Skip to content

Commit 35101ee

Browse files
committed
Close Phase 28: guard the cost of proof
Ship WLA-28-05 and close the phase 5/5. Add ProofCostBudgetTest: a conductor tick may spend at most 75 git spawns (58 measured) and may resolve the git directory at most once (0 in the tick path). Wall clock is deliberately not the guard — it is machine-dependent and noisy in CI, and this phase spent a whole story learning that. Subprocess counts are deterministic, and counting is what actually regressed. An overrun names the offending command and the excess rather than printing a bare number, and the budget is proven to bite by planting a redundant rev-parse --git-dir on every git call in a tick. Phase totals, same desk, same suite: core suite wall clock 814s -> ~93-147s tests 499 -> 530 git subprocesses, slowest test 4,633 -> 2,008 rev-parse --git-dir, that test 2,435 -> 0 git spawns per conductor tick ~111 -> 58 8.8x at best, 5.5x on a loaded desk, against a 2x target — while running 31 more tests than the baseline. Nothing was weakened, skipped, or removed. The plan lost to measurement twice, and both times measurement won: WLA-28-03 dropped its cross-derivation snapshot when attribution showed the target was re-observation itself, and WLA-28-04 was parked mid-flight until the instability turned out to be an incidental 300s wall-clock guard no test asserts. Two latent worktree defects were fixed on the way. final-summary.md and handover.md record what shipped, what was deliberately deferred, where each guard lives, and the traps worth not repeating. Tests: 530 core tests sharded OK, budget/boundary/derivation/runner guards, dw verify --all over 179 commits, gate parity, agent surface, docs lint (490 files), canon lint, 3.9 floor, mirrors, rider docs --check, update.sh --check, git diff --check. PMO-Story: WLA-28-05 PMO-Contract-Digest: sha256:b6afba63feb69bba415a6f0bd507eba16bfd5af0e95152cfd75979cb6ddff020
1 parent 5332c14 commit 35101ee

8 files changed

Lines changed: 686 additions & 19 deletions

File tree

‎.hs/context.md‎

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,8 +6,7 @@ This block is rendered from the rails by `dw rider docs`; edit outside the marke
66

77
### work-log-automation
88

9-
- Current phase: 28 (phase-28-faster-proof)
10-
- Next story: WLA-28-01 — Contract the repository-fact boundary [ready]
9+
- Next story: nothing actionable
1110
- Open roadmap warnings: 1
1211

1312
<!-- END DELIVERY WORKBENCH -->

‎pmo-roadmap/pm/roadmap/work-log-automation/README.md‎

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
# Work Log Automation - Roadmap
22

3-
**Last updated:** 2026-07-26 (Phase 27 closed 10/10; Phase 28 opened on measured profiling evidence).
4-
**Current phase:** [Phase 28 - Faster Proof](./phase-28-faster-proof/) (active, 0/5).
5-
**Status:** Phase 27 closed the usability work: one product vocabulary, one shared presentation boundary, a keyboard and assistive contract, and a fresh-consumer exam. Phase 28 now attacks the cost of proof itself. Profiling found the core suite spending 94% of its slowest test inside `git` subprocesses — 2,435 of them re-asking where `.git` is, a fact that cannot change while the process runs. The phase resolves repository facts once, re-reads changing facts exactly when they can have changed, runs the suite in parallel, and guards the result with an executable budget. Speed may not buy itself with staleness; every fail-closed refusal must still fire. Landing and release remain separate decisions.
3+
**Last updated:** 2026-07-26 (Phase 28 closed 5/5: the suite proves the same work 8.8x faster).
4+
**Current phase:** [Phase 28 - Faster Proof](./phase-28-faster-proof/) (closed, 5/5). Next phase not yet chosen.
5+
**Status:** Phase 28 closed the cost of proof. Repository-derived facts now live behind one versioned boundary that says, per fact, what may be reused: where the repository *is* resolves once per process, what it *contains* is read once per observation and never retained. `rev-parse --git-dir` went from 2,435 spawns in the slowest test to zero, the suite runs sharded across processes, and an executable budget fails the build if a tick starts spending again. The core suite went **814s to ~93-147s while growing from 499 to 530 tests** — 8.8x at best, 5.5x on a loaded desk — with nothing weakened, skipped, or removed. Two latent worktree defects were found and fixed on the way. Landing and release remain separate decisions; phases 25-28 are all unreleased.
66

77
## Vision
88

@@ -108,10 +108,10 @@ summarization can improve those entries after the lifecycle is proven.
108108
zero-SDK "CLI is the plugin API" ecosystem flywheel — candidate phase-26
109109
material recorded in the Phase 25 status.
110110

111-
## Current phase: faster proof
111+
## Last closed phase: faster proof
112112

113-
Phase 28 makes proving work cheap enough that nobody is tempted to skip it. It
114-
was opened on measurement, not suspicion. Profiling the core suite on
113+
Phase 28 made proving work cheap enough that nobody is tempted to skip it. It
114+
was opened on measurement, not suspicion, and closed 5/5. Profiling the core suite on
115115
2026-07-26 found 499 tests taking 814s, with 80% of that time in the slowest
116116
10% of tests, and the slowest single test spending 94% of its life inside
117117
`git` subprocesses — 2,435 of them asking `rev-parse --git-dir`, a fact that
@@ -179,7 +179,7 @@ Phase 28 adds no new autonomy, hosted authority, release, or publication scope.
179179
| 25 | Delivery Workbench hears the world outside the run — CI, reviews, merge state, agent activity — records it as durable facts, and under an explicit grant nudges the right agent back to work: observed, bounded, ledgered, revocable. | done | [phase-25-outward-signals](./phase-25-outward-signals/) |
180180
| 26 | Delivery Workbench optionally adds governed autonomous delivery programs across an explicit roadmap scope—without changing vanilla or bounded-run usage—with hierarchical workflows, independent verification, advanced bounded loops, and only the quality, integration, and roadmap acts named by a finite revocable program grant. | done | [phase-26-autonomous-delivery-programs](./phase-26-autonomous-delivery-programs/) |
181181
| 27 | Make Delivery Workbench's everyday application layer speak and behave like a practical delivery tool, with one plain-language vocabulary and coherent task flows across setup, Program Studio, live operation, help, errors, onboarding, and product documentation, while keeping exact protocol terms available in machine contracts, architecture, and explicit audit views. | done | [phase-27-usability-improvements](./phase-27-usability-improvements/) |
182-
| 28 | Cut the cost of proving work — repository facts resolved once, no redundant git spawns, a parallel proof suite — without weakening any freshness, authority, or fail-closed guarantee. | in-progress | [phase-28-faster-proof](./phase-28-faster-proof/) |
182+
| 28 | Cut the cost of proving work — repository facts resolved once, no redundant git spawns, a parallel proof suite — without weakening any freshness, authority, or fail-closed guarantee. | done | [phase-28-faster-proof](./phase-28-faster-proof/) |
183183

184184
## Operating cadence
185185

‎pmo-roadmap/pm/roadmap/work-log-automation/phase-28-faster-proof/current-phase-status.md‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -76,7 +76,7 @@ existing fail-closed refusal must still fire, proven by planted regressions.
7676
- [x] The core proof suite runs sharded across processes on the declared
7777
Python floor with standard-library tooling only, deterministically and with
7878
no cross-shard temp state (WLA-28-04).
79-
- [ ] An executable budget caps `git` spawns per tick and fails the suite if a
79+
- [x] An executable budget caps `git` spawns per tick and fails the suite if a
8080
new private resolver or redundant spawn appears; the full battery is green
8181
and the suite is at least 2x faster on the same machine (WLA-28-05).
8282

@@ -88,7 +88,7 @@ existing fail-closed refusal must still fire, proven by planted regressions.
8888
| WLA-28-02 | Resolve the repository location once | done | [story-02-resolve-the-repository-location-once](./story-02-resolve-the-repository-location-once.md) | [evidence-story-02](./evidence-story-02.md) |
8989
| WLA-28-03 | Read changing facts once per derivation | done | [story-03-read-changing-facts-once-per-derivation](./story-03-read-changing-facts-once-per-derivation.md) | [evidence-story-03](./evidence-story-03.md) |
9090
| WLA-28-04 | Prove work in parallel | done | [story-04-prove-work-in-parallel](./story-04-prove-work-in-parallel.md) | [evidence-story-04](./evidence-story-04.md) |
91-
| WLA-28-05 | Guard the cost of proof | backlog | [story-05-guard-the-cost-of-proof](./story-05-guard-the-cost-of-proof.md) | - |
91+
| WLA-28-05 | Guard the cost of proof | done | [story-05-guard-the-cost-of-proof](./story-05-guard-the-cost-of-proof.md) | [evidence-story-05](./evidence-story-05.md) |
9292

9393
## Where we are
9494

0 commit comments

Comments
 (0)