Skip to content

Files Changed: prove full-provenance behavior end to end #1084

Description

@jeonghun-jj-lee

Files Changed: prove full-provenance behavior end to end

Important

Problem - Unit and integration coverage can pass while a full session path still drops a writer, misattributes concurrent work, leaks evidence, or presents an old-engine client as fully tracked.
Approach - Build an adversarial end-to-end matrix that exercises the complete session lineage, mutation, assessment, privacy, UI, and mixed-version contracts before default enablement.
Scope - in: root and descendant sessions, task and spawn edges, forks, all origins, filesystem classes, outcomes, privacy, quotas, concurrency, versions, accessibility, and release rehearsal. out: new protocol features beyond the parent contract.
Assumptions - All preceding parent slices are available in a coordinated development build.

Acceptance Criteria

  • The matrix covers agent, child-agent, user, system, and opaque origins across full, partial, and legacy modes.
  • The matrix covers workspace, non-Git external, external repository, internal, binary, artifact, directory, Trash, restore, symlink, alias, and unsupported-provider resources.
  • The matrix covers success, denied, failed, aborted, partial, conflict, unavailable, opaque, quota, and expiry outcomes.
  • The matrix proves unrelated concurrent writes are never attributed to the active root.
  • The matrix proves capability, evidence, and protected metadata do not cross browser, transcript, share, export, telemetry, log, or error boundaries.
  • The matrix covers task and explicit spawn aggregation, fork separation, child archival/deletion, old sessions, upgrade epochs, mixed binaries, and rollback.
  • The matrix validates keyboard operation and both supported themes for the unified surface.
  • Default enablement remains blocked until every required matrix case passes.

Testing Decisions

  • Reuse existing server, app, extension-host, sharing, and release-rehearsal harnesses where each already owns a boundary.
  • Add only end-to-end fixtures that cross otherwise independent harnesses.

Key Decisions

  • This is a release gate, not a confidence-only test suite.
  • A passing happy path cannot substitute for coverage of provenance failure modes.

Constraints & Invariants

  • Test evidence must distinguish legacy behavior from full-provenance behavior.
  • The matrix cannot mutate a real external user directory without an isolated fixture.

Prior Art

Deliberation Resolution

  • The matrix is a versioned manifest of case IDs. Each row declares fixture, setup, trigger, expected authorization decision, expected receipts and assessments, permitted display-safe fields, prohibited egress fields, cleanup, and required mode.
  • A case is covered only when its row runs and produces its declared observable result. The release gate consumes the manifest and emits all_required_passed only when every required case is green; product-denied outcomes are asserted expected results, not failed tests.
  • Fixtures use isolated temporary roots, sandboxed external directories, contained symlinks and aliases, disposable Trash fixtures, deterministic cleanup, and post-run containment assertions. No case uses a real user directory.
  • Privacy rows assert both permitted status projection and absence of prohibited evidence or metadata for browser, transcript, share, export, telemetry, log, and error boundaries.

Source

Part of #972. Blocked by #1083.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

afkImplementable without human interaction

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions