Implementation Campaigns

August 14, 2026 · View on GitHub

This document preserves historical campaign-level context for Codex Goals and long-context contributor work. It is not live execution authority. The campaigns below remain useful for chronology, objectives, and completed work-item context.

Live work selection and ownership come from GitHub issues, pull requests, checks, reviews, and the local worktree. One PR's scope is its ImplementationSliceV1 under .allow/spec-system/slices/; normative behavior lives in RIPR-SPEC requirements. Do not infer current work from a campaign status below.

Campaign 1: Agentic DevEx Foundation

Campaign ID: agentic-devex-foundation

Status: complete

Objective:

Make the repo safe for autonomous Codex Goals work and human review.

Why it matters:

ripr is being built for long-context, agent-assisted implementation. The repo must reject ambiguous PRs before review and produce enough receipts for humans to evaluate trusted change instead of chat transcripts.

End state:

  • architecture guard exists
  • output-contract checks exist
  • first behavior fixtures exist
  • docs-as-tests baseline exists
  • test-oracle report exists
  • dogfood report exists
  • Codex Goals campaign docs exist

Work items:

Work itemStatusNotes
policy/architecture-guarddoneWorkspace, architecture, and public API guardrails exist.
output/output-contract-checkdoneOutput contract registry checks exist.
docs/docs-index-checksdoneDocs index checks exist.
docs/codex-goals-campaignsdoneClarify Codex Goals as multi-PR campaigns.
docs/readme-state-and-link-checksdoneREADME state and repo-local Markdown links are checked.
goals/manifest-checkdoneActive campaign manifest is validated and reportable.
fixtures/runner-comparison-v1doneFixture and golden commands run ripr and compare actual outputs.
fixtures/first-two-goldensdoneboundary_gap and weak_error_oracle fixtures exist with JSON and human goldens.
testing/test-oracle-reportdoneAdvisory report measures ripr's own strong, medium, weak, and smoke test oracles.
dogfood/static-self-checkdoneAdvisory ripr-on-ripr report runs stable fixture diffs and records current output.
campaign/agentic-devex-closeoutdoneCampaign 1 is complete and Campaign 2 is active.

Dependencies:

  • Do not start analyzer rewrites until fixture and golden scaffolding can record behavior.
  • Do not treat test-oracle reports as blocking until baseline debt is measured.

Commands:

cargo xtask shape
cargo xtask fix-pr
cargo xtask check-pr
cargo xtask pr-summary
cargo xtask fixtures
cargo xtask goldens check
cargo xtask test-oracle-report
cargo xtask dogfood
cargo xtask metrics

Blocking conditions:

  • policy exception required
  • architecture exception required
  • output schema change required
  • golden blessing needed without explicit review scope
  • campaign item depends on an unmerged non-stackable PR

Review policy:

Work items should usually produce one scoped PR. Independent docs or reporting items may be stackable when the campaign manifest marks them that way.

Campaign 2: Syntax-Backed Analyzer Foundation

Campaign ID: syntax-backed-analyzer-foundation

Status: complete

Objective:

Move the analyzer from lexical facts to syntax-backed facts.

Why it matters:

Current analyzer behavior still has line-oriented surfaces. ripr needs a stable fact model and parser adapter boundary before replacing lexical checks.

End state:

  • FileFacts model exists
  • syntax adapter boundary exists
  • Rust parser substrate is recorded in an ADR
  • tests and oracles are extracted from syntax-backed facts
  • probes attach to stable owner symbols
  • current probe families are generated from syntax facts

Work items:

Work itemStatusNotes
analysis/file-facts-modeldoneFileFacts DTOs exist and the lexical scanner fills them without output drift.
analysis/syntax-adapter-mvpdoneRustSyntaxAdapter boundary exists with lexical adapter compatibility.
design/rust-syntax-substratedoneADR 0006 selects ra_ap_syntax behind the adapter and keeps parser types internal.
analysis/ast-test-oracle-extractiondoneParser-backed facts identify test functions, assertion macros, and unwrap/expect smoke oracles.
analysis/ast-probe-ownershipdoneChanged lines map to module- and impl-qualified owner symbols without cross-linking duplicate names.
analysis/ast-probe-generationdoneCurrent probe families are generated from parser-backed probe shape facts with lexical fallback.

Dependencies:

  • analysis/file-facts-model should merge before syntax adapter work.
  • Parser-backed extraction should use the substrate decision in ADR 0006.
  • Analyzer work items are non-stackable unless the manifest explicitly says otherwise.

Commands:

cargo xtask shape
cargo xtask fix-pr
cargo xtask check-pr
cargo xtask fixtures
cargo xtask goldens check
cargo xtask pr-summary

Blocking conditions:

  • output drift without golden evidence
  • parser-specific types leaking outside the syntax adapter
  • architecture exception required
  • missing stop reason for new unknowns

Review policy:

Each analyzer work item should include spec, fixture or test, output contract evidence when user-visible output changes, metrics movement when capability status changes, and a clear non-goal list.

Campaign 3: Evidence Quality

Campaign ID: evidence-quality

Status: complete

Objective:

Make findings explain changed behavior, oracle strength, propagation, activation,
and unknown stop reasons with enough precision to guide test work.

End state:

  • oracle kind and strength are probe-relative
  • local delta flow can name visible sinks
  • activation modeling can name observed and missing discriminator values
  • output is evidence-first
  • unknown findings include stop reasons across surfaces
  • negative and metamorphic fixtures protect evidence-first output

Work items:

Work itemStatusNotes
output/unknown-stop-reason-invariantdoneUnknown classifications carry stop reasons across domain, JSON, context, GitHub annotations, and human output.
analysis/oracle-strength-v2doneOracle kind and strength distinguish exact error variants, exact values, broad errors, smoke-only checks, snapshots, relational checks, and mock expectations.
analysis/local-delta-flow-v1doneFindings carry typed local flow sinks for visible return, error, field, match-arm, and effect boundaries.
analysis/activation-value-modeling-v1doneFindings carry observed value facts and missing discriminator facts tied to local flow evidence.
output/evidence-first-outputdoneHuman and JSON output render changed behavior, evidence path, weakness, stop reasons, and next action as first-class finding evidence.
fixtures/negative-metamorphic-baselinedoneNegative and metamorphic fixtures cover whitespace/comment/import noise, unrelated token mentions, strong boundary/error oracles, and syntax variants.
campaign/evidence-quality-closeoutdoneCampaign 3 closed with evidence-first output and negative/metamorphic fixture guardrails.

Dependencies:

  • output/unknown-stop-reason-invariant should land before deeper unknown evidence grows so silent unknowns do not become accepted output.
  • analysis/local-delta-flow-v1 landed before activation/value modeling.
  • analysis/activation-value-modeling-v1 landed before evidence-first output.
  • output/evidence-first-output landed before negative/metamorphic fixture expansion.
  • fixtures/negative-metamorphic-baseline should land before Campaign 3 closeout so the evidence-first output has negative and metamorphic guardrails.

Commands:

cargo xtask shape
cargo xtask fix-pr
cargo xtask check-pr
cargo xtask fixtures
cargo xtask goldens check
cargo xtask check-output-contracts
cargo xtask pr-summary

Blocking conditions:

  • unknown classification without a stop reason
  • output drift without golden evidence
  • schema change required outside the scoped PR
  • fixture expansion before evidence fields are stable

Review policy:

Campaign 3 work should improve evidence precision without claiming real mutation outcomes. Unknown is acceptable, but it must be explicit and actionable.

Campaign 4A: Test Efficiency and Vacuity Signals

Status: complete

Objective:

Make low-discriminator tests visible from the same evidence facts used for
static exposure findings.

End state:

  • per-test ledgers name reachable owners, oracle kind and strength, observed values, and static limitations
  • likely-vacuous, smoke-only, broad-oracle, opaque, circular, and duplicative signals are advisory
  • reports explain evidence and suggested next steps without calling tests bad
  • test-efficiency metrics are available for trend tracking
  • agent and editor surfaces can avoid imitating low-discriminator tests
  • ripr and ripr+ badge artifacts publish unresolved-finding counts as inbox-zero signals, with intent and suppressions as durable exception files

Work items:

Work itemStatusNotes
test-efficiency/test-fact-ledgerdonecargo xtask test-efficiency-report writes advisory per-test ledgers with reached owners, oracle kind/strength, observed values, and static limitations.
test-efficiency/vacuous-signal-v1doneThe advisory report now records smoke-only, broad-oracle, disconnected, opaque, circular, and likely-vacuous reasons.
test-efficiency/duplicate-discriminator-v1doneAdvisory groups expose tests sharing an owner set, role-aware activation signature, and oracle shape; members are reclassified duplicative with reason duplicate_activation_and_oracle_shape and a per-test duplicate_group_id linked to the top-level duplicate_groups array. Already-flagged classes (opaque, likely_vacuous, possibly_circular) are preserved.
test-efficiency/report-and-metricsdoneTop-level metrics object in target/ripr/reports/test-efficiency.json exposes tests_scanned, class_counts (all seven classes), reason_counts (all emitted reasons), and duplicate_discriminator_group_count = duplicate_groups.length. The duplicative test count and the group count are intentionally distinct fields. Capability metadata in metrics/capabilities.toml references the new metrics surface.
docs/badge-policydoneBadge policy locks the badge counting rule, native JSON shape, Shields projection, and exact emitted vocabulary.
badge/summary-renderer-v1donePrivate BadgeSummary, BadgeCounts, BadgePolicy, BadgeKind, BadgeStatus live in pub(crate) mod output::badge. ripr_badge_summary derives counts from CheckOutput; render_native_json and render_shields_json produce the wire shapes. 14 unit tests. Public API and policy/public_api.txt unchanged.
badge/ripr-count-v1doneripr check --format badge-json and --format badge-shields dispatch through output::badge::ripr_badge_summary plus the native and Shields renderers from #189. The temporary #![allow(dead_code)] in output/badge.rs and its .ripr/allow-attributes.txt entry are removed. CLI smoke tests cover both formats and confirm badge-plus-* formats remain rejected until badge/ripr-plus-count-v1.
test-intent/v1done.ripr/test_intent.toml loader attaches declared_intent metadata (intent, owner, reason, source) to matching test-efficiency entries. The original class is preserved — intent is additive metadata, never a replacement. Unmatched and ambiguous (name-only) selectors fail the report; declared tests remain visible in both the JSON ledger and the Markdown ## Declared Test Intent section.
badge/ripr-plus-count-v1doneripr check --format badge-plus-json and --format badge-plus-shields read target/ripr/reports/test-efficiency.json (relative to --root), sum unsuppressed exposure gaps and unsuppressed actionable test-efficiency findings, exclude entries with declared_intent metadata, and report opaque entries as unknowns_test_efficiency. Missing report fails clearly with a regenerator hint.
suppressions/v1done.ripr/suppressions.toml loader with closed-set kinds (exposure_gap, test_efficiency); owner + reason required, expires optional in YYYY-MM-DD. Expired entries do not apply and surface as warnings — silent green-forever debt is impossible. Suppressed findings stay visible in detailed reports; the badge counts move them from unsuppressed_* to suppressed_*. Native badge JSON gains a warnings array; Shields stays exactly four fields.
ci/badge-artifactsdonecargo xtask badge-artifacts writes ripr-badge.json, ripr-badge-shields.json, ripr-plus-badge.json, ripr-plus-badge-shields.json, and ripr-badges.md to target/ripr/reports/. The CI workflow runs cargo xtask test-efficiency-report then cargo xtask badge-artifacts (both advisory, both || true); the existing Upload ripr reports step picks up the new files; the badges Markdown is appended to $GITHUB_STEP_SUMMARY. The badge-artifacts task captures git diff origin/main...HEAD to target/ripr/badge-input.diff and runs each format against --root . so exposure and test-efficiency analyze the same codebase. New ReceiptSpec covers all five files. Advisory by default — no --fail-on-nonzero.
badge/repo-scope-artifactsdonecargo xtask repo-badge-artifacts analyzes the full repo baseline through run_repo_analysis (every currently-probeable production syntax shape, not a diff) and writes repo-ripr-badge.json, repo-ripr-badge-shields.json, repo-ripr-plus-badge.json, repo-ripr-plus-badge-shields.json, and repo-ripr-badges.md. Native badge JSON now carries a scope field ("diff" or "repo") on schema 0.2; Shields projection stays exactly four fields. New OutputFormat::RepoBadge* variants route through app::check_workspace_repo; existing diff-scoped cargo xtask badge-artifacts and the BadgeJson/BadgeShields/BadgePlus* formats are unchanged. The v1 baseline is the currently-probeable repo surface — not full seam inventory, not mutation adequacy proof; the deeper seam / test-grip model is tracked as later work.
badge/publish-main-endpointdoneThe two repo-scoped Shields JSON files (badges/ripr.json, badges/ripr-plus.json) are committed to main and served via raw.githubusercontent.com/EffortlessMetrics/ripr/main/badges/.... Root README.md renders them via img.shields.io/endpoint. Refresh: cargo xtask update-badge-endpoints (regenerates from repo-badge-artifacts and copies into badges/). Verify (advisory, not yet a hard CI gate): cargo xtask check-badge-endpoints. Pages deployment was prototyped and rejected as over-engineered for v1 dogfood — it would have required Pages enablement, a deploy workflow, and would have implied downstream users must also enable Pages. The ripr product contract is "ripr emits Shields-compatible JSON"; hosting is replaceable. See deferred/hosted-badge-service in docs/DEFERRED.md.
campaign/test-efficiency-closeoutdoneCampaign 4A marked complete here and in .ripr/goals/active.toml. Final architecture: per-test ledger + class/reason metrics from cargo xtask test-efficiency-report; .ripr/test_intent.toml declarations and .ripr/suppressions.toml exceptions wired into the ripr+ count; diff-scoped PR badge artifacts via cargo xtask badge-artifacts (#195); repo-scoped baseline via cargo xtask repo-badge-artifacts (#204) on schema 0.2 with scope: "repo"; checked-in badges/ripr.json and badges/ripr-plus.json rendered through img.shields.io/endpoint?url=https://raw.githubusercontent.com/EffortlessMetrics/ripr/main/badges/... (#209). Final dogfood snapshot at this campaign close: ripr 163, ripr+ 163 (main = 6b4b2b0); snapshot, not a fixture expectation. PR chain: #195, #198, #199, #200, #204, #205 (DEFERRED.md), #206 (friction-log graduation), #208 (stale-317-headline correction), #209. Issue #207 was the endpoint design-plan. Pages was rejected for v1 dogfood; hosted badge service is deferred/hosted-badge-service. The seam-inventory + test-grip product reframe is next-campaign work (deferred/seam-inventory-test-grip), not unfinished 4A work.

Dependencies:

  • Campaign 3 evidence fields should remain the source of truth; test-efficiency work should not invent a separate classifier for changed behavior.
  • The first report should be advisory and should not fail CI.
  • Badge counting must use the exact emitted strings audited in Badge policy; aspirational class names that the reporter does not produce must not appear in the badge schema.
  • test-intent/v1 ships before suppressions/v1 so intentional smoke and duplicate tests are positive declarations, not exception entries.

Commands:

cargo xtask shape
cargo xtask fix-pr
cargo xtask check-pr
cargo xtask pr-summary
cargo xtask reports index
cargo xtask receipts check
cargo xtask test-oracle-report

Blocking conditions:

  • output says a test is bad instead of reporting evidence and risk shape
  • static analysis suggests deleting tests
  • report language becomes blocking policy before calibration/configuration
  • new automation bypasses Rust-first xtask policy

Campaign 4: Editor and Agent Loop

Objective:

Turn findings into editor and agent actions that help produce targeted tests.

End state:

  • LSP diagnostics carry finding and probe IDs
  • hovers show evidence for the selected finding
  • code actions can copy context packets or open related tests
  • context packets include missing values and assertion shapes

The original Campaign 4 plan was a direct extension of Campaign 3's Finding/StageEvidence model. Campaign 4A (Test Efficiency) made clear that the editor/agent surface needs a richer substrate — behavior seams classified by test-grip evidence rather than ad-hoc finding metadata. The continuation lives under Campaign 4B; the work items below are subsumed there with seam-aware shapes:

Work itemStatusNotes
lsp/evidence-hover-actionssupersededFolded into Campaign 4B as lsp/seam-evidence-hover-v1 (preceded by lsp/repo-seam-diagnostics-v1).
context/agent-context-v2supersededFolded into Campaign 4B as context/agent-seam-packets-v1, scoped around RepoSeam and SeamGripClass.
docs/how-to-use-agent-contextsupersededFolded into Campaign 4B as docs/agent-dispatch-workflow-v1.

Campaign 4B: Repo Seam Inventory and Test Grip

Campaign ID: repo-seam-inventory-test-grip

Status: complete

Objective:

Inventory behavior seams across the repo, classify how strongly current tests
grip each seam through RIPR evidence, and turn actionable gaps into editor
diagnostics and agent-ready test packets.

The Voice A baseline shipped in Campaign 4A (badge/repo-scope-artifacts, #204) becomes a special case of seam classification rather than the analyzer's only repo mode. The seam evidence loop is the editor/agent loop with the right substrate: first-class RepoSeam and SeamGripClass underneath, evidence-first hover and agent packets on top.

End state:

  • RepoSeam, SeamKind, RequiredDiscriminator, and SeamGripClass exist as a first-class data model
  • seam IDs are stable across runs and across input file walk reorderings
  • test-grip evidence per seam covers reach, activate/infect, propagate, observe, discriminate
  • a separate SeamGripClass / TestGripClass is used for grip classification; mapping to existing ExposureClass and to badge counts is explicit, not implicit through type extension
  • a repo exposure report enumerates seams with their grip class and missing-discriminator hypothesis
  • LSP diagnostics surface ungripped or under-gripped seams
  • hover renders the RIPR evidence path for the classification with cited related tests
  • agent context packets carry the load-bearing fields a coding agent needs to write the missing test
  • public repo badge counts can be derived from seam classification without breaking the existing schema
  • static-language constraints hold: no killed/survived/proven/ adequate in static output
  • static seam evidence does not pretend to prove mutation adequacy

Pre-4B LSP groundwork. Before the seam model was ready, three PRs built editor/agent surfaces on the current Finding / AnalysisSnapshot model. They protect the LSP loop and provide fallback behavior while Campaign 4B types are being designed:

  • PR #211 — evidence-rich hover over current Finding / AnalysisSnapshot, replacing generic "evidence found" text with real StageEvidence.summary, related-test oracle text, and weakness rendering.
  • PR #218 — LSP executeCommand ripr.collectContext with server-side context packet lookup and VS Code LSP-first / CLI-fallback copyContext path.
  • PR #219 — VS Code extension e2e smoke tests for activation, command registration, copyContext, and restartServer; wired CI xvfb-run step.

Campaign 4B LSP work (lsp/repo-seam-diagnostics-v1, lsp/seam-evidence-hover-v1, context/agent-seam-packets-v1) will extend or revise these surfaces for RepoSeam / SeamGripClass.

Work items:

Work itemStatusNotes
spec/repo-seam-inventorydoneLanded in #223 as docs/specs/RIPR-SPEC-0005-repo-seam-inventory.md; defines RepoSeam, SeamKind, RequiredDiscriminator, TestGripEvidence, SeamGripClass, stable seam ID rules, the relationship to ProbeShapeFact, headline-vs-visible mapping, static-language boundaries, and the Voice A vs Voice B contract.
analysis/repo-seam-model-v1doneLanded in #229 as crates/ripr/src/analysis/seams.rs; introduces RepoSeam, SeamId, SeamKind, ExpectedSink, RequiredDiscriminator, SeamGripClass as crate-private types per RIPR-SPEC-0005. Deterministic 16-char SeamId via FNV-1a 64-bit; no public Rust API change; no LSP; no badge change.
analysis/repo-seam-inventory-v1doneWalks production Rust files and emits Vec<RepoSeam>; writes target/ripr/reports/repo-seams.{json,md} via cargo xtask repo-seam-inventory. Initial seam kinds: predicate_boundary, error_variant, return_value, field_construction, side_effect, match_arm, call_presence (validation_branch deferred to a follow-up detection PR).
analysis/test-grip-evidence-v1doneCrate-private TestGripEvidence + RelatedTestGrip attaching reach/activate/propagate/observe/discriminate evidence per inventoried seam. No classification, no public report. Built from existing RustIndex / OracleFact / ValueFact facts.
analysis/repo-ripr-classification-v1doneCrate-private SeamGripClass (re-introduced) + classify_seam(seam, evidence) mapping TestGripEvidence to one of 11 spec classes. Headline-vs-visible table on is_headline_eligible. Replaces the stage-zero discard hook from #236 with a real classifier consumer.
output/repo-exposure-report-v1donecargo xtask repo-exposure-report writes target/ripr/reports/repo-exposure.{json,md} from the classified seam inventory; repo-exposure-json / repo-exposure-md formats live in crates/ripr/src/output/repo_exposure.rs. Schema 0.1 documented in docs/OUTPUT_SCHEMA.md § "Repo Exposure Report". Replaces the stage-zero classification discard from #237 with the real renderer consumer.
lsp/repo-seam-diagnostics-v1doneLSP publishes seam diagnostics with stable ripr-seam-{class} codes under the bounded saved-workspace default, with seamDiagnostics: false available as an explicit initialization option override. WARNING for weakly_gripped/ungripped/reachable_unrevealed; INFORMATION for the four *_unknown classes and opaque. strongly_gripped/intentional/suppressed produce no diagnostic. Diagnostic data carries seam_id for hover lookup.
lsp/seam-evidence-hover-v1doneLSP hover for seam diagnostics: looks up ClassifiedSeam via data.seam_id and renders the seam evidence path (grip class, all five RIPR stages with summary, observed values, missing discriminator, related tests with oracle kind/strength, per-kind next step). Pre-4B Finding hover still works for diff-scoped diagnostics — backend prefers seam hover when seam_id is present, otherwise falls through to Finding hover. Code-action work deferred.
context/agent-seam-packets-v1donecargo xtask agent-seam-packets writes target/ripr/reports/agent-seam-packets.json. Schema 0.2 in crates/ripr/src/output/agent_seam_packets.rs. Each headline-eligible classified seam emits one write_targeted_test packet with seam_id, owner, kind, expression, current_grip, RIPR evidence, observed values, missing input values, missing oracle shape, related tests, and assertion templates. Strongly-gripped/opaque/intentional/suppressed seams emit no packet.
docs/agent-dispatch-workflow-v1donedocs/AGENT_DISPATCH_WORKFLOW.md documents the practical loop: run ripr → inspect report/diagnostic → read seam evidence hover → copy seam packet → hand to agent → agent writes targeted test → rerun ripr → optional cargo-mutants confirmation. Includes per-kind examples (predicate boundary, error variant, return value, field construction, side effect, opaque, intentional, suppressed) and explicit pushback against "add more tests" / "coverage is fine" / "this is proven". Linked from docs/DOCUMENTATION.md.
cache/repo-seam-facts-v1rolled-forwardCarried forward into Campaign 5 (Adoption and Calibration). Optional fact-layer cache (file-facts, owner-index, seam-facts; never final outputs). Gated on real performance signal. Landed in Campaign 5A as #255.
calibration/cargo-mutants-v1rolled-forwardCarried forward into Campaign 5. Optional scaffold for comparing static SeamGripClass against cargo-mutants outcomes. Advisory only; static output adopts no mutation-runtime language.
campaign/seam-inventory-test-grip-closeoutdoneCampaign 4B marked complete here and in .ripr/goals/active.toml. Repo seam evidence is now first-class: RepoSeam model, repo seam inventory, TestGripEvidence, SeamGripClass classification, repo exposure report, agent seam packets, LSP seam diagnostics, seam evidence hover, and agent dispatch workflow docs. Static output remains evidence-first; runtime mutation testing remains a separate confirmation step (calibration/cargo-mutants-v1 in Campaign 5). PR chain: #229, #235, #236, #237, #239, #240, #241, #242, #248. The active manifest now points at Campaign 5; cache/repo-seam-facts-v1 and calibration/cargo-mutants-v1 carry forward as ready items there.

Dependencies:

  • spec/repo-seam-inventory landed in #223, analysis/repo-seam-model-v1 in #229, analysis/repo-seam-inventory-v1 in #235, analysis/test-grip-evidence-v1 in #236, analysis/repo-ripr-classification-v1 in #237, and output/repo-exposure-report-v1 follows. Recommended next core steps: context/agent-seam-packets-v1 (agent work-order packets) or lsp/repo-seam-diagnostics-v1 (editor surface). cache/repo-seam-facts-v1 and calibration/cargo-mutants-v1 remain unblocked but optional.
  • lsp/seam-evidence-hover-v1 extends or revises PR #211, which is already merged as pre-4B evidence-rich hover over the current Finding / AnalysisSnapshot model. The seam-native hover will supersede the Finding-backed hover once RepoSeam and SeamGripClass are stable.
  • PR #218 (LSP executeCommand ripr.collectContext) and PR #219 (VS Code extension smoke tests) are also pre-4B groundwork merged before Campaign 4B seam work began. Campaign 4B agent and editor surfaces will build on or replace these current-model implementations.
  • cache/repo-seam-facts-v1 and calibration/cargo-mutants-v1 subsume their broader analogs from Campaign 5; Campaign 5 retains its config and CI policy work.

Commands:

cargo xtask shape
cargo xtask fix-pr
cargo xtask check-pr
cargo xtask check-spec-format
cargo xtask check-spec-ids
cargo xtask check-output-contracts
cargo xtask check-static-language
cargo xtask markdown-links
cargo xtask check-doc-index

Blocking conditions:

  • analyzer code committed before the spec lands
  • SeamGripClass extended without explicit mapping to badge counts
  • runtime-mutation language (killed, survived, etc.) leaking into static seam reports
  • public Rust API surface change without a policy/public_api.txt update
  • LSP / agent surfaces shipped before the seam model and report are settled

Review policy:

This campaign sits inside the operating contract codified in docs/reference/AGENT_HANDOFF_PROTOCOL.md. Spec/model work pings the owner; mechanical sub-step work proceeds inline once authorized.

Campaign 5A: Seam Evidence Usability and Precision

Campaign ID: seam-evidence-usability-and-precision

Status: done

Objective:

Make repo seam evidence fast, precise, and directly actionable for
developers and coding agents, without adopting mutation-runtime
language in static output.

Why it matters:

Campaign 4B made repo seam evidence first-class (RepoSeam, TestGripEvidence, SeamGripClass, repo exposure report, agent seam packets, LSP diagnostics, hover, agent dispatch docs). The signal is visible but not yet useful every day: full-repo seam classification adds multi-second editor latency before the cache/defaults-first work, related-test fanout is broad, many seams classify as activation_unknown because value extraction does not yet cover common Rust test data patterns, oracle-shape detection misses real-world assertion shapes (field assertions, whole-object equality, mock expectations), and packets explain the gap without telling an agent where and how to close it. This campaign closes that gap along four product axes: fast (cache), precise (related-test, value, oracle-shape), actionable (agent packets v2, LSP code actions), and calibrated (cargo-mutants).

Operationalization items (config/ripr-config-v1, ci/sarif-ci-policy) move to Campaign 5B because their defaults and severity model depend on cache performance and oracle-shape stability.

End state:

  • seam fact layers cache cleanly so the cold path still works and the warm path avoids full repo seam walk when inputs are unchanged
  • cache invalidates on source/config/intent/suppression changes; repo exposure report and LSP diagnostics consume the same cached fact source
  • no rendered outputs are cached; cache serialization stays behind a codec boundary; binary serialization, when introduced, uses postcard (never bincode)
  • related-test fanout is reduced and ranked; related tests carry relation_reason and relation_confidence; high-fanout files show fewer irrelevant top related tests
  • activation/value evidence detects common Rust test data patterns (let bindings, constants, builder methods, table-driven cases, rstest cases, enum variants, Option/Result constructors, fixture factories); activation_unknown count falls without new false positives
  • oracle-shape evidence recognizes assert_matches exact variants, field assertions, whole-object equality, snapshot calls with visible field names, mock expectations, and event/state/persistence assertions
  • agent seam packet v2 carries recommended test name, recommended test file, nearest strong test to imitate, candidate input values, assertion shape with example, patterns to imitate, patterns to avoid, and confidence — enough to write the targeted test directly
  • LSP code actions surface inspect-seam, write-targeted-test, open-related-test, and refresh-analysis actions for diagnostics that carry seam_id; no automatic edits
  • calibration scaffold compares static SeamGripClass against cargo-mutants outcomes; runtime mutation vocabulary stays inside calibration/runtime reports; static reports keep the audit vocabulary

Work items:

Work itemStatusNotes
cache/repo-seam-facts-v1doneLanded in #255. Workspace-level Vec<ClassifiedSeam> fact cache at target/ripr/cache/repo-seam-facts/{schema_version}/{key_hash}.json. serde_json behind a codec module boundary; never bincode. Cache key hashes the same Rust file set fed to build_index (production seam sources + test evidence sources), workspace root, cfg/features, config, test intent, suppressions, analyzer version, and schema version — so test-only edits invalidate. Cold path on miss / corrupt; store failures never fail analysis. Renders (JSON, Markdown, diagnostics, hover, packets) stay outside the cache.
analysis/related-test-precision-v1doneLanded in #310. Adds relation_reason and relation_confidence to related tests; ranks related tests in repo exposure report, agent packets, and LSP hover. Reduces noisy fanout without removing related_tests_total. Schema bumps: cache 0.1→0.2, agent_seam_packets 0.2→0.3, repo_exposure 0.1→0.2. Comment/string-stripping defense added for import_path_affinity.
analysis/value-extraction-v2doneAdds syntactic value resolution for let bindings, same-file constants/statics, builder and fixture-override methods, table-driven loops, rstest cases, enum variants, and one-level Option/Result constructors. Keeps string/comment shadows, cross-file constants, and unrelated builder tokens from inflating observed values.
analysis/oracle-shape-v2doneExpands oracle-shape detection for field assertions, whole-object equality over visible struct literals, event/state/persistence observers, mock expectations, and simple custom assertion helpers. Keeps is_err broad and exact assert_matches!(..., Err(...)) strong without learned priors or helper-body analysis.
context/agent-seam-packets-v2doneSchema 0.3 packets now carry recommended_test, nearest_strong_test_to_imitate, candidate_values, assertion_shape (kind + example), patterns_to_imitate, patterns_to_avoid, and recommendation confidence. Uses ranked related tests from analysis/related-test-precision-v1 when available; no automatic edits or generated test skeletons.
lsp/seam-code-actions-v1doneSeam diagnostics now surface code actions for copying the selected seam packet, copying a concrete suggested assertion when the agent packet assertion shape is available, opening the nearest related test when a related-test location is present, and refreshing ripr analysis. Finding diagnostic context-copy actions still work. No automatic edits, generated tests, CodeLens, or in-memory overlays.
calibration/cargo-mutants-v1doneAdds advisory cargo xtask mutation-calibration report generation and public ripr calibrate cargo-mutants import. Imported cargo-mutants JSON/output is joined to static SeamGripClass evidence by seam_id first and unambiguous normalized file/line second; span-based locations are imported, ambiguous file/line candidates stay unassigned, and unmatched runtime mutants remain visible; runtime mutation vocabulary stays inside calibration reports.
campaign/seam-evidence-usability-closeoutdoneFinal Campaign 5A state transition. Closed the campaign after #255, #310, #313, #314, #315, #316, and #327 landed; operationalization items moved to Campaign 5B.

Dependencies:

  • cache/repo-seam-facts-v1 does not block the precision items technically, but landing it first lets the precision PRs benchmark warm/cold paths without rerunning full inventory.
  • analysis/related-test-precision-v1 should land before context/agent-seam-packets-v2 so v2 packets can use ranked related tests as patterns_to_imitate / patterns_to_avoid.
  • analysis/oracle-shape-v2 can land independently now that analysis/value-extraction-v2 has stabilized the value evidence floor.
  • lsp/seam-code-actions-v1 should land after context/agent-seam-packets-v2 so the "Copy suggested assertion" action can use the v2 assertion_shape field.
  • calibration/cargo-mutants-v1 is independent and can land any time.

Commands:

cargo xtask shape
cargo xtask fix-pr
cargo xtask check-pr
cargo xtask goldens check
cargo xtask check-output-contracts
cargo xtask check-static-language

Blocking conditions:

  • bincode introduced as a serialization dependency (use postcard)
  • rendered outputs cached (only fact layers may be cached)
  • mutation-runtime language (killed, survived, proven, adequate) leaking from calibration into static reports
  • output drift without golden evidence
  • default-on seam diagnostics without the repo-seam cache and bounded saved-workspace defaults

Review policy:

This campaign is product work, not refactor work. Each work item should preserve the spec/test/code/output trail. PRs that mix implementation with refactoring should be split.

Closeout:

Campaign 5A is complete. Landed PR chain:

  • #255 cache/repo-seam-facts-v1
  • #310 analysis/related-test-precision-v1
  • #313 analysis/value-extraction-v2
  • #314 analysis/oracle-shape-v2
  • #315 context/agent-seam-packets-v2
  • #316 lsp/seam-code-actions-v1
  • #327 calibration/cargo-mutants-v1

The active campaign now moves to Campaign 5B. Config, SARIF, and badge count remapping are operationalization work, not unfinished 5A precision work.

Campaign 5B: Operationalization

Campaign ID: operationalization

Status: complete

Objective:

Make ripr deployable: repository config governs analyzer behavior,
SARIF and CI policy modes integrate with PR workflows, and the badge
schema can be remapped onto seam-native counts.

Work items:

Work itemStatusNotes
config/ripr-config-v1doneRepo-root ripr.toml governs analysis mode, oracle policy, severity mapping, suppressions path, report caps, and LSP seam-diagnostic defaults while explicit CLI/LSP options still win.
ci/sarif-ci-policydoneSARIF and policy modes consume configured severity and suppression policy; RIPR-SPEC-0008 pins the rule IDs, severity mapping, suppression visibility, advisory default, renderer, and opt-in baseline policy.
badge/seam-native-count-mappingdoneRepo-scoped ripr and ripr+ badges now count configured-visible seam-native unresolved gaps, while diff-scoped badge artifacts remain versioned as legacy finding-exposure counts. Native badge JSON is schema 0.3 with basis and counts.analyzed_seams; Shields endpoint artifacts were refreshed together.
campaign/operationalization-closeoutdoneClosed Campaign 5B after config, SARIF/CI policy, and seam-native badge count mapping landed. The next active campaign is Campaign 6, starting with a draft-stack audit before structural refactors.

Review policy:

5B started with config/ripr-config-v1, then landed SARIF rendering and the opt-in baseline policy, then remapped public repo badges onto seam-native counts. The closeout is docs/manifest only: no analyzer behavior, output schema, SARIF policy, or badge mapping changes.

Campaign 6: Module SRP Refactoring

Campaign ID: modularize-ripr-submodules

Status: complete

Objective:

Refactor internal modules under crates/ripr/src/ so each module has one
product responsibility, improving maintainability, testability, and reasoning
without splitting the package.

Why it matters:

Current modules mix responsibilities (e.g., analysis/mod.rs orchestrates pipeline and counts summaries; analysis/rust_index.rs parses, indexes, and extracts facts). This makes behavior changes ripple across boundaries, testing harder, and future modularization (async, parallelism, caching) more complex. Module boundaries should align with RIPR stages and clear responsibilities.

End state:

crates/ripr/src/
  domain/           — stable data model
  app/              — use-case orchestration
  analysis/
    diff/           — diff parsing
    workspace/      — file discovery and scope
    facts/          — fact model and index
    syntax/         — syntax adapter
    extract/        — fact extraction
    probes/         — probe generation
    classify/       — classification pipeline
  output/           — rendering
  cli/              — argv parsing and execution
  lsp/              — LSP server
  xtask/            — repo automation

The ripr package stays one crate with one published library and binary. Do not split into ripr-core, ripr-cli, ripr-lsp, or schema crates.

Hard constraints:

- Do not split the crate
- No JSON schema changes
- No static output language changes
- No new probe families or classification behavior changes
- Preserve all public behavior and CLI surface
- Re-bless goldens only if the PR intentionally changes output

Work items:

Work itemStatusNotes
campaign/modularization-stack-auditdoneAudited the old Campaign 6 draft stack against current main after Campaign 5B closeout. That audit was the starting snapshot; the final landed chain replaced the stale #251/#253 path with current-base PRs and closed the parked forks.
modularization/infrastructure-and-planningdoneDocumentation, campaign outline, first-PR pattern, and the post-5B stack audit exist; implementation resumes with the canonical stack order below.
analysis/summary-extractiondonePR 1 (#244): Extracted duplicated summary and sort logic from analysis/mod.rs into focused helper modules with no output/API/schema drift.
analysis/pipeline-extractiondonePR 2 (#245): Extracted diff and repo pipeline orchestration into analysis/pipeline.rs while preserving run_analysis and run_repo_analysis as stable facades.
diff/module-splitdonePR 3 (#246): Split analysis/diff.rs into diff/{mod,model,load,parse}.rs with the parser and git-diff adapter behavior preserved.
workspace/module-splitdonePR 4 (#247): Split workspace concerns into focused modules without changing workspace selection behavior.
probes/module-splitdonePR 5 (#249): Split probe concerns into focused modules and preserved sanitize_path behavior for Unix paths, Windows-style paths, colons, and trimming.
facts/model-extractiondonePR 6 (#354): Moved neutral fact DTOs into analysis/facts/model.rs while leaving syntax adapters, builders, extraction, and query logic in place.
syntax/adapter-extractiondonePR 7 (#357): Moved syntax adapter traits and shared syntax facts into analysis/syntax/adapter.rs without moving builders or extraction logic yet.
facts/builder-extractiondonePR 8 (#359): Moved index construction into analysis/facts/build.rs after syntax adapter type extraction.
syntax/ra-extractiondonePR 9 (#361): Parser-backed RA syntax adapter implementation moved into analysis/syntax/ra.rs after build-index extraction.
syntax/lexical-extractiondonePR 10 (#367): Lexical syntax fallback implementation moved into analysis/syntax/lexical.rs after RA extraction.
extract/fact-extractiondonePR 11 (#369): Moved call, return, literal, oracle, and text extraction helpers plus probe-shape constants into analysis/extract/* while keeping rust_index as the compatibility facade.
probes/family-extractiondonePR 12 (#370): Moved probe-family mapping, changed-line family heuristics, and delta metadata into analysis/probes/family.rs.
probes/expectations-extractiondonePR 13 (#371): Moved expected sink and required oracle helpers into analysis/probes/expectations.rs.
probes/id-extractiondonePR 14 (#372): Moved probe ID construction and path sanitization helpers into analysis/probes/ids.rs.
probes/lexical-extractiondonePR 15 (#373): Moved lexical changed-line probe fallback helpers into analysis/probes/lexical.rs.
probes/diff-repo-splitdonePR 16 (#376): Confirmed diff and repo probe seeding already live in analysis/probes/diff.rs and analysis/probes/repo.rs after the probe module split and helper extractions.
classify/context-extractiondonePR 17 (#377): Created analysis/classify/context.rs with ProbeContext as the shared classifier input for later stage extraction.
classify/related-testsdonePR 18 (#379): Moved related-test discovery into analysis/classify/related_tests.rs while preserving classification behavior.
classify/reach-stagedonePR 19 (#380): Moved reach evidence into analysis/classify/reach.rs while preserving classification behavior.
classify/flow-propagationdonePR 20 (#381): Moved local flow and propagation evidence into analysis/classify/flow.rs while preserving classification behavior.
classify/activation-stagedonePR 21 (#383): Moved activation evidence into analysis/classify/activation.rs while preserving classification behavior.
classify/remaining-stagesdonePR 22 (#385): Moved infection, reveal, decision, confidence, missing, stop reasons, and next-step helpers into focused analysis/classify modules while preserving classification behavior.
app/usecase-splitdonePR 23 (#387): Split check, explain, and context use-case orchestration into focused app modules while preserving public API, CLI, LSP, output, and schema behavior.
output/format-extractiondonePR 24 (#388): Moved OutputFormat to output/format.rs while preserving the app::OutputFormat public path.
output/render-dispatchdonePR 25 (#390): Moved render_check dispatch into output/render.rs while preserving the app::render_check public facade.
cli/command-modeldonePR 26 (#391): Created cli/command.rs with a focused CliCommand enum while preserving top-level CLI dispatch behavior.
cli/parse-commanddonePR 27 (#392): Updated cli/parse.rs to return the parsed command shape while preserving argument behavior.
cli/execute-commanddonePR 28 (#394): Created cli/execute.rs for command execution while preserving argument and handler behavior.
domain/context-packet-dtodonePR 29 (#397): Created domain/context_packet.rs with the context packet DTO shape.
output/json-context-dtodonePR 30 (#398): Updated JSON context renderer to use ContextPacket without changing packet output.
lsp/context-packet-usagedonePR 31 (#399): Updated LSP context packet lookup to use ContextPacket while preserving packet output.
api/doc-hidden-internalsdonePR 32 (#400): Marked compatibility module exports #[doc(hidden)] while preserving public API paths.
api/private-internalsblockedPR 33: Make internal modules private (breaking, optional)
xtask/command-dispatchdonePR 34 (#401): Split xtask into command and run modules.
xtask/policy-modulesdonePR 35 (#403): Organize policy checks into xtask/src/policy/.
xtask/report-modulesdonePR 36 (#405): Organize reports into xtask/src/reports/.
campaign/modularization-closeoutdoneFinal review closed Campaign 6, confirmed stale forks #250, #253, and #352 are closed unmerged, and moved the active manifest to Campaign 7 defaults-first operator adoption.

Stack audit:

The Campaign 6 draft PRs were opened before Campaign 5B config, SARIF, badge, and saved-workspace LSP cockpit work landed. Audit snapshot: 2026-05-06 against main at e2648b6.

PRBranchCurrent baseGitHub stateDisposition
#244claude/c6-01-analysis-summary-extractionmaindraft, conflictingKeep as the canonical first refactor, but rebase onto current main; preserve the summary/sort extraction only and remove .ripr/no-panic-allowlist.toml churn unless focused tests still need it.
#245claude/c6-02-analysis-pipeline-extractionmaindraft, conflictingKeep after #244; rebase on the merged summary extraction so analysis/mod.rs becomes a thin facade without changing analyzer behavior.
#246claude/c6-03-diff-module-splitmaindraft, conflictingKeep after #245; rebase and restrict the diff split to diff/{mod,model,load,parse}.rs. Any #[allow(unused_imports)] re-export must stay narrow and documented, and policy allowlist changes need explicit justification.
#247claude/c6-04-workspace-module-splitmaindraft, conflictingKeep after #246; rebase and preserve current analysis-mode scope semantics for instant, draft / fast, deep / ready, and --no-unchanged-tests.
#249claude/c6-05-probes-module-splitmaindraft, mergeable but unstableKeep after #247 and before #251. Rebase onto the workspace split, confirm sanitize_path still replaces /, \, and : with _, trims leading/trailing underscores, keeps the Unix, Windows-style, and trimming tests, and resolve the stale review thread before validation.
#251claude/c6-05-facts-model-extractionclaude/c6-04-workspace-module-splitdraft, stackedKeep as the canonical facts model extraction after #249 lands or is deliberately skipped; rebase through the stack and keep syntax adapters, builders, extractors, and query logic out of the facts model PR.
new PR 6claude/c6-06-syntax-adapter-type-extraction exists without an open PR#251 successorbranch-onlyOpen or recreate this as the missing syntax-adapter extraction after #251; it must establish the analysis/syntax seam before #253 moves index building.
#253claude/c6-07-index-builder-extractionclaude/c6-06-syntax-adapter-type-extractiondraft, stackedHold until the missing PR 6 base exists and merges; then rebase and keep the PR scoped to build_index movement into analysis/facts/build.rs.
#250claude/c6-06-rust-index-module-splitmaindraft, conflictingDo not repair as-is if #251 remains canonical. It overlaps facts-model extraction; close or rewrite later, salvaging only useful tests or notes.

Canonical merge path:

#244 -> #245 -> #246 -> #247 -> #249 -> #251 -> new PR 6 syntax-adapter extraction -> #253

Hold or rewrite path:

#250: close or rewrite if #251 remains the facts-model path

Per-refactor acceptance bar:

- move code only
- preserve behavior
- add focused seam tests for the moved boundary
- no output drift
- no public API drift
- no schema drift
- no analyzer semantic changes

Required gates for each refactor PR:

cargo xtask shape
cargo xtask fix-pr
cargo xtask check-pr
cargo xtask check-public-api
cargo xtask check-architecture
cargo xtask check-output-contracts
cargo test --workspace
git diff --check

Dependencies:

  • Phase 1 (summary, pipeline) establishes the extraction pattern and should merge before Phase 2
  • Phases 2–5 (analysis breakdown) should follow the audited stack order until the draft stack is retired
  • Phase 6–7 (app/CLI split) should follow analysis stabilization
  • Phase 8–9 (API tightening) should follow all internal movement
  • Phase 10 (xtask) is lowest-priority and can happen any time after Phase 1
  • LSP, SARIF, and badge surfaces are frozen except defect fixes while Campaign 6 structural refactors are in flight

Commands:

cargo fmt --check
cargo test --workspace
cargo xtask shape
cargo xtask fix-pr
cargo xtask check-architecture
cargo xtask check-public-api
cargo xtask check-pr
cargo xtask fixtures
cargo xtask goldens check
cargo xtask dogfood

Blocking conditions:

  • Output or golden drift without intentional spec/test evidence
  • Architecture guard or public API guard fails
  • PR mixes multiple phases or responsibilities
  • JSON schema change without new version docs
  • Static language constraints violated

Review policy:

Each modularization PR should be a pure movement with zero behavior change. Include a production-delta summary noting which responsibilities moved to which modules. No refactoring or cleanup in the same PR. Include the standard acceptance checklist in the PR template.

Closeout:

Campaign 6 is complete. Landed PR chain:

  • #347 campaign/modularization-stack-audit
  • #244 analysis/summary-extraction
  • #245 analysis/pipeline-extraction
  • #246 diff/module-split
  • #247 workspace/module-split
  • #249 probes/module-split
  • #354 facts/model-extraction
  • #357 syntax/adapter-extraction
  • #359 facts/builder-extraction
  • #361 syntax/ra-extraction
  • #367 syntax/lexical-extraction
  • #369 extract/fact-extraction
  • #370 probes/family-extraction
  • #371 probes/expectations-extraction
  • #372 probes/id-extraction
  • #373 probes/lexical-extraction
  • #376 probes/diff-repo-split
  • #377 classify/context-extraction
  • #379 classify/related-tests
  • #380 classify/reach-stage
  • #381 classify/flow-propagation
  • #383 classify/activation-stage
  • #385 classify/remaining-stages
  • #387 app/usecase-split
  • #388 output/format-extraction
  • #390 output/render-dispatch
  • #391 cli/command-model
  • #392 cli/parse-command
  • #394 cli/execute-command
  • #397 domain/context-packet-dto
  • #398 output/json-context-dto
  • #399 lsp/context-packet-usage
  • #400 api/doc-hidden-internals
  • #401 xtask/command-dispatch
  • #403 xtask/policy-modules
  • #405 xtask/report-modules

Stale fork disposition at closeout:

  • #250 closed unmerged as the old rust_index.rs module-directory fork.
  • #253 closed unmerged as the old stacked build-index PR; #359 is the landed current-base replacement.
  • #352 closed unmerged as the old draft PR #10 extractor modularization branch.
  • #351 remains a separate policy lane, not Campaign 6 closeout work.

api/private-internals remains explicitly blocked because making compatibility module exports private is a breaking public API decision, not required for the Campaign 6 internal SRP boundary. The saved-workspace LSP cockpit contract stayed green through every analyzer-affecting refactor; post-merge proof for the final xtask report seam passed on main at 72ee398.

The active campaign now moves to Campaign 7. Operator adoption work should build on the modularized internals without adding speculative LSP features.

Campaign 7: Defaults-First Operator Adoption

Campaign ID: defaults-first-operator-adoption

Status: done

Objective:

Make ripr useful from a clean install by giving CLI, editor, and CI users one
defaults-first path from static seam evidence to a targeted-test action and a
receipt that shows the seam improved.

Why it matters:

The core product surfaces now exist: repo exposure reports, seam-native badges, SARIF, LSP diagnostics/hovers/actions, targeted-test briefs, targeted-test outcome receipts, and mutation calibration import. Adoption now depends on a clear operator loop more than additional analyzer structure.

End state:

  • built-in defaults and generated ripr.toml are documented and conservative
  • fast, normal, and deep mode behavior is clear without hand tuning
  • one operator cockpit joins the existing report surfaces into next action
  • GitHub Actions use a copyable workflow with artifacts and optional SARIF rendering/upload
  • editor install and command docs cover the existing saved-workspace loop only
  • example corpus demonstrates the targeted-test loop and optional calibration
  • install/release paths are verified enough for a new user to run the loop

Work items:

Work itemStatusNotes
defaults/config-initdoneBuilt-in defaults, generated ripr.toml, repo-mode exclusions, seam-diagnostic policy, badge/report defaults, and fast/normal/deep mode behavior are documented and test-pinned without output schema or LSP drift.
reports/operator-cockpitdonecargo xtask operator-cockpit writes target/ripr/reports/operator-cockpit.{json,md} by joining existing repo exposure, LSP cockpit, SARIF policy, badge status, targeted-test outcome, and optional mutation calibration artifacts into one next-action surface. operator-cockpit-report remains an alias for existing automation. Missing inputs stay visible with generator commands; top weak seams carry why-it-matters text, a suggested targeted test, and best related-test context when available. The command does not rerun analysis or change static classifications.
ci/github-action-entrypointdoneripr init --ci github generates the copyable defaults-first GitHub Action entrypoint. It runs ripr pilot, renders diff/repo SARIF only when RIPR_UPLOAD_SARIF is true, writes repo badge JSON and Shields artifacts, uploads the pilot/report directories, and keeps the job plus upload steps advisory.
editor/install-polishdoneDocumented the normal VS Code/Open VSX install path, server-resolution fallback, local VSIX smoke path, saved-workspace default, and existing command coverage. The docs now reflect the current e2e coverage for command registration, draft-mode defaults, LSP-first seam context, targeted-test brief copying, suggested assertions, related-test opening, malformed argument handling, and restart behavior without adding editor features.
fixtures/example-corpusdoneAdded fixtures/EXAMPLE_CORPUS.md, the opaque_fixture_builder executable fixture, checked boundary-gap before/after repo-exposure snapshots, targeted-test outcome receipts, and optional mutation-calibration reports. The corpus maps boundary gap, missing equality boundary, weak oracle, exact error variant, opaque fixture/builder, LSP actions, CLI goldens, receipts, and calibration artifacts.
release/install-polishdoneVerified crate package listing, publish dry-run, local cargo install smoke, VSIX packaging, public v0.3.0 GitHub Release server manifest/assets, Windows server archive checksum, and extracted server CLI/LSP smoke; 0.3.1 is prepared as the first public install line that includes ripr pilot and ripr outcome.
campaign/defaults-first-closeoutdoneClosed Campaign 7 after #409 through #417 landed. The closeout audit is recorded in docs/handoffs/2026-05-07-campaign-7-closeout.md; the installed binary ran the boundary-gap seam packet, outcome receipt, and optional calibration loop, and the active manifest now points to Campaign 8 runtime calibration fixtures.

Dependencies:

  • defaults/config-init landed first so every later surface can use the same default profile and mode vocabulary.
  • reports/operator-cockpit landed before GitHub Action and example-corpus work so the CI and demo paths have one canonical next-action artifact.
  • ci/github-action-entrypoint landed before editor install polish so the public CI path already uploads the same pilot/report artifacts the editor docs can point reviewers toward.
  • editor/install-polish should remain documentation/verification unless a regression appears in the existing saved-workspace contract.
  • fixtures/example-corpus follows editor install polish so the public examples can point to the documented editor and CI adoption paths.
  • release/install-polish follows the example corpus so install and release proof can exercise the same public operator loop.
  • campaign/defaults-first-closeout follows release/install proof so the final review can validate a complete install-to-targeted-test loop instead of approving individual surfaces in isolation.

Commands:

cargo package -p ripr --list
cargo publish -p ripr --dry-run
npm --prefix editors/vscode run package
cargo xtask check-pr
cargo xtask check-output-contracts
cargo xtask check-static-language
cargo xtask check-doc-index
cargo xtask check-traceability
cargo xtask check-capabilities
cargo test --workspace

Blocking conditions:

  • new LSP feature work instead of preserving the existing saved-workspace loop
  • output schema drift without a versioned spec update
  • default policy that makes CI blocking by surprise
  • broad examples that do not prove the targeted-test loop
  • install instructions that require cargo install ripr for the normal editor path

Landed PR chain:

  • #409 vscode: default editor analysis to draft
  • #410 campaign: pin defaults config baseline
  • #411 test: pin defaults mode and repo filters
  • #412 campaign: add operator cockpit report
  • #413 ci: add defaults-first GitHub Action entrypoint
  • #414 ci: gate generated SARIF rendering
  • #415 vscode: document and verify install polish
  • #416 fixtures: add defaults-first example corpus
  • #417 docs: verify release install paths

The active campaign now moves to Campaign 8. Calibration fixture work should keep runtime mutation data as explicit supplied input and must not make RIPR run mutation tests.

Campaign 8: Runtime Calibration Fixture Expansion

Campaign ID: runtime-calibration-fixtures

Status: done

Objective:

Expand the calibration fixture lane so RIPR can compare static test-grip
evidence with supplied cargo-mutants results across representative agreement
buckets without turning RIPR into a mutation runner.

Why it matters:

Campaign 7 made the operator loop usable from install to targeted-test receipt. The next credibility gap is calibration breadth: one boundary-gap sample proves the path, but not the range of static/runtime agreement buckets users will see when importing cargo-mutants data from real repositories.

End state:

  • calibration fixtures cover static gaps with runtime signals and static gaps without runtime signals
  • calibration fixtures cover runtime signals without static gaps, ambiguous file/line joins, and unmatched runtime data
  • every runtime artifact is supplied input or generated calibration output
  • operator cockpit and docs show calibration as optional advisory context
  • static output vocabulary remains unchanged outside explicit calibration reports

Work items:

Work itemStatusNotes
calibration/runtime-fixtures-v1doneAdded fixtures/boundary_gap/calibration/runtime-fixtures-v1/ with supplied repo-exposure and cargo-mutants JSON inputs plus checked Markdown/JSON reports. crates/ripr/tests/cli_smoke.rs::calibration_runtime_fixture_matches_checked_reports verifies the public command output against those reports and pins the main static/runtime buckets, ambiguous file/line joins, unmatched runtime data, static seams without runtime data, and seam_id/file_line joins.
campaign/runtime-calibration-closeoutdoneClosed Campaign 8 after the fixture-backed calibration lane was reviewed, post-merge proof passed on main, and manifests moved to Campaign 9 hot-sidecar latency proof. Runtime calibration remains optional supplied-data context; RIPR still does not run mutation tests.

Commands:

cargo test -p ripr calibration
cargo xtask mutation-calibration fixtures/boundary_gap/input --mutants-json fixtures/boundary_gap/calibration/runtime-fixtures-v1/runtime-mutants.json --repo-exposure-json fixtures/boundary_gap/calibration/runtime-fixtures-v1/repo-exposure.json
cargo xtask check-output-contracts
cargo xtask check-static-language
cargo xtask check-fixture-contracts
cargo xtask check-traceability
cargo xtask check-capabilities
cargo test --workspace

Blocking conditions:

  • adding runtime mutation execution to RIPR
  • changing static classifications to match a runtime sample
  • using runtime outcome vocabulary outside explicit calibration reports
  • making calibration required for the default pilot, LSP, SARIF, or badge paths

Landed PR chain:

  • #420 fixtures: add runtime calibration agreement sample
  • campaign/runtime-calibration-closeout

The active campaign now moves to Campaign 9. Hot-sidecar work should start with measurement of current cache and editor refresh behavior before changing cache semantics.

Campaign 9: Hot Sidecar Latency Proof

Campaign ID: hot-sidecar-latency

Status: done

Objective:

Make the editor and operator paths faster without broadening the analyzer or LSP
surface by measuring current cache and refresh behavior first, then tightening
warm-path reuse only where there is evidence.

Why it matters:

Campaign 5A shipped the first repo seam fact cache, and Campaign 7 made the saved-workspace editor/operator loop usable. The next product risk is latency: large workspaces and repeated editor refreshes need proof that warm paths stay fast without serving stale seam evidence.

End state:

  • current repo seam cache behavior and saved-workspace LSP refresh latency are measured from existing commands
  • any hot-path cache change preserves output schemas, static vocabulary, public API, SARIF, badges, and saved-workspace LSP cockpit behavior
  • rendered outputs remain uncached; only fact layers or in-memory indexes may be reused
  • large-repo and editor latency decisions are backed by reports, not speculative storage

Work items:

Work itemStatusNotes
cache/current-latency-auditdoneMeasured the current proof surfaces without behavior changes. Unit-level seam cache and seam inventory tests, LSP tests, lsp-cockpit-report, and operator-cockpit were cheap on a warm local build. LSP cockpit stayed green with the boundary-gap fixture and all contributed VS Code commands covered. Operator cockpit generated quickly and correctly surfaced missing required report inputs when only LSP and optional calibration reports were present. A direct cargo xtask repo-exposure-report audit did not finish within a 20-minute local timeout, so the next work should add bounded latency visibility before any cache rewrite.
cache/repo-exposure-latency-reportdoneAdded cargo xtask repo-exposure-latency-report, which builds the local debug ripr binary, runs repo-exposure-json under a bounded timeout, captures opt-in analyzer trace lines from stderr, skips Markdown after a JSON timeout, and writes target/ripr/reports/repo-exposure-latency.{json,md}. The report observes cache collection, cache load hit/miss/corrupt state, cold compute, cache store, and total phase timing without changing repo-exposure JSON/Markdown, LSP, SARIF, badge, or public API behavior.
cache/repo-exposure-warm-path-reusedoneAdded a repo file-fact cache under target/ripr/cache/repo-file-facts/0.1, changed repo-exposure cold compute to build its index from already-collected workspace bytes, and reused precomputed related-test context plus seam-independent value-resolution facts during full repo evidence construction. The latency report now exposes file_fact_cache counters and cold sub-phases through classification. Local evidence showed file_fact_cache moving from hits_0_misses_134 at about 3065 ms to hits_134_misses_0 at about 328 ms, and after a long bounded run populated the classified-seam cache, the default 30-second latency report passed on cache hits.
pilot/budget-awaredoneAdded a default 30 second ripr pilot analysis budget plus --timeout-ms. Complete runs keep writing repo exposure, agent seam packets, and summary artifacts with pilot-summary.json schema 0.2; timeout runs write pilot-summary.{json,md} with status: partial, reason: timeout, outputs_written, and a retry command instead of waiting silently.
pilot/first-screen-claritydoneImproved pilot-summary.md and terminal copy so the top recommendation answers what was inspected, why the seam matters, what focused test to write, and what command to run after without opening JSON. The complete-run JSON schema remains 0.2; only human-facing Markdown/terminal copy changed.
cache/evidence-latency-progressdoneCloseout proof found that the bounded repo-exposure latency report can still time out after inventory_seams, even with file-fact cache hits, without identifying how far evidence construction progressed. Added trace-only progress lines inside evidence_for_seams; this changes only opt-in latency stderr/report diagnostics and does not change analyzer outputs, schemas, LSP, SARIF, badges, or public API.
cache/evidence-hot-path-indexesdoneReplaced the per-seam full test scan with indexed related-test candidate lookup, built value-resolution facts lazily per related test, and used an owned classification path in repo inventory to avoid cloning full evidence records. A long bounded cold run completed and stored the classified-seam cache; the following default 30-second latency report passed on JSON and Markdown cache hits. No analyzer output, schema, LSP, SARIF, badge, or public API changes are intended.
campaign/hot-sidecar-latency-closeoutdoneClosed Campaign 9 after latency measurement, file-fact warm reuse, evidence hot-path indexing, bounded pilot behavior, first-screen pilot clarity, and post-merge saved-workspace LSP proof landed. Current-main proof showed the first cold default repo-exposure latency run can still exceed 30 seconds until the classified-seam cache is filled; a 120-second bounded cold run completed, stored the cache, and the following default 30-second JSON/Markdown latency report passed on cache hits.

Commands:

cargo test -p ripr analysis::seam_cache --lib
cargo test -p ripr analysis::seam_inventory --lib
cargo test -p ripr lsp
cargo test -p ripr lsp::tests
cargo xtask lsp-cockpit-report
cargo xtask repo-exposure-latency-report
cargo xtask check-output-contracts
cargo xtask check-static-language
cargo xtask check-pr
cargo test --workspace

Blocking conditions:

  • new LSP features instead of preserving the saved-workspace contract
  • caching rendered JSON, Markdown, diagnostics, hover text, or agent packets
  • stale test, config, intent, or suppression data surviving a warm path
  • output/schema/public API/SARIF/badge drift without an explicit spec update

Audit notes:

  • Warm local command timings for analysis::seam_cache, analysis::seam_inventory, lsp, lsp::tests, lsp-cockpit-report, and operator-cockpit were all sub-second on Windows after the build was already warm. These are smoke measurements, not benchmark claims.
  • target/ripr/reports/lsp-cockpit.{json,md} reported pass, one boundary-gap seam diagnostic, all existing seam actions, and no uncovered contributed VS Code commands.
  • target/ripr/reports/operator-cockpit.{json,md} generated quickly but warned because repo exposure, SARIF policy, badge status, and targeted-test outcome reports had not been generated in that target directory. This is current expected behavior: the cockpit joins existing reports and does not rerun analysis.
  • A direct cargo xtask repo-exposure-report audit did not complete within a 20-minute local timeout on this workspace. The spawned ripr.exe process was stopped after the timeout. Treat this as the first Campaign 9 finding: before optimizing cache internals, add bounded repo-exposure latency visibility that reports phase timing and cache hit/miss state.
  • cargo xtask repo-exposure-latency-report now provides that bounded surface. A local 2-second smoke run and the default 30-second run both timed out in repo-exposure-json; the trace reported collect_workspace_state as fast and observed a repo seam fact cache miss before entering cold compute. That makes the next optimization target concrete without changing analyzer results or output schemas.
  • cache/repo-exposure-warm-path-reuse added file-fact cache reuse below the workspace classified-seam cache. The first local latency run populated 134 file-fact entries and reported file_fact_cache at about 3065 ms; the next run reported 134 hits and about 328 ms for that phase. Full repo evidence also now reuses per-test related and value facts. After one long bounded run populated the classified-seam cache, the default 30-second latency report passed on both JSON and Markdown cache-hit runs. pilot/first-screen-clarity then made the pilot Markdown and terminal first screen spell out the inspected seam, why it matters, the focused test to write, and the before/after command pair.
  • The first campaign/hot-sidecar-latency-closeout proof attempt found bounded repo-exposure latency still timing out after inventory_seams on the current repo. cache/evidence-latency-progress added trace-only progress markers inside evidence construction so the latency report can show whether future timeouts are stuck before context build, during per-seam evidence, or after evidence classification.
  • cache/evidence-hot-path-indexes followed that trace. It moved evidence candidate discovery from per-seam full test scans to precomputed candidate indexes, made value-resolution facts lazy, and classified owned seam/evidence vectors on the repo inventory path. Local proof: a 120-second cold latency run passed and stored the classified-seam cache; the next default 30-second latency report passed with repo-exposure-json and repo-exposure-md cache hits at about 12 seconds each.
  • campaign/hot-sidecar-latency-closeout reran proof on current main after the concurrent agent-brief and clippy-policy PRs had merged below the final cache PR. cargo test -p ripr lsp, cargo test -p ripr lsp::tests, and cargo xtask lsp-cockpit-report passed. The first default 30-second repo-exposure-latency-report run was a cache miss and timed out during evidence construction; a 120-second bounded run completed cold compute in about 33 seconds, stored the classified-seam cache, and the following default 30-second report passed on cache hits (repo-exposure-json about 14.6 seconds, repo-exposure-md about 13.4 seconds). Campaign 9 is closed and the active manifest now moves to Campaign 10 editor-agent integration.

Landed PR chain:

  • #422 campaign: record hot sidecar latency audit
  • #423 cache: add repo exposure latency report
  • #431 cache: reuse warm repo exposure facts
  • #436 cli: make pilot budget-aware
  • #437 cache: reuse repo exposure warm path facts
  • #448 pilot: clarify first-screen recommendation
  • #450 cache: trace repo exposure evidence progress
  • #451 cache: index repo evidence hot path
  • #454 campaign: close hot sidecar latency proof

Campaign 10: Editor Agent Integration

Campaign ID: editor-agent-integration

Status: done

Objective:

Make the saved-workspace editor loop and the agent CLI loop line up:
diagnostic -> evidence -> packet or brief -> targeted test -> verify -> receipt
-> cockpit and CI artifacts.

Why it matters:

Campaigns 4B, 7, 8, and 9 made the major product pieces real: saved-workspace seam diagnostics, hovers, copyable packets and briefs, repo exposure, operator cockpit, advisory CI, badge artifacts, calibration imports, and a bounded pilot path. #457 and #458 added ripr agent verify and ripr agent receipt. The next product risk is not another analyzer capability; it is that users and agents still have to stitch the editor, CLI, receipt, cockpit, and CI surfaces together by hand.

#463 briefly changed the active lane to release-surface-0-4. This campaign keeps the active product lane as editor-agent integration and carries the useful release-readiness requirements as release/editor-agent-readiness-proof before closeout.

End state:

  • a saved-workspace seam diagnostic exposes the same evidence and next commands as the agent CLI path
  • users can copy the agent packet or brief, after-snapshot command, verify command, and receipt command without automatic edits
  • operator-cockpit joins existing before/after, verify, receipt, SARIF, badge, LSP, and optional calibration reports without rerunning analysis
  • one fixture pins the full editor-agent loop from LSP expectations through agent packet, verify, receipt, and cockpit output
  • generated CI uploads the editor-agent artifacts as visible non-blocking evidence first
  • installed CLI, packaged VSIX, package dry-run, and known-limits proof cover the loop before closeout

Work items:

Work itemStatusNotes
editor-agent/integration-contract-auditdoneDefine the editor-agent integration contract and inventory current CLI, LSP, VS Code, agent, receipt, cockpit, CI, fixture, install, and release-readiness surfaces. Docs/manifest only.
lsp/agent-loop-copy-commandsdoneSeam diagnostics expose command-oriented copy actions for agent packet, brief, after-snapshot, verify, and receipt commands. The actions are pinned in the boundary-gap LSP fixture and VS Code command registration coverage without automatic edits, CodeLens, inlay hints, semantic tokens, or unsaved-buffer overlays.
operator/verify-receipt-statusdoneoperator-cockpit now reports the editor-agent before snapshot, after snapshot, agent verify JSON, and agent receipt JSON as required inputs. Missing inputs include next commands that match the saved-workspace editor command chain, and present agent verify artifacts summarize improved, changed, regressed, and unchanged counts without rerunning analysis.
fixtures/editor-agent-loopdoneBoundary-gap now has a checked expected/editor-agent-loop/ packet that pins LSP diagnostics/actions through agent packet, agent brief, agent verify, agent receipt, and operator cockpit output. The fixture also pins host-independent agent packet paths.
ci/editor-agent-artifactsdoneThe generated GitHub workflow now uploads the non-blocking editor-agent loop artifacts: pilot summary, repo exposure, agent packet, agent brief, agent verify, agent receipt, targeted-test outcome, optional operator cockpit when the repo-local xtask exists, SARIF when enabled, and badge JSON.
docs/full-evidence-loopdoneQuickstart and installed-user docs now lead with the real diagnostic-to-receipt loop: ripr pilot, targeted brief, focused test, after snapshot, ripr outcome, ripr agent verify, ripr agent receipt, editor actions, generated CI artifacts, and known limits. They state that ripr init materializes optional repo policy rather than activating the useful default path.
release/editor-agent-readiness-proofdonerelease-readiness --version 0.4.0 now proves the installed CLI command surface, boundary-gap pilot, outcome, agent verify, focused agent receipt, repo-exposure latency, LSP cockpit, advisory workflow defaults, VSIX packaging path, and known-limit docs. Package and publish gates remain explicit release-prep checks until the version bump.
campaign/editor-agent-integration-closeoutdoneClosed Campaign 10 after editor, agent, cockpit, CI, fixture, docs, and release-readiness proof aligned with no new public crates, runtime execution, automatic edits, or speculative editor features.

Closeout:

  • The editor and agent paths now share one evidence chain: saved-workspace diagnostic -> evidence -> packet or brief -> focused test -> after snapshot -> ripr outcome -> ripr agent verify -> ripr agent receipt -> cockpit and CI artifacts.
  • The generated GitHub workflow uploads the non-blocking editor-agent artifact set without running mutation testing or enabling CI blocking by default.
  • cargo xtask release-readiness --version 0.4.0 proves the installed command surface, boundary-gap pilot/outcome/verify/receipt fixtures, repo-exposure latency, LSP cockpit, advisory workflow defaults, VSIX path, and known-limit docs. Package and publish gates remain explicit release-prep checks until the version bump.
  • No new analyzer family, LSP feature expansion, unsaved-buffer overlay, automatic edit, runtime mutation execution, CI blocking policy, public crate split, or SARIF/badge schema change shipped in this campaign.

Commands:

cargo xtask check-doc-index
cargo xtask check-traceability
cargo xtask check-capabilities
cargo xtask check-output-contracts
cargo xtask check-static-language
cargo xtask check-pr

Blocking conditions:

  • new analyzer families
  • LSP feature expansion
  • unsaved-buffer overlays
  • runtime execution
  • CI blocking by default
  • SARIF or badge schema churn unless explicitly versioned
  • broad refactors mixed into release-readiness proof
  • replacing the editor-agent integration lane without an explicit product pivot

Campaign 11: LLM Work Loop

Campaign ID: llm-work-loop

Status: done

Objective:

Make the completed editor-agent loop stateful, deterministic, and useful to LLM
agents under review pressure: status -> task packet -> edit target -> verify ->
receipt -> reviewer summary.

Why it matters:

Campaign 10 made the editor-agent loop functionally complete. The next risk is operator drift: agents can see the commands and artifacts, but still have to infer which step is missing, which seam links the artifacts, and what evidence reviewers should inspect. Campaign 11 adds a read-only, artifact-oriented control plane around the existing loop.

End state:

  • agents can inspect loop state without rerunning analysis or relying on chat history
  • loop commands and artifact paths are centralized across CLI, LSP, cockpit, CI, docs, fixtures, and release proof
  • receipts carry provenance and bounded static next-action guidance
  • a reviewer summary joins status, receipt, cockpit, repo exposure, LSP cockpit when present, and CI artifact state
  • fixtures pin happy, unchanged, regressed, missing-artifact, stale-artifact, configured-off, path-with-spaces, and Windows-separator cases
  • generated CI uploads LLM work-loop packets as advisory evidence

Work items:

Work itemStatusNotes
agent/loop-status-reportdoneAdded ripr agent status --root . --json as a read-only artifact status report for before snapshot, after snapshot, agent brief, agent packet, agent verify, and agent receipt, with recoverable seam_id, missing-input commands, and stale-looking warnings.
agent/centralize-loop-command-templatesdoneAdded crates/ripr/src/agent/loop_commands.rs as the shared internal source for workflow, pilot, and editor-agent artifact paths plus packet, brief, snapshot, verify, receipt, status, review-summary, and outcome command templates; agent status, agent brief, pilot, LSP copy actions, generated CI paths, and operator cockpit missing-input commands now reuse it without changing emitted command text.
agent/workflow-manifestdoneAdded ripr agent start --root . --seam-id <id> --out target/ripr/workflow to write workflow.json, commands.md, and agent-brief.json as a source-edit-free workflow packet with selected seam details, artifact paths, shared commands, missing inputs, and explicit no-edit/no-LLM/no-runtime-execution boundaries.
agent/receipt-provenancedoneAdded agent receipt schema 0.2 provenance with ripr version, repo root, optional config fingerprint, command template version, render timestamp, before/after/verify artifact SHA-256 hashes, selected seam ID, before/after classes, movement, and explicit static-boundary flags.
agent/next-action-guidancedoneAdded structured summary.next_action guidance to agent receipt schema 0.3 for improved, changed, regressed, unchanged, new-gap, and resolved states while preserving existing summary fields.
agent/reviewer-summarydoneAdded ripr agent review-summary --root . Markdown plus --json schema 0.1 output that joins status, workflow, receipt, cockpit, repo exposure, LSP cockpit when present, and local CI artifact state into a compact review packet.
fixtures/llm-work-loopdoneAdded a boundary-gap expected/llm-work-loop/ fixture matrix for happy, unchanged, regressed, missing-artifact, stale-artifact, configured-off, path-with-spaces, and Windows-separator loop cases.
ci/llm-work-packetsdoneGenerated CI now writes and uploads target/ripr/workflow with workflow manifest, commands Markdown, agent status JSON/Markdown, agent review summary JSON/Markdown, agent packet, brief, and verify JSON, plus target/ripr/reports/agent-receipt.json and repo-local operator cockpit artifacts when available. Existing target/ripr/agent compatibility copies remain uploaded.
docs/llm-operator-guidedoneAdded docs/LLM_OPERATOR_GUIDE.md as the source-edit-free operator guide for humans and external LLM tools, covering agent status, workflow packet, packet or brief, focused test target, after snapshot, verify, receipt, reviewer summary, CI/editor artifact paths, and explicit anti-goals.
campaign/llm-work-loop-closeoutdoneClosed Campaign 11 after status, command templates, workflow manifests, receipt provenance, next-action guidance, reviewer summary, fixtures, generated CI artifacts, and the operator guide aligned around a source-edit-free static work loop.

Closeout:

  • Campaign 11 now has a deterministic, source-edit-free work loop: ripr agent status -> ripr agent start workflow packet -> packet or brief -> focused external test edit -> after snapshot -> ripr agent verify -> provenance-backed ripr agent receipt -> ripr agent review-summary.
  • Command templates and artifact paths are centralized for CLI, LSP copy actions, operator cockpit missing-input commands, generated CI, docs, and fixtures.
  • Receipts carry static provenance, artifact hashes, command-template version, static boundary flags, and bounded next-action guidance without claiming runtime confirmation.
  • Generated CI uploads workflow status, manifests, packet/brief/verify, receipt, review summary, and operator cockpit artifacts as advisory evidence.
  • The LLM operator guide documents how humans and external LLM tools consume the packet without RIPR calling models, generating tests, editing source, running mutation testing, or blocking CI by default.
  • Campaign 12 is now the active First-Hour UX lane for making the VS Code and GitHub Action first screens useful without report archaeology.

Commands:

cargo test -p ripr agent_status
cargo test -p ripr agent_review_summary
cargo xtask check-output-contracts
cargo xtask check-static-language
cargo xtask check-pr

Blocking conditions:

  • automatic source edits
  • generated tests committed by RIPR
  • runtime mutation execution
  • speculative LSP features
  • new public crates
  • command strings duplicated into new surfaces after the template centralization work item

Campaign 12: First-Hour UX

Campaign ID: first-hour-ux

Status: complete

This campaign is intentionally separate from Campaign 11. Campaign 11 keeps the LLM work loop stateful and deterministic through status, command templates, workflow manifests, receipts, and reviewer summaries. Campaign 12 starts after that control plane is stable and keeps the CLI as the shared engine while making the first editor and CI screens useful.

Objective:

Make a new user successful in the first hour through either the VS Code
extension or generated GitHub workflow, without requiring them to understand
RIPR's internal report topology.

Why it matters:

RIPR 0.4.0 aligned the editor, CLI, agent, cockpit, and CI evidence loop. The next user-facing risk is translation cost: editor users still need to know why diagnostics did not appear, which code action maps to the next focused test, and how to verify the result; CI users still need a useful GitHub-facing summary before downloading artifacts. Campaign 12 keeps the CLI as the shared engine and receipt surface while making the LSP-first and CI-first paths obvious from the surfaces users already open.

End state:

  • VS Code users can see server, workspace, analysis, staleness, and diagnostic state without reading logs first
  • editor code actions are titled around user intent: write the targeted test, open the best related test, copy an agent handoff, verify after the test, and refresh analysis
  • generated GitHub workflows put the top advisory recommendation in the PR or step summary before artifact download is necessary
  • PR test guidance annotations have a spec, JSON contract, placement rules, caps, and opt-in review-comment boundary before generated workflows post line guidance
  • generated CI workflow behavior is pinned by a fixture that covers artifact paths, non-blocking posture, optional SARIF, badge output, and agent artifacts
  • agent command templates and workflow manifests from Campaign 11 feed these UX surfaces instead of creating another command-string source of truth
  • README and installed-user docs are organized by user type: VS Code, CI, CLI, agent, troubleshooting, and known limits

Work items:

Work itemStatusNotes
spec/pr-test-guidance-annotationsdoneRIPR-SPEC-0012 pins the advisory PR annotation/comment contract before implementing ripr review-comments, including changed-line placement, anti-spam caps, bounded LLM guidance, check annotations by default, optional inline review comments, JSON shape, and non-blocking CI posture.
vscode/first-run-statusdoneVS Code now has a status bar and ripr: Show Status path for server resolution, workspace detection, analysis running/complete/stale/failed, and no-actionable-seam states without adding unsaved-buffer overlays.
vscode/action-discoverabilitydoneSeam diagnostics now group code-action titles around inspect, write targeted test, agent handoff, verify after test, review result, and refresh intent while keeping command IDs and payloads stable.
ci/pr-summary-surfacedoneThe generated workflow now writes a reviewer-oriented RIPR advisory summary with pilot and agent review content, artifact paths, SARIF and badge status, known limits, and PR guidance annotation counts when target/ripr/review/comments.json exists; it also emits non-blocking changed-line check annotations from that report.
ci/generated-workflow-smoke-fixturedoneThe generated workflow smoke fixture now pins artifact paths, top-seam extraction, agent artifact generation, non-blocking posture, optional SARIF gates, badge output, advisory summary sections, and PR guidance annotation hooks.
docs/ux-by-user-typedonedocs/QUICKSTART.md now routes the first hour by VS Code, CI, CLI, and agent/reviewer user type, with troubleshooting and known limits; README keeps the short front-door summary and links to the deeper path.
campaign/first-hour-ux-closeoutdoneCampaign 12 closed after the editor status path, intent-titled actions, generated CI advisory summary, generated workflow smoke fixture, and user-type quickstart made the first hour understandable from VS Code, CI, CLI, and agent/reviewer surfaces.

Dependencies:

  • Campaign 11 should centralize command templates before Campaign 12 adds or rewrites command-copy surfaces.
  • Campaign 11 workflow manifests should become the source for any guided agent work packet shown through editor or CI UX.

Commands:

cargo test -p ripr lsp
cd editors/vscode
npm ci
npm run compile
npm run package
npm run test:e2e
cd ../..
cargo xtask check-output-contracts
cargo xtask check-static-language
cargo xtask check-doc-index
cargo xtask check-pr

Blocking conditions:

  • new analyzer families
  • automatic source edits or generated tests
  • runtime mutation execution
  • default CI blocking
  • unsaved-buffer overlays
  • new public crates
  • duplicated command templates after Campaign 11 centralization
  • more report formats that do not improve the VS Code or GitHub first screen

Campaign 13: PR Review Guidance

Campaign ID: pr-review-guidance

Status: complete

Campaigns 10 through 12 made the editor, CLI, agent loop, cockpit, generated CI artifacts, and first-hour docs converge on the same static evidence loop. The remaining visible gap is pull-request review projection. RIPR-SPEC-0012 defines ripr review-comments, the read-only report producer now exists, and generated CI now runs that producer before the existing summary and annotation consumer steps. The exact placement and suppression cases are now fixture-pinned, and the dedicated PR guidance docs now explain the command, CI behavior, summary-only fallback, and inline-comment opt-in boundary. The next step is choosing the next product campaign explicitly.

Objective:

Project the existing static evidence loop into bounded pull-request review
guidance: changed seam -> focused test intent -> verification command -> review
artifact, without turning RIPR into a free-form reviewer or CI blocker.

Why it matters:

Humans and LLM agents now have a deterministic workflow once they inspect RIPR artifacts, but CI-first reviewers still need to download or open reports before they see the changed seam and focused test intent. Campaign 13 should produce the smallest PR-facing projection of existing evidence: changed line placement when safe, summary-only fallback when not safe, bounded test intent, and the verification command. It must not post comments by default, generate tests, make CI blocking, or let an LLM decide what matters.

End state:

  • ripr review-comments writes target/ripr/review/comments.json and comments.md as read-only advisory reports
  • review guidance only places line annotations on changed lines and falls back to summary-only recommendations otherwise
  • guidance is capped, deterministic, deduplicated, and rooted in existing repo exposure, agent packet, agent brief, related-test, severity, and suppression evidence
  • generated GitHub workflows run the report producer before consuming target/ripr/review/comments.json for summaries and check annotations
  • inline PR comments remain opt-in and are not posted by default
  • fixtures pin exact-line, owner-function-line, same-file-line, summary-only, capped, suppressed, and changed-test skip cases
  • docs explain PR guidance as advisory static evidence, not LLM review, runtime mutation proof, automatic edits, generated tests, or default CI blocking

Work items:

Work itemStatusNotes
campaign/pr-review-guidance-auditdoneAudited the long-term static-evidence control-plane objective against current artifacts. The editor/CLI/CI artifact loop is real, but PR review convergence was incomplete because ripr review-comments was specified and consumed only as a future report.
review/pr-guidance-rendererdoneAdded read-only ripr review-comments --root . --base <sha> --head <sha> --out target/ripr/review/comments.json plus Markdown output, joining existing static evidence to produce bounded PR guidance without posting to GitHub or changing analyzer behavior.
ci/run-pr-guidance-reportdoneUpdated generated GitHub workflows to run ripr review-comments before the existing advisory summary and check-annotation consumer steps, preserving non-blocking defaults.
fixtures/pr-guidance-casesdonePinned PR guidance fixtures for exact changed seam line, owner-function changed line, same-file changed line, summary-only fallback, cap suppression, configured suppression, and nearby changed-test skip.
docs/pr-review-guidancedoneAdded PR review guidance documenting ripr review-comments, generated CI check annotations, summary-only fallback, the inline-comment opt-in boundary, pinned fixture cases, and static-evidence limits.
campaign/pr-review-guidance-closeoutdoneClosed Campaign 13 after PR guidance was produced, consumed by generated CI, fixture-pinned, documented, and kept advisory/non-blocking by default.

Closeout:

  • PR guidance now projects existing RIPR evidence into bounded PR surfaces: ripr review-comments -> generated CI summary/check annotations -> fixture matrix -> dedicated user docs.
  • The default workflow remains advisory and non-blocking. Inline PR review comments are not posted by generated workflows and remain a custom explicit opt-in boundary.
  • The guidance path keeps the normal evidence loop intact: changed seam -> focused test intent -> agent brief command -> after snapshot -> agent verify -> receipt or review summary.
  • No analyzer behavior, LSP feature expansion, source edits, generated tests, runtime mutation execution, default CI blocking, public crate split, SARIF schema change, or badge schema change shipped in this campaign.

Next:

  • Campaign 14 is complete. It measured recommendation quality before any ranking or policy work so future optional gates can consume calibrated evidence rather than unmeasured signal.

Dependencies:

  • RIPR-SPEC-0012 remains the product contract for review guidance.
  • Campaign 11 shared command templates remain the source for agent brief and verify command strings used by review guidance.
  • Campaign 12 generated workflow annotation steps remain the non-blocking consumers of the producer output.

Commands:

cargo test -p ripr review_comments
cargo xtask check-output-contracts
cargo xtask check-static-language
cargo xtask check-traceability
cargo xtask check-capabilities
cargo xtask check-pr

Blocking conditions:

  • free-form LLM review comments
  • automatic source edits or generated tests
  • runtime mutation execution or runtime adequacy claims
  • default CI blocking
  • inline PR review comments without explicit opt-in
  • comments placed on unrelated unchanged lines
  • new public crates

Campaign 14: Recommendation Calibration

Campaign ID: recommendation-calibration

Status: complete

Campaigns 11 through 13 built the deterministic human, CI, editor, and external agent control plane: selected seam -> brief/packet -> focused test -> after snapshot -> verify/receipt -> PR guidance. The next trust layer is not a gate. It is measuring whether the recommendation was worth the reviewer or agent's attention in the first place.

Objective:

Move RIPR from a complete static evidence loop to measured recommendation
quality: determine whether PR-time guidance is useful, correctly placed,
properly suppressed or capped, and correlated with improved static evidence
after one focused test.

Why it matters:

RIPR now emits bounded PR guidance, but that still does not answer the adoption question: was the top recommendation worth showing to a reviewer? Campaign 14 turns that into repo-local calibration evidence before any future ranking or policy work. Calibration stays advisory, deterministic, and static; it does not add telemetry, external services, generated tests, runtime mutation execution, or default CI blocking.

End state:

  • a PR-shaped calibration corpus records useful, noisy, wrong-line, already-covered, summary-only, suppression, generated/migration, macro-heavy, trait/generic, and async/error-boundary cases
  • review guidance outcome receipts can record recommendation outcomes without telemetry, external services, source edits, generated tests, or runtime mutation execution
  • recommendation calibration reports measure top recommendation usefulness, false annotations, summary-only fallback correctness, suppression correctness, recommended test target correctness, and review-comment latency
  • generated CI remains advisory and non-blocking while surfacing calibration artifacts when available
  • calibration results feed future ranking and policy decisions without opaque scores or runtime adequacy claims

Work items:

Work itemStatusNotes
campaign/recommendation-calibration-auditdoneAudited the post-Campaign-13 product objective and made recommendation quality the next trust layer before optional policy gates.
spec/recommendation-calibration-reportdoneDefined RIPR-SPEC-0013 for recommendation calibration reports, including inputs, JSON/Markdown shape, usefulness metrics, false annotation tracking, summary-only correctness, suppression correctness, target-file correctness, latency fields, advisory posture, and non-goals.
fixtures/pr-guidance-calibration-corpusdoneAdded PR-shaped calibration expectation metadata for useful recommendation, noisy recommendation, wrong-line placement, already-covered seam, correct summary-only fallback, suppression correctness, generated/migration exclusion, macro-heavy code, trait/generic boundary, and async/error boundary.
review-feedback/outcome-receiptsdoneAdded a lightweight review guidance outcome receipt schema and pinned useful, noisy, wrong-line, already-covered, wrong-target, summary-only-correct, and suppressed-correctly receipt fixtures without telemetry or external services.
report/recommendation-precisiondoneAdded cargo xtask recommendation-calibration, an advisory JSON/Markdown report that joins PR guidance, calibration corpus expectations, optional outcome receipts, suppression state, target placement, latency, and static movement without changing CI blocking defaults. Checked outputs live under fixtures/boundary_gap/expected/recommendation-calibration/recommendation-calibration.{json,md}.
docs/calibration-workflowdoneAdded Recommendation calibration, documenting how to run and read the report, outcome receipts, placement quality, suppression correctness, static movement buckets, reviewer use, fixture artifacts, and advisory limits.
campaign/recommendation-calibration-closeoutdoneClosed after recommendation quality was specified, fixture-pinned, receipt-backed, reported, documented, surfaced advisory-first, and ready to inform later ranking or policy work.

Dependencies:

  • Campaign 13 PR guidance remains the placement and recommendation source.
  • Campaign 11 receipts and review summaries remain the source for before/after static movement and reviewer context.
  • Campaign 5A/8 mutation calibration remains supplied-data calibration. Recommendation calibration may compare against imported runtime artifacts, but RIPR must not run mutation testing.
  • Future calibrated gates are policy over measured evidence. They should not become active until recommendation quality has a calibration baseline.

Commands:

cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-traceability
cargo xtask check-capabilities
cargo xtask check-pr

Blocking conditions:

  • LSP feature work
  • LLM provider integration
  • automatic source edits or generated tests
  • runtime mutation execution
  • runtime adequacy claims
  • default CI blocking
  • opaque scores
  • telemetry or external service dependencies
  • policy gates or acknowledgement labels as part of the calibration report
  • new public crates

Closeout:

  • Recommendation quality is now specified by RIPR-SPEC-0013 and the output schema.
  • The PR-shaped calibration corpus pins useful, noisy, wrong-line, already-covered, summary-only, suppression, generated/migration, macro-heavy, trait/generic, and async/error-boundary cases.
  • Outcome receipts provide repo-local review feedback labels without telemetry or external services.
  • cargo xtask recommendation-calibration emits advisory JSON and Markdown precision reports from existing artifacts.
  • Recommendation calibration documents how to run and read reports, receipts, placement quality, suppression correctness, static movement buckets, and limits.
  • Campaign 14 closeout records the PR chain, proof commands, and deferred policy boundary.

Next:

  • Campaign 15 is complete. Campaign 15 closeout records the PR chain, proof commands, and explicit boundary: optional calibrated gates are available only when configured, while generated workflows remain advisory by default.

Campaign 15: Calibrated Gate Policy

Campaign ID: calibrated-gate-policy

Status: complete

Recommendation calibration comes first. Once RIPR has measured whether its top recommendations are useful, correctly placed, and low-noise, a later policy lane can define optional gates over that evidence without turning advisory visibility into blocking behavior by accident.

Objective:

Define the optional calibrated gate layer for PR-time test-oracle evidence:
separate visibility from blocking, fail only under explicit policy, preserve
waiver/acknowledgement paths, and use runtime mutation calibration only as
imported confidence evidence.

Why it matters:

RIPR gives reviewers a compact PR-facing test-oracle gap packet, but policy should earn the right to block. Some teams may eventually want narrow, high-confidence checks, acknowledgeable warnings, or baseline comparisons. Campaign 15 should define that policy layer only after Campaign 14 supplies a recommendation-quality baseline.

End state:

  • a gate policy spec defines inputs, outputs, modes, acknowledgement labels, calibration evidence, and non-goals before implementation
  • a read-only gate evaluator consumes existing PR guidance, repo exposure, SARIF policy, suppressions, labels, recommendation calibration, and optional mutation calibration reports
  • default generated workflows remain advisory and non-blocking unless an explicit gate mode is configured
  • blocking decisions are deterministic, narrow, auditable, and limited to calibrated high-confidence new gaps
  • waiver labels such as ripr-waive produce visible acknowledged outcomes, not silent success
  • fixtures pin advisory, acknowledged, fail-on-new-high-confidence-gap, baseline-check, suppression, and calibration agreement/disagreement cases
  • docs explain visibility versus gating and keep static evidence vocabulary separate from runtime mutation outcomes

Work items:

Work itemStatusNotes
spec/calibrated-gate-policydonePin the optional calibrated gate policy after recommendation calibration, including modes, inputs, outputs, acknowledgement labels, runtime calibration boundaries, default advisory posture, and non-goals.
gate/policy-evaluatordoneAdd a read-only gate evaluator that writes gate-decision JSON/Markdown from existing evidence and explicit policy without posting comments, editing source, running mutation tests, or changing generated workflow defaults.
fixtures/calibrated-gate-casesdonePin gate fixtures for advisory, acknowledged, baseline-check, fail-on-new-high-confidence-gap, suppression, missing-input, and calibration agreement/disagreement cases.
ci/generated-gate-wiringdoneWire generated GitHub workflows to optionally run the gate evaluator only when explicitly configured, preserving advisory defaults and surfacing acknowledged or blocking decisions in summaries.
docs/calibrated-gate-policydoneDocument calibrated gates as optional policy over existing static evidence, including modes, waiver labels, CI behavior, calibration evidence, and static/runtime vocabulary boundaries.
campaign/calibrated-gate-closeoutdoneClosed Campaign 15 after optional calibrated gates were specified, evaluated, fixture-pinned, optionally wired into generated CI, documented, and kept advisory by default. The closeout audit is recorded in docs/handoffs/2026-05-08-campaign-15-closeout.md.

Campaign 15 is complete. Landed PR chain:

  • #554 opened the current calibrated gate policy lane after Campaign 14 supplied recommendation calibration.
  • #559 pinned RIPR-SPEC-0014 and the gate decision schema contract.
  • #560 added the read-only ripr gate evaluate producer.
  • #561 pinned the calibrated-gate fixture matrix.
  • Direct commit dceb291 wired generated GitHub workflows to run the gate only when explicitly configured.
  • #564 preserved evidence uploads when explicit gate modes fail.
  • #566 added the calibrated gate policy guide and aligned docs with SARIF policy inputs.
  • campaign/calibrated-gate-closeout recorded the final audit and closed the campaign.

Dependencies:

  • Campaign 14 Recommendation Calibration supplies the signal-quality baseline.
  • Campaign 13 PR guidance remains the visibility surface. Gates consume it; they do not replace it.
  • Campaign 5A/8 mutation calibration remains supplied-data calibration. Gates may import calibration artifacts, but RIPR must not run mutation testing.
  • Campaign 5B SARIF policy remains a related advisory policy surface; gate decisions need their own explicit output contract.
  • The ripr-waive label remains an acknowledgement path, not a hidden suppression.

Closeout:

  • Campaign 15 closeout records the final Campaign 15 PR chain, validation commands, and deferred adoption boundary.

Commands:

cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-capabilities
cargo xtask check-pr

Blocking conditions:

  • default CI blocking
  • broad "fail on any RIPR finding" policy
  • runtime mutation vocabulary in static gate decisions
  • running cargo-mutants or any mutation engine from the gate
  • hiding acknowledged or waived gaps from summaries
  • treating PR-body validation claims as observed evidence
  • posting inline comments as part of the gate evaluator
  • automatic source edits or generated tests
  • new public crates

Next:

  • Campaign 16 is complete. Campaign 16 closeout records the gate adoption PR chain, proof commands, and the boundary that Editor Evidence UX remains queued until an explicit activation PR or parallel-lane decision.

Campaign 16: Gate Adoption UX

Campaign ID: gate-adoption-ux

Status: complete

Campaign 15 built the optional gate. The next product risk is adoption: teams need copyable setup examples, visible waiver workflows, baseline guidance, and first-screen summaries before calibrated policy can be used without surprise.

Objective:

Make optional calibrated gate adoption safe and obvious for real teams:
provide copyable generated-CI examples, visible waiver and baseline workflows,
first-screen gate summaries, dogfood receipts, and guidance for when blocking is
appropriate without changing advisory defaults.

Why it matters:

Calibrated gates are now policy over existing evidence, but the default path must stay low-risk. Campaign 16 should make the adoption path clear enough that a team can start with visible-only, move to acknowledgement labels, add a baseline, and only later enable calibrated blocking when local evidence supports it.

End state:

  • docs provide copyable generated-CI examples for visible-only, acknowledgeable, baseline-check, and calibrated-gate
  • waiver and label workflows show how ripr-waive produces visible acknowledged decisions rather than hidden success
  • baseline creation and refresh guidance lets teams avoid punishing historical debt while identifying new policy-eligible gaps
  • generated CI summaries make gate decisions understandable without opening JSON artifacts
  • ripr dogfood receipts demonstrate visible-only and stricter opt-in gate behavior from repo-local evidence
  • blocking-readiness guidance explains when teams should leave gates advisory, use acknowledgement, or enable calibrated blocking

Work items:

Work itemStatusNotes
docs/gate-adoption-examplesdoneAdded copyable generated-CI repository-variable examples for default advisory posture, visible-only, acknowledgeable, baseline-check, and calibrated-gate while preserving generated workflow defaults.
docs/gate-waiver-workflowsdoneAdded sample ripr-waive label and reviewer workflows that keep acknowledged findings visible in gate decisions, auditable through target/ci/labels.json, and separate from durable suppressions.
docs/gate-baseline-workflowdoneAdded baseline creation, review, and refresh guidance that treats baselines as visible historical-debt ledgers, not suppressions, and ties shrink refreshes to focused-test evidence movement.
ci/gate-decision-summary-polishdoneAdded a generated-CI gate decision at-a-glance summary with mode, status, counts, PR labels, acknowledgement labels, applied waiver, baseline, calibration inputs/effects, blocking reason, and artifact paths before the full Markdown report.
dogfood/gate-adoption-receiptsdoneExtended cargo xtask dogfood with checked repo-local gate adoption receipts for visible-only, acknowledged waiver, baseline-existing, baseline-new, missing-baseline, and explicit calibrated-gate decisions while recording that generated CI remains non-blocking by default.
docs/blocking-readiness-guidedoneAdded RIPR blocking-readiness guidance for staying advisory, requiring acknowledgement, using baseline-check, and enabling calibrated blocking only when local evidence is mature.
campaign/gate-adoption-ux-closeoutdoneClosed Campaign 16 after gate adoption docs, waiver workflows, baseline guidance, CI summary polish, dogfood receipts, and blocking-readiness guidance were complete while defaults stayed advisory. The closeout audit is recorded in docs/handoffs/2026-05-08-campaign-16-closeout.md.

Campaign 16 is complete. Landed PR chain:

  • #571 opened Gate Adoption UX after Campaign 15 supplied explicit optional gates.
  • #573 added copyable generated-CI adoption examples for default advisory, visible-only, acknowledgeable, baseline-check, and calibrated-gate modes.
  • #575 documented visible ripr-waive acknowledgement workflows.
  • #576 documented baseline creation, review, and shrink refresh workflows for historical debt.
  • #578 polished generated-CI gate summaries, and #581 hardened their Markdown escaping.
  • #580 added checked repo-local gate adoption dogfood receipts through cargo xtask dogfood.
  • #582 added blocking-readiness guidance for moving from advisory visibility to acknowledgement, baseline-check, and calibrated blocking.
  • campaign/gate-adoption-ux-closeout recorded the final audit and closed the campaign.

Dependencies:

  • Campaign 15 Calibrated Gate Policy supplies the evaluator, decision schema, generated CI opt-in wiring, fixture matrix, and operating model.
  • Campaign 14 Recommendation Calibration remains the local signal-quality source. Gate adoption docs must not imply calibration exists when an input is missing.
  • Campaign 13 PR guidance remains the reviewer visibility source. Gate adoption should summarize policy decisions over PR guidance, not replace the recommendation packet.
  • The ripr-waive label remains acknowledgement, not suppression.
  • Baselines are adoption tools for historical debt, not a reason to hide new policy-eligible gaps.

Commands:

cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-capabilities
cargo xtask check-pr

Blocking conditions:

  • new gate semantics before adoption examples
  • default CI blocking
  • broader "fail on any RIPR finding" policy
  • hiding acknowledged or waived gaps from summaries
  • treating missing calibration as high confidence
  • runtime mutation vocabulary in static gate adoption docs
  • running cargo-mutants or any mutation engine from adoption workflows
  • automatic source edits or generated tests
  • LSP or analyzer behavior changes in this campaign lane
  • new public crates

Closeout:

  • Campaign 16 closeout records the final Campaign 16 PR chain, validation commands, and adoption boundary.

Next:

  • Campaign 17 closed RIPR Zero Adoption. It turned baselines into burn-down ledgers with create, diff, and shrink-only refresh commands while keeping generated CI advisory by default.

Campaign 17: RIPR Zero Adoption

Campaign ID: ripr-zero-adoption

Status: complete

Campaign 16 made optional gates adoptable. The next PR/CI product risk is movement: teams need to see whether a PR introduces new policy-eligible debt, resolves baseline debt, acknowledges an exception, or moves the repo toward RIPR 0.

Objective:

Make RIPR 0 adoption concrete for PR/CI users: turn baselines into visible
burn-down ledgers, create reviewed baseline checkpoints from gate decisions,
diff current evidence against checked-in debt, support shrink-only refreshes,
and keep every new policy mode explicit and advisory by default.

Why it matters:

Most repositories will not start at RIPR 0. Adoption has to show the whole truth without punishing the first run: visible baseline debt, resolved debt, new policy-eligible gaps, acknowledged exceptions, suppressions, stale baseline entries, and safe commands for shrinking reviewed debt.

End state:

  • a baseline debt delta report compares current evidence against reviewed baseline debt without auto-adopting new findings
  • ripr baseline create writes reviewed baseline ledgers from existing gate-decision evidence without implying accepted-forever debt
  • ripr baseline diff reports still-present, resolved, new policy-eligible, acknowledged, suppressed, stale, invalid, and missing-input identities
  • ripr baseline update --remove-resolved supports shrink-only baseline refreshes and never auto-adopts new debt in CI
  • generated CI uploads baseline debt delta artifacts and summarizes debt movement while the gate evaluator remains responsible for pass or fail
  • RIPR Zero adoption docs explain initial baseline creation, baseline-check rollout, shrink-only refresh, new debt review, and waiver versus baseline versus suppression boundaries

Work items:

Work itemStatusNotes
spec/baseline-debt-delta-reportdoneDefined RIPR-SPEC-0016 and the output-schema contract for comparing current PR/CI evidence to reviewed baseline debt without changing analyzer identity, auto-adopting new debt, or making CI blocking by default.
baseline/createdoneAdded ripr baseline create so users can produce stable reviewed .ripr/gate-baseline.json ledgers from existing gate-decision evidence without overwriting by default.
baseline/diffdoneAdded ripr baseline diff to write baseline-debt-delta JSON/Markdown with still-present, resolved, new, acknowledged, suppressed, stale, invalid, and missing-input buckets.
baseline/update-remove-resolveddoneAdded ripr baseline update --remove-resolved as a shrink-only refresh path that removes resolved baseline entries, preserves malformed or ambiguous entries for review, and refuses to auto-adopt new current debt.
ci/baseline-debt-delta-artifactsdoneGenerated CI now runs ripr baseline diff when RIPR_GATE_BASELINE and gate-decision.json are present, uploads the JSON/Markdown through ripr-reports, and summarizes baseline debt movement without making the delta report the pass/fail authority.
docs/baseline-ledger-workflowdoneAdded docs/BASELINE_LEDGER_WORKFLOW.md to document initial adoption, reviewed baseline creation, baseline-check rollout, shrink-only refresh, new debt review, waiver versus baseline versus suppression, and the path toward RIPR 0.
campaign/ripr-zero-adoption-closeoutdoneClosed Campaign 17 after baseline delta, baseline create/diff/shrink-only update, CI artifacts, and baseline ledger docs were in place while defaults stayed advisory. The closeout audit is recorded in docs/handoffs/2026-05-09-campaign-17-closeout.md.

Dependencies:

  • Campaign 16 supplies the visible gate adoption workflow, waiver docs, baseline docs, first-screen summaries, dogfood receipts, and blocking readiness guide.
  • Campaign 15 supplies the explicit gate evaluator and decision schema. RIPR Zero adoption consumes gate decisions; it does not redefine gate policy.
  • Campaign 14 supplies recommendation calibration. Missing or unknown calibration must stay visible rather than becoming confidence.
  • Campaign 13 supplies PR guidance. Debt-delta summaries may reference that evidence, but the baseline ledger is driven by gate decision identities.
  • Existing baselines are adoption checkpoints for historical debt, not suppressions and not permission to adopt new debt silently.

Commands:

cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-capabilities
cargo xtask check-pr

Blocking conditions:

  • analyzer identity rewrites inside Lane 4
  • default CI blocking
  • baseline auto-adoption of new PR findings
  • treating baselines as suppressions or accepted-forever debt
  • hiding acknowledged, suppressed, stale, invalid, or missing-input entries from summaries
  • auto-refreshing or rewriting baselines in generated CI
  • runtime mutation vocabulary in static debt-delta summaries
  • running cargo-mutants or any mutation engine from adoption workflows
  • automatic source edits or generated tests
  • LSP/editor behavior changes in this campaign lane
  • new public crates

Next:

  • Campaign 18 opened RIPR Zero Reporting. It turns the Campaign 17 baseline ledger mechanics into repo-level progress, stale-baseline, trend, and repair reporting while preserving advisory defaults.

Campaign 18: RIPR Zero Reporting

Campaign ID: ripr-zero-reporting

Status: complete

Campaign 17 made reviewed baselines executable. The next adoption risk is that teams can create a baseline and see one PR's movement, but they still lack a repo-level status surface that explains age, ownership, stale entries, debt trends, top repair areas, and progress toward RIPR 0.

Objective:

Make RIPR Zero progress visible as a reporting layer over reviewed baselines,
baseline debt deltas, gate decisions, and recommendation evidence: show repo
RIPR 0 status, baseline age and ownership, stale-debt warnings, trends, and top
repair areas without changing analyzer identity, gate policy, or advisory
defaults.

Why it matters:

RIPR 0 should be an attainable operational target, not a one-time baseline file. Maintainers need to know whether known debt is aging, whether baseline entries have owners and reasons, whether debt is shrinking, which repair areas matter most, and whether CI is routing focused test work without turning RIPR into default-blocking gateware.

End state:

  • a RIPR Zero reporting spec defines repo-level status, debt trends, baseline metadata, stale warnings, top debt areas, and repair routing without claiming perfect tests or coverage adequacy
  • baseline ledgers can carry reviewed owner/reason/created/review metadata while preserving compatibility with existing Campaign 17 baseline files
  • a read-only RIPR Zero status report joins baseline ledgers, baseline debt deltas, gate decisions, and recommendation evidence into JSON/Markdown progress summaries
  • generated CI can surface RIPR Zero status and top repair areas as advisory evidence without making the report the pass/fail authority
  • user docs explain how teams read RIPR Zero status, age and refresh baselines, route repair packets, and interpret progress toward RIPR 0

Work items:

Work itemStatusNotes
spec/ripr-zero-reporting-surfacedoneAdded RIPR-SPEC-0017 for repo-level RIPR Zero status, baseline metadata, stale warnings, trends, top debt areas, and advisory repair routing without analyzer identity rewrites or default CI blocking.
baseline/metadata-v2doneBaseline create now writes additive owner/reason/created/review-after/source metadata, baseline diff reports preserved metadata on baseline-derived items, and shrink-only update preserves existing entry metadata without breaking Campaign 17 ledgers.
report/ripr-zero-statusdoneAdded ripr zero status, a read-only JSON/Markdown status report that joins reviewed baseline, baseline debt delta, optional gate decision, PR guidance, and recommendation calibration evidence.
ci/ripr-zero-summarydoneGenerated CI now runs ripr zero status when baseline-debt-delta.json exists, uploads ripr-zero-status.{json,md}, and appends a RIPR Zero summary with visible unresolved debt, metadata health, top debt area, and repair route while leaving gate decisions as pass/fail authority.
docs/ripr-zero-reporting-workflowdoneAdded docs/RIPR_ZERO_REPORTING_WORKFLOW.md so teams can read RIPR Zero status, age and refresh baselines, route repair packets, and interpret progress without treating RIPR 0 as perfect tests or 100 percent coverage.
campaign/ripr-zero-reporting-closeoutdoneClosed Campaign 18 after RIPR Zero status, baseline metadata, generated-CI reporting, and user workflow docs were in place while defaults stayed advisory. The closeout audit is recorded in docs/handoffs/2026-05-09-campaign-18-closeout.md.

Dependencies:

  • Campaign 17 supplies reviewed baseline ledgers, debt delta reports, shrink-only refreshes, generated-CI artifacts, and the baseline ledger workflow.
  • Campaign 16 supplies gate adoption modes and visible acknowledgement workflows. RIPR Zero reporting may summarize them; it must not redefine gate policy.
  • Campaign 14 supplies recommendation calibration. Missing calibration remains an explicit unknown, not confidence.
  • Campaign 13 supplies PR guidance and repair-oriented recommendations. RIPR Zero reporting may route to those packets; it must not generate tests or make LLM calls.

Commands:

cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-capabilities
cargo xtask check-pr

Blocking conditions:

  • analyzer identity rewrites inside Lane 4
  • recommendation ranking changes
  • gate policy semantic changes
  • default CI blocking
  • baseline auto-adoption of new current debt
  • treating baselines as suppressions or accepted-forever debt
  • hiding acknowledged, suppressed, stale, invalid, or missing-input entries from summaries
  • runtime mutation vocabulary in static RIPR Zero summaries
  • running cargo-mutants or any mutation engine from adoption workflows
  • automatic source edits or generated tests
  • LSP/editor behavior changes in this campaign lane
  • new public crates

Next:

  • No ready work item remains in Campaign 18. Open the next product lane as a new explicit campaign rather than editing RIPR Zero Reporting in place.

Campaign 19: PR Evidence Ledger

Campaign ID: pr-evidence-ledger

Status: complete

Campaign 18 made RIPR Zero status visible for the current PR and current baseline state. The next adoption risk is history: teams need to know whether PRs are shrinking baseline debt, adding new policy-eligible gaps, accumulating waivers, preserving repair receipts, and improving behavioral grip even when line coverage does not move.

Objective:

Turn PR-time RIPR evidence into a durable adoption ledger: record per-PR
behavioral grip movement, waiver and suppression visibility, baseline burn-down,
repair receipts, and coverage/grip frontier signals without changing analyzer
identity, gate policy, recommendation ranking, or advisory defaults.

Why it matters:

RIPR Zero is not just a status page. Maintainers need an audit trail that explains whether each PR improved or worsened behavioral grip, which waivers are aging, which suppressions remain durable policy exceptions, whether baseline debt is shrinking, and whether focused tests improved static evidence without implying that coverage is adequacy.

End state:

  • a PR evidence ledger spec defines append-only PR movement records for new policy-eligible gaps, resolved baseline debt, acknowledgements, suppressions, gate mode, repair receipts, and optional coverage/grip signals
  • a read-only PR evidence ledger report writes JSON/Markdown from existing gate decisions, baseline debt deltas, RIPR Zero status, recommendation calibration, outcome receipts, and optional coverage data
  • generated CI can upload and summarize the PR evidence ledger as advisory history while leaving gate decisions as the pass/fail authority
  • coverage/grip frontier reporting makes execution coverage and behavioral grip movement visible as separate axes without treating coverage as adequacy
  • user docs explain how teams use PR evidence ledgers for waiver aging, baseline burn-down, repair routing, and movement toward RIPR 0

Work items:

Work itemStatusNotes
spec/pr-evidence-ledger-surfacedoneAdded RIPR-SPEC-0018 as the PR evidence ledger contract for append-only per-PR movement, waiver aging, baseline burn-down, repair receipts, optional coverage/grip frontier signals, and advisory-only CI projection without analyzer identity rewrites or default blocking.
report/pr-evidence-ledgerdoneAdded ripr pr-ledger record, a read-only JSON/Markdown report over existing PR guidance, gate decision, baseline debt delta, RIPR Zero status, recommendation calibration, agent receipt, optional coverage, and optional history inputs.
ci/pr-evidence-ledger-summarydoneGenerated GitHub CI now runs ripr pr-ledger record on pull requests after PR guidance, optional gate, baseline delta, and RIPR Zero reports exist; uploads pr-evidence-ledger.{json,md} with the normal artifact packet; and appends a PR movement card while leaving gate decisions as the pass/fail authority.
report/coverage-grip-frontierdoneAdded ripr coverage-grip frontier, a read-only JSON/Markdown report that keeps coverage delta, RIPR movement, quadrants, interpretation, warnings, and advisory limits as separate axes without treating coverage as adequacy.
docs/pr-evidence-ledger-workflowdoneAdded docs/PR_EVIDENCE_LEDGER_WORKFLOW.md, explaining how teams read PR evidence ledgers, use waiver aging and baseline burn-down, route repair receipts, interpret coverage/grip frontier signals, and track movement toward RIPR 0 without learning internal report topology.
campaign/pr-evidence-ledger-closeoutdoneClosed Campaign 19 after PR evidence ledgers, generated-CI projection, coverage/grip frontier summaries, and user workflow docs landed while defaults stayed advisory and gate decisions remained the pass/fail authority.

Dependencies:

  • Campaign 18 supplies RIPR Zero status, baseline metadata health, trend availability, top debt areas, repair routes, and generated-CI projection.
  • Campaign 17 supplies reviewed baselines and baseline debt delta reports.
  • Campaign 16 supplies visible waiver and baseline adoption workflows.
  • Campaign 15 supplies gate decisions. The ledger may record gate output; it must not redefine gate policy or pass/fail authority.
  • Campaign 14 supplies recommendation calibration and outcome receipts. Missing calibration remains explicit unknown evidence.
  • Coverage data is optional execution evidence. The campaign must not turn RIPR into a coverage dashboard or treat coverage movement as adequacy.

Commands:

cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-capabilities
cargo xtask check-pr

Blocking conditions:

  • analyzer identity rewrites inside Lane 4
  • recommendation ranking changes
  • gate policy semantic changes
  • default CI blocking
  • making the PR evidence ledger the pass/fail authority
  • baseline auto-adoption of new current debt
  • treating baselines, waivers, or suppressions as interchangeable
  • hiding acknowledged, suppressed, stale, invalid, or missing-input entries from summaries
  • runtime mutation vocabulary in static ledger summaries unless imported runtime calibration is explicitly cited
  • treating coverage movement as test adequacy
  • running cargo-mutants or any mutation engine from ledger workflows
  • automatic source edits or generated tests
  • LSP/editor behavior changes in this campaign lane
  • new public crates

Closeout:

Campaign 19 closed PR Evidence Ledger. It turned per-PR RIPR evidence into an adoption ledger for new policy-eligible gaps, resolved baseline debt, acknowledgements, suppressions, gate mode, repair receipts, waiver aging, optional history, and optional coverage/grip frontier signals. The campaign kept Lane 4's boundary: it consumed existing analyzer, gate, calibration, baseline, and receipt artifacts; it did not change analyzer identity, recommendation ranking, gate policy semantics, LSP/editor behavior, mutation execution, source editing, generated tests, public crate shape, or generated-CI advisory defaults.

No ready work item remains in .ripr/goals/active.toml after this closeout. Open the next product campaign explicitly rather than extending PR Evidence Ledger by inertia.

Campaign 20: Test-Oracle Assistant Proof

Campaign ID: test-oracle-assistant-proof

Status: complete

Campaign 19 made per-PR adoption history visible. The next product risk is whether the already-built surfaces form one review loop instead of a collection of reports: changed Rust behavior should lead to one visible recommendation, one bounded handoff packet, one focused test, one after-evidence check, one receipt, and one advisory PR/CI projection.

Objective:

Prove the full PR-time test-oracle assistant loop: changed Rust behavior flows
through static evidence, PR/editor guidance, a bounded focused-test handoff,
before/after verification, receipt, and advisory CI/ledger projection without
changing analyzer semantics, recommendation ranking, gate policy, LSP behavior,
or default CI blocking.

Why it matters:

RIPR has the individual pieces needed for the product promise: PR guidance, editor evidence, agent packets, receipts, calibrated gates, baselines, RIPR Zero reports, ledgers, and coverage/grip frontier reports. Teams still need a checked first path that shows how those pieces fit together for one changed behavior without artifact archaeology or internal vocabulary.

End state:

  • a spec defines the end-to-end proof contract from diff evidence through recommendation, handoff packet, focused-test repair, after-evidence, receipt, and advisory PR/CI projection
  • a canonical review-loop fixture pins one changed-behavior case across before evidence, top recommendation, related test, focused test shape, after evidence, receipt, and ledger projection expectations
  • a dogfood receipt proves the current repo can trace one seam through PR guidance, editor/agent packet surfaces, verification commands, receipts, and advisory CI artifacts without artifact archaeology
  • user docs explain the PR-time assistant workflow without requiring users to learn cockpit or internal report topology first
  • closeout records which parts of the loop are verified, which remain advisory, and which future work must not blur static evidence with runtime mutation confirmation

Work items:

Work itemStatusNotes
spec/test-oracle-assistant-loopdoneAdded RIPR-SPEC-0019 as the end-to-end test-oracle assistant proof contract from changed Rust behavior through static evidence, PR/editor guidance, focused-test handoff, after-evidence verification, receipt, and advisory PR/CI projection without changing analyzer, policy, editor, or CI defaults.
fixtures/canonical-review-loopdoneAdded the canonical boundary-gap replay corpus under fixtures/boundary_gap/expected/test-oracle-assistant-loop/canonical/ and a regression test that pins one seam across recommendation, related-test context, suggested focused test, before/after static movement, receipt, and PR ledger projection expectations.
dogfood/test-oracle-assistant-receiptdoneRecorded a repo-local proof receipt that traces seam 67fc764ba37d77bd through PR guidance, editor/agent packet surfaces, verification commands, after-evidence, receipt, PR evidence ledger, and coverage/grip frontier availability without changing source automatically.
docs/test-oracle-assistant-workflowdoneAdded docs/TEST_ORACLE_ASSISTANT_WORKFLOW.md, documenting the user workflow from PR recommendation or editor diagnostic to bounded handoff, one focused test, after evidence, receipt, and advisory CI/ledger projection while preserving static-evidence limits.
campaign/test-oracle-assistant-proof-closeoutdoneClosed Campaign 20 after the end-to-end assistant proof contract, canonical fixture, dogfood receipt, and user workflow docs demonstrated the full loop while defaults stay advisory.

Dependencies:

  • Campaign 13 supplies bounded PR guidance and changed-line-safe annotation placement.
  • Campaign 14 supplies recommendation calibration and outcome receipts. Missing calibration remains explicit unknown evidence.
  • Campaign 15 supplies optional gate decisions. This campaign may display gate output; it must not redefine gate policy or pass/fail authority.
  • Campaigns 17 and 18 supply baseline debt deltas and RIPR Zero status.
  • Campaign 19 supplies the PR evidence ledger and coverage/grip frontier.
  • Editor Evidence UX supplies the saved-workspace editor handoff surface.

Commands:

cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-capabilities
cargo xtask check-output-contracts
cargo xtask check-pr

Blocking conditions:

  • analyzer identity rewrites inside the proof campaign
  • recommendation ranking changes
  • gate policy semantic changes
  • default CI blocking
  • making any ledger or proof receipt the pass/fail authority
  • hiding acknowledged, suppressed, stale, invalid, or missing-input entries
  • runtime mutation vocabulary in static proof surfaces unless imported runtime calibration is explicitly cited
  • treating coverage movement as test adequacy
  • running cargo-mutants or any mutation engine from proof workflows
  • automatic source edits or generated tests
  • LSP/editor behavior changes in this campaign lane
  • new public crates

Next:

  • No ready work item remains in Campaign 20. Choose the next campaign explicitly before opening another product lane.

Campaign 21: Test-Oracle Assistant Report Producer

Campaign ID: test-oracle-assistant-report-producer

Status: complete

Campaign 20 proved the assistant loop as a contract, fixture, dogfood receipt, and user workflow. The next product gap is that users still need a first-class read-only report producer instead of reading the artifact chain by hand.

Objective:

Make the test-oracle assistant loop a concrete report surface: join existing
PR guidance, editor/agent handoff, before/after static evidence, receipts, PR
ledger, optional gate decisions, and optional coverage/grip frontier inputs
into advisory `test-oracle-assistant-proof.{json,md}` artifacts without
rerunning hidden analysis, editing source, generating tests, calling providers,
running mutation testing, or changing default CI blocking.

End state:

  • ripr assistant-loop proof writes JSON and Markdown from explicit existing artifact paths
  • the report preserves selected seam identity, missing discriminator, placement state, handoff command, static movement, receipt path, PR ledger path, optional gate path, optional coverage/grip frontier path, warnings, and static limits
  • fixtures and tests cover complete proof, summary-only guidance, missing optional inputs, missing required inputs, unchanged movement, and advisory limits
  • generated CI may surface the proof report only as advisory evidence when inputs exist
  • user docs explain how to read the proof report without artifact archaeology
  • closeout records remaining advisory boundaries and future work exclusions

Work items:

Work itemStatusNotes
report/test-oracle-assistant-proofdoneImplemented ripr assistant-loop proof, a read-only report producer that writes advisory JSON and Markdown from explicit Campaign 20 artifact inputs while preserving static vocabulary and advisory limits.
ci/test-oracle-assistant-proof-artifactsdoneGenerated GitHub CI now runs ripr assistant-loop proof only when PR guidance, editor/agent brief, before/after evidence, agent receipt, and PR evidence ledger inputs exist, uploads test-oracle-assistant-proof.{json,md}, and appends proof summary content without changing default blocking.
docs/test-oracle-assistant-proof-reportdoneAdded docs/TEST_ORACLE_ASSISTANT_PROOF_REPORT.md, explaining how reviewers, maintainers, and coding agents read proof report status, warnings, static movement, optional CI projection, handoff fields, and advisory limits without artifact archaeology.
campaign/test-oracle-assistant-report-closeoutdoneClosed Campaign 21 after the proof report producer, generated-CI advisory projection, docs, and validation demonstrated a first-class report surface without changing analyzer, gate, editor, or mutation behavior.

Dependencies:

  • Campaign 20 supplies RIPR-SPEC-0019, the canonical replay corpus, dogfood receipt, and user workflow docs.
  • Campaign 13 supplies bounded PR guidance and changed-line-safe annotation placement.
  • Campaign 19 supplies PR evidence ledger and coverage/grip frontier inputs.
  • Agent loop artifacts supply existing handoff, verify, and receipt paths.
  • Optional gate decisions stay separate from proof report pass/fail authority.

Commands:

cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-capabilities
cargo xtask check-output-contracts
cargo xtask check-pr

Blocking conditions:

  • analyzer identity rewrites
  • recommendation ranking changes
  • gate policy semantic changes
  • default CI blocking
  • hidden reruns or implicit artifact discovery in the proof producer
  • making proof reports the pass/fail authority
  • runtime mutation vocabulary without imported runtime calibration
  • treating coverage movement as test adequacy
  • running cargo-mutants or any mutation engine from proof workflows
  • automatic source edits or generated tests
  • LSP/editor behavior changes in this campaign lane
  • new public crates

Next:

  • Campaign 22, First Useful Action, is now closed as the current completed campaign in .ripr/goals/active.toml. Its report contract, routing corpus, read-only producer, generated CI projection, editor projection, workflow guide, dogfood receipts, and closeout audit are pinned. No ready Campaign 22 work item remains; choose the next campaign explicitly before opening another product lane.

Campaign 22: First Useful Action

Campaign ID: first-useful-action

Status: closed in the work-item ledger. .ripr/goals/active.toml remains the current completed campaign manifest until the next campaign is explicitly opened.

Campaign 21 made the test-oracle assistant proof loop a first-class advisory report. The next product risk is report sprawl: users should not need to know which artifact is authoritative before they know the next useful test action. This campaign compresses existing evidence into one advisory action for developers, reviewers, and coding agents.

Objective:

Given existing RIPR artifacts, produce one advisory first-useful-action report
that tells a developer, reviewer, or coding agent what to do next, why, where,
how to verify, what receipt proves the result, and what limits remain without
rerunning hidden analysis, editing source, generating tests, calling providers,
running mutation testing, changing default CI blocking, or inventing policy.

End state:

  • target/ripr/reports/first-useful-action.json and .md summarize the highest-value next test action or the reason no action should be taken
  • routing is deterministic over explicit existing inputs such as PR guidance, PR evidence ledger, baseline debt delta, assistant proof, receipts, optional gate decisions, optional coverage/grip frontier, editor context, and status/staleness
  • fixtures pin actionable, stale, missing-artifact, baseline-only, acknowledged, waived, suppressed, already-improved, unchanged-after-attempt, and no-actionable-seam cases
  • generated CI surfaces the first useful action as advisory summary/artifact content without changing pass/fail authority
  • the editor may project the report in status or Show Status without new diagnostics, CodeLens, inlay hints, unsaved-buffer overlays, source edits, or generated tests
  • docs and dogfood receipts show how developers, reviewers, and agents use the action without treating static evidence as runtime proof

Work items:

Work itemStatusNotes
spec/first-useful-action-reportdoneAdded RIPR-SPEC-0020 plus OUTPUT_SCHEMA, traceability, capability, campaign, plan, roadmap, and changelog updates for the first-useful-action report contract before implementation.
fixtures/first-useful-action-corpusdoneAdded fixtures/boundary_gap/expected/first-useful-action/ with a routing index plus expected JSON/Markdown report outputs for actionable, stale, missing-required-artifact, baseline-only, acknowledged, waived, suppressed, no-actionable-seam, already-improved, and unchanged-after-attempt cases.
report/first-useful-actiondoneAdded the read-only ripr first-action producer, JSON/Markdown renderers, explicit artifact input parsing, fixture-pinned routing tests, and CLI smoke coverage without rerunning hidden analysis.
ci/first-useful-action-summarydoneGenerated GitHub CI now runs ripr first-action when explicit first-action inputs are already present, uploads first-useful-action.{json,md} with the normal report packet, and appends a First Useful Action summary without changing default blocking.
lsp/first-useful-action-statusdoneVS Code status and ripr: Show Status now project an existing target/ripr/reports/first-useful-action.json report without invoking ripr first-action, adding diagnostics, CodeLens, inlay hints, unsaved-buffer analysis, source edits, or generated tests.
docs/first-useful-action-workflowdoneAdded docs/FIRST_USEFUL_ACTION_WORKFLOW.md, documenting GitHub and editor entry points, status meanings, developer/reviewer/agent actions, verification, receipts, fallback interpretation, and the advisory gate boundary.
dogfood/first-useful-action-receiptsdoneExtended cargo xtask dogfood with checked repo-local first-action receipts for actionable, baseline-only, stale, missing-required-artifact, unchanged-after-attempt, and no-actionable-seam cases while recording advisory limits.
campaign/first-useful-action-closeoutdoneClosed Campaign 22 with a prompt-to-artifact audit, PR chain, validation plan, explicit future-lane boundary, and handoff at docs/handoffs/2026-05-09-campaign-22-closeout.md.

Dependencies:

  • Campaign 13 supplies PR guidance and bounded changed-line recommendation placement.
  • Campaign 14 supplies calibration metrics and outcome receipt vocabulary.
  • Campaign 15 supplies optional gate decision artifacts without making gates the first-action authority.
  • Campaigns 17 and 18 supply baseline debt delta and RIPR Zero status inputs.
  • Campaign 19 supplies PR evidence ledger and coverage/grip frontier inputs.
  • Campaigns 20 and 21 supply the assistant proof loop and proof report.
  • Editor Evidence UX supplies the saved-workspace editor context and projection surface.

Commands:

cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-capabilities
cargo xtask check-output-contracts
cargo xtask check-pr

Blocking conditions:

  • analyzer behavior changes
  • recommendation ranking model or provider calls
  • source edits or generated tests
  • runtime mutation execution
  • default CI blocking
  • policy or gate semantic changes
  • hidden analysis reruns or implicit artifact discovery in the report producer
  • new diagnostics, CodeLens, inlay hints, unsaved-buffer overlays, or other speculative editor surfaces
  • treating coverage, static movement, or first-action routing as runtime adequacy
  • new public crates

Follow-up:

  • Campaign 23, Assistant Loop Health, is now closed. It made assistant-directed test work measurable across existing proof artifacts.

Campaign 23: Assistant Loop Health

Campaign ID: assistant-loop-health

Status: complete

Campaign 21 made one assistant-directed test loop reviewable as test-oracle-assistant-proof.{json,md}. Campaign 22 settled the first-screen routing contract so users get one next action instead of another raw report. Assistant Loop Health now measures whether proof packets are complete, stuck, missing receipts, or actually improving static evidence over time.

Objective:

Summarize proof completeness, missing inputs, static evidence movement,
recurring warnings, and next repair queues across one or more assistant proof
reports without changing analyzer behavior, recommendation ranking, gate
semantics, LSP/editor behavior, mutation execution, provider calls, source
files, generated tests, or default CI blocking.

End state:

  • target/ripr/reports/assistant-loop-health.json and .md summarize assistant proof packet health from explicit existing proof inputs
  • the report counts complete, partial, missing-required, and missing-optional proof packets
  • the report summarizes static movement as improved, unchanged, regressed, or unknown using proof data only
  • recurring warnings and missing inputs are grouped without turning into an opaque score
  • a bounded repair queue routes maintainers or coding agents to rerun missing commands, regenerate stale inputs, inspect unchanged evidence, or attach receipts
  • generated CI uploads and summarizes the report as advisory evidence only

Work items:

Work itemStatusNotes
spec/assistant-loop-health-reportdoneAdded RIPR-SPEC-0022 plus OUTPUT_SCHEMA, traceability, capability, campaign, plan, roadmap, and changelog updates for the assistant-loop-health report contract before implementation.
fixtures/assistant-loop-health-corpusdoneAdded fixtures/boundary_gap/expected/assistant-loop-health/ with complete-improved, partial-missing-optional, missing-required-input, unchanged, regressed, warning-heavy, and multi-proof report fixtures plus representative proof inputs.
report/assistant-loop-healthdoneAdded the read-only ripr assistant-loop health producer over explicit proof inputs, with JSON/Markdown rendering and fixture-backed CLI coverage.
ci/assistant-loop-health-artifactsdoneGenerated GitHub CI runs ripr assistant-loop health when test-oracle-assistant-proof.json exists, uploads assistant-loop-health.{json,md} with the normal report packet, and appends an advisory health summary.
docs/assistant-loop-health-workflowdoneAdded docs/ASSISTANT_LOOP_HEALTH_WORKFLOW.md, explaining proof report versus health report, generated-CI summary use, complete/partial/missing states, static movement interpretation, missing-input repair, agent handoff, and advisory limits.
campaign/assistant-loop-health-closeoutdoneClosed Campaign 23 with a prompt-to-artifact audit, PR chain, validation plan, advisory boundary, and future-lane boundary at docs/handoffs/2026-05-09-campaign-23-closeout.md.

References:

Blocking conditions:

  • analyzer behavior or recommendation ranking changes
  • gate policy, LSP/editor, provider, mutation, source-edit, generated-test, or default-blocking changes
  • adequacy, correctness, or runtime mutation claims

Closeout:

  • Campaign 23 is closed. The report contract, fixture corpus, read-only producer, generated-CI advisory projection, workflow docs, and closeout audit are in place. No ready Campaign 23 work item remains in .ripr/goals/active.toml.
  • Campaign 24, PR Review Front Panel, is now closed. It composes existing artifacts into one advisory generated-CI first screen without changing analyzer, ranking, gate, editor, provider, mutation, source-edit, generated-test, or default-blocking behavior.

Campaign 24: PR Review Front Panel

Campaign ID: pr-review-front-panel

Status: complete

Campaigns 13 through 23 built the PR guidance, calibration, optional gate, baseline, ledger, assistant proof, first useful action, and assistant-loop health surfaces. The next reviewer risk is report sprawl: the evidence exists, but the GitHub first screen still should compose it into one test-oracle review story.

Objective:

Compose existing PR guidance, first useful action, assistant proof,
assistant-loop health, PR evidence ledger, baseline delta, gate decision,
receipts, calibration, and optional coverage/grip frontier artifacts into one
advisory PR review front panel that answers what matters, why, what to do next,
how to verify it, what receipt exists, and what policy state applies without
changing analyzer behavior, recommendation ranking, gate semantics, editor
behavior, mutation execution, provider calls, source files, generated tests, or
default CI blocking.

End state:

  • target/ripr/reports/pr-review-front-panel.json and .md summarize the PR's test-oracle story from explicit existing inputs
  • the panel shows the selected top issue or explains why no safe action is available
  • the panel carries missing discriminator, related test, repair or agent handoff command, verify command, receipt path, and static movement when present
  • baseline, new policy-eligible, acknowledged, waived, suppressed, and gated states remain visible without becoming hidden success
  • optional coverage/grip and calibration inputs are surfaced as advisory context without adequacy claims
  • generated CI uploads and summarizes the panel as advisory evidence only when source artifacts exist

Work items:

Work itemStatusNotes
spec/pr-review-front-panel-reportdoneAdded RIPR-SPEC-0023 plus OUTPUT_SCHEMA, traceability, capability, campaign, plan, roadmap, and changelog updates for the PR review front-panel JSON/Markdown contract, explicit inputs, first-screen fields, artifact grouping, advisory limits, and generated-CI projection boundaries.
fixtures/pr-review-front-panel-corpusdonePinned advisory-only, actionable, summary-only, acknowledged, suppressed, baseline-resolved, blocked, missing-proof, and coverage-flat-grip-improved cases plus an xtask guard before adding the producer.
report/pr-review-front-paneldoneAdded ripr pr-review front-panel, a read-only producer that emits advisory JSON/Markdown from explicit existing artifact paths without rerunning analysis or changing gate authority.
ci/pr-review-front-panel-summarydoneGenerated GitHub CI now runs ripr pr-review front-panel only when explicit input artifacts exist, uploads pr-review-front-panel.{json,md} with the report packet, and appends an advisory first-screen summary while preserving gate-decision pass/fail authority.
docs/pr-review-front-panel-workflowdoneAdded the workflow guide for reviewers, maintainers, developers, and coding agents, including first-screen reading, repair routes, receipt inspection, and advisory gate limits.
dogfood/pr-review-front-panel-receiptsdoneAdded dogfood validation and output-schema documentation for checked front-panel receipts covering actionable, acknowledged, suppressed, baseline-resolved, blocked, missing-proof, no-actionable, and coverage-flat-grip-improved cases while preserving advisory defaults.
campaign/pr-review-front-panel-closeoutdoneClosed Campaign 24 with a prompt-to-artifact audit, PR chain, validation plan, advisory boundary, and future-lane boundary at docs/handoffs/2026-05-10-campaign-24-closeout.md.

References:

Blocking conditions:

  • analyzer behavior changes or recommendation ranking changes
  • gate policy, waiver, suppression, or baseline semantic changes
  • LSP/editor, provider, mutation, source-edit, generated-test, inline-comment, or default-blocking changes
  • adequacy, correctness, or runtime mutation claims
  • hidden analysis reruns or source artifact discovery that changes semantics

Closeout:

  • Campaign 24 is closed. The report contract, fixture corpus, read-only producer, generated-CI advisory projection, workflow docs, dogfood receipts, and closeout audit are in place. No ready Campaign 24 work item remains in .ripr/goals/active.toml.
  • The next Lane 4 adoption surface should be opened explicitly rather than folded into PR Review Front Panel closeout work.

Campaign 25: Report Packet Index

Campaign ID: report-packet-index

Status: complete

Campaigns 13 through 24 made PR guidance, gates, baselines, ledgers, assistant proof, first useful action, assistant-loop health, and the PR review front panel visible in generated CI. The next reviewer risk is artifact packet navigation: the uploaded ripr-reports artifact should have one index that shows where to start, what is missing, and which artifact answers each review question.

Objective:

Make the uploaded RIPR report packet navigable as a reviewer-first index over
explicit existing artifacts: the front panel, PR guidance, first useful action,
assistant proof and health, PR evidence ledger, baseline delta, RIPR Zero, gate
decision, receipts, calibration, coverage/grip frontier, SARIF/badge outputs,
and local validation reports. The index must group artifacts by reviewer use,
show missing or stale expected surfaces, name the next command to regenerate a
missing packet, and remain advisory without changing analyzer behavior,
recommendation ranking, gate semantics, editor behavior, mutation execution,
provider calls, source files, generated tests, inline-comment defaults, or
default CI blocking.

End state:

  • target/ripr/reports/index.json and .md are the report-packet front door for PR reviewers
  • the index groups artifacts by start-here, PR review story, repair or agent handoff, evidence, policy or gates, calibration, validation receipts, and SARIF or badge outputs
  • the index identifies missing expected report surfaces and suggests precise commands to regenerate them
  • generated CI uploads and summarizes the index as advisory evidence only when source artifacts exist
  • the index never becomes pass/fail authority and never hides gate, waiver, suppression, baseline, missing-input, or warning states
  • fixtures and dogfood receipts cover complete packet, sparse packet, missing front-panel, blocked gate, missing proof, and coverage/grip-present cases

Work items:

Work itemStatusNotes
spec/report-packet-index-contractdoneDefined the report-packet index contract, explicit inputs, grouping model, missing-surface warnings, generated-CI projection boundary, advisory limits, and fixture-first implementation plan before changing the producer.
fixtures/report-packet-index-corpusdonePinned report-packet index cases for complete packet, sparse advisory packet, missing front panel, blocked gate, missing assistant proof, missing receipts, and coverage/grip-present packet before changing the producer.
report/report-packet-indexdoneAdded the public read-only ripr reports index producer, JSON/Markdown renderer, CLI/help wiring, and CLI smoke coverage for grouped reviewer-first packet indexes over explicit artifact paths without rerunning analysis or changing gate authority.
ci/report-packet-index-summarydoneGenerated GitHub CI runs ripr reports index only when indexed artifacts exist, uploads index.{json,md} with the report packet, and appends a compact advisory packet-index summary while preserving gate-decision pass/fail authority.
docs/report-packet-index-workflowdoneAdded docs/REPORT_PACKET_INDEX_WORKFLOW.md, explaining reviewer, maintainer, developer, and coding-agent use of the grouped packet map, missing-surface regeneration, and advisory gate boundary.
dogfood/report-packet-index-receiptsdoneExtended cargo xtask dogfood with checked report-packet index receipts for complete, sparse, missing-front-panel, blocked-gate, missing-proof, missing-receipts, and coverage/grip-present cases.
campaign/report-packet-index-closeoutdoneClosed Campaign 25 with a prompt-to-artifact audit, PR chain, validation plan, advisory boundary, and future-lane boundary at docs/handoffs/2026-05-10-campaign-25-closeout.md.

References:

Blocking conditions:

  • analyzer behavior changes or recommendation ranking changes
  • gate policy, waiver, suppression, or baseline semantic changes
  • LSP/editor, provider, mutation, source-edit, generated-test, inline-comment, or default-blocking changes
  • adequacy, correctness, or runtime mutation claims
  • hidden analysis reruns or artifact discovery that changes upstream report semantics

Closeout:

  • Campaign 25 is closed. The report contract, fixture corpus, read-only producer, generated-CI advisory projection, workflow docs, dogfood receipts, and closeout audit are in place. No ready Campaign 25 work item remains in .ripr/goals/active.toml.
  • The next Lane 4 adoption surface should be opened explicitly rather than folded into Report Packet Index closeout work.

Campaign 26: PR Inline Comment Publisher

Campaign ID: pr-inline-comment-publisher

Status: closed

Campaigns 13 through 25 made PR guidance, generated-CI summaries, changed-line check annotations, optional gates, baselines, ledgers, assistant proof, first useful action, assistant-loop health, PR review front panel, and report-packet index artifacts visible without posting durable PR comments. The next adoption risk is explicit inline comment publishing for teams that choose review-thread visibility after the summary and annotation surfaces are trusted.

Objective:

Define and implement an explicit opt-in inline PR comment publisher over the
existing `ripr review-comments` artifact without changing default generated CI.
The lane must first produce a read-only publish plan from explicit
`target/ripr/review/comments.json` input, then optionally publish only safe
changed-line comments when a workflow explicitly enables it. The publisher must
never post `summary_only` guidance, must cap comments, deduplicate by
`dedupe_key`, upsert or replace prior RIPR comments, preserve advisory
language, avoid hidden analysis reruns, and avoid analyzer, ranking, gate,
editor, provider, mutation, source-edit, generated-test, branch-protection, or
default-blocking changes.

End state:

  • target/ripr/review/comment-publish-plan.json and .md describe intended inline comment operations before anything posts
  • the plan consumes only explicit review-comments artifacts and optional existing-comment metadata
  • summary-only guidance is never publishable as an inline comment
  • publishable comments target changed lines only and are capped to three by default
  • dedupe keys drive upsert or replace behavior so RIPR comments do not duplicate across reruns
  • generated CI keeps inline comments disabled by default and only posts when explicit configuration and safe permissions exist
  • fixtures and dogfood receipts cover publishable, summary-only, capped, duplicate, stale-existing, fork or no-token, and missing-input cases

Work items:

Work itemStatusNotes
spec/pr-inline-comment-publisher-contractdoneDefined the optional inline comment publisher contract, read-only publish-plan schema, explicit inputs, permission boundary, dedupe/upsert semantics, cap rules, summary-only exclusion, generated-CI default-off posture, and fixture-first implementation plan before changing producer or workflow behavior.
fixtures/pr-inline-comment-publisher-corpusdonePinned inline comment publish-plan cases for publishable changed-line comments, summary-only exclusion, cap overflow, dedupe/upsert, stale existing RIPR comments, fork or no-token no-op, and missing review-comments input before adding publisher behavior.
report/pr-inline-comment-publish-plandoneAdded read-only ripr pr-comments plan JSON/Markdown producer over explicit review-comments and optional existing-comment metadata without posting to GitHub or changing gate authority.
ci/pr-inline-comment-publisherdoneAdded generated GitHub CI wiring with RIPR_COMMENT_MODE=off by default, opt-in existing-comment metadata capture, advisory publish-plan artifacts and summaries, and inline GitHub comment create/update calls only when RIPR_COMMENT_MODE=inline and the safe plan permits publishing.
docs/pr-inline-comment-publisher-workflowdoneDocumented off, plan, and inline rollout modes, publish-plan review, review-thread noise controls, forks, missing permissions, dedupe/upsert behavior, rollback, and the advisory gate boundary.
dogfood/pr-inline-comment-publisher-receiptsdoneExtended cargo xtask dogfood with checked repo-local receipts for publishable, summary-only, capped, dedupe/upsert, stale-existing, fork or no-token, and missing-input publish plans without posting real PR comments.
campaign/pr-inline-comment-publisher-closeoutdoneClosed Campaign 26 after the spec, fixtures, read-only publish plan, explicit generated-CI opt-in wiring, workflow docs, dogfood receipts, and validation showed inline comments are safe, capped, deduped, advisory, and disabled by default.

References:

Blocking conditions:

  • analyzer behavior changes or recommendation ranking changes
  • gate policy, waiver, suppression, or baseline semantic changes
  • LSP/editor, provider, mutation, source-edit, generated-test, branch protection, or default-blocking changes
  • inline comments posted by default
  • summary_only guidance posted as inline comments
  • comments placed on unchanged or unsafe lines
  • duplicate durable comments across reruns
  • free-form LLM review comments
  • pull_request_target or unproven fork-permission behavior

Next:

  • Campaign 26 is closed. Campaign 27 (Language Adapter Preview) is the explicit next product lane. Do not fold PR summary polish, comment-policy extensions, analyzer, ranking, gate policy, editor, platform, release, dependency, or MSRV work into this closeout.

Campaign 27: Language Adapter Preview

Campaign ID: language-adapter-preview

Status: closed

Campaigns 1 through 26 built a credible Rust static oracle-gap analyzer with an editor evidence loop, an advisory PR review front panel, baselines, RIPR Zero status, an assistant proof loop, first useful action, a report packet index, and an opt-in inline comment publisher. Every surface is language-neutral by intent but single-language by accident. The next adoption gap is mixed-language repositories that want the same evidence surface across Rust, TypeScript/JavaScript, and Python without forking RIPR into separate tools, separate schemas, or separate UX.

Objective:

Introduce a language-neutral analysis adapter boundary inside the existing
`crates/ripr` package. Keep Rust as the reference adapter. Add syntax-first
TypeScript and Python preview adapters that feed the same RIPR domain,
output, LSP, agent, and Lane 4 review surfaces. The adapter boundary must
preserve current Rust behavior, fixtures, and goldens; the output schema
must gain only additive optional `language` and `language_status` fields;
preview adapters must be opt-in via `[languages]` repo configuration and
labeled `preview` in every public surface; preview adapters must report
explicit static limits instead of guessing; generated CI stays Rust-default
and advisory; Rust analyzer behavior, recommendation ranking, gate
semantics, LSP/editor behavior for Rust seams, mutation execution, provider
behavior, source files, generated tests, branch protection,
`pull_request_target` defaults, and default CI blocking do not change.

End state:

  • LanguageId, LanguageAdapter, LanguageFacts, OwnerFact, TestFact, AssertionFact, RelatedTest, FlowSink, Probe, and StaticLimit are language-neutral domain or analysis types
  • Rust fact extraction sits behind RustAdapter with no observable fixture, golden, or output schema change
  • existing reports carry additive optional language and language_status fields without forking schemas
  • TypeScript/JavaScript preview adapter emits syntax-first owners, tests, assertions, related tests, probes, and explicit static limits
  • Python preview adapter emits syntax-first owners, tests, assertions, related tests, probes, and explicit static limits
  • repo configuration adds [languages] enabled = ["rust"] as the default, with explicit opt-in to enable preview adapters
  • VS Code extension language selectors cover Rust plus TypeScript, TypeScript React, JavaScript, JavaScript React, and Python once preview adapters are enabled, without changing saved-workspace defaults
  • generated GitHub CI groups advisory summaries by language only when [languages] declares more than Rust, and Rust-default behavior is unchanged
  • fixtures and cargo xtask dogfood receipts cover at least one TypeScript and one Python preview scenario plus the language router and static-limit cases
  • the workspace remains one published package, one binary, one library, one LSP server, and one VS Code extension

Work items:

Work itemStatusNotes
spec/language-adapter-preview-contractdoneLanded the proposal/spec set: RIPR-PROP-0001 records design intent and alternatives; RIPR-SPEC-0026 pins the language-adapter boundary, additive optional output metadata, [languages] opt-in, preview labeling, and static-limit vocabulary; RIPR-SPEC-0027 and RIPR-SPEC-0028 pin the TypeScript and Python per-language static-fact contracts.
analysis/language-adapter-boundarydoneIntroduced LanguageId, LanguageAdapter, and the language router inside crates/ripr/src/analysis/ without changing Rust fixture, golden, or output schema behavior. The RustAdapter reference type is wired into workspace discovery as a functional no-op so the seam is alive.
analysis/rust-adapter-behind-boundarydoneMoved Rust fact extraction behind the LanguageAdapter trait as the reference adapter while preserving every existing Rust fixture, golden, capability, and output contract. Pipeline orchestration loads diffs, dispatches analyze_diff/analyze_repo to the adapter, and applies the language-neutral sort + summary on returned Findings.
output/language-metadatadoneAdded additive optional language field on each Finding (Rust adapter sets "rust", omitted otherwise) and language_status (preview adapters set "preview"; omitted for Rust per spec). LanguageId/LanguageStatus moved to domain::language as pure-data enums so output renderers can serialize without depending on the analysis layer. JSON renderer emits the fields when populated; goldens refreshed accordingly. owner_kind and static_limit_kind remain deferred until preview adapters populate them.
config/languages-opt-indoneAdded [languages] enabled to ripr.toml with default ["rust"], vocabulary validation (rust/typescript/python), duplicate rejection, deny_unknown_fields, and a doctor-command surface. Generated ripr init config, ripr.toml.example, and docs/CONFIGURATION.md updated.
analysis/typescript-preview-adapterdoneAdd the TypeScript/JavaScript syntax-first adapter, the TypeScript fixture corpus, and the preview labeling without changing Rust behavior, default CI, or inline-comment defaults. Scaffold sub-slice landed oxc_parser, the TypeScriptAdapter struct, and language-aware dispatch through [languages] enabled. Owner+test sub-slice (#777) added top-level function-declaration + test()/it() extraction, related-test matching by name reference, a minimal WeaklyExposed/NoStaticPath classifier, and fixtures/typescript_boundary_gap/. Assertion-shape extraction (#781 closes #767) refined the gradient to Exposed/WeaklyExposed/NoStaticPath via toBe/toEqual/toThrow plus async .resolves/.rejects. Probe-shape classification (#784 closes #768) replaced the placeholder Predicate/Control default with syntax-first ProbeFamily/DeltaKind per changed line, with fixtures/typescript_return_value_shape/. Mocked-module static-limit reporting (#791 closes #769) surfaces vi.mock(...)/jest.mock(...) via evidence/missing text without downgrading classification, with fixtures/typescript_mocked_module_limit/. Together these slices establish the first useful TypeScript preview loop end-to-end. Remaining preview polish — structured static_limit_kind field, additional limit kinds, arrow-function const owners, class methods — is intentionally deferred to follow-up issues and is not on the Campaign 27 critical path. Targets 0.6.0.
analysis/typescript-editor-readinessdoneResolved the TypeScript preview gaps that made editor projection unsafe before lsp/editor-language-routing can consume TypeScript evidence: #779 human output visibly labels preview TypeScript evidence, #780 owner matching is file-scoped before line-range matching, #782 broad toThrow() remains weak broad-error evidence, #785 awaited Promise.reject(...) classifies as error-path preview evidence, and #786 fixture/golden evidence covers every TypeScript probe family currently emitted by the preview adapter. Landed without VS Code selector, LSP routing, source edit, generated test, provider, mutation execution, gate, or default-blocking behavior changes.
adr/python-parser-substratedonePin the Python parser-substrate decision before any Cargo dependency or adapter code lands, mirroring how ADR 0008 (oxc_parser) was sequenced ahead of the TypeScript scaffold. Landed via #794 (closes #770) — adds docs/adr/0009-python-parser-substrate.md, registers it in docs/adr/README.md, and adds the approved-decision comment to policy/dependency_allowlist.txt. ADR 0009 was superseded in-place by a follow-up correction PR after discovering the originally-picked ruff_python_parser is publish = false in the astral-sh/ruff workspace and unavailable on crates.io; the corrected pick is rustpython-parser, the documented natural fallback already named under the ADR's Revisit Criteria. No Cargo dependency, no adapter code, no behavior change.
analysis/python-preview-adapterdoneAdd the Python syntax-first adapter, the Python fixture corpus, and the preview labeling without changing Rust behavior, default CI, or inline-comment defaults. Scaffold sub-slice mirrors the TypeScript scaffold (PR #759): adds the rustpython-parser Cargo dependency approved by the corrected ADR 0009, the PythonAdapter type, language-aware pipeline dispatch through [languages] enabled, and a real production parse-validation use of rustpython-parser. To avoid an LGPL-3.0-only transitive (malachite-bigint), the dependency disables default features and selects num-bigint (MIT/Apache-2.0) for Python int-literal representation. Owner/test sub-slice adds syntax-first def / async def / method owner facts, pytest and unittest test discovery, preview owner_kind output, and Python owner/test fixture families. Assertion/oracle sub-slice adds syntax-first pytest, unittest, boolean, broad-error, and mock-call oracle facts plus fixture families. Probe-shape sub-slice adds syntax-first predicate, return-value, error-path, field-assignment, call, and mock-initializer probe families plus fixture coverage. Related-test sub-slice adds direct-call, import-alias, same-stem, and unrelated-mention fixtures with conservative weak proximity behavior. Static-limit sub-slice adds structured dynamic_dispatch, decorator_indirection, mocked_module, missing_import_graph, metaprogramming, and unsupported_syntax facts plus fixture coverage while preserving strong related-test classifications. Final corpus-completion audit records that owner/test/assertion/probe/related-test/static-limit Python preview facts are fixture-backed and editor-projectable.
lsp/editor-language-routingdoneExtended the VS Code extension activation events and document selector to TypeScript, TypeScript React, JavaScript, JavaScript React, and Python while preserving Rust saved-workspace defaults. Routed stale-buffer guards through the same supported-language selector set; preview findings now carry language, status, owner, and static-limit metadata through LSP diagnostic data, hover shows the preview syntax-first/advisory boundary before RIPR evidence, and status text surfaces preview/static-limit counts from refresh logs. LSP analysis remains config-gated by [languages] through the existing adapter layer. Landed without analyzer behavior changes, source edits, generated tests, provider calls, mutation execution, policy/gate/default-blocking behavior, CodeLens, inlay hints, semantic tokens, or unsaved-buffer overlays.
ci/language-aware-groupingdoneGenerated GitHub CI summaries now read enabled languages through the public ripr doctor surface, keep the language grouping section hidden for Rust-only config, and group TypeScript/Python advisory artifact entries, preview-status counts, classifications, and static-limit kinds only when preview adapters are configured. Preview groups remain advisory presentation only; ripr gate evaluate remains configured pass/fail authority.
docs/language-adapter-preview-workflowdonedocs/LANGUAGE_ADAPTER_PREVIEW.md documents enabling preview adapters, reading mixed-language reports, interpreting preview labels, the static-limit boundary, editor projection, generated-CI language grouping, gate authority, and rollback; Quickstart, Configuration, Support Tiers, capability, traceability, and documentation-index surfaces link to it.
dogfood/language-adapter-preview-receiptsdonecargo xtask dogfood now checks TypeScript and Python preview receipts for preview labels, structured static limits, disabled-language behavior, and no cross-language related-test routing. The dogfood report records generated-CI preview grouping as checked while preserving advisory defaults, Rust-default behavior, gate authority, and inline-comment defaults.
campaign/language-adapter-preview-closeoutdoneClosed after the spec, adapter boundary, Rust adapter, output metadata, preview adapters, editor routing, CI grouping, workflow docs, dogfood receipts, closeout handoff, and validation showed preview adapters are syntax-first, opt-in, advisory, and label-correct, while Rust behavior is preserved.

References:

Blocking conditions:

  • Rust analyzer behavior, recommendation ranking, gate semantics, LSP/editor behavior for Rust seams, mutation execution, provider behavior, source files, generated tests, branch protection, pull_request_target defaults, or default CI blocking change
  • output schema versions change instead of gaining additive optional fields
  • preview adapters run by default
  • preview adapters claim parity or adequacy with Rust
  • preview adapters depend on a runtime typechecker, build graph, or other external tool by default
  • workspace splits into a second published crate, binary, LSP server, or editor extension
  • preview adapters introduce a second JSON schema, second SARIF rule set, or second LSP server
  • preview adapters reinterpret the existing exposure vocabulary
  • preview adapters bypass the unsafe_code = "forbid", panic-family, allow-attribute, dependency, process, or network policy rails

Commands:

cargo xtask check-spec-format
cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-traceability
cargo xtask check-capabilities
cargo xtask check-output-contracts
cargo xtask check-architecture
cargo xtask check-workspace-shape
cargo xtask check-public-api
cargo xtask check-file-policy
cargo xtask check-dependencies
cargo xtask check-pr

Next:

  • Campaign 27 is closed and archived. Campaign 28 (First Useful PR Loop) is also closed and archived. Keep TypeScript and Python preview evidence opt-in, visibly preview/advisory, and outside default gate authority until a later promotion policy explicitly changes that boundary.

Campaign 28: First Useful PR Loop

Campaign ID: first-useful-pr-loop

Status: closed

RIPR now has the structural repair loop: first-pr packets, actionable gaps, ranked repair packets, dry-run attempt context, receipts, outcomes, generated CI, editor packets, and agent handoffs. The next adoption gap is not another abstract control plane. The next gap is making one Rust PR feel obvious, useful, and safe for a new user who has not learned RIPR's internal artifact graph.

Objective:

Make a new user, reviewer, or coding agent get from one changed Rust behavior
to one trustworthy repair receipt with almost no interpretation burden.

End state:

  • ripr first-pr --root . --base origin/main --head HEAD is the obvious front door for one changed Rust PR
  • the first screen names one top repairable gap or a clear no-action state without making users open secondary reports
  • the recommendation explains changed behavior, current proof weakness, missing discriminator, repair intent, verify command, receipt command, and static-evidence boundary
  • ripr outcome receipts are reviewer-native and explain before/after movement without claiming mutation, runtime, or coverage proof
  • a tiny fixture or demo story proves the before -> recommendation -> focused repair -> outcome -> receipt loop
  • generated CI, editor, and agent packet surfaces mirror the same one-screen repair story instead of inventing parallel wording
  • support/status claims remain mapped to proof and preserve advisory/static boundaries

Work items:

Work itemStatusNotes
context/proof-stack-reconciliationdoneReconciled proof-stack language into RIPR's existing context system, accepted source-of-truth stack, and roadmap end-goal framing without adding a runner-local goals namespace or another operating namespace.
goals/active-freshness-validationdoneGoal validation now rejects a closed active campaign unless it declares a successor or explicit no-current-goal marker, so agents cannot silently continue from stale execution state.
first-pr/front-door-polishdoneripr first-pr now writes a read-only preflight section for root, Git/base/head/diff, Cargo workspace, config defaults, output path, mode, and next-command guidance while preserving advisory artifact selection.
first-pr/one-screen-recommendationdoneStart-here now has a golden-backed one-screen recommendation with top gap/no-action, changed behavior, current evidence strength, missing discriminator, focused proof intent, verify command, receipt command, receipt path, and static-advisory boundary.
outcome/reviewer-native-receiptsdoneripr outcome now writes reviewer-native JSON/Markdown receipt sections covering before flags, focused proof signals, movement after verification, remaining weak/unknown seams, and reviewer claim boundaries.
fixtures/first-pr-boundary-gap-demodoneAdded a checked boundary-gap demo story for before -> ripr first-pr -> focused external proof -> ripr outcome -> reviewer receipt.
surfaces/one-screen-loop-convergencedoneGenerated CI, VS Code/editor handoff, and agent packet surfaces now mirror changed behavior, missing discriminator, focused proof intent, verify and receipt commands, receipt artifacts, and the static-advisory boundary.
campaign/first-useful-pr-loop-closeoutdoneClosed Campaign 28 with a handoff, archived active goal manifest, proof commands, claim and policy boundary, remaining limits, and no selected successor goal.

References:

Blocking conditions:

  • source edits generated by RIPR
  • generated tests
  • provider/model calls
  • runtime mutation execution
  • runtime, coverage, or correctness proof claims
  • default blocking gates or public badge semantic changes
  • TypeScript/Python preview promotion
  • a parallel runner-local goals namespace or source-of-truth operating model outside the accepted docs/source-of-truth/ stack

Commands:

cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-pr

Next:

  • Campaign 28 is closed and archived. .ripr/goals/active.toml records no_current_goal = true until a successor campaign is selected from the roadmap or a new accepted source-of-truth stack.

Focused Lane 1 Tracker: Evidence Quality Leadership

Status: closed in documented scope. Campaign 28 is also closed and archived; .ripr/goals/active.toml records no_current_goal = true until a successor is selected. This focused Lane 1 tracker is not the active execution manifest.

Sources of truth:

Objective:

Make RIPR self-aware about evidence quality: what it believes, why it believes
it, which fixture or calibration class supports that belief, what remains
unknown, and which evidence-class repair should happen next.

Work items:

Work itemStatusNotes
report/evidence-quality-scorecarddone#850 added the repo-local scorecard over the Lane 1 audit.
fixtures/evidence-quality-benchmark-corpusdone#851 added the manifest-only benchmark corpus with positive cases and must-not-claim guards.
analysis/static-limitation-taxonomydone#861 normalized static limitation categories and repair routes without turning limitations into user test gaps.
analysis/oracle-semantics-audit-fixesdone#871 tightened clear custom helper, opaque helper, and duplicative equality semantics from audit-backed cases.
calibration/runtime-fixtures-v3done#881 added checked imported-runtime calibration classes while keeping runtime-only signal from creating static gaps.
report/evidence-quality-trenddone#885 added scorecard/audit snapshot trend reporting with explicit no-history states.
campaign/evidence-quality-leadership-closeoutdoneClosed after scorecard, benchmark corpus, two audit-driven improvements, runtime-fixtures-v3, trend reporting, class-scoped capabilities, traceability, and handoff proof.

Future Lane 1 work should open only when the scorecard, audit, or a documented consumer requirement identifies a new measured evidence class. Do not reopen Lane 1 for PR/CI front-panel work, LSP/editor polish, gate policy, generated tests, provider calls, mutation execution, or score redefinition.

Focused Lane 1 Tracker: User-Visible Output Evidence

Status: closed as a focused Lane 1 tracker. Campaign 28 is also closed and archived; .ripr/goals/active.toml records no_current_goal = true until a successor is selected. This focused tracker is not the active execution campaign.

Sources of truth:

Objective:

Make changed presentation/help/report/table text one evidence-quality-aware
action, no-action state, or static limitation instead of raw duplicate
line-local notices.

End state:

  • changed presentation text is a distinct evidence class;
  • visibility is user_visible, internal_only, or unknown;
  • observer shape is snapshot, CLI help output, report render, table render, golden output, none, or unknown;
  • declaration and literal raw seams group into one canonical evidence item;
  • raw line-local findings remain supporting evidence and roll up into canonical evidence items with explicit state, actionability, repair, confidence, and proof;
  • actionability distinguishes snapshot/help-output/report test, already observed, internal no-action, and static limitation states;
  • scorecard or trend fields track presentation-text evidence quality;
  • downstream lanes receive a consumer contract but no rendering change lands in this Lane 1 tracker.

Work items:

Work itemStatusNotes
docs/proposal-user-visible-output-evidencedone#904 opened RIPR-PROP-0005 and the Lane 1 tracker.
docs/spec-presentation-text-evidencedone#909 added RIPR-SPEC-0043 for visibility, observer, actionability, canonical grouping, static limitation, and must-not-claim behavior.
docs/spec-finding-to-gap-alignmentdone#927 defined raw finding to canonical evidence item alignment before behavior changes.
fixtures/finding-alignment-benchmarkdone#931 pinned grouping, no-action, already-observed, static limitation, and actionable raw-to-canonical cases.
fixtures/presentation-text-evidence-benchmarkdone#900 added the screenshot-derived benchmark after the proposal/spec foundation.
analysis/finding-alignment-evidence-fieldsdone#935 added additive raw_findings[], canonical_item, and nullable presentation_text fields to evidence_record without changing rendering, gates, scores, generated tests, provider calls, or mutation execution.
analysis/presentation-text-evidence-fieldsdone#935 reserved nullable evidence-record fields for the class.
analysis/presentation-text-canonical-groupingdone#943 groups supported presentation-text constant declaration plus adjacent literal raw findings into one visibility-unknown canonical limitation item in ripr check --json.
analysis/presentation-text-visibilitydone#947 classifies fixture-backed help/report/internal output evidence as actionable, observed, internal-only, or visibility-unknown while keeping unsupported routes as limitations.
analysis/presentation-text-actionabilitydone#951 extended repair routes with concrete repair kind, target test type, and suggested assertion fields beyond the initial visibility states.
report/presentation-text-scorecard-trend-fieldsdone#957 reports presentation-text quality counts and deltas in scorecard and trend output.
docs/presentation-text-consumer-handoffdone#959 documents downstream rendering contract without changing PR/CI or editor surfaces.
campaign/user-visible-output-evidence-closeoutdone#966 records proof, remaining unknowns, final observer-unknown benchmark guard, and the next repair boundary for this focused Lane 1 evidence class.

Blocking conditions:

  • PR/CI rendering changes
  • LSP/editor polish
  • gate-policy changes or default blocking
  • generated tests or source edits
  • provider/model calls
  • mutation execution
  • score redefinition
  • user-visible claims inferred through opaque helpers or unsupported output paths

Commands:

cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-traceability
cargo xtask check-capabilities
cargo xtask check-pr
git diff --check

Closeout:

Focused Lane 1 Tracker: Finding Alignment Burn-Down

Tracker ID: lane1-finding-alignment-burndown

Status: closed. .ripr/goals/active.toml now records status = "closed" and no_current_goal = true; the archived manifest lives at .ripr/goals/archive/2026-05-22-lane1-finding-alignment-burndown.toml.

Sources of truth:

Objective:

Keep RIPR operating on canonical evidence items instead of raw findings as new
alignment gaps are measured, without reopening completed presentation-text or
config/policy base scope.

End state:

  • alignment coverage by evidence class is auditable;
  • canonical items have placement and supporting-span evidence where safe;
  • top named static limitation buckets become fixture-backed repair queues;
  • config/policy unsupported-flow expansion is scoped by spec and fixtures;
  • actionable canonical items preserve repair-route and verify-command coverage;
  • internal scorecards keep actionable canonical gaps as the leading work count;
  • runtime confidence coverage is visible by canonical evidence class;
  • dogfood and downstream handoff docs refresh only when material burn-down deltas land.

Work items:

Work itemStatusNotes
report/finding-alignment-coverage-auditdoneswarm #229 / source #1140 audits aligned, unaligned, duplicate, unnamed-limitation, missing-repair, and missing-verify queues by evidence class.
analysis/named-static-unknown-invariantdoneswarm #233 / source #1141 preserves named static limitations for user-facing static unknowns.
analysis/canonical-primary-anchor-raw-spansdonesource #1158 closed via source PR #1187; primary-anchor and raw-span support are available for canonical items where placement is safe.
analysis/top-static-limitation-bucket-burndowndoneswarm #238 / source #1159 burned down the sampled call_presence / activation_owner_call_unresolved bucket with fixture-backed positive and must-not-claim coverage.
docs/spec-config-policy-unsupported-flow-expansiondoneswarm #241 / source #1142 selected opaque_config_lookup as the next fixture-backed expansion while keeping generated, macro, dynamic-dispatch, and unsupported cross-file flows as named limitations.
fixtures/config-policy-unsupported-flow-burndowndoneswarm #246 / source #1143 pinned macro-generated config/schema output and dynamic config dispatch as named limitation benchmark cases before analyzer work.
analysis/config-policy-unsupported-flow-supportdoneswarm #250 / source #1144 landed in swarm #252; fixture-backed opaque_config_lookup moved out of limitation while unsupported flows stayed named.
analysis/actionable-repair-route-completenessdoneswarm #254 / source #1145 landed in swarm #257; config-policy repair-route coverage now requires the same top-level structured repair_route predicate as the overall actionable summary.
analysis/actionable-verify-command-coveragedoneswarm #258 / source #1146 landed in swarm #261; config/policy verify coverage now rejects missing sentinels and benchmark fixtures require concrete verify commands for actionable records.
report/actionable-canonical-gaps-scorecard-leaddoneswarm #262 / source #1147 landed in swarm #266; scorecard and trend output now lead with actionable canonical gaps while raw finding, canonical-item, repair-route, verify-command, and capability metric rows remain visible.
calibration/runtime-confidence-coverage-auditdonesource #1160 is closed; current audit and scorecard outputs report runtime confidence coverage by canonical evidence class without adding mutation execution.
dogfood/finding-alignment-examples-refreshdoneswarm #267 / source #1149 landed in swarm #276; finding-alignment dogfood receipts now include canonical gap identity, raw finding summary, before/after context, and material burn-down examples for supported opaque config lookups, actionable predicate-boundary scorecard lead, and runtime static-only class trends.
docs/canonical-alignment-contract-refreshdoneswarm #274 / source #1153 landed in swarm #281; the v2 downstream handoff now reflects the refreshed dogfood receipt fields, supported opaque config report lookup delta, actionable predicate-boundary lead, and runtime static-only class trend boundary.
campaign/finding-alignment-burndown-closeoutdoneswarm #280 closed the burn-down rail in the closeout handoff, recording improved classes, moved counts, remaining limitations, downstream consumers, and the next audit-driven evidence class selection rule.

Blocking conditions:

  • PR/CI rendering changes
  • inline PR comment publishing
  • LSP/editor polish
  • gate-policy or default-blocking changes
  • public badge or score redefinition
  • generated tests
  • automatic source edits
  • provider/model calls
  • mutation execution
  • treating named static limitations as user test debt

Commands:

cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-traceability
cargo xtask check-capabilities
cargo xtask check-pr
git diff --check

Focused Lane 1 Tracker: Value Resolution Audit Fixes

Tracker ID: lane1-value-resolution-audit-fixes

Status: closed. .ripr/goals/active.toml now records status = "closed" and no_current_goal = true after this rail's closeout.

GitHub issue: swarm #285

Sources of truth:

Objective:

Burn down a fixture-backed slice of the predicate-boundary
activation_value_unresolved bucket without broadening unsupported value flows
or treating named static limitations as user test debt.

End state:

  • one audit-derived value-resolution sub-shape is fixture-backed before analyzer behavior changes;
  • supported predicate-boundary cases move out of activation_value_unresolved only when concrete activation values are statically visible;
  • unsupported helper-built, cross-file, generated, macro-expanded, shadowed, pattern-bound, non-literal, or opaque value flows remain named limitations;
  • raw findings remain supporting evidence and canonical items remain the countable unit;
  • audit, scorecard, trend, and dogfood proof record the before/after movement without changing PR/CI, editor, gate, badge, release, provider, generated-test, source-edit, or mutation behavior.

Work items:

Work itemStatusNotes
docs/lane1-value-resolution-audit-fixes-stackdoneswarm #285 opens the active issue-backed rail, active manifest, lane tracker, implementation plan, and docs indexes without analyzer behavior.
fixtures/value-resolution-audit-corpusdonePin one audit-derived supported value-resolution sub-shape plus must-not-claim guards before analyzer behavior changes.
analysis/value-resolution-supported-subshapedoneConfirm the fixture-backed supported sub-shape is already handled by existing value-resolution support and keep unsupported value flows named.
report/value-resolution-audit-deltadoneRecorded zero-movement Lane 1 audit, scorecard, and trend evidence for the already-supported selected bucket without changing claims; see the Value Resolution Audit Delta.
dogfood/value-resolution-receiptsdoneAdded checked dogfood receipt with canonical gap identity, raw finding context, zero movement, remaining limitations, and static-evidence non-claims.
campaign/value-resolution-audit-closeoutdoneClosed the rail with proof, remaining limits, downstream non-impact, and no selected successor; see the closeout.

Blocking conditions:

  • PR/CI rendering changes
  • inline PR comment publishing
  • LSP/editor polish
  • gate-policy or default-blocking changes
  • public badge or score redefinition
  • generated tests
  • automatic source edits
  • provider/model calls
  • mutation execution
  • treating named static limitations as user test debt

Commands:

cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-pr
git diff --check

Focused Lane 2 Tracker: Policy Readiness and Preview Evidence Governance

Tracker ID: policy-readiness-preview-evidence-governance

Status: tracker

GitHub issue: #755

Campaign 28 is closed and archived in the machine-readable manifest. This focused Lane 2 tracker is not a replacement for .ripr/goals/active.toml; it records the policy boundary that Campaign 27 and later policy work must not cross.

Objective:

Make RIPR policy decisions auditable across stable Rust evidence and preview
language-adapter evidence. Preserve advisory defaults, keep preview findings
visible but non-gating by default, and define when evidence is eligible for
baseline, waiver, suppression, calibration, RIPR Zero, and gates.

End state:

  • policy readiness defines which mode is safe for a repo right now
  • preview-language evidence is visible and advisory by default
  • preview-language evidence is not gate-eligible, RIPR Zero blocking debt, or mutation-calibrated confidence unless a later explicit policy promotes it
  • waivers remain visible acknowledgements
  • suppressions remain durable policy exceptions with owner, reason, scope, and review state
  • baselines remain adoption checkpoints, not acceptance forever
  • generated CI can surface readiness artifacts only as advisory evidence

Work items:

Work itemStatusNotes
spec/policy-readiness-reportdoneRIPR-SPEC-0029 defines the read-only policy readiness report answering which mode is safe for the repo right now, including statuses, inputs, fields, warnings, preview-boundary health, and no-mutation/no-gate authority.
spec/preview-evidence-policy-boundarydoneRIPR-SPEC-0030 specifies that TypeScript and Python preview evidence is visible/advisory by default, carries preview/static-limit labels, and is not gate, RIPR Zero, default baseline-check, or mutation-calibrated confidence eligible without later explicit promotion.
report/policy-readinessdoneripr policy readiness writes policy-readiness JSON and Markdown over explicit existing artifacts only, with independent readiness axes and preview-evidence zero-count boundaries, without posting, source edits, hidden analysis, baseline mutation, gate execution, or CI failure authority.
report/waiver-agingdoneripr policy waiver-aging writes advisory waiver-aging JSON and Markdown from current PR evidence ledgers plus optional JSONL history, keeping repeated waiver visible as a repair or policy-review signal without pass/fail authority.
policy/suppression-ledger-healthdoneripr policy suppression-health writes advisory suppression-health JSON and Markdown over .ripr/suppressions.toml, requires static_class for exposure_gap entries but not test_efficiency entries, flags missing owner, missing reason, stale review windows, overbroad scope, unknown selectors, and preview-language suppressions without language_status = "preview", and keeps suppressed findings visible with still_visible = true.
policy/baseline-refresh-guardrailsdoneShrink-only ripr baseline update --remove-resolved remains the only refresh path, --adopt-new is rejected, generated CI is pinned to read-only ripr baseline diff, and docs state that CI never rewrites or auto-adopts baseline entries.
policy/exception-ledger-convergencedonedocs/POLICY_ALLOWLISTS.md now aligns no-panic, Clippy, non-Rust, workflow, RIPR suppression, baseline, and waiver ledgers around one reviewed reason per exception, semantic identity where available, and stale-entry behavior by class.
docs/blocking-readiness-guidedonedocs/BLOCKING_READINESS.md now uses policy readiness as the ceiling for advisory, visible-only, acknowledgeable, baseline-check, and calibrated-gate promotion, including calibration, baseline, waiver, suppression, and preview-evidence health.
ci/policy-readiness-advisory-projectiondoneGenerated CI writes, uploads, and summarizes waiver-aging, suppression-health, and policy-readiness artifacts as advisory-only projections: no pass/fail authority, no new required checks, no default blocking, and no comment posting.
campaign/policy-readiness-closeoutdoneClosed the focused Lane 2 tracker after policy readiness, preview boundary, waiver aging, suppression health, baseline refresh guardrails, exception ledger semantics, blocking readiness guidance, and advisory CI projection landed. The closeout audit is recorded in docs/handoffs/2026-05-12-policy-readiness-closeout.md; Campaign 28 is now closed and archived, and .ripr/goals/active.toml records no_current_goal = true.

References:

Blocking conditions:

  • analyzer behavior changes or recommendation ranking changes
  • LSP/editor, PR summary rendering, provider, mutation, source-edit, generated-test, release, or security changes
  • default CI blocking, new required checks, or comment posting
  • automatic baseline adoption
  • preview-language gate promotion without explicit later policy
  • hidden runtime mutation or proof claims
  • treating suppressions as invisible success or waivers as durable exceptions

Commands:

cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-traceability
cargo xtask check-capabilities
cargo xtask check-output-contracts
cargo xtask check-pr

Focused Lane 2 Tracker: Policy Operations and Promotion Readiness

Status: closed as a focused Lane 2 tracker. Campaign 28 is closed and archived in the machine-readable manifest.

Sources of truth:

Objective:

Make RIPR policy adoption operational. The policy layer should tell maintainers
what policy posture is safe now, what blocks stricter modes, what changed over
time, and what explicit promotion packet would be required before
baseline-check, calibrated-gate, or preview-language evidence promotion. All
outputs are read-only and advisory unless an existing explicit gate mode is
configured.

End state:

  • maintainers can see the current safe policy ceiling
  • maintainers can see the next safe policy action
  • baseline, waiver, suppression, calibration, and preview-boundary blockers are named before stricter modes are recommended
  • promotion packets make manual policy changes reviewable without mutating config
  • preview promotion packets keep TypeScript and Python evidence visible but non-gating until explicit promotion evidence exists
  • policy history shows whether readiness improved or regressed over time
  • generated CI may surface advisory artifacts without pass/fail authority

Work items:

Work itemStatusNotes
campaign/policy-operations-trackerdoneOpened docs/policy/POLICY_OPERATIONS.md, .ripr/goals/lane2-policy-operations.toml, roadmap, plan, and campaign references without behavior changes. Current main already uses RIPR-SPEC-0034 through RIPR-SPEC-0037, so policy operations specs must use the next available IDs.
spec/policy-operations-reportdoneRIPR-SPEC-0039 defines a read-only report composing policy-readiness, waiver-aging, suppression-health, baseline-delta, gate-decision, calibration, and preview-boundary inputs.
policy/operations-reportdoneripr policy operations writes JSON and Markdown over explicit existing artifacts only, with current ceiling, next safe action, promotion blockers, grouped actions, warnings, unknowns, and input artifact status.
spec/policy-history-ledgerdoneRIPR-SPEC-0041 defines a read-only policy history report and optional append-only input without gates, telemetry, dashboards, required history files, or automatic appends.
policy/history-reportdoneripr policy history writes read-only JSON and Markdown trend packets over explicit policy operations and optional history JSONL inputs without automatic appends.
spec/policy-promotion-packetsdoneRIPR-SPEC-0042 defines read-only promotion packets for visible-only, acknowledgeable, baseline-check, and calibrated-gate without config, baseline, suppression, workflow, CI, history, or preview-eligibility mutation.
policy/promotion-packet-reportdoneripr policy promote --to ... writes manual-review packets from policy operations and optional policy history without mutating config, baselines, suppressions, workflows, CI defaults, history, or preview eligibility.
spec/preview-evidence-promotion-packetdoneRIPR-SPEC-0044 defines preview-language promotion packets with default allowed_now = false, explicit required/supplied/missing evidence accounting, advisory generated-CI posture, rollback guidance, and no actual promotion.
policy/preview-promotion-packet-reportdoneAdded ripr policy preview-promote --language ... --class ... while preserving advisory preview defaults.
docs/policy-operator-workflowdonedocs/POLICY_OPERATIONS_WORKFLOW.md documents readiness, operations, history, promotion packets, preview packets, manual config review, post-change monitoring, and hard boundaries for maintainers.
ci/policy-operations-advisory-projectiondoneGenerated CI renders, uploads, indexes, and summarizes policy operations, history, promotion, and configured preview-promotion artifacts as advisory-only packets without pass/fail authority, required checks, comment posting, baseline mutation, config mutation, or default blocking.
campaign/policy-operations-closeoutdoneClosed after operations, history, promotion packets, preview promotion packets, workflow, advisory CI projection, capability, metrics, traceability, and handoff surfaces landed; see docs/handoffs/2026-05-13-policy-operations-closeout.md.

Blocking conditions:

  • analyzer truth changes or evidence identity rewrites
  • recommendation ranking changes
  • LSP/editor behavior changes
  • PR/CI front-panel redesign
  • generated tests, provider calls, or mutation execution
  • default CI blocking, required checks, or comment posting
  • automatic config mutation, baseline adoption, or suppression creation
  • preview-language gate promotion without explicit later policy
  • runtime-proof claims from static evidence

Commands:

cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-pr
git diff --check

Closeout:

  • Policy Operations closeout records the PR chain, prompt-to-artifact audit, validation plan, and the boundary that future policy promotion or preview promotion work should open explicitly.

Focused Repo Operations Lane: Generated Evidence Discipline

Status: closed as a repo-operations lane. This lane does not replace the machine-readable active campaign.

Objective:

Make generated evidence, authored source-of-truth, deterministic repair,
judgment-required decisions, and review receipts mechanically distinct so
agents can prepare reviewable PRs without hand-editing generated trust markers
or relying on chat memory for process rules.

End state:

  • ordinary PRs cannot carry generated badge endpoint diffs or target residue without an explicit generated-artifact refresh context
  • public badge endpoint numbers are generated by cargo xtask badges or the Badge Endpoints workflow, not hand-authored
  • check-pr stays non-mutating for committed badge endpoint files
  • workers can run a worktree doctor before opening or updating PRs
  • operators can produce board-level PR triage and single-PR merge-readiness reports without ad hoc polling
  • spec numbering and campaign/source-of-truth drift have mechanical checks
  • receipts, critic reports, and deterministic suggested-fixes patches stay generated under target/ripr/
  • contributor docs explain which surfaces are authored truth, generated evidence, deterministic repair, and judgment-required decisions
  • cargo xtask pr-ready gives agents one local PR readiness packet before opening or updating a PR
  • cargo xtask cockpit gives maintainers one repo-level advisory action queue for board state, generated-evidence hygiene, source-of-truth checks, and next commands
  • report packets have Markdown for humans and JSON for agents instead of requiring prose scraping

Work items:

Work itemStatusNotes
badge/generated-endpoint-workflowdone#874 added the Badge Endpoints workflow plus badge endpoint docs and commands.
devex/generated-clean-checkdone#930 added cargo xtask check-generated-clean and PR gate wiring for generated residue.
badge/endpoint-ownership-policydone#938 added cargo xtask check-badge-diff-policy, allowed README badge layout edits, and rejected ordinary endpoint JSON diffs.
devex/check-pr-non-mutating-badgesdone#938 routes PR validation through non-mutating badge checks instead of refreshing committed endpoint JSON.
devex/worktree-doctordone#941 added cargo xtask worktree doctor for dirty main, behind branches, generated residue, untracked sample targets, and broad diff warnings.
docs/spec-numbering-helperdone#946 added cargo xtask specs next and cargo xtask check-spec-numbering.
devex/pr-triage-reportdone#950 added cargo xtask pr-triage-report for duplicate families, stale drafts, behind branches, validation gaps, and sensitive surfaces. Follow-up JSON output makes the same advisory queue packet agent-readable under target/ripr/reports/pr-triage.json.
devex/gh-pr-statusdone#952 added cargo xtask gh-pr-status --pr <number> with safe next action guidance. Follow-up JSON output makes the same merge-readiness packet agent-readable under target/ripr/reports/gh-pr-status.json.
policy/lane2-reopening-triggersdone#958 documented when future policy authority changes must reopen explicit Lane 2 work.
devex/campaign-source-of-truth-hardeningdone#965 hardened focused-tracker, done-item command, spec, closeout, and active-manifest checks.
automation/gate-receiptsdone#55 already supplied target-local receipt commands; this lane treats them as generated evidence.
automation/critic-reportdone#84 already supplied the advisory critic report; this lane keeps it target-local and reviewer-focused.
automation/suggested-fixes-patchdone#971 added deterministic suggested-fixes.{patch,md} output under target/ripr/reports/.
docs/generated-evidence-disciplinedone#975 added docs/GENERATED_EVIDENCE.md and linked contributor/automation docs.
devex/command-mutability-catalogdoneAdds cargo xtask commands to classify xtask commands by mutability, generated-output paths, external-state access, and judgment-required boundaries.
campaign/generated-evidence-discipline-closeoutdoneClosed after the generated-clean, badge diff policy, worktree, triage, PR status, spec numbering, campaign hardening, receipt, critic, suggested-fixes, and docs surfaces aligned; see docs/handoffs/2026-05-14-generated-evidence-discipline-closeout.md.
devex/pr-triage-jsondoneCommit 9cf2c039 added target/ripr/reports/pr-triage.json so the board-level advisory packet is agent-readable.
devex/gh-pr-status-jsondone#1011 added target/ripr/reports/gh-pr-status.json for single-PR merge readiness.
reports/repo-ops-packet-indexdone#1015 added repo-ops packet status to cargo xtask reports index, including command mutability, cockpit, PR-ready, worktree doctor, PR triage, merge readiness, generated-clean, badge policy, critic, receipts, suggested fixes, and check-pr artifacts.
devex/check-command-catalogdone#1018 added cargo xtask check-command-catalog so new xtask commands cannot bypass mutability classification.
devex/pr-ready-cockpitdone#1025 added cargo xtask pr-ready, writing target/ripr/reports/pr-ready.{md,json} as the local PR front door.
devex/repo-cockpitdone#1035 added cargo xtask cockpit, writing target/ripr/reports/cockpit.{md,json} as the repo-level maintainer front door.
docs/merge-watch-policydone#1036 added docs/MERGE_WATCH_POLICY.md for polling cadence, branch-refresh decisions, REST fallback, Droid/advisory checks, and local merge limits.
automation/suggested-fixes-expansiondone#1039, #1041, #1044, and #1053 expanded deterministic suggested fixes for docs index ordering, traceability ordering, capability ordering, and command catalog ordering while preserving judgment-required boundaries.
devex/pr-triage-queue-dispositiondone#1047 added advisory queue dispositions for merge candidates, stale/duplicate work, rebase needs, fresh-validation gaps, owner decisions, and wrong-lane work.
campaign/repo-ops-ux-cockpit-closeoutdoneClosed after the front-door packet flow landed; see docs/handoffs/2026-05-16-repo-ops-ux-cockpit-closeout.md.

Blocking conditions:

  • analyzer semantics, evidence identity, or recommendation ranking changes
  • LSP/editor behavior changes
  • generated tests, provider calls, or mutation execution
  • branch protection, default CI blocking, baseline adoption, suppression creation, or preview-language promotion
  • manual badge endpoint number edits
  • deterministic repair for judgment-required decisions

Commands:

cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-generated-clean
cargo xtask pr-ready
cargo xtask cockpit
cargo xtask check-pr
git diff --check

Closeout:

Future Campaign: Editor Evidence UX

Campaign ID: editor-evidence-ux

Status: complete as an explicit parallel Lane 3 closeout. Campaign 17, RIPR Zero Adoption, is complete; Editor Evidence UX closed without replacing that machine-readable campaign.

The saved-workspace LSP path already has alpha diagnostics, evidence hover, seam actions, related-test opening, context collection, agent-loop commands, verify commands, receipt commands, and refresh/status surfaces. The next editor product risk is not existence; it is making the evidence loop feel like the right way to work in the editor.

Objective:

Make RIPR's saved-workspace LSP path project one evidence spine from
diagnostic to hover, related test, focused context packet, one test, verify,
and receipt without automatic edits, generated tests, runtime mutation
execution, or runtime adequacy claims.

End state:

  • diagnostics carry stable seam identity and are not reinterpreted from message text
  • hover is the primary human explanation surface for the seam class, evidence path, missing observation, related test, suggested assertion shape, verify command, receipt command, and static limits
  • code actions appear only when the supporting evidence or command context exists
  • a canonical evidence context packet command gives external agents one bounded work packet without coupling RIPR to an LLM provider
  • protocol-level and VS Code smoke tests prove the editor loop from server startup through diagnostics, hover, actions, copy payloads, related-test opening, and restart/status paths
  • status and staleness make stale, failed, disabled, or unavailable evidence visible rather than presenting it as fresh
  • user-facing docs describe the saved-workspace editor workflow and its limits

Work items:

Work itemStatusNotes
campaign/editor-evidence-ux-auditdoneAdded docs/EDITOR_EVIDENCE_UX.md and the audit handoff, mapping diagnostic data, hover, actions, context collection, VS Code proof, LSP cockpit status, status/staleness, and non-goals into one editor evidence contract without behavior changes.
lsp/evidence-hover-hardeningdoneHardened hover as the primary explanation surface for seam class, evidence path, missing discriminator, related test location, suggested assertion/test shape, packet and brief handoff commands, verify command, receipt command, and static limits.
lsp/evidence-aware-actionsdoneTightened action visibility so targeted-test briefs require related-test or suggested-assertion context, suggested assertions and related-test opening remain evidence-gated, stale seam diagnostics fail closed, and agent-loop commands stay available for stable seam diagnostics.
lsp/context-packet-commanddoneAdded ripr.collectEvidenceContext, a schema 0.1 LSP execute-command packet with seam identity, evidence path, missing discriminator, related test, suggested test, shared agent-loop commands, and static limits without source edits, generated tests, provider coupling, broad analysis reruns, or runtime mutation execution.
test/lsp-protocol-smokedoneExtended framed LSP proof through initialize, saved-workspace refresh, a real boundary-gap seam diagnostic, hover, codeAction, ripr.collectEvidenceContext, and shutdown without relying on the VS Code client.
test/vscode-extension-smokedoneExtended the live VS Code e2e smoke so the real boundary-gap server path reaches a seam diagnostic, hover, code actions, copied seam packet and verify payloads, related-test opening, and restart callability without adding editor features. Bad-server-path status remains in the status/staleness slice.
lsp/editor-status-and-stalenessdoneMade disabled config, missing workspace, unavailable server, queued, running, complete, no-actionable-seam, stale, and failed states explicit in the VS Code status bar and Show Status path. Dirty Rust buffers keep stale status visible until save or close so saved-workspace completion does not look fresh for unsaved evidence.
docs/editor-evidence-workflowdoneAdded docs/EDITOR_EVIDENCE_WORKFLOW.md, a user-facing saved-workspace editor path from install and status through diagnostic, hover, related test, context packet, one focused test, after snapshot, verify, receipt, and refresh with explicit static-evidence limits.
campaign/editor-evidence-ux-closeoutdoneClosed after hover, actions, context packet, protocol proof, VS Code proof, status/staleness, and docs aligned without analyzer, policy, CI, or runtime-claim drift; see the closeout handoff.

Dependencies:

  • Campaign 10 supplies the editor-agent loop and command surfaces.
  • Campaign 11 supplies shared agent-loop command templates, workflow packets, receipts, and reviewer summaries.
  • Campaign 12 supplies first-hour editor status and intent-titled action framing.
  • Campaign 13 supplies PR guidance without making RIPR a free-form reviewer.
  • Campaign 17 is complete; this lane closed as an explicit parallel Lane 3 decision.
  • docs/EDITOR_EVIDENCE_UX.md and the audit handoff define the contract that future behavior PRs should follow.

Closeout:

  • Editor Evidence UX closeout records the prompt-to-artifact audit, PR chain, validation commands, and the boundary that future editor work should be opened explicitly.

Commands:

cargo test -p ripr lsp --lib
cargo test -p ripr lsp::tests --lib
cargo xtask lsp-cockpit-report
npm --prefix editors/vscode run compile
npm --prefix editors/vscode run test:e2e
cargo xtask check-output-contracts
cargo xtask check-static-language
cargo xtask check-traceability
cargo xtask check-capabilities
cargo xtask check-pr
git diff --check

Blocking conditions:

  • analyzer behavior changes
  • policy or gate behavior changes
  • generated workflow behavior changes
  • automatic source edits
  • generated tests
  • runtime mutation execution
  • runtime adequacy claims
  • unsaved-buffer overlays in this campaign
  • CodeLens, inlay hints, semantic tokens, or other speculative editor surfaces
  • new public crates

Lane 3 Campaign: Editor First-Run and Repair Usability

Campaign ID: editor-first-run-usability

Status: complete as an explicit Lane 3 closeout.

Editor Gap Cockpit made the saved-workspace evidence loop projectable. Editor First-Run and Repair Usability made that loop self-orienting for a user who does not already know RIPR's artifact graph.

Objective:

Make the VS Code path explain setup, no-output states, one evidence-backed gap,
one bounded repair action, verification, receipt state, and refresh without
adding analyzer, policy, source-edit, generated-test, provider, mutation, PR,
or gate authority to Lane 3.

End state:

  • ripr: Diagnose Setup and ripr: Show Status name the active workspace, resolved server state, config, enabled languages, artifact presence, freshness, receipt state, and next safe action.
  • No-output states distinguish missing workspace, server unavailable, missing config, disabled language, unavailable adapter, missing artifacts, stale artifacts, no actionable gap, and preview-limited evidence.
  • First-repair actions appear only when typed gap identity, repair route, related-test, verify command, and receipt command evidence is safe.
  • Receipt projection consumes existing receipt artifacts only and fails closed for stale, wrong-root, malformed, unsupported-schema, or gap-mismatched receipts.
  • Preview-language evidence remains opt-in, advisory, syntax-first, and static-limit labeled before action language.

Work items:

Work itemStatusNotes
docs/lane3-editor-first-run-usability-stackdoneAdded RIPR-PROP-0008, RIPR-SPEC-0049, RIPR-SPEC-0050, ADR-0013, the implementation plan, lane tracker state, indexes, and traceability.
vscode/setup-diagnosis-status-modeldoneAdded the setup status model for server path/version, workspace root, config path, enabled and build-available languages, artifacts, freshness, receipt state, and next safe action.
vscode/diagnose-setup-commanddoneAdded ripr: Diagnose Setup as a read-only report in the output channel.
test/vscode-first-run-no-output-statesdoneSmoke-tested no workspace, server unavailable, server available, missing config, Rust default, preview disabled, adapter unavailable, stale evidence, no actionable gap, and actionable gap states.
lsp/receipt-status-in-show-statusdoneProjected existing receipt state in Show Status without producing receipts or claiming runtime adequacy.
lsp/first-repair-action-packetdoneAdded a bounded first-repair packet action gated by typed gap identity, repair route, verify command, receipt command, and path safety.
fixtures/editor-first-run-usabilitydoneAdded setup, server missing, config missing, language disabled, adapter unavailable, artifact missing, artifact stale, receipt found, receipt mismatch, receipt improved, and receipt unchanged fixtures.
docs/editor-first-run-to-first-receiptdoneDocumented the install/open, Diagnose Setup, diagnostic, hover, related-test or packet, verify, receipt, and refresh loop.
dogfood/lane3-first-run-repair-receiptsdoneRecorded first-run repair dogfood receipts and limitations without adding editor behavior.
campaign/lane3-editor-first-run-usability-closeoutdoneClosed the campaign in #1040 with validation evidence and explicit non-goals.

Closeout:

Commands:

cargo xtask lsp-cockpit-report
cargo xtask check-fixture-contracts
cargo test -p ripr lsp --lib
cargo test -p ripr lsp::tests --lib
npm --prefix editors/vscode run compile
npm --prefix editors/vscode run test:e2e
cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-doc-roles
cargo xtask check-traceability
cargo xtask check-pr
git diff --check

Blocking conditions:

  • analyzer truth changes
  • policy or gate behavior changes
  • PR or CI rendering changes
  • source edits or generated tests
  • provider/model calls
  • runtime mutation execution
  • runtime adequacy, Rust-parity, or gate-eligibility claims for preview evidence
  • unsaved-buffer overlays, CodeLens, inlay hints, semantic tokens, or inline patch application in this campaign

Cross-Surface Campaign: Start-Here Surface Convergence

Campaign ID: start-here-surface-convergence

Status: complete.

The editor, CLI, generated CI, PR evidence, report packet index, receipts, preview-language reports, and install/release docs are useful independently. This campaign makes those surfaces lead with the same safe next-action unit so users do not need to understand RIPR's internal artifact graph before acting.

Objective:

Make every start-here surface answer: what is the one repairable gap, why does
it matter, where should the focused test go, what verifies movement, what
receipt proves it, and what remains limited or advisory?

End state:

  • PR/CI summaries and report packets lead with a canonical gap or no-action state instead of raw finding counts.
  • CLI front-door commands use the same safe-next-action and recovery-state vocabulary.
  • Receipt lifecycle state is consistent across CLI, PR/CI, editor projection, first-pr packets, and docs.
  • No-output and fail-closed states are explicit outside the editor.
  • Preview-language promotion criteria are visible and policy-owned.
  • External-style dogfood proves the converged path on normal repo shapes and failure states.

Work items:

Work itemStatusNotes
docs/start-here-surface-convergence-stackdone#201 accepted the proposal/spec/ADR stack, replaced source issue numbers with swarm issue rails, and activated the campaign manifest.
report/pr-ci-start-here-canonical-unitdone#202 made PR evidence ledger, PR review front-panel Markdown, and the CI-appended PR evidence summary lead with Start here canonical repair fields before raw counts.
cli/start-here-command-languagedone#203 aligned CLI/front-door wording on Start Here, generated workflow summary copy, doctor setup guidance, safe next action, fail-closed state names, verify command, receipt command, receipt path, recovery states, and advisory boundaries without changing packet schema.
receipt/lifecycle-state-convergencedone#204 standardizes receipt found/missing/stale/mismatch/improved/unchanged/not-applicable states across agent receipt, first-pr, PR evidence, front-panel, actionable-gap outcome, and editor projection fixtures.
output/no-output-fail-closed-statesdone#205 standardizes clean, no-action, missing, stale, wrong-root, disabled, unavailable, malformed, partial, and unsafe output states outside the editor.
policy/preview-promotion-proof-criteriadone#206 defines proof criteria before preview evidence can claim a stronger tier and keeps TypeScript, JavaScript, and Python preview evidence advisory until a policy-owned packet closes the criteria.
dogfood/external-style-start-here-receiptsdone#207 records normal-repo and failure-state receipts for the converged path in Start-here convergence receipts.
campaign/start-here-surface-convergence-closeoutdone#208 closes the campaign in Start-here surface convergence closeout, archives the active goal, and records no_current_goal = true.

Commands:

cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-doc-roles
cargo xtask check-traceability
cargo xtask check-output-contracts
cargo xtask check-pr
git diff --check

Blocking conditions:

  • analyzer behavior changes in the docs/issue setup PR
  • output schema changes without a scoped behavior PR
  • generated CI blocking or default gate behavior changes
  • preview-language policy promotion without a promotion packet
  • PR comment publishing changes
  • source edits, generated tests, provider/model calls, mutation execution, or editor UI-sprawl work

Lane 3 Campaign: Editor Adoption Assurance

Campaign ID: editor-adoption-assurance

Status: closed.

The editor cockpit, first-run repair loop, first-pr bridge, and preview routing are closed. This campaign makes the first-use editor path safer for outside users by hardening compatibility, active-root, multi-root, receipt mismatch, and first-pr packet mismatch diagnosis without making Lane 3 a producer.

Objective:

Make the editor explain what is active, what is incompatible or unsafe, and
what is safe to do next before a user or agent receives a repair packet.

End state:

  • current Rust/default editor cockpit behavior remains pinned;
  • extension/server compatibility diagnosis names version, path, schema, and safe next action;
  • active workspace root and multi-root ambiguity are explicit;
  • wrong-root, stale, malformed, unsupported, receipt-mismatched, and first-pr mismatched states fail closed;
  • fixtures and VS Code smoke prove success and fail-closed states;
  • install-to-first-pr docs and external-style dogfood receipts prove the path;
  • Lane 3 remains read-only and projection-only.

Work items:

Work itemStatusNotes
docs/lane3-editor-adoption-assurance-stackdoneAdded proposal, spec, ADR, plan, indexes, traceability, and GitHub issues.
test/lsp-editor-adoption-baselinedonePinned the closed Lane 3 contract before compatibility/root behavior changes.
vscode/extension-server-compatibility-diagnosisdone#1262 landed the #1247 implementation; close the still-open issue from that merged work.
vscode/workspace-root-multi-root-diagnosisdone#1267, #1270, #1272, and #1274 landed the #1248 implementation; close the still-open issue from those merged changes.
fixtures/editor-adoption-assurancedoneAdded setup, mismatch, first-pr, receipt, and preview-unavailable fixtures.
test/vscode-editor-adoption-assurancedoneSmoked the packaged extension path for adoption assurance.
docs/editor-install-to-first-prdoneDocumented install/open through first-pr packet inspection and recovery states.
dogfood/lane3-editor-adoption-receiptsdoneRecorded external-style setup, root, receipt, first-pr, preview-unavailable, and fail-closed adoption receipts.
campaign/lane3-editor-adoption-assurance-closeoutdoneRecorded closeout proof, accepted the proposal/spec, and closed the issue burn-down.

Issue reconciliation on 2026-05-18 found #1247 and #1248 satisfied on main. #1249, #1250, #1251, and #1252 are satisfied by the fixture corpus, VS Code smoke, install-to-first-pr guide, and dogfood receipts. #1253 is satisfied by the closeout. Do not restart the compatibility or root-diagnosis slices unless a new regression appears.

Commands:

cargo xtask check-spec-format
cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-doc-roles
cargo xtask check-traceability
cargo xtask check-pr
git diff --check

Blocking conditions:

  • analyzer truth changes
  • policy or gate behavior changes
  • PR or CI producer behavior
  • release publishing, binary download, binary install, or config mutation
  • source edits or generated tests
  • provider/model calls
  • runtime mutation execution
  • runtime adequacy, Rust-parity, policy-eligibility, or gate claims
  • unsaved-buffer overlays, CodeLens, inlay hints, semantic tokens, or inline patch application in this campaign

Lane 3 Campaign: Editor Actionable Gap Queue

Campaign ID: editor-actionable-gap-queue

Status: closed.

Editor Adoption Assurance is closed. The next selected Lane 3 slice projects the existing Lane 1 actionable-gaps artifact into the editor as a bounded local repair queue. Lane 3 validates and projects the artifact; it does not produce the artifact, re-rank gaps, decide policy, or create PR/CI output.

Objective:

Make the editor answer what is safe to work on now from existing typed
actionable-gap artifacts.

End state:

  • post-adoption editor behavior remains pinned;
  • target/ripr/reports/actionable-gaps.json is validated before use;
  • Show Status names the top actionable gap or no-action state;
  • Copy Current Repair Packet is available only for validated actionable gaps;
  • Copy Repo Gap Map is read-only orientation;
  • stale, wrong-root, malformed, unsupported, unsafe, disabled, unavailable, receipt-mismatched, first-pr-mismatched, and actionable-packet-mismatched states fail closed;
  • fixtures, VS Code smoke, docs, dogfood receipts, and closeout proof the path;
  • Lane 3 remains read-only and projection-only.

Work items:

Work itemStatusNotes
docs/lane3-editor-actionable-gap-queue-stackclosedSource-of-truth proposal, spec, ADR, plan, indexes, traceability, capability wiring, lane tracker, and issue burn-down landed.
test/lsp-post-adoption-editor-contractclosedDiagnose Setup, Show Status, first-pr, receipt, Rust diagnostics, preview labels, and fail-closed behavior were pinned before queue projection.
lsp/actionable-gap-packet-validationclosedtarget/ripr/reports/actionable-gaps.json validates as a safe input seam.
lsp/show-status-repair-queueclosedShow Status projects bounded queue summaries and fail-closed/no-action states.
lsp/copy-current-repair-packetclosedCopy one bounded repair packet only when typed safety fields validate.
lsp/copy-repo-gap-mapclosedCopy read-only queue orientation without gate, runtime, mutation, policy, or merge-readiness claims.
fixtures/editor-actionable-gap-queueclosedFixture corpus covers top-gap, multiple-gap, no-action, static-limit-only, stale, wrong-root, malformed, improved, and unchanged states.
test/vscode-actionable-gap-queueclosedPackaged extension smoke covers status, packets, repo map, receipt state, and unsafe-state suppression.
docs/editor-actionable-gap-queueclosedDocument the queue workflow and recovery states.
dogfood/lane3-actionable-gap-queue-receiptsclosedEditor Actionable Gap Queue dogfood receipts record actionable, no-action, static-limit-only, wrong-root, stale, receipt, and preview-advisory proof.
campaign/lane3-actionable-gap-queue-closeoutclosedEditor Actionable Gap Queue closeout records the PR chain, validation, remaining limits, and future-work boundary.

Commands:

cargo xtask check-spec-format
cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-doc-roles
cargo xtask check-traceability
cargo xtask check-capabilities
cargo xtask check-pr
git diff --check

Blocking conditions:

  • analyzer truth changes
  • actionable-gaps producer or schema changes
  • policy or gate behavior changes
  • PR or CI producer behavior
  • release publishing, binary download, binary install, or config mutation
  • source edits or generated tests
  • provider/model calls
  • runtime mutation execution
  • runtime adequacy, Rust-parity, policy-eligibility, gate, or merge-readiness claims
  • unsaved-buffer overlays, CodeLens, inlay hints, semantic tokens, or inline patch application in this campaign

Cross-Surface Campaign: Actionable Surface Translation

Campaign ID: actionable-surface-translation

Status: complete.

The repo now has actionable canonical gap packets, editor queue projection, swarm dry-run attempts, outcome joins, and start-here surfaces. The next cross-surface slice is translation: make every first-screen surface answer the same repair-first question without changing analyzer truth or claim authority.

Objective:

Make badge, PR, editor, swarm dry-run, and outcome/trend surfaces translate
existing actionable canonical gap evidence into the same repair-first user
questions.

End state:

  • badge-adjacent copy explains unresolved actionable static repair gaps at point of use;
  • PR evidence leads with actionable delta and one top next repair packet before raw finding totals;
  • editor Show Status leads with one safe repair action or one precise fail-closed reason;
  • swarm dry-run output includes a compact copy-ready operator or external-agent packet;
  • outcome and trend reports lead with receipt-linked movement since the previous refresh;
  • advisory/static boundaries remain visible and no covered surface claims runtime adequacy, coverage adequacy, mutation proof, policy eligibility, gate pass/fail, merge readiness, source-edit automation, generated tests, or provider execution.

Work items:

Work itemStatusNotes
docs/actionable-surface-translation-stackdoneAdded RIPR-PROP-0016, linked RIPR-SPEC-0059 to RIPR-PLAN-0059, registered the artifacts, updated indexes, and selected this active manifest without behavior changes.
badge/actionable-basis-presentationdoneBadge-adjacent copy and badge-basis output explain the headline count as unresolved actionable static repair gaps using canonical_actionable_gap as the public basis.
pr/actionable-delta-front-paneldonePR summary now starts with an advisory actionable repair front panel over existing actionable-gaps, outcome, and PR front-panel artifacts before raw path inventory.
editor/repair-first-status-hierarchydoneEditor Show Status now starts with a repair cockpit block naming workspace/current-file actionable state, top repair, related proof, verify command, receipt state, and fail-closed next action.
swarm/dry-run-copy-ready-packetdoneripr-swarm attempt --dry-run now starts with a compact copy-ready operator packet naming task, allowed files, boundaries, repair target, verify/receipt commands, stop conditions, and return format.
outcome/movement-front-sectiondoneActionable-gap outcomes now lead with receipt-linked movement since prior refresh: current actionable count, receipt-linked delta, resolved, improved, unchanged after attempt, missing/orphaned receipts, and top blocked reason.
campaign/actionable-surface-translation-closeoutdoneActionable Surface Translation closeout records the PR chain, validation, claim boundary, remaining limits, and no selected successor.

Commands:

cargo xtask check-doc-artifacts
cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-doc-roles
cargo xtask check-traceability
cargo xtask check-capabilities
cargo xtask check-support-tiers
cargo xtask check-pr
git diff --check

Blocking conditions:

  • analyzer truth changes
  • actionable-gap producer or schema changes
  • support-tier promotion in the activation PR
  • public badge semantic change in the activation PR
  • default CI blocking or gate behavior changes
  • PR comment publishing changes
  • source edits or generated tests
  • provider/model calls
  • mutation execution
  • release, publish, signing, or marketplace work
  • runtime adequacy, coverage adequacy, proof-of-correctness, policy eligibility, gate pass/fail, or merge-readiness claims

Closeout:

Cross-Surface Campaign: First Useful PR Loop Continuation

Campaign ID: first-useful-pr-loop-continuation

Status: closed.

Closeout:

  • First Useful PR Loop Continuation closeout records the proof that the CLI first screen, generated CI, VS Code, agent packets, receipts, output contracts, and support-tier boundaries now tell one consistent static-advisory repair story.

Actionable Surface Translation made the covered first screens speak the same repair-first language. Campaign 28 is already closed and archived, so this successor campaign continues the same product loop without reactivating the closed manifest id. It uses the new alignment to make one real Rust PR easy to run from changed behavior to focused proof and receipt.

Objective:

Make a new user, reviewer, or coding-agent operator get from one changed Rust
behavior to one trustworthy repair receipt with minimal interpretation burden.

End state:

  • ripr first-pr --root . --base origin/main --head HEAD is the obvious front door for one PR and explains the top repairable gap or clear no-action state.
  • The first screen names changed behavior, weak proof, missing discriminator, focused test intent, verify command, receipt command or path, and the advisory/static boundary.
  • ripr outcome receipts are reviewer-native and explain before/after static movement without implying mutation, coverage, correctness, gate, or merge proof.
  • A tiny first-PR demo proves the before -> recommendation -> focused proof -> outcome receipt path.
  • Generated CI, VS Code, and agent packets mirror the same top-gap, verify, receipt, and non-claim language instead of introducing a second mental model.
  • Support-tier, traceability, and output-contract surfaces record exactly what users may believe.

Work items:

Work itemStatusNotes
goals/first-useful-pr-loop-activationdoneSelected the First Useful PR Loop continuation as the active repo-owned goal without changing analyzer behavior.
docs/context-system-proof-stack-reconciliationdoneMapped proof-stack terminology into the repo tracking model and Codex Goals entrypoint without adding a runner-local goals namespace or a parallel docs/source-of-truth namespace.
goals/active-goal-freshness-checkdonePinned goal validation for stale closed campaigns, missing work-item proof commands, unknown proof commands, and failed goals next reporting before product behavior work resumes.
cli/first-pr-front-door-polishdoneripr first-pr now explains one top repairable gap, no-action state, or recovery state directly in stdout after #332.
output/one-screen-recommendation-contractdoneGolden-backed first-pr output now carries and validates top gap, why it matters, weak evidence, missing discriminator, focused test intent, verify, receipt, and static boundary after #335.
receipt/reviewer-native-outcomedoneOutcome receipts now make reviewer-visible static claim boundaries explicit after #338.
fixtures/first-pr-demo-storydoneThe boundary-gap fixture story now pins the before -> first-pr recommendation -> focused proof -> outcome receipt -> reviewer receipt path after #341.
surfaces/first-useful-loop-convergencedoneGenerated CI, VS Code, and agent packets now mirror the CLI first-useful loop vocabulary and non-claims.
campaign/first-useful-pr-loop-continuation-closeoutdoneClosed the continuation with proof that the first-pr front door, receipts, generated CI, VS Code, agent packets, output contracts, and support-tier boundaries tell one consistent static-advisory repair story.

Commands:

cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-doc-roles
cargo xtask check-output-contracts
cargo xtask check-pr
git diff --check

Blocking conditions:

  • analyzer truth changes in the activation PR
  • source-of-truth namespace duplication
  • runner-local goals or parallel docs/source-of-truth systems
  • source edits or generated tests
  • provider/model calls
  • mutation execution
  • support-tier promotion without a dedicated proof PR
  • default CI blocking or gate behavior changes
  • PR comment publishing changes
  • release, publish, signing, marketplace, or badge endpoint refresh work
  • runtime adequacy, coverage adequacy, proof-of-correctness, policy eligibility, gate pass/fail, or merge-readiness claims

Closeout:

Repo-Ops Campaign: Self-Hosted Routed Runner Proof

Campaign ID: self-hosted-routed-runner-proof

Status: closed.

First Useful PR Loop Continuation is closed and archived. This repo-ops campaign selected the live cutover gap where #34 tracked CX53/CX43 self-hosted routed Rust proof and #24 tracked the larger source-to-swarm cutover boundary. It closed that proof gap without reopening product behavior, release, badge, source promotion, or branch-protection scope.

Objective:

Restore and prove the self-hosted routed Rust path for ripr-swarm while keeping
the normalized Ripr Rust Small Result gate and GitHub-hosted fallback as the
branch-protection-facing proof.

End state:

  • #34 records CX53 primary proof with target=cx53, reason=cx53_idle, and Ripr Rust Small Result success, or a current bounded image-readiness/runner-visibility blocker.
  • #34 records CX43 fallback proof with target=cx43, reason=cx43_idle, and Ripr Rust Small Result success, or a current bounded image-readiness/runner-visibility blocker.
  • #24 records the same cutover disposition and does not claim machine cutover completion before self-hosted proof or an accepted blocker.
  • Branch protection remains strict and requires only Ripr Rust Small Result.
  • Conditional CX53/CX43/GitHub-hosted implementation jobs remain unrequired.
  • Normal feature, docs, spec, analyzer, editor, badge, and repo-ops work stays routed to ripr-swarm; source ripr remains release/distribution authority.

Work items:

Work itemStatusNotes
goals/self-hosted-routed-runner-proof-activationdoneSelect #34/#24 as the active repo-owned successor after no-current-goal without changing analyzer, product, release, badge, source-promotion, or branch-protection behavior.
ops/current-routed-proof-refreshdoneCurrent routed proof was recorded on #34 and #24 as the issue ledger while the lane was still hosted-fallback-only. Later proof replaced that blocker.
ops/cx53-cx43-proof-closeoutdone#920 run 26859058862 proved CX53 with target=cx53, reason=cx53_idle, and Ripr Rust Small Result success; #921 post-merge run 26860129004 proved CX43 with target=cx43, reason=cx43_idle, and Ripr Rust Small Result success.
campaign/self-hosted-routed-runner-proof-closeoutdoneSelf-hosted routed runner proof closeout records the issue-linked proof, branch-protection status, source/swarm authority boundary, and remaining #24 operational follow-up.

Commands:

git fetch origin --prune
git status --short --branch
gh pr list --repo EffortlessMetrics/ripr-swarm --state open
gh pr list --repo EffortlessMetrics/ripr --state open
cargo xtask pr-triage-report
cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-doc-roles
cargo xtask check-workflows
cargo xtask check-pr
git diff --check

Closeout:

Blocking conditions:

  • analyzer truth changes
  • output schema or product surface changes
  • source repo promotion
  • release, publish, signing, marketplace, or badge endpoint refresh work
  • release/publish/signing secrets in ripr-swarm
  • fork PRs on self-hosted runners
  • branch-protection expansion beyond Ripr Rust Small Result
  • default CI blocking changes beyond the normalized routed result
  • provider/model calls
  • source edits or generated tests
  • mutation execution
  • runtime adequacy, coverage adequacy, proof-of-correctness, policy eligibility, gate pass/fail, or merge-readiness claims

Lane 1 Campaign: Real-Repo Trust Readiness

Campaign ID: lane1-real-repo-trust-readiness

Status: closed. .ripr/goals/active.toml now records status = "closed" and no_current_goal = true; the closeout audit is Lane 1 Real-Repo Trust Readiness closeout.

The self-hosted routed runner proof campaign is closed and archived. Live release handoff state says source ripr 0.8.0 has already been tagged and published, so this campaign treats the new real-repo issue batch as post-release trust debt and possible hotfix work. It must not imply that the published 0.8.0 tag already fixed behavior that lands afterward.

The issue batch:

  • #913: review-comments Markdown omits file:line next to seam IDs.
  • #912 and #909: large monorepos exceed the seam-cache entry limit and cache skips are too easy to miss.
  • #908, #910, and #911: cross-language, TypeScript-tested, binding, and FFI seams can be reported or routed as misleading Rust repair work.

Objective:

Make RIPR's evidence-to-repair foundation honest on large and mixed-language
repositories: review surfaces must be navigable, large seam-cache limits must
be explicit named limitations, and cross-language or binding/FFI seams must
fail closed instead of emitting wrong Rust repair work.

End state:

  • Review-facing seam rows include source file and line/span, or an explicit source_location_unresolved limitation route.
  • Large seam-cache skips report observed seam count, configured limit, downstream consumability, and a repair/configuration route.
  • Rust seams reached through TypeScript, binding, or FFI surfaces fail closed as named limitations until RIPR can prove external oracle visibility or a language-aware target.
  • Public repair-packet queues exclude unresolved cross-language packets.
  • Release-line notes and issue labels stay honest about what shipped in the already-published 0.8.0 tag.

Work items:

Work itemStatusNotes
release/real-repo-trust-issue-triagedoneClassify #913, #912/#909, and #908/#910/#911; link duplicate/overlap clusters; label release-line blockers or post-0.8 follow-ups honestly; update release/freeze non-claims.
report/review-comments-source-locationsdoneReview-comments Markdown rows now carry file:line/span or an explicit unknown-location limitation route.
cache/large-seam-cache-skip-limitationdoneLarge seam-cache skips are named, counted, configured, and preserved as limited state.
analysis/cross-language-oracle-visibility-limitationdoneTS-tested Rust and binding/FFI seams route to named limitations when external oracle visibility is unresolved.
report/binding-ffi-target-placement-fail-closeddoneSuppress unrelated Rust suggested-test placement for binding/FFI or externally tested seams.

Commands:

cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-doc-roles
cargo xtask check-pr
git diff --check

Blocking conditions:

  • forcing actionability without the public repair-packet fields;
  • suggesting unrelated Rust tests for binding/FFI seams;
  • hiding cache skips or representing limited input as full;
  • claiming full cross-language oracle proof before the analyzer route exists;
  • changing provider, autonomous edit, mutation-execution, badge, default CI blocking, source release, publishing, signing, marketplace, or install-doc behavior without explicit authorization.

Closeout:

  • Lane 1 Real-Repo Trust Readiness closeout
  • The closed manifest archive is .ripr/goals/archive/2026-06-03-lane1-real-repo-trust-readiness.toml.
  • #909, #908, #910, and #911 remain broader follow-up routes for scalable seam cache, cross-language oracle graph proof, and language-aware repair target inference. They are not completed by this closeout.

Lane 1 Campaign: Large-Repo Runtime Completeness

Campaign ID: lane1-large-repo-runtime-completeness

Status: closed. .ripr/goals/active.toml records status = "closed" and no_current_goal = true; the closeout audit is Lane 1 Large-Repo Runtime Completeness closeout.

This campaign is scoped to the live #909 follow-up: make large-repo repo-exposure warm paths useful without turning sampled, timeout, incomplete, or otherwise limited runs into full repo truth. It does not reopen the published 0.8.0 release claim boundary and does not claim full large-monorepo optimization until diff-scoped review runtime is separately validated.

Objective:

Make the full classified seam cache usable for large repo-exposure results by
storing entries above RIPR_REPO_SEAM_CACHE_LIMIT as bounded shard files, loading
only complete key-matched shard sets, and keeping the remaining large-repo
runtime work visible as named follow-ups.

End state:

  • Full classified seam cache entries larger than the active limit write a manifest plus bounded shard files under target/ripr/cache instead of skipping the entire cache store.
  • Warm loads stitch shards only when the manifest and every shard match the current cache key.
  • Missing, corrupt, or mismatched shard sets are ignored as corrupt cache state and fall back to cold compute.
  • RIPR_REPO_SEAM_CACHE_LIMIT remains a positive integer tuning knob, now bounding shard size rather than silently disabling large cache entries.
  • Cache report shard summaries and diff-scoped large-repo review fast paths are implemented as explicit large-repo surfaces without turning scoped review input into full-repo truth.

Work items:

Work itemStatusNotes
cache/large-repo-sharded-seam-cachedoneFull repo seam cache entries above RIPR_REPO_SEAM_CACHE_LIMIT now write and reload bounded shard files; corrupt/incomplete shard sets fail closed; docs describe shard-size semantics.
report/large-repo-cache-shard-summarydoneCache reports now summarize sharded seam-cache families with shard counts, manifest counts, bytes, largest shard sets, and orphan/incomplete shard sets.
analysis/diff-scoped-large-repo-review-fast-pathdoneReview-comments default diff rendering now classifies changed production files plus bounded immediate callers, emits analysis_scope.run_status = "limited_diff_scope", and reports review_comments_diff_scope_only rather than full-repo truth.

Commands:

cargo test -p ripr seam_cache -- --test-threads=1
cargo test -p ripr seam_inventory -- --test-threads=1
cargo test -p xtask cache -- --test-threads=1
cargo xtask cache report
cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-pr
git diff --check

Blocking conditions:

  • representing sampled, stale, timeout, runner-failure, incomplete, or cache-preflight-limited runs as full;
  • using raw findings as product truth without canonical evidence items;
  • creating public repair packets from static limitations;
  • claiming full large-monorepo optimization before diff-scoped review runtime is validated;
  • changing source release, publish, signing, marketplace, or install-doc behavior without explicit release authorization.

Closeout:

  • Lane 1 Large-Repo Runtime Completeness closeout
  • The closed manifest archive is .ripr/goals/archive/2026-06-03-lane1-large-repo-runtime-completeness.toml.
  • Future cross-language oracle graph or language-aware placement work should open a successor issue-backed manifest rather than extending this closed #909 campaign.

Lane 1 Campaign: Language-Aware Placement Navigation

Campaign ID: lane1-language-aware-placement-navigation

Status: complete. The Lane 1 Language-Aware Placement Navigation closeout records the closed campaign; .ripr/goals/active.toml now records status = "closed" and no_current_goal = true, with the closed manifest archived at .ripr/goals/archive/2026-06-03-lane1-language-aware-placement-navigation.toml.

This campaign is scoped to live #911: suggested-test placement must stop being confident in the wrong language or crate, while still becoming more useful when RIPR has explicit external observer target evidence. It follows #931, which made binding/FFI target placement fail closed. It does not reopen the published 0.8.0 release claim boundary and does not claim full cross-language oracle graph proof.

Objective:

Make suggested-test placement safe and useful for binding, FFI, and externally
tested seams by routing known external target evidence as navigation-only
limitation context, while keeping unknown targets fail-closed instead of
emitting unrelated Rust test files or repair packets.

End state:

  • Ordinary Rust seams with direct Rust-side test context continue to suggest only locally supported Rust test targets.
  • Binding, FFI, or externally tested seams with explicit configured external observer evidence can surface a navigation-only target file and route without becoming public repair packets.
  • Binding, FFI, or externally tested seams without explicit target evidence keep suggested test placement unknown or not applicable with a named blocked route.
  • LSP, review-comments, and agent packet surfaces suppress repair actions whenever allowed edit surface, verify command, receipt command, or target shape is unresolved.
  • Readiness and route-quality surfaces preserve language-aware target-placement limitations as limitations rather than actionability.

Work items:

Work itemStatusNotes
goals/language-aware-placement-navigation-activationdoneSelect #911 as the first Lane 1 successor after lane1-large-repo-runtime-completeness closed with no_current_goal = true, without changing analyzer behavior, repair-packet authority, release claims, gates, badges, or source distribution authority.
report/language-aware-placement-navigationdone#938 surfaces explicit configured external observer target evidence as navigation-only limitation context in review-comments, LSP static-limit notes, and packet-adjacent targeted-test briefs, while unknown targets keep a named blocked route and no repair action, verify command, receipt command, or allowed edit surface.
report/language-aware-placement-route-qualitydone#940 summarizes language-aware placement limits and navigation-only external target evidence in readiness, route-quality, and calibration outputs without promoting unresolved or preview external targets into public repair packets.
campaign/language-aware-placement-closeoutdoneClose #911 with issue state, claim boundaries, validation evidence, remaining #908/#910 cross-language oracle graph work, and no successor unless current repo-owned state selects one.

Commands:

cargo test -p ripr suggested_test -- --test-threads=1
cargo test -p ripr typescript_preview_card_projects_bun_cross_language_grip -- --test-threads=1
cargo test -p ripr lsp --lib
cargo xtask ripr-swarm readiness
cargo xtask evidence-quality-scorecard
cargo xtask check-output-contracts
cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-doc-roles
cargo xtask check-pr
git diff --check

Blocking conditions:

  • suggesting unrelated Rust test files for binding or FFI seams;
  • inferring TypeScript, Python, or other external test targets without explicit bridge or observer evidence;
  • creating public repair packets from navigation-only external target evidence;
  • inventing verify commands, receipt commands, candidate values, or allowed edit surfaces for unresolved external targets;
  • claiming full cross-language oracle graph proof or runtime coverage proof;
  • changing provider, autonomous edit, mutation-execution, badge, default CI blocking, source release, publishing, signing, marketplace, or install-doc behavior without explicit authorization.

Closeout:

  • Lane 1 Language-Aware Placement Navigation closeout
  • The closed manifest archive is .ripr/goals/archive/2026-06-03-lane1-language-aware-placement-navigation.toml.
  • Future cross-language oracle graph work should continue through #908/#910 or fresh issue-backed manifests rather than extending this closed #911 campaign.

Lane 1 Campaign: Cross-Language Oracle Graph Readiness

Campaign ID: lane1-cross-language-oracle-graph-readiness

Status: folded into the active post-0.8 operating loop after the bounded SPEC-0062, corpus, TS discriminator, and binding-route witness slices landed. .ripr/goals/active.toml now selects lane1-post-08-operating-loop so diff-first real-repo operation can happen before broader route-quality and cross-language graph promotion work.

This campaign is scoped to live #910 and related #908: Rust seams exercised by TypeScript, binding, or FFI surfaces need an explicit oracle graph before RIPR can treat external evidence as more than advisory limitation context. It follows #930, #938, and #940: unresolved oracle visibility and target placement already fail closed, while RIPR-SPEC-0062: Cross-Language Oracle Graph now names the bounded Bun Blob graph shape needed to unlock trustworthy actionability. It does not reopen the published 0.8.0 release claim boundary and does not promote TypeScript or JavaScript preview evidence to a support tier.

Objective:

Make cross-language oracle visibility explicit for Rust seams exercised by
TypeScript, binding, or FFI surfaces: distinguish missing external
discriminators, unknown bridge routes, and complete advisory witnesses, then
only move toward actionability when the Rust seam, binding edge, external
callsite, external assertion/oracle, verify command, receipt command, raw
evidence refs, and edit constraints are all named.

End state:

  • TS-tested Rust seam samples carry a bounded oracle graph shape: Rust seam, boundary, binding or FFI edge, external callsite, external assertion or oracle, and raw evidence refs.
  • Complete configured external witnesses can be reported as advisory external observation without creating public repair packets, generated tests, gates, badges, baselines, or support-tier promotion.
  • Missing discriminator, mention-only, unknown bridge, and unresolved target cases stay static limitations with named repair routes and samples.
  • Readiness, scorecard, review, LSP, and PR surfaces preserve cross-language oracle routes as limitations until public repair-packet fields exist.
  • Full actionability remains blocked unless verify command, receipt command, allowed edit surface, must-not-change guardrails, confidence, and raw evidence refs are present.

Work items:

Work itemStatusNotes
goals/cross-language-oracle-graph-activationdoneSelect #910/#908 as the next Lane 1 successor after lane1-language-aware-placement-navigation closed with no_current_goal = true, without changing analyzer behavior, repair-packet authority, release claims, gates, badges, support tiers, or source distribution authority.
spec/cross-language-oracle-graph-v1doneRIPR-SPEC-0062 defines the bounded #910/#908 graph contract for the configured Bun Blob route: required Rust seam, boundary, binding or FFI edge, external TypeScript callsite, external assertion/oracle, raw evidence refs, allowed states, and fail-closed non-claims before changing analyzer behavior.
fixtures/cross-language-oracle-graph-corpusdonefixtures/cross-language-oracle-graph-corpus pins the #910/#908 Bun Blob graph corpus with Rust seam samples, boundary text, binding/FFI hints, external TypeScript callsites, external oracle/assertion samples, advisory or limitation states, structured raw evidence refs, and fail-closed non-claims before analyzer behavior changes.
analysis/cross-language-ts-discriminator-witnessdoneFor the bounded configured Bun Blob route, complete TS discriminator witnesses stay preview-advisory with graph-leg raw refs, while missing-discriminator and mention-only evidence remain cross-language oracle visibility limitations with named missing graph legs and no public repair packets.
analysis/cross-language-binding-route-witnessdoneConfigured Bun Blob routes now credit a structured binding_edge raw ref, while complete TypeScript discriminators with unknown bridge confidence stay bridge_unknown static limitations with missing binding_or_ffi_edge, no binding raw ref, no placement, and no public repair packet.
report/cross-language-oracle-route-qualitydoneReadiness and evidence-quality scorecard outputs summarize complete advisory witnesses, missing discriminators, unknown bridges, mention-only limitations, and public packet exclusions without treating cross-language preview evidence as repair-ready.
report/bun-ub-calibrationdonecargo xtask bun-ub-calibration writes an operator-readable preview/advisory JSON/Markdown receipt for the Bun Blob TypeScript calibration corpus, including TS-discriminated, missing-discriminator, mention-not-observer, bridge_unknown, missing graph leg, non-claim, and repair_packet_ready=false rows.
output/bun-ub-missing-discriminator-placementdoneConfigured Bun Blob missing shared/resizable discriminator rows now name test/js/web/fetch/blob.test.ts as advisory TypeScript placement in preview cards, route-quality rows, and Bun UB calibration receipts while bridge-unknown, mention-only, partial-oracle, and target-unresolved rows remain suggested_test_file=not_applicable with no public repair packet.
dogfood/bun-ub-cross-language-witness-receiptsdonefixtures/bun-ub-cross-language-dogfood and cargo xtask dogfood now record the #31648 known-good, stripped-resizable, and maxByteLength mention-only operator receipts, including before/after review behavior, manual verdict, advisory action, placement, and repair_packet_ready=false.
docs/bun-ub-typescript-preview-runbookdonedocs/BUN_UB_TYPESCRIPT_PREVIEW_RUNBOOK.md gives Bun operators the copyable advisory loop for configuring the preview, running diff-scoped evidence, interpreting TS-discriminated, missing-discriminator, mention-only, bridge-unknown, and FFI panic-boundary limitation states, and checking calibration/dogfood receipts without runtime Bun, generated tests, public repair packets, gates, badges, baselines, RIPR Zero, or support-tier promotion.
campaign/cross-language-oracle-graph-closeoutdeferredCloseout is deferred until the broader post-0.8 loop reaches the cross-language graph and surface-alignment slices, or a narrower issue-backed closeout is selected.

Focused correction campaign ID: typescript-bun-081-placement-receipt-correction.

Commands:

cargo xtask check-spec-format
cargo xtask check-spec-numbering
cargo xtask check-traceability
cargo test -p xtask cross_language_oracle_graph_corpus_cases_are_checked -- --test-threads=1
cargo test -p xtask typescript_bun_ub_calibration_cases_are_checked -- --test-threads=1
cargo test -p xtask dogfood_bun_ub_cross_language -- --test-threads=1
cargo test -p xtask bun_ub_calibration -- --test-threads=1
cargo xtask bun-ub-calibration
cargo xtask dogfood
cargo test -p ripr typescript_preview_card_projects_bun_cross_language_grip -- --test-threads=1
cargo xtask ripr-swarm readiness
cargo xtask evidence-quality-scorecard
cargo xtask check-output-contracts
cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-doc-roles
cargo xtask check-pr
git diff --check

Blocking conditions:

  • classifying TS-tested Rust seams as actionable from preview evidence alone;
  • suggesting Rust or external-language test targets without explicit bridge and observer evidence;
  • inventing binding edges, external callsites, external oracles, verify commands, receipt commands, candidate values, or allowed edit surfaces;
  • creating public repair packets from advisory cross-language witnesses;
  • claiming full cross-language oracle graph proof or runtime coverage proof before the graph is explicitly named and verified;
  • changing provider, autonomous edit, mutation-execution, badge, default CI blocking, support tier, source release, publishing, signing, marketplace, or install-doc behavior without explicit authorization.

Lane 1 Campaign: Post-0.8 Evidence-To-Repair Operating Loop

Campaign ID: lane1-post-08-operating-loop

Status: closed. .ripr/goals/active.toml records status = "closed" and no_current_goal = true. The archived manifest lives at .ripr/goals/archive/2026-06-04-lane1-post-08-operating-loop.toml, and the closeout handoff is docs/handoffs/2026-06-04-lane1-post-08-operating-loop-closeout.md.

The closed manifest records that live queue hygiene, #913, #909/#912, Bun UB calibration reporting, diff-first changed-surface mode, cross-language oracle fail-closed routing, language-aware target placement navigation, the bounded cross-language oracle graph, repair-packet guidance quality, attempt-ledger outcome hardening, real repair/analyzer-attempt dogfood, route-quality metrics, and surface canonical-state alignment are complete in the current repo state. No successor campaign is selected.

Objective:

Make RIPR's post-0.8 Lane 1 operating loop useful on real large and
mixed-language repositories: route safe repair packets, fail closed into named
limitation backlog items, record receipts and outcomes, and use route quality
to choose the next analyzer work.

Work items:

Work itemStatusNotes
repo/post-08-queue-hygienedoneLive state confirms #680, #582, and the same-file method-chain route split chain are merged or closed; stale local branches from merged PRs and two stale remote heads were pruned.
review/review-comments-file-linedone#913 is closed by #926; review-comments source locations are no longer the next active slice.
cache/large-seam-cache-explicitdone#912 and #909 are closed by the large-cache post-0.8 chain through #936, including explicit skip state and sharded cache follow-ups.
report/bun-ub-calibrationdoneInserted before diff-first for the 0.8.1 TypeScript/Bun patch line: the xtask report turns the Bun Blob calibration corpus into advisory JSON/Markdown operator receipts without public repair-packet, gate, badge, runtime, or support-tier authority.
ripr/diff-first-changed-surface-modedoneripr diff --base <ref> --head <ref> emits diff-complete changed-file and changed-seam evidence before full-repo analysis and preserves full-repo limited state.
analysis/cross-language-oracle-fail-closeddoneExisting evidence-record, packet-queue, readiness, and scorecard coverage routes unresolved external oracle paths to named limitations rather than wrong-language repair packets.
report/language-aware-target-placement-v1done#938 through #941 already closed language-aware placement navigation: explicit external observer targets are navigation-only and unresolved binding/FFI targets stay limitations with no LSP repair action.
analysis/cross-language-oracle-graph-v1doneSPEC-0062, the cross-language oracle graph corpus, TS discriminator witness routes, unknown-bridge limitation routing, route-quality report, and Bun UB calibration receipt now validate the bounded configured Bun Blob graph route, including partial external callsites that still lack stable oracle evidence; broader generic graph support remains non-claimed.
analysis/repair-packet-guidance-qualitydoneExisting swarm-plan packet corpus and focused tests require typed repair route, target shape, verify command, receipt command, allowed edit surface, must-not-change boundaries, confidence, raw evidence refs, and fail-closed missing-field wording before a packet can be queued.
report/attempt-ledger-outcome-hardeningdoneSPEC-0057, the real-repair-attempts corpus, attempt-ledger report, readiness report, and focused xtask tests preserve latest and historical not_attempted, attempted_no_receipt, receipt_present, evidence_improved, evidence_unchanged, evidence_regressed, resolved, unknown, stale synthetic placeholder cleanup, gap mismatch, latest-attempt projection, and orphan-receipt routing.
dogfood/real-repair-analyzer-attemptsdoneThe real-repair-attempts dogfood corpus and report record 67 repo-local repair or analyzer-route attempts with verify command, receipt route when applicable, before/after state, outcome, must-not-change boundaries, raw evidence refs, and operator notes; the set includes 61 improved, 2 resolved, 2 unchanged, and 2 attempted-without-receipt rows, while readiness keeps the latest 36 improved and 2 resolved packets current and preserves older non-success attempts in durable history.
report/route-quality-metricsdoneReadiness and scorecard reports expose repair-route quality, language repair-route quality, top failing repair routes, top missing evidence fields, top limitation routes, limitation route quality, and cross-language oracle route quality. Current readiness derives 38 attempted packets, 36 improved packets, 2 resolved packets, and durable historical non-success counts from real-repair attempts, while focused route-quality tests cover non-empty failing, missing-field, and limitation-route fixtures.
surface/canonical-state-alignmentdoneExisting surface-projection and user-surface-projection dogfood corpora prove CLI-adjacent, review, LSP/editor, PR comment, badge, and CI examples consume the same canonical repair or limitation state, preserve canonical_gap_id, runtime status, receipt state, route-quality non-success cases, and missing-receipt cases, and keep raw findings as supporting evidence rather than product truth.
campaign/lane1-post-08-closeoutdoneLane 1 Post-0.8 Evidence-To-Repair Operating Loop closeout records what users can trust, what remains advisory, what remains non-actionable, validation commands, open issues, explicit non-claims, the archived manifest, and no selected successor.

Non-claims:

  • no provider integration;
  • no autonomous edits;
  • no mutation execution;
  • no default blocking CI or badge semantic switch;
  • no source release, publish, tag, signing, marketplace, or install-doc work without explicit release authorization.

Closeout:

Lane 1 Campaign: Cross-Language Oracle Follow-Up

Campaign ID: lane1-cross-language-oracle-followup

Status: closed. .ripr/goals/active.toml records status = "closed" and no_current_goal = true. The archived manifest lives at .ripr/goals/archive/2026-06-04-lane1-cross-language-oracle-followup.toml.

This campaign extends cross-language oracle evidence only through measured, profile-backed graph slices. It must not convert TypeScript, binding, FFI, or external-oracle evidence into public repair packets until the graph legs and canonical actionability fields are explicit.

Objective:

Make #908/#910 cross-language oracle follow-ups more useful by adding measured
graph profiles beyond the bounded Bun Blob route while preserving the rule that
external-language evidence is advisory or a named limitation until every graph
leg and public repair-packet field is explicit.

Work items:

Work itemStatusNotes
fixtures/cross-language-copy-to-unshared-profiledoneSelects the #908/#910 follow-up and pins the copy_to_unshared TypeScript-exercised Rust seam as a profile-backed bridge_unknown limitation with source locations, missing binding edge, repair route, unlock condition, raw evidence refs, and no public repair-packet fields.
report/configured-cross-language-ts-placementdoneSurfaces test/js/web/fetch/blob.test.ts only for configured Bun Blob missing-discriminator rows while keeping the result advisory: no public projection, verify command, receipt command, allowed edit surface, wrong Rust test target, or repair packet.
analysis/cross-language-copy-to-unshared-bridge-routedoneAdds configured bridge evidence for the copy_to_unshared profile and credits the external TypeScript oracle only as a preview/advisory witness; the row still has no verify command, receipt command, allowed edit surface, suggested test file, public projection eligibility, or repair packet.
analysis/bun-markdown-resizable-cross-language-profiledoneAdds the #951 MarkdownObject::to_string configured Bun.markdown profile and credits test/js/bun/md/md-edge-cases.test.ts only as a preview/advisory witness when resizable ArrayBuffer, configured bridge, callsite, and strong markdown oracle evidence are present; weak markdown oracle evidence remains a named limitation, and the route still has no suggested test file, verify command, receipt command, allowed edit surface, public projection eligibility, repair packet, or generic TypeScript proof claim.
dogfood/bun-blob-witness-receiptsdoneRecords checked Bun Blob cross-language dogfood receipts for complete advisory, missing-discriminator, bridge-unknown, and partial-oracle cases while preserving advisory-only authority, route-quality counters, non-claims, and no public repair packets.
fixtures/bun-ffi-negative-offset-panic-boundary-profiledoneAdds the #950 Bun FFI FFIObject::read negative-offset panic-boundary profile as a named static limitation with source locations, FFI binding sample, missing negative-offset panic oracle, missing safe external observer target, unlock condition, raw evidence refs, and no suggested test file, verify command, receipt command, allowed edit surface, public projection eligibility, or repair packet.
dogfood/bun-ffi-panic-boundary-receiptdoneRecords a checked Bun FFI negative-offset panic-boundary dogfood receipt for #950/#974 that proves the route stays a named limitation with unresolved negative-offset oracle and safe observer target evidence, no suggested test file, no verify command, no receipt command, no allowed edit surface, and no public repair packet.

Non-claims:

  • no generic cross-language oracle proof;
  • no runtime Bun execution;
  • no generated tests;
  • no public repair packet from preview or limitation evidence;
  • no provider integration;
  • no autonomous edits;
  • no mutation execution;
  • no default blocking CI or badge semantic switch;
  • no source release, publish, tag, signing, marketplace, or install-doc work without explicit release authorization.

Closeout:

Lane 1 Campaign: Cross-Language Guidance Safety

Campaign ID: lane1-cross-language-guidance-safety

Status: closed. .ripr/goals/active.toml records status = "closed" and no_current_goal = true. The archived manifest lives at .ripr/goals/archive/2026-06-04-lane1-cross-language-guidance-safety.toml.

This one-slice successor pins the #908 MarkdownObject review-comments guidance failure without reopening generic cross-language oracle support. It proves the agent-facing prompt fails closed when a Rust seam has external TypeScript observer evidence but safe repair target placement remains unresolved.

Objective:

Pin the #908 MarkdownObject review-comments guidance failure so externally
observed TypeScript evidence remains navigation-only when safe target placement
is unresolved, and the agent-facing prompt cannot suggest a wrong Rust test
target.

Work items:

Work itemStatusNotes
output/markdownobject-review-comments-target-safetydoneAdds a MarkdownObject-specific review-comments regression for src/runtime/api/MarkdownObject.rs and test/js/bun/md/md-edge-cases.test.ts: the row stays cross_language_target_unresolved, has no verify command or public repair packet, does not mention vendor/lolhtml/tests/harness/input.rs, and exposes the TypeScript observer only as navigation-only context routed to analysis/cross-language-test-target-inference.

Non-claims:

  • no #908 or #910 closure claim;
  • no generic TypeScript, JavaScript, binding, or FFI oracle proof;
  • no runtime Bun, Jest, Vitest, tsc, tsserver, Miri, or mutation execution;
  • no generated tests;
  • no public repair packet from preview or limitation evidence;
  • no provider integration;
  • no autonomous edits;
  • no default blocking CI or badge semantic switch;
  • no source release, publish, tag, signing, marketplace, or install-doc work.

Lane 1 Campaign: Cross-Language Evidence Router UX

Campaign ID: cross-language-evidence-router-ux

Status: active. .ripr/goals/active.toml selects this campaign after live queue inspection closed the current dangling analysis PR (#982) and cargo xtask goals next reported no_current_goal = true.

This campaign turns the calibrated TypeScript/Bun graph path into a repeatable mixed TypeScript plus Rust operating loop. It preserves preview/advisory authority: cross-language preview evidence may shape operator and agent guidance, but it must not create public repair packets, support-tier promotion, gates, badges, release authority, generated tests, or runtime proof claims.

Objective:

Turn the calibrated TypeScript/Bun graph path into a repeatable mixed
TypeScript plus Rust operating loop for Bun operators and external coding
agents, while preserving preview/advisory authority and preventing unresolved
cross-language evidence from becoming public repair packets.

End state:

  • Bun operators can read compact cross-language preview state without inspecting raw preview-card JSON.
  • Configured advisory packets bound agent work and stop when bridge or placement evidence is missing.
  • Proof-mode projection keeps static witnesses distinct from runtime, mutation, Miri, or model proof.
  • Manifest-only stable-byte profiles make future bridge debt visible before analyzer behavior changes.
  • Bridge inventory and dogfood receipts expose calibrated, missing, mention-only, bridge-unknown, and named limitation states.
  • The campaign closes with TypeScript/Bun support still preview/advisory unless a separate accepted promotion contract changes that boundary.

Work items:

Work itemStatusNotes
goals/cross-language-evidence-router-ux-activationdoneSelect RIPR-SPEC-0063 and RIPR-PLAN-0063 as the active Lane 1 successor after no_current_goal = true, without changing analyzer behavior, report output, repair-packet authority, release claims, gates, badges, support tiers, or source distribution authority.
release/typescript-bun-preview-patch-proofdone0.8.1 TypeScript/Bun preview patch proof records the current Bun Blob / ArrayBuffer calibrated states, copy_to_unshared, MarkdownObject, and FFI panic-boundary follow-up status from existing receipts, preview/advisory authority, repair_packet_ready = false for cross-language preview rows, and validation results as pass, fail, or not run, without performing a release.
output/bun-ub-preview-summarydonecargo xtask bun-ub-preview-summary writes compact advisory JSON/Markdown from existing graph, calibration, and dogfood data, including route counts, named limitations, public packet exclusions, authority = preview_advisory_only, and repair_packet_ready = false, without changing analyzer behavior, public repair-packet authority, generated tests, gates, badges, or support tiers.
agent/bun-cross-language-advisory-packetdoneConfigured TypeScript preview cards project a nested Bun cross-language advisory packet through JSON and human output with state, Rust seam, eligible TypeScript placement, missing discriminators, suggested shape, bridge confidence, missing graph legs, must_not_change, stop condition, raw evidence refs, and repair_packet_ready = false; bridge_unknown packets stop on binding_or_ffi_edge instead of suggesting test edits.
output/stable-byte-proof-modedoneConfigured Bun cross-language grip output projects advisory stable-byte proof mode through TypeScript preview-card JSON and human output, with observable_red_green, mutation_plus_miri, helper_gated, bridge_unknown, and static_limitation modes, short reasons, and explicit runtime_execution=false, mutation_execution=false, miri_execution=false, and proof_claim=false boundaries.
fixtures/bun-node-fs-scalar-write-profiledoneThe cross-language oracle graph corpus pins node:fs scalar write as a manifest-only named_static_limitation with typed witness placement at test/js/node/fs/fs.test.ts, proof_mode = observable_red_green, missing binding_or_ffi_edge:node_fs_scalar_write and external_oracle:stable_byte_scalar_write legs, and repair_packet_ready = false; it adds no analyzer behavior, runtime execution, generated tests, public repair packet, gate, badge, or support-tier claim.
fixtures/bun-write-helper-gated-profiledoneThe cross-language oracle graph corpus pins Bun.write as a manifest-only helper-gated named_static_limitation with proof_mode = helper_gated, suggested_test_file = not_applicable, missing helper:bun_write_fixture_helper, binding_or_ffi_edge:bun_write_sink, and external_oracle:stable_byte_write legs, and repair_packet_ready = false; it adds no analyzer behavior, runtime execution, generated tests, public repair packet, gate, badge, or support-tier claim.
analysis/configured-bridge-inventorydonecargo xtask configured-bridge-inventory writes advisory JSON/Markdown from the existing cross-language oracle graph corpus, listing Blob ArrayBuffer, copy_to_unshared, and MarkdownObject configured bridges; the Bun Blob bridge-unknown row; node:fs scalar write and Bun.write manifest-only future surfaces; named static limitations; and repair_packet_ready = false, without analyzer inference, public repair packets, placement from missing inventory rows, gates, badges, or support-tier promotion.
dogfood/live-bun-stable-byte-receiptsdonefixtures/bun-ub-cross-language-dogfood records live-shaped Bun stable-byte receipts for configured copy_to_unshared and MarkdownObject witnesses, stripped resizable placement, mention-only rejection, bridge_unknown inspection, node:fs scalar write and Bun.write manifest-only limitations, and the FFI panic-boundary limitation; every row stays preview/advisory with manual verdicts, proof mode, review-work notes, repair_packet_ready = false, no Rust placement regression, and no runtime, generated-test, public repair-packet, gate, badge, or support-tier claim.
docs/bun-ub-first-run-polishdoneThe Bun UB TypeScript preview runbook now starts from ripr.toml, ripr doctor, and ripr check, names next actions for missing config, missing discriminator, mention-only, bridge_unknown, and named static limitation states, links the compact summary, advisory packet/proof-mode schema, configured bridge inventory, calibration, and dogfood receipts, and keeps all claims preview/advisory with no new flags, analyzer behavior, generated tests, runtime execution, public repair packets, gates, badges, or support-tier promotion.
docs/post-081-support-decisiondonePost-0.8.1 TypeScript/Bun support decision keeps TypeScript and JavaScript opt-in preview, bounds calibrated Bun stable-byte evidence to advisory TS-discriminated, missing-discriminator, mention-only, bridge-unknown, and named-limitation states, rejects TypeScript stable support, Bun UB proof, runtime execution, generated tests, default gates, public repair packets, and full Bun binding graph coverage, and requires a separate accepted promotion contract for any stronger claim.

Commands:

cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
cargo xtask check-doc-roles
cargo xtask check-pr
git diff --check

Blocking conditions:

  • forcing actionability from cross-language preview evidence;
  • creating public repair packets from preview or limitation evidence;
  • suggesting Rust or external-language test targets without explicit bridge, observer, and typed placement evidence;
  • adding or requiring a ripr check --profile flag;
  • running tsc, tsserver, Bun, Jest, Vitest, Miri, mutation engines, providers, or generated tests;
  • changing gates, badges, baselines, RIPR Zero, support tiers, source release, publishing, signing, marketplace, or install-doc behavior;
  • claiming stable TypeScript or JavaScript support, full Bun binding graph coverage, generic cross-language support, runtime execution, or UB proof.

Non-claims:

  • no stable TypeScript or JavaScript support claim;
  • no full Bun binding graph;
  • no generic cross-language support for every mixed-language repository;
  • no runtime execution or UB proof claim;
  • no generated tests;
  • no provider integration;
  • no autonomous edits;
  • no public repair packets from preview cross-language evidence;
  • no source release, publish, tag, signing, marketplace, or install-doc work without explicit release authorization.

Campaign 29: Use-Case Spec Spine

Campaign ID: use-case-spec-spine

Status: superseded for active execution on 2026-07-09 by Campaign 32. Its accepted specs remain source truth; its release-era execution sequence does not.

RIPR has strong mechanism (reports, packets, runtime status, readiness, preview cards, limitation routes, receipts) and a weak product spine: no written map of who uses each surface, what good output looks like, what must never happen, and which specs make that true. The use-case spec spine fixes that before the next implementation wave.

Objective:

Land specs RIPR-SPEC-0065 through RIPR-SPEC-0073 plus the use-case
implementation plan, then route all post-release implementation work
through plans/use-case-specs/implementation-plan.md.

End state:

  • the roadmap (RIPR-SPEC-0065) and eight use-case specs are registered and merged with adversarial-review fixes applied
  • plans/use-case-specs/implementation-plan.md sequences the eight implementation slices with proof commands and claim boundaries
  • active goals point at the plan, not a parallel product board
  • implementation slices resume from the plan after the 0.9.0 release ships and the source back-merge completes

Work items:

Work itemStatusSummary
docs/use-case-spec-spinedoneSpecs RIPR-SPEC-0065 through RIPR-SPEC-0073 merged via the stacked PR sequence with registry entries, adversarial-review fixes, and green spec gates. Docs-only; no analyzer behavior changes.
goals/route-through-use-case-plandoneActive goals route through the use-case implementation plan; no implementation slice activates until a deliberate post-release decision. Was blocked by docs/use-case-spec-spine; both items completed in the spine merge wave.

Parallel-manifest boundary: .ripr/goals/modularization.toml and the lane tracker manifests remain beside active.toml as repo-operations queues (mechanical SRP refactors and lane bookkeeping), not product boards. The "no parallel product board" end state applies to product sequencing only: product implementation slices route exclusively through the use-case implementation plan, while ops manifests keep feeding refactor-only PRs that change no behavior contract.

Commands:

cargo xtask check-spec-format
cargo xtask check-spec-numbering
cargo xtask check-doc-artifacts
cargo xtask check-support-tiers
cargo xtask check-doc-index
cargo xtask markdown-links
cargo xtask check-static-language
git diff --check

Blocking conditions:

  • analyzer behavior changes inside the spec batch;
  • forcing actionability or treating raw findings as product truth;
  • activating an implementation slice before the post-release decision;
  • public repair packets from preview or limitation evidence;
  • badge, gate, baseline, or CI semantic switches ahead of their spec-backed implementation PRs.

Non-claims:

  • no full TypeScript or JavaScript support claim;
  • no Bun UB proof or full binding graph;
  • no generated tests, provider integration, or autonomous edits;
  • no runtime adequacy-style claims from static evidence;
  • no support-tier promotion from the spec batch.

Campaign 30: Python Repair-Routing Reliability (eval-sweep-driven)

Campaign ID: python-repair-routing-reliability

Status: active

Tracker: issue #1160 (Python usable-tier readiness, partial/open) · plans/python-repair-routing/current-state-inventory.md and plans/python-repair-routing/implementation-plan.md · RIPR-SPEC-0086 / RIPR-SPEC-0092. The former .ripr/goals/python-repair-routing.toml manifest was deleted with the goals scheduler (#2056) and is historical, not a live tracker.

Objective:

Drive Python repair routing from usable-alpha proof to a usable release claim shipped from source ripr, using external-repo evidence as the spine. Each PR adds one production delta plus its evidence; promotion gates on measured crash rate, parse-failure rate, runtime, gap-ID stability, and false-actionability, never on assertion. Ruff is a future parser-substrate watchpoint (EffortlessMetrics/ripr#1430), not a release gate.

Evidence ladder:

  • baseline dogfood (in-repo, saturated 26/26) — done
  • Tier A external robustness sweep (crash / parse-fail / runtime / gap-ID stability)
  • Tier B judged external PR panel (top-1 usefulness, false-actionable rate)
  • Tier C external repair attempts (before/after receipts)
  • rollback / regression proof
  • support-tier promotion (usable)
  • source promotion into ripr

Landed (historical receipts):

  • PR #1161 — Tier A cargo xtask eval-sweep harness + RIPR-SPEC-0086
  • PR #1163 — empty/no-clone sweeps report not_run, never a vacuous pass
  • PR #741 — scoped Python repair-routing loop promoted to usable alpha (the governed scope; broader Python static facts remain preview/advisory)

Current status: Python project detection can enable the adapter by default when no ripr.toml language config is present; explicit config remains authoritative. The scoped repair-routing loop is usable alpha. The usable promotion itself is still open — tracked by #1160, which remains the partial/open promotion tracker.

Non-goals:

  • Ruff integration or parser breadth (EffortlessMetrics/ripr#1430).
  • Completeness across all Python constructs or frameworks.
  • A stable claim; the target is usable.
  • Supporting Django/SQLAlchemy/etc — only failing closed (named limitation) there.

Campaign 31: Perl Repair-Routing Usable Alpha

Campaign ID: perl-repair-routing-bridge

Status: tracker

Tracker: .ripr/goals/perl-repair-routing.toml · umbrella issue #1379

Note: this is a focused tracker campaign, not the selected active campaign in .ripr/goals/active.toml (which remains use-case-spec-spine). Promotion into active.toml is a maintainer decision.

Objective

A working alpha lets a maintainer configure an explicit perl-lsp producer and use the normal RIPR loop:

[languages]
enabled = ["perl"]

[perl]
producer = "perllsp"
ripr doctor --root .
ripr check --root . --base origin/main
# add or strengthen one test
prove -l t/example.t
ripr check --root . --base origin/main --json > after.json
ripr outcome --before before.json --after after.json

The result is exactly one honest outcome: (1) a bounded Perl test-repair packet with a concrete missing discriminator, test location, verify command, edit cage, stop conditions, and receipt path; (2) already-observed evidence explaining why no new test is needed; or (3) a named limitation explaining why the Perl change is not statically actionable.

Not general Perl correctness, coverage adequacy, runtime mutation testing, or support for every dynamic Perl construct.

Why the restructure (ADR 0019)

An earlier draft of this campaign proposed moving the existing PerlStrictActionability out of #[cfg(test)] as the actionability flip authority, with PerlRepairCard/PerlInternalAgentPacket as bespoke renderers. That approach violates ADR 0019 (line 83-86: "An adapter MUST NOT introduce a parallel, mirror, or inline validator; a language-local repair_packet_ready boolean; or a bespoke packet renderer"). The shared authority is validate_agent_gap_record_packet (agent_seam_packets.rs), already used by the TypeScript projection (typescript_gap_record_for + validator_parity_* tests). Perl follows the same pattern.

Verified ground truth (scout-passed, file:line-confirmed)

  • The Perl adapter module is #[cfg(test)] mod perl; under crates/ripr/src/analysis/language/. After PR 2 (#1417) the former 4036-line monolith perl.rs is split into perl/mod.rs + perl/tests.rs.
  • missing_discriminator formerly defaulted to generic enum labels (default_missing_discriminator() returned "return_value" etc.), NOT concrete expressions. TypeScript/Python populate the same shared slot (GapRepairRoute.missing_discriminator, gap_decision_ledger.rs) with concrete values ("amount >= threshold"). Correction #2 is a Perl-local fix — no shared-contract change, no golden re-bless. Landed in PR 12 (#1428).
  • Relations formerly gated by exposure class + confidence + oracle shape but NOT by relation kind. direct_owner_call and file_proximity were treated identically. Correction #3 landed in PR 12 (#1428).
  • prove -l/-lv/-Ilib were rejected by positional matching. Correction #4 landed in PR 13 (#1421).
  • perl-lsp already produced a serde FileFactShard; the exporter is a thin new LaunchAction variant, not a from-scratch build.
  • lang-perl = [] exists but is not in default (Cargo.toml); the pipeline returns a fail-closed stub when the feature is off.
  • Pre-existing ADR-0019 violation (still open as of 2026-06-27): the bespoke Perl projection gap_record_from_perl_preview_finding (gap_decision_ledger.rs:756, read at :424) and the bespoke perl_preview_card renderer (crates/ripr/src/output/perl_preview_card.rs, called from github.rs:99 and human/sections.rs:143) predate ADR 0019 and are still wired into production output on main. They are dormant only because they set agent_packet ineligible + receipt_command: None (failing shared validator gates #1/#6). PR 16 (D16) MUST delete or formally scope them down before the shared-validator path goes live — see Blocking conditions.

Four corrections before productionizing

  1. Shared GapRecord authority. Do not merely remove #[cfg(test)] from PerlStrictActionability. Perl must project into GapRecord via perl_gap_record_for(), pass validate_agent_gap_record_packet, reuse shared edit-surface/render helpers, and carry validator_parity_perl_* tests. The Perl-local model decides eligibility; only the shared validator flips repair_packet_ready.

  2. Concrete discriminator. Stop emitting generic enum labels. The producer must emit concrete facts ($amount == $threshold, returned status changed from pending to paid, exception class/message InvalidAmount); RIPR aligns the changed observable with the assertion's observed sink. A strong assertion somewhere in the same test is not enough.

  3. Relation gating by reason. Restrict actionability by relation kind: direct_owner_call/proven helper-call chain eligible; package_reference/ test-name match/file proximity advisory-only; unknown a limitation. Every related test exposes relation_reason and relation_confidence (Perl-local model + thread into existing RelatedTestGrip; no shared-contract change this campaign).

  4. Typed runner commands. Replace positional matching with a structural model (runner, flags, test targets, working dir, preconditions, scope, confidence). RIPR generates the receipt command; the producer does not.

Phases (each PR one scoped slice)

PRPhaseRepoSliceLanded
1Aripr-swarmRefresh PROP-0018/SPEC-0064, record landed work, add Perl scaffold — blocked on live fact producer support-tier row, create tracker.#1413
2Aripr-swarmSplit the test-only perl.rs into perl/mod.rs + perl/tests.rs; zero behavior change, zero golden drift.#1417
3Aripr-swarmReplace Perl-local readiness authority with perl_gap_record_for() + shared GapRecord validation + validator_parity_perl_* tests. Public projection stays disabled.#1415
4Bperl-lspperllsp ripr-facts command parsing, capability reporting, canonical JSON writer, valid unavailable packets. No LSP server, no Perl execution.
5Bperl-lspExport files, owners, changes, source digests, ranges, provenance, packet fingerprint, diff identity.
6Bperl-lspExport Test::More/Test2/Test::Exception/Test::Fatal test + oracle facts.
7Bperl-lspExport relations with reason/confidence, concrete changed-observable + discriminator facts, oracle-observed-sink facts.
8Bperl-lspExport dynamic boundaries, limitations, typed verify-command candidates, deterministic goldens, schema-capability tests.
9Cripr-swarm--perl-facts PATH + productionize packet parsing with schema/size/uniqueness/referential-integrity/path/fingerprint/source-digest/root/diff-coherence checks.#1422, #1434, #1448
10Cripr-swarmlanguage_runs[] status output (complete/partial/unavailable/invalid). Missing Perl facts must not abort valid Rust/Python/TS output.#1418
11Cripr-swarmProduction PerlAdapter, .pm/.pl/.t/.psgi routing, packet→Finding/limitation conversion.#1426, #1431, #1432
12Cripr-swarmConcrete discriminator + sink alignment + strict relation gating. Heuristic-only relations and generic discriminators cannot project a GapRecord.#1428, #1451, #1449
13Cripr-swarmTyped prove/yath/carton exec prove/dzil command validation incl. -l/-v flags. RIPR generates the receipt command.#1421
14Dripr-swarmManaged producer mode: [perl] producer = "perllsp" / --perl-producer; timeout, executable override, version/schema capability check, cache location, stderr diagnostics. No silent invocation unless configured.#1435
15Dripr-swarmripr doctor Perl upgrade: project markers, producer availability/version, schema compatibility, detected framework, runner availability, exact first command.#1436
16Dripr-swarmProject validated Perl GapRecords as public repair packets across human/JSON/Markdown/SARIF/GitHub/gap-ledger via shared renderers. Gates/badges/RIPR Zero stay false.— (open; ADR-0019 blocker)
17Dripr-swarmBounded agent packets + PR/CI/LSP/swarm advisory projection. Only the selected test file is editable; production files forbidden.
18Dripr-swarmPerl before/after snapshots + outcome receipts keyed by canonical gap ID + producer packet fingerprint.

Landed work beyond the 18-slice spine

The 18-slice table predates the consumer-side contract freeze and the mapper- integrity hotfix wave. These landed after the plan was authored and are recorded here for tracker completeness:

  • #1433 (E1) — CPAN-style three-outcome alpha fixture (fixtures/perl_cpan_alpha/).
  • #1447 (H1) — mapping-integrity hotfix for packet_to_findings: related_test.file routed through packet-owned helpers; the test file is read via test.file_id, with test-specific verify commands, real test lines, and relation reason/confidence. Avoids canonical gaps from generic discriminators.
  • #1448 — boundary check made ordering-independent: the mapper checks all related evidence, not just .first(), so a boundary on a later related test file still blocks. perl_relation_to_domain refactored.
  • #1449 — corrected a false-green test introduced by #1448; proves the ordering test fails on the buggy .first() behavior and passes on .any().
  • #1450 (contract freeze step 2) — consumer-side contract freeze: accepts Test2::V1 and the frozen ChangeFact/OracleFact fields (changed_observable, missing_discriminator, observed_sink, expected_expression).
  • #1451 (H2) — already-observed classification via sink alignment: a Perl change classifies as Exposed only when a direct owner call links a strong exact oracle whose observed_sink aligns to the change's changed_observable; owner-target identity alone is explicitly not enough.
  • perl-lsp-swarm #3104 — producer-side contract freeze: schema-drift fix, Test2::V1 added, nullable changed_observable/missing_discriminator and observed_sink/expected_expression fields. Parser-backed Test2 facts are explicitly left for a later step (still emits null when fields are not derived).

Alpha producer scope (deliberately narrow start)

lib/**/*.pm
t/**/*.t

Test::More
Test2::V0
Test::Exception / Test::Fatal

predicate boundary
exact return
exception path

Scripts, fields, output/warnings, Moose/Moo synthesis, Carton, Dist::Zilla land only when each passes the same fixture + dogfood gates. Existing vocabulary can remain broader than the first release claim.

End-to-end alpha fixture (release-blocking)

Real CPAN-style project: Makefile.PL + lib/Pricing.pm + t/pricing.t, proving all three outcomes:

  • Actionableok(calculate_discount(100)); — a changed equality boundary yields a bounded recommendation for an exact boundary assertion.
  • Already observedis(calculate_discount(100), 10, 'threshold equality'); — no repair packet emitted.
  • Limitedmy $method = $config->{method}; $obj->$method(); — relation visible but dynamic dispatch yields a named limitation and no packet.

The fixture landed (#1433); the fixture-scoped two-binary proof (real perl-ripr-facts compatible output consumed end-to-end) landed in #1491 and turns the consumer from scaffold into a working preview. Committed expected packets remain regression fixtures, not producer proof.

Release gates (usable alpha)

Contract & safety (mechanically enforced):

  • 100% pass on packet schema, referential-integrity, path-safety, stale-digest, partial-packet, and dynamic-boundary fixtures.
  • Zero public repair packets from heuristic-only relations, generic discriminators, low/unknown confidence, partial packets, or unsupported dynamics — enforced by the Perl must_not_emit_repair_packet evidence-promotion-honesty corpus guard.
  • Validator parity demonstrates Perl uses the same shared packet authority as Rust/TypeScript/Python (PR 3 validator_parity_perl_* unit tests + cross-language corpus).
  • lang-perl feature-gated code path exercised in CI (PR 11 matrix job).

Real-world evidence (human-judgment, recorded in PR 18; the checked perl-real-repo-evals corpus starts as producer-dependent launchpoints and does not by itself satisfy alpha promotion):

  • ≥5 materially different Perl repositories; ≥20 human-reviewed candidate routes.
  • top-1 repair-card precision ≥ 80%; verify-command validity ≥ 90%; false-actionable rate ≤ 5%; zero severe false-actionables permitting production edits; ≥5 before/after receipts with ≥3 improved/resolved.

The feature is labelled "usable alpha" only when both the mechanical gates pass in CI and the human-judgment thresholds are documented as met in PR 18's description.

Alpha release claim

Perl repair routing usable alpha: opt-in static analysis for selected CPAN-style Test::More/Test2/Test::Exception/Test::Fatal workflows, powered by deterministic perl-lsp fact packets. RIPR can identify selected changed owners, related tests, concrete missing discriminators, bounded test-only repairs, verify commands, and before/after receipts. Dynamic and unsupported Perl fails closed into named limitations.

Explicit non-claims: no general Perl correctness proof; no coverage/mutation adequacy; no automatic test execution by default; no generated tests; no source edits; no arbitrary custom-helper understanding; no default gate/badge/baseline/ RIPR Zero authority.

Non-goals

  • stable support tier.
  • General Perl correctness or coverage adequacy.
  • Auto-test-execution by default, generated tests, or source edits.
  • Custom-helper understanding beyond the named frameworks.
  • Reconciling the FNV-1a gap-id scheme (deferred; lands before IDs become public receipt keys — receipt keys are established in PR 18, so the reconciliation lands before or with PR 18).

Dependencies

  • Phase A is unblocked. PR 1 (docs) and PR 2 (split) are independent; PR 3 (GapRecord projection) is sequenced after PR 2 for review flow but does NOT hard-depend on it — perl_gap_record_for lives in output/ and reads the public Finding domain surface + perl_* evidence keys, none of which the split changes.
  • Phase B (producer, perl-lsp repo) depends on Phase A PR 1 (frozen schema/plan) but can otherwise proceed in parallel with PRs 2-3.
  • Phase C depends on Phase A PR 3 (shared GapRecord projection) AND Phase B PR 8 (real packets to consume). Within Phase C: PR 9 (ingestion) → PR 11 (adapter); PR 10 (language_runs) independent; PR 12 (discriminator/relations) needs PR 11
    • PR 7 (producer facts); PR 13 (typed commands) depends on PR 11.
  • Phase D depends on Phase C complete. Within Phase D: PR 14 (producer mode) → PR 15 (doctor); PR 16 (public projection) needs PR 14 + PR 12; PR 17 (agent packets) needs PR 16; PR 18 (receipts) needs PR 16.

Blocking conditions

  • Any output-shape change to perl_preview_card.v1 or GapRecord requires a full golden re-bless in the same PR (single-writer-collision awareness).
  • Any flip of a gate/badge/RIPR Zero authority flag to true (out of alpha scope; only repair_packet_ready flips, and only via the shared validator).
  • ADR-0019 parallel-renderer decommissioning (PR 16, blocker, still open as of 2026-06-27): the pre-existing bespoke Perl projection gap_record_from_perl_preview_finding (gap_decision_ledger.rs:756, read at :424) and the bespoke perl_preview_card renderer (perl_preview_card.rs) are still wired into production output on main (github.rs:99, human/sections.rs:143). They predate ADR 0019 and are currently dormant only because they set agent_packet ineligible + receipt_command: None. PR 16 MUST delete or formally scope them down before the shared-validator path goes live, or the campaign creates the exact parallel-renderer drift surface ADR 0019 line 83-86 forbids.
  • lang-perl added to default features is out of scope for this campaign (not a timer that expires when PR 14 lands). PR 14 makes default-inclusion considerable; the actual flip is a separate decision tracked elsewhere.
  • Spec status flip of SPEC-0064 / PROP-0018 / ADR-0018 / ADR-0019 before Phase C completes.

Review policy

  • Each PR follows docs/SCOPED_PR_CONTRACT.md.
  • Phase A PR 1 (docs) is stackable. PR 2 (split) is stackable = false (large mechanical diff; needs independent review). PR 3 (GapRecord) is stackable = false (architectural).
  • Phase B/C/D production-behavior PRs are all stackable = false; each needs a failing fixture that passes only after the change.
  • Cardinal-sin seam: the repair_packet_ready flip must route through validate_agent_gap_record_packet. A Perl-local flip is the forbidden pattern.
  • No merge on self-report — verify the artifact by running the binary.

Commands (non-exhaustive; each PR's issue carries its specific gate set):

cargo xtask check-pr
cargo xtask module-health         # PR 2 proof: perl/ no longer over threshold
cargo xtask goldens check         # PR 2 proof: zero golden drift
cargo xtask check-fixture-contracts
cargo xtask check-evidence-promotion-honesty
cargo xtask check-static-language
cargo xtask check-no-panic-family
cargo xtask check-public-api
cargo xtask check-output-contracts
cargo xtask check-architecture
cargo xtask check-spec-format
cargo xtask check-doc-index
cargo fmt --check
cargo check --workspace --all-targets
cargo test --workspace
cargo clippy --workspace --all-targets -- -D warnings
# perl-lsp side (Phase B): cargo test -p perl-lsp-rs-core, cargo test -p perl-workspace
# alpha gate (Phase D PR 18): the CPAN-style end-to-end fixture proves all three outcomes

Campaign 32: Rust Evidence-Bound Repair Trust and Adoption

Campaign ID: rust-one-shot-evidence-to-repair

Status: active

Tracker: RIPR-PLAN-0062 · .ripr/goals/active.toml · issues #1423, #1424, #1425, #1427, #1440

The completed 0.9.0 release made Campaign 29's post-release activation gate obsolete. The current crate is 0.10.0, and the accepted targeted-rerun contract is now shipped infrastructure rather than the long-range destination. This campaign establishes trust in one exact, safe, test-only repair and current before/after receipt on real Rust work while keeping unsupported analysis explicitly limited.

The queue preserves the shipped bounded-output, canonical-identity, gate-route, targeted-mutation, and targeted-rerun contracts. Remaining work is the authorized real CallPresence evidence packet and a receipt-backed route-quality corpus across at least three Rust repositories; synthetic fixtures remain separate from adoption evidence.

Work itemStatusSummary
control-plane/cargo-allow-spec-system-adoptiondoneAdd advisory cargo-allow profile/ledger and doctor, audit, and worklist evidence without a second active goal.
control-plane/rust-one-shot-goaldoneReplace the stale release-era active manifest and execution plan with Campaign 32.
control-plane/cargo-allow-active-goal-dialectblockedBlocked on cargo-allow #2119 or a separately approved RIPR manifest migration.
output/bounded-start-heredone#1489 merged: bounded human output and human-full are on main.
docs/first-screen-agent-loopdone#1487 merged: the README first screen now describes the shipped bounded repair loop.
review/card-oracle-projectiondone#1483 merged with explicit representative-oracle semantics.
review/canonical-working-set-iddone#1505 merged: working-set cards now carry domain-supplied canonical gap identity.
gate/exact-repair-routedoneStructural route shipped: policy-eligible decisions expose the exact seam, missing discriminator, focused test intent, verify/receipt commands, and producer-owned inspection route without artifact archaeology. Real CallPresence producer eligibility remains a separate fail-closed follow-up.
gate/concrete-targeted-mutationdone#1545 merged: PR-evidence and impacted-evidence now carry a bounded producer-owned predicate/operator candidate and command, or an explicit no-safe-candidate limitation; mutation execution remains opt-in.
analysis/call-presence-gate-producerblocked#1543 remains blocked on an authorized real/current-repo CallPresence receipt proving an unambiguous caller/observer route; docs/handoffs/2026-07-12-call-presence-evidence-packet.md records why synthetic positive tests and stale bounded scans do not qualify; helper-only, dynamic, method-string, and ambiguous cases stay named limitations.
analysis/field-constant-observationdone#1511 merged: safe direct field assignments and named-constant boundaries are credited with conservative invalidation and limitation guards.
analysis/constructor-field-observationdone#1515 merged: safe same-crate constructor and exact-field observers are credited while same-name and unlinked-alias ambiguity stays fail-closed.
perf/targeted-rerundoneAccepted RIPR-SPEC-0123 is shipped as regression-protected infrastructure: canonical-gap and changed-test selection, before/after movement, cache and invalidation disclosure, input fingerprints, graph provenance, selector-scoped parity, and the registered benchmark.
perf/rerun-gap-selectiondone#1524 treats one canonical gap as a behavioral-debt group, deduplicates anchored scopes, preserves partial success, and names stale or conflicting route data.
perf/rerun-before-movementdone#1527 adds explicit before/after movement receipts with typed seam continuity and honest indeterminate states.
perf/rerun-cache-disclosuredone#1529 discloses producer-owned file-fact cache reuse and recomputation without inventing unavailable whole-analysis invalidation reasons.
perf/rerun-classification-paritydone#1558 adds opt-in two-sided selector-scoped comparison against the typed full inventory; missing, unexpected, and differing seams fail closed with retained details.
perf/rerun-evidence-paritydoneTyped selected-scope route and oracle evidence parity is shipped and fails closed with retained mismatch details.
perf/rerun-invalidation-attributiondoneSelected-input fingerprints and explicit invalidation reasons are shipped for file, workspace, configuration, graph, and selector-ledger changes.
perf/rerun-benchmarkdoneThe registered current-main receipt records matched parity, 228 ms warm p50, 1,512 ms cold-full p50, and 6.63x speedup on the benchmark fixture.
perf/rerun-closeoutdoneSPEC-0123, plan, and issue #1424's completed closeout comment reconcile the targeted-rerun lane as complete infrastructure, with merged parity, invalidation, graph-provenance, benchmark, support-boundary, and remaining-limitation evidence.
perf/targeted-rerun-graph-provenancedone#1550 merged: receipts attribute local package/member and feature graph provenance, name unavailable external metadata, and fail parity closed on required graph mismatch without network inference.
dogfood/rust-route-quality-corpusactive#1560 has explicit authorization for the three internal adopting Rust repositories. The first real pilot audit is retained as explicit exclusions for timeouts, static limitations, false actionability, and invalid test paths; none enter the denominator. The schema, validator, and denominator-preserving scorecard remain ready for the next six-attempt pilot. Corpus collection is independent of CallPresence closure.
dogfood/route-quality-closeoutblockedFinal closeout waits for the #1560 corpus threshold and #1543 CallPresence proof or durable limitation disposition; metrics/rust-repair-trust/corpus.json and cargo xtask rust-repair-trust-report preserve missing denominators as limited; keep synthetic fixtures separate and do not claim route-quality closure.

Hard boundaries: preview lanes remain preview; mutation execution stays explicit; there is no automatic test or consumer-source editing, default gate hardening, release/publish work, or claim beyond conservative static evidence. Every work item is one reviewable PR, a source-truth update, or a durable blocked report.

Campaign 33: CLI Finding Navigation Discoverability

Campaign ID: cli-finding-navigation-discoverability

Status: complete

Tracker: issues #2598, #2659, and #2679; PRs #2620 and #2681.

This campaign makes the default human ripr check output useful as an operator entry point. A finding now carries executable explain and context --at follow-up commands, and the follow-up route preserves the analysis scope, artifact inputs, and supported options needed to inspect the same finding. The production contract remains static and advisory.

Work itemStatusSummary
cli/finding-follow-up-guidancedone#2620 added finding-specific human guidance for explain and context --at, with quiet empty and fully suppressed output.
cli/scope-preserving-navigationdone#2681 closed #2659 by preserving scope in replay commands, accepting supported configuration and mode options, and adding executable CLI smoke coverage.
campaign/cli-finding-navigation-closeoutdoneThe closeout handoff records the final merged head, hosted proof, claim boundary, and inherited Clippy follow-up.

Non-goals: runtime mutation execution, adequacy or coverage claims, default CI blocking, release/publish changes, and repair-packet authority changes.

Campaign 34: Analyzer Honesty and Policy Visibility

Campaign ID: analyzer-honesty-and-policy-visibility

Status: complete

Tracker: issues #2698 and #2699; PRs #2702 and #2703.

This campaign makes two previously implicit limits visible without promoting static evidence into runtime or adequacy claims: policy scans cover the actual editor extension source languages, and repo/seam analysis discloses when the parser fell back to lexical facts, including on warm cache paths.

Work itemStatusSummary
policy/static-language-editor-surfacedone#2703 scans .ts, .js, .tsx, and .jsx editor sources, with focused xtask coverage.
analysis/lexical-fallback-disclosuredone#2702 records producer fallback provenance, preserves it through file and classified-seam caches/schema, and emits stable sorted disclosure without claiming runtime mutation or adequacy.
campaign/analyzer-honesty-closeoutdoneThe closeout handoff records merged heads, hosted proof, local proof boundaries, and follow-up disposition.

Non-goals: runtime mutation execution, test adequacy or coverage claims, release/publish changes, default blocking, and broad parser replacement.

Campaign 35: Operator Signal Integrity

Campaign ID: operator-signal-integrity

Status: complete

Tracker: issues #2675, #2599, and #2632; implementation PRs #2720, #2721, #2722; repair PR #2726.

This campaign keeps operator-facing signals faithful to the underlying evidence. Submodule pointer changes are disclosed as skipped content, gate failures surface their first actionable reason inline while retaining the full artifact, and GitHub annotations map the actual severity without downgrading a literal warning to a notice.

Work itemStatusSummary
diff/submodule-pointer-disclosuredone#2720 detects confined gitlink additions, deletions, and changes; forces short submodule diff output; and discloses that contents are not analyzed.
gate/inline-first-reasondone#2721 surfaces the first config, blocking-gap, or exception-policy reason while preserving the full gate report.
annotations/severity-level-mappingdone-with-repair#2722 added severity mapping; #2726 aligns the output with the source-of-truth all-warning policy and adds weak, literal warning, and configured info regressions.
campaign/operator-signal-closeoutdoneThe closeout handoff records final merge proof, issue disposition, claims, and the independent #2718 boundary.

Non-goals: LSP severity redesign (#2718), runtime mutation, adequacy or coverage claims, release/publish changes, default blocking, and broad output refactoring.

Campaign 36: Preview Projection Honesty

Campaign ID: preview-projection-honesty

Status: complete

Tracker: issues #2716, #2744, and follow-up #2764; PRs #2743, #2746, #2753, and #2757.

This campaign keeps preview output faithful when the producer has more than one configured TypeScript/Bun bridge profile. It also closes the JSON-order documentation drift without adding a dependency or making JSON byte order a consumer contract.

Work itemStatusSummary
output/json-order-contractdone#2743 documents semantic JSON object ordering and explicitly excludes exact-byte canonical artifacts.
output/multi-bun-profile-projectiondone#2753 retains every emitted Bun bridge profile across human, JSON, SARIF, and GitHub projections, with Blob plus copy_to_unshared regression coverage; the first producer profile remains the documented singular compatibility alias.
campaign/preview-projection-closeoutdone#2757's closeout handoff records merged heads, proof, claim boundaries, and follow-up disposition.

Non-goals: new Bun taxonomy or discovery, runtime Bun execution, mutation, coverage or adequacy claims, public repair-packet promotion, default blocking, release/publish changes, serde_json preserve_order, and broad refactoring.

Campaign 37: 0.11 Release Control Lens

Campaign ID: release-control-0-11

Status: historical / superseded

Tracker: issues #2766, #2767, #2768, and #2769, under the historical release authority #2379 and candidate manifest authority #1609. Superseded for the live 0.11.0 release train by the transaction-boundary live-head decision in docs/release-candidates/0.11.0-live-head-selection.json; these slices remain audit evidence and are not an active C/T publication path.

The campaign made the temporary 0.11 writer cutoff and merge-eligibility boundary explicit without restoring singleton active-goal authority. Its read-only release lens, execution-surface scope decision, supplemental denominator, and exact-candidate evidence remain audit records. The active sequence is the live-head authority reset, exact SWARM_PARENT pin, exact-head qualification, source preflight, history-preserving join, metadata, artifact proof, ship packet, authorized publication, and back-sync.

Work itemStatusSummary
control/release-lenslanded#2766 / PR #2773: fixture-backed cargo xtask release-control normalizes current-authority input, assigns closed PR dispositions, and fails closed on stale or incomplete evidence.
release/execution-scopelanded#2767 / PR #2788: accepted Outcome A is machine-readable as a complete candidate-only exclusion while development main remains unchanged.
release/supplemental-denominatorin progress#2768 / PR #2790 and the landed #2868 snapshot establish the 234-record captured range through c30a2683; the fresh #2831 B slice adds GitHub-backed typed capture/import, fixed provisional review cutoff fcbb30a7, optional #2766/#2871 claim references, and fail-closed candidate_tree_state_pending rows. All 234 records remain operator decisions until #2832 adjudication; no blanket post-cutoff exclusion or candidate qualification is claimed.
release/exact-candidate-bundlesupersededHistorical #2769/#1609 C/T qualification path; the active release qualifies the exact transaction-boundary live swarm head.
campaign/release-control-closeoutplannedReconcile live state, retain proof and claim boundaries, clean campaign-created artifacts, and capture successor work.

The durable sequence and first-slice acceptance criteria are in plans/release-control-0-11/implementation-plan.md, and the first-slice output contract is RIPR-SPEC-0144. The execution-scope contract is RIPR-SPEC-0145. The supplemental denominator contract is RIPR-SPEC-0146.