docs: establish canonical product, architecture, and acquisition spine - #305
docs: establish canonical product, architecture, and acquisition spine#305seonghobae wants to merge 13 commits into
Conversation
|
Warning Review limit reached
Next review available in: 37 minutes You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughClearfolio의 제품·아키텍처·API·보안·운영·릴리스 문서를 전면 개편했습니다. ADR과 추적성 문서를 추가하고, 문서 구조와 자동화·스케줄러 계약을 검증하는 Python 테스트를 추가했습니다. ChangesClearfolio 문서 체계
Estimated code review effort: 4 (Complex) | ~60 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai review |
✅ Action performedReview finished.
|
There was a problem hiding this comment.
Actionable comments posted: 16
🧹 Nitpick comments (2)
docs/adr/0010-release-provenance-fidelity-gate.md (1)
16-18: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win릴리스 게이트를 canonical 문서와 명시적으로 연결하십시오.
required CI/security...는 감사 가능한 gate 목록이 아닙니다.docs/RELEASE_ACCEPTANCE.md의 exact criteria를 참조하거나 zero skips/failures/errors, zero warnings/deprecations, Javadoc/doclint, Markdown lint, applicable JavaScript coverage, live review/security gates를 명시하십시오. 녹색이지만 불완전한 evidence set을 release acceptance로 처리하지 않도록 해야 합니다.Based on learnings, 최종 acceptance에는 zero skips/failures/errors, zero warnings/deprecations, warning-free public Javadocs/doclint, applicable JavaScript coverage, Markdown lint와 live required gates가 포함됩니다.
Also applies to: 36-45
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/adr/0010-release-provenance-fidelity-gate.md` around lines 16 - 18, Update the Decision section to explicitly reference the canonical release criteria in docs/RELEASE_ACCEPTANCE.md instead of the vague “required CI/security...” wording. State that acceptance requires zero skips/failures/errors and warnings/deprecations, warning-free public Javadocs/doclint, applicable JavaScript coverage, Markdown lint, and successful live required review/security gates, so incomplete evidence cannot pass.Source: Learnings
docs/adr/0009-work-conserving-rca-loop.md (1)
16-18: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win
fresh exit sweep를 검증 가능한 조건으로 정의하십시오.각 sweep이 live head/base를 다시 가져오는지, executable queue를 재생성하는지, deferred identity와 writer lease를 확인하는지 정의하십시오. 두 sweep 사이에 새 safe item이 생긴 경우를 검증하는 test도 추가하십시오.
Also applies to: 44-51
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/adr/0009-work-conserving-rca-loop.md` around lines 16 - 18, “Decision” 섹션에서 fresh exit sweep을 검증 가능한 절차로 정의하십시오: 각 sweep마다 live head/base를 재조회하고 executable queue를 재생성하며 deferred identity와 writer lease를 확인하도록 명시하십시오. 두 sweep 사이에 새 safe item이 추가되면 종료하지 않고 해당 item을 선택하는 테스트를 추가해 이 동작을 검증하십시오.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@CHANGELOG.md`:
- Around line 31-48: Update the duplicate Markdown headings in CHANGELOG.md,
specifically the “Added” and “Security” sections, so each heading is unique
under the current lint policy; preserve the changelog structure and content
while renaming or restructuring only the conflicting headings.
In `@CLAUDE.md`:
- Around line 42-45: CLAUDE.md의 42-45행과 README.md의 17-23행에 있는 로컬 스모크 테스트 절차를 수정해
애플리케이션 시작과 health check가 실행되도록 하십시오. 두 문서 모두 별도 터미널 절차로 명시하거나, PID 저장·종료 정리를 포함한
관리되는 백그라운드 실행 절차를 사용하고 동일한 방식을 유지하십시오.
In `@docs/adr/0001-standalone-msa-ownership.md`:
- Around line 32-34: Update docs/adr/0001-standalone-msa-ownership.md lines
32-34 to explicitly exempt direct-download signed-token consistency migration
from the “Existing HTTP flows remain valid” statement. Update
docs/adr/0002-tenant-artifact-authorization.md lines 32-34 to document the API
contract’s migration requirements: versioned migration, error/response
semantics, rollout order, and client/contract test conditions.
In `@docs/adr/0003-audit-pseudonymization-key-separation.md`:
- Around line 16-18: ADR-0003의 “governed minimum strength”와 “key-strength” 기준을
실행 가능한 요구사항으로 구체화하십시오. HMAC 알고리즘과 digest, 최소 키 길이·엔트로피, 인증된 저장소 또는 KMS 사용 조건을
명시하고 해당 조건을 검증하도록 key-strength 테스트를 갱신하십시오. 키 회전, 버전 활성화, 이전 버전 처리 및 회귀 정책을
정의하며, 근거가 되는 최신 표준 문서의 안정적인 APA 7 링크를 추가하십시오.
In `@docs/adr/0004-durable-lifecycle-generation-fencing.md`:
- Around line 36-38: Update the “Tests and acceptance” section’s coverage
criterion to explicitly identify the measured scope and units, using the
canonical production-owned statement and branch coverage wording or the
equivalent JaCoCo line/branch missed-equals-zero form.
In `@docs/adr/0005-deterministic-conversion-fidelity.md`:
- Around line 35-39: Update the “Failure and recovery” section of ADR-0005 to
explicitly classify degraded evidence as a subtype of the public FAILED terminal
state. State that degraded output does not introduce a fifth terminal state and
must not create a supported-format claim; only introduce a separate public state
if accompanied by a versioned API change and consumer tests.
In `@docs/adr/0006-liveness-readiness-separation.md`:
- Line 18: Clarify the `/healthz` and `/readyz` access policy in the ADR by
replacing the vague orchestration-only authentication statement with testable
rules for allowed network sources or namespaces, HTTP methods, ingress exposure,
and authentication requirements. Define the intended unauthenticated scope and
ensure both probe endpoints cannot be exposed beyond those boundaries.
- Around line 32-34: Update the “Compatibility and migration” section of the ADR
to define the rollout order: deploy /readyz, migrate orchestrator probes and
existing clients, then change or retire /healthz readiness semantics. Specify
rollback steps that preserve the old /healthz behavior and require compatibility
tests covering both endpoints during migration.
In `@docs/adr/0007-exact-head-live-base-evidence.md`:
- Around line 16-18: Document the merge operation’s atomic preconditions in the
Decision section: it must verify the expected source-head SHA and supported
base-tip SHA at merge time, reject the merge if either changes after refetch,
and require fresh-state revalidation; add an acceptance test covering branch
movement in the refetch-to-merge race if the repository defines such tests.
In `@docs/adr/0008-central-vs-local-automation-authority.md`:
- Around line 16-18: Update the Decision section to explicitly define the
Clearfolio-local OpenCode loop as the only actor permitted to process ACTIVE_PR,
while central fleet loops must keep Clearfolio disabled. Document the local
agent’s immutable pinned-agent and supply-chain constraints, or state an
explicit equivalent exception, to prevent duplicate writers and credential-scope
violations.
In `@docs/DOCUMENTATION_ASSESSMENT.md`:
- Line 11: Update the two status labels in the documentation assessment text
around the canonical branch description and the later protected-main statement
from hyphenated forms to the exact underscore forms DESIGN_SUFFICIENT and
PROTECTED_MAIN_SUFFICIENT, matching the definitions at lines 39–40 and
preserving all surrounding wording.
- Around line 3-5: Update the assessment metadata in DOCUMENTATION_ASSESSMENT.md
to pin PR `#305` to its exact head SHA instead of identifying it only by PR
number. Record the headRefOid, baseRefOid, UTC evidence timestamp, review
decision, and required-check results, either in the assessment record or a
dedicated Snapshot document, while preserving the existing baseline and scope
statements.
In `@docs/RESEARCH_TRACEABILITY.md`:
- Around line 8-34: Update the references in “Standards and technical-source
mapping” and “Current Office-adapter source refresh” to use stable, versioned
publication URLs or DOI links where available, and complete each source as an
APA 7 reference entry. Add APA 7 entries for the JODConverter “Office Managers”
and “Configuration overview” sources, and replace `/latest/` links with their
fixed versioned documentation paths, including the existing 4.4.11 migration
guide.
In `@docs/TEST_STRATEGY.md`:
- Around line 74-92: Update the “Canonical Maven acceptance” command block in
TEST_STRATEGY.md to run scripts/test_documentation_spine_contract.py and include
python3 -m unittest discover -s scripts for canonical scripts/*.py acceptance
checks. Keep the existing Maven verification and report-validation commands
unchanged.
In `@scripts/test_documentation_spine_contract.py`:
- Around line 135-149: Update the documentation assertions in the test method
containing the combined variable so each authoritative document is validated
independently for an explicit classification that placeholders are not
production Office fidelity. Add separate assertions rejecting statements that
claim placeholders provide Office fidelity, rather than relying on aggregate
keyword presence in combined.
- Around line 12-26: Add docs/engineering/acceptance-criteria.md to the
CANONICAL_DOCUMENTS tuple in test_documentation_spine_contract.py, and add the
same document to ARCHITECTURE.md’s canonical graph links. Preserve the existing
document-existence validation behavior so deleting the acceptance-criteria file
causes the contract check to fail.
---
Nitpick comments:
In `@docs/adr/0009-work-conserving-rca-loop.md`:
- Around line 16-18: “Decision” 섹션에서 fresh exit sweep을 검증 가능한 절차로 정의하십시오: 각
sweep마다 live head/base를 재조회하고 executable queue를 재생성하며 deferred identity와 writer
lease를 확인하도록 명시하십시오. 두 sweep 사이에 새 safe item이 추가되면 종료하지 않고 해당 item을 선택하는 테스트를
추가해 이 동작을 검증하십시오.
In `@docs/adr/0010-release-provenance-fidelity-gate.md`:
- Around line 16-18: Update the Decision section to explicitly reference the
canonical release criteria in docs/RELEASE_ACCEPTANCE.md instead of the vague
“required CI/security...” wording. State that acceptance requires zero
skips/failures/errors and warnings/deprecations, warning-free public
Javadocs/doclint, applicable JavaScript coverage, Markdown lint, and successful
live required review/security gates, so incomplete evidence cannot pass.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 03662890-d902-4e4a-a431-3c586df829bf
📒 Files selected for processing (32)
AGENTS.mdARCHITECTURE.mdCHANGELOG.mdCLAUDE.mdREADME.mddocs/API_CONTRACT.mddocs/DATA_MODEL.mddocs/DOCUMENTATION_ASSESSMENT.mddocs/FIDELITY_ACCEPTANCE.mddocs/MIGRATION_ROLLBACK.mddocs/OPERABILITY.mddocs/PRD.mddocs/RELEASE_ACCEPTANCE.mddocs/RESEARCH_TRACEABILITY.mddocs/TEST_STRATEGY.mddocs/THREAT_MODEL.mddocs/TRACEABILITY.mddocs/TRD.mddocs/UML.mddocs/adr/0001-standalone-msa-ownership.mddocs/adr/0002-tenant-artifact-authorization.mddocs/adr/0003-audit-pseudonymization-key-separation.mddocs/adr/0004-durable-lifecycle-generation-fencing.mddocs/adr/0005-deterministic-conversion-fidelity.mddocs/adr/0006-liveness-readiness-separation.mddocs/adr/0007-exact-head-live-base-evidence.mddocs/adr/0008-central-vs-local-automation-authority.mddocs/adr/0009-work-conserving-rca-loop.mddocs/adr/0010-release-provenance-fidelity-gate.mddocs/adr/README.mddocs/repository-metadata.mdscripts/test_documentation_spine_contract.py
|
@opencode-agent @cwl-noema-review Please independently review exact current head |
There was a problem hiding this comment.
Actionable comments posted: 10
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (2)
CLAUDE.md (2)
113-121: 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick winStale identity 발생 시 쓰기를 중지하고 작업을 회전하십시오.
현재 규칙은 head, base, review, check, target blob/ref를 다시 조회하도록 요구합니다. 그러나 다른 writer가 조회 후 대상 identity를 변경한 경우의 동작을 정의하지 않습니다. 이 상태에서 writer가 계속 쓰면 stale branch에 변경을 적용할 수 있습니다.
docs/DOCUMENTATION_ASSESSMENT.md의 Line 9-20처럼 stale identity를 거부하고, 현재 작업을 동결한 뒤 새 exact-head 작업으로 회전하는 규칙을 추가하십시오.Based on learnings, a moved target must trigger freeze-and-rotate instead of a write race.
수정 예시
5. refetch target blob/ref before writing. +6. If any refetched identity differs from the write target, stop the current + operation, preserve the evidence, and rotate to a new exact-head work item. + Never write against the stale identity.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@CLAUDE.md` around lines 113 - 121, Update the “Before reviewing, editing or merging” rules in CLAUDE.md to define stale-identity handling: after refetching the PR head, base, reviews, checks, security gates, and target blob/ref, stop and freeze all writes if another writer has moved the target identity, reject the stale work, and rotate to a new exact-head task. Align this behavior with the stale-identity guidance in DOCUMENTATION_ASSESSMENT.md.Source: Learnings
7-20: 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick winCLAUDE.md의 canonical authority set을 두 위치에서 동일하게 보완하십시오.
현재 authority 목록과 material-change 규칙이 모두 fidelity, recovery, release acceptance, research traceability 문서를 누락합니다. 한 위치만 수정하면 Agent가 문서를 읽는 경로와 문서를 갱신하는 규칙이 다시 분리됩니다.
CLAUDE.md#L7-L20:docs/FIDELITY_ACCEPTANCE.md,docs/MIGRATION_ROLLBACK.md,docs/RELEASE_ACCEPTANCE.md,docs/RESEARCH_TRACEABILITY.md를 canonical authority 목록에 추가하거나 명시적 authority 링크를 추가하십시오.CLAUDE.md#L147-L150: 동일한 네 문서를 material-change synchronization 대상에 추가하십시오.As per coding guidelines, material documentation changes must update the corresponding canonical documents in the same reviewed change.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@CLAUDE.md` around lines 7 - 20, CLAUDE.md의 canonical authority 목록에 docs/FIDELITY_ACCEPTANCE.md, docs/MIGRATION_ROLLBACK.md, docs/RELEASE_ACCEPTANCE.md, docs/RESEARCH_TRACEABILITY.md를 추가하고, 동일한 네 문서를 material-change synchronization 대상에도 반영하십시오. CLAUDE.md 7-20행과 147-150행의 두 위치를 모두 수정해 문서 읽기 경로와 갱신 규칙이 일치하도록 하십시오.Source: Coding guidelines
♻️ Duplicate comments (2)
docs/RESEARCH_TRACEABILITY.md (2)
14-14: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick winKubernetes 참고문헌의 날짜를 완전한 APA 7 형식으로 기록하세요.
공식 페이지는 최종 수정일을 2026년 4월 17일로 표시합니다. 이 날짜를 참고문헌 날짜로 사용한다면 두 항목을
(2026, April 17)로 맞추세요. 발행일을 확인할 수 없다면(n.d.)와 검색일을 사용하세요. 현재 연도만 기록한 항목은 완전한 APA 7 항목이 아닙니다. (kubernetes.io)Also applies to: 45-45
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/RESEARCH_TRACEABILITY.md` at line 14, Update the Kubernetes probes reference entry to use the complete APA 7 date format `(2026, April 17)` consistently in both affected entries, preserving the existing citation title, URL, and explanatory text.Source: MCP tools
36-36: 🔒 Security & Privacy | 🟡 Minor | ⚡ Quick winJODConverter 라이선스 링크를 immutable reference로 고정하세요.
master브랜치 링크는 이후 변경될 수 있습니다. JODConverter 4.4.11 태그 또는 커밋 permalink를 사용해 라이선스 근거를 재현 가능하게 유지하세요.As per coding guidelines, material provenance and licensing references require stable links.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/RESEARCH_TRACEABILITY.md` at line 36, Update the JODConverter license citation in the research traceability document to use an immutable reference for version 4.4.11, such as its tag or commit permalink, instead of the mutable master-branch URL. Preserve the existing citation details and license-file target.Source: Coding guidelines
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/adr/0003-audit-pseudonymization-key-separation.md`:
- Around line 42-43: Update the production key-strength acceptance test in the
audit pseudonymization key requirements to reject non-random and deterministic
low-entropy material, not only short keys or known placeholders. Require
provenance from an approved CSPRNG, KMS, or credential registry, and add
coverage for repeated 32-byte values and deterministic fixtures while preserving
the existing purpose-separation checks.
- Around line 62-64: Update the SP 800-224 bibliography entry in the ADR to use
the individual authors Sönmez Turan, M., and Brandão, L. T. A. N. in APA 7
format, retain the publication year and title, place the NIST Special
Publication designation after the title, and list National Institute of
Standards and Technology as the publisher without duplicating it as the author.
In `@docs/adr/0007-exact-head-live-base-evidence.md`:
- Line 20: Update the merge-path requirements in this ADR so acceptance
atomically binds both the expected source-head SHA and supported base-tip SHA,
using compare-and-swap or an equivalent mechanism. Reject platforms that cannot
guarantee exact base-tip equality; do not rely on live-base refetch plus
ancestry rules alone, and abort/restart when either value moves. Update the
acceptance test at the exact-SHA criterion to verify equality rather than
ancestry.
In `@docs/adr/0008-central-vs-local-automation-authority.md`:
- Around line 18-22: Update the central PR-maintenance exception in the ADR so
any source-mutating repair is allowed only after the local writer lease is
released or fenced and the central action acquires that same writer lease.
Alternatively, restrict central actions to read-only review/evaluation and
merging commits produced by the leased local writer; preserve the prohibition on
competing with an active local source writer and align the wording with the
active-writer freeze rule.
In `@docs/adr/0009-work-conserving-rca-loop.md`:
- Around line 36-40: Update the exit-sweep requirements in this ADR to refetch
every evidence authority defined by ADR-0007, including commit status, model
verdict, check runs, and workflow evidence, not only reviews and required
checks. Require each evidence item to bind to the exact current
PR/head/base/run/review identity and invalidate mismatches; extend the
regression tests referenced near the exit-sweep test section to cover stale
evidence for every authority class and reset behavior when a new head or base is
discovered.
In `@docs/RESEARCH_TRACEABILITY.md`:
- Line 13: Update the WCAG 2.2 citation in the Web accessibility row to use the
2024 fixed publication URL, https://www.w3.org/TR/2024/REC-WCAG22-20241212/, and
adjust the publication date to 2024. If retaining the 2023 edition, add the 2024
fixed publication as a separate citation.
- Line 17: Update the CycloneDX entries in docs/RESEARCH_TRACEABILITY.md,
including the references around the existing v1.6 citations, to add the
authoritative current v1.7/ECMA-424 second-edition standard. Clearly label v1.6
as the repository’s historical SBOM baseline, and state that the current
standard has advanced to v1.7 without changing implementation versions.
In `@scripts/test_release_loop_adr_contract.py`:
- Around line 13-16: Update read_text to return the original UTF-8 text without
lowercasing, so canonical path assertions can detect casing errors in
docs/RELEASE_ACCEPTANCE.md. Apply lowercase normalization only at the call sites
that perform case-insensitive phrase checks, while keeping path validation on
the original text.
- Around line 22-36: Update
test_fresh_exit_sweep_is_an_executable_revalidation_procedure so its required
ADR phrases also assert that the exit-sweep counter restarts after safe-item
execution and that termination requires two consecutive fresh sweeps with no
safe work. Preserve the existing assertions and use the exact wording present in
docs/adr/0009-work-conserving-rca-loop.md.
- Around line 38-52: Expand
test_release_adr_delegates_to_canonical_complete_acceptance to assert every
ADR-0010 release-evidence requirement has a documented contract owner, including
exact version/tag, immutable dependency lock, build artifact digests,
SBOM/attribution, provenance, and migration/rollback/restart. If any requirement
is intentionally not owned by a contract test, document its removal from the ADR
instead.
---
Outside diff comments:
In `@CLAUDE.md`:
- Around line 113-121: Update the “Before reviewing, editing or merging” rules
in CLAUDE.md to define stale-identity handling: after refetching the PR head,
base, reviews, checks, security gates, and target blob/ref, stop and freeze all
writes if another writer has moved the target identity, reject the stale work,
and rotate to a new exact-head task. Align this behavior with the stale-identity
guidance in DOCUMENTATION_ASSESSMENT.md.
- Around line 7-20: CLAUDE.md의 canonical authority 목록에
docs/FIDELITY_ACCEPTANCE.md, docs/MIGRATION_ROLLBACK.md,
docs/RELEASE_ACCEPTANCE.md, docs/RESEARCH_TRACEABILITY.md를 추가하고, 동일한 네 문서를
material-change synchronization 대상에도 반영하십시오. CLAUDE.md 7-20행과 147-150행의 두 위치를 모두
수정해 문서 읽기 경로와 갱신 규칙이 일치하도록 하십시오.
---
Duplicate comments:
In `@docs/RESEARCH_TRACEABILITY.md`:
- Line 14: Update the Kubernetes probes reference entry to use the complete APA
7 date format `(2026, April 17)` consistently in both affected entries,
preserving the existing citation title, URL, and explanatory text.
- Line 36: Update the JODConverter license citation in the research traceability
document to use an immutable reference for version 4.4.11, such as its tag or
commit permalink, instead of the mutable master-branch URL. Preserve the
existing citation details and license-file target.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 23ae4dcb-0cd4-43ff-a9d6-a6790e26eae4
📒 Files selected for processing (20)
ARCHITECTURE.mdCHANGELOG.mdCLAUDE.mdREADME.mddocs/DOCUMENTATION_ASSESSMENT.mddocs/FIDELITY_ACCEPTANCE.mddocs/RESEARCH_TRACEABILITY.mddocs/TEST_STRATEGY.mddocs/adr/0001-standalone-msa-ownership.mddocs/adr/0002-tenant-artifact-authorization.mddocs/adr/0003-audit-pseudonymization-key-separation.mddocs/adr/0004-durable-lifecycle-generation-fencing.mddocs/adr/0005-deterministic-conversion-fidelity.mddocs/adr/0006-liveness-readiness-separation.mddocs/adr/0007-exact-head-live-base-evidence.mddocs/adr/0008-central-vs-local-automation-authority.mddocs/adr/0009-work-conserving-rca-loop.mddocs/adr/0010-release-provenance-fidelity-gate.mdscripts/test_documentation_spine_contract.pyscripts/test_release_loop_adr_contract.py
🚧 Files skipped from review as they are similar to previous changes (10)
- docs/adr/0010-release-provenance-fidelity-gate.md
- CHANGELOG.md
- docs/adr/0004-durable-lifecycle-generation-fencing.md
- docs/TEST_STRATEGY.md
- docs/adr/0005-deterministic-conversion-fidelity.md
- docs/adr/0002-tenant-artifact-authorization.md
- scripts/test_documentation_spine_contract.py
- README.md
- docs/FIDELITY_ACCEPTANCE.md
- ARCHITECTURE.md
|
@coderabbitai review Please review the exact current source head |
|
I will treat predecessor-head findings as historical. I will check ADR-0011, the thin-scheduler additions, and the updated documentation-contract tests. I will report only current actionable findings. This review will remain advisory evidence and will not substitute for independent approval.
|
|
@opencode-agent @cwl-noema-review Please independently review exact current head |
There was a problem hiding this comment.
Actionable comments posted: 4
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (2)
CLAUDE.md (2)
7-24: 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win
CLAUDE.md의 문서 권위 목록을AGENTS.md와 일치시키십시오.
AGENTS.md의 canonical spine에는docs/DOCUMENTATION_ASSESSMENT.md가 포함되지만, 이 목록에는 없습니다. 반대로docs/FIDELITY_ACCEPTANCE.md,docs/MIGRATION_ROLLBACK.md,docs/RELEASE_ACCEPTANCE.md,docs/RESEARCH_TRACEABILITY.md는 계약 테스트 컨텍스트에서 별도 supplemental 문서로 취급됩니다. 네 문서를 supplemental로 구분하고docs/DOCUMENTATION_ASSESSMENT.md를 추가하거나,AGENTS.md와 계약 테스트의 분류를 함께 갱신하십시오. 현재 분류는 에이전트가 문서 권위를 잘못 판단하게 할 수 있습니다.권위 목록 수정 예시
- `docs/TRACEABILITY.md` + `docs/DOCUMENTATION_ASSESSMENT.md` - `docs/FIDELITY_ACCEPTANCE.md` - `docs/MIGRATION_ROLLBACK.md` - `docs/RELEASE_ACCEPTANCE.md` - `docs/RESEARCH_TRACEABILITY.md` + Supplemental release and research documents: + - `docs/FIDELITY_ACCEPTANCE.md` + - `docs/MIGRATION_ROLLBACK.md` + - `docs/RELEASE_ACCEPTANCE.md` + - `docs/RESEARCH_TRACEABILITY.md`🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@CLAUDE.md` around lines 7 - 24, Update the documentation authority list in CLAUDE.md to match AGENTS.md and the contract-test classification: add docs/DOCUMENTATION_ASSESSMENT.md to the canonical spine, and mark docs/FIDELITY_ACCEPTANCE.md, docs/MIGRATION_ROLLBACK.md, docs/RELEASE_ACCEPTANCE.md, and docs/RESEARCH_TRACEABILITY.md as supplemental documents. Alternatively, update AGENTS.md and the contract-test classification together so all three sources consistently define the same authority model.
117-126: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win병합 통과 조건에 보호된 브랜치 정책과 독립 승인을 명시하십시오.
현재 목록은 formal approval을 권한 유형으로만 설명합니다. 필수 조건으로 요구하지 않습니다. PR 목표는 qualifying independent approval과 branch-protection 요구사항이 아직 필요하다고 명시합니다. 보호된
main의 필수 검사, 필수 검토자 수, qualifying independent approval을 병합 전 통과 조건으로 추가하십시오. 자동화 댓글, 체크 결과, 모델 출력은 승인으로 계산하지 마십시오.병합 조건 추가 예시
5. refetch target blob/ref before writing; 6. if any refetched target identity differs from the identity the write was prepared against, stop and freeze that write, preserve the fresh evidence, and rotate to a newly revalidated exact-head work item instead of writing against stale state. +7. verify protected-branch requirements and at least one qualifying independent approval before merge;🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@CLAUDE.md` around lines 117 - 126, Update the merge-readiness requirements in the documented pre-merge checklist to explicitly require protected main branch rules, all required checks, the required reviewer count, and qualifying independent approval before merging. Clarify that automated comments, check results, and model output do not count as approval, while preserving the existing distinction between authority classes.Source: Learnings
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/adr/0011-thin-scheduler-control-plane.md`:
- Line 121: 문서 파일 끝에 누락된 단일 개행을 추가하여 MD047 markdownlint 경고를 해결하세요. ADR 본문 내용은
변경하지 마세요.
- Around line 48-58: The pre-write refetch contract must cover more than the PR
head: update the execution-semantics list in
docs/adr/0011-thin-scheduler-control-plane.md (lines 48-58) and the recovery
refetch procedure in docs/OPERABILITY.md (lines 99-103) to require current base,
formal reviews, unresolved threads, exact-head checks, security gates, and
target blob/ref. In both locations, specify freezing or stopping when target
identity changes, while preserving the existing safety and acceptance
requirements.
In `@scripts/test_documentation_assessment_security_contract.py`:
- Around line 38-42: Align the security authority wording between
docs/DOCUMENTATION_ASSESSMENT.md and the assertions in the security assessment
test: update the document to use “root SECURITY.md is the current product
security entrypoint” if that is the intended model, or revise the assertions to
match the canonical document. Remove the conflicting “root SECURITY.md remains
the reporting policy” expectation so the test and documentation express one
consistent authority model.
In `@scripts/test_release_loop_adr_contract.py`:
- Around line 81-91: Extend the required-text assertions in the ADR contract
test around the existing required tuple so it explicitly verifies that the
scheduler reads the current canonical repository documents before selecting or
changing product work. Use wording that matches the ADR-0011 requirement, while
preserving the existing authority and failure-contract checks.
---
Outside diff comments:
In `@CLAUDE.md`:
- Around line 7-24: Update the documentation authority list in CLAUDE.md to
match AGENTS.md and the contract-test classification: add
docs/DOCUMENTATION_ASSESSMENT.md to the canonical spine, and mark
docs/FIDELITY_ACCEPTANCE.md, docs/MIGRATION_ROLLBACK.md,
docs/RELEASE_ACCEPTANCE.md, and docs/RESEARCH_TRACEABILITY.md as supplemental
documents. Alternatively, update AGENTS.md and the contract-test classification
together so all three sources consistently define the same authority model.
- Around line 117-126: Update the merge-readiness requirements in the documented
pre-merge checklist to explicitly require protected main branch rules, all
required checks, the required reviewer count, and qualifying independent
approval before merging. Clarify that automated comments, check results, and
model output do not count as approval, while preserving the existing distinction
between authority classes.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 9146b926-1af6-4115-ac51-3de0a86cd838
📒 Files selected for processing (16)
CLAUDE.mdSECURITY.mddocs/DOCUMENTATION_ASSESSMENT.mddocs/FIDELITY_ACCEPTANCE.mddocs/OPERABILITY.mddocs/RESEARCH_TRACEABILITY.mddocs/TRACEABILITY.mddocs/adr/0003-audit-pseudonymization-key-separation.mddocs/adr/0007-exact-head-live-base-evidence.mddocs/adr/0008-central-vs-local-automation-authority.mddocs/adr/0009-work-conserving-rca-loop.mddocs/adr/0011-thin-scheduler-control-plane.mddocs/adr/README.mdscripts/test_documentation_assessment_security_contract.pyscripts/test_documentation_spine_contract.pyscripts/test_release_loop_adr_contract.py
🚧 Files skipped from review as they are similar to previous changes (8)
- docs/FIDELITY_ACCEPTANCE.md
- docs/adr/0003-audit-pseudonymization-key-separation.md
- docs/RESEARCH_TRACEABILITY.md
- scripts/test_documentation_spine_contract.py
- docs/DOCUMENTATION_ASSESSMENT.md
- docs/adr/0008-central-vs-local-automation-authority.md
- docs/adr/0009-work-conserving-rca-loop.md
- docs/adr/0007-exact-head-live-base-evidence.md
There was a problem hiding this comment.
Actionable comments posted: 1
♻️ Duplicate comments (1)
scripts/test_documentation_spine_contract.py (1)
226-243: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win문서 계약이 필요한 의미 관계를 검증하지 않습니다.
두 테스트는 관련 단어의 존재만 검사합니다. 따라서 한 문서가 placeholder를 production Office fidelity로 잘못 주장하거나, Office runtime을 API container 내부에 둔다고 변경해도 다른 문장의 단어 때문에 통과할 수 있습니다.
scripts/test_documentation_spine_contract.py#L226-L243: 각 canonical 문서에서 placeholder가 production Office fidelity가 아님을 명시적으로 검사하고, 반대 주장을 거부하십시오.scripts/test_office_architecture_documentation_contract.py#L22-L37:sandboxed_office_sidecar또는remote_office_service의 Office-process 실행이 API container outside임을 하나의 관계 assertion으로 검사하십시오. In-processLocalOfficeManager거부도 검사하십시오.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@scripts/test_documentation_spine_contract.py` around lines 226 - 243, Strengthen test_placeholder_conversion_is_not_documented_as_office_fidelity in scripts/test_documentation_spine_contract.py (lines 226-243) to assert in each canonical document that development_placeholder is explicitly described as not being production Office fidelity, and reject wording that claims the opposite; replace broad keyword-presence checks with relationship-based assertions. Update the documentation contract test in scripts/test_office_architecture_documentation_contract.py (lines 22-37) to assert that Office-process execution for sandboxed_office_sidecar or remote_office_service occurs outside the API container, and explicitly reject in-process LocalOfficeManager execution.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@scripts/test_release_loop_adr_contract.py`:
- Around line 105-125: The
test_scheduler_prewrite_refetch_is_complete_and_fail_closed contract is too weak
because it only checks isolated terms. Update it to require each document to
explicitly state the “before every write” ordering, refetch the exact
source/target head, live base, target blob/ref, and relevant review state, and
freeze/rotate or otherwise stop the write when target identity changes or
another writer moves it.
---
Duplicate comments:
In `@scripts/test_documentation_spine_contract.py`:
- Around line 226-243: Strengthen
test_placeholder_conversion_is_not_documented_as_office_fidelity in
scripts/test_documentation_spine_contract.py (lines 226-243) to assert in each
canonical document that development_placeholder is explicitly described as not
being production Office fidelity, and reject wording that claims the opposite;
replace broad keyword-presence checks with relationship-based assertions. Update
the documentation contract test in
scripts/test_office_architecture_documentation_contract.py (lines 22-37) to
assert that Office-process execution for sandboxed_office_sidecar or
remote_office_service occurs outside the API container, and explicitly reject
in-process LocalOfficeManager execution.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 0a580994-7497-4e12-b37c-d1be6157e644
📒 Files selected for processing (13)
ARCHITECTURE.mdCLAUDE.mddocs/ACQUISITION_DILIGENCE.mddocs/DATA_MODEL.mddocs/DOCUMENTATION_ASSESSMENT.mddocs/OPERABILITY.mddocs/TRACEABILITY.mddocs/UML.mddocs/adr/0011-thin-scheduler-control-plane.mdscripts/test_acquisition_diligence_contract.pyscripts/test_documentation_spine_contract.pyscripts/test_office_architecture_documentation_contract.pyscripts/test_release_loop_adr_contract.py
🚧 Files skipped from review as they are similar to previous changes (5)
- docs/DOCUMENTATION_ASSESSMENT.md
- docs/OPERABILITY.md
- CLAUDE.md
- docs/adr/0011-thin-scheduler-control-plane.md
- ARCHITECTURE.md
There was a problem hiding this comment.
♻️ Duplicate comments (1)
scripts/test_release_loop_adr_contract.py (1)
109-124: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick winCanonical 용어에 맞추고 source head와 target head를 각각 요구하십시오.
현재 정규식은
"before every write","live base","relevant review state"를 요구합니다. 제공된docs/adr/0011-thin-scheduler-control-plane.md계약은"Immediately before the write"와"current base"를 사용하고 review 상태를 개별 항목으로 열거합니다. 따라서 현재 canonical ADR에 대해 이 테스트가 실패할 수 있습니다.또한
exact (?:source|target) head는 둘 중 하나만 있으면 통과합니다.exact source head와exact target head를 별도 조건으로 검증하십시오. ADR과docs/OPERABILITY.md의 용어를 먼저 동일한 fail-closed 계약으로 정렬한 뒤, 해당 순서를 검사하십시오.코딩 가이드라인에 따라 모든 write 전에 exact target head, live base, target blob/ref, 관련 review state를 재조회해야 합니다.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@scripts/test_release_loop_adr_contract.py` around lines 109 - 124, Update the ordered_contract check in the test to use the canonical terms “immediately before the write” and “current base,” and require separately ordered “exact source head” and “exact target head” clauses instead of the current alternation. Match the individually enumerated review-state requirements and preserve the fail-closed ordering through target identity/another-writer freeze or stop before rotation/abort; align the ADR and OPERABILITY wording with this same contract.Source: Coding guidelines
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Duplicate comments:
In `@scripts/test_release_loop_adr_contract.py`:
- Around line 109-124: Update the ordered_contract check in the test to use the
canonical terms “immediately before the write” and “current base,” and require
separately ordered “exact source head” and “exact target head” clauses instead
of the current alternation. Match the individually enumerated review-state
requirements and preserve the fail-closed ordering through target
identity/another-writer freeze or stop before rotation/abort; align the ADR and
OPERABILITY wording with this same contract.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 73ff3b1b-8ba5-4c07-99d6-da969a3c51e4
📒 Files selected for processing (1)
scripts/test_release_loop_adr_contract.py
|
@coderabbitai review @opencode-agent @cwl-noema-review Please independently review exact current head |
|
I will assess the current documentation and acquisition diff. I will check the authority and maturity labels, Office placeholder and fidelity claims, Office runtime isolation, exact-head/live-base evidence, acquisition evidence boundaries, references, and documentation-contract tests. I will report only actionable findings for the current head. I will not treat checks, resolved threads, or predecessor review output as approval. ✅ Action performedReview finished.
|
|
@opencode-agent Please independently review exact current head |
|
@cwl-noema-review Please independently review exact current head |
|
Queued @cwl-noema-review for PR #305 at head |
|
@opencode-agent @cwl-noema-review Please independently review exact current head |
|
Queued @cwl-noema-review for PR #305 at head |
|
Queued @cwl-noema-review for PR #305 at head |
|
Queued @cwl-noema-review for PR #305 at head |
|
Queued @cwl-noema-review for PR #305 at head |
There was a problem hiding this comment.
Actionable comments posted: 4
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/TRACEABILITY.md`:
- Around line 3-5: Update the Assessment date in the traceability document to
2026-08-11 or an earlier date matching the actual evidence collection time; do
not leave a future date in the current assessment metadata.
- Line 52: Update the canonical documentation to consistently represent PR `#268`
as a closed, superseded predecessor rather than active implementation, using the
PARTIAL status and successor mapping in docs/TRACEABILITY.md:52 and
docs/TRACEABILITY.md:93. In docs/PRD.md, docs/TRD.md, ARCHITECTURE.md,
docs/DATA_MODEL.md:32-33, docs/OPERABILITY.md:59, docs/API_CONTRACT.md,
docs/THREAT_MODEL.md, docs/MIGRATION_ROLLBACK.md, and docs/TEST_STRATEGY.md,
remove active `#268` claims and describe the work as PARTIAL or target behavior;
update docs/UML.md:126-155, docs/adr/README.md:14,
docs/adr/0004-durable-lifecycle-generation-fencing.md,
docs/DOCUMENTATION_ASSESSMENT.md:29, docs/ACQUISITION_DILIGENCE.md, and
docs/adr/0003-audit-pseudonymization-key-separation.md to use the same status
model. Ensure successor PRs `#341`, `#342`, `#345`, `#350`, `#351`, `#353`, `#361`, `#363`, and
`#380` are not marked IMPLEMENTED_ON_MAIN.
In `@docs/UML.md`:
- Line 108: Update the direct conversion-job download maturity statement in the
UML documentation to IMPLEMENTED_ON_MAIN, matching the classifications in
API_CONTRACT.md and TRACEABILITY.md; only retain ACTIVE_PR if the text
explicitly identifies a separate, not-yet-integrated work item.
In `@scripts/test_live_product_gap_traceability_contract.py`:
- Line 79: Update the assertion in the traceability contract test to expect the
current KPI ledger PR number `#389` instead of `#339`, matching the documented
`ACTIVE_PR` value in `docs/TRACEABILITY.md` while preserving the existing
lowercase comparison behavior.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 270fb6e4-2688-4657-a2ca-10dcb2bcd2c7
📒 Files selected for processing (13)
AGENTS.mddocs/API_CONTRACT.mddocs/DATA_MODEL.mddocs/DOCUMENTATION_ASSESSMENT.mddocs/OPERABILITY.mddocs/TRACEABILITY.mddocs/UML.mddocs/adr/0012-scheduler-execution-receipts.mddocs/adr/README.mdscripts/test_documentation_spine_contract.pyscripts/test_live_product_gap_traceability_contract.pyscripts/test_release_loop_adr_contract.pyscripts/test_scheduler_execution_receipt_documentation_contract.py
🚧 Files skipped from review as they are similar to previous changes (2)
- scripts/test_documentation_spine_contract.py
- scripts/test_release_loop_adr_contract.py
| Status: Canonical traceability index | ||
| Baseline: protected `main` at `55d7ae8647208e301f282350f076eeddaba61d11` | ||
| Assessment date: 2026-08-12 |
There was a problem hiding this comment.
🗄️ Data Integrity & Integration | 🟡 Minor | ⚡ Quick win
평가 날짜를 현재 증거 시점으로 수정하세요.
현재 날짜는 2026-08-11입니다. Assessment date: 2026-08-12는 미래 날짜입니다. 날짜를 2026-08-11 이하의 실제 평가 시점으로 변경하거나, 미래 스냅샷이면 현재 평가 문서로 표현하지 마세요.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/TRACEABILITY.md` around lines 3 - 5, Update the Assessment date in the
traceability document to 2026-08-11 or an earlier date matching the actual
evidence collection time; do not leave a future date in the current assessment
metadata.
| | Production HMAC key readiness | `ACTIVE_PR`; issue #319 dependency; current #313 | clean current-base `ProductionAuthReadinessConfig` rejects missing/null, undersized, normalized, unstable or purpose-reused signing material | exact-head CI, Security Scan, SAST, fuzz and 100% coverage | SECURITY; THREAT_MODEL; MIGRATION_ROLLBACK | | ||
| | Runtime credential registry | `PLANNED`; issue #319 | protected main still receives tenant-claim and artifact-token HMAC values from environment-backed Spring configuration; #313 is readiness, not authority migration | registry lookup, rotation, restart, replica, least-privilege and no-secret-log tests required | issue #319; AGENTS; SECURITY; THREAT_MODEL | | ||
| | Provider-neutral production identity federation | `PLANNED`; issue #314 | current HMAC-signed gateway claim adapter remains bounded; no complete OIDC/JWT federation is shipped | issuer, audience, algorithm, JWK rotation/outage, tenant mapping and migration tests required | issue #314; PRD; API_CONTRACT; THREAT_MODEL | | ||
| | Immutable job identity and durable deletion receipts | `PARTIAL`; issue #263; #268 `SUPERSEDED`; current #345/#350/#351/#353 | the stale broad descendant was closed after its valuable semantics were decomposed into current bounded lanes for permanent job-id reservation, same-job lifecycle serialization, deletion state vocabulary and immutable deletion-receipt identity; durable receipt persistence and recovery are still not shipped | current-base identity/state/locking tests plus future durable replay, crash-tail, fairness, privacy and lifecycle acceptance | ADR-0004; DATA_MODEL; MIGRATION_ROLLBACK | |
There was a problem hiding this comment.
🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy lift
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
gh pr view 268 \
--json number,state,isDraft,mergedAt,closedAt,headRefOid,baseRefOid,url
rg -n -C 2 '(`#268`|`#345`|`#350`|`#351`|`#353`|ACTIVE_PR|SUPERSEDED)' \
docs/DATA_MODEL.md \
docs/OPERABILITY.md \
docs/UML.md \
docs/adr/README.md \
docs/DOCUMENTATION_ASSESSMENT.md \
docs/TRACEABILITY.mdRepository: ContextualWisdomLab/clearfolio
Length of output: 34899
🏁 Script executed:
#!/bin/bash
set -euo pipefail
printf '%s\n' '--- AGENTS.md files ---'
find .. -name AGENTS.md -print
printf '%s\n' '--- repository guidance ---'
for f in $(find .. -name AGENTS.md -print); do
echo "### $f"
cat "$f"
done
printf '%s\n' '--- relevant canonical sections ---'
for spec in \
'docs/adr/0004-durable-lifecycle-generation-fencing.md:1:220' \
'docs/DATA_MODEL.md:1:180' \
'docs/OPERABILITY.md:45:80' \
'docs/UML.md:120:160' \
'docs/DOCUMENTATION_ASSESSMENT.md:15:35' \
'docs/TRACEABILITY.md:45:98'; do
IFS=: read -r file start end <<< "$spec"
echo "### $file:$start-$end"
sed -n "${start},${end}p" "$file"
doneRepository: ContextualWisdomLab/clearfolio
Length of output: 50389
🏁 Script executed:
#!/bin/bash
set -euo pipefail
for spec in \
'docs/adr/0004-durable-lifecycle-generation-fencing.md:1:220' \
'docs/DATA_MODEL.md:125:172' \
'docs/OPERABILITY.md:52:63' \
'docs/UML.md:122:158' \
'docs/DOCUMENTATION_ASSESSMENT.md:15:31' \
'docs/PRD.md:1:80' \
'docs/TRD.md:1:80' \
'ARCHITECTURE.md:1:100'; do
IFS=: read -r file start end <<< "$spec"
echo "### $file:$start-$end"
sed -n "${start},${end}p" "$file"
done
printf '%s\n' '--- live successor states ---'
for n in 341 342 345 350 351 353 361 363 380; do
gh pr view "$n" --json number,state,isDraft,mergedAt,closedAt,url \
--jq '{number,state,isDraft,mergedAt,closedAt,url}'
doneRepository: ContextualWisdomLab/clearfolio
Length of output: 23172
🏁 Script executed:
#!/bin/bash
set -euo pipefail
printf '%s\n' '--- all documentation references to `#268` ---'
rg -n -C 1 '`#268`|ACTIVE_PR.*268|268.*ACTIVE_PR' \
docs ARCHITECTURE.md AGENTS.md 2>/dev/null || true
printf '%s\n' '--- successor titles and descriptions ---'
for n in 341 342 345 350 351 353 361 363 380; do
gh pr view "$n" --json number,title,state,isDraft,body,url \
--jq '"PR #\(.number) [\(.state)\(if .isDraft then ", Draft" else "" end)] \(.title)\n\(.url)\n\(.body // "" | split("\n")[:12] | join("\n"))\n---"'
doneRepository: ContextualWisdomLab/clearfolio
Length of output: 25021
PR #268의 종료 상태와 successor 매핑을 모든 canonical 문서에 반영하세요.
PR #268은 병합되지 않은 CLOSED Draft입니다. ACTIVE_PR #268``은 현재 상태와 맞지 않습니다. docs/TRACEABILITY.md의 `PARTIAL` 성숙도와 `#268 SUPERSEDED` 매핑을 기준으로 갱신하세요.
docs/PRD.md,docs/TRD.md,ARCHITECTURE.md,docs/DATA_MODEL.md,docs/OPERABILITY.md,docs/API_CONTRACT.md,docs/THREAT_MODEL.md,docs/MIGRATION_ROLLBACK.md,docs/TEST_STRATEGY.md:#268의 활성 구현 주장을 제거하고 보호된main에 아직 통합되지 않은PARTIAL또는 target behavior로 명시하세요.docs/UML.md,docs/adr/README.md,docs/adr/0004-durable-lifecycle-generation-fencing.md: 제목, maturity, 다이어그램 설명을#268 SUPERSEDED와 현재 successor 매핑에 맞추세요.docs/DOCUMENTATION_ASSESSMENT.md:Onlyfix(security): require signed tenant claims on admin endpoints #268remains unreconciled를 종료된 predecessor와 현재 successor 작업을 반영하도록 수정하세요.- 관련
#268참조가 있는docs/ACQUISITION_DILIGENCE.md와docs/adr/0003-audit-pseudonymization-key-separation.md도 같은 상태 모델을 사용하세요.
현재 successor PR #341, #342, #345, #350, #351, #353, #361, #363, #380은 모두 보호된 main에 통합되지 않았습니다. 이 PR들의 구현을 IMPLEMENTED_ON_MAIN으로 표시하지 마세요.
📍 Affects 6 files
docs/TRACEABILITY.md#L52-L52(this comment)docs/TRACEABILITY.md#L93-L93docs/DATA_MODEL.md#L32-L33docs/OPERABILITY.md#L59-L59docs/UML.md#L126-L155docs/adr/README.md#L14-L14docs/DOCUMENTATION_ASSESSMENT.md#L29-L29
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/TRACEABILITY.md` at line 52, Update the canonical documentation to
consistently represent PR `#268` as a closed, superseded predecessor rather than
active implementation, using the PARTIAL status and successor mapping in
docs/TRACEABILITY.md:52 and docs/TRACEABILITY.md:93. In docs/PRD.md,
docs/TRD.md, ARCHITECTURE.md, docs/DATA_MODEL.md:32-33, docs/OPERABILITY.md:59,
docs/API_CONTRACT.md, docs/THREAT_MODEL.md, docs/MIGRATION_ROLLBACK.md, and
docs/TEST_STRATEGY.md, remove active `#268` claims and describe the work as
PARTIAL or target behavior; update docs/UML.md:126-155, docs/adr/README.md:14,
docs/adr/0004-durable-lifecycle-generation-fencing.md,
docs/DOCUMENTATION_ASSESSMENT.md:29, docs/ACQUISITION_DILIGENCE.md, and
docs/adr/0003-audit-pseudonymization-key-separation.md to use the same status
model. Ensure successor PRs `#341`, `#342`, `#345`, `#350`, `#351`, `#353`, `#361`, `#363`, and
`#380` are not marked IMPLEMENTED_ON_MAIN.
| API-->>Caller: 200 / 206 / 416 or controlled auth failure | ||
| ``` | ||
|
|
||
| Protected-main `ArtifactController` already follows this authority pattern. Direct conversion-job download alignment is an `ACTIVE_PR` security remediation and must not be described as complete until integrated. |
There was a problem hiding this comment.
🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win
직접 다운로드 성숙도 표기를 protected main과 일치시키세요.
docs/API_CONTRACT.md Line 32와 docs/TRACEABILITY.md Line 42는 signed direct download를 IMPLEMENTED_ON_MAIN으로 분류합니다. src/test/java/com/clearfolio/viewer/controller/ConversionDownloadAuthorizationTest.java:38-284도 토큰, 범위, 철회, 감사 동작을 검증합니다. 이 문장은 아직 통합되지 않은 별도 작업을 명시하지 않는 한 IMPLEMENTED_ON_MAIN으로 변경하세요.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/UML.md` at line 108, Update the direct conversion-job download maturity
statement in the UML documentation to IMPLEMENTED_ON_MAIN, matching the
classifications in API_CONTRACT.md and TRACEABILITY.md; only retain ACTIVE_PR if
the text explicitly identifies a separate, not-yet-integrated work item.
|
Queued @cwl-noema-review for PR #305 at head |
|
Queued @cwl-noema-review for PR #305 at head |
Objective
Replace Clearfolio's scattered/stale MVP-era documentation and dated buyer-diligence snapshots with one discoverable, code-current product/architecture/acquisition graph without presenting active-PR work as shipped behavior. Explicitly answer whether this conversation's Clearfolio-scoped decisions are covered, while separating documentation coverage from scheduler enforcement and protected-main integration.
Fresh exact live state — 2026-08-10
9c63762430ec112c35e17b428fd200cd22d7b8cc;main:55d7ae8647208e301f282350f076eeddaba61d11after protected merge of fix(security): harden audit pseudonymization and refresh Netty evidence #270;31391215750:success;31391215752:success;31391215754:success;AGENTS.mdmerge gates and CWL security/KV guidance are preserved, with canonical PRD/TRD/ADR links added rather than replacing the current guide;docs/DOCUMENTATION_ASSESSMENT.mdis based on current protected main and records fix(security): harden audit pseudonymization and refresh Netty evidence #270 asIMPLEMENTED_ON_MAIN;docs/TRACEABILITY.mdnow maps clean current-base replacements fix(accessibility): reconcile robust focus appearance after #270 #334/fix(openapi): enforce stable unique operationIds #337/fix(analytics): reconcile terminal conversion KPI on protected main #338/fix(analytics): reconcile KPI ledger numeric validity on protected main #339, marks chore: superseded by current-base focus PR #334 #325/chore: superseded by current-base KPI PR #338 #328/chore: superseded by current-base KPI ledger PR #339 #330/chore: superseded by clean operationId PR #337 #332 superseded, and separates currentACTIVE_PRevidence from shipped behavior;APPROVEDreview;Every predecessor SHA, run, review, status and PR-body statement is historical and non-transferable. Any future head/base movement requires full exact-state revalidation.
Documentation fitness verdict
This exact documentation head is DESIGN_SUFFICIENT and CONVERSATION_COVERAGE_SUFFICIENT for the current documented Clearfolio boundary. A reviewer can reconstruct, without this conversation:
The control-plane verdict remains CONTROL_ENFORCEMENT_INCOMPLETE. PR #271's stronger recurring prompt is still
ACTIVE_PR; external durable receipts remainPLANNEDunder issue #331; the counted independent-human review route remains unresolved under issue #321; and this canonical graph is not yet integrated on protected main.Protected
maintherefore remains PROTECTED_MAIN_INSUFFICIENT as the canonical documentation source even though #270's security/privacy implementation is shipped. Documentation sufficiency does not mean product completeness, release readiness, certification, transaction readiness or a $20B valuation claim.Test-first conversation and live-traceability remediation
Conversation coverage RED → GREEN
Test-only head
84c75c9825e2ff798d4dd13f0d7ee29503c41f7dadded the explicit conversation-coverage contract before changing the assessment. CI31383877572failed only Buyer-readiness documentation tests while Maven, Security Scan and SAST passed. The missing contract required:CONVERSATION_COVERAGE_SUFFICIENT;CONTROL_ENFORCEMENT_INCOMPLETE;Current replacement mapping RED → GREEN
Test-only head
1445fa76eebbbe7dc2323a375b9e1cc83da3bb04then required current protected-main identity, #270IMPLEMENTED_ON_MAINmaturity, current clean replacements #334/#337/#338/#339, and explicit #325/#328/#330 supersession. CI31390633933failed only the new traceability contract while Maven passed.Current head
9c63762430ec112c35e17b428fd200cd22d7b8ccrewrites the live requirement/evidence matrix, evidence-authority matrix, replacement map, conversation decision capture and documentation update rule. Exact-head CI, Security Scan and SAST are GREEN.Canonical graph established/refreshed
docs/PRD.md,docs/TRD.md, rootARCHITECTURE.md;SECURITY.md;docs/adr/README.mdplus ADR-0001..0012;docs/DATA_MODEL.mdwith conceptual/logical ERD and explicit memory/file/host/external-control-plane persistence ownership;docs/UML.mdwith component, submit/view/auth, deletion recovery, availability, Office isolation, automation authority, scheduler receipt/continuation, deployment and degraded-mode views;docs/API_CONTRACT.md,docs/THREAT_MODEL.md,docs/TEST_STRATEGY.md,docs/OPERABILITY.md;docs/TRACEABILITY.md,docs/RESEARCH_TRACEABILITY.md,docs/DOCUMENTATION_ASSESSMENT.md;docs/FIDELITY_ACCEPTANCE.md,docs/MIGRATION_ROLLBACK.md,docs/RELEASE_ACCEPTANCE.md;docs/ACQUISITION_DILIGENCE.md,docs/engineering/acceptance-criteria.md;Dated buyer-diligence, scorecard, data-room, Figma/demo and QA artifacts remain historical evidence, not current proof.
Repository-scope boundary
This graph imports only decisions that apply to Clearfolio. Reports about ThreadWeave, fast-mlsirm, BandScope, TEPP, OriginWeave, LifeOS, EmbedRelay, MHTML ETL Gateway and other repositories remain owned by those repositories. Clearfolio references organization
.githubor naruon only where they define an actual control-plane or composition boundary.Current executable product/security/governance gaps
Acquisition/IP truth
docs/ACQUISITION_DILIGENCE.mddistinguishes repository engineering evidence from transaction evidence. Apache-2.0 source licensing, dependency-license review, generated third-party attribution and SBOM/provenance controls are repository evidence. Contributor/IP assignment, trademark/patent freedom-to-operate, customer contracts/data rights, infrastructure attestations, certification and valuation/commercial evidence are external and are not independently proven by this repository.Merge gate
Do not merge until this unchanged exact source head satisfies every live branch/ruleset requirement, current review contains no valid unresolved finding, and the required approving review is delivered by an independent reviewer with write authority. Automated comments, statuses, checks and model outputs do not become approval. Documentation completion is intermediate; product/security/reliability work continues independently.
Summary by CodeRabbit
문서화
테스트