. queued는 GREEN이 아니다. -Current protected source는 GitHub-verified protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`다. Current source SHA는 moving observation이며 future merge 뒤 evergreen identity로 취급하지 않는다. 이 protected revision에는 merged PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`의 producer-authenticated exact-claim evidence admission과 non-vacuous reviewer publication contract가 포함돼 있다. +Current protected source는 GitHub-verified protected `main@e3aa77c3f678336c548440f355f988345b0ba976`다. Current source SHA는 moving observation이며 future merge 뒤 evergreen identity로 취급하지 않는다. 이 protected revision에는 merged PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`의 producer-authenticated exact-claim evidence admission과 non-vacuous reviewer publication contract, 그리고 merged PR #560 exact `5aab7c098f3478069127f34e398326415ec599a4`의 fail-closed external-extension Tool / Capability admission contract가 포함돼 있다. Moving central control-plane snapshot은 central `.github/main@7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db`다. Noema runtime의 reviewed immutable central consumer pin은 `c9052e607e5f3cc76e73207e7786b21500721b79`이고 runtime authority 표현은 `ALLOWED_WORKFLOW_SHA = c9052e607e5f3cc76e73207e7786b21500721b79`다. Moving foreign head와 reviewed immutable pin을 같은 권위로 취급하지 않으며 central moving head가 전진했다고 consumer pin을 자동 승격하지 않는다. -Protected history에는 merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`, merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`, merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`, merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`, merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`, merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`, merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`, merged PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`가 포함돼 있다. 이 SHA들은 역사 증거이지 open-candidate authority가 아니다. +Protected history에는 merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`, merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`, merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`, merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`, merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`, merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`, merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`, merged PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`, merged PR #560 exact `5aab7c098f3478069127f34e398326415ec599a4`가 포함돼 있다. 이 SHA들은 역사 증거이지 open-candidate authority가 아니다. #559가 `docs/product-technical-gap-baseline.md`와 executable documentation-authority tests의 sole writer다. 다른 feature lane의 과거 baseline blob은 ordinary/non-force semantic convergence 때 current authority로 승계하지 않는다. @@ -18,7 +18,7 @@ Noema Core Domain은 Agent Runtime과 Workflow / Task Execution이다. Tool / Ca `contextual-orchestrator`는 provider/model discovery, routing, retry/failover, test-time compute와 provider credential을 소유한다. Noema는 released gateway contract와 canonical `orchestrator/free` alias를 소비하며 direct provider SDK, provider key, provider/model/group fallback policy를 소유하지 않는다. `.github`는 organization reusable workflow/control-plane source다. Keyverse는 identity backend다. `quarantine-sandbox-runtime`, Wardnet, EgressWeave, AppGuardrail은 각자의 isolation/security/outbound/scanning truth를 소유한다. Noema는 그 owner evidence를 reference/pin으로 소비할 뿐 foreign implementation이나 domain table을 복제하지 않는다. Cross-service SQL과 mutable sibling PR dependency는 금지한다. -Baseline의 요구·설계·데이터·경계 authority는 `docs/PRD.md`, `docs/TRD.md`, `docs/UML.md`, `docs/ERD.md`, `docs/CONTEXT_MAP.md`다. 이 register는 그 문서와 ADR을 대체하지 않고 current Gap/Action/Status를 exact source·PR·workflow evidence에 결합한다. PR #560의 ADR 0015는 candidate-only `Proposed`이며 protected ADR authority로 승격하지 않는다. +Baseline의 요구·설계·데이터·경계 authority는 `docs/PRD.md`, `docs/TRD.md`, `docs/UML.md`, `docs/ERD.md`, `docs/CONTEXT_MAP.md`다. 이 register는 그 문서와 ADR을 대체하지 않고 current Gap/Action/Status를 exact source·PR·workflow evidence에 결합한다. ADR 0015는 protected source에 포함됐지만 상태는 `Proposed`이며 durable lifecycle persistence, immutable shared-contract consumption, live pilot와 release evidence가 남아 있다. ## Integrated exact-claim evidence — issue #555 / merged PR #556 @@ -26,9 +26,9 @@ PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`는 unchanged exact-head Protected source는 raw source receipt를 context authority로만 취급하고, `ClaimEvidenceRequirement`와 producer-authenticated receipt의 kind/identity/coordinates/digest가 일치해야 finding/publication authority가 되도록 한다. `produce_source_claim_receipt()`는 exactly-one-line UTF-8 source bytes와 claim equality를 요구하며 paraphrase, embedded multiline, invalid UTF-8을 거부한다. Model `request_changes`/`blocked`는 producer-authenticated finding 없이 publication될 수 없다. Source integration은 execution stdout/stderr producer, research producer, immutable release, released central consumer까지 자동으로 증명하지 않는다. -## Active external-extension candidate — issue #545 / PR #560 +## Integrated external-extension admission — issue #545 / merged PR #560 -이 문서를 수렴시킬 때 관찰한 PR #560 exact는 `26634f181f9c29e875bdd57ab5bc046b109fd91b`이며 Draft, base는 protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`이다. 이 SHA는 moving observation이지 future merge authority가 아니다. Feature lane은 protected `.github`와 `reviewer` owner source를 그대로 승계하고 `docs/product-technical-gap-baseline.md`는 #559에 남겨 둔다. Ordinary/non-force history를 유지하며 force push나 destructive rebase를 쓰지 않는다. +PR #560 exact `5aab7c098f3478069127f34e398326415ec599a4`는 unchanged exact-head application CI `34289599257`, reviewer-ci `34289599291`, required Security Scan `34289599289`, patch-validator-image `34289599248` terminal SUCCESS와 fresh clean review authority를 충족한 뒤 normal merge됐다. Resulting protected merge는 GitHub-verified `e3aa77c3f678336c548440f355f988345b0ba976`다. #559는 그 protected merge를 ordinary/non-force merge-parent로 받아 documentation authority를 수렴하며 predecessor GREEN을 재사용하지 않는다. Earlier Policy / Approval RED `7ca9aebee6f92053913c0bbc665c8de77650891f`의 hosted application CI `34206149899`, job `101995980303`은 valid catalog/AppGuardrail/quarantine evidence만으로 descriptor가 active/product/role grant를 self-broaden할 수 없음을 고정했다. Subsequent production source separates source/catalog/scanner authority from Noema Policy / Approval issuance, keeps the source-issued grant at a pilot ceiling, seals admission/activation/receipt provenance, revalidates the full six-field catalog identity and live scanner receipts, and rejects impossible pre-activation invocation chronology. @@ -50,7 +50,7 @@ Plaintext replay-retention RED `3f41d94af1454926b65b1801004fe245098742b0`는 pub Production `80292ed53943c61aa9d282ed18024b0f98f4cb1f`는 home-grown hash primitive를 제거하고 replay digest를 Worker Web Crypto `crypto.subtle.digest("SHA-256", ...)`에 위임했다. `396514c8f5183324e6c8d0a16d7a5d339b2cbb72`는 digest가 성공하기 전 accepted receipt를 public authority로 publish하지 않도록 success/replay path를 비동기로 만들고 digest-provider failure를 fail closed한다. `d1af4d703bd4c67b8be26d0c105d2a4ed0d4575a`는 standard SHA-256 short/padding-boundary/multi-block/long-message vectors를, `210bc59b17933b908aa20b1de1a160b07672b687`, `90bf018cbb2ea803adb02cd8e98010288f2c8201`, `a220003532901350b1ac9fc81079c7145dbf2b6f`, `26634f181f9c29e875bdd57ab5bc046b109fd91b`는 affected replay/invocation/policy tests가 async publication contract를 실제로 await하도록 수렴시켰다. ADR `62d4ea3f6a7227e66b072e914a0711587ad22279`는 SHA-256 primitive ownership을 Worker runtime에 두고 Noema가 domain/version canonicalization, replay-state lifecycle과 fail-closed interpretation만 소유하도록 기록하며 ADR 0015는 계속 `Proposed`다. -이 baseline 수렴 시 #560 exact `26634f181f9c29e875bdd57ab5bc046b109fd91b`의 fresh generation은 application CI `34245484363`, reviewer-ci `34245484297`, required Security Scan `34245484413`, patch-validator-image `34245484369`이며 모두 queued/nonterminal이었다. Predecessor의 GREEN이나 RED를 현재 exact merge authority로 전용하지 않는다. +Final #560 source generation `5aab7c098f3478069127f34e398326415ec599a4`는 all-four terminal SUCCESS를 충족했고 clean review 뒤 normal merge됐다. Source integration은 local fail-closed admission contract를 protected history로 승격하지만 durable append-only lifecycle evidence, immutable shared contract, AppGuardrail/quarantine/EgressWeave live operation, production pilot, release와 buyer completion까지 자동으로 증명하지 않는다. AppGuardrail/quarantine receipts는 scanner/provenance evidence이지 Noema approval이 아니다. EgressWeave/quarantine references는 outbound/isolation operation의 대체물이 아니다. Anthropic marketplace review는 discovery evidence이지 CWL product authority가 아니다. `context-graph-contracts#27`이 immutable shared external-capability contract를 release하기 전까지 이 local port는 fail-closed ACL/test double이며 live plugin installation 또는 buyer completion을 주장하지 않는다. `context-graph-contracts#27`과 `appguardrail#1099`의 owner evidence를 Noema가 합성하지 않는다. @@ -58,7 +58,7 @@ AppGuardrail/quarantine receipts는 scanner/provenance evidence이지 Noema appr Review resolution, CI, reviewer-ci, required Security, image/SBOM/provenance, branch ancestry, release는 separate evidence classes다. Every source mutation/restack invalidates predecessor workflow evidence. `queued`, `pending`, `in_progress`, `skipped`, `cancelled`, stale 또는 absent-required evidence는 passing이 아니다. -#559 exact `f4807d71ae815a5d79a08ef35628d72bb4ad34b9`의 application CI `34241457271`, job `102112384672`은 exact checkout, live-base guard, lockfile control, install과 release typecheck를 통과한 뒤 release tests에서 terminal FAILURE였다. 원인은 executable documentation-authority test가 이미 바뀐 baseline의 runtime-current RED 문구와 Web Crypto repair lineage를 따라오지 못한 stale expectation이었다. #559는 feature source를 복사하지 않고 이 baseline과 해당 documentation contract만 ordinary/non-force로 함께 수리한다. 이 수리 뒤에는 새 exact-head generation만 merge authority가 된다. +#559 predecessor exact `f4807d71ae815a5d79a08ef35628d72bb4ad34b9`의 application CI `34241457271`, job `102112384672`은 exact checkout, live-base guard, lockfile control, install과 release typecheck를 통과한 뒤 release tests에서 terminal FAILURE였다. 원인은 executable documentation-authority test가 이미 바뀐 baseline의 runtime-current RED 문구와 Web Crypto repair lineage를 따라오지 못한 stale expectation이었다. #559는 feature source를 복사하지 않고 이 baseline과 해당 documentation contract만 ordinary/non-force로 함께 수리한다. #560 integration 뒤에는 protected `main@e3aa77c3f678336c548440f355f988345b0ba976`를 ordinary merge-parent로 받아 reconverge했고, 그 뒤 source mutation은 새 exact-head generation만 merge authority가 된다. Normal merge requires unchanged exact head, independently refreshed live base/head, no valid unresolved review finding, applicable required terminal-success gates and no foreign-owner/protected-contract regression. Concurrent commits나 pushes 자체를 race로 단정하지 않는다. Wrong base/conflict, stale ADR, mutable dependency, missing fixture/contract, single-writer 위반은 force push나 destructive rebase가 아니라 ordinary/non-force semantic convergence로 수리한다. @@ -69,10 +69,10 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge | Priority | Gap | Buyer/operator impact | Current owner | Status | Authoritative completion evidence | Next executable action | | --- | --- | --- | --- | --- | --- | --- | | P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority가 될 위험 | protected #556 + release/consumer lanes | Source integrated; producer/release/consumer open | protected source + execution/research producer + immutable Noema release + released central consumer corpus RED→GREEN | release/producer evidence를 별도 lane에서 완성 | -| P0 | External extension capability admission | third-party plugin metadata, self-asserted grant, stale/cross-admission activation, backdated event time, divergent replay, plaintext replay retention 또는 repository-owned crypto가 runtime authority가 될 위험 | issue #545 / PR #560 | Draft; ADR 0015 Proposed; runtime/replay/complete-mediation/exact-admission/plaintext/crypto-provider RED repaired in source; current exact gates nonterminal | immutable source + independent scan + Noema-issued Policy / Approval + admission-bound live authority + exact-admission activation/receipt authority + runtime-current expiry + digest-only replay + platform Web Crypto + NIST conformance + fresh four-GREEN + normal merge + immutable shared contract/live pilot | unchanged current exact four-GREEN과 clean review 확인 후 normal merge; 이후 #559를 resulting protected main에 ordinary/non-force 수렴 | +| P0 | External extension lifecycle evidence | third-party plugin metadata, self-asserted grant, stale/cross-admission activation, backdated event time, divergent replay 또는 restart 뒤 process-local authority가 runtime truth로 오인될 위험 | merged #560 + issue #561 | Admission source integrated; ADR 0015 Proposed; durable lifecycle/restart evidence open | immutable source + independent scan + Noema-issued Policy / Approval + admission-bound authority + append-only versioned lifecycle stream + CAS/idempotency/restart/rollback proof + immutable shared contract/live pilot | #561에서 Noema State / Checkpoint 경계의 append-only lifecycle evidence를 구현하고 foreign owner truth는 immutable ref/digest로만 보존 | | P0 | Protected-main governance closure | required Security workflow만으로 PR/review/history/deletion/bypass 통제를 증명했다고 오인할 위험 | issue #27 | Open; external control evidence absent | fresh live ruleset + required PR/review/conversation/history/deletion controls + independent bypass/break-glass evidence + protected-source governance receipt | source가 만들 수 없는 organization/admin control은 issue #27에서 독립 검증 | | P0 | Strict orchestrator/free consumer release | source 통합만으로 immutable consumer activation을 증명할 수 없음 | merged #535 + release lane | Source integrated; release/consumer open | version/tag/package/SBOM/provenance/reproducibility/rollback + released consumer | release-ready protected head에서만 publication | -| P0 | Patch-validator operational publication | source/image CI success만으로 reusable immutable runtime을 증명할 수 없음 | issue #66 | Open; publication evidence absent | protected execution + immutable image/signature/SBOM/provenance/reproducibility/rollback | merged #556의 1h59m24s build를 cache-hit/miss로 추정하지 말고 explicit BuildKit cache-reuse evidence를 추가 | +| P0 | Patch-validator operational publication | source/image CI success만으로 reusable immutable runtime을 증명할 수 없음 | issue #66 | Open; publication evidence absent | protected execution + immutable image/signature/SBOM/provenance/reproducibility/rollback | explicit BuildKit cache-reuse evidence와 protected execution receipt를 확보하고 elapsed time만으로 cache hit/miss를 추정하지 않음 | | P0 | Authentic production KPI evidence | fixture·synthetic 또는 source-level KPI 검증이 실제 운영 성능을 대체할 위험 | issue #3 | Open; production window absent | authenticated production-window records + strict provenance + buyer-relevant KPI gate | 실제 production evidence 없이는 readiness를 승격하지 않음 | | P0 | Acquisition coordination | source/docs 완료를 buyer·legal·transfer readiness로 잘못 승격할 위험 | issue #5 | Open; evidence families incomplete | exact protected revision + applicable release/deployment/operational/buyer/legal evidence family | 남은 evidence family를 owner별로 수렴하고 source claim과 분리 | | P0 | External Maintainer/Reviewer App identity | source capability-file 계약이 실제 App 설치·키 custody·rotation·권한·reviewer identity를 대체할 위험 | issues #29 / #227 | Open; live identity evidence absent | live installation + key custody/rotation + repository permission + eligible reviewer/publication identity evidence | 외부 App authority는 해당 issue owner에서 독립 검증 | From 855bbf5d9d6916b8e49752a86e647b4e85145b8f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 10:12:56 +0900 Subject: [PATCH 65/68] test: bind documentation authority to #560 integration --- test/documentation-current-trust-authority.test.ts | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/test/documentation-current-trust-authority.test.ts b/test/documentation-current-trust-authority.test.ts index 02085365a..cc504d16c 100644 --- a/test/documentation-current-trust-authority.test.ts +++ b/test/documentation-current-trust-authority.test.ts @@ -5,13 +5,13 @@ describe("current protected trust authority documentation", () => { it("separates current protected source, moving central head, and immutable pin", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); - expect(baseline).toContain("protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`"); + expect(baseline).toContain("protected `main@e3aa77c3f678336c548440f355f988345b0ba976`"); expect(baseline).toContain("central `.github/main@7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db`"); expect(baseline).toContain("`ALLOWED_WORKFLOW_SHA = c9052e607e5f3cc76e73207e7786b21500721b79`"); expect(baseline).toContain("Current source SHA는 moving observation이며 future merge 뒤 evergreen identity로 취급하지 않는다"); expect(baseline).toContain("Moving foreign head와 reviewed immutable pin을 같은 권위로 취급하지 않으며"); - expect(baseline).toContain("merged PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`"); - expect(baseline).not.toContain("protected `main@0dbfceb850cda3a016ceb39ae1c8a1a96a9f2ad5`"); + expect(baseline).toContain("merged PR #560 exact `5aab7c098f3478069127f34e398326415ec599a4`"); + expect(baseline).not.toContain("protected `main@36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`다"); expect(baseline).not.toContain("central `.github/main@78a4937c684a54ca8e415822c913742f41c6efc4`"); }); }); From c8e5e6f50c36fe8c8528d49e3c0e0f8d8fabb7c4 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 10:13:10 +0900 Subject: [PATCH 66/68] test: treat external-extension admission as protected history --- ...cumentation-live-open-pr-authority.test.ts | 44 +++++-------------- 1 file changed, 11 insertions(+), 33 deletions(-) diff --git a/test/documentation-live-open-pr-authority.test.ts b/test/documentation-live-open-pr-authority.test.ts index 12c55e965..43f7001af 100644 --- a/test/documentation-live-open-pr-authority.test.ts +++ b/test/documentation-live-open-pr-authority.test.ts @@ -1,45 +1,23 @@ import { readFileSync } from "node:fs"; import { describe, expect, it } from "vitest"; -describe("product-technical gap baseline live open-PR authority", () => { - it("treats #556 as integrated history and #560 as the active candidate", () => { +describe("product-technical gap baseline live source authority", () => { + it("treats #560 as integrated protected history without promoting downstream completion", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); - expect(baseline).toContain("Resulting protected merge는 GitHub-verified `36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`"); - expect(baseline).toContain("이 문서를 수렴시킬 때 관찰한 PR #560 exact는 `26634f181f9c29e875bdd57ab5bc046b109fd91b`"); - expect(baseline).toContain("Hosted application CI `34221586992`, job `102045717213`"); + expect(baseline).toContain("Integrated external-extension admission — issue #545 / merged PR #560"); + expect(baseline).toContain("PR #560 exact `5aab7c098f3478069127f34e398326415ec599a4`"); + expect(baseline).toContain("Resulting protected merge는 GitHub-verified `e3aa77c3f678336c548440f355f988345b0ba976`"); + expect(baseline).toContain("application CI `34289599257`"); + expect(baseline).toContain("patch-validator-image `34289599248`"); expect(baseline).toContain("Policy / Approval issuance"); - expect(baseline).toContain("Production `2b50b35b7bdbb834f571dfcae50dceb05766244c`"); - expect(baseline).toContain("runtime wall clock"); + expect(baseline).toContain("Runtime-current authority RED `4be371ec08b852f4d00829ba5aa6936df6564b5e`"); expect(baseline).toContain("Replay semantic RED `cb8ad638875b761aea70aba78a480bd5031c4d7d`"); - expect(baseline).toContain("Production `9c7ae13f7053fa368fd778c3909c4428d1bdf28e`"); - expect(baseline).toContain("core-conflict oracle은 `83ee8e9b54be7ea59cfa11fe03e4ad0c6414950c`"); - expect(baseline).toContain("Unbound core-receipt RED `5a50a9bcfe12f3938b30e4a3cb15af8d30134391`"); - expect(baseline).toContain("Production `cbb64def35bad02024076c1db74e9da4739ae736`"); - expect(baseline).toContain("public binding이 없는 retained receipt를 fail closed"); - expect(baseline).toContain("Activation-time revocation RED `8ff77d9b6428a2c09f2c72bf3b05fdb989e35843`"); - expect(baseline).toContain("production `8251d4bcd2c81dd13d252a576b55dc21e66db9c4`"); - expect(baseline).toContain("새 activation 발행 전에 다시 읽도록 했다"); - expect(baseline).toContain("Invocation-authority substitution RED `abcd1fea4b28b826826fed6b23296b59ceda98ca`"); - expect(baseline).toContain("Production `f8814b8fd7b66f40335df85c6aadab12aa760bc1`"); - expect(baseline).toContain("동일 authority instance"); - expect(baseline).toContain("mutable test cache를 제거했다"); expect(baseline).toContain("Exact-admission provenance RED `0a32ee0a88378931a07b7e3b61cc31e3b494a7ab`"); - expect(baseline).toContain("Hosted application CI `34235691056`, job `102092675348`"); - expect(baseline).toContain("Test-only `49115306b4abf7656f7fd136de8a3ff0c5a1968b`"); - expect(baseline).toContain("Canonical production `225a04ec2c833e9068e79ad7b70f3f5d8f6d934a`"); - expect(baseline).toContain("exact `AdmittedExternalExtension`-bound map"); - expect(baseline).toContain("Plaintext replay-retention RED `3f41d94af1454926b65b1801004fe245098742b0`"); - expect(baseline).toContain("Test-only `b50b43065098609118991e0b0b0b4936725c2899`"); expect(baseline).toContain("Worker Web Crypto `crypto.subtle.digest(\"SHA-256\", ...)`"); - expect(baseline).toContain("application CI `34245484363`"); + expect(baseline).toContain("durable append-only lifecycle evidence"); expect(baseline).toContain("ordinary/non-force"); - expect(baseline).not.toContain("Observed PR #556 exact"); - expect(baseline).not.toContain("Observed PR #560 exact `802b0bff0f32c170ada328b04e87e0db43ee7cd4`"); - expect(baseline).not.toContain("application CI `34219296338`"); - expect(baseline).not.toContain("Observed PR #560 exact `83ee8e9b54be7ea59cfa11fe03e4ad0c6414950c`"); - expect(baseline).not.toContain("Observed PR #560 exact `cbb64def35bad02024076c1db74e9da4739ae736`"); - expect(baseline).not.toContain("Observed PR #560 exact `8251d4bcd2c81dd13d252a576b55dc21e66db9c4`"); - expect(baseline).not.toContain("Observed PR #560 exact `273aa711d1c7611fadab9346944891548b30919a`"); + expect(baseline).not.toContain("## Active external-extension candidate"); + expect(baseline).not.toContain("PR #560의 ADR 0015는 candidate-only"); }); }); From a09dde47312670fa38c719e67a9da84ca2131012 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 10:13:30 +0900 Subject: [PATCH 67/68] test: extend protected integration history through #560 --- test/documentation-post-trust-integration-authority.test.ts | 1 + 1 file changed, 1 insertion(+) diff --git a/test/documentation-post-trust-integration-authority.test.ts b/test/documentation-post-trust-integration-authority.test.ts index b64d2ff11..ad5455007 100644 --- a/test/documentation-post-trust-integration-authority.test.ts +++ b/test/documentation-post-trust-integration-authority.test.ts @@ -14,6 +14,7 @@ describe("post-trust-integration documentation authority", () => { "merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`", "merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`", "merged PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`", + "merged PR #560 exact `5aab7c098f3478069127f34e398326415ec599a4`", ]) { expect(baseline).toContain(integrated); } From 4b3bdfdd9116951953642494642101c105cea1f1 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 9 Sep 2026 10:13:42 +0900 Subject: [PATCH 68/68] test: move external-extension gap to lifecycle successor --- ...chnical-gap-current-candidate-contract.test.ts | 15 ++++++--------- 1 file changed, 6 insertions(+), 9 deletions(-) diff --git a/test/product-technical-gap-current-candidate-contract.test.ts b/test/product-technical-gap-current-candidate-contract.test.ts index c59b381f7..824a15f2c 100644 --- a/test/product-technical-gap-current-candidate-contract.test.ts +++ b/test/product-technical-gap-current-candidate-contract.test.ts @@ -1,13 +1,12 @@ import { readFileSync } from "node:fs"; import { describe, expect, it } from "vitest"; -describe("product-technical gap current candidate contract", () => { - it("records the active external-extension Policy / Approval gap without overclaiming completion", () => { +describe("product-technical gap current authority", () => { + it("records integrated external-extension admission and the durable lifecycle successor without overclaiming completion", () => { const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); - expect(baseline).toContain("issue #545 / PR #560"); + expect(baseline).toContain("issue #545 / merged PR #560"); expect(baseline).toContain("Runtime-current authority RED `4be371ec08b852f4d00829ba5aa6936df6564b5e`"); - expect(baseline).toContain("Hosted application CI `34221586992`, job `102045717213`"); expect(baseline).toContain("Noema Policy / Approval issuance"); expect(baseline).toContain("runtime wall clock"); expect(baseline).toContain("Replay semantic RED `cb8ad638875b761aea70aba78a480bd5031c4d7d`"); @@ -18,12 +17,10 @@ describe("product-technical gap current candidate contract", () => { expect(baseline).toContain("admission-bound live authority"); expect(baseline).toContain("Exact-admission provenance RED"); expect(baseline).toContain("Plaintext replay-retention RED"); - expect(baseline).toContain("`b50b43065098609118991e0b0b0b4936725c2899`"); - expect(baseline).toContain("`34240985563`, job `102111324942`"); expect(baseline).toContain("Worker Web Crypto"); - expect(baseline).toContain("`80292ed53943c61aa9d282ed18024b0f98f4cb1f`"); - expect(baseline).toContain("`396514c8f5183324e6c8d0a16d7a5d339b2cbb72`"); - expect(baseline).toContain("PR #560의 ADR 0015는 candidate-only `Proposed`"); + expect(baseline).toContain("ADR 0015는 protected source에 포함됐지만 상태는 `Proposed`"); + expect(baseline).toContain("merged #560 + issue #561"); + expect(baseline).toContain("append-only versioned lifecycle stream"); expect(baseline).toContain("context-graph-contracts"); expect(baseline).toContain("live plugin installation 또는 buyer completion을 주장하지 않는다"); expect(baseline).toContain("immutable Noema release");