Skip to content

[GOV.11] Enforce Web architecture and canonical naming policy - #20

Merged
deku2026 merged 2 commits into
mainfrom
task/gov-11
Sep 27, 2026
Merged

deku2026 merged 2 commits into
mainfrom
task/gov-11

Conversation

@deku2026

@deku2026 deku2026 commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Task: https://github.com/ArcForges/ArcForges-Design/blob/main/docs/planning/delivery/lanes/governance.md#task-gov-11
Claim: GOV.11 epoch 1 (w-20260927-ai-lane)

Web had no unified executable architecture matrix and did not consume the canonical published naming scanner. GOV.11 now enforces workspace/lock/toolchain boundaries, transitive source and manifest imports, desktop-only DOM restrictions, generated-wire usage, production command recursion, obsolete targets, portable references and fixture exclusion. Positive and negative fixtures cover each rule, including bridge imports and script aliases. The canonical scanner/policy are bound to exact published Contracts129 bytes and tested against every forbidden alias.

The supporting ADP07 bindings admit existing-closure Babel parser/types7.29.8 as direct build dependencies, consume the already-published proto/api-client129 pair, remove the obsolete explicit binary selector under Design84/Plan46 scope, and read genuine published multi-subject ContractSet metadata instead of the retired single-schema field. No schema axis is inferred from package version. Browser r7 and build-identity r3 are immutable successors; all older records remain unchanged. The browser delta has 254 parsed/123 emitted modules, only wire.js newly emitted, and 17/18 identical normalized templates. No new external dependency versions beyond the authorized Contracts pair.

Validation: full npm run check passed (15 dependency, 66 unit, 42 provenance tests), policy/naming/dependency admission passed, and strict local candidate build passed including graph/template/legal/SBOM/build-identity verification. An initial candidate failure was a profile hash serialized as pretty JSON rather than the existing canonical JSON; corrected without changing SBOM identities/edges. No browser/device/live-service test, extra public artifact download or republishing. Hosted checks and independent exact-head review remain the merge gate.

Final exact head202483ae52513716325b382c1093bf0bd87bc951 independently approved5859296384/5859309618 and all applicable CI36346128105 checks pass. The one-line gitleaks path extension preserves8 exact public source checksum exceptions. This security-suppression path scope is excluded from ADP07: the delta was pushed before explicit scope authorization, and product merge waits for the narrow Design/Plan support pair. No broader exception is authorized.

@deku2026

Copy link
Copy Markdown
Contributor Author

Independent GOV11 review approved exact head 88d3e84. Rechecked the three prior findings: production reachability now follows bridges outside app/src, production npm script aliases recursively resolve with cycle/unknown checks, and Apache manifest/source dependency closures reject AGPL workspace edges. Reviewed AST import/type/codec rules and positive generated aliases/UI fixtures, exact published naming assets and 129 pin, Babel direct declarations without added external closure, immutable browser r7 and build-identity r3 successors. The multi-subject ContractSet reads producer-declared versions and checks clean source, artifact pin, complete source-hash set and protobuf descriptor bindings. Independently ran architecture+naming tests (33 passed), build-identity tests (7 passed), and real repository policy (passed). No remaining substantive finding; required exact-head CI remains mandatory. This approval does not claim browser/device runtime or production deployment evidence.

@deku2026

Copy link
Copy Markdown
Contributor Author

Independent incremental approval for 202483a. Reviewed the complete one-line delta: the existing exact browser-resource public-hash exception path class now includes immutable profile r7; rule identity and eight literal whole-line digest patterns remain unchanged. This corresponds to the same existing publicly derived hash rows in the reviewed r7 successor. No source behavior or dependency change. Previous substantive approval remains applicable; exact-head CI required.

@deku2026 deku2026 changed the title GOV.11: enforce Web architecture and canonical naming policy [GOV.11] Enforce Web architecture and canonical naming policy Sep 27, 2026
@deku2026
deku2026 merged commit cd65b03 into main Sep 27, 2026
10 checks passed
@deku2026
deku2026 deleted the task/gov-11 branch September 28, 2026 03:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant