Skip to content
Merged
Show file tree
Hide file tree
Changes from 38 commits
Commits
Show all changes
41 commits
Select commit Hold shift + click to select a range
2b52ab1
docs(preflight): plan seal-bound assurance loop
djm81 Aug 29, 2026
edf19fc
docs(preflight): fail closed on partial seal scope
djm81 Aug 29, 2026
0ca4feb
docs(preflight): bind separate workflow identities
djm81 Aug 29, 2026
a6484cb
docs(preflight): align checkpoint identity contracts
djm81 Aug 29, 2026
01515dc
fix(review): preserve user-scoped module installs
djm81 Aug 29, 2026
e14adde
docs(preflight): close downstream assurance gaps
djm81 Aug 29, 2026
147aeb6
docs(preflight): require cumulative deep assurance
djm81 Aug 29, 2026
b474967
docs(openspec): record paired review delivery
djm81 Aug 29, 2026
ec9ffca
docs(preflight): close final review gaps
djm81 Aug 29, 2026
2d1dd4c
docs(preflight): close late review gaps
djm81 Aug 29, 2026
c9f8927
docs(preflight): reject truncated conform ranges
djm81 Aug 29, 2026
560ce3a
docs(preflight): bind selection and cache inputs
djm81 Aug 29, 2026
1ef2473
fix(review): preserve user-scoped module installs (#454)
djm81 Aug 29, 2026
c7365a9
Merge branch 'dev' into feature/preflight-development-assurance-planning
djm81 Aug 29, 2026
69504af
docs(preflight): close final contract gaps
djm81 Aug 29, 2026
a3631d1
docs(openspec): correct active tree count
djm81 Aug 29, 2026
27ca98e
docs(preflight): validate sealed input influence
djm81 Aug 29, 2026
8f3a3e8
docs(preflight): enforce canonical delivery target
djm81 Aug 29, 2026
e8e7dab
docs(preflight): prevent seal deletion bypass
djm81 Aug 29, 2026
7b066a2
docs(preflight): fail closed on interface discovery
djm81 Aug 29, 2026
dab97c1
docs(preflight): require positive dogfood controls
djm81 Aug 29, 2026
a1fbb1a
docs(preflight): honor sealed no-impact evidence
djm81 Aug 29, 2026
2d164ba
docs(preflight): close release and rollout gaps
djm81 Aug 29, 2026
7955215
docs(preflight): cover interface-capable governed roles
djm81 Aug 29, 2026
e16ab33
docs(preflight): require shareable approval authority
djm81 Aug 30, 2026
14465da
docs(preflight): harden approval and publication authority
djm81 Aug 30, 2026
dbdca2a
docs(preflight): bind rollout and defer registry writes
djm81 Aug 30, 2026
f6a4176
docs(preflight): close final candidate evidence gaps
djm81 Aug 30, 2026
6adeeaf
docs(preflight): preserve compatibility ceiling
djm81 Aug 30, 2026
ada93b6
docs(preflight): enforce scoped applicability
djm81 Aug 30, 2026
7f2b5c6
docs(preflight): verify canonical approval history
djm81 Aug 30, 2026
af776b9
docs(preflight): bind no-impact to deltas
djm81 Aug 30, 2026
39f5391
docs(preflight): make integrity gate reachable
djm81 Aug 30, 2026
8234e97
docs(preflight): select checksum manifests
djm81 Aug 30, 2026
032dac2
docs(preflight): bind signed rollout evidence
djm81 Aug 30, 2026
6f58a33
docs(openspec): relocate abandoned r08 plan
djm81 Aug 30, 2026
557625b
docs(openspec): mark r08 superseded
djm81 Aug 30, 2026
6350a0b
[Planning] Add seal-bound development assurance loop (#453)
djm81 Aug 30, 2026
6b4f563
Merge branch 'main' into dev
djm81 Aug 30, 2026
e83bcea
fix(openspec): address promotion review findings
djm81 Aug 30, 2026
14658da
fix(openspec): address PR #455 markdown findings (#456)
djm81 Aug 30, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion docs/agent-rules/20-repository-context.md
Original file line number Diff line number Diff line change
Expand Up @@ -78,4 +78,4 @@ In this checkout:

- Prefer **`specfact module init --scope project --repo .`** (and project-scoped installs) so bundled modules live under the repo, not only under user scope.
- **`SPECFACT_MODULES_REPO`** is set to the modules repo root for every **`hatch run`** (`pyproject.toml` env-vars) and via **`apply_specfact_workspace_env`** from `specfact_cli_modules.dev_bootstrap` (also used by `ensure_core_dependency`, pytest `conftest`, and `scripts/pre_commit_code_review.py`). **`SPECFACT_REPO_ROOT`** defaults to the resolved sibling/core specfact-cli checkout when discoverable.
- If you still see a precedence warning for a module id, remove the stale user copy: **`specfact module uninstall <module-id> --scope user`**, then confirm with **`specfact module list --show-origin`**.
- A user-scoped copy shadowed here remains installed and available outside this repository. Normal precedence requires no uninstall or cleanup action; use **`specfact module list --show-origin`** only when you need to inspect the effective source.
41 changes: 28 additions & 13 deletions openspec/CHANGE_ORDER.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,13 +7,26 @@ must be read together with the core repo change order in `nold-ai/specfact-cli`.

| Bucket | Count | Location |
|---|---:|---|
| **Active** | 19 | [`openspec/changes/`](changes/) |
| **Parked** | 16 | [`openspec/parking-lot/`](parking-lot/) |
| **Archived** | 49 | [`openspec/changes/archive/`](changes/archive/) |
| **Active-tree entries** | 20 | [`openspec/changes/`](changes/) |
| **Parking-lot entries** | 16 | [`openspec/parking-lot/`](parking-lot/) |
| **Archived** | 50 | [`openspec/changes/archive/`](changes/archive/) |

`openspec list` reflects the active set only. Completed changes are archived
with date-prefixed folders. Parked changes are preserved for later customer pull
but are not implementation-ready.
`openspec list` reflects all 20 direct active-tree entries. The closed R08
proposal is no longer presented as active work. Under an explicit owner decision
on 2026-08-30, its complete historical folder was relocated to the dated archive
without running `openspec archive`; no unimplemented delta entered canonical
Comment thread
djm81 marked this conversation as resolved.
Outdated
specifications. Completed changes still use native OpenSpec archival. Parking-lot
changes are preserved for later customer pull but are not implementation-ready.

## Abandoned Changes Archived Without Specification Promotion

| Change | GitHub issue | Archive status |
|---|---|---|
| [`requirements-08-bounded-red-green-proof`](changes/archive/2026-08-30-requirements-08-bounded-red-green-proof/) | [#414](https://github.com/nold-ai/specfact-cli-modules/issues/414) | Closed Not Planned; never implemented; manually relocated on 2026-08-30 without `openspec archive`; canonical specs unchanged |

This is a bounded exception for an abandoned, never-implemented proposal. It is
not precedent for completed work, which must still use `openspec archive` so
implemented deltas are validated and promoted normally.

## Product Thesis

Expand Down Expand Up @@ -56,6 +69,7 @@ This track is first because no changed-scope assurance claim is trustworthy unti

| Order | Change folder | GitHub # | Positioning | Blocked by |
|---:|---|---|---|---|
| 0 | `module-scope-02-preserve-user-installs` | [#452](https://github.com/nold-ai/specfact-cli-modules/issues/452) | Preserve user-scoped modules when project-local sources shadow them; remove destructive review/bootstrap guidance | none; paired core [#699](https://github.com/nold-ai/specfact-cli/issues/699) is coordinated but independently mergeable |
| 1 | `code-review-14-scope-truth-and-differential-enforcement` | [#416](https://github.com/nold-ai/specfact-cli-modules/issues/416) | Resolve worktree/index/range/full scope explicitly; compare pinned merge-base/head analyses; authenticate one target-tip project-runtime layer for both snapshots; fail closed on unknown scope, runtime provenance, or analyzer coverage | accepted planning PR [#413](https://github.com/nold-ai/specfact-cli-modules/pull/413); paired core adoption is downstream after the signed release |

