Skip to content

docs-v4: IA-deepening plan + seam audit + auth roadmap (planning only)#107

Closed
rickylabs wants to merge 20 commits into
mainfrom
docs/v4-ia-deepening
Closed

docs-v4: IA-deepening plan + seam audit + auth roadmap (planning only)#107
rickylabs wants to merge 20 commits into
mainfrom
docs/v4-ia-deepening

Conversation

@rickylabs

Copy link
Copy Markdown
Owner

docs-v4 IA-deepening — planning only (no docs/site or framework code)

Closes the structural critique on the merged v3 site (PR #106). Grounded by a 4-scout Phase-0
workflow (wf_090ee054-3d5); artifacts under .llm/tmp/run/docs-v4-ia-deepening/.

What this PR contains

  • plan.md — locked decisions, workstreams W0–W6, build/eval/merge flow.
  • ia-tree.md — concrete 3-level Capability-Hub IA (Fresh promoted to a 10-page Web Layer section).
  • seam-coverage.md — full capability seam audit.
  • research.md, drift.md (D1 process failure), and the arch-debt.md auth roadmap entry.

Headline findings

  1. IA: v3 was Diátaxis-flat. New IA = Zone → Product-area pillar → Leaf (max 3 levels), uniform
    Concepts→Quickstart→How-To→Reference per pillar; @netscript/fresh becomes its own multi-page
    Web Layer section grounded in verified export subpaths.
  2. Seam audit: exactly one real build-seam gap in the framework — all 9 better-auth plugins
    are mountable only via the undocumented createBetterAuthBackend({ auth }) escape hatch; the
    documented createNetscriptBetterAuth factory has no plugins field. Every other pillar is
    honestly seamed or documented-as-limitation.
  3. User decision (2026-06-22): build the passthrough (R0) and record the seamless-auth
    roadmap (R1 schema-gen · R2 InteractiveFlowPort · R3 org/tenant primitives · R4 defineAuth()
    builder · R5 mappers/adapters/CLI) in arch-debt.md.
  4. Diagram: the on-page break was a deploy-propagation blip, but the pipeline is structurally
    fragile (hand-authored SVGs, mmdc render not wired to build, soft-degrade to alt-text). Fix =
    real Mermaid pipeline wired into build + a missing-asset build gate.
  5. Links: 2 wrong_step cards on the Fresh page (all 4 tutorials exist — no dead entries).
  6. Process gate (drift D1): caveats were never harvested to drift/debt. Three permanent gates:
    caveat-harvest, link-integrity build gate, seam-coverage discipline.

Gate

This is a hard PLAN gate: a WSL Codex adversarial panel + an OpenHands minimax-M3 PLAN-EVAL must
PASS before any authoring/build. No docs/site or framework changes until then.

🤖 Generated with Claude Code

rickylabs and others added 13 commits June 21, 2026 16:28
…s (planning only)

Planning artifacts only (no doc prose, no framework code). Closes the orphaned
structural backlog (W4/W5/W6) plus verified feature gaps and a public-voice cleanup.

- research.md: grounding synthesis, verified public surface (origin/main export maps),
  stale-baseline correction (auth packages DO exist), real integration spine from the
  netscript-start playground showcase.
- doc-architecture-v3.md: locked IA — sitemap, capability-hub template, 4 independent
  tutorial tracks, full design system + 11 rendered diagrams, auto-resolving xref,
  deployed-v3 -> v3 migration map.
- plan.md: 8 workstreams with acceptance gates, sequencing, risks, layered eval handoff.
- ground/: leakage/voice audit (19 instances), diagram inventory, competitor bar-raising,
  playground showcase map.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018fq9V7ujx7e1rWXi57qkPG
Folds the WSL Codex adversarial hardening panel (commit 1cbe1875,
3 blockers / 6 majors / 1 minor) back into the docs-v3 IA plan so it can
clear PLAN-EVAL on the merits. Planning artifacts only; no docs/site or
code touched.

Adds harness artifacts (worklog.md w/ Design checkpoint, drift.md,
commits.md), the full 32-unit/242-subpath public-surface inventory (B2),
tutorial proof-or-rescope plans for the ungrounded Tracks B/C (B3), and
per-capability hub content contracts for the 8 complex hubs (M6).

Hardens plan.md with an open-decision sweep (locks Mermaid build-time SVG,
dedicated _data/xref.ts + comp.xref keys, Pagefind scope, alpha pill,
archetype-internal-only, marketplace-stub, local+Aspire deploy),
20 ordered commit slices with file sets + proving gates (B1), and an
executable gate table + deterministic leakage-scanner spec (M5).

Edits doc-architecture-v3.md (remove public archetype framing M7, badge
marketplace stub M8, split deploy to local+Aspire M9, ground Tracks B/C)
and research.md (reproducibility section, m10).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018fq9V7ujx7e1rWXi57qkPG
…A refs

The adversarial panel committed its findings as 1cbe1875 inside the WSL
worktree only; that commit was never pushed, so the file the plan/drift/
worklog reference was absent from this branch. Reproduce the authoritative
61-line findings file here and correct the four dangling 1cbe1875 SHA
references to point at the file (noting the WSL-only provenance).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018fq9V7ujx7e1rWXi57qkPG
PLAN-EVAL (OpenHands minimax-M3, run 27908862931) returned PASS with 5
non-blocking follow-ups. Surface inventory headline corrected to the
verified live count 31 units / 210 subpaths (was 32 / 242; per-subpath
classification was already complete). 7 per-unit counts reconciled;
createJobTools reclassified as a scaffold helper (not a published
subpath); S12/§5 surface-completeness gate now asserts 210 read live
from the export maps; Track B proof gate now emits a mandatory SCOPE
verdict so the rescope fallback is exercised, not latent.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018fq9V7ujx7e1rWXi57qkPG
Additive post-PASS deepening per user review note (~90% approved, "expected
more inspiration from competitor-doc-research.md"). No locked decision
(D1-D4, OD1-OD8) or slice changed; surface counts and gates untouched.

- vendor ground/competitor-doc-research.md (verbatim from origin/docs/overhaul-v3)
- doc-architecture-v3 §0.5 front-door positioning contract (Integration-Tax
  lead, skeptical-senior-architect persona, 5 proof-backed credibility anchors,
  honest NestJS/Encore/tRPC/Temporal/Hono comparison matrix)
- §8 rewritten into strict per-page-type section-order contracts (F/H/B/R/E)
  + §8.1 code conventions (file-path comments, line-diffing, types-first)
- §5.1 components prioritized P0/P1/P2 + competitor mapping; add comp.tabbedCode,
  comp.tabbedRuntime (localStorage-synced), comp.learningPath, line-highlight
- §5.3 per-engine schema/ERD diagrams + OTel traceparent propagation diagram
- §11 competitor-pattern adoption matrix (every "what to steal" → a home)
- plan.md: WS4/WS8/S03/S18 wiring + page-structure audit gate (§5, S20)
- hub-content-contracts: Type-H structure rule (schema opener, types-first,
  file-path comments, production-notes close)
- research §6 remapped to the vendored dossier; drift + worklog recorded

Ready for user re-review.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018fq9V7ujx7e1rWXi57qkPG
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018fq9V7ujx7e1rWXi57qkPG
Phase-0 grounding (wf_090ee054-3d5) for the docs-v4 information-architecture
deepening run. Locks: 3-level Capability-Hub IA (Fresh promoted to a 10-page
Web Layer section), real Mermaid build pipeline + missing-asset gate, 2 link
fixes, and the drift-D1 process gates (caveat-harvest, link-integrity,
seam-coverage).

Seam audit verdict: exactly ONE real build-seam gap in the framework -
better-auth plugins are mountable only via an undocumented escape hatch.
Per user decision (2026-06-22): build the createNetscriptBetterAuth plugins
passthrough (R0) and record the full seamless-auth roadmap (R1 schema-gen,
R2 InteractiveFlowPort, R3 org/tenant primitives, R4 defineAuth() builder,
R5 mappers/adapters/CLI) in arch-debt.md.

Planning-only; no docs/site or framework code changes in this commit.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018fq9V7ujx7e1rWXi57qkPG
@rickylabs

Copy link
Copy Markdown
Owner Author

@openhands-agent model=openrouter/minimax/minimax-m3 provider=openrouter output=pr-comment iterations=120 use harness — run PLAN-EVAL (separate-session plan gate) for the docs-v4 IA-deepening run on this PR branch.

This is a planning-only PR. Do NOT implement, author docs, or change docs/site or framework code. Read the artifacts, apply the plan gate, and emit a verdict comment only.

Inputs to read (on this PR branch docs/v4-ia-deepening)

  • .llm/tmp/run/docs-v4-ia-deepening/plan.md — locked decisions, workstreams, build/eval/merge flow
  • .llm/tmp/run/docs-v4-ia-deepening/ia-tree.md — concrete 3-level IA tree (THE design under review)
  • .llm/tmp/run/docs-v4-ia-deepening/seam-coverage.md — capability seam audit + the auth decision
  • .llm/tmp/run/docs-v4-ia-deepening/research.md — Phase-0 scout synthesis (grounded in deno doc)
  • .llm/tmp/run/docs-v4-ia-deepening/drift.md — D1 process failure + remediation gates
  • .llm/harness/debt/arch-debt.md — entry "packages/auth-better-auth — seamless better-auth integration roadmap" (R0–R5)
  • .llm/harness/evaluator/plan-protocol.md and .llm/harness/gates/plan-gate.md — the protocol you enforce

