Skip to content

docs: publish landscape audit and evidence-led delivery strategy - #47

Merged
BunsDev merged 3 commits into
mainfrom
docs/repository-landscape-strategy
Sep 12, 2026
Merged

BunsDev merged 3 commits into
mainfrom
docs/repository-landscape-strategy

Conversation

@BunsDev

@BunsDev BunsDev commented Sep 11, 2026

Copy link
Copy Markdown
Member

Objective

Publish the requested repository landscape audit and delivery strategy, and
reconcile explanatory documentation with actual authority boundaries,
implementation evidence, and the approved solo-maintainer workflow.

Refs #31, #13, #39, #40, #46. Beads: threads-9nf, threads-ufe,
threads-ntd, threads-1e9, and threads-xgc.

Acceptance criteria

  • Source-cited readiness review preserves all eight Phase-5 coherence obligations and four unresolved remediation gates.
  • Ordered delivery strategy identifies canonical owners, issue links, exit evidence, non-goals, and rollback.
  • Current documentation distinguishes library calls from daemon authority, package/profile versions, planned commands, and historical plans.
  • Reconcile merged ci: enforce independent privacy policy with sanitized source reference #40/docs: record enforced main-branch governance #46 with the explicitly authorized solo-maintainer policy; preserve dated evidence rather than relabeling it.
  • Preserve the stable compatibility pin, frozen contracts, unresolved daemon evidence, and human coherence/freeze gates.
  • Exclude mutable Beads interaction history.

Current head and scope

Head: 4f8f75f6fe908023a2aba8f9d035aadf29746b0c.
Base includes #46 at 91ff511609cfb717bf71c3cafe07c0cbb2a2a317 and #40 at
7168dae10f6b59bad8bc653b95f51911334ded74.

The net PR delta against current main is 16 Markdown files only:
CONTRIBUTING.md, README.md, SECURITY.md, docs/README.md,
docs/architecture.md, docs/automation-authority-profile.md,
docs/channels-and-strands.md, docs/concepts.md, docs/diagrams/README.md,
docs/faq.md, docs/glossary.md, docs/phases.md,
docs/reviews/2026-09-11-landscape-and-readiness.md, docs/strategy.md, and
the historical ApplyAudit design and plan under docs/superpowers/.

The privacy workflow and approved source-reference correction landed separately
in #40. This PR does not reintroduce or modify them relative to main.

Human authorization and governance

The maintainer approved the documentation work, confirmed this is a
solo-maintainer repository, and explicitly authorized removing the incompatible
independent-review requirements and proceeding with eligible merges.
Exact authorization, live change, and rollback.

Ruleset 22910327 remains active, with no bypass actors. Only three settings
changed: required approval count 1 -> 0, latest-push approval true -> false,
and extra unattributed-change approval true -> false. PRs, resolved review
conversations, stale-review dismissal, all four strict required GitHub Actions
checks, and deletion/non-fast-forward protection are unchanged.

The policy requires recorded explicit human authorization before agent merges;
GitHub does not enforce this conversational process. No independent review is
fabricated. No collaborator access was granted. Phase-5 coherence/freeze
decisions and their engineering prerequisites remain separate and open.

Canonical contracts consulted

AGENTS.md, agent/manifest.yaml, specs/PHASE-0-DESIGN.md,
specs/PHASE-3-PORTABILITY.md, specs/PHASE-5-APPROVAL-SEMANTICS.md, the
automation profile manifest/reference contract, docs/testing/e2e-contract.md,
e2e/compatibility.toml, and public Rust approval, identity, replay,
validation, audit, and conformance surfaces.

Source findings remain bounded to the recorded downstream revision
8576f41e6d622f63a3576b85bd2d3142776e59ca in OpenCoven/coven#931 and the
hosted artifact provenance in the dated review. No new downstream acceptance
is inferred from this documentation landing.

Impact and non-goals

R4 authority documentation: no runtime, Rust API, SQL/schema, migration,
dependency, fixture, identity, credential, or protected-write behavior changes.
No second audit store or writer. Existing MIT metadata remains unchanged; the
historical license discrepancy is reported, not decided. No PDF, slide, or
rendered-diagram recertification.

The separate privacy job remains PR-controlled and is not a required check.
Adding a privacy or daemon required check is outside this authorized policy
change. No phase gate is closed.

Evidence

  • git diff --cached --check: passed before the combined commit.
  • node scripts/privacy-guard.mjs: clean staged index.
  • Read-only Node Markdown link scan: 16 files, 179 local links, zero errors.
  • Net changed-path inspection against landed main: only the 16 Markdown files.
  • Ruleset API read-back matched the authorized payload exactly; effective branch rules preserve the remaining controls.
  • Separate docs: record enforced main-branch governance #46 exact-head CI: 34664611356, success.
  • Separate ci: enforce independent privacy policy with sanitized source reference #40 combined-head CI: 34664678160, success.
  • This PR's combined-head CI is recorded on its checks and landing comment; earlier head results do not substitute for it.

No new test/build tools were introduced. Required CI provides the existing
repository regression suite; no fresh local daemon result is claimed.

Downstream canary

The stable Coven pin remains 39feb6de98816d10b490091e918f62035e6ce0df,
with harness-required: it lacks the required target. Current Threads
override acceptance and the latest-main canary remain not runnable/not wired.
Earlier hosted downstream green used an older dependency with override false
and does not certify this head.

Rollback and uncertainty

Revert or correct this documentation through the normal PR process. That does
not revert server-side policy; restoring its prior review settings requires
the separate three-field rollback recorded above.

Preserve recorded contradictory evidence and unresolved applying claims.
Supported auto-path reachability, classification-time identity binding,
complete terminal/protected-route recovery matrices, native startup
causation, and full pinned-daemon/OS/Cave acceptance remain unresolved.

Reconcile current governance, candidate privacy rollout, authority boundaries, profile maturity, historical plans, and remaining Phase-5 acceptance. Preserve frozen contracts, runtime ownership, compatibility pins, and independent human decisions.

Refs #31, #13, #39, #40, #46; threads-9nf and threads-ufe.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@BunsDev

BunsDev commented Sep 11, 2026

Copy link
Copy Markdown
Member Author

Publication evidence: exact-head CI 34647315756 passed for 29ae365, including repository quality, Cargo compatibility, Nextest, secret scanning, and informational coverage: https://github.com/OpenCoven/coven-threads/actions/runs/34647315756 . The committed delta is exactly 16 Markdown files; no Beads interactions, Rust, SQL, workflow, frozen-spec, or compatibility-pin change is included. Local documentation links and whitespace were checked. These results are repository evidence, not fresh daemon acceptance or independent approval. Landing remains tracked by threads-xgc; coordinate overlap with #40/#46 and retain all Phase-5 gates.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Three unresolved documentation comments concern audit completeness, canonical tracking, and ownership wording.

Pull request overview

This documentation-only PR publishes a repository readiness audit and delivery strategy while clarifying authority, governance, privacy status, and historical documentation.

Changes:

  • Adds strategy and readiness-review documents.
  • Reconciles project status, ownership, evidence, and acceptance boundaries.
  • Updates explanatory and historical documentation without changing runtime behavior.
File summaries
File Summary
SECURITY.md Clarifies privacy rollout and checker limitations.
README.md Updates project status, authority model, and documentation links.
docs/superpowers/specs/2026-07-19-apply-audit-migration-repair-design.md Routes historical design documentation to the current strategy.
docs/superpowers/plans/2026-07-19-apply-audit-migration-repair.md Marks historical commit instructions as non-actionable.
docs/strategy.md Adds ordered workstreams and evidence gates; three tracked-link and ownership wording issues remain (nit, 1 vote each).
docs/reviews/2026-09-11-landscape-and-readiness.md Adds the cited readiness audit; retain the complete audit-completeness obligation chain (nit, 1 vote).
docs/README.md Updates documentation routing and status.
docs/phases.md Reconciles phase, governance, and acceptance evidence.
docs/glossary.md Clarifies Cave and replay terminology.
docs/faq.md Corrects replay and isolation explanations.
docs/diagrams/README.md Labels diagrams as explanatory or historical artifacts.
docs/concepts.md Marks the inspection command as design-only.
docs/channels-and-strands.md Clarifies portability and promotion status.
docs/automation-authority-profile.md Documents profile release and adoption boundaries.
docs/architecture.md Clarifies daemon authority and acceptance limits.
CONTRIBUTING.md Documents verification and daemon-E2E limitations.
Review details

