Implementation Plan
July 29, 2026 · View on GitHub
This is the working PR checklist for building ripr incrementally. It is more
operational than the roadmap: each entry should become a scoped PR
with clear artifacts, tests, documentation updates, and gates.
The checklist is grouped into implementation campaigns. A campaign may work through multiple work items, but each work item should follow the scoped PR contract.
This file is one layer of the repo's centralized, agent-neutral tracking
model. The full layering — proposals (why), specs (what), ADRs (durable
decisions), this plan (work queue), campaign ledger, active manifest, and
closeout handoffs — is documented in the
repo tracking model. Reach for a proposal in
docs/proposals/ before a spec when the change spans more
than one behavior contract or touches repo shape.
Campaign Map
| Campaign | Objective | Work items |
|---|---|---|
| Rust One-Shot Evidence-to-Repair Product Closure (32) | Make RIPR's Rust PR workflow lead from one changed behavior to one exact test-only repair and a receipt, without artifact archaeology or known-ineffective routing. | Active: RIPR-PLAN-0062 and .ripr/goals/active.toml select the campaign; cargo-allow spec-system is advisory while active-goal dialect support is blocked on cargo-allow #2119. |
| CLI Finding Navigation Discoverability (33) | Make the default human check output lead directly to executable, scope-preserving explain and context follow-up commands. | Complete: #2598/#2620 and #2659/#2681 landed the navigation route, governed golden updates, replay coverage, and the closeout handoff. Inherited all-target Clippy debt remains isolated in #2679. |
| Analyzer Honesty and Policy Visibility (34) | Make analyzer and policy limitations visible instead of silently skipped or over-credited, while preserving conservative advisory semantics. | Complete: #2698/#2702 disclose parser-to-lexical fallback through repo and seam-inventory cache paths; #2699/#2703 make the static-language policy scan the editor's .ts, .js, .tsx, and .jsx sources; the campaign closeout records the proof and claim boundary. |
| Operator Signal Integrity (35) | Ensure operator-facing disclosures, gate failures, and GitHub annotations preserve the actual limitation or severity instead of silently disappearing, being downgraded, or hiding the first actionable reason. | Complete: #2675/#2720 submodule-pointer disclosure, #2599/#2721 inline gate reasons, #2632/#2722 annotation mapping, and repair #2726 for the source-of-truth all-warning contract. #2718 merged independently and remains outside this campaign. See the closeout handoff. |
| Agentic DevEx Foundation | Make the repo safe for Codex Goals and human review. | policy/architecture-guard, output/output-contract-check, docs/codex-goals-campaigns, fixtures/runner-comparison-v1, fixtures/first-two-goldens, testing/test-oracle-report, dogfood/static-self-check |
| Syntax-Backed Analyzer Foundation | Move the analyzer from lexical facts to syntax-backed facts. | analysis/file-facts-model, analysis/syntax-adapter-mvp, design/rust-syntax-substrate, analysis/ast-test-oracle-extraction, analysis/ast-probe-ownership, analysis/ast-probe-generation |
| Evidence Quality | Improve oracle strength, local flow, activation values, output evidence, and stop reasons. | output/unknown-stop-reason-invariant, analysis/oracle-strength-v2, analysis/local-delta-flow-v1, analysis/activation-value-modeling-v1, output/evidence-first-output, fixtures/negative-metamorphic-baseline |
| Test Efficiency and Vacuity Signals (4A) | Make low-discriminator, smoke-only, broad-oracle, opaque, circular, and duplicate test signals visible as advisory evidence; ship ripr and ripr+ badge artifacts. | test-efficiency/test-fact-ledger, test-efficiency/vacuous-signal-v1, test-efficiency/duplicate-discriminator-v1, test-efficiency/report-and-metrics, badge/ripr-count-v1, badge/ripr-plus-count-v1, badge/repo-scope-artifacts, badge/publish-main-endpoint |
| Repo Seam Inventory and Test Grip (4B) | Inventory behavior seams, classify test-grip per seam, and turn actionable gaps into editor diagnostics and agent-ready packets. | spec/repo-seam-inventory, analysis/repo-seam-model-v1, analysis/repo-seam-inventory-v1, analysis/test-grip-evidence-v1, analysis/repo-ripr-classification-v1, output/repo-exposure-report-v1, lsp/repo-seam-diagnostics-v1, lsp/seam-evidence-hover-v1, context/agent-seam-packets-v1, docs/agent-dispatch-workflow-v1 |
| Seam Evidence Usability and Precision (5A) | Make repo seam evidence fast, precise, and directly actionable for developers and coding agents. | Complete: #255, #310, #313, #314, #315, #316, #327, and campaign/seam-evidence-usability-closeout. |
| Operationalization (5B) | Govern analyzer behavior with repository config, integrate SARIF/CI policy modes, and remap badges onto seam-native counts. | Complete: config/ripr-config-v1, ci/sarif-ci-policy, badge/seam-native-count-mapping, and campaign/operationalization-closeout. |
| Module SRP Refactoring (6) | Refactor internal modules under crates/ripr/src/ so each module has one product responsibility, without splitting the package. | Complete: #347, the Campaign 6 refactor chain through #405, and campaign/modularization-closeout. |
| Defaults-First Operator Adoption (7) | Make a clean install useful through conservative defaults, one operator cockpit, CI artifacts, editor install docs, examples, and install/release proof. | Complete: #409 through #417 plus campaign/defaults-first-closeout. |
| Runtime Calibration Fixture Expansion (8) | Expand supplied-runtime calibration fixtures without making RIPR run mutation tests. | Complete: #420 plus campaign/runtime-calibration-closeout. |
| Hot Sidecar Latency Proof (9) | Measure current cache and saved-workspace editor refresh behavior before changing warm-path reuse. | Complete: latency reporting, warm-path reuse, bounded ripr pilot, first-screen clarity, evidence progress tracing, hot-path indexes, and campaign/hot-sidecar-latency-closeout. |
| Editor Agent Integration (10) | Make the saved-workspace editor loop and the agent CLI loop line up from diagnostic to evidence, packet/brief, focused test, verify, receipt, cockpit, CI, and install proof. | Complete: campaign/editor-agent-integration-closeout. |
| LLM Work Loop (11) | Make the completed editor-agent loop stateful, deterministic, and useful to LLM agents under review pressure. | Complete: status, command templates, workflow manifests, receipt provenance, next-action guidance, reviewer summary, fixture matrix, CI work packets, operator guide, and campaign/llm-work-loop-closeout. |
| First-Hour UX (12) | Make new LSP-first and CI-first users successful without learning RIPR's internal report topology. | Complete: editor status, intent-titled actions, advisory CI summary, workflow smoke fixture, user-type docs, and campaign/first-hour-ux-closeout. |
| PR Review Guidance (13) | Project existing RIPR evidence into bounded pull-request review guidance without making CI blocking or turning RIPR into a free-form reviewer. | Complete: renderer, generated CI, fixtures, docs, and campaign/pr-review-guidance-closeout. |
| Recommendation Calibration (14) | Measure whether top CI, LSP, and PR recommendations are clear, correctly placed, low-noise, and correlated with better static evidence after one focused test. | Complete: spec, corpus, receipts, report, guide, and campaign/recommendation-calibration-closeout. |
| Calibrated Gate Policy (15) | Define optional calibrated gates over existing PR-time evidence without changing advisory defaults or blurring static/runtime evidence. | Complete: spec, evaluator, fixtures, generated CI opt-in wiring, evidence-preserving CI behavior, calibrated gate guide, and campaign/calibrated-gate-closeout. |
| Gate Adoption UX (16) | Make optional calibrated gate adoption safe and obvious for real teams without changing advisory defaults. | Complete: generated-CI examples, waiver workflows, baseline guidance, CI gate summary polish, dogfood receipts, blocking-readiness guidance, and campaign/gate-adoption-ux-closeout. |
| RIPR Zero Adoption (17) | Turn baselines into burn-down ledgers with create, diff, and shrink-only refresh commands while keeping generated CI advisory by default. | Complete: spec, baseline create, baseline diff, shrink-only update, generated CI baseline-delta artifacts, baseline ledger workflow guide, and campaign/ripr-zero-adoption-closeout. |
| RIPR Zero Reporting (18) | Turn reviewed baselines and debt deltas into repo-level RIPR 0 status, stale-debt, trend, and repair-area reporting while preserving advisory defaults. | Complete: spec, baseline metadata, status report, generated CI summary, user workflow docs, and campaign/ripr-zero-reporting-closeout. |
| PR Evidence Ledger (19) | Turn per-PR RIPR evidence into an adoption ledger for movement history, waiver aging, baseline burn-down, repair receipts, and coverage/grip frontier signals while preserving advisory defaults. | Complete: spec, producer, generated-CI projection, coverage/grip frontier report, user workflow docs, and campaign/pr-evidence-ledger-closeout. |
| Test-Oracle Assistant Proof (20) | Prove the full PR-time loop from changed Rust behavior to static evidence, PR/editor guidance, focused-test handoff, verification, receipt, and advisory CI/ledger projection. | Complete: spec, canonical fixture, dogfood receipt, user workflow docs, and campaign/test-oracle-assistant-proof-closeout. |
| Test-Oracle Assistant Report Producer (21) | Turn the proved assistant loop into a public read-only JSON/Markdown report producer and optional advisory CI projection. | Complete: report producer, generated-CI projection, proof-report docs, and campaign/test-oracle-assistant-report-closeout. |
| First Useful Action (22) | Compress existing editor, PR, ledger, proof, receipt, optional gate, coverage/grip, and staleness evidence into one advisory next test action. | Complete: RIPR-SPEC-0020 defines the report contract, the routing corpus is pinned, ripr first-action writes the read-only advisory report, generated CI surfaces it as advisory summary/artifact content, VS Code status/Show Status project an existing report, workflow docs explain developer, reviewer, and agent use, dogfood receipts are checked, and campaign/first-useful-action-closeout records the final audit. |
| Assistant Loop Health (23) | Summarize proof completeness, missing inputs, static evidence movement, recurring warnings, and next repair queues across one or more assistant proof reports. | Complete: RIPR-SPEC-0022 defines the report contract, the assistant-loop-health fixture corpus is pinned, ripr assistant-loop health writes advisory JSON/Markdown from explicit proof inputs, generated GitHub CI uploads and summarizes health artifacts when proof artifacts exist, docs/ASSISTANT_LOOP_HEALTH_WORKFLOW.md explains maintainer and agent use, and campaign/assistant-loop-health-closeout records the final audit. |
| PR Review Front Panel (24) | Compose existing PR guidance, first useful action, assistant proof, assistant-loop health, PR evidence ledger, baseline delta, gate decision, receipts, calibration, and optional coverage/grip frontier artifacts into one advisory generated-CI first screen. | Complete: report contract, fixture corpus, ripr pr-review front-panel, generated-CI projection, workflow docs, dogfood receipts, and closeout audit are in place. |
| Report Packet Index (25) | Make the uploaded ripr-reports packet navigable as a reviewer-first index over explicit existing artifacts. | Complete: report contract, fixture corpus, ripr reports index, generated-CI projection, workflow docs, dogfood receipts, and closeout audit are in place. |
| PR Inline Comment Publisher (26) | Make optional durable PR comments safe and explicit by planning, capping, deduplicating, and publishing only changed-line review-comments entries when configured. | Complete: spec, fixture corpus, read-only publish plan, generated-CI opt-in wiring, workflow docs, dogfood receipts, and closeout audit are in place. |
| Language Adapter Preview (27) | Introduce a language-neutral analysis adapter boundary, keep Rust as the reference adapter, and add syntax-first TypeScript and Python preview adapters that feed the existing RIPR domain, output, LSP, agent, and Lane 4 surfaces without changing Rust behavior or default CI blocking. | Complete: RIPR-PROP-0001 records the adapter design intent, RIPR-SPEC-0026 pins the adapter contract, RIPR-SPEC-0027 pins the TypeScript preview static-fact contract, and RIPR-SPEC-0028 pins the Python preview static-fact contract. TypeScript and Python preview facts are fixture-backed; Lane 3 editor routing landed from RIPR-PROP-0003, RIPR-SPEC-0036, RIPR-SPEC-0037, ADR-0011, and plans/campaign-27/lane3-editor-preview-routing.md; generated CI language grouping projects configured preview evidence as advisory-only groups while keeping Rust defaults and gate authority unchanged; docs/LANGUAGE_ADAPTER_PREVIEW.md documents the adoption and rollback path; cargo xtask dogfood checks TypeScript/Python preview receipts for labels, static limits, disabled-language behavior, and no cross-language related-test routing; the closeout audit records the preview/advisory boundary. |
| TypeScript Enablement | Make the completed TypeScript/JavaScript preview surface more useful, precise, repair-card-shaped, and promotion-ready without reopening preview completion or changing advisory authority. | Active successor lane: TypeScript Enablement records that preview completion is closed and future TypeScript work should focus on weak-oracle guidance, false-actionable audits, narrow mock/error payload support, bounded method receiver relation follow-ons, module initializer guidance, repair-card projection, dogfood, route quality, and an explicit remain-preview or promotion decision. |
| Python Repair Routing (28) | Turn changed Python behavior into bounded test-repair work with project detection, repair cards, verify commands, agent packets, and outcome receipts while keeping broader Python static facts preview/advisory outside the scoped repair-routing support tier. | Active: RIPR-PROP-0017 and the Python repair-routing plan define the staged lane. The current slice makes Python before/after receipt evidence and noise-control fixtures fixture-backed: repair cards already project to GapRecords, agent packets, queue items, verify commands, and receipt commands; ripr swarm ingest has a Python preview fixture for a test-only closed attempt; first_successful_pr/python-preview-gap pins ripr outcome JSON/Markdown receipts where the canonical Python gap closes, stays unchanged, opens, strengthens, or weakens across check-output snapshots; first_successful_pr/python-return-gap, python-exception-gap, python-field-gap, and python-output-gap pin non-boundary closure from broad to exact evidence; generated Python diffs such as *_pb2.py, dynamic import calls such as importlib.import_module(...), decorator indirection, monkeypatch/module patches, unresolved fixtures, property-based tests, opaque custom helpers, and metaclass declarations are pinned as fail-closed limitations or exclusions rather than repair-ready gaps; same-line returned-dict return/field/string signals collapse to one user-facing canonical gap; fixtures/real-repair-attempts/corpus.json records a repo-local Python packet that edits only tests, passes verify evidence, and closes the canonical Python gap through an outcome receipt; fixtures/python-real-repo-evals/corpus.json records tiny controlled pytest, no-config pyproject project detection, normal pytest app, external-repo-style src/ package layout, CLI/output pytest, API status-code, mixed Rust/Python, and decorated route evals with Python repair cards, focused verify passes, closed outcome receipts, plus no-related-test, already-observed, and heuristic-only ordinary no-action evals with no repair card, no packet, and no receipt movement; the application-useful HTTP, CLI/output, parameterized boundary, existing-test strengthening, and model-field slices are fixture-backed; the scoped support-tier review promotes only the Python repair-routing loop to usable alpha; broader Python static facts remain preview/advisory, and dogfood/python-stability-evals-v1 is the next checkpoint before any stable-support consideration. |
| Policy Readiness and Preview Evidence Governance (Lane 2 tracker) | Make policy decisions auditable across stable Rust evidence and preview-language evidence without changing advisory defaults. | Complete: tracker #755, readiness reporting, preview evidence policy, waiver aging, suppression health, baseline refresh guardrails, exception ledger convergence, blocking guidance, advisory CI projection, and closeout audit are in place. |
| Policy Operations and Promotion Readiness (Lane 2 tracker) | Make policy adoption operational with current safe ceiling, next safe action, blockers to stricter modes, policy history, and read-only promotion packets. | Complete: Policy operations and .ripr/goals/lane2-policy-operations.toml define the closed focused tracker. RIPR-SPEC-0039 defines the policy operations report contract, ripr policy operations writes the first operator packet, RIPR-SPEC-0041 defines policy history trends, ripr policy history writes the advisory trend packet, RIPR-SPEC-0042 defines manual-review promotion packets, ripr policy promote --to ... writes those packets, RIPR-SPEC-0044 defines default-blocked preview evidence promotion packets, ripr policy preview-promote writes preview evidence promotion packets, Policy operations workflow documents maintainer use, generated CI surfaces operations, history, promotion, and configured preview-promotion artifacts as advisory-only packets, and closeout audit records the final Lane 2 boundary. |
| Generated Evidence Discipline (repo operations lane) | Make generated evidence, authored truth, deterministic repair, judgment-required decisions, and review receipts mechanically distinct for agentic development. | Complete: badge endpoint ownership, generated-clean checks, worktree doctor, PR triage, PR status, spec numbering, campaign checks, command mutability catalog, existing receipts/critic surfaces, suggested fixes, contributor docs, pr-ready, repo cockpit, repo-ops report indexing, merge-watch policy, queue disposition, and closeout audits / Repo-Ops UX cockpit closeout are in place. |
| Evidence Quality Leadership (Lane 1 tracker) | Make analyzer evidence self-aware about quality, proof, calibration, unknowns, and next repair. | Complete: scorecard, benchmark corpus, static limitation taxonomy, oracle semantics audit fix, runtime-fixtures-v3, evidence-quality trend, capability metadata, traceability, and closeout audit are in place. Future Lane 1 work opens only for a new measured evidence class or contract change. |
| User-Visible Output Evidence (Lane 1 tracker) | Make changed presentation/help/report/table text one evidence-quality-aware action, no-action state, or static limitation. | Complete: RIPR-PROP-0005, RIPR-SPEC-0043, RIPR-SPEC-0045, and the lane tracker define the source-of-truth stack. Finding-alignment benchmarks are pinned, evidence_record carries additive raw_findings[], canonical_item, and nullable presentation_text fields, ripr check --json groups supported presentation-text declaration plus adjacent literal raw findings into one canonical item, fixture-backed visibility/observer/actionability states are implemented for help/report/internal text, scorecard/trend output reports raw-to-canonical and presentation-text quality counts, the downstream consumer handoff is merged, and the closeout audit records proof, remaining unknowns, and downstream boundaries. |
| Finding Alignment Burn-Down (Lane 1 tracker) | Keep the raw-finding to canonical-item to actionable-gap model useful as new gaps are measured. | Complete: Lane 1 Finding Alignment Burn-Down, the implementation plan, and the closeout handoff record the issue-backed queue, improved evidence classes, moved counts, remaining limits, and audit-driven next-class selection rule. |
| Value Resolution Audit Fixes (Lane 1 tracker) | Burn down one fixture-backed predicate_boundary / activation_value_unresolved sub-shape from current audit and scorecard proof. | Complete: Lane 1 Value Resolution Audit Fixes, the implementation plan, and the closeout handoff record the issue-backed queue, fixture-first selection, already-supported analyzer disposition, zero-movement audit delta, dogfood receipt, remaining limitations, and no selected successor. |
| Target-Affinity Owner-Call Tracing (Lane 1 follow-up) | Burn down measured activation_owner_call_absent_*_target_affinity routes by adding fixture-backed owner-call tracing while preserving advisory/static-limitation boundaries. | Active: analysis/call-presence-target-affinity-owner-call-tracing remains the top sampled work queue. The current scoped PR extends direct same-package multi-owner production-wrapper tracing to value-insensitive assertion-target affinity, same-file unit-test wrapper calls, crate-local module-alias wrapper calls, crate-local direct imported-owner calls, package-local explicit crate-qualified owner calls, and file-scope direct-imported indexed support-helper calls, and it keeps call-presence assertion-target matching on extracted callee names rather than argument/context tokens from full call expressions; bare/external aliases, test-local shadows, ambiguous imported owner names, cross-package crate-qualified paths, other-owner helper imports, block-local helper imports, other-target affinity, and bare qualified paths stay limited, predicate-boundary value checks stay excluded, and no observed values are invented. |
| Editor Evidence UX (future) | Make the saved-workspace LSP path feel like an editor-native test-intent cockpit from diagnostic to hover, related test, context packet, one test, verify, and receipt. | Complete as an explicit parallel Lane 3 closeout: contract audit, hover hardening, evidence-aware actions, context packet, protocol smoke, VS Code smoke, status/staleness, workflow docs, and closeout audit. |
| Editor First-Run and Repair Usability (Lane 3 tracker) | Make the existing editor cockpit self-orienting from setup diagnosis to one bounded repair packet, verify command, receipt visibility, and refresh. | Complete: RIPR-PROP-0008, RIPR-SPEC-0049, RIPR-SPEC-0050, ADR-0013, and the implementation plan define the closed Lane 3 stack. #1012 through #1040 added setup diagnosis, first-run/no-output smoke, receipt visibility, first-repair packets, first-run fixtures, user docs, dogfood receipts, and closeout proof. |
| Editor First-PR Bridge (Lane 3 tracker) | Connect the editor repair loop to the existing first-pr start-here packet without making Lane 3 a PR/CI producer. | Complete: RIPR-PROP-0010, RIPR-SPEC-0052, ADR-0014, and the implementation plan define the closed Lane 3 stack. #1098 through #1116 added first-pr packet validation, status projection, bounded actions, fixtures, VS Code smoke, workflow docs, and dogfood receipts; the closeout proof is recorded in the Editor First-PR Bridge closeout. |
| Start-Here Surface Convergence | Make PR/CI, CLI, editor handoffs, receipts, no-output states, preview promotion criteria, and dogfood receipts lead with the same canonical gap-to-repair unit. | Complete: RIPR-PROP-0011, RIPR-SPEC-0053, ADR-0015, the implementation plan, dogfood receipts, and the closeout audit are in place. The active manifest later selected and closed Finding Alignment Burn-Down and Value Resolution Audit Fixes; .ripr/goals/active.toml now records no_current_goal = true with no successor selected. |
| Editor Adoption Assurance (Lane 3 tracker) | Make first-use editor setup, compatibility, root selection, multi-root, receipt mismatch, and first-pr packet mismatch states safe and legible. | Complete: RIPR-PROP-0012, RIPR-SPEC-0054, ADR-0016, and the implementation plan define the closed Lane 3 adoption-assurance stack. Setup/root diagnosis, fixtures, VS Code smoke, install-to-first-pr docs, external-style dogfood, and closeout proof are in place. |
| Editor Actionable Gap Queue (Lane 3 tracker) | Project existing actionable-gap artifacts into the editor as a bounded local repair queue. | Complete: RIPR-PROP-0013, RIPR-SPEC-0055, ADR-0017, and the implementation plan define the closed stack. Validation, Show Status queue projection, Copy Current Repair Packet, Copy Repo Gap Map, fixtures, VS Code smoke, workflow docs, dogfood receipts, and closeout proof are in place. |
| Actionable Surface Translation | Make badge, PR, editor, swarm dry-run, and outcome/trend first screens translate existing actionable canonical gap evidence into the same repair-first user questions. | Complete: RIPR-PROP-0016, RIPR-SPEC-0059, RIPR-PLAN-0059, and the closeout handoff record the accepted source-of-truth stack, badge/PR/editor/swarm/outcome first-screen proof, advisory claim boundary, and no selected successor. |
| First Useful PR Loop Continuation | Make one changed Rust behavior become one clear repairable gap, one focused proof intent, one verification command, and one reviewer- and agent-readable receipt. | Complete: the goal-freshness guardrail, first-pr front door, one-screen recommendation contract, reviewer-native outcome, first-pr demo story, generated CI/VS Code/agent packet convergence, and closeout handoff are in place. .ripr/goals/active.toml now records no_current_goal = true with no successor selected. |
| Self-Hosted Routed Runner Proof | Prove the CX53/CX43 self-hosted routed Rust path for the active swarm trunk, or keep the runner image-readiness/visibility blocker explicit while hosted fallback remains healthy. | Complete: Self-hosted routed runner proof closeout records CX53/CX43 routed proof, #24/#34 issue-ledger updates, unchanged branch-protection boundary, and remaining non-goal follow-ups. |
| Lane 1 Real-Repo Trust Readiness | Make the evidence-to-repair foundation honest on large repositories, cross-language test suites, binding/FFI seams, and review-comment navigation. | Complete: Lane 1 Real-Repo Trust Readiness closeout records the post-0.8 issue-batch slices through #931, the no-0.8.0-tag claim boundary, and the remaining scalable-cache, cross-language oracle graph, and language-aware placement follow-ups. |
| Lane 1 Large-Repo Runtime Completeness | Make large-repo repo-exposure warm paths usable without representing limited or sampled input as full truth. | Complete: Lane 1 Large-Repo Runtime Completeness closeout records the #909 post-0.8 trust-debt PR chain through #935, including explicit large-cache skip state, sharded classified seam cache storage, cache-report shard summaries, and diff-scoped review-comments runtime. |
| Lane 1 Language-Aware Placement Navigation | Make suggested-test placement safe and useful for binding, FFI, and externally tested seams without turning unresolved external targets into repair packets. | Complete: Lane 1 Language-Aware Placement Navigation closeout records the #911 campaign chain through #941, the issue-state boundary, remaining #908/#910 cross-language oracle graph work, and no_current_goal = true. |
| Lane 1 Cross-Language Oracle Graph Readiness | Make cross-language oracle visibility explicit for Rust seams exercised by TypeScript, binding, or FFI surfaces without promoting preview evidence into public repair packets. | Folded into the active post-0.8 operating loop after #943 through #948 landed SPEC-0062, the graph corpus, TS discriminator witnesses, and binding-route witness behavior. The route-quality report adds readiness and evidence-quality scorecard summaries for complete advisory witnesses, missing discriminators, mention-only rows, bridge-unknown rows, and public packet exclusions; the Bun UB calibration report adds an operator-readable JSON/Markdown receipt for the calibrated TypeScript/Bun Blob corpus without public repair packets. A follow-up placement receipt correction makes configured missing shared/resizable discriminator rows name test/js/web/fetch/blob.test.ts as advisory TypeScript placement while keeping bridge-unknown, mention-only, and partial-oracle rows at not_applicable. #908/#910 remain open as broader cross-language follow-ups rather than completed generic oracle support. |
| Lane 1 Post-0.8 Evidence-To-Repair Operating Loop | Make RIPR useful on real large and mixed-language repos by routing safe repair packets and fail-closed limitation backlog items through receipts, outcomes, route quality, and user surfaces. | Complete: Lane 1 Post-0.8 Evidence-To-Repair Operating Loop closeout records live queue hygiene, #913 and #909/#912 disposition, source ripr release authority, the Bun UB calibration report slice, ripr/diff-first-changed-surface-mode, cross-language oracle fail-closed routing, language-aware target placement navigation, the bounded SPEC-0062 cross-language oracle graph, repair-packet guidance quality, attempt-ledger outcome hardening, real repair/analyzer-attempt dogfood, route-quality metrics, and surface canonical-state alignment. .ripr/goals/active.toml now records no_current_goal = true with no successor selected. |
| Lane 1 Cross-Language Oracle Follow-Up | Extend #908/#910 cross-language oracle evidence through measured, profile-backed graph slices beyond the bounded Bun Blob route while preserving preview/advisory and fail-closed boundaries. | Complete: Lane 1 Cross-Language Oracle Follow-Up closeout records the measured Bun Blob, copy_to_unshared, #951 MarkdownObject, and #950 FFI panic-boundary slices, their advisory/limitation claim boundary, and no_current_goal = true. #908/#910 remain open as broader cross-language oracle follow-ups rather than completed generic oracle support. |
| Lane 1 Cross-Language Guidance Safety | Pin the #908 MarkdownObject review-comments wrong-target sample so externally observed TypeScript evidence remains navigation-only when target placement is unresolved. | Complete: output/markdownobject-review-comments-target-safety adds a MarkdownObject-specific review-comments regression proving no guessed vendor/lolhtml Rust test target, no verify command, no public repair packet, and navigation-only test/js/bun/md/md-edge-cases.test.ts context routed to analysis/cross-language-test-target-inference; #908/#910 remain open for broader cross-language oracle work. |
| Cross-Language Evidence Router UX | Turn the calibrated TypeScript/Bun graph path into a repeatable mixed TypeScript plus Rust operating loop for Bun operators, Claude Code, and other configured projects without promoting preview evidence. | Complete: RIPR-SPEC-0063 and RIPR-PLAN-0063 defined PR-sized slices for 0.8.1 patch proof, compact Bun UB summary, advisory agent packet, proof-mode projection, node:fs and Bun.write manifest-only profiles, bridge inventory, live Bun dogfood, runbook polish, and the post-0.8.1 support decision. The post-0.8.1 TypeScript/Bun support decision keeps TypeScript/JavaScript preview/advisory, confirms calibrated Bun stable-byte evidence is useful for TS-discriminated, missing-discriminator, mention-only, bridge-unknown, and named-limitation states, and requires a separate accepted promotion contract for any stronger claim. |
The following machine-readable execution record is historical. The current
manifest is .ripr/goals/active.toml with
id = "rust-one-shot-evidence-to-repair"; see
RIPR-PLAN-0062 for current work
items. The prior manifest recorded status = "active" for
cross-language-evidence-router-ux and
records release/typescript-bun-preview-patch-proof,
output/bun-ub-preview-summary, and
agent/bun-cross-language-advisory-packet,
output/stable-byte-proof-mode, and
fixtures/bun-node-fs-scalar-write-profile, and
fixtures/bun-write-helper-gated-profile,
analysis/configured-bridge-inventory, and
dogfood/live-bun-stable-byte-receipts,
docs/bun-ub-first-run-polish, and
docs/post-081-support-decision as completed selected slices. The active
manifest now records no_current_goal = true. The prior
post-release successor kept normal development in
ripr-swarm, preserved source ripr as release/distribution authority, and closed
the selected Lane 1 evidence-to-repair operating loop:
queue hygiene, navigable review comments, explicit large-repo limits,
user-facing diff-first changed-surface mode, cross-language fail-closed
routing, target placement, oracle graph proof, packet guidance, receipt/outcome
hardening, dogfood attempts, route-quality metrics, user-surface alignment, and
the final closeout handoff.
The fail-closed, target-placement, bounded oracle-graph, repair-packet
guidance, attempt-ledger outcome hardening, and real repair/analyzer-attempt
dogfood items now point at their
already-merged #930, #938-#941, SPEC-0062 corpus/report evidence,
swarm-plan packet corpus evidence, SPEC-0057 state coverage, and
attempt-ledger/readiness report evidence, plus the real-repair-attempts corpus
and dogfood report covering improved, resolved, unchanged, and
attempted-without-receipt outcomes. Route-quality metrics now point at
readiness and evidence-quality scorecard route summaries for repair-kind,
language, missing-field, failing-route, limitation-route, and cross-language
oracle quality. Surface canonical-state alignment now points at the checked
surface-projection and user-surface-projection dogfood corpora, which preserve
canonical gap identity, runtime state, repair or limitation state, receipt
state, non-success route-quality cases, missing receipts, and raw-finding
non-claims across badge, LSP/editor, PR comment, and CI examples. The
closeout
records the trust boundary, advisory limits, validation evidence, remaining
open work themes, and archived manifest. The later #908/#910
cross-language oracle follow-up is also closed for the current repo state:
it added profile-backed copy_to_unshared, #951 MarkdownObject, and #950
FFI panic-boundary evidence while preserving advisory-only and fail-closed
behavior. No successor campaign is selected; future #908/#910 work must start
from live issue and artifact state with a fresh measured profile or narrow
analyzer route instead of extending the closed manifest. A later one-slice
guidance-safety campaign pins the exact #908 MarkdownObject review-comments
wrong-target sample at the agent prompt surface while preserving the same
non-closure boundary for #908/#910.
RIPR-SPEC-0062
continues to define bounded named Bun TypeScript graph profiles where complete
configured external witnesses may become advisory external observation, but
missing discriminators, mention-only samples, unknown bridges, and unresolved
targets remain named limitations until the Rust seam, binding or FFI edge,
external callsite, external assertion or oracle, raw evidence refs, verify
command, receipt command, and edit constraints are all explicit. The
closed
lane1-language-aware-placement-navigation campaign records that #938 made
explicit external observer target evidence navigation-only across
review-comments, LSP, and packet-adjacent output, #940 summarized those
limitations in readiness and scorecard surfaces, and #942 closed #911. The
closed
lane1-large-repo-runtime-completeness
campaign records the #909 post-0.8 trust-debt PR chain through #935, including
explicit large-cache skip state, sharded classified seam cache storage,
cache-report shard summaries, and diff-scoped review-comments runtime. The
preceding lane1-real-repo-trust-readiness closeout records that #913, #912,
and the post-0.8 issue-batch slices landed through #931 while #908 and #910
remain broader follow-up routes rather than completed cross-language oracle
support. Live repo handoff state says 0.8.0 has already been published, so
these post-release trust-debt campaigns must not be represented as behavior
included in the published tag. The goal-freshness guardrail is pinned,
the first-pr front-door stdout behavior landed in #332, the one-screen
recommendation contract landed in #335, reviewer-native outcome claim
boundaries landed in #338, the fixture-backed first successful PR demo story
landed in #341, and generated CI, VS Code, and agent packet convergence landed
in #344. The
focused Lane 2 policy readiness tracker lives in
.ripr/goals/lane2-policy-readiness.toml and
Policy readiness; it is a GitHub issue/PR board,
not the active execution manifest. The next focused Lane 2 tracker lives in
.ripr/goals/lane2-policy-operations.toml and
Policy operations; it is also not the active
execution manifest. Campaigns 1 through 8 are complete.
Campaign 6 closed after the internal module SRP chain
landed through #405 while preserving the saved-workspace LSP cockpit contract,
output schemas, public API, SARIF, and badge behavior. Campaign 7 closed after
the defaults-first CLI, editor, CI, fixture, release, and report surfaces were
verified; the closeout audit lives at
docs/handoffs/2026-05-07-campaign-7-closeout.md. Campaign 8 added the checked
fixtures/boundary_gap/calibration/runtime-fixtures-v1/ sample for the main
static/runtime agreement buckets and closed with runtime calibration still
confined to supplied-data reports. Campaign 9 measured the cache/editor proof
surfaces, added bounded latency reporting, reused warm-path facts below rendered
outputs, bounded ripr pilot, improved first-screen pilot clarity, added
evidence progress tracing, and closed after hot-path evidence indexes made the
default latency report pass on cache hits. Campaign 10 closed after aligning
the saved-workspace editor and agent CLI loop through diagnostics, evidence,
packet/brief commands, focused-test receipts, cockpit status, generated CI
artifacts, and release-readiness proof. Campaign 11 closed after adding a
read-only ripr agent status lens over existing agent-loop artifacts,
centralized command templates for CLI, LSP, cockpit, generated CI, docs, and
fixtures, source-edit-free workflow manifests, provenance-backed receipts,
bounded next-action guidance, review summaries, a fixture matrix, generated CI
work-loop packet uploads, and the LLM operator guide. Campaign 12 closed the
First-Hour UX lane after the LLM work-loop control plane: the PR guidance
annotation contract is pinned, the extension has a first-run status path,
diagnostic actions are titled around user intent, and the generated GitHub
workflow now writes a reviewer-oriented advisory summary before artifact
download. The generated workflow smoke fixture pins artifact paths,
top-seam extraction, agent artifacts, optional SARIF gates, badges, summary
sections, and PR guidance annotation hooks. The first-hour docs route
users by VS Code, CI, CLI, and agent/reviewer path. Campaign 13 closed PR
Review Guidance: ripr review-comments now produces the advisory JSON and
Markdown report, generated CI runs it before the existing summary and
annotation consumer steps, placement and suppression fixtures are pinned, and
PR review guidance documents the bounded advisory
workflow. Campaign 14 closed Recommendation Calibration: RIPR-SPEC-0013 pins
the recommendation calibration report contract, the PR-shaped calibration
corpus plus local outcome receipts are checked, cargo xtask recommendation-calibration emits the advisory report, and Recommendation
calibration documents how to read metrics,
receipts, placement quality, suppression correctness, static movement buckets,
and advisory limits. Campaign 15 closed the Calibrated Gate Policy lane:
RIPR-SPEC-0014 pins optional gates as explicit policy over measured evidence,
with advisory defaults, visible acknowledgement paths, and runtime mutation
calibration only as imported confidence evidence. gate/policy-evaluator is
implemented as a read-only report producer; fixtures/calibrated-gate-cases
pins the decision matrix; generated GitHub workflows now run gate evaluation
only when RIPR_GATE_MODE is explicitly configured; and
Calibrated gate policy documents modes, waivers,
CI behavior, calibration evidence, and the static/runtime boundary. The
closeout handoff records the PR chain, prompt-to-artifact audit, and explicit
boundary that adoption should be opened explicitly after closeout. Campaign 16
closed Gate Adoption UX after making explicit gate adoption safe and reviewable
without changing advisory defaults. It added copyable generated-CI examples for
default advisory, visible-only, acknowledgeable, baseline-check, and
calibrated-gate modes; documented ripr-waive as visible acknowledgement
rather than suppression; documented baseline creation and shrink refreshes as
a visible historical-debt workflow; polished generated CI summaries for gate
mode, status, labels, waiver, baseline, calibration, blocking reason, and
artifact paths; recorded checked repo-local gate adoption receipts through
cargo xtask dogfood; and added RIPR blocking
readiness for deciding when to stay advisory, require
acknowledgement, use baseline-check, or enable calibrated blocking. The
Campaign 16 closeout records
the PR chain and proof commands. Campaign 17 closed RIPR Zero
Adoption: RIPR-SPEC-0016 defines the baseline debt delta report contract,
ripr baseline create can write reviewed baseline ledgers, ripr baseline diff can report baseline debt movement, and ripr baseline update --remove-resolved can shrink reviewed baselines without adopting new current
debt. Generated CI can now upload and summarize baseline debt delta artifacts
when a baseline and gate decision are present; the baseline ledger workflow
guide now documents initial adoption, baseline-check rollout, shrink-only
refresh, new debt review, and the path toward RIPR 0. The
Campaign 17 closeout records
the PR chain, prompt-to-artifact audit, proof commands, and next-work boundary.
Campaign 18 closed as RIPR Zero Reporting. RIPR-SPEC-0017 defines the
repo-level status surface for baseline owner/reason/age metadata, stale
warnings, trends, top debt areas, and repair routing. Baseline metadata
preservation, the read-only RIPR Zero status report, generated-CI summary
projection, and the user workflow docs are in place. The
Campaign 18 closeout records
the PR chain, proof commands, and boundary that progress toward RIPR 0 remains
separate from analyzer identity, gate policy, and advisory defaults.
Editor Evidence UX closed as a separate Lane 3 campaign; its contract audit is
recorded in Editor Evidence UX, the user path is
documented in the editor evidence workflow, and
the closeout handoff
records the prompt-to-artifact audit. Future editor work should be opened as a
new explicit campaign.
Campaign 19 closed as PR Evidence Ledger. It made append-only per-PR movement
records, waiver aging, baseline burn-down, repair receipts, and optional
coverage/grip frontier signals visible without changing advisory defaults.
RIPR-SPEC-0018 pins the contract; ripr pr-ledger record writes the read-only
ledger; generated CI uploads pr-evidence-ledger.{json,md} and appends the
advisory PR movement card; ripr coverage-grip frontier keeps coverage and
behavioral grip movement separate; and
docs/PR_EVIDENCE_LEDGER_WORKFLOW.md explains the adoption workflow. Campaign
20 closed as Test-Oracle Assistant Proof. RIPR-SPEC-0019 defines the
end-to-end proof contract from changed Rust behavior through static evidence,
PR/editor guidance, focused-test handoff, verification, receipt, and advisory
CI/ledger projection without changing analyzer, policy, editor, or CI defaults.
The canonical boundary-gap replay corpus pins one seam across recommendation,
handoff, receipt, and ledger projection. The repo-local dogfood receipt traces
seam 67fc764ba37d77bd through PR guidance, editor/agent handoff,
before/after evidence, receipt, PR ledger projection, and coverage/grip
frontier availability. docs/TEST_ORACLE_ASSISTANT_WORKFLOW.md explains the
user-facing PR/editor-to-receipt workflow and static evidence limits. The
Campaign 20 closeout records
the prompt-to-artifact audit, proof commands, and boundary that future proof
report producers, PR/CI polish, analyzer improvements, and editor UX work
should be opened as explicit follow-up campaigns. Campaign 21 closed as
Test-Oracle Assistant Report Producer. ripr assistant-loop proof now produces
advisory test-oracle-assistant-proof.{json,md} artifacts from explicit
existing inputs without changing analyzer, ranking, gate, editor, provider,
mutation, or default CI behavior. Generated GitHub CI now projects that report
only when the required artifact chain already exists.
docs/TEST_ORACLE_ASSISTANT_PROOF_REPORT.md now explains how to read the
report, warnings, static movement, optional CI projection, and limits. Campaign
21 closed with
docs/handoffs/2026-05-09-campaign-21-closeout.md. Campaign 22 closed as
First Useful Action. It compresses existing evidence into one advisory next
test action; RIPR-SPEC-0020 pins the report contract, the routing corpus pins
expected statuses and fallback outputs, ripr first-action writes the
read-only report from explicit artifacts, generated CI projects it as advisory
summary/artifact content, and VS Code status projects existing reports without
rerunning analysis. The first-action workflow docs explain how developers,
reviewers, and coding agents read the action, verify movement, emit receipts,
and interpret fallback states. cargo xtask dogfood checks repo-local
first-action receipts for actionable, baseline-only, stale,
missing-required-artifact, unchanged-after-attempt, and no-actionable-seam
routes. The
Campaign 22 closeout records
the prompt-to-artifact audit, validation commands, and boundary that future
health, analyzer, policy, or editor lanes need explicit follow-up campaigns.
Campaign 23 closed as Assistant Loop Health. It uses the
Assistant Loop Health proposal as its
design brief, RIPR-SPEC-0022
defines the report contract, and the
fixtures/boundary_gap/expected/assistant-loop-health/ corpus pins the health
states. The producer, generated-CI projection, and
assistant loop health workflow are in
place. The Campaign 23 closeout
records the audit and future-lane boundary. The campaign measures whether
assistant proof packets are complete, stuck, missing receipts, or moving static
evidence over time, without changing analyzer behavior, ranking, gate
semantics, LSP/editor behavior, mutation execution, provider calls, source
files, generated tests, or default CI blocking.
Campaign 24 is now closed as PR Review Front Panel. It uses the
PR Review Front Panel proposal as its
design brief, and
RIPR-SPEC-0023 now
defines the report contract. The boundary-gap fixture corpus now pins the
advisory-only, actionable, summary-only, acknowledged, suppressed,
baseline-resolved, blocked, missing-proof, and coverage-flat-grip-improved
routes. ripr pr-review front-panel now writes the advisory JSON/Markdown
report from explicit existing artifact paths. Generated GitHub CI now runs the
front-panel producer only when explicit input artifacts exist, uploads
pr-review-front-panel.{json,md} with the normal report packet, and appends the
front-panel Markdown and at-a-glance fields to the advisory job summary while
leaving ripr gate evaluate as the only explicit pass/fail authority. The
PR review front panel workflow now
documents how reviewers, maintainers, developers, and coding agents use the
panel, repair routes, receipts, and advisory gate boundary. The
dogfood report now checks repo-local front-panel receipts for actionable,
acknowledged, suppressed, baseline-resolved, blocked, missing-proof,
no-actionable, and coverage-flat-grip-improved reviewer states. The
campaign composes existing PR guidance, first useful action, assistant proof,
assistant-loop health, PR evidence ledger, baseline delta, gate decision,
receipts, calibration, and optional coverage/grip frontier artifacts into one
advisory GitHub PR first screen without changing analyzer behavior,
recommendation ranking, gate semantics, editor behavior, mutation execution,
provider calls, source files, generated tests, inline-comment defaults, or
default CI blocking. The
Campaign 24 closeout records the
PR chain, prompt-to-artifact audit, validation plan, and future-lane boundary.
Campaign 25 closed as Report Packet Index. It used the
Report Packet Index proposal as its design
brief. The campaign made target/ripr/reports/index.{json,md} the
reviewer front door for the uploaded ripr-reports packet, grouping explicit
existing artifacts by start-here, PR review story, repair or agent handoff,
evidence, policy or gates, calibration, validation receipts, and SARIF or badge
outputs. It stayed advisory and read-only: no analyzer behavior,
recommendation ranking, gate semantics, editor behavior, mutation execution,
provider calls, source edits, generated tests, inline-comment defaults, hidden
analysis reruns, or default CI blocking. The fixture corpus now pins complete,
sparse, missing-front-panel, blocked-gate, missing-proof, missing-receipt, and
coverage/grip-present packet states. ripr reports index now writes the
read-only target/ripr/reports/index.{json,md} producer output from explicit
artifact directories. Generated GitHub CI now runs that producer when indexed
artifacts exist, uploads index.{json,md} with the report packet, and appends
the advisory packet-index summary without changing gate authority. The
report packet index workflow now explains
how reviewers, maintainers, developers, and coding agents use the index.
cargo xtask dogfood now checks the repo-local report-packet index receipts
for complete, sparse, missing-front-panel, blocked-gate, missing-proof,
missing-receipts, and coverage/grip-present cases. The
Campaign 25 closeout records
the PR chain, prompt-to-artifact audit, validation plan, advisory boundary, and
future-lane boundary.
Campaign 26 is closed as PR Inline Comment Publisher. It used the
PR Inline Comment Publisher proposal
and RIPR-SPEC-0025 as
its design contract. The campaign made optional durable PR comments safe
by adding a read-only publish plan over existing ripr review-comments
artifacts before anything posts to GitHub. It must stay explicit opt-in and
advisory: no analyzer behavior, recommendation ranking, gate semantics, editor
behavior, mutation execution, provider calls, source edits, generated tests,
branch-protection changes, hidden analysis reruns, pull_request_target
defaults, or default CI blocking. The fixture corpus under
fixtures/boundary_gap/expected/pr-inline-comment-publisher/ now pins the
publishable, summary-only, capped, dedupe/upsert, stale-existing, fork or
no-token, and missing-input cases. ripr pr-comments plan now writes the
read-only JSON/Markdown publish plan from those explicit inputs without
posting to GitHub or changing gate authority. Generated GitHub CI now keeps
inline comments disabled by default, emits publish-plan artifacts only in
opt-in modes, and posts or updates comments only when RIPR_COMMENT_MODE=inline
and the safe plan permits it. docs/PR_INLINE_COMMENT_PUBLISHER_WORKFLOW.md
now documents the opt-in workflow, plan review, fork and permission behavior,
dedupe/upsert, rollback, and advisory gate boundary. cargo xtask dogfood now
checks repo-local publish-plan receipts without posting real PR comments.
Campaign 26 is closed by
docs/handoffs/2026-05-10-campaign-26-closeout.md.
PR 0: planning-and-tracking-docs
Purpose: put the plan, engineering rules, metrics, ADRs, specs, changelog, and traceability conventions in the repository before analyzer rewrites begin.
Deliverables:
- Update
docs/ROADMAP.mdwith the release sequence and PR queue. - Add an implementation checklist that future PRs can update.
- Add ADR scaffolding and initial ADRs for product-shaping decisions.
- Add spec scaffolding for behavior contracts.
- Add metrics definitions for capability and regression tracking.
- Add learnings and repo-knowledge log.
- Add spec-test-code traceability rules.
- Update the README doc index and metric summary.
- Add a root changelog.
- Add PR review checklist guidance.
- Add contributor workflow guidance.
- Add CI strategy guidance.
- Add dogfooding guidance.
- Add ADR and spec templates.
- Add changelog policy guidance.
- Add scoped evidence-heavy PR doctrine.
- Add first executable policy checks for static language and panic-family debt.
Acceptance:
- A contributor can identify the next PR from docs alone.
- A contributor can identify which spec, tests, and code modules belong together for a feature.
- The docs state that production and test code should avoid
panic,unwrap, andexpect, and that existing uses are tracked debt. - The docs preserve the product contract and conservative static language.
- PRs are scoped by production risk rather than line count.
PR 1: verify-one-click-extension-install
Purpose: verify the normal VS Code extension path without requiring users to
install ripr separately.
Deliverables:
- Manual install verification matrix for VS Marketplace and Open VSX.
- Fresh-profile check with no
ripronPATH. - Server auto-download and checksum verification evidence.
- Output-channel log checklist for mode, base, config, server path, and download source.
- Clear-error scenarios for disabled auto-download, missing manifest, unsupported platform, and checksum mismatch.
Tests and gates:
-
cd editors/vscode && npm ci -
cd editors/vscode && npm run compile -
cd editors/vscode && npm run package
PR 1A: xtask-policy-checks
Purpose: expand the initial policy checks into a broader local and CI quality rail.
Deliverables:
- Move static language and panic-family checks into CI.
- Add markdown local link check.
- Add doc index check for README, docs, specs, and ADRs.
- Add traceability manifest validation.
- Add capability matrix validation.
- Add PR-scope check for production delta and evidence delta.
Acceptance:
-
cargo xtask ci-fastruns the core policy checks. - Existing debt is allowlisted with counts, and new debt fails the check.
- Docs explain how to remove allowlist entries as debt is paid down.
PR 1B: rust-first-file-policy
Purpose: keep repo implementation and automation Rust-first by denying unapproved non-Rust programming files, checked-in executable scripts, and workflow shell sprawl.
Deliverables:
- Add Rust-first file policy docs.
- Add non-Rust allowlist with owner, kind, and reason.
- Add workflow shell-budget allowlist.
- Add
cargo xtask check-file-policy. - Add
cargo xtask check-executable-files. - Add
cargo xtask check-workflows. - Wire checks into
cargo xtask ci-fast. - Wire checks into CI.
Acceptance:
- Rust is documented as the default implementation and automation language.
- Existing VS Code, workflow, docs, fixture, asset, and config surfaces are explicitly allowlisted.
- New shell, Python, JavaScript, TypeScript, or other programming files outside approved surfaces fail the file policy check.
- Checked-in executable bits fail unless allowlisted.
- Long workflow run blocks fail unless allowlisted.
Future policy PRs:
- generated-file policy
- dependency-surface policy
- process-spawn policy
- network policy
- workspace-shape policy
- architecture import guard
- public API guard
PR 1C: spec-fixture-contracts
Purpose: make specs and fixtures agent-readable and mechanically checkable before fixture and golden output work expands.
Deliverables:
- Add spec format reference.
- Add test taxonomy reference.
- Add fixture contract README.
- Update existing specs to the checked format.
- Add
cargo xtask check-spec-format. - Add
cargo xtask check-fixture-contracts. - Wire checks into
cargo xtask ci-fast. - Wire checks into CI.
Acceptance:
- Every
docs/specs/RIPR-SPEC-*.mdhas required sections and a valid status. - Spec filename IDs match title IDs.
- Future fixture directories must include
SPEC.md,diff.patch, andexpected/check.json. - Fixture
SPEC.mdfiles must include Given/When/Then/Must Not sections.
PR 1D: automation-guardrails
Purpose: finish the first Rust-first policy family by making generated files, dependency surfaces, process spawning, and network behavior explicit.
Deliverables:
- Add generated-file allowlist and
cargo xtask check-generated. - Add dependency-surface allowlist and
cargo xtask check-dependencies. - Add process-spawn allowlist and
cargo xtask check-process-policy. - Add network allowlist and
cargo xtask check-network-policy. - Wire checks into
cargo xtask ci-fast. - Wire checks into CI.
- Update the file policy, CI docs, contributor docs, and PR template.
Acceptance:
- Tracked generated lockfiles and future fixture goldens require explicit allowlist entries.
- New dependency manager files fail unless they belong to approved Cargo, VS Code, or fixture surfaces.
- New process spawning fails unless allowlisted with a reason.
- New network behavior fails unless allowlisted with a reason.
PR 1E: shape-fix-pr
Purpose: add the first mutating PR-shaping commands without changing existing policy semantics.
Deliverables:
- Add
cargo xtask shape. - Add
cargo xtask fix-pr. - Run
cargo fmtthroughshape. - Sort
.ripr/*.txtandpolicy/*.txtallowlists throughshape. - Ensure
target/ripr/reportsexists. - Write
target/ripr/reports/shape.md. - Write
target/ripr/reports/fix-pr.md. - Document safe mutations and repair guidance.
Acceptance:
-
cargo xtask shapepasses. -
cargo xtask fix-prpasses. -
cargo xtask ci-fastpasses after shaping. - Shaping does not add policy exceptions or bless output drift.
PR 1F: pr-summary
Purpose: generate a reviewer packet before human review without mutating source files.
Deliverables:
- Add
cargo xtask pr-summary. - Read changed paths from git diff and git status.
- Write
target/ripr/reports/pr-summary.md. - Classify production delta and evidence/support delta.
- Classify detected surfaces, public contracts, and policy exceptions.
- Suggest reviewer focus files.
- Update
cargo xtask fix-prto refresh the PR summary after shaping.
Acceptance:
-
cargo xtask pr-summarypasses. -
target/ripr/reports/pr-summary.mdexists after the command. -
cargo xtask fix-prrefreshes shape, PR summary, and fix-pr reports.
PR 1G: automation-path-docs
Purpose: document the fix/check/guide operating model and the Codex Goals campaign handoff so automation and analyzer implementation work share the same review contract.
Deliverables:
- Add a PR automation operating model.
- Document deterministic shaping, non-mutating checks, and repair briefs.
- Document the scoped PR contract.
- Record the automation cutoff that made Campaign 1 safe to leave setup mode.
- Link the new docs from the roadmap, documentation map, agent workflow, contributor docs, and README.
Acceptance:
- A contributor can identify which cleanup should be automated and which changes require explicit judgment.
- A coding agent can identify the next automation PRs without confusing them with product campaign work.
- A coding agent can use a standard task template for the analyzer queue.
PR 1H: check-pr-precommit
Purpose: add obvious local gates for cheap pre-commit checks and review readiness checks.
Deliverables:
- Add
cargo xtask precommit. - Add
cargo xtask check-pr. - Keep
precommitcheap and non-mutating. - Make
check-prrun the review-ready command set that exists today. - Update CI, contributor, and agent docs.
Acceptance:
-
cargo xtask precommitpasses on main. -
cargo xtask check-prpasses on main. -
check-prdoes not run release packaging unless the repo later adds a path-aware release lane.
PR 1I: guided-check-reports
Purpose: make existing policy checks emit repair briefs instead of only command failure text.
Deliverables:
- Add a shared report model or helper for Markdown check reports.
- Upgrade static-language, panic-family, file-policy, executable-file,
workflow, spec-format, fixture-contract, generated, dependency, process,
and network checks to write reports under
target/ripr/reports. - Classify failures as auto-fixable, author decision, reviewer decision, or policy exception.
- Include exact rerun commands and exception templates where useful.
Acceptance:
- Each upgraded check writes a useful report on failure.
- Successful checks either write a pass report or are summarized by
pr-summary. - Report generation does not hide the non-zero exit status of failed checks.
PR 1J: ci-report-artifacts
Purpose: make CI upload review artifacts even when a check fails.
Deliverables:
- Run
cargo xtask pr-summarywhere possible in CI. - Defer metrics report generation until
cargo xtask metricsexists. - Upload
target/ripr/reportswith an always step. - Document report artifact names and expected contents.
Acceptance:
- CI artifacts include the PR summary and any check reports that were generated before failure.
- CI remains non-mutating.
PR 1K: fixture-golden-scaffolding
Purpose: add the command surface for fixture execution and golden comparison before analyzer internals change.
Deliverables:
- Add
cargo xtask fixtures. - Add
cargo xtask fixtures <name>. - Add
cargo xtask goldens check. - Add
cargo xtask goldens bless <name> --reason "...". - Document the fixture and golden directory conventions.
Acceptance:
- Fixture commands pass with a clear "no fixtures found" message if no executable fixtures exist yet.
- Existing fixture contract checks still pass.
- Golden blessing requires an explicit reason.
PR 1L: traceability-spec-id-checks
Purpose: make spec IDs and behavior manifest entries checkable.
Deliverables:
- Harden
.ripr/traceability.toml. - Add
cargo xtask check-spec-ids. - Add
cargo xtask check-behavior-manifest. - Add warning-only drift checks for analysis, output, docs, fixture, and metric changes.
Acceptance:
- Accepted specs point to real docs and at least one test or fixture unless explicitly planned.
- Fixture specs reference valid spec IDs.
- Missing expected evidence appears in the PR summary.
PR 1M: capability-metrics-report
Purpose: make capability progress and automation debt visible.
Deliverables:
- Add or harden a machine-readable capability source.
- Add
cargo xtask metrics. - Add
cargo xtask check-capabilities. - Write
target/ripr/reports/metrics.mdormetrics.json. - Keep the README capability snapshot aligned with the capability source.
Acceptance:
- Capability statuses have valid values and required fields.
- Stable or calibrated statuses require the evidence defined by policy.
- Metrics reports are generated without changing product behavior.
PR 1N: architecture-guard
Purpose: protect internal seams while keeping one published package.
Deliverables:
- Add
cargo xtask check-workspace-shape. - Add
cargo xtask check-architecture. - Add
cargo xtask check-public-apior document why it is deferred. - Add policy metadata for allowed workspace packages and module-boundary rules.
Acceptance:
- New workspace packages require an explicit approved policy entry.
- Domain and analysis layers cannot accidentally depend on adapters.
- CLI, LSP, and output layers do not own exposure classification.
PR 1O: readme-state-and-link-checks
Purpose: make README state and Markdown links part of the checked trust packet.
Deliverables:
- Add
cargo xtask check-readme-state. - Add
cargo xtask markdown-links. - Check README front-door sections and headline capability snapshot shape.
- Check README/capability matrix checkpoint drift against
metrics/capabilities.toml. - Check repo-local Markdown links in tracked
.mdfiles. - Wire the checks into
precommitandci-fast. - Update CI and PR automation docs.
Acceptance:
- Deleted or renamed docs fail before review when still linked.
- README remains linked to active campaign, metrics, capability, and automation docs.
-
cargo xtask check-readme-stateandcargo xtask markdown-linkspass on main.
PR 1P: campaign-manifest-check
Purpose: make the active Codex Goals campaign queue mechanically checkable and reportable.
Deliverables:
- Add
cargo xtask check-campaign. - Add
cargo xtask check-goalsas an alias. - Add
cargo xtask goals status. - Add
cargo xtask goals next. - Validate
.ripr/goals/active.tomlagainstdocs/IMPLEMENTATION_CAMPAIGNS.md. - Validate work item IDs, statuses, branch fields, acceptance claims, stackability, merge boundaries, blocked dependencies, and command names.
- Wire the manifest check into
precommitandci-fast.
Acceptance:
-
cargo xtask check-campaignpasses on main. -
cargo xtask goals statuswritestarget/ripr/reports/goals.md. -
cargo xtask goals nextwritestarget/ripr/reports/goals-next.md.
PR 1Q: fixtures-runner-comparison-v1
Purpose: make fixture and golden commands execute the current product and compare actual output against checked-in expected output.
Deliverables:
-
cargo xtask fixturesruns all fixtures when fixture directories exist. -
cargo xtask fixtures <name>runs one fixture. - Actual JSON and human outputs are written under
target/ripr/fixtures/<name>/. -
cargo xtask goldens checkcompares actualcheck.jsonand optionalhuman.txtoutputs againstfixtures/<name>/expected/. -
cargo xtask goldens bless <name> --reason "..."requires a reason, updatesexpected/check.jsonandexpected/human.txt, and appends the fixture changelog.
Acceptance:
- Fixture commands still pass with a clear report when no fixture directories exist.
- Golden checks fail on drift without mutating expected outputs.
- Golden blessing remains explicit and does not run from
shapeorfix-pr.
PR 2: fixture-laboratory
Purpose: build the regression control bench before changing analyzer internals.
Deliverables:
-
fixtures/boundary_gap -
fixtures/weak_error_oracle -
fixtures/field_not_asserted -
fixtures/side_effect_unobserved -
fixtures/smoke_assertion_only -
fixtures/no_static_path -
fixtures/opaque_fixture -
fixtures/workspace_cross_crate -
fixtures/duplicate_symbols -
fixtures/stacked_test_attrs -
fixtures/nested_src_tests_layout -
fixtures/macro_unknown -
fixtures/snapshot_oracle -
fixtures/mock_effect
Each fixture should include:
- source and tests
-
diff.patch - expected JSON output
- expected human output
- expected context packet
- expected LSP diagnostic shape when relevant
Invariants:
- Static output never says
killedorsurvived. - Unknowns include stop reasons.
- Weak or smoke oracle evidence does not silently become strong.
- Finding order is deterministic.
- Context packets are parseable.
PR 2A: testing-test-oracle-report
Purpose: measure ripr's own test oracle strength as analyzer work expands.
Deliverables:
-
cargo xtask test-oracle-reportwritestarget/ripr/reports/test-oracles.md. -
cargo xtask test-oracle-reportwritestarget/ripr/reports/test-oracles.json. -
cargo xtask check-test-oraclesaliases the same advisory report. - The report classifies detected Rust tests as strong, medium, weak, or smoke.
- Existing weak or smoke debt is advisory and non-blocking.
Acceptance:
-
cargo xtask test-oracle-report -
cargo xtask check-test-oracles -
cargo xtask metrics -
cargo xtask check-pr
PR 2B: dogfood-static-self-check
Purpose: add a focused non-blocking ripr-on-ripr report.
Deliverables:
-
cargo xtask dogfoodruns stable fixture diffs throughripr check --mode fast. - Actual dogfood JSON and human outputs are written under
target/ripr/dogfood/<fixture>/. -
target/ripr/reports/dogfood.mdsummarizes findings, exposure classes, runtime, and errors. -
target/ripr/reports/dogfood.jsonprovides the same advisory summary for future machine readers. - Dogfood is advisory and non-blocking.
Acceptance:
-
cargo xtask dogfood -
cargo xtask check-pr
PR 3: file-facts-model
Purpose: introduce an internal fact model while preserving current scanner behavior.
Deliverables:
-
FileFacts -
FunctionFact -
TestFact -
OracleFact -
CallFact -
ReturnFact -
StructConstructionFact -
EnumConstructionFact -
LiteralFact -
BuilderChainFact -
EffectFact
Acceptance:
- Existing sample findings are unchanged.
- Analysis consumes facts rather than ad hoc scanner structures.
- Scanner behavior remains available as the fallback.
PR 4: syntax-adapter-mvp
Purpose: create the parser boundary before relying on parser-specific details.
Deliverables:
-
RustSyntaxAdaptertrait or equivalent boundary. - Lexical adapter
summarize_fileimplementation. - Changed range to syntax-node mapping.
- No public API commitment to a parser crate.
- Parser substrate decision recorded in ADR 0006.
- Parser-backed
summarize_fileimplementation.
Acceptance:
- Existing outputs remain stable or intentionally updated with fixture evidence.
- Parser errors produce
static_unknownor structured diagnostics, not panics.
PR 5: ast-test-oracle-extraction
Purpose: extract tests and oracles from syntax nodes instead of line substrings.
Deliverables:
-
#[test]function extraction. - Stacked attribute preservation.
- Multi-line assertion macro extraction.
-
assert!,assert_eq!,assert_ne!,assert_matches!, andmatches!handling. -
unwrapandexpectsmoke-oracle handling.
Acceptance:
- Fixture output remains deterministic.
- Line scanning is fallback only.
PR 6: ast-probe-ownership
Purpose: attach probes to stable owner symbols.
Deliverables:
- Diff hunk to changed text range.
- Changed range to syntax-backed owner node.
- Syntax node to enclosing function, method, or module.
- Stable
SymbolId.
Acceptance:
- Duplicate function names across modules or crates do not cross-link tests.
- Probe IDs remain stable enough for
explainandcontext.
PR 7: ast-probe-generation
Purpose: generate probes from syntax kind and ownership facts.
Deliverables:
- Predicate boundary probes.
- Return value probes.
- Error path probes.
- Field construction probes.
- Side-effect or call-change probes.
-
static_unknownfallback with reason.
Acceptance:
- Multi-line predicate changes produce one useful probe.
- Tail-expression return changes produce return probes.
-
Err(Error::X)changes produce error-path probes.
PR 8: oracle-strength-v2
Purpose: make oracle kind and strength explicit and probe-relative.
Deliverables:
- Exact value oracle.
- Exact error variant oracle.
- Broad error oracle.
- Whole-object equality oracle.
- Snapshot oracle.
- Mock expectation oracle.
- Relational check oracle.
- Shape-only oracle.
- Smoke-only oracle.
- Unknown oracle kind.
Acceptance:
-
is_err()differs from exact error variant assertions. -
unwrap()differs from exact return assertions. - JSON and human output keep the stable schema while rendering probe-relative oracle strength.
PR 9: local-delta-flow-v1
Purpose: explain what changed behavior appears to flow to.
Deliverables:
- Changed expression to
letbinding flow. - Binding to return flow.
- Binding to struct field flow.
- Changed expression to
OkorErrflow. - Predicate branch to return or field construction flow.
- Changed call to effect boundary candidate.
Acceptance:
- Findings can name at least one sink when locally visible.
-
propagation_unknownincludes a concrete stop reason.
PR 10: activation-value-modeling-v1
Purpose: detect whether tests appear to activate the changed behavior.
Deliverables:
- Numeric and string literal value facts.
- Function argument value facts.
- Builder-chain value facts.
- Table-row value facts.
- Enum variant value facts.
- Boundary equality discriminator facts.
Acceptance:
- Boundary findings include detected values.
- Boundary findings include missing equality value.
- Opaque fixtures produce
infection_unknown, not false confidence.
PR 11: evidence-first-output
Purpose: make CLI output the reference explanation.
Deliverables:
- Changed behavior section.
- RIPR stage evidence section.
- Related tests section.
- Oracle evidence section.
- Missing discriminator section.
- Next step section.
- Stop reason section for unknowns.
Acceptance:
- Golden human and JSON output cover current Campaign 3 fixtures.
- Static language remains conservative.
- Negative and metamorphic fixtures cover noise-only and syntax-variant cases.
PR 12: lsp-evidence-hover-actions
Purpose: make editor diagnostics specific and actionable.
Deliverables:
- Diagnostic data with finding and probe IDs.
- Stable diagnostic codes.
- Hover evidence for exact finding.
- Copy context packet code action.
- Open related tests code action.
- Run deep check command.
- Output-channel lifecycle logs.
Acceptance:
-
didChangerefreshes diagnostics after debounce. - Code action copies the context for the selected finding.
PR 13: agent-context-v2
Purpose: turn ripr context into a test-writing brief.
Deliverables:
- Recommended test location.
- Related existing tests.
- Fixture or builder hints.
- Missing input values.
- Missing oracle shape.
- Suggested assertion shapes.
- Confidence and stop reasons.
Acceptance:
- Context packet is golden-tested.
- CLI and LSP use the same packet shape.
PR 14: ripr-config-v1
Purpose: let repositories teach ripr topology and oracle conventions.
Deliverables:
- Workspace-root config discovery.
- Missing config accepted.
- Useful invalid-config errors.
- Test topology override.
- Custom oracle macro config.
- Snapshot, mock, and external-boundary config.
Acceptance:
- Config changes oracle classification only through explicit rules.
PR 15: suppression-v1
Purpose: support honest noise control without hiding the model.
Deliverables:
- Inline suppression comment form.
- Config suppression form.
- Required reason.
- Optional expiry.
-
--show-suppressed.
Acceptance:
- Suppressed findings remain visible when requested.
- Suppression rate can be measured.
PR 16: sarif-ci-policy
Purpose: support PR workflows without making default CI noisy.
Deliverables:
- SARIF output.
- Markdown summary.
- JSON artifact guidance.
- Advisory mode.
- Opt-in failure modes.
- Baseline-aware mode.
Acceptance:
- SARIF validates.
- SARIF results point to static evidence locations.
- Blocking policy is opt-in.
PR 17: cargo-mutants-calibration-scaffold
Purpose: compare static predictions with real mutation results.
Deliverables:
- Import cargo-mutants output through
cargo xtask mutation-calibrationand publicripr calibrate cargo-mutants. - Match static seam evidence to runtime records by
seam_idfirst and unambiguous normalized file/line second; report ambiguous file/line candidates separately. - Emit advisory static class vs runtime outcome reports at
target/ripr/reports/mutation-calibration.{json,md}. - Keep mutation-runtime language out of static findings; runtime vocabulary is confined to calibration/runtime reports.
Acceptance:
- Runtime mutation vocabulary appears only in explicit calibration data and static-language checks remain clean.
PR 18: persistent-cache-v1
Purpose: cache stable facts after the fact model is worth caching.
Deliverables:
- File-hash invalidation.
- Warm
FileFactsreuse. - LSP reuse of test and oracle facts.
- Graceful stale-cache recovery.
Acceptance:
- Warm run avoids reparsing unchanged files.
Required Gates
Rust PRs must run:
cargo fmt --check
cargo check --workspace --all-targets
cargo test --workspace
cargo clippy --workspace --all-targets -- -D warnings
cargo doc --workspace --no-deps
cargo package -p ripr --list
cargo publish -p ripr --dry-run
Extension PRs must run:
cd editors/vscode
npm ci
npm run compile
npm run package