Назад
docs/ITERATION_LOG.md
# ITERATION LOG > Короткий active tail значимых итераций. Старые записи вынесены в `archive/ITERATION_ARCHIVE.md`. ### ITER-0442 — 2026-08-01 — Retrospective recorded window `6781-6790` and simplified the next-cycle memory contract - Goal: - classify the real delivery and churn pattern across cycles `6781-6790` from the original `codex_live.md` evidence instead of from late summaries only; - preserve only the process corrections that directly reduce repeated stale-gate and docs-memory churn in the next window. - Result: - active process memory now records window `6781-6790` as: - `6781` = `release/promotion`: shipped repo-owned hosted proof for `action_depth_pause`, promoted runtime `8cb13f1`, prod public/auth green, prod boundary-fixture `404` left as separate operational debt - `6782` = `docs-memory`: preserved the new anonymous `/dashboard` continuity contract and roadmap seeds after the broader auth slice, without new runtime/release delta - `6783` = `product/runtime`: implemented grouped-overload `action_depth_pause` recommendation-quality follow-up as a local clean-review candidate - `6784` = `release/promotion`: promoted that grouped-only follow-up through runtime `52040a5` with prod smoke green - `6785` = `no-release-delta`: rechecked the anonymous continuity residue against refreshed upstream and correctly stopped at stale-local equivalence - `6786` = `docs-memory`: moved live memory from the grouped follow-up back to the next promotion-review lane with exact accepted-line/prod anchors - `6787` = `docs-memory`: preserved the unfinished anonymous handoff verification lane, but no new product or release consequence survived beyond later curator truth - `6788` = `product/runtime`: added the repo-owned anonymous hosted handoff proof seam and advanced the lane to accepted-line/deployed runtime - `6789` = `docs-memory`: preserved the narrower prod blocker on runtime `06b2e0a` so the next executor could continue the same gate - `6790` = `release/promotion`: closed the same anonymous handoff gate on prod; source on `06b2e0a` was already correct and the real fix was sequential prod rebuild/restart/save on that accepted line - counted by outcome: - `5` change-bearing cycles - `3` useful docs-memory syncs - `1` honest `no release delta` - `1` avoidable docs-memory churn cycle - recurring blockers were narrower than earlier windows: - missing or brittle repo-owned hosted proof paths still delayed promotion until a canonical fixture/verify command existed - once the proof path existed, stale active blockers and strategist restatements risked stealing the next cycle even after the same gate had already moved - control-plane/process docs now push one tighter correction: - executor delivery plus one curator sync should normally end the memory work for one fact - if prod recovery closes a gate on the same accepted-line commit, replace the old blocker immediately and move on - Runtime changes: - none; retrospective/process/docs only. - Checks: - read full `codex_live.md` evidence for cycles `6781-6790` - compared active prompts, `AGENTS.md`, and living docs against current git state ### ITER-0441 — 2026-08-01 — Curator advanced the anonymous handoff gate to runtime `06b2e0a` and preserved the narrower prod foregrounding blocker - Goal: - replace the stale deployed anchor `72963fe` with the executor-confirmed accepted-line/prod truth after the two real follow-up fixes; - preserve the exact remaining blocker so the next executor continues the same gate instead of rechecking deploy/proxy drift or reopening auth breadth. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `TESTING.md`, `SMOKE_TESTS.md`, `DEV_RUNBOOK.md`, `PROD_RUNBOOK.md`, `OPEN_QUESTIONS.md`, `TECH_DEBT.md`, `DECISIONS.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now treat runtime `06b2e0a` as the current accepted-line/prod truth for the still-unpromoted anonymous handoff seam; - living memory now preserves the exact accepted-line fix chain and proof bases: - clean review worktree = `/tmp/trajectory-anon-handoff-gate` - `9745cd3` = `fix: uncache dashboard request context` - `06b2e0a` = `fix: allow anonymous handoff session routes` - local aligned proof on `http://127.0.0.1:3016` is green - canonical dev hosted proof on `https://dev.journeyup.ru` is green - `/root/apps/trajectory-prod` deployed runtime `06b2e0a` - the remaining blocker is now preserved more narrowly than the previous marker-only wording: - prod restore writes `bundle_restored` - prod creates the expected `anonymous_identity_recovery_handoff_v1:*` session for the restored profile - both `GET https://journeyup.ru/dashboard` and direct app endpoint `GET http://127.0.0.1:3000/dashboard` still omit `dashboard-anonymous-handoff-discovery` - next executor should inspect why prod `getActiveQuestionStateForUser` still does not foreground that fresh handoff session immediately after restore - Runtime changes: - none in this curator pass; runtime `06b2e0a` and the two preceding deploys were already accepted-line and deployed before memory sync. - Checks: - docs-only consistency pass against the executor result, current local branch state `main...origin/main [ahead 9, behind 105]` at `e5eb05a`, accepted-line/prod runtime `06b2e0a`, and the active anonymous smoke/runbook docs set ### ITER-0440 — 2026-08-01 — Curator synced the deployed anonymous handoff hosted-proof seam and left the exact prod marker blocker live - Goal: - align living docs with the executor-confirmed accepted-line/deployed follow-up `72963fe` without overstating the lane as fully promoted; - preserve the exact runtime seam, proof commands, and final prod blocker so the next executor can finish the same slice instead of reopening planning. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, and `ROADMAP.md` now classify the lane as `deployed but not fully promoted` on runtime `72963fe`, with the live step narrowed to the last prod hosted anonymous smoke gate; - `SYSTEM_MAP.md`, `DOMAIN_MODEL.md`, and `DECISIONS.md` now preserve the runtime-owned discovery seam itself: - source `src/features/dashboard/anonymous-handoff-discovery.ts` - dashboard render seam `src/features/dashboard/components/dashboard-home-surface.tsx` - repo-owned readers `scripts/lib/anonymous-handoff-smoke.ts` and `scripts/read-anonymous-handoff-dashboard-contract.ts` - `TESTING.md`, `SMOKE_TESTS.md`, `DEV_RUNBOOK.md`, `PROD_RUNBOOK.md`, `TECH_DEBT.md`, `OPEN_QUESTIONS.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now preserve the exact proof chain and blocker: - local aligned proof on `http://127.0.0.1:3001` is green - canonical dev hosted proof on `https://dev.journeyup.ru` is green - `/root/apps/trajectory-prod` deployed runtime `72963fe` - prod public/auth smoke is green on `https://journeyup.ru` - final repo-owned hosted anonymous smoke is still red because restored `GET https://journeyup.ru/dashboard` returns `200` without the expected `dashboard-anonymous-handoff-discovery` marker - Runtime changes: - none in this curator pass; runtime `72963fe` was already accepted-line and deployed before memory sync. - Checks: - docs-only consistency pass against the executor result, current local branch state `main` at `e5eb05a`, accepted-line/deployed runtime `72963fe`, and the active anonymous smoke/runbook docs set ### ITER-0439 — 2026-08-01 — Curator synced the promoted anonymous continuity handoff and moved live focus past the shipped specimen - Goal: - align living docs with the executor-confirmed promotion of `anonymous identity recovery handoff verification`; - preserve exact branch/commit/deploy/smoke truth while moving active memory off the now-shipped specimen and onto the next real product-bearing step. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, and `ROADMAP.md` now treat runtime `3b0d0be` with docs sync `ecccf49` as the latest accepted-line/prod truth for the anonymous continuity handoff lane instead of keeping the old locale-blocked clean-review state; - `SYSTEM_MAP.md`, `DECISIONS.md`, and `DOMAIN_MODEL.md` now preserve the exact shipped contract: - one accepted SFM specimen launches from already-shipped restore/attach continuity facts - localized copy now resolves truthfully in RU/EN on `/dashboard` and `/sfm/[sessionId]` - attached-path wording stays distinct where runtime facts differ - anonymous breadth remains `/dashboard` plus the owned `(dashboard-protected)` session path only - `TESTING.md`, `SMOKE_TESTS.md`, `OPEN_QUESTIONS.md`, `TECH_DEBT.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now preserve the exact proof chain and the only remaining limitation: - local proof base URL `http://127.0.0.1:3014` is green through public smoke, auth matrix, anonymous dashboard smoke, and owner `/operator/sfms/anonymous_identity_recovery_handoff_v1 -> 200` - `/root/apps/trajectory-prod` deployed runtime `3b0d0be` - prod public/auth smoke is green on `https://journeyup.ru` - the remaining hosted prod anonymous gap is helper extraction only: repo-owned smoke reaches `/dashboard?recoveryRestore=restored` and renders localized continuity copy, but still cannot recover the launched `/sfm/<sessionId>` from hosted dashboard HTML after restore - Runtime changes: - none in this curator pass; runtime `3b0d0be` and docs sync `ecccf49` were already shipped before memory sync. - Checks: - docs-only consistency pass against the executor result, current local branch state `main` at `e5eb05a`, accepted-line runtime `3b0d0be`, docs sync `ecccf49`, and the active SFM/auth/smoke docs set ### ITER-0438 — 2026-08-01 — Curator narrowed the anonymous handoff blocker to one locale-contract defect - Goal: - replace the stale pre-bootstrap memory for `anonymous identity recovery handoff verification` with the executor-confirmed near-gate state; - preserve the exact remaining blocker, green local gates, and next executable proof sequence without overstating the slice as accepted-line or prod truth. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, and `ROADMAP.md` now record that `/tmp/trajectory-anon-handoff` is installed and largely green rather than blocked on missing `node_modules`; - living memory now preserves the real local runtime facts: - specimen wiring exists across runtime, reviewed/generated/trusted/builder registries - `/sfm/[sessionId]`, `/sfm/[sessionId]/answer`, and `/sfm/[sessionId]/complete` moved under `(dashboard-protected)` so anonymous dashboard identity can reach its own bounded handoff session - the restore route locally fixes `bundle_restored` attribution to the switched-to profile - local proof already reached `/dashboard?recoveryRestore=restored`, launched the specimen, and reached `/sfm/<sessionId>` on `http://127.0.0.1:3014` - `SYSTEM_MAP.md`, `TESTING.md`, `SMOKE_TESTS.md`, `TECH_DEBT.md`, `OPEN_QUESTIONS.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now preserve the narrow remaining stop: - unresolved `⟦tutorial.definitions...⟧` keys on `/dashboard` and `/sfm/[sessionId]` - root cause in `src/lib/i18n.ts`: nested-vs-flat locale shape mismatch while `t()` resolves nested paths - final anonymous smoke, owner `/operator/sfms/anonymous_identity_recovery_handoff_v1 -> 200` proof, commit/push/merge, deploy, and prod smoke remain unrun - Runtime changes: - none in this curator pass; accepted-line runtime remains `52040a5`, latest docs sync on `origin/main` remains `16e8291`, and `/root/apps/trajectory-prod` was not changed. - Checks: - docs-only consistency pass against the later executor continuation, clean review worktree state `review/anonymous-identity-recovery-handoff` at `16e8291`, and the active promotion-review docs set ### ITER-0437 — 2026-08-01 — Curator preserved the unfinished `anonymous identity recovery handoff verification` clean-review lane - Goal: - sync living docs to the executor-confirmed state of the next accepted-machine slice without overstating it as accepted-line or prod truth; - keep the next executor from re-investigating the clean worktree path, partial files, blocker, and first required bootstrap step. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, and `ROADMAP.md` now move the live `draft-to-runtime promotion review path` from a generic label to the exact local clean-review specimen `anonymous identity recovery handoff verification`; - living memory now preserves the precise unreleased facts: - clean review worktree = `/tmp/trajectory-anon-handoff` - review branch = `review/anonymous-identity-recovery-handoff` - executor started from refreshed `origin/main` `16e8291` - partial code exists in `src/features/sfm/anonymous-identity-recovery-handoff.ts`, `src/features/sfm/components/anonymous-identity-recovery-handoff-panel.tsx`, `src/features/sfm/runtime.ts`, `src/app/(dashboard-protected)/dashboard/page.tsx`, and `src/features/sfm/session-route-access.ts` - reviewed/generated artifacts remain placeholders, and builder/operator/test wiring is incomplete - only attempted check was `pnpm typecheck`, which failed before compilation because the clean worktree had no `node_modules` and therefore no `tsc` - `OPEN_QUESTIONS.md`, `TECH_DEBT.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now preserve the exact next-step bootstrap and the still-open trigger/branch-family questions without rewriting accepted-line runtime maps. - Runtime changes: - none in this curator pass; accepted-line runtime remains `52040a5`, docs sync on `origin/main` remains `16e8291`, and `/root/apps/trajectory-prod` was not changed. - Checks: - docs-only consistency pass against the executor result, local branch state `main...origin/main [ahead 9, behind 100]` at `e5eb05a`, refreshed accepted-line anchor `16e8291`, and the active promotion-review docs set ### ITER-0436 — 2026-08-01 — Curator synced the promoted grouped-overload `action_depth_pause` follow-up and returned live focus to promotion review - Goal: - align living docs with the executor-confirmed promotion of `grouped-overload action_depth_pause recommendation-quality follow-up`; - preserve exact branch/commit/deploy/smoke truth while moving active memory off the already shipped grouped lane. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, and `ROADMAP.md` now treat runtime `52040a5` with docs sync `16e8291` as the latest accepted-line/prod truth and return live focus to `draft-to-runtime promotion review path`; - `SYSTEM_MAP.md` and `DECISIONS.md` now preserve the exact bounded runtime consequence: - only grouped-overload `action_depth_pause` deepened - grouped completion plus active-question payload now carry one richer grouped-specific rationale summary and one safer concrete next-step recommendation - `calendar-boundary` pause semantics remain at the earlier shipped `8cb13f1` level - `OPEN_QUESTIONS.md` now treats grouped follow-up classification as closed and keeps only the changed-since question about whether `calendar-boundary recommendation quality` should ever reopen before the broader promotion-review lane. - Runtime changes: - none in this curator pass; runtime `52040a5` and docs sync `16e8291` were already shipped before the memory sync. - Checks: - docs-only consistency pass against the executor result, current branch state `main` at `e5eb05a`, and the active week-first/SFM docs set ### ITER-0435 — 2026-08-01 — Curator synced the sharper grouped-overload `action_depth_pause` follow-up without overstating release truth - Goal: - preserve the first concrete post-`8cb13f1` recommendation-gap verdict as exact living memory instead of leaving active docs on the earlier generic fork; - keep accepted-line/prod truth `8cb13f1` / `0c5fb12` explicit while recording the new grouped-only local/dev-green candidate separately. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, and `ROADMAP.md` now move live focus from the abstract `grouped or boundary recommendation quality` choice to the exact bounded slice `grouped-overload action_depth_pause recommendation-quality follow-up`; - `SYSTEM_MAP.md` and `DECISIONS.md` now preserve the sharper contract and rationale: - clean upstream worktree = `/tmp/trajectory-grouped-pause-followup` - grouped pause alone gains one richer inspectable rationale plus one safer concrete next-step recommendation derived from clustered overload context - `calendar-boundary` pause remains at the earlier shipped level - no new apply path, no new canonical `events` mutation family, and no auth widening were introduced - `OPEN_QUESTIONS.md` now treats lane selection as answered for this cycle and leaves only the later boundary follow-up question plus the broader return to `draft-to-runtime promotion review path`. - Runtime changes: - none in this curator pass; accepted-line runtime remains `8cb13f1`, docs sync on `origin/main` remains `0c5fb12`, and the grouped recommendation-quality follow-up remains local clean-review truth only. - Checks: - docs-only consistency pass against the executor result, current branch state `main` at `e5eb05a`, refreshed accepted-line anchor `origin/main` `0c5fb12`, and the active SFM week-first docs set ### ITER-0434 — 2026-08-01 — Curator recorded the anonymous `/dashboard` continuity recheck as upstream-equivalent stale residue - Goal: - preserve the exact executor-confirmed verdict for the requested old auth-continuity scope without disturbing the later shipped live focus; - distinguish accepted-line anonymous `/dashboard` truth from the stale rollback residue still visible on local `main` `e5eb05a`. - Result: - living active docs stayed unchanged outside this tail entry because the current product/runtime memory already preserves the promoted anonymous `/dashboard` chain and the current live focus already sits later at runtime `8cb13f1` / docs sync `0c5fb12`; - [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now records the exact bounded recheck: - refreshed `origin/main` `0c5fb12` already contains the anonymous continuity chain `2049727 -> 5009809/c707615 -> 1c01c48/309f43b -> b07c4df -> cb7a9f2 -> cd14e08 -> 124b221 -> 6f9abe3 -> 652eec1 -> 7722ee7` - accepted-line code still carries the contract in `src/proxy.ts`, `src/lib/dashboard-identity.ts`, `src/lib/mixed-mode-access.ts`, `src/app/(dashboard-protected)/layout.tsx`, `src/app/(dashboard-protected)/dashboard/attach-credentials/route.ts`, `src/db/schema/anonymous-profiles.ts`, and repo-owned anonymous smoke wiring - current local `main...origin/main [ahead 9, behind 98]` is not a promotion candidate for that scope because the visible anonymous bucket is mostly destructive rollback/noise against already-shipped upstream files and migrations - release truth therefore stays explicit: - verdict = `no release delta` - tests / smoke / commit / push / deploy / prod smoke = `not run` - no active roadmap/task reorder followed from this pass - Runtime changes: - none; docs/state-sync only. - Checks: - docs-only consistency pass against the executor result, current branch state `e5eb05a` vs `origin/main` `0c5fb12`, existing active auth memory, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0433 — 2026-08-01 — Curator synced the promoted `action-depth pause` truth and moved live focus past the shipped gate - Goal: - align living docs with the executor-confirmed promotion of `action-depth pause runtime contract`; - remove the stale local-only/release-blocked wording without reopening the already shipped product decision. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, and `ROADMAP.md` now treat runtime `8cb13f1` with docs sync `0c5fb12` as the latest accepted-line/prod truth for the current approved-action-depth decision, and they move the immediate live step from finishing pause release gates to choosing the next bounded slice from that shipped baseline; - `DECISIONS.md`, `DOMAIN_MODEL.md`, and `SYSTEM_MAP.md` now record `action_depth_pause` as shipped runtime truth rather than local clean-review state; - `TESTING.md`, `SMOKE_TESTS.md`, `DEV_RUNBOOK.md`, `PROD_RUNBOOK.md`, `TECH_DEBT.md`, `OPEN_QUESTIONS.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now preserve the exact repo-owned hosted smoke path, the real dev/prod commands, the review/proof branch `origin/review/action-depth-pause-hosted-proof`, and the remaining prod hosted-domain-data limitation. - Runtime changes: - none in this curator pass; runtime `8cb13f1` and docs sync `0c5fb12` were already shipped before the memory sync. - Checks: - docs-only consistency pass against the executor result, active docs, runbooks, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0432 — 2026-08-01 — Curator corrected the `action-depth pause` gate state after the executor finished dev smoke and isolated the real hosted-proof blocker - Goal: - replace the stale “all smoke still unrun” memory for the local `action-depth pause` candidate with the exact executor-confirmed gate state; - keep accepted-line/prod truth `b3c5217` / `ac9397e` unchanged while preserving the real next blocker for release completion. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DECISIONS.md`, `DOMAIN_MODEL.md`, `TECH_DEBT.md`, and `TESTING.md` now all distinguish the already-green dev gates from the still-red hosted proof: - green on canonical dev `https://dev.journeyup.ru`: - `DEV_PUBLIC_BASE_URL=https://dev.journeyup.ru scripts/smoke-public-dev.sh` - `AUTH_URL=https://dev.journeyup.ru NEXTAUTH_URL=https://dev.journeyup.ru DEV_PUBLIC_BASE_URL=https://dev.journeyup.ru pnpm smoke:auth:matrix -- --email action-depth-pause-dev-smoke@example.test --password 'TempSmokePass!2026' --name '[trajectory-smoke-fixture] action depth pause dev matrix' --role owner` - still incomplete: - hosted/dev proof for the changed `/sfm/[sessionId]/complete` pause branch - commit / push / merge - prod deploy / prod smoke - living memory now preserves the exact hosted-proof blocker instead of the earlier generic “not run” wording: - missing `SMOKE_OWNER_*` in `.env.local` required the documented dev override fixture path - the temporary proof harness failed on `tsx` stdin/module/env plumbing before route assertion - the grouped temporary seed used the wrong schema; runtime expects `grouped_overload_cluster_plan_session_context_v3` - the final rerun also failed because the temporary seed file had already been cleaned up - [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now keeps the fuller unreleased slice evidence, including the corrected smoke status and the next executor step inside `/tmp/trajectory-action-depth-pause`. - Runtime changes: - none in this curator pass; accepted-line runtime remains `b3c5217`, docs sync on `origin/main` remains `ac9397e`, and `action_depth_pause` remains local clean-review truth only. - Checks: - docs-only consistency pass against the executor result, the active-doc `action-depth pause` sections, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0431 — 2026-08-01 — Curator synced the local `action-depth pause` candidate and closed the third-family fork in product memory - Goal: - preserve the exact executor-confirmed local candidate after the old `third approved-action family vs action-depth pause` fork was resolved in code; - keep accepted-line/prod truth `b3c5217` / `ac9397e` separate from the still-unreleased clean-review implementation in `/tmp/trajectory-action-depth-pause`. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, and `ROADMAP.md` now move live focus from a generic fork to the exact local slice `action-depth pause runtime contract`; - `DECISIONS.md` now records the product decision explicitly: for the current baseline, approved-action depth stops at the two shipped families and falls back to recommendation-first `action_depth_pause` instead of opening a third canonical mutation family; - `SYSTEM_MAP.md`, `DOMAIN_MODEL.md`, `TESTING.md`, `OPEN_QUESTIONS.md`, and `TECH_DEBT.md` now preserve the exact local candidate surface and the honest gate state: - clean upstream-based worktree `/tmp/trajectory-action-depth-pause` - runtime files `src/features/sfm/calendar-boundary-consent-preview.ts`, `src/features/sfm/grouped-overload-cluster-plan.ts`, `src/features/dashboard/active-question.ts`, `src/app/(protected)/sfm/[sessionId]/complete/page.tsx`, `src/features/sfm/components/action-depth-pause-panel.tsx`, and `src/lib/i18n.ts` - reviewed/generated/fixture updates for both approved-action bundles - green repo gates in that worktree: - targeted pause-branch suite - `pnpm exec tsc --noEmit --pretty false` - `pnpm sfm:authoring:generate` - `pnpm sfm:authoring:parity` - `pnpm sfm:authoring:validate` - `pnpm exec next typegen` - `pnpm typecheck` - `pnpm lint` - placeholder-env `pnpm build` - still unrun: - public smoke - signed-in auth matrix - hosted/dev SFM smoke for the new pause branch - commit / push / merge - prod deploy / prod smoke - [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now keeps the fuller evidence trail for this unreleased clean-review candidate. - Runtime changes: - none in this curator pass; accepted-line runtime remains `b3c5217`, docs sync on `origin/main` remains `ac9397e`, and the new `action_depth_pause` contract is still local clean-review truth only. - Checks: - docs-only consistency pass against the executor result, active docs, and the executor-reported clean-worktree verification list ### ITER-0430 — 2026-08-01 — Curator synced the shipped grouped hosted proof and moved live focus to action-depth choice - Goal: - replace the stale blocked-proof memory with exact accepted-line/dev/prod truth after the hosted grouped proof shipped; - move active memory forward to the next change-bearing product decision instead of leaving the closed proof gate as live focus. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `TESTING.md`, `SMOKE_TESTS.md`, `OPEN_QUESTIONS.md`, `TECH_DEBT.md`, and `DECISIONS.md` now treat `grouped approved-action hosted proof` as shipped truth on runtime `b3c5217`, with accepted-line docs sync `ac9397e`; - living memory now preserves the exact hosted-dev attachment fix: - `pnpm dev:hosted:recover` uses repaired `scripts/recover-hosted-dev.sh` - that helper reattaches PM2 by `pm_cwd` instead of restarting a stale checkout - canonical hosted dev `https://dev.journeyup.ru` now serves `/tmp/trajectory-grouped-hosted-proof` on port `3001` - living memory now preserves the exact grouped hosted-proof release chain: - review/proof branch `origin/review/grouped-hosted-proof` advanced to `b3c5217` - accepted line advanced to runtime `b3c5217` - `/root/apps/trajectory-prod` deployed runtime `b3c5217` - docs sync then advanced `origin/main` and prod checkout to `ac9397e` - the next live focus is now product-shaped: - `third approved-action family vs action-depth pause` - prod grouped hosted smoke hardening stays separate as operational debt because seeded `/sfm/[sessionId]/complete` still returned `404` on `https://journeyup.ru` - Runtime changes: - none in this curator pass; runtime `b3c5217` and docs sync `ac9397e` were already established before memory sync. - Checks: - docs-only consistency pass against the executor result, current local branch state `main...origin/main [ahead 9, behind 96]`, accepted-line docs truth `ac9397e`, and the grouped hosted-proof sections in active docs ### ITER-0429 — 2026-08-01 — Curator synced the pushed grouped hosted-proof candidate and isolated hosted-dev attachment drift - Goal: - replace the stale `local-only scaffold + red hosted proof` wording with the exact executor-confirmed branch/commit/smoke truth for the grouped hosted-proof step; - keep accepted-line/prod runtime `1af4137` separate from the pushed clean-review candidate `6a7f7db` and from the still-red canonical hosted-dev gate. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, `TECH_DEBT.md`, `TESTING.md`, and `SMOKE_TESTS.md` now preserve the exact pushed proof state: - clean review worktree `/tmp/trajectory-grouped-hosted-proof` - review branch `review/grouped-hosted-proof` - review commit `6a7f7db` - pushed proof ref `origin/review/grouped-hosted-proof` - grouped `/sfm/[sessionId]/complete` seam fix in `src/app/(protected)/sfm/[sessionId]/complete/page.tsx` so grouped sessions no longer fall through onboarding write-through - repo-owned grouped fixture/write-path files plus `smoke:grouped-overload:*` package wiring - living memory now preserves the exact green local hosted proof on `http://127.0.0.1:3014`: - public smoke passed - signed-in auth matrix passed - hosted grouped proof passed - hosted `/complete` returned `200` - apply deferred exactly one canonical edge event - anchor plus other cluster rows stayed unchanged - stale review failed closed through `apply_blocked_conflict` / `event_changed_since_review` - fixture cleanup removed the temporary data - blocker classification is now corrected from app/runtime logic to hosted-dev infra attachment drift: - `https://dev.journeyup.ru` was still serving the stale PM2/runtime definition from `/root/apps/trajectory-dev` - `pnpm dev:hosted:recover` from the clean review worktree restarted that stale PM2 definition instead of attaching hosted dev to the clean candidate - PM2 logs therefore still showed grouped hosted `/complete` `500` on the old runtime - canonical dev service in `/root/apps/trajectory-dev` was restored afterward - release truth stays strict and separate: - pushed review proof exists - no merge / fast-forward - no deploy - no prod smoke - exact next executable commands are now preserved in active memory: - `cd /tmp/trajectory-grouped-hosted-proof && pnpm exec pm2 logs trajectory-dev --lines 120 --nostream` - then reattach `https://dev.journeyup.ru` to this clean worktree on port `3001` - rerun public smoke, auth matrix, and `pnpm smoke:grouped-overload:hosted` on `https://dev.journeyup.ru` - Runtime changes: - none in this curator pass; accepted-line and prod runtime remain `1af4137`. - Checks: - docs-only consistency pass against the executor result, current local branch state `main...origin/main [ahead 9, behind 93]`, accepted-line/prod truth `1af4137`, and the existing grouped hosted-proof sections in active docs ### ITER-0428 — 2026-08-01 — Curator synced the blocked grouped hosted-proof candidate without overstating accepted-line truth - Goal: - preserve the executor-confirmed state of the live `grouped approved-action hosted proof and next action-depth decision` step so the next executor can continue from exact bounded facts instead of re-investigating the clean review worktree; - keep accepted-line/prod truth `1af4137` separate from the unfinished hosted-proof candidate. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, and `TECH_DEBT.md` now record that the live step is no longer only a generic fixture gap: a partial implementation exists in clean review worktree `/tmp/trajectory-grouped-hosted-proof` on top of accepted line `origin/main` / `1af4137`; - living memory now preserves the exact local candidate surface: - grouped fixture/runtime files `src/features/sfm/grouped-overload-smoke-fixture.ts`, `src/features/sfm/grouped-overload-smoke-fixture.test.ts`, `scripts/manage-grouped-overload-smoke-fixture.ts`, `scripts/verify-grouped-overload-smoke.ts`, `scripts/verify-grouped-overload-stale-review-smoke.ts`, `scripts/run-grouped-overload-hosted-smoke.ts`, `scripts/lib/grouped-overload-smoke.ts`, and `scripts/lib/grouped-overload-smoke.test.ts` - package wiring for `smoke:grouped-overload:*` - bounded runtime seam patch in `/tmp/trajectory-grouped-hosted-proof/src/app/(protected)/sfm/[sessionId]/complete/page.tsx` so grouped sessions no longer fall through to onboarding write-through - release truth stays explicit and unchanged: - targeted grouped tests, authoring gates, `next typegen`, `typecheck`, `lint`, placeholder-env `build`, public smoke, and auth matrix all passed - hosted grouped proof is still red because `GET /sfm/<sessionId>/complete` returned `500` on `https://dev.journeyup.ru` for the seeded grouped session and the failure reproduced after `pnpm dev:hosted:recover` - grouped cleanup and auth cleanup still completed successfully - no commit, push, merge, deploy, or prod smoke happened - the exact next executable step remains: - diagnose the server-side cause of hosted grouped `/complete` `500` for the seeded grouped session shape - rerun `pnpm dev:hosted:recover` - rerun `SMOKE_USER_EMAIL=... SMOKE_USER_PASSWORD=... SMOKE_USER_NAME=... pnpm smoke:grouped-overload:hosted` - Runtime changes: - none in this curator pass; accepted-line and prod runtime remain `1af4137`. - Checks: - docs-only consistency pass against executor result, current local branch state `main...origin/main [ahead 9, behind 93]`, accepted-line/prod truth `1af4137`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0427 — 2026-08-01 — Curator synced the promoted grouped edge defer apply slice and moved live focus past the second approved-action decision - Goal: - replace the now-stale `second real external-style action decision` planning state with the executor-confirmed accepted-line and production truth for shipped runtime `1af4137`; - preserve exact grouped review/apply, branch/release, smoke, and fixture-gap facts without reopening another docs-only paraphrase cycle. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, and `ROADMAP.md` now treat `grouped edge defer apply lane` as shipped truth on runtime `1af4137`, not as a live candidate; - living memory now preserves the exact approved grouped-action contract: - only reviewed branch `protect_anchor_and_defer_edge` can apply - review freezes exactly one grouped cluster snapshot plus exactly one selected edge-event snapshot - apply mutates exactly one canonical `events` row by setting `status = deferred` for that selected edge event - the anchor event and every other cluster row remain unchanged - stale review leaves canonical truth unchanged and reports `event_changed_since_review` through fail-closed `apply_blocked_conflict` - no multi-row apply, alternate edge selection, hidden regrouping, provider write-back, or second source of truth were introduced - live focus therefore moves forward one step inside the same lane: - next unlocked step = `grouped approved-action fixture/write-path for hosted proof` - next product decision after that = `decide whether any third approved-action family is justified or whether action depth should pause` - `persisted draft store decision` remains later-only behind changed-since evidence - the release limitation is preserved explicitly instead of being mistaken for a runtime defect: - deeper hosted `/sfm/[sessionId]/complete` grouped apply smoke stayed blocked because no documented repo-owned grouped-cluster domain-data fixture/write path exists yet - Runtime changes: - none in this curator pass; runtime `1af4137` was already pushed, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, current local branch state `main` `e5eb05a`, accepted-line/prod truth `1af4137`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0426 — 2026-08-01 — Curator synced the promoted boundary-carry apply slice and moved live focus to the second approved-action decision - Goal: - replace the now-stale `real external action consent/apply lane` planning state with the executor-confirmed accepted-line and production truth for shipped runtime `a320bc7`; - preserve exact branch/release/smoke/fixture-gap facts without reopening another docs-only paraphrase cycle. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, and `ROADMAP.md` now treat `calendar-boundary carry apply` as shipped truth on runtime `a320bc7`, not as a live candidate; - living memory now preserves the exact approved-action contract: - only reviewed branch `approve_preview` can apply - review freezes exactly one future current-week timed event snapshot - apply mutates exactly one canonical `events` row into the exact reviewed next-day same-time carry slot - visible outcomes are `draft_ready`, `event_carried_across_boundary`, and fail-closed `apply_blocked_conflict` - stale review leaves canonical truth unchanged and reports `event_changed_since_review` - no alternate slot search, grouped silent apply, provider write-back, or second source of truth were introduced - live focus therefore moves forward one step inside the same lane: - next unlocked step = `second real external-style action decision` - bounded operational follow-up = `boundary-carry apply fixture/write-path` - `persisted draft store decision` remains later-only behind changed-since evidence - the release limitation is preserved explicitly instead of being mistaken for a runtime defect: - deeper hosted `/sfm/[sessionId]/complete` carry/apply smoke stayed blocked because no documented repo-owned domain-data fixture/write path exists yet - Runtime changes: - none in this curator pass; runtime `a320bc7` was already pushed, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, current local branch state `main` `e5eb05a`, accepted-line/prod truth `a320bc7`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0425 — 2026-08-01 — Curator synced the promoted grouped-overload slice and moved live focus to real external action consent/apply - Goal: - replace the stale unfinished `multi-event overload clustering` clean-review narrative with the executor-confirmed accepted-line and prod truth; - preserve exact release, smoke, branch, and limitation facts without reopening another docs-only restatement cycle. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, and `ROADMAP.md` now treat `multi-event overload clustering` as shipped truth on runtime `4cab1b5` with docs sync `0a8f4e1`, not as an unfinished clean review worktree; - living memory now preserves the exact grouped-overload contract: - trigger = `small_related_current_week_commitment_cluster` - guard = exactly one shared-project cluster of `2-3` current-week commitments within `36h` - bounded family = `protect_anchor_and_shrink_cluster`, `protect_anchor_and_defer_edge`, `cut_cluster_together` - `not_answered` and `low_confidence` still fail closed to raw capture - canonical `events` still do not mutate - live focus therefore moves forward inside the same lane: - next unlocked step = `real external action consent/apply lane` - `persisted draft store decision` remains later-only behind changed-since evidence - grouped-overload follow-up stays later-only unless changed-since evidence justifies deeper observability or apply semantics - the release limitation is preserved explicitly instead of being mistaken for regression: - generic owner smoke for `/sfm/grouped-overload` stayed `404` because no repo-owned grouped-cluster domain-data fixture path exists yet - Runtime changes: - none in this curator pass; runtime `4cab1b5` and docs sync `0a8f4e1` were already pushed, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, current local branch state `main...origin/main [ahead 9, behind 91]`, accepted-line/prod truth `4cab1b5` / `0a8f4e1`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0424 — 2026-08-01 — Curator synced the unfinished grouped-overload clean-review candidate without overstating runtime truth - Goal: - preserve the executor-confirmed state of the live `multi-event overload clustering` slice so the next executor can continue from exact bounded facts instead of re-investigating the clean review worktree; - keep accepted-line/prod truth `8a31302` separate from the unfinished local candidate. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, and `ROADMAP.md` now record that the live slice is no longer only a strategist decomposition: a partial implementation exists in clean review worktree `/tmp/trajectory-grouped-overload-review` on top of refreshed `origin/main` `8a31302`; - living memory now preserves the exact local candidate surface: - new files `src/features/dashboard/grouped-overload-trigger.ts`, `src/features/sfm/grouped-overload-cluster-plan.ts`, and `src/app/(protected)/sfm/grouped-overload/page.tsx` - wiring in `src/features/events/data.ts`, `src/features/dashboard/active-question.ts`, `src/features/sfm/runtime.ts`, `src/features/sfm/authoring/{index.ts,reviewed.ts,generated.ts,trusted-runtime.ts}`, `src/features/sfm/builder/{adapter.ts,authoring.ts}`, and `scripts/generate-sfm-authoring-artifacts.ts` - new fixture `src/features/sfm/authoring/fixtures/grouped-overload-cluster-plan.ts` - release truth stays explicit and unchanged: - reviewed/generated artifacts were not created - targeted tests, typegen, typecheck, lint, build, smoke, commit, push, merge, deploy, and prod smoke were not run - the exact next executable step remains to finish registry/test/`i18n` surfaces in that same clean worktree, then generate artifacts and run the bounded check suite before any promotion decision - Runtime changes: - none in this curator pass; accepted-line and prod runtime remain `8a31302`. - Checks: - docs-only consistency pass against the executor result, current local branch state `main...origin/main [ahead 9, behind 89]`, and active docs ### ITER-0423 — 2026-08-01 — Curator synced the shipped eighth specimen and moved live focus past boundary preview - Goal: - replace the still-live `calendar-boundary consent preview` planning state with the executor-confirmed accepted-line and production truth for the eighth accepted week-first machine; - preserve the exact split between dirty local checkout `main` `e5eb05a`, accepted-line/prod runtime `8a31302`, and the earlier seventh-specimen baseline `7fb5699` / `5959fd1`. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DOMAIN_MODEL.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, `TESTING.md`, `TECHNICAL_STRATEGY.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now treat `calendar-boundary consent preview` as shipped truth instead of the live next candidate; - living memory now preserves the exact promoted eighth-specimen contract: - canonical trigger opens only when exactly one future current-week timed event would cross the week boundary on its exact next-day carry - bounded preview/consent family = `approve_preview`, `reject_preview`, `safer_internal_only` - reviewed/generated/trusted bundle paths are checked in - owner route `/operator/sfms/calendar_boundary_consent_preview_v1` is part of the shipped diagnostics surface - `not_answered` and `low_confidence` still fail closed to raw capture, and canonical `events` still do not mutate silently - live focus therefore moves forward inside the same authoring/promotion lane: - next unlocked step = `multi-event overload clustering` - competing later follow-up still preserved = `real external action consent/apply lane` - `persisted draft store decision` remains later-only behind changed-since evidence - Runtime changes: - none in this curator pass; runtime `8a31302` was already pushed, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, current local branch state `main...origin/main [ahead 9, behind 88]`, accepted-line/prod truth `8a31302`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0422 — 2026-08-01 — Retrospective recorded the 6761-6770 throughput lesson and trimmed process churn - Goal: - evaluate window `6761-6770` against real shipped product/release movement rather than log formality; - keep only the process corrections that were supported by evidence. - Result: - the window is now preserved as a high-throughput period with eight change-bearing slices: - rebuild apply deepened through `e07576b`, `ebf55f4`, `a36723f` - recommendation-first week reduction shipped on `6612be0` - accepted-line branch cleanup closed on `dd6efb5` - promotion-review diagnostics shipped on `ff3befa` - first reviewed-artifact refresh workflow shipped on `f460867` - seventh accepted specimen `new-constraint insertion triage` shipped on `7fb5699` with docs sync `5959fd1` - repeated avoidable churn is now explicit: - strategist often restated the next slice after curator had already moved live focus and preserved release truth; - some active docs were broadly rewritten when only `latest promoted runtime`, `latest docs sync`, or the next live slice had changed. - prompts and agent rules were tightened toward: - `one new fact -> one memory update` - no strategist file edits when curator already preserved the same roadmap consequence - updating stable anchors instead of rotating long shipped ladders - Runtime changes: - none; retrospective/process/docs only. - Checks: - full read of retrospective window `6761-6770` - current prompts plus active docs inspected against current git state in `/root/apps/ControlPlane` and `/root/apps/trajectory-dev` ### ITER-0421 — 2026-08-01 — Curator synced the shipped seventh specimen and moved live focus past selection - Goal: - replace the still-live `seventh accepted specimen selection` planning state with the executor-confirmed accepted-line and production truth for `new-constraint insertion triage`; - preserve the exact split between dirty local checkout `main` `e5eb05a`, accepted-line runtime `7fb5699`, docs sync `5959fd1`, and the older refresh-workflow baseline `f460867`. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DOMAIN_MODEL.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, `TESTING.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now treat `new-constraint insertion triage` as shipped truth instead of the next candidate; - living memory now preserves the exact promoted seventh-specimen contract: - canonical trigger = `single_current_week_new_hard_constraint` - bounded family = `keep_new_constraint`, `move_other_commitment`, `cut_week_scope`, `defer_other_pressure` - reviewed/generated/trusted bundle paths are checked in - owner route `/operator/sfms/new_constraint_insertion_triage_v1` is part of the shipped diagnostics surface - `not_answered` and `low_confidence` still fail closed to raw capture, and canonical `events` still do not mutate silently - live focus therefore moves forward inside the same authoring/promotion lane: - next unlocked step = `calendar-boundary consent preview` - competing later fork still preserved = `multi-event overload clustering` - `persisted draft store decision` remains later-only behind changed-since evidence - Runtime changes: - none in this curator pass; runtime `7fb5699` and docs sync `5959fd1` were already pushed, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, current local branch state `main...origin/main [ahead 9, behind 88]`, accepted-line truth `7fb5699` / `5959fd1`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0420 — 2026-08-01 — Strategist turned the seventh-specimen step into a concrete week-first ladder - Goal: - avoid leaving the live SFM lane at the abstract label `seventh accepted specimen selection` after curator had already preserved the shipped refresh workflow on `f460867`; - pick a product-first default order for the next accepted machine without reopening already-closed refresh/diagnostics or older machine-choice forks. - Result: - `ACTIVE_TASKS.md`, `ROADMAP.md`, `PROJECT_STATUS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now preserve one explicit seventh-specimen order: - first `new-constraint insertion triage` - second `calendar-boundary consent preview` - third `multi-event overload clustering` - living memory now also preserves why the first candidate wins: - shipped runtime already handles reported overload, pause/return, slipped single commitments, four one-event repair families, and recommendation-first minimum-week cuts; - the sharper remaining week-first gap is still the earlier moment when a new hard constraint lands before the week has already degraded into slip or explicit overload. - stale open-question pressure was reduced too: - old fourth-machine rebuild-choice questions that are already answered by shipped `cd447d9` were removed from the live question set; - the remaining live fork is only whether changed-since evidence should displace the new default order. - Runtime changes: - none; strategist/doc-memory only. - Checks: - current git branch/worktree inspection against `main...origin/main [ahead 9, behind 86]` - docs-only consistency pass planned through diff inspection ### ITER-0419 — 2026-08-01 — Curator synced the shipped reviewed-artifact refresh workflow and advanced live focus to the seventh specimen - Goal: - replace the still-live `reviewed artifact refresh workflow` planning state with the executor-confirmed accepted-line and production truth; - preserve the exact split between dirty local checkout `main` `e5eb05a`, accepted-line/prod runtime `f460867`, and the earlier diagnostics-only baseline `ff3befa` / `79f6216`. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, `TESTING.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now treat the first checked-in refresh workflow as shipped truth instead of the next candidate; - living memory now preserves the exact promoted refresh contract: - canonical machine = `home-intake-week-first` - canonical command = `pnpm sfm:authoring:refresh -- home-intake-week-first` - canonical files = `src/features/sfm/authoring/refresh.ts`, `src/features/sfm/authoring/refresh-contract.ts`, `scripts/refresh-sfm-authoring-artifacts.ts` - refresh rebuilds the reviewed artifact from trusted runtime truth, regenerates the generated projection, and fails closed on foreign machine key, artifact absence, invalid refreshed document, and projection mismatch - `/operator/sfms/[sfmKey]` remains read-only and now shows the same refresh contract, while `initial_onboarding_first_week_assembly` proves post-refresh `in_sync` - the first refresh run produced no reviewed/generated content diff because the checked-in `home-intake-week-first` bundle was already aligned - live focus therefore moves forward inside the same lane: - next unlocked step = `seventh accepted specimen selection` - later only = `persisted draft store decision`, `multi-machine refresh sweep`, and any stronger promotion automation - Runtime changes: - none in this curator pass; runtime/docs commit `f460867` was already pushed, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, current local branch state `main...origin/main [ahead 9, behind 86]`, accepted-line/prod truth at `f460867`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0418 — 2026-08-01 — Curator synced the shipped operator promotion-review diagnostics and advanced live focus to refresh workflow - Goal: - replace the still-live `operator promotion-review diagnostics` planning state with the executor-confirmed accepted-line and production truth; - preserve the exact split between dirty local checkout `main` `e5eb05a`, pushed/prod runtime `ff3befa`, and docs/control-plane sync `79f6216`. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, `TESTING.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now treat operator promotion-review diagnostics as shipped truth instead of the next candidate; - living memory now preserves the exact promoted operator contract: - owner-authenticated `/operator/sfms/[sfmKey]` renders one explicit read-only `Promotion-review diagnostics` section for accepted shipped bundles; - surfaced state is now operator-visible, not CLI-only: artifact presence, explicit `in_sync` vs `mismatch`, mismatch taxonomies `reviewed_artifact_drift`, `generated_artifact_drift`, `trusted_runtime_drift`, review key, trusted runtime definition key, reviewed artifact path, generated artifact path, and trusted runtime module path; - exact shipped route bindings are: - `initial_onboarding_first_week_assembly -> home-intake-week-first` - `event_report_v1 -> event-report-write-through` - `week_rebuild_current_week_v1 -> week-rebuild-overload-replan` - `re_entry_v1 -> pause-return-check-in` - `slipped_event_triage_v1 -> slipped-event-triage` - `weekly_planning_v1 -> minimum-viable-week-replan` - the lane stays read-only: no reviewed-artifact rewrite, no runtime-registry mutation, no persisted draft store, no DB write, and no auth widening. - live focus therefore moves forward inside the same authoring/promotion lane: - next unlocked step = `reviewed artifact refresh workflow` - later only = `seventh accepted specimen selection` - `persisted draft store decision` and continuity telemetry follow-ups remain dormant behind changed-since evidence. - Runtime changes: - none in this curator pass; runtime `ff3befa` and docs sync `79f6216` were already pushed, and runtime `ff3befa` was already deployed and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, current local branch state, accepted-line docs sync `79f6216`, prod runtime `ff3befa`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0417 — 2026-08-01 — Curator closed branch pruning on accepted line and returned live focus to the next SFM lane - Goal: - sync living docs to the executor-confirmed accepted-line closure of `historical branch pruning / anchor cleanup`; - preserve the exact split between runtime truth `6612be0`, docs/control-plane sync `dd6efb5`, and the untouched dirty local checkout `main` `e5eb05a`. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, `TECHNICAL_STRATEGY.md`, `TECH_DEBT.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now treat branch pruning as closed accepted-line throughput work instead of the live task; - living memory now preserves the exact accepted-line cleanup truth: - `origin/main` advanced to `dd6efb5` (`docs: close branch pruning cleanup`) - pushed review proof branch is `origin/review/historical-branch-pruning-anchor-cleanup` - register baseline now tracks accepted-line checkpoint `29f2256` - parked bucket `staged-event-report-residue` remains explicit as duplicate local index residue - six local mirrors were removed after their memory was preserved in the register: - `feature/anonymous-trust-ux-hardening` - `feature/attached-identity-reassurance` - `release/attached-identity-reassurance` - `release/minimal-help-pattern-contract-promote` - `release/auth-matrix-helper` - `release/knowledge-boundary-recovery` - live focus now returns to `draft-to-runtime promotion review path` as the next product-bearing SFM lane, while `persisted draft store decision` and `continuity-use repeat restore follow-up` stay dormant behind changed-since evidence only. - Runtime changes: - none in this curator pass; `dd6efb5` is docs/register/tooling only, and `/root/apps/trajectory-prod` was intentionally not updated. - Checks: - docs-only consistency pass against executor result, `origin/main` `dd6efb5`, current local branch/register state, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0416 — 2026-08-01 — Curator synced the promoted `minimum_viable_week_replan` runtime and moved live focus to branch pruning - Goal: - replace the still-live local-candidate memory for `minimum_viable_week_replan` with the executor-confirmed accepted-line and production truth; - preserve the exact distinction between shipped runtime `6612be0`, docs sync `29f2256`, and the still-dirty local checkout `main` `e5eb05a`. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DOMAIN_MODEL.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, `TESTING.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now treat `minimum_viable_week_replan` as shipped truth instead of a blocked candidate; - living memory now preserves the exact promoted fifth response contract: - machine key = `minimum_viable_week_replan` - trigger = the week remains overloaded after the shipped four one-event rebuild apply families are insufficient - output = one recommendation-first survivable minimum-week cut with inspectable rationale - `not_answered` and `low_confidence` still fail closed to raw capture - no canonical `events` mutation, no bulk rewrite, no calendar write-back, and no second source of truth were introduced - the bounded release unblocker is preserved too: - Auth.js callback handling now preserves same-port loopback callback URLs - smoke-origin resolution now treats `AUTH_URL` as canonical and `NEXTAUTH_URL` as legacy fallback - signed-in smoke on `http://127.0.0.1:3014` is green and prod smoke on `https://journeyup.ru` is green - active focus therefore moves from release classification of this machine to `historical branch pruning / anchor cleanup`, while any fifth internal apply family stays closed by default unless changed-since evidence appears later. - Runtime changes: - none in this curator pass; runtime `6612be0` and docs sync `29f2256` were already pushed, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, current accepted-line/prod truth at `29f2256`, local git branch state, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0415 — 2026-08-01 — Curator synced the local `minimum_viable_week_replan` candidate and kept release truth separate - Goal: - turn the abstract `stop at four` strategist verdict into exact runtime/doc memory for the executor-confirmed clean-review candidate; - preserve the split between accepted-line/prod truth at `a36723f` / `10bf770` and the still-unreleased candidate in `/root/apps/trajectory-review-energy-collapse`. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, `TECHNICAL_STRATEGY.md`, `SYSTEM_MAP.md`, `DOMAIN_MODEL.md`, `DECISIONS.md`, `TESTING.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now record one exact local candidate instead of only a roadmap default; - living memory now preserves the exact candidate contract: - machine key = `minimum_viable_week_replan` - trigger = the week remains overloaded after the shipped four one-event rebuild apply families are insufficient - output = one recommendation-first survivable-minimum-week cut - rationale = inspectable explanation of why the machine chose week reduction instead of another internal repair - mutation boundary = no canonical `events` mutation, no bulk update, no calendar write-back, no second source of truth, no auth widening - authoring bundle = fixture + reviewed artifact + generated artifact + runtime helper + active-question routing - release truth stays explicit: - accepted-line/runtime prod truth remains `a36723f` - docs sync on `origin/main` remains `10bf770` - targeted tests, typegen, typecheck, lint, placeholder-env build, and public smoke on `http://127.0.0.1:3014` passed in the clean review worktree - commit/push, merge, deploy, and prod smoke remain `not run` because signed-in `pnpm smoke:auth:matrix` still redirects to `http://localhost:3014` instead of same-host `/dashboard` - Runtime changes: - none in this curator pass; the new machine remains local clean-review state only. - Checks: - docs-only consistency pass against executor result, current accepted-line/prod truth at `a36723f`, docs sync `10bf770`, local git branch state, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0414 — 2026-08-01 — Strategist turned the post-`a36723f` fork into a strict verdict ladder and queued branch-pruning after the next product step - Goal: - stop the live `stop at four or prove one sharper gap` focus from remaining too broad after the fourth rebuild apply family was already promoted; - convert the next decision into an explicit ladder that either returns to recommendation-first week reduction or reopens apply-depth growth under a much stricter fifth-family rule. - Result: - `ACTIVE_TASKS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, `TECHNICAL_STRATEGY.md`, and `PROJECT_STATUS.md` now preserve a tighter post-ship order: - first deliver one explicit four-family sufficiency verdict; - if the answer is `stop`, the default next machine is `energy-collapse / minimum-viable-week replan` with a bounded trigger, survival-cut recommendations, and inspectable rationale; - if the answer is `continue`, the fifth family must stay one-event-only, deterministic, review/apply-visible, and fail-closed enough to beat the recommendation-first fallback. - strategic memory now also turns git/release hygiene into one bounded follow-up instead of background drift: - local `main...origin/main` is refreshed to `ahead 9, behind 80`; - after the next product-bearing verdict or ship, run one explicit `historical branch pruning / anchor cleanup` pass against the branch register so local mirrors stop masquerading as unfinished delivery work. - Runtime changes: - none; strategist/doc-memory only. - Checks: - strategic-doc consistency pass against current branch state, release anchors, and the promoted `a36723f` baseline ### ITER-0413 — 2026-08-01 — Curator synced the promoted fourth rebuild apply proof and moved live focus past release classification - Goal: - replace the still-live `single-event rebuild same-week move apply release classification` planning state with the executor-confirmed accepted-line and production truth for the fourth explicit rebuild apply path; - preserve the exact distinction between promoted runtime `a36723f`, docs sync `10bf770`, retained review proof branch `origin/review/single-event-rebuild-same-week-move-apply`, and the still-dirty local checkout `main` `e5eb05a`. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DOMAIN_MODEL.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, `TESTING.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now treat the fourth rebuild apply family as shipped truth instead of a live release-classification lane; - living memory now preserves the exact promoted same-week-move contract: - rebuild review still freezes one selected current-week event snapshot before apply; - explicit action is `move_later_same_week`; - apply mutates exactly one canonical `events` row only when the exact next-day same-time slot still fits inside the frozen current-week boundary; - duration and status stay unchanged; - visible outcomes are `draft_ready`, `event_moved_later_same_week`, and fail-closed `apply_blocked_conflict`; - earlier `event_applied`, `event_released`, and `event_shrunk` paths remain intact; - recommendation-only branches, raw-capture fallback, auth boundaries, and no-calendar-write-back rules remain unchanged. - active focus therefore moves from release classification of that branch to the narrower post-ship question: should the rebuild lane now stop apply-depth growth at four, or does one sharper remaining internal repair gap still outrank `energy-collapse / minimum-viable-week replan`? - Runtime changes: - none in this curator pass; runtime `a36723f` and docs sync `10bf770` were already pushed, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, current accepted-line/prod truth at `a36723f`, docs sync `10bf770`, local git branch state, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0412 — 2026-08-01 — Curator synced the local fourth rebuild apply candidate and kept release truth honest - Goal: - replace the still-hypothetical `same-week move` planning state with the executor-confirmed local clean-review candidate facts; - preserve the exact split between promoted runtime `ebf55f4` / docs sync `14eb1f4` and the still-unpromoted branch `review/single-event-rebuild-same-week-move-apply`. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `DOMAIN_MODEL.md`, `SYSTEM_MAP.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, `TESTING.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now record the exact local candidate contract instead of only the strategist default; - living memory now preserves the deterministic same-week rule precisely: - canonical action = `move_later_same_week` - rebuild review still freezes one selected current-week event snapshot before apply - apply still mutates exactly one canonical `events` row - duration and status stay unchanged - deterministic slot rule = exact next-day same-time slot only, and only if that slot still fits inside the frozen current-week boundary - success outcome = `event_moved_later_same_week` - stale review still fails closed as `apply_blocked_conflict` - if the exact next-day slot is unsafe, apply mutates nothing and does not guess another slot - release truth stays explicit: - local checks and local smoke on `http://localhost:3014` are green - commit/push, merge to accepted line, production deploy, and prod smoke on `https://journeyup.ru` remain `not run` - latest promoted runtime on `origin/main` and `/root/apps/trajectory-prod` remains `ebf55f4` - Runtime changes: - none in this curator pass; the same-week move slice remains local clean-review state only. - Checks: - docs-only consistency pass against executor result, current living docs, current git branch state, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0411 — 2026-08-01 — Curator synced the promoted third rebuild apply proof and moved live focus past shrink itself - Goal: - replace the still-live `single-event rebuild shrink apply` planning state with the executor-confirmed accepted-line and production truth for the third explicit rebuild apply path; - preserve the exact distinction between promoted runtime `ebf55f4`, docs sync `14eb1f4`, retained review proof branch `origin/review/single-event-rebuild-shrink-apply`, and the still-dirty local checkout `main` `e5eb05a`. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DOMAIN_MODEL.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, `TESTING.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now treat the third rebuild apply family as shipped truth instead of the live next slice; - living memory now preserves the exact promoted shrink contract: - rebuild review still freezes one selected current-week event snapshot before apply; - explicit action is `shrink_in_place`; - eligibility is limited to scheduled timed events longer than `30` minutes; - apply keeps the same start and cuts the reviewed duration to half, never below `30` minutes; - visible outcomes are `draft_ready`, `event_shrunk`, and fail-closed `apply_blocked_conflict`; - earlier `event_applied` and `event_released` paths remain intact; - recommendation-only branches, raw-capture fallback, auth boundaries, and no-calendar-write-back rules remain unchanged. - active focus therefore moves from `ship shrink` to the narrower next fork: `fourth bounded rebuild apply family or stop at three`. - Runtime changes: - none in this curator pass; runtime `ebf55f4` and docs sync `14eb1f4` were already pushed, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, current accepted-line/prod truth at `ebf55f4`, docs sync `14eb1f4`, local git branch state, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0410 — 2026-08-01 — Strategist resolved the post-release rebuild fork into shrink-in-place as the next apply family - Goal: - stop the newly shipped `shift` plus `release` rebuild baseline from leaving the next move at the abstract question “third apply family or another recommendation-first machine?”; - choose the next bounded product slice in a way that deepens week-first repair without jumping to deletion-like or multi-event semantics. - Result: - `ACTIVE_TASKS.md`, `ROADMAP.md`, `PROJECT_STATUS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now treat `single-event rebuild shrink apply` as the live next slice instead of keeping the post-`e07576b` fork open-ended; - living memory now preserves the rationale explicitly: - after `move it` and `release it`, the next missing week-first proof is `make it smaller so it fits`; - this stays inside the same one-event rebuild review/apply contract and remains closer to overload/slip recovery than reopening another advisory-only machine; - deletion-like, completion-like, and multi-event semantics remain later because they widen semantic risk faster than this narrower repair move. - Runtime changes: - none; strategist/doc-memory only. - Checks: - current git branch/worktree inspection - docs-only consistency pass planned through `git diff --check` ### ITER-0409 — 2026-08-01 — Curator synced the promoted second rebuild apply proof and advanced live focus past release-vs-shift - Goal: - replace the still-live `single-event rebuild release apply` planning state with the executor-confirmed accepted-line and production truth for the second explicit rebuild apply path; - preserve the exact distinction between promoted runtime `e07576b`, later docs sync `2d4c121`, retained review proof branch `origin/review/single-event-rebuild-release-apply`, and the still-dirty local checkout `main` `e5eb05a`. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DOMAIN_MODEL.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, `TECHNICAL_STRATEGY.md`, `TESTING.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now treat the second rebuild apply family as shipped truth instead of the live next slice; - living memory now preserves the exact promoted release-apply contract: - rebuild review still freezes one selected current-week event snapshot before apply; - explicit apply mutates exactly one canonical `events` row by setting `status = deferred`; - prior timing remains inspectable and is not silently rewritten; - visible outcomes are `draft_ready`, `event_released`, and fail-closed `apply_blocked_conflict`; - the earlier `+7 days` path remains intact and still reports `event_applied`; - recommendation-only paths, raw-capture fallback, auth boundaries, and no-calendar-write-back rules remain unchanged. - active focus therefore moves from `release versus shift` to the narrower next question: whether any third bounded rebuild apply family outranks another recommendation-first machine from the stronger baseline formed by `8ba162b` plus `e07576b`. - Runtime changes: - none in this curator pass; runtime `e07576b` and docs sync `2d4c121` were already pushed, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, current accepted-line/prod truth at `e07576b`, docs sync `2d4c121`, local git branch state, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0408 — 2026-08-01 — Curator synced the promoted first rebuild apply proof and advanced live focus past “first apply” - Goal: - replace the still-live `bounded rebuild write-through follow-up` planning state with the executor-confirmed accepted-line and production truth for the first explicit rebuild apply path; - preserve the exact distinction between promoted runtime/docs `8ba162b`, pushed proof branch `origin/review/bounded-rebuild-apply`, and the still-dirty local checkout `main` `e5eb05a`. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DOMAIN_MODEL.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, `TECHNICAL_STRATEGY.md`, `TESTING.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now treat the first rebuild apply path as shipped truth instead of the next candidate; - living memory now preserves the exact promoted apply contract: - rebuild review freezes one selected current-week event snapshot; - explicit apply mutates exactly one canonical `events` row by shifting timing `+7` days; - visible outcomes are `draft_ready`, `event_applied`, and fail-closed `apply_blocked_conflict`; - changed-after-review events stop with inspectable conflict state instead of silent overwrite; - recommendation-only paths, raw-capture fallback, auth boundaries, and no-calendar-write-back rules remain unchanged. - active focus therefore moves from “first apply path” to the narrower next question: whether any second bounded rebuild apply family outranks another recommendation-first machine on top of the shipped `8ba162b` baseline. - Runtime changes: - none in this curator pass; runtime/docs commit `8ba162b` was already pushed, merged, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, current accepted-line/prod truth at `8ba162b`, local git branch state, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0407 — 2026-08-01 — Strategist resolved the post-slipped week-first fork into the first bounded apply lane - Goal: - stop the shipped `slipped-event-triage` baseline from leaving the next move as a generic week-first fork; - choose whether the product now needs another recommendation-first machine or the first narrow apply path over canonical `events`. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now treat `bounded rebuild write-through follow-up` as the live next slice instead of keeping `post-slipped-event next week-first choice` open-ended; - living memory now preserves the rationale explicitly: - six accepted machines already prove recommendation-first intake, branching, event reporting, overload rebuild, pause/return, and slipped-event triage; - the next missing product proof is one inspectable apply boundary under canonical `events`, not a seventh advisory branch by default; - `external action consent gate` stays later, because the next step is still internal bounded write-through rather than outbound or sensitive action semantics. - the remaining open question is now narrower: which exact first `events` mutation family is smallest and still useful enough to ship inside that bounded apply lane. - Runtime changes: - none; strategist/doc-memory only. - Checks: - current git state inspection in `/root/apps/trajectory-dev` - docs-only consistency pass with `git diff --check` on the updated strategic docs ### ITER-0406 — 2026-08-01 — Curator synced the promoted sixth accepted machine and moved live focus past residue cleanup - Goal: - replace the still-live `dirty local residue integration register` handoff with the executor-confirmed accepted-line and production truth for `slipped-event-triage`; - preserve the exact distinction between promoted runtime/docs `abf6989` and the still-dirty local checkout `main` `e5eb05a`. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `DOMAIN_MODEL.md`, `SYSTEM_MAP.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, `TECHNICAL_STRATEGY.md`, `TESTING.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now treat `slipped-event-triage` as shipped truth rather than the next candidate; - living memory now preserves the exact sixth-machine contract: - fixture `src/features/sfm/authoring/fixtures/slipped-event-triage.ts` - reviewed artifact `src/features/sfm/authoring/reviewed/slipped-event-triage.reviewed.json` - generated artifact `src/features/sfm/authoring/generated/slipped-event-triage.generated.json` - canonical trigger `single_current_week_slipped_commitment` - trigger guard = exactly one current-week slipped event candidate and that event is between `30` minutes and `72` hours late - bounded triage family = `keep_commitment`, `move_commitment`, `shrink_commitment`, `drop_commitment` - fail-closed fallback for `not_answered` and `low_confidence` - minimal observability fields `slippedEventAvailable`, `slippedEventOverridesWeekRebuildTrigger`, `slippedEventBranch`, and `slippedEventTrigger` - active focus therefore moves past residue cleanup and onto the next week-first choice: compare `bounded rebuild write-through follow-up` against another concrete recommendation-first machine, while keeping dirty local `main...origin/main [ahead 9, behind 73]` visible only as secondary git state. - Runtime changes: - none in this curator pass; runtime/docs commit `abf6989` was already pushed, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, current `origin/main` / prod truth at `abf6989`, local git branch state, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0405 — 2026-08-01 — Curator synced the promoted fifth accepted machine and separated shipped truth from dirty local residue - Goal: - replace the still-live `pause / return check-in` planning state with the executor-confirmed promoted runtime/docs truth; - preserve the exact split between promoted runtime `bd03dc6`, docs sync `6ac4d4e`, and the still-dirty local checkout `main` `e5eb05a`. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, `SYSTEM_MAP.md`, `DECISIONS.md`, `TECHNICAL_STRATEGY.md`, `TESTING.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now treat `pause-return-check-in` as shipped truth rather than the live next machine; - living memory now preserves the exact fifth-machine contract: - fixture `src/features/sfm/authoring/fixtures/pause-return-check-in.ts` - reviewed artifact `src/features/sfm/authoring/reviewed/pause-return-check-in.reviewed.json` - generated artifact `src/features/sfm/authoring/generated/pause-return-check-in.generated.json` - canonical trigger `current_week_return_after_inactivity` - trigger guard = current-week activity, at least `72` hours inactivity, and at least one current-week open event - bounded output = one orientation question or one short recommendation-first branch set - fail-closed fallback for `not_answered` and `low_confidence` - minimal observability fields that distinguish resume from rebuild - active focus therefore moved off the shipped machine itself and onto the now-closed residue handoff, because local `main...origin/main` still read `[ahead 9, behind 71]` at `e5eb05a` while shipped truth already lived on `origin/main`. - Runtime changes: - none in this curator pass; runtime `bd03dc6` and docs sync `6ac4d4e` were already pushed, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, current `origin/main` / prod truth, local git branch state, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0404 — 2026-08-01 — Strategist decomposed the post-rebuild lane into a concrete pause/return ladder - Goal: - prevent the newly active `pause / return check-in` focus from remaining only a title after `week rebuild / overload replan` reached accepted-line and prod truth; - turn the next week-first machine into one planner-ready sequence with a product consequence and a release shape. - Result: - `ACTIVE_TASKS.md`, `ROADMAP.md`, `PROJECT_STATUS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now treat `pause / return check-in` as a three-step ladder rather than one broad next-machine label: - `resume signal contract` - `orientation check-in machine` - `resume-state observability` - living memory now also preserves the default release path for that lane: - start from refreshed upstream in a clean review worktree; - use machine-shaped branch names such as `feature/pause-return-check-in` and `release/pause-return-check-in` instead of generic authoring/cleanup labels. - Runtime changes: - none; strategist/doc-memory only. - Checks: - current git branch/worktree inspection - docs-only consistency pass across `ACTIVE_TASKS.md`, `ROADMAP.md`, `PROJECT_STATUS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` ### ITER-0403 — 2026-08-01 — Curator synced the promoted fourth accepted machine and advanced live focus to pause/return - Goal: - replace the still-open review-proof memory for `week rebuild / overload replan` with the executor-confirmed accepted-line and production truth; - preserve the exact distinction between pushed review proof `0019b69`, promoted runtime/docs commit `cd447d9`, and the next bounded machine order after rebuild shipped. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DOMAIN_MODEL.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, `TECHNICAL_STRATEGY.md`, `TESTING.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now treat `week rebuild / overload replan` as shipped truth rather than local/pushed candidate state; - living memory now preserves the exact promoted fourth-machine contract: - review proof branch `origin/review/week-rebuild-overload-replan` `0019b69` - accepted-line and prod runtime/docs commit `cd447d9` - fixture, reviewed artifact, generated artifact, registry wiring, and narrow runtime proof for `week-rebuild-overload-replan` - bounded runtime contract remains `one overload report from /dashboard -> one bounded rebuild recommendation branch set`, with `not_answered` and `low_confidence` still fail-closed to raw capture - active focus therefore moves from rebuild promotion to `pause / return check-in`, while `bounded rebuild write-through follow-up` stays dormant pending changed-since evidence. - Runtime changes: - none in this curator pass; runtime/docs commit `cd447d9` was already pushed, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against the executor report, current branch facts (`origin/main` and `/root/apps/trajectory-prod` at `cd447d9`), and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0402 — 2026-08-01 — Curator synced the pushed fourth-machine rebuild candidate and its honest release boundary - Goal: - replace the still-planning-only memory for `week rebuild / overload replan` with the executor-confirmed local/pushed review-candidate state; - preserve the exact distinction between accepted-line/prod truth `81ee8ec` and pushed review proof `origin/review/week-rebuild-overload-replan` `0019b69`. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, `TESTING.md`, `DECISIONS.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now record that the fourth-machine lane is no longer just selected in strategy memory: - clean review worktree implementation exists and is pushed as `origin/review/week-rebuild-overload-replan` at `0019b69` - the bounded bundle already exists as fixture + reviewed artifact + generated artifact + trusted/runtime registry wiring - the narrow runtime proof already exists in `src/features/sfm/week-rebuild-overload-replan.ts` with targeted tests - living memory now preserves the exact first contract choices for that candidate: - trigger = one overload report from `/dashboard` - output = one bounded rebuild recommendation branch set - `not_answered` / `low_confidence` still fail closed to raw capture - release truth remains explicit: - authoring/test/type/build gates are green in the clean review worktree - merge to `main`, prod deploy, and prod smoke remain `not run` - Runtime changes: - none in accepted-line or prod truth during this curator pass; the fourth-machine candidate is pushed review state only. - Checks: - docs-only consistency pass against the executor report, current git branch facts, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0401 — 2026-08-01 — Strategist resolved the fourth-machine fork into week rebuild / overload replan - Goal: - stop the post-residue authoring lane from lingering on a generic `fourth accepted SFM machine selection` label after the duplicate verdict already removed the competing event-report residue path; - turn the next live week-first step into one named product slice that can ship direct user value rather than another authoring-only choice loop. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now treat `week rebuild / overload replan` as the live next slice instead of keeping selection itself active; - living memory now preserves the rationale and order explicitly: - `week rebuild / overload replan` wins because rebuild is the clearest missing proof in the north-star loop `week -> capacity -> rebuild -> clarity`; - `pause / return check-in` remains later because resumed-week continuity matters, but it does not close the larger rebuild gap yet; - `external action consent gate` remains later because it broadens system scope faster than current week-first value; - the open questions are now narrowed to the rebuild contract itself rather than the old candidate fork: - which first trigger becomes canonical; - whether the first accepted output should stay recommendation-only, permit bounded event updates, or combine both narrowly. - Runtime changes: - none; strategist/doc-memory only. - Checks: - current git branch/worktree inspection - docs-only consistency pass across `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` ### ITER-0400 — 2026-08-01 — Executor closed staged event-report residue as accepted-line duplicate - Goal: - resolve `staged-event-report-residue` to one explicit release-throughput verdict from refreshed `origin/main` instead of leaving the local staged bucket ambiguous after shipped `81ee8ec`; - preserve exact git evidence across `origin/main`, `origin/release/event-report-root-note-guard`, and the dirty local index without inventing a runtime delta. - Result: - refreshed git truth was inspected first: - dirty local checkout stayed `main` at `e5eb05a` with unrelated modified/untracked files and staged event-report bucket intact - accepted-line baseline is `origin/main` `81ee8ec` - preserved replay anchor is `origin/release/event-report-root-note-guard` `dce8c78` - inspected refs also included `origin/feature/event-report-write-through`, `origin/review/home-save-residue-closure`, and `origin/feature/branch-provenance-register` - clean review worktree `/tmp/trajectory-event-report-verdict` was created directly from refreshed `origin/main` `81ee8ec` - bounded compare closed `staged-event-report-residue` as `stale duplicate of accepted-line truth`: - staged blobs for `scripts/lib/event-report-smoke.test.ts`, `scripts/lib/event-report-smoke.ts`, `scripts/manage-event-report-smoke-fixture.ts`, `scripts/verify-event-report-smoke.ts`, `src/features/sfm/event-report-smoke-fixture.ts`, `src/features/sfm/event-report-write-through.test.ts`, and `src/features/sfm/event-report-write-through.ts` are byte-identical to both `origin/main` `81ee8ec` and anchor `dce8c78` - staged `package.json` is not unique value either; it matches older anchor `dce8c78` instead of accepted-line `81ee8ec`, so replay would only rewind later accepted-line script wiring - `ops/branch-provenance-register.json`, `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, `TECHNICAL_STRATEGY.md`, and `TECH_DEBT.md` now preserve that exact duplicate verdict and move the next live slice to `fourth accepted SFM machine selection` - Runtime changes: - none; this was an upstream-first git/register/docs classification pass only - Checks: - `git fetch origin --prune` - git status/branch/remote/local-remote ref inspection in dirty checkout - clean worktree compare from `/tmp/trajectory-event-report-verdict` at `origin/main` `81ee8ec` - blob-level compare for all bounded staged files against `81ee8ec` and `dce8c78` - runtime tests, typegen, lint, build, smoke, commit, deploy: not run because the verdict produced no reviewable runtime delta ### ITER-0399 — 2026-08-01 — Curator synced the promoted event-report write-through specimen - Goal: - replace the still-live `event-report write-through` planning state with the executor-confirmed accepted-line and prod truth for the third accepted SFM authoring machine; - preserve the exact distinction between local dirty `main` `e5eb05a`, accepted-line/prod `81ee8ec`, and the still-parked `staged-event-report-residue` bucket that remains a separate release-throughput question. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DOMAIN_MODEL.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, `TECHNICAL_STRATEGY.md`, `TESTING.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now treat `event-report write-through` as shipped runtime/docs truth instead of a live fork; - living memory now preserves the exact shipped third-machine contract: - fixture `src/features/sfm/authoring/fixtures/event-report-write-through.ts` - reviewed artifact `src/features/sfm/authoring/reviewed/event-report-write-through.reviewed.json` - generated artifact `src/features/sfm/authoring/generated/event-report-write-through.generated.json` - trusted/runtime registry wiring in `src/features/sfm/authoring/trusted-runtime.ts`, `reviewed.ts`, `generated.ts`, and `src/features/sfm/builder/authoring.ts` - canonical write-through targets the project root note, while stale child-note pointers remain observable fallback/reference semantics only - active focus therefore moves from the product-bearing event-report machine to the separate `event-report residue verdict`, while `persisted draft store decision` stays dormant and the next accepted machine remains intentionally blocked behind an explicit parked-residue fate. - Runtime changes: - none in this curator pass; runtime/docs commit `81ee8ec` was already pushed, merged, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, current git branch/worktree facts, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0398 — 2026-08-01 — Strategist turned the post-branching authoring lane into an explicit event-report ladder - Goal: - keep the newly live `event-report write-through` focus from collapsing into vague “next machine or maybe residue” wording; - separate the next product-bearing authoring proof from the separately parked staged event-report residue so planner/executor do not conflate them. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now preserve one stricter order: - first ship one bounded `event-report write-through` machine in the accepted reviewed/generated/trusted bundle shape; - keep root-note write-through as the canonical target and stale child-note pointers as inspectable fallback/reference semantics only; - only after that slice ships or stops on a real blocker should the parked `staged-event-report-residue` bucket receive its own replay-or-park verdict. - strategist also corrected one active-memory release reference: - the promoted `8e69f94` specimen is now linked to `origin/review/answer-check-branching-expansion`, matching the current git-visible branch truth. - Runtime changes: - none; strategist/doc-memory only. - Checks: - current git branch/worktree inspection - docs-only consistency pass across `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` ### ITER-0397 — 2026-08-01 — Curator synced the promoted answer-check branching authoring specimen - Goal: - replace the still-live `answer-check branching expansion` planning state with the executor-confirmed accepted-line and prod truth for the second accepted SFM authoring machine; - preserve the exact distinction between local dirty `main` `e5eb05a`, accepted-line/prod `8e69f94`, and the still-parked staged event-report residue bucket. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DOMAIN_MODEL.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now treat `answer-check branching expansion` as shipped runtime/docs truth instead of a live fork; - living memory now preserves the exact shipped second-machine contract: - fixture `src/features/sfm/authoring/fixtures/answer-check-branching-week-first.ts` - reviewed artifact `src/features/sfm/authoring/reviewed/answer-check-branching-week-first.reviewed.json` - generated artifact `src/features/sfm/authoring/generated/answer-check-branching-week-first.generated.json` - trusted runtime definition set in `src/features/sfm/authoring/trusted-runtime.ts` - fail-closed reviewed/generated/trusted coverage now spans both accepted machines - active focus therefore moves from `answer-check branching expansion` to `event-report write-through`, while keeping the separately parked `staged-event-report-residue` bucket as local release-throughput state rather than automatically promoting it into the next product slice. - Runtime changes: - none in this curator pass; runtime/docs commit `8e69f94` was already pushed, merged, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, refreshed `origin/main` / `/root/apps/trajectory-prod` truth at `8e69f94`, current git branch/worktree facts, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0396 — 2026-08-01 — Strategist resolved the second-machine fork into answer-check branching expansion - Goal: - stop the live authoring lane from lingering on the abstract label `second machine fixture selection`; - turn the next post-bundle step into one planner-ready week-first slice that keeps release-throughput residue secondary. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now resolve the former fixture-choice fork in favor of `answer-check branching expansion`; - living memory now preserves the new order explicitly: - first broaden the reviewed/generated/trusted comparison contract with one branching-heavy intake machine; - keep `event-report write-through` second in order, not co-equal with the live slice; - keep the parked staged event-report residue subordinate to the current authoring lane unless the lane stops on a real blocker. - open questions also moved down one level: - no longer “which second machine at all”; - now “which exact bounded answer-check path and artifact depth should ship first”. - Runtime changes: - none; strategist/doc-memory only. - Checks: - current git branch/worktree inspection - docs-only consistency pass across `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` ### ITER-0395 — 2026-08-01 — Curator synced the accepted SFM promotion bundle and closed the first bundle-shape fork - Goal: - replace the still-live `promotion bundle shape decision` planning state with the executor-confirmed accepted-line and prod truth for the first accepted SFM promotion bundle; - preserve the exact distinction between local dirty `main` `e5eb05a`, accepted-line/prod `8a3cf6c`, and the still-parked unrelated staged event-report residue. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, `TECHNICAL_STRATEGY.md`, `TESTING.md`, `DOMAIN_MODEL.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now treat the accepted bundle shape as shipped runtime/docs truth instead of a live fork; - living memory now preserves the exact shipped contract: - reviewed artifact `src/features/sfm/authoring/reviewed/home-intake-week-first.reviewed.json` - generated artifact `src/features/sfm/authoring/generated/home-intake-week-first.generated.json` - trusted runtime definition `src/features/sfm/authoring/trusted-runtime.ts` - generator command `pnpm sfm:authoring:generate` - parity/validation commands `pnpm sfm:authoring:parity` and `pnpm sfm:authoring:validate` - fail-closed mismatch taxonomy `reviewed_artifact_drift`, `generated_artifact_drift`, and `trusted_runtime_drift` - active focus therefore moves from `promotion bundle shape decision` to `second machine fixture selection`, with `answer-check branching expansion` as the default first candidate and `event-report write-through` second. - Runtime changes: - none in this curator pass; runtime/docs commit `8a3cf6c` was already pushed, merged, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, current branch/worktree facts, living docs, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0394 — 2026-08-01 — Strategist turned the promotion-bundle decision into two explicit downstream ladders - Goal: - keep the live `promotion bundle shape decision` from ending as one abstract yes/no fork with no immediate product consequence; - close the already-resolved question about reviewed-artifact placement and make the next single-machine step explicit before any second-machine broadening. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now preserve one sharper authoring order: - first decide whether the accepted promotion bundle is `reviewed JSON only` or `reviewed JSON plus generated runtime/code diff`; - if reviewed JSON only wins, the next slice becomes `reviewed-artifact readability tightening`; - if generated diff wins, the next slice becomes `deterministic generated diff artifact` for `home-intake-week-first`; - only after that single-machine consequence ships should `second machine fixture selection` broaden the lane. - strategist also closed one stale open question: - reviewed artifact placement is no longer open because the promoted artifact already lives in `src/features/sfm/authoring/reviewed/`; - the remaining open questions now focus on reviewer readability versus generated diff shape. - Runtime changes: - none; strategist/doc-memory only. - Checks: - current git branch/worktree inspection - docs-only consistency pass across `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` ### ITER-0393 — 2026-08-01 — Curator synced the promoted reviewed-artifact parity checkpoint - Goal: - replace the still-live “prove reviewed artifact plus parity” planning state with the executor-confirmed accepted-line and prod truth for the first promotion-review checkpoint; - preserve the exact distinction between local dirty `main` `e5eb05a`, accepted-line/prod `68ef9ee`, and the still-parked unrelated staged event-report residue. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, `TECHNICAL_STRATEGY.md`, and `TESTING.md` now treat the first reviewed promotion checkpoint as shipped runtime/docs truth instead of future work; - living memory now preserves the exact shipped contract: - reviewed artifact `src/features/sfm/authoring/reviewed/home-intake-week-first.reviewed.json` - parity helper `src/features/sfm/authoring/parity.ts` - parity CLI `scripts/validate-sfm-authoring-parity.ts` - `pnpm sfm:authoring:parity` - `pnpm sfm:authoring:validate` now runs validation plus parity - trusted-runtime drift and reviewed-artifact drift both fail closed with inspectable mismatch output - parity does not mutate DB rows, runtime registry definitions, or shipped fixture files - active focus therefore narrows from the general `draft-to-runtime promotion review path` to its next concrete decision `promotion bundle shape decision`, while `second machine fixture selection` stays queued behind that decision and the staged event-report bucket remains secondary local state only. - Runtime changes: - none in this curator pass; runtime/docs commit `68ef9ee` was already pushed, merged, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, current `origin/main` / `/root/apps/trajectory-prod` truth at `68ef9ee`, current living docs, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0392 — 2026-08-01 — Retrospective repaired control-plane pressure after cycles 6741-6750 - Goal: - evaluate the ten-cycle window by real product/release movement rather than by log volume; - remove instruction pressure that encouraged repeated curator/strategist rewrites after executor had already preserved the fact pattern. - Result: - window classification is now preserved explicitly: - `product/runtime`: 6744, 6748, 6750 - `release/promotion`: 6746, 6747 - `docs-memory`: 6743 - `no-release-delta`: 6745 - `unknown evidence`: 6741, 6742 - `docs-memory churn`: 6749 - control-plane rules now bias toward `one new fact -> one memory update`, finishing the current bounded release path before opening a parallel lane, and leaving strategist idle when curator truth already preserves roadmap order. - Runtime changes: - none; retrospective/doc-instruction repair only. - Checks: - full read of available `codex_live.md` files for cycles `6741-6750` - current prompt review for planner/curator/strategist - current git status review in `/root/apps/ControlPlane` and `/root/apps/trajectory-dev` - docs-only consistency pass after the instruction/doc updates ### ITER-0393 — 2026-08-01 — Retrospective captured cycles 6751-6760 and removed remaining release/docs churn - Goal: - evaluate cycles `6751-6760` by delivered product/release movement instead of by the number of supporting docs passes; - remove the last instruction ambiguity that still allowed sequential release truth to be blurred by parallel git/prod commands or by a second strategist restatement after curator had already preserved the fact. - Result: - window classification is now explicit: - `product/runtime`: 6751, 6752, 6753, 6754, 6758, 6759 - `no-release-delta`: 6755 - `release/promotion`: 6756, 6757 - `docs-memory`: 6760 - `unknown evidence`: none from the available logs - the ten-cycle window delivered real product/runtime depth rather than maintenance churn: - `6751` shipped the first reviewed promotion checkpoint for `home-intake-week-first` on `68ef9ee`; - `6752` shipped the first accepted promotion bundle with reviewed JSON plus deterministic generated runtime projection on `8a3cf6c`; - `6753` shipped the second accepted branching-heavy authoring specimen `answer-check-branching-week-first` on `8e69f94`; - `6754` shipped the third accepted specimen `event-report-write-through` on `81ee8ec`; - `6755` correctly closed `event-report residue verdict` as `no release delta` and moved the live lane back to week-first rebuild instead of replaying stale local residue; - `6756` produced a real pushed review candidate for `week rebuild / overload replan` on `0019b69`, but the accepted line and prod still remained `81ee8ec`, so this cycle is release-throughput progress rather than a shipped runtime fact; - `6757` promoted `week rebuild / overload replan` to accepted line and prod on `cd447d9`; - `6758` shipped `pause / return check-in` with accepted runtime commit `bd03dc6`, docs sync `6ac4d4e`, and corrected sequential prod recovery after an invalid parallel restart/build attempt; - `6759` shipped `slipped-event triage machine` and strategist correctly moved the live gap from “another advisory machine” to “first bounded rebuild apply path”; - `6760` shipped the first bounded rebuild apply path on `8ba162b`, then narrowed the next step to `single-event rebuild release apply`. - counted by outcome, `9` cycles were change-bearing and `1` cycle was a justified `no release delta`; the window shows no stop/no-op-only cycle. - memory quality was mostly strong: - executor plus one curator sync usually preserved exact artifact paths, branch names, commit ids, smoke base URLs, and next-step rationale without losing detail; - the only repeated churn still visible in the window was a small strategist-after-curator echo on `6751`, `6752`, `6754`, and `6760`, where the second pass mainly narrowed wording/order after curator had already moved live memory forward. - git/release discipline worked end-to-end across the window, but two operational mistakes repeated: - git/release commands were sometimes launched in parallel, creating false lock/prod-state noise before the same cycle recovered and finished sequentially; - docs patches occasionally targeted stale paragraph context, which wasted time but did not change product direction once smaller hunks were used. - instruction repair is now narrower and more concrete: - release evidence is explicitly sequential: `commit -> push -> merge/fast-forward -> prod build -> restart -> save -> smoke`; - if curator already moved live focus to the next bounded slice and roadmap order did not change, strategist should normally leave files untouched. - Runtime changes: - none in this retrospective pass; product code stayed untouched. - Checks: - full read of available `codex_live.md` files for cycles `6751-6760` - current prompt review for `03_CURATOR.md`, `04_STRATEGIST.md`, and `05_CODEX_RETROSPECTIVE.md` - current git status review in `/root/apps/ControlPlane` and `/root/apps/trajectory-dev` - docs-only consistency pass after the instruction/doc updates ### ITER-0391 — 2026-08-01 — Strategist turned promotion review into a stricter reviewed-artifact ladder - Goal: - keep the live `draft-to-runtime promotion review path` from remaining a single broad label after `stage 1B` promotion; - make the next week-first authoring work cumulative enough that the following cycle can ship one reviewed artifact, one parity gate, and one explicit promotion-bundle decision before broadening to another machine. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now preserve a tighter execution order inside the live authoring lane: - first `reviewed machine artifact extraction` for `home-intake-week-first`; - then `runtime parity report + mismatch gate`; - then `promotion bundle shape decision` (`reviewed JSON only` versus `reviewed JSON plus generated runtime/code diff`); - only after that should `second machine fixture selection` broaden scope. - strategist also tightened release-throughput memory instead of letting it drift in the background: - local `main...origin/main` is now recorded as `[ahead 9, behind 64]`; - the separately parked `staged-event-report-residue` bucket remains visible, but stays subordinate to the live promotion-review lane. - Runtime changes: - none; strategist/doc-memory only. - Checks: - current git branch/worktree inspection - docs-only consistency pass across `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` ### ITER-0390 — 2026-08-01 — Curator synced living docs to the promoted `stage 1B` authoring runtime - Goal: - replace the stale clean-review-only `stage 1B` memory with the executor-confirmed accepted-line and prod truth; - preserve the exact distinction between local dirty `main` `e5eb05a`, accepted-line/prod `e5ba68f`, and the still-parked unrelated local residue. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `DOMAIN_MODEL.md`, `SYSTEM_MAP.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, `TECH_DEBT.md`, and testing/runbook docs now treat `SFM authoring contract stage 1B` as shipped runtime/docs truth rather than local candidate state; - living memory now preserves the exact shipped contract: `sfm_machine_draft_envelope_v1`, exact trusted payload under `machineDocument`, separate draft metadata (`draftEnvelopeVersion`, provenance, `editedAt`, optional UI-only state), browser-local reload behavior per machine key, import/export/reset, and fail-closed diagnostics for malformed JSON, unsupported version, foreign machine key, and invalid machine document; - active focus moves forward from `local draft import/export shell` to `draft-to-runtime promotion review path`, while the separately parked `staged-event-report-residue` bucket stays secondary and local `main` remains non-authoritative dirty state. - Runtime changes: - none in this curator pass; runtime/docs commit `e5ba68f` was already pushed, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, current `origin/main` `e5ba68f`, `/root/apps/trajectory-prod` HEAD `e5ba68f`, current living docs, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0389 — 2026-08-01 — Strategist turned the clean-review `stage 1B` result into a release-shaped authoring ladder - Goal: - develop the next authoring horizon beyond “stage 1B exists locally” so the next cycle does not stop at owner-smoke blockage or reopen parked residue too early; - make the first promotion bridge reviewable on one real machine before any second scenario broadens scope. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now preserve a tighter next sequence: - finish `stage 1B` through one documented repo-owned owner-smoke/bootstrap path rather than inventing a second authoring-only fixture system; - keep `draft-to-runtime promotion review path` centered on `home-intake-week-first`; - require one inspectable parity diff between the reviewed machine-document artifact and the trusted runtime definition before treating the bridge as trustworthy; - only then broaden to the second machine fixture, with `answer-check branching expansion` still ahead of `event-report write-through`. - strategist also tightened release-throughput memory: - the parked `staged-event-report-residue` bucket remains subordinate to the authoring lane; - it should not reopen ahead of `stage 1B` owner-smoke/release classification or the first promotion-specimen proof. - Runtime changes: - none; strategist/doc-memory only. - Checks: - current git branch/worktree inspection - docs-only consistency pass across `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` ### ITER-0388 — 2026-08-01 — Curator synced living docs to the clean-review `stage 1B` authoring candidate - Goal: - replace the purely planned `local draft import/export shell` wording with the executor-confirmed clean-review implementation state; - preserve the exact distinction between shipped baseline `f211c34`, dirty local checkout `e5eb05a`, and clean review worktree `/tmp/trajectory-sfm-authoring-stage1b-review`. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DOMAIN_MODEL.md`, `TESTING.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, and `TECH_DEBT.md` now record that stage `1B` is no longer only a planned slice: - clean-review code adds `sfm_machine_draft_envelope_v1` - exact trusted payload remains under `machineDocument` - separate draft metadata now includes envelope version, fixture/source provenance, edited-at timestamp, and optional editor-only UI state - `/operator/sfms/[sfmKey]` now has a browser-local draft shell with local save, import, export, reset, and fail-closed diagnostics - living memory now preserves the honest gate state too: - `pnpm sfm:authoring:validate`, targeted tests, `next typegen`, `typecheck`, `lint`, `build`, and anonymous `GET /operator/sfms -> /login` passed in the clean review worktree - signed-in owner smoke did not complete there because `.env.local` was absent and the documented placeholder DB override failed with `PostgresError: password authentication failed for user "test"` - commit/push/release integration/deploy/prod smoke therefore remain `not run` - [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now also carries the fuller bounded execution record so the next planner/executor does not have to reconstruct the candidate from the executor report. - Runtime changes: - none in accepted-line/prod truth during this curator pass; stage `1B` remains local clean-review state only. - Checks: - docs-only consistency pass against executor result, current git state, living docs, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0387 — 2026-08-01 — Strategist turned the first post-authoring follow-up into a tighter delivery ladder - Goal: - make `SFM authoring contract stage 1B` more executable than one broad `local draft import/export shell` label; - keep the parked staged event-report residue visible without letting it outrank the next week-first product slice. - Result: - `ACTIVE_TASKS.md`, `ROADMAP.md`, `PROJECT_STATUS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now preserve a stricter immediate authoring order: - versioned draft envelope first; - reversible import/export of machine document plus separate draft metadata second; - visible stale-version / invalid-draft handling third; - reviewed promotion path immediately after that. - strategist also made the next authoring horizon more cumulative: - the first reviewed promotion specimen should stay `home-intake-week-first`; - only after that bridge exists should the second real machine scenario be chosen, with default order `answer-check branching expansion` before `event-report write-through`. - release-throughput memory is now clearer too: - the parked `staged-event-report-residue` bucket stays visible as separate local state; - it should not reopen ahead of `stage 1B` unless the live authoring slice stops on a real blocker. - Runtime changes: - none; strategist/doc-memory only. - Checks: - current git branch/worktree inspection - docs-only consistency pass across `ACTIVE_TASKS.md`, `ROADMAP.md`, `PROJECT_STATUS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` ### ITER-0386 — 2026-08-01 — Curator synced living docs to the promoted first executable SFM authoring contract - Goal: - replace the stale active-memory focus on `staged event-report residue replay-or-park verdict` with the executor-confirmed promoted authoring baseline; - preserve the exact distinction between accepted-line/prod truth `f211c34` and the still-dirty local checkout at `e5eb05a`. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DOMAIN_MODEL.md`, `OPEN_QUESTIONS.md`, `TECHNICAL_STRATEGY.md`, and `DECISIONS.md` now treat `f211c34` as the latest fully promoted runtime/docs baseline; - living memory now preserves the exact shipped authoring contract: - canonical machine-document module `src/features/sfm/authoring/document.ts` - canonical week-first fixture `src/features/sfm/authoring/fixtures/home-intake-week-first.ts` - repo-owned validator entry `pnpm sfm:authoring:validate` - explicit authoring/runtime split: machine documents are authoring truth, while trusted runtime definitions remain code-defined until later reviewed promotion - browser-local-first drafts are the chosen first storage boundary; persisted drafts remain deferred - the next live product slice is now `SFM authoring contract stage 1B: local draft import/export shell`, while the old staged event-report bucket is preserved only as non-authoritative local residue in the dirty checkout. - Runtime changes: - none in this curator pass; runtime/docs commit `f211c34` was already pushed, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, current living docs, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0385 — 2026-08-01 — Strategist turned the post-register horizon into an executable SFM-authoring ladder - Goal: - keep the accepted-line branch-register success from stretching into another neutral cleanup chapter after the parked event-report verdict; - make the next week-first product return more executable than one broad `SFM authoring contract stage 0` label. - Result: - `ACTIVE_TASKS.md`, `ROADMAP.md`, `PROJECT_STATUS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now preserve a stricter post-residue order: - finish `staged event-report residue replay-or-park verdict`; - move immediately to `SFM authoring contract stage 0`; - let stage 0 itself nominate the first executable follow-up from three prepared candidates: - `machine document schema + validator` - `local draft import/export shell` - `draft-to-runtime promotion review path` - strategist also made the builder initiative more product-bearing: - the first real authoring fixture should exercise a week-first runtime scenario such as home intake routing, answer-check branching, or event-report write-through instead of a synthetic demo-only machine; - if browser-local drafts win, the later persisted-draft question must be reopened only by concrete evidence such as collaboration, multi-device authoring, review-workflow pressure, or promotion friction. - git/release memory is now stricter too: - after the parked event-report verdict, regular branch-to-release integration should happen inside the next useful product slice rather than as another standalone cleanup rhythm. - Runtime changes: - none; strategist/doc-memory only. - Checks: - current git branch/worktree inspection - docs-only consistency pass across `ACTIVE_TASKS.md`, `ROADMAP.md`, `PROJECT_STATUS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` ### ITER-0384 — 2026-08-01 — Curator synced accepted-line truth after protected note route recovery and branch-register landing - Goal: - replace the stale “branch register is local/pushed-only and merge-blocked” memory with the executor-confirmed accepted-line and prod truth; - preserve the exact relationship between original proof commit `53f14e1`, accepted-line recovery commit `49e2a15`, production verification on `https://journeyup.ru`, and the now-narrowed next slice. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `OPEN_QUESTIONS.md`, `TECH_DEBT.md`, and `DECISIONS.md` now treat the branch provenance register as accepted-line truth rather than local/pushed-only evidence: - original isolated register proof remains `53f14e1` on `feature/branch-provenance-register` and `origin/feature/branch-provenance-register`; - accepted line and prod are now at `49e2a15`, which carries both the protected note route type-contract recovery and the merged repo-owned branch register workflow; - the old merge blocker on protected note `RouteContext` / `PageProps` is closed. - living memory now preserves the exact bounded framework nuance: - `src/app/(protected)/projects/[id]/notes/[noteId]/page.tsx` - `src/app/(protected)/projects/[id]/notes/[noteId]/export/route.ts` - both now use the current Next.js promised-`params` contract directly instead of local ad-hoc typing. - active focus is therefore narrowed again: - live task becomes `staged event-report residue replay-or-park verdict`; - `protected note route type-contract recovery` moves to closed release memory; - after the staged bucket verdict, roadmap priority returns to `SFM authoring contract stage 0`. - Runtime changes: - none in this curator pass; runtime/docs commit `49e2a15` was already pushed, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, current `origin/main` `49e2a15`, current remote branch map, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0383 — 2026-08-01 — Strategist redirected the post-register path back to week-first product depth - Goal: - keep the newly clarified `branch provenance register integration gate` from expanding into another long neutral cleanup chapter; - make the next post-integration horizon explicit: one accepted-line residue verdict, then one product-bearing return to core week-first/SFM work. - Result: - `ACTIVE_TASKS.md`, `ROADMAP.md`, `PROJECT_STATUS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now preserve a stricter sequence after the current gate: - merge the branch-register slice into the accepted line; - give the staged event-report bucket one replay-or-park verdict; - if merge remains blocked, open one bounded `protected note route type-contract recovery` slice on the exact upstream `RouteContext` / `PageProps` failures; - then return roadmap priority to `SFM authoring contract stage 0` as the first week-first product-depth initiative after the current release-throughput lane. - strategist also made the next core initiative more executable: - the first SFM authoring slice must decide one canonical machine document shape, one draft-storage boundary, and one promotion path from editable draft to trusted runtime definition; - it is explicitly not a canvas/UI build or a second hidden source of truth. - Runtime changes: - none; strategist/doc-memory only. - Checks: - `git status --short --branch` - `git branch -vv` - `git for-each-ref --format='%(refname:short)|%(objectname:short)|%(upstream:short)|%(committerdate:short)|%(subject)' refs/heads refs/remotes/origin | sort` - docs-only consistency pass across `ACTIVE_TASKS.md`, `ROADMAP.md`, `PROJECT_STATUS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` ### ITER-0382 — 2026-08-01 — Curator corrected branch-register memory from “exists” to “local+pushed, not merged” - Goal: - align living docs with the real executor outcome for the branch provenance register slice instead of implying that the register already landed on `origin/main`; - preserve the exact local, pushed, merge-blocked, and next-step state so the next planner/executor can continue without re-investigating git truth. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `OPEN_QUESTIONS.md`, `TECH_DEBT.md`, and `DECISIONS.md` now distinguish three different states explicitly: - local checkout contains the repo-owned register and validator; - pushed branch `origin/feature/branch-provenance-register` contains reviewable commit `53f14e1`; - accepted line does not yet contain this slice because clean-upstream `pnpm typecheck` is red outside the slice. - the exact merge blocker is now preserved in living memory: - `src/app/(protected)/projects/[id]/notes/[noteId]/export/route.ts` missing `RouteContext` - `src/app/(protected)/projects/[id]/notes/[noteId]/page.tsx` missing `PageProps` - active memory therefore moves the immediate next git step to `clear/resolve blocker -> rerun pnpm typecheck -> merge branch-register slice`, and only then to `staged event-report residue replay-or-park verdict`. - Runtime changes: - none; docs/state-sync only. - Checks: - docs-only consistency pass against executor result, current branch state, current register files, and archive memory ### ITER-0381 — 2026-08-01 — Executor shipped the repo-owned branch provenance register and parked event-report bucket contract - Goal: - turn the live `branch/release integration register for surviving useful branches` task into a repo-owned artifact plus validator instead of leaving it as docs-only memory; - give the surviving staged event-report residue bucket an explicit parked home with exact files, baseline, and replay anchor. - Result: - new canonical source of truth now lives in [ops/branch-provenance-register.json](/root/apps/trajectory-dev/ops/branch-provenance-register.json); - new validator flow now lives in `scripts/validate-branch-provenance-register.ts` with pure coverage in `scripts/lib/branch-provenance-register.ts` and `scripts/lib/branch-provenance-register.test.ts`; - `package.json` now exposes: - `pnpm branch-register:validate` - `pnpm test:branch-register` - the register now preserves four concrete classes against the real current checkout: - retained proof branch: `origin/review/home-save-residue-closure` `a25851a` - historical anchors: promoted `origin/release/*` auth/performance/help/event-report chain plus `origin/review/dashboard-payload-reduction` - prune-later local mirrors: `feature/anonymous-trust-ux-hardening`, `feature/attached-identity-reassurance`, `release/attached-identity-reassurance`, `release/minimal-help-pattern-contract-promote`, `release/auth-matrix-helper`, `release/knowledge-boundary-recovery` - parked bucket: `staged-event-report-residue` - the staged event-report bucket is no longer generic dirty state: - status = `parked local source` - replay baseline = `origin/main` `db7fe7d` - compare/replay anchor = `origin/release/event-report-root-note-guard` `dce8c78` - files = `package.json`, `scripts/lib/event-report-smoke.test.ts`, `scripts/lib/event-report-smoke.ts`, `scripts/manage-event-report-smoke-fixture.ts`, `scripts/verify-event-report-smoke.ts`, `src/features/sfm/event-report-smoke-fixture.ts`, `src/features/sfm/event-report-write-through.test.ts`, `src/features/sfm/event-report-write-through.ts` - Runtime changes: - none; repo tooling/docs only. - Checks: - `pnpm test:branch-register` - `pnpm branch-register:validate` - `pnpm typecheck` - `pnpm lint` ### ITER-0380 — 2026-08-01 — Strategist turned branch/release hygiene into an explicit retained-vs-historical register - Goal: - stop the new live task `branch/release integration register for surviving useful branches` from remaining an abstract reminder; - classify current named branches into active proof, historical anchor, and prune-later mirror groups so the next executor slice can act on one concrete residue bucket instead of a vague branch cloud. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now preserve the first explicit branch register: - retained proof branch: `origin/review/home-save-residue-closure` at `a25851a`; - promoted historical anchors: the current `origin/release/*` auth/performance/help/history chain plus `origin/review/dashboard-payload-reduction`; - prune-later local mirrors: `feature/anonymous-trust-ux-hardening`, `feature/attached-identity-reassurance`, `release/attached-identity-reassurance`, `release/minimal-help-pattern-contract-promote`, `release/auth-matrix-helper`, and `release/knowledge-boundary-recovery` unless later evidence shows unique delivery value. - strategist also converted the next release-throughput step into one narrower change-bearing outcome: - after the register, the only still-live ambiguous residue is the staged event-report smoke/fixture bucket; - the next executor pass should give that bucket one honest fate: replay from refreshed upstream as a bounded candidate, or explicitly park/discard it as stale local state. - Runtime changes: - none; strategist/doc-memory only. - Checks: - `git status --short --branch` - `git branch -vv` - `git for-each-ref --format='%(refname:short)|%(objectname:short)|%(upstream:short)|%(committerdate:short)|%(subject)' refs/heads refs/remotes/origin | sort` ### ITER-0379 — 2026-08-01 — Curator closed the bounded home-save residue and moved live focus to branch/register cleanup - Goal: - sync living docs to the executor-confirmed upstream-first result for the unstaged `home-save/dashboard residue` bucket; - preserve the exact split between the cooled dashboard outcome scope and the separately parked staged event-report bucket without inventing a new runtime or release fact. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now treat `branch/release integration register for surviving useful branches` as the live task instead of keeping residue classification open generically; - living memory now preserves the exact August 1 closure evidence: - clean worktree `/tmp/trajectory-home-save-review` was created from refreshed `origin/main` `db7fe7d`; - the canonical client-safe `/dashboard` home-save outcome path was already upstream in `src/features/dashboard/home-save-outcome.ts`, `src/features/dashboard/components/dashboard-home-save-outcome-notice.tsx`, and `src/features/state-flow-machine/intake.ts`; - review branch `review/home-save-residue-closure` was committed as `a25851a` and pushed to `origin/review/home-save-residue-closure`; - tests, smoke, deploy, and prod verification stayed `not run` because the bounded slice ended as `no release delta`; - [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now records this closure next to the earlier August 1 export-friction promotion and the failed residue-split attempt, so the next planner can distinguish git-integrity facts from runtime facts without re-investigation. - Runtime changes: - none; docs/state-sync only. - Checks: - docs-only consistency pass against current living docs, `/tmp/trajectory-home-save-review`, current git branch/worktree state, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0378 — 2026-08-01 — Curator synced the promoted supporting export-friction telemetry and cooled the lane - Goal: - replace the still-live pre-executor telemetry-follow-up planning state with the executor-confirmed promoted runtime/docs baseline `db7fe7d`; - preserve the exact supporting-view contract, observed `0 -> 0` windows, unchanged main funnel numbers, and the forced next consequence that this lane is cooled rather than reopened. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now treat `db7fe7d` as the latest promoted runtime/docs baseline instead of leaving `export-friction / continuity-use telemetry follow-up` as the live task; - living memory now preserves the exact shipped supporting operator contract: - owner-only `/operator/runtime` shows one secondary `bundle_issued -> bundle_exported` view for trailing `7` days and trailing `30` days; - the view is sourced only from `anonymous_recovery_audit_logs`; - the canonical main funnel `bundle_exported -> bundle_restored -> attach_completed` remains unchanged and explicitly primary; - the observed outcome is also fixed precisely: - current `trajectory_dev` supporting windows showed `bundle_issued = 0`, `bundle_exported = 0` for both trailing `7` days and trailing `30` days; - the unchanged main funnel in that same environment stayed `bundle_exported = 10`, `bundle_restored = 0`, `attach_completed = 0`; - therefore no `dashboard recovery export confirmation/copy tightening` slice opens from this baseline, and the next live task becomes upstream-first classification of the staged event-report residue bucket plus the separate unstaged home-save/auth/dashboard bucket. - Runtime changes: - none in this curator pass; runtime/docs commit `db7fe7d` was already pushed, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, current living docs, current git-visible branch/worktree state, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0377 — 2026-08-01 — Strategist turned the telemetry follow-up into concrete product consequences - Goal: - keep the post-`7722ee7` lane from collapsing into another neutral telemetry reread after the failed planner/executor pass; - make the next change-bearing sequence explicit without inventing a new runtime or release fact beyond the already-known dirty/diverged local state. - Result: - `ACTIVE_TASKS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, `PROJECT_STATUS.md`, and `TECHNICAL_STRATEGY.md` now force the live telemetry lane to do one real product job: - first supporting view remains `bundle_issued -> bundle_exported`; - if that view shows meaningful friction, the immediate next slice is `dashboard recovery export confirmation/copy tightening` inside the existing trust/help cluster; - if that view does not change priority, the lane must cool explicitly and hand off to the upstream-first residue-classification pass instead of spawning another report-only loop. - strategist also prepared one additional bounded fallback slice so the roadmap stays cumulative rather than binary: - if export friction is low but continuity reuse is still the sharper unresolved signal, a later `continuity-use repeat restore follow-up` may open; - stronger-proof and second-device policy remain frozen and were not reopened by this pass. - git/release continuation stays unchanged and explicit: - local `main...origin/main` remains `[ahead 9, behind 58]`; - the next code-bearing pass still has to start from refreshed upstream and later classify the staged event-report bucket and unstaged home-save/auth/dashboard bucket separately. - Runtime changes: - none; strategist/doc-memory only. - Checks: - current git branch/worktree inspection - docs-only consistency pass across `ACTIVE_TASKS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, `PROJECT_STATUS.md`, and `TECHNICAL_STRATEGY.md` ### ITER-0376 — 2026-08-01 — Curator sharpened the local git-integrity state after the failed executor pass - Goal: - sync living memory to the exact post-executor git state without inventing a new runtime or release fact from a failed pass; - preserve the sharper split between promoted upstream truth on `origin/main` `7451786` and the two different kinds of remaining local residue on stale local `HEAD` `e5eb05a`. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now record the changed-since git fact precisely: local `main...origin/main` moved to `[ahead 9, behind 58]`; - living memory now also preserves that the remaining local residue is not one undifferentiated bucket: - staged/index residue currently contains repo-owned event-report smoke and fixture files even though that release lane is already promoted upstream; - unstaged/worktree residue still contains older dashboard/auth/home-save/proxy/docs changes on top of local `HEAD` `e5eb05a`; - this curator pass therefore did not reopen a runtime slice or claim a release candidate; it only tightened the next integration question so planner/executor can classify each bucket honestly after the telemetry follow-up or if that lane cools immediately. - Runtime changes: - none; docs/state-sync only. - Checks: - `git rev-parse --short HEAD` - `git rev-parse --short origin/main` - `git branch -vv` - `git log --oneline --decorate --graph --all -n 40` - `git diff --name-status origin/main...HEAD` - `git diff --cached --name-status` - `git diff --name-status` ### ITER-0375 — 2026-07-31 — Curator synced living memory to the promoted dashboard trust payload reduction - Goal: - replace the still-live `dashboard trust/timeline payload reduction` planning state with the executor-confirmed promoted runtime `7722ee7` and docs sync `7451786`; - preserve the exact removed duplicate path, the unchanged trust/help contract, the real dev/prod validation bases, and the next-step consequence that no alignment slice is currently needed. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `OPEN_QUESTIONS.md`, `TECHNICAL_STRATEGY.md`, and `TECH_DEBT.md` now treat runtime `7722ee7` as the latest promoted dashboard-shell change and `7451786` as the later docs/control-plane sync on `origin/main`; - living memory now preserves the exact runtime reduction: - `src/features/dashboard/dashboard-request-context.ts` is the single canonical builder of normalized anonymous trust-cluster state; - `src/app/(dashboard-protected)/layout.tsx` passes that shape through; - `src/features/dashboard/components/dashboard-anonymous-profile-control.tsx` consumes it directly instead of maintaining a second anonymous trust payload assembly path; - one visible trust sentence plus the promoted `?` help interaction stayed unchanged. - the roadmap consequence is also explicit now: - no copy/runtime contradiction surfaced during the payload cut, so `dashboard trust-cluster copy/runtime alignment` is not the active next slice; - the next default move is `export-friction / continuity-use telemetry follow-up`, with later residue classification still preserved as a separate upstream-first integration question. - Runtime changes: - none in this curator pass; runtime `7722ee7` and docs sync `7451786` were already pushed, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, current `origin/main` `7451786`, local `HEAD` `e5eb05a`, living docs, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0374 — 2026-07-31 — Strategist sharpened the post-help shell order and kept broader local residue in memory - Goal: - turn the current post-`652eec1` non-auth lane into a stricter delivery order so the next cycle ships one shell reduction slice before jumping to telemetry again; - preserve the new git/release continuation fact `main...origin/main [ahead 9, behind 56]` together with the still-visible event-report/home-save local residue, without pretending it is promoted runtime truth. - Result: - `ACTIVE_TASKS.md`, `ROADMAP.md`, `PROJECT_STATUS.md`, `TECHNICAL_STRATEGY.md`, and `OPEN_QUESTIONS.md` now make the next sequence more concrete: - first `dashboard trust/timeline payload reduction`, with strategist default tightened from broad “payload or timeline” to trust-cluster payload assembly first and timeline-shell assembly second; - second `dashboard trust-cluster copy/runtime alignment` only if the payload pass exposes a real contradiction between promoted trust/help semantics, assembled shell payload, and smoke/copy assertions; - third `export-friction / continuity-use telemetry follow-up` only if those shell slices do not expose a sharper product bottleneck first. - strategist memory now also preserves a broader integration truth than the earlier cooled named buckets: - local `main...origin/main` is now recorded as `[ahead 9, behind 56]`; - event-report fixture/runtime files, home-save/localization files, and neighboring docs are still visibly modified locally, so the next integration pass must either isolate them with an upstream-first compare or park them explicitly instead of letting them disappear behind the dashboard lane. - no auth-policy reopening was introduced: - stronger-proof and second-device work stay frozen on promoted baseline `2cebf4e`; - `/subscription` stays out of scope unless later evidence justifies reusing the compact help contract there without reopening auth semantics. - Runtime changes: - none; strategist/doc-memory only. - Checks: - current git branch/worktree inspection - docs-only consistency pass across `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `TECHNICAL_STRATEGY.md`, and `OPEN_QUESTIONS.md` ### ITER-0373 — 2026-07-31 — Curator synced living memory to the promoted dashboard trust help contract - Goal: - replace the still-live `minimal help-pattern contract` planning state with the executor-confirmed promoted runtime/docs baseline `652eec1`; - preserve the exact distinction between the earlier promoted performance seam `a1c9246`, the newly shipped help contract, the removed duplicate explanation path, and the next payload-cleanup consequence. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now treat `652eec1` as the latest promoted runtime/docs baseline instead of leaving help as the live task; - living memory now preserves the exact shipped help rule: - one real `?` button works on desktop and touch; - help opens inline inside the same trust cluster; - close paths are repeat trigger, explicit close, outside click, and `Escape`; - the resting shell keeps exactly one visible trust sentence; - the duplicate attach-limitation explanation line was removed from the visible shell and now lives only inside help; - active focus therefore moves forward to `dashboard trust/timeline payload reduction`, with `export-friction / continuity-use telemetry follow-up` still third and the `/subscription` extension question left as later evidence-dependent. - Runtime changes: - none in this curator pass; runtime/docs commit `652eec1` was already pushed, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, current git branch/release facts for `652eec1`, living docs, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0372 — 2026-07-30 — Strategist sharpened the next non-auth slices and synced the git/release continuation fact - Goal: - make the post-`a1c9246` roadmap more executable than `help -> payload -> telemetry` labels by forcing concrete outcomes for each slice; - sync strategist-owned docs with the current git continuation fact `main...origin/main [ahead 9, behind 55]` so the next code-bearing pass does not reopen dirty local `main` by accident. - Result: - `ACTIVE_TASKS.md`, `ROADMAP.md`, `PROJECT_STATUS.md`, and `TECHNICAL_STRATEGY.md` now preserve a sharper three-slice order: - `minimal help-pattern contract` must answer trigger, touch fallback, close behavior, and remove at least one duplicated explanation path on the dashboard trust cluster; - `dashboard trust/timeline payload reduction` must choose one exact shell duplication to remove next, defaulting to trust-cluster payload or timeline-shell assembly on top of the shipped request-context seam; - `export-friction / continuity-use telemetry follow-up` stays third and should open one concrete downstream slice only if a supporting continuity metric can still change product priority now. - `OPEN_QUESTIONS.md` now carries the tighter forks that still matter immediately: - which touch-safe help interaction becomes canonical on `/dashboard`; - which explanation path should disappear after the help contract lands; - which bounded shell duplication should be removed first on top of `dashboard-request-context`. - strategist memory now also preserves the active release-throughput constraint more consistently across docs: local `main` remains `ahead 9, behind 55`, so the next code-bearing slice should start from refreshed upstream in a clean review worktree rather than from the dirty canonical branch. - Runtime changes: - none; strategist/doc-memory only. - Checks: - current git branch/worktree inspection - docs-only consistency pass across `ACTIVE_TASKS.md`, `ROADMAP.md`, `PROJECT_STATUS.md`, `TECHNICAL_STRATEGY.md`, and `OPEN_QUESTIONS.md` ### ITER-0371 — 2026-07-30 — Curator synced the promoted dashboard performance verdict and first reversible seam - Goal: - replace the still-live `2cebf4e` non-auth planning snapshot with the executor-confirmed promoted runtime/docs baseline `a1c9246`; - preserve the exact distinction between the shipped performance winner bucket, the rejected buckets, the measured `/dashboard` improvement, and the explicit `no full split yet` consequence. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, and `TECH_DEBT.md` now treat `a1c9246` as the latest promoted runtime/docs baseline and no longer leave `performance branch decision for possible front/back split` as the live task; - living memory now preserves the exact performance verdict: - winner bucket = `auth/home overhead around /dashboard`; - rejected buckets = hosted runtime/process shape, DB/query hotspots, and frontend/render for this bounded slice; - shipped fix = shared cached dashboard request context in `src/features/dashboard/dashboard-request-context.ts` reused by the protected layout and page; - measured local warm-path improvement on `http://localhost:3002` dropped from roughly `0.37s` average before the seam to roughly `0.23s` average after it; - strategic consequence = `no full split yet`, but the first reversible seam now exists in code. - active focus therefore moves forward to `minimal help-pattern contract`, with `dashboard trust/timeline payload reduction` next and telemetry-supporting export-friction follow-up only after those. - Runtime changes: - none in this curator pass; runtime/docs commit `a1c9246` was already pushed, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, branch/release facts for `a1c9246`, current living docs, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0370 — 2026-07-30 — Strategist fixed the next non-auth order and made the downstream consequences more executable - Goal: - stop the roadmap from keeping `performance` and `minimal help` as two equal abstract options after the promoted auth/telemetry lane was already closed on `2cebf4e`; - make the next non-auth work produce immediate change-bearing follow-ups instead of another diagnosis-only or docs-only loop. - Result: - `ACTIVE_TASKS.md`, `ROADMAP.md`, `PROJECT_STATUS.md`, and `TECHNICAL_STRATEGY.md` now preserve one explicit order for the next horizon: - first `performance branch decision for possible front/back split`; - second `minimal help-pattern contract`; - third `export-friction / continuity-use telemetry follow-up` only if the first two do not expose a more urgent bottleneck. - living memory now also fixes the expected downstream consequence for the performance pass: - process/runtime winner -> hosted runtime discipline slice; - DB/query winner -> one bounded query/index/read-path slice; - frontend/render winner -> one dashboard-shell payload/render slice; - auth/home overhead winner -> first split-preparation seam around dashboard identity/save contracts. - `OPEN_QUESTIONS.md` now closes the vague `performance or help first?` fork and keeps the sharper open questions instead: - which bottleneck bucket actually wins in the performance pass; - which reversible seam should be first if a split is justified; - which exact shell target should receive the first codified touch-safe help rule after the contract is written. - git/release continuation is refreshed too: local `main...origin/main` is now recorded as `[ahead 9, behind 54]`, and the same refreshed-upstream worktree rule is now stated for upcoming non-auth slices, not only auth lanes. - Runtime changes: - none; strategist/doc-memory only. - Checks: - current git branch/worktree inspection - docs-only consistency pass against `ACTIVE_TASKS.md`, `ROADMAP.md`, `PROJECT_STATUS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` ### ITER-0369 — 2026-07-30 — Curator synced the promoted interpretation-lane hardening baseline and closed the exact release-integration lane - Goal: - replace the still-active `bea4d71` integration-checkpoint memory with the executor-confirmed promoted baseline on `origin/main` and `/root/apps/trajectory-prod`; - preserve the exact distinction between recovery runtime `bea4d71`, hardening runtime/docs `2cebf4e`, and the unchanged stage-2 telemetry verdict. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `TECHNICAL_STRATEGY.md`, `OPEN_QUESTIONS.md`, and `TECH_DEBT.md` now treat `2cebf4e` as the latest promoted runtime/docs baseline and no longer keep `release-integration checkpoint on interpretation recovery lane` as the live task; - living memory now preserves the exact new guard contract: - dashboard trust props are normalized through a shared fail-closed boundary before render, so missing/malformed `continuityState`, `attachedReassuranceState`, and `credentialsState` no longer crash `/dashboard`, `/api/ready`, or PM2; - changed-origin credentials smoke now fails fast with explicit env-contract diagnostics when `AUTH_URL` points at a different origin than the candidate `DEV_PUBLIC_BASE_URL`; - the stage-2 telemetry interpretation itself did not change and still freezes stronger-proof and second-device work. - active focus therefore moves forward to `performance branch decision for possible front/back split`, with `minimal help-pattern contract` next and one narrower telemetry-supporting follow-up after those. - Runtime changes: - none in this curator pass; runtime/docs commit `2cebf4e` was already pushed, deployed, and production-smoked before memory sync. - Checks: - docs-only consistency pass against executor result, `origin/main` `2cebf4e`, `/root/apps/trajectory-prod` HEAD `2cebf4e`, current living docs, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0368 — 2026-07-30 — Strategist closed the stale red-gate strategy wording and extended the next horizon beyond integration - Goal: - remove the remaining contradiction where `TECHNICAL_STRATEGY.md` still described telemetry interpretation as a red prod-recovery lane even though promoted runtime `bea4d71` is already green on `https://journeyup.ru`; - make the next post-recovery horizon more cumulative: integration checkpoint first, then performance/help, then one narrower telemetry/product follow-up that does not reopen frozen stronger-proof policy by accident. - Result: - `TECHNICAL_STRATEGY.md` now treats `bea4d71` as the promoted baseline, closes the stale prod-recovery framing, and redirects the immediate work to one bounded release-integration checkpoint on that exact lane; - `ROADMAP.md` and `ACTIVE_TASKS.md` now preserve a stricter next order: - `release-integration checkpoint on interpretation recovery lane` - `performance branch decision for possible front/back split` - `minimal help-pattern contract` - then `export-friction / continuity-use telemetry follow-up` only if a more urgent product bottleneck does not overtake it; - `OPEN_QUESTIONS.md` now preserves two sharper forks that were previously implicit: - which supporting telemetry view is worth opening now that stronger-proof is frozen; - which concrete shell gets the first touch-safe help-pattern application after the contract is written. - Runtime changes: - none; strategist/doc-memory only. - Checks: - current git state inspection (`main...origin/main [ahead 9, behind 53]`) - docs-only consistency pass against `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, and `TECHNICAL_STRATEGY.md` ### ITER-0367 — 2026-07-30 — Curator synced interpretation recovery as promoted runtime truth - Goal: - replace the stale red-gate memory for merged `37fe5fd` with the executor-confirmed recovered runtime truth; - preserve the exact distinction between failing merged commit `37fe5fd`, bounded recovery fix `bea4d71`, and the next non-frozen post-recovery lanes. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `OPEN_QUESTIONS.md`, `TECH_DEBT.md`, `TESTING.md`, `DEV_RUNBOOK.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now record the exact promoted state: prod is healthy again on `https://journeyup.ru`, interpretation remains shipped on `/operator/runtime`, and rollback was not used; - living memory now preserves the exact failure class and fix: the crash came from null-shape trust state in `src/features/dashboard/components/dashboard-anonymous-profile-control.tsx`, and `bea4d71` hardened missing `continuityState`, `attachedReassuranceState`, and `credentialsState` to fail-closed defaults instead of crashing `/dashboard`, `/api/ready`, and PM2; - the next live task is no longer prod recovery, but one bounded release-integration checkpoint on the interpretation-recovery lane before moving to `performance branch decision for possible front/back split` and then `minimal help-pattern contract`. - Runtime changes: - none in this curator pass; runtime `bea4d71` was already pushed, deployed, and prod-smoked before docs sync. - Checks: - docs-only consistency pass against executor result, current `origin/main` `2bb5a88`, promoted runtime `bea4d71`, current living docs, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0366 — 2026-07-30 — Strategist made the post-incident lane and the next non-frozen slices more executable - Goal: - keep the roadmap from jumping directly from the red `37fe5fd` prod gate into another abstract product theme; - turn the two likely post-recovery lanes, `performance` and `minimal help`, into planner-ready bounded outcomes instead of labels. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now preserve one stricter delivery order: - first recover or roll back the red `37fe5fd` runtime; - then do one bounded release-integration checkpoint on that exact recovery lane; - only then move to the next non-frozen slice. - the two default successors are now sharper: - `performance branch decision for possible front/back split` must end with one forced consequence, either a bounded modular-monolith cleanup slice or one explicit split-preparation seam; - `minimal help-pattern contract` must end with one immediate UI application target on the current shell, not only a doctrine note. - living memory now also preserves the newest git continuation fact from the current worktree: local `main...origin/main [ahead 9, behind 51]`. - Runtime changes: - none; strategist/doc-memory only. - Checks: - current git status/branch inspection - docs-only consistency pass and diff inspection ### ITER-0365 — 2026-07-30 — Curator synced stage-2 interpretation as merged truth and red prod blocker - Goal: - replace the stale `stage 2 interpretation is next` memory with the exact executor-confirmed state after the slice was implemented, merged, pushed, and deploy-attempted; - preserve the distinction between promoted runtime `185ea33`, merged runtime/docs `37fe5fd`, and the failed prod gate on `https://journeyup.ru`. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, `TECHNICAL_STRATEGY.md`, `TECH_DEBT.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now record the exact stage-2 truth: - the interpretation contract is merged on `origin/main` through `37fe5fd`; - the verdict is explicit in code and docs: `restore is not common enough yet, so stronger-proof and second-device work stay frozen`; - prod evidence recorded from the shipped telemetry source of truth is `bundle_exported = 5`, `bundle_restored = 0`, `attach_completed = 0` in both trailing `7`-day and `30`-day windows. - living memory now keeps release state honest: - latest fully promoted runtime remains `185ea33`; - `/root/apps/trajectory-prod` is checked out at `37fe5fd`; - prod promotion is blocked because `/dashboard` and `/api/ready` returned `502`, PM2 fell to `errored`, and the latest log points at `src/features/dashboard/components/dashboard-anonymous-profile-control.tsx:250:33`. - active focus no longer jumps to the next product slice; it first points at bounded prod recovery or rollback for `37fe5fd`, while `recovery proof threshold for sensitive follow-up actions` is explicitly frozen until changed-since telemetry appears. - Runtime changes: - none in this curator pass; runtime code was already merged before docs sync. - Checks: - docs-only consistency pass against executor result, current branch facts (`origin/main` / `origin/release/identity-continuity-interpretation` / `origin/feature/identity-continuity-interpretation` at `37fe5fd`), `/root/apps/trajectory-prod` HEAD `37fe5fd`, and current living docs ### ITER-0364 — 2026-07-30 — Strategist sharpened telemetry interpretation, the next proof-threshold lane, and the clean-slice release path - Goal: - turn `identity continuity telemetry contract / stage 2 interpretation` from a generic `read the report` label into a tighter product decision contract; - keep the next auth/trust cycles change-bearing by naming the likely first stronger-proof candidate and preserving the clean-branch delivery rule. - Result: - `ACTIVE_TASKS.md`, `ROADMAP.md`, `PROJECT_STATUS.md`, and `TECHNICAL_STRATEGY.md` now require stage 2 to read both shipped windows explicitly (`7` days and `30` days), end with one written verdict sentence, and either open or freeze the stronger-proof lane instead of producing another metrics-only recap; - the likely stage-3 successor is now narrower in memory: if stronger proof is justified at all, evaluate `cross-device re-entry / identity-transfer-like follow-up` first, not the already-shipped first attach flow, `/subscription`, or generic settings breadth; - `OPEN_QUESTIONS.md` now preserves the next real forks after stage 2 more precisely: what to do if `7`-day and `30`-day windows disagree, and which product lane should move next if stronger proof stays frozen; - git/release continuation is updated with the newest concrete fact `main...origin/main [ahead 9, behind 50]`, and the next code-bearing slice is now documented as `refresh upstream -> clean review worktree -> slice-named feature branch -> same-name release branch only if promotion is warranted`. - Runtime changes: - none; strategist/doc-memory only. - Checks: - docs-only consistency pass against current living docs and factual git state in `/root/apps/trajectory-dev` ### ITER-0363 — 2026-07-30 — Curator synced living memory to the promoted identity-continuity telemetry report - Goal: - replace the stale `telemetry stage 1 is next` memory with the executor-confirmed production truth for the owner-only continuity report; - preserve the exact distinction between promoted runtime/docs commit `185ea33`, dirty local `main` `e5eb05a`, and the still-unfinished stage-2 interpretation/policy work. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, `TECHNICAL_STRATEGY.md`, `DOMAIN_MODEL.md`, `TESTING.md`, `SMOKE_TESTS.md`, `DEV_RUNBOOK.md`, `PROD_RUNBOOK.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now treat `identity continuity telemetry contract / stage 1 report` as shipped runtime rather than planner-ready future work; - living memory now preserves the exact telemetry contract: owner-only `/operator/runtime`, dual `7`-day and `30`-day windows, distinct `user_id + profile_code` denominator with in-window `bundle_exported`, ordered main stages `bundle_exported -> bundle_restored -> attach_completed`, and separate side counters for `bundle_verified`, `attach_blocked`, restore conflicts, and attach conflicts; - active focus moves forward from report implementation to `identity continuity telemetry contract / stage 2 interpretation`, then `recovery proof threshold for sensitive follow-up actions`, while anonymous breadth and the mixed-mode `/dashboard` exception remain unchanged. - Runtime changes: - none in this curator pass; runtime/docs commit `185ea33` was already pushed, merged, deployed, and production-verified before docs sync. - Checks: - docs-only consistency pass against the executor report, current branch/release facts (`origin/main` and `origin/release/identity-continuity-telemetry` at `185ea33`, `origin/feature/identity-continuity-telemetry` at `5be22b6`), living docs, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0362 — 2026-07-30 — Retrospective window 6541-6550 captured delivery facts and repaired docs-rotation churn - Goal: - preserve one factual retrospective over cycles `6541-6550` so the next ten-cycle review can continue from the real product/release trajectory instead of reconstructing it from scattered run logs; - reduce control-plane churn where adjacent docs-only passes kept restating the same promoted or local truth without changing roadmap or release consequence. - Result: - the window now has one compact factual summary in active memory: - `6541` implemented dashboard verify-and-restore and proved the contract locally/on dev, but stopped before commit/push/prod promotion; - `6542` completed verify-and-restore promotion and synced docs to merged runtime truth; - `6543` promoted the continuity cue slice; - `6544` implemented dashboard-local credentials attach but stopped on public-dev runtime drift; - `6545` promoted credentials attach; - `6546` promoted trust UX hardening; - `6547` built attached-identity reassurance in a clean review worktree but could not promote it through the canonical dirty tree in the same cycle; - `6548` advanced reassurance to real dev-origin verification and release readiness; - `6549` promoted attached-identity reassurance; - `6550` promoted progression semantics and moved the auth/trust line onto telemetry. - the main delivery pattern is now explicit: - six cycles in the window reached real release/promotion (`6542`, `6543`, `6545`, `6546`, `6549`, `6550`); - the remaining four still produced real change-bearing progress (`6541`, `6544`, `6547`, `6548`) rather than no-op classification, because they implemented or validated the next bounded slice and left a precise executable continuation. - the repeated blockers are preserved as concrete operational knowledge instead of vague caution: - dirty/diverged canonical `main` repeatedly forced clean upstream worktrees and replay branches before promotion; - hosted-dev/proxy drift (`502`, stale PM2 target) repeatedly looked like app regressions until local endpoint and process checks separated infra from code; - prod deploys briefly served stale `.next` output more than once, so build completion plus restart/save order matters; - smoke harness, env, and fixture issues (`SMOKE_OWNER_*`, multipart upload, quota assumptions, helper output noise) repeatedly extended validation tails even when the product contract itself was already right. - retrospective repair changed the working rules: - planner now explicitly forbids spending a fresh cycle on another docs-memory retelling when the last ship already preserved the needed facts; - retrospective now distinguishes useful memory from repeated rotation and pushes toward `one new fact -> one memory update`; - `AGENTS.md` now states that one precise memory sync is normally enough and that a second docs-only echo pass should not be created when roadmap consequence is unchanged. - Runtime changes: - none; retrospective and instruction repair only. - Checks: - read all `codex_live.md` logs for cycles `6541-6550`, current prompts, active roadmap/status docs, and current git state in both repos before patching docs/instructions. ### ITER-0361 — 2026-07-30 — Strategist decomposed the telemetry lane into report, interpretation, and policy slices - Goal: - prevent the post-progression roadmap from stopping at the abstract label `identity continuity telemetry contract`; - make the next auth/trust lane concrete enough that planner/executor can ship one operator report, one interpretation verdict, and one policy consequence without reopening route breadth. - Result: - `ACTIVE_TASKS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now define the telemetry line in three bounded steps: - stage 1 report over `bundle_exported -> bundle_restored -> attach_completed`; - stage 2 interpretation that answers whether restore materially precedes attach often enough to justify stronger-proof or second-device work; - stage 3 policy consequence that either names one later stronger-proof action family or explicitly freezes that work. - strategic memory now also makes the release lane more concrete for the next code-bearing pass: start from refreshed upstream in a clean review worktree and name the next feature/release branches for telemetry itself rather than generic auth follow-up. - open questions are now sharper on telemetry execution details that matter immediately: report window, whether `bundle_issued -> bundle_exported` should also be visible, and which owner-only operator surface should host the first report. - Runtime changes: - none; strategist/doc-memory only. - Checks: - docs-only consistency pass against current living docs plus factual git state `main...origin/main [ahead 9, behind 49]` ### ITER-0360 — 2026-07-30 — Curator synced living memory to the promoted dashboard progression-semantics runtime - Goal: - replace the stale `124b221 / 322bf00` reassurance-only active memory with the executor-confirmed production truth for the bounded mixed-mode explanation slice; - preserve the exact distinction between promoted runtime/docs commit `6f9abe3`, the local dirty `main` at `e5eb05a`, and the next live telemetry slice. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DOMAIN_MODEL.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, `TECHNICAL_STRATEGY.md`, `TECH_DEBT.md`, `TESTING.md`, `SMOKE_TESTS.md`, `DEV_RUNBOOK.md`, `PROD_RUNBOOK.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now treat `anonymous progression semantics without /subscription` as shipped runtime rather than planner-ready future work; - living memory now preserves the exact promoted contract: explanation home is the existing `/dashboard` help payload, that payload says exactly three bounded truths, and the canonical mixed-mode rule is now explicit in runtime helpers as `anonymous bypass on /dashboard only` while attached/credentials identities stay on `pending / active / banned` for credentials surfaces including `/subscription`; - active focus moves forward from progression semantics promotion to `identity continuity telemetry contract`, then `recovery proof threshold for sensitive follow-up actions`, while route breadth stays frozen and the explanation-home fork is closed. - Runtime changes: - none in this curator pass; runtime/docs commit `6f9abe3` was already pushed, merged, deployed, and production-verified before docs sync. - Checks: - docs-only consistency pass against the executor report, refreshed `origin/main` `6f9abe3`, current branch fact `main...origin/main [ahead 9, behind 49]`, living docs, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0359 — 2026-07-30 — Strategist hardened the next mixed-mode auth contract and made the release-shaped follow-up explicit - Goal: - keep the post-reassurance roadmap from looping on the same abstract `progression semantics -> telemetry -> proof threshold` labels; - turn the next bounded slice into a more concrete product contract and preserve the next clean-branch release path for that work. - Result: - `ACTIVE_TASKS.md`, `ROADMAP.md`, `PROJECT_STATUS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now carry a sharper default for `anonymous progression semantics without /subscription`: - explanation home should be the existing `/dashboard` help payload first; - anonymous bypass remains scoped to `/dashboard` only; - attached and credentials identities stay on the existing `pending / active / banned` contract outside that bounded exception; - the first help payload is constrained to three truths only: this surface keeps the current week reachable, recovery/export plus attach improve continuity rather than breadth, and broader credentials surfaces still follow the normal status rules. - the same docs now also make `identity continuity telemetry contract` more implementation-shaped: start with one operator-facing recent-window report sourced only from `anonymous_recovery_audit_logs`, then use that evidence to decide whether stronger proof for a later action is warranted or explicitly frozen. - git/release memory now preserves the next delivery shape more concretely: the next progression-semantics and telemetry slices should both start from refreshed upstream in a clean review worktree and promote through reviewable slice-named release branches rather than dirty local `main`. - Runtime changes: - none; strategist/doc-memory only. - Checks: - docs-only consistency pass against current living docs and factual git state `main...origin/main [ahead 9, behind 48]` ### ITER-0358 — 2026-07-30 — Curator synced living memory to the promoted attached reassurance runtime - Goal: - replace the stale dev-green-only reassurance snapshot with the executor-confirmed production truth; - preserve the exact distinction between promoted runtime `124b221`, docs sync `322bf00`, the review branch `origin/release/attached-identity-reassurance-promote`, and the still-dirty local `main`. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DOMAIN_MODEL.md`, `OPEN_QUESTIONS.md`, `TECHNICAL_STRATEGY.md`, `TESTING.md`, `SMOKE_TESTS.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now treat `attached identity reassurance` as shipped runtime rather than local/release-path work; - living memory now preserves the exact promoted contract: reassurance appears only when current attached-credentials state and matching persisted `attach_completed` proof agree for the same profile plus attached email digest, the same trust cluster keeps one equally visible limitation about no merge/sync/broader anonymous access, and mismatched proof fails closed to the older ownership/continuity wording; - active focus moves forward from reassurance promotion to `anonymous progression semantics without /subscription`, then `identity continuity telemetry contract`, then one telemetry-backed proof-threshold decision. - Runtime changes: - none in this curator pass; runtime `124b221` was already promoted before docs sync. - Checks: - docs-only consistency pass against the executor report, current branch facts, living docs, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0357 — 2026-07-30 — Strategist extended the post-reassurance auth line from telemetry into an explicit proof-threshold decision - Goal: - keep the next auth/trust horizon from stopping at `progression semantics` plus `telemetry` as two abstract planning labels; - turn the first telemetry funnel into a concrete downstream product/policy step and tighten the release-shape memory for the still-unpromoted reassurance slice. - Result: - `ACTIVE_TASKS.md`, `ROADMAP.md`, `PROJECT_STATUS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now carry one additional change-bearing step after telemetry: `recovery proof threshold for sensitive follow-up actions`, whose job is to decide whether any later trust-expanding action needs recovery-artifact possession or whether stronger proof remains explicitly frozen; - strategic memory now also preserves a sharper release fact for the current live slice: local `release/attached-identity-reassurance` is still only an upstream-based validation surface rooted at `09a9816`, so the next executor pass must still create the first reviewable reassurance release commit before push/merge/deploy can happen; - the next auth sequence is therefore explicit and cumulative rather than cyclical: promote reassurance -> define progression semantics on `/dashboard` help or one bounded adjacent surface -> derive the first continuity funnel -> convert that funnel into one evidence-backed proof-threshold or freeze decision. - Runtime changes: - none; strategist/doc-memory only. - Checks: - docs-only consistency pass against current living docs and factual git state `main...origin/main [ahead 9, behind 46]` ### ITER-0356 — 2026-07-30 — Curator synced living memory to the dev-verified reassurance slice and resolved the hosted-dev drift story - Goal: - correct the stale memory that still treated `attached identity reassurance` as unproven on the real hosted dev origin; - preserve the exact distinction between clean-worktree verification, real dev-origin verification after infra repair, and the still-unfinished release/prod path. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `OPEN_QUESTIONS.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now record the sharper truth: reassurance is green in clean review worktree `/root/apps/trajectory-reassurance-review`, green in clean upstream-based release worktree `/root/apps/trajectory-release-reassurance`, and green on the actual hosted dev origin `https://dev.journeyup.ru`; - living memory now also preserves the real hosted-dev incident: PM2 app `trajectory-dev` was wrongly running from `/root/apps/trajectory-trust-ux`, executor recreated it from canonical `/root/apps/trajectory-dev`, and only after that fix did the public dev smoke, anonymous dashboard smoke, and signed-in auth matrix become valid reassurance evidence on the changed runtime; - active docs no longer describe canonical-dev overlap as the live blocker; the remaining blocker is release completion only: reviewable commit/push on `release/attached-identity-reassurance`, merge to `origin/main`, prod deploy in `/root/apps/trajectory-prod`, and prod smoke on `https://journeyup.ru` all remain pending. - Runtime changes: - none in this curator pass; runtime code was already changed before memory sync, but promotion is still incomplete. - Checks: - docs-only consistency pass against the executor report, current branch facts, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0355 — 2026-07-30 — Strategist turned the reassurance blocker into an explicit delivery order for progression semantics and telemetry - Goal: - prevent the next cycle from stopping at the already-known canonical-dev overlap blocker for `attached identity reassurance`; - make the next post-attach work execute in a strict product order: promote reassurance first, then clarify mixed-mode progression semantics, then derive telemetry for the next auth-surface decision. - Result: - `ACTIVE_TASKS.md`, `ROADMAP.md`, `PROJECT_STATUS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now carry one sharper continuation contract: - the reassurance replay/promotion path is part of the slice itself, not optional cleanup after local green checks; - `anonymous progression semantics without /subscription` now has a stronger strategist default: use existing dashboard help first and let attached identities inherit the current credentials-status model unless later evidence proves a clearer unified rule; - `identity continuity telemetry contract` now has a preferred first consumer decision: determine whether restore meaningfully precedes attach often enough to justify any later stronger-proof or second-device path. - strategic memory now also preserves one operational fork that still matters if replay remains blocked: whether to reconcile canonical `/root/apps/trajectory-dev` directly or replay the bounded reassurance files straight onto a fresh upstream-based release worktree before dev-tree reconciliation. - Runtime changes: - none; strategist/doc-memory only. - Checks: - docs-only consistency pass against current living docs plus factual git state `main...origin/main [ahead 9, behind 46]` ### ITER-0354 — 2026-07-30 — Curator synced living memory to the local reassurance candidate and its canonical-dev integration blocker - Goal: - align living docs with the executor-confirmed state for the bounded `attached identity reassurance` slice instead of leaving it as planning-only future work; - preserve the exact distinction between promoted trust-hardening runtime `cd14e08` / docs sync `09a9816` and the new clean-worktree reassurance delta that is not yet committed, pushed, merged, deployed, or prod-smoked. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DOMAIN_MODEL.md`, `TECHNICAL_STRATEGY.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, `TESTING.md`, and `SMOKE_TESTS.md` now record the concrete local reassurance contract: - the visible reassurance stays in the existing trust cluster; - it renders only when current attached-credentials state and a matching persisted `anonymous_recovery_audit_logs.attach_completed` fact agree for the same profile plus email digest; - it keeps one visible limitation that attach did not create merge, sync, or broader anonymous access; - if proof is missing, the UI fails closed to the already-shipped ownership/continuity wording. - living memory now also preserves the exact release blocker: - clean review worktree `/root/apps/trajectory-reassurance-review` on branch `feature/attached-identity-reassurance` passed targeted tests, `pnpm test:smoke-auth-matrix`, `typecheck`, `lint`, and placeholder-env `build`; - executor also ran `pnpm dev:hosted:recover`, public dev smoke, and the signed-in matrix on `https://dev.journeyup.ru`, but that origin still served the canonical `/root/apps/trajectory-dev` PM2 tree with overlapping dirty auth-lane residue on the same files, so those runs cannot be treated as reassurance proof on the changed runtime; - commit/push/release-branch replay/deploy/prod smoke therefore remain honestly `not run`. - [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now records the full executor fact pattern for this local-but-not-integrated reassurance slice, including the exact bounded files and next executable replay step on canonical dev. - Runtime changes: - none in this curator pass; code already exists only in the clean review worktree and is not yet runtime truth. - Checks: - docs-only consistency pass against the executor report, current living docs, current git state in both worktrees, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0353 — 2026-07-30 — Strategist made the post-attach roadmap planner-ready and refreshed git continuation facts - Goal: - sharpen the next post-promotion auth line so the next cycle ships one bounded reassurance, one bounded progression explanation, or one bounded telemetry contract instead of another vague auth-planning pass; - refresh living memory where the local git continuation fact changed again after the latest upstream movement. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now make the next three slices more executable: - `attached identity reassurance` is now defined as one visible same-week credentials re-entry confirmation plus one equally truthful limitation that keeps merge/sync/breadth out of scope; - `anonymous progression semantics without /subscription` is now constrained to choose one explanation home and one mixed-mode status rule rather than opening `/subscription` for copy; - `identity continuity telemetry contract` is now constrained to one canonical audit-derived funnel plus supporting counters and one explicit downstream decision it should inform. - living memory now also preserves the updated git continuation fact: local `main...origin/main` moved from `behind 44` to `behind 46`, so the clean-upstream rule for the next code-bearing auth slice remains active and even stricter. - Runtime changes: - none; strategist/doc-memory only. - Checks: - docs-only consistency pass against current living docs plus factual git state `main...origin/main [ahead 9, behind 46]` ### ITER-0352 — 2026-07-30 — Curator synced living memory to the promoted anonymous trust-hardening runtime - Goal: - replace the stale `anonymous trust UX hardening` prepared/live-task state with the executor-confirmed production truth; - preserve the exact distinction between promoted runtime `cd14e08`, docs sync `09a9816`, the still-dirty local `main`, and the bounded deploy incident that happened during promotion. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `TECHNICAL_STRATEGY.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, `TESTING.md`, and `SMOKE_TESTS.md` now treat trust hardening as shipped rather than queued: the anonymous `/dashboard` trust cluster keeps exactly one visible ownership/continuity sentence, and secondary switch/export/verify/restore/attach semantics now live behind the existing help affordance; - active memory now advances the next live slice from `anonymous trust UX hardening` to `attached identity reassurance`, while keeping `anonymous progression semantics without /subscription` and `identity continuity telemetry contract` as the next queued bounded follow-ups; - release memory now preserves the real promotion facts: runtime `cd14e08`, docs sync `09a9816`, dev smoke on `https://dev.journeyup.ru`, prod smoke on `https://journeyup.ru`, the exact repo-owned fixture emails used for the signed-in matrix reruns, and the bounded prod `502` incident caused by `deploy:restart` racing ahead of a finished build before the successful rerun. - Runtime changes: - none in this curator pass; runtime `cd14e08` was already deployed before docs sync. - Checks: - docs-only consistency pass against the executor report, current living docs, current i18n/runtime copy, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0351 — 2026-07-30 — Strategist turned the post-attach auth line into four tighter delivery contracts and refreshed git continuation state - Goal: - make the next post-attach slices more executable than generic labels so planner/executor can keep shipping vertical trust value without reopening route breadth by default; - refresh living memory where the local git continuation fact changed again after the attach promotion. - Result: - `ACTIVE_TASKS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, `PROJECT_STATUS.md`, and `TECHNICAL_STRATEGY.md` now define the next trust horizon more concretely: - `anonymous trust UX hardening` should land one always-visible trust sentence plus one bounded help payload, not another broad copy pass; - `attached identity reassurance` should land one visible post-attach state plus one explicit limitation, not an account-center expansion; - `anonymous progression semantics without /subscription` should choose one explanation surface and one mixed-mode status mapping before any route-opening debate restarts; - `identity continuity telemetry contract` should start from one canonical audit-derived funnel, with the current default candidate `bundle_exported -> bundle_restored -> attach_completed`. - strategic memory now also preserves one new operational fact: local `main...origin/main` advanced from `behind 43` to `behind 44`, so the clean-upstream rule for the next code-bearing auth slice remains active and even more concrete; - open questions are narrowed around the immediate product choices that now matter most: the exact always-visible trust sentence, the source of truth for post-attach reassurance state, and the first canonical telemetry funnel. - Runtime changes: - none; strategist/doc-memory only. - Checks: - docs-only consistency pass against current living docs plus factual git state `main...origin/main [ahead 9, behind 44]` ### ITER-0350 — 2026-07-30 — Curator synced living memory to the promoted anonymous credentials attach runtime - Goal: - replace the stale local/dev-blocked attach snapshot with the executor-confirmed production truth for the bounded `credential handoff contract` slice; - preserve the exact distinction between already-promoted runtime `cb7a9f2`, existing merged docs baseline `1d21bf8`, and this still-local docs sync pass. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DOMAIN_MODEL.md`, `TECHNICAL_STRATEGY.md`, `OPEN_QUESTIONS.md`, `TECH_DEBT.md`, `DEV_RUNBOOK.md`, `PROD_RUNBOOK.md`, `SMOKE_TESTS.md`, `TESTING.md`, and `DECISIONS.md` now treat dashboard-local credentials attach as shipped runtime rather than a blocked local candidate; - living memory now preserves the exact release evidence: runtime `cb7a9f2` is live on both `https://dev.journeyup.ru` and `https://journeyup.ru`, `origin/release/anonymous-credential-handoff` was the reviewable release branch, anonymous `/dashboard` stayed `200`, attach completed with `303 /dashboard?attachCredentials=attached`, credentials login returned to the same underlying profile/week, and direct enum verification passed on both dev and prod for `attach_started` / `attach_completed` / `attach_blocked` alongside the earlier recovery events; - memory also preserves the only bounded follow-up discovered during validation: repo-owned smoke packaging, not runtime behavior, needed correction through `package.json` helper wiring and silent helper output in `scripts/smoke-anonymous-dashboard.sh`, and the next live slices now move to `anonymous trust UX hardening`, `attached identity reassurance`, `anonymous progression semantics without /subscription`, and `identity continuity telemetry contract`. - Runtime changes: - none in this curator pass; runtime `cb7a9f2` was already promoted before docs sync. - Checks: - docs-only consistency pass against the executor report, current living docs, current git-visible branch facts (`origin/main` contains `cb7a9f2`, `origin/release/anonymous-credential-handoff` exists), and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0349 — 2026-07-30 — Strategist extended the post-attach horizon into reassurance, progression semantics, telemetry, and an explicit release lane - Goal: - prevent the auth line from stalling at `credential handoff contract` plus a recurring hosted-dev blocker; - turn the next steps after attach into explicit change-bearing slices while keeping git/release integration reviewable. - Result: - `ACTIVE_TASKS.md`, `ROADMAP.md`, `PROJECT_STATUS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now extend the current auth sequence beyond promotion of the local attach slice: `anonymous trust UX hardening` -> `attached identity reassurance` -> `anonymous progression semantics without /subscription` -> `identity continuity telemetry contract`; - strategic memory now also fixes the release path for the already-implemented attach delta: once `https://dev.journeyup.ru` is healthy again, replay the bounded branch `feature/anonymous-credential-attach` onto a refreshed upstream-based release branch and verify/promote from there, rather than continuing from dirty local `main`; - open questions now include the smallest post-attach reassurance promise and the minimum attach/export/restore/conflict metrics that should become inspectable before another auth-surface expansion is chosen. - Runtime changes: - none; strategist/doc-memory only. - Checks: - docs consistency pass against current living memory plus factual git state `main...origin/main [ahead 9, behind 43]` ### ITER-0348 — 2026-07-30 — Curator synced living memory to the local dashboard-local credentials attach candidate and its red hosted-dev gate - Goal: - align living docs with the executor-confirmed attach slice instead of leaving active memory at the earlier `credential handoff decision` stage; - preserve the exact distinction between promoted continuity runtime `b07c4df` / docs sync `1d21bf8` and the new local attach implementation that has clean-worktree checks but a red public dev gate. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, `TECHNICAL_STRATEGY.md`, `DOMAIN_MODEL.md`, `SYSTEM_MAP.md`, `TECH_DEBT.md`, `SMOKE_TESTS.md`, `TESTING.md`, and `DECISIONS.md` now record that the first named-identity bridge is no longer undecided: dashboard-local attach was chosen and implemented locally with the bounded contract `dashboard surface + recommended-not-required recovery proof + no-merge conflict rule + attach_started/attach_completed/attach_blocked audit`; - living memory now also preserves the exact verification split: targeted tests, `next typegen`, `typecheck`, `lint`, `db:migrate`, and `build` passed in `/root/apps/trajectory-attach-review` on branch `feature/anonymous-credential-attach`, the local app recovered on `http://127.0.0.1:3001/api/ready`, but `DEV_PUBLIC_BASE_URL=https://dev.journeyup.ru scripts/smoke-public-dev.sh` still failed at `502 https://dev.journeyup.ru/`, so anonymous attach smoke, signed-in matrix rerun, commit/push/merge/deploy/prod smoke all stayed pending; - [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now keeps the full executor fact pattern for this local/dev-blocked attach slice, including migration `0027_anonymous_credentials_attach` already applied on the dev DB and the next executable recovery step on the exact dev origin. - Runtime changes: - none in this curator pass; code already existed locally before the memory sync and is not yet release truth. - Checks: - docs-only consistency pass against the executor report, current attach code paths, current git state, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0347 — 2026-07-30 — Strategist decomposed the post-continuity auth horizon into a handoff contract and follow-up vertical slices - Goal: - keep the roadmap from stopping at the abstract label `credential handoff decision` after continuity proof was already promoted; - make the next auth-bearing cycles sequentially shippable without reopening route breadth or merge sprawl by accident. - Result: - `ACTIVE_TASKS.md` now defines the immediate next pressure more concretely: after the handoff decision itself, the next prepared bounded slice is `credential handoff contract`, which must specify one bridge surface, recovery-proof expectations, minimum audit events, and the truthful user promise before broader UX/policy follow-ups begin; - `ROADMAP.md` now decomposes the next auth line into four explicit vertical slices: `credential handoff decision` -> `credential handoff contract` -> `anonymous trust UX hardening` -> `anonymous progression semantics without /subscription`, and it also fixes one release-shape rule that the next release branch should be named after the chosen handoff contract rather than generic auth cleanup; - `OPEN_QUESTIONS.md` and `TECHNICAL_STRATEGY.md` now capture the exact unresolved contract edges for the bridge: whether recovery-artifact possession is required before attach, how to fail closed when the target named identity already has trajectory state, and which minimum audit events are really needed for the first named-identity handoff. - Runtime changes: - none; strategist/doc-memory only. - Checks: - docs-only consistency pass against the current promoted auth baseline, active roadmap bundle, and current git continuation state (`main...origin/main [ahead 9, behind 43]`) ### ITER-0346 — 2026-07-30 — Curator synced living memory to the promoted dashboard continuity proof - Goal: - replace the stale `continuity cues` as live-task planning state with the executor-confirmed production truth; - preserve the exact distinction between runtime promotion `b07c4df`, docs sync `1d21bf8`, and the still-dirty local `main` that did not become runtime truth. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, `TECHNICAL_STRATEGY.md`, `TECH_DEBT.md`, `SMOKE_TESTS.md`, `DEV_RUNBOOK.md`, `PROD_RUNBOOK.md`, `TESTING.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now record the real shipped continuity contract: one compact top-bar trust state on `/dashboard`, derived from current UUID identity plus the latest successful `bundle_restored` or `bundle_exported` row, with ownership-only wording when no successful recovery action exists; - active memory now moves the live task forward from `anonymous continuity cues` to `credential handoff decision`, while preserving the already-shipped continuity-proof rationale and the frozen non-dashboard anonymous boundary; - git/release memory is now explicit for the full auth line on Thursday, July 30, 2026: `origin/main` and `origin/release/anonymous-continuity-cues` carry docs sync `1d21bf8`, production runtime is `b07c4df`, and local `main` remains dirty/diverged at `e5eb05a` rather than becoming release truth. - Runtime changes: - none in this curator pass; runtime `b07c4df` was already deployed before docs sync. - Checks: - docs-only consistency pass against the executor report, current branch/release pointers, living docs, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0345 — 2026-07-30 — Strategist turned continuity cues into a concrete proof shape and refreshed git/release continuation state - Goal: - make the next auth-bearing slice more executable than a generic `continuity cues` placeholder; - keep living memory honest about the current post-promotion git/release state so the next code slice starts from the right base. - Result: - `ROADMAP.md`, `ACTIVE_TASKS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now define a narrower preferred continuity shape: top-bar trust cluster first, current-profile ownership cue plus latest successful recovery-action cue, and a compact combined state if two separate cues feel too heavy; - active memory now also sharpens the next comparison after that slice: `credential handoff decision` should explicitly compare login-adjacent attach, dashboard-local attach, and one more deliberate defer phase instead of remaining an abstract future label; - git/release memory is refreshed with the current continuation fact pattern: local `main...origin/main [ahead 9, behind 41]`, plus the existing release-branch chain `8570be3` -> `0f00ffe` -> `036b3e9`, with the next auth code slice expected to start from refreshed upstream or another clean release surface. - Runtime changes: - none; strategist/doc-memory only. - Checks: - docs-only consistency pass against current living docs and current git branch/worktree state ### ITER-0344 — 2026-07-30 — Strategist moved the auth line from verify/restore promotion to continuity proof - Goal: - stop active memory from lingering on a now-promoted verify/restore release candidate; - turn the next auth-bearing slice into a smaller user-facing proof step instead of another release-isolation loop. - Result: - `ROADMAP.md`, `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now treat `anonymous continuity cues` as the live next slice after promoted verify/restore; - the next auth sequence is now explicit and ordered by trust depth: continuity cues first, credential handoff second, broader surface expansion only after those; - living memory no longer describes the verify/restore panel as a local-only candidate or pending release work. - Runtime changes: - none; strategist/doc-memory only. - Checks: - docs-only consistency pass against executor promotion facts, current git-visible release branches, and current living docs ### ITER-0343 — 2026-07-30 — Curator synced living memory to the promoted verify/restore runtime - Goal: - replace the stale local-only verify/restore snapshot with the executor-confirmed production truth; - preserve the exact distinction between feature commit `1c01c48`, bounded prod follow-up fix `309f43b`, and docs sync `036b3e9`. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `DOMAIN_MODEL.md`, `SYSTEM_MAP.md`, `OPEN_QUESTIONS.md`, `TECH_DEBT.md`, `SMOKE_TESTS.md`, `DEV_RUNBOOK.md`, `PROD_RUNBOOK.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now record the real shipped contract: anonymous `/dashboard` still returns `200`, verify happens before any cookie mutation, restore is offered only after successful verification, and bounded audit now includes `bundle_verified` plus `bundle_restored`; - living memory now records the prod incident honestly: raw feature commit `1c01c48` was not fully shippable by itself because a `"use server"` file exported a plain object, and follow-up runtime commit `309f43b` fixed that defect before prod smoke passed on `https://journeyup.ru`; - the next live task moved from promotion/integration to `anonymous continuity cues`, while `/subscription` and `/operator*` remain frozen on the old credentials contract. - Runtime changes: - none in this curator pass; runtime `309f43b` was already deployed before docs sync. - Checks: - docs-only consistency pass against executor promotion facts, current release branches (`release/anonymous-recovery-verify-restore` at `036b3e9`), and living docs ### ITER-0342 — 2026-07-30 — Strategist turned the local verify/restore candidate into a tighter trust sequence and release-isolation lane - Goal: - prevent the next cycle from stopping at “promote current candidate somehow” without a clearer post-promotion trust sequence; - make release isolation for the local verify/restore slice an explicit delivery step rather than another vague dirty-worktree warning. - Result: - `ROADMAP.md`, `ACTIVE_TASKS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now treat the current auth horizon as one concrete sequence: promote dashboard-local verify/restore from an upstream-based clean candidate, then ship `anonymous continuity cues`, and only then choose the first credential handoff; - active memory now gives the next executor cycle a stricter release shape: do not attempt the next promotion from dirty `main...origin/main [ahead 9, behind 38]`; reconstruct or copy the bounded verify/restore files onto a refreshed-upstream release worktree and decide ship-readiness there; - product memory now holds a clearer post-promotion outcome as well: the first continuity slice should prefer audit-backed cues already present in recovery/export logs instead of inventing an account-history surface. - Runtime changes: - none; strategist/doc-memory only. - Checks: - current git branch/worktree inspection (`main...origin/main [ahead 9, behind 38]`, local `HEAD` `e5eb05a`) - docs-only consistency pass against the latest curator snapshot and current strategic bundle ### ITER-0341 — 2026-07-30 — Curator synced living memory to the local verify-and-restore consumer candidate - Goal: - align active docs with the executor-confirmed state after the first real `anonymous_recovery_kit_v1` consumer was implemented locally on `/dashboard`; - preserve the exact distinction between promoted runtime `c707615` / docs sync `0f00ffe` and the new dev-green but still-unreleased verify/restore slice. - Result: - `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DOMAIN_MODEL.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, `TECH_DEBT.md`, `DEV_RUNBOOK.md`, `SMOKE_TESTS.md`, and `TESTING.md` now treat phase-2 breadth as intentionally frozen for this iteration and record the real next live slice as the local `dashboard recovery artifact verify-and-restore panel`; - living memory now preserves the bounded local contract in detail: result classes `success / mismatch / tampered / malformed / unsupported_version`, restore through the existing manual profile-switch boundary only, and local audit extensions `bundle_verified` / `bundle_restored` with bounded metadata and no raw artifact storage; - [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now records the exact dev checks, base URL `https://dev.journeyup.ru`, and honest release state: no commit/push/main merge/prod deploy/prod smoke happened for this slice. - Runtime changes: - none in this curator pass; code already existed locally before the memory sync. - Checks: - docs-only consistency pass against the executor result, current local git state (`main` `e5eb05a`, `origin/main` `0f00ffe`), and existing archive memory ### ITER-0340 — 2026-07-30 — Retrospective captured the real development yield of cycles 6531-6540 and removed stop-contract churn - Goal: - evaluate the full retrospective window `6531-6540` by delivered product/runtime change, not just by log completeness; - preserve which cycles created new user/runtime value, which cycles devolved into upstream-equivalence churn, and which instruction changes are needed so the next window spends fewer turns on no-release-delta rediscovery. - Result: - retrospective evidence now distinguishes one unavailable cycle and nine observed ones: - `6531`: `unknown evidence` because the available `codex_live.md` contains only the run header; - `6532`: `product/runtime` because owner input about anonymous UUID open testing and possible front/back split was archived in full, distributed into roadmap/docs, and the first bounded implementation of anonymous `/dashboard` entry started in code; - `6533`: `product/runtime` because the anonymous `/dashboard` slice was narrowed to the right boundary, split away from sibling protected routes, and moved materially closer to acceptance even though first-hit `/dashboard -> 200` was still red; - `6534`: `product/runtime` because the anonymous `/dashboard` phase-1 contract reached green hosted-dev smoke with direct `GET /dashboard -> 200`, correct public-origin switching, and preserved signed-in matrix behavior; - `6535`: `release/promotion` because phase-1 anonymous `/dashboard` was pushed, merged, deployed, prod-smoked, and documented on `https://journeyup.ru` through `2049727`, `507f003`, and `8570be3`; - `6536`: `no-release-delta` because the `runtime tooling candidate` turned out to be already shipped upstream and only docs/memory were cooled down; - `6537`: `no-release-delta` because the `event-report promotion candidate` was upstream-equivalent to refreshed `origin/main` and produced no new runtime delta; - `6538`: `no-release-delta` because the remaining auth-neighbor residue around auth smoke/process wiring was also upstream-equivalent and should have ended the cleanup lane rather than reopening it again; - `6539`: `product/runtime` because the first durable anonymous trust action landed as `5009809 feat: add anonymous recovery kit`, with deterministic `anonymous_recovery_kit_v1`, separate `bundle_issued` / `bundle_exported` audit, and updated smoke/docs, even though prod promotion stopped on a dirty prod worktree; - `6540`: `release/promotion` because the bounded prod-only defect in the recovery-kit server action was fixed by `c707615`, deployed to `https://journeyup.ru`, and proven by public smoke, anonymous smoke, signed-in matrix, live-schema verification, and DB audit proof. - by count, the window yielded `6` change-bearing cycles (`6532`, `6533`, `6534`, `6535`, `6539`, `6540`), `3` cycles of repeated upstream-equivalence/classification churn (`6536`, `6537`, `6538`), and `1` cycle with unavailable evidence (`6531`); - delivered capabilities across the window were substantial: - anonymous UUID open-testing entry on `/dashboard` only, with cookie-backed identity, top-bar profile switch, per-IP daily switch limit, and preserved credentials gating for `/subscription` and `/operator*`; - deterministic anonymous recovery/export as the first durable trust action, including the signed `anonymous_recovery_kit_v1` bundle and inspectable recovery audit rows; - stronger repo-owned dev/prod smoke paths and release memory around anonymous entry, auth matrices, and migration/deploy incidents; - long-horizon roadmap advanced rather than merely rotating logs: - auth moved from owner idea -> local candidate -> hosted-dev green -> prod promotion -> trust-continuity follow-up; - the next auth line is now explicitly `auth phase-2 surface map` -> `credential handoff decision` -> `recovery artifact consumer contract` -> dashboard-local verify/restore consumer -> trust UX / continuity cues; - the future performance/front-back split and SFM authoring work survived in docs as real queued initiatives instead of being lost during auth delivery. - Operational lessons preserved: - knowledge retention in docs was mostly good: owner inputs, rationale, exact commits, smoke commands, prod incidents, schema verification, and next slices were repeatedly written into active docs and archive without obvious compaction loss; - git/release discipline did eventually work end-to-end: the window contains real branch isolation, pushes, mainline integration, deploys, prod smoke, and a bounded prod hotfix, but too many cycles immediately after `507f003` were spent rediscovering that local residue was already upstream-equivalent; - the main repeated error was control-plane churn around cooled `no release delta` scopes, amplified by an overgrown stop/no-op contract in `AGENTS.md`; the fix in this retrospective is simplification, not another larger template system. - Instruction changes made from this retrospective: - [AGENTS.md](/root/apps/trajectory-dev/AGENTS.md) now replaces the oversized repeated-stop template block with a short upstream-first rule set that still prevents duplicate promotion but stops encouraging long no-op ceremony; - [01_PLANNER.md](/root/apps/ControlPlane/prompts/01_PLANNER.md) now says more directly that a cooled `no release delta` scope must not be selected again without a concrete changed-since fact; - [05_CODEX_RETROSPECTIVE.md](/root/apps/ControlPlane/prompts/05_CODEX_RETROSPECTIVE.md) now requires per-cycle classification and explicitly prefers simplifying churn-causing instructions over layering new prohibitions. - Runtime changes: - none in this retrospective pass; changes were limited to prompts/instructions and this evidence record. - Checks: - full read of the available retrospective-window `codex_live.md` files for cycles `6531-6540`; - review of current prompts, [AGENTS.md](/root/apps/trajectory-dev/AGENTS.md), active roadmap/status docs, current git status in both repos, and recent `trajectory-dev` git history/diffstat ### ITER-0339 — 2026-07-30 — Strategist turned the next auth horizon into a concrete restore-first sequence - Goal: - prevent the post-promotion auth plan from stalling at `surface map -> consumer someday` without a concrete first trust consumer; - define where trust/progression semantics should live if `/subscription` stays closed for another phase. - Result: - `ROADMAP.md`, `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now make the next trust implementation more concrete: the preferred first consumer under `recovery artifact consumer contract` is a `dashboard recovery artifact verify-and-restore panel`, not a generic later restore idea; - active memory now also keeps one follow-up product/policy slice ready if phase 2 freezes non-dashboard breadth: `anonymous progression semantics without /subscription`, which will decide where anonymous users learn trust/progression limits and how that message coexists with `pending / active / banned`; - the roadmap therefore advances in a clearer sequence: `auth phase-2 surface map` -> `credential handoff decision` -> `recovery artifact consumer contract` -> concrete dashboard-local consumer -> trust UX/continuity/progression semantics, instead of another abstract auth-planning loop. - Runtime changes: - none; strategist/doc-memory only. - Checks: - docs-only consistency pass against the current living-memory bundle and current git-visible release state ### ITER-0338 — 2026-07-30 — Curator synced living memory to the actual recovery-kit production outcome - Goal: - replace the stale `5009809 pushed-but-not-promoted` snapshot with the executor-confirmed production truth for the bounded recovery-kit slice; - preserve the exact distinction between the intended feature commit, the bounded prod-only follow-up fix, docs sync, and the prod-worktree blocker that existed earlier in the same day. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `DOMAIN_MODEL.md`, `SYSTEM_MAP.md`, `OPEN_QUESTIONS.md`, `TECH_DEBT.md`, `SMOKE_TESTS.md`, `PROD_RUNBOOK.md`, and `TECHNICAL_STRATEGY.md` now record the real release state: raw feature commit `5009809` was not fully shippable by itself on prod, the bounded runtime fix landed as `c707615`, docs sync landed as `0f00ffe`, and `https://journeyup.ru` now carries the recovery/export contract with green smoke and live-schema proof; - active memory no longer treats `promote anonymous recovery kit` as the live task; the next bounded task is back to `auth phase-2 surface map`, with `recovery artifact consumer contract` as the default next implementation if non-dashboard anonymous expansion stays frozen; - [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now keeps both facts from the same day without erasing history: the earlier prod-worktree blocker and the later successful promotion with exact commands, schema verification, smoke base URL, and DB audit proof. - Runtime changes: - none in this curator pass; runtime `c707615` was already deployed before docs sync. - Checks: - docs-only consistency pass against the executor promotion report, current living docs, current git-visible release state, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0337 — 2026-07-30 — Strategist extended the auth roadmap from export-only trust into artifact consumption and continuity cues - Goal: - prevent the post-promotion auth horizon from stalling at `surface map -> decide later` without another user-visible trust improvement; - turn the new `anonymous_recovery_kit_v1` export into a staged product line that can deliver one real consumer and one minimal continuity signal before broader route opening or merge complexity. - Result: - `ROADMAP.md`, `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now make the next trust horizon more specific: after `promote anonymous recovery kit` and `auth phase-2 surface map`, the default next implementation becomes `recovery artifact consumer contract` rather than another abstract auth decision; - active memory now also keeps one smaller product slice ready behind that implementation: `anonymous continuity cues`, which will decide the minimum persistent audit-backed signals that reassure the user their week still belongs to the same identity without bloating `/dashboard`; - open questions now preserve the concrete design pressure for that line: which first artifact-consumer surface is narrowest and safest, and which failure classes or continuity signals must become user-visible first. - Runtime changes: - none; strategist/doc-memory only. - Checks: - docs-only consistency pass against the current living-memory bundle and current git-visible release state ### ITER-0336 — 2026-07-30 — Curator synced memory to the pushed-but-not-promoted anonymous recovery kit slice - Goal: - align living docs with the executor-confirmed state of the anonymous recovery-kit slice instead of leaving memory at the earlier `507f003 promoted / 8570be3 docs sync` snapshot; - preserve the exact distinction between `507f003` as the latest production runtime, `5009809` as the merged runtime delta on `origin/main`, and the blocked prod deploy in `/root/apps/trajectory-prod`. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, and `TECH_DEBT.md` now record the actual git/release state: commit `5009809` (`feat: add anonymous recovery kit`) is pushed to `origin/main` and `origin/release/anonymous-recovery-kit`, while production still runs `507f003`; - active memory now makes the immediate bounded task operational instead of strategic: first clear the unrelated staged prod-worktree residue `A docs/product/STATE_FLOW_MACHINE.md`, then deploy/smoke `5009809` before reopening `auth phase-2 surface map` as the next product slice; - [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now keeps the full execution fact pattern for this slice, including the exact green dev checks and the honest prod blocker. - Runtime changes: - none in this curator pass; runtime code was already committed and pushed before docs sync. - Checks: - docs-only consistency pass against the executor report, current `origin/main` / branch state, and existing living-memory bundle ### ITER-0335 — 2026-07-30 — Strategist turned phase-2 auth planning into a trust-first sequence - Goal: - evolve the post-promotion roadmap beyond "pick the next surface" so the next planner cycle cannot drift back into cleanup or route taxonomy only; - choose a reversible default for the next auth horizon without pretending that a broader anonymous expansion is already justified. - Result: - `ROADMAP.md`, `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now bias the next horizon toward trust continuity before breadth: the default is to keep `/subscription` and the rest of the credentials shell closed for one more phase unless new evidence proves otherwise; - active memory now stages the next auth work as a sequence instead of one vague continuation: `auth phase-2 surface map` -> `credential handoff decision` -> `anonymous recovery kit contract` -> `anonymous trust UX hardening`; - open questions now preserve the unresolved implementation details that matter for that direction: what evidence would justify opening another anonymous surface early, and what the first recovery/export audit bundle must contain. - Runtime changes: - none; strategist/doc-memory only. - Checks: - docs-only consistency pass against current roadmap/active-memory docs and current git-visible release state ### ITER-0334 — 2026-07-30 — Curator synced living memory after the auth-neighbor residue closed as no release delta - Goal: - align active memory with the executor-confirmed upstream-equivalence result for the last named auth-neighbor cleanup bucket; - remove leftover wording that still implied a live cleanup slice after `package.json`, `scripts/smoke-authenticated.sh`, and `ecosystem.config.cjs` were proven upstream-identical. - Result: - `PROJECT_STATUS.md`, `TECHNICAL_STRATEGY.md`, and `TECH_DEBT.md` now distinguish the real post-run state more precisely: the named auth-neighbor bucket is closed as stale local noise, while the remaining dirty/diverged `main` state is only a general integration-hygiene debt until a fresh bounded scope is chosen; - `ACTIVE_TASKS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, `SYSTEM_MAP.md`, runbooks, smoke docs, and `DECISIONS.md` were rechecked and left unchanged because they already matched the executor facts: no runtime contract changed, no verification gate ran, and the next live slice is `auth phase-2 surface map`; - [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) already held the bounded no-release-delta evidence, so no second archive restatement was needed. - Runtime changes: - none; docs/state-sync only. - Checks: - docs-only consistency pass against the executor report, current living docs, current git branch/worktree state (`main` `e5eb05a`, `origin/main` `8570be3`), and existing archive memory ### ITER-0333 — 2026-07-30 — Auth-neighbor runtime-contract residue closed as upstream-equivalent - Goal: - classify the last named auth-neighbor cleanup bucket before spending any redundant verification or release gates; - decide whether `package.json`, `scripts/smoke-authenticated.sh`, and `ecosystem.config.cjs` still contain a real release-throughput delta after the anonymous `/dashboard` promotion. - Result: - refreshed `origin/main` `8570be3` already matches the ship-candidate tree for `package.json`, `scripts/smoke-authenticated.sh`, and `ecosystem.config.cjs`, so the requested bucket closes as `no release delta`; - the visible local diff on that bucket came from stale local `HEAD`/index state around already-shipped history, including `e2c5ee4` for the `/subscription` smoke contract and the already-promoted hosted-dev PM2 wiring; - active memory now closes the last post-auth cleanup lane and moves the live task straight to `auth phase-2 surface map` plus the first trust-handoff decision. - Runtime changes: - none; upstream-equivalent closure only. - Checks: - upstream-first bounded compare against refreshed `origin/main`, local worktree/index/`HEAD` blob review, and nearby-branch history on the three bounded files ### ITER-0332 — 2026-07-30 — Strategist advanced the post-auth roadmap from residue cleanup into phase-2 trust work - Goal: - prevent the remaining auth-neighbor residue lane from turning into another generic cleanup loop; - make the next product horizon explicit so release integration feeds directly into the next user-value slice. - Result: - `ROADMAP.md`, `ACTIVE_TASKS.md`, `OPEN_QUESTIONS.md`, `TECHNICAL_STRATEGY.md`, and `PROJECT_STATUS.md` now treat the remaining `package.json` + `scripts/smoke-authenticated.sh` + `ecosystem.config.cjs` bucket as the last live auth-neighbor lane that must end with a concrete git/release outcome, not just another classification pass; - active memory now makes the post-cleanup handoff stricter: the next product slice is `auth phase-2 surface map`, and that slice must also name the first trust action that follows it instead of stopping at route taxonomy; - roadmap/product memory now prefers the smallest next anonymous-adjacent surface that improves week-first continuity or trust clarity before opening broader shells such as `/subscription` by default. - Runtime changes: - none; strategist/doc-memory only. - Checks: - docs-only consistency pass against current living docs, current dirty/diverged git state (`main` `e5eb05a`, `origin/main` `8570be3`), and the latest iteration tail ### ITER-0331 — 2026-07-30 — Event-report promotion candidate closed as already-shipped upstream state - Goal: - classify the bounded event-report/root-note residue with an upstream-first check before spending any verification gates; - remove that bucket from active cleanup if refreshed `origin/main` already carries the same ship-candidate tree. - Result: - refreshed `origin/main` `8570be3` proved byte-identical on the bounded event-report files: `scripts/lib/event-report-smoke*`, `scripts/manage-event-report-smoke-fixture.ts`, `scripts/verify-event-report-smoke.ts`, `src/features/sfm/event-report-smoke-fixture.ts`, `src/features/sfm/event-report-write-through*`, and the related `/events/[id]/edit` report-result readers; - active memory now closes the `event-report promotion candidate` as upstream-equivalent through the already-promoted runtime commits `dce8c78` and `7a2c9e5`, so it is no longer a live cleanup lane; - the remaining post-auth cleanup focus narrows to the auth-neighbor runtime-contract residue, after which planning should return directly to `auth phase-2 surface map`. - Runtime changes: - none; upstream-equivalent closure only. - Checks: - upstream-first bounded compare against refreshed `origin/main` and the nearby `release/event-report-root-note-guard` branch ### ITER-0330 — 2026-07-30 — Strategist split the post-promotion cleanup into two real residue lanes and prepared the first trust-handoff slice - Goal: - prevent the next cycle from treating all remaining local divergence after auth promotion as one undifferentiated cleanup problem; - evolve the roadmap so release integration work feeds directly into the next user-visible auth decision instead of another no-op memory pass. - Result: - `ROADMAP.md`, `ACTIVE_TASKS.md`, `PROJECT_STATUS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now distinguish two visible residue lanes from the current worktree: an `event-report promotion candidate` around root-note write-through/smoke-fixture files, and an `auth-neighbor runtime contract residue` around `package.json`, `scripts/smoke-authenticated.sh`, and `ecosystem.config.cjs`; - active memory now adds a stricter completion rule for the cleanup slice: at least one bucket must end as isolated candidate, explicit park, or upstream-equivalent closure, and if both buckets close without a ship candidate the next planner step should move straight to `auth phase-2 surface map`; - the post-cleanup auth roadmap now explicitly queues one more trust slice after `anonymous trust UX hardening`: decide the first durable handoff from anonymous UUID usage to named identity, recovery/export, or another explicit trust action. - Runtime changes: - none; strategist/doc-memory only. - Checks: - docs-only consistency pass against living docs plus current git-visible residue (`event-report` staged files and `package.json` / `scripts/smoke-authenticated.sh` / `ecosystem.config.cjs` modifications) ### ITER-0329 — 2026-07-30 — Curator closed the requested runtime-tooling bucket as already-shipped upstream state - Goal: - sync living docs to the executor-confirmed upstream-first result for the bounded `runtime tooling candidate`; - remove active-memory wording that still treated hosted-dev recovery/auth-matrix tooling as a live cleanup bucket. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, and `TECH_DEBT.md` now reflect the bounded fact: refreshed `origin/main` `8570be3` already carries the repo-owned recovery/auth-matrix tooling contract through shipped commits `0997b75`, `015a1ca`, `f7db663`, `bd080dc`, and docs sync `c22106b`; - active memory no longer offers `runtime tooling candidate` or the exact `e5eb05a` localization scope as live residue buckets, and instead pushes the next planner toward the remaining change-bearing residue rather than repeating the same upstream-equivalent tooling check; - [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now records the exact 2026-07-30 no-release-delta pass, including the bounded file set and the fact that tests/smoke/deploy stayed `not run`. - Runtime changes: - none; docs/state-sync only. - Checks: - docs-only consistency pass against the executor report, current living docs, current git state (`main` `e5eb05a`, `origin/main` `8570be3`), and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0328 — 2026-07-30 — Strategist turned post-promotion cleanup into named release candidates and phase-2 auth slices - Goal: - prevent the next cycle from orbiting around generic “dirty worktree cleanup” after the anonymous `/dashboard` promotion; - evolve the roadmap into concrete post-promotion slices that preserve product direction and git/release throughput at the same time. - Result: - `ROADMAP.md`, `ACTIVE_TASKS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now break the current residue into explicit candidate buckets instead of one broad cleanup stream: event-report/root-note residue, dashboard outcome/localization residue, and runtime tooling/recovery residue; - strategic memory now names the first two post-cleanup auth slices explicitly: `auth phase-2 surface map` and `anonymous trust UX hardening`, so the next product step is not just operational cleanup; - branch/release integration is now stated as a first-class delivery lane: each residue bucket must soon resolve to isolated candidate, explicit park with rationale, or upstream-equivalent closure. - Runtime changes: - none; strategist/doc-memory only. - Checks: - docs-only consistency pass against current living docs plus the visible local git branch/worktree state (`main` `e5eb05a`, `origin/main` docs sync `8570be3`, dirty residue buckets visible in `git status`) ### ITER-0327 — 2026-07-30 — Curator synced living docs to the promoted anonymous `/dashboard` runtime - Goal: - replace the earlier dev-green-only auth memory with the actual promoted release state after executor finished push, prod deploy, and prod smoke; - preserve the exact distinction between local dirty `e5eb05a`, merged `origin/main` `8570be3`, and the latest fully promoted runtime `507f003`. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `TECHNICAL_STRATEGY.md`, `DOMAIN_MODEL.md`, `SYSTEM_MAP.md`, `SMOKE_TESTS.md`, `DEV_RUNBOOK.md`, `PROD_RUNBOOK.md`, `DECISIONS.md`, `OPEN_QUESTIONS.md`, and `TECH_DEBT.md` now treat the phase-1 anonymous `/dashboard` slice as shipped rather than merely local/dev-green; - active memory now closes the `/anonymous-profile/bootstrap` question for phase 1 by recording the shipped remove decision, advances the live task to release-integration cleanup, and keeps the next auth-policy/help/performance/builder slices queued without reopening the released auth scope; - [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now records the full release path, including the clean release worktree, exact dev/prod smoke base URLs, pushed commits `2049727` / `507f003` / `8570be3`, and the first-prod-attempt migration-journal incident. - Runtime changes: - none in this curator pass; runtime was already promoted by the executor before docs sync. - Checks: - docs-only consistency pass against the executor promotion report, refreshed `origin/main`, current living docs, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0326 — 2026-07-30 — Strategist expanded the post-promotion course around auth phase 2, release integration, and builder promotion boundaries - Goal: - evolve strategic memory beyond the already-known dev-green auth fact instead of repeating the same release blocker; - turn the next horizon into concrete change-bearing slices: post-promotion auth policy, release integration discipline, performance evidence, and SFM builder promotion rules. - Result: - `ROADMAP.md`, `ACTIVE_TASKS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now describe the next step after auth promotion more explicitly: make a keep/remove decision on the transitional bootstrap helper, choose whether any non-dashboard surface migrates under open testing, and treat residual dirty work as named release candidates rather than permanent branch noise; - performance diagnosis is now framed as a bounded evidence pass across four buckets: hosted runtime/process shape, DB/query hotspots, frontend payload/render cost, and auth/home-specific overhead; - the future SFM builder initiative now starts with a stricter stage-0 question: what artifact becomes reviewable and promotable before any editable draft can alter trusted runtime definitions. - Runtime changes: - none; strategist/doc-memory only. - Checks: - docs-only consistency pass against current living docs and local git/worktree state ### ITER-0325 — 2026-07-30 — Curator synced living docs to the dev-green anonymous `/dashboard` reality - Goal: - align product memory with the actual executor result after the phase-1 anonymous UUID slice turned green on hosted dev; - preserve the difference between local dev-green runtime facts and the still-unfinished release/promotion path. - Result: - `PROJECT_STATUS.md`, `DECISIONS.md`, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) now reflect the corrected auth state: direct anonymous `/dashboard -> 200` is green on `https://dev.journeyup.ru`, anonymous `/subscription` and `/operator/runtime` still fail closed to `/login`, and the remaining blocker is bounded release isolation on dirty `main` `e5eb05a`, not route behavior; - living memory now records the stable phase-1 auth decision explicitly: anonymous access is `/dashboard`-only, same-origin profile switching is mandatory, `/anonymous-profile/bootstrap` is no longer the main entry contract, and signed-in auth matrix regression coverage remains required; - roadmap, active tasks, domain model, system map, runbooks, smoke docs, open questions, and tech debt were rechecked and kept because they already matched the executor facts added in this run. - Runtime changes: - none in this curator pass; code already existed locally before the memory sync. - Checks: - docs-only consistency pass against the executor report, current living docs, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0324 — 2026-07-30 — Anonymous `/dashboard` phase-1 slice reached green hosted-dev smoke - Goal: - finish phase 1 of the anonymous UUID migration so anonymous `GET /dashboard` is direct `200` on `https://dev.journeyup.ru` while `/subscription` and `/operator*` remain on the old credentials gate; - make the hosted anonymous switch smoke deterministic instead of depending on stale per-IP/day quota residue. - Result: - `src/proxy.ts` now owns the anonymous `/dashboard` cookie/bootstrap boundary: it issues the `trajectory_anonymous_profile` cookie on first-hit `/dashboard`, injects the same-request UUID header, and leaves `/login` / `/register` query cleanup intact in one proxy entrypoint; - `/dashboard` now lives behind the dedicated `(dashboard-protected)` host plus `src/lib/dashboard-identity.ts`, so anonymous access is scoped to `/dashboard` only while `/subscription` and `/operator/runtime` stay fail-closed to `/login` when logged out; - `scripts/manage-anonymous-dashboard-smoke-fixture.ts` plus the updated `scripts/smoke-anonymous-dashboard.sh` now reset stale `manual_switch` residue by resolving the actual requester bucket from a fresh same-day `issued` UUID instead of guessing from forwarded headers. - Runtime changes: - direct anonymous `/dashboard -> 200` is green on both `http://127.0.0.1:3001` and `https://dev.journeyup.ru`; - manual profile switch now stays on the public origin (`https://dev.journeyup.ru/dashboard`) and the 11th switch is rejected with `profileSwitchError=limit` without mutating the cookie; - signed-in `active / pending / banned` auth behavior on `/dashboard` and `/subscription` stayed unchanged on hosted dev. - Checks: - `pnpm test -- src/middleware.test.ts src/lib/redirect-url.test.ts src/lib/dashboard-identity.test.ts src/features/auth/anonymous-profile.test.ts src/features/dashboard/components/dashboard-shell.test.tsx scripts/lib/smoke-auth-matrix.test.ts` - `pnpm test:smoke-auth-matrix` - `pnpm typecheck` - `pnpm lint` - `pnpm build` - `DEV_PUBLIC_BASE_URL=https://dev.journeyup.ru scripts/smoke-public-dev.sh` - `DEV_PUBLIC_BASE_URL=https://dev.journeyup.ru bash scripts/smoke-anonymous-dashboard.sh` - `DEV_PUBLIC_BASE_URL=https://dev.journeyup.ru pnpm smoke:auth:matrix -- --email codex-smoke-auth-20260730@example.com --password TempSmokePass!2026 --name '[trajectory-smoke-fixture] codex dev matrix' --role owner` ### ITER-0324 — 2026-07-30 — Anonymous recovery kit made the `/dashboard` UUID entry reversible - Goal: - land the first durable anonymous trust action after the phase-1 `/dashboard` auth promotion without widening any non-dashboard route; - make UUID-backed week continuity exportable/copyable through one visible dashboard action plus inspectable server audit. - Result: - the anonymous top bar now exposes one `recovery kit` action on `/dashboard`; it returns a deterministic `anonymous_recovery_kit_v1` JSON bundle with `profileCode`, stable signed `recoveryArtifact`, `currentRestorePath = /dashboard`, and `currentRestoreMethod = manual_profile_switch`; - same-origin export now exists at `/dashboard/recovery-kit/export`, and server-owned audit for this trust action is separate from switch audit through `anonymous_recovery_audit_logs` plus enum `anonymous_recovery_audit_event` with `bundle_issued` and `bundle_exported`; - the anonymous smoke path now also checks that the visible recovery affordance remains present and that `/dashboard/recovery-kit/export` returns the deterministic attachment while `/subscription` and `/operator/runtime` stay fail-closed for anonymous users. - Runtime changes: - new schema/migration: `drizzle/0025_anonymous_recovery_kit.sql`, `anonymous_recovery_audit_logs`, and enum `anonymous_recovery_audit_event`; - new server contract: `src/features/auth/anonymous-recovery-kit.ts`, `src/features/auth/anonymous-recovery-kit-actions.ts`, and `/dashboard/recovery-kit/export`; - dashboard anonymous profile control now supports show/copy/export for the recovery bundle without adding commentary-heavy shell chrome. - Checks: - `pnpm test -- src/features/auth/anonymous-profile.test.ts src/features/auth/anonymous-recovery-kit.test.ts src/lib/dashboard-identity.test.ts src/features/dashboard/components/dashboard-shell.test.tsx src/lib/i18n.test.ts` - `pnpm test:smoke-auth-matrix` - `pnpm typecheck` - `pnpm lint` - `pnpm build` - `pnpm db:migrate` - live dev schema verification for enum `anonymous_recovery_audit_event` and table `anonymous_recovery_audit_logs` - `DEV_PUBLIC_BASE_URL=https://dev.journeyup.ru scripts/smoke-public-dev.sh` - `DEV_PUBLIC_BASE_URL=https://dev.journeyup.ru bash scripts/smoke-anonymous-dashboard.sh` - `DEV_PUBLIC_BASE_URL=https://dev.journeyup.ru pnpm smoke:auth:matrix -- --email codex-smoke-auth-recovery-20260730@example.com --password TempSmokePass!2026 --name '[trajectory-smoke-fixture] codex dev matrix recovery' --role owner` ### ITER-0323 — 2026-07-30 — Owner Input Distributor archived the full SFM constructor sketch verbatim - Goal: - archive the current `docs/OWNER_INPUT.md` entry without losing any detail, including the full React Flow-based constructor sketch and code blocks; - distribute that owner direction into living product/technical memory as a phased future builder contract instead of a short summary. - Result: - [archive/OWNER_INPUT_HISTORY.md](/root/apps/trajectory-dev/archive/OWNER_INPUT_HISTORY.md) now contains the full verbatim owner input from `docs/OWNER_INPUT.md`, with processing date and the complete living-doc distribution list; - `docs/OWNER_INPUT.md` is cleared back to an empty file after archival; - living docs now make the builder direction more concrete: the future SFM authoring slice is phased through machine JSON, typed ports, validation, local-first drafts, import/export, and promotion rules before any editable runtime surface is treated as trustworthy. - Runtime changes: - none; docs/control-plane only. - Checks: - docs-only consistency pass and diff inspection ### ITER-0322 — 2026-07-30 — Strategist opened the next SFM authoring horizon from the owner constructor sketch - Goal: - distribute the new owner-provided SFM constructor direction into living strategy instead of leaving it only inside `docs/OWNER_INPUT.md`; - connect that future authoring work to the existing read-only `/operator/sfms` builder projection so the roadmap does not pretend the builder starts from zero. - Result: - `ROADMAP.md`, `ACTIVE_TASKS.md`, `OPEN_QUESTIONS.md`, `TECHNICAL_STRATEGY.md`, `DOMAIN_MODEL.md`, `SYSTEM_MAP.md`, and `PROJECT_STATUS.md` now explicitly describe the new authoring horizon: current code already has an inspectable derived builder layer, while the next bounded slice must define editable JSON/validation/promotion contracts before any mutable visual canvas ships; - active memory keeps the auth recovery slice as the immediate priority, then the performance/help decisions, and only then the first change-bearing SFM builder contract slice; - git/release direction remains unchanged for this cycle: promoted runtime stays `dce8c78`, the local anonymous UUID slice is still the only live release candidate, and no commit/push/deploy/smoke facts changed here. - Runtime changes: - none; strategist/doc-memory only. - Checks: - docs-only consistency pass against current living docs, current operator builder code (`/operator/sfms`, `src/features/sfm/builder`), and the active local anonymous-slice status ### ITER-0321 — 2026-07-30 — Curator synced the remaining anonymous dashboard-entry blockers into living memory - Goal: - align living docs with the latest executor facts on the still-red anonymous UUID auth slice instead of leaving memory at the earlier two-blocker summary; - preserve the difference between the local candidate contract, the failed acceptance gate, and the stateful hosted-dev smoke residue. - Result: - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DOMAIN_MODEL.md`, and `TECH_DEBT.md` now record that the local candidate still misses the direct-entry acceptance contract because cookie-less `/dashboard` first hits still redirect to `/anonymous-profile/bootstrap?returnTo=/dashboard` before reaching `200`; - `DEV_RUNBOOK.md` and `docs/SMOKE_TESTS.md` now also record that the manual-switch limit check is stateful on hosted dev: if `anonymous_profile_switch_logs` already contains `10` `manual_switch` rows for the same IP/current UTC day, a fresh smoke run can hit `profileSwitchError=limit` immediately and must report that residue explicitly rather than calling the switch path green; - [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) keeps the fuller 2026-07-30 execution history, while promoted runtime state stays unchanged at `dce8c78` and no commit/push/deploy/prod-smoke facts were added. - Runtime changes: - none in this curator pass; code already existed locally before the memory sync. - Checks: - docs-only consistency pass against the latest executor report, current local code paths (`dashboard-identity`, bootstrap route, profile-switch route), and existing anonymous-slice memory ### ITER-0320 — 2026-07-30 — Owner-input distribution for the minimal-help UI constraint - Goal: - fully archive the new owner note about UI minimalism and on-demand comments without losing the exact wording; - distribute that constraint into doctrine and living execution memory so it survives beyond `OWNER_INPUT.md`. - Result: - the owner note about keeping comments behind a top-right `i` affordance is now appended verbatim to [archive/OWNER_INPUT_HISTORY.md](/root/apps/trajectory-dev/archive/OWNER_INPUT_HISTORY.md) with the processing date and exact living-doc distribution list; - `docs/OWNER_INPUT.md` is cleared again after reliable archival; - living docs now make the UI rule more explicit: minimal home stays commentary-light by default, the current desktop help pattern is the top-right `i`, and the future bounded slice must still define touch/mobile fallback plus which comments should disappear entirely. - Runtime changes: - none; docs/memory-gardening only. - Checks: - docs-only consistency pass and final diff inspection ### ITER-0319 — 2026-07-30 — Strategist extended roadmap with the minimal-help UI contract and post-auth product slices - Goal: - distribute the new owner signal about UI minimalism and hover-only explanations into strategic memory instead of leaving it only in `OWNER_INPUT.md`; - keep the roadmap change-bearing by tying that UX direction to the active auth pivot and the queued phone/performance branch. - Result: - `ROADMAP.md`, `ACTIVE_TASKS.md`, `OPEN_QUESTIONS.md`, and `TECHNICAL_STRATEGY.md` now explicitly treat minimal explanatory UI as a product constraint: trust/help copy should stay behind one top-right help affordance and not re-expand the home shell; - active memory now names one new bounded post-auth slice: define the canonical minimal-help interaction across desktop hover and touch/mobile fallback before broader shell evolution; - git/release direction stays unchanged: finish the red hosted-dev anonymous auth slice first, then run the performance diagnosis, then carry the UI help-pattern contract into whichever shell path survives. - Runtime changes: - none; strategist/doc-memory only. - Checks: - docs-only consistency pass against current living memory and dirty-worktree runtime facts ### ITER-0318 — 2026-07-30 — Curator synced docs to the real local anonymous-dashboard slice and its red dev-smoke state - Goal: - bring living memory to the actual post-executor state instead of leaving it at owner-direction-only planning; - distinguish the promoted `dce8c78` runtime from the unfinished local anonymous UUID auth slice. - Result: - living docs now explicitly separate three states: promoted runtime `dce8c78`, local dirty-worktree anonymous UUID implementation, and the red hosted-dev smoke blockers that stopped commit/push/deploy; - `PROJECT_STATUS.md`, `ACTIVE_TASKS.md`, `ROADMAP.md`, `SYSTEM_MAP.md`, `DOMAIN_MODEL.md`, `TECH_DEBT.md`, and the runbook/testing/smoke docs now record the actual anonymous slice facts: UUID cookie issuance, `/dashboard` identity resolver, top-bar UUID switch UI, audit tables/logging, `10` switches-per-IP-per-UTC-day rule, and the new repo-owned `scripts/smoke-anonymous-dashboard.sh` path; - active memory now points the next planner/executor at the real bounded fix: keep anonymous entry dashboard-only and correct the public-origin redirect bug before any release isolation or promotion resumes. - Runtime changes: - none in this curator pass; code already existed locally before docs sync. - Checks: - docs-only consistency pass against the executor result, current code, working-tree diff, and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md) ### ITER-0317 — 2026-07-30 — Owner input redistributed into auth-pivot and performance-branch memory - Goal: - fully archive the 2026-07-30 owner input batch verbatim and clear `docs/OWNER_INPUT.md`; - distribute the new owner direction into doctrine and living technical memory without pretending the runtime already changed. - Result: - both owner notes are now appended to [archive/OWNER_INPUT_HISTORY.md](/root/apps/trajectory-dev/archive/OWNER_INPUT_HISTORY.md) with verbatim text, processing date, and the exact living-doc distribution list; - `docs/OWNER_INPUT.md` is now intentionally empty after reliable archival; - living docs now record two new strategic facts: - anonymous UUID open-testing auth with top-bar profile switching is the next owner-directed auth branch and explicitly conflicts with the current credentials/register baseline; - a possible frontend/backend split is now a documented performance/mobile branch, but not an approved rewrite order without a bounded diagnosis. - Runtime changes: - none; docs/memory-gardening only. - Checks: - docs-only consistency pass and final diff inspection - no code tests or smoke runs, because no product code changed ### ITER-0316 — 2026-07-08 — Strategist re-compacted active memory around the promoted `dce8c78` baseline - Goal: - keep active memory compact around the latest fully promoted runtime and the durable `/dashboard` / no-integration / SFM save contracts; - move the older active tail into the archive without reopening closed `no release delta` scopes or turning roadmap into a deploy log. - Result: - `ACTIVE_TASKS.md`, `ROADMAP.md`, `OPEN_QUESTIONS.md`, `TECH_DEBT.md`, and `PROJECT_STATUS.md` now keep the same release/runtime truth in shorter form: latest promoted runtime stays `dce8c78`, no live bounded slice is open, and only the compact operational contracts remain in active memory; - `ITER-0314` and `ITER-0315` moved to [archive/ITERATION_ARCHIVE.md](/root/apps/trajectory-dev/archive/ITERATION_ARCHIVE.md), leaving one fresh strategist handoff in the active tail; - release truth did not change: `dce8c78` remains the latest fully promoted runtime, with prod smoke evidence still delegated to [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md). - Runtime changes: - none; docs/memory-gardening only. - Checks: - docs-only consistency pass against living docs, [archive/ITERATION_ARCHIVE.md](/root/apps/trajectory-dev/archive/ITERATION_ARCHIVE.md), and [archive/TASK_HISTORY.md](/root/apps/trajectory-dev/archive/TASK_HISTORY.md)
Сохранить