Merge branch 'feature/iop-agent-chronos-extraction-decoupling' into dev

This commit is contained in:
toki 2026-08-02 21:53:44 +09:00
commit 878c4fd6e2
9 changed files with 2101 additions and 1 deletions

View file

@ -60,7 +60,7 @@
- 완료 근거: `inventory`는 Task 03/16/10/13의 303행 historical baseline, corrected 300행 manifest, 137행 delta·addendum과 437행 effective matrix로 충족했다. `transfer`는 Task 04~06/16의 versioned bundle, 격리 behavior test, 12-record owner-state 이전과 digest evidence로 충족했다.
- 완료 근거: `decouple`·`retain-node`는 Task 07~10의 제거/audit·provider-only focused regression과 현재 금지 surface 재스캔으로, `handoff-gate`는 Task 13~15의 pre-deletion receipt·최종 삭제 evidence·tracked `HANDOFF.md` 복합 receipt로 충족했다.
- 완료 근거: 2026-08-02 fresh 검증에서 `go test -count=1 ./...`, `make client-test`(44 tests), `make client-build-web`, `make test-control-plane-edge-wire`, `make readability-audit`, initial/reconnect diagnostic, 삭제 surface scan과 `git diff --check`가 모두 통과했다. 삭제된 reconnect spec 포인터와 제거된 domain-agent UI 활성 정의는 현행 service test와 Node/provider operation UI 기준으로 바로 동기화했다.
- 완료 근거: staging task archive의 `17+15,16_canonical_promotion_closure/complete.log`가 세 차례 review loop와 최종 PASS를 기록하며, canonical [HANDOFF.md](../../../../../HANDOFF.md)가 승격 receipt를 보존한다. 검토된 승격은 canonical `dev``c8e98d4e10b30114de7bafe426a4045abd6c1205`에, provider-only 경계 정정은 `81243284cb89206911ec45e99f80701b591c88ae`에 반영됐다.
- 완료 근거: 최종 task archive의 [complete.log](../../../../../agent-task/archive/2026/08/m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/complete.log)가 세 차례 review loop와 최종 PASS를 기록하며, canonical [HANDOFF.md](../../../../../HANDOFF.md)가 승격 receipt를 보존한다. 검토된 승격은 canonical `dev``c8e98d4e10b30114de7bafe426a4045abd6c1205`에, provider-only 경계 정정은 `81243284cb89206911ec45e99f80701b591c88ae`에 반영됐다.
- Spec sync: Spec update not needed. [Edge-Node 실행](../../../../../agent-spec/runtime/edge-node-execution.md), [Provider Pool 설정 갱신](../../../../../agent-spec/runtime/provider-pool-config-refresh.md), [OpenAI-compatible 입력](../../../../../agent-spec/input/openai-compatible-surface.md), [Control Plane 운영](../../../../../agent-spec/control/control-plane-operations.md)의 상태와 evidence 포인터가 현행 구현과 일치한다.
- 검토 항목: 없음
- 리뷰 코멘트: canonical provider/Node Go tests, Flutter 44 tests, Control PlaneEdge wire smoke, Agent UI reconciliation, 충돌·whitespace 검사가 모두 통과했다. Milestone과 SDD를 archive하고 Chronos `rely-on``enable`로 전환했다.

View file

@ -0,0 +1,344 @@
<!-- task=m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure plan=2 tag=REVIEW_REFACTOR milestone-task=handoff-gate -->
# Code Review Reference - REVIEW_REFACTOR
> **[IMPLEMENTING AGENT — READ FIRST] Filling in this file is the mandatory final step of implementation.**
> The task is NOT complete until every implementation-owned section below is filled in.
> Complete the `Implementation Checklist`; the final checklist item is mandatory before saving.
> Fill implementation-owned sections, then stop with active files in place and report ready for review.
> If implementation is blocked, record the exact blocker, attempted commands/output, and resume condition only in implementation-owned evidence fields.
> Do not ask the user directly, present choices, call user-input tools, create control-plane stop files, or classify the next state.
> Finalization (`Code Review Result`, log rename, `complete.log`, archive moves, `Review-Only Checklist`) is review-agent-only, even after compaction/resume.
> Follow the ownership table at the bottom of this file for which sections you own.
## Overview
date=2026-08-02
task=m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure, plan=2, tag=REVIEW_REFACTOR
## Archive Evidence Snapshot
- `agent-task/m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/code_review_cloud_G10_0.log` recorded the first FAIL because canonical promotion had not occurred.
- `agent-task/m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/code_review_cloud_G10_1.log` records the current FAIL: promotion commit `c8e98d4e10b30114de7bafe426a4045abd6c1205`, the 34-path conflict digest, recovery artifacts, fresh regressions, mirroring, and the disabled lock were verified, but three active source descriptions still claim Agent/terminal ownership.
- The Required finding affects `packages/go/execution/doc.go`, `packages/go/execution/types.go`, and `apps/node/cmd/node/main.go`; `apps/node/cmd/node/main_test.go` is the focused regression target. The current canonical and staging source text is identical at each affected hunk, while canonical `types.go` intentionally retains unrelated credential support absent from staging.
- Roadmap carryover remains unchanged: the Milestone is review-open, the Chronos dependency lock remains `disable`, and this task must not archive the Milestone, enable the lock, push either branch, or mutate Chronos or any remote repository.
## For the Review Agent
> **[REVIEW AGENT ONLY]** The finalization steps below are review-agent only. Implementing agents must not execute this section.
Compare implementation of each item against source files and verify that output in `Verification Results` matches code.
Review completion means the following steps are finished:
1. Append verdict and `review_rework_count` / `evidence_integrity_failure` routing signals.
2. Archive `CODE_REVIEW-cloud-G08.md` → `code_review_cloud_G08_2.log` and `PLAN-cloud-G08.md` → `plan_cloud_G08_2.log`.
3. If PASS, write `complete.log` and move active task directory to `agent-task/archive/YYYY/MM/m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/`. If WARN/FAIL, fully write the next filesystem state required by the code-review skill.
4. If PASS and task group is `m-iop-agent-chronos-extraction-decoupling`, preserve the first-line `milestone-task` metadata in `complete.log` and report it for the runtime aggregation event. Roadmap state evaluation belongs to `sync-milestone-workstate`.
5. Check applicable `Review-Only Checklist` items at the final `.log` location before reporting.
---
## Implementation Item Completion
| Item | Status |
|------|---------|
| REVIEW_REFACTOR-1 — Correct provider-only source wording and add a focused regression | [x] |
| REVIEW_REFACTOR-2 — Commit and record equivalent corrective closure | [x] |
## Implementation Checklist
- [x] Correct the provider-only ownership wording in staging and canonical source, and add the focused Node CLI regression test.
- [x] Create exact staging/canonical corrective commits, update mirrored HANDOFF evidence, and verify protected state, ancestry, recovery, and lock preservation.
- [x] Fill implementation-owned sections in CODE_REVIEW-*-G??.md with actual implementation notes and verification output.
## Review-Only Checklist
> **[REVIEW AGENT ONLY]** This checklist is used only by the review agent.
> Implementing agents must not modify or check this section.
- [x] Append one verdict of `PASS`, `WARN`, or `FAIL` and verified `review_rework_count`, `evidence_integrity_failure` to `Code Review Result`.
- [x] Verify that verdict, `Dimension Assessment`, and Required/Suggested/Nit classifications match.
- [x] Archive active `CODE_REVIEW-*-G??.md` to `code_review_cloud_G08_2.log`.
- [x] Archive active `PLAN-*-G??.md` to `plan_cloud_G08_2.log`.
- [x] Verify that the Agent-Ops managed block in `.gitignore` unignores `agent-task/**/*.md` and `agent-task/**/*.log` and ignores `agent-roadmap/current.md`.
- [x] If PASS, write `complete.log` based on `agent-ops/skills/common/code-review/templates/complete-log-template.md` and leave no active `.md` files.
- [x] If PASS, move active task directory `agent-task/m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/` to `agent-task/archive/YYYY/MM/m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/` and update this checklist at the final archive path.
- [x] If PASS and task group is `m-iop-agent-chronos-extraction-decoupling`, preserve and report `milestone-task` metadata for runtime aggregation, without modifying roadmap or directly calling `update-roadmap`.
- [x] If PASS for split work, remove empty active parent `agent-task/m-iop-agent-chronos-extraction-decoupling/` or verify it was kept due to remaining siblings/files.
- [ ] If WARN/FAIL, write the next filesystem state matching code-review verdict and do not write `complete.log`.
## Deviations from Plan
No verification command was replaced; the plan's command set was executed exactly. Additive, non-substitutive notes only:
- `mkdir -p .tmp` was run once in each checkout before `go test` because the plan's `TMPDIR="$PWD/.tmp" GOTMPDIR="$PWD/.tmp"` requires the directory to exist; `.tmp` is gitignored in both checkouts and does not appear in either dirty inventory.
- The REVIEW_REFACTOR-1 block and the REVIEW_REFACTOR-2 closure block were run both as-written and with added `echo` labels / `set -e` grouping for readable per-assertion evidence. The underlying commands are unchanged; the verbatim closure block was also run in full and reached exit 0 (see the consolidated evidence).
- A supplementary `go test -count=1 -v -run TestRootCmdUsesProviderOnlyDescription ./apps/node/cmd/node` was run in staging solely to show the new regression executing; it is additional evidence, not a replacement for the plan's package-level `go test`.
## Key Design Decisions
- The three wording corrections and the new `TestRootCmdUsesProviderOnlyDescription` were applied as byte-identical hunks in both checkouts. `doc.go`, `main.go`, and `main_test.go` are byte-identical across staging and canonical after the edit; `types.go` differs only by canonical's pre-existing `ProviderCredential` block, which was left untouched, so the changed hunk (the `ErrRunCancelled` comment) is identical and the two commits share stable patch id `2e89dc0ed8a45542531af2e16efaf397dd3b2602`.
- The regression guards the user-visible `rootCmd().Short` (case-insensitive `provider` required, `agent` rejected) rather than parsing Go comments, matching the plan's oracle: executable test for the CLI string, deterministic forbidden-text scan for the two non-executable documentation comments.
- The corrective work was recorded as one child commit per checkout on top of the reviewed promotion/staging commits rather than by amending them, preserving the reviewed promotion identity, the recovery stash objects, and the full-regression receipt. Only the four source/test paths were staged; canonical's seven protected dirty paths (HANDOFF.md, three roadmap files, three Agent UI files) were left unstaged.
- HANDOFF.md was edited once in staging and mirrored to canonical with `cp` to guarantee byte equality, and canonical HANDOFF.md was left unstaged so promotion, recovery, and full-regression receipt evidence remains intact while the new correction identities are added.
- Commit subjects follow each checkout's existing promotion-commit language (staging Korean, canonical English); commit messages do not affect patch id, path set, or any closure assertion.
## Reviewer Checkpoints
- Confirm the three production descriptions use provider-only, run-scoped language in both checkouts and the Node regression rejects Agent wording.
- Confirm each corrective commit has its required parent and exact four-path change set, and the stable patch ids match without overwriting canonical-only credential code.
- Confirm both HANDOFF copies identify the actual corrective commits while retaining the reviewed promotion, recovery, and full-regression receipt.
- Confirm canonical keeps exactly its protected seven unstaged paths, both indexes and unmerged sets are empty, Agent UI mirrors match, and the Chronos lock remains `disable`.
## Verification Results
Paste actual stdout/stderr beneath each command block. If output is long, record the exact saved output path and the exact command that created it. If a command changes, record the replacement and reason in `Deviations from Plan`. Fresh Go results are required.
### REVIEW_REFACTOR-1 — Source wording and focused regression in staging
Run from `/config/workspace/iop-s1`:
```bash
gofmt -w packages/go/execution/doc.go packages/go/execution/types.go apps/node/cmd/node/main.go apps/node/cmd/node/main_test.go
if rg --sort path -n -i 'standalone agent|terminal session primitives|terminating the session|IOP Node Agent' packages/go/execution/doc.go packages/go/execution/types.go apps/node/cmd/node/main.go; then exit 1; fi
rg --sort path -n 'provider-only|single run is cancelled|IOP Node — runs provider executions' packages/go/execution/doc.go packages/go/execution/types.go apps/node/cmd/node/main.go
TMPDIR="$PWD/.tmp" GOTMPDIR="$PWD/.tmp" go test -count=1 ./packages/go/execution ./apps/node/cmd/node
git diff --check
```
_Actual output:_
```text
=== gofmt -w ===
gofmt exit: 0
=== forbidden-text scan ===
FORBIDDEN_NONE # rg found no match on doc.go, types.go, main.go
=== required provider/run-scoped text ===
packages/go/execution/doc.go:1:// Package execution contains provider-only, host-neutral execution contracts
packages/go/execution/types.go:1:// Package execution defines provider-only execution contracts shared by Node
packages/go/execution/types.go:15:// ErrRunCancelled is returned by providers when a single run is cancelled.
apps/node/cmd/node/main.go:29: Short: "IOP Node — runs provider executions on this device",
=== go test ===
ok iop/packages/go/execution 0.009s
ok iop/apps/node/cmd/node 0.045s
go test exit: 0
=== git diff --check ===
git diff --check exit: 0
# Supplementary (staging-only) confirmation of the new regression:
# go test -count=1 -v -run TestRootCmdUsesProviderOnlyDescription ./apps/node/cmd/node
=== RUN TestRootCmdUsesProviderOnlyDescription
--- PASS: TestRootCmdUsesProviderOnlyDescription (0.00s)
PASS
ok iop/apps/node/cmd/node 0.056s
```
### REVIEW_REFACTOR-1 — Source wording and focused regression in canonical
Run from `/config/workspace/iop`:
```bash
gofmt -w packages/go/execution/doc.go packages/go/execution/types.go apps/node/cmd/node/main.go apps/node/cmd/node/main_test.go
if rg --sort path -n -i 'standalone agent|terminal session primitives|terminating the session|IOP Node Agent' packages/go/execution/doc.go packages/go/execution/types.go apps/node/cmd/node/main.go; then exit 1; fi
rg --sort path -n 'provider-only|single run is cancelled|IOP Node — runs provider executions' packages/go/execution/doc.go packages/go/execution/types.go apps/node/cmd/node/main.go
TMPDIR="$PWD/.tmp" GOTMPDIR="$PWD/.tmp" go test -count=1 ./packages/go/execution ./apps/node/cmd/node
git diff --check
```
_Actual output:_
```text
=== gofmt -w ===
gofmt exit: 0
=== forbidden-text scan ===
FORBIDDEN_NONE # rg found no match on doc.go, types.go, main.go
=== required text ===
packages/go/execution/doc.go:1:// Package execution contains provider-only, host-neutral execution contracts
packages/go/execution/types.go:1:// Package execution defines provider-only execution contracts shared by Node
packages/go/execution/types.go:15:// ErrRunCancelled is returned by providers when a single run is cancelled.
apps/node/cmd/node/main.go:29: Short: "IOP Node — runs provider executions on this device",
=== go test ===
ok iop/packages/go/execution 0.009s
ok iop/apps/node/cmd/node 0.046s
go test exit: 0
=== git diff --check ===
git diff --check exit: 0
```
_Cross-checkout byte equality of the changed files (before commit):_ `cmp` reports `doc.go`, `main.go`, and `main_test.go` byte-identical across `/config/workspace/iop` and `/config/workspace/iop-s1`; `types.go` differs only by canonical's pre-existing `ProviderCredential` block, and the changed hunk (line 15) is identical in both.
### REVIEW_REFACTOR-2 — Preflight
Run from `/config/workspace/iop-s1` before editing or committing:
```bash
test "$(git rev-parse HEAD)" = 7b90b7e5af9035fae2b5349c65eb322096d21b1b
test -z "$(git diff --cached --name-only)"
test -z "$(git ls-files -u)"
test "$(git -C /config/workspace/iop rev-parse HEAD)" = c8e98d4e10b30114de7bafe426a4045abd6c1205
test -z "$(git -C /config/workspace/iop diff --cached --name-only)"
test -z "$(git -C /config/workspace/iop ls-files -u)"
diff -u <(printf '%s\n' HANDOFF.md agent-roadmap/phase/automation-runtime-bridge/PHASE.md agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md agent-roadmap/priority-queue.md agent-ui/.sync-state.json agent-ui/definition/components/console-shell/index.md agent-ui/definition/components/index.md) <(git -C /config/workspace/iop diff --name-only | sort)
```
_Actual output:_ (captured before any mutation; all assertions passed)
```text
=== staging HEAD ===
7b90b7e5af9035fae2b5349c65eb322096d21b1b
=== staging cached ===
(empty)
=== staging unmerged ===
(empty)
=== canonical HEAD ===
c8e98d4e10b30114de7bafe426a4045abd6c1205
=== canonical cached ===
(empty)
=== canonical unmerged ===
(empty)
=== canonical dirty inventory diff ===
CANONICAL_DIRTY_MATCH # diff -u produced no differences; the 7 protected paths match exactly
```
Tool versions confirmed present: `git version 2.43.0`, `go version go1.26.2 linux/arm64`.
### REVIEW_REFACTOR-2 — Commit, receipt, state, and lock closure
Run from `/config/workspace/iop-s1` after both commits and the mirrored receipt update:
```bash
staging_correction="$(git rev-parse HEAD)"
canonical_correction="$(git -C /config/workspace/iop rev-parse HEAD)"
test "$(git rev-parse HEAD^)" = 7b90b7e5af9035fae2b5349c65eb322096d21b1b
test "$(git -C /config/workspace/iop rev-parse HEAD^)" = c8e98d4e10b30114de7bafe426a4045abd6c1205
expected_paths="$(printf '%s\n' apps/node/cmd/node/main.go apps/node/cmd/node/main_test.go packages/go/execution/doc.go packages/go/execution/types.go)"
test "$(git diff-tree --no-commit-id --name-only -r HEAD | sort)" = "$expected_paths"
test "$(git -C /config/workspace/iop diff-tree --no-commit-id --name-only -r HEAD | sort)" = "$expected_paths"
test "$(git diff 7b90b7e5af9035fae2b5349c65eb322096d21b1b..HEAD -- $expected_paths | git patch-id --stable | awk '{print $1}')" = "$(git -C /config/workspace/iop diff c8e98d4e10b30114de7bafe426a4045abd6c1205..HEAD -- $expected_paths | git patch-id --stable | awk '{print $1}')"
test -z "$(git diff --cached --name-only)"
test -z "$(git -C /config/workspace/iop diff --cached --name-only)"
test -z "$(git ls-files -u)"
test -z "$(git -C /config/workspace/iop ls-files -u)"
diff -u <(printf '%s\n' HANDOFF.md agent-roadmap/phase/automation-runtime-bridge/PHASE.md agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md agent-roadmap/priority-queue.md agent-ui/.sync-state.json agent-ui/definition/components/console-shell/index.md agent-ui/definition/components/index.md) <(git -C /config/workspace/iop diff --name-only | sort)
cmp /config/workspace/iop/HANDOFF.md HANDOFF.md
test "$(sed -n 's/^staging_boundary_correction_commit: //p' HANDOFF.md)" = "$staging_correction"
test "$(sed -n 's/^canonical_boundary_correction_commit: //p' HANDOFF.md)" = "$canonical_correction"
git -C /config/workspace/iop merge-base --is-ancestor c8e98d4e10b30114de7bafe426a4045abd6c1205 "$canonical_correction"
git -C /config/workspace/iop cat-file -e a91e4af2bc23c7fab2ef0ea026e2b453e9393848^{commit}
git -C /config/workspace/iop cat-file -e ff81ecb5e8b16fc81ecce4273afe24ff06236287^{commit}
cmp /config/workspace/iop/agent-ui/.sync-state.json agent-ui/.sync-state.json
cmp /config/workspace/iop/agent-ui/definition/components/console-shell/index.md agent-ui/definition/components/console-shell/index.md
cmp /config/workspace/iop/agent-ui/definition/components/index.md agent-ui/definition/components/index.md
agent-ops/bin/roadmap-dependency-checker.sh --find-milestone 'iop:agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md' both /config/workspace/.agent-roadmap-sync/locks.yaml
rg -n -A4 'id: chronos:chronos-architecture-ownership-boundary' /config/workspace/.agent-roadmap-sync/locks.yaml
```
_Actual output:_
Corrective commits created — staging `7cc9f2d142fac863eff173515f2a81e0a5c9e0f4` (parent `7b90b7e5...`), canonical `81243284cb89206911ec45e99f80701b591c88ae` (parent `c8e98d4e...`). Per-assertion evidence:
```text
staging_correction=7cc9f2d142fac863eff173515f2a81e0a5c9e0f4
canonical_correction=81243284cb89206911ec45e99f80701b591c88ae
--- parents ---
staging parent OK # HEAD^ == 7b90b7e5af9035fae2b5349c65eb322096d21b1b
canonical parent OK # HEAD^ == c8e98d4e10b30114de7bafe426a4045abd6c1205
--- change sets ---
staging change-set OK # HEAD touches exactly the four paths
canonical change-set OK # HEAD touches exactly the four paths
--- patch-id equivalence ---
patch-id OK # both == 2e89dc0ed8a45542531af2e16efaf397dd3b2602
--- clean indexes / unmerged ---
staging index clean
canonical index clean
staging no unmerged
canonical no unmerged
--- canonical protected dirty inventory ---
canonical dirty inventory OK # diff -u empty; 7 protected paths unchanged
--- HANDOFF byte equality ---
HANDOFF cmp OK
--- receipt fields resolve to actual commits ---
staging field OK # staging_boundary_correction_commit == 7cc9f2d1...
canonical field OK # canonical_boundary_correction_commit == 81243284...
--- promotion ancestry ---
promotion ancestry OK # c8e98d4e... is ancestor of 81243284...
--- retained recovery stash objects ---
recovery stash initial OK # a91e4af2bc23c7fab2ef0ea026e2b453e9393848 exists
recovery stash prepromotion OK # ff81ecb5e8b16fc81ecce4273afe24ff06236287 exists
--- Agent UI mirrors ---
sync-state OK
console-shell OK
components index OK
=== roadmap dependency checker ===
rely-on:chronos:chronos-architecture-ownership-boundary
checker exit: 0
=== chronos lock block ===
7:- id: chronos:chronos-architecture-ownership-boundary
8- locked: chronos:agent-roadmap/phase/runtime-ownership-transition/milestones/chronos-architecture-ownership-boundary.md
9- rely-on:
10- - target: iop:agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md
11- status: disable
```
The exact CODE_REVIEW closure block above was also re-run verbatim (no echo labels, `set -e`) and reached exit 0 with only the dependency-checker line and the lock block on stdout, confirming every `test`/`cmp`/`diff`/`cat-file`/`merge-base` assertion passed.
### Final Verification
Run every REVIEW_REFACTOR-1 command from both checkouts and every REVIEW_REFACTOR-2 command in the stated order. Require fresh focused Go PASS, no forbidden ownership text, exact corrective commit parents/path sets/patch equivalence, clean indexes and unmerged state, canonical protected dirty paths preserved, byte-identical HANDOFF/UI evidence, retained recovery commit objects, promotion ancestry, and a disabled Chronos lock.
_Actual consolidated evidence:_
Fresh focused Go tests and forbidden-text scans were re-run on the committed heads of both checkouts:
```text
########## STAGING (committed HEAD) ##########
HEAD=7cc9f2d142fac863eff173515f2a81e0a5c9e0f4
FORBIDDEN_NONE
ok iop/packages/go/execution 0.013s
ok iop/apps/node/cmd/node 0.070s
diff-check OK
########## CANONICAL (committed HEAD) ##########
HEAD=81243284cb89206911ec45e99f80701b591c88ae
FORBIDDEN_NONE
ok iop/packages/go/execution 0.024s
ok iop/apps/node/cmd/node 0.043s
diff-check OK
```
Consolidated result: fresh focused Go tests PASS in both checkouts; no forbidden ownership text remains in the three production files; both corrective commits have the exact required parents, the exact four-path change set, and matching stable patch id `2e89dc0ed8a45542531af2e16efaf397dd3b2602`; both indexes and unmerged sets are empty; canonical retains exactly its seven protected unstaged paths; HANDOFF.md and the three Agent UI mirrors are byte-identical across checkouts; recovery stash objects `a91e4af2...` and `ff81ecb5...` and the promotion commit `c8e98d4e...` remain intact with `c8e98d4e...` an ancestor of the canonical correction; the Chronos dependency lock remains `disable`. Neither branch was pushed, and Chronos/remote repositories were not mutated.
---
> **[IMPLEMENTING AGENT — BEFORE SAVING] Have you filled in every implementation-owned section?**
> If anything is blank, go back and fill it in before saving this file.
> Leave review-agent-only sections unchanged.
## Section Ownership
| Section | Owner | Note |
|---------|-------|------|
| Header comment, Overview, Review Agent Instructions | Fixed at stub creation | Implementing agent must not modify or execute these (archive, complete.log, and task-directory archive move are review-agent only) |
| Archive Evidence Snapshot | Fixed at stub creation from plan when present | Implementing agent uses it as default prior-loop context; read only the specific archive files cited there when more detail is required |
| Implementation Item Completion (item names) | Fixed at stub creation | Implementing agent checks `[ ]` → `[x]` only |
| Implementation Checklist (item text/order) | Fixed at stub creation from plan | Implementing agent checks `[ ]` → `[x]` only |
| Review-Only Checklist | Review agent only | Implementing agent must not modify or check this section |
| Deviations from Plan, Key Design Decisions | Implementing agent | Replace placeholder text with actual content |
| Reviewer Checkpoints | Fixed at stub creation | Pre-filled from plan |
| Verification Results (section headings + commands) | Fixed at stub creation | Implementing agent fills in command output only; command changes require a `Deviations from Plan` entry |
| Code Review Result | Review agent appends | Not included in stub |
## Code Review Result
- Overall Verdict: PASS
- Dimension Assessment:
- Correctness: Pass — both corrective commits contain the intended provider-only wording and focused CLI regression, with identical logical patches and no unintended canonical credential change.
- Completeness: Pass — REVIEW_REFACTOR-1 and REVIEW_REFACTOR-2 are implemented, the mirrored receipt contains both actual corrective commit identities, and all inherited Required findings are closed.
- Test Coverage: Pass — fresh focused tests passed in both checkouts, the new CLI regression executed successfully, and the broader Node, platform-common, execution race, and vet checks passed.
- API Contract: Pass — package and CLI descriptions now match the provider-only execution contract without changing any runtime symbol, wire field, or caller behavior.
- Code Quality: Pass — the four-path commits are focused, formatted, free of stale forbidden wording, and preserve canonical-only credential support and protected worktree state.
- Implementation Deviation: Pass — documented additive verification labels and temporary test-directory setup do not replace or weaken any planned command or acceptance condition.
- Verification Trust: Pass — fresh review reproduced both HEADs and parents, exact path sets, stable patch id, receipt fields, ancestry, recovery objects, clean indexes, protected dirty inventory, UI mirrors, origin state, and disabled lock.
- Spec Conformance: Pass — the corrected descriptions and regression satisfy SDD S04 provider-only ownership and preserve the S05 handoff, rollback, and downstream-lock traceability chain.
- Findings: None
- Routing Signals: `review_rework_count=2`, `evidence_integrity_failure=false`
- Next Step: Write `complete.log`, archive this PASS task under `agent-task/archive/2026/08/`, and emit milestone completion metadata for runtime aggregation without modifying the roadmap.

View file

@ -0,0 +1,301 @@
<!-- task=m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure plan=0 tag=REFACTOR milestone-task=handoff-gate -->
# Code Review Reference - REFACTOR
> **[IMPLEMENTING AGENT — READ FIRST] Filling in this file is the mandatory final step of implementation.**
> The task is NOT complete until every implementation-owned section below is filled in.
> Complete the `Implementation Checklist`; the final checklist item is mandatory before saving.
> Fill implementation-owned sections, then stop with active files in place and report ready for review.
> If implementation is blocked, record the exact blocker, attempted commands/output, and resume condition only in implementation-owned evidence fields.
> Do not ask the user directly, present choices, call user-input tools, create control-plane stop files, or classify the next state.
> Finalization (`Code Review Result`, log rename, `complete.log`, archive moves, `Review-Only Checklist`) is review-agent-only, even after compaction/resume.
> Follow the ownership table at the bottom of this file for which sections you own.
## Overview
date=2026-08-02
task=m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure, plan=0, tag=REFACTOR
## Archive Evidence Snapshot
- `agent-task/archive/2026/08/m-iop-agent-chronos-extraction-decoupling/15+14_handoff_closure/complete.log`: PASS; the tracked final composite receipt and exact `HANDOFF.md` digest were accepted after Task 14 removal evidence.
- `agent-task/archive/2026/08/m-iop-agent-chronos-extraction-decoupling/16_manifest_baseline_repair/complete.log`: PASS; corrected pinned-transfer manifest baseline is 300 rows (`file=290`, `state=10`, `retain-generic=135`) with SHA-256 `d8598134dee99d96fc05a045091dd3d8932d4708d2c980c2a78c8b11825d2ccf`.
- No Required, Suggested, or Nit findings remain in those predecessor completion records. This plan does not reinterpret archived evidence; it promotes the already accepted result and records the canonical identity.
## For the Review Agent
> **[REVIEW AGENT ONLY]** The finalization steps below are review-agent only. Implementing agents must not execute this section.
Compare implementation of each item against source files and verify that output in `Verification Results` matches code.
Review completion means the following steps are finished:
1. Append verdict and `review_rework_count` / `evidence_integrity_failure` routing signals.
2. Archive `CODE_REVIEW-cloud-G10.md` → `code_review_cloud_G10_0.log` and `PLAN-cloud-G10.md` → `plan_cloud_G10_0.log`.
3. If PASS, write `complete.log` and move active task directory to `agent-task/archive/YYYY/MM/m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/`. If WARN/FAIL, fully write the next filesystem state required by the code-review skill.
4. If PASS and task group is `m-iop-agent-chronos-extraction-decoupling`, preserve the first-line `milestone-task` metadata in `complete.log` and report it for the runtime aggregation event. Roadmap state evaluation belongs to `sync-milestone-workstate`.
5. Check applicable `Review-Only Checklist` items at the final `.log` location before reporting.
---
## Implementation Item Completion
| Item | Status |
|------|---------|
| REFACTOR-1 Protect canonical state and apply the reviewed staging commit | [ ] |
| REFACTOR-2 Prove canonical closure readiness and reconcile Agent UI | [ ] |
| REFACTOR-3 Record exact promotion evidence without opening the lock | [ ] |
| REFACTOR-4 Run final guarded verification and retain rollback evidence | [ ] |
## Implementation Checklist
- [ ] Freeze and promote the reviewed staging change set into canonical IOP without losing the canonical roadmap patch.
- [ ] Verify canonical code, contracts, UI, and provider-only boundaries, then reconcile milestone-scoped Agent UI state while keeping the Chronos lock disabled.
- [ ] Record exact staging/canonical promotion evidence in HANDOFF.md and mirror reconciled UI evidence in this workspace.
- [ ] Run the complete final verification matrix and preserve recovery evidence.
- [x] Fill implementation-owned sections in CODE_REVIEW-*-G??.md with actual implementation notes and verification output.
## Review-Only Checklist
> **[REVIEW AGENT ONLY]** This checklist is used only by the review agent.
> Implementing agents must not modify or check this section.
- [x] Append one verdict of `PASS`, `WARN`, or `FAIL` and verified `review_rework_count`, `evidence_integrity_failure` to `Code Review Result`.
- [x] Verify that verdict, `Dimension Assessment`, and Required/Suggested/Nit classifications match.
- [x] Archive active `CODE_REVIEW-*-G??.md` to `code_review_cloud_G10_0.log`.
- [x] Archive active `PLAN-*-G??.md` to `plan_cloud_G10_0.log`.
- [x] Verify that the Agent-Ops managed block in `.gitignore` unignores `agent-task/**/*.md` and `agent-task/**/*.log` and ignores `agent-roadmap/current.md`.
- [ ] If PASS, write `complete.log` based on `agent-ops/skills/common/code-review/templates/complete-log-template.md` and leave no active `.md` files.
- [ ] If PASS, move active task directory `agent-task/m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/` to `agent-task/archive/YYYY/MM/m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/` and update this checklist at the final archive path.
- [ ] If PASS and task group is `m-iop-agent-chronos-extraction-decoupling`, preserve and report `milestone-task` metadata for runtime aggregation, without modifying roadmap or directly calling `update-roadmap`.
- [ ] If PASS for split work, remove empty active parent `agent-task/m-iop-agent-chronos-extraction-decoupling/` or verify it was kept due to remaining siblings/files.
- [x] If WARN/FAIL, write the next filesystem state matching code-review verdict and do not write `complete.log`.
## Deviations from Plan
- The active `17+15,16_canonical_promotion_closure` PLAN/review pair was excluded from the staging promotion commit because it is the unreviewed control artifact for this implementation run. The reviewed predecessor change set and evidence were committed; the active pair remains in place as required.
- `git diff --cached --check` reported trailing spaces in immutable archived terminal-output logs. Those archive bytes were preserved because they are accepted evidence snapshots. The non-archive staged diff passed `git diff --cached --check -- . ':(exclude)agent-task/archive/**'`.
- The guarded cherry-pick produced 34 conflicts rather than the three roadmap conflicts authorized by the plan. The staging parent `1debc7ada01d98442560bbc4ac52dcef9cae25cc` is an ancestor of current `origin/dev` `c3a24ec5febab9fc978fd62392efcb6c96e12ec9`, but 324 paths changed between them. The cherry-pick was aborted instead of applying an unplanned source/contract/proto conflict policy.
- The REFACTOR-3 and final cross-workspace diagnostics allowed the expected missing `canonical_promotion: applied` match to return nonzero so the lock and recovery state could still be captured after the blocker. They are blocker diagnostics, not passing substitutes for the fixed gates.
## Key Design Decisions
- Created local staging promotion commit `7b90b7e5af9035fae2b5349c65eb322096d21b1b` with 608 staged paths (620 paths reported with rename expansion) and did not push because push was not authorized.
- Stopped at the first out-of-plan conflict boundary. No conflict was resolved by choosing `ours` or `theirs`, and no canonical source, contract, proto, Agent UI, HANDOFF promotion field, or workspace lock was changed by the failed cherry-pick.
- Retained two byte-identical recovery copies of the original canonical roadmap patch: `/tmp/iop-canonical-promotion.QOCOar/canonical-roadmap.patch` and named stash `stash@{0}` (`iop-canonical-promotion-roadmap-20260802T102956Z`), both SHA-256 `1f1afe533e910b6311390071e07799bf6cc24ca742853bb45a3eceb3da1d4575`.
- After aborting the cherry-pick, canonical remains at fast-forwarded `origin/dev` commit `c3a24ec5febab9fc978fd62392efcb6c96e12ec9`, and the protected three-file roadmap patch was reapplied from the retained stash. The Chronos dependency remains `disable`.
- Resume condition: re-plan the promotion against `origin/dev` `c3a24ec5febab9fc978fd62392efcb6c96e12ec9` by first producing a reviewed staging commit based on that upstream state, or provide an explicit reviewed resolution policy for all 34 conflicts. Then retry canonical promotion before running closure, Agent UI reconciliation, HANDOFF promotion recording, or final regressions.
## Reviewer Checkpoints
- Confirm the staging promotion commit is backed by the previously accepted Task 15/16 evidence and contains the intended milestone change set.
- Confirm canonical user-owned `[separation-01]` and priority-queue edits were preserved through fetch/cherry-pick/reconciliation.
- Compare promoted non-roadmap source and contract trees; reject unexplained divergence or unmerged paths.
- Verify fresh canonical Go, Flutter, Control Plane/Edge wire, reconnect, readability, and forbidden-surface results.
- Verify Agent UI reconciliation occurred only after check-only closure readiness and both status/index/sync-state agree.
- Verify both handoff copies record actual commit identities and preserve every prior receipt/digest.
- Verify the parent Chronos lock remains disabled and the milestone remains active for a subsequent `complete-milestone` archive transaction.
- Verify the saved canonical patch and named stash remain recoverable and their locators/digest are recorded.
## Verification Results
Paste actual stdout/stderr below each command. If output is too long, record the exact saved-output path and the command that created it. Any replacement command requires a matching entry in `Deviations from Plan`.
### REFACTOR-1 Canonical state and merge checks
```bash
git -C /config/workspace/iop status -sb
git -C /config/workspace/iop diff --name-only | LC_ALL=C sort
git -C /config/workspace/iop diff --check
git -C /config/workspace/iop diff --name-only --diff-filter=U
```
_Actual output:_
```text
BLOCKED before promotion completion.
Guarded cherry-pick:
staging promotion commit: 7b90b7e5af9035fae2b5349c65eb322096d21b1b
canonical fast-forward HEAD: c3a24ec5febab9fc978fd62392efcb6c96e12ec9
cherry-pick result: conflict (34 paths; plan authorized only three roadmap conflicts)
exact conflict list: /tmp/iop-canonical-promotion.QOCOar/unexpected-conflicts.txt
conflict-list SHA-256: 15e564744e83accd74981a5976432d14d8638815cab0fefc1d1eaabe97a4aca4
recovery action: git cherry-pick --abort; git stash apply stash@{0}
Current canonical state after recovery:
## dev...origin/dev
M agent-roadmap/phase/automation-runtime-bridge/PHASE.md
M agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md
M agent-roadmap/priority-queue.md
agent-roadmap/phase/automation-runtime-bridge/PHASE.md
agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md
agent-roadmap/priority-queue.md
`git diff --check`: exit 0, no output.
`git diff --name-only --diff-filter=U`: exit 0, no output.
Canonical promotion commit does not exist because the guarded cherry-pick was aborted.
```
### REFACTOR-2 Canonical runtime and UI checks
Run from `/config/workspace/iop`:
```bash
mkdir -p /config/workspace/iop/.tmp
TMPDIR=/config/workspace/iop/.tmp GOTMPDIR=/config/workspace/iop/.tmp go test -count=1 ./...
make client-test
make client-build-web
make test-control-plane-edge-wire
make readability-audit
IOP_DEV_RECONNECT_BIND_TIMEOUT=60 scripts/dev/edge-node-reconnect-diagnostic.sh
```
_Actual output:_
```text
BLOCKED — not run. Canonical runtime verification is not valid until a reviewed promotion commit is applied without unresolved upstream conflicts.
Resume after the 34-conflict upstream integration policy is reviewed and canonical promotion succeeds.
```
### REFACTOR-3 Promotion identity and lock checks
Run from `/config/workspace/iop-s1`:
```bash
git -C /config/workspace/iop rev-parse --verify HEAD^{commit}
git -C /config/workspace/iop-s1 rev-parse --verify HEAD^{commit}
rg -n '^canonical_promotion: applied$|^staging_promotion_commit: [0-9a-f]{40}$|^canonical_promotion_commit: [0-9a-f]{40}$|^canonical_promotion_verified_at: ' /config/workspace/iop/HANDOFF.md HANDOFF.md
agent-ops/bin/roadmap-dependency-checker.sh --find-milestone 'iop:agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md' both /config/workspace/.agent-roadmap-sync/locks.yaml
```
_Actual output:_
```text
c3a24ec5febab9fc978fd62392efcb6c96e12ec9
7b90b7e5af9035fae2b5349c65eb322096d21b1b
No `canonical_promotion: applied`, staging/canonical promotion commit, or verification timestamp fields matched because promotion was aborted.
rely-on:chronos:chronos-architecture-ownership-boundary
Lock excerpt:
7:- id: chronos:chronos-architecture-ownership-boundary
8- locked: chronos:agent-roadmap/phase/runtime-ownership-transition/milestones/chronos-architecture-ownership-boundary.md
9- rely-on:
10- - target: iop:agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md
11- status: disable
```
### Final canonical regression
Run from `/config/workspace/iop`:
```bash
mkdir -p /config/workspace/iop/.tmp
TMPDIR=/config/workspace/iop/.tmp GOTMPDIR=/config/workspace/iop/.tmp go test -count=1 ./...
make client-test
make client-build-web
make test-control-plane-edge-wire
make readability-audit
IOP_DEV_RECONNECT_BIND_TIMEOUT=60 scripts/dev/edge-node-reconnect-diagnostic.sh
git diff --check
```
_Actual output:_
```text
BLOCKED — not run. The canonical checkout contains the upstream baseline plus the restored user-owned roadmap patch, not the reviewed staging promotion tree.
```
### Final canonical boundary and state checks
Run from `/config/workspace/iop`:
```bash
if rg --sort path -n -i 'chronos|agent_bridge|iop-agent|iop_agent|IopAgent|agentruntime|agentprovider|agenttask|agentworkspace' apps packages/go cmd proto configs; then exit 1; fi
test ! -d apps/agent
test -z "$(find packages/go -maxdepth 1 -type d -name 'agent*' -print -quit)"
test -z "$(git diff --name-only --diff-filter=U)"
rg -n '^status: 구현됨$|^Status: `구현됨`$' agent-ui/definition/components/console-shell/index.md
jq -e '.pending_milestone_work | length == 0' agent-ui/.sync-state.json
jq -e '.reconciled_milestone_work | any(.milestone_path == "agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md" and .state == "reconciled")' agent-ui/.sync-state.json
rg -n '^canonical_promotion: applied$|^staging_promotion_commit: [0-9a-f]{40}$|^canonical_promotion_commit: [0-9a-f]{40}$' HANDOFF.md
git diff --check
```
_Actual output:_
```text
BLOCKED — not run as a passing gate. The forbidden-surface and applied-promotion assertions are expected to fail before canonical promotion.
No unmerged paths remain after `git cherry-pick --abort`.
```
### Final cross-workspace preservation checks
Run from `/config/workspace/iop-s1`:
```bash
git diff --check
rg -n '^canonical_promotion: applied$|^staging_promotion_commit: [0-9a-f]{40}$|^canonical_promotion_commit: [0-9a-f]{40}$' HANDOFF.md
agent-ops/bin/roadmap-dependency-checker.sh --find-milestone 'iop:agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md' both /config/workspace/.agent-roadmap-sync/locks.yaml
rg -n -A4 'id: chronos:chronos-architecture-ownership-boundary' /config/workspace/.agent-roadmap-sync/locks.yaml
```
_Actual output, including retained patch path, SHA-256, and named stash locator:_
```text
Staging `git diff --check`: exit 0, no output.
No applied-promotion fields matched in `HANDOFF.md` because promotion was aborted.
rely-on:chronos:chronos-architecture-ownership-boundary
7:- id: chronos:chronos-architecture-ownership-boundary
8- locked: chronos:agent-roadmap/phase/runtime-ownership-transition/milestones/chronos-architecture-ownership-boundary.md
9- rely-on:
10- - target: iop:agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md
11- status: disable
Retained recovery patch: /tmp/iop-canonical-promotion.QOCOar/canonical-roadmap.patch
Patch SHA-256: 1f1afe533e910b6311390071e07799bf6cc24ca742853bb45a3eceb3da1d4575
Named stash: stash@{0} (iop-canonical-promotion-roadmap-20260802T102956Z)
Stash patch copy: /tmp/iop-canonical-promotion.QOCOar/stash-roadmap.patch
Stash patch SHA-256: 1f1afe533e910b6311390071e07799bf6cc24ca742853bb45a3eceb3da1d4575
Patch/stash byte comparison: equal
Unexpected conflict list: /tmp/iop-canonical-promotion.QOCOar/unexpected-conflicts.txt
Conflict-list SHA-256: 15e564744e83accd74981a5976432d14d8638815cab0fefc1d1eaabe97a4aca4
```
---
> **[IMPLEMENTING AGENT — BEFORE SAVING] Have you filled in every implementation-owned section?**
> If anything is blank, go back and fill it in before saving this file.
> Leave review-agent-only sections unchanged.
## Section Ownership
| Section | Owner | Note |
|---------|-------|------|
| Header comment, Overview, Review Agent Instructions | Fixed at stub creation | Implementing agent must not modify or execute these (archive, complete.log, and task-directory archive move are review-agent only) |
| Archive Evidence Snapshot | Fixed at stub creation from plan when present | Implementing agent uses it as default prior-loop context; read only the specific archive files cited there when more detail is required |
| Implementation Item Completion (item names) | Fixed at stub creation | Implementing agent checks `[ ]` → `[x]` only |
| Implementation Checklist (item text/order) | Fixed at stub creation from plan | Implementing agent checks `[ ]` → `[x]` only |
| Review-Only Checklist | Review agent only | Implementing agent must not modify or check this section |
| Deviations from Plan, Key Design Decisions | Implementing agent | Replace placeholder text with actual content |
| Reviewer Checkpoints | Fixed at stub creation | Pre-filled from plan |
| Verification Results (section headings + commands) | Fixed at stub creation | Implementing agent fills in command output only; command changes require a `Deviations from Plan` entry |
| Code Review Result | Review agent appends | Not included in stub |
## Code Review Result
- Overall Verdict: FAIL
- Dimension Assessment:
- Correctness: Fail — the reviewed staging tree was not applied to the canonical checkout.
- Completeness: Fail — REFACTOR-1 through REFACTOR-4 remain incomplete.
- Test Coverage: Fail — the required fresh canonical Go, Flutter, wire, reconnect, readability, and boundary verification matrix was not run.
- API Contract: Fail — the canonical source, contract, proto, and UI trees remain on the upstream pre-promotion baseline.
- Code Quality: Pass — the unexpected cherry-pick was aborted without resolving unreviewed conflicts, and the protected roadmap patch remains recoverable.
- Implementation Deviation: Fail — the planned three-roadmap-conflict promotion expanded to 34 conflicts and could not produce the required canonical commit.
- Verification Trust: Pass — fresh review reproduced the reported commit identities, 34-path conflict list and digest, retained patch/stash digest, clean abort state, three restored roadmap edits, and disabled downstream lock.
- Spec Conformance: Fail — SDD S05 requires canonical traceability through the final composite receipt, but canonical promotion and closure evidence are absent.
- Findings:
- Required — `HANDOFF.md:83`, `/config/workspace/iop/apps/agent/cmd/agent/main.go:1`, and `CODE_REVIEW-cloud-G10.md:156`: canonical promotion is still pending, the canonical checkout still tracks the legacy Agent runtime surface, and the mandatory canonical verification matrix was not run. Rebuild or rebase the reviewed promotion change set onto canonical `c3a24ec5febab9fc978fd62392efcb6c96e12ec9`, review and resolve the full 34-path upstream overlap, apply the resulting commit to `/config/workspace/iop`, then complete the canonical regression, Agent UI reconciliation, mirrored handoff evidence, and lock-preservation checks before requesting another review.
- Routing Signals: `review_rework_count=1`, `evidence_integrity_failure=false`
- Next Step: Create a freshly routed follow-up PLAN/CODE_REVIEW pair for the required canonical integration and closure verification work; do not write `complete.log` or update the roadmap.

View file

@ -0,0 +1,453 @@
<!-- task=m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure plan=1 tag=REVIEW_REFACTOR milestone-task=handoff-gate -->
# Code Review Reference - REVIEW_REFACTOR
> **[IMPLEMENTING AGENT — READ FIRST] Filling in this file is the mandatory final step of implementation.**
> The task is NOT complete until every implementation-owned section below is filled in.
> Complete the `Implementation Checklist`; the final checklist item is mandatory before saving.
> Fill implementation-owned sections, then stop with active files in place and report ready for review.
> If implementation is blocked, record the exact blocker, attempted commands/output, and resume condition only in implementation-owned evidence fields.
> Do not ask the user directly, present choices, call user-input tools, create control-plane stop files, or classify the next state.
> Finalization (`Code Review Result`, log rename, `complete.log`, archive moves, `Review-Only Checklist`) is review-agent-only, even after compaction/resume.
> Follow the ownership table at the bottom of this file for which sections you own.
## Overview
date=2026-08-02
task=m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure, plan=1, tag=REVIEW_REFACTOR
## Archive Evidence Snapshot
- Prior plan: `agent-task/m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/plan_cloud_G10_0.log`
- Prior review: `agent-task/m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/code_review_cloud_G10_0.log`
- Prior verdict: `FAIL`
- Required finding count: `1`
- Suggested finding count: `0`
- Nit count: `0`
- Review routing signals: `review_rework_count=1`, `evidence_integrity_failure=false`
- Recovery evidence retained by the failed attempt:
- roadmap patch: `/tmp/iop-canonical-promotion.QOCOar/canonical-roadmap.patch`
- conflict inventory: `/tmp/iop-canonical-promotion.QOCOar/unexpected-conflicts.txt`
- retained stash at review time: `stash@{0}` named `iop-canonical-promotion-roadmap-20260802T102956Z`
- roadmap patch SHA-256: `1f1afe533e910b6311390071e07799bf6cc24ca742853bb45a3eceb3da1d4575`
- conflict inventory SHA-256: `15e564744e83accd74981a5976432d14d8638815cab0fefc1d1eaabe97a4aca4`
## For the Review Agent
> **[REVIEW AGENT ONLY]** The finalization steps below are review-agent only. Implementing agents must not execute this section.
Compare implementation of each item against source files and verify that output in `Verification Results` matches code.
Review completion means the following steps are finished:
1. Append verdict and `review_rework_count` / `evidence_integrity_failure` routing signals.
2. Archive `CODE_REVIEW-cloud-G10.md` → `code_review_cloud_G10_1.log` and `PLAN-cloud-G10.md` → `plan_cloud_G10_1.log`.
3. If PASS, write `complete.log` and move active task directory to `agent-task/archive/YYYY/MM/m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/`. If WARN/FAIL, fully write the next filesystem state required by the code-review skill.
4. If PASS, preserve first-line `milestone-task=handoff-gate` metadata in `complete.log` and report it for runtime aggregation. Roadmap state evaluation belongs to `sync-milestone-workstate`.
5. Check applicable `Review-Only Checklist` items at the final `.log` location before reporting.
---
## Implementation Item Completion
| Item | Status |
|------|---------|
| REVIEW_REFACTOR-1 | [x] |
| REVIEW_REFACTOR-2 | [x] |
| REVIEW_REFACTOR-3 | [x] |
| REVIEW_REFACTOR-4 | [x] |
## Implementation Checklist
- [x] Rebuild the reviewed extraction change on exact canonical base `c3a24ec5febab9fc978fd62392efcb6c96e12ec9` in an isolated integration worktree and resolve all 34 overlaps with recorded dispositions.
- [x] Prove the integrated result preserves managed credential/TLS behavior and removes IOP Agent ownership, then promote it to canonical while restoring the three-file user roadmap patch.
- [x] Reconcile canonical Agent UI and mirrored HANDOFF evidence with exact promotion identities while keeping the Chronos lock disabled.
- [x] Run the complete final verification matrix, retain rollback evidence, and fill implementation-owned sections in `CODE_REVIEW-*-G??.md` with actual output.
## Review-Only Checklist
> **[REVIEW AGENT ONLY]** This checklist is used only by the review agent.
> Implementing agents must not modify or check this section.
- [x] Append one verdict of `PASS`, `WARN`, or `FAIL` and verified `review_rework_count`, `evidence_integrity_failure` to `Code Review Result`.
- [x] Verify that verdict, `Dimension Assessment`, and Required/Suggested/Nit classifications match.
- [x] Archive active `CODE_REVIEW-*-G??.md` to `code_review_cloud_G10_1.log`.
- [x] Archive active `PLAN-*-G??.md` to `plan_cloud_G10_1.log`.
- [x] Verify that the Agent-Ops managed block in `.gitignore` unignores `agent-task/**/*.md` and `agent-task/**/*.log` and ignores `agent-roadmap/current.md`.
- [ ] If PASS, write `complete.log` based on `agent-ops/skills/common/code-review/templates/complete-log-template.md` and leave no active `.md` files.
- [ ] If PASS, move active task directory `agent-task/m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/` to `agent-task/archive/YYYY/MM/m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/` and update this checklist at the final archive path.
- [ ] If PASS, preserve and report `milestone-task=handoff-gate` for runtime aggregation, without modifying roadmap or directly calling `update-roadmap`.
- [ ] If PASS for split work, remove empty active parent or verify it was kept due to remaining siblings/files.
- [x] If WARN/FAIL, write the next filesystem state matching code-review verdict and do not write `complete.log`.
## Deviations from Plan
- The isolated worktree is on `/tmp`, which is mounted `noexec`; Go test binaries therefore use `TMPDIR` and `GOTMPDIR` at `/config/workspace/iop-s1/.tmp/canonical-integration`. The source checkout and integration state remain in the required isolated `/tmp` worktree.
- The literal final boundary command names the removed `cmd` directory. Because `rg` returns status 2 for a missing path, verification uses the same pattern over the existing `apps`, `packages/go`, `proto`, and `configs` roots plus an explicit `test ! -d cmd` assertion.
- Canonical credential-plane tests referenced removed provider `env` and `args` fields. The integration removes those dead field-level checks and extends load-time legacy-provider rejection coverage for both keys, preserving fail-closed behavior at the actual configuration boundary.
- The bundled `sync_state.py reconcile-milestone` schema intentionally drops the pending entry's `state` field when it creates `reconciled_milestone_work`. The plan's literal `.state == "reconciled"` jq predicate is therefore not representable without prohibited manual state editing. Verification instead requires the exact milestone path plus non-empty closure evidence, `validate-agent-ui PASS` evidence, and `reconciled_at`; the helper itself returned `status: reconciled`.
- Pre-existing ignored permission-failure fixtures below `build/dev-runtime` and `build/tmp-go-test` made the first canonical `go test ./...` setup scan fail; an incomplete first quarantine attempt left the second root present and exposed that the retry shell lacked `set -e`. The result was not accepted. Both ignored roots were atomically renamed to `build/.canonical-promotion-quarantine-{dev-runtime,tmp-go-test}-20260802`, preserving them for inspection while excluding them from Go package discovery. A corrected `set -euo pipefail` fresh Go run with both roots absent passed, its log contains no `FAIL` line, and the complete generation-idempotency matrix was rerun afterward and passed.
## Key Design Decisions
- Treat `packages/go/execution` as the sole host-neutral provider runtime while retaining `session_id` only as opaque correlation; run cancellation is keyed only by `run_id`.
- Preserve canonical managed projection, TLS identity, recipient registration, exact route/slot/revision binding, sealed lease consumption/replay protection, and credential attribution. Remove only IOP-owned Agent, workspace, terminal, persistent-session, CLI-provider, and local status ownership.
- Generate Go and Dart bindings only from the synthesized source proto reservations and keep the canonical full security/provider documentation rather than replacing it with the shorter staging variants.
- Preserve unrelated canonical roadmap/SDD content, apply extraction state only to the target automation milestone, and defer the user-owned three-file `[separation-01]` patch to the guarded canonical restoration step.
## Reviewer Checkpoints
- Confirm the integration commit has exact parent `c3a24ec5febab9fc978fd62392efcb6c96e12ec9`, the unmerged inventory initially matched all 34 retained paths, and each path has a concrete disposition rather than wholesale ours/theirs selection.
- Confirm managed projection, mTLS identity, recipient keys, exact lease binding/consume/replay protection, and credential tests survive the `agentruntime` → `execution` extraction while AgentKind, workspace, CLI Agent, terminal, and session-termination ownership are removed.
- Confirm generated Go/Dart bindings came from resolved proto sources, removed field numbers/names are reserved, and full fresh Go/Flutter/wire/credential/readability/reconnect verification passed in both integration and canonical contexts as required.
- Confirm the canonical user roadmap patch was neither committed nor lost, both recovery generations remain locatable, canonical has no unmerged state, and no push/reset/destructive cleanup occurred.
- Confirm Agent UI and HANDOFF bytes are mirrored, Task 13-16 receipts remain intact, exact promotion ancestry resolves, the milestone was not archived, and the Chronos lock remains `disable`.
## Verification Results
### External Verification Preflight
Commands:
```bash
test "$(git -C /config/workspace/iop symbolic-ref --short HEAD)" = dev
test "$(git -C /config/workspace/iop rev-parse HEAD)" = c3a24ec5febab9fc978fd62392efcb6c96e12ec9
test "$(git -C /config/workspace/iop rev-parse origin/dev)" = c3a24ec5febab9fc978fd62392efcb6c96e12ec9
test "$(git rev-parse HEAD)" = 7b90b7e5af9035fae2b5349c65eb322096d21b1b
test "$(git rev-parse 7b90b7e5af9035fae2b5349c65eb322096d21b1b^1)" = 1debc7ada01d98442560bbc4ac52dcef9cae25cc
test "$(git -C /config/workspace/iop diff --name-only | LC_ALL=C sort)" = $'agent-roadmap/phase/automation-runtime-bridge/PHASE.md\nagent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md\nagent-roadmap/priority-queue.md'
test -z "$(git -C /config/workspace/iop diff --name-only --diff-filter=U)"
test "$(sha256sum /tmp/iop-canonical-promotion.QOCOar/canonical-roadmap.patch | awk '{print $1}')" = 1f1afe533e910b6311390071e07799bf6cc24ca742853bb45a3eceb3da1d4575
test "$(sha256sum /tmp/iop-canonical-promotion.QOCOar/unexpected-conflicts.txt | awk '{print $1}')" = 15e564744e83accd74981a5976432d14d8638815cab0fefc1d1eaabe97a4aca4
test "$(wc -l < /tmp/iop-canonical-promotion.QOCOar/unexpected-conflicts.txt)" -eq 34
git -C /config/workspace/iop diff --check
```
Actual output:
All guards exited 0 before integration state was created. Exact identities were canonical `HEAD=dev=c3a24ec5febab9fc978fd62392efcb6c96e12ec9`, `origin/dev=c3a24ec5febab9fc978fd62392efcb6c96e12ec9`, staging `HEAD=7b90b7e5af9035fae2b5349c65eb322096d21b1b`, and staging parent `1debc7ada01d98442560bbc4ac52dcef9cae25cc`. Canonical had exactly the three guarded roadmap paths and no unmerged entry. The retained patch digest was `1f1afe533e910b6311390071e07799bf6cc24ca742853bb45a3eceb3da1d4575`; the 34-line conflict inventory digest was `15e564744e83accd74981a5976432d14d8638815cab0fefc1d1eaabe97a4aca4`. `git diff --check` exited 0.
### REVIEW_REFACTOR-1 Integration Resolution and Focused Tests
Commands:
```bash
test "$(git rev-parse HEAD)" = c3a24ec5febab9fc978fd62392efcb6c96e12ec9
test -z "$(git diff --name-only --diff-filter=U)"
if rg --sort path -n '^(<<<<<<<|=======|>>>>>>>)' --glob '!agent-task/**'; then exit 1; fi
git diff --name-only --diff-filter=ACM -z -- '*.go' | xargs -0 -r gofmt -w
go mod tidy
make proto
make proto-dart
go test -count=1 ./packages/go/config ./packages/go/credentiallease ./apps/edge/internal/node ./apps/edge/internal/transport ./apps/edge/internal/openai ./apps/node/internal/node
git diff --check
```
After commit:
```bash
test "$(git rev-parse HEAD^)" = c3a24ec5febab9fc978fd62392efcb6c96e12ec9
go mod tidy
make proto
make proto-dart
git diff --exit-code
```
Actual output and 34-path disposition table:
Integration worktree: `/tmp/iop-canonical-integration.A3nmqQ/worktree`.
`git cherry-pick --no-commit 7b90b7e5af9035fae2b5349c65eb322096d21b1b` produced exactly the retained 34-path set. `/tmp/iop-canonical-promotion.QOCOar/integration-unmerged.txt` is byte-identical to `unexpected-conflicts.txt`, has 34 lines, and has SHA-256 `15e564744e83accd74981a5976432d14d8638815cab0fefc1d1eaabe97a4aca4`.
| Path | Disposition category | Evidence command |
|------|----------------------|------------------|
| `Makefile` | provider-only build plus canonical credential/wire targets | `make proto`; focused/full Go tests; later smoke matrix |
| `agent-contract/index.md` | managed contracts plus execution-runtime successor | `rg -n 'execution-runtime|credential|projection|lease' agent-contract/index.md` |
| `agent-contract/inner/client-control-plane-wire.md` | canonical credential ownership retained | focused/full Go tests and contract boundary scan |
| `agent-contract/inner/control-plane-edge-wire.md` | projection/lease retained; Agent status removed | source proto generation and boundary scan |
| `agent-contract/inner/edge-config-runtime-refresh.md` | managed TLS/config retained; CLI/process fields removed | `go test -count=1 ./packages/go/config` |
| `agent-contract/inner/edge-node-runtime-wire.md` | recipient lease retained; run-id cancel only | Node focused tests and wire generation |
| `agent-contract/outer/openai-compatible-api.md` | managed route/metrics/stream gate retained; workspace authoring removed | OpenAI focused tests and boundary scan |
| `agent-roadmap/ROADMAP.md` | canonical unrelated roadmap retained | `git diff c3a24ec5 -- agent-roadmap/ROADMAP.md` |
| `agent-roadmap/phase/automation-runtime-bridge/PHASE.md` | canonical phase plus target review state | target milestone/phase diff inspection |
| `agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md` | staging extraction evidence, still review-only | milestone diff and check-only workflow |
| `agent-roadmap/phase/knowledge-tool-optimization-extension/PHASE.md` | canonical unrelated phase retained | per-path diff inspection |
| `agent-roadmap/phase/knowledge-tool-optimization-extension/milestones/iop-hot-path-one-shot-execution.md` | canonical unrelated milestone retained | per-path diff inspection |
| `agent-roadmap/phase/operational-observability-provider-management/PHASE.md` | canonical unrelated phase retained | per-path diff inspection |
| `agent-roadmap/phase/operational-observability-provider-management/milestones/node-provider-execution-liveness-recovery.md` | canonical reconnect scope with external ownership wording | reconnect diagnostic plus per-path diff |
| `agent-roadmap/phase/personal-edge-packaging-deployment/PHASE.md` | canonical unrelated phase retained | per-path diff inspection |
| `agent-roadmap/phase/personal-edge-packaging-deployment/milestones/personal-local-edge-deployment-profiles.md` | canonical provider-only ownership retained | per-path diff inspection |
| `agent-roadmap/priority-queue.md` | canonical grouped queue retained pending guarded user-patch restore | canonical patch hash and post-promotion semantic diff |
| `agent-roadmap/sdd/operational-observability-provider-management/node-provider-execution-liveness-recovery/SDD.md` | canonical liveness design with external runtime ownership | reconnect diagnostic and per-path diff |
| `agent-spec/control/control-plane-operations.md` | canonical projection/lease operational spec retained | credential smoke and spec check-only |
| `agent-spec/index.md` | execution-runtime index; removed IOP Agent CLI spec entry | boundary scan and spec check-only |
| `agent-spec/input/openai-compatible-surface.md` | managed ingress retained; workspace semantics removed | OpenAI focused tests and boundary scan |
| `agent-spec/runtime/edge-node-execution.md` | concise provider-only runtime plus canonical mTLS/lease rules | Node/Edge focused tests |
| `agent-spec/runtime/provider-pool-config-refresh.md` | canonical managed config plus normalized native providers only | config focused tests |
| `apps/edge/internal/node/registry.go` | AgentKind removed; recipient bytes and generation clone retained | `go test -count=1 ./apps/edge/internal/node` |
| `apps/edge/internal/openai/dispatch_context.go` | workspace removed; trusted managed binding overwrite retained | `go test -count=1 ./apps/edge/internal/openai` |
| `apps/edge/internal/transport/connection_handlers.go` | AgentKind metadata removed; mTLS recipient registration retained | `go test -count=1 ./apps/edge/internal/transport` |
| `apps/node/internal/node/node.go` | execution package plus credential consumer | Node focused tests |
| `apps/node/internal/node/provider_tunnel_test.go` | lease consume/replay retained; run-id-only cancel | `go test -count=1 ./apps/node/internal/node` |
| `apps/node/internal/node/tunnel_handler.go` | execution package plus admission-before-lease consumption | Node focused tests |
| `docs/edge-local-dev-guide.md` | canonical full TLS/credential guide; AgentKind removed | boundary/readability checks |
| `go.mod` | Agent-only dependency removal plus canonical dependencies | `go mod tidy`; full Go test |
| `packages/go/config/edge_types.go` | TLS/credential config retained; Agent/workspace/console aliases removed | config focused tests |
| `proto/gen/iop/control.pb.go` | regenerated from resolved source proto | `make proto`; post-commit clean diff |
| `proto/gen/iop/runtime.pb.go` | regenerated from resolved source proto | `make proto`; post-commit clean diff |
Pre-commit checks exited 0: no unmerged entries or conflict markers; `go mod tidy`, `make proto`, `make proto-dart`, and `git diff --check` succeeded. Focused output is saved at `/tmp/iop-canonical-promotion.QOCOar/evidence/integration-focused.log` and reports PASS for config, credentiallease, streamgate, Edge node/transport/OpenAI, and Node node packages. A fresh pre-commit `go test -count=1 ./...` also passed; output is `/tmp/iop-canonical-promotion.QOCOar/evidence/integration-go-test.log`.
### REVIEW_REFACTOR-2 Integration Qualification and Canonical Promotion
Commands from the isolated integration worktree:
```bash
mkdir -p .tmp
TMPDIR="$PWD/.tmp" GOTMPDIR="$PWD/.tmp" go test -count=1 ./...
make client-test
make client-build-web
make test-control-plane-edge-wire
make test-credential-slot-smoke
make readability-audit
IOP_DEV_RECONNECT_BIND_TIMEOUT=60 scripts/dev/edge-node-reconnect-diagnostic.sh
git diff --exit-code
```
Canonical preservation/promotion evidence:
The final integration commit is `c8e98d4e10b30114de7bafe426a4045abd6c1205`, with exact parent `c3a24ec5febab9fc978fd62392efcb6c96e12ec9`. It is the only commit in `c3a24ec5febab9fc978fd62392efcb6c96e12ec9..c8e98d4e10b30114de7bafe426a4045abd6c1205`. The merge source worktree remains at `/tmp/iop-canonical-integration.A3nmqQ/worktree`; because `/tmp` is `noexec`, the exact committed tree was checked out at `/config/workspace/iop-canonical-integration` for executable test qualification.
Qualification commands all exited 0. Evidence is retained as follows:
| Check | Result | Saved output |
|------|--------|--------------|
| fresh `go test -count=1 ./...` | PASS | `/tmp/iop-canonical-promotion.QOCOar/evidence/qualification-go-test.log` |
| `make client-test` | PASS, 44 tests | `/tmp/iop-canonical-promotion.QOCOar/evidence/qualification-client-test.log` |
| `make client-build-web` | PASS | `/tmp/iop-canonical-promotion.QOCOar/evidence/qualification-client-build-web.log` |
| `make test-control-plane-edge-wire` | PASS | `/tmp/iop-canonical-promotion.QOCOar/evidence/qualification-control-plane-edge-wire.log` |
| `TMPDIR="$PWD/.tmp" make test-credential-slot-smoke` | PASS | `/tmp/iop-canonical-promotion.QOCOar/evidence/qualification-credential-slot-smoke.log` |
| `make readability-audit` after fixed-point baseline regeneration | PASS | `/tmp/iop-canonical-promotion.QOCOar/evidence/qualification-readability-audit-final.log` |
| reconnect diagnostic | PASS, three mock-provider messages across restart | `/tmp/iop-canonical-promotion.QOCOar/evidence/qualification-reconnect.log` |
The first qualification readability log records the expected pre-regeneration ratchet failure. The baseline was regenerated from the final integrated tree, all 122 readability audit unit tests passed, the ratchet passed, and the final PASS was rerun and saved separately at the `-final.log` path above. Post-amend `go mod tidy`, `make proto`, `make proto-dart`, and `git diff --exit-code` all exited 0.
Immediately before promotion, the exact guarded preservation sequence was:
```bash
git -C /config/workspace/iop diff --binary -- \
agent-roadmap/phase/automation-runtime-bridge/PHASE.md \
agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md \
agent-roadmap/priority-queue.md \
> /tmp/iop-canonical-promotion.QOCOar/canonical-roadmap-prepromotion-20260802T112929Z.patch
git -C /config/workspace/iop stash push \
-m iop-canonical-promotion-roadmap-20260802T112929Z -- \
agent-roadmap/phase/automation-runtime-bridge/PHASE.md \
agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md \
agent-roadmap/priority-queue.md
git -C /config/workspace/iop update-ref \
refs/heads/codex/iop-canonical-promotion-c8e98d4e \
c8e98d4e10b30114de7bafe426a4045abd6c1205
git -C /config/workspace/iop merge --ff-only c8e98d4e10b30114de7bafe426a4045abd6c1205
git -C /config/workspace/iop stash apply ff81ecb5e8b16fc81ecce4273afe24ff06236287
git -C /config/workspace/iop restore --staged -- \
agent-roadmap/phase/automation-runtime-bridge/PHASE.md \
agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md \
agent-roadmap/priority-queue.md
```
The new patch SHA-256 is `314132fd4943d5a49e47a0fd499c39761bf4ff65f725f129c3a949f7e2927db6`; its retained stash commit is `ff81ecb5e8b16fc81ecce4273afe24ff06236287`, currently `stash@{0}`. The earlier patch remains at SHA-256 `1f1afe533e910b6311390071e07799bf6cc24ca742853bb45a3eceb3da1d4575`; its retained stash commit is `a91e4af2bc23c7fab2ef0ea026e2b453e9393848`, currently `stash@{1}`. The only apply overlap was the target Phase line, resolved to preserve the user's `[검토중] [separation-01]` state and the canonical milestone link. Immediately after restore, canonical had exactly the three expected unstaged roadmap paths, no staged entry, and no unmerged entry.
Canonical `dev` fast-forwarded to `c8e98d4e10b30114de7bafe426a4045abd6c1205`; `origin/dev` remains `c3a24ec5febab9fc978fd62392efcb6c96e12ec9`. No push was performed.
### REVIEW_REFACTOR-3 Agent UI, HANDOFF, and Lock Evidence
Commands:
```bash
cmp /config/workspace/iop/agent-ui/.sync-state.json agent-ui/.sync-state.json
cmp /config/workspace/iop/agent-ui/definition/components/console-shell/index.md agent-ui/definition/components/console-shell/index.md
cmp /config/workspace/iop/agent-ui/definition/components/index.md agent-ui/definition/components/index.md
cmp /config/workspace/iop/HANDOFF.md HANDOFF.md
jq -e '.pending_milestone_work | length == 0' agent-ui/.sync-state.json
jq -e '.reconciled_milestone_work | any(.milestone_path == "agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md" and .state == "reconciled")' agent-ui/.sync-state.json
rg -n '^canonical_promotion: applied$|^staging_promotion_commit: [0-9a-f]{40}$|^canonical_promotion_commit: [0-9a-f]{40}$|^canonical_promotion_verified_at: ' HANDOFF.md
agent-ops/bin/roadmap-dependency-checker.sh --find-milestone 'iop:agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md' both /config/workspace/.agent-roadmap-sync/locks.yaml
rg -n -A4 'id: chronos:chronos-architecture-ownership-boundary' /config/workspace/.agent-roadmap-sync/locks.yaml
```
Actual output:
`complete-milestone mode=check-only` found the target milestone closure-ready: all five feature tasks are checked, the SDD is approved and unlocked, the code-level audit and final qualification matrix pass, and the milestone remains `[검토중]`. `update-spec mode=check-only` found the current provider/runtime specs synchronized with the final code and returned `Spec update not needed`.
`update-agent-ui` changed `component:console-shell` from `계획` to `구현됨` and updated the component index. `validate-agent-ui scope=component:console-shell sync-intent=skip` passed: frontmatter/body status agree, every source-evidence path exists, the index agrees, the implementation has no Agent enum/slot/rail action, and no active `agent-ui/USER_REVIEW.md` exists.
The bundled reconciliation helper was invoked with state digest `7198e66e8f6ba2d4d325220531651fc45580fc446d916eb53f6774578c6827b2`, the exact milestone path, stable closure and validation evidence, reconciliation time `2026-08-02T11:33:33Z`, and sync result head `c8e98d4e10b30114de7bafe426a4045abd6c1205`. It returned:
```json
{"after_sha256":"abce070a46563ebd9b45599882c91814ac1236966c4d3c6a53ce3dbb840f1788","before_sha256":"7198e66e8f6ba2d4d325220531651fc45580fc446d916eb53f6774578c6827b2","milestone_path":"agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md","status":"reconciled"}
```
`pending_milestone_work` is empty. The `reconciled_milestone_work` record contains the exact milestone, mapped code/status paths, closure evidence, `validate-agent-ui PASS` evidence, reconciliation timestamp, and promotion commit. As recorded under Deviations, the common helper's normalized reconciled schema has no `.state` field, so the final jq assertion validates those schema-owned fields instead.
`HANDOFF.md` retains every Task 13-16 field and adds `canonical_promotion: applied`, staging commit `7b90b7e5af9035fae2b5349c65eb322096d21b1b`, canonical base `c3a24ec5febab9fc978fd62392efcb6c96e12ec9`, promotion commit `c8e98d4e10b30114de7bafe426a4045abd6c1205`, verified time `2026-08-02T11:42:32Z`, both recovery generations, the 34-conflict inventory, the verification matrix, and the explicitly disabled downstream lock. All four `cmp` commands between canonical and staging exited 0.
Lock lookup output was:
```text
rely-on:chronos:chronos-architecture-ownership-boundary
false
lock-check-exit=1
```
The matching `locks.yaml` entry remains `status: disable`. No milestone archive, lock enable, close operation, commit of post-promotion evidence, or push was performed.
### REVIEW_REFACTOR-4 Final Canonical Runtime Verification
Commands from `/config/workspace/iop`:
```bash
mkdir -p .tmp
TMPDIR="$PWD/.tmp" GOTMPDIR="$PWD/.tmp" go test -count=1 ./...
make client-test
make client-build-web
make test-control-plane-edge-wire
make test-credential-slot-smoke
make readability-audit
IOP_DEV_RECONNECT_BIND_TIMEOUT=60 scripts/dev/edge-node-reconnect-diagnostic.sh
go mod tidy
make proto
make proto-dart
git diff --check
test -z "$(git diff --name-only --diff-filter=U)"
```
Actual output:
The complete corrected canonical matrix ran from `/config/workspace/iop` and exited 0:
| Command | Result | Saved output |
|---------|--------|--------------|
| `TMPDIR="$PWD/.tmp" GOTMPDIR="$PWD/.tmp" go test -count=1 ./...` | PASS, fresh; no `FAIL` line | `/tmp/iop-canonical-promotion.QOCOar/evidence/canonical-go-test.log` (SHA-256 `dc4924270bc0073207dd79e881614287f46a6e6c8b706a72524560e944ef0d4f`) |
| `make client-test` | PASS, 44 tests | `/tmp/iop-canonical-promotion.QOCOar/evidence/canonical-client-test.log` |
| `make client-build-web` | PASS | `/tmp/iop-canonical-promotion.QOCOar/evidence/canonical-client-build-web.log` |
| `make test-control-plane-edge-wire` | PASS, including secure-delivery three-process test | `/tmp/iop-canonical-promotion.QOCOar/evidence/canonical-control-plane-edge-wire.log` |
| `TMPDIR="$PWD/.tmp" GOTMPDIR="$PWD/.tmp" make test-credential-slot-smoke` | PASS, two deterministic profiles, exact auth, ciphertext-only, TLS negative matrix, rotate/revoke no-fallback | `/tmp/iop-canonical-promotion.QOCOar/evidence/canonical-credential-slot-smoke.log` |
| `make readability-audit` | PASS, 482 files, 220631 LOC, 6544 functions, 533 baseline violations and no ratchet increase | `/tmp/iop-canonical-promotion.QOCOar/evidence/canonical-readability-audit.log` |
| reconnect diagnostic | PASS, three ordered mock-provider runs across restart and absent session/status ownership commands | `/tmp/iop-canonical-promotion.QOCOar/evidence/canonical-reconnect.log` |
After the corrected fresh Go run, `go mod tidy`, `make proto`, and `make proto-dart` all exited 0. Binary diffs and porcelain status were captured before and after generation. The before/after binary diff files are byte-identical with SHA-256 `0c875b93427b1deb8904e8c0eab6062f7a775486f30e68bb3a0e1c5d8cfd8420`, and the before/after status files are byte-identical. `git diff --check` passed and both `git diff --name-only --diff-filter=U` and `git ls-files -u` were empty.
### Final Boundary, Mirroring, Recovery, and Lock Verification
Commands from `/config/workspace/iop`:
```bash
if rg --sort path -n -i 'chronos|agent_bridge|iop-agent|iop_agent|IopAgent|agentruntime|agentprovider|agenttask|agentworkspace' apps packages/go cmd proto configs; then exit 1; fi
test ! -d apps/agent
test -z "$(find packages/go -maxdepth 1 -type d -name 'agent*' -print -quit)"
test ! -e proto/iop/agent.proto
test ! -e proto/gen/iop/agent.pb.go
test -z "$(git diff --name-only --diff-filter=U)"
rg -n '^status: 구현됨$|^Status: `구현됨`$' agent-ui/definition/components/console-shell/index.md
jq -e '.pending_milestone_work | length == 0' agent-ui/.sync-state.json
jq -e '.reconciled_milestone_work | any(.milestone_path == "agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md" and .state == "reconciled")' agent-ui/.sync-state.json
rg -n '^canonical_promotion: applied$|^staging_promotion_commit: [0-9a-f]{40}$|^canonical_promotion_commit: [0-9a-f]{40}$' HANDOFF.md
git merge-base --is-ancestor "$(sed -n 's/^canonical_promotion_commit: //p' HANDOFF.md)" HEAD
```
Commands from `/config/workspace/iop-s1`:
```bash
git diff --check
cmp /config/workspace/iop/HANDOFF.md HANDOFF.md
cmp /config/workspace/iop/agent-ui/.sync-state.json agent-ui/.sync-state.json
cmp /config/workspace/iop/agent-ui/definition/components/console-shell/index.md agent-ui/definition/components/console-shell/index.md
cmp /config/workspace/iop/agent-ui/definition/components/index.md agent-ui/definition/components/index.md
agent-ops/bin/roadmap-dependency-checker.sh --find-milestone 'iop:agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md' both /config/workspace/.agent-roadmap-sync/locks.yaml
rg -n -A4 'id: chronos:chronos-architecture-ownership-boundary' /config/workspace/.agent-roadmap-sync/locks.yaml
```
Actual output:
The active-root forbidden-surface scan produced no match. The removed `cmd` root, `apps/agent`, every top-level `packages/go/agent*` directory, `proto/iop/agent.proto`, and `proto/gen/iop/agent.pb.go` are absent. There are no unmerged index entries or active conflict markers. The complete boundary/ancestry output is saved at `/tmp/iop-canonical-promotion.QOCOar/evidence/canonical-boundary-and-ancestry.log` and ends with `PASS canonical-boundary-and-ancestry`.
Canonical identities are:
```text
HEAD=c8e98d4e10b30114de7bafe426a4045abd6c1205
HEAD^=c3a24ec5febab9fc978fd62392efcb6c96e12ec9
origin/dev=c3a24ec5febab9fc978fd62392efcb6c96e12ec9
commit-count(base..HEAD)=1
```
`git merge-base --is-ancestor c8e98d4e10b30114de7bafe426a4045abd6c1205 HEAD` exited 0. Canonical has no staged or unmerged path. Its seven intentional unstaged tracked paths are exactly the three restored user roadmap files plus `HANDOFF.md` and the three reconciled Agent UI files.
Recovery evidence remains intact:
| Generation | Patch and SHA-256 | Retained stash |
|------------|------------------|----------------|
| initial failed attempt | `/tmp/iop-canonical-promotion.QOCOar/canonical-roadmap.patch`, `1f1afe533e910b6311390071e07799bf6cc24ca742853bb45a3eceb3da1d4575` | `a91e4af2bc23c7fab2ef0ea026e2b453e9393848`, `stash@{1}`, `iop-canonical-promotion-roadmap-20260802T102956Z` |
| guarded pre-promotion | `/tmp/iop-canonical-promotion.QOCOar/canonical-roadmap-prepromotion-20260802T112929Z.patch`, `314132fd4943d5a49e47a0fd499c39761bf4ff65f725f129c3a949f7e2927db6` | `ff81ecb5e8b16fc81ecce4273afe24ff06236287`, `stash@{0}`, `iop-canonical-promotion-roadmap-20260802T112929Z` |
The exact conflict inventory and unexpected-conflict files each have 34 lines and SHA-256 `15e564744e83accd74981a5976432d14d8638815cab0fefc1d1eaabe97a4aca4`.
All four canonical/staging `cmp` commands and staging `git diff --check` exited 0. UI output was:
```text
4:status: 구현됨
24:Status: `구현됨`
pending_milestone_work length: 0
reconciled milestone record with closure, validation, and timestamp: true
```
HANDOFF output identifies `canonical_promotion: applied`, staging commit `7b90b7e5af9035fae2b5349c65eb322096d21b1b`, promotion commit `c8e98d4e10b30114de7bafe426a4045abd6c1205`, and verification time `2026-08-02T11:42:32Z`.
Final dependency output remains:
```text
rely-on:chronos:chronos-architecture-ownership-boundary
false
lock-check-exit=1
status: disable
```
No lock, roadmap completion/archive state, remote branch, or external repository was mutated.
The consolidated recovery, dirty-path, saved-log, generation, UI, ancestry, and lock audit is `/tmp/iop-canonical-promotion.QOCOar/evidence/final-canonical-audit.log`; it ends with `PASS final-canonical-audit`.
---
> **[IMPLEMENTING AGENT — BEFORE SAVING] Have you filled in every implementation-owned section?**
> If anything is blank, go back and fill it in before saving this file.
> Leave review-agent-only sections unchanged.
## Section Ownership
| Section | Owner | Note |
|---------|-------|------|
| Header comment, Overview, Review Agent Instructions | Fixed at stub creation | Implementing agent must not modify or execute these (archive, complete.log, and task-directory archive move are review-agent only) |
| Archive Evidence Snapshot | Fixed at stub creation from plan when present | Implementing agent uses it as default prior-loop context; read only the specific archive files cited there when more detail is required |
| Implementation Item Completion (item names) | Fixed at stub creation | Implementing agent checks `[ ]` → `[x]` only |
| Implementation Checklist (item text/order) | Fixed at stub creation from plan | Implementing agent checks `[ ]` → `[x]` only |
| Review-Only Checklist | Review agent only | Implementing agent must not modify or check this section |
| Deviations from Plan, Key Design Decisions | Implementing agent | Replace placeholder text with actual content |
| Reviewer Checkpoints | Fixed at stub creation | Pre-filled from plan |
| Verification Results (section headings + commands) | Fixed at stub creation | Implementing agent fills in command output only; command changes require a `Deviations from Plan` entry |
| Code Review Result | Review agent appends | Not included in stub |
## Code Review Result
- Overall Verdict: FAIL
- Dimension Assessment:
- Correctness: Pass — the canonical integration commit, resolved conflict inventory, recovery artifacts, mirrored closure state, and fresh runtime verification were independently reproduced.
- Completeness: Fail — active production-facing source text still assigns execution ownership to a standalone Agent and terminal-session model, so the provider-only closure is not complete.
- Test Coverage: Fail — the current forbidden-surface scan does not cover the plain-language ownership strings that remain in package documentation and the Node command description.
- API Contract: Fail — the residual Agent and terminal-session descriptions contradict the provider-only execution contract and SDD S04 ownership boundary.
- Code Quality: Fail — duplicate package documentation now gives conflicting ownership descriptions inside `packages/go/execution`.
- Implementation Deviation: Pass — the reviewed conflict-resolution, promotion, reconciliation, and recovery deviations are fully recorded and match the inspected state.
- Verification Trust: Pass — fresh review reproduced the claimed identities, conflict digest, artifact hashes, clean generation, Go/Flutter/wire/credential results, mirroring, ancestry, and disabled dependency lock.
- Spec Conformance: Fail — SDD S04 requires Node and Edge to remain provider-only with no surviving Agent or terminal ownership, but three active source descriptions still state that ownership.
- Findings:
- Required — `/config/workspace/iop/packages/go/execution/doc.go:1`, `/config/workspace/iop/packages/go/execution/types.go:15`, and `/config/workspace/iop/apps/node/cmd/node/main.go:29`: the canonical source still says the execution package is shared with standalone Agent hosts, owns terminal-session primitives, preserves a session on cancellation, and identifies Node as an `IOP Node Agent`. Replace those descriptions with provider-only, run-scoped wording; mirror the exact corrections into the staging checkout; record traceable corrective commit identities without disturbing the protected roadmap/UI state; and extend the deterministic boundary scan to reject these ownership phrases before rerunning focused fresh tests and closure checks.
- Routing Signals: `review_rework_count=2`, `evidence_integrity_failure=false`
- Next Step: Create a freshly routed follow-up PLAN/CODE_REVIEW pair for the required provider-only wording correction and traceable canonical/staging closure verification; do not write `complete.log` or update the roadmap.

View file

@ -0,0 +1,43 @@
<!-- task=m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure plan=2 tag=REVIEW_REFACTOR milestone-task=handoff-gate -->
# Complete - m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure
## Completed At
2026-08-02
## Summary
Closed the provider-only canonical promotion boundary after three review loops with final verdict PASS.
## Loop History
| Plan | Review | Verdict | Notes |
|------|--------|---------|-------|
| `plan_cloud_G10_0.log` | `code_review_cloud_G10_0.log` | FAIL | Canonical promotion and its required verification matrix were not yet complete. |
| `plan_cloud_G10_1.log` | `code_review_cloud_G10_1.log` | FAIL | Canonical promotion passed, but three active descriptions retained standalone Agent or terminal-session ownership wording. |
| `plan_cloud_G08_2.log` | `code_review_cloud_G08_2.log` | PASS | Provider-only wording, focused regression, equivalent corrective commits, mirrored receipt, recovery evidence, and disabled-lock preservation were independently verified. |
## Implementation and Cleanup
- Replaced residual standalone Agent and terminal-session ownership descriptions with provider-only, run-scoped wording in both staging and canonical checkouts.
- Added `TestRootCmdUsesProviderOnlyDescription` and recorded equivalent four-path corrective commits with stable patch id `2e89dc0ed8a45542531af2e16efaf397dd3b2602`.
- Added both corrective commit identities and verification time to byte-identical staging and canonical `HANDOFF.md` receipts while preserving promotion, recovery, protected roadmap/UI, and lock evidence.
## Final Verification
- `TMPDIR="$PWD/.tmp" GOTMPDIR="$PWD/.tmp" go test -count=1 ./packages/go/execution ./apps/node/cmd/node` in both checkouts — PASS; fresh package and focused CLI tests succeeded.
- `go run ./apps/node/cmd/node --help` in both checkouts — PASS; the actual CLI entrypoint displayed the provider-only description and no Agent or terminal-session wording.
- `TMPDIR="$PWD/.tmp" GOTMPDIR="$PWD/.tmp" go test -count=1 ./packages/go/execution ./apps/node/...` in both checkouts — PASS; all Node packages succeeded.
- `TMPDIR="$PWD/.tmp" GOTMPDIR="$PWD/.tmp" go test -count=1 ./packages/go/execution ./packages/go/streamgate ./packages/go/config` in both checkouts — PASS; platform-common profile succeeded.
- `TMPDIR="$PWD/.tmp" GOTMPDIR="$PWD/.tmp" go test -race -count=1 ./packages/go/execution` and `go vet ./packages/go/execution` in both checkouts — PASS.
- Deterministic source and history closure checks — PASS; no forbidden ownership phrase remained, commit parents and four-path sets matched, stable patch ids were equal, indexes and unmerged sets were empty, and canonical-only credential support was preserved.
- Receipt and protected-state checks — PASS; `HANDOFF.md` and Agent UI mirrors matched, recovery commit objects and promotion ancestry remained available, `origin/dev` stayed at `c3a24ec5febab9fc978fd62392efcb6c96e12ec9`, and the Chronos dependency lock remained `disable`.
## Remaining Nit
- None
## Follow-up Work
- None

View file

@ -0,0 +1,248 @@
<!-- task=m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure plan=2 tag=REVIEW_REFACTOR milestone-task=handoff-gate -->
# Plan - Provider-Only Ownership Wording Closure
## For the Implementing Agent
Filling the implementation-owned sections in `CODE_REVIEW-cloud-G08.md` is mandatory. Run every verification command, record actual notes and stdout/stderr, keep the active files in place, and report ready for review; finalization belongs only to the code-review skill. If blocked, record the exact blocker, attempted commands/output, and resume condition only in implementation-owned evidence fields. Do not ask the user, call user-input tools, create control-plane stop files, classify the next state, archive logs, or write `complete.log`.
## Background
Canonical promotion and the full regression matrix are reproducible, but active package and CLI descriptions still assign IOP execution to a standalone Agent and terminal-session model. This follow-up removes only those residual ownership statements, adds a focused CLI regression, and records equivalent staging and canonical corrective commits without disturbing protected roadmap, Agent UI, recovery, or lock state.
## Archive Evidence Snapshot
- `agent-task/m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/code_review_cloud_G10_0.log` recorded the first FAIL because canonical promotion had not occurred.
- `agent-task/m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/code_review_cloud_G10_1.log` records the current FAIL: promotion commit `c8e98d4e10b30114de7bafe426a4045abd6c1205`, the 34-path conflict digest, recovery artifacts, fresh regressions, mirroring, and the disabled lock were verified, but three active source descriptions still claim Agent/terminal ownership.
- The Required finding affects `packages/go/execution/doc.go`, `packages/go/execution/types.go`, and `apps/node/cmd/node/main.go`; `apps/node/cmd/node/main_test.go` is the focused regression target. The current canonical and staging source text is identical at each affected hunk, while canonical `types.go` intentionally retains unrelated credential support absent from staging.
- Roadmap carryover remains unchanged: the Milestone is review-open, the Chronos dependency lock remains `disable`, and this task must not archive the Milestone, enable the lock, push either branch, or mutate Chronos or any remote repository.
## Analysis
### Files Read
- `/config/workspace/iop/packages/go/execution/doc.go`
- `/config/workspace/iop/packages/go/execution/types.go`
- `/config/workspace/iop/packages/go/execution/conformance_test.go`
- `/config/workspace/iop/apps/node/cmd/node/main.go`
- `/config/workspace/iop/apps/node/cmd/node/main_test.go`
- `packages/go/execution/doc.go`
- `packages/go/execution/types.go`
- `packages/go/execution/conformance_test.go`
- `apps/node/cmd/node/main.go`
- `apps/node/cmd/node/main_test.go`
The canonical files were read in full. Staging `doc.go`, `main.go`, `main_test.go`, and `conformance_test.go` were byte-compared with canonical; staging `types.go` was read in full because canonical contains an unrelated `ProviderCredential` delta.
### SDD Criteria
- SDD: `agent-roadmap/sdd/automation-runtime-bridge/iop-agent-chronos-extraction-decoupling/SDD.md`; status `[승인됨]`; SDD lock `해제`.
- First-line Milestone task: `handoff-gate`.
- Targeted scenarios: S04 (`retain-node`) and S05 (`handoff-gate`). S04 requires provider-focused regression plus a forbidden-reference audit proving no CLI Agent, terminal, workspace, remote-control, or Chronos surface. S05 requires the tracked `HANDOFF.md`, rollback evidence, regression evidence, and lock identity to remain traceable.
- Evidence Map rows S04 and S05 therefore require the checklist to pair the source wording correction with a focused Node/execution regression and deterministic forbidden-text scan, then preserve the existing promotion/recovery evidence while adding exact corrective commit identities to the mirrored receipt. Final Milestone archive and lock enable remain excluded.
### Verification Context
No separate handoff was supplied. Repository-native evidence came from the active PLAN/review pair, the prior review log, approved SDD, active Milestone/Phase, execution contract/spec, domain and local-test rules, the five source/test files above, both HANDOFF files, git state, and fresh review commands.
Concrete criteria already applied: both affected checkouts were inspected; canonical HEAD is `c8e98d4e10b30114de7bafe426a4045abd6c1205` on `dev`; staging HEAD is `7b90b7e5af9035fae2b5349c65eb322096d21b1b` on `feature/iop-agent-chronos-extraction-decoupling`; neither checkout has staged or unmerged paths. Canonical has exactly seven intentional unstaged tracked paths: `HANDOFF.md`, three roadmap files, and three Agent UI files. `git version 2.43.0`, `go version go1.26.2 linux/arm64`, Linux/aarch64, and local filesystem access are available. Confidence is high because the offending strings and intended regression entry point are direct source evidence.
External Verification Preflight: the only verification outside the current checkout is the local canonical repository at `/config/workspace/iop`; no remote runner, binary artifact, credential, config, port, process, or external host is required. The implementer must require the exact HEADs above, empty index/unmerged state, and the canonical seven-path dirty inventory before mutation. If any identity or protected path differs, record a blocker instead of rebasing, resetting, stashing, or broadening scope.
### Test Coverage Gaps
- Package and error comments are non-executable; current runtime tests cannot detect ownership wording. The deterministic exact-file forbidden-text scan is the regression oracle.
- Cobra root help exposes `Command.Short`, but existing `main_test.go` checks only command presence and behavior. Add `TestRootCmdUsesProviderOnlyDescription` to require provider wording and reject Agent wording.
- Execution behavior does not change. Existing fresh tests in `./packages/go/execution` and `./apps/node/cmd/node` cover compilation and run/provider behavior; no broader runtime test source change is justified.
### Symbol References
None. No symbol, type, command, flag, or wire field is renamed or removed.
### Split Judgment
Do not split. Four small source/test hunks, their equivalent two-repository commits, and the mirrored corrective receipt are one compact closure invariant: the reviewed text must be provider-only and traceable in both checkouts before the S04/S05 evidence can pass.
### Scope Rationale
Exclude runtime logic, wire/proto/config, generated files, roadmap/SDD state, Agent UI content, existing recovery artifacts, remote branches, Chronos sources, and lock mutation. The fresh full regression evidence from the preceding review remains valid because this packet changes comments, Cobra help text, one focused test, and receipt metadata only; focused uncached Go tests and deterministic boundary/state checks are sufficient.
### Final Routing
- `evaluation_mode=isolated-reassessment`; `finalizer=finalize-task-policy.sh`; `finalizer_mode=pair`.
- Build closures: scope, context, verification, evidence trust, ownership, and decision are all closed; no capability gap. Scores: scope coupling 2, state/concurrency 2, blast/irreversibility 1, evidence/diagnosis 1, verification complexity 2; grade G08. Base `local-fit` is promoted by `recovery-boundary` to `cloud`; canonical filename `PLAN-cloud-G08.md`.
- Review closures: all closed; no capability gap. Scores 2/2/1/1/2; route `official-review`, cloud G08; canonical filename `CODE_REVIEW-cloud-G08.md`.
- `large_indivisible_context=false`; positive loop risks: `temporal_state`, `boundary_contract`; count 2. `review_rework_count=2`; `evidence_integrity_failure=false`; recovery boundary matched, risk boundary did not. No capability-gap evidence applies.
## Implementation Checklist
- [ ] Correct the provider-only ownership wording in staging and canonical source, and add the focused Node CLI regression test.
- [ ] Create exact staging/canonical corrective commits, update mirrored HANDOFF evidence, and verify protected state, ancestry, recovery, and lock preservation.
- [ ] Fill implementation-owned sections in CODE_REVIEW-*-G??.md with actual implementation notes and verification output.
### [REVIEW_REFACTOR-1] Correct provider-only source wording and add a focused regression
**Problem**
`packages/go/execution/doc.go:1-4` says the package is shared with standalone Agent hosts and owns terminal-session primitives. `packages/go/execution/types.go:15` describes cancellation through persistent-session termination semantics. `apps/node/cmd/node/main.go:29` labels the provider device runtime as `IOP Node Agent`. These active descriptions contradict SDD S04 and the provider-only execution contract.
**Solution**
Apply the same logical edits independently in staging and canonical so canonical-only credential code remains untouched.
Before (`packages/go/execution/doc.go:1-4`):
```go
// Package execution contains the host-neutral execution contract shared by
// IOP Node and standalone agent hosts. It owns provider lifecycle, streaming
// events, typed failures, registry lifecycle, and terminal session primitives;
// host wire translation remains outside this package.
```
After:
```go
// Package execution contains provider-only, host-neutral execution contracts
// shared by Node and Edge-facing provider transports. It owns provider
// lifecycle, streaming events, typed failures, and registry lifecycle;
// host wire translation remains outside this package.
```
Before (`packages/go/execution/types.go:15`):
```go
// ErrRunCancelled is returned by adapters when a run is cancelled without terminating the session.
```
After:
```go
// ErrRunCancelled is returned by providers when a single run is cancelled.
```
Before (`apps/node/cmd/node/main.go:29`):
```go
Short: "IOP Node Agent — runs adapter executions on this device",
```
After:
```go
Short: "IOP Node — runs provider executions on this device",
```
Add `TestRootCmdUsesProviderOnlyDescription` to assert that `rootCmd().Short` contains `provider` and does not contain `agent`, case-insensitively.
**Modified Files and Checklist**
- [ ] Update `packages/go/execution/doc.go` in staging and canonical with provider-only ownership.
- [ ] Update `packages/go/execution/types.go` in staging and canonical with run-scoped cancellation wording, preserving unrelated canonical credential fields.
- [ ] Update `apps/node/cmd/node/main.go` in staging and canonical with the provider-device description.
- [ ] Add the identical focused regression to `apps/node/cmd/node/main_test.go` in both checkouts.
- [ ] Run `gofmt` only on the changed Go files and prove the exact forbidden phrases are absent from the three production files.
**Test Strategy**
Add the regression test `TestRootCmdUsesProviderOnlyDescription` in `apps/node/cmd/node/main_test.go`; it guards the user-visible CLI description. Do not add a test that parses Go comments. The exact-file, case-insensitive forbidden-text scan directly guards the two documentation corrections. Fresh Go execution is required; cached output is not accepted.
**Verification**
Run from each checkout:
```bash
gofmt -w packages/go/execution/doc.go packages/go/execution/types.go apps/node/cmd/node/main.go apps/node/cmd/node/main_test.go
if rg --sort path -n -i 'standalone agent|terminal session primitives|terminating the session|IOP Node Agent' packages/go/execution/doc.go packages/go/execution/types.go apps/node/cmd/node/main.go; then exit 1; fi
rg --sort path -n 'provider-only|single run is cancelled|IOP Node — runs provider executions' packages/go/execution/doc.go packages/go/execution/types.go apps/node/cmd/node/main.go
TMPDIR="$PWD/.tmp" GOTMPDIR="$PWD/.tmp" go test -count=1 ./packages/go/execution ./apps/node/cmd/node
git diff --check
```
Expected: no forbidden match; all three provider/run-scoped assertions match; the focused fresh tests and diff check pass.
### [REVIEW_REFACTOR-2] Commit and record equivalent corrective closure
**Problem**
`HANDOFF.md:83-86` records the staging promotion commit and canonical promotion commit but has no identity for a post-promotion boundary correction. Leaving the text only as dirty worktree state would break the S05 traceability chain, while rewriting either reviewed commit would invalidate the verified promotion and recovery evidence.
**Solution**
In staging, require parent HEAD `7b90b7e5af9035fae2b5349c65eb322096d21b1b`, stage only the four REVIEW_REFACTOR-1 paths, and create one corrective commit. In canonical, require parent HEAD `c8e98d4e10b30114de7bafe426a4045abd6c1205` and the exact seven protected dirty paths, stage only the same four logical paths, and create one child corrective commit while leaving all protected paths unstaged. Do not amend, reset, stash, push, or touch the retained recovery artifacts.
Then update canonical and staging `HANDOFF.md` identically: preserve `staging_promotion_commit` and `canonical_promotion_commit`; add `staging_boundary_correction_commit`, `canonical_boundary_correction_commit`, and `canonical_boundary_correction_verified_at`; and update the Canonical Promotion Receipt prose to identify the child correction. The new fields must contain actual commits with the required parents and exact four-path change sets.
**Modified Files and Checklist**
- [ ] Preflight exact staging/canonical HEAD, empty staged/unmerged state, and canonical protected seven-path inventory.
- [ ] Commit only the four source/test paths in staging with parent `7b90b7e5...`.
- [ ] Commit only the four source/test paths in canonical with parent `c8e98d4...`; preserve its seven unstaged tracked paths.
- [ ] Prove the two corrective diffs have the same stable patch id and neither commit contains task, roadmap, UI, receipt, generated, or unrelated source paths.
- [ ] Add actual corrective commit ids and verification time to both `HANDOFF.md` files and require byte equality.
- [ ] Re-run focused tests and boundary scans on committed heads; verify promotion/correction ancestry, retained recovery commits, clean indexes, UI mirrors, and disabled Chronos lock.
**Test Strategy**
No additional test source is required beyond REVIEW_REFACTOR-1. This item is a history/evidence transaction guarded by exact parent, path-set, stable patch-id, ancestry, dirty-inventory, mirror, stash-object, and lock checks. Any mismatch is a blocker; do not repair it with a history rewrite.
**Verification**
Run the preflight before editing or committing:
```bash
test "$(git rev-parse HEAD)" = 7b90b7e5af9035fae2b5349c65eb322096d21b1b
test -z "$(git diff --cached --name-only)"
test -z "$(git ls-files -u)"
test "$(git -C /config/workspace/iop rev-parse HEAD)" = c8e98d4e10b30114de7bafe426a4045abd6c1205
test -z "$(git -C /config/workspace/iop diff --cached --name-only)"
test -z "$(git -C /config/workspace/iop ls-files -u)"
diff -u <(printf '%s\n' HANDOFF.md agent-roadmap/phase/automation-runtime-bridge/PHASE.md agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md agent-roadmap/priority-queue.md agent-ui/.sync-state.json agent-ui/definition/components/console-shell/index.md agent-ui/definition/components/index.md) <(git -C /config/workspace/iop diff --name-only | sort)
```
After the two source/test commits and mirrored receipt update, run:
```bash
staging_correction="$(git rev-parse HEAD)"
canonical_correction="$(git -C /config/workspace/iop rev-parse HEAD)"
test "$(git rev-parse HEAD^)" = 7b90b7e5af9035fae2b5349c65eb322096d21b1b
test "$(git -C /config/workspace/iop rev-parse HEAD^)" = c8e98d4e10b30114de7bafe426a4045abd6c1205
expected_paths="$(printf '%s\n' apps/node/cmd/node/main.go apps/node/cmd/node/main_test.go packages/go/execution/doc.go packages/go/execution/types.go)"
test "$(git diff-tree --no-commit-id --name-only -r HEAD | sort)" = "$expected_paths"
test "$(git -C /config/workspace/iop diff-tree --no-commit-id --name-only -r HEAD | sort)" = "$expected_paths"
test "$(git diff 7b90b7e5af9035fae2b5349c65eb322096d21b1b..HEAD -- $expected_paths | git patch-id --stable | awk '{print $1}')" = "$(git -C /config/workspace/iop diff c8e98d4e10b30114de7bafe426a4045abd6c1205..HEAD -- $expected_paths | git patch-id --stable | awk '{print $1}')"
test -z "$(git diff --cached --name-only)"
test -z "$(git -C /config/workspace/iop diff --cached --name-only)"
test -z "$(git ls-files -u)"
test -z "$(git -C /config/workspace/iop ls-files -u)"
diff -u <(printf '%s\n' HANDOFF.md agent-roadmap/phase/automation-runtime-bridge/PHASE.md agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md agent-roadmap/priority-queue.md agent-ui/.sync-state.json agent-ui/definition/components/console-shell/index.md agent-ui/definition/components/index.md) <(git -C /config/workspace/iop diff --name-only | sort)
cmp /config/workspace/iop/HANDOFF.md HANDOFF.md
test "$(sed -n 's/^staging_boundary_correction_commit: //p' HANDOFF.md)" = "$staging_correction"
test "$(sed -n 's/^canonical_boundary_correction_commit: //p' HANDOFF.md)" = "$canonical_correction"
git -C /config/workspace/iop merge-base --is-ancestor c8e98d4e10b30114de7bafe426a4045abd6c1205 "$canonical_correction"
git -C /config/workspace/iop cat-file -e a91e4af2bc23c7fab2ef0ea026e2b453e9393848^{commit}
git -C /config/workspace/iop cat-file -e ff81ecb5e8b16fc81ecce4273afe24ff06236287^{commit}
cmp /config/workspace/iop/agent-ui/.sync-state.json agent-ui/.sync-state.json
cmp /config/workspace/iop/agent-ui/definition/components/console-shell/index.md agent-ui/definition/components/console-shell/index.md
cmp /config/workspace/iop/agent-ui/definition/components/index.md agent-ui/definition/components/index.md
agent-ops/bin/roadmap-dependency-checker.sh --find-milestone 'iop:agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md' both /config/workspace/.agent-roadmap-sync/locks.yaml
rg -n -A4 'id: chronos:chronos-architecture-ownership-boundary' /config/workspace/.agent-roadmap-sync/locks.yaml
```
Expected: both commits have exact parents and four-path change sets; their stable patch ids match; receipt fields resolve to the actual commits; canonical promotion and recovery ancestry remain intact; indexes are clean; UI and HANDOFF mirrors match; dependency output identifies the Chronos boundary and lock status remains `disable`.
## Modified Files Summary
| File | Items |
|------|-------|
| `packages/go/execution/doc.go` | REVIEW_REFACTOR-1, REVIEW_REFACTOR-2 |
| `packages/go/execution/types.go` | REVIEW_REFACTOR-1, REVIEW_REFACTOR-2 |
| `apps/node/cmd/node/main.go` | REVIEW_REFACTOR-1, REVIEW_REFACTOR-2 |
| `apps/node/cmd/node/main_test.go` | REVIEW_REFACTOR-1, REVIEW_REFACTOR-2 |
| `HANDOFF.md` | REVIEW_REFACTOR-2 |
| `agent-task/m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/CODE_REVIEW-cloud-G08.md` | REVIEW_REFACTOR-1, REVIEW_REFACTOR-2 |
## Final Verification
Run every REVIEW_REFACTOR-1 command from both checkouts and every REVIEW_REFACTOR-2 command in the stated order. Require fresh focused Go PASS, no forbidden ownership text, exact corrective commit parents/path sets/patch equivalence, clean indexes and unmerged state, canonical protected dirty paths preserved, byte-identical HANDOFF/UI evidence, retained recovery commit objects, promotion ancestry, and a disabled Chronos lock. Record actual stdout/stderr or exact saved output paths in the active review artifact; cached Go output is not accepted.
After completing all code changes, fill implementation-owned sections in `CODE_REVIEW-*-G??.md`.

View file

@ -0,0 +1,348 @@
<!-- task=m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure plan=0 tag=REFACTOR milestone-task=handoff-gate -->
# Canonical IOP Promotion and Closure Readiness
## For the Implementing Agent
Filling implementation-owned sections in `CODE_REVIEW-cloud-G10.md` is mandatory. Run every verification command, paste actual output or an exact saved-output path, keep the active PLAN/review files in place, and report ready for review. Finalization belongs only to the code-review skill. If blocked, record the exact blocker, attempted commands/output, and resume condition in implementation-owned evidence fields; do not ask the user, call user-input tools, create control-plane stop files, classify the next state, archive logs, or write `complete.log`.
## Background
All implementation tasks and fresh regressions for the extraction milestone pass in `/config/workspace/iop-s1`, but `HANDOFF.md:83-88` still records canonical promotion as pending. The approved SDD requires a reviewed commit to be applied to `/config/workspace/iop` before the canonical `iop:` milestone can justify the Chronos lock. The canonical checkout is one commit behind `origin/dev` and has three user-owned roadmap edits, so promotion, reconciliation, and rollback evidence must be handled as one ordered closure packet.
## Archive Evidence Snapshot
- `agent-task/archive/2026/08/m-iop-agent-chronos-extraction-decoupling/15+14_handoff_closure/complete.log`: PASS; the tracked final composite receipt and exact `HANDOFF.md` digest were accepted after Task 14 removal evidence.
- `agent-task/archive/2026/08/m-iop-agent-chronos-extraction-decoupling/16_manifest_baseline_repair/complete.log`: PASS; corrected pinned-transfer manifest baseline is 300 rows (`file=290`, `state=10`, `retain-generic=135`) with SHA-256 `d8598134dee99d96fc05a045091dd3d8932d4708d2c980c2a78c8b11825d2ccf`.
- No Required, Suggested, or Nit findings remain in those predecessor completion records. This plan does not reinterpret archived evidence; it promotes the already accepted result and records the canonical identity.
## Analysis
### Files Read
- `HANDOFF.md`
- `agent-roadmap/current.md`
- `agent-roadmap/priority-queue.md`
- `agent-roadmap/phase/automation-runtime-bridge/PHASE.md`
- `agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md`
- `agent-roadmap/sdd/automation-runtime-bridge/iop-agent-chronos-extraction-decoupling/SDD.md`
- `agent-ui/.sync-state.json`
- `agent-ui/definition/components/console-shell/index.md`
- `agent-ui/definition/components/index.md`
- `/config/workspace/.agent-roadmap-sync/locks.yaml`
- `/config/workspace/iop/agent-roadmap/current.md`
- `/config/workspace/iop/agent-roadmap/priority-queue.md`
- `/config/workspace/iop/agent-roadmap/phase/automation-runtime-bridge/PHASE.md`
- `/config/workspace/iop/agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md`
- `/config/workspace/iop/agent-ui/.sync-state.json`
- `/config/workspace/iop/agent-ui/definition/components/console-shell/index.md`
No production source or test behavior changes are planned. Existing milestone behavior is verified through repository-native commands rather than new test source.
### SDD Criteria
- SDD: `agent-roadmap/sdd/automation-runtime-bridge/iop-agent-chronos-extraction-decoupling/SDD.md`, status `[승인됨]`, SDD lock `해제`.
- Milestone task metadata: `handoff-gate`.
- Acceptance Scenario: S05. Its `Then` condition requires every disposition input, state transfer, deletion/regression result, rollback point, and Chronos lock release condition to remain traceable.
- Evidence Map row: S05 requires the state fixture, effective matrix, Task 13 receipt, Task 14 evidence, tracked `HANDOFF.md`, and lock check, with a final composite receipt suitable for Roadmap Completion.
- Cross-repo dependency: the predecessor identity is the canonical `iop:agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md`; `iop-s1` cannot satisfy it by itself.
- These rows require the checklist to preserve all predecessor receipts, record both promotion commits, rerun canonical regressions, reconcile milestone-scoped UI state, and leave the parent lock disabled until a later successful `complete-milestone` archive transaction.
### Verification Context
- No separate handoff object was supplied. Repository-native fallback evidence came from the milestone, approved SDD, `HANDOFF.md`, scoped predecessor `complete.log` files, Agent UI sync state, parent workspace lock, current git state, and executable Make targets.
- Fresh checks already passed in `/config/workspace/iop-s1`: `go test -count=1 ./...`, `make client-test` (44 tests), `make client-build-web`, `make test-control-plane-edge-wire`, `make readability-audit`, `IOP_DEV_RECONNECT_BIND_TIMEOUT=60 scripts/dev/edge-node-reconnect-diagnostic.sh`, and `git diff --check`.
- The direct reconnect spec pointer was also verified with `go test -count=1 ./apps/edge/internal/service -run '^TestAcceptedReconnectActivatesCandidateAndPumpsWaiter$'`.
- Required tools are present: Git 2.43.0, Go 1.26.2, GNU Make, Flutter, and Dart on Linux 6.10.14 aarch64.
- Cached Go output is not accepted for canonical closure; use `-count=1` and a canonical-checkout-local `TMPDIR`/`GOTMPDIR`.
#### External Verification Preflight
- Runner: current host.
- Staging repo/workdir: `/config/workspace/iop-s1`, branch `feature/iop-agent-chronos-extraction-decoupling`, pre-plan HEAD `1debc7ada01d98442560bbc4ac52dcef9cae25cc`, dirty milestone change set.
- Canonical repo/workdir: `/config/workspace/iop`, branch `dev`, HEAD `6d6bb3a44d1384e8248d482f57de522dc800aade`, `dev...origin/dev [behind 1]`.
- Canonical dirty state is exactly:
- `agent-roadmap/phase/automation-runtime-bridge/PHASE.md`
- `agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md`
- `agent-roadmap/priority-queue.md`
- Those edits add canonical `[separation-01]` labels and queue grouping. They are user-owned and must be preserved, not replaced by staging roadmap bytes.
- Source sync status: unresolved until implementation fetches `origin`, verifies that the canonical branch relationship and dirty set have not changed, and forms one reviewed staging promotion commit.
- Binary/artifact paths: repository-local Go/Flutter builds only; no pre-existing binary is trusted.
- Config/runtime identity: repository test fixtures and loopback scripts; no live provider credential or external host is required.
- Ports/process state: `make test-control-plane-edge-wire` and the reconnect diagnostic allocate their documented loopback processes; pre-existing shared processes are not assumed.
- Recovery: before canonical mutation, save the exact three-file binary diff and SHA-256 under a `mktemp -d /tmp/iop-canonical-promotion.XXXXXX` directory and create a named Git stash with only those three paths. Use `git stash apply`, not `pop`, and retain the stash until all canonical verification and patch-equivalence checks pass.
- If branch, HEAD, remote relation, dirty paths, patch digest, or lock identity differs, stop and record the mismatch; do not reset, overwrite, drop a stash, archive the milestone, or enable the lock.
### Test Coverage Gaps
- Promotion does not change runtime behavior. Existing fresh Go, Flutter, Control Plane/Edge wire, reconnect, readability, and forbidden-surface checks cover the promoted code paths.
- Git conflict resolution and the cross-workspace lock transition have no automated end-to-end test. They are covered by exact pre/post git tree comparisons, the dependency checker, retained patch/stash rollback evidence, and a mandatory later `complete-milestone` check-only pass.
- No new test source is required because this packet changes integration state and evidence only.
### Symbol References
- None. No symbol is renamed or removed by this packet.
### Split Judgment
- This remains one plan because canonical apply, regression proof, UI reconciliation, and lock ordering share one safety invariant: the canonical identity must not become closure-ready unless the exact reviewed staging tree is present and verified, and the Chronos lock must remain disabled until the later archive transaction succeeds.
- Dependency `15` is satisfied by `agent-task/archive/2026/08/m-iop-agent-chronos-extraction-decoupling/15+14_handoff_closure/complete.log`.
- Dependency `16` is satisfied by `agent-task/archive/2026/08/m-iop-agent-chronos-extraction-decoupling/16_manifest_baseline_repair/complete.log`.
- A staging-only commit is not treated as an independently complete milestone result, so it is not split from canonical reconciliation.
### Scope Rationale
- Included: promotion of the existing reviewed change set, preservation of canonical user-owned roadmap edits, canonical regression verification, Agent UI milestone reconciliation, and exact promotion evidence.
- Excluded: new runtime behavior, Chronos repository import, Chronos Server/Node implementation, provider credentials, remote deployment, and final milestone archive/lock enable. Final archive and lock enable remain owned by a subsequent `complete-milestone` run after this plan receives PASS.
- `/config/workspace/iop/**` and `/config/workspace/.agent-roadmap-sync/locks.yaml` are external preflight/action targets, not dispatcher write claims for this `/config/workspace/iop-s1` task. The implementing agent must use the explicit guarded procedure below and must not broaden external writes.
### Final Routing
- `evaluation_mode=first-pass`; `finalizer=finalize-task-policy.sh`, mode `pair`.
- Build closures: scope/context/verification/evidence/ownership/decision all closed by the exact repositories, protected dirty-path procedure, deterministic commands, and no unresolved product choice. Scores: scope 2, state 2, blast 2, evidence 2, verification 2 => G10. Base/final route: `grade-boundary`, cloud, `PLAN-cloud-G10.md`.
- Review closures: all closed. Scores: scope 2, state 2, blast 2, evidence 2, verification 2 => G10. Route: `official-review`, cloud, `CODE_REVIEW-cloud-G10.md`, Codex `gpt-5.6-sol` xhigh.
- `large_indivisible_context=false`; the invariant is explicit and commands are deterministic.
- Positive loop-risk signatures: `temporal_state`, `boundary_contract`, `structured_interpretation`; count 3. Risk boundary not matched.
- `review_rework_count=0`; `evidence_integrity_failure=false`; recovery boundary not matched; capability gap none.
## Implementation Checklist
- [ ] Freeze and promote the reviewed staging change set into canonical IOP without losing the canonical roadmap patch.
- [ ] Verify canonical code, contracts, UI, and provider-only boundaries, then reconcile milestone-scoped Agent UI state while keeping the Chronos lock disabled.
- [ ] Record exact staging/canonical promotion evidence in HANDOFF.md and mirror reconciled UI evidence in this workspace.
- [ ] Run the complete final verification matrix and preserve recovery evidence.
- [ ] Fill implementation-owned sections in CODE_REVIEW-*-G??.md with actual implementation notes and verification output.
### [REFACTOR-1] Protect canonical state and apply the reviewed staging commit
**Problem**
`HANDOFF.md:83-88` says canonical promotion is pending. `/config/workspace/iop` is both behind `origin/dev` and dirty in three roadmap files, so a direct pull/cherry-pick can lose user-owned separation labels or mix an unreviewed tree into the canonical identity.
**Solution**
1. Re-run the external preflight and require the exact branch/dirty-path facts above.
2. Use the project `commit-push` workflow to form one intentional staging promotion commit. Push only if the execution request authorizes push; a local commit is sufficient for a local canonical fetch/cherry-pick.
3. Save the canonical three-file binary diff and its SHA-256 under a task-specific `/tmp` directory, then stash only those explicit paths with a descriptive name. Do not use a broad reset or checkout.
4. Fetch `origin` and the staging promotion commit, fast-forward canonical `dev` only when it is still an ancestor of `origin/dev`, then cherry-pick the staging commit.
5. Resolve only the three known roadmap conflicts by retaining canonical `[separation-01]`/queue semantics and applying the newer milestone completion evidence. Apply the retained stash, verify patch equivalence, and keep the stash until all checks pass.
Before (`/config/workspace/iop`):
```text
dev...origin/dev [behind 1]
M agent-roadmap/phase/automation-runtime-bridge/PHASE.md
M agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md
M agent-roadmap/priority-queue.md
```
After:
```text
canonical dev contains the reviewed staging promotion commit
the three canonical separation/queue edits remain represented
no unmerged paths exist
the saved patch and named stash remain recoverable until verification passes
```
**Modified Files and Checklist**
- [ ] Preserve and reconcile `/config/workspace/iop/agent-roadmap/phase/automation-runtime-bridge/PHASE.md`.
- [ ] Preserve and reconcile `/config/workspace/iop/agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md`.
- [ ] Preserve and reconcile `/config/workspace/iop/agent-roadmap/priority-queue.md`.
- [ ] Do not modify `/config/workspace/.agent-roadmap-sync/locks.yaml` in this item.
**Test Strategy**
No new test source. Verify exact dirty-path preservation, no unmerged entries, commit ancestry, and non-roadmap tree equivalence between the staging promotion commit and canonical result.
**Verification**
```bash
git -C /config/workspace/iop status -sb
git -C /config/workspace/iop diff --name-only | LC_ALL=C sort
git -C /config/workspace/iop diff --check
git -C /config/workspace/iop diff --name-only --diff-filter=U
```
Expected: canonical is on `dev`; only intentional post-apply evidence edits may be dirty; `diff --check` passes; no unmerged path is printed.
### [REFACTOR-2] Prove canonical closure readiness and reconcile Agent UI
**Problem**
The current staging Agent UI state at `agent-ui/.sync-state.json:21-49` still has pending milestone work for `component:console-shell`, and `agent-ui/definition/components/console-shell/index.md:4,24` remains `계획`. The pending entry may be reconciled only after canonical code and required Flutter verification pass. The parent lock must remain disabled until final archive.
**Solution**
Run the full canonical regression matrix on fresh output. Execute `complete-milestone` in check-only mode in `/config/workspace/iop`; only a closure-ready result may trigger `sync-agent-ui mode=reconcile-milestone-completion`. Update both the component document and components index to `구현됨`, move the exact pending entry to reconciled milestone work with the actual verification evidence, validate Agent UI, and re-run check-only. Do not archive the milestone or enable the parent lock in this task.
Before:
```yaml
component_id: console-shell
status: 계획
```
After:
```yaml
component_id: console-shell
status: 구현됨
```
**Modified Files and Checklist**
- [ ] Reconcile `/config/workspace/iop/agent-ui/.sync-state.json` only after canonical Flutter tests/build pass.
- [ ] Update `/config/workspace/iop/agent-ui/definition/components/console-shell/index.md` status and decision history.
- [ ] Update `/config/workspace/iop/agent-ui/definition/components/index.md` summary status.
- [ ] Mirror those reconciled Agent UI bytes into `agent-ui/.sync-state.json`, `agent-ui/definition/components/console-shell/index.md`, and `agent-ui/definition/components/index.md` in this workspace.
- [ ] Confirm `/config/workspace/.agent-roadmap-sync/locks.yaml` still reports the canonical target as `disable` before the later archive run.
**Test Strategy**
No new test source. Existing Flutter shell tests and web build are the declared pending-work requirements. Full Go, Control Plane/Edge wire, reconnect, readability, forbidden-surface, and Agent UI structure checks prevent a promotion-only false positive.
**Verification**
```bash
mkdir -p /config/workspace/iop/.tmp
TMPDIR=/config/workspace/iop/.tmp GOTMPDIR=/config/workspace/iop/.tmp go test -count=1 ./...
make client-test
make client-build-web
make test-control-plane-edge-wire
make readability-audit
IOP_DEV_RECONNECT_BIND_TIMEOUT=60 scripts/dev/edge-node-reconnect-diagnostic.sh
```
Run from `/config/workspace/iop`. Expected: all commands exit 0; reconnect initial and reconnect cycles preserve Node-local/Edge-rendered payload equivalence and one terminal completion.
### [REFACTOR-3] Record exact promotion evidence without opening the lock
**Problem**
`HANDOFF.md:83-88` has no staging promotion commit, canonical commit, verification timestamp, or applied status. Without exact commit identities, SDD S05 evidence cannot distinguish a verified canonical apply from the staging checkout result.
**Solution**
After canonical verification and Agent UI reconciliation, update `HANDOFF.md` in canonical and this workspace with actual 40-hex commit identities, `canonical_promotion: applied`, UTC verification time, canonical identity, and the still-disabled downstream lock result. Update the prose status at `HANDOFF.md:94-109` and evidence sequence at `HANDOFF.md:140-145` so it describes completed D04 separation and pending final roadmap archive, not unfinished Tasks 10/13/14/15.
Before:
```yaml
canonical_promotion: pending
canonical_lock_identity: iop:agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md
canonical_lock_result: rely-on:chronos:chronos-architecture-ownership-boundary
```
After schema:
```yaml
canonical_promotion: applied
staging_promotion_commit: <actual 40-hex commit>
canonical_promotion_commit: <actual 40-hex commit>
canonical_promotion_verified_at: <actual UTC timestamp>
canonical_lock_identity: iop:agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md
canonical_lock_result: rely-on:chronos:chronos-architecture-ownership-boundary (disabled until final archive)
```
**Modified Files and Checklist**
- [ ] Update `/config/workspace/iop/HANDOFF.md` with actual canonical promotion evidence.
- [ ] Mirror the same promotion evidence into `HANDOFF.md` in this workspace.
- [ ] Preserve every Task 13-16 digest and receipt pointer already present.
- [ ] Leave milestone archive and lock enable to the subsequent `complete-milestone` run.
**Test Strategy**
No new test source. Validate commit existence, 40-hex formatting, ancestor relationships, receipt digests, and exact dependency-checker output.
**Verification**
```bash
git -C /config/workspace/iop rev-parse --verify HEAD^{commit}
git -C /config/workspace/iop-s1 rev-parse --verify HEAD^{commit}
rg -n '^canonical_promotion: applied$|^staging_promotion_commit: [0-9a-f]{40}$|^canonical_promotion_commit: [0-9a-f]{40}$|^canonical_promotion_verified_at: ' /config/workspace/iop/HANDOFF.md HANDOFF.md
agent-ops/bin/roadmap-dependency-checker.sh --find-milestone 'iop:agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md' both /config/workspace/.agent-roadmap-sync/locks.yaml
```
Expected: both commit objects resolve; both handoff files contain exact promotion fields; dependency checker prints `rely-on:chronos:chronos-architecture-ownership-boundary`; the corresponding lock entry remains disabled.
### [REFACTOR-4] Run final guarded verification and retain rollback evidence
**Problem**
The next completion run must be able to distinguish closure-ready canonical state from partial promotion. A successful code test alone does not prove canonical roadmap reconciliation, UI state, lock ordering, or rollback preservation.
**Solution**
Capture all final command output in the review evidence. Require clean diff checks in both workspaces, no forbidden migration surface, no pending Agent UI entry for this milestone, canonical `[검토중]` with all five task ids checked, and the parent lock still disabled. Retain the `/tmp` patch and named stash locator in review evidence; do not drop the stash in this plan.
**Modified Files and Checklist**
- [ ] Fill `agent-task/m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/CODE_REVIEW-cloud-G10.md` with actual outputs and recovery locators.
- [ ] Do not archive the milestone, delete recovery evidence, or enable the Chronos lock.
**Test Strategy**
No new test source. This item aggregates deterministic state, content, and regression oracles required for the later completion transaction.
**Verification**
Run the commands in Final Verification and require every stated result.
## Modified Files Summary
| File | Items |
|------|-------|
| `HANDOFF.md` | REFACTOR-3 |
| `agent-ui/.sync-state.json` | REFACTOR-2, REFACTOR-3 |
| `agent-ui/definition/components/console-shell/index.md` | REFACTOR-2, REFACTOR-3 |
| `agent-ui/definition/components/index.md` | REFACTOR-2, REFACTOR-3 |
| `agent-task/m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/CODE_REVIEW-cloud-G10.md` | REFACTOR-4 |
## Final Verification
Run canonical runtime verification from `/config/workspace/iop`:
```bash
mkdir -p /config/workspace/iop/.tmp
TMPDIR=/config/workspace/iop/.tmp GOTMPDIR=/config/workspace/iop/.tmp go test -count=1 ./...
make client-test
make client-build-web
make test-control-plane-edge-wire
make readability-audit
IOP_DEV_RECONNECT_BIND_TIMEOUT=60 scripts/dev/edge-node-reconnect-diagnostic.sh
git diff --check
```
Expected: every command exits 0 with fresh Go execution; Flutter tests/build, real Control Plane/Edge wire, readability ratchet, and initial/reconnect diagnostic pass.
Run deterministic boundary and state checks from `/config/workspace/iop`:
```bash
if rg --sort path -n -i 'chronos|agent_bridge|iop-agent|iop_agent|IopAgent|agentruntime|agentprovider|agenttask|agentworkspace' apps packages/go cmd proto configs; then exit 1; fi
test ! -d apps/agent
test -z "$(find packages/go -maxdepth 1 -type d -name 'agent*' -print -quit)"
test -z "$(git diff --name-only --diff-filter=U)"
rg -n '^status: 구현됨$|^Status: `구현됨`$' agent-ui/definition/components/console-shell/index.md
jq -e '.pending_milestone_work | length == 0' agent-ui/.sync-state.json
jq -e '.reconciled_milestone_work | any(.milestone_path == "agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md" and .state == "reconciled")' agent-ui/.sync-state.json
rg -n '^canonical_promotion: applied$|^staging_promotion_commit: [0-9a-f]{40}$|^canonical_promotion_commit: [0-9a-f]{40}$' HANDOFF.md
git diff --check
```
Expected: forbidden runtime surfaces and old package roots are absent; no unmerged entry exists; console shell and sync state are reconciled; promotion evidence is exact; diff check passes.
Run cross-workspace lock and preservation checks from `/config/workspace/iop-s1`:
```bash
git diff --check
rg -n '^canonical_promotion: applied$|^staging_promotion_commit: [0-9a-f]{40}$|^canonical_promotion_commit: [0-9a-f]{40}$' HANDOFF.md
agent-ops/bin/roadmap-dependency-checker.sh --find-milestone 'iop:agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md' both /config/workspace/.agent-roadmap-sync/locks.yaml
rg -n -A4 'id: chronos:chronos-architecture-ownership-boundary' /config/workspace/.agent-roadmap-sync/locks.yaml
```
Expected: local evidence matches canonical evidence; dependency checker prints `rely-on:chronos:chronos-architecture-ownership-boundary`; its `rely-on` status is still `disable`. Record the retained canonical roadmap patch path, SHA-256, and named stash locator in `CODE_REVIEW-cloud-G10.md`.
After completing all code changes, fill implementation-owned sections in `CODE_REVIEW-*-G??.md`.

View file

@ -0,0 +1,345 @@
<!-- task=m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure plan=1 tag=REVIEW_REFACTOR milestone-task=handoff-gate -->
# Canonical Promotion Integration Rework
## For the Implementing Agent
Execute only the implementation, verification, and evidence steps in this plan. Do not classify user-review state, create control-plane stop files, archive this task pair, write `complete.log`, change roadmap completion state, or enable the Chronos dependency lock. If a guarded precondition fails, record the exact blocker and recovery state in the active code-review artifact and stop safely.
## Background
The first canonical promotion attempt safely aborted after `git cherry-pick 7b90b7e5af9035fae2b5349c65eb322096d21b1b` exposed 34 conflicts against canonical commit `c3a24ec5febab9fc978fd62392efcb6c96e12ec9`. The attempt preserved the canonical three-file roadmap patch and left no unmerged state, but no extraction code reached canonical IOP and none of the required canonical regression commands ran. This follow-up rebuilds the reviewed extraction change on the exact canonical base in an isolated worktree, explicitly preserves the newer managed credential/TLS/projection work, then performs the guarded canonical promotion and closure evidence steps.
## Archive Evidence Snapshot
- Prior plan: `agent-task/m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/plan_cloud_G10_0.log`
- Prior review: `agent-task/m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/code_review_cloud_G10_0.log`
- Prior verdict: `FAIL`
- Required finding count: `1`
- Suggested finding count: `0`
- Nit count: `0`
- Review routing signals: `review_rework_count=1`, `evidence_integrity_failure=false`
- Recovery evidence retained by the failed attempt:
- roadmap patch: `/tmp/iop-canonical-promotion.QOCOar/canonical-roadmap.patch`
- conflict inventory: `/tmp/iop-canonical-promotion.QOCOar/unexpected-conflicts.txt`
- retained stash at review time: `stash@{0}` named `iop-canonical-promotion-roadmap-20260802T102956Z`
- roadmap patch SHA-256: `1f1afe533e910b6311390071e07799bf6cc24ca742853bb45a3eceb3da1d4575`
- conflict inventory SHA-256: `15e564744e83accd74981a5976432d14d8638815cab0fefc1d1eaabe97a4aca4`
## Analysis
### Files Read
- Active task artifacts: the current `PLAN-cloud-G10.md`, `CODE_REVIEW-cloud-G10.md`, and the exact Task 15/16 predecessor `complete.log` evidence named by the plan.
- Project workflow: project rules, roadmap rules/current pointer, code-review skill, plan skill, final routing skill, review stub template, local testing rules, and applicable Node, Edge, Control Plane, Client, platform-common, and testing domain rules.
- Roadmap/SDD: the active automation-runtime-bridge Phase, `iop-agent-chronos-extraction-decoupling` Milestone, and its approved/unlocked SDD.
- Current canonical/staging evidence: both worktree statuses and identities, canonical dirty roadmap diff, retained recovery patch/stash/conflict inventory, lock checker output, HANDOFF promotion fields, and Agent UI sync/component state.
- Conflict documents: `Makefile`, `go.mod`, `agent-contract/index.md`, the four affected inner contracts, `agent-contract/outer/openai-compatible-api.md`, the selected roadmap/phase/milestone/queue documents, related active roadmap/SDD documents, `agent-spec/index.md`, and the four affected implementation specs in both staging and canonical forms.
- Conflict source and tests: `apps/edge/internal/node/registry.go`, `apps/edge/internal/openai/dispatch_context.go`, `apps/edge/internal/transport/connection_handlers.go`, `apps/node/internal/node/node.go`, `apps/node/internal/node/tunnel_handler.go`, `apps/node/internal/node/provider_tunnel_test.go`, `packages/go/config/edge_types.go`, `proto/iop/control.proto`, and `proto/iop/runtime.proto` in both staging and canonical forms, plus adjacent managed-route, registration, config, credential-lease, workspace-removal, and cancellation test references.
- Generated/document surfaces: generated Go binding headers and change shape, `docs/edge-local-dev-guide.md`, canonical/staging HANDOFF files, and canonical/staging Agent UI sync and console-shell component documents.
### SDD Criteria
The approved SDD requires S05 `handoff-gate` evidence to prove traceable disposition, state transfer, deletion, regression, rollback, and the still-disabled downstream lock in one composite receipt. The checklist therefore requires: an exact reviewed source commit; an explicit 34-path three-way merge disposition; preservation of current canonical credential/TLS/projection behavior; deletion of IOP Agent/workspace/terminal ownership; deterministic wire regeneration; fresh canonical runtime, Flutter, wire, reconnect, readability, credential, and boundary verification; mirrored HANDOFF/UI evidence; preserved rollback artifacts; and a disabled Chronos lock. Final milestone archive and lock enable remain excluded.
### Verification Context
- Supplied and freshly reproduced facts:
- staging promotion commit `7b90b7e5af9035fae2b5349c65eb322096d21b1b` has parent `1debc7ada01d98442560bbc4ac52dcef9cae25cc`;
- canonical `dev` and `origin/dev` were both `c3a24ec5febab9fc978fd62392efcb6c96e12ec9` at review time;
- the staging promotion is not a canonical ancestor;
- canonical still tracks 83 files under the forbidden legacy Agent surfaces sampled by the review;
- canonical has exactly three intentional dirty roadmap files and no unmerged entry;
- the saved patch and retained stash patch reproduce the reported digest and semantic user edits;
- the conflict inventory has exactly 34 paths and reproduces its reported digest;
- the Chronos dependency lock is still `disable`.
- External precondition: implementation must re-prove that canonical `HEAD`, `dev`, and `origin/dev` are exactly the reviewed `c3a24ec5febab9fc978fd62392efcb6c96e12ec9`. Any advance requires a new overlap review and is a blocker for this fixed-base plan.
- Confidence: high for the failure cause and recovery state; medium-high for the merge recipe because the exact conflicts are known, but the combined result must be established only by compilation, focused dual-boundary tests, and the complete canonical matrix.
#### External Verification Preflight
Run from `/config/workspace/iop-s1` before creating or modifying any integration state:
```bash
test "$(git -C /config/workspace/iop symbolic-ref --short HEAD)" = dev
test "$(git -C /config/workspace/iop rev-parse HEAD)" = c3a24ec5febab9fc978fd62392efcb6c96e12ec9
test "$(git -C /config/workspace/iop rev-parse origin/dev)" = c3a24ec5febab9fc978fd62392efcb6c96e12ec9
test "$(git rev-parse HEAD)" = 7b90b7e5af9035fae2b5349c65eb322096d21b1b
test "$(git rev-parse 7b90b7e5af9035fae2b5349c65eb322096d21b1b^1)" = 1debc7ada01d98442560bbc4ac52dcef9cae25cc
test "$(git -C /config/workspace/iop diff --name-only | LC_ALL=C sort)" = $'agent-roadmap/phase/automation-runtime-bridge/PHASE.md\nagent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md\nagent-roadmap/priority-queue.md'
test -z "$(git -C /config/workspace/iop diff --name-only --diff-filter=U)"
test "$(sha256sum /tmp/iop-canonical-promotion.QOCOar/canonical-roadmap.patch | awk '{print $1}')" = 1f1afe533e910b6311390071e07799bf6cc24ca742853bb45a3eceb3da1d4575
test "$(sha256sum /tmp/iop-canonical-promotion.QOCOar/unexpected-conflicts.txt | awk '{print $1}')" = 15e564744e83accd74981a5976432d14d8638815cab0fefc1d1eaabe97a4aca4
test "$(wc -l < /tmp/iop-canonical-promotion.QOCOar/unexpected-conflicts.txt)" -eq 34
git -C /config/workspace/iop diff --check
```
Expected: every guard exits 0. Preserve the recovery patch and existing named stash. On any mismatch, do not stash, cherry-pick, resolve, or commit; record the mismatch in the review artifact.
### Test Coverage Gaps
No new product capability is introduced. The risk is a bad three-way merge that independently valid extraction and credential-plane tests do not catch together. Preserve the upstream credential lease test in `provider_tunnel_test.go`, preserve the extraction cancellation test using the provider-only `CancelRequest{run_id}`, and add or adjust focused regression assertions only where the integrated source has no existing test for a merged boundary. Full fresh Go execution and the credential-slot smoke are mandatory; cached `go test` output is not accepted.
### Symbol References
- Extraction symbols to remove or reserve: `AgentKind`, `WorkspaceRequired`, `RunSessionMode`, `CancelAction`, `AgentUsageStatus`, CLI adapter config, `metadata.workspace`, and the `packages/go/agentruntime` package name.
- Upstream symbols to preserve: `EdgeCredentialPlaneConf`, nested TLS config, `PrincipalProjection`, `ProjectedPrincipalToken`, `ProjectedPrincipalRoute`, `SignedCredentialLease`, `CredentialLeaseBinding`, recipient key fields on node registration/registry entries, trusted managed route metadata, and `credentiallease.Consumer`.
- Provider-neutral successor: `packages/go/execution` owns runtime request/event/provider types after extraction and must receive auto-merged upstream credential additions formerly made under `packages/go/agentruntime`.
### Split Judgment
Do not split. The merge commit, canonical promotion, UI/HANDOFF reconciliation, and final composite receipt form one guarded transaction. Splitting would allow a code merge or evidence update to be reviewed without the canonical regression and rollback proof required by S05.
### Scope Rationale
The only required fix is canonical integration of the already reviewed extraction commit on the newer canonical base. The plan does not add features, push branches, archive the milestone, enable the Chronos lock, delete recovery stashes, or rewrite unrelated user work. Unrelated canonical roadmap content is retained; extraction-related wording is merged only where required to remove stale IOP Agent ownership.
### Final Routing
- Evaluation mode: isolated reassessment
- Build route basis: `grade-boundary`
- Build large indivisible context: `false`
- Positive risk categories: `temporal_state`, `boundary_contract`, `structured_interpretation`
- Review feedback: `review_rework_count=1`, `evidence_integrity_failure=false`
- Build lane/grade: `cloud/G10`
- Review lane/grade: `cloud/G10`
- Routed files: `PLAN-cloud-G10.md`, `CODE_REVIEW-cloud-G10.md`
## Implementation Checklist
- [ ] Rebuild the reviewed extraction change on exact canonical base `c3a24ec5febab9fc978fd62392efcb6c96e12ec9` in an isolated integration worktree and resolve all 34 overlaps with recorded dispositions.
- [ ] Prove the integrated result preserves managed credential/TLS behavior and removes IOP Agent ownership, then promote it to canonical while restoring the three-file user roadmap patch.
- [ ] Reconcile canonical Agent UI and mirrored HANDOFF evidence with exact promotion identities while keeping the Chronos lock disabled.
- [ ] Run the complete final verification matrix, retain rollback evidence, and fill implementation-owned sections in `CODE_REVIEW-*-G??.md` with actual output.
### [REVIEW_REFACTOR-1] Build an explicit canonical-base integration commit
**Problem**
The reviewed extraction commit is based on `1debc7a`, while canonical `c3a24ec` adds managed principal projection, mTLS peer identity, credential recipient registration, sealed credential leases, config fields, generated wire bindings, tests, and extensive contract/docs content. The failed direct cherry-pick found 34 conflicts. Choosing staging or canonical wholesale would respectively drop security work or retain removed Agent/workspace ownership.
**Solution**
Create a task-specific detached worktree under `/tmp` from exact canonical `c3a24ec`. Apply `7b90b7e5` with `git cherry-pick --no-commit`, confirm the unmerged path set exactly matches the retained 34-line inventory, and resolve every path using the matrix below. Do not resolve generated bindings manually. After source proto resolution, run the repository generators, `go mod tidy`, format changed Go, and create one integration commit whose parent is exactly `c3a24ec`.
Resolution matrix:
| Paths | Required disposition |
|------|----------------------|
| `Makefile`, `go.mod` | Remove Agent build/parity/smoke targets and Agent-only dependencies; preserve credential-slot smoke, secure-delivery wire coverage, managed credential dependencies, and provider-only targets. Run `go mod tidy` rather than hand-pruning shared dependencies. |
| `agent-contract/index.md`, affected inner contracts, `agent-contract/outer/openai-compatible-api.md` | Preserve managed projection, exact route/slot/revision binding, mTLS, recipient-sealed lease, stream-gate, provider passthrough, metrics, and reconnect semantics. Remove workspace authoring, CLI Agent/session/terminal ownership, Agent-specific status/commands, and stale `agentruntime` references. Point provider-neutral runtime semantics to `execution-runtime.md`. |
| `agent-spec/index.md` and four affected specs | Synthesize current managed credential/TLS/route evidence with the extraction boundary. Keep Control Plane credential ownership and Edge/Node provider execution; remove IOP task loop, workspace, terminal, CLI Agent, session termination, and Agent command ownership. Preserve current source-of-truth paths after the `agentruntime` to `execution` move. |
| selected automation roadmap/milestone and `priority-queue.md` | Apply the extraction completion/evidence state while preserving the canonical user-owned `[separation-01]` edits and queue placement. Do not mark the milestone complete or archive it. |
| other conflicting active roadmap/SDD files | Preserve all unrelated `c3a24ec` content and incorporate only extraction boundary substitutions needed to replace IOP Agent/CLI/session/terminal ownership with Chronos ownership. Do not reorder unrelated milestones or regress newer roadmap work. |
| `apps/edge/internal/node/registry.go` | Remove `AgentKind` defaulting and storage; preserve immutable credential recipient key id/public key and connection-generation/dispatch-ready fencing, including clone safety. |
| `apps/edge/internal/openai/dispatch_context.go` | Remove workspace parsing/validation/storage; preserve route-aware trusted managed metadata overwrite for route id/revision and credential slot/revision. |
| `apps/edge/internal/transport/connection_handlers.go` | Remove AgentKind registration/event metadata; preserve authenticated mTLS node identity validation and credential recipient fields from `RegisterRequest`. |
| `apps/node/internal/node/node.go`, `tunnel_handler.go`, `provider_tunnel_test.go` | Use `packages/go/execution`; preserve `credentiallease.Consumer`, admission-before-consumption, exact binding validation, secret zeroing, and replay rejection. Preserve provider-only run-id cancellation and remove action/session termination requirements. |
| `packages/go/config/edge_types.go` | Preserve credential-plane and nested TLS configuration. Remove AgentKind, workspace-required routing, and console Agent aliases while retaining provider route/session correlation fields that remain in the reviewed extraction contract. |
| `proto/iop/control.proto`, `proto/iop/runtime.proto` and generated Go/Dart outputs | Preserve projection/lease/recipient wire messages and fields. Reserve the removed workspace/session-mode/cancel-action/usage-status/CLI config/control-plane domain-agent field numbers and names exactly as staged. Regenerate all bindings; never take ours/theirs for generated files. |
| `docs/edge-local-dev-guide.md` | Preserve current provider quickstart, managed credential/TLS startup, safe slot lifecycle, and redaction guidance. Remove `agent_kind`, CLI/workspace-agent instructions, and stale Agent ownership without replacing the full guide with the short staging version. |
Before committing, record a deterministic table in the active review artifact with each of the 34 paths, its disposition category, and the evidence command used. Verify no conflict marker or unmerged entry remains and inspect the integrated diff against both parents for unexpected deletions of credential/TLS work or retention of Agent surfaces.
**Modified Files and Checklist**
- [ ] Create an isolated detached integration worktree from exact `c3a24ec` without mutating either existing worktree.
- [ ] Apply `7b90b7e5` without committing and prove the unmerged set exactly matches the retained 34-path inventory.
- [ ] Resolve every conflict using the matrix and preserve auto-merged upstream credential additions moved into `packages/go/execution`.
- [ ] Regenerate Go and Dart protobuf bindings from resolved source proto files; do not edit generated bindings manually.
- [ ] Run formatting/tidy and create an integration commit with parent exactly `c3a24ec`.
- [ ] Save exact integration worktree path, commit id, parent id, resolved-path inventory digest, and diff summaries in the active review artifact.
**Test Strategy**
This is an internal integration repair. Preserve and update existing tests; add a focused assertion only if the merged boundary is otherwise untested. The minimum focused set must exercise managed route metadata, mTLS/recipient registration, registry clone fencing, credential lease consume/replay behavior, provider-only cancel, config rejection, and wire round-trip/reservation behavior.
**Intermediate Verification**
Run from the isolated integration worktree after resolution and before promotion:
```bash
test "$(git rev-parse HEAD)" = c3a24ec5febab9fc978fd62392efcb6c96e12ec9
test -z "$(git diff --name-only --diff-filter=U)"
if rg --sort path -n '^(<<<<<<<|=======|>>>>>>>)' --glob '!agent-task/**'; then exit 1; fi
git diff --name-only --diff-filter=ACM -z -- '*.go' | xargs -0 -r gofmt -w
go mod tidy
make proto
make proto-dart
go test -count=1 ./packages/go/config ./packages/go/credentiallease ./apps/edge/internal/node ./apps/edge/internal/transport ./apps/edge/internal/openai ./apps/node/internal/node
git diff --check
```
After committing the integrated source, require `test "$(git rev-parse HEAD^)" = c3a24ec5febab9fc978fd62392efcb6c96e12ec9`, rerun `go mod tidy`, `make proto`, and `make proto-dart`, then require `git diff --exit-code`. Expected: all commands exit 0; generated output is reproducible; the integration commit parent is exact canonical base; no unmerged path or marker exists.
### [REVIEW_REFACTOR-2] Qualify and promote the integrated commit without losing user state
**Problem**
Canonical contains an intentional uncommitted three-file roadmap patch. Promotion must neither commit nor discard it. The failed attempt retained both a patch and named stash, but canonical has not received the integrated code and its full test matrix remains unexecuted.
**Solution**
First run the complete source/regression and boundary qualification in the isolated integration worktree. Only after it passes, write a fresh copy of the canonical three-file diff to the same task-specific recovery directory, hash it, create a newly named safety stash limited to those exact files, and confirm canonical is clean. Fetch the integration commit into a task-specific canonical ref and fast-forward `dev` from exact `c3a24ec` to that commit. Apply, but do not drop, the new safety stash. If patch application conflicts, resolve only the three roadmap files by retaining both the reviewed extraction state and the user `[separation-01]`/queue edits, then verify the restored semantic diff. Leave both old and new recovery stashes intact.
Do not push. Do not use reset, force checkout, or destructive cleanup. If integration qualification, stash creation, fast-forward, or restoration fails, preserve the exact state and record a blocker rather than improvising a broader history rewrite.
**Modified Files and Checklist**
- [ ] Run all qualification commands in the isolated integration worktree and require zero failures.
- [ ] Save and hash a fresh exact three-file canonical roadmap patch and create a new named safety stash limited to those paths.
- [ ] Prove canonical is clean, still based on exact `c3a24ec`, and fast-forward only to the qualified integration commit.
- [ ] Restore the three-file user roadmap patch without committing it and prove the same user decisions remain present alongside extraction state.
- [ ] Retain the original and new recovery patch/stash locators and record their digests.
- [ ] Confirm canonical has no unmerged entry and only the intentional roadmap patch plus later evidence edits are dirty.
**Test Strategy**
Run the full fresh suite in the isolated result before promotion, then repeat the canonical suite after promotion. This dual execution prevents a valid temp result from masking canonical state or environment drift.
**Intermediate Verification**
Run from the isolated integration worktree:
```bash
mkdir -p .tmp
TMPDIR="$PWD/.tmp" GOTMPDIR="$PWD/.tmp" go test -count=1 ./...
make client-test
make client-build-web
make test-control-plane-edge-wire
make test-credential-slot-smoke
make readability-audit
IOP_DEV_RECONNECT_BIND_TIMEOUT=60 scripts/dev/edge-node-reconnect-diagnostic.sh
git diff --exit-code
```
Expected: all commands exit 0 and the committed integration worktree stays clean. After canonical fast-forward and user-patch restoration, require `git merge-base --is-ancestor <integration-commit> /config/workspace/iop/HEAD`, `git diff --check`, no unmerged path, and an exact sorted dirty-path set of the three roadmap files before evidence reconciliation.
### [REVIEW_REFACTOR-3] Reconcile UI and promotion evidence while the lock stays closed
**Problem**
Canonical Agent UI still describes the removed Agent shell and has no reconciled milestone record. Both HANDOFF files still report `canonical_promotion: pending`. SDD S05 requires actual commit identities, verification evidence, rollback locators, state-transfer receipts, and downstream lock state; placeholder or staging-only evidence is insufficient.
**Solution**
After canonical runtime and Flutter verification passes, execute the repository's `complete-milestone` check-only workflow. If closure-ready, execute the routed `sync-agent-ui mode=reconcile-milestone-completion` workflow for this exact milestone, validate Agent UI, and repeat check-only. Update canonical console-shell/component index and sync state to the provider-only, reconciled milestone state, then mirror those exact bytes into this workspace.
Update canonical and local `HANDOFF.md` with `canonical_promotion: applied`, the reviewed staging commit `7b90b7e5...`, actual qualified integration/canonical promotion commit, UTC verification timestamp, canonical base, exact recovery patch/stash locators and hashes, 34-conflict disposition evidence, full test results, and the still-disabled lock result. Preserve all Task 13-16 receipt/digest pointers. Do not archive the milestone or enable the lock.
**Modified Files and Checklist**
- [ ] Run milestone check-only before and after Agent UI reconciliation; do not run completion/archive mode.
- [ ] Reconcile `/config/workspace/iop/agent-ui/.sync-state.json`, console-shell component definition, and components index only after canonical Flutter verification passes.
- [ ] Mirror those exact three Agent UI files into this workspace.
- [ ] Update canonical and local `HANDOFF.md` with exact applied promotion, conflict-resolution, verification, recovery, and lock evidence.
- [ ] Preserve all existing Task 13-16 receipt and digest pointers.
- [ ] Prove the dependency checker still returns the Chronos boundary and its lock entry remains `disable`.
**Test Strategy**
No new UI test source is required. Existing Flutter tests/build plus Agent UI validation and byte equality are the gates. HANDOFF checks validate actual commit objects/ancestry, exact 40-hex fields, retained digests, and disabled lock output.
**Intermediate Verification**
```bash
cmp /config/workspace/iop/agent-ui/.sync-state.json agent-ui/.sync-state.json
cmp /config/workspace/iop/agent-ui/definition/components/console-shell/index.md agent-ui/definition/components/console-shell/index.md
cmp /config/workspace/iop/agent-ui/definition/components/index.md agent-ui/definition/components/index.md
cmp /config/workspace/iop/HANDOFF.md HANDOFF.md
jq -e '.pending_milestone_work | length == 0' agent-ui/.sync-state.json
jq -e '.reconciled_milestone_work | any(.milestone_path == "agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md" and .state == "reconciled")' agent-ui/.sync-state.json
rg -n '^canonical_promotion: applied$|^staging_promotion_commit: [0-9a-f]{40}$|^canonical_promotion_commit: [0-9a-f]{40}$|^canonical_promotion_verified_at: ' HANDOFF.md
agent-ops/bin/roadmap-dependency-checker.sh --find-milestone 'iop:agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md' both /config/workspace/.agent-roadmap-sync/locks.yaml
rg -n -A4 'id: chronos:chronos-architecture-ownership-boundary' /config/workspace/.agent-roadmap-sync/locks.yaml
```
Expected: mirrored files are byte-identical; pending milestone work is empty; the exact milestone appears as reconciled; promotion fields contain actual ids; dependency checker prints `rely-on:chronos:chronos-architecture-ownership-boundary`; lock status remains `disable`.
### [REVIEW_REFACTOR-4] Run final canonical and cross-workspace closure verification
**Problem**
The failed attempt did not run canonical Go, Flutter, wire, reconnect, readability, credential, generated-wire, or final boundary checks. A promotion claim without fresh canonical results and recoverable user state cannot close the Required finding.
**Solution**
Run the full canonical matrix again after UI/HANDOFF evidence edits, save long stdout/stderr under a task-specific ignored `/tmp` evidence directory, and paste concise actual output or the exact saved paths and commands into the active review artifact. Re-run deterministic boundary searches, generated-file reproducibility, commit ancestry, dirty-state, mirrored-evidence, lock, and rollback checks. Keep the integration worktree and recovery artifacts until review finalization. Do not write `complete.log`, archive the milestone, or enable the lock.
**Modified Files and Checklist**
- [ ] Execute every final verification command with fresh Go test execution and record actual outputs or exact saved output paths.
- [ ] Prove generated Go/Dart bindings remain reproducible and canonical contains no unmerged or conflict-marker state.
- [ ] Prove forbidden Agent/workspace/terminal ownership surfaces and old package roots are absent from active runtime/config/wire paths.
- [ ] Prove the canonical promotion commit is an ancestor of canonical `HEAD` and the user roadmap diff remains recoverable.
- [ ] Fill all implementation-owned sections in `agent-task/m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/CODE_REVIEW-cloud-G10.md` and leave review-only sections unchanged.
**Test Strategy**
This is the final regression and evidence gate. Fresh canonical execution is required; no test cache substitution is accepted. Any failed command, missing output, unexpected forbidden surface, lost user patch, unmerged entry, or enabled lock leaves the item incomplete.
**Verification**
Run from `/config/workspace/iop`:
```bash
mkdir -p .tmp
TMPDIR="$PWD/.tmp" GOTMPDIR="$PWD/.tmp" go test -count=1 ./...
make client-test
make client-build-web
make test-control-plane-edge-wire
make test-credential-slot-smoke
make readability-audit
IOP_DEV_RECONNECT_BIND_TIMEOUT=60 scripts/dev/edge-node-reconnect-diagnostic.sh
go mod tidy
make proto
make proto-dart
git diff --check
test -z "$(git diff --name-only --diff-filter=U)"
```
After generation, require no source/generated drift outside the intentional evidence/user-roadmap edits. Then run:
```bash
if rg --sort path -n -i 'chronos|agent_bridge|iop-agent|iop_agent|IopAgent|agentruntime|agentprovider|agenttask|agentworkspace' apps packages/go cmd proto configs; then exit 1; fi
test ! -d apps/agent
test -z "$(find packages/go -maxdepth 1 -type d -name 'agent*' -print -quit)"
test ! -e proto/iop/agent.proto
test ! -e proto/gen/iop/agent.pb.go
test -z "$(git diff --name-only --diff-filter=U)"
rg -n '^status: 구현됨$|^Status: `구현됨`$' agent-ui/definition/components/console-shell/index.md
jq -e '.pending_milestone_work | length == 0' agent-ui/.sync-state.json
jq -e '.reconciled_milestone_work | any(.milestone_path == "agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md" and .state == "reconciled")' agent-ui/.sync-state.json
rg -n '^canonical_promotion: applied$|^staging_promotion_commit: [0-9a-f]{40}$|^canonical_promotion_commit: [0-9a-f]{40}$' HANDOFF.md
git merge-base --is-ancestor "$(sed -n 's/^canonical_promotion_commit: //p' HANDOFF.md)" HEAD
```
Run from `/config/workspace/iop-s1`:
```bash
git diff --check
cmp /config/workspace/iop/HANDOFF.md HANDOFF.md
cmp /config/workspace/iop/agent-ui/.sync-state.json agent-ui/.sync-state.json
cmp /config/workspace/iop/agent-ui/definition/components/console-shell/index.md agent-ui/definition/components/console-shell/index.md
cmp /config/workspace/iop/agent-ui/definition/components/index.md agent-ui/definition/components/index.md
agent-ops/bin/roadmap-dependency-checker.sh --find-milestone 'iop:agent-roadmap/phase/automation-runtime-bridge/milestones/iop-agent-chronos-extraction-decoupling.md' both /config/workspace/.agent-roadmap-sync/locks.yaml
rg -n -A4 'id: chronos:chronos-architecture-ownership-boundary' /config/workspace/.agent-roadmap-sync/locks.yaml
```
Expected: all runtime, UI, credential, wire, readability, reconnect, generator, boundary, ancestry, mirroring, rollback, and lock checks pass. Canonical may remain dirty only for the intentional three-file user roadmap patch and post-promotion evidence/UI files. The active review artifact contains exact recovery locators and actual command evidence.
## Modified Files Summary
| File | Items |
|------|-------|
| `HANDOFF.md` | REVIEW_REFACTOR-3, REVIEW_REFACTOR-4 |
| `agent-ui/.sync-state.json` | REVIEW_REFACTOR-3, REVIEW_REFACTOR-4 |
| `agent-ui/definition/components/console-shell/index.md` | REVIEW_REFACTOR-3, REVIEW_REFACTOR-4 |
| `agent-ui/definition/components/index.md` | REVIEW_REFACTOR-3, REVIEW_REFACTOR-4 |
| `agent-task/m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/CODE_REVIEW-cloud-G10.md` | REVIEW_REFACTOR-1, REVIEW_REFACTOR-2, REVIEW_REFACTOR-3, REVIEW_REFACTOR-4 |
## Final Verification
The final verification contract is the union of every command in REVIEW_REFACTOR-1 through REVIEW_REFACTOR-4. Run commands in their stated worktree and order. Record actual stdout/stderr; when output is long, save it under the exact task-specific `/tmp` evidence directory and record both the path and command. Require all exit codes to be zero, no unexplained dirty or unmerged path, no forbidden runtime surface, exact mirrored evidence, recoverable user state, and a still-disabled Chronos lock.
After completing all implementation and verification work, fill every implementation-owned section in `CODE_REVIEW-*-G??.md` and stop for review.

View file

@ -0,0 +1,18 @@
# Milestone Work Log
> Dispatcher-owned execution timeline. Workers and reviewers do not edit this file.
| seq | time | event | task | loop | role | attempt | model | result | locator |
|---:|---|---|---|---:|---|---:|---|---|---|
| 1 | 26-08-02 19:23:48 | START | m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/PLAN-cloud-G10.md | 0 | worker | 0 | codex/gpt-5.6-sol xhigh | running | /config/workspace/iop-s1/.git/agent-task-dispatcher/runs/20260802T102348Z__m-iop-agent-chronos-extraction-decoupling__17__15__16_canonical_promotion_closure__p0__worker__a00/locator.json |
| 2 | 26-08-02 19:34:41 | FINISH | m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/PLAN-cloud-G10.md | 0 | worker | 0 | codex/gpt-5.6-sol xhigh | succeeded:0 | /config/workspace/iop-s1/.git/agent-task-dispatcher/runs/20260802T102348Z__m-iop-agent-chronos-extraction-decoupling__17__15__16_canonical_promotion_closure__p0__worker__a00/locator.json |
| 3 | 26-08-02 19:34:41 | START | m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/CODE_REVIEW-cloud-G10.md | 0 | review | 0 | codex/gpt-5.6-sol xhigh | running | /config/workspace/iop-s1/.git/agent-task-dispatcher/runs/20260802T103441Z__m-iop-agent-chronos-extraction-decoupling__17__15__16_canonical_promotion_closure__p0__review__a00/locator.json |
| 4 | 26-08-02 19:59:07 | FINISH | m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/CODE_REVIEW-cloud-G10.md | 0 | review | 0 | codex/gpt-5.6-sol xhigh | succeeded:0 | /config/workspace/iop-s1/.git/agent-task-dispatcher/runs/20260802T103441Z__m-iop-agent-chronos-extraction-decoupling__17__15__16_canonical_promotion_closure__p0__review__a00/locator.json |
| 5 | 26-08-02 19:59:08 | START | m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/PLAN-cloud-G10.md | 1 | worker | 0 | codex/gpt-5.6-sol xhigh | running | /config/workspace/iop-s1/.git/agent-task-dispatcher/runs/20260802T105907Z__m-iop-agent-chronos-extraction-decoupling__17__15__16_canonical_promotion_closure__p1__worker__a00/locator.json |
| 6 | 26-08-02 20:49:15 | FINISH | m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/PLAN-cloud-G10.md | 1 | worker | 0 | codex/gpt-5.6-sol xhigh | succeeded:0 | /config/workspace/iop-s1/.git/agent-task-dispatcher/runs/20260802T105907Z__m-iop-agent-chronos-extraction-decoupling__17__15__16_canonical_promotion_closure__p1__worker__a00/locator.json |
| 7 | 26-08-02 20:49:16 | START | m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/CODE_REVIEW-cloud-G10.md | 1 | review | 0 | codex/gpt-5.6-sol xhigh | running | /config/workspace/iop-s1/.git/agent-task-dispatcher/runs/20260802T114915Z__m-iop-agent-chronos-extraction-decoupling__17__15__16_canonical_promotion_closure__p1__review__a00/locator.json |
| 8 | 26-08-02 21:06:47 | FINISH | m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/CODE_REVIEW-cloud-G10.md | 1 | review | 0 | codex/gpt-5.6-sol xhigh | succeeded:0 | /config/workspace/iop-s1/.git/agent-task-dispatcher/runs/20260802T114915Z__m-iop-agent-chronos-extraction-decoupling__17__15__16_canonical_promotion_closure__p1__review__a00/locator.json |
| 9 | 26-08-02 21:06:48 | START | m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/PLAN-cloud-G08.md | 2 | worker | 0 | claude/claude-opus-4-8 xhigh | running | /config/workspace/iop-s1/.git/agent-task-dispatcher/runs/20260802T120648Z__m-iop-agent-chronos-extraction-decoupling__17__15__16_canonical_promotion_closure__p2__worker__a00/locator.json |
| 10 | 26-08-02 21:18:34 | FINISH | m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/PLAN-cloud-G08.md | 2 | worker | 0 | claude/claude-opus-4-8 xhigh | succeeded:0 | /config/workspace/iop-s1/.git/agent-task-dispatcher/runs/20260802T120648Z__m-iop-agent-chronos-extraction-decoupling__17__15__16_canonical_promotion_closure__p2__worker__a00/locator.json |
| 11 | 26-08-02 21:18:34 | START | m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/CODE_REVIEW-cloud-G08.md | 2 | review | 0 | codex/gpt-5.6-sol xhigh | running | /config/workspace/iop-s1/.git/agent-task-dispatcher/runs/20260802T121834Z__m-iop-agent-chronos-extraction-decoupling__17__15__16_canonical_promotion_closure__p2__review__a00/locator.json |
| 12 | 26-08-02 21:28:01 | FINISH | m-iop-agent-chronos-extraction-decoupling/17+15,16_canonical_promotion_closure/CODE_REVIEW-cloud-G08.md | 2 | review | 0 | codex/gpt-5.6-sol xhigh | succeeded:0 | /config/workspace/iop-s1/.git/agent-task-dispatcher/runs/20260802T121834Z__m-iop-agent-chronos-extraction-decoupling__17__15__16_canonical_promotion_closure__p2__review__a00/locator.json |