diff --git a/docs/product-technical-gap-live-refresh-2026-09-04.md b/docs/product-technical-gap-live-refresh-2026-09-04.md new file mode 100644 index 000000000..42cc2f5a5 --- /dev/null +++ b/docs/product-technical-gap-live-refresh-2026-09-04.md @@ -0,0 +1,69 @@ +# Product and technical gap live refresh — 2026-09-04 + +Status: **Non-authoritative live supplement** +Protected-product basis: `main@b5a3a0c1057d4b53d7a4bb18e0de69f630c2b45c` +Canonical historical baseline: `docs/product-technical-gap-baseline.md` +Latest immutable release: `v0.9.1` (published 2026-08-26) + +This supplement exists because the preceding refresh lane replaced the 1,036-line protected-main baseline with a 121-line live inventory. That rewrite removed valid PRD/TRD/UML, completion-profile, claim-register, standards/research, buyer-gate, release, accessibility and traceability material rather than refreshing it. The canonical baseline has therefore been restored byte-for-byte from protected `main`; current facts are carried here until a later reviewed consolidation can update the baseline without deleting valid evidence. + +A capability remains product authority only after integration into protected `main` and terminal applicable scientific, package, coverage, security, review, SBOM/provenance and release evidence on one unchanged exact head. Drafts, queued checks and predecessor approvals are evidence inputs only. + +## Current ownership and scientific boundary + +`fast-mlsirm` remains the canonical reusable psychometric numerical owner for LSIRM/MLSIRM/IRT/generalized-dependence kernels, true-parameter recovery and stable public bindings. Result-affecting likelihood, estimation, scoring, uncertainty, covariance/correlation, vector/linear/matrix and recovery arithmetic remain Rust/PyO3 owned. Python remains validation, provenance sealing, marshalling, orchestration, reporting and explicit reference/parity only. + +TEPP owns temporal/event semantics and composition. `contextual-orchestrator` owns provider/model routing and LLM orchestration. Foreign scientific/domain truth is consumed only through released/versioned contracts or explicit ACLs; no source copying, mutable sibling-head dependency or cross-service SQL is product authority. + +## Current high-leverage owner lanes + +| Gap | State | Exact owner evidence | Acceptance before product claim | +| --- | --- | --- | --- | +| Residual interaction-map public provenance | ACTIVE DRAFT | #1417 `f78f1a74c55ca770e106f1894c0d8fb92f3ea751` | Preserve Rust-owned Gabriel map arithmetic and versioned public envelope. The provenance digest must canonicalize every observed IEEE-754 NaN payload/sign variant, including quiet and signaling NaNs, to one missing-response byte identity in both Python and direct Rust while preserving exact finite binary64 evidence. Current-head hosted checks and independent review must be reacquired after RED `f2d0dd1d...` / `c65dd272...` → GREEN `ad9917f4...` / `6aeb9e8c...`; follow-up `2431666c...` / `f78f1a74...` closes the quiet-only edge-coverage gap without changing production arithmetic. | +| Validation-profile preregistration chronology | ACTIVE DRAFT | #1737 `6a0e43e10192895703cf18c5f50fdfb0fa73cc76` | Preserve exact UTC datetime admission after nested evidence replay. Caller-controlled chronology callbacks must fail closed. Exact-head required checks and independent approval must be reacquired after the RED→GREEN repair. | +| Generalized dependence / Model Specification | ACTIVE DRAFT | #1714 `619c9fa3daf37d59b96baf10e41b1f1df7813f6a` | Preserve supported/research-candidate/unsupported semantics; promotion still requires the exact primary citation, generative equation, identification contract, Rust estimator and formulation-specific recovery. | +| Machine-readable fit capability support | ACTIVE DRAFT | #1710 `41d2c5600db59c49999236b27c73b91b0359589a` | Canonical 1.0 support authority stays in package-owned sealed primitive rows. Returned `FitCapability` values are fresh, forged construction fails closed, and later mutation of live config-set aliases cannot redefine the already-imported versioned manifest/value-object contract. Current-head checks and an independent current-head approval must be reacquired after RED `7e937f65...` → GREEN `32021603...`. | +| Static covariance standardization | ACTIVE PR | #1722 `338dbb2d25f32b0e201102e7bf73076846fb57b3` | Rust numerical ownership, exact represented-input admission and scale/permutation invariance; TEPP may consume only a released immutable contract. | +| Mokken/AISP admission and decision controls | ACTIVE STACK | #1506 `cd46160c0a035fec2ded13fbacb11159f0d33ad4`; child #1724 `7764245d3d7618de08dc57e1434bb9b8e8c918ac` | Preserve package-owned response/result/control snapshots and Rust-owned H/Z/AISP arithmetic. Parent integrates first; child evidence is regenerated after ancestry movement. Embedded PR-body references to other predecessor SHAs are historical, not live head authority. | +| Multiple-membership/crossed recovery | ACTIVE PR | #1536 `77bef27cff780b909be484b52be35e97be752780` | Known-truth bias/MAE/RMSE, membership invariants, direct-Rust admission and worker determinism; no longitudinal or interval-coverage claim without its own evidence. | +| Rust distribution boundary + `sha2` 0.11 | ACTIVE PR | #1694 `756cf889a111717725de806329e8e5a64bbb5bc0` | Both internal Cargo implementation crates remain `publish = false`; Maturin/PyPI remains the external product unless a separate Rust SDK release boundary is governed. | +| Marginal objective binary64 reproducibility | ACTIVE DRAFT / SUCCESSOR | #1742 `959c05bf9e40877d65bd02aed82e6373ef16c99d`; retired #1746 `8f7262d14249269aef0589082b1afc78f221832e` | Preserve the deterministic CPU-f64 per-cell objective reduction until a profiled optimization has explicit numerical-contract, recovery and parity evidence. The retained tests prove two failure modes of rejected split reductions: an ordinary finite fixture moves by exactly one ULP, and the later algebraic `vdot(r, eta) + vdot(n, log_sigmoid(-eta))` route becomes `NaN` for finite saturated `eta=1e308`, `r=n=2` while the established reduction remains exactly `0.0`. #1746 is closed unmerged only after forward restoration to an empty effective diff and transfer of its valid stability finding here; formatter churn, temporary patch artifacts, duplicate Bolt guidance and unsupported speed claims are not product delta. Material hot-path work belongs in the Rust numerical owner. | +| Oblimax deterministic CPU-f64 reference semantics | ACTIVE DRAFT / STATIONARITY + RANGE + OPTIMIZER EVIDENCE | #1736 `fa54f33e36b4ea1087a0e6b453ec71e4680b490f`; issue #1747 | Initial RED `f1599d04...` / GREEN `e6235c78...` replace Oblimax `f64::powi`/`f64::ln`; RED `72be252b...` / GREEN `4401a9f9...` remove large-log cancellation by forming `(sum4 / sum2) / sum2` before the deterministic logarithm. RED `557789cd...` / GREEN `350c59fe...` condition exact `2^300`/`2^-300` scale-equivalent loadings before moment formation; `9ea947e6...` / `9b170fdd...` carry that contract through public oblique optimization. RED `720300d4...` / GREEN `72e5e6a9...` remove reciprocal-term cancellation at exact one-support stationary points. Current review then extended the stationary contract to the complete represented equal-magnitude support manifold: RED `5e78ac9d...` shows that accumulated `sum4/sum2` can round one ULP away from the common represented square for three equal supports, producing a false optimizer direction; causal GREEN `b00e91e4...` records exact bit-identical nonzero conditioned squares during the existing moment pass and reuses that represented square only on that exact manifold. `34e5e52e...` / `fa54f33e...` make changelog and doctoring current. These remain numerical-contract and integration fixtures, not VV-SCI-006 realistic recovery. Formula identity, bitwise route identity, psychometric recovery and supported-target parity remain distinct claims; current hosted gates are still non-terminal. | +| Strict JSON deserialization at judge/rubric boundaries | ACTIVE DRAFT / STACKED REPAIR | #1744 `6f80811036a22043755889e424667b579d5458ce`; prerequisite #1738 `c8ef8b0d2532393a77bfc5321a353d028b9bab18` | Reject Python non-finite constants at both boundaries and duplicate object members where protected main did not already reject them. Focused regression coverage is branch-owned. Security doctoring now distinguishes the pre-existing judge duplicate-key guard from the new rubric guard and removes unsupported impact claims. #1738 must integrate first; the non-force #1744 restack must preserve both guards, remove formatter-only drift, and add the missing production docstring for `_reject_nonfinite` before landing. | +| Item-bank report accessibility | ACTIVE DRAFT / SUCCESSOR | #1741 `c65543ee071cd19b1e1d0362f80c9f17cf230b9c`; retired predecessor #1743 | Preserve a focusable skip-link target, pointer-only focus suppression together with an explicit keyboard focus ring, reduced-motion behavior, semantic row headers and tabular numeric presentation. #1743 is closed only after its valid behavior and focused-test intent were inherited by #1741; formatter-only churn and competing `.Jules/palette.md` guidance are not product delta. | +| Iterator-fold performance rewrite | DISPOSITIONED / NO VALID DELTA | closed #1745 `f7d49c08eb0100860cd0ac2244deeb4794f4da2a`; rotation numerical-contract owner #1736 | The automated rewrite changed the rotation `powi(4)` arithmetic route without parity/recovery evidence and made an unsupported blanket fold recommendation. Person-fit iterator chains were lazy and supplied no reproducible benchmark proving material benefit. Forward repair restores every changed path to protected-main bytes; fresh main→head comparison has `files=[]`. Future optimization starts from profiling/benchmark evidence and preserves the deterministic CPU-f64/scientific contract. | +| Product/technical gap documentation | ACTIVE DRAFT | #1519 | Never trade live freshness for evidence deletion. The full protected baseline and the current live supplement must both survive until a reviewed consolidation proves no valid PRD/TRD/UML/research/release/buyer evidence is lost. | + +## Current merge and release gate + +Protected `main` is still `b5a3a0c1057d4b53d7a4bb18e0de69f630c2b45c`. It independently requires `Analyze (actions)`, `close-empty`, `scan-pr-queue`, `dependency-review`, `osv-scan`, `trivy-fs`, `scorecard`, `required-workflow-bootstrap`, `coverage-evidence`, `opencode-review`, `python`, `rust`, `package` and `fuzz` contexts. The latest observed central workflow owner is `.github/main@769691526f8c73cf714de8fe8ba51ae6cfa2901a`. + +Central `.github#1838` advanced the owner to `f0dd4065...` by consolidating Exact Artifact SBOM quality while preserving actual publication/attestation and removing a redundant quality workflow. Merged `.github#1819` then advanced `main` to `f8c3b304...` by recording Actions congestion and Noema/Strix hot-file divergence. Merged `.github#1839` advanced `main` to `80719692...` with a one-file Strix shell-output repair. Merged `.github#1842` then advanced authority to `07db37e5...`: generated repository-local CodeQL is kept off pull-request heads while protected default-branch push/schedule scanning remains, central `codeql-pr.yml` is retained as the single PR scanner, and ruleset-audit concurrency is isolated by trigger. Merged `.github#1845` advanced authority to `d6c636a9...` by admitting the exact live PR head before OpenCode/Noema review concurrency and cancelling stale review heads; push/schedule/release and Strix behavior are explicitly out of scope. Merged `.github#1847` advanced authority to `9c7d28a1...` by moving empty non-draft PR cleanup into the existing metadata-only merge scheduler, revalidating live head/open/draft/changed-file state before closure, and removing one standalone workflow/job. `109d79b7...` removed unsupported `queue: max` from central agent/coalescer workflows and moved exact-head admission ahead of per-PR concurrency. `df996797...` then added workflow-level concurrency to the hourly review scheduler so same-schedule pending heartbeats coalesce before `resolve-target` needs a runner. Merged `.github#1854` advanced authority to `34b79038...` by moving repository+PR concurrency for Strix, Required OpenCode Review and Required Noema Review to workflow admission, so queued superseded model runs can be cancelled before runner assignment; non-PR push/schedule runs retain run-id isolation. Merged `.github#1855` advanced authority to `4aad2690...` with runtime proof for that native cancellation contract: successive same-PR generations cancelled the preceding Strix/OpenCode/Noema runs while another PR and another repository remained isolated. Merged `.github#1856` then advanced authority to `f893b473...` by restoring `codeql-pr.yml` to the canonical required-workflow inventory and removing the stale scheduler exclusion that prevented exact-head CodeQL PR startup recovery. Its stated live acceptance is materialization of a non-startup-failure CodeQL PR run after the trusted-base/ruleset change. Current `.github#1851` advances authority to `76969152...` by installing the required HTTPX2 runtime and binding the exact OpenAI lock for Strix; that latest delta is Strix-runtime-specific and is not evidence that CodeQL/CI runner admission itself is healthy. These foreign-owner deltas are adopted rather than copied. + +The historical Actions defect remains relevant incident evidence rather than authority to churn clean leaf heads. On substantive #1710 head `41d2c560...`, CodeQL run `33827965206` materialized `Analyze (actions)` job `100884576993`, but it remained runnerless with `steps=[]`; CI `33827965233` remained pending with `jobs=[]`. This exact canary is recorded on central `.github#712` comment `5534619066`. Queued or absent execution is non-passing. + +The #1741 successor head `c65543ee...` independently reproduced the same pre-fix class: CodeQL run `33835387666` materialized `Analyze (actions)` job `100906727383` on `ubuntu-latest`, but it was queued with `runner_id=0`, no runner/group identity and `steps=[]`; its Python analysis was scope-skipped. CI run `33835387729` remained pending with `jobs=[]`. This remains incident evidence, not a reason to weaken or retrigger the leaf. + +The #1744 documentation-corrected head `6f808110...` also reproduced the pre-fix admission defect without a no-op retrigger: CodeQL run `33839177278` materialized required `Analyze (actions)` job `100917769805`, but it remained queued with no runner/group identity and `steps=[]`; Python analysis was scope-skipped. CI run `33839177204` remained pending with `jobs=[]`. This did not convert the still-open formatter/docstring/prerequisite findings into leaf GREEN. The matching #1519 canary was recorded with it on central `.github#712` comment `5535961011`. + +The #1742 successor head `959c05bf...` independently reproduced the same pre-fix class after a substantive numerical-contract test commit: CodeQL run `33851585887` materialized required `Analyze (actions)` job `100955381194`, but it remained queued with `runner_id=0`, empty runner/group identity and `steps=[]`; `Analyze (python)` was scope-skipped. CI run `33851585889` was pending with `jobs=[]`, while Semgrep `33851585663` and Security Scan `33851585771` were also queued. This exact canary followed a real stability regression, not a no-op retrigger, and predecessor success was not transferred. + +The #1417 provenance head `f78f1a74...` was a substantive test-evidence canary after the production NaN-canonicalization repair. CodeQL run `33849079557` materialized required `Analyze (actions)` job `100947516369`, but it remained queued before runner/source execution with empty runner/group identity and `steps=[]`; `Analyze (python)` was scope-skipped. CI run `33849079449` was pending; Semgrep `33849079438`, Security Scan `33849079593`, and ClusterFuzzLite `33849079522` were also non-terminal. The two newest branch commits close an edge-coverage gap by proving positive/negative signaling NaNs share the same missing-response digest as quiet NaNs in both public Python and direct Rust; no production arithmetic changed. Predecessor `3cdc684a...` had repository CI, CodeQL, Semgrep, Security Scan, OSV, Scorecard and fuzzing terminal green, but that predecessor evidence is deliberately not transferred. + +The pre-central-fix #1736 head `88573ea9...` included the scale-cancellation repair after the deterministic-log route was introduced. CodeQL run `33864345780` materialized required `Analyze (actions)` job `100995661527`, but it remained queued before runner/source execution with `steps=[]`; `Analyze (python)` was scope-skipped. CI `33864345169` was pending, while Semgrep `33864344772`, Security Scan `33864345094`, and ClusterFuzzLite `33864344857` were queued. RED `72be252b...` is source-level evidence only because its causal successor immediately superseded it; no predecessor or superseded-head success is transferred. + +The predecessor #1736 head `274362b...` was the first post-central-`109d79b7...` numerical/documentation canary. CodeQL run `33866642621` materialized `Analyze (actions)` job `101002902427` but remained queued; `Analyze (python)` was scope-skipped. CI run `33866642682` remained pending with `jobs=[]`; Security Scan `33866642666`, Semgrep `33866642629`, and ClusterFuzzLite `33866642593` were queued. That evidence is historical after later optimizer-contract commits and is not transferred. + +The predecessor #1736 head `9b170fdd...` added the optimizer integration contract. CodeQL run `33868864092` materialized required `Analyze (actions)` job `101009864493`, but it remained queued with `runner_id=0`, empty runner/group identity and `steps=[]`; `Analyze (python)` was scope-skipped. CI run `33868863936` remained pending with `jobs=[]`; Semgrep `33868864094`, Security Scan `33868864018`, and ClusterFuzzLite `33868864057` were queued. That head is historical after current doctoring moved and its status is not transferred. + +The predecessor #1736 head `4f26d996...` completed the range/optimizer doctoring boundary before the stationary-gradient repair. CodeQL run `33869375346` materialized required `Analyze (actions)` job `101011473756`, queued without runner/group identity and with `steps=[]`; `Analyze (python)` was scope-skipped. CI run `33869375312` was pending with `jobs=[]`; Security Scan `33869375370`, Semgrep `33869375345`, and ClusterFuzzLite `33869375319` were non-terminal. That head is historical and its status is not transferred. + +The current #1736 head `fa54f33e...` is a substantive Rust numerical-contract canary after the equal-magnitude stationary-manifold RED→GREEN repair and was created after central `.github#1856` merged. CodeQL PR run `33874447012` now materializes `Detect CodeQL languages` job `101027933479`, which establishes that the #1856 startup/materialization repair reached this leaf event; however that job remains queued with `runner_id=0`, empty runner/group identity and `steps=[]`. The separate CodeQL run `33874447020` materializes required `Analyze (actions)` job `101027928022`, likewise queued runnerless with `steps=[]`, while `Analyze (python)` is scope-skipped. CI `33874446901`, Security Scan `33874447009`, Semgrep `33874446941`, and ClusterFuzzLite `33874447002` remain non-terminal. Thus startup materialization improved, but this exact head is still not hosted GREEN and no predecessor evidence is transferred. + +The #1519 documentation lane has repeatedly reproduced the same queue/admission class on substantive additive-document heads. Its exact current head and current-head workflow evidence are maintained in the PR landing authority rather than self-referentially embedding the file's own future commit SHA here. Central owner issue `.github#712` remains the causal Actions/RCA path; documentation movement is not used as a retrigger mechanism. + +The only observed #1710 `APPROVED` review remains bound to predecessor `e50033e00dc392d532a4fa941ce390c8ef4e8dbe`, so it does not authorize landing the current `41d2c560...` head. Therefore no current open PR is landed merely because repository-owned source tests or predecessor checks were green. Self-approval, administrator bypass, force update, no-op retrigger and predecessor-evidence transfer remain prohibited. + +## Non-destructive refresh rule + +Future baseline refreshes must be additive or surgically replacement-scoped. Before any update, compare line count and semantic sections against protected main. A refresh that removes valid completion profiles, PRD/TRD/UML, standards/research traceability, claim limitations, release gates or buyer acceptance evidence is a repair finding, not successful maintenance. The correct response is forward restoration or verified supersession, never silent truncation. \ No newline at end of file diff --git a/docs/product-technical-gap-live-refresh-2026-09-05.md b/docs/product-technical-gap-live-refresh-2026-09-05.md new file mode 100644 index 000000000..b4c276081 --- /dev/null +++ b/docs/product-technical-gap-live-refresh-2026-09-05.md @@ -0,0 +1,40 @@ +# Product and technical gap live refresh — 2026-09-05 + +Status: **Non-authoritative live supplement** +Protected-product basis: `main@493326f2de49ea1704da0ded19868ed05d2fe00f` +Canonical historical baseline: `docs/product-technical-gap-baseline.md` +Previous additive supplement: `docs/product-technical-gap-live-refresh-2026-09-04.md` +Latest immutable release: `v0.9.1` + +This file updates live evidence that moved after the 2026-09-04 supplement. The protected 1,036-line baseline and preceding supplement remain preserved. Draft/Ready branches are evidence, not shipped product authority; a capability becomes product authority only after protected integration and the applicable scientific, package, coverage, security, review, SBOM/provenance and release gates are terminal on one unchanged exact head. + +## Ownership boundary + +`fast-mlsirm` remains the canonical reusable psychometric numerical owner for LSIRM/MLSIRM/IRT/generalized-dependence kernels, true-parameter recovery and stable public bindings. Result-affecting likelihood, estimation, scoring, uncertainty, covariance/correlation, vector/linear/matrix and recovery arithmetic remain Rust/PyO3 owned. Python remains validation, provenance sealing, marshalling, reporting and explicit reference/parity evidence. + +TEPP owns temporal/event semantics and composition. `contextual-orchestrator` owns provider/model routing and LLM orchestration. Foreign domain truth is consumed only through released/versioned contracts or explicit ACLs; source copying, mutable sibling-head dependencies and cross-service SQL are not product authority. + +## Exact live owner lanes + +| Gap | Exact owner state | Remaining acceptance | +| --- | --- | --- | +| Protected GPU merge gate + repository PR lifecycle | #1717 Ready `fbe1262050bf00e6bd71b6709fca81902ae21a52` | Reconciliation preserves explicit Ubuntu 24.04 identity and the protected `python -> [python-matrix, gpu-smoke]` dependency while retaining #1749 lifecycle/concurrency semantics. Current-head hosted execution and independent approval remain required; queue pressure is not a reason to weaken the GPU or other protected gates. | +| ClusterFuzzLite inactive-PR cancellation | #1754 Ready `2ecfea90cbc4eb35a2b2eedeb262cd83ead24efe` | Original `f9f93607...` incorrectly removed `converted_to_draft`/`closed`; concurrent forward `9e288c92...` restored them, removed competing `ci.yml` ownership and kept ClusterFuzzLite concurrency at workflow admission. Current `2ecfea90...` pins the exact lifecycle event set. On this unchanged head the Draft-state CI run `33943673921` reached cancelled; marking the repaired PR Ready then created CI `33944125746` and ClusterFuzzLite `33944125764`, both still non-terminal. Earlier predecessor cancellation/skip evidence remains historical and is not current GREEN. | +| Local-dependence stable public API | #1748 Ready `013e1d8995d751d03922dc733ae3ed717a512519` | Existing Chen–Thissen X2/G2 arithmetic remains Rust-owned. Python seals public controls/results while the public Rust boundary now owns versioned `ld-resource-v1` work ceilings before ICC-node or pair allocation. Xi cardinality is single-owned by `nodes::xi_node_count`; direct-Rust evidence covers Halton/Monte Carlo support and MIRT Xi non-use. CI `33938505419`, ClusterFuzzLite `33938505459`, Security `33938505478`, CodeQL `33938505443`, CodeQL PR `33938505402` and Semgrep `33938505373` remain non-terminal; no qualifying current-head approval exists. | +| Factor-retention governed result invariants | #1479 Ready `48ec1d357aca76cada2720c2f7918ac30baa5f3b` | Effective delta remains four factor-retention owner paths after non-force merge-forward to current protected main. Public result construction replays method/count/evidence/decision invariants rather than trusting forgeable frozen records. Exact-current hosted gates and independent approval remain required; predecessor GREEN is historical only. | +| Marginal reduction reproducibility | #1742 Ready `dbb6a9bf74e940280fc5b0c247469b7850534709` | Test-only successor preserves ordinary one-ULP objective drift, finite-to-NaN saturated-logit drift, and one-ULP row-distance drift from rejected reassociations. Production marginal arithmetic remains protected-main behavior. Ready-event CI `33935708280` is not terminal; future optimization requires profiling plus deterministic CPU-f64 and realistic recovery/parity evidence and should prefer the Rust numerical owner. | +| Person-fit scalar loop-fusion optimization | #1752 Draft `ca9d1b717ae8052a66041af928ef68d46173fbf5` | The one-pass ZU3 scalar fold is only a performance hypothesis. Focused correctness tests do not prove cache behavior, material speedup or release-codegen binary64 parity. `ca9d1b71...` has the same source tree `623b1eee991e4f8a495b11a9e95d00d31d7a0092` as predecessor `6a9182c5...`, so it adds no benchmark/test delta and is retained only because destructive history rewrite is prohibited. Ready requires a repository-controlled same-profile benchmark with dispersion/uncertainty plus exact `f64::to_bits()` parity on adversarial finite fixtures; without reproducible material benefit, restore protected-main implementation. | +| Oblimax deterministic CPU-f64 reference | #1736 Draft `44806471463dda11ed251c4e43c3f9e9e0f7293a`; issue #1747 | Deterministic log/power routing, ratio-before-log cancellation repair, exact power-of-two range conditioning, public optimizer scale contract and represented stationary-manifold fixes are numerical evidence. Scientific completion still requires supported-target bit parity and VV-SCI-006 realistic known-population recovery with global sign/permutation alignment, Tucker congruence, loading/target RMSE where identified, uncertainty/stability, basin support and degeneracy diagnostics. | +| v0.9.2 immutable release | #1471 Draft `d6edc8ea83d8bd0b0840786ca4e8974623560b1f` | Current-main ancestry and Draft provenance are repaired, but release serialization remains RED. `CHANGELOG.md` still contains the superseded managed Unreleased block and historical `[0.9.2] - 2026-08-27`, while authoritative fragments include later protected-main evidence. The exact tag target must atomically recut the managed block and release section, preserve the historical 17 folded deltas, assign the real release date only at cut time, then reacquire version/lock/test/security/package/SBOM/provenance/reproducibility/rollback/review evidence. | +| Item-bank evidence-reference provenance child | #1476 Draft `f3c66f0e9f7788e0e20e4f3ef4cbbe5f110fa811`, stacked on #1471 | Its three provenance/error-boundary files remain valid, but parent #1471 is still source-RED. Integrate/reconcile the release parent first, then non-force restack the child and reacquire exact-current hosted evidence. | +| Product/technical gap evidence preservation | #1519 single writer | Preserve the protected historical baseline plus dated additive supplements. Do not replace evidence-rich PRD/TRD/UML/research/release/buyer/accessibility/traceability history with a short inventory. Consolidation is allowed only after a reviewed diff proves no valid evidence is lost. | + +## Current merge and workflow authority + +Protected `main@493326f2de49ea1704da0ded19868ed05d2fe00f` still requires `Analyze (actions)`, `close-empty`, `scan-pr-queue`, `dependency-review`, `osv-scan`, `trivy-fs`, `scorecard`, `required-workflow-bootstrap`, `coverage-evidence`, `opencode-review`, `python`, `rust`, `package` and `fuzz` contexts. + +Central workflow authority is `.github/main@8a15cde08116d6a1d9c3ab4ec70f9db56ab2b56c` (#1887). Parent #1886 pins the remaining named residual workflows to explicit Ubuntu 24.04 but leaves the dominant organization-wide queue congestion unexplained. Parent #1888 separates CodeQL native-dispatch concurrency by `required_language`, preventing same-PR language shards from cancelling one another. Current #1887 hardens current-head run coalescing: an accepted cancellation request is not reported as complete until GitHub is polled to terminal `completed/cancelled`; unproven cancellation fails closed instead of being counted as reclaimed queue work. These are central workflow-owner repairs only; they do not retroactively make existing leaf runs GREEN, repair unrelated Actions acquisition congestion, or authorize protected-gate weakening. + +## Release/scientific claim rule + +No Draft or Ready branch above is a shipped capability. Source-level RED/GREEN lineage, lifecycle canaries, queued workflow creation, resolved review threads and predecessor success are evidence inputs, not substitutes for unchanged-current-head terminal hosted success. Scientific/release claims additionally require their stated recovery/parity/provenance gates and a qualifying independent current-head approval. No self-approval, bypass, force update, destructive rebase, gate weakening, skip/xfail success accounting, no-op source churn or predecessor-success transfer is authorized. diff --git a/docs/product-technical-gap-live-refresh-2026-09-07.md b/docs/product-technical-gap-live-refresh-2026-09-07.md new file mode 100644 index 000000000..b5229f7d4 --- /dev/null +++ b/docs/product-technical-gap-live-refresh-2026-09-07.md @@ -0,0 +1,81 @@ +# Product and technical gap live refresh — 2026-09-07 + +Status: **Non-authoritative point-in-time supplement** +Observed at: **2026-09-06T22:23:00Z** +Protected-product basis: **`main@493326f2de49ea1704da0ded19868ed05d2fe00f`** +Canonical historical baseline: **`docs/product-technical-gap-baseline.md`** +Previous additive supplement: **`docs/product-technical-gap-live-refresh-2026-09-05.md`** +Latest immutable release: **`v0.9.1`**, published 2026-08-26 + +This supplement records only evidence that changed after the preceding snapshot. +It does not replace the PRD, TRD, architecture, ADR, UML/ERD, Context Map, +requirements traceability, scientific evidence, or the protected historical +baseline. Open branches and their checks remain evidence, not shipped product +authority. Every merge or release decision must re-fetch the exact head, live +base, review threads, required checks, ruleset result, and active writer. + +## Authority and ownership continuity + +- Product scope and acceptance authority remain `docs/PRD.md` and + `docs/TRD.md`. +- The repository boundary and Context Map remain `ARCHITECTURE.md` and the + status-bearing ADR graph under `docs/adr/`. +- UML/ERD and requirements authority remain the linked document families in + the protected baseline; this supplement creates no competing model. +- `fast-mlsirm` owns reusable, domain-neutral IRT/LSIRM/MLSIRM mathematical and + Psychometrics kernels, true-parameter recovery, stable bindings, and release + evidence. Result-affecting covariance, correlation, vector, linear, matrix, + likelihood, estimation, scoring, uncertainty, and recovery arithmetic remain + Rust/PyO3 owned. +- `ContextualWisdomLab/.github` owns reusable CI, review, security, and release + orchestration. A leaf repository does not copy or bypass an immature central + workflow; it waits behind the released contract or uses a bounded test double. + +## Fresh inventory + +GitHub search returned **64 open pull requests** and **201 open issues** for +`ContextualWisdomLab/fast-mlsirm` at the observation time. These counts are a +denominator for this snapshot, not a live invariant. Protected `main` and the +latest immutable release have not moved since the 2026-09-05 supplement. + +## Buyer-visible gap and action status + +| Gap / bounded context | Exact evidence | Action | Status | +| --- | --- | --- | --- | +| Central scheduler REST workflow identity | `ContextualWisdomLab/.github#1986` exact head `4604909a9b68cb29cda431d71bc0ed3d37f11af3`, protected base `c9052e607e5f3cc76e73207e7786b21500721b79`, two changed files | Preserve per-workflow parallelism while coalescing concurrent reads for one `(repository, workflow_id)`; treat a deleted workflow's HTTP 404 as an absent static identity while propagating other failures | **Ready, auto-merge armed behind protection.** RED reproduced 11 duplicate reads and 404 propagation. GREEN: 21 focused tests; scheduler aggregate 349 passed; repository 2,990 passed / 1 skipped / 21 subtests; coverage and public-doc checks 100%. Hosted exact-head security/review checks remain non-terminal and no current-head approval exists. | +| Actions queue measurement and workflow-waste evidence boundary | `ContextualWisdomLab/.github#1905` exact head `fcdb8dfe6951704cce688ec2e3756837b04bd71c`, two-parent reconciled on current #1903 `f4ff7f8c025c4d0a15145c3cd634d96c92326ec3`, one ledger path | Preserve the 35-workflow static observations while distinguishing a modeled admission ceiling from observed concurrent occupancy and a measured lower bound; continue capacity investigation and required-context-preserving graph repair in parallel | **Ready stacked evidence, not protected authority.** Current #1903 is an ancestor (`behind_by=0`); the contradicted global conclusions remain removed or bounded, and the residual literal `job\\namong` formatting defect is repaired. Exact-head baseline contracts are 5 passed and diff check is clean. Ready review admission was restored on the unchanged head at `2026-09-07T03:16:43Z`; CodeQL PR `34079111710`, Semgrep `34079111737`, and Security `34079111714` are queued. The predecessor-head CHANGES_REQUESTED review does not transfer; independent current-head review and ordinary stacked integration remain pending. | +| Review and CodeQL dispatch identity | `ContextualWisdomLab/.github#1929`; actor canary run `34069437294`; earlier cross-repository status failures `34017996201` and `34018021069` | Preserve actor=sender=one reviewed identity; prove a same-repository terminal canary and repair the separate cross-repository status credential without widening trust | **Actor admission repaired; issue remains open.** Live configuration now admits both `github-actions[bot]` and `opencode-agent[bot]`, and the canary passed actor validation before a later live-head mismatch. No same-repository terminal receipt is yet proven, while the cross-repository publication path still has HTTP 403 evidence. | +| CodeQL rerun recovery, live-base binding, terminal receipt, and SARIF evidence boundary | `ContextualWisdomLab/.github#1902` exact head `4b025af481f3a4fb0bdb4d400a7e055066a496a2`, tree `f0fa29d998727d9c8720cf2921611ff463667377`, nine CodeQL-owned paths | Require a trusted creator plus exact base/head/language/workflow/run receipt before consuming terminal status; ignore old-base status and redispatch once as `verdict=pending`; validate live/event base; require the same shard's SARIF upload outcome to be `success` before terminal publication or wake | **Ready for review admission; not merge-authorized.** A new CodeRabbit CWE-345 finding was reproduced and repaired. The requested old-base-only fixture proves pending redispatch; CodeRabbit confirmed the finding addressed and the sole thread is resolved. Exact-tree verification: 57 focused tests normally and 57 with `GITHUB_ACTIONS=true`; repository 3,005 passed / 1 skipped / 21 subtests; statement/branch coverage and public-doc coverage 100%; diff check clean. Local actionlint was unavailable, so predecessor evidence is not transferred. The Ready event admitted replacement runs `34077606247`, `34077606217`, `34077606226`, and `34077606207`, all queued/pending. Hosted GREEN and qualifying independent approval remain merge gates, not Ready prerequisites. No auto-merge action was taken. | +| Scheduler live-PR, Strix rerun identity, and lifecycle evidence preservation | `ContextualWisdomLab/.github#1999` exact head `64d19495095f42c292675dac9d7b73e8a6316d58`, tree `212153594cf4d90a9efb2e14526f408aa7634210`, stacked on `.github#1938@056226c56eff8c1aa01d29722f14c9820b97438d`, twelve scheduler/Strix/workflow-contract/doctoring paths | Require an explicitly open live PR, bind reruns to the verified failed Strix job, preserve executing same-head evidence across Draft/Ready/dispatch, wait for stale-run cleanup before launching the replacement provider, query/cancel central workflow runs at the run-owning repository while reading live PR state from the target repository, and retain protected-ref push coalescing with cancellation authority only for a newer push | **Ready for review admission; no auto-merge authorization.** Exact-head review found that the replacement provider could start before cleanup and that cleanup omitted stale `repository_dispatch` runs. RED reproduced both defects and the cross-repository ownership mismatch. GREEN is six focused lifecycle/cleanup tests, the focused Strix shell contract, repository 3,045 passed / 1 skipped / 21 subtests, statement/branch coverage 100% (`13,251` statements and `5,362` branches, zero miss/partial), and public-doc coverage 100%; `bash -n` and diff check are clean. The repair covers native and dispatched runs, separates target-repository PR reads from central run queries/cancellations, and gates provider start on cleanup success or skip. The stack is behind 0 and mergeable with zero unresolved threads; Ready was restored at `2026-09-07T05:39:30Z` only for review admission. Ready-event Security `34087645347`, CodeQL PR `34087645423`, and Semgrep `34087645342` are queued; the earlier push runs, including Semgrep `34087573459`, were cancelled after the Ready event, and none is promoted to GREEN. Local actionlint was unavailable; hosted workflow validation and qualifying independent review remain merge gates. | +| Immutable release SBOM and provenance | `fast-mlsirm#1692` exact head `a6ac0f49d5123244fe89f26748a65f551ad9d514`, protected base `493326f2de49ea1704da0ded19868ed05d2fe00f`, 12 changed files | Restore an authenticated current-head CodeQL dispatch verdict at the central owner, obtain a qualifying approval on the unchanged current head, then ordinary merge and release verification | **Source-ready, control-plane blocked.** Repository CI, native CodeQL, Security Scan, Semgrep, mergeability, and all review threads are GREEN/resolved. `CodeQL PR` run `34020936743` fails closed because a rerun has no authenticated terminal verdict; predecessor approval does not transfer. | +| Rust-owned local-dependence public API | `fast-mlsirm#1748` exact head `ef2dd4baa11027c43fccc448a8eb07e4dca6e104`, protected base `493326f2de49ea1704da0ded19868ed05d2fe00f`, 14 changed files | Re-fetch current-head scientific recovery, public-contract, coverage, security, and independent-review evidence before merge | **Ready and mergeable; not yet revalidated in this supplement.** The prior supplement's older head and checks are historical only. | +| Rust covariance-standardization stack | `fast-mlsirm#1722` exact head `28b0305595107fd0ba21d7b27c1ac5db68ae8bf1`, direct protected base `main@493326f2de49ea1704da0ded19868ed05d2fe00f`, five changed files | Preserve the Rust production owner and reacquire exact-head numerical recovery, formatting, security, CodeQL, and independent-review evidence before ordinary integration | **Non-force reconciled, behind 0, partially GREEN.** The prior `b5a3a0c1` value was an older protected-main SHA, not a live stacked base. Current `main` was merged normally and a changelog fragment was added. Native CodeQL `34076849581` and CI `34076849582` are terminal success; Semgrep `34076849554`, CodeQL PR `34076849542`, ClusterFuzzLite `34076849579`, and Security `34076849578` remain queued. The local environment has no Cargo, so no separate local Rust test or formatting GREEN is claimed; predecessor evidence and approval do not transfer. | +| Product/technical gap evidence | `fast-mlsirm#1519`, draft single-writer branch `docs/refresh-product-gap-baseline-20260828` | Preserve the historical baseline and dated supplements; consolidate only after a reviewed proof that no PRD/TRD/UML/ERD/Context Map/scientific/release evidence is lost | **Active single writer.** This file is an additive delta on that branch, not a competing baseline writer. | + +## Release and claim boundary + +`v0.9.1` remains the latest immutable release. Neither a mergeable PR, a local +GREEN suite, queued hosted work, a resolved thread, nor an approval on an older +head is a release or GA claim. Technical GA still requires a bounded support +matrix, unchanged-head scientific recovery and cross-engine evidence where +applicable, stable API/artifact migration and rollback contracts, package/SBOM/ +provenance evidence, security and operability gates, and ordinary protected +integration. Domain validation, high-stakes use, hosted identity, consent, +persistence, human decision policy, and buyer workflow validation remain owned +by the consuming product. + +## Next safe sequence + +1. Prove a same-repository terminal dispatch receipt under the repaired actor + setting tracked by `.github#1929`, then repair and prove the separate + cross-repository HTTP 403 status path without weakening actor=sender. +2. Let `.github#1902@4b025af4` and stacked `.github#1999@64d19495` acquire exact-head + hosted checks and independent review; neither Ready transition is approval or + merge authority, and no auto-merge change is recorded here. +3. Revalidate `fast-mlsirm#1692` on its unchanged head after the owner repair, + merge ordinarily, and + produce immutable release evidence before changing the released-version + claim. +4. Revalidate `fast-mlsirm#1722@28b03055` on its direct protected-main base, + including Cargo/Rust formatting and numerical recovery evidence, before + continuing the Rust numerical stack in dependency order.