Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
113 changes: 106 additions & 7 deletions BACKLOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ CC-001/CC-002 were consumed by PR #24 fix bundle inline, with no standalone entr
| CC-509 | ✅ closed 2026-07-22 | detached gate launch liveness:對 sandbox parent-death 早期死亡 fail-loud,提供 supervisor readiness/identity evidence | arch/gate | 2026-07-22 | pr:#440 | P2 | hygiene |
| CC-510 | ✅ closed 2026-07-23 | Codex detached dispatch continuation:App Server callback、authenticated completion envelope 與 foreground fallback | arch/DX | 2026-07-23 | pr:#443 | P2 | design |
| CC-511 | ⚠️ partial 2026-07-24 | ship publish authorization:Phase A current-tree authoritative full-suite 已交付;Phase B review-closure evidence 仍待 CC-515/CC-517 | release/gate | 2026-07-23 | pr:#446 | P1 | design |
| CC-512 | ⚠️ partial 2026-07-27 | Slice A 已交付 coordinate sources/CLI resolutionmachine envelopeevidence captureshared verifier 仍待 Slice B/C | ops/gate | 2026-07-23 | | P1 | design |
| CC-512 | ✅ closed 2026-07-27 | Slices A/B/C 已交付coordinate sources/CLI resolutionmachine-owned assurance envelopeevidence captureshared verifier/parity ratchets;targeted 不再是 tier | ops/gate | 2026-07-23 | pr:#451 | P1 | design |
| CC-513 | 🔵 active | canonical gate policy resolver:minimum tier、required reviewers、mode recommendation 與 downgrade audit | security/gate | 2026-07-23 | — | P1 | design |
| CC-514 | 🔵 active | orthogonal delivery assurance map、machine-derived tables 與 feature/docs/high-risk recipes | docs/process | 2026-07-23 | — | P2 | design |
| CC-515 | 🔵 active | gate artifact immutable subject、freshness 與 consumer applicability shared verifier | arch/gate | 2026-07-23 | — | P1 | design |
Expand All @@ -41,6 +41,7 @@ CC-001/CC-002 were consumed by PR #24 fix bundle inline, with no standalone entr
| CC-519 | 🔵 active | selected-reviewer coverage/finding contract:declared coverage、stable IDs 與 actionable fix boundary | ops/gate | 2026-07-23 | — | P1 | design |
| CC-520 | 🔵 active | synthesis parity 與 remediation seed:findings union、root-cause grouping、coverage matrix 與 no-silent-drop | ops/gate | 2026-07-23 | — | P1 | design |
| CC-521 | 🔵 active | test-gap matrix、protocol recovery 與 live recall evaluation 分層 | ops/test | 2026-07-23 | — | P2 | design |
| CC-522 | 🔵 active | 任意 `--test-cmd` 的 opaque/structured capability negotiation、執行失敗分類與外部 evidence recovery | ops/test | 2026-07-27 | feedback:2026-07-27 | P1 | design |
| CC-465 | 🔵 active | memory/context 關鍵詞管線 CJK 支援:抽出共用零依賴斷詞 lib,取代三處各自 ASCII-only 抽詞;工作序列起點(465→467→468→466)(2026-07-07 記憶系統深入分析) | memory | 2026-07-07 | feedback:2026-07-07 | P2 | retrieval |
| CC-466 | ⏸ deferred | 記憶卡片生命週期閉環:expires_at 執行 + 關窗式 supersede + usage sidecar 休眠偵測 + doctor→distill 接線;僅在 CC-467 證明 stale/dormant card 已形成實際問題時啟動 | memory | 2026-07-07 | feedback:2026-07-07 | P2 | retrieval |
| CC-467 | 🔵 active | `pmctl memory stats`:注入效益可視化(唯讀聚合器)——注入 bytes/卡片命中分佈/從未命中卡/episode 填寫率,回答「記憶有跟沒有差在哪」;排在 CC-466 之前(2026-07-07;業界僅離線 recall 評測,無 per-injection 遙測) | DX/memory | 2026-07-07 | — | P2 | retrieval |
Expand Down Expand Up @@ -1616,7 +1617,7 @@ authorization。

---

## CC-512 — tier/mode/pass/coverage/independence assurance 正交化 ⚠️ partial 2026-07-27
## CC-512 — tier/mode/pass/coverage/independence assurance 正交化 2026-07-27

**Problem**: runtime 雖已將 tier detection、reviewer selection 與
`SEQUENTIAL=true|false` 分開,但目前仍有三個 truth gap:
Expand Down Expand Up @@ -1695,11 +1696,12 @@ authorization。
invalid/conflicting inputs,以及 dispatch brief 中的 requested/resolved/coverage
coordinates。`--tier full --reviewers critic` 保留 full intent + critic-only
selection;新 producer/verifier 尚未交付。
2. **B — machine-owned envelope + evidence capture(pending)**:sequential combined session、
parallel per-reviewer/synthesis sessions、targeted initial reference、copy-mode
truthful degradation。
3. **C — verifier + remaining parity ratchets(pending)**:claim consistency、v1 legacy
classification、result/help/docs parity、affected-test mapping。
2. **B — machine-owned envelope + evidence capture(✅ delivered 2026-07-27,
pr:#451)**:sequential combined session、parallel per-reviewer/synthesis sessions、
targeted initial reference、copy-mode truthful degradation。
3. **C — verifier + remaining parity ratchets(✅ delivered 2026-07-27,
pr:#451)**:claim consistency、v1 legacy classification、result/help/docs parity、
affected-test mapping。

**Done-when**:

Expand All @@ -1722,6 +1724,17 @@ engine、FSM或 mandatory parallel policy。
[[CC-513]]再產 policy resolution,[[CC-515]]再把 structural evidence 與
subject/freshness/applicability接起來。

**Outcome**: Slices A/B/C 已完成。Gate producer 現在以分離的 portable policy
sources解析 tier、mode、pass、coverage與independence,並產生 machine-owned
assurance sidecar;dispatch outcome、canonical run evidence、result/repository/
subject bindings與protected attestation皆由 runtime 擷取,不再由 reviewer Markdown
自述。Shared verifier會檢查 structural/claim consistency、coverage partition、
mode/topology、targeted initial reference與v1 legacy降級;copy-mode fallback由
shared verifier產生並受parity ratchet保護。Formal full gate為GO且assurance verified,
current-tree authoritative full suite為97 passed、0 failed、0 skipped。

**See**: pr:#451

**Cross-link**: [[CC-513]]、[[CC-515]]、[[CC-518]]、[[CC-519]]、
`docs/review-model.md`。

Expand Down Expand Up @@ -2119,6 +2132,92 @@ deterministic fail closed,後者具模型波動,不應混成 CI hard gate。

---

## CC-522 — `--test-cmd` execution outcome 與 evidence capability 分層 🔵 active

**Framing**: 本票強化既有 `pmctl gate run --test-cmd` pre-flight 與 qa-tester
對測試執行證據的解讀,不重寫 gate 流程。任意可執行 shell command 永遠是合法輸入;
structured result 是 opt-in capability,不是導入 gate 前必須先改造各 repo runner 的
門檻。本票保留 [[CC-491]] 的 portable opaque evidence 與 structured reusable
evidence 分工;tier/mode/pass/coverage/independence 仍由 [[CC-512]] 擁有,
subject freshness/consumer applicability 仍由 [[CC-515]] 擁有,test-gap內容仍由
[[CC-521]] 擁有。禁止新增 gate kind、workflow engine、強制 runner migration,
或以 stdout/stderr 關鍵字猜測 assertion/環境失敗。

**Problem**: `--test-cmd` 可能是任意 legacy command,未必產生建議的 structured
result;即使 command 有執行,也可能因 reviewer sandbox、依賴、網路、資源限制或
timeout 非零退出,而同一 tree 在外部環境可正常通過。目前 pre-flight 雖能保存
opaque evidence 並在內部辨識 timeout/stale/invalid,最後仍把所有非 PASS 合併成
一般 test FAIL/NO-GO;qa-tester 也把 non-runnable/flaky 一律視為 block。這會把
「沒有可用 authorization evidence」誤寫成「diff 已證明有 defect」,同時迫使使用者
為了避免 false block 先投入 runner 格式改造。

**Requirement**:

1. capability negotiation 必須是漸進式:
- command 未寫 structured sink 時,接受 portable opaque evidence;
- command 寫出 schema-valid result 時,提升為 structured evidence;
- command 有寫 sink 但內容 malformed/subject 不符時標 `invalid-evidence`,
不得靜默降級 opaque。
2. machine outcome 分開記錄 command execution、test verdict、evidence richness 與
authorization applicability。closed execution classification 至少涵蓋
`pass|test-fail|timeout|environment-error|stale|invalid-evidence|
unclassified-nonzero`;opaque 非零不得靠 log heuristic 自動宣稱 `test-fail`。
3. 只有 subject-valid structured assertion/test failure 可產生機械 test NO-GO。
`timeout|environment-error|unclassified-nonzero` 使 operation
`INCOMPLETE/non-authorizing`,保留 command digest、exit、timeout、log digest、
tree fingerprint與 recovery instructions,但不得冒充 diff-caused reviewer
blocker。Opaque PASS 只證明該 command 對該 subject exit 0,不宣稱 suite coverage
完整或可作 no-duplicate reuse。
4. qa-tester output 增加 `inconclusive` run result、failure class 與 evidence refs。
已有 outer pre-flight PASS 時不得反射性重跑 full suite,只能追加 scope-bounded
targeted checks;reviewer sandbox 的 timeout/environment failure回報
inconclusive,只有可歸因 assertion failure、diff-caused coverage gap或測試
anti-pattern 可 block。
5. qa-tester 在執行任何可能耗時的自主測試前,必須先寫入並 flush early
checkpoint,至少含已完成 matrix/audit、預定 command、開始時間、timeout budget、
evidence refs 與 `run.status: running`。測試必須經 bounded shell-owned wrapper
執行,持續保存 stdout/stderr log、process exit/timeout 與最後可觀察進度;
reviewer session被外層 watchdog終止時,gate仍機械產生
`partial/inconclusive` artifact,列出完成/未完成 sections、checkpoint與 log
pointer。不得只依賴模型在 command 返回後才首次寫檔,也不得讓 timeout留下
0-byte/無結果。
6. sequential combined session與parallel reviewer session都必須保留上述 qa
checkpoint/result;partial qa artifact不是有效 reviewer verdict,synthesis不得
將它補寫成 pass/block或納入正常 findings union,operation只能
`INCOMPLETE/non-authorizing`。若模型在 checkpoint 前違規直接執行長測試,wrapper
仍須留下 shell-owned attempt/log evidence並明示 `checkpoint: missing`。
7. 外部執行 evidence recovery 必須驗證同一 repository subject、HEAD/tree
fingerprint、command digest、suite identity與 artifact integrity;符合
[[CC-515]] freshness/applicability 才能取代 inconclusive。口頭/純 log PASS
可作 manual clue,不得單獨授權 GO。不得自動重跑或提高 timeout 掩蓋 performance
regression;重跑由使用者明示或 policy-bounded recovery 觸發並記錄 attempts。
8. human result 明確區分 `code/test NO-GO`、`gate INCOMPLETE` 與
`evidence unavailable`,提供可複製的 same-command/adjusted-timeout/external
evidence recovery 指令,不要求使用者先採用 structured producer。
9. deterministic fixtures 覆蓋:opaque PASS、opaque nonzero、structured PASS/
test-fail、sink missing、sink malformed、timeout、environment error、tree drift、
external evidence subject match/mismatch、qa targeted failure、timeout 前已寫
checkpoint、checkpoint 前違規執行仍有 shell log、sequential/parallel partial
preservation,以及不得把 inconclusive轉成 blocker或 GO。

**Done-when**: 任意 legacy `--test-cmd` 不需格式改造即可得到 truthful opaque
evidence;structured producer可獲得更強 reuse/coverage 語意;環境/timeout失敗會
fail closed 但不誤報產品 defect;qa-tester與 gate artifact對同一 execution class
給出一致、可恢復的結論;qa自主測試即使 timeout 也必有非空 checkpoint、attempt
metadata與 log pointer。

**Non-goals**: 不保證任意 command 可自動判斷失敗根因;不解析自由文字 log 作
authorization;不降低 current-tree test evidence要求;不讓 external PASS 省略
subject/digest驗證;不在本票建立通用 CI provider integration。

**Dependencies**: outcome/capability Phase A 複用 [[CC-470]]/[[CC-491]] 可先行;
external reusable evidence Phase B 依賴 [[CC-515]]。與 [[CC-521]] 的 test-gap/
protocol recovery contract保持正交。P1。

**Cross-link**: [[CC-470]]、[[CC-491]]、[[CC-512]]、[[CC-515]]、[[CC-521]]。

---

## CC-508 — 所有間接 dispatch 的 parent-operation control plane ✅ 2026-07-25

**Problem**: `pmctl gate run`、`pmctl ship --parallel`/adapter 路徑、`pmctl task dispatch` 與任何未來 producer 都可能以一個 parent operation 間接啟動一或多個 detached dispatch;但產品控制面主要只暴露個別 `pmctl dispatch cancel <run_id>`。parent ID 與其子 run 沒有強制、可查的 ownership relation,也沒有一致的 producer-level cancel surface。當任一 producer 卡住、選錯 executor 或需中止時,操作者無法透過 pmctl 取消整個 operation;直接對 supervisor PID 操作會繞過 run state、sentinel 與 cancel-vs-complete 單一終態契約,並可能留下無法判定的 stale operation。
Expand Down
3 changes: 2 additions & 1 deletion MILESTONES.md
Original file line number Diff line number Diff line change
Expand Up @@ -107,7 +107,7 @@

| 票 | 摘要 | 狀態 |
|----|------|------|
| CC-512 | Slice A coordinate sources/CLI resolution 已交付;machine-owned assurance envelopeevidence capture、verifier 仍待 B/C;targeted 不再是 tier | ⚠️ |
| CC-512 | Slices A/B/C:coordinate sources/CLI resolutionmachine-owned assurance envelopeevidence capture、shared verifier/parity ratchets;targeted 不再是 tier | ✅ pr:#451 |
| CC-513 | canonical resolver:minimum tier、required reviewers、recommended/required mode、generic vs maintainer policy 與 downgrade audit | 🔵 |
| CC-515 | immutable subject;artifact validity、subject freshness、policy applicability 三軸 shared verifier | 🔵 |

Expand All @@ -122,6 +122,7 @@
| CC-519 | selected-reviewer coverage/finding contract;sequential logical sections 與 parallel session isolation 分開 | 🔵 |
| CC-520 | synthesis findings-union parity、root-cause grouping、coverage matrix、remediation seed、no silent drop | 🔵 |
| CC-521 | actionable test-gap matrix + bounded protocol recovery;seeded live recall 僅作 quality evaluation | 🔵 |
| CC-522 | arbitrary `--test-cmd` opaque/structured negotiation;test failure 與 timeout/environment INCOMPLETE 分流 | 🔵 |

### Phase 9 — maintainer closure + publish authorization

Expand Down
15 changes: 13 additions & 2 deletions commands/pr-gate.md
Original file line number Diff line number Diff line change
Expand Up @@ -277,8 +277,19 @@ When the `pmctl gate wait` background Bash completion notification arrives:
brief failure summary: exit code + last ~20 lines of the supervisor log at
`pmctl artifacts show <gate_id> --cd "<work_dir>"`).
4. Read `result_file` directly (both executor routes write it in-process). To
re-confirm out of band, run `pmctl gate verify <result_file_path>` (the
literal path parsed in step 2, not a shell variable; exit 0 = valid).
re-confirm out of band, run `pmctl gate verify <result_file_path>` from the
repository the gate reviewed (use the literal path parsed in step 2, not a
shell variable; exit 0 = valid).
New results must report `assurance: verified` and point to a sibling
`gate_assurance_v2` JSON file. A legacy result or unbound v1 envelope may report
`assurance: unavailable`; do not treat that as proof of tier/mode/coverage
or reviewer-session independence. For repo-layout results that claim
verified independence, verification also requires the protected producer
attestation, a result under that repository's canonical state partition,
and matching canonical terminal run records. The producer publishes the
sidecar before the v2 result that references it; verification briefly
retries when it observes an in-flight v2 result before its protected
attestation rename completes.
5. Prepend `PR-gate complete.` to completion relay and include the full gate
result (including `Final: GO` / `Final: NO-GO`) unchanged.
6. On failure, avoid collapsing findings; relay the actual stderr summary and
Expand Down
10 changes: 6 additions & 4 deletions core/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,8 @@

This directory contains the canonical PM-runtime data contract. **`core/` is definitions only — it knows nothing executable.**

- `schema/` — JSON Schema files (`.schema.json`) for the 8 first-class
entities: Task, Run, Event, Review, Decision, Brief,
Handover, ContextPack.
- `schema/` — JSON Schema files (`.schema.json`) for runtime entities
and evidence envelopes, including gate assurance.
- `policy/` — declarative YAML/TSV tables for enums, presets, and state
machines.
- `state/` — definition of the on-disk state-store layout
Expand Down Expand Up @@ -38,4 +37,7 @@ The designated writer module in `runtime/lib/state-writer.sh` is the sole manage

## Schema versioning

Every payload schema includes `schema_version: { const: 1 }` as a required field. Future breaking changes bump the int; old payloads remain valid against the old schema version. `jq '.schema_version'` is the bash-readable discriminator. No `$id` URLs.
Every payload schema includes `schema_version` as a required integer `const`
field. Breaking changes bump that integer; old payloads remain valid against
the schema version that defines them. `jq '.schema_version'` is the
bash-readable discriminator. No `$id` URLs.
Loading