Skip to content

spec(corpus): electron-apps-v0 cell contract — app-run cell kind, install/activation/four-step observables, the X01-T3 digest and authority rules applied to app-run cells (mapping consumed from X03-T5) and the committed-id procedure #587

Description

@0monish

Generated by an AI agent (Claude Code) on behalf of @0monish during Wayfinder charting of the Electron compatibility program; rewritten 2026-10-07 by the doctrine-audit repair pass (change log at the end). Planning only — no implementation is authorized by this issue.

Parent

Epic #496 · Map #391 · Unit X02 · Kind: spec · Tier: Tier 1 · Maturity target: L0 · Size: S · Milestone: first-proof

What to build

Write the approved spec for product-corpus cells.

  • The app-run cell kind. Inputs: pinned source commit, artefact digest, Keld SHA, Bun version, OS/arch, authority profile. Output: one KEL-74 record per cell with an immutable evidence locator.
  • The install observable. Recommendation: unknown until a KEL-141 prebuilt distribution artefact exists; a dev-staged run is never relabelled as install.
  • The activation observable: a host-observed first load of the app's own page, no fatal module-evaluation error, and a live role.
  • Oracles and negative controls for open, edit, save, and close-with-unsaved-prompt.
  • How a declared source patch is recorded if PANEL-P1 forces 'config + 1 edit'.
  • How the X01-T3 artifact-digest rule (exact committed manifest bytes) applies to app-run cells whose app source is pinned by commit, reconciling the arch 04 §6 sentences in the same PR. The rule itself stays X01-T3's.
  • A citation of X03-T5's mapping from the guard legacy profile state to legacy_sandbox_off, and of X01-T3's authority-label rule. This spec defines neither.
  • The procedure for adding a product id to the documented committed list: a code change plus a scoreboard document change, with a named reviewer.

Acceptance criteria

  • Every required heading of the repository spec template is present and non-empty
  • Every cell row names its OperationKind, its observable, its independent oracle and one negative control
  • The install row states its observable or unknown with the KEL-141 task artifact it waits on
  • After the edit, architecture 04 §6 has no sentence that leaves the manifest bytes uncommitted and no --headless --smoke flag
  • The spec cites X03-T5 for the legacy→legacy_sandbox_off mapping and X01-T3 for the authority-label rule, and contains no mapping table of its own

Negative controls (each names the one mutation that must fail)

  • Deleting one template section body makes the heading check fail
  • A cell row without a negative control makes the row check fail
  • Re-inserting 'gitignored fixtures' as the manifest location makes the §6 consistency check fail
  • Adding a local ProfileState→authority_profile table to this spec makes the single-owner check fail

External predecessors (outside this tracker)

  • KEL-141 (Backlog, unassigned): no distribution task artifact exists; the install cell stays unknown until one does

Ownership and gates

The authoritative agent contract is the latest Agent Brief comment on this issue (triage skill); this body is the planning record.

Out of scope

Implementation (X02-T4, X02-T6); the legacy profile key, its mapping and its parser (X03-T5, X03-T7); the pin, red-until-implemented and digest rules themselves (X01-T3); Zettlr cells.

Notes

This is a separate spec from X02-T1 because it has a different crate owner (keld-compat versus keld-cli) and a different review. Claim: post the workflow ## Agent claim block as a comment on this ticket's GitHub issue (earliest comment wins; the assignee mirrors it) and cite #517 as the documented exception, because root AGENTS.md and the workflow still describe Linear-only tracking until the separate owner-authorized amendment lands.

Change log (doctrine-audit repair, 2026-10-07)

  • New ticket: the corpus cell contract split out so X02-T4 has a spec and X02-T1 keeps one concern (repair rule 2; refuter X02-A6 'reconcile arch 04 §6 with exact-bytes before writing the harness')
  • Install observable labelled UNKNOWN with the KEL-141 dependency (critic coverage gap / ambiguity laundering on install)
  • Added the ProfileState→AuthorityProfile mapping (X03 finding on two profile enumerations)
  • Added the 'config + 1 edit' patch recording path (critic hidden coupling F02-T3/F06-T2/PANEL-P1/X02-T4)
  • Added the committed-id procedure as a code + doc change (refuter X02-A6 precision fix 2)
  • Edge X01-T1 replaced by X01-T3, whose pin, digest and authority-label rules this spec applies (cross-check finding 2: first-proof slices gated on next-milestone X01-T1)
  • ready_state ready-for-human → ready-for-agent; owner line rewritten to the GitHub tracker of record and the KEL-237 reference per Linear owner for repo-writing Electron-compat slices (owner decision: align to nearest Linear issue, else GitHub is the tracker of record) #517 (X06-D7) (cross-check finding 1: X06-D7 vs the Linear owner for repo-writing Electron-compat slices (owner decision: align to nearest Linear issue, else GitHub is the tracker of record) #517 owner decision)
  • Added edge X03-T5. The ProfileState→authority_profile mapping is now cited from X03-T5 instead of defined here (AC5 and its negative control rewritten), so the mapping atom has one owner (cross-check finding 6, profile key location pre-decided without an X03-T5 edge, applied to the same atom in X02-T5)

Activity

  1. added theissue type on Oct 6, 2026
  2. added
    enhancementNew feature or request
    compat:tier-1Electron compat Tier 1 (arch 04 §4)
    ready-for-agentFully specified; an AFK agent can take it
    milestone:first-proofNeeded for the first migration proof (drawio-desktop on macOS, explicit legacy profile)
    on Oct 6, 2026
  3. 0monish commented on Oct 6, 2026

    @0monish
    MemberAuthor

    This was generated by AI during triage.

    Agent Brief

    Category: enhancement
    Summary: spec(corpus): electron-apps-v0 cell contract — app-run cell kind, install/activation/four-step observables, the X01-T3 digest and authority rules applied to app-run cells (mapping consumed from X03-T5) and the committed-id procedure

    Current behavior:
    FACT: the arch 04 §6 harness text says 'separate repo, gitignored fixtures' and keld migrate && keld dev --headless --smoke. That contradicts the exact-bytes digest rule of the KEL-74 denominator, and keld dev takes no flags. No observable is defined for install, activation or the four workflow steps. keld-guard ProfileState (unverified, legacy, strict) and keld-compat AuthorityProfile have no stated mapping.

    Desired behavior:
    Write the approved spec for product-corpus cells.

    • The app-run cell kind. Inputs: pinned source commit, artefact digest, Keld SHA, Bun version, OS/arch, authority profile. Output: one KEL-74 record per cell with an immutable evidence locator.
    • The install observable. Recommendation: unknown until a KEL-141 prebuilt distribution artefact exists; a dev-staged run is never relabelled as install.
    • The activation observable: a host-observed first load of the app's own page, no fatal module-evaluation error, and a live role.
    • Oracles and negative controls for open, edit, save, and close-with-unsaved-prompt.
    • How a declared source patch is recorded if PANEL-P1 forces 'config + 1 edit'.
    • How the X01-T3 artifact-digest rule (exact committed manifest bytes) applies to app-run cells whose app source is pinned by commit, reconciling the arch 04 §6 sentences in the same PR. The rule itself stays X01-T3's.
    • A citation of X03-T5's mapping from the guard legacy profile state to legacy_sandbox_off, and of X01-T3's authority-label rule. This spec defines neither.
    • The procedure for adding a product id to the documented committed list: a code change plus a scoreboard document change, with a named reviewer.

    Key interfaces:

    • KEL-74 OperationKind and AuthorityProfile;
    • X01-T3 evidence rules;
    • X03-T5 profile mapping (consumed).

    Acceptance criteria:

    • Every required heading of the repository spec template is present and non-empty
    • Every cell row names its OperationKind, its observable, its independent oracle and one negative control
    • The install row states its observable or unknown with the KEL-141 task artifact it waits on
    • After the edit, architecture 04 §6 has no sentence that leaves the manifest bytes uncommitted and no --headless --smoke flag
    • The spec cites X03-T5 for the legacy→legacy_sandbox_off mapping and X01-T3 for the authority-label rule, and contains no mapping table of its own
    • Negative control: Deleting one template section body makes the heading check fail
    • Negative control: A cell row without a negative control makes the row check fail
    • Negative control: Re-inserting 'gitignored fixtures' as the manifest location makes the §6 consistency check fail
    • Negative control: Adding a local ProfileState→authority_profile table to this spec makes the single-owner check fail

    Out of scope:

    • Implementation (X02-T4, X02-T6); the legacy profile key, its mapping and its parser (X03-T5, X03-T7); the pin, red-until-implemented and digest rules themselves (X01-T3); Zettlr cells.

    Tracker of record and claim location: see "Ownership and gates" in the issue body.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    compat:tier-1Electron compat Tier 1 (arch 04 §4)electron-compatElectron compatibility program areaenhancementNew feature or requestmilestone:first-proofNeeded for the first migration proof (drawio-desktop on macOS, explicit legacy profile)ready-for-agentFully specified; an AFK agent can take it

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions