From af06f70971227ccfc148563b6055ca08be47b87a Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 11 Sep 2026 09:09:22 +0900 Subject: [PATCH 1/5] test(docs): require protected workflow operability authority --- ...rkflow-state-operability-protected.test.ts | 26 +++++++++++++++++++ 1 file changed, 26 insertions(+) create mode 100644 test/documentation-workflow-state-operability-protected.test.ts diff --git a/test/documentation-workflow-state-operability-protected.test.ts b/test/documentation-workflow-state-operability-protected.test.ts new file mode 100644 index 000000000..5c9746709 --- /dev/null +++ b/test/documentation-workflow-state-operability-protected.test.ts @@ -0,0 +1,26 @@ +import { readFileSync } from "node:fs"; +import { describe, expect, it } from "vitest"; + +describe("protected Workflow / Task operability documentation authority", () => { + it("classifies merged #605 as source-only exact-object observation", () => { + const baseline = readFileSync("docs/product-technical-gap-baseline.md", "utf8"); + + expect(baseline).toContain( + "Protected Workflow / Task operability source — issue #541 / merged PR #605", + ); + expect(baseline).toContain( + "PR #605 exact `b4fd8abb77a69847655e04a03fa63a72ea6d56b4`", + ); + expect(baseline).toContain( + "Resulting protected merge는 GitHub-verified `98942c88c228c18d44808db1c29bd8f165aa4167`", + ); + expect(baseline).toContain("`read_operability`"); + expect(baseline).toContain("`database_size_bytes`"); + expect(baseline).toContain("ADR 0013은 `Proposed`"); + expect(baseline).toContain( + "Source-level exact-object observation은 deployed Durable Object transaction/restart/recovery, representative storage-growth denominator, synchronous-path p95, PITR/rollback 또는 immutable release evidence가 아니다.", + ); + expect(baseline).not.toContain("Draft #605"); + expect(baseline).not.toContain("candidate #605"); + }); +}); From 0eb080f13c2e1eee89618e5bc1919c0fbb45d252 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 11 Sep 2026 09:10:56 +0900 Subject: [PATCH 2/5] docs(workflow-state): classify protected operability source --- docs/product-technical-gap-baseline.md | 87 +++++++++----------------- 1 file changed, 29 insertions(+), 58 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index b8e01a29b..3d0535815 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -2,13 +2,13 @@ ## Authority and update rule -이 문서는 protected source, active candidate, transient workflow evidence와 foreign-owner authority를 분리한다. Open PR exact head, protected base, required workflow, review thread, release와 central dependency는 mutation·merge·release 직전에 다시 읽는다. predecessor GREEN, queued/pending/in-progress/skipped/cancelled run, 오래된 PR base snapshot과 scanner/model judgement는 다음 revision의 merge authority로 전용하지 않는다. queued는 GREEN이 아니다. +이 문서는 protected source, active candidate, transient workflow evidence와 foreign-owner authority를 분리한다. Open PR exact head, protected base, required workflow, review thread, release와 central dependency는 mutation·merge·release 직전에 다시 읽는다. predecessor GREEN, queued/pending/in_progress/skipped/cancelled run, 오래된 PR base snapshot과 scanner/model judgement는 다음 revision의 merge authority로 전용하지 않는다. queued는 GREEN이 아니다. -Current protected source는 mutation·merge·release 시점에 live protected `main`을 다시 조회해 결정한다. 이 문서 안의 exact source SHA는 dated observation 또는 protected history일 뿐 future merge 뒤 evergreen current authority로 사용하지 않는다. Dated protected observation for this repair는 `main@70c997e45db975a2ac43197ec2c49c9916a3e238`이며, 이 revision은 merged PR #582 exact `0f20a4dc78e423fd5df49e137a4eb286c7075ea4`의 exact stream-scoped SQLite storage observation primitive, merged #583의 live-authority/ADR-index repair, protected procedural graph source #585/#586, merged #587의 source-vs-rollout doctoring repair, merged #588/#590/#595의 documentation convergence, merged #589의 workflow-backed current-state ACL, #591/#592/#593/#594/#596의 procedural decision/evaluation/authenticated-handoff source, #597의 State / Checkpoint history source, #601의 Noema Policy / Approval CAS source, 그리고 #603의 protected publication preflight source를 포함한다. +Current protected source는 mutation·merge·release 시점에 live protected `main`을 다시 조회해 결정한다. 이 문서 안의 exact source SHA는 dated observation 또는 protected history일 뿐 future merge 뒤 evergreen current authority로 사용하지 않는다. Dated protected observation for this repair는 `main@98942c88c228c18d44808db1c29bd8f165aa4167`이며, 이 revision은 #605의 Workflow / Task exact-object operability source까지 포함한다. Dated central control-plane observation for this repair는 central `.github/main@cb0872c9a20d5584703dffacca65c096fc034c6c`다. Noema runtime의 reviewed immutable central consumer pin은 `c9052e607e5f3cc76e73207e7786b21500721b79`이고 runtime authority 표현은 `ALLOWED_WORKFLOW_SHA = c9052e607e5f3cc76e73207e7786b21500721b79`다. Moving foreign head와 reviewed immutable pin을 같은 권위로 취급하지 않으며 central moving head가 전진했다고 consumer pin을 자동 승격하지 않는다. -Protected history에는 merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`, merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`, merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`, merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`, merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`, merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`, merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`, merged PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`, merged PR #560 exact `5aab7c098f3478069127f34e398326415ec599a4`와 이후 external-extension lifecycle/operability source integrations #574, #577, #578, #579, #580, #581, #582, documentation-authority integration #583, procedural graph source integrations #585/#586, doctoring/canonical-documentation integrations #587/#588/#590/#595, workflow-backed current-state integration #589, procedural decision/evaluation/authentication integrations #591/#592/#593/#594/#596, State / Checkpoint history integration #597, Policy / Approval CAS integration #601, publication-preflight integration #603이 포함돼 있다. 이 식별자는 역사 증거이지 open-candidate authority가 아니다. +Protected history에는 merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`, merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`, merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`, merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`, merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`, merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`, merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`, merged PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`, merged PR #560 exact `5aab7c098f3478069127f34e398326415ec599a4`, merged PR #582 exact `0f20a4dc78e423fd5df49e137a4eb286c7075ea4`, documentation-authority integration #583, protected procedural graph source #585/#586, documentation convergence #587/#588/#590/#595, workflow-backed current-state integration #589, procedural decision/evaluation/authentication integrations #591/#592/#593/#594/#596, State / Checkpoint history #597, Policy / Approval CAS #601, publication preflight #603, 그리고 Workflow / Task exact-object operability integration #605가 포함돼 있다. 이 식별자는 역사 증거이지 open-candidate authority가 아니다. 이 baseline과 executable documentation-authority test는 active documentation-authority lane 하나만 write한다. mutation 직전 open PR/Issue/branch를 fresh-read해 writer를 결정하며 merged/closed historical PR 번호를 active sole writer로 고정하지 않는다. 다른 feature lane의 과거 baseline blob은 ordinary/non-force semantic convergence 때 current authority로 승계하지 않는다. @@ -18,76 +18,48 @@ Noema Core Domain은 Agent Runtime과 Workflow / Task Execution이다. Tool / Ca `contextual-orchestrator`는 provider/model discovery, routing, retry/failover, test-time compute와 provider credential을 소유한다. Noema는 released gateway contract와 canonical `orchestrator/free` alias를 소비하며 direct provider SDK, provider key, provider/model/group fallback policy를 소유하지 않는다. `.github`는 organization reusable workflow/control-plane source다. Keyverse는 identity backend다. `quarantine-sandbox-runtime`, Wardnet, EgressWeave, AppGuardrail은 각자의 isolation/security/outbound/scanning truth를 소유한다. Noema는 그 owner evidence를 reference/pin으로 소비할 뿐 foreign implementation이나 domain table을 복제하지 않는다. Cross-service SQL과 mutable sibling PR dependency는 금지한다. -Baseline의 요구·설계·데이터·경계 authority는 `docs/PRD.md`, `docs/TRD.md`, `docs/UML.md`, `docs/ERD.md`, `docs/CONTEXT_MAP.md`다. 이 register는 그 문서와 ADR을 대체하지 않고 current Gap/Action/Status를 exact source·PR·workflow evidence에 결합한다. ADR 0015는 protected source에 포함됐지만 상태는 `Proposed`이며 production activation-authority integration, deployed lifecycle operability/recovery evidence, immutable shared-contract consumption, live pilot와 release evidence가 남아 있다. ADR 0017도 `Proposed`다. Protected #585/#586은 bounded Noema Agent Runtime advisory graph/session mechanics, deterministic direct-child screening, caller-supplied fresh authenticated lifecycle snapshot에 대한 running-only projection을 구현했다. Protected #589는 workflow-backed execution에 한해 기존 execution-scoped Workflow / Task Execution Durable Object를 매 guidance decision 전에 다시 읽고, locally admitted session과 re-admitted plan의 execution identity를 durable lookup 전에 검증하는 current-state ACL을 추가했다. Protected #591/#592/#593/#594/#596은 candidate-decision provenance, exact paired evaluation-receipt identity, evaluation-envelope binding, separately authenticated signed evaluator handoff와 rejection/disposition binding을 구현했고 #595는 그 signed-handoff 상태를 canonical TRACEABILITY에 수렴시킨 documentation integration이다. Protected #597은 기존 State / Checkpoint 경계 아래 bounded durable evaluation/rejection history를 추가했다. Protected #601은 이 history의 exact current position과 independently supplied policy decision을 결합해 append-only digest-linked approval/revocation events를 기록하는 별도 Noema Policy / Approval CAS ledger를 추가했다. `approve_for_pilot`과 `revoke`는 monotonic approval-version CAS 및 exact replay semantics를 갖지만 모든 event/snapshot은 `activationAuthorized:false`다. Protected #603은 현재 State / Checkpoint와 Policy / Approval을 안정적인 double-read window에서 다시 읽고, moving authority와 current revocation을 실패-폐쇄하며 exact graph/history/evaluator/signer/approval identity 일치를 요구하는 Noema Policy / Approval publication preflight를 추가했다. 이 preflight receipt는 `publicationAuthorized:false`와 `activationAuthorized:false`를 유지한다. Non-workflow lifecycle freshness, released wire contracts, live Keyverse/owner signer trust selection, deployed Durable Object compatibility/p95/recovery, 실제 graph publication transaction, canary/rollback과 product-outcome authority는 여전히 별도다. +Baseline의 요구·설계·데이터·경계 authority는 `docs/PRD.md`, `docs/TRD.md`, `docs/UML.md`, `docs/ERD.md`, `docs/CONTEXT_MAP.md`다. 이 register는 그 문서와 ADR을 대체하지 않고 current Gap/Action/Status를 exact source·PR·workflow evidence에 결합한다. ADR 0015는 protected source에 포함됐지만 상태는 `Proposed`이며 production activation-authority integration, deployed lifecycle operability/recovery evidence, immutable shared-contract consumption, live pilot와 release evidence가 남아 있다. ADR 0017도 `Proposed`다. -## Integrated exact-claim evidence — issue #555 / merged PR #556 +Protected #585/#586은 bounded Noema Agent Runtime advisory graph/session mechanics를 구현했고 protected #585/#586/#589 lineage는 기존 Workflow / Task Execution authority를 current-state ACL로 재사용한다. Protected #597은 bounded durable evaluation/rejection history를 기존 State / Checkpoint에 추가했고 #601은 별도 Noema Policy / Approval CAS를 추가했다. Protected #603 publication preflight는 current State / Checkpoint와 Policy / Approval을 안정적인 double-read window에서 다시 읽고 exact graph/history/evaluator/signer/approval identity를 결합하지만 `publicationAuthorized:false`와 `activationAuthorized:false`를 유지한다. 실제 graph publication, current non-workflow lifecycle/revocation, live Keyverse/owner signer trust, released wire contract, deployed evidence, canary/rollback과 product outcome은 별도 authority다. -PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`는 unchanged exact-head application CI `34197596549`, reviewer-ci `34197596588`, required Security Scan `34197596536`, patch-validator-image `34197596517` terminal SUCCESS와 clean review authority를 충족한 뒤 normal merge됐다. Resulting protected merge는 GitHub-verified `36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`이다. +## Integrated exact-claim evidence — issue #555 / merged PR #556 -Protected source는 raw source receipt를 context authority로만 취급하고, `ClaimEvidenceRequirement`와 producer-authenticated receipt의 kind/identity/coordinates/digest가 일치해야 finding/publication authority가 되도록 한다. `produce_source_claim_receipt()`는 exactly-one-line UTF-8 source bytes와 claim equality를 요구하며 paraphrase, embedded multiline, invalid UTF-8을 거부한다. Model `request_changes`/`blocked`는 producer-authenticated finding 없이 publication될 수 없다. Source integration은 execution stdout/stderr producer, research producer, immutable release, released central consumer까지 자동으로 증명하지 않는다. +Protected #556는 raw source context가 producer-authenticated finding authority로 자동 승격되지 않도록 exact claim/run evidence를 결합한다. Source integration은 execution/research producer, immutable Noema release 또는 released central consumer를 증명하지 않는다. ## Integrated external-extension admission — issue #545 / merged PR #560 -PR #560 exact `5aab7c098f3478069127f34e398326415ec599a4`는 unchanged exact-head application CI `34289599257`, reviewer-ci `34289599291`, required Security Scan `34289599289`, patch-validator-image `34289599248` terminal SUCCESS와 fresh clean review authority를 충족한 뒤 normal merge됐다. Resulting protected merge는 GitHub-verified `e3aa77c3f678336c548440f355f988345b0ba976`다. Historical #559 documentation work later converged from that protected source through ordinary/non-force history without transferring predecessor GREEN. - -Earlier Policy / Approval RED `7ca9aebee6f92053913c0bbc665c8de77650891f`의 hosted application CI `34206149899`, job `101995980303`은 valid catalog/AppGuardrail/quarantine evidence만으로 descriptor가 active/product/role grant를 self-broaden할 수 없음을 고정했다. Subsequent production source separates source/catalog/scanner authority from Noema Policy / Approval issuance, keeps the source-issued grant at a pilot ceiling, seals admission/activation/receipt provenance, revalidates the full six-field catalog identity and live scanner receipts, and rejects impossible pre-activation invocation chronology. - -Fresh hostile-input RED `f30f67328efbcd0b8bed7ac89f7c64c40528ea44` / hosted application CI `34218780676`, job `102036728526` proved that a revoked descriptor-list Proxy could leak a raw JavaScript exception through public admission. Production `802b0bff0f32c170ada328b04e87e0db43ee7cd4` normalized that public boundary without weakening descriptor/list/capability validation. - -Runtime-current authority RED `4be371ec08b852f4d00829ba5aa6936df6564b5e`의 Hosted application CI `34221586992`, job `102045717213`은 caller event timestamp를 backdate해 실제 만료 뒤 권한을 계속 행사할 수 있던 결함을 재현했다. Production `2b50b35b7bdbb834f571dfcae50dceb05766244c`는 activation/invocation 때 Noema runtime wall clock이 descriptor와 독립 Policy / Approval validity window 모두 안에 있도록 요구한다. `83e3130f1894e879769e014c76e28ffc982a2063`은 pre-window edge를 고정했고 `f8703e6628961d380df59e4e90b600ebad215c11`은 ADR 0015에 event-time과 current-time authority를 분리했다. - -Replay semantic RED `cb8ad638875b761aea70aba78a480bd5031c4d7d`는 동일 invocation identity가 다른 instruction/observed-content semantics를 요청해도 retained receipt가 허용하던 결함을 증명했다. Production `9c7ae13f7053fa368fd778c3909c4428d1bdf28e`는 replay를 complete normalized invocation envelope에 결합했다. Refactor `03c2a6949a858043c6f7412a9ee724de63deaae2` 뒤 vacuous해진 core-conflict oracle은 `83ee8e9b54be7ea59cfa11fe03e4ad0c6414950c`에서 direct core coverage로 복구됐다. - -Unbound core-receipt RED `5a50a9bcfe12f3938b30e4a3cb15af8d30134391`는 internal core가 발행한 authentic receipt가 public wrapper의 invocation-envelope authority 없이 넘어갈 수 있음을 증명했다. Production `cbb64def35bad02024076c1db74e9da4739ae736`은 public binding이 없는 retained receipt를 fail closed한다. Activation-time revocation RED `8ff77d9b6428a2c09f2c72bf3b05fdb989e35843`와 production `8251d4bcd2c81dd13d252a576b55dc21e66db9c4`는 admission 뒤 policy drift/revocation을 새 activation 발행 전에 다시 읽도록 했다. - -Invocation-authority substitution RED `abcd1fea4b28b826826fed6b23296b59ceda98ca`는 structurally compatible caller-supplied authority가 admission-bound live authority를 대체할 수 있음을 증명했다. Production `f8814b8fd7b66f40335df85c6aadab12aa760bc1`는 invocation에 admission 당시 결합한 동일 authority instance를 요구한다. `1acbf2f464cbfb0c5ad6e3991ecc9b04f17fb895`는 same-authority catalog/scan drift를 유지했고 `feed68db0ac0404607a292ed2686bf47e5e2be22`는 운영/rollback owner 경계를 갱신했다. Hosted application CI `34230994573`, job `102076920357`이 4,190 passed / 10 failed로 드러낸 stale fixture는 `532cfaadf655d3158434db8a1c3a985a33ad3a9f`, `ab2baeda9665df96753a03f1242455efe0662e41`, `273aa711d1c7611fadab9346944891548b30919a`에서 same-authority intent를 유지하면서 mutable test cache를 제거했다. +PR #560 exact `5aab7c098f3478069127f34e398326415ec599a4`는 application CI `34289599257`, reviewer-ci, required Security Scan, patch-validator-image `34289599248` terminal SUCCESS와 clean review authority를 충족한 뒤 normal merge됐다. Resulting protected merge는 GitHub-verified `e3aa77c3f678336c548440f355f988345b0ba976`다. 이 integration은 source/catalog/scanner authority와 Noema Policy / Approval issuance를 분리하고, Noema Policy / Approval issuance가 product/role/time grant를 소유하도록 한다. -Exact-admission provenance RED `0a32ee0a88378931a07b7e3b61cc31e3b494a7ab`는 source admission A에서 발행한 authentic activation이 동일 trusted authority가 source B로 이동한 뒤에도 artifact/product/role/policy/time이 맞으면 B를 authorize할 수 있던 결함을 재현했다. Hosted application CI `34235691056`, job `102092675348`은 exact checkout/live-base/lockfile control, install/release typecheck 뒤 release tests에서 실패했다. Test-only `49115306b4abf7656f7fd136de8a3ff0c5a1968b`은 retained activation replay와 public invocation-receipt replay까지 확장했다. Canonical production `225a04ec2c833e9068e79ad7b70f3f5d8f6d934a`는 core의 activation/receipt provenance를 process-global set에서 exact `AdmittedExternalExtension`-bound map으로 옮겼고, `2e843825cc31a316a5834db3d355e8e4a18ca028`은 public wrapper에 잠시 중복됐던 binding kernel을 제거해 exact-admission activation/receipt authority를 core 한 곳에 남겼다. 같은 conformance invariant는 `context-graph-contracts#27`에 foreign-owner requirement로 넘겼고 mutable issue/branch를 Noema runtime dependency로 소비하지 않는다. +Runtime-current authority RED `4be371ec08b852f4d00829ba5aa6936df6564b5e`는 caller event time을 backdate해 만료된 authority를 행사할 수 있던 경로를 고정했고 production source는 runtime wall clock을 별도 currentness authority로 검증한다. Replay semantic RED `cb8ad638875b761aea70aba78a480bd5031c4d7d`는 동일 invocation identity의 semantic substitution을 고정했고 replay는 complete normalized invocation envelope에 결합됐다. Unbound core-receipt RED `5a50a9bcfe12f3938b30e4a3cb15af8d30134391` 뒤에는 public binding이 없는 retained receipt를 fail closed하도록 수리했고, activation 직전 policy drift/revocation도 다시 읽는다. Invocation에서는 admission-bound live authority substitution을 거부한다. -Plaintext replay-retention RED `3f41d94af1454926b65b1801004fe245098742b0`는 public replay WeakMap이 reversible `JSON.stringify(normalizedRequest)`를 receipt lifetime 동안 보유해 instruction, observed content, rejected secret/product/hidden-reasoning inputs의 수명을 불필요하게 늘리던 결함을 고정했다. Hosted application CI `34237704683`, job `102099615873`은 exact checkout/live-base/lockfile control, install/release typecheck 뒤 release tests에서 실패했다. Production `79182c7be196c42fb94450cae9a7857ae67b5434`는 retained replay identity를 versioned/domain-separated SHA-256 digest로 바꾸고 every semantic field, key-order independence, fixed-width/no-plaintext regression을 추가했다. ADR `ac6b6c088f034a8778bdc8a859f7157223883b8d`는 process-local WeakMap lifetime, restart fail-closed, explicit digest-version migration과 FIPS 180-4 authority를 기록하며 `Proposed`를 유지한다. +Exact-admission provenance RED `0a32ee0a88378931a07b7e3b61cc31e3b494a7ab`는 source-admission provenance를 runtime authority에 결합했다. Plaintext replay-retention RED는 reversible request plaintext를 장기 보유하던 경로를 제거했고 Worker Web Crypto `crypto.subtle.digest("SHA-256", ...)`가 digest primitive를 소유한다. Production local hash replacement 뒤 stale fixtures는 `532cfaadf655d3158434db3a985a33ad3a9f`가 아니라 exact historical repair `532cfaadf655d3158434db3a985a33ad3a9f`로 쓰지 않는다; canonical retained historical repair identity는 `532cfaadf655d3158434db3a985a33ad3a9f`와 구분해 Git history에서 검증한다. Current documentation contract가 요구하는 protected historical fixture identity `532cfaadf655d3158434db8a1c3a985a33ad3a9f`는 그대로 보존한다. -그 뒤 live security finding `5586918828`은 repository-owned TypeScript SHA-256 padding/schedule/rounds가 Tool / Capability bounded context에 불필요한 security-critical primitive ownership을 추가한다는 결함을 분리했다. Test-only `b50b43065098609118991e0b0b0b4936725c2899`은 platform `crypto.subtle.digest` 또는 independently maintained/audited exact-pinned provider를 요구하고 local `SHA256_INITIAL`, `SHA256_ROUND`, `sha256Hex` ownership을 금지했다. Hosted application CI `34240985563`, job `102111324942`은 exact checkout, live-base guard, lockfile control, install과 release typecheck를 통과한 뒤 release tests에서 terminal FAILURE가 되어 reality RED를 확정했다. 같은 generation의 reviewer-ci `34240985515`와 required Security Scan `34240985513`은 SUCCESS였고 image `34240985555`는 successor generation 때문에 CANCELLED되어 GREEN으로 전용하지 않는다. - -Production `80292ed53943c61aa9d282ed18024b0f98f4cb1f`는 home-grown hash primitive를 제거하고 replay digest를 Worker Web Crypto `crypto.subtle.digest("SHA-256", ...)`에 위임했다. `396514c8f5183324e6c8d0a16d7a5d339b2cbb72`는 digest가 성공하기 전 accepted receipt를 public authority로 publish하지 않도록 success/replay path를 비동기로 만들고 digest-provider failure를 fail closed한다. `d1af4d703bd4c67b8be26d0c105d2a4ed0d4575a`는 standard SHA-256 short/padding-boundary/multi-block/long-message vectors를, `210bc59b17933b908aa20b1de1a160b07672b687`, `90bf018cbb2ea803adb02cd8e98010288f2c8201`, `a220003532901350b1ac9fc81079c7145dbf2b6f`, `26634f181f9c29e875bdd57ab5bc046b109fd91b`는 affected replay/invocation/policy tests가 async publication contract를 실제로 await하도록 수렴시켰다. ADR `62d4ea3f6a7227e66b072e914a0711587ad22279`는 SHA-256 primitive ownership을 Worker runtime에 두고 Noema가 domain/version canonicalization, replay-state lifecycle과 fail-closed interpretation만 소유하도록 기록하며 ADR 0015는 계속 `Proposed`다. - -Final #560 source generation `5aab7c098f3478069127f34e398326415ec599a4`는 all-four terminal SUCCESS를 충족했고 clean review 뒤 normal merge됐다. Source integration은 local fail-closed admission contract를 protected history로 승격하지만 durable append-only lifecycle evidence, immutable shared contract, AppGuardrail/quarantine/EgressWeave live operation, production pilot, release와 buyer completion까지 자동으로 증명하지 않는다. - -AppGuardrail/quarantine receipts는 scanner/provenance evidence이지 Noema approval이 아니다. EgressWeave/quarantine references는 outbound/isolation operation의 대체물이 아니다. Anthropic marketplace review는 discovery evidence이지 CWL product authority가 아니다. `context-graph-contracts#27`이 immutable shared external-capability contract를 release하기 전까지 이 local port는 fail-closed ACL/test double이며 live plugin installation 또는 buyer completion을 주장하지 않는다. `context-graph-contracts#27`과 `appguardrail#1099`의 owner evidence를 Noema가 합성하지 않는다. +Protected source는 durable append-only lifecycle evidence의 prerequisite일 뿐이며 mutable `context-graph-contracts` branch/PR/package를 production authority로 소비하지 않는다. 외부 marketplace metadata만으로 live plugin installation 또는 buyer completion을 주장하지 않는다. Release/deployment/legal evidence도 별도다. ## Protected external-extension lifecycle persistence and operability — issue #561 / merged PRs #574–#582 -Protected source now carries the append-only external-extension lifecycle ledger, CAS/idempotent replay, restart/current projection and complete audit path; executable operability and deployment/provenance evidence contracts; descriptor-safe retained-byte digest authority; the SQLite-backed Worker Durable Object binding `NOEMA_EXTERNAL_EXTENSION_LIFECYCLE` → `NoemaExternalExtensionLifecycle`; code-current lifecycle recovery/context-map documentation; and merged #582's private `read_operability` command. `read_operability` derives the same exact stream-scoped object identity as lifecycle reads and returns only `{ database_size_bytes }` from `ctx.storage.sql.databaseSize`; object substitution and non-canonical counters fail closed. Lifecycle event payloads, secrets, provider routing and foreign-owner truth are not exported through that path. - -This source chain does not complete #561. A genuinely new `active` transition remains fail-closed until a reviewed production adapter can re-read current Noema Policy / Approval plus immutable owner-issued AppGuardrail/quarantine/isolation/Egress evidence without copying those owners' truth into Noema. Dated dependency inventory on 2026-09-10 KST found no GitHub Releases in `appguardrail`, `quarantine-sandbox-runtime`, `EgressWeave`, or `context-graph-contracts`; mutable sibling PR/branch/package heads therefore remain ineligible production authority. +Protected source는 append-only external-extension lifecycle ledger, CAS/idempotent replay, restart/current projection, complete audit path, SQLite-backed Worker Durable Object binding과 exact stream-scoped `read_operability`를 보유한다. Lifecycle `read_operability`는 `{ database_size_bytes }`만 반환하며 foreign-owner truth나 lifecycle payload를 metrics authority로 복제하지 않는다. -Operational acceptance still requires the actual deployed SQLite Durable Object: realistic current-read and contended-append denominators with evaluator-computed p95 ≤20 ms where synchronous, exactly-one-winner CAS contention, >128-event audit/restart continuity, malformed/truncated state rejection, exact-object storage growth, PITR or equivalent recovery rehearsal, and deployment/release provenance authenticating the producer. Local/workerd timing, namespace storage charts, synthetic evidence and self-asserted JSON do not satisfy that boundary. +Status는 **production activation adapter + deployed operability/recovery/release evidence open**이다. Actual deployed SQLite Durable Object에서 realistic read/contended-append denominator, exactly-one-winner CAS, >128-event continuity, malformed/truncated-state rejection, exact-object storage growth, p95 ≤20 ms where synchronous, PITR/equivalent recovery 및 immutable deployment/release provenance가 필요하다. ## Protected procedural graph advisory source — issue #584 / merged #585 + #586 + #589 + #597 + #601 + #603 -Protected source includes the library-only Agent Runtime procedural graph aggregate, its execution-lifecycle projection, and the workflow-backed current-state ACL. The graph boundary uses strict descriptor-safe input, immutable tenant/task/graph snapshots, canonical content/structure identities, module-local graph/session admission, canonical execution identity, cycle-safe bounded directed context and explicit unknown/budget abstention. Candidate screening accepts only an admitted direct child under exact paired held-out evidence, rejects training/holdout leakage, incomplete/duplicate cases, invalid scores, candidate safety violations and measured mean regression, and retains `activationAuthorized: false` for every decision. `guideProceduralExecution()` projects context only from a locally admitted session when the caller supplies a fresh authenticated same-execution `running` lifecycle snapshot; accepted, cancellation-requested and terminal states suppress guidance. Protected #589 adds a read-only workflow-backed ACL that verifies session/plan execution identity before durable lookup and re-reads the existing Workflow / Task Execution owner before every decision so current cancellation, terminal work and pre-start evidence suppress guidance. Neither adapter becomes a second lifecycle store or approval/activation authority. +Protected source는 immutable bounded procedural graph/session admission, deterministic traversal, explicit abstention, workflow-backed current-state ACL, paired evaluation identity, authenticated signed evaluator handoff, bounded durable evaluation/rejection history, Noema Policy / Approval CAS와 #603 publication preflight를 포함한다. #601 approval/revocation event와 #603 preflight receipt는 모두 `activationAuthorized:false`이며 preflight는 `publicationAuthorized:false`다. ADR 0017도 `Proposed`다. -Protected #591/#592/#593/#594/#596 additionally bind process-local candidate-decision provenance, exact paired evaluation-receipt identities, evaluator/version/policy plus dataset/rubric/model/tool/protocol/validation-plan digests, separately authenticated P-256 signed evaluator handoff, canonical signature transport, bounded validity and rejection/disposition semantics; #595 is the documentation convergence for the signed-handoff classification. The verifier accepts a public key and signer identity chosen by the composition root; it does not discover, store, rotate or administer private signer keys. Protected #597 adds bounded durable evaluation/rejection history under the existing State / Checkpoint boundary, retaining payload-minimized graph/evaluation/authenticated signed-claim identities with monotonic CAS, exact authenticated replay, digest-chain verification, durable rejection projection, duplicate-handoff refusal, restart reconstruction and fail-closed 128-event capacity without silent eviction. This retained history is evidence state, not graph publication, Policy / Approval or activation authority. +Released procedural graph schema는 `context-graph-contracts`, signer trust와 key custody는 Keyverse/owner, provider routing은 `contextual-orchestrator`, product outcome은 consumer product owner가 소유한다. Noema는 실제 graph publication transaction, immutable release, live trust/lifecycle authority와 matched canary evidence 없이 publication/activation을 주장하지 않는다. -Protected #601 adds the distinct Noema Policy / Approval CAS ledger. It consumes the current admitted State / Checkpoint history snapshot plus an independently supplied exact policy decision and binds candidate graph digest, evaluation-history version/head, evaluation envelope, authenticated evaluator handoff, signer key id and expected approval version into an append-only digest chain. `approve_for_pilot` requires the latest history to remain eligible with validation non-regression; explicit `revoke` may bind a newer authenticated non-eligible regression history only from an already approved prior state. Exact replay is idempotent and stale writers lose monotonic approval-version CAS. Every retained approval event/snapshot remains `activationAuthorized:false`; point-in-time approval evidence is not publication or activation authority. +## Protected Workflow / Task operability source — issue #541 / merged PR #605 -Protected #603 adds the Noema Policy / Approval publication preflight. It rereads the admitted current State / Checkpoint history and Policy / Approval snapshots twice, proves that both positions stayed stable across the overlapping read window, rejects a currently revoked approval, and requires the candidate graph, evaluation history, evaluator handoff, signer and approval identities to agree exactly. The process-local admitted preflight receipt remains `publicationAuthorized:false` and `activationAuthorized:false`; it is not a graph publication transaction, lifecycle authority, Keyverse trust selector or activation capability. +PR #605 exact `b4fd8abb77a69847655e04a03fa63a72ea6d56b4`는 application CI `34542741791`, reviewer-ci `34542741784`, required Security Scan `34542741748`, patch-validator-image `34542741760` terminal SUCCESS와 clean exact-head review 뒤 normal merge됐다. Resulting protected merge는 GitHub-verified `98942c88c228c18d44808db1c29bd8f165aa4167`이다. -Noema does not absorb downstream owners to complete this lane. Released procedural graph wire/schema identity belongs to `context-graph-contracts`; enterprise adoption and decision records to `enterprise-architecture-core`; model discovery/routing to `contextual-orchestrator`; credentials and live signer trust selection to Keyverse/owner composition; graph content, evaluation design and production outcome truth to the consuming product. Protected graph/session identity, `eligibleForApproval`, authenticated handoff, retained State / Checkpoint history, a #601 approval snapshot, or a #603 publication preflight receipt are Noema evidence, not tool, lifecycle, publication or activation authority. This source adds no provider SDK/key, second Workflow / Task or lifecycle store, product-domain graph store, HTTP activation route or automatic model refiner. +Protected #605는 기존 execution-scoped `NOEMA_WORKFLOW_STATE` private command surface에 observation-only `read_operability`를 추가한다. Router는 admitted plan에서 canonical object identity를 다시 도출하고 caller-only field를 private transport에서 제거한다. Durable Object는 `DurableWorkflowStateRepository.readState(plan)`으로 retained execution-plan/state authority를 먼저 검증한 뒤에만 `ctx.storage.sql.databaseSize`를 읽어 `{ database_size_bytes }`만 반환한다. Uninitialized/malformed/mismatched retained authority, foreign object routing과 unavailable/throwing/negative/non-integer storage metadata는 fail closed한다. 두 번째 state/metrics store, public route, mutation/retry/recovery authority는 만들지 않는다. -Source integration is complete for #585/#586/#589, #591/#592/#593/#594/#596, #597, #601 and #603; #595 is documentation-only convergence. ADR 0017 remains `Proposed` until immutable released contracts, live Keyverse/owner trust selection, non-workflow current-lifecycle/revocation authority, deployed Workflow / Task, State / Checkpoint history, Policy / Approval and publication-preflight compatibility plus synchronous buyer-path p95/recovery evidence, an actual graph-publication transaction consuming the exact admitted #603 preflight, canary/rollback evidence and product-owner production outcome evidence exist. Canonical documentation must describe that separation without treating historical PR numbers as moving current authority. - -## Protected workflow-backed procedural current-state ACL — merged PR #589 - -Merged #589 adds a read-only Agent Runtime ACL over the existing execution-scoped Workflow / Task Execution Durable Object. Every workflow-backed guidance decision re-admits the plan, verifies that the locally admitted procedural session has the same canonical execution identity before any Durable Object lookup, then reads current workflow state through the existing private `read` command. Exact execution/plan identity, complete unique task identities, allowed task states, cancellation identity and transition sequence are validated before a conservative lifecycle projection reaches the protected running-only procedural gate. Current cancellation, terminal work and pre-start evidence suppress guidance. Cross-execution mismatch is rejected without reading the foreign execution object. - -This protected ACL does not create a second lifecycle database, mutate Workflow / Task Execution state, grant retry/tool/Policy / Approval authority, or turn graph/evaluation data into activation truth. Source integration also does not prove deployed Durable Object compatibility, restart/failure behavior, synchronous p95, non-workflow lifecycle freshness, immutable release, graph publication/promotion, canary/rollback or product outcome. Those remain later acceptance classes under issue #584. +ADR 0013은 `Proposed`다. Source-level exact-object observation은 deployed Durable Object transaction/restart/recovery, representative storage-growth denominator, synchronous-path p95, PITR/rollback 또는 immutable release evidence가 아니다. #541의 다음 acceptance는 exact immutable release/deployment/object/workload/window/retention에 결합된 before/after storage evidence와 실제 transaction/restart/recovery 및 rollback rehearsal이다. ## Evidence and merge rules Review resolution, CI, reviewer-ci, required Security, image/SBOM/provenance, branch ancestry, release는 separate evidence classes다. Every source mutation/restack invalidates predecessor workflow evidence. `queued`, `pending`, `in_progress`, `skipped`, `cancelled`, stale 또는 absent-required evidence는 passing이 아니다. -PR #559 predecessor exact `f4807d71ae815a5d79a08ef35628d72bb4ad34b9`의 application CI `34241457271`, job `102112384672`은 exact checkout, live-base guard, lockfile control, install과 release typecheck를 통과한 뒤 release tests에서 terminal FAILURE였다. 원인은 executable documentation-authority test가 이미 바뀐 baseline의 runtime-current RED 문구와 Web Crypto repair lineage를 따라오지 못한 stale expectation이었다. #559는 feature source를 복사하지 않고 이 baseline과 해당 documentation contract만 ordinary/non-force로 함께 수리했다. #560 integration 뒤에는 protected `main@e3aa77c3f678336c548440f355f988345b0ba976`를 ordinary merge-parent로 받아 reconverge했고, 그 뒤 source mutation은 새 exact-head generation만 merge authority가 된다. 이 문단은 historical repair evidence이며 current writer/current protected-head authority가 아니다. - Normal merge requires unchanged exact head, independently refreshed live base/head, no valid unresolved review finding, applicable required terminal-success gates and no foreign-owner/protected-contract regression. Concurrent commits나 pushes 자체를 race로 단정하지 않는다. Wrong base/conflict, stale ADR, mutable dependency, missing fixture/contract, single-writer 위반은 force push나 destructive rebase가 아니라 ordinary/non-force semantic convergence로 수리한다. PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge 또는 verified successor가 모든 유효 delta/test/fixture/contract/evidence를 완전히 승계한 경우에만 사라진다. Blocked lane은 자기 lane만 막고 unrelated safe review, owner-path repair, docs-to-code repair와 buyer-gap work는 계속한다. @@ -96,17 +68,16 @@ PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge | Priority | Gap | Buyer/operator impact | Current owner | Status | Authoritative completion evidence | Next executable action | | --- | --- | --- | --- | --- | --- | --- | -| P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority가 될 위험 | protected #556 + release/consumer lanes | Source integrated; producer/release/consumer open | protected source + execution/research producer + immutable Noema release + released central consumer corpus RED→GREEN | release/producer evidence를 별도 lane에서 완성 | -| P0 | External extension lifecycle evidence | third-party extension의 stale/revoked authority, process-local lifecycle, forged operability 또는 unbound storage/recovery evidence가 runtime truth로 오인될 위험 | protected #574/#577/#578/#579/#580/#581/#582 + issue #561 | Lifecycle/SQLite DO source integrated; production activation adapter + deployed operability/recovery/release evidence open | immutable source + Noema Policy/Approval + immutable foreign-owner refs + append-only lifecycle/CAS/restart + exact deployed p95/contention/storage/recovery + deployment/release provenance | fail-closed `active`를 유지하고 immutable owner-issued refs가 준비된 뒤 production adapter를 연결한 후 actual deployed #561 acceptance를 실행 | -| P0 | Procedural graph advisory activation boundary | deterministic graph/session/screening, authenticated evaluation, retained history 또는 point-in-time approval/preflight가 durable publication/activation이나 product authority처럼 소비될 위험 | protected #585/#586/#589/#591/#592/#593/#594/#596/#597/#601/#603 + issue #584 | Advisory/runtime/evaluation-auth/history/Policy-Approval CAS/publication-preflight source integrated; publication/activation intentionally unavailable | protected exact source + protected #603 admitted preflight + released `context-graph-contracts` contract + live owner/Keyverse signer trust + current lifecycle/revocation + deployed current-state/history/Policy-Approval/preflight evidence + actual graph publication/canary/rollback + product-owner outcome evidence | publication은 fail-closed로 유지한다. immutable `context-graph-contracts` release, live Keyverse/owner trust, current non-workflow lifecycle/revocation evidence가 준비된 뒤 exact admitted #603 preflight를 소비하는 실제 publication transaction을 test-first로 구현하되 `activationAuthorized:false`를 유지 | -| P0 | Protected-main governance closure | required Security workflow만으로 PR/review/history/deletion/bypass 통제를 증명했다고 오인할 위험 | issue #27 | Open; external control evidence absent | fresh live ruleset + required PR/review/conversation/history/deletion controls + independent bypass/break-glass evidence + protected-source governance receipt | source가 만들 수 없는 organization/admin control은 issue #27에서 독립 검증 | -| P0 | Strict orchestrator/free consumer release | source 통합만으로 immutable consumer activation을 증명할 수 없음 | merged #535 + release lane | Source integrated; release/consumer open | version/tag/package/SBOM/provenance/reproducibility/rollback + released consumer | release-ready protected head에서만 publication | -| P0 | Patch-validator operational publication | source/image CI success만으로 reusable immutable runtime을 증명할 수 없음 | issue #66 | Open; publication evidence absent | protected execution + immutable image/signature/SBOM/provenance/reproducibility/rollback | protected-main operational image receipt 뒤 immutable publication/signing/attestation/activation을 별도 증거로 완성 | -| P0 | Authentic production KPI evidence | fixture·synthetic 또는 source-level KPI 검증이 실제 운영 성능을 대체할 위험 | issue #3 | Open; production window absent | authenticated production-window records + strict provenance + buyer-relevant KPI gate | 실제 production evidence 없이는 readiness를 승격하지 않음 | -| P0 | Acquisition coordination | source/docs 완료를 buyer·legal·transfer readiness로 잘못 승격할 위험 | issue #5 | Open; evidence families incomplete | exact protected revision + applicable release/deployment/operational/buyer/legal evidence family | 남은 evidence family를 owner별로 수렴하고 source claim과 분리 | -| P0 | External Maintainer/Reviewer App identity | source capability-file 계약이 실제 App 설치·키 custody·rotation·권한·reviewer identity를 대체할 위험 | issues #29 / #227 | Open; live identity evidence absent | live installation + key custody/rotation + repository permission + eligible reviewer/publication identity evidence | 외부 App authority는 해당 issue owner에서 독립 검증 | -| P0 | Durable workflow/state production evidence | source Durable Object logic이 실제 deployed transaction/recovery를 증명하지 않음 | merged #542 / ADR 0013 | Source integrated; ADR 0013 Proposed | deployment compatibility + recovery/rollback receipt + immutable release | deployed runtime evidence 확보 전 ADR 0013 `Proposed` 유지 | +| P0 | Exact-claim evidence supply chain | producer evidence 없는 tool/research claim이 reviewer authority가 될 위험 | protected #556 + issue #555 | source integrated; producer/release/consumer open | authenticated producer + immutable Noema release + released central consumer | released contract 전 mutable consumer bump 금지 | +| P0 | External extension lifecycle evidence | stale/revoked foreign authority 또는 local lifecycle source가 production truth로 오인될 위험 | protected #574–#582 + issue #561 | production activation adapter + deployed operability/recovery/release evidence open | immutable owner refs + Noema approval + deployed p95/contention/storage/recovery | immutable owner evidence 준비 뒤 fail-closed adapter 검증 | +| P0 | Procedural graph publication boundary | advisory/evaluation/preflight가 publication/activation으로 오인될 위험 | protected #585/#586/#589/#597/#601/#603 + issue #584 | source integrated; publication/activation unavailable | released graph contract + live signer trust + lifecycle/revocation + deployed evidence + graph publication/canary | prerequisites 전 graph publication fail closed 유지 | +| P0 | Durable workflow/state production evidence | source Durable Object logic·object-size observation이 deployed recovery/SLO로 오인될 위험 | protected #542 + #605 / ADR 0013 / issue #541 | source + exact-object observation integrated; ADR 0013 Proposed | immutable release/deployment + exact-object transaction/restart/recovery + representative storage-growth denominator + p95 + PITR/rollback | approved deployment owner에서 exact protected release 대상으로 runtime/recovery receipt 확보 | +| P0 | Protected-main governance closure | Security workflow 하나로 PR/review/history/deletion/bypass 통제를 과대 주장할 위험 | issue #27 | external control evidence open | live ruleset + PR/review/conversation/history/deletion + bypass evidence | admin/owner control을 독립 검증 | +| P0 | Patch-validator operational publication | PR image CI가 immutable runtime publication으로 오인될 위험 | issue #66 | source/image integrated; publication open | protected-main execution + immutable image/signature/SBOM/provenance/rollback | operational receipt 뒤 publication/signing 검증 | +| P0 | Authentic production KPI evidence | synthetic/source KPI가 실제 운영 성능으로 오인될 위험 | issue #3 | >=30-day production window absent | authenticated production bytes + provenance + strict KPI gate | 실제 production evidence만 수집 | +| P0 | Acquisition coordination | source/docs completion이 buyer/legal/transfer readiness로 오인될 위험 | issue #5 | evidence families incomplete | exact release/deployment/operational/legal evidence | owner별 evidence family 수렴 | +| P0 | External Maintainer/Reviewer App identity | source preflight가 실제 App installation/reviewer authority로 오인될 위험 | issues #29 / #227 | live identity evidence absent | installation/key custody/permission/reviewer eligibility | external control-plane에서 독립 검증 | ## Release boundary -Dated release observation for this repair (2026-09-11 KST)는 GitHub Releases 0건이다. 이 관측은 이후 publication을 영구 부정하는 authority가 아니며 release 판단 직전에 live collection을 다시 읽는다. GitHub release collection에 immutable Noema release가 실제 존재하기 전 version/tag/package/SBOM/provenance/reproducibility/rollback completion을 주장하지 않는다. Release-ready exact protected head에서만 publication하고, consumer는 released/versioned contract만 bump한다. +Dated release observation for this repair (2026-09-11 KST)는 GitHub Releases 0건이다. GitHub release collection에 immutable Noema release가 실제 존재하기 전 version/tag/package/SBOM/provenance/reproducibility/rollback completion을 주장하지 않는다. Release-ready exact protected head에서만 publication하고 consumer는 released/versioned contract만 bump한다. From e24537150a1bff3e812d1ee6b52a585b150e5f22 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 11 Sep 2026 09:11:43 +0900 Subject: [PATCH 3/5] docs(workflow-state): preserve exact historical fixture identity --- docs/product-technical-gap-baseline.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 3d0535815..ebf0681d0 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -32,7 +32,7 @@ PR #560 exact `5aab7c098f3478069127f34e398326415ec599a4`는 application CI `3428 Runtime-current authority RED `4be371ec08b852f4d00829ba5aa6936df6564b5e`는 caller event time을 backdate해 만료된 authority를 행사할 수 있던 경로를 고정했고 production source는 runtime wall clock을 별도 currentness authority로 검증한다. Replay semantic RED `cb8ad638875b761aea70aba78a480bd5031c4d7d`는 동일 invocation identity의 semantic substitution을 고정했고 replay는 complete normalized invocation envelope에 결합됐다. Unbound core-receipt RED `5a50a9bcfe12f3938b30e4a3cb15af8d30134391` 뒤에는 public binding이 없는 retained receipt를 fail closed하도록 수리했고, activation 직전 policy drift/revocation도 다시 읽는다. Invocation에서는 admission-bound live authority substitution을 거부한다. -Exact-admission provenance RED `0a32ee0a88378931a07b7e3b61cc31e3b494a7ab`는 source-admission provenance를 runtime authority에 결합했다. Plaintext replay-retention RED는 reversible request plaintext를 장기 보유하던 경로를 제거했고 Worker Web Crypto `crypto.subtle.digest("SHA-256", ...)`가 digest primitive를 소유한다. Production local hash replacement 뒤 stale fixtures는 `532cfaadf655d3158434db3a985a33ad3a9f`가 아니라 exact historical repair `532cfaadf655d3158434db3a985a33ad3a9f`로 쓰지 않는다; canonical retained historical repair identity는 `532cfaadf655d3158434db3a985a33ad3a9f`와 구분해 Git history에서 검증한다. Current documentation contract가 요구하는 protected historical fixture identity `532cfaadf655d3158434db8a1c3a985a33ad3a9f`는 그대로 보존한다. +Exact-admission provenance RED `0a32ee0a88378931a07b7e3b61cc31e3b494a7ab`는 source-admission provenance를 runtime authority에 결합했다. Plaintext replay-retention RED는 reversible request plaintext를 장기 보유하던 경로를 제거했고 Worker Web Crypto `crypto.subtle.digest("SHA-256", ...)`가 digest primitive를 소유한다. Hosted application CI `34230994573`에서 드러난 stale fixture 수리는 `532cfaadf655d3158434db8a1c3a985a33ad3a9f`를 포함한 historical Git lineage에 남아 있다. Protected source는 durable append-only lifecycle evidence의 prerequisite일 뿐이며 mutable `context-graph-contracts` branch/PR/package를 production authority로 소비하지 않는다. 외부 marketplace metadata만으로 live plugin installation 또는 buyer completion을 주장하지 않는다. Release/deployment/legal evidence도 별도다. From c8f29474a1fb4bde2ee576844370fee525d2bdee Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 11 Sep 2026 09:14:46 +0900 Subject: [PATCH 4/5] docs(doctoring): preserve pre-convergence gap history --- ...technical-gap-baseline-history-20260911.md | 112 ++++++++++++++++++ 1 file changed, 112 insertions(+) create mode 100644 docs/doctoring/product-technical-gap-baseline-history-20260911.md diff --git a/docs/doctoring/product-technical-gap-baseline-history-20260911.md b/docs/doctoring/product-technical-gap-baseline-history-20260911.md new file mode 100644 index 000000000..b8e01a29b --- /dev/null +++ b/docs/doctoring/product-technical-gap-baseline-history-20260911.md @@ -0,0 +1,112 @@ +# Noema Product and Technical Gap Baseline + +## Authority and update rule + +이 문서는 protected source, active candidate, transient workflow evidence와 foreign-owner authority를 분리한다. Open PR exact head, protected base, required workflow, review thread, release와 central dependency는 mutation·merge·release 직전에 다시 읽는다. predecessor GREEN, queued/pending/in-progress/skipped/cancelled run, 오래된 PR base snapshot과 scanner/model judgement는 다음 revision의 merge authority로 전용하지 않는다. queued는 GREEN이 아니다. + +Current protected source는 mutation·merge·release 시점에 live protected `main`을 다시 조회해 결정한다. 이 문서 안의 exact source SHA는 dated observation 또는 protected history일 뿐 future merge 뒤 evergreen current authority로 사용하지 않는다. Dated protected observation for this repair는 `main@70c997e45db975a2ac43197ec2c49c9916a3e238`이며, 이 revision은 merged PR #582 exact `0f20a4dc78e423fd5df49e137a4eb286c7075ea4`의 exact stream-scoped SQLite storage observation primitive, merged #583의 live-authority/ADR-index repair, protected procedural graph source #585/#586, merged #587의 source-vs-rollout doctoring repair, merged #588/#590/#595의 documentation convergence, merged #589의 workflow-backed current-state ACL, #591/#592/#593/#594/#596의 procedural decision/evaluation/authenticated-handoff source, #597의 State / Checkpoint history source, #601의 Noema Policy / Approval CAS source, 그리고 #603의 protected publication preflight source를 포함한다. + +Dated central control-plane observation for this repair는 central `.github/main@cb0872c9a20d5584703dffacca65c096fc034c6c`다. Noema runtime의 reviewed immutable central consumer pin은 `c9052e607e5f3cc76e73207e7786b21500721b79`이고 runtime authority 표현은 `ALLOWED_WORKFLOW_SHA = c9052e607e5f3cc76e73207e7786b21500721b79`다. Moving foreign head와 reviewed immutable pin을 같은 권위로 취급하지 않으며 central moving head가 전진했다고 consumer pin을 자동 승격하지 않는다. + +Protected history에는 merged PR #535 exact `82b20b293f0a5f0ac0e69857c1b61dddfe478491`, merged PR #540 exact `05bc2d47c3899ebe17538070f9a30172f90307ac`, merged PR #542 exact `ca839298fcaeec409091dc909789b6f87eb67fdc`, merged PR #547 exact `30b7e7e5cdab8de65715834a16f994b2047eafa6`, merged PR #550 exact `f2ec2dc6709814070cc3e3d6932ce280aee966db`, merged PR #553 exact `3bd9f543e97ce856f78b1c608141436298ce9e74`, merged PR #558 exact `2f91bf8641212ecae435b5fbcc9084cc0acd6295`, merged PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`, merged PR #560 exact `5aab7c098f3478069127f34e398326415ec599a4`와 이후 external-extension lifecycle/operability source integrations #574, #577, #578, #579, #580, #581, #582, documentation-authority integration #583, procedural graph source integrations #585/#586, doctoring/canonical-documentation integrations #587/#588/#590/#595, workflow-backed current-state integration #589, procedural decision/evaluation/authentication integrations #591/#592/#593/#594/#596, State / Checkpoint history integration #597, Policy / Approval CAS integration #601, publication-preflight integration #603이 포함돼 있다. 이 식별자는 역사 증거이지 open-candidate authority가 아니다. + +이 baseline과 executable documentation-authority test는 active documentation-authority lane 하나만 write한다. mutation 직전 open PR/Issue/branch를 fresh-read해 writer를 결정하며 merged/closed historical PR 번호를 active sole writer로 고정하지 않는다. 다른 feature lane의 과거 baseline blob은 ordinary/non-force semantic convergence 때 current authority로 승계하지 않는다. + +## Canonical product boundary + +Noema Core Domain은 Agent Runtime과 Workflow / Task Execution이다. Tool / Capability Boundary, State / Checkpoint, Isolation Integration, Policy / Approval, Observability, Recovery는 명시적 bounded context다. Execution identity, side-effect authority, claim/checkpoint CAS, cancellation/recovery invariant와 Noema-owned product/role/time approval issuance는 Noema 경계에 남긴다. + +`contextual-orchestrator`는 provider/model discovery, routing, retry/failover, test-time compute와 provider credential을 소유한다. Noema는 released gateway contract와 canonical `orchestrator/free` alias를 소비하며 direct provider SDK, provider key, provider/model/group fallback policy를 소유하지 않는다. `.github`는 organization reusable workflow/control-plane source다. Keyverse는 identity backend다. `quarantine-sandbox-runtime`, Wardnet, EgressWeave, AppGuardrail은 각자의 isolation/security/outbound/scanning truth를 소유한다. Noema는 그 owner evidence를 reference/pin으로 소비할 뿐 foreign implementation이나 domain table을 복제하지 않는다. Cross-service SQL과 mutable sibling PR dependency는 금지한다. + +Baseline의 요구·설계·데이터·경계 authority는 `docs/PRD.md`, `docs/TRD.md`, `docs/UML.md`, `docs/ERD.md`, `docs/CONTEXT_MAP.md`다. 이 register는 그 문서와 ADR을 대체하지 않고 current Gap/Action/Status를 exact source·PR·workflow evidence에 결합한다. ADR 0015는 protected source에 포함됐지만 상태는 `Proposed`이며 production activation-authority integration, deployed lifecycle operability/recovery evidence, immutable shared-contract consumption, live pilot와 release evidence가 남아 있다. ADR 0017도 `Proposed`다. Protected #585/#586은 bounded Noema Agent Runtime advisory graph/session mechanics, deterministic direct-child screening, caller-supplied fresh authenticated lifecycle snapshot에 대한 running-only projection을 구현했다. Protected #589는 workflow-backed execution에 한해 기존 execution-scoped Workflow / Task Execution Durable Object를 매 guidance decision 전에 다시 읽고, locally admitted session과 re-admitted plan의 execution identity를 durable lookup 전에 검증하는 current-state ACL을 추가했다. Protected #591/#592/#593/#594/#596은 candidate-decision provenance, exact paired evaluation-receipt identity, evaluation-envelope binding, separately authenticated signed evaluator handoff와 rejection/disposition binding을 구현했고 #595는 그 signed-handoff 상태를 canonical TRACEABILITY에 수렴시킨 documentation integration이다. Protected #597은 기존 State / Checkpoint 경계 아래 bounded durable evaluation/rejection history를 추가했다. Protected #601은 이 history의 exact current position과 independently supplied policy decision을 결합해 append-only digest-linked approval/revocation events를 기록하는 별도 Noema Policy / Approval CAS ledger를 추가했다. `approve_for_pilot`과 `revoke`는 monotonic approval-version CAS 및 exact replay semantics를 갖지만 모든 event/snapshot은 `activationAuthorized:false`다. Protected #603은 현재 State / Checkpoint와 Policy / Approval을 안정적인 double-read window에서 다시 읽고, moving authority와 current revocation을 실패-폐쇄하며 exact graph/history/evaluator/signer/approval identity 일치를 요구하는 Noema Policy / Approval publication preflight를 추가했다. 이 preflight receipt는 `publicationAuthorized:false`와 `activationAuthorized:false`를 유지한다. Non-workflow lifecycle freshness, released wire contracts, live Keyverse/owner signer trust selection, deployed Durable Object compatibility/p95/recovery, 실제 graph publication transaction, canary/rollback과 product-outcome authority는 여전히 별도다. + +## Integrated exact-claim evidence — issue #555 / merged PR #556 + +PR #556 exact `860714cba46dba06260a5dce09d0e9152fcb0a8c`는 unchanged exact-head application CI `34197596549`, reviewer-ci `34197596588`, required Security Scan `34197596536`, patch-validator-image `34197596517` terminal SUCCESS와 clean review authority를 충족한 뒤 normal merge됐다. Resulting protected merge는 GitHub-verified `36e5cf957ee20a8bb3e19ff50fea6c97771d2ba1`이다. + +Protected source는 raw source receipt를 context authority로만 취급하고, `ClaimEvidenceRequirement`와 producer-authenticated receipt의 kind/identity/coordinates/digest가 일치해야 finding/publication authority가 되도록 한다. `produce_source_claim_receipt()`는 exactly-one-line UTF-8 source bytes와 claim equality를 요구하며 paraphrase, embedded multiline, invalid UTF-8을 거부한다. Model `request_changes`/`blocked`는 producer-authenticated finding 없이 publication될 수 없다. Source integration은 execution stdout/stderr producer, research producer, immutable release, released central consumer까지 자동으로 증명하지 않는다. + +## Integrated external-extension admission — issue #545 / merged PR #560 + +PR #560 exact `5aab7c098f3478069127f34e398326415ec599a4`는 unchanged exact-head application CI `34289599257`, reviewer-ci `34289599291`, required Security Scan `34289599289`, patch-validator-image `34289599248` terminal SUCCESS와 fresh clean review authority를 충족한 뒤 normal merge됐다. Resulting protected merge는 GitHub-verified `e3aa77c3f678336c548440f355f988345b0ba976`다. Historical #559 documentation work later converged from that protected source through ordinary/non-force history without transferring predecessor GREEN. + +Earlier Policy / Approval RED `7ca9aebee6f92053913c0bbc665c8de77650891f`의 hosted application CI `34206149899`, job `101995980303`은 valid catalog/AppGuardrail/quarantine evidence만으로 descriptor가 active/product/role grant를 self-broaden할 수 없음을 고정했다. Subsequent production source separates source/catalog/scanner authority from Noema Policy / Approval issuance, keeps the source-issued grant at a pilot ceiling, seals admission/activation/receipt provenance, revalidates the full six-field catalog identity and live scanner receipts, and rejects impossible pre-activation invocation chronology. + +Fresh hostile-input RED `f30f67328efbcd0b8bed7ac89f7c64c40528ea44` / hosted application CI `34218780676`, job `102036728526` proved that a revoked descriptor-list Proxy could leak a raw JavaScript exception through public admission. Production `802b0bff0f32c170ada328b04e87e0db43ee7cd4` normalized that public boundary without weakening descriptor/list/capability validation. + +Runtime-current authority RED `4be371ec08b852f4d00829ba5aa6936df6564b5e`의 Hosted application CI `34221586992`, job `102045717213`은 caller event timestamp를 backdate해 실제 만료 뒤 권한을 계속 행사할 수 있던 결함을 재현했다. Production `2b50b35b7bdbb834f571dfcae50dceb05766244c`는 activation/invocation 때 Noema runtime wall clock이 descriptor와 독립 Policy / Approval validity window 모두 안에 있도록 요구한다. `83e3130f1894e879769e014c76e28ffc982a2063`은 pre-window edge를 고정했고 `f8703e6628961d380df59e4e90b600ebad215c11`은 ADR 0015에 event-time과 current-time authority를 분리했다. + +Replay semantic RED `cb8ad638875b761aea70aba78a480bd5031c4d7d`는 동일 invocation identity가 다른 instruction/observed-content semantics를 요청해도 retained receipt가 허용하던 결함을 증명했다. Production `9c7ae13f7053fa368fd778c3909c4428d1bdf28e`는 replay를 complete normalized invocation envelope에 결합했다. Refactor `03c2a6949a858043c6f7412a9ee724de63deaae2` 뒤 vacuous해진 core-conflict oracle은 `83ee8e9b54be7ea59cfa11fe03e4ad0c6414950c`에서 direct core coverage로 복구됐다. + +Unbound core-receipt RED `5a50a9bcfe12f3938b30e4a3cb15af8d30134391`는 internal core가 발행한 authentic receipt가 public wrapper의 invocation-envelope authority 없이 넘어갈 수 있음을 증명했다. Production `cbb64def35bad02024076c1db74e9da4739ae736`은 public binding이 없는 retained receipt를 fail closed한다. Activation-time revocation RED `8ff77d9b6428a2c09f2c72bf3b05fdb989e35843`와 production `8251d4bcd2c81dd13d252a576b55dc21e66db9c4`는 admission 뒤 policy drift/revocation을 새 activation 발행 전에 다시 읽도록 했다. + +Invocation-authority substitution RED `abcd1fea4b28b826826fed6b23296b59ceda98ca`는 structurally compatible caller-supplied authority가 admission-bound live authority를 대체할 수 있음을 증명했다. Production `f8814b8fd7b66f40335df85c6aadab12aa760bc1`는 invocation에 admission 당시 결합한 동일 authority instance를 요구한다. `1acbf2f464cbfb0c5ad6e3991ecc9b04f17fb895`는 same-authority catalog/scan drift를 유지했고 `feed68db0ac0404607a292ed2686bf47e5e2be22`는 운영/rollback owner 경계를 갱신했다. Hosted application CI `34230994573`, job `102076920357`이 4,190 passed / 10 failed로 드러낸 stale fixture는 `532cfaadf655d3158434db8a1c3a985a33ad3a9f`, `ab2baeda9665df96753a03f1242455efe0662e41`, `273aa711d1c7611fadab9346944891548b30919a`에서 same-authority intent를 유지하면서 mutable test cache를 제거했다. + +Exact-admission provenance RED `0a32ee0a88378931a07b7e3b61cc31e3b494a7ab`는 source admission A에서 발행한 authentic activation이 동일 trusted authority가 source B로 이동한 뒤에도 artifact/product/role/policy/time이 맞으면 B를 authorize할 수 있던 결함을 재현했다. Hosted application CI `34235691056`, job `102092675348`은 exact checkout/live-base/lockfile control, install/release typecheck 뒤 release tests에서 실패했다. Test-only `49115306b4abf7656f7fd136de8a3ff0c5a1968b`은 retained activation replay와 public invocation-receipt replay까지 확장했다. Canonical production `225a04ec2c833e9068e79ad7b70f3f5d8f6d934a`는 core의 activation/receipt provenance를 process-global set에서 exact `AdmittedExternalExtension`-bound map으로 옮겼고, `2e843825cc31a316a5834db3d355e8e4a18ca028`은 public wrapper에 잠시 중복됐던 binding kernel을 제거해 exact-admission activation/receipt authority를 core 한 곳에 남겼다. 같은 conformance invariant는 `context-graph-contracts#27`에 foreign-owner requirement로 넘겼고 mutable issue/branch를 Noema runtime dependency로 소비하지 않는다. + +Plaintext replay-retention RED `3f41d94af1454926b65b1801004fe245098742b0`는 public replay WeakMap이 reversible `JSON.stringify(normalizedRequest)`를 receipt lifetime 동안 보유해 instruction, observed content, rejected secret/product/hidden-reasoning inputs의 수명을 불필요하게 늘리던 결함을 고정했다. Hosted application CI `34237704683`, job `102099615873`은 exact checkout/live-base/lockfile control, install/release typecheck 뒤 release tests에서 실패했다. Production `79182c7be196c42fb94450cae9a7857ae67b5434`는 retained replay identity를 versioned/domain-separated SHA-256 digest로 바꾸고 every semantic field, key-order independence, fixed-width/no-plaintext regression을 추가했다. ADR `ac6b6c088f034a8778bdc8a859f7157223883b8d`는 process-local WeakMap lifetime, restart fail-closed, explicit digest-version migration과 FIPS 180-4 authority를 기록하며 `Proposed`를 유지한다. + +그 뒤 live security finding `5586918828`은 repository-owned TypeScript SHA-256 padding/schedule/rounds가 Tool / Capability bounded context에 불필요한 security-critical primitive ownership을 추가한다는 결함을 분리했다. Test-only `b50b43065098609118991e0b0b0b4936725c2899`은 platform `crypto.subtle.digest` 또는 independently maintained/audited exact-pinned provider를 요구하고 local `SHA256_INITIAL`, `SHA256_ROUND`, `sha256Hex` ownership을 금지했다. Hosted application CI `34240985563`, job `102111324942`은 exact checkout, live-base guard, lockfile control, install과 release typecheck를 통과한 뒤 release tests에서 terminal FAILURE가 되어 reality RED를 확정했다. 같은 generation의 reviewer-ci `34240985515`와 required Security Scan `34240985513`은 SUCCESS였고 image `34240985555`는 successor generation 때문에 CANCELLED되어 GREEN으로 전용하지 않는다. + +Production `80292ed53943c61aa9d282ed18024b0f98f4cb1f`는 home-grown hash primitive를 제거하고 replay digest를 Worker Web Crypto `crypto.subtle.digest("SHA-256", ...)`에 위임했다. `396514c8f5183324e6c8d0a16d7a5d339b2cbb72`는 digest가 성공하기 전 accepted receipt를 public authority로 publish하지 않도록 success/replay path를 비동기로 만들고 digest-provider failure를 fail closed한다. `d1af4d703bd4c67b8be26d0c105d2a4ed0d4575a`는 standard SHA-256 short/padding-boundary/multi-block/long-message vectors를, `210bc59b17933b908aa20b1de1a160b07672b687`, `90bf018cbb2ea803adb02cd8e98010288f2c8201`, `a220003532901350b1ac9fc81079c7145dbf2b6f`, `26634f181f9c29e875bdd57ab5bc046b109fd91b`는 affected replay/invocation/policy tests가 async publication contract를 실제로 await하도록 수렴시켰다. ADR `62d4ea3f6a7227e66b072e914a0711587ad22279`는 SHA-256 primitive ownership을 Worker runtime에 두고 Noema가 domain/version canonicalization, replay-state lifecycle과 fail-closed interpretation만 소유하도록 기록하며 ADR 0015는 계속 `Proposed`다. + +Final #560 source generation `5aab7c098f3478069127f34e398326415ec599a4`는 all-four terminal SUCCESS를 충족했고 clean review 뒤 normal merge됐다. Source integration은 local fail-closed admission contract를 protected history로 승격하지만 durable append-only lifecycle evidence, immutable shared contract, AppGuardrail/quarantine/EgressWeave live operation, production pilot, release와 buyer completion까지 자동으로 증명하지 않는다. + +AppGuardrail/quarantine receipts는 scanner/provenance evidence이지 Noema approval이 아니다. EgressWeave/quarantine references는 outbound/isolation operation의 대체물이 아니다. Anthropic marketplace review는 discovery evidence이지 CWL product authority가 아니다. `context-graph-contracts#27`이 immutable shared external-capability contract를 release하기 전까지 이 local port는 fail-closed ACL/test double이며 live plugin installation 또는 buyer completion을 주장하지 않는다. `context-graph-contracts#27`과 `appguardrail#1099`의 owner evidence를 Noema가 합성하지 않는다. + +## Protected external-extension lifecycle persistence and operability — issue #561 / merged PRs #574–#582 + +Protected source now carries the append-only external-extension lifecycle ledger, CAS/idempotent replay, restart/current projection and complete audit path; executable operability and deployment/provenance evidence contracts; descriptor-safe retained-byte digest authority; the SQLite-backed Worker Durable Object binding `NOEMA_EXTERNAL_EXTENSION_LIFECYCLE` → `NoemaExternalExtensionLifecycle`; code-current lifecycle recovery/context-map documentation; and merged #582's private `read_operability` command. `read_operability` derives the same exact stream-scoped object identity as lifecycle reads and returns only `{ database_size_bytes }` from `ctx.storage.sql.databaseSize`; object substitution and non-canonical counters fail closed. Lifecycle event payloads, secrets, provider routing and foreign-owner truth are not exported through that path. + +This source chain does not complete #561. A genuinely new `active` transition remains fail-closed until a reviewed production adapter can re-read current Noema Policy / Approval plus immutable owner-issued AppGuardrail/quarantine/isolation/Egress evidence without copying those owners' truth into Noema. Dated dependency inventory on 2026-09-10 KST found no GitHub Releases in `appguardrail`, `quarantine-sandbox-runtime`, `EgressWeave`, or `context-graph-contracts`; mutable sibling PR/branch/package heads therefore remain ineligible production authority. + +Operational acceptance still requires the actual deployed SQLite Durable Object: realistic current-read and contended-append denominators with evaluator-computed p95 ≤20 ms where synchronous, exactly-one-winner CAS contention, >128-event audit/restart continuity, malformed/truncated state rejection, exact-object storage growth, PITR or equivalent recovery rehearsal, and deployment/release provenance authenticating the producer. Local/workerd timing, namespace storage charts, synthetic evidence and self-asserted JSON do not satisfy that boundary. + +## Protected procedural graph advisory source — issue #584 / merged #585 + #586 + #589 + #597 + #601 + #603 + +Protected source includes the library-only Agent Runtime procedural graph aggregate, its execution-lifecycle projection, and the workflow-backed current-state ACL. The graph boundary uses strict descriptor-safe input, immutable tenant/task/graph snapshots, canonical content/structure identities, module-local graph/session admission, canonical execution identity, cycle-safe bounded directed context and explicit unknown/budget abstention. Candidate screening accepts only an admitted direct child under exact paired held-out evidence, rejects training/holdout leakage, incomplete/duplicate cases, invalid scores, candidate safety violations and measured mean regression, and retains `activationAuthorized: false` for every decision. `guideProceduralExecution()` projects context only from a locally admitted session when the caller supplies a fresh authenticated same-execution `running` lifecycle snapshot; accepted, cancellation-requested and terminal states suppress guidance. Protected #589 adds a read-only workflow-backed ACL that verifies session/plan execution identity before durable lookup and re-reads the existing Workflow / Task Execution owner before every decision so current cancellation, terminal work and pre-start evidence suppress guidance. Neither adapter becomes a second lifecycle store or approval/activation authority. + +Protected #591/#592/#593/#594/#596 additionally bind process-local candidate-decision provenance, exact paired evaluation-receipt identities, evaluator/version/policy plus dataset/rubric/model/tool/protocol/validation-plan digests, separately authenticated P-256 signed evaluator handoff, canonical signature transport, bounded validity and rejection/disposition semantics; #595 is the documentation convergence for the signed-handoff classification. The verifier accepts a public key and signer identity chosen by the composition root; it does not discover, store, rotate or administer private signer keys. Protected #597 adds bounded durable evaluation/rejection history under the existing State / Checkpoint boundary, retaining payload-minimized graph/evaluation/authenticated signed-claim identities with monotonic CAS, exact authenticated replay, digest-chain verification, durable rejection projection, duplicate-handoff refusal, restart reconstruction and fail-closed 128-event capacity without silent eviction. This retained history is evidence state, not graph publication, Policy / Approval or activation authority. + +Protected #601 adds the distinct Noema Policy / Approval CAS ledger. It consumes the current admitted State / Checkpoint history snapshot plus an independently supplied exact policy decision and binds candidate graph digest, evaluation-history version/head, evaluation envelope, authenticated evaluator handoff, signer key id and expected approval version into an append-only digest chain. `approve_for_pilot` requires the latest history to remain eligible with validation non-regression; explicit `revoke` may bind a newer authenticated non-eligible regression history only from an already approved prior state. Exact replay is idempotent and stale writers lose monotonic approval-version CAS. Every retained approval event/snapshot remains `activationAuthorized:false`; point-in-time approval evidence is not publication or activation authority. + +Protected #603 adds the Noema Policy / Approval publication preflight. It rereads the admitted current State / Checkpoint history and Policy / Approval snapshots twice, proves that both positions stayed stable across the overlapping read window, rejects a currently revoked approval, and requires the candidate graph, evaluation history, evaluator handoff, signer and approval identities to agree exactly. The process-local admitted preflight receipt remains `publicationAuthorized:false` and `activationAuthorized:false`; it is not a graph publication transaction, lifecycle authority, Keyverse trust selector or activation capability. + +Noema does not absorb downstream owners to complete this lane. Released procedural graph wire/schema identity belongs to `context-graph-contracts`; enterprise adoption and decision records to `enterprise-architecture-core`; model discovery/routing to `contextual-orchestrator`; credentials and live signer trust selection to Keyverse/owner composition; graph content, evaluation design and production outcome truth to the consuming product. Protected graph/session identity, `eligibleForApproval`, authenticated handoff, retained State / Checkpoint history, a #601 approval snapshot, or a #603 publication preflight receipt are Noema evidence, not tool, lifecycle, publication or activation authority. This source adds no provider SDK/key, second Workflow / Task or lifecycle store, product-domain graph store, HTTP activation route or automatic model refiner. + +Source integration is complete for #585/#586/#589, #591/#592/#593/#594/#596, #597, #601 and #603; #595 is documentation-only convergence. ADR 0017 remains `Proposed` until immutable released contracts, live Keyverse/owner trust selection, non-workflow current-lifecycle/revocation authority, deployed Workflow / Task, State / Checkpoint history, Policy / Approval and publication-preflight compatibility plus synchronous buyer-path p95/recovery evidence, an actual graph-publication transaction consuming the exact admitted #603 preflight, canary/rollback evidence and product-owner production outcome evidence exist. Canonical documentation must describe that separation without treating historical PR numbers as moving current authority. + +## Protected workflow-backed procedural current-state ACL — merged PR #589 + +Merged #589 adds a read-only Agent Runtime ACL over the existing execution-scoped Workflow / Task Execution Durable Object. Every workflow-backed guidance decision re-admits the plan, verifies that the locally admitted procedural session has the same canonical execution identity before any Durable Object lookup, then reads current workflow state through the existing private `read` command. Exact execution/plan identity, complete unique task identities, allowed task states, cancellation identity and transition sequence are validated before a conservative lifecycle projection reaches the protected running-only procedural gate. Current cancellation, terminal work and pre-start evidence suppress guidance. Cross-execution mismatch is rejected without reading the foreign execution object. + +This protected ACL does not create a second lifecycle database, mutate Workflow / Task Execution state, grant retry/tool/Policy / Approval authority, or turn graph/evaluation data into activation truth. Source integration also does not prove deployed Durable Object compatibility, restart/failure behavior, synchronous p95, non-workflow lifecycle freshness, immutable release, graph publication/promotion, canary/rollback or product outcome. Those remain later acceptance classes under issue #584. + +## Evidence and merge rules + +Review resolution, CI, reviewer-ci, required Security, image/SBOM/provenance, branch ancestry, release는 separate evidence classes다. Every source mutation/restack invalidates predecessor workflow evidence. `queued`, `pending`, `in_progress`, `skipped`, `cancelled`, stale 또는 absent-required evidence는 passing이 아니다. + +PR #559 predecessor exact `f4807d71ae815a5d79a08ef35628d72bb4ad34b9`의 application CI `34241457271`, job `102112384672`은 exact checkout, live-base guard, lockfile control, install과 release typecheck를 통과한 뒤 release tests에서 terminal FAILURE였다. 원인은 executable documentation-authority test가 이미 바뀐 baseline의 runtime-current RED 문구와 Web Crypto repair lineage를 따라오지 못한 stale expectation이었다. #559는 feature source를 복사하지 않고 이 baseline과 해당 documentation contract만 ordinary/non-force로 함께 수리했다. #560 integration 뒤에는 protected `main@e3aa77c3f678336c548440f355f988345b0ba976`를 ordinary merge-parent로 받아 reconverge했고, 그 뒤 source mutation은 새 exact-head generation만 merge authority가 된다. 이 문단은 historical repair evidence이며 current writer/current protected-head authority가 아니다. + +Normal merge requires unchanged exact head, independently refreshed live base/head, no valid unresolved review finding, applicable required terminal-success gates and no foreign-owner/protected-contract regression. Concurrent commits나 pushes 자체를 race로 단정하지 않는다. Wrong base/conflict, stale ADR, mutable dependency, missing fixture/contract, single-writer 위반은 force push나 destructive rebase가 아니라 ordinary/non-force semantic convergence로 수리한다. + +PR 0은 useful work를 닫아 제조하지 않는다. Open lane은 normal merge 또는 verified successor가 모든 유효 delta/test/fixture/contract/evidence를 완전히 승계한 경우에만 사라진다. Blocked lane은 자기 lane만 막고 unrelated safe review, owner-path repair, docs-to-code repair와 buyer-gap work는 계속한다. + +## Commercial gap register + +| Priority | Gap | Buyer/operator impact | Current owner | Status | Authoritative completion evidence | Next executable action | +| --- | --- | --- | --- | --- | --- | --- | +| P0 | Exact-claim evidence supply chain | Tool/research claim이 producer evidence 없이 reviewer authority가 될 위험 | protected #556 + release/consumer lanes | Source integrated; producer/release/consumer open | protected source + execution/research producer + immutable Noema release + released central consumer corpus RED→GREEN | release/producer evidence를 별도 lane에서 완성 | +| P0 | External extension lifecycle evidence | third-party extension의 stale/revoked authority, process-local lifecycle, forged operability 또는 unbound storage/recovery evidence가 runtime truth로 오인될 위험 | protected #574/#577/#578/#579/#580/#581/#582 + issue #561 | Lifecycle/SQLite DO source integrated; production activation adapter + deployed operability/recovery/release evidence open | immutable source + Noema Policy/Approval + immutable foreign-owner refs + append-only lifecycle/CAS/restart + exact deployed p95/contention/storage/recovery + deployment/release provenance | fail-closed `active`를 유지하고 immutable owner-issued refs가 준비된 뒤 production adapter를 연결한 후 actual deployed #561 acceptance를 실행 | +| P0 | Procedural graph advisory activation boundary | deterministic graph/session/screening, authenticated evaluation, retained history 또는 point-in-time approval/preflight가 durable publication/activation이나 product authority처럼 소비될 위험 | protected #585/#586/#589/#591/#592/#593/#594/#596/#597/#601/#603 + issue #584 | Advisory/runtime/evaluation-auth/history/Policy-Approval CAS/publication-preflight source integrated; publication/activation intentionally unavailable | protected exact source + protected #603 admitted preflight + released `context-graph-contracts` contract + live owner/Keyverse signer trust + current lifecycle/revocation + deployed current-state/history/Policy-Approval/preflight evidence + actual graph publication/canary/rollback + product-owner outcome evidence | publication은 fail-closed로 유지한다. immutable `context-graph-contracts` release, live Keyverse/owner trust, current non-workflow lifecycle/revocation evidence가 준비된 뒤 exact admitted #603 preflight를 소비하는 실제 publication transaction을 test-first로 구현하되 `activationAuthorized:false`를 유지 | +| P0 | Protected-main governance closure | required Security workflow만으로 PR/review/history/deletion/bypass 통제를 증명했다고 오인할 위험 | issue #27 | Open; external control evidence absent | fresh live ruleset + required PR/review/conversation/history/deletion controls + independent bypass/break-glass evidence + protected-source governance receipt | source가 만들 수 없는 organization/admin control은 issue #27에서 독립 검증 | +| P0 | Strict orchestrator/free consumer release | source 통합만으로 immutable consumer activation을 증명할 수 없음 | merged #535 + release lane | Source integrated; release/consumer open | version/tag/package/SBOM/provenance/reproducibility/rollback + released consumer | release-ready protected head에서만 publication | +| P0 | Patch-validator operational publication | source/image CI success만으로 reusable immutable runtime을 증명할 수 없음 | issue #66 | Open; publication evidence absent | protected execution + immutable image/signature/SBOM/provenance/reproducibility/rollback | protected-main operational image receipt 뒤 immutable publication/signing/attestation/activation을 별도 증거로 완성 | +| P0 | Authentic production KPI evidence | fixture·synthetic 또는 source-level KPI 검증이 실제 운영 성능을 대체할 위험 | issue #3 | Open; production window absent | authenticated production-window records + strict provenance + buyer-relevant KPI gate | 실제 production evidence 없이는 readiness를 승격하지 않음 | +| P0 | Acquisition coordination | source/docs 완료를 buyer·legal·transfer readiness로 잘못 승격할 위험 | issue #5 | Open; evidence families incomplete | exact protected revision + applicable release/deployment/operational/buyer/legal evidence family | 남은 evidence family를 owner별로 수렴하고 source claim과 분리 | +| P0 | External Maintainer/Reviewer App identity | source capability-file 계약이 실제 App 설치·키 custody·rotation·권한·reviewer identity를 대체할 위험 | issues #29 / #227 | Open; live identity evidence absent | live installation + key custody/rotation + repository permission + eligible reviewer/publication identity evidence | 외부 App authority는 해당 issue owner에서 독립 검증 | +| P0 | Durable workflow/state production evidence | source Durable Object logic이 실제 deployed transaction/recovery를 증명하지 않음 | merged #542 / ADR 0013 | Source integrated; ADR 0013 Proposed | deployment compatibility + recovery/rollback receipt + immutable release | deployed runtime evidence 확보 전 ADR 0013 `Proposed` 유지 | + +## Release boundary + +Dated release observation for this repair (2026-09-11 KST)는 GitHub Releases 0건이다. 이 관측은 이후 publication을 영구 부정하는 authority가 아니며 release 판단 직전에 live collection을 다시 읽는다. GitHub release collection에 immutable Noema release가 실제 존재하기 전 version/tag/package/SBOM/provenance/reproducibility/rollback completion을 주장하지 않는다. Release-ready exact protected head에서만 publication하고, consumer는 released/versioned contract만 bump한다. From 6ad29763934e93051371f1e722bb0c233d2659c3 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 11 Sep 2026 10:06:01 +0900 Subject: [PATCH 5/5] test(docs): bind operability field to response shape --- test/documentation-workflow-state-operability-protected.test.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/test/documentation-workflow-state-operability-protected.test.ts b/test/documentation-workflow-state-operability-protected.test.ts index 5c9746709..e9b937682 100644 --- a/test/documentation-workflow-state-operability-protected.test.ts +++ b/test/documentation-workflow-state-operability-protected.test.ts @@ -15,7 +15,7 @@ describe("protected Workflow / Task operability documentation authority", () => "Resulting protected merge는 GitHub-verified `98942c88c228c18d44808db1c29bd8f165aa4167`", ); expect(baseline).toContain("`read_operability`"); - expect(baseline).toContain("`database_size_bytes`"); + expect(baseline).toContain("`{ database_size_bytes }`"); expect(baseline).toContain("ADR 0013은 `Proposed`"); expect(baseline).toContain( "Source-level exact-object observation은 deployed Durable Object transaction/restart/recovery, representative storage-growth denominator, synchronous-path p95, PITR/rollback 또는 immutable release evidence가 아니다.",