Skip to content

docs: establish live product and technical gap baseline - #1163

Open
seonghobae wants to merge 89 commits into
mainfrom
docs/product-technical-gap-baseline-20260820
Open

docs: establish live product and technical gap baseline#1163
seonghobae wants to merge 89 commits into
mainfrom
docs/product-technical-gap-baseline-20260820

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

Purpose

Create the buyer-facing product and technical gap baseline that turns current evidence into reviewable, stackable work for the naruon ecosystem and central .github control plane.

Exact current identity

  • source head: 7a2a51e560adc2e1f2f7020702fdc5802ca62b58;
  • base branch: main;
  • exact base SHA: 731af58e954901c4f1cc853231c592abb1eaf617;
  • current diff: 5 files, 317 additions;
  • this is documentation/control-plane scope; no protected-branch direct push or force-push was used.

The inventory in docs/product-technical-gap-baseline.md is an observational snapshot captured on 2026-08-21. It is not merge, approval, or current-PR evidence. Every future loop must re-read live repository, base/head, review, thread, Checks, and ruleset state.

Buyer and implementation boundary

  • PRD/TRD/UML acceptance targets connect the buyer journey to retrieval, temporal conflict resolution, multi-membership, consented disclosure, adaptive orchestration, and standalone/plugin integration.
  • Gap register G-01 through G-14 assigns the next customer-visible action to the owning product or control-plane boundary.
  • The inventory preserves each observed PR's actual base branch, including stacked feature branches.
  • The central repository has no UI surface, so Figma File ID is explicitly N/A (UI scope 없음); UI repositories must record real Figma File IDs, Storybook inventory, design tokens, and interaction/i18n evidence in their own ADRs.
  • APA 7 references cover security, AI governance, accessibility, retrieval, and multi-agent orchestration claims; source snapshots are not treated as live facts.

Open in Devin Review

Exact-head verification

Local verification on 7a2a51e560adc2e1f2f7020702fdc5802ca62b58:

  • uv run pytest --import-mode=importlib -q tests/test_product_technical_gap_baseline.py: 3 passed;
  • compileall for tests and central CI modules: passed;
  • git diff --check: passed;
  • previous stale inventory-SHA and structural findings were corrected in the current lineage; current inline review threads are resolved.

Hosted and review state

For exact head 7a2a51e5:

  • Organization Commercial Readiness Loop Quality CI: completed success (run 32471901534);
  • Exact Artifact SBOM Attestation Quality: completed success (run 32471901623);
  • Strix Changed Path Quality CI: completed success (run 32471901603);
  • SAST Semgrep, Security Scan, CodeQL PR, SBOM Generation, OSV-Scanner PR, Secret Scan, Scorecard PR, and Python Security: queued;
  • formal reviews are COMMENTED only; no qualifying independent approval exists.

Normal merge remains blocked by non-terminal hosted security/supply-chain gates and missing independent approval. This documentation PR is not a D1-D6 control-plane deadlock and is not eligible for guarded force merge.

Acceptance gate

Merge only after all required exact-head Checks are terminal-success, current findings/threads are resolved, an independent current-head approval exists, and live branch protection permits normal integration. After merge, the next action is to select the highest-leverage live Gap ID and implement it in the owning product repository, reusing the baseline only as a roadmap—not as stale merge evidence.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Current-head review request for exact commit b8f57e1f8b748a740017f937f04aea5d8cad0ad5: baseline contract tests pass (3 passed) and diff checks pass. Please have @opencode-agent independently verify the live PR inventory, source links, Gap IDs, APA references, and protected current Checks; do not treat the snapshot as merge evidence for other PRs.

@coderabbitai

coderabbitai Bot commented Aug 20, 2026

Copy link
Copy Markdown

Review Change Stack

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 5b4f706d-2e3d-4c9c-9d0f-26519c523901

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch docs/product-technical-gap-baseline-20260820

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Current-head follow-up for exact commit 1e16f9fbd7ddb7781e34cedebfce4d860cfcc5de: refreshed the inventory to include PR #1163 itself and the repaired current heads for #1146 and #1156. Baseline contract tests remain green (3 passed) and diff checks pass. Please re-review this exact HEAD only.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Live baseline refreshed at exact head 620fb4f: current PR inventory now records #1158=e2c00317, #1155=5ef1fc6b, #1156=f19549cd, #1146=38fbf9fc, and the baseline PR itself=1e16f9fb. The table remains observational evidence only; merge decisions still require current-head Checks, independent review, and ruleset verification. @opencode-agent please review this exact head.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Baseline inventory refreshed at exact head 275afa1; #1156 now records the normal forward scope-repair head 558c437.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Baseline updated at 75bb459 with the latest #1156 scope-repair head dee2528.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Baseline current head is 7a9f464; self-row binding and latest live #1156 scope-repair evidence are synchronized.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Baseline header and G-04 are refreshed to the live 99-open-PR snapshot at exact head 89e579c; table membership was checked against the full live inventory.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Baseline security evidence refreshed at 2b5d574: #1158=d1da6056 clean CLI boundary and #1156=d4948f21 latest normal scope repair.

Copy link
Copy Markdown
Contributor Author

@opencode-agent please re-review exact current head 6aad0b87198b9da44ea32e901876251991359150. The prior inventory-SHA mismatch thread is resolved, but current-head review evidence is still required after the fix.

Copy link
Copy Markdown
Contributor Author

Exact-head renewal after protected-main advancement

  • branch was one protected-main release behind; merged current main@55a8b576725451dfe0a21a57d36a2f1a41619b24 without rewriting history
  • new exact head: c54dd374514fc8a001337376dc141fedd0cd0be7
  • focused baseline plus exact-artifact regression tests: 52 passed; git diff --check passed
  • the baseline remains documentation/control-plane scope and records Figma as N/A for this UI-less repository
  • fresh hosted Checks are now required for the new head; no qualifying independent approval is present

A local actionlint pass also exposed an existing base-main defect in .github/workflows/exact-artifact-sbom-attestation.yml (job.workflow_repository/workflow_sha and shell quoting). That is being isolated into its owning workflow repair PR rather than widening this baseline PR.

Copy link
Copy Markdown
Contributor Author

Correction to the local actionlint note

The job.workflow_repository / job.workflow_sha messages are actionlint schema diagnostics, not a workflow runtime defect: GitHub documents both properties for reusable workflows and gives the same self-checkout example. The shellcheck notices are likewise emitted inside the existing expression-templated heredoc. No separate source PR is warranted from that local-only diagnostic.

Reference: https://docs.github.com/en/actions/reference/workflows-and-actions/contexts#job-context

Copy link
Copy Markdown
Contributor Author

Exact-head repair verification: 567f5bd1616708cddac85ec8a9ad0a7ed318a1d0 keeps the full-SHA inventory regression green (3 passed), compileall and git diff --check pass, and separates live protected main@55a8b576725451dfe0a21a57d36a2f1a41619b24 from the historical inventory snapshot source aa8503f4383e8328d89104796bc3e9f7da810376. The resolved inventory thread remains resolved; no approval or merge inferred.

Copy link
Copy Markdown
Contributor Author

Current-head review refresh (2026-08-21):

  • Verified live HEAD 567f5bd1616708cddac85ec8a9ad0a7ed318a1d0; the baseline's inventory is explicitly historical at aa8503f4383e8328d89104796bc3e9f7da810376, and the PR body now says so instead of presenting it as current-main evidence.
  • The document still requires each loop to revalidate live PR SHA, reviews, and Checks; Figma is correctly N/A for this UI-less control-plane repository while UI repositories must record real File IDs in their own ADRs.
  • Local proof: baseline tests 3 passed; compileall and git diff --check passed. Hosted exact-head baseline, SBOM, security, secret, SAST, OSV, Scorecard, and related Checks show no failure; queued checks remain non-terminal.
  • Existing review threads are resolved/outdated and automated reviews are COMMENTED only. No independent APPROVED review exists, so this PR remains unmerged under protected governance.

Copy link
Copy Markdown
Contributor Author

Current-head revalidation for the refreshed baseline:

  • exact head: 03e7d27128538aaa79a9f80549df5eda89613585
  • base: main at 55a8b576725451dfe0a21a57d36a2f1a41619b24
  • local proof: python3 -m pytest -q tests/test_product_technical_gap_baseline.py → 3 passed; git diff --check → passed; CodeGraph reindexed
  • unresolved review threads: 0
  • formal reviews at this head: COMMENTED only; no independent APPROVED review
  • hosted required workflows: queued at the exact head; no terminal PASS yet

This remains unmergeable by protected policy until an independent current-head approval and terminal required Checks exist. Duplicate #1193 was closed and is not a second merge path.

devin-ai-integration[bot]

This comment was marked as resolved.

Copy link
Copy Markdown
Contributor Author

Exact-head review disposition

  • Exact head: d6bfaca7
  • Base: 731af58e954901c4f1cc853231c592abb1eaf617
  • Fixed structural defects: consolidated the duplicate ## [Unreleased] section; corrected G-04 from 100 to the captured 90-PR inventory; clarified that the inventory base column records each PR's actual base branch, including stacked feature branches; and made the inventory test derive its expected row count from the declared snapshot count rather than duplicating a magic number.
  • Snapshot provenance: the document intentionally preserves the captured main SHA 55a8b576725451dfe0a21a57d36a2f1a41619b24; it is historical evidence, not current merge evidence. The current protected main is re-read before any merge decision.
  • Verification: 3 baseline tests and git diff --check pass.
  • Rollback: revert d6bfaca7 if the documentation contract regresses.
  • Decision: normal protected merge only after an independent approval and all required exact-head checks are terminal-success. No bypass or stale evidence is used.

@seonghobae
seonghobae enabled auto-merge (squash) August 21, 2026 08:59
@seonghobae

Copy link
Copy Markdown
Contributor Author

Exact-head review disposition

The live product/technical gap baseline was refreshed from the GitHub REST inventory observed on 2026-08-21: protected main is 731af58e954901c4f1cc853231c592abb1eaf617, and 106 open PR rows are present. The inventory is observational evidence only; it is not approval or merge evidence for this PR or any listed PR.

Local exact-head evidence for 7a2a51e560adc2e1f2f7020702fdc5802ca62b58:

  • .venv/bin/python -m pytest tests -q: 1294 passed, 16 subtests passed.
  • Coverage: 8123/8123 statements and 3144/3144 branches, 100%.
  • .venv/bin/python -m compileall -q tests scripts/ci organization_commercial_readiness_fixtures.py: pass.
  • git diff --check: pass; working tree clean after push.
  • Interrogate remains 99.7% because of the two pre-existing constructor docstring gaps in organization_commercial_readiness_fixtures.py and scripts/ci/organization_commercial_readiness_loop.py; those are separately repaired in PR fix(strix): retry transient visibility API failures #1114 and are not mixed into this documentation snapshot.

Hosted state for the same exact head: Python 3.10 contract, Python 3.14 exact contract/complete coverage, and exact-head policy have succeeded; security, review-provider, workflow bootstrap, and other required runs remain queued (exact-head path policy was still in progress at observation). No formal APPROVED review exists for this exact head; prior bot comments are on predecessor commits. This is not a D1-D5 deadlock finding, and no bypass or force merge is authorized.

Please review this exact head only and publish substantive findings or approval after the current Checks settle.

Copy link
Copy Markdown
Contributor Author

Exact-head review disposition

  • Pull request: docs: establish live product and technical gap baseline #1163
  • Exact head: 7a2a51e560adc2e1f2f7020702fdc5802ca62b58
  • Exact base: 731af58e954901c4f1cc853231c592abb1eaf617
  • Scope: documentation/control-plane baseline; inventory is explicitly historical observational evidence.
  • Local proof: baseline contract 3 passed; compileall and diff check passed.
  • Review: no unresolved threads; formal reviews are COMMENTED only; no independent approval.
  • Hosted: organization readiness, exact-artifact SBOM, and Strix passed; security/supply-chain/static-analysis gates remain queued.
  • Decision: WAIT_AND_REMEDIATE. No D1-D6 control-plane deadlock is evidenced; do not bypass protection.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Current-head verification update

  • Exact head: f77dcf0b0080093cddc3ec898891e8d77b658882
  • Exact base: fce028b4c3bf8e2e5e4819c1c5622e90cfa6ab39
  • Normal branch update onto current main completed; predecessor evidence is discarded.
  • Review threads: 0 unresolved; no qualifying approval is currently recorded.
  • Local exact-head verification: product-gap baseline tests 3 passed; compileall and diff check passed.
  • Hosted required Checks are queued/in progress; no current source failure is evidenced.
  • Decision: WAIT_AND_REMEDIATE; normal squash auto-merge remains enabled; no force merge.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Exact-head audit update\n\nObserved hosted exact-head-path-policy failure on the prior head: the scheduler contract test still expected the former repository-dispatch run-id scope and shorter cancellation expression. The hosted pip lock also remained on pip 26.1.2.\n\nRoot-cause fix: updated the hash-locked CI dependency to pip 26.2.1 with both package hashes and aligned both scheduler assertions with the current repository-dispatch and orphaned workflow-run scopes.\n\nExact head: 1a568aa\nExact base: fce028b\nLocal verification: pip-audit clean; 55 technical-gap/scheduler tests passed; shell syntax and diff checks passed.\nHosted required checks and exact-head approval remain pending; decision remains WAIT_AND_REMEDIATE.

devin-ai-integration[bot]

This comment was marked as resolved.

@opencode-agent
opencode-agent Bot disabled auto-merge August 21, 2026 18:51

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 new potential issue.

Open in Devin Review

Comment thread CHANGELOG.md

## [Unreleased]

- Documented the live product and technical gap baseline, current open-PR inventory, ownership boundaries, acceptance criteria, and buyer next-action loop in `docs/product-technical-gap-baseline.md`.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: CHANGELOG entry sits outside any category heading

The added bullet sits directly under ## [Unreleased], before the ### Added subheading, while every other entry lives under a Keep-a-Changelog category (Added/Changed/Fixed/Security/Documentation). No contract test enforces this, so it is a formatting inconsistency only.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant