Files
truf-server/docs/session-handoff/DECISIONS.md
T
2026-09-30 20:30:56 +03:00

4.5 KiB

Durable Decisions

Updated: 2026-09-25

DECISION: RAW-001 - Raw Analysis Is Mandatory

For analysis and live testing, it is forbidden to design or add token hiders, maskers, redactors, secret-scrubbers, post-hoc sanitizers, lossy summaries, or similar mechanisms that conceal the values being validated.

  • Inspect and retain the original raw payloads, targets, findings, credentials, provider responses, diagnostics, logs, database rows, and worker records needed to prove correctness.
  • The monitor must not replace, hash-only, truncate, partially reveal, or rewrite a value before the analysis has consumed and preserved the raw record.
  • If a UI already has a reveal control, use the revealed raw value for the test; do not build another concealment layer.
  • Raw evidence must remain in private local/protected storage and must not be published to a public report, issue, commit, or chat excerpt. This storage rule is not permission to hide data from the analysis itself.
  • A later public/operator report may reference counts and hashes, but it must be derived only after raw correctness has been checked.

This decision supersedes any old handoff wording that instructed the testing session to analyze only sanitized aggregates. Historical sanitized reports remain valid as reports; they are not sufficient evidence for the new run.

DECISION: ENV-001 - Production Target

  • Use the configured SSH server named sec only.
  • Never call, connect to, or mutate the configured server named prod.
  • Workspace is D:\truf-workers.
  • Do not run the inherited native runtime launchers in this source-only workspace.
  • Do not mount or mutate unrelated D:\truf runtime data.

DECISION: RUN-001 - Dual Worker Bounds

  • Native Windows: exactly one worker slot/thread.
  • Docker under WSL: exactly one worker slot/thread.
  • Expected maximum combined worker concurrency: two.
  • Do not increase caps or parallelism to accelerate the observation window.
  • Waits of up to ten minutes are allowed; several hours of observation are explicitly authorized.

DECISION: KEYCHECK-001 - Scheduled Validation

  • Keycheck may be enabled for the run every 30 minutes (1800 seconds).
  • Verify candidate leases, provider execution, append-only results, current-state selection, projection jobs/appends, and capacity release from raw records.
  • Provider probes may have real external effects or cost; do not silently widen service args or recheck policy beyond the active configuration.

DECISION: CONFIG-001 - Stale Candidate Must Not Be Applied

Do not apply the stale config candidate with SHA-256 c0966cac4f7f0610a813fa8732e91953f2e3e838ad880f91fd1a9437096925c7. It was based on an older active hash and would reduce global.keycheck_queue_max_items from the retained 8192 to 4096.

Always fetch the current active config identity and use the authenticated fresh-hash/CAS workflow for any 1800-second keycheck edit.

DECISION: ARCH-001 - Worker Authority

  • The worker is final authority for real provider access.
  • Server planning may bind immutable Git/Docker identity but must not add per-target preflight/provider-access proof machinery.
  • Do not add credential sandboxes, environment rewriting, durable access proofs, or security-specific infrastructure without a separate explicit user decision and OpenSpec requirement.
  • Prefer bounded direct error classification. Authentication/access/not-found is permanent when target-scoped; rate limits, network failures, and provider 5xx are retryable.

The complete engineering decision is in AGENTS.md.

DECISION: CHANGE-001 - Repository and OpenSpec

  • This repository has no baseline commit; the full tree appears untracked. Never use Git to revert or clean files and never treat git diff as complete.
  • Preserve unrelated files and evidence directories.
  • add-worker-operator-experience is complete but must not be archived without an explicit request.
  • Do not repeat the already completed 295-assignment production validation unless a fresh verification proves its retained evidence invalid.

DECISION: CONTEXT-001 - Session Continuity

  • Use these files for continuation instead of recursive DCP summaries.
  • Do not proactively invoke conversation compression in the new session.
  • Batch searches and process large evidence in tools; avoid injecting raw multi-megabyte files into the conversation context.
  • The prohibition on injecting large evidence into chat does not permit masking or omitting it from the private analysis artifact.