Skip to content

Docs Council Execution Releases P0 P0 R0 Stage0 Test Plan

Arun Prakash N edited this page Aug 16, 2026 · 2 revisions

Canonical source: docs/council/execution/releases/P0-P0-R0-STAGE0-TEST-PLAN.md · Snapshot commit: 6b8b70b72148

P0/R0 Stage 0 test plan

  • Fixture class: fictional/synthetic/public-safe only
  • External mutation: prohibited during candidate verification
  • Private access: prohibited
  • Primary oracle: stable result codes plus exact normalized evidence

Required suites

Suite Positive proof Mandatory negative proof
Preparation Gate A One exact substantive R0 proposal becomes Ready to prepare — Gate A and remains executionAllowed=false Unknown/extra field, historical/out-of-scope task, private access, external mutation, stale publication, missing/duplicate/conflicted seat, veto/blocker, dependency drift, and attestation tamper
Stage Gate B One composite R0 task permits exactly one bound stage pair while direct task-wide approval still fails cardinality; the dedicated ordinary-status branch alone permits exact delivery-control/delivery-status-transition plus the code-owned p0.delivery-transition module with neither P0-OA-001 nor P0-OA-002 due; standalone accepted-preparation history and later stage history are append-only, registry-only, and one contiguous per-task chain Task/stage/scope/action/candidate/predecessor/idempotency/definition/module/requirement/QA/rollback/publication drift; generic local or private-execution/project-workflow-mutation authority on an ordinary status-transition suffix; wrong transition module ID/path/mode; fabricated owner-action requirement; workflow configuration/non-delivery mutation through the status branch; duplicate/gapped sequence or non-immediate predecessor; persisted transition-stage key; unrelated or multi-parent publication delta; historical/R1-R10 task; Gate A replay; legacy-seat substitution; stale authority
Successor control review Bootstrap-pending is inert; later one exact five-seat add-only review verifies candidate/history/full diff Historical record edit/delete, pre-candidate record, rewrite, duplicate seat, omitted/extra path, task approval/runtime effect, unsafe evidence
Running-log trust Prior bytes are an exact prefix; append parses, is public-safe, provenance-bound, and has no gate/permission effect Edit/truncate/insert/rename/mode drift, malformed event, duplicate provenance, secret/private/authentic canary, arbitrary descendant path
Staged runner executeStageFromExactMain synchronously captures exactly six immutable identity data fields plus one callback and accepts only the exact code-owned callback bound to the reviewed module ID/path/mode/hash, trusted-public-synthetic-no-native-io-v1 profile, and SHA-256 review evidence. It resolves one reviewed stage, holds stage/global locks, persists running, then freshly rechecks predecessor/exact-main Gate B/deadlines and takes the actual start time immediately before invocation; expiry or movement terminalizes no-mutation and the primordial timer uses only remaining authority from actual start. Ordinary dynamic console/process stream interception is a guardrail, not a sandbox; static eligibility forbids saved bindings, direct/native FDs/streams, subprocess/worker/background output, and sensitive/private raw material. runSerializableStageFromExactMain separately captures six own data descriptors synchronously and supports definition-bound exact-main Gate B windows through four hours. It checks before inert-launcher spawn, arms outcome observation/cancellation before the first post-spawn await, durably fsyncs the child identity into the lock, then repeats predecessor/Gate-B/all initial/fresh/current deadline checks directly before LAUNCH_SIGNAL; denial/expiry terminates the waiting launcher with zero module calls and durable non-executing replay. Both lanes require a durable recovery/terminal append or exact regular tail-file fsync, inode/hash/same-tail reread, then event-directory fsync before post-start lock release Missing/extra/accessor identity, mutation after first yield, or injected trust hooks in either public lane; wrong function/profile/review-evidence binding; callback with forbidden native/output/raw-material capability; delayed running-journal/fsync that consumes authority with callback count zero; serializable delayed pre-spawn expiry/Gate-B drift with zero launcher, plus authority drift or timer expiry during child lock-record persistence with one terminated launcher, zero module receipt, and replay without a second launcher; serializable deadline above four hours or callback above five minutes; identity/predecessor/idempotency/result mismatch; absent stage/module; unfrozen context; callback before durable running; ordinary console/process write or binding tamper; Date/hrtime/timer mutation; throw, early/invalid receipt, ignored abort, non-settlement/global-lock escape, concurrent replay; post-action append failure before write; readable verification-pending/recovery write plus file- or directory-fsync uncertainty with fail-stuck replay denial and no dependent append; source/authority movement after settlement or final append; arbitrary serializable command/shell/env/cwd/path/output/trust hook; lock theft, receipt rewrite, runtime-root tamper, orphan process, raw-output leak
Delivery transition All three declared edges require a task-bound immutable -DELIVERY-TRANSITION Gate B stage with exact delivery-control/delivery-status-transition, the code-owned p0.delivery-transition module, and neither owner action due; the pure one-task dry-run reconstructs the preimage, exact operations/inverse, protected surfaces, rollback reference/recovery digest, projection digests, and immutable frozen-snapshot digest; mocked exact apply durably persists directory entries/events, holds one unique-owner task lock, verifies frozen-50 parity before/after every mutation and at every success/rollback/replay boundary, and verifies projections immediately/twice-quiescently Gate A or generic local-synthetic/private-workflow authority on any edge including Backlog to Next; non-transition/missing/stale Gate B, wrong module binding, fabricated owner-action requirement, or workflow/non-delivery mutation through this branch; digest-recomputed semantic/authority/rollback/freeze forgery; frozen-50 drift before or after an operation with side-effect bounds; historical/non-delivery target; undeclared edge; multiple/unknown status labels; forbidden-surface weakening; concurrent same-plan or cross-plan invocation; creation/deletion/reconfiguration; concurrency/automation drift; saga/lock/directory durability tamper; rollback or replay drift/failure
Frozen 50 Exact 50 tasks, 300 artifacts, 40 Backlog + 10 historical Done, zero allowed, exact issue/Project/artifact bytes Missing/extra/duplicate task; any authored field, issue, Project, artifact, review, owner action, evidence, or permission drift; unknown aggregate exception
Wiki trust --help writes nothing; exact source maps N/N once; zero collisions/broken links/fragments; stable Page Audit source binding Option-like output path, stale source, missing/collision page, missing fragment, Unicode/deduplicated anchor error, README semantic-key drift, self-declared current Wiki hash
Workflow integrity Exact PR/push SHA runs every named suite, double generation/dry-run/Wiki build, workbook safety, generated tracking, frozen prototype check Missing/renamed/skipped command, continue-on-error, false if, `

The callback durability negatives separately cover complete readable verification-pending and recovery tails with uncertain tail-file fsync, plus complete readable recovery bytes with uncertain event-directory fsync. Each retains the stage lock and denies replay without a second callback execution; the unproven verification-pending tail receives no dependent recovery append.

Repository-wide acceptance

  1. Parse every changed JavaScript module.
  2. Run all legacy readiness, historical review, exact-start, sync, generated-tracking, and structural validators without weakening their existing assertions.
  3. Run every new positive/adversarial suite above.
  4. Run the frozen v10 prototype syntax check; no product code changes are expected.
  5. Run task-artifact and roadmap generators twice and reject any second-pass drift.
  6. Render two byte-identical safe GitHub dry-run plans; no gh process in dry-run.
  7. Verify the 50-task freeze before generation and after every projection; the pure delivery dry-run binds only the immutable snapshot digest, while every future operational transition adapter must prove live exact-50 parity at each declared boundary.
  8. Rebuild the workbook through the approved spreadsheet runtime, then inspect all 7 sheets, 58 unique issue links, 78 requirements, 2,009 formulas with zero errors, exact R10 blanks, manifest SHA binding, raw archive safety, and all paginated renders.
  9. Build the Wiki twice from the same exact source plus a complete prior clone, compare trees, and require N/N mapping with zero collisions and broken links/fragments.
  10. Run the public-safety scan over tracked, staged, unstaged, untracked, generated Markdown/JSON, workflow output schemas, and workbook package text.

Fail-closed claim

Passing proves only that the Stage 0 controls and factual projections are internally consistent for the reviewed exact candidate. It does not prove product implementation, private-system access, deployment, restore, R0 acceptance, release, or production.

Life in Days

Home

Product, experience, architecture, and delivery

Discovery and research

Governance and council

Prototype handoffs

Prototype run guides

Prototype councils

QA and audits

Repository and project record

Evidence and maintenance

Clone this wiki locally