Skip to content

docs: record the 2026-09-02 product-goal-directive revisions (2nd + 3rd) - #1692

Open
seonghobae wants to merge 11 commits into
mainfrom
docs/product-goal-directive-2026-09-02-revision
Open

docs: record the 2026-09-02 product-goal-directive revisions (2nd + 3rd)#1692
seonghobae wants to merge 11 commits into
mainfrom
docs/product-goal-directive-2026-09-02-revision

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Current purpose — 2026-09-02

This PR is the single writer for the standing docs/product-goal-directive.md revision, its doctoring record, and the directly conflicting docs/CWL-MASTER-CONTEXT.md architecture boundary. It carries CWL DEVELOPMENT PHILOSOPHY v2026-09-02B without creating a competing directive copy.

Current exact head: e7c5eec969a4a063769f53c89e130f62d18bef6a on docs/product-goal-directive-2026-09-02-revision.

Current-main reconciliation

Protected .github main is 78271917b526469c559fa75cb5ee39426e5494d1. The writer is now non-destructively reconciled with that exact protected head (behind_by=0). A first reconciliation accidentally reused the stale branch tree and temporarily widened the PR to 26 files; that defect was immediately repaired by rebuilding the tree from protected main and overlaying only owner-path blobs. No force push, destructive rebase, branch reset, or concurrent protected-main delta deletion was used.

The current effective delta is exactly four files:

  1. docs/product-goal-directive.md
  2. docs/doctoring/product-goal-directive.md
  3. docs/CWL-MASTER-CONTEXT.md
  4. tests/test_product_technical_gap_baseline.py

Quarantine ownership RCA and contract

The product directive already identified quarantine-sandbox-runtime as the isolation owner, while the master context still contained residual claims that Noema owned plugin quarantine and was the shared quarantine runtime. Direct owner evidence already recorded in this PR establishes the opposite boundary: Noema is the GitHub Actions OIDC short-lived repository-capability / exact-revision evidence control plane; quarantine-sandbox-runtime owns untrusted artifact/code isolation.

A genuine RED regression commit 7deae853bbb7697dab79c235b21340ba03f5f7ea, based on pre-fix source 61104eabac120e3751b1daec399538ff0d689fb9, rejects the two residual Noema-quarantine phrases and requires both the canonical Noema responsibility and UML edges. The production source repair is 575f5a0c71048e837b62d64de92ec9dedd56e9be; merge successor e7c5eec969a4a063769f53c89e130f62d18bef6a integrates RED + repair without force. Exact-head source inspection confirms the forbidden current-role phrases are absent and the canonical owner markers are present.

Admission state

All existing review threads are resolved on the current diff. Fresh exact-head Python Security, Secret Scan, Scorecard, OSV, Semgrep, CodeQL, Security Scan, and SBOM runs have been regenerated and are queued/pending; predecessor results do not transfer. This governance PR remains Proposed / not merge-ready until exact-current-head required evidence is terminal and any new substantive finding is repaired. Do not administrator-bypass it solely because the central Actions fleet is saturated.

The owner reissued the full nine-section autonomous PR/merge/development
loop directive with substantially expanded text (core/consumer boundary
policy in §2, i18n and Keyverse-scoping detail in §4, ontology-ownership
split and broadened identifier-naming rule in §5, an explicit
orchestrator/free pin folded into §8, and a full named core-repo table
with a core-vs-domain-product classification in §9).

Recorded verbatim per this file's own conflict policy. Verified all 29
repos named in §5/§9 exist under ContextualWisdomLab with exact-matching
case, and reconciled the new §5 identifier-naming rule against
CWL-MASTER-CONTEXT.md §7's DB-object grandfather clause (still binding,
now with an explicit note that the broader rule applies going forward on
touched/new code, not as a mandate to force-rename existing identifiers
ecosystem-wide). Flagged, but did not resolve, an open tension between
§9's quarantine-sandbox-runtime repo and CWL-MASTER-CONTEXT.md §3's
description of noema owning the sandbox — needs each repo's own docs
read before deciding, not guessed.

Nine-section transcription independently verified byte-for-byte against
the source text by a separate review pass before this commit.

See docs/doctoring/product-goal-directive.md for the full reconciliation
record.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016ErwZSYW3pm585NiM3Q7aN
@coderabbitai

coderabbitai Bot commented Sep 2, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 16 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Team

Run ID: c8014c3c-feba-41d0-87d6-9b8467fa0c5a

📥 Commits

Reviewing files that changed from the base of the PR and between 8c08583 and c12d594.

📒 Files selected for processing (4)
  • docs/CWL-MASTER-CONTEXT.md
  • docs/doctoring/product-goal-directive.md
  • docs/product-goal-directive.md
  • tests/test_product_technical_gap_baseline.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae added documentation Improvements or additions to documentation priority: high High-priority or P1 work status: draft Draft pull request type: docs Documentation, ADR, PRD, or technical writing labels Sep 2, 2026 — with ChatGPT Codex Connector
The owner issued one further refinement of the directive after the second
revision (already on this branch/PR): §1 clarifies "0 open PRs" must come
from merges or full successor-absorption, never a bare close; §2 gains a
substantial repair-vs-close PR-lifecycle policy; §4 drops the named-framework
shortlist for framework-agnostic criteria; §5 moves its per-repo ontology
breakdown into §9; §8 spells out exactly how the orchestrator/free pin must
be implemented at the workflow layer; §9 adds a definition of what "core
foundation" means and reorganizes the repo table into five categories with
concrete interim-boundary mechanisms.

Continuing the existing branch/PR per the directive's own "edit this file in
place, do not fork a second copy" policy, applied to the PR level too, since
#1692 was still open when this third revision arrived.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016ErwZSYW3pm585NiM3Q7aN
@seonghobae seonghobae changed the title docs: record the 2026-09-02 product-goal-directive revision docs: record the 2026-09-02 product-goal-directive revisions (2nd + 3rd) Sep 2, 2026
devin-ai-integration[bot]

This comment was marked as resolved.

Three confirmed findings from Devin Review's pass on PR #1692, fixed in
place:

- docs/product-goal-directive.md §5's rename-reconciliation note told an
  agent to "pause and confirm" before a contract-breaking rename, which
  directly contradicts docs/CWL-MASTER-CONTEXT.md §7's binding "Do NOT ask
  the user to decide" full-autonomy convention. Replaced with an
  autonomous, contract-safe process (preserve the published boundary,
  prepare a versioned migration plan, record an ADR) instead of asking.

- The repo-count arithmetic in docs/product-goal-directive.md §9 and its
  doctoring record was wrong: §9 actually lists 23 core repos (not 21),
  and the four ontology repos named in §5 are a named subset of those 23,
  not an additional group — so the correct total is 23 + 7 domain-consumer
  repos = 30 unique names, not 29. Fixed both files' counts and the
  double-counting framing.

- The §9 "sandbox ownership" reconciliation item was left flagged as open
  rather than resolved. Read quarantine-sandbox-runtime's and noema's
  actual current READMEs (plus noema's own sandbox-planning doc, which
  states the review agent runs in "a separate quarantined execution
  plane" and must not run untrusted code in the Noema Worker process):
  quarantine-sandbox-runtime is the current AI-SOC sandbox owner, not
  noema. Updated docs/CWL-MASTER-CONTEXT.md at all four locations that
  said "noema quarantine sandbox" (§3, §6 header, the P1 roadmap bullet,
  and the ecosystem UML diagram's node/edge) to name
  quarantine-sandbox-runtime instead, and marked the directive's
  reconciliation note resolved.

docs/doctoring/product-goal-directive.md records the full reasoning for
all six Devin findings (three fixed, one requiring cross-repo evidence,
two informational/no-action) per this file's existing pattern from the
original PR #1429 Devin Review pass.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016ErwZSYW3pm585NiM3Q7aN
…ring section

Devin Review caught a residual inconsistency the previous fix missed: the
doctoring file's third-revision section ("What changed in the directive
text" and its own "Verification performed this revision") repeated the
same stale "21 core repos" figure twice, independently of the
second-revision section already corrected to 23. Fixes both remaining
occurrences.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016ErwZSYW3pm585NiM3Q7aN

Copy link
Copy Markdown
Contributor Author

Fresh owner-stack reconciliation before write: protected main is now 78271917b526469c559fa75cb5ee39426e5494d1. Exact head 53e85f0e0fe7db8714f23a119892b57a7295514f is content-diverged only on the three intended governance-owner paths (docs/CWL-MASTER-CONTEXT.md, docs/product-goal-directive.md, docs/doctoring/product-goal-directive.md) even though ancestry is behind_by=14. Importantly, this exact delta contains the source-of-truth repair for the Noema/quarantine ownership contradiction: quarantine-sandbox-runtime owns untrusted artifact/code isolation; Noema no longer claims the quarantine sandbox.

I will preserve the exact head tree and both histories with a non-force two-parent reconciliation against current protected main. This is ancestry repair only; it does not promote a Proposed/open owner contract to protected authority, transfer old Checks, or discard concurrent main intent. A fast-forward ref update will be attempted only if the branch head is still exactly 53e85f0e0fe7db8714f23a119892b57a7295514f.

@opencode-agent
opencode-agent Bot disabled auto-merge September 3, 2026 12:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation priority: high High-priority or P1 work status: draft Draft pull request type: docs Documentation, ADR, PRD, or technical writing

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants