Legacy IDEA authority hardening supersession audit
PR #35 (fix/v0.9.1-field-hardening, head bbb55e9ceaa819620f0e6ea52848499b94ed69bb) is a stale pre-v0.10 branch. It must not be merged directly, but its authority hardening exposed protections that are only partially represented in v0.11.1.
Audit against current v0.11.1
Present in current architecture
Partial / insufficient compared with PR #35
Missing from current v0.11.1 runtime
Disposition
The audit is therefore not a simple supersession: several PR #35 protections remain valuable and are absent or weaker in current v0.11.1.
Required current-generation implementation
Port the missing behavior as a new bounded v0.11.1+ change, using current architecture rather than copying the old branch wholesale:
- Add a current-generation persisted IDEA discovery/workflow state model.
- Make requirement origin/provenance and authority transitions explicit and fail-closed.
- Persist the exact pending interaction before asking it.
- Require exact interaction fingerprint when consuming the reply.
- Add append-only replay protection.
- Add crash-safe resume/journal semantics.
- Bind final Idea Brief approval to current discovery/source fingerprints.
- Integrate Design Authority disposition without allowing caller-supplied mock state.
- Preserve the current Numbered Decision Interface rather than replacing it.
- Add adversarial regression tests before closing this issue.
Evidence retained
Historical implementation and regression suite remain available on PR #35/head bbb55e9ceaa819620f0e6ea52848499b94ed69bb. Use them as behavioral evidence, not as a merge candidate.
Legacy IDEA authority hardening supersession audit
PR #35 (
fix/v0.9.1-field-hardening, headbbb55e9ceaa819620f0e6ea52848499b94ed69bb) is a stale pre-v0.10 branch. It must not be merged directly, but its authority hardening exposed protections that are only partially represented in v0.11.1.Audit against current v0.11.1
Present in current architecture
runtime/orchestration/po-decisions.mjspersists decisions under.development-kit/decisionsand validates content fingerprints.decision-menu.mjspersistsactive-menu.jsonplus history.resolveDecisionInputrejects a supplied current fingerprint that no longer matches the menu'ssourceFingerprint.agents/product-discovery-agent.mdexplicitly requires one question per turn.Partial / insufficient compared with PR #35
decisionAuthority = 'Product Owner'/ product-owner provenance. PR fix(reliability): v0.9.1 field hardening and IDEA authority persistence #35 deliberately removed implicit approving-authority defaults for authoritative transitions.expectedInteractionFingerprintfor the exact pending interaction.Missing from current v0.11.1 runtime
runtime/orchestrationtree has noidea-workflow.mjs.idea-discovery.mjsequivalent implementing candidate confirmation/adoption/rejection/supersession transitions.discovery-journal.jsonworkflow implementation.idea-consumptions.mjsequivalent.DK_INTERACTION_FINGERPRINT_MISMATCH.Disposition
The audit is therefore not a simple supersession: several PR #35 protections remain valuable and are absent or weaker in current v0.11.1.
Required current-generation implementation
Port the missing behavior as a new bounded v0.11.1+ change, using current architecture rather than copying the old branch wholesale:
Evidence retained
Historical implementation and regression suite remain available on PR #35/head
bbb55e9ceaa819620f0e6ea52848499b94ed69bb. Use them as behavioral evidence, not as a merge candidate.