Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
35 changes: 19 additions & 16 deletions openspec/CHANGE_ORDER.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,26 +7,27 @@ must be read together with the core repo change order in `nold-ai/specfact-cli`.

| Bucket | Count | Location |
|---|---:|---|
| **Active-tree entries** | 20 | [`openspec/changes/`](changes/) |
| **Active-tree entries** | 19 | [`openspec/changes/`](changes/) |
| **Parking-lot entries** | 16 | [`openspec/parking-lot/`](parking-lot/) |
| **Archived** | 50 | [`openspec/changes/archive/`](changes/archive/) |
| **Abandoned history** | 1 | [`openspec/history/abandoned/`](history/abandoned/) |

`openspec list` reflects all 20 direct active-tree entries. The closed R08
proposal is no longer presented as active work. Under an explicit owner decision
on 2026-08-30, its complete historical folder was relocated to the dated archive
without running `openspec archive`; no unimplemented delta entered canonical
specifications. Completed changes still use native OpenSpec archival. Parking-lot
changes are preserved for later customer pull but are not implementation-ready.
`openspec list` reflects all 19 direct active-tree entries. The closed R08
proposal is retained under non-canonical abandoned history, outside
`openspec/changes/` and its completed-change archive; no unimplemented delta
entered canonical specifications. Completed changes still use native OpenSpec
archival. Parking-lot changes are preserved for later customer pull but are not
implementation-ready.

## Abandoned Changes Archived Without Specification Promotion
## Abandoned Planning History Without Specification Promotion

| Change | GitHub issue | Archive status |
| Change | GitHub issue | Historical status |
|---|---|---|
| [`requirements-08-bounded-red-green-proof`](changes/archive/2026-08-30-requirements-08-bounded-red-green-proof/) | [#414](https://github.com/nold-ai/specfact-cli-modules/issues/414) | Closed Not Planned; never implemented; manually relocated on 2026-08-30 without `openspec archive`; canonical specs unchanged |
| [`requirements-08-bounded-red-green-proof`](history/abandoned/2026-08-30-requirements-08-bounded-red-green-proof/) | [#414](https://github.com/nold-ai/specfact-cli-modules/issues/414) | Closed Not Planned on 2026-08-27; never implemented; retained outside the completed-change archive; canonical specs unchanged |

This is a bounded exception for an abandoned, never-implemented proposal. It is
not precedent for completed work, which must still use `openspec archive` so
implemented deltas are validated and promoted normally.
This non-canonical history is not an OpenSpec archive and is not implementation
authority. Completed work must use `openspec archive` so implemented deltas are
validated and promoted normally.

## Product Thesis

Expand Down Expand Up @@ -58,6 +59,7 @@ issues and are now archived:
| `code-review-11-simplification-feedback-loop` | archived 2026-06-06 |
| `code-review-12-guided-simplification-enforcement` | archived 2026-06-06 |
| `code-review-13-cleanup-forecast-agent-handoff` | archived 2026-06-06 |
| `module-scope-02-preserve-user-installs` | archived 2026-08-30 after #454 merged to `dev` |

These archived specs are now the shipped basis for the flagship demo: run review,
produce JSON evidence, identify AI-bloat findings, hand remediation packets to an
Expand All @@ -69,7 +71,6 @@ This track is first because no changed-scope assurance claim is trustworthy unti

| Order | Change folder | GitHub # | Positioning | Blocked by |
|---:|---|---|---|---|
| 0 | `module-scope-02-preserve-user-installs` | [#452](https://github.com/nold-ai/specfact-cli-modules/issues/452) | Preserve user-scoped modules when project-local sources shadow them; remove destructive review/bootstrap guidance | none; paired core [#699](https://github.com/nold-ai/specfact-cli/issues/699) is coordinated but independently mergeable |
| 1 | `code-review-14-scope-truth-and-differential-enforcement` | [#416](https://github.com/nold-ai/specfact-cli-modules/issues/416) | Resolve worktree/index/range/full scope explicitly; compare pinned merge-base/head analyses; authenticate one target-tip project-runtime layer for both snapshots; fail closed on unknown scope, runtime provenance, or analyzer coverage | accepted planning PR [#413](https://github.com/nold-ai/specfact-cli-modules/pull/413); paired core adoption is downstream after the signed release |

The immutable C14 compatibility smoke establishes core 0.55.1 as the minimum: lightweight tag `v0.55.1`, full commit `b1e517e60e669eaba15a18ecfa83ef5a9df65276`, and full tree `47984be5434d7ae65ed6908bf525a32053290337`. Runtime metadata therefore uses `>=0.55.1,<1.0.0`: the ceiling is required because recursive installation includes Codebase and Requirements modules whose current manifests reject core 1.x. Current paired-core validation exercises compatible versions above the minimum; a routine compatible core update within the dependency graph does not require a module metadata release. Remove the ceiling only after widening and validating the required dependency graph. This correction supersedes C14's exact-only admission wording without changing its frozen provenance identities or historical evidence.
Expand Down Expand Up @@ -221,7 +222,7 @@ dedicated issue-linked worktree and session.
- `requirements-05-dogfood-evidence-gate`
- `requirements-06-evidence-enforcement` (after requirements-05 archival/release evidence)
- `requirements-07-scenario-runtime-proof` (current-run reconciliation correction after requirements-06)
- archived `requirements-08-bounded-red-green-proof` is superseded and historical only; no replay implementation or canonical spec promotion occurred
- abandoned-history `requirements-08-bounded-red-green-proof` is superseded and non-canonical; no replay implementation or specification promotion occurred
- `architecture-01-solution-layer`
- `sync-01-unified-kernel`
- `requirements-03-backlog-sync` (parked 2026-07-13)
Expand Down Expand Up @@ -251,4 +252,6 @@ implementation starts.
After a change ships and merges, run `openspec archive <change-id>` from the repo
root. Do not manually move completed changes into `openspec/changes/archive/`.
Parking-lot moves are allowed for paused proposals that are explicitly not active
scope.
scope. Abandoned, never-implemented proposals may be retained only under
`openspec/history/abandoned/`, whose records are non-canonical and never imply
specification promotion or implementation authority.
Original file line number Diff line number Diff line change
Expand Up @@ -16,5 +16,5 @@ Contributor and agent bootstrap guidance SHALL treat project-over-user module sh

- **GIVEN** a test process imported a bundled module from the user-scoped source path
- **WHEN** the local bundle source bootstrap realigns the test process to repository sources
- **THEN** it may remove the loaded module from in-memory import state
- **THEN** it removes the loaded module from in-memory import state or enforces an equivalent before-import guarantee that prevents reuse of the cached user-scoped module
- **AND** it does not delete or uninstall the user-scoped module files
Original file line number Diff line number Diff line change
Expand Up @@ -14,13 +14,17 @@

- This change owns thin Codex, ECC, and hatch3r installation/invocation adapters.
- The signed modules runtime remains the only validator/readiness implementation.
- Core #251 owns generic installation/export and core #253 owns generated instruction references.
- Core #251 owns generic installation/export and must expose the explicit `verified-install-result-v1` contract defined by this planning change; core #253 owns generated instruction references.

## Dependency Review

- Parent Feature: modules [#163](https://github.com/nold-ai/specfact-cli-modules/issues/163).
- Required delivery order: signed modules checkpoint/conformance identity #434,
then core #251 and #253, then this adapter change #433.
- Adapter implementation remains blocked until the completed #251 contract binds
verifier, module, artifact, signed manifest, registry, signer/trust root, core,
installed inventory, and both role-specific workflow mappings to the exact
installed bytes and requested descriptor.
- Native dependency relationships must be refreshed and read back before
implementation so #433 consumes the exact #434 identity and does not become
a prerequisite of #434.
Expand Down
4 changes: 3 additions & 1 deletion openspec/changes/preflight-04-harness-adapters/design.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,9 @@ These are integration inputs, not permanent assumptions. Each adapter must decla

### 1. Shared adapter descriptor

Every adapter consumes a descriptor containing three separately named release inputs: the exact signed SpecFact #434 module version/artifact digest/signature/trust-root/registry identity, the preflight workflow identity/digest, and the implementation-check workflow identity/digest. The descriptor also binds compatible core identity, supported harness and version range, native invocation form, asset mapping, instruction markers, install scope, and uninstall inventory. It consumes the official installer's verified result when that interface owns verification and proves the two role-specific signed-manifest mappings: preflight identity to preflight digest, and implementation-check identity to implementation-check digest. Mere presence or cross-pairing is invalid. Invalid, untrusted, unsupported, omitted, or mismatched identities fail closed before installation, upgrade, invocation, or packaging.
Every adapter consumes a descriptor containing three separately named release inputs: the exact signed SpecFact #434 module version/artifact digest/signature/trust-root/registry identity, the preflight workflow identity/digest, and the implementation-check workflow identity/digest. The descriptor also binds compatible core identity, supported harness and version range, native invocation form, asset mapping, instruction markers, install scope, and uninstall inventory.

Core #251 must first define and ship `verified-install-result-v1`. A successful result binds the verifier identity/version, requested and installed module version, artifact and signed-manifest digests, registry, signer/trust root, compatible core, exact installed asset inventory/digests, and both role-specific signed-manifest workflow mappings to the installed bytes and requested descriptor. Every adapter consumes that result and proves the preflight identity-to-digest and implementation-check identity-to-digest mappings. Missing, unsuccessful, stale, incomplete, untrusted, omitted, mismatched, or cross-paired evidence fails closed before installation, upgrade, invocation, or packaging. Descriptor text and adapter-generated assertions are not verification fallbacks.

### 2. Codex plugin is an installation shell

Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,22 @@
schema_version: "2"
requirements:
openspec:preflight-04-harness-adapters:preflight-harness-adapters:core-installer-verification-result-is-explicit:
rationale: "The proposal must block adapter implementation until core #251 exposes a result bound to the exact verified installation."
stakeholder_refs:
- "nold-ai/specfact-cli-modules#433"
- "nold-ai/specfact-cli#251"
touchpoints:
- id: openspec-source-spec
kind: config_file
locator: "openspec/changes/preflight-04-harness-adapters/specs/preflight-harness-adapters/spec.md"
verification_cases:
- case_id: PF04-008
scenario_id: core-installer-verification-result-is-explicit
method: inspection
intent: "Inspect the explicit verified-install-result-v1 prerequisite and fail-closed behavior before implementation."
observable: >-
Strict OpenSpec validation retains the complete result binding and
prohibits descriptor-only or adapter-generated verification fallback.
openspec:preflight-04-harness-adapters:preflight-harness-adapters:codex-plugin-adapter:
rationale: "The proposal must make this requirement reviewable before implementation begins."
stakeholder_refs: ["nold-ai/specfact-cli-modules#433"]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,19 @@
## ADDED Requirements

### Requirement: Core installer verification result is explicit

Before adapter implementation begins, core #251 SHALL define and ship a machine-readable `verified-install-result-v1` for the exact installed or exported assets. A successful result SHALL bind the verification outcome, verifier identity and version, requested and installed module version, artifact and signed-manifest digests, registry identity, authorized signer and trust-root identity, compatible core identity, installed asset inventory and digests, and the signed-manifest mappings for both the preflight and implementation-check workflow identities and digests. The result SHALL be bound to the installed bytes and the requested adapter descriptor. A missing, unsuccessful, stale, incomplete, or mismatched result SHALL fail closed. Adapters SHALL NOT replace it with descriptor text or an adapter-generated verification assertion.

#### Scenario: Core installer result contract is unavailable

- **GIVEN** core #251 does not expose `verified-install-result-v1` with every required identity and digest binding
- **WHEN** adapter implementation, installation, upgrade, invocation, or packaging is requested
- **THEN** the adapter work remains blocked
- **AND** adapter-owned verification is not used as an implicit fallback.

### Requirement: Shared adapter identity contract

Every harness adapter SHALL declare and verify the exact signed #434 module version, artifact digest, authorized signature/trust-root identity, registry identity, compatible core identity, separately named preflight workflow identity/digest and implementation-check workflow identity/digest, supported harness versions, native invocation mapping, installed asset inventory, and upgrade/uninstall rules. When the released installer owns cryptographic verification, adapters SHALL consume its verified result and SHALL verify the role-specific manifest mappings `preflight workflow identity -> preflight workflow digest` and `implementation-check workflow identity -> implementation-check workflow digest` before installation, upgrade, invocation, or packaging. Presence of both identities and both digests without the correct pairings SHALL NOT satisfy verification.
Every harness adapter SHALL declare and verify the exact signed #434 module version, artifact digest, authorized signature/trust-root identity, registry identity, compatible core identity, separately named preflight workflow identity/digest and implementation-check workflow identity/digest, supported harness versions, native invocation mapping, installed asset inventory, and upgrade/uninstall rules. Adapters SHALL consume the successful core #251 `verified-install-result-v1` and SHALL verify the role-specific manifest mappings `preflight workflow identity -> preflight workflow digest` and `implementation-check workflow identity -> implementation-check workflow digest` before installation, upgrade, invocation, or packaging. Presence of both identities and both digests without the correct pairings SHALL NOT satisfy verification.

#### Scenario: Immutable release identity does not match

Expand All @@ -13,7 +24,7 @@ Every harness adapter SHALL declare and verify the exact signed #434 module vers

#### Scenario: Signature or installed workflow is invalid or untrusted

- **GIVEN** signature verification fails against the authorized trust root, the verified installer result is absent, either role-specific workflow identity/digest pair is omitted or mismatched, the identities/digests are cross-paired, or either installed workflow digest differs from its corresponding signed manifest mapping
- **GIVEN** signature verification fails against the authorized trust root, `verified-install-result-v1` is absent, unsuccessful, stale, incomplete, or mismatched, either role-specific workflow identity/digest pair is omitted or mismatched, the identities/digests are cross-paired, or either installed workflow digest differs from its corresponding signed manifest mapping
- **WHEN** installation, upgrade, invocation, or packaging is requested
- **THEN** the adapter fails closed before the operation
- **AND** it does not treat descriptor text alone as verification.
Expand Down
8 changes: 4 additions & 4 deletions openspec/changes/preflight-04-harness-adapters/tasks.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,18 +6,18 @@ All tasks below are future implementation and external integration work. This pl

- [ ] 1.1 In a dedicated issue-linked session, create `feature/preflight-04-harness-adapters` from current `origin/dev` in a new modules worktree before any implementation edit.
- [ ] 1.2 Refresh hierarchy metadata and verify this issue is `Todo`, correctly parented/labeled/assigned, blocked by core #253, and not concurrently `In Progress`.
- [ ] 1.3 Verify the exact signed #434 module and preflight/implementation-check workflow identities, completed #251/#253 contracts, and current Codex/ECC/hatch3r contribution and packaging rules. For hatch3r, require the selected release to contain and document a supported distribution/extension surface; an upstream contribution qualifies only after it is merged, included in that release, and documented there. Stop hatch3r work otherwise.
- [ ] 1.3 Verify the exact signed #434 module and preflight/implementation-check workflow identities, a completed core #251 `verified-install-result-v1` contract bound to installed bytes and the requested descriptor, the completed #253 contract, and current Codex/ECC/hatch3r contribution and packaging rules. The #251 result must bind every verifier, module, artifact, manifest, registry, signer/trust-root, core, installed-inventory, and role-specific workflow identity/digest field required by the specification. Stop all adapter work if that result contract is absent or incomplete. For hatch3r, require the selected release to contain and document a supported distribution/extension surface; an upstream contribution qualifies only after it is merged, included in that release, and documented there. Stop hatch3r work otherwise.

## 2. Adapter specs and failing-first tests

- [ ] 2.1 Finalize the shared descriptor and a tested harness/version matrix; remove assumptions contradicted by current upstream primary sources.
- [ ] 2.2 Add failing contract tests for install, invocation mapping, semantic parity, exact-version rejection, registry/core identity mismatch, invalid/untrusted signature rejection, absent verified-installer result, role-specific signed workflow identity-to-digest binding including omission/mismatch/cross-pairing, unsupported hatch3r distribution rejection, drift, upgrade, and safe uninstall before adapter production edits; exercise every fail-closed identity case across installation, upgrade, invocation, and packaging.
- [ ] 2.2 Add failing contract tests for install, invocation mapping, semantic parity, exact-version rejection, registry/core identity mismatch, invalid/untrusted signature rejection, missing/unsuccessful/stale/incomplete/mismatched `verified-install-result-v1`, forbidden adapter-generated verification fallback, role-specific signed workflow identity-to-digest binding including omission/mismatch/cross-pairing, unsupported hatch3r distribution rejection, drift, upgrade, and safe uninstall before adapter production edits; exercise every fail-closed identity case across installation, upgrade, invocation, and packaging.
- [ ] 2.3 Capture failing-first results in a newly created `TDD_EVIDENCE.md`.

## 3. Minimal adapter implementation

- [ ] 3.1 Implement the Codex plugin shell using the exact signed #434 module identity, preflight workflow identity/digest, implementation-check workflow identity/digest, and installed CLI.
- [ ] 3.2 Implement the ECC skills-first companion and only the command shims required by the supported matrix.
- [ ] 3.1 Implement the Codex plugin shell using the successful core #251 `verified-install-result-v1`, exact signed #434 module identity, preflight workflow identity/digest, implementation-check workflow identity/digest, and installed CLI.
- [ ] 3.2 Implement the ECC skills-first companion using the same verified result and only the command shims required by the supported matrix.
- [ ] 3.3 Implement hatch3r packaging only through the released and documented supported surface verified in 1.3; an accepted or merged upstream prerequisite alone is insufficient until the selected release contains and documents it. Never write internal inventory data or depend on private package layout.
- [ ] 3.4 Keep all validators, approval decisions, and readiness aggregation in the released SpecFact runtime.

Expand Down
Loading
Loading