Skip to content

[Task] Prove selected product maintenance artifacts and clean consumers #8693

Description

@sfmskywalker

Current scheduling — native proof awaits owner decision, 2026-10-10

This Task remains open and unaccepted, with all seven acceptance criteria open. Project52 uses Todo / Not Ready / Verification Pending for this external gate because it has no Blocked status. The required resume event is the owner's MySQL/.NET10 support decision, followed by the corresponding reviewed compatibility correction and fresh complete six-cell native/artifact proof. The prior native run remains FAILED; historical failures are not converted into passes.

Controller #8694 at29147db1019bd583fd2a3631c2b647a39d80ae42 has exact-head independent APPROVE + HIGH (including73-path review-chain coverage), Greptile5/5 and no unresolved review threads. All applicable exact-head controller CI is now terminal green, and the original consolidated artifact has passed the bounded independent audit and lead admission recorded in the linked current evidence. The controller is not merged; neither green controller CI nor that bounded artifact audit establishes the required six-cell native acceptance. Current evidence.

#8636 is now the sole active implementation/delivery Task. No framework/support gate is narrowed, no unchanged known-failing native graph is rerun, and no publication/maintenance activation/archive is performed. The requirements and retained evidence below remain in force; earlier execution-status statements are historical where they differ from this checkpoint.


Program #8194. Parent Feature #8217. Dependency: #8688 is accepted on actual main 570aaa95b09a7043273df2bcd4f533f216804694; seven-criterion acceptance.

Outcome

Build and verify the actual selected-product maintenance release artifacts for Core, Studio and Extensions on supported 3.8/3.9 source lines, without publication. Consume an exact reviewed eligible product plan; prove that retained packages and clean consumers match its selection, dependencies, source and version. Include Studio's existing same-version WASM/npm pair. This is the next bounded deliverable before selected-artifact publisher/recovery and operational cutover.

Implementation boundaries

Reuse the accepted planner/native NuGet semantics, maintenance build/SDK metadata/archive/test verification and clean-consumer/npm isolation primitives. Add a bounded selected-plan adapter; do not redesign the release engine or change the sealed consolidated 3.10 executor. The plan alone selects product, line, source and requested version. Require fresh complete eligible prerequisites and exact plan SHA before product work. Bind planner/artifact controllers, source SHA/tree, ownership/register/recipe identities and actual run/attempt separately.

Start with one real Studio 3.8 vertical control before scaling the matrix: original host publish using supported TFM/recipe, genuine content and manifests, original two npm names, same-run local WASM archive, original wrapper build/package bytes, normal clean downstream lifecycle/import/Vite. Historical inline copy and dist packaging are not defects merely because the current-main verifier expects a different helper/ledger. Reproduce a functionality defect before proposing any separately reviewed maintenance source correction. Then run a generator-bearing Extensions control before the full six-cell proof. No historical publisher workflow is executed.

Preserve original product recipes and output policies, including real manifests, resources, satellite assemblies, content/browser assets and applicable source-supported framework coverage. Planning's NoBuild/file-collection projections are not artifact evidence. If original full recipes privately pack excluded copies, record those private outputs explicitly and retain only the selected set. Do not claim excluded projects were never built or packed. Keep product tests/affected source closure separate from publication selection.

Clean consumers use empty caches, verified exact local selected archives and already reviewed external prerequisites under original feed mapping. Reject source/ProjectReference fallback, unintended versions or feeds, and selected-package registry fallback. Require all selected applicable-TFM restore/compile coverage with output/content-only accounting, plus representative source-supported runtime contracts joined to exact archived loaded bytes. Preserve original assembly-version policies, including Extensions' 1.0.0+source-SHA policy; requested NuGet identities remain exact. Representative runtime proof is not complete product behavioral certification.

Acceptance criteria

  • Exact reviewed plan bytes/hash, controller/source/version/line and complete selected/excluded partition bind all work. Wrong/stale/ineligible/malformed/ambiguous inputs fail before builds or remote side effects; no version/tag/ref is allocated and no prerequisite is added to publication scope.
  • Source-faithful Studio 3.8 vertical and generator-bearing Extensions controls prove actual producer/consumer interfaces before the full matrix. Any genuine source defect is surfaced and corrected through an explicit reviewed maintenance continuation, never silently patched or bypassed.
  • All six Core/Studio/Extensions × 3.8/3.9 cells retain genuine selected main/symbol package bytes and complete inventories, original SDK dependency/framework metadata, manifest/resources/content/satellite/compiler/SourceLink proof as applicable, and an exact artifact-name/package/version bijection to the plan. Private recipe-only excluded outputs are explicitly accounted for.
  • Applicable original product tests execute with explicit legitimate skip/placeholder policy. Every selected applicable TFM has clean restore/compile proof; representative product runtime contracts join loaded bytes to exact verified archives and dependencies. Genuine failed outcomes are retained and remain failures.
  • Both historical Studio lines prove original WASM and React wrapper npm artifacts as an atomic same-version/source pair, exact local-WASM dependency and normal downstream lifecycle/import/Vite behavior. Current/main [Task] Build and prove paired Studio npm archives from Core without publishing #8679 evidence is not relabeled as historical proof.
  • Normal/optimized focused contracts cover plan admission, selection, archive safety and isolation/fallback negatives. Preserve unchanged Slack/coupled-unit contracts. Extend release-plan workflow path filters for all consumed runtime/test helpers and input documents, including maintenance containment and ownership data, addressing PR8692 comment4233486842 before changing any omitted input. Actionlint and exact-controller hosted proofs pass; original provider ZIP identities and independent safe archive readback are verified without publishing raw diagnostics.
  • Document commands, supported boundaries, failures and remaining publisher/cutover steps. Obtain author-independent exact-head APPROVE + HIGH, current-head green CI and Greptile5/5, then normal shared/main integration and criterion-by-criterion acceptance. Keep Feature [Feature] F3.1: Explicit release-unit manifests and scoped versions #8217 and Program [Program] Elsa 3 integration ecosystem: monorepo consolidation, independent releases, and researched connector catalog #8194 open for their remaining outcomes.

Non-goals / authority

No registry upload, publisher credentials/OIDC activation, protected environment approval, permanent maintenance refs/protections, deployed/browser certification, authority retirement or repository archival. No full3.10 certification, Slack provider or React Studio implementation. Publication/recovery must later consume the same verified original bytes without rebuilding and handle matching/missing/conflicting/unknown remote outcomes.

Work only in isolated worktrees; preserve user changes. Root owns one active delivery Task, integration and QA. Sol6.1High suits the compatibility-sensitive adapter; Luna6ExtraHigh suits bounded independent receipt/archive audits. Adopt any matching existing PR before starting a competing implementation.

Definition of ready

Existing owner decisions settle product boundaries, original historical source lines, Secrets ownership and atomic Studio pairing. The 2026-10-09 source/tooling proposal maps reused seams and their incompatibilities; #8688 acceptance supplies the reviewed planner prerequisite. Board/issue/open-PR/source refresh completed before claim: #8688 is closed Done/Accepted/Passed, all35 advertised3.8/3.9 release refs remain contained, and no matching open artifact PR exists. Current main is570aaa95b09a7043273df2bcd4f533f216804694, treecfc65f4e6db94b06eb6794a67acec4f3143531ec. Existing shared target codex/elsa-integration-program was recreated at accepted main 570aaa95b09a7043273df2bcd4f533f216804694 after the prior integration merged. The current slice targets that shared branch through an ordinary PR. Keep #8636 Todo/AgentReady/Pending as the existing independent ready buffer.

Activity

  1. self-assigned this
    on Oct 9, 2026
  2. added
    enhancementNew feature or request
    prio highIs on the roadmap for the near-future
    elsa 3This issue is specific to Elsa 3
    on Oct 9, 2026
  3. sfmskywalker commented on Oct 9, 2026

    @sfmskywalker
    MemberAuthor

    Claimed after fresh board/open-PR/source refresh and actual-main acceptance of predecessor #8688. Native parent #8217 and resolved native dependency #8688 verified. Sole active Task: In Progress / Assigned / Verification Pending; #8636 stays the independent ready buffer.

    Assigned Sol6.1High an exclusive clean isolated writer checkout, new branch from accepted main570aaa95, while the lead's isolated QA checkout stays detached at that main. First bounded assignment is the selected-plan admission/setup + source-faithful Studio3.8 producer/npm/consumer interface and cheap contracts. The release-plan path-filter correction is included before any omitted input changes. The worker will freeze a coherent candidate and exact live invocation for lead preflight/source review before the first costly control; no full matrix is started yet.

    This preserves all seven Task criteria and the later publisher/cutover outcomes. It is not permission to upload packages, activate credentials, allocate versions/tags, create permanent maintenance refs/protections, retire authorities or archive repositories. Root retains integration, review, final QA and acceptance.

  4. sfmskywalker commented on Oct 9, 2026

    @sfmskywalker
    MemberAuthor

    First-control checkpoint: Sol 6.1 froze candidate b005e14 (tree960d978b328c97e1659c5a2229b5b2831ff7cc1f), covering admission/setup, selected archive retention, original historical Studio npm control, focused contracts and the #8692 trigger-filter follow-up. The lead read the full five-file change and independently ran all14 focused contracts in normal and optimized Python modes; both passed.

    Author-independent Luna6ExtraHigh review found two issues that must be corrected before the first costly control: local executions must not acquire arbitrary operator-supplied GitHub run identities, and Node/SDK preflight must happen before the full historical producer. The writer is correcting both in its isolated checkout; the frozen b005 review remains attributable to b005 only. No product build, npm consumer, registry upload or source mutation was executed. A fresh GET-only Studio3.8 planning process is currently live.

    This is a first-control implementation checkpoint, not all-six artifact/consumer proof or Task acceptance. Core/Extensions adapters, selected NuGet clean consumers, generator-bearing control, complete six-cell hosted receipts and final review/integration remain required. All seven acceptance criteria stay open; #8693 remains the sole active Task.

  5. sfmskywalker commented on Oct 9, 2026

    @sfmskywalker
    MemberAuthor

    First-control source corrections are now reviewed at exact head11930eaa40426860d882e09b625dce738350fd5c, treecdb30a21af353b32392095935dabf33bc8145ed6. Author-independent Luna6ExtraHigh gave APPROVE + HIGH for readiness to execute the first local Studio3.8 control only; both previous source findings are closed. Local controls now use an explicit UUID/UTC envelope and reject GitHub context, and Node/npm/SDK/original host TFM preflight precedes expensive product work. The lead read the full correction, verified source/report hashes, reran19 normal+19 optimized focused contracts and actionlint, all passing. Source gate SHA256420dab35faf87e3a6d1e659b1d808de64bd754b9e26ebaf298ed02893e6fa319.

    The fresh planning process remains live; no product build or npm consumer has started. Its exact original planning assets will be hash-bound and retained privately for later transitive dependency/consumer checks. The read-only next-interface audit also identified an Extensions generator control using the original HTTP I/O shell feature and its original assembly-version policy; that is preparation, not an executed control.

    All seven Task acceptance criteria remain open. This source-readiness approval is not full-task, hosted CI, Greptile, archive or consumer acceptance, and author-independent approval of the final implementation/ordinary shared-main integration remains required.

  6. sfmskywalker commented on Oct 9, 2026

    @sfmskywalker
    MemberAuthor

    Actual cheap tool/source compatibility check at11930eaa found a deterministic preflight interface failure before any product build: the shared runner's merged log includes workstation build-slot wrapper stderr before MSBuild's otherwise valid JSON property output. This is retained as a failed preflight, not a Studio product failure or successful control. No wrapper bypass or arbitrary prefix stripping is planned.

    A bounded Luna6ExtraHigh correction now owns the producer worktree to parse actual stdout separately and keep diagnostics private, with regression coverage for stderr noise and genuine command/stdout failures. Exact-head source review will be repeated before the live setup/product control. Verification is Failed during rework; Task remains In Progress/Assigned. The previous11930 first-control approval is historical and does not approve the forthcoming corrected head.

    Sol6.1 continues the same Task's selected NuGet consumer adapter in a separate isolated worktree while the original fresh planning process remains live. No additional active board Task, product/consumer execution, provider publication or operational activation occurred. Raw wrapper diagnostics include local process details and remain private.

  7. sfmskywalker commented on Oct 9, 2026

    @sfmskywalker
    MemberAuthor

    Verification checkpoint: the first Studio 3.8 setup failed before any product build, at fresh-prerequisite verification. Root diagnosis isolated a verifier clock-order bug: npm history was fetched after the timestamp used to assess its freshness. The deterministic regression reproduces the failure on 6437b07; correction 8c034bd passes 21 normal and 21 optimized contracts and awaits author-independent review. The original failed receipt is preserved; no acceptance is claimed.

    Separately, independent audit reconciled all 50 original planning asset snapshots and 150 project/framework joins to the exact plan and source hashes. This is planning-input evidence only. The consumer candidate's native metadata check passes 140/150 cases and fails closed on 10 Blazor Server cases where separate original restore snapshots disagree on external versions. That adapter assumption is under investigation; no product defect or consumer success is claimed. Verification remains Failed, #8693 remains the sole active Task, and all seven acceptance criteria remain open. No publication, allocation, permanent ref/protection, publisher activation or archival occurred.

  8. sfmskywalker commented on Oct 9, 2026

    @sfmskywalker
    MemberAuthor

    The clock correction at 8c034bd now has author-independent Spec/Standards APPROVE with HIGH confidence, 21 normal/21 optimized contracts, root full-delta review and scoped actionlint. A new source-faithful Studio 3.8 producer/npm control is running on that exact head and has passed prerequisite admission into the original product recipe. Both historical frontend bundles built; .NET work is in progress. The prior failed setup remains retained. Verification is Running; no artifact or consumer success is claimed.

    The consumer candidate remains under correction for producer-controller binding and retained runtime path privacy; the ten snapshot-closure conflicts remain unresolved proof inputs. Current main remains570aaa95. GitHub had removed the shared codex/elsa-integration-program branch after PR8692; it has been recreated from exact current main570aaa95 for ordinary slice integration. This is only the delivery branch, not a permanent product maintenance ref or publisher activation. Latest stable is still3.9.0 in Core, Studio and Extensions. #8693 is the sole active Task; #8636 remains the ready buffer.

  9. sfmskywalker commented on Oct 9, 2026

    @sfmskywalker
    MemberAuthor

    Studio 3.8 selected-artifact verification is still running on frozen, independently reviewed controller 8c034bd7a37f9a990d464e4936bafa1116ac7ccc. The original frontend and .NET builds completed. Test logs report 834 passes across 14 framework results; the producer has advanced through test reconciliation. The original recipe produced 100 NuGet archives, and inventory, SDK metadata and content verification are in progress. No final successful artifact/npm receipt or clean-consumer acceptance is claimed.

    The root integration candidate 1dd8550584cd024654a4b691f5dcf1431a65ba49 includes the controller/privacy corrections and native NuGet consumer discovery. Focused contracts pass 43 tests normally and 43 with optimized Python; actionlint and diff checks pass. Author-independent source review is running. The consumer implementation has not executed a real restore/build/runtime yet.

    A narrow follow-up will keep historical producer admission separate from fresh current consumer prerequisites if the long producer run outlasts the original planning window. It must preserve the exact successful producer bytes and fail before consumer restore/build on current ineligibility or prerequisite metadata drift; it will receive independent review before execution.

    The Extensions first-control source audit identifies Elsa.IO.Http as the generator-bearing representative and preserves its distinct package and assembly version policies. This is source preparation only. All six product/line artifact and clean-consumer cells remain required, and all seven Task acceptance criteria remain unchecked. The board still has one active delivery Task, #8693, In Progress / Assigned / Verification Running. No publication, publisher activation, maintenance-ref activation or archival occurred.

  10. sfmskywalker commented on Oct 9, 2026

    @sfmskywalker
    MemberAuthor

    The selected-consumer source at local integration candidate da345b203ba92ec2e16d42d9d8c8ee25b9ce4173 (tree 4263e8218f9bfc23ac512b5513d0ee841c7e605b) now has author-independent specification and Elsa 3 standards APPROVE + HIGH. Root read back the full review and immutable Git identities. All 49 normal and 49 optimized producer/consumer contracts, actionlint and diff checks pass.

    The prior framework-reference finding was reproduced: five archive-metadata mutations passed the old admission code. The correction now compares native archive framework-reference groups with the plan before the test project can supply them. Historical producer-start admission and new current consumer prerequisite checks are separate; the unchanged default producer admission still rejects the original expired plan now. No caller as-of clock or expiry extension was introduced.

    Source-gate receipt SHA-256: a8a855d63145b15f9fc9f0a62f2b4e36bc7f7aea78ca5f6c970d7945611be7a9. Independent review JSON SHA-256: 260d7f0946d0129df9b8057d4c2bbf0185374ce9af34d051a6580c47aa3e0976. This is source approval, not current-head hosted CI, merge approval or actual consumer proof.

    Root separately read all 100 actual original Studio 3.8 NuGet archives: their package/version/name partition, exact source commit, dependency groups and framework-reference groups match the plan. That archive observation does not replace SDK/compiler/symbol/content verification, which is still running under frozen producer controller 8c034bd7. No final successful producer/npm receipt exists yet, so actual clean-consumer execution remains gated. The generator-bearing Extensions adapter is being prepared separately within this same Task. All seven acceptance criteria remain open; no publication or operational cutover occurred.

  11. 23 remaining items

  12. sfmskywalker commented on Oct 11, 2026

    @sfmskywalker
    MemberAuthor

    Bounded Core failure audit confirms both original d91 jobs failed in the original product recipe at package-verification with source-producer-unverified (run38070354211 attempt1; Core3.8 job114266313330 and Core3.9 job114266313122). The exact package, TFM, PDB document and rejected subcheck remain unknown. The existing source-pinned diagnosis maps the reason to nontracked-PDB producer verification, whose public failure projection discards the underlying exception; the attempt contains zero provider artifacts, so runner-local receipt hashes cannot supply their contents.

    This establishes the failure class, not its package-level cause or proof that the current preview.53 correction resolves those failures. No MySQL attribution is supported for Core. No native rerun, build/test, artifact download or publication occurred during this audit. All seven Task acceptance criteria remain open, and the MySQL/.NET10 support decision remains pending for Extensions.

  13. sfmskywalker commented on Oct 11, 2026

    @sfmskywalker
    MemberAuthor

    Fresh external constraint check — 2026-10-11 01:00 UTC. The published MySQL provider constraint has not changed. NuGet.org's current Pomelo index contains172 versions and no10.x entry; the documented official nightly feed contains609 versions and no10.x entry. Lead re-fetched both indexes and stable9.0.0 nuspec and matched the worker's exact SHA256s. Lead additionally fetched the newest documented nightly9.0.1-servicing.1.ci.20250817232638 nuspec: it also requires Microsoft.EntityFrameworkCore.Relational [9.0.0,9.0.999] and targets net8.0, as stable9.0.0 does. Neither resolves the observed EF Core Relational10.0.9 conflict. .NET runtime compatibility does not widen that EF Core dependency range.

    Upstream EF Core10 work #2019 and #2047 remains unmerged proposal-level input, not released-package evidence. No owner support choice is inferred, no MySQL/.NET10 criterion is waived, and no source-build/provider substitution or EF-major downgrade was made. This constraint remains separate from Core's actual d91 source-producer-unverified failure.

    Task #8693 remains Todo / Not Ready / Verification Pending with all criteria open. Task #8636 is the sole active Task; its independently reviewed native diagnostic 38099782866 is live at3c3a90d64160e508a4c5ad61f52d1cd677ec0bda against source correction c0f. All source PR #8719 CI is green; no native result, merge, publisher activation or archival is claimed. This refresh performed no package restore/build or producer rerun.

    Primary package metadata: NuGet version index, stable9.0.0 nuspec, and official nightly feed documentation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

elsa 3This issue is specific to Elsa 3enhancementNew feature or requestprio highIs on the roadmap for the near-futuretriaged

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions