Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
86 commits
Select commit Hold shift + click to select a range
ca9eb29
docs: plan canonical product architecture baseline
seonghobae Aug 9, 2026
81436c8
docs: assess canonical architecture documentation gaps
seonghobae Aug 9, 2026
35155bf
docs: add canonical LifeOS product requirements
seonghobae Aug 9, 2026
7b1fe16
docs: add canonical LifeOS technical requirements
seonghobae Aug 9, 2026
5ff1985
docs: add canonical LifeOS data model and ERD
seonghobae Aug 9, 2026
3530e69
docs: add canonical LifeOS UML views
seonghobae Aug 9, 2026
466ef84
docs: add LifeOS ADR index
seonghobae Aug 9, 2026
46d15b9
docs: record LifeOS hosting and data evolution ADR
seonghobae Aug 9, 2026
c932338
docs: record UUIDv4 internal identifier ADR
seonghobae Aug 9, 2026
d54c412
docs: record service data ownership ADR
seonghobae Aug 9, 2026
a4eab02
docs: record inert auditable AI proposal ADR
seonghobae Aug 9, 2026
21e8962
docs: record purpose-bound privacy access ADR
seonghobae Aug 9, 2026
c73d1b5
docs: record work-conserving maintenance ADR
seonghobae Aug 9, 2026
77b6b8e
docs: record canonical documentation graph ADR
seonghobae Aug 9, 2026
361759c
docs: add canonical LifeOS threat model
seonghobae Aug 9, 2026
d745e7f
docs: add canonical LifeOS test strategy
seonghobae Aug 9, 2026
3b5eb5c
docs: add canonical LifeOS operability boundary
seonghobae Aug 9, 2026
42f53e2
docs: add LifeOS requirement traceability matrix
seonghobae Aug 9, 2026
4af2dbe
docs: align root architecture with current bounded contexts
seonghobae Aug 9, 2026
482ea7b
test(docs): enforce canonical documentation contract
seonghobae Aug 9, 2026
b93a691
docs: align agent contract with canonical documentation graph
seonghobae Aug 9, 2026
578dd8e
docs: align Claude contract with canonical documentation
seonghobae Aug 9, 2026
8a0b653
docs: expose canonical LifeOS documentation from README
seonghobae Aug 9, 2026
c9802e7
docs: record canonical documentation baseline
seonghobae Aug 9, 2026
fdd06c1
docs: link canonical traceability to live buyer-gap issues
seonghobae Aug 9, 2026
7f8afad
docs: reconcile traceability with live gap ownership
seonghobae Aug 9, 2026
1261fee
docs: add canonical API and event contract registry
seonghobae Aug 9, 2026
1e27f8e
docs: add privacy and data lifecycle contract
seonghobae Aug 9, 2026
61ba484
docs: add release migration and rollback contract
seonghobae Aug 9, 2026
376028b
docs: add standards and research traceability index
seonghobae Aug 9, 2026
f0ab9e3
test(docs): cover API privacy release and standards contracts
seonghobae Aug 9, 2026
56a7037
test(docs): fix release contract assertion casing
seonghobae Aug 9, 2026
0f8a9df
docs: expose complete canonical documentation graph
seonghobae Aug 9, 2026
5aca4e6
test(docs): require README to link canonical documents
seonghobae Aug 9, 2026
2058820
docs: complete canonical documentation graph ADR
seonghobae Aug 9, 2026
591c5e0
test(docs): require merged OpenCode loop as protected-main evidence
seonghobae Aug 9, 2026
d641c6d
docs: promote merged OpenCode loop to protected-main evidence
seonghobae Aug 9, 2026
8a4d4a0
docs: reconcile PRD with merged autonomous loop and live gaps
seonghobae Aug 9, 2026
6149a58
docs: align TRD with merged autonomous development boundary
seonghobae Aug 9, 2026
6d78659
docs: complete architecture documentation graph and automation status
seonghobae Aug 9, 2026
fb9276b
docs: complete canonical documentation graph in agent contract
seonghobae Aug 9, 2026
8c5b6d1
docs: complete canonical evidence graph in Claude contract
seonghobae Aug 9, 2026
afb53b7
docs: finalize documentation completeness assessment
seonghobae Aug 9, 2026
e51981a
docs: register plugin runtime buyer gap
seonghobae Aug 9, 2026
72ad992
docs: align planning ERD with protected-main persistence
seonghobae Aug 9, 2026
514492b
docs: correct event and database ownership diagrams
seonghobae Aug 9, 2026
5d425cb
docs: reconcile documentation plan with completed work
seonghobae Aug 9, 2026
4188daa
docs: make service-owned database trust boundaries explicit
seonghobae Aug 9, 2026
5e46c86
test(docs): lock event direction and planning persistence status
seonghobae Aug 9, 2026
e1c0722
test(docs): fail on canonical status and traceability drift
seonghobae Aug 9, 2026
df74a10
docs(product): reconcile active buyer-gap implementations
seonghobae Aug 9, 2026
e4cc65c
docs(uml): normalize statuses and active Today state
seonghobae Aug 9, 2026
a3a092f
docs(ops): align deployment status vocabulary
seonghobae Aug 9, 2026
8e70198
docs(adr): separate capability maturity from buyer gaps
seonghobae Aug 9, 2026
1f2f579
docs(adr): unify canonical decision statuses
seonghobae Aug 9, 2026
121f3e7
docs(adr): normalize hosting decision status
seonghobae Aug 9, 2026
d86c7b1
docs(adr): normalize identifier decision status
seonghobae Aug 9, 2026
39591ca
docs(adr): normalize service ownership status
seonghobae Aug 9, 2026
bb2a014
docs(adr): normalize AI authority status
seonghobae Aug 9, 2026
de1f1f2
docs(adr): normalize privacy decision status
seonghobae Aug 9, 2026
da51a04
docs(adr): align autonomous maintenance evidence
seonghobae Aug 9, 2026
a34a4e6
docs(adr): strengthen canonical documentation contract
seonghobae Aug 9, 2026
8420082
docs(traceability): bind active implementations and readiness gaps
seonghobae Aug 9, 2026
1cddd6a
docs(trd): reconcile active implementation contracts
seonghobae Aug 9, 2026
702015e
docs(assessment): record exact-head documentation fitness
seonghobae Aug 9, 2026
c39b850
Merge branch 'main' into docs/canonical-product-architecture-baseline
opencode-agent[bot] Aug 9, 2026
0368607
docs(adr): assign unique hosting architecture record
seonghobae Aug 9, 2026
3aa92f0
docs(adr): remove colliding hosting ADR path
seonghobae Aug 9, 2026
b0fcfda
docs(adr): preserve historical identifier decision as superseded
seonghobae Aug 9, 2026
c9d8e52
docs(adr): index unique canonical decisions
seonghobae Aug 9, 2026
831be32
test(docs): require unique hosting ADR identity
seonghobae Aug 9, 2026
4e746b9
test(docs): enforce API and privacy status vocabulary
seonghobae Aug 9, 2026
fad60e2
docs(api): separate contract status from tracking evidence
seonghobae Aug 9, 2026
91a55f6
docs(privacy): separate lifecycle status from issue tracking
seonghobae Aug 9, 2026
9695bee
docs(adr): normalize legacy OAuth decision
seonghobae Aug 9, 2026
e46ee32
docs(adr): index decisions by stable filename identity
seonghobae Aug 9, 2026
dc2bf10
test(docs): index ADRs by full stable identity
seonghobae Aug 9, 2026
ac0397b
test(docs): accept equivalent ADR section headings
seonghobae Aug 9, 2026
2fb4605
docs(readiness): promote buyer-gap separation to protected-main evidence
seonghobae Aug 9, 2026
a05c548
docs(readiness): record integrated buyer-gap governance
seonghobae Aug 9, 2026
745ea8c
docs(readiness): reconcile protected-main buyer-gap governance
seonghobae Aug 9, 2026
0917dfc
docs(traceability): reconcile merged readiness governance
seonghobae Aug 9, 2026
c45c90e
docs(agent): reconcile integrated runtime hardening
seonghobae Aug 9, 2026
9b88572
docs(changelog): retain integrated OpenCode hardening
seonghobae Aug 9, 2026
bc6f83c
docs(traceability): reconcile current protected and active work
seonghobae Aug 9, 2026
d37e0a3
test(docs): detect stale active-PR lifecycle claims
seonghobae Aug 9, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
137 changes: 84 additions & 53 deletions AGENTS.md

Large diffs are not rendered by default.

169 changes: 120 additions & 49 deletions ARCHITECTURE.md

Large diffs are not rendered by default.

5 changes: 5 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@ All notable changes to LifeOS are documented in this file.

### Added

- A canonical product documentation graph covering the PRD, TRD, architecture decisions, logical ERD/data model, UML interaction/deployment views, threat model, test strategy, operability boundary, requirements traceability, and a machine-checked documentation contract.
- An hourly and manually dispatchable NVIDIA NIM live-conformance harness that pins contextual-orchestrator to an exact reviewed commit, compares strong single-route reasoning with bounded conducted workflows, and retains only validated credential-free quality, safety, orchestration, usage, and ablation evidence.
- A versioned, immutable AI proposal quality evaluator that separates production validity, semantic operation conformance, evidence grounding, benign utility, forbidden-text leakage, and prompt-injection resistance across realistic English, Korean, temporal, empty-context, completed-item, and adversarial fixtures.
- An explicit `contextual-orchestrator` proposal-model mode with bounded OpenAI-compatible transport, strict structured output, model provenance, and an independent local rule-based default.
Expand All @@ -23,6 +24,9 @@ All notable changes to LifeOS are documented in this file.

### Fixed

- The OpenCode development loop now prevents project settings from overriding its pinned offline NVIDIA model, records catalog failures accurately, parses the accepted candidate's exact Compose file outside the model account, and requires digest-pinned PostgreSQL queries plus NATS JetStream probes in pull-request CI.
- Canonical documentation now marks early browser-only local-first, single-application, and UUIDv7 design proposals as superseded where they conflict with the current multi-user modular MSA and UUIDv4 protected-main contracts.
- Root architecture and agent handoff documents now include current notification/privacy bounded contexts and distinguish protected-main, active-PR, partial, planned, research-only, superseded, and out-of-scope behavior.
- Live contextual-orchestrator responses now classify successful empty bodies as evaluation failures, emit exactly one terminal observation, canonicalize retained timestamps safely, and preserve null metric denominators instead of fabricating deltas.
- Stale AI proposal revision conflicts now belong to the technology-independent audit domain while the PostgreSQL adapter preserves its compatibility export.
- Planning search now normalizes browser query text and prevents stale or unmounted requests from replacing the latest visible result state.
Expand All @@ -32,6 +36,7 @@ All notable changes to LifeOS are documented in this file.

### Security

- The commercial-development model account no longer performs Docker commands, never receives Docker-socket authority, and cannot trigger provider-wide model discovery through the credential bridge.
- The scheduled live-model harness uses only `NVIDIA_NIM_API_KEY`, seeds it through the encrypted contextual-orchestrator credential registry, installs hash-locked dependencies from an exact commit, confines LifeOS traffic to loopback, allowlists NVIDIA NIM egress, and excludes provider credentials, prompts, responses, traces, and hidden reasoning from retained artifacts.
- Proposal quality reports now discard nested model failures and response bodies, normalize labeled sentinel checks, expose no provider credential or mutation dependency, and measure prompt-injection resistance together with benign utility instead of rewarding blanket refusal.
- External proposal generation now accepts only one credential-free HTTPS orchestrator origin, stops responses at 65536 bytes, enforces a bounded abort timeout, supplies no tools, treats planning context as untrusted data, and exposes only sanitized failures.
Expand Down
68 changes: 42 additions & 26 deletions CLAUDE.md
Original file line number Diff line number Diff line change
@@ -1,47 +1,63 @@
# Claude operating contract for LifeOS

`AGENTS.md` is the canonical repository-wide instruction file. This document maps that contract into a concise execution order for Claude-compatible agents and must not override `AGENTS.md`, `ARCHITECTURE.md`, branch protection, or security policy.
`AGENTS.md` is the canonical repository-wide agent instruction file. The canonical product/technical evidence graph is `docs/PRD.md`, `docs/TRD.md`, `ARCHITECTURE.md`, `docs/adr/README.md`, `docs/DATA_MODEL.md`, `docs/UML.md`, `docs/API_CONTRACTS.md`, `SECURITY.md`, `docs/THREAT_MODEL.md`, `docs/PRIVACY_DATA_LIFECYCLE.md`, `docs/TEST_STRATEGY.md`, `docs/OPERABILITY.md`, `docs/RELEASE_AND_MIGRATION.md`, `docs/STANDARDS_TRACEABILITY.md`, `docs/TRACEABILITY.md`, and `docs/DOCUMENTATION_ASSESSMENT.md`. This document maps them into a concise execution order and must not override live branch protection, security policy, or protected-main behavior.

## Execution order

1. Inspect every open pull request before starting unrelated implementation.
2. Read all human, CodeRabbit, AppGuardrail, code-scanning, and security feedback.
3. Determine the root cause of every failing or pending-required check.
4. Make the smallest complete correction, including tests and documentation.
5. Re-run the exact pull-request head and resolve only threads whose finding is actually addressed.
6. Merge only when required checks pass, no actionable findings remain, and the repository's merge policy accepts the exact head.
7. Continue with the highest-impact buyer-visible gap after the pull-request queue is empty.
1. Refetch every open PR, exact current head and exact live base tip before relying on historical state.
2. Read all human, CodeRabbit, AppGuardrail, code-scanning, security and configured automated feedback.
3. Determine the first causal boundary of every failed/missing/stale/required check and verify a remedy is operationally real.
4. Make the smallest complete test-first correction, including documentation/cleanup/migration evidence required by the root cause.
5. Rerun/inspect exact-head verification and resolve only threads whose underlying finding is actually fixed.
6. Merge only when repository protections accept the unchanged exact head and no actionable finding remains.
7. Immediately continue with another safe PR/review/cleanup/documentation/product/operability/release-readiness task while finite run budget remains.
8. When PR work is exhausted, implement the highest-impact bounded buyer-visible product gap rather than ending at gap identification.

Routine progress narration is not a substitute for repository evidence. Record decisions in code, tests, ADRs, specifications, plans, runbooks, issues, and pull-request descriptions.
A successful commit, PR creation, merge, documentation pack, review request, check dispatch, queued workflow, or RCA is an intermediate result while safe work remains. Routine status narration is not repository evidence.

## Non-negotiable boundaries
## Writer/concurrency discipline

- Never use `COPILOT_GITHUB_TOKEN`.
- Scheduled model-assisted work uses `NVIDIA_NIM_API_KEY` through the approved OpenCode or contextual-orchestrator boundary.
- Do not alter or repurpose the credential scheme of existing review agents.
- Never forward browser cookies, provider credentials, hidden reasoning, raw prompts, raw model responses, or stack traces into retained artifacts.
- Internal identifiers are UUIDv4 strings; numeric external identifiers are mapped through an explicit provider-identity boundary.
- Database objects use multiword `snake_case` names unless an external protocol mandates a different spelling.
Before branch-affecting writes, refetch exact target head/base/ref/blob. If another source writer moves the same target, discard stale assumptions, freeze only that target for the run, and continue non-conflicting work. Never turn one branch conflict or unavailable tool path into a repository-wide stop.

## Architecture boundaries

- LifeOS is multi-user, server-backed, self-hostable and domain-oriented; early browser-only local-first/single-app primary designs are historical/superseded.
- Internal identifiers are opaque UUIDv4 strings; old UUIDv7 design language is superseded.
- Database objects use descriptive multiword `snake_case` unless an external protocol requires otherwise.
- Services do not read or mutate another service's database tables.
- AI proposals remain inert until a separately authorized user-confirmed execution capability exists.
- Mathematical and psychometric numerical kernels require Rust, deterministic CPU/GPU execution boundaries, realistic parameter-recovery tests, multilevel or multiple-membership structure, and temporal modeling where applicable.
- Browser-local drafts/caches do not become durable truth until an authorized owning service confirms persistence.
- AI proposals remain inert until a separately authorized domain execution capability exists.
- Sensitive access uses purpose/resource/actor/lifetime controls and auditable evidence; blanket masking is not an authorization model.
- The bounded hourly OpenCode commercial-development loop is protected-main automation after PR #122, but deterministic policy and normal review/security/exact-head gates remain authoritative and the automation has no product-data authority.

## Documentation discipline

Use exact statuses: `Implemented on protected main`, `Implemented on active PR`, `Partial`, `Accepted architecture`, `Planned`, `Research only`, `Superseded`, `Out of scope`.

Do not present active-PR/roadmap behavior as shipped. When source/tests disagree with prose, correct the prose or behavior according to the approved product decision; do not use documentation to override protected-main runtime truth.

The original `docs/superpowers/specs/2026-08-02-life-os-design.md` is historical input. Canonical docs/ADRs explicitly reconcile its local-first/single-app/UUIDv7/post-MVP assumptions with current architecture.

When documentation exposes a missing product journey, stale runtime contract, migration/recovery gap, security/privacy flaw, accessibility issue or release blocker, continue into executable work when safe rather than stopping at the audit.

## LLM orchestration decisions

Use a strong single-model route as the mandatory baseline. Allocate additional test-time compute only through explicit profiles that identify reasoning effort, workflow stages, role assignment, decomposition, recursive depth, and access topology. Use measured proposal validity, grounding, utility, and prompt-injection resistance to justify deeper orchestration. Do not optimize this decision for latency alone.
Use a strong single-model route as the mandatory baseline. Allocate additional test-time compute only through explicit profiles identifying reasoning effort, workflow stages, roles, decomposition, recursive depth and access topology, justified by measured validity/grounding/utility/safety evidence rather than latency alone.

Live model tests may use `NVIDIA_NIM_API_KEY`. Deterministic pull-request checks must remain meaningful when that secret or the provider is unavailable. Provider failures produce sanitized unavailable evidence, never fabricated scores.
Model-assisted tests/development use `NVIDIA_NIM_API_KEY` through the approved OpenCode/contextual-orchestrator boundary where required. Do not casually alter independent review-agent credential schemes. Deterministic checks remain meaningful when the live provider is absent or unavailable; provider failures produce sanitized unavailable evidence, never fabricated scores.

## Verification standard

- Production declarations have explanatory docstrings.
- Changed production code maintains 100% statement, branch, function, and line coverage where the package enforces those gates.
- Tests model realistic domain outcomes, not only mocked implementation calls.
- Standards and research claims are documented with APA 7 references and publication status is distinguished from drafts or preprints.
- Packages with exact gates maintain 100% statement, branch, function and line coverage using meaningful tests.
- Persistence behavior uses realistic PostgreSQL tests for tenant, transaction, replay, concurrency and recovery semantics.
- Core web journeys include accessibility/localization/mobile/PWA evidence where relevant.
- Standards/research claims use appropriate primary/current sources with APA 7 traceability and publication-status distinctions.
- API/event, privacy/data lifecycle, migration/rollback and operability docs remain synchronized with owning implementations.
- `CHANGELOG.md` records buyer-visible behavior.
- `ARCHITECTURE.md` and relevant feature ADR/specification files record boundary changes.
- Release tags and versions are created only after the repository proves release readiness; unreleased work stays under `Unreleased`.
- Canonical evidence documents remain code-current and `docs/TRACEABILITY.md` distinguishes protected-main evidence from active-PR/planned gaps.
- Release versions/tags are created only after exact integrated release readiness; unreleased work stays under `Unreleased`.

## Safe escalation

Escalate only for a decision or permission that cannot be resolved from repository policy, tests, standards, or available credentials. Waiting for checks or reviews is not itself an escalation condition; continue independent analysis, documentation, or the next non-conflicting planned task while preserving merge safety.
Escalate only for a concrete external decision, permission, secret, governance action or safety boundary that cannot be derived/resolved from current repository evidence and realistically available tools after alternatives are tested. Waiting for checks/reviews/providers is not itself an escalation condition; continue independent work.
Loading
Loading