From 02de0e9fcb72403ebc41335b42e4576773f25d2d Mon Sep 17 00:00:00 2001 From: Amruth Pillai Date: Sat, 5 Sep 2026 23:32:29 +0200 Subject: [PATCH] docs: record backend audit corrections --- docs/execution/approved-issue-plans-ledger.md | 14 +++++++------- docs/execution/briefs/implement-plan-09.md | 9 ++++++--- 2 files changed, 13 insertions(+), 10 deletions(-) diff --git a/docs/execution/approved-issue-plans-ledger.md b/docs/execution/approved-issue-plans-ledger.md index 9a4d94d2e..d7e754afe 100644 --- a/docs/execution/approved-issue-plans-ledger.md +++ b/docs/execution/approved-issue-plans-ledger.md @@ -35,11 +35,11 @@ state changes are outside scope. | 04 AI provider compatibility | #2732, #2766, #2723, #2708 | blocked | audit `task_855fbee0a803` | `codex-audit-backend-01-06` | `7a98f6662` → no source change | serialize edits to AI service | zero drift; historical #2708 Responses path and #2766 structured Test path absent; remaining tuples differ | focused API 96 and full API suites/typecheck/boundaries passed in audit | — | select wire/state/import/base-path unit only after exact current tuple fails | provider/model/base URL/path/version/action/error tuple and allowed endpoint unavailable | | 05 AI provider migrations | #3152 | blocked | audit `task_855fbee0a803` | `codex-audit-backend-01-06` | `7a98f6662` → no source change | coordinate DB/startup with 03 | zero drift; table schema, migration, startup ordering, Docker copy path coherent; `42P01` historical cause unresolved | audit API/server/DB tests, typechecks, boundaries passed; no real PostgreSQL migration fixture | — | choose config/packaging/startup/migration repair only after disposable reproduction | affected image layout/digest, working directory, DB schema/search path/journal, fresh+upgrade DB fixture | | 06 image storage delivery | #2684, #2778 | blocked | audit `task_855fbee0a803` | `codex-audit-backend-01-06` | `7a98f6662` → no source change | coordinate 12/15/25 renderer/image fixtures | #2684 ACL cause fixed by merged #3432 (`35cecf9`); #2778 Browserless path obsolete; current topology unproved | #3432 hosted checks successful; audit storage/upload/PDF tests, typechecks, boundaries passed | #3432 merged before run | deployment retest plus shared real-encoding/backend/render fixture before repair | deployed digest; disposable S3/Garage/SeaweedFS/MinIO/proxy and browser/server raster matrix unavailable | -| 07 AIO deployment | #2722 | pending | unassigned | — | `7a98f6662` → — | none | Q12: PostgreSQL remains separate | — | — | record declined AIO direction; inspect Compose/Unraid docs; improve only proven gaps | no AIO implementation permitted | -| 08 root public resume | #2669 | pending | unassigned | — | `7a98f6662` → — | none | live revalidation pending | — | — | verify self-hosted root routing proposal against current routes | — | -| 09 external version backup | #2705 | pending | unassigned | — | `7a98f6662` → — | none | live revalidation pending | — | — | document explicit JSON backup in user-controlled Git | no automatic sync scope | -| 10 legacy link routing | #2836 | pending | unassigned | — | `7a98f6662` → — | none | live revalidation pending | — | — | validate owner-only notice/public 404 scope | prospective behavior only where historical data absent | -| 11 job search policy | #3010 | pending | unassigned | — | `7a98f6662` → — | none | live revalidation pending | — | — | document JSearch removal/current tailoring workflow | — | +| 07 AIO deployment | #2722 | pending implementation; requested feature declined | audit `task_9f27829ca50f` | planned `codex/issue-2722-postgres-docs` | `7a98f6662` → — | none | Q12 and runtime confirm one app process plus separate PostgreSQL; docs already cover core quickstart/backups, with topology/Unraid/reused-DB/upgrade gaps | audit markdown lint and Compose config passed | — | make exact two-file docs improvement without AIO/runtime changes or closing keyword | no AIO implementation permitted; optional Unraid host smoke unavailable | +| 08 root public resume | #2669 | plan amendment required before implementation | audit `task_9f27829ca50f` | planned `codex/issue-2669-root-resume` | `7a98f6662` → — | none | current password redirect rejects `/`; public view is slug-hook-bound; SSR canonical cannot import server env; expanded auth/canonical contract identified | audit focused API/web suites, typechecks, boundaries passed | — | amend ownership for identity-vs-return auth flow and server-derived canonical root, then dispatch coherent feature | engineering scope correction; feature remains narrower than arbitrary domain/TLS registry | +| 09 external version backup | #2705 | pending implementation | audit `task_9f27829ca50f` | planned `codex/issue-2705-git-backup-docs` | `7a98f6662` → — | none | current resume, independent cover-letter, and account export shapes verified; manual local Git workflow approved | audit export/import suites, markdown lint, typechecks, boundaries passed | — | publish plain Git commands and format distinctions; validate in disposable local repo | no automatic sync, remote, or whole-account restore; agent-only `rtk` syntax forbidden in user docs | +| 10 legacy link routing | #2836 | pending implementation after brief correction | audit `task_9f27829ca50f` | planned `codex/issue-2836-retired-slug-notices` | `7a98f6662` → — | none | prospective same-username slug-attempt notice remains coherent; exact DB/API/UI/E2E owner set verified | audit focused API/web suites, DB/API/web typechecks, boundaries passed | — | correct final E2E target to `public-sharing.spec.ts`, then implement migration/API/owner UI atomically | historical cause absent; no redirects/emails/recovery; prospective partial coverage only | +| 11 job search policy | #3010 | pending implementation | audit `task_9f27829ca50f` | planned `codex/issue-3010-jsearch-docs` | `7a98f6662` → — | none | history proves JSearch removed in v5.1.0; current provider-native search and supplied-description tailoring verified | audit agent/capability tests, markdown lint, typechecks, boundaries passed | — | make minimal three-file factual docs correction | removal motive unknown; JSearch not restored and live search remains provider/model-dependent | | 12 preview/export failures | #3323, #3290, #3033, #3007, #2609 | blocked corrective work; diagnostic-ready | audit `task_1c6582ccdeae` | `codex-audit-rendering-12-19` | `7a98f6662` → no source change | renderer ownership; share observation harness with 18 | zero drift; staged-preview/error-boundary baselines remain; reports cross persistence/font/PDF/viewer/deployment boundaries | audit focused web/PDF suites, affected typechecks, boundaries, build passed | — | isolate PT Sans, browser/config, and template-selection boundaries; no shared fix | exact JSON/output/browser/config/current reproduction missing | | 13 font/glyph/spacing | #3249, #3159, #3147, #3093, #3089, #2988 | blocked corrective work; diagnostic-ready | audit `task_1c6582ccdeae` | `codex-audit-rendering-12-19` | `7a98f6662` → no source change | serialize font sources with 14/27 | merged metrics/cache/Unicode fixes present and passing; residuals require per-font/per-symptom fixtures | audit focused PDF/font suites, affected typechecks, boundaries, build passed | — | retain regressions; create residual unit only from exact failing font fixture | missing Ropa Sans/source strings/font hashes/before-after artifacts | | 14 RTL export layout | #3275 | blocked corrective work; diagnostic-ready | audit `task_1c6582ccdeae` | `codex-audit-rendering-12-19` | `7a98f6662` → no source change | serialize renderer/fonts with 13/27 | merged canvas-direction fix remains; broader shaping/bidi cause unproved | audit RTL/preview suites, affected typechecks, boundaries, build passed | — | run controlled same-bytes export matrix against approved shaping oracle | exact JSON/font/version and known-good reference absent | @@ -63,14 +63,14 @@ state changes are outside scope. | 32 section date sorting | #2725 | pending implementation | audit `task_47ed7eb02d48` | planned `codex/issue-2725-one-shot-sort` | `7a98f6662` → — | shared-file exclusion with 20–24; behavior independent of 24 | existing `parsePeriod` reusable; pure stable one-shot sort contract approved for Experience/Education | audit resume/schema/web suites and typechecks/boundaries passed | — | implement pure helper, exact unresolved IDs, menu/undo/persistence tests | bare Present/reversed/blank remain stable unresolved by design | | 33 Europass template | #2689 | blocked after approved research/proposal unit | audit `task_47ed7eb02d48` | planned `codex/issue-2689-europass-research` | `7a98f6662` → — | 33A → explicit visual approval → possible 33B | no current template; historical draft obsolete/incomplete; research/proposal only approved now | audit registry/gallery/schema suites and typechecks/boundaries passed | — | research authoritative references/licensing and publish concrete one-page/overflow proposal; stop | explicit future visual approval required before any template code | | 34 Gengar skill layout | #2611 | pending after 22 | audit `task_47ed7eb02d48` | planned `codex/issue-2611-gengar-skill-level` | `7a98f6662` → — | 22 → 34; serialize shared Skills renderer | typed template capability + single shared renderer consumption is ready; no template-name branch | audit PDF skills/semantic suites and typechecks/boundaries passed | — | implement after keyword layout lands; assert Gengar-only delta and unchanged peers | file serialization only | -| 35 resume import errors | #2768 | pending | unassigned | — | `7a98f6662` → — | none | live revalidation pending | — | — | reproduce before changing parser/dialog lifecycle | source fixture may be missing | +| 35 resume import errors | #2768 | diagnostic-ready; corrective work blocked | audit `task_9f27829ca50f` | planned `codex/issue-2768-import-reproduction` | `7a98f6662` → — | none | no reporter fixture/stack; current suites pass; empty-MIME detector/form mismatch is only an unproved candidate | audit import 144, focused web 36, typechecks, boundaries passed | — | create synthetic Playwright-generated PDF/JSON lifecycle E2E; change source only after deterministic 3× failure | historical evidence absent; separate stale import-doc correction from issue fix | ## Active orchestration | Scope | Task / dispatch | Owner worktree | State | Deliverable | | --- | --- | --- | --- | --- | | Plans 01–06 | `task_855fbee0a803` / `ctx_949458744061` | `codex-audit-backend-01-06` | complete; worker released | zero drift; plans 01/04/05/06 blocked on named evidence; plan 03 no-change; plan 02 synthetic unit ready | -| Plans 07–11, 35 | `task_9f27829ca50f` / `ctx_11f7d7cf6d17` | `codex-audit-backend-07-11-35` | diagnosing | current issue/source/PR audit and executable unit split | +| Plans 07–11, 35 | `task_9f27829ca50f` / `ctx_11f7d7cf6d17` | `codex-audit-backend-07-11-35` | complete; worker release pending | 07/09/10/11 ready after named brief corrections; 08 needs engineering scope amendment; 35 diagnostic-only | | Plans 12–19 | `task_1c6582ccdeae` / `ctx_795fced595ef` | `codex-audit-rendering-12-19` | complete; worker release pending | 15A/16/19 implementation-ready; remaining causes split into diagnostics with named evidence gates | | Plans 20–34 | `task_47ed7eb02d48` / `ctx_50d8257459ab` | `codex-audit-builder-20-34` | complete; worker release pending | ready: 20A, 21, 22, 23A, 28 diagnostics, 32, 34; remaining plans split at evidence/design gates | | Plan 07 implementation | `task_aee702e37eae` / not dispatched | planned `codex/issue-2722-postgres-docs` | waits on plans 07–11 audit | two-file docs change, verification, commit, independent review | diff --git a/docs/execution/briefs/implement-plan-09.md b/docs/execution/briefs/implement-plan-09.md index ad849b967..69a76433b 100644 --- a/docs/execution/briefs/implement-plan-09.md +++ b/docs/execution/briefs/implement-plan-09.md @@ -19,12 +19,15 @@ Required execution: `docs/guides/undoing-changes-and-version-history.mdx`. - Document single-resume JSON, independent cover-letter JSON, and account archive differences; stable filenames; image URL availability; private-data/repository-visibility warning; local-only Git workflow; non-destructive import-as-new recovery; - rolling in-app versions versus owner-managed Git. Include plan's exact local-only command sequence. No automatic sync, - credentials, remote URL, `git push`, whole-account restore promise, or new product UI. + rolling in-app versions versus owner-managed Git. Correct planning prose before publication: every user-facing code block + must use ordinary `git init`, `git add -- ...`, `git diff`, `git commit`, and `git show`. Never publish agent-only + `rtk proxy git` commands. No automatic sync, credentials, remote URL, `git push`, whole-account restore promise, or new + product UI. - Use only synthetic data. Run API export/version tests specified by plan. Validate single-resume import round-trip using existing synthetic fixtures/tests or a bounded disposable test; never use private data. - Execute command sequence in `mktemp -d`, staging only `resume.json` and `cover-letter.json`; show changed visible field in - `git diff`. Do not modify global Git config if identity missing; record limitation. + `git diff`. Executor shell may wrap validation with `rtk proxy`, but copied documentation commands must remain plain Git. + Do not modify global Git config if identity missing; record limitation. - Run plan's focused `rg`, markdown lint, `git diff --check`, and two-file name-only gate. Self-review every acceptance item. - Commit with normal message. Leave branch local for independent review.