The immutable C14 compatibility smoke establishes core 0.55.1 as the minimum: lightweight tag `v0.55.1`, full commit `b1e517e60e669eaba15a18ecfa83ef5a9df65276`, and full tree `47984be5434d7ae65ed6908bf525a32053290337`. Runtime metadata therefore uses `>=0.55.1,<1.0.0`: the ceiling is required because recursive installation includes Codebase and Requirements modules whose current manifests reject core 1.x. Current paired-core validation exercises compatible versions above the minimum; a routine compatible core update within the dependency graph does not require a module metadata release. Remove the ceiling only after widening and validating the required dependency graph. This correction supersedes C14's exact-only admission wording without changing its frozen provenance identities or historical evidence.
Expand Down Expand Up @@ -110,8 +124,8 @@ and adapters reference it without duplicating Python checks.
|---:|---|---|---|---|
| 1 | `preflight-02-assurance-runtime` | [#431](https://github.com/nold-ai/specfact-cli-modules/issues/431) | Unpublished runtime, Python validators, CLI/rendering/persistence, and canonical bundled `specfact-preflight` workflow | core contract [#682](https://github.com/nold-ai/specfact-cli/issues/682) |
| 2 | `preflight-03-dogfood-hardening-and-release` | [#432](https://github.com/nold-ai/specfact-cli-modules/issues/432) | Evidence-backed hardening, bounded compatibility proof, signing, and stable publication | modules #431; core C14 dogfood/readiness [#683](https://github.com/nold-ai/specfact-cli/issues/683) |
| 3 | `preflight-04-harness-adapters` | [#433](https://github.com/nold-ai/specfact-cli-modules/issues/433) | Later thin Codex plugin, ECC companion, and hatch3r pack; no duplicate validators | stable modules release #432; core generated instructions [#253](https://github.com/nold-ai/specfact-cli/issues/253) |
| 4 | `preflight-05-implementation-conformance` | [#434](https://github.com/nold-ai/specfact-cli-modules/issues/434) | Later postimplementation extraction/comparison/rendering; explicitly outside preflight MVP | modules #432 and adapters #433; paired core conformance contract [#684](https://github.com/nold-ai/specfact-cli/issues/684) |
| 3 | `preflight-05-implementation-conformance` | [#434](https://github.com/nold-ai/specfact-cli-modules/issues/434) | Worktree/index checkpoints, final range conformance, C14/Requirements/review evidence reuse, seal-aware pre-commit, bounded agent handoff, and signed publication | modules #432; paired core implementation-assurance contract [#684](https://github.com/nold-ai/specfact-cli/issues/684) |
| 4 | `preflight-04-harness-adapters` | [#433](https://github.com/nold-ai/specfact-cli-modules/issues/433) | Later thin Codex plugin, ECC companion, and hatch3r pack; no duplicate validators | exact signed #434 module identity plus preflight and implementation-check workflow identities/digests; core generated instructions [#253](https://github.com/nold-ai/specfact-cli/issues/253) |

### Track B - Upstream Context Adapters

Expand All @@ -123,7 +137,6 @@ and adapters reference it without duplicating Python checks.
| 4 | `requirements-05-dogfood-evidence-gate` | [#352](https://github.com/nold-ai/specfact-cli-modules/issues/352) | CI evidence adapter that reports green/red requirement-source validity and traceability evidence; not test-execution proof | requirements-04 shipped; existing Requirements runtime |
| 5 | `requirements-06-evidence-enforcement` | [#361](https://github.com/nold-ai/specfact-cli-modules/issues/361) | Reusable Requirements evidence command plus staged pre-commit enforcement and CI parity | [#352](https://github.com/nold-ai/specfact-cli-modules/issues/352); paired core [#657](https://github.com/nold-ai/specfact-cli/issues/657) |
| 6 | `requirements-07-scenario-runtime-proof` | [#368](https://github.com/nold-ai/specfact-cli-modules/issues/368) | Plan exact selectors and reconcile current-run JUnit independently from historical chronology | requirements-06; paired corrected core R07 |
| 7 | `requirements-08-bounded-red-green-proof` | [#414](https://github.com/nold-ai/specfact-cli-modules/issues/414) | Validate a core-emitted structural B < R < H <= D replay capsule as an independent chronology claim; pass requires distinct H/D (`H < D`) | corrected R07; paired core [#675](https://github.com/nold-ai/specfact-cli/issues/675) |
| 8 | `architecture-01-solution-layer` | [#164](https://github.com/nold-ai/specfact-cli-modules/issues/164) | Architecture-boundary validation input | core architecture-boundary contracts |
| 9 | `sync-01-unified-kernel` | [#157](https://github.com/nold-ai/specfact-cli-modules/issues/157) | Preview/apply safety only where validation adapters need it | project/runtime safety specs |
| Parked | `requirements-03-backlog-sync` | [#166](https://github.com/nold-ai/specfact-cli-modules/issues/166) | Read-first backlog drift evidence; no write-back critical path. Deprioritized 2026-07-13 behind openspec-01 | requirements-02, sync-01 |
Expand Down Expand Up @@ -172,7 +185,9 @@ ceremony rather than validation evidence:
3. Core C14 adoption [#680](https://github.com/nold-ai/specfact-cli/issues/680).
4. Core C14 dogfood/readiness [#683](https://github.com/nold-ai/specfact-cli/issues/683).
5. Evidence-backed modules hardening and stable publication [#432](https://github.com/nold-ai/specfact-cli-modules/issues/432).
6. Shared skill installation #251 -> generated instructions #253 -> adapters #433; later conformance #684/#434; modules C15 #417 -> core C15 #679.
6. Core implementation-assurance contracts [#684](https://github.com/nold-ai/specfact-cli/issues/684).
7. Modules checkpoint/conformance runtime, dogfood, signing, and publication [#434](https://github.com/nold-ai/specfact-cli-modules/issues/434).
8. Shared skill installation #251 -> generated instructions #253 -> adapters #433. Modules C15 #417 -> core C15 #679 may proceed independently after stable #432.

Modules C15 #417 keeps its existing policy and exception blockers (#158,
core #248, and modules #167) plus the stable preflight release. Existing native
Expand Down Expand Up @@ -206,7 +221,7 @@ dedicated issue-linked worktree and session.
- `requirements-05-dogfood-evidence-gate`
- `requirements-06-evidence-enforcement` (after requirements-05 archival/release evidence)
- `requirements-07-scenario-runtime-proof` (current-run reconciliation correction after requirements-06)
- `requirements-08-bounded-red-green-proof` (paired with core bounded replay after corrected R07)
- archived `requirements-08-bounded-red-green-proof` is superseded and historical only; no replay implementation or canonical spec promotion occurred
Comment thread
djm81 marked this conversation as resolved.
Outdated
- `architecture-01-solution-layer`
- `sync-01-unified-kernel`
- `requirements-03-backlog-sync` (parked 2026-07-13)
Expand All @@ -216,8 +231,8 @@ dedicated issue-linked worktree and session.
- `docs-16-core-accountability-sync`
- `architecture-02-module-well-architected`
- `docs-14-module-release-history`
- `preflight-04-harness-adapters` after core #253 and stable publication
- `preflight-05-implementation-conformance` after stable publication and core #684
- `preflight-05-implementation-conformance` after stable #432 and core #684
- `preflight-04-harness-adapters` after signed #434, core #251, and core #253

## Parent Issues And Epic Framing

Expand Down
40 changes: 26 additions & 14 deletions openspec/INTEGRATION.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,8 +7,9 @@ changes without creating runtime behavior.
## Preflight Ownership

- Core `preflight-01-design-contract-core` owns design-contract,
validation-result, digest, approval-seal, and side-effect-free verifier
interfaces.
role-classified scope, component/risk/verification intent, Requirements-plan
references, validation-result, digest, approval-seal, and side-effect-free
verifier interfaces.
- Modules `preflight-02-assurance-runtime` owns executable Python validators,
CLI orchestration, rendering, explicit persistence, and canonical bundled
`specfact-preflight` workflow content.
Expand All @@ -19,10 +20,20 @@ changes without creating runtime behavior.
canonical `.agents/skills` export. Core `ai-integration-03-instruction-files`
owns generated gate references. Neither owns the workflow body or validators.
- Modules `preflight-04-harness-adapters` owns thin Codex, ECC, and hatch3r
packaging. Adapters map native invocation and assets only.
- Core `preflight-05-implementation-conformance` owns later comparison
interfaces; paired modules owns extraction and runtime comparison. This phase
is explicitly excluded from the preflight MVP.
packaging after the signed #434 handoff. That handoff is one exact signed
module identity plus separately named preflight and implementation-check
workflow identities/digests. Adapters map native invocation and assets only.
- Core `preflight-05-implementation-conformance` owns worktree/index/range
snapshot, obligation-map, finding/result, authority, and pure comparison
interfaces. Paired modules owns checkpoint/conform commands, C14-backed Git
extraction, Requirements pytest/JUnit and code-review evidence, caching,
pre-commit policy, remediation packets, bounded agent workflow,
checkpoint/conformance-result rendering, optional atomic snapshot/result
persistence under its distinct result schema, signing, and publication of the
module identity plus separately bound preflight and implementation-check
workflow identities/digests. These surfaces are separate from
`preflight-02-assurance-runtime`, which exclusively owns preflight
readiness/validation/seal rendering and persistence.

## Shared Rules

Expand All @@ -32,21 +43,22 @@ changes without creating runtime behavior.
OpenSpec, Spec Kit, ECC, hatch3r, and Codex instructions contain a compact
gate/reference only.
- Python validators are the canonical determinate checks. Prompts and adapters
must not recompute readiness, approval, or conformance.
must not recompute readiness, approval, checkpoint, or conformance status.
- A seal proves exact reviewed-input identity and recorded approval, not design,
LLM, implementation, security, or semantic correctness.
- Any pre-implementation bound-input change invalidates readiness and requires
a complete rerun and explicit user approval. During later conformance, the
approved seal is verified against its sealed contract and base source
snapshot while the implementation head/range is captured as a separate,
explicit identity; implementation commits do not silently rewrite the seal.
snapshot while worktree/index/range implementation evidence is captured as a
separate identity; implementation commits do not silently rewrite the seal.
- Worktree/index checkpoint results have local authority only. They cannot be
promoted to protected PR-range evidence; final conformance requires a new
explicit immutable base/head evaluation.
- Native GitHub parents, project status, blockers, and blocked-by relationships
are required before implementation; body-only references are insufficient.

