-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathphases.jsonl
More file actions
29 lines (29 loc) · 43 KB
/
Copy pathphases.jsonl
File metadata and controls
29 lines (29 loc) · 43 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
{"id":"STACK-0","priority":0,"title":"repository, naming, and evidence baseline","status":"done","deps":[],"gate":"A fresh checkout from the graphrefly-stack remote installs with pinned pnpm, passes pnpm check, imports @graphrefly/ts, and exposes only the active GraphReFly Stack identity outside explicitly superseded historical records.","deliverables":["toolchain","renamed repository metadata","public/private evidence boundaries","initial product records"],"refs":["D4","D5","D9","M1","M3","M4"],"note":"Verified from origin/main at 140c1d6415861739ba9ab3e52aed1e8193347745 with the user-reported fresh-checkout transcript recorded in M4."}
{"id":"STACK-1","priority":1,"title":"canonical authority and project workflow system","status":"done","deps":["STACK-0"],"gate":"Every structured concern has one indexed JSONL authority; the STACK sequencer and project-local stack-* skills pass reproducible validation; milestone provenance records the baseline and pivot commits.","deliverables":["docs/sources.jsonl","canonical sequencer","stack decision/design/dispatch/QA skills","long-lived Goal dispatcher","milestone provenance"],"refs":["D6","D7","D13","D14","M2","M4","M5"],"note":"The fresh checkout verified all canonical authorities and the four gate-owning skills; D14 adds a validated flow-only Goal dispatcher without creating a competing source of truth."}
{"id":"STACK-2","priority":2,"title":"freeze the flagship semantic-stack demo contract","status":"done","deps":["STACK-1"],"gate":"One refresh-token-rotation stack specifies the task, GPT-5.6 ChangePlan, real commit lineage, commit-indexed blueprints, concurrent architecture change, clean Git rebase, selective invalidation, replan, GateResult recovery, high-level review, and 90-second judge path.","deliverables":["scenario records","commit and blueprint fixture outline","semantic review storyboard","open-question resolution"],"refs":["D15","SC1","SC2","SC3","SC4","SC5","SC6","SC7","SC8","SC9","M6"],"note":"D15 and SC1-SC9 lock the exact refresh-token task, disjoint real-Git lineage, broker invalidation, selective recovery assertions, controls, and 90-second judge path."}
{"id":"STACK-3","priority":3,"title":"lock domain contracts and invariants","status":"done","deps":["STACK-2"],"gate":"Versioned schemas and golden deterministic bytes cover current-valid, clean-rebase-semantic-stale, unrelated-change-still-valid, stale-parent, forged-or-wrong-scope, and fresh-selective-replan cases.","deliverables":["BlueprintProvider and capability schema","BlueprintSnapshot and BlueprintDelta schemas","ChangePlan and WorkUnit schemas","SemanticChangeRecord schema","Evidence and GateResult schemas","contract tests"],"refs":["D16","C7","C8","C9","C10","C11","C12","C13","C14","E2","E3","E4","M7"],"note":"Strict draft-07 schemas, pinned validation, RFC 8785 canonical bytes, immutable rebind semantics, fixed reason ordering, six SHA-256 golden cases, and evidence boundaries pass contract and project checks."}
{"id":"STACK-4","priority":4,"title":"choose the smallest deployable architecture","status":"done","deps":["STACK-3"],"gate":"An accepted decision identifies the TypeScript package boundaries, canonical CLI commands and JSON output, local UI framework, Git adapter, GraphReFly provider seam, Codex runtime seam, fixture storage, and live-versus-replay flow without a services split.","deliverables":["architecture decision","runnable CLI shell","runnable local UI shell"],"refs":["D4","D5","D10","D11","D17","C1","C6","C15","C16","C17","C18","M8"],"note":"D17 and C15-C18 are implemented as four private TypeScript workspaces, one strict-envelope CLI shell, and one same-process React review shell; M8 records deterministic build, architecture, browser, security-header, and responsive evidence."}
{"id":"STACK-5","priority":5,"title":"build the deterministic semantic-stack slice","status":"done","deps":["STACK-4"],"gate":"All golden cases pass locally, produce stable evidence bundles, and prove that a clean Git rebase cannot override a stale architectural witness.","deliverables":["Git stack fixture","commit-indexed GraphReFly snapshots","claim validation","impact and freshness engine","checks","GateResult","selective invalidation","bundle export"],"refs":["P12","P13","E2","E3","E8","E9","D17","C15","C16","C17","C18","M8","M9"],"note":"M9 verifies byte-stable real Git objects, detached permission-limited GraphReFly snapshots, real fixture checks, all six deterministic semantic cases, selective U2/U3 recovery, strict CLI exits, a hash-verified redacted bundle, and synchronized read-only web review."}
{"id":"STACK-6","priority":6,"title":"integrate GPT-5.6 and Codex behind the verified seam","status":"done","deps":["STACK-5"],"gate":"Real GPT-5.6 ChangePlan and selective-replan outputs replace their fixtures without changing deterministic GateResult semantics; provider failure falls back to replay safely.","deliverables":["Codex SDK integration","structured proposal schemas","grounded prompts","output validation","model configuration","usage and provenance capture","replay cache"],"refs":["D5","D10","P7","P11","C6","C17","C18","C19","M9","M10"],"note":"M10 verifies real gpt-5.6-sol plan and corrected selective-replan proposals through Codex SDK 0.143.0 with an explicit compatible runtime override, strict anchor and policy validation, exact redacted provenance, explicit-only fallback, and invariant deterministic gate semantics."}
{"id":"STACK-7","priority":7,"title":"build the synchronized Git and Blueprint review UI","status":"done","deps":["STACK-6"],"gate":"A first-time user selects each real U1-U3 commit and sees the full GraphBlueprint produced by upstream graph.blueprint() at that Git object, a highlighted structural delta from its real stack parent, the synchronized deterministic gate state, and a GitHub-style parsed code diff; primary UI contains no implementation/session/provenance clutter or inert controls, relevant secondary details are collapsible, and the complete path works on desktop and mobile within 90 seconds.","deliverables":["real GraphReFly fixture modules","A1 and per-commit runtime GraphBlueprint snapshots","deterministic commit-parent deltas","GitLens-style commit graph","full Blueprint diagram","claim-impact highlighting","GateResult","GitHub-style code diff","collapsible change and check details","bundle export"],"refs":["D12","D18","P14","P16","C5","C20","SC10","E1","E8","M14"],"note":"M14 supersedes the earlier M11 projection: the corrected gate executes pinned GraphReFly modules in real detached Git worktrees, validates graph.blueprint() truth against describeToMermaid() structure, renders that source with Mermaid, synchronizes all U1-U3 evidence, and passes desktop plus 390px browser QA."}
{"id":"PRODUCT-0","priority":8,"title":"land upstream Blueprint product APIs","status":"done","deps":["STACK-7"],"gate":"A pinned published @graphrefly/ts release based on 0.2.1 or later emits GraphBlueprint v2 with stable Graph-owned subgraph mount identity and provides version-aware parsing and validation, canonical hash verification, deterministic GraphBlueprint-direct readable rendering, and canonical node, edge, metadata, and subgraph deltas with upstream acceptance tests and a Stack compatibility fixture.","deliverables":["upstream Blueprint API design","GraphBlueprint v2 stable mount identity","GraphBlueprint parser and validator","hash verifier","Blueprint-direct readable renderer","canonical structural delta","published pinned release","Stack compatibility fixture"],"refs":["D21","D24","P19","C23","C26","N6","M15"],"note":"@graphrefly/ts 0.3.0 is published and exactly pinned for the Stack compatibility gate. M15 verifies its public graph and render exports from the npm installation, including stable v2 mount identity, parsing and freezing, hash verification, Blueprint-direct Mermaid, node, edge, metadata, and subgraph deltas, fail-closed cases, offline frozen installation, and the full Stack check."}
{"id":"PRODUCT-1","priority":9,"title":"build the generic linear GraphReFly repository review","status":"done","deps":["PRODUCT-0"],"gate":"The same public CLI command reviews at least two compatible repositories, including one non-flagship small repository, discovers a real linear stack without fixture IDs, executes each revision with the target repository's pinned GraphReFly runtime, and synchronizes per-commit upstream GraphBlueprint v2 delta and GitHub-style code diff in the local UI with focused failure and browser evidence.","deliverables":["repository config contract","generic target-runtime provider","linear Git range discovery","generic review payload","per-commit upstream Blueprint delta","structured code diff","non-flagship sample repository","conformance and browser tests","redacted evidence"],"refs":["D22","D24","D25","P17","P20","C21","C23","C24","C25","C26","C27","SC11","E12","M16"],"note":"M16 validates D25 and C27 end to end: the same public review command discovers real flat and mounted Git stacks, uses each target repository's exact 0.3.0 runtime and upstream-only Blueprint v2 helpers, synchronizes commit, diagram, delta, and split diff without fixture identities or a fake gate, fails closed for every SC11 error case, and passes desktop and mobile browser QA. Per-revision installs and monorepo package selection remain deferred in B14."}
{"id":"PRODUCT-2","priority":10,"title":"ship the installable grfs local runner","status":"done","deps":["PRODUCT-1"],"gate":"One npm tarball installed as @graphrefly/stack in an independent compatible repository exposes pnpm exec grfs, generates onboarding files from explicit graph-module input, accepts 0.3.x-compatible manifests across ordinary dependency changes, runs generic review without workspace-relative files, and serves the embedded UI; malformed onboarding and incompatible runtime ranges fail closed.","deliverables":["single publishable npm package","grfs binary","grfs init onboarding","0.3.x runtime compatibility","ordinary dependency-change review","embedded schemas and UI","npm pack isolated install test"],"refs":["D27","C29","B14","P20","E12","M18"],"note":"M18 verifies a packed @graphrefly/stack 0.1.0 tarball through pnpm exec grfs in an independent GraphReFly 0.3.x Git repository, including generated onboarding, real Blueprint and Git deltas, embedded UI serving, package and lockfile changes, fail-closed inputs, and the complete project gate. Registry publication remains an explicit external action."}
{"id":"PRODUCT-VERIFY","priority":11,"title":"user acceptance of the installable grfs product","status":"done","deps":["PRODUCT-2"],"gate":"The user follows the documented registry-equivalent steps in an independent GraphReFly repository and confirms that grfs init, real linear stack discovery, branch context, per-commit Blueprint diagram and delta, GitHub-style code diff, help guidance, and durable local approve or request-changes review work without the Stack workspace or working-tree artifact noise.","deliverables":["user-run verification transcript","usable split-diff layout","on-demand Git-Blueprint-diff help","strict .git/grfs review decisions and portable review export","accepted product boundary or concrete defects"],"refs":["D27","D28","D29","C29","C31","P20","P23","M18","M19","M20","M21","M22","M23"],"note":"M20 validates the corrected local review workflow, M22 verifies the published 0.1.2 package and independent three-commit browser path, and M23 records the user's explicit confirmation that they already verified and accepted that workflow in ~/src/test-graphrefly. The bounded local product is accepted without claiming production completeness; PRODUCT-ROADMAP is now ready and event-delivery work remains parked."}
{"id":"PRODUCT-ROADMAP","priority":12,"title":"select the next production-grade product tranche","status":"done","deps":["PRODUCT-VERIFY"],"gate":"A project-adapted nine-question design review orders the committed P22 roadmap, selects the next smallest production-usable tranche, defines its user, domain, Git and Blueprint model, trust and privacy boundary, failure semantics, UX, migration, acceptance evidence and explicit non-goals, then adds only its approved implementation phases to the canonical sequencer.","deliverables":["nine-question product review","ordered roadmap dependencies","next production-usable tranche","locked contracts and success criteria","approved implementation phases","explicit deferred capabilities"],"refs":["D23","D30","D31","P22","P24","P25","P26","N9","C32","C33","C34","C35","C36","B1","B4","B7","B8","B9","B10","B11","B12","B14","B15","B16","B17","M23","M24"],"note":"The user approved the complete Q1-Q9 recommendation. D31, P25-P26, N9 and C32-C36 lock the repository-owned semantic lifecycle tranche and ordered later roadmap; only PRODUCT-SEMANTIC-0 is ready, later phases remain blocked, and event-delivery work stays parked."}
{"id":"PRODUCT-SEMANTIC-0","priority":13,"title":"lock the generic semantic lifecycle wire contracts","status":"done","deps":["PRODUCT-ROADMAP"],"gate":"A separately versioned strict semantic repository contract family and byte-stable golden suite define repository policy, typed Blueprint predicates, accepted ChangePlan and WorkUnits, Git trailer binding, model context manifest, immutable SemanticChangeRecord derivation, checks, GateInput, GateResult and SelectiveReplan. Golden cases cover normal valid, clean-rebase architecture stale with selective dependency invalidation, unrelated immutable rebind, missing or duplicate trailer, ambiguous or unsupported predicate, widened scope or check, policy freshness, artifact tamper and unauthorized live context without implementing runtime behavior.","deliverables":["semantic repository policy schema","typed Blueprint predicate schema","accepted ChangePlan and WorkUnit schemas","commit trailer binding contract","model context manifest schema","SemanticChangeRecord and deterministic gate schemas","selective replan schema","byte-stable golden suite","migration and compatibility contract tests"],"refs":["D16","D19","D20","D21","D24","D31","P11","P17","P18","P26","C7","C8","C9","C10","C11","C19","C21","C23","C26","C32","C33","C34","C35","C37","E3","E4","E8","E9","M25"],"note":"C37 locks the exact additive v1 schema IDs, normalized path and mount semantics, fixed reason order, JCS and SHA-256 bytes, storage split and packaged twelve-case golden suite. M25 verifies the full contract, package and project gates without implementing runtime behavior."}
{"id":"PRODUCT-SEMANTIC-1","priority":14,"title":"build generic semantic planning and commit binding","status":"done","deps":["PRODUCT-SEMANTIC-0"],"gate":"The installed grfs package in at least two independent compatible repositories can create replay or explicitly authorized live typed plan drafts, reject widened context and invalid claims, explicitly accept a repository policy and ChangePlan before implementation, discover exactly one stable WorkUnit trailer per linear implementation commit, and derive immutable bindings without workspace reads, source mutation during review or fixture identities.","deliverables":["repository semantic onboarding","generic plan provider request","explicit model context authorization","plan draft and acceptance flow","Git-owned policy and plan artifacts","stable WorkUnit trailer discovery","immutable commit binding","independent package tests"],"refs":["D10","D19","D20","D27","D29","D31","P7","P11","P17","P18","P26","C19","C21","C29","C31","C32","C33","C35","C37","C38","M25","M26","PRODUCT-SEMANTIC-0"],"note":"C38 and M26 verify replay and explicitly authorized live proposal admission, explicit Git-owned acceptance, strict acceptance commits, exact linear WorkUnit trailer discovery and immutable content-addressed bindings in flat and mounted workspace and installed-package repositories."}
{"id":"PRODUCT-SEMANTIC-2","priority":15,"title":"build generic deterministic gate and selective recovery","status":"done","deps":["PRODUCT-SEMANTIC-1"],"gate":"For adopted compatible repositories, grfs gate deterministically constructs current semantic records and returns pass, blocked or error with stable ordered reasons; a clean architecture-changing rebase selectively invalidates impacted work, an unrelated change immutably rebinds unaffected work, allowlisted checks and policy freshness are enforced, live or replay replan replaces only invalid WorkUnits, and the local UI synchronizes plan intent, claim impact, GateResult, exact witnesses, checks, Git, Blueprint and code diff while keeping ReviewDecision separate and not-configured repositories structural-only.","deliverables":["generic GateInput builder","typed claim evaluator","policy and check runner","immutable rebind engine","generic GateResult CLI","selective replan","semantic review projection","portable semantic export","focused failure and browser tests"],"refs":["D10","D12","D16","D31","P11","P12","P13","P14","P26","C4","C5","C9","C10","C11","C13","C19","C31","C32","C33","C34","C35","C36","C37","C38","C39","M26","M27","M28","E8","E9","E10","PRODUCT-SEMANTIC-1"],"note":"C39 and M27 verify strict generic GateInput and GateResult construction, finite predicate witnesses, policy-bounded isolated checks, unrelated immutable rebind, architecture-selective invalidation, replay and authorized-live recovery with preserved bindings, additive semantic review, redacted portable export and installed-package HTTP serving. M28 subsequently closes installable lifecycle verification; event-delivery work remains deferred and parked."}
{"id":"PRODUCT-SEMANTIC-VERIFY","priority":16,"title":"verify the installable repository semantic lifecycle","status":"done","deps":["PRODUCT-SEMANTIC-2"],"gate":"A packed and registry-equivalent @graphrefly/stack installation passes the semantic lifecycle in materially different independent GraphReFly repositories: normal plan and gate, clean Git rebase with selective architecture-stale invalidation, unrelated rebind, selective recovery, malformed or tampered artifacts, unauthorized model context, scope, policy and check failures, deterministic byte replay, explicit live provenance, portable export, desktop and mobile review, no review-generated worktree noise and the complete stack-qa gate. The evidence states remaining topology, runtime, hosted and integration limits without starting event-delivery work work.","deliverables":["independent repository conformance fixtures","installable semantic package test","normal and adversarial semantic evidence","live and replay provenance","privacy and security evidence","portable semantic bundle","user acceptance path","complete QA verdict"],"refs":["D5","D10","D20","D27","D29","D31","P7","P13","P18","P26","N9","C8","C19","C22","C28","C29","C31","C32","C33","C34","C35","C36","C39","M27","M28","E1","E3","E4","E5","E6","E8","E9","E11","E12","PRODUCT-SEMANTIC-2"],"note":"M28 verifies the expanded packed-package lifecycle in independent flat and mounted repositories, including unrelated rebind, architecture-selective invalidation, unauthorized-live rejection, accepted selective recovery with preserved bindings, policy and local artifact tamper, strict portable verification, responsive semantic HTTP assets, no worktree noise and the complete gate. No credentialed model request or public evidence mutation is claimed; event-delivery work remains manually blocked and parked."}
{"id":"PRODUCT-CI","priority":17,"title":"deliver CI and required-check parity","status":"done","deps":["PRODUCT-SEMANTIC-VERIFY"],"gate":"A packed repository-pinned @graphrefly/stack installation generates and executes the D33 GitHub Actions pull-request workflow in materially different independent compatible repositories. The strict v1 adapter binds exact platform and Git identities, deterministically selects one tip-covering plan, invokes the unchanged canonical gate, proves local and CI GateInput and GateResult equality, maps pass to required-job success and blocked or error to failure, preserves redacted content-addressed evidence for seven days, and fails closed for architecture staleness, unrelated rebind, stale or ambiguous revision, zero or multiple plans, malformed event, fork permissions, dependency lifecycle scripts, missing sandbox, cancellation, rerun and tamper without secrets, cached verdicts, source upload, repository mutation, merge-group support or event-delivery work work. At least one explicitly authorized real GitHub pull-request run confirms the generated required job outside the workspace, and the complete stack-qa gate passes.","deliverables":["D33 approved CI decision","strict CI invocation and result schemas plus golden bytes","grfs ci init and run surfaces","deterministic GitHub Actions pull-request workflow","tip-covering plan discovery","least-privilege fork-safe execution","dependency-only cache and seven-day redacted artifact","event and lifecycle adversarial suite","independent packed-package conformance","authorized real required-job evidence","complete stack-qa verdict"],"refs":["D10","D19","D20","D31","D32","D33","D34","D35","P11","P17","P18","P25","P27","P28","N10","C4","C8","C9","C10","C11","C17","C21","C22","C29","C34","C38","C39","C40","C41","C42","B4","E8","E10","E11","E13","M28","M30","M31","M32","M33","M34","AP10"],"note":"M31 verifies local implementation and stack-qa, M32 proves registry 0.1.2 predates CI, and M33 preserves the 0.1.4 hosted-runner incompatibility finding. D35 then locks the minimal generator repair without weakening the sandbox. M34 proves that immutable public 0.1.5 source and installed-tarball conformance emit the same Ubuntu 22.04 workflow, that its exact bytes pass the protected public pull-request required job with a fully revalidated redacted artifact, and that next and latest now point to those verified bytes. PRODUCT-CI is complete. GitHub App, Check Runs, annotations, OIDC attestations, hosted upload, direct push gating and merge-group support remain outside v1; merge queues wait for PRODUCT-DAG, and event-delivery work remains parked."}
{"id":"PRODUCT-HOSTED","priority":18,"title":"build hosted identity, teams, and redacted persistence","status":"done","deps":["PRODUCT-CI"],"gate":"An approved complete Q1-Q9 design first locks tenancy, authentication and authorization, repository installation, runner-to-control-plane protocol, redaction, retention, deletion, audit, availability and cost boundaries. The implemented tranche then proves that a repository-owned runner can authenticate, upload only schema-valid policy-selected content-addressed redacted envelopes, and let an authorized team discover and review immutable GateResult and human-decision history without uploading raw source, unredacted Blueprints, raw model or check output, credentials or repository execution, while local and CI operation remain usable when the hosted service is unavailable.","deliverables":["approved hosted Q1-Q9 decision","tenant and repository identity model","authenticated redacted upload protocol","immutable evidence index and retention policy","team authorization and audit log","hosted read-only review projection","offline and outage behavior","privacy, deletion, abuse and cost evidence","complete stack-qa verdict"],"refs":["D20","D23","D32","D36","P18","P22","P25","P27","P29","P30","N11","C22","C28","C31","C35","C39","C43","C44","C45","C46","C47","B1","E6","E11","E14","M34","M35","M36","M37","M38","M39","M40"],"note":"M35-M39 verify the wire, cryptographic ingest core, production-shaped persistence lifecycle, browser identity, role intersection, decisions, audit and read-only projection. M40 completes the permitted hermetic E14 shape with concrete GitHub App source-run and artifact authorization, bounded canonical ZIP extraction, exact downloaded-CI cross-binding, PostgreSQL browser identity queries, secure cookie and CSRF HTTP composition, responsive no-script web projection and integrated public/private pass, blocked and error conformance. Deployment, concrete cloud drivers and external provider lifecycle evidence remain explicit post-gate operational work rather than claimed here; PRODUCT-COLLAB is ready and event-delivery work remains parked."}
{"id":"PRODUCT-COLLAB","priority":19,"title":"gate pull-request semantic integration","status":"done","deps":["PRODUCT-HOSTED"],"gate":"The approved D37 Q1-Q9 design is implemented as one repository-owned optimistic integration boundary. For an exact unique merge base, current target and immutable merge-free pull-request head, the runner constructs a real isolated Git three-way candidate without changing source worktree files, refs or commits; derives verified base, target, head and candidate GraphBlueprints plus both branch deltas; reuses the unchanged semantic GateResult; and emits a strict deterministic IntegrationResult that distinguishes compatible shared graph identity from textual conflict, incompatible graph effects, invalid combined topology, stale claims, dependencies or policy, ambiguous ancestry, execution failure and tamper. Target movement makes old evidence stale, local and CI bytes agree, recovery produces new evidence, no merge is performed, and complete stack-qa passes.","deliverables":["D37 approved optimistic integration decision","strict IntegrationCandidate and IntegrationResult schemas plus golden bytes","isolated three-way candidate builder","base, target, head and candidate Blueprint evidence","graph identity and semantic witness conflict engine","local CLI and pull-request required-check composition","staleness and recovery behavior","independent repository conformance","complete stack-qa verdict"],"refs":["D9","D10","D19","D20","D33","D37","P11","P13","P17","P18","P28","P31","P32","N12","C2","C3","C4","C8","C9","C10","C21","C22","C26","C32","C33","C34","C39","C40","C41","C42","C48","B10","E8","E9","E10","E11","E15","M41","M42","M43","M44","M45","M46","M47","M48","M49","M50","M51","M52","M53","AP1","AP7","AP8","AP9"],"note":"M41-M53 satisfy D37, C48 and E15 with strict candidate/result bytes, isolated Git and GraphReFly evidence, exact overlap and conflict witnesses, typed failure and drift, byte-identical local and pull-request CI adapters, installable flat and mounted conformance, recovery and complete stack-qa. PRODUCT-DAG is next; reservations and event-delivery work remain outside."}
{"id":"PRODUCT-CONFLICT","priority":20,"title":"consider preventive coordination only from usage evidence","status":"deferred","deps":["PRODUCT-COLLAB"],"gate":"This phase is no longer part of the fixed product sequence. It may be redesigned and reactivated only if real PRODUCT-COLLAB usage proves that pull-request-time optimistic semantic integration cannot safely coordinate a concrete workflow and identifies the smallest additional pre-implementation signal required.","deliverables":["external usage evidence","new Q1-Q9 design","explicit reactivation decision"],"refs":["D37","P31","N12","B9","B11"],"note":"The earlier reservation and proactive-preflight design was superseded by D37. No lease, actor credential or pre-implementation prediction work is authorized."}
{"id":"PRODUCT-DAG","priority":21,"title":"extend semantic stacks to DAG topology","status":"done","deps":["PRODUCT-COLLAB"],"gate":"The approved D38 and D42 designs are implemented as additive topology, semantic, review and multi-Plan merge-group contracts without changing verified v1 or existing v2 bytes. For one explicit ancestor base and head, at most 64 selected Git objects, topological width eight and binary parentage, the repository-owned runner derives every exact Git object and ordered parent, executes and verifies GraphBlueprint evidence at every object, binds normal one-parent implementation commits to repository-scoped planId and workUnitId identities, proves two-parent commits as clean transport-only joins, and evaluates separate acyclic per-Plan semantic dependency graphs in canonical partial order. It fails closed for ambiguous ancestry or ownership, unsupported topology, unattributed merge resolution, invalid claims, dependencies, policy, joins, runtime or artifacts; preserves unaffected branches; emits exact parent, join, semantic and cross-Plan integration witnesses; recovers only through new immutable evidence; explicitly converts valid linear v1 evidence without reinterpreting old bytes; supplies one decision-first DAG review projection and a one-to-eight-Plan clean-merge merge_group aggregate through the same domain results; leaves source worktree, refs and commits unchanged; and passes complete stack-qa plus independent packed conformance.","deliverables":["D38 and D42 approved DAG and multi-Plan decisions","strict v2 topology, binding, record, gate and review contracts plus golden bytes","bounded Git DAG discovery and clean binary join reconstruction","per-object GraphReFly evidence and parent deltas","partial-order semantic gate and selective invalidation","immutable rebase, cherry-pick, implementation-change and selective-replan recovery","decision-first DAG review visualization","explicit v1 linear conversion","Plan-qualified commit and multi-Plan aggregate contracts","real join and group integration evaluation","bounded clean-merge merge_group required-check adapter","independent DAG and merge-group conformance repositories","complete stack-qa verdict"],"refs":["D19","D37","D38","D39","D40","D41","D42","D43","P17","P31","P32","P33","P34","N12","N13","N14","C2","C9","C10","C12","C21","C34","C42","C48","C49","C50","C51","C52","C53","C54","C55","B7","B18","B19","B20","B21","E16","E17","AP7","AP8","M53","M54","M55","M56","M57","M58","M59","M60","M61","M62","M63","M64","M65","M66","M67","M68","M69","M70","M71","M72"],"note":"D38-D43, C49-C55 and M54-M72 complete the bounded additive DAG product: exact Git and GraphReFly topology, partial-order semantic gates and structural failures, immutable rebase and cherry-pick evidence, decision-first review, automatic topology routing, explicit v1 conversion, Plan-qualified multi-Plan merge_group evaluation, independent packed conformance, fresh implementation-change gates and independently verified selective-replan lineage all pass complete stack-qa without changing verified v1 or DAG v2 bytes. B18-B21 remain explicit unsupported or trigger-gated work."}
{"id":"PRODUCT-ROLLBACK","priority":22,"title":"deliver evidence-backed rollback and dependent recovery","status":"done","deps":["PRODUCT-DAG"],"gate":"The approved D44 design is implemented as an additive repository-owned recovery operation. From exact current DAG evidence and one or more Plan-qualified WorkUnit records, it derives a reproducible dependant impact closure and separately accepted recovery-step DAG with per-unit inverse, compensate or retain dispositions; requires an exact explicit local authorization before isolated recovery-ref mutation; records partial execution as a content-addressed resumable or abortable attempt chain; and independently proves a RecoveryResult that covers every required disposition and embeds the unchanged canonical post-recovery DAG GateResult. Git success, review or hosted identity never supplies semantic recovery or execution authority; drift, ambiguity, incomplete dependants, unresolved external effects and tamper fail closed; the caller worktree and non-recovery refs remain unchanged; complete E18 and stack-qa evidence pass.","deliverables":["D44 approved recovery decision","strict recovery impact, plan, authorization, attempt and result schemas plus golden bytes","Plan-qualified target and dependant impact engine","inverse and compensating recovery-step DAG","explicit isolated recovery-branch authorization and CAS boundary","post-recovery unchanged DAG GateResult workflow","content-addressed partial-failure, resume and abort protocol","audit and portable evidence projection","independent DAG recovery and packed conformance","complete stack-qa verdict"],"refs":["D9","D10","D12","D16","D20","D29","D36","D38","D43","D44","P35","N15","C4","C8","C9","C10","C11","C13","C22","C49","C50","C54","C55","C56","B12","E8","E9","E18","AP8","M73"],"note":"D44, P35, N15, C56, E18 and M73 complete the additive recovery v1 product: exact WorkUnit or whole-Plan targets, canonical dependant impact, accepted inverse, compensation or retain steps, isolated explicitly authorized recovery-ref mutation, append-only resume or abort evidence, portable independent verification and the unchanged post-recovery DAG gate all pass complete stack-qa. GraphReFly 0.3.0 and Blueprint v2 evidence remain exact; semantic v1, DAG v2 and D43 bytes are unchanged. Release targets, external execution, push, merge, force updates, recovery-branch cleanup, hosted execution authority remain outside."}
{"id":"PRODUCT-SIMPLIFY","priority":23,"title":"make semantic review decision-sized","status":"done","deps":["PRODUCT-ROLLBACK"],"gate":"The approved D45 experience boundary is implemented without changing existing deterministic artifact bytes. One grfs review surface automatically selects exactly one compatible tip-covering accepted Plan, stays structural-only for zero on merge-free history, retains fail-closed semantic requirements for merge history, and fails closed for ambiguity; the primary local review presents Intent, expected versus observed and unexpected Reach, and unchanged Readiness reasons and next actions before raw code, with proof vocabulary confined to technical details. Normal changes, broad refactors, unexpected reach, architecture-stale promises, failed checks and responsive long histories remain truthful; the browser does not execute or translate the gate; packed conformance and complete stack-qa pass.","deliverables":["D45 approved simplification decision","automatic semantic Plan discovery","derived Intent Reach and Readiness projection","exception-first local review UI","collapsed technical evidence","broad and unexpected Reach behavior","long-history scrolling and responsive review","independent packed-package conformance","complete stack-qa verdict"],"refs":["D12","D16","D18","D25","D29","D31","D39","D40","D41","D45","P13","P14","P16","P23","P36","N16","C5","C13","C31","C34","C39","C50","C52","C53","C57","E19","AP11","M73","M74"],"note":"M74 verifies automatic Plan discovery, the decision-sized Intent, Reach and Readiness UI, secondary technical evidence, long-history scrolling, real test-graphrefly browser behavior, independent packed conformance and complete stack-qa. No existing deterministic artifact bytes changed."}
{"id":"PRODUCT-FLOW-DESIGN","priority":24,"title":"design the ordinary developer-reviewer correction loop","status":"done","deps":["PRODUCT-SIMPLIFY"],"gate":"A stack-design-review nine-question packet locks the smallest user-facing loop from change intent through review, request changes, corrective commits, automatic staleness, fresh readiness and request-review-again. The design identifies what developers and reviewers see and do, what the repository-owned runner derives invisibly, what existing contracts remain unchanged, and what ritual is removed; it uses the real test-graphrefly workflow and does not introduce a new proof authority or expose internal evidence vocabulary as required user input.","deliverables":["Q1-Q9 user and scenario lock","developer and reviewer action model","automatic derivation boundary","request-changes and correction lifecycle","staleness and fresh-evidence semantics","UI navigation and action model","CLI and CI parity boundary","adoption and failure evidence plan","approved PRODUCT-FLOW implementation gate"],"refs":["D29","D45","D47","D48","P23","P36","P37","P38","N17","C13","C31","C52","C57","C58","E20","AP11","M74"],"note":"The user approved D48 after the complete Q1-Q9 review: whole-change decisions, same-branch corrective commits, exact automatic outdated history and provider-native re-request guidance are locked; line comments and provider mutation remain deferred."}
{"id":"PRODUCT-FLOW","priority":25,"title":"deliver the ordinary developer-reviewer correction loop","status":"done","deps":["PRODUCT-FLOW-DESIGN"],"gate":"The approved D48 and C58 correction loop works through the one grfs review surface for compatible structural, semantic and bounded DAG changes: review decisions target the whole exact current change; request changes remains append-only; a same-branch correction produces fresh deterministic review evidence and visibly outdated prior decisions; current human state returns to Needs review independently of unchanged Readiness semantics; a new decision binds only the fresh target; the UI explains provider-native re-request without a fake notification action; old generic v1 and DAG v2 records remain verifiable; current generic decisions export through strict portable v2; real test-graphrefly, independent packed repositories, desktop and mobile behavior and complete stack-qa pass without source or Git mutation, line-comment relocation, provider credentials, merge authority or internal evidence ritual.","deliverables":["additive generic review decision and bundle v2 contracts","whole-change review target digest","append-only current and outdated decision projection","same-branch correction and fresh review lifecycle","generic and DAG UI history and human status","provider-native re-request guidance","v1 and DAG compatibility evidence","real repository and packed-package conformance","complete stack-qa verdict"],"refs":["D16","D20","D29","D40","D45","D47","D48","P23","P36","P37","P38","N17","C13","C22","C31","C52","C57","C58","E20","AP11","M74","M75"],"note":"M75 verifies the whole-change decision target, same-branch correction and exact outdated history, independent human status and Readiness, provider-native guidance, strict portable v2 integrity, generic v1 and DAG v2 compatibility, real test-graphrefly browser behavior, independent packed conformance and complete stack-qa without source or Git mutation."}
{"id":"PRODUCT-RELEASE","priority":26,"title":"automate reviewed npm releases","status":"done","deps":["PRODUCT-FLOW"],"gate":"The approved D49 and C59 release path turns repository-owned Changesets into one reviewable version PR and, only after its merge, an exact @graphrefly/stack npm release from main. Pull requests have no publish identity; the release job uses the bounded GitHub App token for release PR, tag and GitHub release maintenance and npm OIDC Trusted Publishing without NPM_TOKEN; concurrency cannot race; the full pnpm check and independent packed consumer pass before publish; the initial pending patch versions 0.1.7 to 0.1.8; static workflow and isolated versioning evidence satisfy E21; product evidence and GateResult semantics remain unchanged. The phase may close before the one-time external Trusted Publisher binding or first live workflow publish only if those prerequisites are named and no external release success is claimed.","deliverables":["D49 approved release decision","Changesets configuration and contributor command","PRODUCT-FLOW patch changeset","generated changelog path","read-only pull-request CI","non-cancelling release workflow","GitHub App release-PR authority","npm OIDC Trusted Publishing boundary","isolated version and tarball proof","complete stack-qa verdict"],"refs":["D4","D6","D7","D13","D47","D49","P39","N18","C29","C59","E6","E21","AP3","M75","M76","M77"],"note":"M76 verifies the release automation contract and M77 closes its live external proof: reviewed release PR #1, successful CI and non-cancelling Release runs, one exact annotated Git tag and GitHub Release, npm 0.1.8 under latest, registry integrity and SLSA provenance all bind merge commit e3991014ea967c89bb1d445e0bd84a74b4a5385f. The canonical sequencer has no remaining ready phase; a new product tranche requires explicit design approval."}
{"id":"PRODUCT-DOGFOOD","priority":27,"title":"dogfood the published advanced review journey","status":"done","deps":["PRODUCT-RELEASE"],"gate":"Without changing the established /Users/davidchenallio/src/test-graphrefly main or codex/ci-semantic-gate-proof tips, original checkout files, HEAD, index, uncommitted 0.1.6 dependency change or existing review records, a linked worktree creates dedicated local codex/dogfood-dag-* refs that install the exact public @graphrefly/stack 0.1.8, accept one bounded two-WorkUnit scenario and produce two independent qualified implementations plus one clean transport join. A prospective user can run the single grfs review surface from the scenario base to final join and observe automatic bounded DAG routing, decision-sized review and whole-change review state; exact integration and correction variants may follow only within those dedicated refs. Evidence distinguishes user-visible actions from repository-owned derivation, records setup friction and hidden vocabulary for the later adoption Q1-Q9, verifies protected checkout and branch witnesses remain unchanged, and does not add product semantics, deploy hosted infrastructure, execute rollback, activate deferred capabilities or push external state.","deliverables":["protected-reference before and after witness","linked public-0.1.8 scenario worktree","accepted two-WorkUnit scenario","independent qualified implementation branches","clean transport join","automatically routed bounded DAG walkthrough","whole-change review-state walkthrough","user-visible versus internal action inventory","observed adoption-design inputs","focused package and browser evidence"],"refs":["D37","D41","D45","D48","D49","D51","D52","P32","P33","P36","P38","P39","P40","N19","C48","C53","C57","C58","C59","AP11","M77","M78"],"note":"M78 completes the protected public-0.1.8 exercise: dedicated local refs expose two parallel implementation lanes, one clean binary join, both parent comparisons and the whole-change correction lifecycle while the original checkout and established refs remain byte-exact and no remote refs are created. Dogfood deliberately does not claim P40 adoption success: automatic topology routing works, but stale incompatible Plan discovery and repository-policy replacement remain observed normal-path friction for D52 and PRODUCT-ADOPTION-DESIGN."}
{"id":"PRODUCT-ADOPTION-DESIGN","priority":28,"title":"design the ten-minute ordinary adoption journey","status":"ready","deps":["PRODUCT-DOGFOOD"],"gate":"A stack-design-review nine-question packet starts from M78's exact public-package consumer journey and locks the smallest ordinary path from installation to a first useful pull-request review. It decides how compatible accepted intent is found, how repository policy evolves, which setup the tool or repository owner derives, what a developer and reviewer actually see and do, and how existing fail-closed evidence and advanced diagnostic escape hatches remain available without turning Plan, WorkUnit, policy, binding, predicate or witness vocabulary into required user ritual. The design names measurable success and failure evidence in test-graphrefly, preserves existing deterministic bytes and does not authorize implementation until the user approves all nine answers.","deliverables":["Q1-Q9 adoption scenario and user lock","ten-minute developer and reviewer journey","compatible intent discovery design","repository policy lifecycle design","automatic derivation and hidden-internal boundary","ordinary failure and recovery language","advanced diagnostic escape-hatch boundary","real consumer acceptance evidence plan","approved PRODUCT-ADOPTION implementation gate"],"refs":["D45","D48","D51","D52","D53","P36","P38","P40","N19","C57","C58","AP11","M78","M79"],"note":"D53 and M79 repair the dogfood review workspace without claiming this design gate: real Git lanes, target-runtime GraphReFly diagrams, structured diffs and stable selection are now the user-facing baseline. Run the remaining stack-design-review Q1-Q9 next, and treat the public-0.1.8 --plan-id workaround and manual repository-policy replacement as defects to eliminate rather than concepts to document for ordinary users."}