diff --git a/docs/plans/open-core-split-continuation.md b/docs/plans/open-core-split-continuation.md index 9c4aa6b..d01aec2 100644 --- a/docs/plans/open-core-split-continuation.md +++ b/docs/plans/open-core-split-continuation.md @@ -24,7 +24,7 @@ This plan preserves the actual technical boundary. It is not a license-text-only ### Public core -`trackdubllc/Trackdub` is private, unarchived, and has a fresh-root history. Its root commit was `8bac38a8fa3e0343c5d10c558b64d269d15e7828`; follow-up commits have added CI and cross-platform fixes. The current inspected head is `d590533b3220edf5211ce773b7620487c29eb1e7`. +`trackdubllc/Trackdub` **is public** (made public since this section was last written; Phase 1's release gates passed) and has a fresh-root history. Its root commit was `8bac38a8fa3e0343c5d10c558b64d269d15e7828`; follow-up commits have added CI and cross-platform fixes. See "STATUS: Phase 3 partly complete" under Phase 3 below for current validated state. The core contains: @@ -240,6 +240,33 @@ Gate: a clean clone of the fresh gated repository builds through the pinned core ## Phase 3: Cross-Repository Validation and Publication +### STATUS: Phase 3 partly complete (2026-07-31) — validation steps run, ownership/protection steps need you + +Step 5 (make `Trackdub` public, keep `Trackdub-gated` private) was already +done independent of this checklist. Steps 1–3 (dependency direction, +boundary scan, package metadata) were run this round — see +`docs/plans/phase-3-validation-report.md` for the full detail; Step 1 is +partially verified (reverse dependency direction not independently rerun +against fresh Trackdub-gated clone), Steps 2–3 passed with caveats noted +there (package metadata is source-only, no `dotnet` SDK available to inspect +built artifacts). Step 4 (branch +protection) could not be verified or configured for **either** repository — +no branch-protection/ruleset tool was available in the session that ran this +check. Private repositories support branch protection and repository rulesets +on GitHub Pro, Team, and Enterprise plans, while GitHub Free excludes these +features for private repositories — this session doesn't know `trackdubllc`'s +plan, so `Trackdub-gated`'s gap is recorded as unverified, not accepted. Needs a human +to check `Settings → Branches` on both `Trackdub` and `Trackdub-gated` +directly. **Step 7 itself (recreating relevant historical issues from the +archive in their new canonical repositories) was not attempted this round — +don't read it as done.** What actually happened alongside this validation +work was unrelated general hygiene: the public core's issue tracker had +accumulated unrelated cross-project issues (a different project's Nushell +plugin-registry backlog, nothing to do with the open-core split or the +archive migration); the genuinely-Trackdub ones were kept, the rest closed +`not_planned`. That's noise removal, not the archive-to-new-repo issue +migration Step 7 describes. + 1. Verify the dependency direction from independent clean clones: ```text Trackdub-gated -> Trackdub diff --git a/docs/plans/phase-3-validation-report.md b/docs/plans/phase-3-validation-report.md new file mode 100644 index 0000000..76df822 --- /dev/null +++ b/docs/plans/phase-3-validation-report.md @@ -0,0 +1,147 @@ +# Phase 3 validation report + +Status: complete for what tooling in this session could verify. Ad hoc audit +run 2026-07-31, not a recurring CI gate — see "Gaps" below for what still +needs a human or different tooling. + +Cross-reference `open-core-split-continuation.md`'s Phase 3 section, which +this report fulfills. + +## 1. Dependency direction + +**Verified: `Trackdub` has no reference to `Trackdub-gated`.** + +```shell +grep -rEln "Trackdub-gated|App\.Avalonia|DesktopExportTierGate|DesktopLicensingComposition" \ + --include="*.cs" --include="*.md" --include="*.props" --include="*.targets" \ + --include="*.csproj" --include="*.sln" --include="*.slnx" \ + src/ docs/ *.props *.targets *.csproj *.sln *.slnx +``` + +Two source-code hits, both deliberate seams, not violations: + +- `src/Trackdub.Media.Playback/PlaybackAbstractions.cs:257` — comment + explaining why a member is `public` rather than `internal` (the presenter + that constructs it lives in `Trackdub.App.Avalonia`, a different assembly + in a different repo). +- `src/Trackdub.Application/Properties/AssemblyInfo.cs:4` — + `[assembly: InternalsVisibleTo("Trackdub.App.Avalonia")]`, the actual + friend-assembly grant that seam requires. + +`Directory.Packages.props` has one comment mentioning `App.Avalonia.Tests` +(a pending-migration note about xunit v2 vs FsCheck 3.x) — informational, +not a dependency. + +Every other hit is in `docs/` (plans, specs, audits, architecture, decisions, +operations, development, strategy) — historical/internal-engineering +documents that legitimately predate or describe the split. Per +`docs/repository-policy.md`'s conflict order, historical plans are evidence, +not binding implementation truth, and are explicitly out of scope for the +project's own boundary scanner (see below). + +Separately checked every `` in every `*.csproj` under +`src/`, `tests/`, and `tools/` (94 entries across 25 files): all resolve to +relative paths inside this repo's own tree (`..\..\src\...`, +`..\..\..\src\...`), none point outside it. No `.gitmodules` file or git +submodule/gitlink exists in this repo — expected, since `Trackdub` is the +consumed side of the pin, not the consumer. + +**Confirmed direction from this repo's side: `Trackdub` has no reference to +`Trackdub-gated`, in source, docs, or project files.** The other half of the +direction — that `Trackdub-gated`'s project references genuinely resolve +into `external/Trackdub` and nowhere else — was not independently re-verified +in this session against a fresh clean clone of `Trackdub-gated`; it's known +from `Trackdub-gated/AGENTS.md`'s explicit dependency-direction diagram and +this session's own submodule-pin work on PR #10, not from a repeated grep +here. + +## 2. Boundary scan + +**Ran the repo's existing scanner rather than writing a new one:** + +```console +$ python3 scripts/ci/check-repository-boundary.py +Repository-boundary scan passed. +``` + +This checks for stale monorepo-era license claims (GPL/dual-license wording +outside legitimate third-party-notice discussion) and desktop/cloud project +names bleeding into files a public consumer would read as authoritative. It +already special-cases `src/Trackdub.Media/Process/FfmpegAutoDownloader.cs` +(legitimately discusses GPL ffmpeg builds) and excludes `docs/plans/`, +`docs/decisions/`, `docs/audits/`, `docs/architecture/`, `docs/specs/`, +`docs/operations/`, `docs/development/`, and `tools/` as historical/internal. + +No stale `Trackdub-Monorepo-Archive`, `BSL`, or `Business Source License` +references found anywhere in `docs/legal/`, `src/`, or root `.props` files. + +## 3. Package metadata (source-only — no `dotnet` SDK available) + +**Source declarations verified; generated artifacts not inspected.** No +`dotnet` SDK was available in this session (`which dotnet` found nothing), +so `dotnet pack` could not be run for either project and the resulting +`.nupkg`/`.nuspec` license metadata was never actually inspected. What +follows is a source-only check, not artifact validation — flagging that +distinction explicitly rather than overclaiming. + +Only two projects are packable (with `PackageId` and license metadata set) +in this repo: `Trackdub.Cli` (via `PackAsTool=true`, which implicitly +enables packing — it doesn't itself set `IsPackable`) and +`Trackdub.OnnxRuntime.Dnnl.Native` (via explicit `IsPackable=true`). Several +test projects also declare `IsPackable` — explicitly `false` (e.g. +`tests/Trackdub.Application.Tests/Trackdub.Application.Tests.csproj:7`) — +which correctly excludes them from packing; they aren't a metadata gap. + +| Project | Declared license | Why | +|---|---|---| +| `Trackdub.Cli` | `Apache-2.0` | Trackdub-owned, matches root `LICENSE` | +| `Trackdub.OnnxRuntime.Dnnl.Native` | `MIT` | Third-party-derived native package; kept distinct per Phase 1.4's requirement to preserve real upstream metadata rather than blanket-applying Apache-2.0 | + +`Directory.Build.props` sets no repo-wide package metadata (no +`PackageLicenseExpression`, `RepositoryUrl`, etc.) — correct, since it +would incorrectly apply to `Trackdub.OnnxRuntime.Dnnl.Native`'s MIT license +if it did. Each packable project sets its own metadata explicitly instead. + +**Follow-up:** run `dotnet pack` for both projects on a machine with the .NET +10 SDK and confirm the emitted `.nuspec`/`.nupkg` actually carries the +license expression declared in source — MSBuild property evaluation or a +packaging-target override could in principle diverge from what the +`.csproj` states, and that hasn't been checked. + +## 4. Branch protection + +**Unverified for both repositories — no tool available, and no assumption +made about what plan tier would allow.** The GitHub MCP server this session +had access to exposes no branch-protection or repository-ruleset read/write +tools (checked via broad keyword search across its full tool surface). This +earlier version of this report additionally claimed that `Trackdub-gated` +being private meant branch protection/rulesets weren't available "on +GitHub's private-repo tier" — that claim was wrong and has been removed. +Private repositories support branch protection and repository rulesets on +GitHub Pro, Team, and Enterprise plans, while GitHub Free excludes these +features for private repositories. This session doesn't know which plan +`trackdubllc` is on, so neither repo's branch-protection status is recorded +as an accepted gap — both are simply unverified. + +Action needed from you: check `Settings → Branches` (or `Settings → Rules → +Rulesets`) directly on **both** `trackdubllc/Trackdub` and +`trackdubllc/Trackdub-gated`, record the org's actual GitHub plan and each +repo's actual settings, and decide from there whether the existing +compensating controls in `Trackdub-gated` (PR-merge convention in its +`AGENTS.md`, `REVIEW.md` checklist, green-CI-before-merge) are sufficient on +their own or should be supplemented with real branch protection. + +## Gaps / follow-ups + +- **Branch protection state on both `Trackdub` and `Trackdub-gated`** — + needs a human check with actual repo-settings access, see above. Do not + assume either is or isn't possible based on visibility alone. +- **Stale GitHub labels on `Trackdub`** — `repo:quickshell`, + `repo:numan-plugins`, `repo:numan-registry`, `repo:olive-studio` still + exist on the label set (confirmed via `get_label`) from when this repo's + issue tracker briefly served as a catch-all for unrelated projects. No + label-delete tool was available this session; delete manually via + `Settings → Labels`. +- **Closed cross-project issues #8–#14** — flagged in the original audit for + your skim (closed but world-readable on a now-public repo); not re-checked + in this pass.