Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions changes/cc-g00-legacy-reference-reconcile.evidence.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
format_version: 1
kind: evidence
claims:
- id: overlay-records-separate-live-and-legacy-issues
evidence:
- unit:scripts/ci/test_preflight_check_catalog.py
- architecture:scripts/generate-architecture-catalogs.py
- id: backlog-rows-point-at-live-trackers
evidence:
- architecture:scripts/generate-architecture-catalogs.py
unresolved: []
4 changes: 4 additions & 0 deletions changes/cc-g00-legacy-reference-reconcile.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
Category: internal
Audience: developers
Breaking-Change: no
Summary: Separate live studio-berry/loop issue records from frozen legacy ones in the preflight catalog overlay (#111) — github_issues entries now carry `repository`, legacy snapshots are keyed `legacy#<n>` and can never be an open row's `closed_by`, the generator adds an opt-in `--verify-github` read-back that rejects a missing issue, a pull request, or a changed title, state, or milestone, sixteen open backlog rows re-point to the reset issues filed for them, and 25 of the 28 legacy issue and pull-request links under docs/ become `legacy #<n>` text (the three in docs/GOVERNED_EXECUTION.md and ADR-011 wait for a change that can carry the governed-execution proof lanes), with the convention recorded in docs/LEGACY_ISSUE_PROVENANCE.md.
2 changes: 1 addition & 1 deletion docs/CORRECTION_COVERAGE_MATRIX.md
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,7 @@ Save-mode semantics for the source artifact are defined once in the generated
catalog under `save_modes` and referenced per operation.

Target scopes describe the current implicit selector behaviour. The shared
selector AST tracked in GitHub #587 is not yet wired into repair plans; until it
selector AST tracked in legacy #587 is not yet wired into repair plans; until it
lands, operations declare whole-document, page, resource, or production-geometry
scopes resolved during `analyze()`.

Expand Down
2 changes: 1 addition & 1 deletion docs/EDITOR_RECOVERY.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ only half reachable today: the approval half is pinned by
`UnitTestsOperationHistory::noSavePathProducesAnApprovedOutputRecord` (no save
path records an approval or an approved output, so a recovered file cannot be
presented as approved), and the restore half is tracked by
[#575](https://github.com/studio-berry/loop/issues/575).
legacy #575.

## Safety contract

Expand Down
18 changes: 9 additions & 9 deletions docs/EVIDENCE_CORE_RESET_INVENTORY.md
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ The catalog has **22 registered checks**: 5 `covered`, 17 `partial`, and no `not
| Canonical Pass/Fail/Incomplete/Error reducer and certificate gate | **Reuse; prove** all four states and no zero-finding budget PASS under [#16](https://github.com/studio-berry/loop2/issues/16). Core verdict. | [`pdfpreflightverdict.cpp`](../LoopLibCore/sources/pdfpreflightverdict.cpp), [verdict contract](PREFLIGHT_VERDICT.md); `UnitTestsPreflightVerdict`, `UnitTestsPreflightEngine`. `PreflightResult::pass` is derived compatibility data. |
| Fixed-capacity job scheduler, cancellation, stale-result discard | **Reuse** the existing scheduler; **repair** producer/result fencing under [#17](https://github.com/studio-berry/loop2/issues/17). Core scheduling. | [`pdfjobscheduler.cpp`](../LoopLibCore/sources/pdfjobscheduler.cpp), [scheduler contract](JOB_SCHEDULER.md); `UnitTestsJobScheduler`, `UnitTestsRevisionStress`, `scripts/ci/check_unmanaged_async.py`. Caller coverage is not complete merely because the scheduler exists. |
| Parser, reader, renderer, session, processing and resource budgets | **Reuse** Core primitives; **prove** hostile and production envelopes under [#19](https://github.com/studio-berry/loop2/issues/19). Core PDF. | [`pdfdocumentreader.cpp`](../LoopLibCore/sources/pdfdocumentreader.cpp) calls [`pdfparser.cpp`](../LoopLibCore/sources/pdfparser.cpp); [`pdfrenderer.cpp`](../LoopLibCore/sources/pdfrenderer.cpp) and [budget contract](RESOURCE_BUDGETS.md) bound work. `UnitTestsProcessingBudget`, `UnitTestsResourceBudget`, `UnitTestsBudgetExhaustion`, `UnitTestsBudgetCorpus` are mapped tests. The unbudgeted cumulative `PDFFunction::createFunction()` path remains an explicit deferred contract-level gap in that document. |
| PdfTool open/preflight process boundary | **Reuse** the Linux-first worker proof from [legacy #618](https://github.com/studio-berry/loop/issues/618); **repair/audit** remaining privileged-host paths under [#20](https://github.com/studio-berry/loop2/issues/20). PdfTool supervisor and Core. | [`pdfworkerprotocol.h`](../PdfTool/pdfworkerprotocol.h) allowlists `ping`, `open`, `preflight`, `cancel`; [`pdfworkerclient.cpp`](../PdfTool/pdfworkerclient.cpp) maps worker failure/timeout to unavailable/incomplete; [`pdfworkersandbox.cpp`](../PdfTool/pdfworkersandbox.cpp), `UnitTestsPdfWorkerIsolation`, `scripts/ci/check_pdf_worker_isolation.py`. Windows runtime tests skip the Linux sandbox proof; [`editorhost.cpp`](../LoopEditor/editorhost.cpp) still constructs an in-process `PreflightEngine`. The open [legacy #619](https://github.com/studio-berry/loop/issues/619) does not justify a replacement worker primitive. |
| PdfTool open/preflight process boundary | **Reuse** the Linux-first worker proof from legacy #618; **repair/audit** remaining privileged-host paths under [#20](https://github.com/studio-berry/loop2/issues/20). PdfTool supervisor and Core. | [`pdfworkerprotocol.h`](../PdfTool/pdfworkerprotocol.h) allowlists `ping`, `open`, `preflight`, `cancel`; [`pdfworkerclient.cpp`](../PdfTool/pdfworkerclient.cpp) maps worker failure/timeout to unavailable/incomplete; [`pdfworkersandbox.cpp`](../PdfTool/pdfworkersandbox.cpp), `UnitTestsPdfWorkerIsolation`, `scripts/ci/check_pdf_worker_isolation.py`. Windows runtime tests skip the Linux sandbox proof; [`editorhost.cpp`](../LoopEditor/editorhost.cpp) still constructs an in-process `PreflightEngine`. The open legacy #619 does not justify a replacement worker primitive. |
| Independent standards/rendering validation | **Reuse** the validation harness; **prove** independent oracle outputs and fidelity claims under [#18](https://github.com/studio-berry/loop2/issues/18). Core qualification. | [`check_independent_validation_gate.py`](../scripts/ci/check_independent_validation_gate.py), [independent evidence schema](schemas/independent-validation-evidence.schema.json), [coverage matrix](PREFLIGHT_COVERAGE_MATRIX.md), `UnitTestsConversionOracle`. The source gate checks presence/guards; it is not a current installed-runtime oracle result. |
| Cross-platform exact-SHA admission | **Defer** release admission to [#21](https://github.com/studio-berry/loop2/issues/21). Core qualification with CI owners. | [Proof lanes](../architecture/proof-lanes.yaml) bind `linux-build` and `windows-build`; [parent exit gate](https://github.com/studio-berry/loop2/issues/2) requires one exact-SHA packet. No such packet is asserted by this inventory. |

Expand All @@ -48,22 +48,22 @@ These are **all 18 `open` rows** in the [generated coverage backlog](generated/p

| Open gap ID | Priority | Disposition; evidence/legacy owner |
| --- | --- | --- |
| `barcode-slug-braille` | P1 | **Defer**; backlog row, [Loop #604](https://github.com/studio-berry/loop/issues/604). |
| `devicen-per-colorant-ink-limit` | P1 | **Defer**; backlog row, [Loop #600](https://github.com/studio-berry/loop/issues/600). |
| `gwg-2022-2024-certificates` | P1 | **Defer**; backlog row, [Loop #664](https://github.com/studio-berry/loop/issues/664). |
| `imposition-and-reader-spreads` | P1 | **Defer**; backlog row, [Loop #603](https://github.com/studio-berry/loop/issues/603). |
| `pdfvt-variable-data` | P1 | **Defer**; backlog row, [Loop #605](https://github.com/studio-berry/loop/issues/605). |
| `bleed-raster-strip-depth` | P2 | **Defer**; backlog row, [Loop #47](https://github.com/studio-berry/loop/issues/47). |
| `barcode-slug-braille` | P1 | **Defer**; backlog row, legacy #604. |
| `devicen-per-colorant-ink-limit` | P1 | **Defer**; backlog row, legacy #600. |
| `gwg-2022-2024-certificates` | P1 | **Defer**; backlog row, legacy #664. |
| `imposition-and-reader-spreads` | P1 | **Defer**; backlog row, legacy #603. |
| `pdfvt-variable-data` | P1 | **Defer**; backlog row, legacy #605. |
| `bleed-raster-strip-depth` | P2 | **Defer**; backlog row, legacy #47. |
| `color-mode-icc-alternate` | P2 | **Defer**; backlog row, unfiled. |
| `dieline-geometry` | P2 | **Defer**; backlog row, [Loop #604](https://github.com/studio-berry/loop/issues/604). |
| `dieline-geometry` | P2 | **Defer**; backlog row, legacy #604. |
| `font-glyph-coverage` | P2 | **Defer**; backlog row, unfiled. |
| `hidden-layers-ocmd` | P2 | **Defer**; backlog row, unfiled. |
| `ink-coverage-raster-tac` | P2 | **Defer**; backlog row, unfiled. |
| `invisible-content-breadth` | P2 | **Defer**; backlog row, unfiled. |
| `obscured-content-occlusion` | P2 | **Defer**; backlog row, unfiled. |
| `off-page-content-clipping` | P2 | **Defer**; backlog row, unfiled. |
| `transparency-rip-interaction` | P2 | **Defer**; backlog row, unfiled. |
| `white-overprint-renderer` | P2 | **Defer**; backlog row, [Loop #49](https://github.com/studio-berry/loop/issues/49). |
| `white-overprint-renderer` | P2 | **Defer**; backlog row, legacy #49. |
| `color-inventory-probe-depth` | P3 | **Defer**; backlog row, unfiled. |
| `thin-parts-raster-budget` | P3 | **Defer**; backlog row, unfiled; current failure is incomplete rather than a silent PASS. |

Expand Down
94 changes: 94 additions & 0 deletions docs/LEGACY_ISSUE_PROVENANCE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,94 @@
# Legacy issue provenance

Loop's planning history predates the reset repository. This page records what a bare
issue number means in this tree, where the retired repository's content can still be
recovered, and how references are written from now on.

## What happened

`studio-berry/loop2` was created on 2026-09-24 as the reset codebase and now serves as
`studio-berry/loop`. The repository that held `studio-berry/loop` before the rename is
not reachable from either the `studio-berry` or the `mberrys` account as of 2026-09-28:
`gh repo view` finds no `mberrys/loop`, `mberrys/loop2`, `mberrys/Loop-pdf`, or
`studio-berry/Loop-pdf`, and `studio-berry` lists no repository with that history. Its
issue and pull-request numbers (at least through #686) overlap the reset repository's
sequence, which started again at 1.

Consequences:

- A link to `github.com/studio-berry/loop/issues/<n>` written before the rename either
returns 404 or opens an unrelated reset issue. Neither is the issue the author meant.
- A bare `#<n>` in a file dated before 2026-09-24 means the legacy issue or pull request
unless the file says otherwise (`loop2 #15`, `#15`, and every issue in the roadmap's
L01–L12 suite are reset issues).
- Issue and pull-request numbers share one sequence, so the collision surface grows with
every new issue or PR.

## Where legacy content is recoverable

The retired repository itself cannot be recovered from GitHub here. The specifications
and dispositions survive in Notion:

- the *Loop Issues* ledger and the *Sessions* ledger, linked from the master roadmap
(§2) — the source of record for legacy titles, bodies, and status;
- `docs/ROADMAP_0.5.0-0.8.0.md`, `docs/github-milestones/`, and the handoff documents
under `docs/`, which quote legacy numbers as they were written.

Do not treat a legacy issue's status as reset-repository status. Reconcile against code,
tests, and exact-SHA evidence, and write a new issue for a demonstrated remaining gap.

## How references are written

| Reference | Meaning |
| --- | --- |
| `#<n>` in an issue, PR, or code comment | An issue or PR in `studio-berry/loop` (the reset repository), resolved by GitHub. |
| `legacy #<n>` in prose, `legacy#<n>` in machine-read files | A retired-repository issue. Never linked; never a live tracker. |
| `studio-berry/loop#<n>` or the full URL | A reset issue, when a file could be read outside the repository. |

Rules:

1. **Never link a legacy number.** No `github.com/studio-berry/loop/issues/<n>` URL may
point at a legacy issue. Existing ones were rewritten to `legacy #<n>` text, except
the links to legacy #656 and #675 in `docs/GOVERNED_EXECUTION.md` and
`docs/adr/adr-011-architecture-contracts-d1-d5.md`: both belong to the
governed-execution subsystem, whose binding proof lanes (build, packaging, unit)
cannot be produced by a documentation change, so they are rewritten with the next
change that carries them.
2. **Machine-read records name their repository.** `github_issues` entries in
`docs/preflight-check-catalog-overlay.json` carry `repository`. Live records are
`#<n>` with `studio-berry/loop`; frozen snapshots are `legacy#<n>` with `legacy`.
3. **A legacy record can document closed work, never open a gap.** The catalog generator
refuses an open legacy issue as a backlog row's `closed_by`. Re-point the row to a
live issue.
4. **Live records are read back before promotion.**
`python3 scripts/generate-architecture-catalogs.py --check --verify-github` compares
title, state, and milestone with GitHub and rejects a number that now resolves to a
pull request or another issue.

## Preflight backlog re-pointing

Open backlog rows used to cite legacy trackers. Each now cites the reset issue filed for
the gap; the legacy number is kept here as provenance.

| Backlog row | Legacy tracker | Live tracker |
| --- | --- | --- |
| `barcode-slug-braille`, `dieline-geometry` | legacy #604 | #143 (X00-04) |
| `devicen-per-colorant-ink-limit` | legacy #600 | #142 (X00-03) |
| `gwg-2022-2024-certificates` | legacy #664 | #144 (X00-05) |
| `imposition-and-reader-spreads`, `pdfvt-variable-data` | legacy #603, legacy #605 | #141 (X00-02) |
| `bleed-raster-strip-depth` | legacy #47 | #120 (L01-15) |
| `white-overprint-renderer` | legacy #49 | #119 (L01-14) |
| `transparency-rip-interaction` | unfiled | #119 (L01-14) |
| `color-mode-icc-alternate` | unfiled | #113 (L01-08) |
| `font-glyph-coverage` | unfiled | #114 (L01-09) |
| `hidden-layers-ocmd` | unfiled | #115 (L01-10) |
| `ink-coverage-raster-tac` | unfiled | #116 (L01-11) |
| `invisible-content-breadth` | unfiled | #117 (L01-12) |
| `obscured-content-occlusion`, `off-page-content-clipping` | unfiled | #118 (L01-13) |

Rows that landed (`corrupt-embedded-fonts`, `nested-font-resources`,
`output-intent-identity`, `thin-filled-parts`, `pdfx5-pdfa3-output`) and the closed
`devicen-dieline-detection` row keep their legacy references as `legacy#<n>` snapshots,
as does the `invisible-content-breadth` gap text for its earlier detector.
`color-inventory-probe-depth` and `thin-parts-raster-budget` stay register-only with a
reviewed deferral.
34 changes: 28 additions & 6 deletions docs/PREFLIGHT_COVERAGE_MATRIX.md
Original file line number Diff line number Diff line change
Expand Up @@ -143,12 +143,34 @@ State and closure (`state_rule` in the generated file):

`closed_by` is a verified GitHub issue (`#<number>`), a registered check id, or
the literal `unfiled` when neither exists. Issue numbers are never inferred: the
overlay records each one in `github_issues` with the number, title, state, and
milestone read back from `gh issue view`, the generator refuses a reference with
no verified record, and it refuses a row whose `state` disagrees with the
recorded issue state — so a closed issue forces a row to be re-triaged rather
than left stale. Every `not_covered` class must appear in a P1 row's `gap`, and
no P1 row may invent a class the matrix does not list.
overlay records each one in `github_issues` with the number, title, state,
milestone, and `repository` read back from `gh issue view`, the generator
refuses a reference with no verified record, and it refuses a row whose `state`
disagrees with the recorded issue state — so a closed issue forces a row to be
re-triaged rather than left stale. Every `not_covered` class must appear in a P1
row's `gap`, and no P1 row may invent a class the matrix does not list.

`github_issues` holds two kinds of record, keyed by how they are written:

- `#<number>` is an issue in `studio-berry/loop`. It may be a row's `closed_by`
and can be read back at any time.
- `legacy#<number>` is a frozen snapshot from the retired repository, whose
numbers overlap the live ones and can no longer be read back (see
[`LEGACY_ISSUE_PROVENANCE.md`](LEGACY_ISSUE_PROVENANCE.md)). It may document a
row that was closed there, in `closed_by` or in `gap` text, but the generator
refuses a legacy record that is still `OPEN` as a row's `closed_by`, and a
bare `#<number>` in `gap` text never satisfies a `legacy#<number>` record.

Issue and pull-request numbers share one sequence, so a live record can drift or
collide as the repository grows. `--check` stays offline; run

```text
python3 scripts/generate-architecture-catalogs.py --check --verify-github
```

to read every live record back with `gh` and fail on a missing issue, a pull
request, or a changed title, state, or milestone. Run it before a promotion and
after retitling or closing a cited issue.

A row that is not filed carries a `deferral` reason instead, and the generator
refuses both an unfiled row without one and a filed row that still carries one —
Expand Down
2 changes: 1 addition & 1 deletion docs/REPO_MAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ tooling. Do not infer Loop branch policy from upstream's `master` branch.

The reviewed machine-readable policy is
[`branch-policy.json`](branch-policy.json). The current factual branch and
workflow audit is tracked in GitHub issue [#232](https://github.com/studio-berry/loop/issues/232).
workflow audit is tracked in legacy issue #232.

## Versioning

Expand Down
4 changes: 2 additions & 2 deletions docs/SESSION_09_HANDOFF.md
Original file line number Diff line number Diff line change
Expand Up @@ -49,9 +49,9 @@ Deleted Phase 5 identities remain recorded in `docs/product-surface.json` with
packaging and budget work beyond this ledger-closeout diff; qualification lanes
should not treat it as the Session 09 ledger baseline.

**Dev integration:** merged via [PR #535](https://github.com/studio-berry/loop/pull/535) @
**Dev integration:** merged via legacy PR #535 @
`1f69bdf8bff037e5cae2d37e3c2e3eae8b2ca6b5`. Session 13 scaffolding landed on
`dev` via [PR #539](https://github.com/studio-berry/loop/pull/539) @
`dev` via legacy PR #539 @
`ebde8661bff037e5cae2d37e3c2e3eae8b2ca6b5` (current qualification
`candidate_sha`).

Expand Down
2 changes: 1 addition & 1 deletion docs/adr/adr-007-qt-quick-controls-shell.md
Original file line number Diff line number Diff line change
Expand Up @@ -169,4 +169,4 @@ adoption preserves feature delivery while those risks are measured.
- [Qt Quick Controls](https://doc.qt.io/qt-6/qtquickcontrols-index.html)
- [Qt 6.11 changes to Qt Quick](https://doc.qt.io/qt-6/quick-changes-qt6.html)
- [QQuickWindow scene-graph backend selection](https://doc.qt.io/qt-6/qquickwindow.html)
- [Loop issue #178](https://github.com/studio-berry/loop/issues/178)
- legacy issue #178
8 changes: 4 additions & 4 deletions docs/adr/adr-008-generated-history-rewrite.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,18 +9,18 @@

## Context

[#265](https://github.com/studio-berry/loop/issues/265) asked to decide
legacy #265 asked to decide
whether to rewrite or retain generated dependency and build blobs already
present in the 195 unreleased `dev` commits, and originally recommended a
`dev`-only rewrite because `stable` had not yet received that history.

That window closed when [PR #188](https://github.com/studio-berry/loop/pull/188)
That window closed when legacy PR #188
merged to `stable` on 2026-08-13. After the merge, both `origin/dev` and
`origin/stable` still contained the same 982 blobs (~400.5 MiB):
`.docker-vcpkg*`, `build-fuzz-docker/` (including a 45 MiB
`libLoopLibCore.so`), `debug-b0e75b.log`, `scripts/debug-pr188.*`, and stray
`loop-ocr` bytecode. Branch tips were already clean ([#249](https://github.com/studio-berry/loop/pull/249),
[#258](https://github.com/studio-berry/loop/pull/258)); only history held the
`loop-ocr` bytecode. Branch tips were already clean (legacy #249,
legacy #258); only history held the
blobs.

Rewriting only `dev` would not reclaim GitHub storage. Rewriting `stable`
Expand Down
2 changes: 1 addition & 1 deletion docs/adr/adr-009-canvas-hosting-benchmark.md
Original file line number Diff line number Diff line change
Expand Up @@ -147,4 +147,4 @@ Those remain explicit later gates in ADR-007 and ADR-010.
- [Quick-root admission](adr-010-quick-root-admission.md)
- [Qt Quick Controls shell](adr-007-qt-quick-controls-shell.md)
- [Quick composition contract](../QUICK_COMPOSITION.md)
- [Issue #247](https://github.com/studio-berry/loop/issues/247)
- legacy issue #247
Loading
Loading