## Delivery Sequence

`core #682 -> modules #431 -> core C14 #680 -> core #683 -> modules #432`.
After the signed release, `#251 -> #253 -> modules #433`; stable modules #432,
modules #433, and core #684 all block modules #434. Issue #434 remains a later
branch; modules C15 `#417` -> core C15 #679 remains the signal-calibration
branch. Existing policy/exception blockers remain in force.
`core #682 -> modules #431 -> core C14 #680/#683 -> modules #432 -> core #684 -> modules #434 -> core #251 -> core #253 -> modules #433`.
Modules C15 `#417` -> core C15 #679 remains an independent signal-calibration
branch after stable #432. Existing policy/exception blockers remain in force.
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
# Change Validation

## Status

`ARCHIVED / SUPERSEDED / NOT IMPLEMENTED — NO SPEC PROMOTION`

Issues #414 and nold-ai/specfact-cli#675 are closed as `not planned`. The
seal-bound development assurance work in #431/#434 and core #682/#684 replaces
the expensive historical replay proposal. No package behavior or signed release
implements this change. The dated folder relocation was explicitly authorized
on 2026-08-30 and did not run `openspec archive`, so the unimplemented deltas
were not merged into the canonical specification.

## Planning evidence

- Paired core issue/PR: nold-ai/specfact-cli#675 / nold-ai/specfact-cli#674.
- Modules tracking issue: #414 with required labels and assignee.
- Strict command required before implementation: `openspec validate requirements-08-bounded-red-green-proof --strict`.
- Failing-before and passing-after implementation artifacts: unavailable; no behavior changed.
- Package, registry, checksum, signature, and verifier-epoch evidence: unavailable because implementation and release never occurred.

## Supersession record

- Modules issue #414: closed `not planned` on 2026-08-27.
- Core issue #675: closed `not planned` on 2026-08-27.
- Replacement planning: modules #431/#434 and core #682/#684.
- The complete folder is preserved at
`openspec/changes/archive/2026-08-30-requirements-08-bounded-red-green-proof/`.
- `openspec archive` was deliberately not invoked because it would have promoted
never-implemented delta specifications into canonical requirements.
- The relocation preserved the historical artifacts only. It changed no file
under `openspec/specs/`, package, registry, version, signature, or runtime path.
- Reopening requires a new issue and a new active OpenSpec change revalidated
against current architecture; this archived proposal is not implementation authority.
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
# Requirements 08: Bounded Red-Green Proof

> **Archived without specification promotion — superseded and never
> implemented.** Modules issue #414 and paired core issue #675 were closed as
> `not planned` on 2026-08-29. On 2026-08-30, an explicit repository-owner
Comment thread
coderabbitai[bot] marked this conversation as resolved.
Outdated
> decision moved this complete historical folder to the dated archive without
> running `openspec archive`; therefore none of its delta specifications were
> merged into canonical requirements. The lower-cost seal-bound checkpoint
> design in modules #431/#434 and core #682/#684 supersedes this replay approach.

This module-side change historically proposed a typed B/R/H/D replay capsule and chronology reconciliation contract for paired core issue nold-ai/specfact-cli#675. It was never implemented, shipped, or merged. The active replacement is the seal-bound planning and checkpoint/conformance path in modules #431/#434 and core #682/#684; the retained replay artifacts are historical traceability only.

Historical planning only: no package behavior, registry artifact, version, or signature implemented this change.
Original file line number Diff line number Diff line change
Expand Up @@ -47,7 +47,7 @@ The Requirements module should validate a typed capsule produced by trusted core
- **GitHub Issue**: #414
- **Issue URL**: https://github.com/nold-ai/specfact-cli-modules/issues/414
- **Repository**: nold-ai/specfact-cli-modules
- **Last Synced Status**: open
- **Last Synced Status**: closed-not-planned / archived without spec promotion / superseded
- **Parent Feature**: #161
- **Paired Core Issue**: nold-ai/specfact-cli#675
- **Paired Core PR**: nold-ai/specfact-cli#674
Expand Down
Loading
Loading