From d5c816198cb977b0f099585e46fbbf8c91c3e9af Mon Sep 17 00:00:00 2001 From: Chris Phillipson Date: Sun, 27 Sep 2026 09:44:47 -0700 Subject: [PATCH 01/24] docs(plan): Branch 4 upstream watch live code-level plan --- ...2026-09-27-branch-4-upstream-watch-live.md | 1129 +++++++++++++++++ 1 file changed, 1129 insertions(+) create mode 100644 docs/superpowers/plans/2026-09-27-branch-4-upstream-watch-live.md diff --git a/docs/superpowers/plans/2026-09-27-branch-4-upstream-watch-live.md b/docs/superpowers/plans/2026-09-27-branch-4-upstream-watch-live.md new file mode 100644 index 00000000..545860dc --- /dev/null +++ b/docs/superpowers/plans/2026-09-27-branch-4-upstream-watch-live.md @@ -0,0 +1,1129 @@ +# Branch 4 — Upstream Watch Live Implementation Plan + +> **For agentic workers:** REQUIRED SUB-SKILL: Use superpowers:subagent-driven-development (recommended) or superpowers:executing-plans to implement this plan task-by-task. Steps use checkbox (`- [ ]`) syntax for tracking. + +**Goal:** Make the upstream watch trustworthy enough to run daily: a release counts only when a published version provably contains the merged fixing change, AgentDB fixes count only when Ruflo bundles them, the registry separates "state re-read" from "conformance verified", and the registry's data (ledger issue, tracking issues, doc citations, the reply and stale queues) matches reality. + +**Architecture:** Two sequential implementer slices in worktree `../agentic-kit-b4` on `feat/upstream-watch-live`. Slice 1 changes code and schema (`scripts/upstream-watch/*`, `src/lib/hook-audit/upstream*.mjs`, the JSON Schema, schema version 5 → 6). Slice 2 changes registry data, the citation guard, and documentation, and writes draft upstream comments into its report (never posted). All network access stays behind the injectable `exec` in `scripts/upstream-watch/fetch.mjs`; every rule is tested from recorded fixtures. + +**Tech Stack:** Node 22+/26 ESM, `node:test`, GitHub CLI (`gh api`, `gh api graphql`), `npm view`. + +**Spec:** [Remediation program, Branch 4](2026-09-26-remediation-program.md#branch-4-featupstream-watch-live), [audit record](../../audits/2026-09-26-issues-237-238-239-verification-and-decisions.md) ("Upstream watch and dispatch", "Ruflo support window", "Ruflo 3.46.0", "Retroactive upstream sweep"), [the upstream watch](../../UPSTREAM-WATCH.md), and the SDD ledger's Branch 4 maintainer decisions (B4-G1, B4-G2, B4-Q1, B4-Q2, B4-Q3) and rulings (main checkout `.superpowers/sdd/2026-09-26-remediation-program/progress.md`, lines 56 and 64–72). + +## Global Constraints + +Copied from the program plan; every task's requirements include these. + +- Commits carry no `Co-Authored-By` or other attribution trailer. +- Nothing is pushed, opened as a pull request, merged, posted upstream, or created as a cloud routine without the maintainer's explicit go-ahead for that action. +- Upstream publication follows the constraint registry's `issuePublication: explicit-user-approval-required`. +- Never run `pnpm` in a worktree whose `node_modules` is a symlink; use `node --test`, `npx eslint`, `npx tsc -p tsconfig.json`, `npx markdownlint-cli2` and `node scripts/build-check.mjs`. +- Disposable environments use `env -u XDG_CONFIG_HOME -u XDG_DATA_HOME -u XDG_CACHE_HOME -u XDG_STATE_HOME` (or `env -i`), a `mktemp -d