Suppressed comments (3)

docs/reviews/2026-09-11-landscape-and-readiness.md:185

  • The #13 checklist names this obligation Audit completeness and requires the full proposal_submitted → window_opened → close(reason) chain with no gap. Renaming it to only “Exactly one typed terminal close” leaves the submission/opening linkage unassessed in this eight-item mapping; please retain the exact obligation and state whether each link is proven or remains open.
| Exactly one typed terminal close | [Typed close/SQL guards][audit] and hosted terminal families exist; full failure/recovery coverage and explicit ambiguous-applying resolution remain open. |

docs/strategy.md:32

  • threads-chk is not a tracked bead or issue reference, and #46 identifies its bead as threads-6qw; this leaves the governance/privacy workstream with an unusable tracking link. Replace it with the canonical bead IDs so readers can follow the work.
**Tracking:** #46, #40, #39; `threads-chk`, `threads-t6t`.

docs/strategy.md:65

  • This row conflates implementation ownership with a human acceptance gate and overstates the cited issue's scope. OpenCoven/coven#888 is specifically the retired-Ward schedulability blocker, while #13 explicitly describes Nova sign-off as a gate, not an implementation bead; either narrow the row to the retired-Ward route or name the actual implementation owner(s) and list #13 only as the acceptance gate.
| Every approval ceremony reaches supported intake | #13 and OpenCoven/coven#888; `threads-zav` | Prove both auto variants and the human paths through a supported production route; do not lower protected region floors or insert test-only envelopes |
  • Files reviewed: 16/16 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Address PR #47 review by retaining submission-to-window-to-close acceptance, distinguishing completed governance from remaining landing work, and separating daemon route implementation from the human coherence gate.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@BunsDev

BunsDev commented Sep 12, 2026

Copy link
Copy Markdown
Member Author

Addressed the new review in ad81d9d (two Markdown files only). Audit completeness now retains the entire proposal_submitted -> window_opened -> close(reason) obligation, with source-cited evidence and explicit remaining proof for each link. Approval-route implementation is assigned to the Coven producer/harness lane (OpenCoven/coven#972, OpenCoven/coven#884, integrated in OpenCoven/coven#931); #13 is identified only as the acceptance gate, and OpenCoven/coven#888 keeps its narrower retired-corpus scope. The claim that threads-chk does not exist is incorrect: bd show confirms it is the blocked documentation-landing task, while closed threads-6qw records server-side governance setup. The strategy now names both roles and supplies public GitHub links so clean-clone readers need no private Beads database. No source, workflow, frozen contract, stable pin, or human decision changed. Local links/whitespace pass. gh run watch 34660282587 --exit-status completed successfully for this exact new head: https://github.com/OpenCoven/coven-threads/actions/runs/34660282587 . Eligible independent approval remains absent; CI is not that approval. The reviewer/access prerequisite is recorded in threads-1e9 and on #31.

@BunsDev

BunsDev commented Sep 12, 2026

Copy link
Copy Markdown
Member Author

Human approval of the documentation audit, strategy, and follow-up corrections has been recorded at ad81d9d: #31 (comment) . This is assistant-recorded conversational approval, not a qualifying independent GitHub review or Phase-5 coherence/freeze decision. Normal landing still requires non-author review; no protection has been changed.

Reconcile the authorized solo-maintainer policy, explicit human approval process, landed privacy job, and historical audit evidence. Preserve downstream acceptance gaps and the Phase-5 human gates. Relative to current main, this PR remains Markdown-only.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@BunsDev

BunsDev commented Sep 12, 2026

Copy link
Copy Markdown
Member Author

Reconciled the audit with merged #46 (91ff511) and #40 (7168dae). CONTRIBUTING.md now defines the authorized solo-maintainer process; strategy, ledger, security policy, and docs index match the actual controls and landed privacy job. The dated review preserves its original evidence with an explicit later-policy/landing section. No runtime, workflow, frozen-spec, or compatibility-pin delta remains relative to current main: 16 Markdown files only. Staged privacy scan and local-link scan pass (179 local links, zero errors); required checks must now run for this combined head before normal merge. Authorization and rollback: #31 (comment) . No Phase-5 human decision or privacy required-check activation is included.

@BunsDev
BunsDev merged commit 3ff49c0 into main Sep 12, 2026
6 checks passed
@BunsDev

BunsDev commented Sep 12, 2026

Copy link
Copy Markdown
Member Author

Landed normally at 3ff49c0 after exact combined-head CI 34664819612 succeeded for 4f8f75f. All three authorized PRs are now merged: #46 at 91ff511, #40 at 7168dae, and this audit. No admin bypass, force push, independent-review impersonation, or Phase-5 closure was used. Required checks and branch safeguards remained active; privacy required-check activation remains a separate decision. Main-push CI is separate from this exact-head pre-merge result.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants