Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
41 commits
Select commit Hold shift + click to select a range
2b52ab1
docs(preflight): plan seal-bound assurance loop
djm81 Aug 29, 2026
edf19fc
docs(preflight): fail closed on partial seal scope
djm81 Aug 29, 2026
0ca4feb
docs(preflight): bind separate workflow identities
djm81 Aug 29, 2026
a6484cb
docs(preflight): align checkpoint identity contracts
djm81 Aug 29, 2026
01515dc
fix(review): preserve user-scoped module installs
djm81 Aug 29, 2026
e14adde
docs(preflight): close downstream assurance gaps
djm81 Aug 29, 2026
147aeb6
docs(preflight): require cumulative deep assurance
djm81 Aug 29, 2026
b474967
docs(openspec): record paired review delivery
djm81 Aug 29, 2026
ec9ffca
docs(preflight): close final review gaps
djm81 Aug 29, 2026
2d1dd4c
docs(preflight): close late review gaps
djm81 Aug 29, 2026
c9f8927
docs(preflight): reject truncated conform ranges
djm81 Aug 29, 2026
560ce3a
docs(preflight): bind selection and cache inputs
djm81 Aug 29, 2026
1ef2473
fix(review): preserve user-scoped module installs (#454)
djm81 Aug 29, 2026
c7365a9
Merge branch 'dev' into feature/preflight-development-assurance-planning
djm81 Aug 29, 2026
69504af
docs(preflight): close final contract gaps
djm81 Aug 29, 2026
a3631d1
docs(openspec): correct active tree count
djm81 Aug 29, 2026
27ca98e
docs(preflight): validate sealed input influence
djm81 Aug 29, 2026
8f3a3e8
docs(preflight): enforce canonical delivery target
djm81 Aug 29, 2026
e8e7dab
docs(preflight): prevent seal deletion bypass
djm81 Aug 29, 2026
7b066a2
docs(preflight): fail closed on interface discovery
djm81 Aug 29, 2026
dab97c1
docs(preflight): require positive dogfood controls
djm81 Aug 29, 2026
a1fbb1a
docs(preflight): honor sealed no-impact evidence
djm81 Aug 29, 2026
2d164ba
docs(preflight): close release and rollout gaps
djm81 Aug 29, 2026
7955215
docs(preflight): cover interface-capable governed roles
djm81 Aug 29, 2026
e16ab33
docs(preflight): require shareable approval authority
djm81 Aug 30, 2026
14465da
docs(preflight): harden approval and publication authority
djm81 Aug 30, 2026
dbdca2a
docs(preflight): bind rollout and defer registry writes
djm81 Aug 30, 2026
f6a4176
docs(preflight): close final candidate evidence gaps
djm81 Aug 30, 2026
6adeeaf
docs(preflight): preserve compatibility ceiling
djm81 Aug 30, 2026
ada93b6
docs(preflight): enforce scoped applicability
djm81 Aug 30, 2026
7f2b5c6
docs(preflight): verify canonical approval history
djm81 Aug 30, 2026
af776b9
docs(preflight): bind no-impact to deltas
djm81 Aug 30, 2026
39f5391
docs(preflight): make integrity gate reachable
djm81 Aug 30, 2026
8234e97
docs(preflight): select checksum manifests
djm81 Aug 30, 2026
032dac2
docs(preflight): bind signed rollout evidence
djm81 Aug 30, 2026
6f58a33
docs(openspec): relocate abandoned r08 plan
djm81 Aug 30, 2026
557625b
docs(openspec): mark r08 superseded
djm81 Aug 30, 2026
6350a0b
[Planning] Add seal-bound development assurance loop (#453)
djm81 Aug 30, 2026
6b4f563
Merge branch 'main' into dev
djm81 Aug 30, 2026
e83bcea
fix(openspec): address promotion review findings
djm81 Aug 30, 2026
14658da
fix(openspec): address PR #455 markdown findings (#456)
djm81 Aug 30, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion docs/agent-rules/20-repository-context.md
Original file line number Diff line number Diff line change
Expand Up @@ -78,4 +78,4 @@ In this checkout:

