You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
CURRENT CONTROL-PLANE CHECKPOINT — 2026-10-06 — FINAL RETENTION TERMINAL / R4 ADMISSION NEXT
CURRENT_MAIN = bf745090f7e980e167b1bbf01c7f6dea51fb451f
RESULTING_MAIN_CI_CD = 37434052556 / SUCCESS
RESULTING_MAIN_CODEQL = 37434052501 / SUCCESS
VERCEL_PRODUCTION = dpl_75HQcQhuYP6CxX43EjMov8Sjosdb / READY / exact CURRENT_MAIN / canonical HTTP 200
ROLLBACK = dpl_7XTy9jGDikUauvgT8oPQUtq7YAmq / READY
OPEN_PULL_REQUESTS = 0
DEPENDENCY_TRAIN = TERMINAL
FINAL_RETENTION = TERMINAL
RETENTION_RESULT = 11 stale deployments deleted; 79 orphaned aliases removed; 4 deployments remain; 3 protected Production/Main aliases remain; UNKNOWN = 0
B2A = TERMINAL
B2 = NOT TERMINAL
B2_IMPLEMENTATION_ALLOWED = NO until fresh read-only R4 admission returns READY
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO
ACTIVE_GATE = Gate 4D / #359 / QNB-11
NEXT = fresh read-only R4 admission from exact current main; implement only if explicitly re-admitted
GATE_4 = OPEN
GATE_4E_5_6_7 = GATED
The dependency train and its consolidated Vercel cleanup are terminal. R-15 is again the sole release-critical engineering program. No deferred RustCrypto/Tauri modernization, post-release UX work, or production authority switch is admitted by this checkpoint.
CURRENT_MAIN = 2001e63f3b7b1fbf2faa0270238f0de43ba84db1
PR_953 = MERGED / Successor A read-snapshot slice landed
PR_954 = OPEN / DRAFT / MERGEABLE
PR_954_HEAD = 93384b5a71f8bed4f2cde1428b762d2db0b13790
PR_954_BASE = 2001e63f3b7b1fbf2faa0270238f0de43ba84db1
PR_954_SCOPE = Successor B — Mutation / Root-Recovery / Lifecycle Closure
PR_954_SIZE = 16 files / 2 commits / +2121 -100
CODEANT = Quality / Coverage / SCR / SAST / SCA SUCCESS exact head
CODERABBIT = status SUCCESS, but Draft PR auto-review is disabled; do not call review clean
DEEPSOURCE = Python / Shell / Docker SUCCESS; review grade A; Rust status not inferred
VERCEL_PREVIEW = dpl_2JuoEypL2STM2hXvq9ESVa1Gmz9N BUILDING exact head
CI_CD = IN PROGRESS / not yet terminally proven here
CODEQL = not yet terminally proven here
REVIEWS = no submitted reviewer epoch yet
UNRESOLVED_REVIEW_THREADS = 0 at this checkpoint
PR_952 = OPEN / DRAFT / FROZEN PROVENANCE — DO NOT MERGE
GATE_4B = ACTIVE
4C / 4D / 4E = PENDING
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO
Successor B is correctly based on the #953 resulting main and carries the semantic A+B union: #953 SessionBinding/rebind semantics plus the mutation/root-recovery/lifecycle mechanisms extracted from frozen #952. The prepared-root Step-F same-instance recovery R1–R5 proof remains this PR's material closure scope.
Do not close Gate 4B, #922, #445, or advance #359/4D until #954 converges on its exact final head, merges normally, and the exact resulting-main CI/CD + CodeQL + Vercel Production gate is terminal.
HISTORICAL / SUPERSEDED — Successor A exact-head checkpoint — PR #953 — 2026-10-03
PR = #953
HEAD = e9bd7556ab0f8111f843b78038fa56078792a097
BASE = 3cd2b6a37ab8b5bbe8abe32830cd8170b0c9d052
FILES = 15
COMMITS = 3 signed
MEANINGFUL_LINES = 1870
PR_952 = OPEN / DRAFT / frozen provenance
CODEQL = SUCCESS
CHANGELOG/TEXT GUARDS = SUCCESS
CODEANT = all gates SUCCESS
CI_CD = IN_PROGRESS; all Rust/Node/platform/signature/security/build jobs green, E2E/VRT downstream still running
VERCEL = SUCCESS exact head
CODEX_EXACT_HEAD = one new P2 race remains open
MERGE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO
The Terra/Codex closure commit e9bd7556... is now on the remote despite the executor's final report having observed a delayed remote ref. The earlier transport blocker is therefore RESOLVED / transient.
The three P2s from 12cf7833... are implemented and their threads are now resolved:
admitted snapshot-backed catalog enumeration with raw production list/load paths gated away.
Fresh exact-head Codex review on e9bd7556... found one additional VALID same-slice blocker: a mid-capture TOCTOU can occur when provider.state() observes the old runtime as Unlocked, another process commits root N+1, then the subsequent anchor read sees N+1. Current code publishes N+1 into AuthorityCell.current before proving the provider is bound to N+1; resolve_ref then returns Locked, and future retry cannot take the strict-forward rebind path because N+1 has already poisoned current.
Required invariant for closure: never publish a newer snapshot into current before provider/key usability for that exact anchor is established. Prefer rebinding/validation before publication, or otherwise restore/retain the previous snapshot on resolution failure. Preserve explicit-lock, route-change/rotation, rollback, same-generation mismatch and incompatible-authority refusals.
This is still Read/Snapshot scope, but anti-cascade remains binding. One surgical race fix with a deterministic mid-capture regression is admissible; if it needs broad provider redesign or another architectural expansion, stop/split rather than cascade.
The new CodeScene Large Method warning on the 134-line cross-process integration test is non-material and resolved by evidence; no suppression or proof weakening.
Resource horizon remains unchanged: after #953 protected merge + exact resulting-main CI/CD/CodeQL/Vercel Production + cleanup/retention, executor reports and STOPs. No successor B or 4C.
CURRENT EXECUTION MODE — 2026-10-03 — RESOURCE-BOUNDED GATE 4B SPLIT
Anti-cascade/resource decision: PR #952 is no longer a correction target. It is the immutable reviewed extraction source. The current coding-agent run is deliberately bounded to the first successor PR only and must stop after its normal protected merge, exact resulting-main CI/CD + CodeQL + Vercel Production verification, worktree/branch cleanup, and safe Vercel retention. It must not start successor B or 4C in the same execution epoch.
Control-plane ownership is also split deliberately: GitHub issue, Linear, milestone, release-program and checkpoint curation is performed from the ChatGPT control-plane session; the coding agent should only read those records when needed and should not spend token/week quota duplicating status maintenance.
The prepared-root Step-F coordinator-recovery Critical is Gate 4B successor-B scope, not Gate 4D. Gate 4D remains crash-resumable rotation/rekey after 4B and 4C. #360/QNB-12 remains open until complete Gate 4B closure.
CURRENT_MAIN = 3cd2b6a37ab8b5bbe8abe32830cd8170b0c9d052
4A = TERMINAL via 950
4B_FOUNDATION = TERMINAL via 951
4B_INTEGRATION = ACTIVE / PR 952
PR_952_HEAD = e34aae28bba31269a814a9a2778346e568c3577e
PR_BUDGET = 16 files / 3000 meaningful lines / 5 signed commits
CODEQL = 37132489430 SUCCESS
CI_CD = 37132489420 SUCCESS — all required exact-head jobs terminal green
VERCEL_PREVIEW = dpl_FBpTZftnpnum9ZahLkPCeMfAWUtz READY exact head
CODEX = exact e34aae28 review reports no major issue
CODERABBIT = current incremental review 401b81b8 to e34aae28 complete / no actionable finding
CODEANT_QUALITY_SCR = FAILURE — valid material recovery finding is not dismissed
CODEANT = fresh full review completed; validated prepared-root recovery gap remains OPEN
MERGE_READY = NO
GH_360 = OPEN / QNB-12 In Progress
GATE_4 = ACTIVE / QNB-168 In Progress / M3 Active
4C = PENDING
4D = PENDING via 359 / QNB-11
4E = PENDING
RELEASE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO
The minimal stale-CAS correction is signed/pushed and locally verified: success and reconciled stale CAS clear the local mutation latch only after physical/writer/admission revalidation; all uncertain errors remain fail-closed. Normal Git transport works; no sandbox/protection/signing bypass occurred.
New material finding: after an injected step-F COMMIT failure, the public coordinator reconciliation returns PreparationPending even when the provider fault is removed. Existing authenticated recover_root is not integrated into the provider-owning coordinator operation API. Lock/shutdown correctly refuse, but same-instance recovery is incomplete. Diagnostic proof is retained locally; temporary probes were removed from source. Do not merge or close 360/QNB-12 until this is fixed with fault proof and fresh exact-head convergence.
No-op RootBusy is separately proved retryable after contention release; its conservative latch is not the prepared-root recovery defect. Remaining DeepSource Rust / CodeScene reds are understood test-only advisory findings, not green. No 4C journal, 4D rekey, collector, deletion, current-app authority change or Gate-7 switch was introduced. At saturated budget, establish a bounded mutation/root-recovery/lifecycle proof slice rather than expand or delete meaningful safety evidence.
HISTORICAL / SUPERSEDED — prior Gate-4B foundation checkpoint
CURRENT R-15 CHECKPOINT — 2026-10-03 — GATE 4B FOUNDATION TERMINAL VIA #951
CURRENT_MAIN = 3cd2b6a37ab8b5bbe8abe32830cd8170b0c9d052
RESULTING_MAIN_VERIFICATION = TERMINAL
4A = TERMINAL via #950
4B_FOUNDATION = TERMINAL via #951
PR_951_FINAL_HEAD = d3c87fe675300b2d29e797625b192516a94fd191
PR_951_MERGED_AT = 2026-10-03T04:51:40Z
RESULTING_MAIN_CI_CD = 37097936085 SUCCESS
RESULTING_MAIN_CODEQL = 37097936105 SUCCESS
VERCEL_PRODUCTION = dpl_9W7p2XZ4dscci5d2sXasPHK7iibz READY / PROMOTED exact CURRENT_MAIN / HTTP 200
HOUSEKEEPING = COMPLETE — clean local main; merged branch/tracking ref removed; other worktrees preserved
RETENTION = COMPLETE — 3 stale predecessor previews deleted; all 15 protected IDs and alias bindings verified
4B_OVERALL = ACTIVE / #360 / QNB-12
4B_INTEGRATION = NEXT — protected operation / authority-key / snapshot / lifecycle integration
GH_360 = OPEN until complete 4B acceptance
4C = PENDING / authenticated journal + paged manifest
4D = PENDING / #359 / QNB-11 / rekey + key-epoch crash window
4E = PENDING / first enable + disable refusal + Gate 4 closure
GATE_4 = ACTIVE
RELEASE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO
All resulting-main CI/CD jobs succeeded, including Security Audit, Verified Signatures, Node 22/24, Core/Tauri Rust, Linux/macOS/Windows platform evidence, Build, Playwright, Deep Coverage, Storybook, Browser Quality, CI Success and Pages. Final-head CodeRabbit/CodeAnt/Codex review converged with no actionable finding and no unresolved thread. The two DeepSource test false positives remain evidence-dispositioned advisory red, not green; unavailable reviewer quotas remain recorded.
This terminal checkpoint is for the kernel admission foundation only. It does not complete issue 360, Gate 4B overall, Gate 4 or production Core authority. The next bounded engineering owner remains 4B integration, not 4C.
HISTORICAL / SUPERSEDED — #951 merged, post-merge proof was pending
CURRENT_MAIN = 3cd2b6a37ab8b5bbe8abe32830cd8170b0c9d052
LAST_VERIFIED_MAIN = 4f33d7786076c1d00e73d5db9c527fbd1ea31693
4A = TERMINAL via #950
4B = ACTIVE / #360 / QNB-12
4B_FOUNDATION_PR = #951 MERGED at 2026-10-03T04:51:40Z
PR_951_FINAL_HEAD = d3c87fe675300b2d29e797625b192516a94fd191
4B_FOUNDATION_TERMINAL = NO — resulting-main + Production + housekeeping pending
RESULTING_MAIN_CI_CD = 37097936085 IN_PROGRESS
RESULTING_MAIN_CODEQL = 37097936105 IN_PROGRESS
VERCEL_PRODUCTION_EXACT_CURRENT_MAIN = PENDING VERIFICATION
GH_360 = OPEN until complete 4B integration acceptance
NEXT_ENGINEERING = 4B protected-operation integration, only after foundation terminal proof
4C = PENDING / journal + paged manifest
4D = PENDING / #359 / QNB-11 / rekey + key-epoch crash window
4E = PENDING / first enable + disable refusal + Gate 4 closure
GATE_4 = ACTIVE
RELEASE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO
Final-head CI/CD and CodeQL succeeded; CodeRabbit, CodeAnt and Codex reviewed the final delta/head without remaining actionable findings. All review threads are resolved. The two DeepSource test findings remain evidence-dispositioned advisory false positives, not a green status; quotas are recorded as unavailable. The normal protected squash merge did not close #360 or switch production Core authority. No next semantic slice or retention deletion starts before the exact resulting-main gate.
CURRENT_MAIN = 4f33d7786076c1d00e73d5db9c527fbd1ea31693
GATE_3 = TERMINAL via #949
GATE_4 = ACTIVE via #922
4A = TERMINAL via #950
PR_950_FINAL_HEAD = f2dde0e65bb4dacfd6753f16a6bce1e28bf13078
RESULTING_MAIN_CI_CD = 36994420903 SUCCESS
RESULTING_MAIN_CODEQL = 36994420828 SUCCESS
VERCEL_PRODUCTION = dpl_7Z1r45ckAp4YeYpdHWtHdzQ8BWNN READY exact CURRENT_MAIN
4B = ACTIVE / #360 / QNB-12 / PR #951 kernel admission foundation; protected-operation integration follows
PR_951_HEAD = d3c87fe675300b2d29e797625b192516a94fd191
PR_951_STATUS = OPEN / exact-head CI and review pending / not terminal
GH_360 = OPEN until full 4B acceptance
4C = PENDING / journal + paged manifest
4D = PENDING / #359 / QNB-11 / rekey + key-epoch crash window
4E = PENDING / first enable + disable refusal + Gate 4 closure
NEXT = 4B → 4C → 4D → 4E → Gate 5 → Gate 6 → explicit Gate 7 authorization
PRE_GATE_7_RESIDUAL = #948
RELEASE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO
Live reconciliation confirms Gate 4A terminal, including exact resulting-main CI/CD, CodeQL and Production evidence. Gate 4B is the current renderer-neutral admission/fencing owner. Historical legacy filesystem defects remain provenance; this checkpoint does not claim a production authority switch or Gate 4 closure.
HISTORICAL / SUPERSEDED — CURRENT AUTHORITATIVE PROGRAM — complete desktop at-rest encryption → v1.30.0 — 2026-10-02 10:21 CEST — superseded by verified Gate 4A terminal checkpoint
Gate 3 is terminal and production-proven at the headless/Core evidence level. Gate 4 is now the sole active R-15 engineering gate. PR #950 is not merge-ready yet: its exact-head review/CI epoch is still running. Asset-pair commit semantics are owned by Gate 5; packaged physical power-loss qualification remains Gate 6; #948 must be terminal before Gate 7 for classes whose current authority deletes records.
HISTORICAL / SUPERSEDED — CURRENT AUTHORITATIVE PROGRAM — complete desktop at-rest encryption → v1.30.0 — 2026-10-01 23:12 CEST — superseded 2026-10-02 10:21 CEST
PRIMARY_MILESTONE = COMPLETE_DESKTOP_AT_REST_ENCRYPTION
TARGET_RELEASE = v1.30.0
RELEASE_OWNER = #926
PRE_RELEASE_DOC_TRUTH_GATE = #932
POST_RELEASE_RESET = #927
CURRENT_MAIN = 03a24786f1c9fda76656dbbd2a635e324331ec81 (#941 resulting main)
RESULTING_MAIN_VERIFICATION = TERMINAL
CURRENT_MAIN_CI / CODEQL / SECURITY / SIGNATURES = SUCCESS
VERCEL_PRODUCTION = READY on exact CURRENT_MAIN (dpl_4PYKR16tDmSWQnEvqFXLVesrpe3p)
GATE_1A / GATE_1B = TERMINAL
GATE_2 = TERMINAL
GATE_3 = #921 — ACTIVE
GATE_3_3A = TERMINAL via #930
GATE_3_3B_PART_1 = TERMINAL via #937
GATE_3_3B_PART_2 = TERMINAL via #940
GATE_3_3C_PART_1 = TERMINAL via #941 → main 03a24786f1c9fda76656dbbd2a635e324331ec81
GATE_3_3C_PART_2 = ACTIVE via PR #942 @ 48525c99ed20c88774df161b8d8c0d474a785302
PR_942_MERGE_READY = NO
GATE_3_3C_PART_3 = NEXT after #942 terminal
THEN = Gate 3 closure + #357/QNB-10 reconciliation
GATE_4 = #922
GATE_5 = #923
GATE_6 = #924
GATE_7 = #925
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO
AUTONOMOUS_CONTINUATION = YES
Current Gate 3 execution
PR #941 is terminal. Its resulting main 03a24786... passed CI Success, Node 22/24, Core/Tauri Rust, Linux/macOS/Windows secure-store evidence, Build, Playwright, Deep Coverage, Storybook, Browser Quality, Security Audit, Verified Signatures, CodeQL, Pages and deployment-retention; Vercel Production is READY on the exact SHA.
3C part 2 is active via #942. Current exact-head evidence on 48525c99...: CodeQL, Security Audit, Verified Signatures, Core/Tauri Rust, all three secure-store platform jobs, PR-size admission, workflow policy, changelog and reviewer-governance trust checks are green; Node 22/24 and Cubic are still running at the latest readback. Vercel Preview is READY on the exact head. Current review remainder on exact head 48525c99... is material and must be validated before any correction wave: Codex returned four P2s — (1) catalog pages must preserve enough authenticated/reversible identity material to enumerate records whose logical/project IDs use hashed bindings, (2) decoded descriptors must reject non-ordinary/control/retained classes, (3) catalog_set_digest must enforce the fixed 0..255 shard universe, and (4) catalog Debug output must redact direct identity/scope bytes. CodeRabbit independently reports the non-ordinary-class admission as a Major. CodeAnt reports the same class-admission gap plus a Major on decoded binding/template/project-scope validation, and a shard-bound API nitpick. CodeScene reports argument-count/code-health findings; DeepSource has one minor range-style finding. Node 22/24 and Cubic are still running; Sourcery is quota-limited. Do not merge until findings are validated/dispositioned, any material corrections are bundled coherently, and the resulting exact-head epoch converges.
HISTORICAL / SUPERSEDED — CURRENT AUTHORITATIVE PROGRAM — complete desktop at-rest encryption → v1.30.0 — 2026-10-01 — superseded 2026-10-01 23:12 CEST
PRIMARY_MILESTONE = COMPLETE_DESKTOP_AT_REST_ENCRYPTION
TARGET_RELEASE = v1.30.0
RELEASE_OWNER = #926
PRE_RELEASE_DOC_TRUTH_GATE = #932
POST_RELEASE_RESET = #927
CURRENT_MAIN = e43559b9bd6c5a8b6f5ba06ed9a2da42079551e1 (#940 resulting main)
RESULTING_MAIN_VERIFICATION = TERMINAL
CURRENT_MAIN_CI = SUCCESS
CURRENT_MAIN_CODEQL = SUCCESS
CURRENT_MAIN_SECURITY_AUDIT / VERIFIED_SIGNATURES = SUCCESS
VERCEL_PRODUCTION = READY on exact CURRENT_MAIN
GATE_1A / GATE_1B = TERMINAL
GATE_2 = TERMINAL
GATE_3 = #921 — ACTIVE
GATE_3_3A = TERMINAL via #930
GATE_3_3B_PART_1 = TERMINAL via #937 → main 90ae5c4c44596b423a502dc4ce2d2213886092ca
GATE_3_3B_PART_2 = TERMINAL via #940 → main e43559b9bd6c5a8b6f5ba06ed9a2da42079551e1
GATE_3_3C_PART_1 = ACTIVE via PR #941, head 7a1edcf1527947e7b75cc8e8c6fbe6e1ea11a701
PR_941_MERGE_READY = NO — exact-head convergence still active
GATE_3_3C_PART_2 = NEXT — catalog descriptors/pages + shard assignment
GATE_3_3C_PART_3 = THEN — two-phase root/anchor commit + write integration + list_records + retention + Gate 3 closure/#357 reconciliation
GATE_4 = #922
GATE_5 = #923
GATE_6 = #924
GATE_7 = #925
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO
AUTONOMOUS_CONTINUATION = YES
Current Gate 3 execution
Gate 3B is now terminal. PR #940's resulting main e43559b9... is fully proven: CI Success, Node 22/24, Core/Tauri Rust, Linux/macOS/Windows secure-store evidence, Build, Playwright, Deep Coverage, Storybook, Browser Quality, Security Audit, Verified Signatures, CodeQL and Pages are green; Vercel Production is READY on the exact SHA.
Gate 3C is split at proof boundaries:
3C part 1 — feat(core): add the Gate 3 slice 3C authority-root digests (#445) #941: pure authority-root/set/pointer digests. Current head 7a1edcf1... is open and mergeable; CodeQL, Security Audit, platform/Rust checks, CodeScene, Semgrep and reviewer-governance checks are green, while Node 22/24 are still running at the latest readback. Current review remainder includes a material Codex P2 on asset-pair admission to marker_set_digest plus a Cubic P3 documentation mismatch for the bootstrap journal_revision = 0 sentinel. Resolve/disposition the full current-head epoch before another push/merge.
3C part 2: catalog descriptors/pages + shard assignment.
The deterministic gate-status hardening follow-up is merged as #936 to resulting main cd12c104...; #935 is closed. Exact-head review had converged before merge. Post-merge proof is now the only remaining support activity: CodeQL, Security Audit and Verified Signatures are already green; Vercel Production is READY on the exact SHA; Node 22/24 are still running at the latest readback.
This support lane is not a new product gate. Do not reopen it absent new material evidence.
Until v1.30.0 is VERIFIED, the primary engineering lane is the complete R-15 desktop at-rest encryption program. Unrelated roadmap expansion must not preempt it unless a fresh P0/P1 security, data-loss or release blocker requires admission.
Gate 2 completed as #917 → #928 (Slice A) → #929 (closure, which replaced the planned Slices B/C); Slice B's locator adapters were re-assigned to Gate 5 (#923). Evidence: #920 closing comment.
Program priority
Until v1.30.0 is VERIFIED, the primary engineering lane is the complete R-15 desktop at-rest encryption program. Unrelated roadmap expansion must not preempt it unless a fresh P0/P1 security, data-loss or release blocker requires admission.
R-15 is not complete because crypto primitives or OS key stores exist. It is complete only when every packaged-desktop PROTECTED class is either authoritative through the renderer-neutral Rust Core encrypted path or explicitly retained under an approved separate protected authority; migration/rekey is crash-resumable and race-free; durable writes survive the required failure matrix; packaged Linux/macOS/Windows evidence is recorded; and Gate 7 is explicitly authorized and executed without plaintext fallback.
Then and only then may #926 cut v1.30.0 and product/security documentation claim the new desktop at-rest authority.
Autonomous continuation rule
semantic admission required, fresh admission, not yet admitted, or re-read before coding means the executing agent performs the bounded proof itself, records it, and continues. It is not a chat handoff. After each merge: resulting-main CI/CD + CodeQL + exact-SHA Production/HTTP proof → evidence sync + housekeeping → re-read main/contracts → next highest-priority unblocked bounded owner → self-perform admission → continue.
Only stop for a genuinely unresolved maintainer-only decision: Gate 7 Production Authority Switch authorization; branch-protection/ruleset/admin/bypass mutation; tag movement/reuse; explicitly approval-gated destructive provider action; or materially incompatible security/authority designs not resolved by current contract/decision.
HISTORICAL — release-recovery hold — 2026-09-29 (superseded 2026-09-30 by the block above)
R-15 remains open and urgent, but implementation is frozen until #872 reaches v1.29.1 VERIFIED.
#851 / #852 / #853 = PARKED / FROZEN
GATE_1B_PLATFORM = NOT RESUMED
GATES_2_7 = NOT ADMITTED
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO
RESUME_AFTER = #872 v1.29.1 VERIFIED
After the release, re-read current main and governance state before re-anchoring any parked branch. Do not merge stale R-15 branches opportunistically during release recovery.
Dependabot #883–#887 are not required predecessors for v1.29 on current evidence.
Live source confirms src-tauri links worldscript-project; worldscript-secure-storage remains a separate workspace member and is not linked into the shipped Tauri desktop runtime.
getrandom 0.4 uses Edition 2024 and declares MSRV Rust 1.85;
WorldScript currently declares/proves Rust 1.77.2 for the relevant native/Core line.
Therefore #883 cannot be treated as a routine release dependency bump without an explicit MSRV-policy change. #884–#887 likewise remain major cryptographic dependency changes requiring bounded API/MSRV/security review.
Absent a concrete current advisory requiring immediate adoption, disposition #883–#887 as DEFERRED_WITH_RELEASE_SAFE_EVIDENCE and resume them after v1.29 under #445/#572.
This does not admit any further Gate 1b-platform implementation before release. #851 remains parked; #852/#853 remain frozen provenance/source material; PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.
v1.29.0 release freeze — 2026-09-29
R-15 remains open and important, but no further R-15 implementation slice is admitted before the current v1.29.0 release convergence unless new release-blocking evidence explicitly changes that decision.
do not merge any of them merely because they are open;
Gates 2–7 remain not admitted;
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO;
dependency PRs touching RustCrypto/security primitives must be qualified against this owner, but must not be used as a back door to resume broad R-15 architecture.
After the release, re-anchor this issue on then-current main and reconstruct the smallest correct next Gate 1b-platform slice from live source/evidence.
Current execution gate — 2026-09-27 (post-merge guardrail remediation pending)
Gate 2 remainder (per-class §5.2.1 project_id scope enforcement) remains not admitted ahead of Gate 1 completion.
Gates 2–7: not admitted. PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.
Detailed exact-SHA post-merge evidence for Slice A and the later Slice B recovery is recorded in checkpoint comments below. This section updates only the current execution-gate state; the binding R-15 contract remains authoritative for semantics.
Purpose
Implement R-15 as the renderer-neutral encrypted-storage authority for native desktop. This is a Core/security migration requirement, not a Tauri-specific enhancement and not work that should be discarded when Qt replaces Tauri.
The current product truth remains explicit: authoritative Tauri filesystem project data is not yet protected at rest by this future Core design. No UI, release note, or documentation may imply otherwise until the protected path is authoritative and packaged evidence exists.
Renderers consume typed operations; they do not own keys, migration state, record identity, or durable-write policy.
QML/React must not become a second crypto/storage authority.
Direct renderer-specific implementations do not satisfy R-15.
Existing Tauri behavior must remain truthful and fail safe during the transition.
Required protected-data inventory
Before implementation, enumerate every native desktop record class and classify it as PROTECTED, NON-SENSITIVE, DERIVED/REGENERABLE, or OUT-OF-SCOPE with rationale. At minimum inspect:
project/manuscript data;
snapshots/backups/recovery data;
settings that contain sensitive values;
provider/API credentials;
images/assets and metadata;
Codex/RAG/vector/index payloads;
task/recovery/migration metadata;
temporary/staging files created by save, import/export, migration, or recovery.
The inventory is part of the security contract: no protected class may silently fall back to plaintext because a renderer or migration path was overlooked.
Required envelope/key properties
The admitted design must define and test:
authenticated encryption;
versioned envelope/algorithm metadata;
key identity/epoch and rotation semantics;
renderer-neutral key lifecycle;
explicit locked/unlocked/readability states;
logical-record identity binding (AAD or equivalent);
A successful protected write must have a documented crash-durability contract, not merely atomic rename semantics. Define platform-appropriate behavior for:
create/write temporary file;
flush/sync file contents as required;
atomic replacement/rename;
persist directory metadata where the platform/filesystem contract requires it;
report failures without claiming durability that has not been reached;
recover safely from orphan temporary/staging files.
The implementation belongs in renderer-neutral/native Core infrastructure wherever practical; do not create a new Tauri-only durable-write authority simply because #357 was originally reported against the Tauri path.
Protected ciphertext must be cryptographically or structurally bound to the logical record it represents so valid ciphertext cannot be substituted between records undetected.
Define stable identities for each protected class, e.g. project/snapshot/image/index/settings credential records. The binding scheme must survive legitimate moves/migrations where intended and must be included in rekey/migration logic.
Plaintext → protected migration
Existing desktop users require an explicit recoverable migration path.
The migration plan must specify:
discovery/inventory of legacy plaintext;
admission and locking behavior;
resumability;
staging and durable commit;
rollback/recovery behavior;
treatment of backups/snapshots/temp files;
version compatibility/downgrade behavior;
what happens when a record is corrupt or unreadable;
when plaintext originals are removed and what durability evidence permits that removal.
Do not delete the only recoverable copy before the protected replacement is durably committed.
Threat / failure matrix
Tests and design evidence must cover at least:
Scenario
Required outcome
wrong key/passphrase
fail closed; no destructive rewrite
modified ciphertext/tag
detected
cross-record substitution
detected
interrupted ordinary write
old or new valid state; no torn authoritative record
crash during enable/migration
resumable/recoverable
crash during rotation
resumable/recoverable; no silent mixed-key loss
concurrent autosave during migration
admitted/blocked coherently
locked session + legacy plaintext
fail according to secure-storage policy, never bypass it silently
disk full / permission failure
actionable failure; old durable state preserved where possible
stale temp/journal
deterministic recovery
rollback/downgrade
explicit supported/blocked behavior
key loss / reset
explicit non-deceptive recovery semantics
large project / long migration
bounded memory and observable progress/cancellation policy
Headless and packaged evidence
Core behavior must be testable headlessly without Tauri/Qt. Packaged desktop evidence is additionally required for OS/filesystem/key-store integration and destructive lifecycle cases that unit tests cannot establish.
Evidence maturity must be explicit (LOCAL_ONLY, CI_ONLY, PACKAGED_LOCAL, PACKAGED_TARGET_ENV, FIELD_OBSERVED).
Qt migration relationship
R-15 is pre-Qt / parallel-to-Qt foundation work, not sunk cost. Qt should consume the same Core storage authority rather than reimplementing it.
Qt Beta admission is blocked until the required R-15 desktop security/data-integrity contract is implemented and evidenced.
Tauri may remain transitional while Core work lands, provided UI/docs remain truthful about what is and is not encrypted.
Tauri retirement must not strand plaintext or renderer-private encrypted data.
Those issues remain useful provenance and detailed threat evidence. R-15/#445 is the canonical integration/closure issue. When implementation lands, reconcile each child requirement explicitly; do not close them merely because #445 has code.
Related migration acceptance: #332 and the Qt/Tauri roadmap documentation.
Acceptance criteria
Protected-data inventory is complete and reviewed.
Rust/Core contracts are renderer-neutral and parity/headless tested.
Authenticated versioned envelope and key-epoch model are implemented.
Keep this issue as the single canonical native R-15 secure-storage integration/closure issue. The latest Revision-3 roadmap in PR #477 reinforces rather than changes that ownership.
No parallel renderer crypto/storage authority
Do not create:
Qt-private project encryption;
a new Tauri-only encrypted project store;
renderer-owned migration journals;
renderer-owned key epochs/record identity;
a second durable-write implementation created solely for one renderer.
Tauri and Qt should consume the same renderer-neutral Core authority through typed contracts/adapters.
Child requirement treatment
#357/#359/#360/#361 remain detailed requirements, threat evidence, and closure provenance. Their code may consolidate under R-15, but their acceptance criteria and negative tests should be individually reconciled before those issues close.
Reuse-first implementation gate
Before adding a new crate/service specifically for storage/crypto, record the existing authority/seed audit. Roadmap capability names are responsibilities, not automatic crate names. Split only where security boundary, dependency isolation, testability, reuse, or durability evidence materially improves.
PWA relationship
Do not force PWA WebCrypto/IDB/OPFS implementation details into native Core for symmetry. Share product/security semantics where appropriate (authenticated envelopes, identity binding, migration truth, fail-closed behavior), while browser-specific storage mechanisms remain PWA implementation concerns.
Qt gate
Qt Beta remains blocked on the required R-15 native security/data-integrity contract and packaged evidence, but early disposable Qt qualification may proceed according to Rev-3 without inventing private temporary storage authority.
PR #516 (fix(fs): fail closed on corrupt/unreadable desktop project data (DA-01)) materially improves the current Tauri filesystem path while not completing R-15. This distinction should remain explicit.
into absence-like results such as null/empty state. In particular, failed LZ decompression could become '{}', after which startup could treat damaged-but-existing authority as effectively absent and later overwrite it through normal autosave.
genuine file absence still maps to the legitimate null/not-found outcome;
corrupt/truncated compressed data throws instead of becoming {};
malformed JSON and non-project-shaped payloads fail closed;
filesystem read/exists failures are classified as I/O failure rather than absence;
cold boot propagates the failure into the existing storage-error surface instead of silently starting as though no saved project existed;
backup enumeration can continue around an individually unreadable project without reclassifying that project as valid empty data.
This is an important pre-R-15 data-integrity hardening because it removes a silent-destructive failure mode from today's shipping renderer-specific path.
authoritative desktop project storage is still on the transitional Tauri/filesystem path;
Rust Core does not yet own the final encrypted storage semantics;
there is still no R-15 authenticated envelope/key-epoch/identity-binding implementation delivered by this slice;
plaintext-to-protected migration, crash-resumable rekey, durable directory sync, migration admission, and renderer-neutral protected-data inventory remain open under this issue;
Issue #515 records a separate current-path gap exposed by the new fail-closed behavior: StorageErrorScreen's Reset Database & Reload action resets IndexedDB/localStorage, but a corrupted Tauri project file remains under the desktop filesystem path. Therefore the app can now fail honestly but leave the user in a recovery loop.
That is intentionally separate from #516's core safety invariant:
CURRENT CONTROL-PLANE CHECKPOINT — 2026-10-06 — FINAL RETENTION TERMINAL / R4 ADMISSION NEXT
The dependency train and its consolidated Vercel cleanup are terminal. R-15 is again the sole release-critical engineering program. No deferred RustCrypto/Tauri modernization, post-release UX work, or production authority switch is admitted by this checkpoint.
HISTORICAL / SUPERSEDED CONTROL-PLANE CHECKPOINT — 2026-10-04 — R-15 / #957 RETENTION UNBLOCKED
HISTORICAL / SUPERSEDED — previous control-plane checkpoint
Successor B is correctly based on the #953 resulting main and carries the semantic A+B union: #953 SessionBinding/rebind semantics plus the mutation/root-recovery/lifecycle mechanisms extracted from frozen #952. The prepared-root Step-F same-instance recovery R1–R5 proof remains this PR's material closure scope.
Do not close Gate 4B, #922, #445, or advance #359/4D until #954 converges on its exact final head, merges normally, and the exact resulting-main CI/CD + CodeQL + Vercel Production gate is terminal.
HISTORICAL / SUPERSEDED — Successor A exact-head checkpoint — PR #953 — 2026-10-03
The Terra/Codex closure commit
e9bd7556...is now on the remote despite the executor's final report having observed a delayed remote ref. The earlier transport blocker is therefore RESOLVED / transient.The three P2s from
12cf7833...are implemented and their threads are now resolved:Fresh exact-head Codex review on
e9bd7556...found one additional VALID same-slice blocker: a mid-capture TOCTOU can occur whenprovider.state()observes the old runtime as Unlocked, another process commits root N+1, then the subsequent anchor read sees N+1. Current code publishes N+1 intoAuthorityCell.currentbefore proving the provider is bound to N+1;resolve_refthen returns Locked, and future retry cannot take the strict-forward rebind path because N+1 has already poisonedcurrent.Required invariant for closure: never publish a newer snapshot into
currentbefore provider/key usability for that exact anchor is established. Prefer rebinding/validation before publication, or otherwise restore/retain the previous snapshot on resolution failure. Preserve explicit-lock, route-change/rotation, rollback, same-generation mismatch and incompatible-authority refusals.This is still Read/Snapshot scope, but anti-cascade remains binding. One surgical race fix with a deterministic mid-capture regression is admissible; if it needs broad provider redesign or another architectural expansion, stop/split rather than cascade.
The new CodeScene Large Method warning on the 134-line cross-process integration test is non-material and resolved by evidence; no suppression or proof weakening.
Resource horizon remains unchanged: after #953 protected merge + exact resulting-main CI/CD/CodeQL/Vercel Production + cleanup/retention, executor reports and STOPs. No successor B or 4C.
CURRENT EXECUTION MODE — 2026-10-03 — RESOURCE-BOUNDED GATE 4B SPLIT
Anti-cascade/resource decision: PR #952 is no longer a correction target. It is the immutable reviewed extraction source. The current coding-agent run is deliberately bounded to the first successor PR only and must stop after its normal protected merge, exact resulting-main CI/CD + CodeQL + Vercel Production verification, worktree/branch cleanup, and safe Vercel retention. It must not start successor B or 4C in the same execution epoch.
Control-plane ownership is also split deliberately: GitHub issue, Linear, milestone, release-program and checkpoint curation is performed from the ChatGPT control-plane session; the coding agent should only read those records when needed and should not spend token/week quota duplicating status maintenance.
The prepared-root Step-F coordinator-recovery Critical is Gate 4B successor-B scope, not Gate 4D. Gate 4D remains crash-resumable rotation/rekey after 4B and 4C. #360/QNB-12 remains open until complete Gate 4B closure.
CURRENT R-15 CHECKPOINT — PR 952 / e34aae2 — recovery finding blocks merge
The minimal stale-CAS correction is signed/pushed and locally verified: success and reconciled stale CAS clear the local mutation latch only after physical/writer/admission revalidation; all uncertain errors remain fail-closed. Normal Git transport works; no sandbox/protection/signing bypass occurred.
New material finding: after an injected step-F COMMIT failure, the public coordinator reconciliation returns
PreparationPendingeven when the provider fault is removed. Existing authenticatedrecover_rootis not integrated into the provider-owning coordinator operation API. Lock/shutdown correctly refuse, but same-instance recovery is incomplete. Diagnostic proof is retained locally; temporary probes were removed from source. Do not merge or close 360/QNB-12 until this is fixed with fault proof and fresh exact-head convergence.No-op RootBusy is separately proved retryable after contention release; its conservative latch is not the prepared-root recovery defect. Remaining DeepSource Rust / CodeScene reds are understood test-only advisory findings, not green. No 4C journal, 4D rekey, collector, deletion, current-app authority change or Gate-7 switch was introduced. At saturated budget, establish a bounded mutation/root-recovery/lifecycle proof slice rather than expand or delete meaningful safety evidence.
HISTORICAL / SUPERSEDED — prior Gate-4B foundation checkpoint
CURRENT R-15 CHECKPOINT — 2026-10-03 — GATE 4B FOUNDATION TERMINAL VIA #951
All resulting-main CI/CD jobs succeeded, including Security Audit, Verified Signatures, Node 22/24, Core/Tauri Rust, Linux/macOS/Windows platform evidence, Build, Playwright, Deep Coverage, Storybook, Browser Quality, CI Success and Pages. Final-head CodeRabbit/CodeAnt/Codex review converged with no actionable finding and no unresolved thread. The two DeepSource test false positives remain evidence-dispositioned advisory red, not green; unavailable reviewer quotas remain recorded.
This terminal checkpoint is for the kernel admission foundation only. It does not complete issue 360, Gate 4B overall, Gate 4 or production Core authority. The next bounded engineering owner remains 4B integration, not 4C.
HISTORICAL / SUPERSEDED — #951 merged, post-merge proof was pending
Final-head CI/CD and CodeQL succeeded; CodeRabbit, CodeAnt and Codex reviewed the final delta/head without remaining actionable findings. All review threads are resolved. The two DeepSource test findings remain evidence-dispositioned advisory false positives, not a green status; quotas are recorded as unavailable. The normal protected squash merge did not close #360 or switch production Core authority. No next semantic slice or retention deletion starts before the exact resulting-main gate.
HISTORICAL / SUPERSEDED — pre-merge #951 checkpoint
Live reconciliation confirms Gate 4A terminal, including exact resulting-main CI/CD, CodeQL and Production evidence. Gate 4B is the current renderer-neutral admission/fencing owner. Historical legacy filesystem defects remain provenance; this checkpoint does not claim a production authority switch or Gate 4 closure.
HISTORICAL / SUPERSEDED — CURRENT AUTHORITATIVE PROGRAM — complete desktop at-rest encryption → v1.30.0 — 2026-10-02 10:21 CEST — superseded by verified Gate 4A terminal checkpoint
Gate 3 is terminal and production-proven at the headless/Core evidence level. Gate 4 is now the sole active R-15 engineering gate. PR #950 is not merge-ready yet: its exact-head review/CI epoch is still running. Asset-pair commit semantics are owned by Gate 5; packaged physical power-loss qualification remains Gate 6; #948 must be terminal before Gate 7 for classes whose current authority deletes records.
HISTORICAL / SUPERSEDED — CURRENT AUTHORITATIVE PROGRAM — complete desktop at-rest encryption → v1.30.0 — 2026-10-01 23:12 CEST — superseded 2026-10-02 10:21 CEST
Current Gate 3 execution
PR #941 is terminal. Its resulting main
03a24786...passed CI Success, Node 22/24, Core/Tauri Rust, Linux/macOS/Windows secure-store evidence, Build, Playwright, Deep Coverage, Storybook, Browser Quality, Security Audit, Verified Signatures, CodeQL, Pages and deployment-retention; Vercel Production is READY on the exact SHA.3C part 2 is active via #942. Current exact-head evidence on
48525c99...: CodeQL, Security Audit, Verified Signatures, Core/Tauri Rust, all three secure-store platform jobs, PR-size admission, workflow policy, changelog and reviewer-governance trust checks are green; Node 22/24 and Cubic are still running at the latest readback. Vercel Preview is READY on the exact head. Current review remainder on exact head48525c99...is material and must be validated before any correction wave: Codex returned four P2s — (1) catalog pages must preserve enough authenticated/reversible identity material to enumerate records whose logical/project IDs use hashed bindings, (2) decoded descriptors must reject non-ordinary/control/retained classes, (3)catalog_set_digestmust enforce the fixed 0..255 shard universe, and (4) catalog Debug output must redact direct identity/scope bytes. CodeRabbit independently reports the non-ordinary-class admission as a Major. CodeAnt reports the same class-admission gap plus a Major on decoded binding/template/project-scope validation, and a shard-bound API nitpick. CodeScene reports argument-count/code-health findings; DeepSource has one minor range-style finding. Node 22/24 and Cubic are still running; Sourcery is quota-limited. Do not merge until findings are validated/dispositioned, any material corrections are bundled coherently, and the resulting exact-head epoch converges.Immediate order
list_records, retention, asset-pair closure where required, and terminal Gate 3/Desktop atomic writes: fsync temp file + parent directory before/after rename for true crash durability #357 reconciliation.HISTORICAL / SUPERSEDED — CURRENT AUTHORITATIVE PROGRAM — complete desktop at-rest encryption → v1.30.0 — 2026-10-01 — superseded 2026-10-01 23:12 CEST
Current Gate 3 execution
Gate 3B is now terminal. PR #940's resulting main
e43559b9...is fully proven: CI Success, Node 22/24, Core/Tauri Rust, Linux/macOS/Windows secure-store evidence, Build, Playwright, Deep Coverage, Storybook, Browser Quality, Security Audit, Verified Signatures, CodeQL and Pages are green; Vercel Production is READY on the exact SHA.Gate 3C is split at proof boundaries:
7a1edcf1...is open and mergeable; CodeQL, Security Audit, platform/Rust checks, CodeScene, Semgrep and reviewer-governance checks are green, while Node 22/24 are still running at the latest readback. Current review remainder includes a material Codex P2 on asset-pair admission tomarker_set_digestplus a Cubic P3 documentation mismatch for the bootstrapjournal_revision = 0sentinel. Resolve/disposition the full current-head epoch before another push/merge.list_records, retention and terminal Gate 3/Desktop atomic writes: fsync temp file + parent directory before/after rename for true crash durability #357 reconciliation.Immediate order
Current child-owner reconciliation
HISTORICAL / SUPERSEDED — checkpoint before Gate 3B/3C convergence — 2026-10-01
Current M2 execution — Gate 3 (#921)
Gate 3 remains admitted as three bounded slices:
#935 / PR #936 — merged support follow-up
The deterministic gate-status hardening follow-up is merged as #936 to resulting main
cd12c104...; #935 is closed. Exact-head review had converged before merge. Post-merge proof is now the only remaining support activity: CodeQL, Security Audit and Verified Signatures are already green; Vercel Production is READY on the exact SHA; Node 22/24 are still running at the latest readback.This support lane is not a new product gate. Do not reopen it absent new material evidence.
Immediate order
cd12c104....Current child-owner reconciliation
Program priority
Until v1.30.0 is VERIFIED, the primary engineering lane is the complete R-15 desktop at-rest encryption program. Unrelated roadmap expansion must not preempt it unless a fresh P0/P1 security, data-loss or release blocker requires admission.
HISTORICAL / SUPERSEDED — M1 execution (Gate 2, 2026-10-01)
Gate 2 completed as #917 → #928 (Slice A) → #929 (closure, which replaced the planned Slices B/C); Slice B's locator adapters were re-assigned to Gate 5 (#923). Evidence: #920 closing comment.
Program priority
Until v1.30.0 is VERIFIED, the primary engineering lane is the complete R-15 desktop at-rest encryption program. Unrelated roadmap expansion must not preempt it unless a fresh P0/P1 security, data-loss or release blocker requires admission.
Gate owners and closure relationships
Definition of milestone success
R-15 is not complete because crypto primitives or OS key stores exist. It is complete only when every packaged-desktop PROTECTED class is either authoritative through the renderer-neutral Rust Core encrypted path or explicitly retained under an approved separate protected authority; migration/rekey is crash-resumable and race-free; durable writes survive the required failure matrix; packaged Linux/macOS/Windows evidence is recorded; and Gate 7 is explicitly authorized and executed without plaintext fallback.
Then and only then may #926 cut v1.30.0 and product/security documentation claim the new desktop at-rest authority.
Autonomous continuation rule
semantic admission required,fresh admission,not yet admitted, orre-read before codingmeans the executing agent performs the bounded proof itself, records it, and continues. It is not a chat handoff. After each merge: resulting-main CI/CD + CodeQL + exact-SHA Production/HTTP proof → evidence sync + housekeeping → re-read main/contracts → next highest-priority unblocked bounded owner → self-perform admission → continue.Only stop for a genuinely unresolved maintainer-only decision: Gate 7 Production Authority Switch authorization; branch-protection/ruleset/admin/bypass mutation; tag movement/reuse; explicitly approval-gated destructive provider action; or materially incompatible security/authority designs not resolved by current contract/decision.
HISTORICAL — release-recovery hold — 2026-09-29 (superseded 2026-09-30 by the block above)
R-15 remains open and urgent, but implementation is frozen until #872 reaches v1.29.1 VERIFIED.
After the release, re-read current main and governance state before re-anchoring any parked branch. Do not merge stale R-15 branches opportunistically during release recovery.
v1.29 RustCrypto dependency disposition — 2026-09-29
Dependabot #883–#887 are not required predecessors for v1.29 on current evidence.
Live source confirms
src-taurilinksworldscript-project;worldscript-secure-storageremains a separate workspace member and is not linked into the shipped Tauri desktop runtime.Additional blocker evidence:
getrandom0.2.17 → 0.4.3;getrandom0.4 uses Edition 2024 and declares MSRV Rust 1.85;Therefore #883 cannot be treated as a routine release dependency bump without an explicit MSRV-policy change. #884–#887 likewise remain major cryptographic dependency changes requiring bounded API/MSRV/security review.
Absent a concrete current advisory requiring immediate adoption, disposition #883–#887 as
DEFERRED_WITH_RELEASE_SAFE_EVIDENCEand resume them after v1.29 under #445/#572.This does not admit any further Gate 1b-platform implementation before release. #851 remains parked; #852/#853 remain frozen provenance/source material;
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.v1.29.0 release freeze — 2026-09-29
R-15 remains open and important, but no further R-15 implementation slice is admitted before the current v1.29.0 release convergence unless new release-blocking evidence explicitly changes that decision.
For the pre-release period:
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO;After the release, re-anchor this issue on then-current main and reconstruct the smallest correct next Gate 1b-platform slice from live source/evidence.
Current execution gate — 2026-09-27 (post-merge guardrail remediation pending)
4972e000; resulting-main CI/CD, CodeQL and Production passed.6a99a2cf; resulting-main CI/CD, CodeQL and Production passed.06f2ef4753cf82c797693e524833044cc79c0488; exact resulting-main CI/CD and CodeQL passed and Production was READY on that SHA. Slice B was admitted and merged through PR feat(core): Gate 1b durable authority bootstrap #855 (feat(core): Gate 1b durable authority bootstrap). Its resulting-main admission exposed a release-truth/main-context gate defect; PR docs(core): reconcile post-merge changelog history #856 restored green resulting main5910ae7e9bc9f60f00eafd03be853b846f16fdbb, with CI/CD and CodeQL passed and Production READY on the same SHA. Permanent main-context admission remediation is pending before another R-15 implementation slice. Runtime cache/unlock/resolve and anchor transitions remain later slices. PR feat(core): R-15 Gate 1b-platform OS secure-store key provider (#445) #851 stays parked for OS adapters; feat(core): R-15 Gate 1b-platform headless secure-store key provider (#445) #852/feat(core): R-15 Gate 1b-platform headless secure-store key provider — successor of #852 (#445) #853 stay frozen as provenance/source material.project_idscope enforcement) remains not admitted ahead of Gate 1 completion.PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.Detailed exact-SHA post-merge evidence for Slice A and the later Slice B recovery is recorded in checkpoint comments below. This section updates only the current execution-gate state; the binding R-15 contract remains authoritative for semantics.
Purpose
Implement R-15 as the renderer-neutral encrypted-storage authority for native desktop. This is a Core/security migration requirement, not a Tauri-specific enhancement and not work that should be discarded when Qt replaces Tauri.
The current product truth remains explicit: authoritative Tauri filesystem project data is not yet protected at rest by this future Core design. No UI, release note, or documentation may imply otherwise until the protected path is authoritative and packaged evidence exists.
Architecture boundary
Requirements:
Required protected-data inventory
Before implementation, enumerate every native desktop record class and classify it as
PROTECTED,NON-SENSITIVE,DERIVED/REGENERABLE, orOUT-OF-SCOPEwith rationale. At minimum inspect:The inventory is part of the security contract: no protected class may silently fall back to plaintext because a renderer or migration path was overlooked.
Required envelope/key properties
The admitted design must define and test:
Durability — incorporates #357
A successful protected write must have a documented crash-durability contract, not merely atomic rename semantics. Define platform-appropriate behavior for:
The implementation belongs in renderer-neutral/native Core infrastructure wherever practical; do not create a new Tauri-only durable-write authority simply because #357 was originally reported against the Tauri path.
Crash-resumable rekey — incorporates #359
Rotation, enable/disable transitions, and migration from plaintext/legacy envelopes must be resumable and idempotent.
Persist enough journal/checkpoint state to identify:
Crash/power-loss at every meaningful phase must not silently strand a mixed-key dataset.
Migration admission — incorporates #360
Reads/writes and migration must participate in one coherent admission model.
Required invariants:
Record identity binding — incorporates #361
Protected ciphertext must be cryptographically or structurally bound to the logical record it represents so valid ciphertext cannot be substituted between records undetected.
Define stable identities for each protected class, e.g. project/snapshot/image/index/settings credential records. The binding scheme must survive legitimate moves/migrations where intended and must be included in rekey/migration logic.
Plaintext → protected migration
Existing desktop users require an explicit recoverable migration path.
The migration plan must specify:
Do not delete the only recoverable copy before the protected replacement is durably committed.
Threat / failure matrix
Tests and design evidence must cover at least:
Headless and packaged evidence
Core behavior must be testable headlessly without Tauri/Qt. Packaged desktop evidence is additionally required for OS/filesystem/key-store integration and destructive lifecycle cases that unit tests cannot establish.
Evidence maturity must be explicit (
LOCAL_ONLY,CI_ONLY,PACKAGED_LOCAL,PACKAGED_TARGET_ENV,FIELD_OBSERVED).Qt migration relationship
R-15 is pre-Qt / parallel-to-Qt foundation work, not sunk cost. Qt should consume the same Core storage authority rather than reimplementing it.
Related issues / reconciliation
Historical detailed requirements:
Those issues remain useful provenance and detailed threat evidence. R-15/#445 is the canonical integration/closure issue. When implementation lands, reconcile each child requirement explicitly; do not close them merely because #445 has code.
Related migration acceptance: #332 and the Qt/Tauri roadmap documentation.
Acceptance criteria
Non-goals