Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@ All notable changes are documented here. RealDone follows semantic versioning wh

### Added

- Fresh Phase L qualification at fingerprint `3663ff0c…` across TodoMVC, Actual Budget, Conduit SQLite/PostgreSQL 17/Supabase Data API and Pocket Ledger, including PostgreSQL CRUD cleanup, authenticated Level 7 visual suppression and a new Codex RD901 regression/repair cycle.
- Pre-capture visual privacy for automatic scans and contract/role verification: known-sensitive inputs, `secretEnv` and auth-state contexts now suppress screenshot/video binaries while safe controls retain them, with additive value-free report metadata.
- Fresh Phase K qualification at fingerprint `4625a9cc…` across TodoMVC, Actual Budget, Conduit SQLite/PostgreSQL 17/Supabase Data API and Pocket Ledger, including PostgreSQL CRUD cleanup, 6/6 visible Pocket Ledger actions, Level 7 roles and a new Codex MCP RD901 regression/repair cycle.
- Fail-closed per-trace retention for automatic scans and contract/MCP verification: bounded ZIP inspection now checks generated sensitive fields, contract `secretEnv`, opaque Playwright auth-state cookies/tokens and generic credential patterns before report linkage, with additive value-free suppression metadata for deleted unsafe or unscannable traces.
Expand All @@ -19,6 +20,7 @@ All notable changes are documented here. RealDone follows semantic versioning wh

### Fixed

- MCP and CLI managed scans now use a dedicated configurable startup-health timeout (30 seconds by default), emit bounded process-state/PID/restart diagnostics, and exercise delayed startup plus dynamic-port cleanup instead of relying on a fixed CI port and a 10-second shared render budget.
- Playwright traces containing known sensitive field values, generic credential/token material, invalid ZIP data, or bounded-inspection limit failures are removed immediately instead of surviving until the aggregate release artifact gate.
- Report timelines and environment summaries now render arrows and separators as UTF-8 instead of mojibake.

Expand Down
2 changes: 2 additions & 0 deletions docs/ADVANCED.md
Original file line number Diff line number Diff line change
Expand Up @@ -40,6 +40,8 @@ realdone scan --project ../my-app --manage-runtime --runtime-mode production
realdone scan --project ../my-app --manage-runtime --runtime-mode docker
```

Managed startup waits up to 30 seconds by default but proceeds immediately when the health check passes. Use `--runtime-startup-timeout <milliseconds>` for a legitimately slower local/staging app; `--environment-timeout` remains the separate browser bootstrap/render budget.

Before action discovery, RealDone checks the main HTML document, same-origin scripts/stylesheets, content types, bootstrap errors, configured health endpoint, auth-state readability, and render readiness. It repeats the static-root/bootstrap check for discovered routes. A JavaScript or CSS URL receiving an HTML SPA fallback produces `ENVIRONMENT_INVALID` and RD1001/RD1002 instead of an application `BROKEN` finding. The report stores this evidence in `environment.json`; `--accept-environment-risk` is the explicit override when the operator has independently confirmed the harness is representative.

Automatic discovery prepares hover-revealed and scroll/lazy content, executes native checkbox/select and context-menu actions, and records popup/download evidence. Same-origin iframe execution is explicit:
Expand Down
2 changes: 2 additions & 0 deletions docs/COMPATIBILITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,8 @@ Phase J fingerprint `0b39d542…` repeated the matrix in hosted main run [`30200

Phase K fingerprint `4625a9cc…` repeated the matrix in hosted main run [`30203185815`](https://github.com/datzle123/RealDone/actions/runs/30203185815). All 15 gates passed after one Windows Node 22 managed-runtime startup retry, GitHub signed both aggregate artifacts for merge `ca9e9db`, and `gh attestation verify` accepted their provenance.

The Phase L candidate adds optional `ManagedScanRequest.runtimeStartupTimeoutMs`, CLI `--runtime-startup-timeout`, and MCP `scan.runtimeStartupTimeoutMs` controls. Existing API callers remain source-compatible because the request field is optional; CLI/MCP defaults change only the managed-runtime health wait and do not alter report schema or already-running URL scans. Cross-platform hosted qualification is pending.

| Surface | Release gate |
| --- | --- |
| Node.js | 20 and 22 |
Expand Down
2 changes: 1 addition & 1 deletion docs/MCP.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ Coding agent -> RealDone MCP -> RealDone core

MCP browser-action tools are disabled unless the user starts that project session with `--allow-project-actions` after confirming disposable local/staging data. This one-time session consent covers the possibility of opaque app handlers, but never enables classified destructive actions, classified external effects, production providers, or paths outside the configured project root. Replay discards any historical side-effect grants stored in a reproduction, and MCP exposes no way for an agent to re-enable them. The agent's message is operational output, not verification evidence.

When `scan` is called without a URL, MCP discovers, starts, health-checks, scans, and stops the configured project. With an explicit URL, the caller remains responsible for that runtime.
When `scan` is called without a URL, MCP discovers, starts, health-checks, scans, and stops the configured project. Managed startup waits up to 30 seconds by default and accepts a bounded `runtimeStartupTimeoutMs` override; it does not consume extra time after the health check passes. With an explicit URL, the caller remains responsible for that runtime.

`scan` also accepts project-relative `sqlite`, `databaseConfigs`, `providerConfigs`, and `sourceSnapshotLimit` inputs. Database inputs attach read-only, value-free source snapshots and diffs. Provider configs may link an explicitly matched action/request to bounded read-only Level 6 confirmation. `replay` accepts the same project-relative `providerConfigs`; a provider-backed reproduction stays `REPLAY_UNCERTAIN` unless the fresh action causally confirms every recorded provider name/kind/resource/operation/state requirement. Neither path exposes source rows, provider references, or credentials to the agent, and project-root confinement applies to replay configs too.

Expand Down
2 changes: 2 additions & 0 deletions docs/PERFORMANCE.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@

Quick scan remains intentionally light: one Chromium worker, no provider/database adapter, no extra role, and no trace or video unless explicitly requested.

Managed project startup has a separate 30-second health-check ceiling for CLI/MCP and returns as soon as the app is ready. This protects slower package-manager startup without spending 30 seconds on every scan or weakening the independent browser render, action, and global budgets.

`--deep` opens one additional browser context per executed mutation to confirm persistence scope. Keep it opt-in for important flows or scheduled audits rather than paying that cost in every quick scan.

`--trace` records Playwright snapshots/screenshots and `--video` records the browser viewport. Both add I/O, storage, and post-processing work; use them for diagnosis or release evidence rather than routine scans. Every newly closed trace receives one bounded ZIP secret inspection before it can be linked; unsafe, invalid, oversized, or over-expanded traces are deleted fail-closed. Screenshot/video recording is not started for known-sensitive or authenticated contexts because binary inspection cannot prove rendered content safe. `--trace-on-failure` then deletes safe passing traces, retaining portable ZIP evidence only for findings or failed contract verification.
Expand Down
2 changes: 2 additions & 0 deletions docs/PRODUCT_SPECIFICATION.md
Original file line number Diff line number Diff line change
Expand Up @@ -365,6 +365,8 @@ Runtime Manager chịu trách nhiệm:
* hỗ trợ production build;
* hỗ trợ Docker khi được cấu hình.

Managed runtime startup phải có health-check timeout hữu hạn, tách biệt với page-render/action timeout và có thể cấu hình từ CLI/MCP. Giá trị mặc định phải đủ cho package-manager startup trên Windows, macOS và Linux nhưng không được thêm độ trễ khi health check đã pass; timeout phải dừng process tree và trả diagnostics đã redaction gồm state, PID/restart count và log gần nhất.

---

# 7. Environment Health Gate
Expand Down
4 changes: 3 additions & 1 deletion docs/PRODUCT_STATUS.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,14 +16,16 @@ Phase J is complete on `main`: scan and contract/MCP traces are inspected immedi

Phase K is complete on `main` at fingerprint `4625a9cc…`: automatic standalone/trace screenshots and browser videos are suppressed before capture whenever the action has a known sensitive field or the context uses auth state; contract trace screenshots/videos are suppressed for `secretEnv` or authenticated contexts. Safe unauthenticated controls still retain visual evidence, and reports use additive value-free `visualSuppressions` metadata. Fresh TodoMVC, Actual Budget, Conduit SQLite/PostgreSQL + Supabase and Pocket Ledger/Codex runs are bound to this fingerprint. Local check (142 pass, 2 service-dependent skips), audit, full Chromium smoke, pack and installed-tarball smoke passed. PR run `30202575079` and main run `30203185815` passed 15/15 across Linux, macOS and Windows; the Windows Node 22 managed-runtime smoke needed one retry in each run, and the main aggregate was signed for merge `ca9e9db`.

Phase L is the current unreleased runtime-readiness candidate at fingerprint `3663ff0c…`: CLI/MCP managed startup now has a dedicated bounded timeout (30 seconds by default) instead of sharing the 10-second page-render budget, accepts an explicit override, and reports redacted process state, PID and restart counts on failure. The MCP browser smoke uses a dynamic port and an intentionally delayed app: a 1-second broken case times out and cleans up, while the default control starts, scans and stops successfully. Local check (144 pass, 2 service-dependent skips), audit, full Chromium smoke, pack and installed-tarball smoke passed. Fresh SHA-256-bound TodoMVC, Actual Budget, Conduit SQLite/PostgreSQL + Supabase, PostgreSQL CRUD cleanup, Pocket Ledger Level 7 and Codex RD901 regression/repair evidence all validate with a clean artifact secret scan. Hosted cross-platform and signed aggregate qualification remain pending.

| Specification area | Status | Evidence currently in the repository | Remaining normative gap |
| --- | --- | --- | --- |
| §4 Quick scan | IMPLEMENTED | `scan`, browser execution, report, reload checks, fixture smoke, and deterministic coverage-balanced selection with explicit eligible/selected/omitted/route telemetry | Broader action and environment coverage is tracked below |
| §4 Deep scan | IMPLEMENTED | hard reload, new tab, clean context, versioned logout/login rehydration, managed app restart, API read-back, roles, trace/video, source snapshots, and explicit causal read-only provider confirmation; hosted run `29940370416` passed Windows/macOS/Linux | Application-specific adapters may extend the implemented orchestration without changing its evidence contract |
| §4 Record and verify | IMPLEMENTED | bounded semantic recording and deterministic verification for navigation, click/fill/select/check/keypress/upload/rich-text/drag, popup/download outcomes, masked rrweb, env-only secrets/files and non-ordinal locator fallbacks | Widget-specific adapters may extend recording without changing the implemented contract |
| §4 Baseline/regression | IMPLEMENTED | baseline, affected-flow selection, first-class `EXPECTED_CHANGE`/`REGRESSION` outcomes, RD901–RD905 classification, CI diff and Playwright export | Additional domain-specific diff adapters may extend the implemented contract |
| §4 Coding-agent verification | IMPLEMENTED | shared-core MCP tools retain workspace/action confinement, sealed contracts/baselines, final post-build attribution and fail-closed affected selection; authenticated Codex Desktop `0.143.0` produced a green baseline, selected 1 real RD901 regression, repaired the app without changing the contract, then selected 1 flow with 0 regressions; SHA-256-bound cycle artifacts are parsed by the release validator | New agent clients must preserve the implemented evidence boundary; agent prose is never verification evidence |
| §6 Project Discovery/Runtime Manager | IMPLEMENTED | `init` profiles single-package/monorepo projects; npm fallback without lock metadata; project-local Python virtual environments; zero-config static HTML plus conventional Node, Django/FastAPI/Flask, Laravel/PHP, Rails, ASP.NET Core, Spring Boot, Deno, Go and Rust managed runtimes; occupied-port rejection, development/production/Docker health-checks, logs, bounded restarts and process cleanup; installed-tarball scans start, verify and stop metadata-free static and npm projects in hosted run `29977292441` | Custom runtimes use an explicit HTTP URL; new ecosystem hints must add cross-platform broken/control and package evidence |
| §6 Project Discovery/Runtime Manager | IMPLEMENTED | `init` profiles single-package/monorepo projects; npm fallback without lock metadata; project-local Python virtual environments; zero-config static HTML plus conventional Node, Django/FastAPI/Flask, Laravel/PHP, Rails, ASP.NET Core, Spring Boot, Deno, Go and Rust managed runtimes; occupied-port rejection, development/production/Docker health-checks, dedicated configurable startup timeout, redacted process diagnostics, bounded restarts and process cleanup; installed-tarball scans start, verify and stop metadata-free static and npm projects in hosted run `29977292441` | Phase L must repeat full cross-platform and package evidence before its candidate becomes complete; custom runtimes may still use an explicit HTTP URL |
| §7 Environment Health Gate | IMPLEMENTED | main/route document, critical asset/content-type, bootstrap/render, health-endpoint and auth-state checks; separate `environment.json`; broken/control fixtures and TodoMVC defect copy | Additional ecosystem-specific diagnostics may be added without changing the implemented fail-closed contract |
| §8–11 Discovery, classification, data, executor | IMPLEMENTED | forms/links/buttons/native controls, Enter, hover/context, lazy-scroll, popup/download, opt-in same-origin iframe, complex-action recording boundaries, constraint-aware canaries, network-idle/stale/retry safety, and budget selection that avoids route/semantic starvation and known-denial budget waste | Framework-specific discovery adapters may broaden coverage without changing the implemented safe-execution contract |
| §12–13 Evidence and snapshots | IMPLEMENTED | URL, redacted semantic DOM/control hashes, cookie hashes, local/session storage, bounded IndexedDB metadata, request/response, WebSocket frames, console/page error, upload/download digests, screenshots, trace/video/timeline, value-free source diffs, and redacted automatic provider evidence/artifacts; every retained browser/contract trace passes bounded ZIP inspection against generated sensitive fields, `secretEnv`, opaque auth-state cookies/tokens and generic credential patterns before linkage, while unsafe/unscannable traces are deleted; screenshots/videos are not created for known-sensitive or authenticated contexts and both policies emit only value-free suppression metadata; reproductions retain value-free provider requirements and replay requires fresh exact causal confirmation | New evidence adapters must preserve the implemented redaction, retention, linkage and replay contract |
Expand Down
4 changes: 2 additions & 2 deletions docs/REAL_WORLD_VALIDATION.md
Original file line number Diff line number Diff line change
Expand Up @@ -54,7 +54,7 @@ The current-engine rerun binds each compact evidence document to both the raw `s
| Conduit + PostgreSQL 17 + Supabase Data API | `VALID`, untruncated | 17 `VERIFIED`; signup was `SOURCE_OF_TRUTH_CONFIRMED` Level 6 through both adapters with the same added-row hash | 0 |
| Pocket Ledger | `VALID`, untruncated | all 5 member/public actions `VERIFIED`, including focus-revealed skip link, multipart upload and non-empty CSV export; admin-only Reset was verified separately at Level 7 | 0 |

The current checked-in evidence is bound to Phase K fingerprint `4625a9ccdcec3484a0251ad00253a719fb04a81c8ce552b1d77763f3deccef94`. Every primary scan was `VALID` and untruncated. Compact documents bind fresh TodoMVC `20260726T115450Z-9640`, Actual Budget `20260726T115602Z-0e1b`, Conduit SQLite `20260726T120053Z-d309`, Conduit PostgreSQL + Supabase `20260726T121026Z-1d20`, Pocket Ledger `20260726T115844Z-3380`, PostgreSQL CRUD, Level 7 roles and Codex MCP cycle artifacts by SHA-256. The Pocket role control retained safe traces with no binary visual entries while authenticated-context suppression kept videos at zero. Local source, audit, browser, pack and installed-tarball gates passed. Main run [`30203185815`](https://github.com/datzle123/RealDone/actions/runs/30203185815) passed and signed 15/15 for merge `ca9e9db`; `gh attestation verify` accepted both aggregate artifacts. Released `v1.3.3` and run [`30189340006`](https://github.com/datzle123/RealDone/actions/runs/30189340006) remain the historical published-package qualification.
The current checked-in candidate evidence is bound to Phase L fingerprint `3663ff0c5e291f6a54b335d5d33fb9035e4e4495785dd15d2f1923e97b4e9d74`. Every primary scan was `VALID` and untruncated. Compact documents bind fresh TodoMVC `20260726T134853Z-47e8`, Actual Budget `20260726T135032Z-94f7`, Conduit SQLite `20260726T140120Z-f665`, Conduit PostgreSQL + Supabase `20260726T140645Z-88ef`, Pocket Ledger `20260726T135405Z-d811`, PostgreSQL CRUD, Level 7 roles and Codex regression/repair artifacts by SHA-256. The Pocket role control retained safe snapshot-only traces, suppressed authenticated screenshots/video before capture and kept videos at zero. Local source, audit, browser, pack, installed-tarball, evidence-validation and artifact-secret gates passed; Phase L remains a candidate until its hosted signed 15/15 aggregate passes. Main run [`30203185815`](https://github.com/datzle123/RealDone/actions/runs/30203185815) remains the signed Phase K qualification, while released `v1.3.3` and run [`30189340006`](https://github.com/datzle123/RealDone/actions/runs/30189340006) remain the historical published-package qualification.

PostgreSQL qualification used the pinned upstream Conduit app with only a harness port mapping, an isolated native PostgreSQL 17.10 cluster, real create/update/delete row diffs and key-bounded cleanup. The Supabase source adapter read the same action through a local Supabase Data API-compatible PostgREST 14.15 endpoint; the official Supabase CLI was also checked, but its full Auth/Storage local stack could not start on this machine because Docker Desktop/WSL is absent. This evidence therefore claims the maintained Supabase Data API adapter boundary, not a hosted Supabase service.

Expand All @@ -66,7 +66,7 @@ The first current-engine Conduit rerun exposed an RD501 false positive: the publ

The 2026-07-23 Actual Budget rerun then exposed a safety regression: its server target is a text input with an `https://example.com` placeholder rather than `type="url"`. RealDone initially filled a canary and clicked Connect, producing a DNS failure. URL-bearing placeholders now retain external-target classification; the rerun returned to 6 `VERIFIED`, 1 safe `UNCERTAIN`, 3 policy `SKIPPED`, and zero defects.

Machine-readable Phase K inputs are in `release/external-cases.json` and `release/evidence/`; hosted main run [`30203185815`](https://github.com/datzle123/RealDone/actions/runs/30203185815) validated and signed their aggregate. Run [`30200299159`](https://github.com/datzle123/RealDone/actions/runs/30200299159) remains the signed Phase J history, while run [`30189340006`](https://github.com/datzle123/RealDone/actions/runs/30189340006) independently passed and signed all 15 gates for released `v1.3.3`.
Machine-readable Phase L candidate inputs are in `release/external-cases.json` and `release/evidence/`; their local semantic, SHA-256 and secret-scan gates pass, but they are not yet represented by signed main evidence. Hosted run [`30203185815`](https://github.com/datzle123/RealDone/actions/runs/30203185815) remains the signed Phase K history, while run [`30189340006`](https://github.com/datzle123/RealDone/actions/runs/30189340006) independently passed and signed all 15 gates for released `v1.3.3`.

### Actual Budget original application

Expand Down
Loading