- Prefer **`specfact module init --scope project --repo .`** (and project-scoped installs) so bundled modules live under the repo, not only under user scope.
- **`SPECFACT_MODULES_REPO`** is set to the modules repo root for every **`hatch run`** (`pyproject.toml` env-vars) and via **`apply_specfact_workspace_env`** from `specfact_cli_modules.dev_bootstrap` (also used by `ensure_core_dependency`, pytest `conftest`, and `scripts/pre_commit_code_review.py`). **`SPECFACT_REPO_ROOT`** defaults to the resolved sibling/core specfact-cli checkout when discoverable.
- If you still see a precedence warning for a module id, remove the stale user copy: **`specfact module uninstall <module-id> --scope user`**, then confirm with **`specfact module list --show-origin`**.
- A user-scoped copy shadowed here remains installed and available outside this repository. Normal precedence requires no uninstall or cleanup action; use **`specfact module list --show-origin`** only when you need to inspect the effective source.
46 changes: 32 additions & 14 deletions openspec/CHANGE_ORDER.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,13 +7,27 @@ must be read together with the core repo change order in `nold-ai/specfact-cli`.

| Bucket | Count | Location |
|---|---:|---|
| **Active** | 19 | [`openspec/changes/`](changes/) |
| **Parked** | 16 | [`openspec/parking-lot/`](parking-lot/) |
| **Archived** | 49 | [`openspec/changes/archive/`](changes/archive/) |
| **Active-tree entries** | 19 | [`openspec/changes/`](changes/) |
| **Parking-lot entries** | 16 | [`openspec/parking-lot/`](parking-lot/) |
| **Archived** | 50 | [`openspec/changes/archive/`](changes/archive/) |
| **Abandoned history** | 1 | [`openspec/history/abandoned/`](history/abandoned/) |

`openspec list` reflects the active set only. Completed changes are archived
with date-prefixed folders. Parked changes are preserved for later customer pull
but are not implementation-ready.
`openspec list` reflects all 19 direct active-tree entries. The closed R08
proposal is retained under non-canonical abandoned history, outside
`openspec/changes/` and its completed-change archive; no unimplemented delta
entered canonical specifications. Completed changes still use native OpenSpec
archival. Parking-lot changes are preserved for later customer pull but are not
implementation-ready.

## Abandoned Planning History Without Specification Promotion

| Change | GitHub issue | Historical status |
|---|---|---|
| [`requirements-08-bounded-red-green-proof`](history/abandoned/2026-08-30-requirements-08-bounded-red-green-proof/) | [#414](https://github.com/nold-ai/specfact-cli-modules/issues/414) | Closed Not Planned on 2026-08-27; never implemented; retained outside the completed-change archive; canonical specs unchanged |

This non-canonical history is not an OpenSpec archive and is not implementation
authority. Completed work must use `openspec archive` so implemented deltas are
validated and promoted normally.

## Product Thesis

Expand Down Expand Up @@ -45,6 +59,7 @@ issues and are now archived:
| `code-review-11-simplification-feedback-loop` | archived 2026-06-06 |
| `code-review-12-guided-simplification-enforcement` | archived 2026-06-06 |
| `code-review-13-cleanup-forecast-agent-handoff` | archived 2026-06-06 |
| `module-scope-02-preserve-user-installs` | archived 2026-08-30 after #454 merged to `dev` |

These archived specs are now the shipped basis for the flagship demo: run review,
produce JSON evidence, identify AI-bloat findings, hand remediation packets to an
Expand Down Expand Up @@ -110,8 +125,8 @@ and adapters reference it without duplicating Python checks.
|---:|---|---|---|---|
| 1 | `preflight-02-assurance-runtime` | [#431](https://github.com/nold-ai/specfact-cli-modules/issues/431) | Unpublished runtime, Python validators, CLI/rendering/persistence, and canonical bundled `specfact-preflight` workflow | core contract [#682](https://github.com/nold-ai/specfact-cli/issues/682) |
| 2 | `preflight-03-dogfood-hardening-and-release` | [#432](https://github.com/nold-ai/specfact-cli-modules/issues/432) | Evidence-backed hardening, bounded compatibility proof, signing, and stable publication | modules #431; core C14 dogfood/readiness [#683](https://github.com/nold-ai/specfact-cli/issues/683) |
| 3 | `preflight-04-harness-adapters` | [#433](https://github.com/nold-ai/specfact-cli-modules/issues/433) | Later thin Codex plugin, ECC companion, and hatch3r pack; no duplicate validators | stable modules release #432; core generated instructions [#253](https://github.com/nold-ai/specfact-cli/issues/253) |
| 4 | `preflight-05-implementation-conformance` | [#434](https://github.com/nold-ai/specfact-cli-modules/issues/434) | Later postimplementation extraction/comparison/rendering; explicitly outside preflight MVP | modules #432 and adapters #433; paired core conformance contract [#684](https://github.com/nold-ai/specfact-cli/issues/684) |
| 3 | `preflight-05-implementation-conformance` | [#434](https://github.com/nold-ai/specfact-cli-modules/issues/434) | Worktree/index checkpoints, final range conformance, C14/Requirements/review evidence reuse, seal-aware pre-commit, bounded agent handoff, and signed publication | modules #432; paired core implementation-assurance contract [#684](https://github.com/nold-ai/specfact-cli/issues/684) |
| 4 | `preflight-04-harness-adapters` | [#433](https://github.com/nold-ai/specfact-cli-modules/issues/433) | Later thin Codex plugin, ECC companion, and hatch3r pack; no duplicate validators | exact signed #434 module identity plus preflight and implementation-check workflow identities/digests; core generated instructions [#253](https://github.com/nold-ai/specfact-cli/issues/253) |

### Track B - Upstream Context Adapters

Expand All @@ -123,7 +138,6 @@ and adapters reference it without duplicating Python checks.
| 4 | `requirements-05-dogfood-evidence-gate` | [#352](https://github.com/nold-ai/specfact-cli-modules/issues/352) | CI evidence adapter that reports green/red requirement-source validity and traceability evidence; not test-execution proof | requirements-04 shipped; existing Requirements runtime |
| 5 | `requirements-06-evidence-enforcement` | [#361](https://github.com/nold-ai/specfact-cli-modules/issues/361) | Reusable Requirements evidence command plus staged pre-commit enforcement and CI parity | [#352](https://github.com/nold-ai/specfact-cli-modules/issues/352); paired core [#657](https://github.com/nold-ai/specfact-cli/issues/657) |
| 6 | `requirements-07-scenario-runtime-proof` | [#368](https://github.com/nold-ai/specfact-cli-modules/issues/368) | Plan exact selectors and reconcile current-run JUnit independently from historical chronology | requirements-06; paired corrected core R07 |
| 7 | `requirements-08-bounded-red-green-proof` | [#414](https://github.com/nold-ai/specfact-cli-modules/issues/414) | Validate a core-emitted structural B < R < H <= D replay capsule as an independent chronology claim; pass requires distinct H/D (`H < D`) | corrected R07; paired core [#675](https://github.com/nold-ai/specfact-cli/issues/675) |
| 8 | `architecture-01-solution-layer` | [#164](https://github.com/nold-ai/specfact-cli-modules/issues/164) | Architecture-boundary validation input | core architecture-boundary contracts |
| 9 | `sync-01-unified-kernel` | [#157](https://github.com/nold-ai/specfact-cli-modules/issues/157) | Preview/apply safety only where validation adapters need it | project/runtime safety specs |
| Parked | `requirements-03-backlog-sync` | [#166](https://github.com/nold-ai/specfact-cli-modules/issues/166) | Read-first backlog drift evidence; no write-back critical path. Deprioritized 2026-07-13 behind openspec-01 | requirements-02, sync-01 |
Expand Down Expand Up @@ -172,7 +186,9 @@ ceremony rather than validation evidence:
3. Core C14 adoption [#680](https://github.com/nold-ai/specfact-cli/issues/680).
4. Core C14 dogfood/readiness [#683](https://github.com/nold-ai/specfact-cli/issues/683).
5. Evidence-backed modules hardening and stable publication [#432](https://github.com/nold-ai/specfact-cli-modules/issues/432).
6. Shared skill installation #251 -> generated instructions #253 -> adapters #433; later conformance #684/#434; modules C15 #417 -> core C15 #679.
6. Core implementation-assurance contracts [#684](https://github.com/nold-ai/specfact-cli/issues/684).
7. Modules checkpoint/conformance runtime, dogfood, signing, and publication [#434](https://github.com/nold-ai/specfact-cli-modules/issues/434).
8. Shared skill installation #251 -> generated instructions #253 -> adapters #433. Modules C15 #417 -> core C15 #679 may proceed independently after stable #432.

Modules C15 #417 keeps its existing policy and exception blockers (#158,
core #248, and modules #167) plus the stable preflight release. Existing native
Expand Down Expand Up @@ -206,7 +222,7 @@ dedicated issue-linked worktree and session.
- `requirements-05-dogfood-evidence-gate`
- `requirements-06-evidence-enforcement` (after requirements-05 archival/release evidence)
- `requirements-07-scenario-runtime-proof` (current-run reconciliation correction after requirements-06)
- `requirements-08-bounded-red-green-proof` (paired with core bounded replay after corrected R07)
- abandoned-history `requirements-08-bounded-red-green-proof` is superseded and non-canonical; no replay implementation or specification promotion occurred
- `architecture-01-solution-layer`
- `sync-01-unified-kernel`
- `requirements-03-backlog-sync` (parked 2026-07-13)
Expand All @@ -216,8 +232,8 @@ dedicated issue-linked worktree and session.
- `docs-16-core-accountability-sync`
- `architecture-02-module-well-architected`
- `docs-14-module-release-history`
- `preflight-04-harness-adapters` after core #253 and stable publication
- `preflight-05-implementation-conformance` after stable publication and core #684
- `preflight-05-implementation-conformance` after stable #432 and core #684
- `preflight-04-harness-adapters` after signed #434, core #251, and core #253

## Parent Issues And Epic Framing

Expand All @@ -236,4 +252,6 @@ implementation starts.
After a change ships and merges, run `openspec archive <change-id>` from the repo
root. Do not manually move completed changes into `openspec/changes/archive/`.
Parking-lot moves are allowed for paused proposals that are explicitly not active
scope.
scope. Abandoned, never-implemented proposals may be retained only under
`openspec/history/abandoned/`, whose records are non-canonical and never imply
specification promotion or implementation authority.
40 changes: 26 additions & 14 deletions openspec/INTEGRATION.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,8 +7,9 @@ changes without creating runtime behavior.
## Preflight Ownership

- Core `preflight-01-design-contract-core` owns design-contract,
validation-result, digest, approval-seal, and side-effect-free verifier
interfaces.
role-classified scope, component/risk/verification intent, Requirements-plan
references, validation-result, digest, approval-seal, and side-effect-free
verifier interfaces.
- Modules `preflight-02-assurance-runtime` owns executable Python validators,
CLI orchestration, rendering, explicit persistence, and canonical bundled
`specfact-preflight` workflow content.
Expand All @@ -19,10 +20,20 @@ changes without creating runtime behavior.
canonical `.agents/skills` export. Core `ai-integration-03-instruction-files`
owns generated gate references. Neither owns the workflow body or validators.
- Modules `preflight-04-harness-adapters` owns thin Codex, ECC, and hatch3r
packaging. Adapters map native invocation and assets only.
- Core `preflight-05-implementation-conformance` owns later comparison
interfaces; paired modules owns extraction and runtime comparison. This phase
is explicitly excluded from the preflight MVP.
packaging after the signed #434 handoff. That handoff is one exact signed
module identity plus separately named preflight and implementation-check
workflow identities/digests. Adapters map native invocation and assets only.
- Core `preflight-05-implementation-conformance` owns worktree/index/range
snapshot, obligation-map, finding/result, authority, and pure comparison
interfaces. Paired modules owns checkpoint/conform commands, C14-backed Git
extraction, Requirements pytest/JUnit and code-review evidence, caching,
pre-commit policy, remediation packets, bounded agent workflow,
checkpoint/conformance-result rendering, optional atomic snapshot/result
persistence under its distinct result schema, signing, and publication of the
module identity plus separately bound preflight and implementation-check
workflow identities/digests. These surfaces are separate from
`preflight-02-assurance-runtime`, which exclusively owns preflight
readiness/validation/seal rendering and persistence.

## Shared Rules

Expand All @@ -32,21 +43,22 @@ changes without creating runtime behavior.
OpenSpec, Spec Kit, ECC, hatch3r, and Codex instructions contain a compact
gate/reference only.
- Python validators are the canonical determinate checks. Prompts and adapters
must not recompute readiness, approval, or conformance.
must not recompute readiness, approval, checkpoint, or conformance status.
- A seal proves exact reviewed-input identity and recorded approval, not design,
LLM, implementation, security, or semantic correctness.
- Any pre-implementation bound-input change invalidates readiness and requires
a complete rerun and explicit user approval. During later conformance, the
approved seal is verified against its sealed contract and base source
snapshot while the implementation head/range is captured as a separate,
explicit identity; implementation commits do not silently rewrite the seal.
snapshot while worktree/index/range implementation evidence is captured as a
separate identity; implementation commits do not silently rewrite the seal.
- Worktree/index checkpoint results have local authority only. They cannot be
promoted to protected PR-range evidence; final conformance requires a new
explicit immutable base/head evaluation.
- Native GitHub parents, project status, blockers, and blocked-by relationships
are required before implementation; body-only references are insufficient.

## Delivery Sequence

`core #682 -> modules #431 -> core C14 #680 -> core #683 -> modules #432`.
After the signed release, `#251 -> #253 -> modules #433`; stable modules #432,
modules #433, and core #684 all block modules #434. Issue #434 remains a later
branch; modules C15 `#417` -> core C15 #679 remains the signal-calibration
branch. Existing policy/exception blockers remain in force.
`core #682 -> modules #431 -> core C14 #680/#683 -> modules #432 -> core #684 -> modules #434 -> core #251 -> core #253 -> modules #433`.
Modules C15 `#417` -> core C15 #679 remains an independent signal-calibration
branch after stable #432. Existing policy/exception blockers remain in force.
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
schema: spec-driven
created: 2026-08-29
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
# TDD Evidence

## Failing Before

- `hatch run pytest tests/unit/test_dev_bootstrap.py tests/unit/test_local_bundle_source_alignment.py -q`
- Result: FAIL before production edits (`2 failed, 11 passed`).
- The new bootstrap and repository-guidance assertions could not find the required preservation language; both existing surfaces still prescribed a user-scope uninstall.

## Passing After

- `hatch run pytest tests/unit/test_dev_bootstrap.py tests/unit/test_local_bundle_source_alignment.py -q`
- Result: PASS (`13 passed`).
- The bootstrap and repository rule surfaces now preserve user-scoped installations, and the local import-isolation test remains green under its accurate in-memory eviction name.

## Quality Gates

- `hatch run format`: PASS (1,229 files unchanged).
- `hatch run type-check`: PASS (0 errors, 0 warnings).
- `hatch run lint`: PASS (Pylint 10.00/10).
- `hatch run yaml-lint`: PASS (seven manifests plus registry).
- `hatch run check-bundle-imports`: PASS.
- `hatch run verify-modules-signature --payload-from-filesystem --enforce-version-bump --allow-missing-public-key`: PASS for all seven modules. No signed payload or manifest changed, so no module version bump is required. The strict local-key form was also attempted and stopped only because this worktree does not contain the public key.
- `hatch run contract-test`: PASS (`28 passed, 1753 deselected`).
- Staged Requirements evidence gate at maturity `planned`: PASS with schema-v2 mappings for all changed scenarios and exact pytest selectors.
- `hatch run smart-test`: reached the full suite with one failure in `test_capsule_runtime_loads_the_packaged_signed_lock_before_materialization`; the same failure reproduces from an isolated clean `origin/dev` worktree at `870fea3d`, so it is baseline C14/environment debt rather than a regression from this change.
- `hatch run test`: `1780 passed, 1 failed`; the only failure is the same clean-`origin/dev` capsule-runtime baseline failure.
- `hatch run specfact code review run --enforcement changed --bug-hunt --json --out .specfact/code-review.json`: PASS after replacing one changed-file `print(..., file=sys.stderr)` warning; the worktree review reported schema 1.4, score 120, zero findings, exit code 0.
- The staged commit-hook review exposed three whole-file Pylint warnings in pre-existing test helpers; they were refactored and the focused tests/lint reran green. Its remaining advisory is environment-only: the external CrossHair process cannot import `pytest` while inspecting the staged test module.
- `git diff --check`: PASS.
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
## Overview

Keep module precedence unchanged while removing guidance that turns normal shadowing into destructive cleanup. The modules repository only needs to describe the correct contract and protect that wording with focused tests; core owns runtime discovery and doctor output.

## Decisions

- Treat project-over-user shadowing as workspace-local precedence, not evidence of a stale or invalid user installation.
- State that the user copy remains installed and available in repositories without the project-scoped copy.
- Keep explicit user-initiated uninstall behavior unchanged. This change removes routine recommendations; it does not disable the command.
- Test the exact contributor-facing surfaces that caused the defect instead of adding a new runtime abstraction.
- Rename the local test bootstrap test to describe in-memory import eviction accurately. The helper changes `sys.path` and `sys.modules`; it does not delete installed files.

## Risks

- A user may still need to remove a genuinely unwanted duplicate. Mitigation: origin diagnostics remain available through `specfact module list --show-origin`, and explicit uninstall remains documented elsewhere.
- A wording-only regression could reintroduce destructive agent behavior. Mitigation: focused tests reject user-scope uninstall recommendations on these bootstrap surfaces.
- Core output could remain inconsistent with repository guidance. Mitigation: paired bug `nold-ai/specfact-cli#699` carries matching OpenSpec and tests.

## Rollback

Revert the guidance and test changes. No module data, installation state, manifest, registry row, or signature is migrated by this change.
Loading
Loading