Skip to content

P20: verify whole product release candidate - #54

Draft
Techshrr wants to merge 66 commits into
mainfrom
develop/p20-whole-product-verification
Draft

P20: verify whole product release candidate#54
Techshrr wants to merge 66 commits into
mainfrom
develop/p20-whole-product-verification

Conversation

@Techshrr

@Techshrr Techshrr commented Aug 29, 2026

Copy link
Copy Markdown
Owner

GoJet V10 / P20 — Whole Product Verification

Refs #1
Closes #53

Current status

CONTRACT FROZEN / EXACT-HEAD CONTRACT GUARD PASS / ENTRY SATISFIED / VERIFICATION IMPLEMENTATION AUTHORIZED / NO EXIT CLAIM

  • Branch: develop/p20-whole-product-verification
  • Integration base: 6e628b9879eb4dddf335a324e4f4d7ae3a77cd5c (merged P19)
  • P20 contract authority: 050fd7052d71ff77858b153abcbc466a1243af2f
  • Verification-entry HEAD: aa0e93d728b3d86101ee30f7f7288bc29ae94448
  • Frozen cases: P20-T001..P20-T049
  • Pre-sign evidence range: P20-T001..P20-T048
  • Frozen test-plan blob: f6d7831be48fcc8f378ad1a90efbb7e96e01c4e8
  • Pending review blob: 9c1410dc02f62bfead5a12b2d323291152bf1ea6
  • Validator blob: 8d2617834e63c65166b091bcb4d520725020cec9
  • Contract workflow blob: accb1b67f8ee13315dc8d562c382a41a4f280843

Contract guard authority

  • Authority run: 33269592158SUCCESS
  • Authority artifact: 9719700238
  • Authority artifact digest: sha256:f04ba16b170c6c094de8db43192887c163dab0103af8bc05e1e5e46b64c75249
  • Verification-entry run: 33269675417SUCCESS
  • Verification-entry artifact: 9719726009
  • Verification-entry artifact digest: sha256:e210a47eb509e40fed73b4488be47e8526dc600dbc891005d3369d2be46917af
  • Baseline: frozen validator PASS / go test ./... PASS / full frontend workspace typecheck+build PASS
  • Contract authority mode: contract-freeze, implementation not authorized on the authority revision itself
  • Entry descendant mode: verification-guard, implementation authorized while review remains pending

The contract authority is exactly one direct child of the verified P19 integration commit and adds only the four frozen P20 contract files. The verification-entry child changes no files and exists only to enter the authorized descendant phase without mutating frozen authority.

Immediate predecessor authority

  • P19 signed source: 44ea701ae464550ce920c5f2131428270e22fb41
  • P19 integration commit: 6e628b9879eb4dddf335a324e4f4d7ae3a77cd5c
  • P19 Closure run: 33268403700SUCCESS
  • P19 closure artifact: 9719405957
  • P19 closure digest: sha256:de62ca1484b7eeedc7249303fa525885584f49d5983ca9378000eb7bb82e7bd2
  • P19 final authority: phase=signed, review_phase=signed, review_only_signed_child=true, merge_authoritative=true, matrix 19/19, G4/G5/G7/G8/G9 5/5, defects 0/0/0

Frozen P20 ownership

P20 owns whole-product verification only: exact candidate/schema/frontend/evidence freeze, capability/route closure, one real correlated P0 workflow, cross-surface consistency, failure/recovery verification, release-candidate evidence index, defect ledger and P20's G0-G10 release-candidate disposition.

The Master Plan-required P0 sequence is register → verify → login → link → redirect → analytics → QR → file → text → bio → domain → ticket → billing → notification → admin.

P20 must not add unplanned features, invent routes, reinterpret P00-P19 signed authority, replace required real flows with mocks, weaken fail-closed/security behavior, or claim P21/P22 native package/fresh-install/production obligations complete.

For the G0-G10 ledger, P20 must prove release-wide PASS for G0/G3/G4/G5/G6/G7/G8/G9/G10, live-bind/revalidate signed G2 authority, and preserve G1 as the explicit P01/P21/P22 native-architecture carry-forward row without falsely closing CAP-NATIVE-INSTALL or CAP-NATIVE-ONLY-RELEASE. G11-G13 remain later-owned.

Closure discipline

PR remains Draft. Final merge authority later requires P20-T001..P20-T049 PASS, complete applicable exact-head regression, the complete non-conditional G0-G10 release-candidate ledger, P0/P1/DECISION REQUIRED 0/0/0, accountable review-only signing and final signed merge_authoritative=true closure.

Integrate the scoped P20-T009 remediation into the blocked P20 candidate. Defect #55 remains open until exact-head P20 verification passes.

Copy link
Copy Markdown
Owner Author

P20-D001 / #55 is the current fail-fast blocker. Clean T009 reproduction was run 33272014441 at 1500a531...; scoped remediation PR #57 has now been merged into this branch as 6f4ecb6150c2bef3262457634c536f39d5c4079a. Frozen contract is unchanged. New exact-head contract guard and go test ./... already pass; T009 run 33283016320 is queued. This Draft PR remains non-merge-authoritative and no T010+ claim is made until T009 passes and the defect ledger is closed with live evidence.

@Techshrr Techshrr left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P20-D001 closure authority is now exact-head coherent.

Final verified candidate HEAD: 200e2604886933b1a1dd4f48ee1ecfda00ea36e4

  • P20 Candidate and Traceability Freeze run 33283499484 / job 99182546399: SUCCESS
    • T001-T008 all PASS, including T008 defect/decision ledger closure
    • artifact 9723739465
    • digest sha256:6914e14b77692e7a661ca358b0f3c0d6cd55150211c1c685e561f5594468e512
  • P20 P0 Auth Timeline run 33283499620 / job 99182546670: SUCCESS
    • T009 PASS on real native platformapi + MySQL 8.4.11 + Redis 7.4.10 + all immutable migrations + GOJET_TEST_AUTH_ENABLED=0
    • real owner Workspace correlation restored
    • artifact 9723704217
    • digest sha256:2837faa1dcabd7c49e23644a3ae22fdd0731341c8f82f15018e272a7af53399e
  • Defect #55 is closed as completed only after this same-head re-verification.

P20 remains Draft / no exit claim. Next authorized frozen case is P20-T010 — Real email verification workflow; implementation must continue the same T009 user/workspace/grant timeline and must not substitute mock mail/token authority.

@Techshrr Techshrr left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Master-tracker handoff note: P20 exact-head 200e2604886933b1a1dd4f48ee1ecfda00ea36e4 now has T001-T008 and T009 both green with exact-head artifacts/digests, and release-blocking defect #55 is closed only after same-head re-verification. P20 is still active/Draft with no exit claim. The next authorized case is T010, continuing the same real registration identity/workspace/grant timeline through queued verification mail, real verification transition, and replay protection.

Remediate #58 / P20-D002 by composing the signed Redis auth rate limiter into the real platformapi auth HTTP path and supplying explicit CI-only rate policy values. Keep Workspace/session integration and T012+ out of scope pending fail-fast P20-T011 rerun.
Remediate #61 / P20-D003 by binding auth rate IP authority to the originating client across trusted proxy chains, rejecting untrusted/spoofed forwarding authority, bounding trusted-hop traversal, and enabling repository Vite proxies to emit forwarding headers. Keep #62 / D004 and T012+ out of scope.
Remediate #62 / P20-D004 by composing the real P15 server-side session and unsafe Origin/CSRF authority into the Workspace principal boundary while preserving P12 membership/RBAC and predecessor test-auth fixtures. No T012+ work.
Compose real P15 session, Origin/CSRF, and server-authoritative Workspace membership role into the P05 Links API while preserving predecessor test-auth behavior and Link business semantics.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

P20 — Whole Product Verification

1 participant