diff --git a/TODO.md b/TODO.md index b2fb78a..b9bb48c 100644 --- a/TODO.md +++ b/TODO.md @@ -7,20 +7,12 @@ validator, trusted approval boundary, reusable governance CI, stack-specific gates and pinned adoption in `todo2code`; extend it with safe concurrent workstreams, dependency-aware intents and non-overlapping write scopes. - Current state: `IN_PROGRESS / EDIT` for approved AC-30..AC-40: - allowlisted independent Validator App reviews bound to the exact PR head SHA - plus a non-mutating `direct-pr` strategy in `subactor/validator-agent`. - No governance, workflow, source or test implementation file has changed for - this follow-up. Earlier AC-11..AC-29 remain complete: - pinned, read-only and attested `koru / code-review` PR check plus a required - ruleset. `koru / code-review` and `governance / enforce` now run as required - checks on `main`; the ruleset is active with no bypass actors. - Current follow-up state: `IN_PROGRESS / VALIDATION` for AC-26..AC-29, normalizing - the three tracked generated-analysis - artifacts after `npm run verify` detected a volatile `/tmp` worktree root; - no analysis regeneration and no `project2.sh` execution are in scope. - AC-11..AC-29, governance and Docker core/full pass; only the pre-existing - publication/external governance blockers remain recorded separately. + Current state: `BLOCKED / PUBLICATION`; AC-01..AC-40, governance and Docker + core/full pass, including exact-head Validator App reviews accepted by the + reusable gate. Central `wellmanifest/new-project` PR #2 is green and + mergeable but still needs an independent review; `wellmanifest` currently + has no Validator App installation. The governance workstream reservation is + released while waiting. ## Backlog tickets diff --git a/project/ticket-018/README.md b/project/ticket-018/README.md index 7f7249e..6931f1b 100644 --- a/project/ticket-018/README.md +++ b/project/ticket-018/README.md @@ -2,8 +2,8 @@ - **ID**: ticket-018 - **Owner**: unresolved:human -- **Status**: IN_PROGRESS -- **Workflow state**: VALIDATION +- **Status**: BLOCKED +- **Workflow state**: PUBLICATION - **Created**: 2026-08-01 ## Goal and scope @@ -154,7 +154,7 @@ existing README/runbook/permissions documentation. No application source in - [x] AC-05: Approval provenance is checked against a trusted GitHub review boundary in CI; local or Markdown-only approval is never presented as a cryptographically trusted fact. -- [ ] AC-06: A centrally maintained reusable GitHub workflow is pinned by +- [x] AC-06: A centrally maintained reusable GitHub workflow is pinned by immutable revision and documented together with the required repository ruleset/CODEOWNERS settings. - [x] AC-07: Stack profiles provide appropriate gates for Node, Python, Go, @@ -247,12 +247,12 @@ existing README/runbook/permissions documentation. No application source in and mutable/unpinned heads are rejected. - [x] AC-39: Focused negative/positive tests, both complete repository suites, governance, Java, gold, SDK examples and Docker smoke pass. -- [ ] AC-40: After a separately trusted bootstrap review merges the policy, +- [x] AC-40: After a separately trusted bootstrap review merges the policy, the real Validator App reviews PR #13 at its exact SHA and the rerun proves `governance / enforce` accepts that independent agent evidence. Central adoption for AC-31..AC-33 is pinned to -`wellmanifest/new-project@78b365272b5b258931f9a66d7124122ec19d7814`. +`wellmanifest/new-project@d082373f314191dba794aba58aca2d4475ea497a`. The caller passes `ifuri-validator-agent[bot]` through the App-only allowlist; the reusable workflow resolves the ticket and writes current-event approval evidence under `runner.temp`, outside the pull-request checkout. @@ -330,3 +330,21 @@ remain historical evidence, not evidence for AC-11..AC-17. and requires strict `governance / enforce` plus `koru / code-review` checks. Enforcement remains disabled only until this bootstrap evidence commit is merged; AC-24 is not claimed until the rule is activated and queried back. + +## Validator App publication evidence + +- Installation `151227156` makes `ifuri-validator-agent` available to + `semcod/todo2code`; repository-scoped App-token creation passes. +- Validator run `30924588549` approved PR #14 at exact head + `17715cc6af4d983918462a23d0f37a810b910eec` for `ticket-018`; governance, + verify, Java and Koru passed, and the human maintainer merged it as + `944feda7b3914f747cc67d3682ce8427a7305ff4`. +- Validator run `30925171580` approved PR #13 at exact head + `68b0c0985f0aa95f8a41e252399491fe7aea29ca` for `ticket-034`; the rerun proved + `governance / enforce` accepts the independent App evidence. Validator did + not merge either pull request. +- The remaining blocker is central `wellmanifest/new-project` PR #2 at exact + head `d082373f314191dba794aba58aca2d4475ea497a`. It is green and mergeable but + has no independent review, and the `wellmanifest` organization currently has + no Validator App installation. Ticket-018 therefore remains + `BLOCKED / PUBLICATION` and does not reserve its write scope while waiting. diff --git a/project/ticket-018/ai-codex-logs.txt b/project/ticket-018/ai-codex-logs.txt index 7bcd4f8..661f975 100644 --- a/project/ticket-018/ai-codex-logs.txt +++ b/project/ticket-018/ai-codex-logs.txt @@ -356,3 +356,14 @@ repository selection: all transition: BLOCKED -> IN_PROGRESS / VALIDATION next boundary: publish a fresh ticket-only head, pass deterministic hosted checks, then request an exact-head direct-pr review from the installed App +2026-08-04 VALIDATOR APP END-TO-END EVIDENCE +PR #14 run 30924588549: APPROVED exact head 17715cc6af4d983918462a23d0f37a810b910eec, ticket-018 +PR #14 governance/verify/Java/Koru: PASS; merged by human as 944feda7b3914f747cc67d3682ce8427a7305ff4 +PR #13 run 30925171580: APPROVED exact head 68b0c0985f0aa95f8a41e252399491fe7aea29ca, ticket-034 +PR #13 governance/verify/Java/Koru: PASS; merged by human as 4387943e4095926fe2466628b767c3dd83034281 +AC-40: PASS; Validator auto-merge remained disabled +2026-08-04 CENTRAL PUBLICATION RECHECK +wellmanifest/new-project PR #2 head: d082373f314191dba794aba58aca2d4475ea497a +PR state: OPEN, CLEAN, tests PASS, no reviews +wellmanifest organization App installations: 0 +transition: IN_PROGRESS / VALIDATION -> BLOCKED / PUBLICATION; reservation released diff --git a/project/ticket-018/ai-codex.md b/project/ticket-018/ai-codex.md index de1241d..0474366 100644 --- a/project/ticket-018/ai-codex.md +++ b/project/ticket-018/ai-codex.md @@ -190,7 +190,7 @@ Current verified baseline: metadata, Issues, Projects, or merge state. - Full local and container validation passes, including Validator 96/96, todo2code full E2E with JDK 17 at 342/342, gold v1/v2, SDK examples, - governance and Docker smoke. AC-40 remains an external bootstrap sequence. + governance and Docker smoke. - Audited Koru's failed PR #13 artifact and found a deterministic tool mismatch: the Python-only Vallm regression plugin invoked missing `pytest` for every TypeScript file. Removed that plugin from Koru while retaining the real npm @@ -200,44 +200,30 @@ Current verified baseline: The required merge decision remains in deterministic governance, verify and Java checks; the Koru job enforces exact report bindings, not an LLM verdict. - Adopted central standard 0.9.0 at immutable revision - `78b365272b5b258931f9a66d7124122ec19d7814`. CI now calls that exact reusable + `d082373f314191dba794aba58aca2d4475ea497a`. CI now calls that exact reusable workflow and passes only the observed `ifuri-validator-agent[bot]` App login. Approval evidence is generated in `runner.temp` and bound to repository, PR, current head, ticket and actor. The earlier checkout-owned resolver is detached from CI and retained only until the tracked generated-analysis index is refreshed. -## Blockers +## Publication blocker -- `GOV-INTENT-003`: concurrent commit `5f1f4bd` placed the ticket intent and - implementation in the same commit; correcting this requires an authorized - history/commit split. -- `GOV-SCOPE-001`: the same commit contains eight implementation/generated - paths not allowed by ticket-018. They must be routed to their actual ticket, - not retroactively claimed here. - Central standard 0.9.0 is published at immutable commit - `78b365272b5b258931f9a66d7124122ec19d7814`; its PR #2 is green and still - awaits an independent merge review. -- Live Validator run `30918035304` proved the dedicated App credentials are - valid but the App has no installation for `semcod/todo2code`; repository- - scoped token creation failed closed with GitHub API 404 before validation. -- The earlier AC-17 Rust lock failure no longer reproduces on current HEAD: - locked Cargo fetch and full Docker E2E pass without a governance-owned SDK - edit. + `d082373f314191dba794aba58aca2d4475ea497a`; its PR #2 is green and still + awaits an independent merge review. The `wellmanifest` organization reports + zero App installations, so the existing Validator identity cannot yet + provide that review. ## Approval boundary -- Current state: `IN_PROGRESS / VALIDATION`. GitHub now reports installation +- Current state: `BLOCKED / PUBLICATION`. GitHub now reports installation `151227156` for App `ifuri-validator-agent` in organization `semcod`, with - repository selection `all`. A fresh ticket-only HEAD will bind the hosted - checks and Validator review to evidence created after this installation. + repository selection `all`; todo2code publication evidence is complete. + Central PR #2 still requires an independent reviewer or installation of the + Validator App in `wellmanifest`. - Required response from: `unresolved:human`. - The user explicitly approved AC-18..AC-25 in chat. This authorizes the implementation workflow but is not itself merge-time review evidence. -- The current follow-up is planned as AC-26..AC-28 in - `IN_PROGRESS / VALIDATION`. The user's `kontynuuj` response authorizes this exact - interactive implementation scope, but remains insufficient merge evidence. -- Current follow-up state: `IN_PROGRESS / WAIT_FOR_APPROVAL` for AC-30..AC-40. - The user's request authorizes planning and policy evolution; executable edits - begin only after explicit approval of this exact allowlist/direct-PR design. -- The user explicitly approved AC-30..AC-40 on 2026-08-04. Current state: - `IN_PROGRESS / VALIDATION`; protected merge evidence remains independent. +- The user explicitly approved AC-26..AC-40 on 2026-08-04. Those criteria are + complete; current `BLOCKED / PUBLICATION` state concerns only the independent + review of central PR #2. diff --git a/project/ticket-018/changelog.md b/project/ticket-018/changelog.md index 4f4d517..100a48a 100644 --- a/project/ticket-018/changelog.md +++ b/project/ticket-018/changelog.md @@ -11,8 +11,8 @@ scoped its workflow App token to one repository. - Verified 96 Validator tests, 342 full Docker E2E tests with JDK 17, both gold datasets at 100%, all SDK examples, governance, smoke and Docker smoke. -- Entered `VALIDATION`; AC-40 remains open until the policy receives a separate - trusted bootstrap review and the real App reviews todo2code PR #13. +- Entered `VALIDATION` pending a separately trusted bootstrap review and a real + App review of todo2code PR #13. - Removed Vallm's Python-only `--regression` plugin from the TypeScript Koru review after live evidence showed it called missing `pytest` for every TS file. Regression remains strictly enforced by the separate `verify` and Java @@ -26,7 +26,7 @@ - Bound trusted App evidence to the exact active `ticket-NNN` and safe correlation ID recorded in the current-head review body; human review behavior remains unchanged. -- Adopted central standard 0.9.0 at immutable commit `78b3652`, including the +- Adopted central standard 0.9.0 at immutable commit `d082373`, including the reusable protected resolver and ephemeral current-event approval evidence. - Verified PR #14 remotely: Koru v2, Node/Docker verification and required Java passed. Live Validator run `30918035304` stopped before review because the App @@ -46,6 +46,13 @@ - Confirmed the new `semcod` installation `151227156` for `ifuri-validator-agent` with repository selection `all`; resumed `IN_PROGRESS / VALIDATION` before creating fresh current-head evidence. +- Completed AC-40: production Validator runs approved exact heads for PR #14 + (`ticket-018`) and PR #13 (`ticket-034`), and the governance reruns accepted + the App evidence while merge remained human-controlled. +- Recorded central PR #2 as the sole remaining publication blocker: it is green + and mergeable, but `wellmanifest` has no Validator App installation and the + author cannot supply an independent self-review. Released the workstream at + `BLOCKED / PUBLICATION`. ## [0.5.0] - 2026-08-04