integration/consolidated-current — single-branch consolidation + Phase 2 (2A/2B) - #8
Draft
focusedbrain wants to merge 149 commits into
Draft
focusedbrain wants to merge 149 commits into
focusedbrain wants to merge 149 commits into
Conversation
…trix, migration and risk, refactor plan) Co-authored-by: Cursor <cursoragent@cursor.com>
…y, ingress admission, dead-path removal) One shared full-claim identity guard (issuer+subject+email+wrdesk id, exact match) replaces every partial comparison on ingest/ack/return paths; old comparators deleted. Additive iss columns on coordination_handshake_registry with lazy backfill (first write wins). New per-relationship ingress admission filter is the first stage for all inbound deliveries incl. the BEAP inbox - blocked transmissions die pre-visibility with an audit record. Removes dead skipConsentForAutomation field, unused verifier, and no-op version step, with structural-absence tests. Realm-distribution inventory + phase report in docs/analysis/wr-handshake-gap/phase-1-report.md. Co-authored-by: Cursor <cursoragent@cursor.com>
… frozen core record, key extraction, anti-rollback) Canonicalization module with domain-separation tags; frozen signed core record (wr_canonical_v3 envelope) carrying the complete capsule content as a critical declaration, verified fail-closed on receive on top of legacy rules; containers with preserve-unknown parsing and criticality refusal naming the namespace; namespace registry (implemented + reserved-inert). Dual-format emission: v2 surface stays byte-compatible for old peers; new receivers verify the envelope and mark evidence wire_format canonical_v3 / legacy_v2. Core nonce store rejects replayed cores; generic anti-rollback high-water store lands with documented backup/restore semantics. Key extraction migration (v73) moves private key material into a dedicated handshake_key_store (copy-before-null, idempotent); reads overlay the store. Acceptance tests 1-7 green (replay compat, container semantics, canonical determinism, nonce replay, key extraction, anti-rollback, do-not-regress at exact baseline parity). ingress_path log-only guard added. Phase report in docs/analysis/wr-handshake-gap/phase-2-report.md.
…, ledger freeze
- Profile registry (packages/ingestion-core/profileRegistry.ts): five records
(pbeap_publisher, private_personal, org_internal, org_cross, legacy_v0) fixing
signature cardinality, attestation rules, role symmetry, permitted ingress
paths. resolveProfile is fail-closed [VII.4.2]; no conversion path [VII.4.7].
- verifyCanonicalEnvelope dispatches on the registry: unknown profile/version
refusal naming the profile, distinct-key signature cardinality [VII.3.2],
schema-level attestation presence/absence [VII.4.5]. New reason codes
UNKNOWN_PROFILE / PROFILE_SCHEMA_VIOLATION surfaced in denial audit entries.
- Core store split (v75): wr_handshake_core append-only (UPDATE/DELETE aborted
by triggers, anti-rollback high-water gated) + wr_handshake_runtime mutable
slice; legacy writers dual-write through coreStore adapter; legacy_v0
backfill with null ingress_path, unknown_legacy provenance, empty signature
list (never fabricated).
- Ledger freeze at v74 via freezeAtVersion option + persisted ledger_meta
marker (closes the lazy-migration hole); one-time hygiene sweep copies out
and drops undocumented tables, re-asserts row-level key hygiene; hygiene
assertion on every ledger open.
- ingress_path registry with initial identifiers (Q4 groundwork; log-only).
- Fix: 64-char-hex seed keys signed with a RANDOM key because
generateKeyPairSync('ed25519', {seed}) silently ignores the seed; now
wrapped in PKCS#8 DER (canonicalCore.ts, signatureKeys.ts).
- 30 new acceptance tests (profile dispatch, migration parity, hash
stability, ledger freeze/sweep); phase report with handshake_type inventory
(249 occurrences / 78 files) and rollback plan.
Co-authored-by: Cursor <cursoragent@cursor.com>
…gate, handshake_type elimination, silent revocation, edge-agent retirement) Single formation pipeline (V1): formationPipeline.ts dispatches on the Phase-3 profile registry; the four dialects are deleted (initiatorPersist, recipientPersist, inbound auto-insert, edge-agent pairing). handshake_type branching is eliminated - the admission situation is the profile parameter same_principal (Q9: internal_device, UI label "Cross-Device"); legacy wire compat is confined to samePrincipalWire.ts, the frozen db column, and declared envelope-parse boundaries. Capture methods + Connect-offer staging (V2, C1-C3): capture-method and invitation-class registries (scan/assisted_discovery fail-closed stubs, targeted_bound refusal-only); inbound invitations land in connect-offers.db (own SQLite file, outside both relationship handles) and only a consent event forms a record. Failed verification suppresses the offer entirely - structurally unreachable, no override. 7-day timeout (Q7). Capture provenance is a signed contract declaration (optirando.decl.capture_provenance) on new formations; consent records are Hash-Pinned (preview + bound-definition + contract-state hashes) with tamper invalidation. Silent revocation (V5): revoke-notify capsule removed - enforcement is exclusively the Phase-1 ingress admission filter (zombie old-build peers' sends die pre-visibility with a logged record, verified). Q8: revocation no longer deletes context blocks/embeddings/audit rows; content deletion is the separate explicit operator action deleteRevokedRelationshipContent (handshake.deleteRevokedContent RPC). Edge-agent fold-in (V8/I3): edge_ingestor dialect retired for new formations (RETIRED_FORMATION_DIALECTS, fail-closed unknown_profile); legacy pairings stay readable by the agent dist; lockstep upgrade documented. Acceptance tests 1-8 green (phase4OneFormationPipeline, phase4SilentRevocation, phase4EdgeAgentFoldIn acceptance suites + structural scans). Wide do-not-regress sweep: failure set byte-identical to the Phase-3 baseline (0 new, 0 fixed). Sequencing evidence and deviations in docs/analysis/wr-handshake-gap/phase-4-report.md. Co-authored-by: Cursor <cursoragent@cursor.com>
…tap execution consent, Tier-L evidence chain, capability tokens) Grant objects (E2-E4, E9) [VII.10.x]: wr_grants (migration v76, vault only) with delivery/preparation rights and deliberately no execute variant; the Phase-1 receiver-side ingress filter now consumes grant scopes (off-scope blocked pre-visibility + logged + revoke offer after repetition); admitted deliveries carry grant_ref provenance on email and P2P BEAP paths; legacy relationships lazily backfilled from effective_policy (never a fabricated consent); limit extensions parse-level critical. Execution grants deleted + per-tap consent (V4) [VII.10.1, IX.19.2]: GRANTED_TOOLS and ACTIVE-handshake blanket authorization removed; every execution requires a fresh, single-use, Intent-Hash-bound human consent tap (executionConsent.ts, wr_execution_consents); divergence from the presented preview refuses execution and records a deviation PoAE; fail-closed kill switch WRDESK_EXECUTION_CONSENT_TAP (never a consent-free path). Evidence chain (H1-H4) [IX.19.1, X.10.1]: wr_evidence_chain - append-only by trigger, per-contract monotonic sequence, SHA-256 prev-hash chaining, explicit genesis at cutover; PoAC/PoAE writers on formation, grant lifecycle, admission blocks, content deletion, and executions; BER schema representable now (writers in Phase 6). Ledger repurposing (Q10): handshake-ledger.db is the Tier-L evidence home (ledger-native schema, hygiene-allowlisted); header docs state the actual transitional dual role honestly. Capability-token schema (T4/Q13) [XII.12.6 annex-number-provisional]: carriage-only tokens with preserve-unknown-optional parsing (p2p_signal pattern), optional context_scope/delegation_chain, delegable defaults false, critical limit extensions. Hygiene (H5): deleteHandshakeRecord no longer deletes audit rows; audit_log frozen for mutation via triggers on both handles (INSERT stays open); retention carve-out excludes wr_evidence_chain and audit_log. Pre-existing purge losses are unrecoverable and the chain claims no pre-cutover continuity. Also fixes a Phase-4 latent bug: the default Connect-offer staging DB now uses :memory: under vitest so test runs stop staging offers into the developer-profile connect-offers.db (163 leaked fixture rows purged). Acceptance tests 1-8 green (phase5GrantsEvidence.acceptance.test.ts et al); do-not-regress verified against the Phase-4 baseline worktree - identical pre-existing failure set, zero new regressions. Report: docs/analysis/wr-handshake-gap/phase-5-report.md Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…sponsibility logging EOF Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…json Co-authored-by: Cursor <cursoragent@cursor.com>
…; stamp build046 Co-authored-by: Cursor <cursoragent@cursor.com>
…nce import depth Channel provenance (SPF/DKIM/DMARC) and publisher resolution are mandatory structural pipeline stages, not an opt-in trigger filter. A message failing them yields no WR code and no affordance at all, so there is no class of "WRCode-stamped email" a per-trigger checkbox could select. Disabling the control left it naming a concept that does not exist. Nothing ever produced the verdict it read: NormalizedEvent.wrcodeValid had no writer, EventTagMatcher.evaluate has no production caller, and the router behind the control is fed inline-chat and OCR text, never mail. Removes the type, union member, evaluators, schema enum value, vestigial wrcodeMatch field and the control itself; strips the condition from stored agent configs at every read boundary. InputCoordinator's default: branch now fails closed to match EventTagMatcher, which makes that stripping load-bearing rather than cosmetic. Also fixes email/providers/zoho.ts, which resolved aiProvenance five levels up where its three peers in the same directory correctly use six - the cause of both the blocked session:build and the 77 suite-load failures. Co-authored-by: Cursor <cursoragent@cursor.com>
Brings main's document commits onto the branch so a fresh build covers the complete state: WR Handshake Phases 1-5, art50 AI provenance, WR Code email E2E Phase 1, and main. No code conflicts - main touched no source files. Co-authored-by: focusedbrain <focusedbrain@users.noreply.github.com>
…II additions) Additive delta to the v1.0 email E2E order: A-series decisions A1-A5, Phase 3 additions 3D-3F (CatalogHead, DualAssuranceEnvelope, EVP), Phase 4 offer-schema and status additions, Phase 5 EVP-first-render, and acceptance items (e)-(h). Tracked rather than left in chat because the v1.0 order never was, which is part of how the work lost its paper trail. Co-authored-by: focusedbrain <focusedbrain@users.noreply.github.com>
…ug 2026) Normative source for Delta v1.1 decisions A2 (EVP-first-render, XVII.4.4), A4 (audit link, XVII.6) and A5 (platform suspension, XVII.3.3). Placed at repository root alongside the other annexes. Note: this annex depends throughout on Annex XIV 5.5 (Execution Authorization Proof Chain and Catalog Commitment), which the Annex XIV copy in this repo (v1.0, 26 July 2026) does not contain. Co-authored-by: focusedbrain <focusedbrain@users.noreply.github.com>
Author ruling on the collision named against Annex XVII XVII.3.2/XVII.3.3: three orthogonal layers whose convergence is display-only. entry.status is publisher-signed and platform suspension lives only in the envelope, so the two cannot collide in data. Admission is conjunctive and fail-closed across D4 status, entry.status and envelope.suspension; display keeps all three distinct with headline precedence platform > entry > publisher-part. Phase 4 bullet cross-references A6 for the composition rule. Co-authored-by: focusedbrain <focusedbrain@users.noreply.github.com>
Supersedes the A5 cross-reference wording with the authoritative statement: the surface composes three orthogonal fields (D4 publisher-part status, publisher-signed entry.status, platform envelope.suspension) under A6's conjunctive fail-closed admission rule and headline precedence, with distinct copy per layer. Offer-schema bullet unchanged. Co-authored-by: focusedbrain <focusedbrain@users.noreply.github.com>
Brings Refactor Order v1.0 (754e87e), the authoritative Annex XIV v1.1 carrying XIV.5.5, Annex XVII, and the updated Annexes IX/X/XI onto the Phase-2 branch before order-02 work begins. Plain merge commit per the author ruling: no cherry-picks, no rebase. Co-authored-by: focusedbrain <focusedbrain@users.noreply.github.com>
…e security DB Co-authored-by: Cursor <cursoragent@cursor.com>
… dispatcher) + anti-bypass proofs Co-authored-by: Cursor <cursoragent@cursor.com>
…es, retention pruning, never touches floors/uses/devices) Co-authored-by: Cursor <cursoragent@cursor.com>
…art/crash safety - after-capture identical failing set, +78 passing Co-authored-by: Cursor <cursoragent@cursor.com>
…026-08-12) Preserves uncommitted host-tree work found during the 2026-09 resync (A0/A6). Removes the full disclosure mount and import from five surfaces: EmailInboxBulkView, EmailInboxView, LetterComposerView, WRChatDashboardView, DashboardAutomationHome. HybridSearch keeps its mount. Committed as found; not reviewed, typechecked, or tested in this commit.
…8-12) Preserves uncommitted host-tree work found during the 2026-09 resync (A0/A6). User-facing copy WR Desk/WRDesk -> Optirando, APP_NAME, extension manifest name/title and web-accessible assets, Optirando logo/symbol/wordmark assets, BrandLogo component, wrdesk-logo.png replaced (legacy filename kept). Also contains the uncommitted build-output change build007 -> build009 (electron-builder.config.cjs, extension vite.config.ts). Keep it off the integration line unless intended. Includes repo-root source assets (code/optirando-*.png) and apps/extension-chromium/_symbol_raw.png as found; prune if not wanted. Committed as found; not reviewed, typechecked, or tested in this commit.
…ce unverified) Separate from Rebrand Wave 1 because the file's mtime is 2026-09-25 09:20, six weeks after the rest of the wave. The Author made no edit that day; it is probably left over from an interrupted earlier agent session. Two confirm-dialog strings only. Committed as found; not reviewed or tested.
Analysis-only run after the four-week pause. Resume point 8f0a564 (Run 5). Runs 2-5 were complete on the host but unpushed; secured and pushed in this run (integration fast-forward, wip/host-2026-08-12-art50-rebrand-w1, archive/*). Before-captures at 8f0a564: failure identities (153 in both runs, 0 new / 0 repaired vs the a62d485 capture; testResults.length 589, numTotalTestSuites 2165) and normalized typecheck lists (extension 183 unchanged; workspace +16 since adcc99c, 14 from the stale ingestion-core dist, 2 genuine TS2322). Findings: wrc.* has no production route (dispatcher forwards only vault./ handshake./beap./ingestion.; no UI caller), class register vs the utility-model texts (SPEC-PENDING), ruling-2/3/4 conflicts, contract drift (/v1/directory, entry_id semantics). No product code changed.
…packet, housekeeping
Part A: ruling 2 -> CONFORMANT (signed, status-bearing entries are addressable
sub-handshakes); ruling 1 -> SPEC-PENDING (committed XVI.13.2 governs); ruling 4
-> ANNEX NONCONFORMANCE (Run 1) per Annex XVI v1.95 XVI.3 and XVI.7.4a, fix
first (S1); ruling 3 split into the desktop route (S2b) and the resolver
response contract (S2).
Part B: Author decision packet (12 questions, 8 resolved by evidence), slice
plan with S2a acceptance review of Runs 3-5 before S2b, acceptance table, rig
checklist mapped to slices.
Part C: salvage branch bundled and verified outside OneDrive; stash@{1} and
stash@{2} archived as pushed branches (archive/stash-1-20260516,
archive/stash-2-20260516); ignored-items and absolute-path inventories. No
product code changed; nothing deleted.
…spawn The validator-process lifecycle tests fork a tsx subprocess that resolves @repo/ingestion-core through its package.json (dist/), and the coordination-service startup test spawns dist/server.js. A fresh clone has neither build output, so 11 tests fail there that pass on a tree with a (possibly stale) dist. Run 'pnpm test:prepare' before the sanctioned runner. Verified: fresh clone at C:\dev\optirando reproduces the 153-set after test:prepare (one extra identity is the documented 5 s timing flake in userDataBootstrapPersistence, green in isolation); host tree unchanged at 153.
… and Rebrand Wave 1 Brings the host-tree work of 2026-08-12 onto integration: - 296123b Art. 50: remove the duplicate full disclosure mounts from five surfaces; HybridSearch and the extension popup keep theirs. - 1702378, c67d14c Rebrand Wave 1: WR Desk -> Optirando copy, APP_NAME, manifest name/title, logo assets, BrandLogo. The build007 -> build009 output-dir change in electron-builder.config.cjs and extension vite.config.ts is deliberately NOT taken (integration keeps build007). Verified: sanctioned runner 153-set unchanged (plus the documented userDataBootstrapPersistence timing flake); typecheck extension 183 / workspace 430, sets identical to before the merge.
…VI 3, 7.4a) Annex XVI v1.95 requires the signed WR script block for automatic detection and auto-insertion from pages and e-mail; loose textual references are captured only on explicit user request. Run 1 (d5e4db5) scanned every channel-authenticated plain message at ingest and persisted the results into the sealed metadata - an annex nonconformance. - messageRouter: the ingest scan and the wr_code_detections metadata write are removed. - wrCodeEmailDetection: reduced to the pure, explicit-trigger scanner. - New local RPC wrc.detectReferences (no network) as the explicit trigger; candidates are still submitted through wrc.submitReference. - Tests: source guard that the router never scans or writes detections; handler tests; the full-path capture-origin case now goes through the RPC. Rows ingested since d5e4db5 may still carry a wr_code_detections key in their sealed metadata; nothing reads it.
…sked TS2322 - tsconfig (electron app): map @repo/ingestion-core to its src, like @repo/shared-beap-ui. The headless typecheck no longer depends on a built (and possibly stale) packages/ingestion-core/dist: 26 ingestion-core files now resolve from src, 0 from dist. - entryLifecycle: the transition table is built with a typed helper, so every target state is checked against WrEntryLifecycleStatus. - useLimitStore (memory store): consume returns the settled state through a typed local; applyConsume never leaves a row claimed, so behaviour is unchanged. Workspace typecheck 430 -> 428 (the two TS2322 gone; one pre-existing error in ingestionPipeline.ts now reports its src path). Lifecycle, use-limit, pipeline, acceptance, restart-matrix and pairing suites green.
- productionCompositionRoot.e2e: initWrcClient with no test seam builds every store on the durable security DB (redirected to a temp file) and an unconfigured deployment refuses a valid reference at Gate 2. - connectOfferWrCodeSchema: pin the preview-hash key set (top level, entry, bound definition) and prove wr_code_class does not change the hash. - provenanceGatesParsing.guard: pin the total of seven DepackageCutoverHeldError hold sites. - relayRelease.e2e: source guard that the Gate-5 release chain carries one principal delegation, never a list. Test-only change.
… SSO session (S2b, route) Until now the WR Code RPCs existed only inside handleHandshakeRPC: the renderer RPC dispatcher and the extension WebSocket forwarded vault., handshake., beap. and ingestion. only, so Runs 1-5 were reachable from tests alone. Both dispatchers now route wrc.* and refuse without an active SSO session (getCurrentSession); unlike handshake.*, there is no skipVaultContext escape. Submission and acceptance are therefore structurally account-bound (ruling 3). The claimant party and keys still come from deployment config (Q19 default B). Guard: productionRoute.guard.test.ts pins both routes, the session check, the absent escape, and the five dispatcher targets.
153-set unchanged (plus the documented timing flake), +8 net tests, typecheck extension 183 / workspace 428; fresh clone proven with test:prepare.
…ation (S2) Agent draft under Q17 = A. Records what the client already expects (directory endpoint, per-class entry lookup keys, designation, closed signed objects, DNS and manifest formats), maps the wire shapes to Annex XVI v1.95 Appendix A.4, proposes public/account disclosure tiers (ruling 3, XVI.6.3), and leaves the relay/capsule wire legs open for S7. Lists client work C1-C8 and questions Q20-Q27. Not normative until ratified.
…-on domain by DNS (C1, C2) C1 (XVI.6.5 entry assignment, XVI.16 entry substitution): deriveEntryDesignator refuses a P entry whose repository id differs from the reference's local block (designation_mismatch at Gate 3). Before, a registry could serve any other signed P entry of the same publisher under a local block and all six gates passed. C2 (XVI.6.5 email-domain agreement): WrcDirectoryClient.dnsVerifiedDomains proves each registered domain live against its own _wr record. Gate 2 (acting principal) and Gate 6 (initiator SSO domain) accept only DNS-proven domains; before, only domains[0] was proven and any listed domain was accepted. Tests: entryDesignator, fullChain (P substitution), directoryGate2 and capsuleAdmission (secondary domain with and without its own proof). Negative control: the 5 refusal tests fail without the fix. WRC contract v2.0 section 9.
…rt and captures The Author accepted every recommended default on 2026-09-26. The delta loses its _DRAFT suffix, records the answers, and marks C1/C2 as implemented in fdf4a40. Before/after captures from the C:\\dev\\optirando checkout: 153-set unchanged, 0 regressions.
…ust pinned in source pnpm run build:wrc-test compiles an in-process WR Code test registry behind the transport seam: six deterministic, seeded test publishers (catalogs, envelopes, Merkle proofs, dual-signed directory records, manifests, _wr answers) and 19 test codes covering every class and namespace status, through the real six gates. The signed-in SSO domain is registered live for the own test publisher. Test state lives in wrc-security.wrc-test.db and its own record cache; the app packages into build007-wrc-test beside the release build and shows a non-dismissible test-data banner; wrc.runtimeStatus reports the flavor. Release builds alias the registry to an empty stub, scripts/verify-wrc-build-flavor.cjs fails any build chain whose bundle does not match its flavor, and WRC trust comes only from wrcTrustAnchors.ts (XVI.6.4 pinned; environment ignored; test- key ids refused). Only unbundled dev runs read WRDESK_WRC_* trust variables. Tests: wrcTestRegistry (every code's gate outcome, one-time use, SSO domain, determinism, containment), wrcBuildFlavor.guard (alias, define, build chains, stub parity, pinned trust, output folder, code sheet), wrcTestRegistryRuntime.e2e (per-flavor composition root on a real security DB). Both builds verified. Code sheet: docs/operational/wrc-test-build.md.
…egistry, pinned release trust) Records the reachability decision (built-in registry behind the transport seam, test builds only; no dev address allowance), what f8bf53f changed, and the verification: 153-set unchanged, 0 regressions, both build flavors verified.
A WR Code button in the message toolbar opens a panel: manual entry with a local format check, Find WR Codes in this message, Check through the six gates, then the offer with Accept/Decline or a status refusal. The surface renders main's view model (wrcSubmissionView.ts): offers are the EVP-first projection of offerPresentation.ts, statuses reuse the three-layer copy of entryStatusSurface.ts, every refusal has human copy and a tone, reason codes stay secondary. Main decides the scan: wrc.scanMessage reads the sealed row and scans only when its Channel Provenance Record decodes with channel_pass (HC2, W5); manual entry is always available (HC3). wrc.declineReference releases the XVI.8.4 reservation at once; the panel declines an offer left open when the user checks another code, closes the panel or leaves the message. Tests: wrcSubmissionView (every test code), wrcMessageScan (authenticated, unauthenticated, tampered, missing), runtime decline e2e, WrCodePanel (scan gating, offer render, decline on new check and on leave, none after accept; negative control verified). Route guard: eight wrc.* methods. docs/operational/wrc-test-build.md: where codes are entered.
…2b UI, first increment) Maps the increment to HC2-HC4, HC6, W1, W2, W5; records what is not in it (HC5 connect-offer consent, S5, audit link, S7). Twelve review screenshots of the real panel with real pipeline outcomes. 153-set unchanged, 0 regressions.
…e rendered preview (HC5); directory C3/C4/C5/C8 The desktop handshake:accept answered HANDSHAKE_NOT_FOUND for every staged Connect offer, so no inbound request could be accepted in the app since Phase 4. It now resolves the staged offer, requires expected_preview_hash for it, and forwards the hash to consent. handshake.list carries connect_offer_preview; the accept dialog renders it and returns its hash. WRC directory: the SC responder check uses the signed directory status (C3); the record carries a connector (C4); a grammar other than 2 is refused (C5); display_origin reaches the namespace verdict only after normalization and membership checks (C8).
…C5 desktop accept, directory C3/C4/C5/C8)
…r channel (C6); account-tier credential and 401 (C7); HC5 in the extension and on every product route S5: the WR Code offer shows the checked display_origin as the responsible domain, re-rendered from the verified directory record, never a link. C6: GET /v1/directory/operator-rollovers is decoded and folded from the pinned anchor when a record names an unknown operator key (at most once a minute, one shared fetch); the test registry's TEST03 verifies only through it. C7: the HTTP transport sends a bearer on entry and object reads only; 401 is entry_account_required with its own copy, not the capture error. The production credential source is not wired yet. HC5: the extension renders the connect-offer preview and sends its hash; both product RPC dispatchers require the hash for a staged offer and for consentToOffer. The extension accept dialog no longer reports a refused accept as accepted. S4: stale interim comments in gatePipeline.ts updated.
…5, C6, C7, HC5 extension)
focusedbrain
force-pushed
the
integration/consolidated-current
branch
from
September 26, 2026 18:42
3a57dc6 to
ad03c74
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
WR Code / Public Handshake — Email E2E slice, complete through Phase 5 on the single permanent development branch, now stamped for the final rig build.
phase-2-complete@a310cb96b46680a4phase-3-complete@1c1cb3efd8ac21b156dbf7c2phase-4-complete@0a7ca3ae6c758b80phase-5-complete@f12c6262build04721389e8eRig build state
HOST_HASH=21389e8ebe3936a573b292ad53c76a7ccd095f1b(short21389e8), origin tip matches, tree clean,phase-5-completeis an ancestor. Expected[RUNTIME_IDENTITY]:commit == 21389e8e…,buildStamp == build047 (21389e8).The stamp bump moves three literals together because three consumers read them: the extension
outDir,VITE_EXT_BUILD_STAMP, and the Windows output-dir marker parsed bykill-wr-desk.cjs. The Electron stamp derives from the extensionoutDirby regex and appends the short HEAD at build time.Slice content
Phases 2–5 delivered the provenance gate and fail-open closure, the unsuppressible rule-8 alert, CPR as a typed analysis input, the resolution infrastructure (hardened client, dual-channel validation, head/envelope/EVP verification, contract v1.1 embedded delegation), the A6 three-field status composition with resolution-bearing offers, and the email→offer path with EVP-first-render and manual entry.
E2E acceptance (a)–(d) met at logic level. UI rendering is unverified by design (no build, no app start in the agent session) — Phase-5 report §6 states exactly what that leaves for the rig. The
integration-pendinglist is carried complete: nothing waived, no substitute trust path.Details:
code/docs/analysis/wr-code-email-e2e/(reports + committedcaptures/) andcode/docs/spec/.Notes
mainremains for author-designated document drops only.