Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

# Contributing

Boatstack is a generated content distribution. Propose changes to workflow semantics, templates, evidence rules, or generated presentation in [Intelligence Flow](https://github.com/operatorstack/intelligence-flow/tree/c5f3e330d6167247446e1915deaf1bc593cf2e0d/labs/12-product-engineering-loop).
Boatstack is a generated content distribution. Propose changes to workflow semantics, templates, evidence rules, or generated presentation in [Intelligence Flow](https://github.com/operatorstack/intelligence-flow/tree/5227e7828d9bcac8c6b11c19289c2b4ef5be92a2/labs/12-product-engineering-loop).

The Boatstack repository receives product/runtime changes through a generated pull request. Review the PR's `UPSTREAM.json`, tests, adapter diff, and context-size change; do not hand-edit generated output on `main`. `.github/workflows` is the exception: it is Boatstack's executable control plane, excluded from scheduled projection and changed only through a separate manually reviewed Boatstack PR.

Expand Down
16 changes: 9 additions & 7 deletions UPSTREAM.json
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
},
"files": {
".gitignore": "a7079e923a776f14f1bb3a6aa0a11a133a8e1dfb35af020f327623357b7e3957",
"CONTRIBUTING.md": "87a58a3120f70e719a3471f4ad2be5673242ef29150a65a5fd6d2b1079ee69f4",
"CONTRIBUTING.md": "77a60a6dbf5dd2f29aefc942283201f8c48f45ed72a3caf105065ad3322ffcd6",
"README.md": "125b47671a68556df382f19756fb61fa18925606cbbaf54d6bc9df8872b36870",
"assets/boatstack-journey.svg": "e465befc50c8ce30f3e07e8fd97012931beeb053392c8fbf38ad645023b3cc63",
"assets/boatstack-mark.svg": "be1f984da1bfa69fa5d1f986d8343d21f7e20921b71db888c928b4d2e54b09b5",
Expand Down Expand Up @@ -78,6 +78,7 @@
"boatstack/pr_test.go": "7f82954d94c1ceae848a581dda25e58af92251d78a5a94ed2d672bedf5a0349e",
"boatstack/provision.go": "4882d49681f99b11ba9d182ca13772131b7f9a11a6c2b560800654ca14f5111e",
"boatstack/provision_test.go": "214e9edb991a66d5bbb696a7c1b63876d2f799f2cab4e3f40785f4e8f1eac57b",
"boatstack/publication_ignored_repro_test.go": "b6f3aeb8ba22949ff9af7ac5afe8fb828385d9708d5d5893ef41f33a3de873e1",
"boatstack/recovery.go": "dd816b18b54a0085b8d8276a93ee98d2b1e90099059a0d85cf6e24edf6f37d5b",
"boatstack/recovery_test.go": "29490e7477ba602491330036a491289dd9117b99ff862f66dae421ba17e04c9f",
"boatstack/references/artifacts.md": "5fa888ac519085d65cee1d04df5902761651bcf2d7af81711fa0f8ecd1fc0f59",
Expand All @@ -94,7 +95,7 @@
"boatstack/runtime.go": "d1e95895002ea2b27199b6e05b33c4c6e20f63455a44f63ca3cfeedecfc23420",
"boatstack/runtime_cache.go": "60c4eb0c7dde91d40d6ef3f05adc1a1282d17ff1ca12470d0a008454f7ca7489",
"boatstack/runtime_cache_test.go": "b981467ddc9f0f562da6bff5de7a80a9fe5a433a0317541d1e48df268546ac85",
"boatstack/safety.go": "e5d91bf219838f5e0c80daaf5b18a2cca9661f211fa60e2c1fab9e5835082b36",
"boatstack/safety.go": "b0fb94bc802baf39bc39d09276e1f0eb76a39027a421b0dfd49188173571bfe8",
"boatstack/safety_test.go": "01f28bc3bfcb6bdd47b307e309e36bbc1921b6426ad0b777d81fe4131200c37e",
"boatstack/skill_frontmatter.go": "73364df463ce828c2d005aab55f72bb92f7a34d99cf3f53d4e0cd5a4da9dbd0e",
"boatstack/skill_frontmatter_test.go": "a3ec52e7df357a72265c95dd66db15d9c0effc7e5f90f14ce69c27792ce394eb",
Expand All @@ -117,10 +118,10 @@
"docs/benchmark-corpus-audit.md": "f2d206fe8579a514f9da82b2c96c19b343ac004be67617e1bd34f0f8e0e5e6c6",
"docs/benchmark-submission-audit.md": "9518abdd17690729c6423f87cab20418ed47b0915b5faa44b9ef975e9e9c3b79",
"docs/configuration.md": "df054f49d532c8b1b7d94184810d1b3b5bf18cdc30eb985b4b6d0639162e341a",
"docs/evidence-engineered-coding.md": "091930ef2e129debd56a13f9465364fb1b30d2bdc09d28cafb99f8bdf372a899",
"docs/evidence-engineered-coding.md": "ae3c106e9d1b04ea97cda781048a7dd2641104662aa2f8b7c05356c7fcfcaa31",
"docs/generated-files.md": "437791765b0a4015032ae21d1a6618563cad92b7402819e4f963bf5ae16284a3",
"docs/getting-started.md": "f314270c5ed1a55bbef5f3ddbcb5596693dbee9374e5f0d3df8838cefbd68052",
"docs/public-claims.json": "1cd0ea8ce15058bf69e18bef9a8eabcc57d77bf7fb6c05d0ff46b5ba78ca0ff2",
"docs/public-claims.json": "9ba4aa7c99afee1b30ee1ac75e32c4d3e8724fbfbbb6142957407ae2165de27f",
"docs/public-surface.md": "713f7a050b5f339cf948299103ef3800417dccfecf2cc1a4166397ea6f978907",
"docs/research-and-design.md": "8d78678108f0a6c924e1ff9b32c0f81aae9d1f779e0082843b6f99ad993ae2b6",
"docs/safety.md": "7b9b5c515d36e683767ec8d3d9d6d119ac93650b2f629d351deadd4c600ed6a6",
Expand All @@ -134,7 +135,7 @@
"labs/diagram-json/compiled/evidence.md": "1ba1c989ade070a8ef9a508fbd788d100d7292f2dbacbb2bce895468019f619d",
"labs/diagram-json/compiled/tasks.json": "88f60851abf79d851e9fccc754ff3040034ae595306bc87d64784c19eb403e71",
"labs/diagram-json/compiled/test-matrix.json": "424657ff505768e50fa113801fd8363364a18269d5297480907a993d44063a39",
"labs/diagram-json/plan.lock.json": "1dfe1ea29c712d61940cc77f259f8bb0ecdcd073d6426eb29eda6612cbb645b5",
"labs/diagram-json/plan.lock.json": "5a5e68c8129157e18219f5ce21ba319234d4ec11572ee9196cb31f6ec9843b96",
"labs/diagram-json/plan.md": "3cc4f533b8d69386deff16b3a594a3ba09d4c0c3db636cccd8c4380084ce6a51",
"labs/diagram-json/questions.md": "74733b015002c8a6777c558e7e997fa48c94850b9bd39054fe9366c97ecf728d",
"labs/diagram-json/request.md": "0808fc41c36779c404f4a3a121167da6e76cac56df526e70f9ed6d3e0d4c02ed",
Expand Down Expand Up @@ -206,12 +207,13 @@
"release-notes/2026-07-23-recoverable-repository-sync.md": "3afc4f6220ae76df3bd6dcd15fc180135274c808729e9c512a2c53462ec690c2",
"release-notes/2026-07-23-shipped-feature-candidate-resolution.md": "bd8ee8e7f3f216b356b121a83ef10cb0c8131a90b9ab803edebf23b882d9cf89",
"release-notes/2026-07-23-sync-title-contract.md": "2869d6d084ea60402e57ffe985d0fc4cd83ef9bb09958cc53e349157d3383202",
"release-notes/2026-07-23-visual-evidence-external-host.md": "09edbe5e6e1bfc866cf5ee744a5001d678f7a67f0f330cf43bd5157eedf04276"
"release-notes/2026-07-23-visual-evidence-external-host.md": "09edbe5e6e1bfc866cf5ee744a5001d678f7a67f0f330cf43bd5157eedf04276",
"release-notes/2026-07-24-ignored-deliveries-publication-authority.md": "a25f8469316276101490c79a57c1a236c18072dfbb23682bb1778871d247067d"
},
"generator": "operatorstack/intelligence-flow:boatstack-distribution",
"schema_version": 1,
"source": {
"commit": "c5f3e330d6167247446e1915deaf1bc593cf2e0d",
"commit": "5227e7828d9bcac8c6b11c19289c2b4ef5be92a2",
"path": "labs/12-product-engineering-loop",
"repository": "operatorstack/intelligence-flow"
}
Expand Down
34 changes: 34 additions & 0 deletions boatstack/publication_ignored_repro_test.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
package boatstack

import "testing"

// TestPublicationBypassHonorsIgnoredDeliveries reproduces the external report on
// PR #322: `next`/`run` scope ambiguity through workflow.ignored_deliveries
// (see TestResolveNextIgnoredActiveDeliveryClearsAmbiguity), but the
// publication-authority path — publicationBypassFinding, which emits
// relation=ambiguous on a denied push — iterates ActiveManagedDeliveries
// directly and never filters ignored slugs. A single ignored, stale-but-active
// delivery (agentic-l3-full: APPROVED lock, never published) therefore poisons
// publication authority for every other delivery.
//
// This mirrors the `next` test: two active deliveries, one ignored, neither on
// the current branch. With the ignore list honored, only one active delivery
// remains and the finding must not be ambiguous.
func TestPublicationBypassHonorsIgnoredDeliveries(t *testing.T) {
repo := nextTestRepo(t)
writeNextDelivery(t, repo, "agentic-l3-full", "BUILD", 0) // stale, ignored blocker
writeNextDelivery(t, repo, "roles-access-policies", "BUILD", 0)
setIgnoredDeliveries(t, repo, "agentic-l3-full")

finding, blocked := publicationBypassFinding(repo, "denied push", "tool-input")
if !blocked {
t.Fatalf("expected a publication finding for the remaining active delivery")
}
if finding.BranchRelation == "ambiguous" {
t.Fatalf("ignored active delivery poisoned publication authority: BlockingFeature=%q relation=%q",
finding.BlockingFeature, finding.BranchRelation)
}
if finding.BlockingFeature != "roles-access-policies" {
t.Fatalf("expected the un-ignored delivery to be blocking, got %q", finding.BlockingFeature)
}
}
9 changes: 9 additions & 0 deletions boatstack/safety.go
Original file line number Diff line number Diff line change
Expand Up @@ -270,6 +270,15 @@ func publicationBypassFinding(repo, reason, source string) (SafetyFinding, bool)
if err != nil {
return SafetyFinding{Category: "workflow-state-invalid", Reason: "publication is denied because managed delivery state cannot be verified", Source: "delivery-state"}, true
}
// Scope publication-authority resolution to un-ignored deliveries so it
// matches ResolveNext and the run coordinator. Without this, a stale-but-
// active ignored delivery (e.g. an APPROVED lock whose code shipped out of
// band) poisons authority for every other delivery with relation=ambiguous.
// A config that fails to load leaves active unfiltered, preserving the prior
// behavior.
if config, _, configErr := LoadConfig(filepath.Join(repo, ".product-loop", "project.json")); configErr == nil {
active = withoutIgnoredDeliveries(active, config.Workflow.IgnoredDeliveries)
}
if len(active) == 0 {
return SafetyFinding{}, false
}
Expand Down
2 changes: 1 addition & 1 deletion docs/evidence-engineered-coding.md
Original file line number Diff line number Diff line change
Expand Up @@ -146,6 +146,6 @@ Delivery and system improvement also remain separate. A failed task may suggest

## What is evidence-backed

The current moves were derived from the Intelligence Flow benchmark corpus and product-repository studies. The generated source commit is [`c5f3e330d6167247446e1915deaf1bc593cf2e0d`](https://github.com/operatorstack/intelligence-flow/tree/c5f3e330d6167247446e1915deaf1bc593cf2e0d/labs/12-product-engineering-loop).
The current moves were derived from the Intelligence Flow benchmark corpus and product-repository studies. The generated source commit is [`5227e7828d9bcac8c6b11c19289c2b4ef5be92a2`](https://github.com/operatorstack/intelligence-flow/tree/5227e7828d9bcac8c6b11c19289c2b4ef5be92a2/labs/12-product-engineering-loop).

The evidence supports specific failure mechanisms and guardrails. It does not establish that Boatstack is optimal, that control-theory notation proves software quality, or that one workflow dominates every team. Those are evaluation questions, so the distribution preserves measurements, provenance, gaps, and negative results.
24 changes: 12 additions & 12 deletions docs/public-claims.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"schema_version": 1,
"source_commit": "c5f3e330d6167247446e1915deaf1bc593cf2e0d",
"source_commit": "5227e7828d9bcac8c6b11c19289c2b4ef5be92a2",
"statuses": ["verified", "observed", "still_being_evaluated"],
"claims": [
{
Expand All @@ -12,7 +12,7 @@
"readable_evidence": "why-these-steps.md#portable-workflow-and-state",
"implementation": ["../boatstack/export.go", "../boatstack/references/artifacts.md", "../boatstack/references/workflow.md"],
"verification": ["../boatstack/export_test.go"],
"last_verified_version": "source:c5f3e330d6167247446e1915deaf1bc593cf2e0d"
"last_verified_version": "source:5227e7828d9bcac8c6b11c19289c2b4ef5be92a2"
},
{
"id": "human-decisions",
Expand All @@ -23,7 +23,7 @@
"readable_evidence": "why-these-steps.md#human-decisions",
"implementation": ["../boatstack/references/workflow.md", "../boatstack/plan.go"],
"verification": ["../boatstack/plan_test.go", "../boatstack/planning_test.go"],
"last_verified_version": "source:c5f3e330d6167247446e1915deaf1bc593cf2e0d"
"last_verified_version": "source:5227e7828d9bcac8c6b11c19289c2b4ef5be92a2"
},
{
"id": "validation-provenance",
Expand All @@ -34,7 +34,7 @@
"readable_evidence": "why-these-steps.md#validation-provenance",
"implementation": ["validation-and-evidence.md", "../boatstack/plan.go"],
"verification": ["../boatstack/plan_test.go"],
"last_verified_version": "source:c5f3e330d6167247446e1915deaf1bc593cf2e0d"
"last_verified_version": "source:5227e7828d9bcac8c6b11c19289c2b4ef5be92a2"
},
{
"id": "irreversible-operations",
Expand All @@ -46,7 +46,7 @@
"readable_evidence": "why-these-steps.md#irreversible-operations",
"implementation": ["safety.md", "../boatstack/safety.go", "../boatstack/hooks.go"],
"verification": ["../boatstack/safety_test.go", "../boatstack/hooks_test.go"],
"last_verified_version": "source:c5f3e330d6167247446e1915deaf1bc593cf2e0d"
"last_verified_version": "source:5227e7828d9bcac8c6b11c19289c2b4ef5be92a2"
},
{
"id": "reviewer-ready-pr",
Expand All @@ -57,7 +57,7 @@
"readable_evidence": "why-these-steps.md#reviewer-ready-pr",
"implementation": ["../boatstack/pr.go", "getting-started.md"],
"verification": ["../boatstack/pr_test.go"],
"last_verified_version": "source:c5f3e330d6167247446e1915deaf1bc593cf2e0d"
"last_verified_version": "source:5227e7828d9bcac8c6b11c19289c2b4ef5be92a2"
},
{
"id": "phase-scoped-delivery",
Expand All @@ -68,7 +68,7 @@
"readable_evidence": "why-these-steps.md#phase-scoped-delivery",
"implementation": ["../boatstack/delivery.go", "../boatstack/safety.go", "../boatstack/hooks.go", "../boatstack/references/workflow.md"],
"verification": ["../boatstack/delivery_test.go", "../boatstack/pr_test.go"],
"last_verified_version": "source:c5f3e330d6167247446e1915deaf1bc593cf2e0d"
"last_verified_version": "source:5227e7828d9bcac8c6b11c19289c2b4ef5be92a2"
},
{
"id": "model-neutral-contract",
Expand All @@ -79,7 +79,7 @@
"readable_evidence": "why-these-steps.md#model-choice-and-budget",
"implementation": ["research-and-design.md", "../boatstack/references/workflow.md"],
"verification": ["../boatstack/export_test.go", "../boatstack/planning_test.go"],
"last_verified_version": "source:c5f3e330d6167247446e1915deaf1bc593cf2e0d"
"last_verified_version": "source:5227e7828d9bcac8c6b11c19289c2b4ef5be92a2"
},
{
"id": "cross-model-failures",
Expand All @@ -90,7 +90,7 @@
"readable_evidence": "why-these-steps.md#model-choice-and-budget",
"implementation": ["research-and-design.md"],
"verification": ["benchmark-corpus-audit.md", "benchmark-submission-audit.md"],
"last_verified_version": "source:c5f3e330d6167247446e1915deaf1bc593cf2e0d"
"last_verified_version": "source:5227e7828d9bcac8c6b11c19289c2b4ef5be92a2"
},
{
"id": "lower-cost-outcomes",
Expand All @@ -101,7 +101,7 @@
"readable_evidence": "why-these-steps.md#model-choice-and-budget",
"implementation": ["research-and-design.md"],
"verification": ["benchmark-corpus-audit.md", "benchmark-submission-audit.md"],
"last_verified_version": "source:c5f3e330d6167247446e1915deaf1bc593cf2e0d"
"last_verified_version": "source:5227e7828d9bcac8c6b11c19289c2b4ef5be92a2"
},
{
"id": "git-worktree-activation",
Expand All @@ -112,7 +112,7 @@
"readable_evidence": "why-these-steps.md#git-worktree-activation",
"implementation": ["../boatstack/runtime_cache.go", "../boatstack/hooks.go"],
"verification": ["../boatstack/runtime_cache_test.go", "../boatstack/hooks_test.go"],
"last_verified_version": "source:c5f3e330d6167247446e1915deaf1bc593cf2e0d"
"last_verified_version": "source:5227e7828d9bcac8c6b11c19289c2b4ef5be92a2"
},
{
"id": "visible-updates",
Expand All @@ -123,7 +123,7 @@
"readable_evidence": "why-these-steps.md#visible-updates",
"implementation": ["../boatstack/update.go", "../boatstack/init.go"],
"verification": ["../boatstack/update_test.go", "../boatstack/init_test.go", "../boatstack/export_test.go"],
"last_verified_version": "source:c5f3e330d6167247446e1915deaf1bc593cf2e0d"
"last_verified_version": "source:5227e7828d9bcac8c6b11c19289c2b4ef5be92a2"
}
]
}
2 changes: 1 addition & 1 deletion labs/diagram-json/plan.lock.json
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
"plan_path": "labs/diagram-json/plan.md",
"plan_sha256": "3cc4f533b8d69386deff16b3a594a3ba09d4c0c3db636cccd8c4380084ce6a51",
"schema_version": 1,
"source_commit": "c5f3e330d6167247446e1915deaf1bc593cf2e0d",
"source_commit": "5227e7828d9bcac8c6b11c19289c2b4ef5be92a2",
"source_plan_path": "labs/diagram-json/source-plan.md",
"source_plan_sha256": "e10593ddaa7522ab80cc991d0a09399257139799e37f737794cd49d68a39985b",
"spec_path": "labs/diagram-json/spec.md",
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
### Publication authority honors ignored deliveries

Publication-authority resolution now excludes `workflow.ignored_deliveries` when deciding whether a push or PR mutation is ambiguous, matching the behavior `next` and `run` already had. Previously a stale-but-active ignored delivery — for example an approved plan lock whose code shipped out of band, leaving zero delivery progress — still counted toward ambiguity and denied every unrelated push with `relation=ambiguous`, even though the slug was explicitly listed as ignored.

The safety interlock is unchanged for genuinely ambiguous work: a new, un-ignored active delivery that does not match the current branch still blocks publication. A configuration that fails to load leaves the delivery set unfiltered, preserving the prior conservative behavior.
Loading