Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
160 changes: 160 additions & 0 deletions evidence/design/native-acceptance-2026-09-01/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,160 @@
# Native macOS owner-review evidence — 2026-09-01

These screenshots were regenerated on 2026-09-02 as deterministic offscreen
AppKit/SwiftUI renders from the current native migration working tree. They do
not activate CodeVetter or take focus from the operator's desktop.

The set covers the primary product workspaces plus Testing's substantial
execution modes. It is the visual review packet for issue #201 task 11; owner
acceptance remains a distinct decision and is not inferred from automated
rendering.

[Open the filterable exact-pixel gallery](gallery.html). Every card links to
the original render; the gallery contains no external assets or network calls.

## Primary workspaces

- `usage.png` — local agent usage, aligned separate Devin window, chart, and
adapter health.
- `repo-unpack.png` — retained snapshot ledger and bounded source map.
- `repository-query-desk.png` — canonical structural/history search with
freshness, trust, source identity, and explicit read-only bounds.
- `repository-query-evidence-workbench.png` — node explanation, bounded impact,
path origin, directed traversal, relationship counts, and trace controls.
- `review-findings.png` — source-qualified finding, acceptance coverage, and
limitations.
- `review-cross-review.png` and `review-cross-review-light.png` — independent
Claude then Codex provenance, deterministic source-qualified reconciliation,
disagreement classes, and the explicit boundary between review coverage and
executable proof in both appearances.
- `testing.png` — large direct-preview receipt with failed and passing journeys.
- `performance.png` — exact workload selection beside a digest-verified stored run.
- `runs.png` — 100-receipt ledger with a 100-response evidence index.
- `capabilities-mcp.png` — deterministic Rust-registry glossary with the
repository-scoped read-only MCP capability selected and explicit
UI/CLI/agent authority, including external-collector availability.
- `settings.png` — native notification settings and explicit authority boundary.
- `settings-rubrics.png` and `settings-rubrics-light.png` — Rust-owned rubric
packs, usage evidence, deterministic selection controls, and custom-pack
authoring in both appearances.
- `settings-history-roots.png` and `settings-history-roots-light.png` — bounded
Codex history recovery beside guarded archive retention in both appearances.
- `settings-memories.png` and `settings-memories-light.png` — one premium
source-first memory reader with opaque identity, bounded content, local
source/content search, copy, and redacted Git-diff handoff in both appearances.
- `settings-agent-island.png` and `settings-agent-island-light.png` — the exact
opt-in presentation and speech preferences, a non-activating status preview,
and an explicit configuration-live/runtime-pending authority boundary.
- `settings-ops.png` and `settings-ops-light.png` — read-only local
operational aggregates, configuration-presence signals, fixed time windows,
and an explicit no-credential/no-network authority boundary.

## Supporting verification workspaces

- `review-proof-map.png` — deterministic manifest, review readiness, and graph
context explicitly separated from execution proof.
- `review-intent.png` — Rust-owned intent chronology, recorded-QA signals,
explicit evidence conflict, and the human-only closure boundary.
- `qa-journey-workspace.png` — saved workflow, discovered repository targets,
explicit route/goal selection, and preview-consent boundary.
- `testing-warm.png` — changed-proof evidence and retained artifacts.
- `testing-differential.png` — paired behavior regression with no manufactured
pass evidence.
- `testing-scenario.png` — hash-bound candidate validation and explicit file
acceptance.
- `testing-watcher.png` — app-lifetime PR watcher schedule, retained receipts,
and no-hidden-daemon boundary.

## Audit

The packet was inspected at its native point sizes: 980 at the supported
minimum for dense workspaces, 1,100–1,180 for modal verification desks, and
1,280 for the full shell. Primary action hierarchy, state labels, evidence
identity, local path truncation, true-black plane separation, keyboard-oriented
navigation, and limitation visibility are intact. No unresolved P0 or P1 visual
finding remains in the rendered states.

The 2026-09-02 pass corrected a cross-surface depth defect without weakening
the owner's black-canvas direction. Canvas and chrome remain true black;
working surfaces now rise only 1–4% so nested evidence remains legible without
turning charcoal. Review Proof map and Intent also own an opaque canvas, which
removes misleading bright outlines from standalone captures. Both repository
query states are now produced explicitly by the test harness rather than
retaining one manually staged state.

The same current-tree harness now records light-appearance counterparts for
the primary Review findings, Testing receipt, Performance evidence lane, and
Runs ledger. They preserve the same information hierarchy on a warm system
canvas with white evidence planes, amber intentional actions, and distinct
success/failure state colors. The visual inspection exposed fixed bright
accent colors that were too weak for small text on light surfaces. Action-fill
amber now remains bright while amber evidence foregrounds and semantic
success, warning, and failure colors resolve to darker light-mode values. A
Swift regression requires at least 4.5:1 contrast against the true-black
canvas, warm light canvas, and white evidence planes. These are
appearance-parity improvements, not a change to the owner's dark-first visual
direction.

The history-recovery capture exposed an appearance-dependent system-button
label failure in the combined Usage settings layout. The cleanup preview now
uses the workbench's deterministic primary-button style with a text label; both
dark and light captures retain the complete action name and clear hierarchy.

The Rubrics capture exposed the same system-button failure on a lower pack card
in light appearance. Pack selection now uses that deterministic primary-button
style too; all active and available pack labels remain complete in both
appearances.

The final gallery audit also caught a selected-pack hierarchy defect: the
current pack was presented as a disabled amber action, making its label look
washed out in both appearances. The current pack now uses a high-contrast,
non-interactive green `Selected` receipt with an explicit accessibility label;
only available packs retain the amber `Use pack` action.

The memory-reader capture also removed unavailable-location clutter from the
working catalog. Rust still reports how many known locations were checked, but
the source rail contains only existing files; absent probes cannot overwhelm
the selected private document. Absolute paths never enter the receipt.

The Agent Island capture exposed a light-appearance inheritance defect in the
always-black status capsule. Its primary status text now owns an explicit white
foreground while the count retains product amber, so the same compact preview
is legible in both appearances. The preview never launches the helper or
contains live session content.

The Ops capture preserves the same source-first evidence hierarchy for local
operational status. Configuration presence and bounded aggregate rows are
visible in both appearances; credentials, webhook URLs, provider refreshes,
webhook sends, configuration writes, and agent/MCP authority remain absent.

An agent pixel audit of all 35 states found no P0 or P1 visual or interaction
defect. It did find one P2 orientation issue at the supported 980-point minimum:
compact navigation hid every workspace label. The compact rail now keeps the
selected workspace label visible while retaining quiet icon-only destinations;
the Testing and Performance dark/light rerenders fit without clipping or content
movement. Owner acceptance remains a separate gate.

The prior complete isolated hosted qualification passed 81 Swift package tests in
26.294 seconds, compiled Debug and coverage-free Release applications, and
passed all nine XCUITests in 113.009 seconds. During the earlier visual rerun,
the cancellation fixture reproduced a shell that could defer
SIGTERM while blocked on stdin. The worker now closes stdin, allows a bounded
200 ms graceful exit, and force-terminates only its owned read-only process if
needed; the full lane passed and no fixture worker remained. The interaction
lane ran on GitHub's isolated hosted desktop, not the operator's active Mac.
Its exact results are recorded in the
[hosted qualification receipt](../../verification/native-hosted-qualification-2026-09-02.md).

`owner-review-manifest.json` records the exact pixel dimensions and SHA-256 of
all 35 current-tree renders so the packet can be reviewed without confusing an
older state for the accepted candidate.

The hosted runner also produced a complete 33-state packet, but its PNG bytes
are not identical to this committed local packet because the rendering
environments differ. Each packet is internally manifest-bound; neither is
treated as a cross-host pixel oracle. Owner acceptance remains separate.

The shared Fleet design validator currently requires 390, 768, and 1440
viewport receipts for every surface. CodeVetter's native window has a 980-point
minimum, so this packet records the real supported native widths rather than
misrepresenting phone-sized renders as product states.
Original file line number Diff line number Diff line change
@@ -0,0 +1,184 @@
{
"schema_version": "codevetter.native-owner-review/v1",
"rendered_at": "2026-09-02",
"surface": "native macOS Evidence Workbench",
"scale": "deterministic offscreen pixels",
"owner_acceptance": "pending",
"entries": [
{
"path": "usage.png",
"pixels": "2560x1600",
"sha256": "f603f10c13fc4324ccc3ee477de5713c263a154f861e9044529678da12c1bd69"
},
{
"path": "repo-unpack.png",
"pixels": "2560x1600",
"sha256": "d7f6f28b89aade7a0845ad921a2e417399248320a60db7b0737813e579804b5f"
},
{
"path": "repository-query-desk.png",
"pixels": "3040x1960",
"sha256": "4b7dbedef4e3c879d69cb1a36f9167dc68430e1a6b92115c3201a4e019df8618"
},
{
"path": "repository-query-evidence-workbench.png",
"pixels": "3040x1960",
"sha256": "b8e62af3eb87633692407801c4b5fec81767fd8dd15f08951b8a08903bf6293e"
},
{
"path": "review-findings.png",
"pixels": "2560x1600",
"sha256": "e183b009b6b068d2fc125cf7890d4b861f66ce553551431c1c8a460d84592da4"
},
{
"path": "review-findings-light.png",
"pixels": "2560x1600",
"sha256": "2f20a5029021d89dec5d266178f7c8f8f5dda8ee6d425ee73c221bd411c41182"
},
{
"path": "review-cross-review.png",
"pixels": "2560x1600",
"sha256": "ef50d2c371be35feaf3c33945e2e4e80c046bec5510890557234ec10c748ddad"
},
{
"path": "review-cross-review-light.png",
"pixels": "2560x1600",
"sha256": "0af64672caefd92e52611dbeb29e1d28ceff58a4a6f05bd05230c8e631c8ddd3"
},
{
"path": "review-proof-map.png",
"pixels": "1520x1600",
"sha256": "226e4e236fcae302f26b2cfb3fe702f958fdd9f3dd47a39cdb4184d34a9fbf95"
},
{
"path": "review-intent.png",
"pixels": "1520x1600",
"sha256": "8feac4aa85a0e6fc9f1c7968525f9fdc2f7702d121407292335adeede4b68b8c"
},
{
"path": "testing.png",
"pixels": "1960x1280",
"sha256": "f64f5c7b7f706a26d30fab8554b208c7a4dc92c1a6914fdfc77039c6380be4d4"
},
{
"path": "testing-light.png",
"pixels": "1960x1280",
"sha256": "808d820250a37cf25ff8f68859b519be32a8dcd0db11a98a0a5238793f35bec3"
},
{
"path": "testing-warm.png",
"pixels": "2200x1440",
"sha256": "4d60fc7dc3513df8b1a2f194553553d74af7eeb3c4d59f0ba133a412903b6013"
},
{
"path": "testing-differential.png",
"pixels": "2200x1440",
"sha256": "fbaf9a510170f8bb2a3808556d542ecc5ce18987699ba290ec7d415fe6ad776f"
},
{
"path": "testing-scenario.png",
"pixels": "2360x1520",
"sha256": "478038d6ac8fcefd3b1a11db166c47b0da4b89a13ec27f9fd6cccf58df60a7b2"
},
{
"path": "testing-watcher.png",
"pixels": "2360x1520",
"sha256": "d0089f3d40a1faea6435a9532ff0ec24ba225fa786908524051a97bb1c3378ff"
},
{
"path": "qa-journey-workspace.png",
"pixels": "2360x1520",
"sha256": "1d9c803ca87c3816e0af010fcb3cecb1a7fb96c1dbf7779948d25f249e9ebc8e"
},
{
"path": "performance.png",
"pixels": "1960x1280",
"sha256": "f27f619c7d8373f83652d62a9d5d68f67ac492a9480e155ed30c3cf4466efe85"
},
{
"path": "performance-light.png",
"pixels": "1960x1280",
"sha256": "6223808dc786c31a379bde7ea326e63796474b1c050631ea0165d0cae4927971"
},
{
"path": "runs.png",
"pixels": "2560x1600",
"sha256": "4ac3a0ab68a8724073e8a8d5117a667be7d570bc3abb5935c2c7b917ecac81ec"
},
{
"path": "runs-light.png",
"pixels": "2560x1600",
"sha256": "eca6f837581274cdda73dbcde9ed8424809c81c7ef93367accdb74905527be43"
},
{
"path": "capabilities-mcp.png",
"pixels": "2560x1600",
"sha256": "000a1536430b4baf36ffe5c77dbe2e73ca82bb6a8c4bcaa9f4b65f5b51cc037f"
},
{
"path": "settings.png",
"pixels": "2560x1600",
"sha256": "7d78ff7489947473b751f643fcde8f2eee88196a0d32a67539a1ee00fa6713c2"
},
{
"path": "settings-rubrics.png",
"pixels": "2560x1600",
"sha256": "2c1498b412f50ee2976822c96f6d1d5a5552fb6c976d2705d90e2000e8ae6dcf"
},
{
"path": "settings-rubrics-light.png",
"pixels": "2560x1600",
"sha256": "55f67ac4ef5a9f3721ec781652cbcfc85295b72a07cd208dacd2a02499277691"
},
{
"path": "settings-history-roots.png",
"pixels": "2560x1600",
"sha256": "48a02f9745fec4ca31ea62cd34df137c94deb93b7f5e14f62a41113b21102619"
},
{
"path": "settings-history-roots-light.png",
"pixels": "2560x1600",
"sha256": "5fa9db9b1b44551ab6a77159ba79b42b77e277a9aecf86d62834259913ded610"
},
{
"path": "settings-memories.png",
"pixels": "2560x1600",
"sha256": "7c800c08c1185e69febc350fa958091eb6e44d1ab6539aa8cab3174cdcbd8da5"
},
{
"path": "settings-memories-light.png",
"pixels": "2560x1600",
"sha256": "37883294c28f863159726af6d0cfc3f453fab8e9f90caecf65963facf34f9f42"
},
{
"path": "settings-agent-island.png",
"pixels": "2560x1600",
"sha256": "a6bd6714cec4668d1082f70b74afe7fa0448cff6aa4b121cbf9fa2043289dca6"
},
{
"path": "settings-agent-island-light.png",
"pixels": "2560x1600",
"sha256": "2b3ded2c3088fc1cb76e0d9f19db2d84fa3061daadb50368a21a7687950c508b"
},
{
"path": "settings-ops.png",
"pixels": "2560x1600",
"sha256": "c8b89c953425a58e27acfee69cb055550754b4c045fa63b25b8681d4abf65bd5"
},
{
"path": "settings-ops-light.png",
"pixels": "2560x1600",
"sha256": "0e36c9fa209eec2801a704c1d34e086426ca3d838f8a7f5e38e257a1570af796"
},
{
"path": "onboarding-purpose.png",
"pixels": "1520x1200",
"sha256": "f8a50752aa38edfaa9da4ed0d9ac9865c747d63c3d9ffd947a18138b105cbbb7"
},
{
"path": "onboarding-agent.png",
"pixels": "1520x1200",
"sha256": "c1a7c840ca52a87845efb354d1ded5ebe48dd57b32016d21facc36ce2e21baec"
}
]
}
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
10 changes: 10 additions & 0 deletions evidence/design/native-directions/appkit-workbench.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
# Direction: AppKit-led Evidence Workbench

AppKit owns the application lifecycle, multi-window behavior, menus, toolbars,
split views, source outlines, dense tables, keyboard routing, and focus. SwiftUI
composes bounded forms, evidence panels, settings, inspectors, and transitions.
Rust remains the capability, execution, persistence, and receipt authority.

Selected because CodeVetter is a dense professional Mac instrument and because
this direction preserves access to the full native desktop surface without
moving verification policy into Swift.
10 changes: 10 additions & 0 deletions evidence/design/native-directions/proof-ledger.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
# Direction: Proof Ledger

The proof ledger presents identity, correctness, performance, and verdict as a
numbered evidence chain. It communicates CodeVetter's execution-first model
well, but a persistent left icon rail and stacked ledger make the setup state
feel more navigational and less decisive than the selected chamber.

Its evidence-chain model remains in the production proof inspector.

Rendered evidence: `artifacts/design/native-probes/ledger.png`.
11 changes: 11 additions & 0 deletions evidence/design/native-directions/source-desk.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
# Direction: Source Desk

The source desk is a dense post-execution workspace: changed paths, source or
receipt detail, selected finding, executable evidence, and limitations share a
single technical plane. It is stronger after evidence exists than as an empty
setup experience.

Its composition becomes the production receipt state after the chamber emits a
versioned Rust result.

Rendered evidence: `artifacts/design/native-probes/source-desk.png`.
6 changes: 6 additions & 0 deletions evidence/design/native-directions/swiftui-cockpit.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
# Direction: SwiftUI-only cockpit

A SwiftUI lifecycle and navigation split view would reduce initial shell code
and accelerate composition. It was not selected because CodeVetter's mature
product needs stronger control over dense outlines, tables, menus, focus,
windowing, source inspection, and long-lived workbench state.
Loading