Skip to content

Clarify source intake and current-subject review - #136

Merged
iperev merged 1 commit into
mainfrom
feature/traceability-chain-closure
Sep 20, 2026
Merged

iperev merged 1 commit into
mainfrom
feature/traceability-chain-closure

Conversation

@iperev

@iperev iperev commented Sep 20, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Make seven source-intake classes discoverable through the existing six authoring reference roles. Preserve provenance, unresolved owner questions and candidate-only authority, including coverage-only observations.
  • Add demand-loaded change plan --help guidance and a checkpoint template. Explain actual current-subject construction, retained assessment identity and public successor-delta composition without claiming filesystem authentication or approval.
  • Add whole-CLI source-class and real-file current-subject controls. Keep default native-evidence JSON/text unchanged and verify installed launcher forms.
  • Repair the direct-process import guard: pure DisplayCommand is allowed; os/exec remains forbidden with ordinary, aliased, dot and blank imports and quoted or raw literals.
  • Rebind native-source digests and their generated projections. An independent complete JSON comparison confirms all other CLI contract fields are unchanged.

Validation

  • Full npm run check passed on f913073de744e41eaf618d2f8f4669c96a8453bd with repository-pinned npm 12.0.2. The final head remained unchanged and the worktree remained clean.
  • 333 browser tests passed across Chromium, Firefox and WebKit; Go/static, npm/Python packaging, self-hosting and release-closeout gates passed.
  • Targeted positive controls cover seven source classes plus PR facts, both trust modes, both authoring modes and fourteen independent current-subject operands.
  • Two isolated Go overlays reproduce the original test gaps and fail the repaired assertions: swapped intent/code role descriptions and authoring guidance added to unrelated help.
  • Forty-six retained receipt/scheduler/currentness/trust/bundle/decision handoffs were replayed on the committed CLI with complete output and diagnostic equality. This is compatibility evidence, not new native execution.
  • Five bounded independent review lanes examined the changed owners. Two test-oracle findings were confirmed and repaired with the controls above; original unresolved context rows remain retained rather than rewritten as passing reviews.
  • git diff --check passed for the committed range.

Scope And Non-Claims

This is the first independently deliverable product delta in the portable traceability batch, not completion of the entire batch. TRACEABILITY-DESIGN-01 remains active.

Remaining work includes real bounded intake and owner acceptance, the common qualified discovery/execution chain, automatic consumer-trigger integration, the scenario-storage decision and same-workflow StrictDoc/OpenSpec/TS/FastAPI comparison.

No new source format, public source-v2 cutover, input schema, native runner, approval service, arbitrary repository dependency discovery, authentication or registry publication is claimed. No design or implementation-plan documents are added to the package.

Retro

The original tests checked vocabulary membership without role/meaning pairing and checked other guides' laziness without an authoring-specific negative. Both now have isolated violating controls. A preliminary broad run was invalidated by concurrent test edits; the final successful run used one immutable commit. Active skills were not changed.

@iperev
iperev marked this pull request as ready for review September 20, 2026 12:26
@iperev
iperev merged commit 9ad627c into main Sep 20, 2026
10 checks passed
@iperev
iperev deleted the feature/traceability-chain-closure branch September 20, 2026 12:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant