Skip to content

[WAIFUS Phase 5] Canonical PR 2: complete technical and installed identity #150

Description

@slashdevcorpse

Current control issue in slashdevcorpse/synara. During Phase 6, recreate any still-open phase tracker in slashdevcorpse/waifus and preserve this URL in the cutover map.

Owner: slashdevcorpse
Source plan: docs/plans/waifus-rebrand-and-repository-independence.md
Approved plan SHA-256: B3D07F514F3E7D90C3EC4A8C586CD34E145D1673ED661B8D76D52F278AEC336A

Goal

Merge Canonical PR 2 so WAIFUS becomes the sole active technical, installed, packaged, generated, and writer identity while retaining only explicit hidden migration adapters and preparing default-disabled Windows qualification.

Gates and dependencies

  • Blocked by: Phase 4
  • Gate coverage: Phase 4; P-1A; G-3/G-6/G-7/G-12; Phase 7 later closes P-1B, P-2A, P-2B, P-3, and P-4.
  • Exit gate: The full supported Windows migration matrix passes, WAIFUS is the only active visible and technical writer identity, allowed legacy readers are isolated and time-bounded, no inherited art is active, and the canonical public repository is anonymously readable and protected. Only x64 is emitted; unsupported OS/architecture/user/topology rejection and the default-disabled G-12 qualification graph pass without publication credentials.

Tracking

  • Dependency and gate inputs are verified.
  • Every requirement in the collapsed goal.md is complete.
  • Required evidence is linked in this issue.
  • STOP conditions are clear.
  • Exit gate is independently verified.

Outputs

  • WAIFUS-only package/import/environment/CLI/MCP/protocol/storage/installer/runtime identity.
  • Transactional migration with one selected .8/.9/.10 topology, immutable backup, health commit, rollback, and removal inventory.
  • x64-only Windows guards and default-disabled qualification graph with no publication credential.

PR structure

GitHub native Stacked PRs is private preview and is not a dependency. Do not combine this phase with an adjacent phase and do not use an atomic multi-PR stack merge. Exactly Canonical PR 2, based on merged Phase 4 main. Do not stack Phase 6 mutations or Phase 7 activation onto it.

goal.md

Phase 5 — Canonical PR 2: complete technical and installed identity

Objective

Merge Canonical PR 2 so WAIFUS becomes the sole active technical, installed, packaged, generated, and writer identity while retaining only explicit hidden migration adapters and preparing default-disabled Windows qualification.

Source of truth

  • Plan path: docs/plans/waifus-rebrand-and-repository-independence.md
  • Approved SHA-256: B3D07F514F3E7D90C3EC4A8C586CD34E145D1673ED661B8D76D52F278AEC336A
  • Owner: slashdevcorpse
  • Applicable gate coverage: Phase 4; P-1A; G-3/G-6/G-7/G-12; Phase 7 later closes P-1B, P-2A, P-2B, P-3, and P-4.
  • If this embedded goal conflicts with the approved plan, stop and resolve the conflict before mutation.

Prerequisites

  • The native blocked-by dependency above is complete.
  • Applicable provisioning, identity, governance, release, and migration gates are verified at the exact current state.
  • Required mutation authority exists before any external write.
  • No later phase is pulled forward.

Requirements

  • Replace the selectable production/development/Canary/Super identity model
    with one WAIFUS product identity. Stable/dev are update channels, not separate
    branded applications.
  • Rename package scopes/imports, package metadata, source types/functions,
    environment variables, CLI/MCP discovery, protocols, active files, workflows,
    scripts, fixtures, current docs, logs, generated schemas, and release
    assertions to WAIFUS as defined by FR-28 and G-7. Keep the root and internal
    workspaces non-publishable, enforce internal workspace:* resolution, make
    only @slashdevcorpse/waifus public, and replace the optional token/toggle
    publication path with two mutually exclusive exact-tarball branches:
    one-day-token 0.6.0, then post-P-1B OIDC for every later stable/dev version.
  • Change desktop display/executable name, bundle/AUMID, profile/home target,
    protocol, shortcuts, Apps & Features metadata, installer/uninstaller copy,
    notifications/dialogs, updater cache, and all active icons to WAIFUS. Encode
    Windows 11 25H2 Home/Pro native x64 base-build-family 26200,
    LocalAppData/HKCU per-user installation, and
    explicit oneClick: true, perMachine: false, allowElevation: false,
    packElevateHelper: false, and deleteAppDataOnUninstall: false; reject
    unsupported OS/architecture/elevation/user/topology before mutation.
  • Implement the G-6 transactional migration: positively identify the closed
    source, snapshot/journal outside both profiles, copy into staged WAIFUS roots,
    apply target-wins collision handling, migrate protected secrets through the
    secret-store boundary, reattach provider-owned auth, atomically promote, and
    commit only after the complete two-launch/restart health gate. Record every
    adapter, collision, backup, rollback, and exact removal release.
  • Run the same-normal-user x64 per-user .8/.9/.10 cross-brand matrix as
    one topology decision. Retain
    ab3ea852-4edf-4caa-977e-9d00ccab2b1e only if all three prove the primary
    one-registration takeover. Otherwise use fallback GUID
    41f4087f-f48d-59ac-a73a-01e30e490434 for all three, preserve Super through
    the health commit, then remove its app-owned registration/files/shortcuts/
    protocol ownership automatically. Quarantine every pending Super update.
  • Update brand scans, package/import checks, artifact policy, packaged-startup,
    migration recovery, installer qualification, and snapshot fixtures. Delete
    every active inherited logo/file rather than allowlisting its filename.
  • Test fresh install plus direct transitions from every supported published
    Super Synara source: .8, .9, and .10. Reject every unrecognized, older,
    newer, modified, cross-user, elevated, per-machine, ARM, or downgrade source;
    do not invent an intermediate route.
  • For every source verify projects, threads, settings, provider configuration,
    protocol handling, update-channel default, restart, native Windows provider
    discovery/spawn, recovery, Start menu/taskbar/Apps & Features identity,
    uninstall, reinstall, and application-data survival.
  • Prove exact pre-commit restore/return to untouched Super and state before
    installation that post-health-commit reverse rollback is unsupported. Prove
    reinstall/roll-forward WAIFUS recovery from the immutable backup instead.
  • Run the exact active-tree and packaged-artifact legacy scan. Only legal,
    historical, upstream-remote, and named hidden migration-adapter matches pass.
  • Re-run the public-readiness and anonymous-access checks before canonical
    issue creation, website launch, npm application-package publication, or
    GitHub release publication. No repository visibility change exists.
  • Add the default-disabled G-12 qualification graph and deterministic
    qualificationInputHash: one windows-2025 x64 build, same-byte
    windows-2022 inspection, and a protected-main GitHub-hosted coordinator that
    streams the candidate to the OIDC-authenticated external broker. Prove the
    broker has no GitHub credential/API authority; no GitHub self-hosted runner is
    registered; every never-registered standard or filtered-administrator worker
    accepts one bound job;
    and signed image/reset/destruction evidence returns without enabling
    publication.

Required outputs

  • WAIFUS-only package/import/environment/CLI/MCP/protocol/storage/installer/runtime identity.
  • Transactional migration with one selected .8/.9/.10 topology, immutable backup, health commit, rollback, and removal inventory.
  • x64-only Windows guards and default-disabled qualification graph with no publication credential.

Verification

  • Fresh install plus all supported .8/.9/.10 transitions pass with data, provider, updater, recovery, uninstall, and reinstall coverage.
  • Only x64 is emitted and unsupported OS/architecture/user/elevation/topology aborts before mutation.
  • Active-tree and packaged-artifact scans contain only classified legal, historical, upstream, or hidden adapter references.

Exit criteria

The full supported Windows migration matrix passes, WAIFUS is the only active visible and technical writer identity, allowed legacy readers are isolated and time-bounded, no inherited art is active, and the canonical public repository is anonymously readable and protected. Only x64 is emitted; unsupported OS/architecture/user/topology rejection and the default-disabled G-12 qualification graph pass without publication credentials.

Non-goals

  • Any package, release, Pages, live TUF, or updater enrollment.
  • Closing the Phase 7 provisioning gates.
  • macOS, Linux, ARM64, elevated, per-machine, cross-user, or unsupported Windows work.

STOP conditions

  • Any active legacy writer/identity or inherited art remains.
  • No single topology passes all three supported sources.
  • Publication activates or the qualification broker/worker gains GitHub authority.
  • The exact current PR head, base, checks, review, DCO, provenance, or owner authorization is stale or incomplete where a PR is required.
  • Work would expand beyond this phase or contradict the approved plan.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions