Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions .github/workflows/reusable-docs-governance.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,14 @@ jobs:
with:
node-version: ${{ inputs.node-version }}

- name: Setup Python
uses: actions/setup-python@v7
with:
python-version: "3.12"

- name: Validate failure ledger projection synchronization
run: python -m unittest discover -s scripts/agent_hooks -p "test_render_failure_ledger.py"
Comment thread
Chris0Jeky marked this conversation as resolved.

- name: Validate docs governance invariants
run: node scripts/check-docs-governance.mjs

Expand Down
4 changes: 4 additions & 0 deletions docs/IMPLEMENTATION_MASTERPLAN.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,10 @@ Companion Active Docs:
- `docs/MANUAL_TEST_CHECKLIST.md`
- `docs/GOLDEN_PRINCIPLES.md`

## Delivery update (2026-07-26, agentic governance)

- **Failure-ledger projection gate (`#1492`):** Required Docs Governance now pins Python 3.12 and runs the existing JSONL↔Markdown synchronization unittest before the governance checks, so a JSONL-only change with stale generated Markdown fails Required CI before regeneration can mask it. The agentic operating-layer smoke sequence records the same fail-before-render order.

## Delivery update (2026-07-26, security runway)

- **SQLite native security floor (`#1345`):** centrally pin `SQLitePCLRaw.bundle_e_sqlite3` 2.1.12 and make Infrastructure's dependency direct, which moves the matched bundle/core/provider/native family from 2.1.6 to 2.1.12 without enabling global transitive pinning. A runtime regression enforces SQLite >= 3.50.2 (2.1.12 loads 3.53.3); the NuGet vulnerability audit is clean, EF reports no pending model changes after a fresh update, and a self-contained `win-x64` binary reaches `/health/ready` with SQLite loaded.
Expand Down
5 changes: 4 additions & 1 deletion docs/STATUS.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,9 @@

Last Updated: 2026-07-26

Required Docs Governance hardening (2026-07-26, `#1492`):
- **Required CI now enforces failure-ledger projection synchronization.** The reusable Docs Governance job pins Python 3.12 and runs the existing `failure_ledger.jsonl` ↔ `FAILURE_LEDGER.md` synchronization unittest before its governance checks, so a stale checked-in projection fails before any renderer can rewrite it. The documented agentic operating-layer sequence mirrors the same fail-before-render order.

Paper-default regression alignment (2026-07-14, `#1274`): authenticated E2E sessions now follow the production Paper default unless a frozen Legacy-selector suite opts out explicitly. The refreshed core lane proves the real capture → Accept → Review → approve/apply → board path and runs the full axe WCAG 2.1 A/AA ruleset against settled Paper Home, Today, Inbox, Review, and a seeded Board, plus Login and functional skip-link keyboard coverage. The global Vitest Legacy pin remains intentional because those component tests assert the frozen Legacy DOM directly. Focused Chromium verification is 37/37 across `accessibility`, `onboarding`, `capture-loop`, `review-proposals`, `first-run`, and `smoke`.

Direction change (2026-07-10, maintainer-decided, **ADR-0044**): **the 2026-06-13 archive pivot is superseded — Taskdeck is being revived** and shipped as a **free open beta** (adoption/feedback/exposure first; the commercial side is developed in parallel by the maintainer). Positioning: the local-first, review-first **action-item engine** — transcripts/notes in, evidence-linked proposals out, applied to a board only on human approval — with the write-gated MCP server as the developer-facing second act. Everything shipped under MIT stays MIT (no retroactive relicensing). The active planning spine is **`docs/REVIVAL_PLAN.md`** (Phase 1 "truth + safety before strangers" repurposes the #1278 archive exit criteria as the v0.1 ship gate; Phase 2 is the LLM transcript-triage engine — the largest authorized new-backend-surface slice; Phase 3 is the beta launch; other scoped exceptions include registration gating, feedback/telemetry, and MCP key/identity hardening as enumerated in §7; then a ~8-week traction checkpoint with the archive plan as the documented fallback). New backend surface is authorized only by REVIVAL_PLAN §7 — the Phase-2 transcript-engine grants (ADR-0044) plus the Phase-4 generalist-expansion grants (**ADR-0046, Accepted 2026-07-13**: artefact intake, dossier read model, mode-scoped navigation; tracker `#1327`; the twin generalist app is explicitly deferred behind the GEN-12 `#1326` evidence gate). Evidence base: `docs/analysis/2026-07-10_revival_assessment.md` (7 code-review dimensions, ~25 adversarially verified claims, live-verified market data). Archive-closeout issues #1269–#1278 are re-scoped in place (same work, new purpose); dogfooding (#1271) remains the acceptance test for either path. **Dogfooding is now instrumented (2026-07-25):** `docs/dogfooding/README.md` holds the protocol — a dedicated `TASKDECK_DOGFOOD_DB` so dev/demo/E2E traffic cannot contaminate the signal, `scripts/dogfooding/dogfood-snapshot.py` (read-only; counts and dates only) for objective metrics, `docs/dogfooding/LOG.md` for friction, and a checkpoint rubric fixed before any real usage data existed. Read it before collecting checkpoint evidence, or the evidence will not be comparable. The measured pre-dogfooding baseline is recorded in `LOG.md`: **8 active days, none in the last 28, last activity 2026-04-23, 10 of 13 boards demo/test residue** — sustained use has not started, though the loop itself works (**17 of 20 proposals reached Apply**, counted by `AppliedAt`; a status-based count reads 1/20 because `Dismiss()` overwrites an `Applied` status).
Expand All @@ -19,7 +22,7 @@ PR-queue clearing wave (2026-07-25, **8 PRs merged**, and the open-PR queue is d
- **`#1295` CLOSED as superseded, not merged.** The deny-floor overlay failed **13 of 13 of its own bypass tests** and targeted global floor v1.3.0 against an installed 1.6.5. A repo-local overlay is still needed — **11 rule-classes are `allow` at every tier including T4** — so the full salvage plan, with acceptance criteria and the branch's 16 review threads retained as the successor's regression corpus, is recorded on **`#1293`**.
- **Repository hardening:** `main` previously permitted **force-pushes and deletions**; both are now blocked (deliberately relaxed otherwise — no required checks, no required approvals). The GitHub project priority sync was reporting a false all-clear because its default `-Limit 1000` silently truncated a 1444-item project; **288 items** were actually unsynced and are now clean (`#1474`).
- **Backlog triage (`#1270`):** 12 already-decided issues closed with dated pivot notes, after an adversarial pass **bounced 13 of 25 proposed closures** — including `#1123`, the v0.1 ship-gate item. `#1270` itself stays open: two of its own acceptance criteria are obsolete against ADR-0044 and REVIVAL_PLAN §6 and must not be executed as written.
- **Seeded this wave:** `#1470`, `#1473`, `#1474`, `#1475` (the repo hook denies 6 of 8 *benign* commands), `#1476` (`scripts/agent_hooks/` has **zero** CI coverage), `#1480`, `#1482`, plus upstream `agent-harness#56` (`docker exec` is not unwrapped by the global floor at any tier).
- **Seeded this wave:** `#1470`, `#1473`, `#1474`, `#1475` (the repo hook denies 6 of 8 *benign* commands), `#1476` (the configured-handler `smoke_test.py` / deny-floor matrix remains ungated; failure-ledger renderer synchronization now runs in Required Docs Governance), `#1480`, `#1482`, plus upstream `agent-harness#56` (`docker exec` is not unwrapped by the global floor at any tier).
- **Still open — human-gated:** `#1457` only. Its pinned dispatcher hash was stale (v1.5.2 vs installed 1.6.5) and has been refreshed; what remains is a fresh interactive Codex `/hooks` trust session plus recorded live allow/deny canaries, which no agent can perform.

Overnight wave (2026-07-23/24, **6 PRs merged** + 3 dependabot PRs — the four feature/substrate PRs below plus `#1447`, the docs sync that recorded the maintainer-merged `#1414` (its content is the 2026-07-18 post-merge comment further down), and `#1448` below; per-PR gate: two independent adversarial review lenses, all-severity findings fixed with posted evidence, full backend suite on the exact head where code changed, required CI green, bot window honored with a content sweep). The wave's own delivery sweep was `#1454`; `#1448`, `#1427`, and dependabot `#1441` merged *after* that sweep ran, so their entries below were added on 2026-07-25:
Expand Down
3 changes: 2 additions & 1 deletion docs/TESTING_GUIDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

This is the active testing guide for Taskdeck.

Last Updated: 2026-07-14
Last Updated: 2026-07-26
Companion Active Docs:
- `docs/STATUS.md`
- `docs/IMPLEMENTATION_MASTERPLAN.md`
Expand Down Expand Up @@ -71,6 +71,7 @@ python $env:USERPROFILE\.codex\skills\.system\skill-creator\scripts\quick_valida
python $env:USERPROFILE\.codex\skills\.system\skill-creator\scripts\quick_validate.py .claude\skills\taskdeck-interface-map
Get-ChildItem scripts\agent_hooks -Filter *.py | ForEach-Object { python -m py_compile $_.FullName; if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE } }
python scripts\agent_hooks\smoke_test.py
py -3 -B -m unittest discover -s scripts\agent_hooks -p "test_render_failure_ledger.py"; if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
python scripts\agent_hooks\render_failure_ledger.py
node scripts\check-docs-governance.mjs
node scripts\check-golden-principles.mjs
Expand Down
9 changes: 4 additions & 5 deletions docs/agentic/FAILURE_LEDGER.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,6 @@ Rows sharing a surface and first tracking issue in `future_fix` show only their

| Date | Class | Surface | Failure | Workaround | Future fix | Status |
| --- | --- | --- | --- | --- | --- | --- |
| 2026-05-11 | seed | agentic-pack | Ledger created | n/a | Start recording recurring failures and promote confirmed lessons | open |
| 2026-05-29 | blocker | dependabot/nuget | dotnet-minor-patch repeatedly proposed EF Core 9.x while Sqlite/Design remained 8.x, causing ambiguous ExecuteDeleteAsync errors on #1102/#1106 | Pin EF Core back to 8.0.27 per PR | Resolved by #1112 ignore rule and the EF runtime 8.x pins in #760/#767 | resolved |
| 2026-05-29 | blocker | dependabot/nuget | After FluentAssertions moved to free 7.x in #1088, Dependabot immediately proposed paid v8 in #1117 | Close the v8 PR | Resolved by the FluentAssertions major ignore rule in #1118/ADR-0034 | resolved |
| 2026-05-29 | invalid_signal | ci/e2e-smoke | E2E Smoke intermittently times out at multi-board.spec.ts:197 restoredBoard visibility with a transient DB connection error unrelated to the PR diff | Investigate against the diff; rerun only the failed job when unrelated | Stabilize the archive-to-restore seed or adjust the visibility wait after root-cause proof | open |
Expand All @@ -17,13 +16,13 @@ Rows sharing a surface and first tracking issue in `future_fix` show only their
| 2026-07-13 | pre_existing_noise | test/redis-lifecycle | #1298's second full backend run failed RedisCacheServiceTests.Dispose_IsNotSerialized_BehindAnInFlightConnect; the exact test passed 5/5 | Park #1298 without a PR instead of treating a narrow rerun as a green full gate | Resolved by #1392 (closes #1332) on 2026-07-17: a dedicated named background Thread replaces Task.Run so the dispose-vs-connect seam is reached deterministicall... | resolved |
| 2026-07-13 | pre_existing_noise | test/background-workers | #1334's full suite let a hosted LLM worker pre-claim a test row and a delayed presence join arrive after events were cleared | Keep the full run non-green and link exact evidence from the PR | Resolved 2026-07-17: workers half by #1394 (closes #1335) + #1391 (closes #1383); presence half by #1366 (snapshot ordering) + #1371 (phase drains). A shared Ho... | resolved |
| 2026-07-17 | non_blocking_risk | github/project-sync | Resolution record for the 2026-07-13 project-sync scope row: the gh token lacked read:project scope so Priority fields were unaudited | No workaround needed any longer | Resolved 2026-07-17 (#1327 scope item): maintainer ran gh auth refresh -s project; Sync-TaskdeckProjectPriority.ps1 audit scanned 1000 items with 0 needing sync | resolved |
| 2026-07-13 | pre_existing_noise | frontend/workspace-mode-ordering | #1334 required E2E observed a late workspace summary restore guided after the user selected workbench during a failed preference save; exact local Playwright th... | Treat the CI failure as real, track the asynchronous ordering seam separately from the auth PR, and rerun only after focused investigation | #1343: version summary mode application against newer explicit preference actions and prove it with deterministic store tests plus repeated E2E | open |
| 2026-07-13 | blocker | frontend/paper-review-contract | Real Paper Review proposals deserialize numeric ConflictTone values into a frontend string-only contract, causing tone.toLowerCase to throw and the ErrorBoundar... | Park #1274 after preserving a clean local branch; do not treat passing API-level apply assertions as valid Paper UI proof | #1347: align deep-review enum wire contracts and add serialized API plus Paper browser regressions | open |
| 2026-07-13 | blocker | backend/similar-past | GET /api/automation/proposals/{id}/similar-past returned HTTP 500 for at least four distinct real SQLite-backed capture proposals during #1274 Paper runs | Keep the failure visible despite Promise.allSettled fallback and frontend retries; park the coverage PR rather than certifying a noisy review path | #1348: capture the server exception in a SQLite API test and repair the bounded board-scoped query path | open |
| 2026-07-14 | blocker | ci/extended-workflow | Resolution record for the earlier #1330 open row: CI Extended reusable Gitleaks permission startup failures are repaired and the tracking issue is closed | No workaround remains; use exact-head Extended runs as the verification signal | Resolved by 66382e6c (Fix CI Extended Gitleaks permissions); #1330 closed 2026-07-13 | resolved |
| 2026-07-14 | blocker | ci/nightly-k6 | CI Nightly run 29229402012 and prior runs lost both k6 summary JSON files to bind-mount permission denial while the tagged SQLite board-write p95 gate failed at... | Do not treat the always-red lane as trustworthy regression evidence until summary ownership and the measured capacity contract are repaired | #1358: map both k6 containers to the host UID/GID, warn at the measured 2000ms capacity, gate at 2200ms, and prove exact-head CI. Resolved: First post-#1359 nig... | resolved |
| 2026-07-25 | non_blocking_risk | dependency/sqlite-native | Resolution record: the inherited HIGH SQLite native advisory is removed from Taskdeck's resolved dependency graph | No workaround remains; keep the runtime security-floor regression and dependency audit green | #1345 resolved by centrally pinning the matched SQLitePCLRaw bundle/core/provider/native family at 2.1.12; SQLite 3.53.3 loads, the >= 3.50.2 floor test passes,... | resolved |
| 2026-07-26 | non_blocking_risk | agent/tool-command-composition | Repeated PowerShell/native composition mistakes caused parser failures, GitHub body argument splitting, jq quote loss, and optional rg exits hiding independent ... | Collect statement-form foreach output before piping; handle optional rg exit 1 explicitly; use typed GitHub connectors for multiline bodies; prefer gh --json pl... | #1490: add copyable PowerShell/native composition forms to the MCP tooling guide, verify the failure-ledger renderer and docs gates, then append a resolution re... | open |
| 2026-07-26 | pre_existing_noise | frontend/workspace-mode-ordering | Resolution record for the #1343 preference-vs-summary ordering defect; the original observed failure remains in append-only history | No workaround remains for the core stale-summary overwrite; retain separate residual debt instead of overstating closure | #1343 core resolved by PR #1386 merge dba47320e348b80ecb678c41a51b686c954527ee; separate server-order/cross-device and client-state residuals remain #1388/#1410... | resolved |
| 2026-07-26 | blocker | frontend/paper-review-contract | Resolution record for the #1347 numeric deep-review enum wire-contract crash; the original observed failure remains in append-only history | No workaround remains; valid numeric payloads render directly and unexpected values fail closed to visible warning states | #1347 resolved by PR #1360 merge ed2538ffb0388523882238653b34fcc6f431a512: API numeric-enum serialization, frontend mapping, conservative malformed-value handli... | resolved |
| 2026-07-26 | blocker | backend/similar-past | Resolution record for the #1348 SQLite-backed similar-past HTTP 500; the original observed failure remains in append-only history | No workaround remains; keep the bounded board/user scope and real SQLite/browser coverage as regression evidence | #1348 resolved by PR #1361 merge ccd7bf93721c07171099383c77bfb508c23fbf48; Paper-browser completion by PR #1362 merge 40b7bb2f3819dcc7d0bd6349a8f516fd3169190f. ... | resolved |
| 2026-07-26 | non_blocking_risk | agent/tool-command-composition | Resolution record for the repeated #1490 PowerShell/native command-composition failures; the original recurrence remains in append-only history | No workaround remains; use the copyable safe forms and classify future failures through the ledger process | #1490 resolved by PR #1491 merge 61f718af941c56c31b8b7595333b9debd6e47da8: the MCP tooling guide now covers collected foreach output, optional rg exits, safe mu... | resolved |

## Classification

Expand Down
Loading
Loading