Context and scope
Part of the incremental CodeCartographer engineering evolution. Planned, not shipped. Read the agent handoff, vision/decisions, record contract, and implementation plan. Documentation baseline PR #410 is merged at bbdf6b1a8b3bc348aa9e8f20a409c66df087af13. Follow this issue's prerequisite gates before starting.
Host-executed/framework-tracked; preserve analysis state ABI, both Pi analysis guards, and current synthesis confirmation gates. Ordinary in-place changes accept zero external references. No implicit source execution, provider spend, GitHub write, release/deployment, or private-data publication. E01 owns schema/API/authority decisions; dependent workers consume its merged contract rather than inventing another.
Tracking: #398
Blocked by: #399. Prerequisites must be merged, not merely started.
Objective: preserve one change's history while creating/resuming another, with retry-safe framework ownership.
Depends on: E01. Files: create core/engineering/store.ts, tests/engineering-store.test.mjs, tests/engineering-distribution.test.mjs; update the engineering barrel, core/workspace.ts template-copy exclusion sets, package.json files exclusions, .codecarto/.gitignore, and .codecarto/templates/gitignore. Extend tests/init-workspace-isolation.test.mjs where appropriate. Reuse appropriate primitives from core/utils.ts/core/status.ts after inspecting their actual contracts.
Steps:
- Write tests creating two changes, separate slices/attempts, and immutable completed observations; assert no writes to
workflow/status.yaml or another change.
- Add tests for duplicate idempotency keys, conflicting payload reuse, stale CAS revisions, malformed/truncated records, symlink escape, and unknown versions; run RED.
- Implement the smallest file-backed store, typed operations, atomic publication, per-change serialization, and directory enumeration with explicit corrupt-record reporting.
- Add subprocess fault injection before/after the commit point and concurrent-writer tests. A success projection cannot reference an observation that was not durably published.
- Explicitly exclude
.codecarto/engineering/ runtime state from template copying, default Git tracking, and npm packaging. Keep this exclusion distinct from distributable templates and schemas; deliberate shareable exports belong outside the private runtime namespace. Add synthetic-source initialization tests and a packed-file inventory test proving histories, approvals, and artifacts reach neither a fresh workspace nor the tarball. Never use real private records as fixtures.
- Resume after process exit, confirm prior failed attempts remain intact, then run GREEN/full gates and the isolation/pack-inventory tests.
Acceptance: second change and retry do not overwrite history; duplicate ingestion is idempotent; stale revisions fail clearly; interruption leaves a recoverable state; existing analysis files remain untouched. Synthetic engineering records are ignored by default and absent from fresh-workspace copies and actual npm tarballs, while distributable guidance still arrives. Storage is not complete until these distribution-isolation checks pass.
Out of scope: distributed scheduling, database migration, automatic worktree management, or filesystem reorganization of legacy analyses.
Required verification and handoff
- Run the named RED/GREEN tests,
npm run build, npm test, and git diff --check; record actual results, not historical counts.
- Inspect current source and dependency PRs first. All new paths are proposed until their owning issue lands.
- Get independent review on the exact candidate; stop on missing authority or unresolved security design.
- Attach commit/PR, changed paths, observed proof, remaining limits, compatibility notes, and the next eligible issue.
- Keep shared barrel/registration/invariant edits small and coordinate them; do not absorb unrelated work.
- This issue does not authorize implementation of the later reuse/team/release backlog.
Context and scope
Part of the incremental CodeCartographer engineering evolution. Planned, not shipped. Read the agent handoff, vision/decisions, record contract, and implementation plan. Documentation baseline PR #410 is merged at
bbdf6b1a8b3bc348aa9e8f20a409c66df087af13. Follow this issue's prerequisite gates before starting.Host-executed/framework-tracked; preserve analysis state ABI, both Pi analysis guards, and current synthesis confirmation gates. Ordinary in-place changes accept zero external references. No implicit source execution, provider spend, GitHub write, release/deployment, or private-data publication. E01 owns schema/API/authority decisions; dependent workers consume its merged contract rather than inventing another.
Tracking: #398
Blocked by: #399. Prerequisites must be merged, not merely started.
Objective: preserve one change's history while creating/resuming another, with retry-safe framework ownership.
Depends on: E01. Files: create
core/engineering/store.ts,tests/engineering-store.test.mjs,tests/engineering-distribution.test.mjs; update the engineering barrel,core/workspace.tstemplate-copy exclusion sets,package.jsonfiles exclusions,.codecarto/.gitignore, and.codecarto/templates/gitignore. Extendtests/init-workspace-isolation.test.mjswhere appropriate. Reuse appropriate primitives fromcore/utils.ts/core/status.tsafter inspecting their actual contracts.Steps:
workflow/status.yamlor another change..codecarto/engineering/runtime state from template copying, default Git tracking, and npm packaging. Keep this exclusion distinct from distributable templates and schemas; deliberate shareable exports belong outside the private runtime namespace. Add synthetic-source initialization tests and a packed-file inventory test proving histories, approvals, and artifacts reach neither a fresh workspace nor the tarball. Never use real private records as fixtures.Acceptance: second change and retry do not overwrite history; duplicate ingestion is idempotent; stale revisions fail clearly; interruption leaves a recoverable state; existing analysis files remain untouched. Synthetic engineering records are ignored by default and absent from fresh-workspace copies and actual npm tarballs, while distributable guidance still arrives. Storage is not complete until these distribution-isolation checks pass.
Out of scope: distributed scheduling, database migration, automatic worktree management, or filesystem reorganization of legacy analyses.
Required verification and handoff
npm run build,npm test, andgit diff --check; record actual results, not historical counts.