Skip to content

Latest commit

 

History

History
124 lines (107 loc) · 12.2 KB

File metadata and controls

124 lines (107 loc) · 12.2 KB

V1.0 prioritized backlog

Estimates are ideal engineering/operations days and exclude elapsed specialist review. P0 blocks V1.0; P1 is cut before a P0 slips. Owners are roles from the master plan.

Implementation ledger (2026-07-17)

This ledger records landed software scope without marking external evidence complete:

  • SRC-03/04/05: registry evidence/expiry/fetch-policy fields, derived anti-fabrication tests, and the shared fail-closed predicate are implemented. The 152 real verification and policy decisions remain human work under SRC-01/02.
  • SRC-03 writers (2026-08-15, #18): the record the predicate requires can now be produced by the tooling rather than only read by it. sentinel verify writes the verification evidence reference — a receipt of the page as the human was shown it — and the recheck expiry, and sentinel sources policy writes the dated robots/terms decision with reviewer, evidence, reason and expiry. Both refuse blanks. Neither makes the decision: the policy outcome is a reading of somebody else's terms and is never inferred, which is why an absent decision stays unreviewed and keeps the source out of the attempt denominator.
  • DATA-01: immutable normalizer/extractor contract versions are persisted on every new snapshot and successful fetch attempt; a checksummed migration labels older snapshots legacy-unknown, and database triggers reject invented or missing provenance. Release-trace propagation remains open, so the backlog item is not complete.
  • DATA-04: every terminal fetch attempt persists its complete evidence — final URL and per-hop redirect chain, distinct raw-byte/normalized-text hashes, byte count, byte bound and truncation, MIME, extraction outcome, and a stable error class — with insert/update triggers that make incomplete or fabricated evidence unstorable, legacy-unknown labelling (never invented values) for pre-migration rows, and a restore-boundary test that reads the evidence back from a copied database file. A distinct TLS-failure error class is not implemented (TLS failures record as unreachable with the literal error string), and the production encrypted backup/restore rehearsal remains OPS-02.
  • ENG-01: the ordered, checksummed, per-migration atomic framework plus run, attempt, and run-observation entities are implemented. Remaining V1 review, correction, publication, retention, and backup entities plus a production backup/rollback rehearsal keep the item open.
  • ENG-02: exact registry revision and eligible/attempted/successful source sets, persisted attempts, atomic observation associations, race-safe terminalization, and constrained quiet/complete/partial/failed receipts are implemented. Deployment, alerting, and qualifying operational receipts remain open.
  • ENG-03: closed-schema aggregate status.json, derived stale health, separate last-attempted/last-successful aggregate runs, explicit scope, and site health that ignores scoped-only success and does not reuse generation time are implemented. Staging/production evidence remains open.
  • ENG-04: substantive observations now require a distinct append-only independent decision; same-actor, missing qualification/conflict evidence, returned, and insufficient review states are structurally unpublishable. Real reviewer policy, calibration, authentication, and the high-impact tabletop remain governance/operations gates.
  • ENG-05: append-only correction and withdrawal events, controlled reason codes, visible schema-v2 lifecycle state, replacement integrity, and cycle-safe supersession are implemented. Incident exercises, publication receipts, retention pins, and signed atomic releases remain.
  • ENG-06: the publisher now enforces the shared source predicate and canonical source identity. Atomic promotion, signed manifests, and the clean verifier remain open.
  • ENG-07: the status schema and real-output compatibility test are implemented; correction and release contracts and the complete migration guide remain open.
  • ENG-10: free-form first/second-review rationale and registry notes remain private; only bounded observation copy and controlled lifecycle reasons serialize, prohibited legal-claim terms fail closed, and legacy mutable notes are quarantined pending explicit audit. Counsel approval of the templates and the real legacy-store audit remain open.

No line above substitutes for the acceptance receipt in the backlog table or the release checklist.

Governance

Item Pri Est. Owner Depends on Acceptance / linked requirement
GOV-01 convene paid community safety panel P0 3 Governance budget ≥3 qualified members, conflicts and authority documented
GOV-02 adopt reviewer qualifications, independence, and escalation P0 3 Governance GOV-01, counsel calibration set passes; policy approved (REV-01/02)
GOV-03 counsel review of product claims, crawling, excerpts, privacy P0 2 Legal reviewer PRD/data map written issues disposition; blockers closed

Source and evidence operations

Item Pri Est. Owner Depends on Acceptance / linked requirement
SRC-01 verify every active source P0 5 Verification GOV-02 all active entries named/dated; skips remain ineligible (SRC-01)
SRC-02 resolve rejects, recheck-due, and active-but-unfetchable entries P0 5 Verification SRC-01 repair with reachable equally official source or structured gap; all six planning-time unfetchable active sources, including SS-5, have dated disposition before the operational baseline (SRC-01/02/PDF-01)
SRC-03 add verification expiry, fetch-policy decision, and eligibility rules P0 2 Engineering GOV-02 canonical registry stores dated robots/terms/fetch-policy reviewer, evidence, outcome and reason; redirect/authority/content sanity events trigger recheck; one predicate fails closed for unverified/recheck-due/policy-ineligible sources (SRC-01/02)
SRC-04 require verification evidence reference and migrate registry P0 3 Engineering SRC-03 schema/CLI reject blank evidence; clean-clone migration preserves provenance (SRC-01)
SRC-05 replace fixed zero-verification test with derived invariant P0 2 Engineering SRC-04 legitimate verification stays green while fabricated or incomplete records fail (SRC-01)
DATA-01 add normalizer/extractor version to provenance P0 2 Engineering architecture every snapshot/release trace has versions (DET-01)
DATA-02 complete hostile/golden fixture corpus P0 4 Engineering threat model all cases in test plan represented (DET-01/02)
DATA-03 replace five-snapshot pruning with time/pin retention P0 4 Engineering ENG-01, OPS-02 24-month expiry, publication/correction/incident pins, backup-before-delete, restore boundary tests (DET-01/PUB-02/OPS-01)
DATA-04 persist complete fetch evidence P0 4 Engineering ENG-01 redirect chain, status, raw/normalized hashes, byte bound/truncation, MIME and extraction outcome survive restore (DET-01)
PDF-01 implement bounded PDF extraction and manual comparator P0 5 Engineering DATA-01/04 every active PDF produces a cited passage comparison or labeled reproducible manual receipt; empty normalization cannot publish (PDF-01/DET-01)

Engineering and publication controls

Item Pri Est. Owner Depends on Acceptance / linked requirement
ENG-01 introduce migration framework and V1 entities P0 4 Engineering data model clean/current backup migrations and rollback rehearsal pass
ENG-02 persist run/attempt/source-health status P0 4 Engineering ENG-01, SRC-03 watcher uses the shared eligibility predicate; exact attempted/eligible numerator and denominator plus quiet, partial, failed, stale states are tested (DET-02/SRC-02)
ENG-03 expose status.json and accurate site health P0 3 Engineering ENG-02 generated time cannot masquerade as successful watch (DET-02/PUB-01)
ENG-04 enforce independent high-impact approval P0 5 Engineering GOV-02, ENG-01 same actor rejected; insufficient review unpublishable (REV-02)
ENG-05 add correction/withdrawal/supersession state P0 5 Engineering ENG-01, GOV-03 immutable history and cycle-safe links (PUB-02)
ENG-06 atomic release and signed release manifest P0 4 Engineering ENG-03/05, SEC-03, SRC-03 publisher rejects unverified, expired/recheck-due, policy-ineligible, rejected, withdrawn, and gap sources; interrupted build leaves old release intact; clean verifier validates hashes/signature (PUB-01/OPS-01/SRC-02)
ENG-07 schema/compatibility fixtures and migration guide P0 3 Engineering ENG-03/05 all artifacts conform; old major-1 fixture reads (PUB-01)
ENG-08 PII screening/quarantine before diff publication P0 3 Engineering data policy seeded canary never publishes (PRIV-01)
ENG-10 separate internal rationale from constrained public copy P0 4 Engineering GOV-03, ENG-01 arbitrary CLI/registry notes stay private; legacy public fields audited; legal-claim terms fail closed (REV-01/PUB-01/PRIV-01)
QA-01 enforce per-target safety-critical branch coverage P0 3 Engineering V1 module boundaries versioned target manifest covers registry/fetch/detect/changes/store/publish/verify, V1 health/retention/signing/migrations, and state-changing CLI handlers; CI reports each target and fails any below 95% while retaining ≥90% overall; no waiver
ENG-09 accessible static review bundle P1 6 Engineering ENG-04 keyboard/screen-reader review; writes remain privileged (REV-03)

Security, accessibility, and operations

Item Pri Est. Owner Depends on Acceptance / linked requirement
SEC-01 SSRF/redirect/path/body hardening and tests P0 4 Engineering threat model, SRC-03 private targets/traversal/bombs blocked; live-policy audit proves UA/TLS/robots/terms decisions match canonical eligibility records (SRC-02/PRIV-01)
SEC-02 CI, secrets, dependency, and host-permission review P0 2 Security RC config no critical/high findings; least privilege evidenced
SEC-03 release-signing trust and key lifecycle P0 3 Security + engineering hosting decision pinned trust manifest, verifier, custody, rotation overlap, revocation and compromise rehearsal pass (PUB-01/OPS-01)
ACC-01 remediate automated/manual WCAG audit P0 4 Accessibility RC surfaces no critical/serious core-task issue (ACC-01)
I18N-01 reviewed Spanish stable metadata P0 4 Language lead message catalog two-person review and stale-string gate (I18N-01)
OPS-01 implement run lock, bounded retry, alerts, and health checks P0 4 Operations ENG-02 fault injection raises correct alert (OPS-01)
OPS-02 encrypted backup plus clean restore command/runbook P0 3 Operations ENG-01 RPO/RTO drill passes (OPS-01)
OPS-03 complete and exercise incident/correction/rollback runbooks P0 4 Operations ENG-05/06 three table-tops, actions/evidence recorded (OPS-01)
OPS-04 complete eight consecutive weekly bootstrap cycles P0 8 Operations OPS-01/02/05 per-run gates pass; rolling objectives report available sample without premature quarter claim (OPS-01)
OPS-05 provision persistent runner and deployment path P0 5 Operations + engineering architecture, SEC-02 named host/volume/scheduler/static host/off-host backup; staging promotion, rollback and recovery receipts (OPS-01)

Release

Item Pri Est. Owner Depends on Acceptance / linked requirement
REL-01 assemble traceability and release receipts P0 3 Product all P0 every checklist item dated, owned, linked
REL-02 multidisciplinary go/hold decision P0 1 Release authority REL-01 signed decision; hold if any must-pass fails

Execution order

The critical path is: GOV-01 → GOV-02 → ENG-04/10 → OPS-04, SRC-04 → SRC-01/02 → PDF-01, and ENG-01 → DATA-03/04 → ENG-02/05 → SEC-03/ENG-06 → OPS-05 → QA-01 → RC evidence. Source verification runs in parallel and finishes before any alert is treated as production-like.