Files
2026-07-30 02:14:43 +02:00

2.2 KiB

WP-PA-001 Evidence

Scope delivered

  • standalone generic repository root;
  • relational schema and migration;
  • append-only project event log;
  • projects, actors, formal roles, work packages, results, reviews, decisions, escalations, links, gates, baselines, and cursor synchronization;
  • authorization, identity abstraction, idempotency, atomic claims, and concurrency-safe writes;
  • MCP Streamable HTTP request/response interface;
  • unit, governance, concurrency, and HTTP integration tests;
  • deployment example, architecture, tool contract, threat model, production delta, and independent review brief.

Verification commands

PYTHONPATH=src python -m compileall -q src tests
PYTHONPATH=src python -m unittest discover -v
python -m unittest discover -v

The third command is run after editable installation and proves the packaged import path. Record the final observed counts and hashes in VERIFICATION.txt; generated database files are excluded.

Acceptance mapping

Requested evidence Location
Append-only event log migrations/001_initial.sql, trigger tests
Project/actor/role model migration, models.py, service tests
Work/result/review lifecycle service.py, full workflow test
Decision and gate separation authorization tests
Reviewer independence request/submit checks and test
Idempotency table, canonical hash logic, replay/mismatch test
Concurrency safety BEGIN IMMEDIATE, concurrent claim test
Cursor synchronization sync_since, pagination test
Commit/artifact/baseline links service and MCP tools
Authentication abstraction AuthProvider, static adapter
MCP interface mcp.py, HTTP integration tests
Deployment and production differences deploy/, production profile
Threat model docs/THREAT_MODEL.md
Independent review input CLAUDE_REVIEW_BRIEF.md

Explicit exclusions

  • no external repository creation, commit, or push;
  • no production deployment or ChatGPT/Claude activation;
  • no PostgreSQL adapter, OIDC provider, SSE push channel, or chat wake-up;
  • no Sandbox/Epimonos product domain logic;
  • no copy of the Sandbox SG handoff delta;
  • no modification of the canonical Sandbox v0.1.0 ZIP.