diff --git a/investigation/ui-parity-matrix.md b/investigation/ui-parity-matrix.md index 9815f83b..b90b745d 100644 --- a/investigation/ui-parity-matrix.md +++ b/investigation/ui-parity-matrix.md @@ -52,21 +52,32 @@ provider dependency. This changes delivery priority only: all row names, statuses and runtime evidence below are unchanged, and exposed unsafe behavior is not waived. -**2026-10-01 post-wave audit:** accepted main is -`7d382687eadbce24b0f72eb23633896414153671`. The audit re-read all **98** -surface rows after [#572](https://github.com/scgopi/GraphCode/pull/572), the -standalone merged implementation/tooling PRs -[#573](https://github.com/scgopi/GraphCode/pull/573) through -[#578](https://github.com/scgopi/GraphCode/pull/578), and app-native stack `#581` -containing [#579](https://github.com/scgopi/GraphCode/pull/579) and -[#580](https://github.com/scgopi/GraphCode/pull/580). The exact result remains -**62 Validated / 36 Partial / 0 Missing / 0 Blocked / 0 Divergent**. The wave -fixes real source and evidence-pipeline defects, but supplies no exact packaged +**2026-10-01 post-queue audit:** accepted main is +`ca535d0c4042a60ab748f7ff01d6460e9c9ec0d1`. The audit re-read all **98** +surface rows after the first implementation wave, documentation reconciliation +[#584](https://github.com/scgopi/GraphCode/pull/584) merged as +`f1c5a57f3ba7e9f5743c34a87628806992e1089f`, resilient Zig bootstrap +[#586](https://github.com/scgopi/GraphCode/pull/586), app-native stack `#595` +containing [#585](https://github.com/scgopi/GraphCode/pull/585) and +[#594](https://github.com/scgopi/GraphCode/pull/594), and redirected-profile +daemon fix [#593](https://github.com/scgopi/GraphCode/pull/593). The exact +result remains **62 Validated / 36 Partial / 0 Missing / 0 Blocked / +0 Divergent**. These changes fix real source, contributor-flow, and +evidence-pipeline defects, but supply no exact packaged production-daemon/native-client flight or matched macOS observation that closes -the remaining residuals of a whole row. In particular, Four-page onboarding -is now source-fixed and locally/CI qualified while remaining Partial pending -the packaged/native evidence tracked by open -[#556](https://github.com/scgopi/GraphCode/issues/556). +the remaining residuals of a whole row. + +In particular, Four-page onboarding remains source-fixed and locally/CI +qualified but `Partial` pending the packaged/native evidence tracked by open +[#556](https://github.com/scgopi/GraphCode/issues/556). The real pinned +build/run/stop cycle in #585/#594 proves a checkout-owned contributor path, not +installed onboarding, native keyboard/UIA, authenticated-agent terminal, or +persistence behavior. The direct-process and exact-head Windows/macOS evidence +in #593 closes the redirected-profile source defect, not a parity surface. +Open [#587](https://github.com/scgopi/GraphCode/pull/587) bounds the harness +worker and cleanup but still fails required integration; [#560](https://github.com/scgopi/GraphCode/issues/560) +is now product-attributed UI-thread starvation pending an authorized full +process dump and child-process inventory before shared product changes. ## Application shell and navigation @@ -247,11 +258,43 @@ case proves ownership only. All existing Partial rows remain Partial. **Known shared-environment gate instability surfaced while validating the Window toolbar/Update command rows above:** with the local shell toolchain unblocked (PR #433), multiple parity sessions now build and run `graphcode-windows.exe`/`zmx.exe` concurrently on the same interactive desktop. The pre-existing worktree reorder/removal focus-retention stress block in `Tools/windows/uia-live-gate.ps1` (`Retain-FocusWithRetry`, its `Start-Job` concurrent-UIA-read stress, and the plain `Get-DirectChildren` tree walks around it) repeatedly hit raw, uncaught COM exceptions (`GetFirstChild`/`GetNextSibling` "Could not open the process token"/"Unrecognized error.") at different, unrelated call sites across many local runs, and a separate run was independently derailed by another desktop application (Chrome) stealing the foreground window during a modal-dialog wait. None of this reproduced from this branch's own changes — a minimal, standalone re-run that skips straight to the Update command assertions using the same shell process, native menu, and gate helpers passed cleanly and repeatably. This matches flakiness independently reported by sibling parity sessions and is a pre-existing, shared test-infrastructure limitation, not a product regression; it blocked getting one single uninterrupted top-to-bottom `uia-live-gate.ps1` run this session and is flagged here for follow-up (likely hardening `Get-DirectChildren`/`Retain-FocusWithRetry` against concurrent-desktop contention). -**Validation-infrastructure work items from a 2026-10-01 clean-clone setup:** these are evidence-pipeline facts, not product parity changes, and no row status depends on them. -- The local `uia-live-gate.ps1` run timed out twice after the Worktrees lane click on an otherwise passing `windows-shell` validation ([#560](https://github.com/scgopi/GraphCode/issues/560)). This is a different call site from the instability noted above. It is unresolved, so a local gate failure there is not attributed to the product. +**Validation-infrastructure reconciliation from the 2026-10-01 clean-clone +setup:** these are source/tooling/evidence-pipeline facts, not product parity +changes, and no row status depends on them. +- The checkout-owned contributor entry point and its quick-start documentation + are accepted through [#585](https://github.com/scgopi/GraphCode/pull/585) and + [#594](https://github.com/scgopi/GraphCode/pull/594), merged atomically as + `7d5cf3be8a86b7562b527f90d854845a52f2ac82`. Their real pinned cycle built + all four artifacts, started production daemon before shell in owned roots, + stopped only captured checkout-owned processes, and preserved the default + profile. That closes [#557](https://github.com/scgopi/GraphCode/issues/557) + and [#552](https://github.com/scgopi/GraphCode/issues/552), but it is not + installation, native UI, backend, persistence, or parity evidence. +- Bootstrap retry/resume/stall/mirror/cache/checksum behavior is + source/tooling-fixed by [#586](https://github.com/scgopi/GraphCode/pull/586), + which closed [#559](https://github.com/scgopi/GraphCode/issues/559). Its + deterministic HTTP fixtures and 12/12 contracts improve contributor setup; + no ledger row depends on real ziglang.org transport or a package flight. +- The local `uia-live-gate.ps1` Worktrees timeout is product-attributed + UI-thread starvation, not merely unclassified shared-desktop flakiness + ([#560](https://github.com/scgopi/GraphCode/issues/560)). Open + [#587](https://github.com/scgopi/GraphCode/pull/587) bounds and cleans up the + harness workers but still fails required integration. Before shared + `App.zig` / `WorktreeStatus.zig` changes, capture an authorized full + `graphcode-windows.exe` process dump at the first timeout plus the complete + child-process inventory and command lines; confirm the synchronous + `applyOverviewLaneAction → inspectWorktreesImpl → WorktreeStatus.inspect` + stack or capture provider locks. - The deep-checkout fixture failure is source/tooling-fixed by [#575](https://github.com/scgopi/GraphCode/pull/575), which closed [#561](https://github.com/scgopi/GraphCode/issues/561) after a deep-root positive run and 21 immutable regression logs. That improves evidence reliability; it is not product-runtime proof. - Validation profile leakage is source/tooling-fixed by [#576](https://github.com/scgopi/GraphCode/pull/576), which closed [#562](https://github.com/scgopi/GraphCode/issues/562) after 4/4 isolation tests and 380 validation-runner contracts. This qualifies the harness boundary, not an installed user's profile behavior. -- Redirecting `USERPROFILE` makes `graphcoded` exit silently with `0xC000001D` ([#558](https://github.com/scgopi/GraphCode/issues/558)). Isolated runs must therefore use `GRAPHCODE_SUPPORT_DIR`, not a redirected profile. +- Redirected `USERPROFILE` startup is source-fixed by [#593](https://github.com/scgopi/GraphCode/pull/593), + which closed [#558](https://github.com/scgopi/GraphCode/issues/558) at current + main `ca535d0c4042a60ab748f7ff01d6460e9c9ec0d1`. The direct-process regression + now exits cleanly, the Windows Swift production suite passed, and mandatory + exact-head macOS shared CI passed. Qualification still uses explicit owned + support/temp roots for isolation; this source fix is not an installed-client + or parity observation. + ## Audit conclusion The Windows branch has substantial protocol, lifecycle, persistence, terminal, graph diff --git a/investigation/windows-preview-release-plan.md b/investigation/windows-preview-release-plan.md index adc8e251..16645d3e 100644 --- a/investigation/windows-preview-release-plan.md +++ b/investigation/windows-preview-release-plan.md @@ -11,20 +11,28 @@ flight, followed by fixes for any reproduced core bugs. It is not closing all 36 Partial rows, and it is not just visual polish. Assessment date: **2026-10-01**. Accepted repository source floor: -`7d382687eadbce24b0f72eb23633896414153671` (`origin/main` after -[#575](https://github.com/scgopi/GraphCode/pull/575)). It includes the -documentation audit in [#572](https://github.com/scgopi/GraphCode/pull/572), -the six standalone implementation/tooling PRs -[#573](https://github.com/scgopi/GraphCode/pull/573) through -[#578](https://github.com/scgopi/GraphCode/pull/578), and app-native stack -`#581` containing [#579](https://github.com/scgopi/GraphCode/pull/579) and -[#580](https://github.com/scgopi/GraphCode/pull/580), merged to main as -`acdb2a625c93046b9443d2437361ef5464b0f347`. At this audited HEAD, a -row-by-row review of the [parity ledger](ui-parity-matrix.md) still contains -exactly **98 surfaces: 62 Validated and 36 Partial**, with zero Missing, -Blocked, or Divergent rows. No implementation-wave result supplies the -packaged/native-client evidence required to promote a whole row. A newer -candidate must be qualified at its own exact source and package hashes. +`ca535d0c4042a60ab748f7ff01d6460e9c9ec0d1` (`origin/main` after +[#593](https://github.com/scgopi/GraphCode/pull/593)). The first-wave source +floor remains `7d382687eadbce24b0f72eb23633896414153671`; its post-wave +documentation reconciliation [#584](https://github.com/scgopi/GraphCode/pull/584) +merged as `f1c5a57f3ba7e9f5743c34a87628806992e1089f`. The second wave then +merged resilient Zig downloads [#586](https://github.com/scgopi/GraphCode/pull/586) +as `c19e277eef2728ef5046770a34fef8f0bbd63f33`, app-native stack `#595` +(not a GitHub PR) containing [#585](https://github.com/scgopi/GraphCode/pull/585) +and [#594](https://github.com/scgopi/GraphCode/pull/594) atomically as +`7d5cf3be8a86b7562b527f90d854845a52f2ac82`, and redirected-profile +daemon fix [#593](https://github.com/scgopi/GraphCode/pull/593) from accepted +head `285b73e8e5a7634a9033b8e72f950efc703b4f60` as the current main +merge. Exact-head #593 checks include successful Windows shell, Windows Swift +production coverage, and the mandatory macOS shared regression. + +At this audited HEAD, a row-by-row review of the +[parity ledger](ui-parity-matrix.md) still contains exactly **98 surfaces: +62 Validated and 36 Partial**, with zero Missing, Blocked, or Divergent rows. +These source, contributor-flow, and evidence-pipeline fixes supply no installed +production-daemon/native-client or matched macOS observation that closes the +remaining residuals of a whole row. A newer candidate must be qualified at its +own exact source and package hashes. The earlier `0765419a6d1e7ad401422903edf9102dbf0c9a17` assessment recorded 63 Validated and 35 Partial before a clean-clone setup and manual launch showed @@ -39,7 +47,7 @@ routing [#567](https://github.com/scgopi/GraphCode/pull/567), launch-free packaged-core preparation [#568](https://github.com/scgopi/GraphCode/pull/568), workspace recovery preservation [#570](https://github.com/scgopi/GraphCode/pull/570), and the completed -implementation wave summarized below. These improve accepted source, focused +implementation waves summarized below. These improve accepted source, focused coverage, and qualification readiness; none independently supplies the missing installed production-daemon, owned native-input, authenticated-backend, destructive-lifecycle, cross-platform, or published-artifact evidence required @@ -75,7 +83,7 @@ Mixed rows are split within their notes. Clipboard, IME, DPI, accessibility and font quality are not blanket polish categories. Existing code bugs blocking either parity or ordinary app features are legitimate functional work. -### Evidence-state vocabulary and completed implementation wave +### Evidence-state vocabulary and completed implementation waves Use these states literally rather than treating "merged" as "release-ready": @@ -88,9 +96,10 @@ Use these states literally rather than treating "merged" as "release-ready": | **Deferred** | Work is deliberately outside the current critical path unless a concrete dependency appears. | | **Evidence-only** | The work changes documentation, attribution, or observation reliability without itself changing the product behavior being assessed. | -| Delivery | Accepted mapping | State at `7d382687` | Residual | +| Delivery | Accepted mapping | State at `ca535d0c` | Residual | |---|---|---|---| | Audit reconciliation | [#572](https://github.com/scgopi/GraphCode/pull/572) | **Evidence-only**, merged | Superseded by this post-wave audit; no product or parity-row change. | +| Post-wave documentation reconciliation | [#584](https://github.com/scgopi/GraphCode/pull/584) | **Evidence-only**, merged as `f1c5a57f3ba7e9f5743c34a87628806992e1089f` | Superseded by this second-wave audit; no product or parity-row change. | | Onboarding support directory | [#573](https://github.com/scgopi/GraphCode/pull/573) closes [#554](https://github.com/scgopi/GraphCode/issues/554) | **Source-fixed; locally/CI qualified** by 3/3 focused and 10/10 full onboarding tests | Exact packaged first launch must prove the selected support directory changes while the real profile remains byte-for-byte unchanged. | | Provider bootstrap paths | [#574](https://github.com/scgopi/GraphCode/pull/574) closes [#551](https://github.com/scgopi/GraphCode/issues/551) | **Source/tooling-fixed; locally/CI qualified** by 5/5 bootstrap tests and the provider-pin contract | Contributor setup improvement only; not packaged-client evidence. | | Deep worktree fixtures | [#575](https://github.com/scgopi/GraphCode/pull/575) closes [#561](https://github.com/scgopi/GraphCode/issues/561) | **Source/tooling-fixed; locally qualified** by a deep-root positive run and 21 immutable regression case logs | Evidence-pipeline reliability only; no product parity effect. | @@ -98,6 +107,11 @@ Use these states literally rather than treating "merged" as "release-ready": | Missing-secret daemon startup | [#577](https://github.com/scgopi/GraphCode/pull/577) closes [#555](https://github.com/scgopi/GraphCode/issues/555) | **Source-fixed; locally/CI qualified** by the focused startup contract and 177/177 DaemonClient tests | The ordinary packaged empty-support-directory first run remains part of the production-core flight. | | Explicit local package mode | [#578](https://github.com/scgopi/GraphCode/pull/578) closes [#553](https://github.com/scgopi/GraphCode/issues/553) | **Source/tooling-fixed; packaging-gate qualified** with local provenance and publication refusal | No exact candidate was installed on a client or published; local mode is not release authorization. | | First-run connection and UIA | App-native stack `#581` (not a GitHub PR): [#579](https://github.com/scgopi/GraphCode/pull/579) + [#580](https://github.com/scgopi/GraphCode/pull/580); [#556](https://github.com/scgopi/GraphCode/issues/556) remains open | **Source-fixed; locally/CI qualified**, including 734/734 App tests and a shown-window UIA/message probe | Evidence remains for packaged install through connected Welcome, desktop-level native keyboard input, and any claimed assistive-technology behavior. | +| Resilient pinned Zig downloads | [#586](https://github.com/scgopi/GraphCode/pull/586) closes [#559](https://github.com/scgopi/GraphCode/issues/559) | **Source/tooling-fixed; locally/CI qualified** by 12/12 bootstrap contracts, deterministic HTTP Range/stall fixtures, provider-pin checks, and privacy validation | Contributor bootstrap reliability only; real ziglang.org transport was not part of the PR evidence and no packaged-client gate changes. | +| Checkout-owned build/run/stop | App-native stack `#595`: [#585](https://github.com/scgopi/GraphCode/pull/585) closes [#557](https://github.com/scgopi/GraphCode/issues/557) | **Source/tooling-fixed; real pinned cycle qualified** at merge `7d5cf3be8a86b7562b527f90d854845a52f2ac82` | The final pinned build produced all four executables; run started production daemon before shell in owned roots; stop removed only captured checkout-owned processes and preserved the real profile. This is not installation, native UI, agent, persistence, accessibility, or packaging evidence. | +| Contributor quick-start documentation | App-native stack `#595`: [#594](https://github.com/scgopi/GraphCode/pull/594) closes [#552](https://github.com/scgopi/GraphCode/issues/552) | **Evidence-only**, merged atomically with #585 | Documents measured bootstrap/build/run/stop durations, status markers, and honest failure/evidence limits; it changes no product behavior or parity status. | +| Redirected `USERPROFILE` daemon startup | [#593](https://github.com/scgopi/GraphCode/pull/593) closes [#558](https://github.com/scgopi/GraphCode/issues/558) | **Source-fixed; locally/CI qualified** by the direct-process RED/GREEN, 101 XCTest plus 6 Swift Testing cases, release builds, clean smoke, and exact-head Windows/macOS CI | Removes the `0xC000001D` trap. It does not substitute for the installed production-core, onboarding, native-input, terminal, or persistence flight. | +| Worktrees UIA timeout attribution | Open [#587](https://github.com/scgopi/GraphCode/pull/587) at head `c249b9f8731741167bd11ca400691f26f0639903`, part of open [#560](https://github.com/scgopi/GraphCode/issues/560) | **Evidence-only harness boundary; required integration failing** | Bounded workers and cleanup establish product UI-thread starvation during synchronous worktree inspection, but an authorized full process dump and child-process inventory are required before changing shared `App.zig` / `WorktreeStatus.zig`. | ## Provider work deferred for preview prioritization @@ -106,7 +120,7 @@ than continue expanding validation before attempting the installed GraphCode core workflow. Preserve their open draft PRs, branches, working changes and evidence; pausing is not completion, abandonment or a passing check. Accepted GraphCode repository floor is -`7d382687eadbce24b0f72eb23633896414153671`; neither provider change is +`ca535d0c4042a60ab748f7ff01d6460e9c9ec0d1`; neither provider change is included in its pinned provider. No parity status changes here. The pause is a priority reset, not a permanent prohibition or a requirement for @@ -400,79 +414,78 @@ Do not enable or advertise in-app install/relaunch until its own real running-EXE/session-continuity flight passes. This plan neither creates a tag or release nor dispatches CI, uploads assets, installs an app or changes pins. -## Known work items from a clean-clone setup +## Assigned work inventory after the clean-clone queue The 2026-10-01 assignment audit resolved the canonical programme assignee as `coneilen` (GitHub user ID `41757757`) separately from the authenticated writer `coneilen_microsoft`. The same 13 assigned `windows`-label issues remain the -audited inventory, all in `scgopi/GraphCode`; live GitHub state is now exactly -**7 open / 6 closed**. The two provider repositories still have zero matching +audited inventory, all in `scgopi/GraphCode`; live GitHub state at this commit is +exactly **3 open / 10 closed**. The two provider repositories still have zero matching assigned issues. Empty provider results are inventory facts, not passing product evidence. | Issue | Live state and accepted source | Evidence tier | Remaining criterion | |---|---|---|---| | [#551](https://github.com/scgopi/GraphCode/issues/551) | **Closed** by [#574](https://github.com/scgopi/GraphCode/pull/574) | Source/tooling-fixed; 5/5 bootstrap tests plus provider-pin regression | No preview gate; retain the documented short-root remedy for legacy path budgets. | -| [#552](https://github.com/scgopi/GraphCode/issues/552) | **Open; deferred until #557** | Documentation work not started | Stack contributor quick-start documentation after the build/run entry point exists, using measured durations and observed failures rather than planned values. | +| [#552](https://github.com/scgopi/GraphCode/issues/552) | **Closed** by [#594](https://github.com/scgopi/GraphCode/pull/594), merged with lower [#585](https://github.com/scgopi/GraphCode/pull/585) in app-native stack `#595` at `7d5cf3be8a86b7562b527f90d854845a52f2ac82` | Evidence-only documentation; 3 focused documentation cases plus inherited 4-case dev regression | The quick start now records measured timings, supported commands, known failures, and evidence limits. It does not qualify native UI, installation, an authenticated backend, or parity. | | [#553](https://github.com/scgopi/GraphCode/issues/553) | **Closed** by [#578](https://github.com/scgopi/GraphCode/pull/578) | Source/tooling-fixed; packaging gate qualified | Local packages have explicit provenance and publication refusal; installed-client and publication evidence remain separate alpha gates. | | [#554](https://github.com/scgopi/GraphCode/issues/554) | **Closed** by [#573](https://github.com/scgopi/GraphCode/pull/573) | Source-fixed; 3/3 focused and 10/10 full tests | Prove the exact packaged first launch writes only the selected support directory and leaves the real profile unchanged. | | [#555](https://github.com/scgopi/GraphCode/issues/555) | **Closed** by [#577](https://github.com/scgopi/GraphCode/pull/577) | Source-fixed; focused contract and 177/177 DaemonClient tests | Prove the production daemon starts/connects from an empty support directory in the packaged core flight. | | [#556](https://github.com/scgopi/GraphCode/issues/556) | **Open; source-fixed/evidence-remaining** through app-native stack `#581` ([#579](https://github.com/scgopi/GraphCode/pull/579) + [#580](https://github.com/scgopi/GraphCode/pull/580)) | Local/CI and shown-window probe evidence; no packaged/native-client qualification | Witness ordinary install → first launch → onboarding → connected Welcome with production `graphcoded`, desktop-level keyboard input, and any claimed assistive-technology behavior. | -| [#557](https://github.com/scgopi/GraphCode/issues/557) | **Open; bounded source/tooling lane** | Not implemented | Add an owned-sandbox build/run/stop entry point that uses the pinned environment, does not pre-seed around first-run behavior, and stops only checkout-owned processes. | -| [#558](https://github.com/scgopi/GraphCode/issues/558) | **Open; evidence/diagnosis lane** | Credible report, root cause unproven | Reproduce current `7d382687` source with redirected `USERPROFILE`, capture the trapping instruction/stack and environment, then add the narrow direct-process regression for the established cause. | -| [#559](https://github.com/scgopi/GraphCode/issues/559) | **Open; bounded source/tooling lane** | Source-supported | Add bounded timeout/retry/resume/progress and an explicit mirror path while preserving checksum enforcement and corrupt/exhausted-path tests. | -| [#560](https://github.com/scgopi/GraphCode/issues/560) | **Open; evidence/reliability lane** | Intermittent timeout not attributed | Capture a timeout dump and distinguish stale-element/desktop contention from a product UI-thread/provider deadlock; harden only the established failing boundary. | +| [#557](https://github.com/scgopi/GraphCode/issues/557) | **Closed** by [#585](https://github.com/scgopi/GraphCode/pull/585), merged with upper [#594](https://github.com/scgopi/GraphCode/pull/594) in app-native stack `#595` at `7d5cf3be8a86b7562b527f90d854845a52f2ac82` | Source/tooling-fixed; 4 focused behavioral cases plus a real pinned build/run/stop cycle | The supported entry point builds the runnable layout, launches production daemon before shell in checkout-owned roots, and stops only revalidated captured identities. Full validation and every native/product release gate remain separate. | +| [#558](https://github.com/scgopi/GraphCode/issues/558) | **Closed** by [#593](https://github.com/scgopi/GraphCode/pull/593), current main `ca535d0c4042a60ab748f7ff01d6460e9c9ec0d1` from head `285b73e8e5a7634a9033b8e72f950efc703b4f60` | Source-fixed; direct-process behavioral regression, Swift production suite, Windows shell, and mandatory macOS shared CI passed at exact head | The redirected-profile trap is fixed. Continue to use explicit owned support/temp roots for qualification isolation; this closure does not prove installed-product behavior. | +| [#559](https://github.com/scgopi/GraphCode/issues/559) | **Closed** by [#586](https://github.com/scgopi/GraphCode/pull/586), merged as `c19e277eef2728ef5046770a34fef8f0bbd63f33` | Source/tooling-fixed; 12/12 bootstrap tests plus deterministic Range/resume/stall/mirror/cache/checksum fixtures | Preserve checksum enforcement, bounded retry/timeout behavior, useful partial archives, and explicit mirror semantics. Real ziglang.org transport was not claimed by the PR. | +| [#560](https://github.com/scgopi/GraphCode/issues/560) | **Open; product-attributed evidence lane** with harness-only [#587](https://github.com/scgopi/GraphCode/pull/587) at `c249b9f8731741167bd11ca400691f26f0639903` | Bounded worker/reacquisition/cleanup contracts pass; exact-head Windows shell integration still fails during synchronous product worktree inspection | Obtain an authorized full process dump at the first post-click timeout and a child-process inventory with command lines. Confirm the UI thread in `applyOverviewLaneAction → inspectWorktreesImpl → WorktreeStatus.inspect` or capture provider locks before changing shared `App.zig` / `WorktreeStatus.zig`. | | [#561](https://github.com/scgopi/GraphCode/issues/561) | **Closed** by [#575](https://github.com/scgopi/GraphCode/pull/575) | Source/tooling-fixed; deep-root positive execution and 21 regression logs | No product gate; preserve positive execution counts and bounded fixture roots. | | [#562](https://github.com/scgopi/GraphCode/issues/562) | **Closed** by [#576](https://github.com/scgopi/GraphCode/pull/576) | Source/tooling-fixed; 4/4 isolation tests and 380 runner contracts | Qualification isolation is accepted; installed-product profile behavior remains a separate flight. | | [#564](https://github.com/scgopi/GraphCode/issues/564) | **Open; deferred** | No extraction accepted | Keep deferred unless a concrete next-wave overlap requires one small ownership extraction; do not turn the broad split into a preview prerequisite. | -Closing an issue does not promote a ledger row by itself. The six closures -record real source/tooling completion; packaged/native-client qualification, +Closing an issue does not promote a ledger row by itself. The ten closures +record real source/tooling/documentation completion; packaged/native-client qualification, publication, and parity promotion retain their separate evidence standards. -## Next-wave orchestration and dependency map - -The completed implementation wave removes the former source prerequisites. -The next wave should not spend its first slot on another parity-row sweep: - -1. **Critical path - installed production-core qualification:** build an exact - `7d382687`-or-newer source-bound local candidate through [#578](https://github.com/scgopi/GraphCode/pull/578)'s - supported route, verify provenance, then use the authorized owned client to - run install → first launch → onboarding → connected Welcome → local project - → one named authenticated backend → readable input/output → persisted reopen - → safe exit. Exercise the destructive fixture and native-input portions of - the seven gates. Close [#556](https://github.com/scgopi/GraphCode/issues/556) - only if its packaged/native residuals pass; otherwise file or update the - exact reproduced blocker without converting missing permission into failure. -2. **Independent bounded source/tooling lane - #557:** implement the - checkout-owned quick-start build/run/stop entry point. It may proceed beside - the client flight and must not pre-seed onboarding, mutate global - environment, or stop non-owned processes. -3. **Independent bounded source/tooling lane - #559:** make Zig downloads - resilient with bounded timeout/retry/resume/progress/mirror behavior and - retained checksum/corruption/exhaustion contracts. It does not block a - prebuilt candidate flight. -4. **Independent evidence lane - #558:** diagnose the redirected-`USERPROFILE` - `0xC000001D` crash on exact current source. Capture the trap before selecting - a code fix; keep qualification isolation on `GRAPHCODE_SUPPORT_DIR` rather - than relying on the crashing profile redirect. -5. **Independent evidence/reliability lane - #560:** reproduce and attribute - the UIA timeout with dump/timing evidence, then harden the smallest proven - boundary. Do not relabel a shared-desktop or stale-element failure as a - product deadlock, or vice versa. -6. **Dependent documentation lane - #552 after #557:** stack the contributor - quick-start documentation after the script contract is accepted. Include - measured durations, the supported launch/stop path, and failures actually - observed by the script and production-core flight. - -Keep [#564](https://github.com/scgopi/GraphCode/issues/564) deferred unless one -of these lanes demonstrates a concrete overlap that a small extraction can -remove safely. Keep -[coneilen/winghostty#11](https://github.com/coneilen/winghostty/pull/11) and -[coneilen/winghostty#10](https://github.com/coneilen/winghostty/pull/10) -paused unless actual client/backend evidence demonstrates respectively a -provider-validation dependency or the glyph-capacity failure. No PR count, -provider branch, or full parity-row closure is an implicit preview prerequisite. +## Post-queue orchestration and dependency map + +The bounded source/tooling queue is complete. Remaining work is bottom-up and +permission-bound; it should not start with another parity-row sweep: + +1. **Installed production-core and onboarding qualification - #556:** build an + exact source-bound local candidate from + `ca535d0c4042a60ab748f7ff01d6460e9c9ec0d1` or a newer explicitly audited + main through [#578](https://github.com/scgopi/GraphCode/pull/578)'s supported + route, verify provenance, then use an authorized owned Windows client to run + install → first launch → onboarding → connected Welcome → local project → + one named authenticated backend → readable input/output → persisted reopen + → safe exit. This packaged/native-client flight **can close #556** only when + its exact residuals pass; missing desktop, backend, destructive-fixture, or + assistive-technology permission remains NotExecuted rather than failure or + success. +2. **Authorized timeout attribution - #560 / #587:** keep open + [#587](https://github.com/scgopi/GraphCode/pull/587) harness-only and + evidence-only at head `c249b9f8731741167bd11ca400691f26f0639903`. + Its bounded workers and cleanup are useful but cannot close #560 while + required integration still times out. On an authorized owned desktop, + capture a full process dump at the first timeout plus a child-process + inventory and command lines. Only then make the smallest source change + supported by the stacks/locks, rerun the targeted regression and exact-head + integration, and decide whether that combined evidence can close #560. +3. **Keep the release gates honest:** all **seven** gates remain open. The + installed production-core result, native input and destructive fixture + permission, named authenticated backend authorization, exact artifact + provenance, and publication permission are independent. A green + build/run/stop cycle, a local package, or harness attribution does not + authorize tester publication or promote a ledger row. +4. **Keep #564 deferred:** do not split shared files merely to create work. + Open a bounded extraction session/PR only if the #556 flight or the + dump-backed #560 fix identifies a concrete ownership dependency. Such an + extraction may unblock delivery but is not preview qualification by itself. +5. **Keep provider work deferred:** retain + [coneilen/winghostty#11](https://github.com/coneilen/winghostty/pull/11) and + [coneilen/winghostty#10](https://github.com/coneilen/winghostty/pull/10) + paused unless actual client/backend evidence demonstrates respectively a + provider-validation dependency or the glyph-capacity failure. No PR count, + provider branch, or full parity-row closure is an implicit preview + prerequisite. ## Measuring progress