Skip to content

docs: refresh live product gap baseline - #238

Draft
seonghobae wants to merge 347 commits into
mainfrom
docs/refresh-live-gap-baseline-2026-08-28
Draft

seonghobae wants to merge 347 commits into
mainfrom
docs/refresh-live-gap-baseline-2026-08-28

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 28, 2026 •

Copy link
Copy Markdown
Contributor

Scope

Canonical documentation/product-gap owner for OriginWeave. This lane keeps the buyer-facing baseline and acceptance evidence code-current while preserving dated history. It does not duplicate browser/runtime production logic or sibling-owner contracts.

Current exact head is e92917e18038fd8c2cf5979b91412ddf85d6e4ec, 347 ahead / 0 behind, directly based on protected main@87c4daa1830bac5a5228b6036752ad5633232085; merge base is exactly protected main. Ready is review/execution admission, not merge acceptance.

HTTP buyer-gap currentization

#327 is exact 0d3911e558188db805a0affbe50e53ed02b481d0, 46 ahead / 0 behind on canonical HTTP parent #37 219b43bfa87ab4fd90a77bb962df2797925bf661, with merge base exactly #37.

The earlier hosted RED on 093aa188... remains valid lineage: CI 35954076460 exposed one ADR contract drift plus one impossible parser-state coverage arm. #327 repaired those ordinary-forward with 6ce821f2... and a5f5957a...; current exact-head GREEN remains pending.

The performance path now exposes three independent non-latency authority gaps instead of allowing one to masquerade as another. Parent #37 still exposes the untimed ConnectionPlan, so canonical network owner #50 exact ad87cfea59db711cb29ef90559790ba77e22029f must land/release a FreshConnectionPlan contract; #327 remains network_acceptance_status=UNACCEPTED_PARENT_NETWORK_AUTHORITY. The benchmark payload is deliberately synthetic, so #327 emits fixture_authority=deterministic_synthetic_no_external_dataset and fixture_acceptance_status=UNACCEPTED_SYNTHETIC_FIXTURE; this fixture is regression evidence only and cannot become commercial buyer-path acceptance. Separately, the local receipt remains caller-produced evidence and therefore evidence_acceptance_status=UNACCEPTED_UNATTESTED_RECEIPT until the released/pinned ContextualWisdomLab/.github#2162 performance-attestation owner is consumed. Candidate #2166 remains mutable/Draft and is not a dependency here. Central attestation proves origin/integrity only; OriginWeave retains the p95≤20 ms policy.

The source/budget separation remains repaired lineage: test-first 495e616ac08440c3687cf76db5afe18caa2ce199 rejected source-provenance dependence on latency, and a3f7ba3c76ef47fe7ae2299a7fb4460a13f7a6d8 made explicit source provenance remain PASS independently of budget_status while keeping GITHUB_SHA fallback at UNACCEPTED_SOURCE_FALLBACK.

The leaf evidence-shaping repair also remains current. .github#2162/#2166 require exactly three root-level JSON evidence members — result, runtime and fixture — and bind selected_profile plus exact candidate_sha in result/runtime. Test-first aad07d21dce2a8534917432dda56fadc141eee47 made that handoff a repository contract, and c881bac13b202d3a5fff4c85c38f7c7d177e9482 added the strict product-owned packager for content-coding-result.json, content-coding-runtime.json, and content-coding-fixture.json with SHA-256 file identities.

The buyer-fixture audit closed the promotion bypass without inventing a corpus. Test-first cac5e1619770123d6d2b78e3ef58b9ac18647df3 requires fixture authority to be visible; repair b66ef73dfc10c60774d8388d079be9774b3f0bdd adds the fail-closed FixtureAuthoritySource; 1031b45a652959bb32c2dc9acd4dcb110e36ea38 propagates fixture authority/status into the three-file evidence package and rejects relabeling the synthetic fixture as accepted; 0d3911e558188db805a0affbe50e53ed02b481d0 binds it into the Rust receipt contract.

The next realistic-fixture authority already has a canonical owner rather than requiring a new sibling implementation: issue #203 owns benchmark corpus/source/license, case identity, data classification/retention and release-grade realistic evidence. Downstream canary comment 5817864397 records that #327 must consume an approved/versioned fixture or capture identity from #203 rather than embed an ad hoc external dataset. Network freshness remains #50; evidence origin/integrity remains .github#2162/#2166; final latency policy remains OriginWeave.

This documentation lane followed test-first/currentization order. 89c4ed255b1d2fad0deee51b541878726145f5ba first required the synthetic fixture gate, 9b4b892adee1168b7fef62e6fb8afdbc084513b5 updated the buyer row, then bdf061a01e36ec6457ce8b91f244fae51be4a451 required the canonical #203 benchmark-corpus owner route and e92917e18038fd8c2cf5979b91412ddf85d6e4ec currentized docs/product-technical-gap-baseline.md. The row remains not an accepted performance receipt and makes no ≤20 ms claim.

Current exact-head verification

Current #238 workflows on e92917e1... are nonterminal: CI 36026345672, CodeQL 36026345615, SAST Semgrep 36026345767, and Security Scan 36026345536 are pending. Predecessor receipts do not transfer. No current-head repository/security/CodeQL/review acceptance, protected integration, accepted network authority, accepted realistic fixture authority, authenticated performance attestation, latency acceptance, or release is claimed. Do not blind-rerun or create source-neutral wake commits.

Controlled-benchmark stack authority

#237 remains independently gated; #322/#324 keep ancestor-first ordinary/non-force adoption and fresh exact-head revalidation requirements. Leaf evidence does not transfer through ancestor restacks.

Acceptance

docs/product-technical-gap-baseline.md remains single-writer here. #327 does not duplicate it. #327 must consume a normally integrated released/pinned #50 network-freshness contract, consume an approved/versioned realistic buyer-path fixture/capture identity through #203, and consume a released/pinned central performance-attestation contract; then it must reacquire exact-head repository/security/review evidence and execute the governed benchmark. The three-file packager closes only local byte shaping. Authenticated attestation still requires the central owner, and commercial acceptance still requires an OriginWeave verifier that checks the authenticated result under product policy. Only explicit-source provenance PASS + accepted network authority + accepted realistic fixture authority + accepted evidence authority + p95 budget PASS may become buyer acceptance.

Preserve unchanged heads and owner-path evidence. No force push, destructive rebase, self-approval, review dismissal, bypass, gate weakening, blind rerun, source-neutral wake, protected-main merge, tag, package, publish or release is authorized by the current state.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Aug 28, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

Understand this PR’s impact

Explore downstream dependencies and potential security impact with Blast Radius.

View blast radius →

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

제품 기준선, MCP 상태 문서, 라이브 증거 수집기와 역사 계약 테스트가 갱신되었습니다. 현재 관측값과 보관된 역사 자료가 분리됩니다.

Changes

기준선 및 역사 증거 정리

Layer / File(s) Summary
구매자 기준선과 보관 증거 갱신
CHANGELOG.md, docs/product-technical-gap-baseline.md, docs/evidence/*, docs/traceability/*
현재 수령증, PR·이슈 수치, Ready 상태, exact-head 및 역사 자료를 갱신합니다.
유지보수 및 릴리스 계약 기록
AGENTS.md, docs/evidence/AGENTS-through-2026-09-09.md, docs/evidence/2026-09-06-delivery-checkpoint.md
로컬 검증, 호스팅 실행, 승인, 릴리스 및 역사 체크포인트의 구분 규칙을 기록합니다.

MCP 병합 상태 문서화

Layer / File(s) Summary
MCP tools/list 보호된 main 상태 반영
README.md, docs/adr/*, docs/traceability/*, tests/test_documentation_fitness_contract.py, tests/test_bap_adr_provenance_contract.py
tools/list discovery 계약을 보호된 main 병합 기능으로 기록합니다. 정책 경계와 실행 가능한 증거 경로를 검증합니다. 완전한 MCP 어댑터는 계속 Planned입니다.

라이브 증거 수집 강화

Layer / File(s) Summary
Merge 증거 수집 및 안정성 판정
scripts/ci/collect_live_merge_evidence.sh, docs/evidence/collect-live-merge-evidence-through-2026-09-09.sh, docs/traceability/live-merge-evidence-stability.md
페이지네이션, 정확한 head/base 및 workflow provenance, 승인 판정, 안정성 재검증, 인벤토리 불변성 검사 및 완료 수령증 생성을 추가합니다.

문서 계약 테스트 정렬

Layer / File(s) Summary
역사 계약 로더와 회귀 검증
tests/_historical_baseline_contract_loader.py, tests/legacy_*.py, tests/test_*.py
레거시 계약을 보관 입력으로 실행합니다. 현재 기준선, 과거 증거, 실패·승인·workflow 상태 및 문서 추적성 링크를 검증합니다.

Priority: ⬇️ Low

Estimated code review effort: 4 (Complex) | ~60 minutes

Change: Other

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 44.95% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 109 functions across 19 files. (3 skipped… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 라이브 제품 및 기술 갭 기준선을 갱신하는 변경 내용을 정확히 요약합니다. 변경 범위와 일치하며 간결하고 구체적입니다.
Full details: Docstring Coverage

Explanation

Docstring coverage is 44.95% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 109 functions across 19 files. (3 skipped: 3 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

devin-ai-integration[bot]

This comment was marked as resolved.

coderabbitai[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Current-head update: pushed 6e5c0af after verifying remote fast-forward from 9625854. The maintenance record now binds the prior same-day observation to 114 open PRs (30 ready, 84 draft), and the 13-row table explicitly distinguishes 11 open issues from 2 governance signals. Added regression contracts for both claims and updated CHANGELOG.md. Verification: 155 Python tests passed, compileall passed, git diff --check passed. Current hosted checks are pending; mergeable=true but mergeable_state=blocked and no counted approval is present.

devin-ai-integration[bot]

This comment was marked as resolved.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Exact-head maintenance audit for 6e5c0af671c5b3435843bdbeab827baef8edabad against protected main 542ca1e9c0a863595b8b6697790005d2471f5413:

  • The live product/technical gap baseline and exact stack evidence are present at this head; all current check runs are successful.
  • Current exact-head review-thread query reports 0 unresolved non-outdated threads.
  • reviewDecision=REVIEW_REQUIRED; no qualifying independent approval is present.
  • This documentation PR remains unmerged. No protected-gate bypass or synthetic approval was made.

devin-ai-integration[bot]

This comment was marked as resolved.

coderabbitai[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

@seonghobae

Copy link
Copy Markdown
Contributor Author

@opencode-agent Review only: inspect exact current head 0b2f278 against protected main 542ca1e. Do not merge, modify files, or change governance.

coderabbitai[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

coderabbitai[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

@seonghobae seonghobae added documentation Improvements or additions to documentation priority: medium status: needs-review labels Sep 2, 2026 — with ChatGPT Codex Connector

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • AGENTS.md — repository behavior
  • CHANGELOG.md — repository behavior
  • CLAUDE.md — repository behavior
  • README.md — repository behavior
  • docs/README.md — operator or user guidance
  • docs/adr/0016-bap-task-lifecycle-authority.md — operator or user guidance
  • docs/adr/0107-browser-protocol-adapter-strategy.md — operator or user guidance
  • docs/adr/README.md — operator or user guidance
  • docs/evidence/2026-09-06-delivery-checkpoint.md — operator or user guidance
  • docs/evidence/AGENTS-through-2026-09-09.md — operator or user guidance
  • docs/evidence/CHANGELOG-through-2026-09-09.md — operator or user guidance
  • docs/evidence/DOCUMENTATION_FITNESS-through-2026-09-09.md — operator or user guidance
  • docs/evidence/active-pr-maturity-through-2026-09-09.md — operator or user guidance
  • docs/evidence/collect-live-merge-evidence-through-2026-09-09.sh — operator or user guidance
  • docs/evidence/historical-contract-root-through-2026-09-09/CHANGELOG.md — operator or user guidance
  • docs/evidence/historical-contract-root-through-2026-09-09/scripts/ci/collect_live_merge_evidence.sh — operator or user guidance
  • docs/evidence/product-technical-gap-baseline-through-2026-09-09-navigation.md — operator or user guidance
  • docs/evidence/product-technical-gap-baseline-through-2026-09-09.md — operator or user guidance
  • docs/product-technical-gap-baseline.md — operator or user guidance
  • docs/traceability/README.md — operator or user guidance
  • docs/traceability/live-merge-evidence-stability.md — operator or user guidance
  • docs/traceability/mcp-authority-route.md — operator or user guidance
  • docs/traceability/product-gap-baseline-navigation.md — operator or user guidance
  • scripts/ci/collect_live_merge_evidence.sh — review and security gate shell path
  • tests/_historical_baseline_contract_loader.py — regression suite
  • tests/legacy_documentation_active_pr_evidence_contract.py — regression suite
  • tests/legacy_gap_snapshot_inventory_consistency.py — regression suite
  • tests/legacy_live_gap_evidence_integrity_contract.py — regression suite
  • tests/legacy_product_completion_gap_contract.py — regression suite
  • tests/test_agent_maintenance_lessons.py — regression suite
  • tests/test_bap_adr_provenance_contract.py — regression suite
  • tests/test_current_delivery_checkpoint_20260906_contract.py — regression suite
  • tests/test_documentation_active_pr_evidence_contract.py — regression suite
  • tests/test_documentation_fitness_contract.py — regression suite
  • tests/test_gap_snapshot_inventory_consistency.py — regression suite
  • tests/test_historical_baseline_input_isolation_contract.py — regression suite
  • tests/test_live_gap_evidence_integrity_contract.py — regression suite
  • tests/test_product_completion_gap_contract.py — regression suite
  • tests/test_product_documentation_contract.py — regression suite
  • tests/test_product_gap_baseline_navigation_contract.py — regression suite
  • tests/test_product_gap_http_baseline_contract.py — regression suite

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: AGENTS.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: AGENTS.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Repository file: CHANGELOG.md"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Repository file: CHANGELOG.md"]
  R2 --> V2["required checks"]
  Evidence --> S3["Repository file: CLAUDE.md"]
  S3 --> I3["repository behavior"]
  I3 --> R3["Review risk: Repository file: CLAUDE.md"]
  R3 --> V3["required checks"]
  Evidence --> S4["Repository file: README.md"]
  S4 --> I4["repository behavior"]
  I4 --> R4["Review risk: Repository file: README.md"]
  R4 --> V4["required checks"]
  Evidence --> S5["Docs: README.md (19 files)"]
  S5 --> I5["operator or user guidance"]
  I5 --> R5["Review risk: Docs: README.md (19 files)"]
  R5 --> V5["docs review"]
  Evidence --> S6["CI script: collect_live_merge_evidence.sh"]
  S6 --> I6["review and security gate shell path"]
  I6 --> R6["Review risk: CI script: collect_live_merge_evidence.sh"]
  R6 --> V6["bash -n plus Strix self-test"]
  Evidence --> S7["Test: _historical_baseline_contract_loader.py (17 files)"]
  S7 --> I7["regression suite"]
  I7 --> R7["Review risk: Test: _historical_baseline_contract_loader.py (17 files)"]
  R7 --> V7["targeted test run"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: e92917e18038fd8c2cf5979b91412ddf85d6e4ec
  • Workflow run: 36086242445
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: AGENTS.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: AGENTS.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Repository file: CHANGELOG.md"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Repository file: CHANGELOG.md"]
  R2 --> V2["required checks"]
  Evidence --> S3["Repository file: CLAUDE.md"]
  S3 --> I3["repository behavior"]
  I3 --> R3["Review risk: Repository file: CLAUDE.md"]
  R3 --> V3["required checks"]
  Evidence --> S4["Repository file: README.md"]
  S4 --> I4["repository behavior"]
  I4 --> R4["Review risk: Repository file: README.md"]
  R4 --> V4["required checks"]
  Evidence --> S5["Docs: README.md (19 files)"]
  S5 --> I5["operator or user guidance"]
  I5 --> R5["Review risk: Docs: README.md (19 files)"]
  R5 --> V5["docs review"]
  Evidence --> S6["CI script: collect_live_merge_evidence.sh"]
  S6 --> I6["review and security gate shell path"]
  I6 --> R6["Review risk: CI script: collect_live_merge_evidence.sh"]
  R6 --> V6["bash -n plus Strix self-test"]
  Evidence --> S7["Test: _historical_baseline_contract_loader.py (17 files)"]
  S7 --> I7["regression suite"]
  I7 --> R7["Review risk: Test: _historical_baseline_contract_loader.py (17 files)"]
  R7 --> V7["targeted test run"]
Loading

Copy link
Copy Markdown
Contributor Author

Exact-head admission audit: e92917e18038fd8c2cf5979b91412ddf85d6e4ec (base main@87c4daa1830bac5a5228b6036752ad5633232085, 347 ahead / 0 behind).

현재 blocker:

  • terminal workflow blocker: CodeQL PR:failure
  • 활성 CHANGES_REQUESTED 1건

유효 commit·diff·review evidence를 보존한 채 Draft/Proposed로 교정합니다. Base 이동이나 queue 대기만으로 Close하지 않으며 Force Push·synthetic status/approval·manual rerun·bypass를 사용하지 않습니다. Blocker 수리 후 새 exact head에서 Checks와 review admission을 다시 받아야 합니다.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant