Files
DevRunbook-Public/docs/46-milestone-three-repository-profiles.md
DevRunbook release export cfd2804e27
Managed validation / full (push) Successful in 3m18s
Publish DevRunbook source
2026-09-03 04:09:17 +02:00

115 lines
6.8 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# 46 — Milestone 3 Repository Profiles evidence
## Outcome
Milestone 3 passed on 2026-07-27. The implementation spans commits `9401304`
through `76b28de`; the corrected production runtime was built from commit
`184af5c`. Authoritative validation used the isolated checkout
`/mnt/user/appdata/devrunbook-validation/m3` on Unraid 7.2 (`linux/amd64`),
Docker 27.5.1, Compose 2.40.3, Node.js 24.18.0 and PostgreSQL 17.9. The Windows
workstation's Node.js 23.7.0 results are supporting feedback only.
The application remains usable without Gitea. Repository commands are stored
only as inert, untrusted prompt context; this milestone adds no command
execution path.
## Delivered behavior
- A dedicated `@devrunbook/repository-intel` boundary strictly parses JSON and
YAML, rejects duplicate keys, aliases, custom tags, invalid UTF-8, oversized
input and unsafe path or command semantics, and returns exact JSON Pointer,
rule, message and remediation details.
- Canonical JSON and YAML export use deterministic line endings and content
digests. Imported source provenance is server-owned, and the supplied example
retains digest
`041e20f67e299665e85e5f14800a4bbcfa5e6c42ccdd7b22d29206e2c3f6727e`.
- Workspace-authorized application use cases provide list, detail, atomic
create, current-profile read, append-only revision and export operations.
Viewer/editor/owner permissions remain monotonic without an instance-admin
bypass.
- PostgreSQL stores repository identity separately from immutable profile
revisions. Revision number and lowercase SHA-256 invariants are database
checks; row locking and strong ETags serialize concurrent writes; semantic
no-ops do not create revisions.
- Generated runs retain their frozen repository-profile JSON after later
revisions. No mutable current-profile pointer can rewrite historical runs.
- Governed HTTP routes support manual JSON creation, raw JSON/YAML import,
listing/filtering/pagination, detail, current profile, conditional revision
append and deterministic JSON/YAML export. Mutations require same-origin and
profile updates require exact `If-Match`.
- The responsive authenticated UI includes repository overview, filters,
lifecycle/source badges, detail and provenance, explicit inert commands,
protected/generated/excluded paths, policies, deterministic exports and
viewer-only states.
- Manual and import creation plus full structured revision editing cover stack,
commands, paths, policies, required validation and preserved source facts.
Conflict handling keeps the local draft and requires explicit adopt-current
or reviewed rebase; it never silently overwrites.
- Repository revision, digest and protected paths are visibly carried into the
composer handoff. Full guided composition, prompt linting and final prompt
generation remain Milestone 4.
## Defect found by live validation
The first PostgreSQL repository integration run exposed an incorrectly
correlated summary subquery. Drizzle emitted `repository_id = id`, allowing the
inner revision table's `id` to shadow the outer repository identity, so a newly
created repository displayed `currentProfileRevision: null`. The summary query
now uses an explicit outer table alias and fully qualified correlated columns.
A generated-SQL unit regression test and all four live repository-store tests
prove the fix.
The broad integration command was initially invoked without the Milestone 0
suite's bootstrap state and `/content/playbooks` mount. Its three M0 fixtures
failed for those explicit missing preconditions; the independent repository
test exposed the real defect above. The final scoped PostgreSQL command ran the
four repository and three job/lease integration tests together and passed all
seven.
## Authoritative validation
| Command or check | Result |
| --- | --- |
| Frozen install and `pnpm verify` in the pinned Node 24.18.0 container | PASS: formatting, 14-workspace lint/typecheck/build, all unit tests, 28 P0 packages, 6 examples, 72 catalog entries, 9 schemas and 28 byte-identical prompts. |
| `pnpm test:security` | PASS: 2 files and 11 tests. |
| Repository intelligence tests | PASS: 23 semantic, parser, canonicalization, digest and import/export tests. |
| Application repository tests | PASS within 67 application tests, including actor matrix, server metadata, ETags, validation and immutable revision semantics. |
| Database unit tests | PASS: 41 tests; 7 environment-gated tests intentionally excluded from the unit command. |
| Live PostgreSQL integration | PASS: 2 files and 7 tests covering atomic create, workspace isolation, pagination, concurrent ETags, no-op suppression, frozen run snapshots, job fencing and stale-lease recovery. |
| Migration application and replay | PASS: migrations `0000`, `0001` and `0002` applied to an empty PostgreSQL 17.9 volume; a subsequent production startup replay exited successfully. |
| Database invariant drill | PASS: positive revision, lowercase 64-hex digest, immutable update, cascade and workspace-list index behavior. |
| Production Compose build/start | PASS: migrate completed; web, worker and PostgreSQL healthy. |
| Live API matrix | PASS: create, list summary revision, read/ETag, no-op `200`, revision `201`, stale `409`, missing precondition `428`, JSON/YAML export and re-import, traversal `422`, foreign-origin `403`. |
| Playwright production matrix | PASS: 4 tests passed and 2 deliberate duplicate-mutation skips across desktop Chromium and 390×844 narrow projects. |
| Full-stack restart | PASS: readiness recovered and repository/revision counts remained 9/13. |
| Container and log inspection | PASS: web and worker run as `node` with read-only roots; zero sensitive-pattern matches and zero error/fatal/exception matches. |
The browser matrix also proved zero console/page errors, keyboard command-palette
operation, persisted light theme, reduced-motion media behavior, no narrow
horizontal overflow, manual create/edit, protected-path display and repository
context in the composer.
## Requirement status
Completed with runtime, database and browser evidence:
- `FR-REP-001` through `FR-REP-008`.
Improved but not overstated:
- `FR-DET-007` and `FR-COM-002`: both profile-free and profile-bound handoffs
are available, and protected paths are visible, but the complete guided
composer remains Milestone 4.
## Operational notes
The validation environment and browser credentials remain outside the Git
checkout with restricted permissions. No password, cookie, token, session
secret, encryption key or database credential is recorded in this evidence.
The production validation stack is `devrunbook-m3-prod-927731a` at the existing
restricted Unraid validation location. Prior milestone volumes were preserved;
no unrelated server data was deleted.
No project-wide `release-evidence.json` or `FINAL_HANDOFF.md` is created at this
intermediate gate. Those artifacts remain reserved for final release evidence.