docs: record backend audit corrections

This commit is contained in:
Amruth Pillai
2026-09-05 23:32:29 +02:00
parent 39c564cdf1
commit 02de0e9fcb
2 changed files with 13 additions and 10 deletions
@@ -35,11 +35,11 @@ state changes are outside scope.
| 04 AI provider compatibility | #2732, #2766, #2723, #2708 | blocked | audit `task_855fbee0a803` | `codex-audit-backend-01-06` | `7a98f6662` → no source change | serialize edits to AI service | zero drift; historical #2708 Responses path and #2766 structured Test path absent; remaining tuples differ | focused API 96 and full API suites/typecheck/boundaries passed in audit | — | select wire/state/import/base-path unit only after exact current tuple fails | provider/model/base URL/path/version/action/error tuple and allowed endpoint unavailable |
| 05 AI provider migrations | #3152 | blocked | audit `task_855fbee0a803` | `codex-audit-backend-01-06` | `7a98f6662` → no source change | coordinate DB/startup with 03 | zero drift; table schema, migration, startup ordering, Docker copy path coherent; `42P01` historical cause unresolved | audit API/server/DB tests, typechecks, boundaries passed; no real PostgreSQL migration fixture | — | choose config/packaging/startup/migration repair only after disposable reproduction | affected image layout/digest, working directory, DB schema/search path/journal, fresh+upgrade DB fixture |
| 06 image storage delivery | #2684, #2778 | blocked | audit `task_855fbee0a803` | `codex-audit-backend-01-06` | `7a98f6662` → no source change | coordinate 12/15/25 renderer/image fixtures | #2684 ACL cause fixed by merged #3432 (`35cecf9`); #2778 Browserless path obsolete; current topology unproved | #3432 hosted checks successful; audit storage/upload/PDF tests, typechecks, boundaries passed | #3432 merged before run | deployment retest plus shared real-encoding/backend/render fixture before repair | deployed digest; disposable S3/Garage/SeaweedFS/MinIO/proxy and browser/server raster matrix unavailable |
| 07 AIO deployment | #2722 | pending | unassigned | — | `7a98f6662` → — | none | Q12: PostgreSQL remains separate | — | — | record declined AIO direction; inspect Compose/Unraid docs; improve only proven gaps | no AIO implementation permitted |
| 08 root public resume | #2669 | pending | unassigned | — | `7a98f6662` → — | none | live revalidation pending | — | — | verify self-hosted root routing proposal against current routes | — |
| 09 external version backup | #2705 | pending | unassigned | — | `7a98f6662` → — | none | live revalidation pending | — | — | document explicit JSON backup in user-controlled Git | no automatic sync scope |
| 10 legacy link routing | #2836 | pending | unassigned | — | `7a98f6662` → — | none | live revalidation pending | — | — | validate owner-only notice/public 404 scope | prospective behavior only where historical data absent |
| 11 job search policy | #3010 | pending | unassigned | — | `7a98f6662` → — | none | live revalidation pending | — | — | document JSearch removal/current tailoring workflow | — |
| 07 AIO deployment | #2722 | pending implementation; requested feature declined | audit `task_9f27829ca50f` | planned `codex/issue-2722-postgres-docs` | `7a98f6662` → — | none | Q12 and runtime confirm one app process plus separate PostgreSQL; docs already cover core quickstart/backups, with topology/Unraid/reused-DB/upgrade gaps | audit markdown lint and Compose config passed | — | make exact two-file docs improvement without AIO/runtime changes or closing keyword | no AIO implementation permitted; optional Unraid host smoke unavailable |
| 08 root public resume | #2669 | plan amendment required before implementation | audit `task_9f27829ca50f` | planned `codex/issue-2669-root-resume` | `7a98f6662` → — | none | current password redirect rejects `/`; public view is slug-hook-bound; SSR canonical cannot import server env; expanded auth/canonical contract identified | audit focused API/web suites, typechecks, boundaries passed | — | amend ownership for identity-vs-return auth flow and server-derived canonical root, then dispatch coherent feature | engineering scope correction; feature remains narrower than arbitrary domain/TLS registry |
| 09 external version backup | #2705 | pending implementation | audit `task_9f27829ca50f` | planned `codex/issue-2705-git-backup-docs` | `7a98f6662` → — | none | current resume, independent cover-letter, and account export shapes verified; manual local Git workflow approved | audit export/import suites, markdown lint, typechecks, boundaries passed | — | publish plain Git commands and format distinctions; validate in disposable local repo | no automatic sync, remote, or whole-account restore; agent-only `rtk` syntax forbidden in user docs |
| 10 legacy link routing | #2836 | pending implementation after brief correction | audit `task_9f27829ca50f` | planned `codex/issue-2836-retired-slug-notices` | `7a98f6662` → — | none | prospective same-username slug-attempt notice remains coherent; exact DB/API/UI/E2E owner set verified | audit focused API/web suites, DB/API/web typechecks, boundaries passed | — | correct final E2E target to `public-sharing.spec.ts`, then implement migration/API/owner UI atomically | historical cause absent; no redirects/emails/recovery; prospective partial coverage only |
| 11 job search policy | #3010 | pending implementation | audit `task_9f27829ca50f` | planned `codex/issue-3010-jsearch-docs` | `7a98f6662` → — | none | history proves JSearch removed in v5.1.0; current provider-native search and supplied-description tailoring verified | audit agent/capability tests, markdown lint, typechecks, boundaries passed | — | make minimal three-file factual docs correction | removal motive unknown; JSearch not restored and live search remains provider/model-dependent |
| 12 preview/export failures | #3323, #3290, #3033, #3007, #2609 | blocked corrective work; diagnostic-ready | audit `task_1c6582ccdeae` | `codex-audit-rendering-12-19` | `7a98f6662` → no source change | renderer ownership; share observation harness with 18 | zero drift; staged-preview/error-boundary baselines remain; reports cross persistence/font/PDF/viewer/deployment boundaries | audit focused web/PDF suites, affected typechecks, boundaries, build passed | — | isolate PT Sans, browser/config, and template-selection boundaries; no shared fix | exact JSON/output/browser/config/current reproduction missing |
| 13 font/glyph/spacing | #3249, #3159, #3147, #3093, #3089, #2988 | blocked corrective work; diagnostic-ready | audit `task_1c6582ccdeae` | `codex-audit-rendering-12-19` | `7a98f6662` → no source change | serialize font sources with 14/27 | merged metrics/cache/Unicode fixes present and passing; residuals require per-font/per-symptom fixtures | audit focused PDF/font suites, affected typechecks, boundaries, build passed | — | retain regressions; create residual unit only from exact failing font fixture | missing Ropa Sans/source strings/font hashes/before-after artifacts |
| 14 RTL export layout | #3275 | blocked corrective work; diagnostic-ready | audit `task_1c6582ccdeae` | `codex-audit-rendering-12-19` | `7a98f6662` → no source change | serialize renderer/fonts with 13/27 | merged canvas-direction fix remains; broader shaping/bidi cause unproved | audit RTL/preview suites, affected typechecks, boundaries, build passed | — | run controlled same-bytes export matrix against approved shaping oracle | exact JSON/font/version and known-good reference absent |
@@ -63,14 +63,14 @@ state changes are outside scope.
| 32 section date sorting | #2725 | pending implementation | audit `task_47ed7eb02d48` | planned `codex/issue-2725-one-shot-sort` | `7a98f6662` → — | shared-file exclusion with 20–24; behavior independent of 24 | existing `parsePeriod` reusable; pure stable one-shot sort contract approved for Experience/Education | audit resume/schema/web suites and typechecks/boundaries passed | — | implement pure helper, exact unresolved IDs, menu/undo/persistence tests | bare Present/reversed/blank remain stable unresolved by design |
| 33 Europass template | #2689 | blocked after approved research/proposal unit | audit `task_47ed7eb02d48` | planned `codex/issue-2689-europass-research` | `7a98f6662` → — | 33A → explicit visual approval → possible 33B | no current template; historical draft obsolete/incomplete; research/proposal only approved now | audit registry/gallery/schema suites and typechecks/boundaries passed | — | research authoritative references/licensing and publish concrete one-page/overflow proposal; stop | explicit future visual approval required before any template code |
| 34 Gengar skill layout | #2611 | pending after 22 | audit `task_47ed7eb02d48` | planned `codex/issue-2611-gengar-skill-level` | `7a98f6662` → — | 22 → 34; serialize shared Skills renderer | typed template capability + single shared renderer consumption is ready; no template-name branch | audit PDF skills/semantic suites and typechecks/boundaries passed | — | implement after keyword layout lands; assert Gengar-only delta and unchanged peers | file serialization only |
| 35 resume import errors | #2768 | pending | unassigned | — | `7a98f6662` → — | none | live revalidation pending | — | — | reproduce before changing parser/dialog lifecycle | source fixture may be missing |
| 35 resume import errors | #2768 | diagnostic-ready; corrective work blocked | audit `task_9f27829ca50f` | planned `codex/issue-2768-import-reproduction` | `7a98f6662` → — | none | no reporter fixture/stack; current suites pass; empty-MIME detector/form mismatch is only an unproved candidate | audit import 144, focused web 36, typechecks, boundaries passed | — | create synthetic Playwright-generated PDF/JSON lifecycle E2E; change source only after deterministic 3× failure | historical evidence absent; separate stale import-doc correction from issue fix |
## Active orchestration
| Scope | Task / dispatch | Owner worktree | State | Deliverable |
| --- | --- | --- | --- | --- |
| Plans 01–06 | `task_855fbee0a803` / `ctx_949458744061` | `codex-audit-backend-01-06` | complete; worker released | zero drift; plans 01/04/05/06 blocked on named evidence; plan 03 no-change; plan 02 synthetic unit ready |
| Plans 07–11, 35 | `task_9f27829ca50f` / `ctx_11f7d7cf6d17` | `codex-audit-backend-07-11-35` | diagnosing | current issue/source/PR audit and executable unit split |
| Plans 07–11, 35 | `task_9f27829ca50f` / `ctx_11f7d7cf6d17` | `codex-audit-backend-07-11-35` | complete; worker release pending | 07/09/10/11 ready after named brief corrections; 08 needs engineering scope amendment; 35 diagnostic-only |
| Plans 12–19 | `task_1c6582ccdeae` / `ctx_795fced595ef` | `codex-audit-rendering-12-19` | complete; worker release pending | 15A/16/19 implementation-ready; remaining causes split into diagnostics with named evidence gates |
| Plans 20–34 | `task_47ed7eb02d48` / `ctx_50d8257459ab` | `codex-audit-builder-20-34` | complete; worker release pending | ready: 20A, 21, 22, 23A, 28 diagnostics, 32, 34; remaining plans split at evidence/design gates |
| Plan 07 implementation | `task_aee702e37eae` / not dispatched | planned `codex/issue-2722-postgres-docs` | waits on plans 07–11 audit | two-file docs change, verification, commit, independent review |
+6 -3
View File
@@ -19,12 +19,15 @@ Required execution:
`docs/guides/undoing-changes-and-version-history.mdx`.
- Document single-resume JSON, independent cover-letter JSON, and account archive differences; stable filenames; image URL
availability; private-data/repository-visibility warning; local-only Git workflow; non-destructive import-as-new recovery;
rolling in-app versions versus owner-managed Git. Include plan's exact local-only command sequence. No automatic sync,
credentials, remote URL, `git push`, whole-account restore promise, or new product UI.
rolling in-app versions versus owner-managed Git. Correct planning prose before publication: every user-facing code block
must use ordinary `git init`, `git add -- ...`, `git diff`, `git commit`, and `git show`. Never publish agent-only
`rtk proxy git` commands. No automatic sync, credentials, remote URL, `git push`, whole-account restore promise, or new
product UI.
- Use only synthetic data. Run API export/version tests specified by plan. Validate single-resume import round-trip using
existing synthetic fixtures/tests or a bounded disposable test; never use private data.
- Execute command sequence in `mktemp -d`, staging only `resume.json` and `cover-letter.json`; show changed visible field in
`git diff`. Do not modify global Git config if identity missing; record limitation.
`git diff`. Executor shell may wrap validation with `rtk proxy`, but copied documentation commands must remain plain Git.
Do not modify global Git config if identity missing; record limitation.
- Run plan's focused `rg`, markdown lint, `git diff --check`, and two-file name-only gate. Self-review every acceptance item.
- Commit with normal message. Leave branch local for independent review.