Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

# Contributing

Boatstack is a generated content distribution. Propose changes to workflow semantics, templates, evidence rules, or generated presentation in [Intelligence Flow](https://github.com/operatorstack/intelligence-flow/tree/1ac8b94231a1489bdc960f43fd573c386735bbfa/labs/12-product-engineering-loop).
Boatstack is a generated content distribution. Propose changes to workflow semantics, templates, evidence rules, or generated presentation in [Intelligence Flow](https://github.com/operatorstack/intelligence-flow/tree/ece98ce518af68377bb5229ed04c3e50804ef844/labs/12-product-engineering-loop).

The Boatstack repository receives product/runtime changes through a generated pull request. Review the PR's `UPSTREAM.json`, tests, adapter diff, and context-size change; do not hand-edit generated output on `main`. `.github/workflows` is the exception: it is Boatstack's executable control plane, excluded from scheduled projection and changed only through a separate manually reviewed Boatstack PR.

Expand Down
49 changes: 25 additions & 24 deletions UPSTREAM.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"canonical_context": {
"characters": 50008,
"estimated_tokens": 12502,
"characters": 50219,
"estimated_tokens": 12555,
"estimator": "ceil(total characters / 4); compactness signal, not provider billing",
"files": [
"product-engineering-loop/references/workflow.md",
Expand All @@ -12,12 +12,12 @@
},
"files": {
".gitignore": "a7079e923a776f14f1bb3a6aa0a11a133a8e1dfb35af020f327623357b7e3957",
"CONTRIBUTING.md": "705ba2cd2f801ea022aa27b0459f7bd6fec964d53a1e4e06356808077f07ae6a",
"CONTRIBUTING.md": "ca1460610c2af4bf6a8e7524b9afa84652d07f63d84dd144f41c74a13f2edfc8",
"README.md": "1b8b3dea6186faa18f01afa096117c57e2bd0b1c4765f35ef87518018e3839e0",
"assets/boatstack-journey.svg": "e465befc50c8ce30f3e07e8fd97012931beeb053392c8fbf38ad645023b3cc63",
"assets/boatstack-mark.svg": "be1f984da1bfa69fa5d1f986d8343d21f7e20921b71db888c928b4d2e54b09b5",
"assets/boatstack-portability.svg": "66dfdfa85db857b3bd18b32047a6975f1fbbfc4dc091158e8277193f9969a346",
"boatstack/SKILL.md": "25e125bfc20bea38c70d00cf1d49109a6df04b1d6995fae2636c6bf8ac8ba09e",
"boatstack/SKILL.md": "dec9864826a789b7f794565e870deab4f15bf62658370565bb7605aba7a1c585",
"boatstack/agents/gemini.yaml": "cbf43b387399e456fa6178f86d83e6e35567e6142ff800f8de6ffca306fa963e",
"boatstack/agents/openai.yaml": "68a30a60859556c5a26e16d184594ca243a6043d99c8cf7d66b5dd6d50a93cd1",
"boatstack/assets/templates/adr.md": "c577a3c1c1319061f61deb053597e6e853657022185fe28b8f733327e2a78565",
Expand All @@ -26,23 +26,23 @@
"boatstack/assets/templates/feature-spec.md": "c7e007cc4295ed4c599642c0587021ef978e729cf0946f6bf3a6c4f01d366ad4",
"boatstack/assets/templates/gaps.md": "911cc2f086104d35071b952950c2ec44258641419f10b2355c594f33eb492cbe",
"boatstack/assets/templates/move.md": "91bfd9a9b9426ac023eb88fd19f4f638190481c1855f1239acc73830528e50f0",
"boatstack/assets/templates/plan-lock.json": "a51e17bb74aa7cd95daaa70fab646a20374ff4bc1d63468d61c5119da61e930f",
"boatstack/assets/templates/plan-lock.json": "fe5507bfdb99ff892e56be0f3015056a72171183a06930b4555d6075b3ee04d9",
"boatstack/assets/templates/plan.md": "46b3f9017fe72d97efc429191aafa1711515101b7372cc5488813abc29a64547",
"boatstack/assets/templates/questions.md": "1133b557a832d4988545f3694b365ebffa808640ed696b6c04b5a390266eed80",
"boatstack/assets/templates/test-plan.md": "6db8a9f27dd171fb80222a501cae50eb051e7278c04703fa43b5ff86dd4d2df4",
"boatstack/atomic_unix.go": "89f2723361591de2bb8bd22ce7e34ec529d3278509f0df78fd5c4a7d4140fbe9",
"boatstack/atomic_windows.go": "cefd775cbe7e7c3bd8a3f5673b11cdd784c6d3ebd6de7dcb8f39406b0bee511f",
"boatstack/changelog.go": "c5e1f31440b44d61e6037ad27af0333540af3545d655e35819a0241cbbebd8ec",
"boatstack/changelog_test.go": "ce792f23a7fe1e09fb3096cd1314130a6ab69321d4877b12a8e994027541baf7",
"boatstack/cmd/boatstack-helper/main.go": "3bd1e15435ea0468f0de77677c0574d699d739235721c590a1cc713a7d73b25b",
"boatstack/cmd/boatstack-helper/main.go": "506bed1a3a44a17440b86db7902ef0cc5a45a74bcecd86cb2561cf5ad111ba58",
"boatstack/cmd/boatstack-helper/main_test.go": "ff73003b6a5157202fa09ddf1129fb13c3d79702b2e05a8721ce5a11bf5ab779",
"boatstack/config_documentation_test.go": "109f2c8550c695db6ff0eb2bd1d24856d0f5af2e36c78de11819d6016062c97b",
"boatstack/config_documentation_test.go": "bd34ac570d08c8d1d1e4f5e86c327c02a55dd5e96bd785b895a05f28fcd3f7a2",
"boatstack/decision.go": "257ca328da6ae19ab252f10ee5d06bd7daf49dd8141d083ab1b32f106ea7a94c",
"boatstack/decision_test.go": "1a92ff832610f9559bd47ccac7fc1755a8b4f8261c35bc72a092830dff05f7c0",
"boatstack/delivery.go": "6ff71b6f4ae4f85a184edaf453b5933a79366e36137802fda056e58f83fe319c",
"boatstack/delivery_test.go": "e0323d4e2ef9c74a07c799cf42df91c90a43d61a0fdfddd8b10c5e3e27d5e492",
"boatstack/delivery.go": "d28cf4e944df4bdd72be403fea1c62bb79783cde76969d7144f8ef0a1a2722e0",
"boatstack/delivery_test.go": "3d2e9ff746a6b71a27dbac4e9011deae4ac2303188a972ee26974c167ab7744f",
"boatstack/evidence.go": "497a31e6ff632cb1d7c3adfc9f269af3f6aa84e948dd5d417c162767542a27df",
"boatstack/export.go": "35a9b0935acc4652f1a4db935b3036b82f623434dc02764c49069d318a469a78",
"boatstack/export.go": "be25e4b901d5c868549e1092a858e10066fab6719c41fd4897d36a1731093b83",
"boatstack/export_test.go": "27f9895f39d0958b5b4824193865a8a30333db709e5b91788aff3d49304457ed",
"boatstack/go.mod": "6086ef1b2a83f5696190dca692c653925f27b61f652f659fd3fca43ed54a1641",
"boatstack/go.sum": "26c315c867b11b886f3c9402fce7f341f6a9115a5d61f54afbb5e1b1fb5f6017",
Expand All @@ -54,23 +54,23 @@
"boatstack/integrations.go": "75b39ce2e662fccd66bf4b9bff0e097a4db558f23b3aa1d9bc83a5fc6373444c",
"boatstack/migrate.go": "eaf589e2b266238068e42c6d78e01dc040266d28e342cb24f09e33e8541749b3",
"boatstack/migrate_test.go": "9f4bda2fb158c5e54bcc0242dace1da3c1965f9846a213c573956a35b7d1724e",
"boatstack/next.go": "a4262b2dd310db4e92903ea09cd5f7bd9236cc725341081f6a1a236a46bcb06e",
"boatstack/next_test.go": "d158288d66628ab868061f85503663974c0b3cfe3fce0828d8ec5c85ed3ed81c",
"boatstack/plan.go": "fc2c7c457c28b0c4f956bea1b63077c4603340f38ee16e6d749add069b879e3a",
"boatstack/plan_test.go": "878dd9086bb583328a7eba1cf45318baeef3d55693be745d5520f07c6ace5e3e",
"boatstack/next.go": "a76779f5f54099686dd38d0d76623c32eafb6994aaa84bf29b240ccbaf64ef77",
"boatstack/next_test.go": "667a5ca5a2d40b2aaee3c6e47b8b698caa004a869a27b88b2eb03f52f0809701",
"boatstack/plan.go": "dc34c2b37767574b6bd1327688f002e09b7ed39465a2851712434f151a169825",
"boatstack/plan_test.go": "ea96bf0047a43e8224f02e0b8761978ce48636a83a63b6296c9bd3336f51250c",
"boatstack/plan_validation.go": "412f06750832fe46f01190ea5e475fc6f6ea59c8ba78131f94ec031053a405d2",
"boatstack/plan_validation_test.go": "6cbde4ac719baef6b73aa569515d6a9daadcbf14b33f76fa78159826954e20fa",
"boatstack/planning.go": "4b86ae9dc16393f099ca26812bf3e62909fee42a541b33c33275cc16a80262aa",
"boatstack/planning_test.go": "6b156a64182ed76d4c3d392b4c5a26abe5d8b81cea27ee12ac7c4627c827e186",
"boatstack/pr.go": "b07b9ec75c8be88f0fafe54df3ed872f810cb6a0657228038738721fc2b48651",
"boatstack/pr_test.go": "441ca6faf59f228744f2fa1d4af74e2681a13ead308acfffc20a0679d31c16ca",
"boatstack/pr.go": "173392fd40ff1c111ec89b1f3dabaf666347be299ac7653bfe5ea2de407fc26f",
"boatstack/pr_test.go": "838e6c244aed84317d00e6f49de6b65bb08f6fe1e1a11fb37aad8428ae2f6ea1",
"boatstack/references/artifacts.md": "25e854ba2c4f31659c613e9284f063976dcd9f9dd5bc5304904aad506e5f8783",
"boatstack/references/config-schema.md": "b7931c381c904213a5f05c6efb1a3fdbc251dc99dedbb5cdd19534db3e3505a8",
"boatstack/references/config-schema.md": "c07c2d532ef95ea6ae538a1fffefb92ded1f8dc6a06eb3b8d463e371d1ed8416",
"boatstack/references/failure-moves.md": "1d35126348d0b681976e8819665e16fd745fd65eca271492603cb80aab75bf49",
"boatstack/references/host-hook-contracts.md": "1382213ad004389de6da5a03af43ec28ace6329c9e7a3f07148566cf2ea12727",
"boatstack/references/irreversible-operation-boundary.md": "631743991ace65977586e4537f8dd50f8ae88f8e16f27cf7baad93b2791a73df",
"boatstack/references/portability.md": "fb683095991bb0cb06ec56fb8884c49038b283172a7d2f8b203483b7cacb4bae",
"boatstack/references/workflow.md": "1e010eac018fb3734b87633e8068e40c28570c6baf41229e6435ee816ed3f39f",
"boatstack/references/workflow.md": "ef4c8b91522ac99e3f62d0f94c0502e18f713a4363b663bfba885a9c852659d6",
"boatstack/release.go": "fa2ac926df89c90c5844e938a2e02d4b8dbbaefbf85bb7a1a89fc51690bea520",
"boatstack/release_test.go": "5cf2d76fe9b836a91ca68eba53d5585e2c4be5b9421aaf939ea0723063a24690",
"boatstack/run.go": "fbdbf583c862c41f23d1a200f53d042842db72f19c29fe94e4288a69b0ac4a6b",
Expand All @@ -94,15 +94,15 @@
"docs/account-recovery-walkthrough.md": "676034974594a7d1a559b24dbed31d7ccc429eb81404b203ca07bbdaa19ec3d3",
"docs/benchmark-corpus-audit.md": "f2d206fe8579a514f9da82b2c96c19b343ac004be67617e1bd34f0f8e0e5e6c6",
"docs/benchmark-submission-audit.md": "9518abdd17690729c6423f87cab20418ed47b0915b5faa44b9ef975e9e9c3b79",
"docs/configuration.md": "2d677cf67a5949440ebcb392d0d2ade311891fe4370ac55fcf6f17459cd2a46a",
"docs/evidence-engineered-coding.md": "08574673d7dbf44c8cf483dce244fe8d387d5d4a00b1b4498c9e59edddcd6aa7",
"docs/configuration.md": "f530c5dcbacf32dcb6fdab590901d8f658a4f29bd93f6264cec5d4f449c2cbd1",
"docs/evidence-engineered-coding.md": "67ed44ed535248ad47ed162bbec6564a2f798d66ab4b5bccfe08809baf58c17f",
"docs/generated-files.md": "bb8cd6e4b7d0042c899685a916ea0170ece363388328786cb0ba8fad6df3b780",
"docs/getting-started.md": "eacc814fdffdfa3c7d8052b7cd99a79c04da5c75d88d8b44f3fb68d9afec0316",
"docs/public-claims.json": "265637b0e2d99586d3e1316d703ea9aaa30c06b81afdfb41edc0b25b4fc12cb1",
"docs/public-claims.json": "1a1b59b77877f7327bb2114034619fc7f2e3797c36974398ec0e883c22dd8182",
"docs/public-surface.md": "713f7a050b5f339cf948299103ef3800417dccfecf2cc1a4166397ea6f978907",
"docs/research-and-design.md": "d65c66e323037bda5d45aacef5d48afa6bf93da55901378891d235aca3a5684f",
"docs/safety.md": "7b9b5c515d36e683767ec8d3d9d6d119ac93650b2f629d351deadd4c600ed6a6",
"docs/troubleshooting.md": "be7c31d2eaec138ac469d72b12dc967ea32d93813e6474a125dffecfb4ba0218",
"docs/troubleshooting.md": "ea21358dfe862bd55bb983af570e5b592665768b874ac99fab2dfb28bedd4d38",
"docs/validation-and-evidence.md": "e7d91ad49c6adb44784ebe7d94feceb6abd445857f9a0716f0758bf6b55296c5",
"docs/why-these-steps.md": "80957af13979070e8b2f2a8db78ce06d20d152bbc8ec41c3a8003f28393f6369",
"install.ps1": "960b2b20b406bb2878a560e9ace53fe7226bc510be6ee8466ce4e608beb5625a",
Expand All @@ -112,7 +112,7 @@
"labs/diagram-json/compiled/evidence.md": "1ba1c989ade070a8ef9a508fbd788d100d7292f2dbacbb2bce895468019f619d",
"labs/diagram-json/compiled/tasks.json": "88f60851abf79d851e9fccc754ff3040034ae595306bc87d64784c19eb403e71",
"labs/diagram-json/compiled/test-matrix.json": "424657ff505768e50fa113801fd8363364a18269d5297480907a993d44063a39",
"labs/diagram-json/plan.lock.json": "c0049741c503939b05288cfaf8352d8f94bbe0c91d0ff85a526f6c874fae667f",
"labs/diagram-json/plan.lock.json": "796d6f30221eda359d85e28105bcaa3c5b7b57a1f90cf7f80f77970d57542e02",
"labs/diagram-json/plan.md": "3cc4f533b8d69386deff16b3a594a3ba09d4c0c3db636cccd8c4380084ce6a51",
"labs/diagram-json/questions.md": "74733b015002c8a6777c558e7e997fa48c94850b9bd39054fe9366c97ecf728d",
"labs/diagram-json/request.md": "0808fc41c36779c404f4a3a121167da6e76cac56df526e70f9ed6d3e0d4c02ed",
Expand Down Expand Up @@ -162,6 +162,7 @@
"release-notes/2026-07-21-value-translation-readme.md": "8dd16fd08c1591667a1074fc6825dcbf58beda0faa18ede1526647267418c8ea",
"release-notes/2026-07-22-boundary-analysis-dx.md": "60d727ab3b109fff95a82eb36ee4c6c5833760535b14f386fda349a21b4fe588",
"release-notes/2026-07-22-boundary-oracle-loop.md": "698c2ed7dd0a000e6e210f521989992b8fa476376987819ba92c12feb3528f7c",
"release-notes/2026-07-22-enforce-public-configuration-controls.md": "3c0904e206c483fa1c148c20125dd0f63e4fdac165775fbde984f168e62f4a96",
"release-notes/2026-07-22-pr-visual-evidence.md": "097e66a778a1d3197796c44c374b346a0cf29f24baa895080863372816696921",
"release-notes/2026-07-22-product-configuration-guide.md": "45e96862336bd53a2628ce3fe718c829ea20315555f53187eb7f04ba749f3a97",
"release-notes/2026-07-22-projection-layout-validation.md": "fd0d2935f3f0c4caa41bda678e3bd9a9b496eb2652ab38d80c1c1434cbba3159",
Expand All @@ -170,7 +171,7 @@
"generator": "operatorstack/intelligence-flow:boatstack-distribution",
"schema_version": 1,
"source": {
"commit": "1ac8b94231a1489bdc960f43fd573c386735bbfa",
"commit": "ece98ce518af68377bb5229ed04c3e50804ef844",
"path": "labs/12-product-engineering-loop",
"repository": "operatorstack/intelligence-flow"
}
Expand Down
17 changes: 9 additions & 8 deletions boatstack/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -124,27 +124,28 @@ Treat repository-owned product context as canonical. Do not require it to be mig
```

2. Present the draft spec, plan, open decisions, accepted assumptions, gaps, risks, validation provenance, and `PLAN_FINGERPRINT` in a reviewable form.
3. Ask the developer to approve it or request changes. End the pending response with exactly this Markdown: Reply `a` to approve. Silence, continued conversation, tool permission, permission to build, `[a]`, and an `a` embedded in other text are not approval.
3. When `workflow.human_plan_approval` is true, ask the developer to approve it or request changes and end with: Reply `a` to approve. When false, state that Build will create a policy-activation lock and do not imply human approval.
4. On changes, return to `auto-plan`, preserve the feedback in the question ledger, and issue a new draft.
5. On explicit approval, invoke `boatstack-helper record-approval` with the plan, named human, RFC3339 timestamp, and exact fingerprint returned before approval. It verifies the current plan and creates only `approval.md`.
6. End in Plan mode and tell the developer the feature is approved and ready for the host's normal Build transition. Do not compile tasks, create a lock, request Agent mode merely to write a file, or edit product code.
5. When human approval is enabled, invoke `boatstack-helper record-approval` with the plan, named human, RFC3339 timestamp, and exact fingerprint. When disabled, create no `approval.md`.
6. End in Plan mode and tell the developer the feature is authorized for the host's normal Build transition. Do not compile tasks, create a lock, request Agent mode merely to write a file, or edit product code.

All files created or updated by `auto-plan` and `plan-gate` must be Markdown. gstack and Spec Kit may help produce those documents, but their implementation stages and non-Markdown executable state are deferred to `build`.

## Build without erasing evidence

- First confirm the host is in an execution-capable mode. If a requested transition is rejected or product-code writes remain unavailable, return `READY_FOR_BUILD` and stop without activating, compiling, or writing a lock.
- Before the first product-code edit, activate the exact approved Markdown plan:
- Before the first product-code edit, activate the exact authorized Markdown plan. Include `--approval` only when `workflow.human_plan_approval` is true:

```bash
.product-loop/bin/boatstack-helper activate-plan \
--plan .product-loop/features/<feature>/plan.md \
--approval .product-loop/features/<feature>/approval.md \
--out-dir .product-loop/features/<feature>/compiled \
--output .product-loop/features/<feature>/plan.lock.json
```

- Activation verifies the approval fingerprint, compiles `tasks.json`, `test-matrix.json`, and the evidence skeleton, writes the content-addressed lock last, and rechecks it. It adds no semantics. Missing approval, open blocking questions, or any change to the source plan, spec, or complete `plan.md` returns `BLOCKED`.
For human authorization, add `--approval .product-loop/features/<feature>/approval.md`.

- Activation verifies the plan fingerprint and any required approval, compiles `tasks.json`, `test-matrix.json`, and the evidence skeleton, then writes a schema-v2 lock with `authorization_mode: human` or `policy`. Missing required approval, open blocking questions, or any changed input returns `BLOCKED`.
- Activation also creates ignored delivery state bound to the plan lock. Read it with `delivery-status`; implement only the active slice's `task_ids`. A multi-slice plan advances only after the current slice publishes through `ship-gate`.
- Keep the source plan present and hash-current through completion of `build`.
- Choose any suitable model, tool, or implementation tactic inside the approved boundary. Boatstack controls transitions and claims, not local creativity.
Expand Down Expand Up @@ -180,14 +181,14 @@ A published delivery is immutable. Record the observation against it, then plan
- For relevant PR visual scenarios, use the repository runner first, then a host browser against the existing development server, one supplied launch instruction, or an explicitly approved machine-local runtime. Do not modify repository dependencies or configuration for capture. Review each exact PNG for secrets and private data, then import the temporary manifest with `record-pr-visual-evidence`; keep the images outside the repository.
- Treat model-authored tests and same-model self-review as evidence, not ground truth.
- Validate that tests load and exercise the intended interface. For high-risk code, add an independent oracle such as contract fixtures, mutation testing, differential checks, staging verification, or human acceptance.
- A failing check blocks the gate. A skipped check must include a reason and risk owner.
- A failing check blocks the gate. A skipped check must include a reason and risk owner. `PASS_WITH_GAPS` is accepted only when `workflow.allow_pass_with_gaps` is true.
- Commit the intentional active-slice product and evidence diff, then record the test result with `record-delivery-gate --feature <feature> --slice <slice> --gate test`. The receipt is bound to the base/head branches, commit, product diff, and evidence hash. Editing an evidence status is not a gate transition.

### Review gate

- Review the actual diff, not the intended plan alone.
- Check spec traceability, invariants, data/security/tenancy boundaries, failure behavior, backward compatibility, migrations, observability, tests, docs, and gaps.
- Use an independent reviewer for high-risk changes, repeated failures, or when the existing review evidence is circular.
- When configured high-risk paths changed, use a human peer or separate agent and record `--reviewer-identity` with `--review-method human_peer|separate_agent`.
- Convert actionable findings into tasks. Do not pass while critical findings are open.
- On pass, record `record-delivery-gate --feature <feature> --slice <slice> --gate review`. Review is rejected unless the same diff already has a test receipt; any later product change makes both receipts stale.

Expand Down
6 changes: 4 additions & 2 deletions boatstack/assets/templates/plan-lock.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,8 @@
{
"schema_version": 1,
"status": "APPROVED",
"schema_version": 2,
"status": "LOCKED",
"authorization_mode": "human",
"activated_at": "<ISO-8601 timestamp>",
"approved_by": "<human identity>",
"approved_at": "<ISO-8601 timestamp>",
"source_commit": "<git commit>",
Expand Down
Loading
Loading