What to evaluate

  1. IA soundness. Is the 3-level Capability-Hub tree complete, navigable (≤3 levels), and free of orphan/duplicate coverage? Does every named @netscript/fresh Web-Layer page map to a REAL export subpath (verify against deno doc packages/fresh/mod.ts)? Flag any invented symbol or page with no backing export.
  2. The 3 open IA questions in ia-tree.md (Background-Processing vs Durable-Workflows split; Reference pillar-local vs global; Fresh examples leaf) — RULE on each with a recommendation and rationale.
  3. Seam verdict correctness. Re-verify the headline claim with deno doc packages/auth-better-auth/mod.ts: that NetscriptBetterAuthOptions has no plugins field and createBetterAuthBackend({ auth }) accepts a structural BetterAuthInstance. Confirm R0 (passthrough) is the right minimal seam and that R1 (plugin DB-schema generation) is correctly flagged as a hard prerequisite for the documented path to actually work at runtime.
  4. Honesty constraints. Does the plan correctly require docs to state the R1 schema-gen requirement and the R2 interactive-flow caveat (magic-link/passkey) rather than implying full parity?
  5. Process gates. Are the three drift-D1 gates (caveat-harvest, link-integrity build gate, seam-coverage discipline) concrete and enforceable, or hand-wavy?
  6. Scope/sequencing. Is the R0 framework slice correctly ordered relative to the docs that document it? Any missing workstream or under-scoped slice?

Verdict

Emit PASS or FAIL_PLAN with specific, file-referenced findings and your rulings on the 3 open questions. Two FAIL_PLAN cycles then escalate. Preserve lock hygiene: do not commit deno.lock or source churn.

SKILL

  • .agents/skills/netscript-harness — harness phases, PLAN-EVAL protocol, plan-gate, verdict definitions
  • .agents/skills/netscript-doctrine — package/plugin archetype + public-surface gates (auth seam touches ARCHETYPE code)
  • .agents/skills/netscript-deno-toolchaindeno doc / deno doc --filter to verify export surfaces (Fresh subpaths, auth options)
  • .agents/skills/openhands-handoff — OpenHands run/verdict conventions, pr-comment output mode
  • .agents/skills/netscript-tools — validation evidence + raw-git verification conventions

@rickylabs

rickylabs commented Jun 22, 2026

Copy link
Copy Markdown
Owner Author

OpenHands Agent — Completed

Model: openrouter/minimax/minimax-m3
Provider: OPENROUTER
Job status: success
Trace: .llm/tmp/run/openhands/pr-107/run-27936594391-1 (committed to the PR branch)
Artifact: openhands-agent-27936594391-1

OpenHands Run Summary — 27936594391-1

Run-id: 27936594391-1
Trigger: @openhands-agent model=openrouter/minimax/minimax-m3 provider=openrouter output=pr-comment iterations=120 use harness — run PLAN-EVAL (separate-session plan gate) for the docs-v4 IA-deepening run on this PR branch.
PR: #107 (planning-only PR for docs-v4-ia-deepening)
Branch: docs/v4-ia-deepening @ 2db524bd
Output mode: pr-comment
Selected model: openrouter/minimax/minimax-m3 (provider OPENROUTER)
Selected role: PLAN-EVAL (separate session; not the Claude author / not the WSL Codex implementer)
Verdict: FAIL_PLAN — see plan-eval.md for required fixes.

Summary

Performed a PLAN-EVAL pass on the docs-v4-ia-deepening planning PR. Read the run artifacts
(plan.md, research.md, ia-tree.md, seam-coverage.md, drift.md, arch-debt.md entry
935, gates/plan-gate.md, evaluator/plan-protocol.md) and spot-checked headline claims
against the live source tree on origin/docs/v4-ia-deepening @ 2db524bd.

The plan is largely complete and internally consistent: locked decisions carry rationale,
the 7 workstreams are commit-sized and gated, the drift-D1 process-failure is correctly framed
(caveat-harvest + link-integrity + seam-coverage discipline), and the seam-coverage matrix
correctly identifies ONE real build-seam gap (auth-better-auth plugin passthrough).

The three open IA questions explicitly delegated to PLAN-EVAL were ruled PASS:

  1. Background-Processing vs Durable-Workflows: SPLIT (pillars 3 and 4).
  2. Reference layout: pillar-local Reference leaves + thin global index.
  3. Fresh Examples/sandbox: prose now, StackBlitz backlog.

One evaluator-run open-decision sweep finding was missed by the plan: a symbol-name drift
between the IA-tree / seam-coverage text (createDurableSagaRuntime) and the live export
(createSagaRuntime at packages/plugin-sagas-core/src/runtime/create-saga-runtime.ts:73).
This is the exact class of untracked caveat drift.md D1 was opened to prevent — fixed as
Required Fix #1.

Changes

Deliverable artifacts written

  • .llm/tmp/run/docs-v4-ia-deepening/plan-eval.md — full PLAN-EVAL verdict with 7 spot-checks,
    checklist table, rulings on the 3 IA questions, and 3 required fixes.
  • /home/runner/work/_temp/openhands/27936594391-1/summary.md — this file.

Verdict comment (PR #107)

Per the trigger contract (output=pr-comment), emit a PR-comment body for the workflow to
post. The PR-comment body follows the existing docs-v3-ia-plan--supervisor precedent
format — a short verdict statement + link to plan-eval.md + the 3 required fixes + the
3 IA-question rulings. See "PR-comment body" section below.

Source-tree / framework changes

  • None. This is a planning-only PR (per plan.md §"Build / eval / merge flow" step 1:
    "No authoring/build before PASS"). No files under packages/, plugins/, docs/site,
    or framework code were modified.
  • No commit was created in this run.

Validation

  • No source code or docs modified → no deno check / deno task check / deno task e2e:cli
    needed. PLAN-EVAL is a planning verdict; validation lives in IMPL-EVAL after the build branch
    ships.
  • Spot-checks performed (read-only):
    1. packages/fresh/deno.json exports map → 11 subpaths (./server, ./builders, ./route,
      ./defer, ./form, ./error, ./streams, ./query, ./interactive, ./vite,
      ./testing) — every IA-tree Web-Layer page maps to a real subpath.
    2. packages/fresh/src/application/builders/mod.ts:26definePage exists.
    3. packages/fresh/src/application/route/mod.ts:99defineRouteContract exists.
    4. packages/plugin-sagas-core/src/public/mod.ts and src/runtime/create-saga-runtime.ts:73
      createSagaRuntime is the live export; createDurableSagaRuntime is only in historical
      artifacts under .llm/tmp/run/feat-prime-time-sagas-telemetry-spans--impl/ etc.
    5. packages/auth-better-auth/src/better-auth.ts:23NetscriptBetterAuthOptions fields:
      prisma, provider, debugLogs?, usePlural?, transaction?, appName?, baseURL?,
      basePath?, secret?no plugins field. Matches seam-coverage.md headline.
    6. packages/auth-better-auth/src/better-auth.ts:77BetterAuthInstance is a structural
      { handler, api.getSession } interface. createBetterAuthBackend({ auth }) accepts it
      structurally (matches the escape-hatch code in seam-coverage.md:1322).
    7. packages/plugin-streams-core/src/public/mod.ts — public exports are producer-only
      (createDurableStream, DurableStreamProducer, defineStreamSchema,
      inspectStreamTopic, URL resolvers). No consumer / replay / consumer-group export.
      The "absent — already documented" verdict in seam-coverage.md:63 is correct.

Verdict (from plan-eval.md)

FAIL_PLAN

Required fixes (file-referenced)

  1. Symbol-name drift. seam-coverage.md:61 and ia-tree.md pillar-4 prose reference
    createDurableSagaRuntime. Real export is createSagaRuntime
    (packages/plugin-sagas-core/src/runtime/create-saga-runtime.ts:73,
    re-exported via packages/plugin-sagas-core/src/public/mod.ts and
    packages/plugin-sagas-core/src/runtime/mod.ts:75). Fix in W2/W6 — and record D2 in
    drift.md so the caveat-harvest gate has a reference.

  2. Risk-register row for docs-vs-R0 ordering. plan.md:6465 says "R0 seam slice
    rides its own framework PR — ordering: seam green first, or docs state 'shipping in
    '". Convert to a named risk-register row (in drift.md or new
    risk-register.md) so IMPL-EVAL can verify the auth-pillar pages carry explicit
    "shipping in " caveats if R0 is not green at docs-merge time.

  3. (Minor, optional.) W4 scope — auth-pillar Plugins leaf must carry R1 schema-gen
    caveat.
    plan.md:4648 says the workspace tutorial documents the R1 caveat "if R1
    not built this run" — extend the same conditional to the auth-pillar Plugins leaf itself
    (page-level, not buried in the tutorial). One-line edit to W4.

Rulings on the 3 PLAN-EVAL-delegated IA questions

# Question Ruling
1 Background-Processing vs Durable-Workflows split? SPLIT (pillars 3 and 4; DurableStream is a durability primitive, not a worker).
2 Reference: pillar-local vs global catalog? PILLAR-LOCAL + THIN GLOBAL INDEX (matches ia-tree.md:76).
3 Fresh Examples/sandbox: prose now, live StackBlitz? PROSE NOW, STACKBLITZ BACKLOG (no @netscript/fresh subpath backing for prose-only is honest; defer avoids new external CI integration).

PR-comment body

The workflow will post this on PR #107 as the OpenHands status comment:

## OpenHands PLAN-EVAL — docs-v4-ia-deepening

**Verdict:** `FAIL_PLAN` (first cycle; per `evaluator/plan-protocol.md` §"Loop limit", one
`FAIL_PLAN` cycle is allowed; a second unfixed cycle escalates to the user).

**Evaluator:** OpenHands minimax-M3, separate session (not the Claude author / not the
WSL Codex implementer). Run-id: 27936594391-1. Branch: `docs/v4-ia-deepening` @ `2db524bd`.

**Full verdict:** `.llm/tmp/run/docs-v4-ia-deepening/plan-eval.md`

### Required fixes

1. **`createSagaRuntime` symbol-name drift** (`seam-coverage.md:61`, `ia-tree.md` pillar-4).
   The real export on this branch is `createSagaRuntime`
   (`packages/plugin-sagas-core/src/runtime/create-saga-runtime.ts:73`, re-exported via
   `packages/plugin-sagas-core/src/public/mod.ts`). Fix in W2 (IA restructure) + W6 (pillar
   rewrite), and carry a `D2` entry in `drift.md` so the caveat-harvest gate has a reference.
   This is the exact class of untracked caveat `drift.md` D1 was opened to prevent.
2. **Risk-register row for docs-vs-R0 ordering.** `plan.md:64``65` names the policy
   ("seam green first, or docs state 'shipping in <ref>'") but not as a tracked risk. Add a
   named row (in `drift.md` or new `risk-register.md`) so IMPL-EVAL can verify the auth-pillar
   pages carry the caveat if R0 is not green at docs-merge time.
3. **(Minor.) W4 scope — auth-pillar Plugins leaf must carry R1 schema-gen caveat.** Extend
   the W4 conditional from the workspace tutorial to the auth-pillar Plugins leaf itself
   (one-line edit).

### Rulings on the 3 delegated IA questions

| # | Question | Ruling |
|---|----------|--------|
| 1 | Background-Processing vs Durable-Workflows split? | **SPLIT** |
| 2 | Reference: pillar-local vs global catalog? | **PILLAR-LOCAL + THIN GLOBAL INDEX** |
| 3 | Fresh Examples/sandbox: prose now, StackBlitz? | **PROSE NOW, STACKBLITZ BACKLOG** |

### Spot-checks (against the live tree)

- `packages/fresh/deno.json` exports → all 11 subpaths exist; every IA-tree Web-Layer
  page maps to a real export. ✓
- `packages/fresh/src/application/builders/mod.ts:26``definePage` exists. ✓
- `packages/fresh/src/application/route/mod.ts:99``defineRouteContract` exists. ✓
- `packages/auth-better-auth/src/better-auth.ts:23``NetscriptBetterAuthOptions` has no
  `plugins` field (matches `seam-coverage.md` headline). ✓
- `packages/auth-better-auth/src/better-auth.ts:77``BetterAuthInstance` is structural;
  `createBetterAuthBackend({ auth })` accepts it (escape-hatch code is type-correct). ✓
- `packages/plugin-streams-core/src/public/mod.ts` — producer-only exports (no consumer /
  replay / consumer-group); "absent — already documented" verdict in `seam-coverage.md:63`
  is correct. ✓

### What was NOT changed

- No source code, no `packages/**`, no `plugins/**`, no `docs/site`, no framework churn.
- No `deno.lock` mutation; no `git` commit; no push. This was a planning-only evaluation
  per the trigger contract.

Responses to review comments or issue comments

N/A — this is a planning-only PR with no review comments yet. The PR-comment body above is
the OpenHands status comment that the workflow will post.

Remaining risks

  • createSagaRuntime drift may exist in other artifacts. I only spot-checked the docs
    artifacts in this run dir. If other v4-era docs (under docs/site/_plan/ or other
    ground/ scouts) reference createDurableSagaRuntime, the fix S0: initial public repo genesis #1 should sweep those too.
    The drift D2 entry should carry a list of all such locations.
  • R0 seam ordering hazard is the largest residual risk (see Required Fix S1: package quality — slow-types + docs (supervisor) — Waves 0–6 ✅ merged  #2). The plan
    says "seam green first, or docs state 'shipping in '" but does not commit to which
    branch holds if neither holds at merge time. IMPL-EVAL will need to check this explicitly.
  • Caveat-harvest + link-integrity + seam-coverage gates (plan.md:2834) are
    correctly aimed at the systemic process failure (drift.md D1) but their exact CI wiring
    is described as "wired into CI/review" without a named task or script. This is the kind of
    thing that drifts during implementation — IMPL-EVAL should verify the gates actually fail
    the build before they pass on paper. Marked PASS in this PLAN-EVAL pass per Phase-A
    reporting (gates/plan-gate.md:4245) — "absence of a script is not permission to omit
    the check".

Files touched in this OpenHands run

  • .llm/tmp/run/docs-v4-ia-deepening/plan-eval.md (created — verdict)
  • /home/runner/work/_temp/openhands/27936594391-1/summary.md (created — this file)

No deno.lock, no source code, no commit. Lock hygiene preserved.
Run: https://github.com/rickylabs/netscript/actions/runs/27936594391

openhands-agent and others added 4 commits June 22, 2026 07:35
- seam-coverage: createDurableSagaRuntime -> createSagaRuntime (real export; verified against source)
- drift: add D2 (saga symbol drift) + risk register RR-1 (docs-vs-R0 ordering) and RR-2 (R0-without-R1 page-level caveat)
- plan: W4 page-level R1 caveat line; build-flow step 5 references RR-1

PLAN-EVAL cycle 1 (OpenHands minimax-M3) = FAIL_PLAN; this closes all 3 required fixes.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018fq9V7ujx7e1rWXi57qkPG
Layered PLAN gate, Layer B (Codex panel, PANEL: CHANGES_REQUIRED). All 7
planning-artifact precision/enforceability fixes applied; none contradict a
locked user decision; panel concurs with OpenHands on the 3 open IA questions.

- D2/W4: createSagaRuntime is reachable ONLY via @netscript/plugin-sagas-core/runtime
  (NOT root `.`, NOT src/public/mod.ts, NOT legacy createDurableSagaRuntime) — verified
- W3/IA: 10 export-backed Web Layer pages + 1 non-export examples showcase leaf (relabeled)
- IA query leaf: name root `.` cache helpers (hasAllCacheEntries/minCachedAt/projectCachedItemFromList)
- W5/decision 5: process gates made mechanically enforceable (marker grammar + check scripts
  + featureGrid/diagram throw-on-missing, wired into build+CI)
- W1: Track-D = repoint 2 hrefs (default), not author a new tutorial
- seam-coverage: table-backed plugins (organization/twoFactor/admin/apiKey) require R1 schema-gen;
  only bearer/jwt are turnkey via R0
- W0: Mermaid pipeline gets determinism/rollback gate (temp-render diff + defer-not-block)

Audit trail: panel/fold-in.md. Next: OpenHands PLAN-EVAL cycle 2.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018fq9V7ujx7e1rWXi57qkPG
@rickylabs

Copy link
Copy Markdown
Owner Author

@openhands-agent model=openrouter/minimax/minimax-m3 output=pr-comment

use harness

PLAN-EVAL — docs-v4-ia-deepening (cycle 2 of 2, FINAL)

You are the PLAN-EVAL evaluator (separate session from the generator). This is the layered PLAN
gate's binding Layer-A pass. Cycle 1 returned FAIL_PLAN with 3 required fixes; this is the single
remaining cycle before escalation. Read .llm/harness/evaluator/plan-protocol.md and
.llm/harness/gates/plan-gate.md, then evaluate the corrected plan and emit PASS or FAIL_PLAN.

This is a PLANNING evaluation only. Do NOT author docs, do NOT change framework code, do NOT touch
docs/site. Work from the local worktree + deno doc + source reads. Write your verdict to
.llm/tmp/run/docs-v4-ia-deepening/plan-eval.md AND post it as this PR comment.

What changed since cycle 1

  • Cycle-1 required fixes (commit 949d1d99): (1) saga symbol corrected, (2) risk register
    RR-1/RR-2 added, (3) W4 R1 schema-gen caveat added.
  • WSL Codex adversarial panel (Layer B, separate session) returned CHANGES_REQUIRED with 7
    findings; all folded in commit b9f46222.
    The fold-in record + what-could-not-be-broken is in
    .llm/tmp/run/docs-v4-ia-deepening/panel/fold-in.md. The panel independently concurred with your
    cycle-1 rulings on the 3 open IA questions.

NOTE/CORRECTION you should verify: cycle-1 plan-eval.md stated createSagaRuntime is re-exported via
packages/plugin-sagas-core/src/public/mod.ts. The Codex panel and a source re-check found this is
WRONG — createSagaRuntime is reachable ONLY via the ./runtime export subpath
(@netscript/plugin-sagas-core/runtimesrc/runtime/mod.ts:75), NOT root . and NOT
src/public/mod.ts. deno.json maps ../mod.ts, ./runtime./src/runtime/mod.ts. The plan
now cites the subpath; please confirm the corrected claim against source rather than re-asserting the
cycle-1 path.

Inputs to read (under .llm/tmp/run/docs-v4-ia-deepening/)

  • plan.md — locked decisions (esp. 1, 4, 5), workstreams W0–W6, build/eval/merge flow
  • ia-tree.md — the concrete 3-level Capability-Hub IA tree
  • seam-coverage.md — capability seam audit + the better-auth R0 decision + R1 table-backed caveat
  • drift.md — D1 process failure, D2 saga-symbol drift (corrected), risk register RR-1/RR-2
  • research.md — Phase-0 scout synthesis
  • panel/fold-in.md — the 7 panel findings + how each was resolved
  • .llm/harness/debt/arch-debt.md — entry "packages/auth-better-auth — seamless better-auth
    integration roadmap" (R0–R5)

Verify (emit FAIL_PLAN only on a genuine, evidenced defect)

  1. The 3 cycle-1 required fixes are correctly applied (re-verify the saga subpath per the correction
    above; confirm RR-1/RR-2 and the W4 R1 caveat are concrete and correct).
  2. The 7 panel fixes are sound: (a) saga subpath citation; (b) "10 export-backed + 1 examples leaf"
    page accounting matches ia-tree.md; (c) query leaf names the root . cache helpers that
    actually exist; (d) W5 gates are now mechanically enforceable (marker grammar + named check
    scripts + featureGrid/diagram throw-on-missing); (e) Track-D is repoint-only; (f) table-backed
    better-auth plugins carry the R1 caveat and only bearer/jwt are turnkey via R0; (g) W0 Mermaid
    determinism/rollback gate exists.
  3. Plan-Gate checklist items (gates/plan-gate.md): scope bounded, archetype/overlay correct
    (SCOPE-docs + the auth R0 ARCHETYPE slice), every documented capability either seamed or
    tracked-as-limitation, no >3 authored IA levels, no orphan leaf.
  4. Ground every symbol/export claim in deno doc or a source read — no assertions from memory.

Output

Emit a one-line verdict (PASS or FAIL_PLAN) at the top, then the rationale. If FAIL_PLAN, list
ONLY genuine blocking defects with file:line + source evidence + concrete fix — do not re-litigate
already-correct items. Preserve lock hygiene: do not commit deno.lock or source churn.

SKILL

  • .agents/skills/netscript-harness — harness phases, PLAN-EVAL/plan-gate doctrine, verdict shape
  • .agents/skills/netscript-doctrine — package/plugin archetype + public-surface gates (auth R0
    touches ARCHETYPE code; IA pillars mirror package boundaries)
  • .agents/skills/netscript-deno-toolchaindeno doc / deno doc --filter to verify export
    surfaces (Fresh subpaths, saga/auth symbols) — primary verification tool
  • .agents/skills/netscript-tools — raw-git verification + validation-evidence conventions
  • .agents/skills/netscript-cli — CLI surface (netscript db add, scaffold) referenced by Data/Identity pillars

@rickylabs

rickylabs commented Jun 22, 2026

Copy link
Copy Markdown
Owner Author

OpenHands Agent — Completed

Model: openrouter/minimax/minimax-m3
Provider: OPENROUTER
Job status: success
Trace: .llm/tmp/run/openhands/pr-107/run-27938414502-1 (committed to the PR branch)
Artifact: openhands-agent-27938414502-1

OpenHands Run Summary — 27938414502-1

Run-id: 27938414502-1
Trigger: @openhands-agent model=openrouter/minimax/minimax-m3 output=pr-comment — run PLAN-EVAL (separate-session plan gate) for the docs-v4 IA-deepening run on PR #107, cycle 2 of 2, FINAL.
PR: #107 (planning-only PR for docs-v4-ia-deepening)
Branch: docs/v4-ia-deepening @ b9f46222
Output mode: pr-comment
Selected model: openrouter/minimax/minimax-m3 (provider OPENROUTER)
Selected role: PLAN-EVAL (separate session; not the Claude author / not the WSL Codex implementer / not the WSL Codex panel that ran cycle 2 Layer-B)
Verdict: PASS — see plan-eval.md for full rationale. This is cycle 2 of 2 (FINAL).

Summary

Performed the FINAL PLAN-EVAL pass on the docs-v4-ia-deepening planning PR. Cycle 1 returned
FAIL_PLAN with 3 required fixes (commit 949d1d99); the WSL Codex adversarial panel (separate
Layer-B session) returned CHANGES_REQUIRED with 7 findings, all folded into b9f46222. This
cycle 2 (the single remaining cycle before escalation) verified the corrected plan against the
live repo source tree on origin/docs/v4-ia-deepening @ b9f46222 and against the 8 Plan-Gate
checklist items.

Headline: PASS. All 3 cycle-1 fixes are correctly applied; all 7 panel fixes are folded;
the user-flagged NOTE/CORRECTION about the createSagaRuntime subpath is source-verified (the
cycle-1 claim about src/public/mod.ts re-export was wrong — createSagaRuntime is reachable
ONLY via the @netscript/plugin-sagas-core/runtime subpath, and b9f46222 cites the subpath);
the Plan-Gate checklist is fully satisfied; the 3 open IA questions were ruled (panel concurred).

Changes

Deliverable artifacts written

  • .llm/tmp/run/docs-v4-ia-deepening/plan-eval.md — full cycle-2 PLAN-EVAL verdict: 8
    independent spot-checks against the live source tree (with file:line citations), 8-row
    Plan-Gate checklist table, rulings on the 3 IA questions, PR-comment body, and explicit
    "What this PR may NOT do" guard rails (no packages/**/plugins/** code on this docs PR;
    docs/site stays worktree-orphan; no deno.lock/source churn).
  • /home/runner/work/_temp/openhands/27938414502-1/summary.md — this file.

PR-comment body (cycle 2)

A PR-comment body for PR #107 (rendered verbatim from the ## PR-comment body section of
plan-eval.md) is included above for the workflow to post:

  • Verdict: PASS (cycle 2 of 2, FINAL).
  • Verification of all 3 cycle-1 fixes + all 7 panel fixes.
  • 3 IA-question rulings (Background Processing vs Durable Workflows = SPLIT; Reference =
    pillar-local + thin global index; Fresh Examples = prose now).
  • Guard rails (no code on docs PR; docs/site orphan; no deno.lock churn).

Source-tree / framework changes

  • None. PLAN-EVAL is a planning verdict; no files under packages/, plugins/,
    docs/site, or framework code were modified in this run.
  • No commit was created in this run.
  • deno.lock is untouched.

Validation

This is a planning-only PR (per plan.md §"Build / eval / merge flow" step 1: "No
authoring/build before PASS"). No deno check / deno task check / deno task e2e:cli was
needed; validation lives in IMPL-EVAL after the build branch ships.

Spot-checks performed (read-only, source-grounded):

  1. packages/plugin-sagas-core/src/runtime/mod.ts:75export { createSagaRuntime } from './create-saga-runtime.ts';
  2. packages/plugin-sagas-core/deno.json"exports" maps ../mod.ts,
    ./runtime./src/runtime/mod.ts. createSagaRuntime reachable ONLY via ./runtime. ✓
  3. packages/plugin-sagas-core/src/public/mod.ts — grep for createSagaRuntime returns
    ZERO matches; the cycle-1 plan-eval's claim of a src/public/mod.ts re-export is
    confirmed WRONG against source. ✓ (This is exactly the user-flagged NOTE/CORRECTION.)
  4. packages/fresh/deno.json — 11 export subpaths (./server, ./builders, ./route,
    ./defer, ./form, ./error, ./streams, ./query, ./interactive, ./vite,
    ./testing) — every IA-tree Web-Layer export-backed page maps to a real subpath; the
    11th is the prose-only "Examples / sandbox" showcase leaf. ✓
  5. packages/fresh/src/application/builders/mod.ts:26definePage exists; root .
    exports hasAllCacheEntries, minCachedAt, projectCachedItemFromList. ✓
  6. packages/auth-better-auth/src/better-auth.tsNetscriptBetterAuthOptions interface
    has no plugins field (fields present: prisma, provider, debugLogs?, usePlural?,
    transaction?, appName?, baseURL?, basePath?, secret?, trustedOrigins?, advanced?,
    telemetry?); BetterAuthInstance is a structural { handler, api.getSession }
    interface; the createBetterAuthBackend({ auth }) escape hatch type-checks. ✓
  7. .llm/tools/docs/ — does NOT exist yet; per plan, W5 ships .llm/tools/docs/check-caveat-harvest.ts
    and .llm/tools/docs/check-seam-coverage.ts as deliverables (consistent with panel
    fix Wave 0b·A — Plan-Gate reinforcement (Plan & Design — READY FOR REVIEW) #4).
  8. packages/plugin-sagas-core/mod.tsexport * from './src/public/mod.ts'; — no
    createSagaRuntime on root .. Confirms the corrected subpath claim.

Responses to review comments or issue comments

Remaining risks

  • RR-1 (ordering: R0 seam PR must land before docs that document R0 path go live). Mitigations
    documented in drift.md (hold-merge OR explicit "shipping in <ref>" callout). IMPL-EVAL
    verifies mitigation before docs go live.
  • RR-2 (R0 ships without R1 schema-gen → documented plugins fail at runtime on missing tables).
    Page-level R1 caveat is locked in plan.md W4 lines 71–72 + seam-coverage.md:3642.
  • W5 deliverables are still to be authored (check-caveat-harvest.ts,
    check-seam-coverage.ts, featureGrid/diagram throw-on-missing extensions). Plan names
    them by path + behaviour; verification happens in IMPL-EVAL on the build branch.
  • docs/site is worktree-orphan in this planning run — opens in the build branch AFTER
    this verdict lands.
    Run: https://github.com/rickylabs/netscript/actions/runs/27938414502

openhands-agent and others added 3 commits June 22, 2026 08:19
Layer A OpenHands minimax-M3 PLAN-EVAL cycle 2 = PASS (run 27938414502-1);
Layer B WSL Codex panel findings all folded + re-verified. Hard stop lifted;
build phase (W0-W6 + R0 seam) unblocked. 3 IA questions ruled (split BG/DW;
pillar-local Reference + thin index; Fresh examples prose-now).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018fq9V7ujx7e1rWXi57qkPG
rickylabs added a commit that referenced this pull request Jun 22, 2026
…ith stable id seamless-auth-roadmap

Carries the auth-better-auth seamless-integration roadmap (R0 passthrough through R5 plugin-aware Principal mapping) from PR #107 onto docs/v4-ia-build, adding a backtick stable id so the caveat-reference gate can resolve arch-debt:seamless-auth-roadmap markers in the upcoming supervised marker pass.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

Claude-Session: https://claude.ai/code/session_018fq9V7ujx7e1rWXi57qkPG
@rickylabs

Copy link
Copy Markdown
Owner Author

Closing as superseded. This is a planning-only PR — 58 files, all under .llm/tmp/ run-artifacts (+1 harness doc), zero docs/site content.

The docs-v4 content it planned already shipped to main via #110 (docs-only re-land). The auth R0–R5 roadmap and the ERP-sync CSV finding from this track are recorded in .llm/harness/debt/arch-debt.md via #112 (merged). Nothing here is mergeable to main.

Reopen if the planning trail is needed; the branch is left in place.

@rickylabs rickylabs closed this Jun 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants