Repository navigation
spec(corpus): electron-apps-v0 cell contract — app-run cell kind, install/activation/four-step observables, the X01-T3 digest and authority rules applied to app-run cells (mapping consumed from X03-T5) and the committed-id procedure #587
Description
Activity
- addedelectron-compatElectron compatibility program areaElectron compatibility program area
on Oct 6, 2026 - addedenhancementNew feature or requestNew feature or requestcompat:tier-1Electron compat Tier 1 (arch 04 §4)Electron compat Tier 1 (arch 04 §4)ready-for-agentFully specified; an AFK agent can take itFully specified; an AFK agent can take itmilestone:first-proofNeeded for the first migration proof (drawio-desktop on macOS, explicit legacy profile)Needed for the first migration proof (drawio-desktop on macOS, explicit legacy profile)
on Oct 6, 2026 This was generated by AI during triage.
Agent Brief
Category: enhancement
Summary: spec(corpus): electron-apps-v0 cell contract — app-run cell kind, install/activation/four-step observables, the X01-T3 digest and authority rules applied to app-run cells (mapping consumed from X03-T5) and the committed-id procedureCurrent behavior:
FACT: the arch 04 §6 harness text says 'separate repo, gitignored fixtures' andkeld migrate && keld dev --headless --smoke. That contradicts the exact-bytes digest rule of the KEL-74 denominator, andkeld devtakes no flags. No observable is defined for install, activation or the four workflow steps. keld-guard ProfileState (unverified, legacy, strict) and keld-compat AuthorityProfile have no stated mapping.Desired behavior:
Write the approved spec for product-corpus cells.- The app-run cell kind. Inputs: pinned source commit, artefact digest, Keld SHA, Bun version, OS/arch, authority profile. Output: one KEL-74 record per cell with an immutable evidence locator.
- The install observable. Recommendation:
unknownuntil a KEL-141 prebuilt distribution artefact exists; a dev-staged run is never relabelled as install. - The activation observable: a host-observed first load of the app's own page, no fatal module-evaluation error, and a live role.
- Oracles and negative controls for open, edit, save, and close-with-unsaved-prompt.
- How a declared source patch is recorded if PANEL-P1 forces 'config + 1 edit'.
- How the X01-T3 artifact-digest rule (exact committed manifest bytes) applies to app-run cells whose app source is pinned by commit, reconciling the arch 04 §6 sentences in the same PR. The rule itself stays X01-T3's.
- A citation of X03-T5's mapping from the guard
legacyprofile state tolegacy_sandbox_off, and of X01-T3's authority-label rule. This spec defines neither. - The procedure for adding a product id to the documented committed list: a code change plus a scoreboard document change, with a named reviewer.
Key interfaces:
- KEL-74 OperationKind and AuthorityProfile;
- X01-T3 evidence rules;
- X03-T5 profile mapping (consumed).
Acceptance criteria:
- Every required heading of the repository spec template is present and non-empty
- Every cell row names its OperationKind, its observable, its independent oracle and one negative control
- The install row states its observable or
unknownwith the KEL-141 task artifact it waits on - After the edit, architecture 04 §6 has no sentence that leaves the manifest bytes uncommitted and no
--headless --smokeflag - The spec cites X03-T5 for the legacy→legacy_sandbox_off mapping and X01-T3 for the authority-label rule, and contains no mapping table of its own
- Negative control: Deleting one template section body makes the heading check fail
- Negative control: A cell row without a negative control makes the row check fail
- Negative control: Re-inserting 'gitignored fixtures' as the manifest location makes the §6 consistency check fail
- Negative control: Adding a local ProfileState→authority_profile table to this spec makes the single-owner check fail
Out of scope:
- Implementation (X02-T4, X02-T6); the legacy profile key, its mapping and its parser (X03-T5, X03-T7); the pin, red-until-implemented and digest rules themselves (X01-T3); Zettlr cells.
Tracker of record and claim location: see "Ownership and gates" in the issue body.
Parent
Epic #496 · Map #391 · Unit X02 · Kind:
spec· Tier: Tier 1 · Maturity target: L0 · Size: S · Milestone:first-proofWhat to build
Write the approved spec for product-corpus cells.
unknownuntil a KEL-141 prebuilt distribution artefact exists; a dev-staged run is never relabelled as install.legacyprofile state tolegacy_sandbox_off, and of X01-T3's authority-label rule. This spec defines neither.Acceptance criteria
unknownwith the KEL-141 task artifact it waits on--headless --smokeflagNegative controls (each names the one mutation that must fail)
External predecessors (outside this tracker)
Ownership and gates
docs/agents/workflow.md§ Tracker issue (rule lands with docs(agents): record the #517 tracker-of-record rule in root AGENTS.md and the workflow claim protocol #520). Linear reference: KEL-237 (In Progress) carries a link to this issue.legacyprofile key — one location, parse into admit(Legacy), ProfileState↔AuthorityProfile mapping, forfeit printing,unverifiedunscoreable by design #586)The authoritative agent contract is the latest Agent Brief comment on this issue (triage skill); this body is the planning record.
Out of scope
Implementation (X02-T4, X02-T6); the legacy profile key, its mapping and its parser (X03-T5, X03-T7); the pin, red-until-implemented and digest rules themselves (X01-T3); Zettlr cells.
Notes
This is a separate spec from X02-T1 because it has a different crate owner (keld-compat versus keld-cli) and a different review. Claim: post the workflow
## Agent claimblock as a comment on this ticket's GitHub issue (earliest comment wins; the assignee mirrors it) and cite #517 as the documented exception, because root AGENTS.md and the workflow still describe Linear-only tracking until the separate owner-authorized amendment lands.Change log (doctrine-audit repair, 2026-10-07)