95 lines
4.5 KiB
Markdown
95 lines
4.5 KiB
Markdown
# Durable Decisions
|
|
|
|
Updated: 2026-09-25
|
|
|
|
## DECISION: RAW-001 - Raw Analysis Is Mandatory
|
|
|
|
For analysis and live testing, it is forbidden to design or add token hiders,
|
|
maskers, redactors, secret-scrubbers, post-hoc sanitizers, lossy summaries, or
|
|
similar mechanisms that conceal the values being validated.
|
|
|
|
- Inspect and retain the original raw payloads, targets, findings, credentials,
|
|
provider responses, diagnostics, logs, database rows, and worker records needed
|
|
to prove correctness.
|
|
- The monitor must not replace, hash-only, truncate, partially reveal, or rewrite
|
|
a value before the analysis has consumed and preserved the raw record.
|
|
- If a UI already has a reveal control, use the revealed raw value for the test;
|
|
do not build another concealment layer.
|
|
- Raw evidence must remain in private local/protected storage and must not be
|
|
published to a public report, issue, commit, or chat excerpt. This storage rule
|
|
is not permission to hide data from the analysis itself.
|
|
- A later public/operator report may reference counts and hashes, but it must be
|
|
derived only after raw correctness has been checked.
|
|
|
|
This decision supersedes any old handoff wording that instructed the testing
|
|
session to analyze only sanitized aggregates. Historical sanitized reports remain
|
|
valid as reports; they are not sufficient evidence for the new run.
|
|
|
|
## DECISION: ENV-001 - Production Target
|
|
|
|
- Use the configured SSH server named `sec` only.
|
|
- Never call, connect to, or mutate the configured server named `prod`.
|
|
- Workspace is `D:\truf-workers`.
|
|
- Do not run the inherited native runtime launchers in this source-only workspace.
|
|
- Do not mount or mutate unrelated `D:\truf` runtime data.
|
|
|
|
## DECISION: RUN-001 - Dual Worker Bounds
|
|
|
|
- Native Windows: exactly one worker slot/thread.
|
|
- Docker under WSL: exactly one worker slot/thread.
|
|
- Expected maximum combined worker concurrency: two.
|
|
- Do not increase caps or parallelism to accelerate the observation window.
|
|
- Waits of up to ten minutes are allowed; several hours of observation are
|
|
explicitly authorized.
|
|
|
|
## DECISION: KEYCHECK-001 - Scheduled Validation
|
|
|
|
- Keycheck may be enabled for the run every 30 minutes (`1800` seconds).
|
|
- Verify candidate leases, provider execution, append-only results, current-state
|
|
selection, projection jobs/appends, and capacity release from raw records.
|
|
- Provider probes may have real external effects or cost; do not silently widen
|
|
service args or recheck policy beyond the active configuration.
|
|
|
|
## DECISION: CONFIG-001 - Stale Candidate Must Not Be Applied
|
|
|
|
Do not apply the stale config candidate with SHA-256
|
|
`c0966cac4f7f0610a813fa8732e91953f2e3e838ad880f91fd1a9437096925c7`.
|
|
It was based on an older active hash and would reduce
|
|
`global.keycheck_queue_max_items` from the retained `8192` to `4096`.
|
|
|
|
Always fetch the current active config identity and use the authenticated
|
|
fresh-hash/CAS workflow for any 1800-second keycheck edit.
|
|
|
|
## DECISION: ARCH-001 - Worker Authority
|
|
|
|
- The worker is final authority for real provider access.
|
|
- Server planning may bind immutable Git/Docker identity but must not add
|
|
per-target preflight/provider-access proof machinery.
|
|
- Do not add credential sandboxes, environment rewriting, durable access proofs,
|
|
or security-specific infrastructure without a separate explicit user decision
|
|
and OpenSpec requirement.
|
|
- Prefer bounded direct error classification. Authentication/access/not-found is
|
|
permanent when target-scoped; rate limits, network failures, and provider 5xx
|
|
are retryable.
|
|
|
|
The complete engineering decision is in `AGENTS.md`.
|
|
|
|
## DECISION: CHANGE-001 - Repository and OpenSpec
|
|
|
|
- This repository has no baseline commit; the full tree appears untracked.
|
|
Never use Git to revert or clean files and never treat `git diff` as complete.
|
|
- Preserve unrelated files and evidence directories.
|
|
- `add-worker-operator-experience` is complete but must not be archived without
|
|
an explicit request.
|
|
- Do not repeat the already completed 295-assignment production validation unless
|
|
a fresh verification proves its retained evidence invalid.
|
|
|
|
## DECISION: CONTEXT-001 - Session Continuity
|
|
|
|
- Use these files for continuation instead of recursive DCP summaries.
|
|
- Do not proactively invoke conversation compression in the new session.
|
|
- Batch searches and process large evidence in tools; avoid injecting raw
|
|
multi-megabyte files into the conversation context.
|
|
- The prohibition on injecting large evidence into chat does not permit masking
|
|
or omitting it from the private analysis artifact.
|