feat(plan-01): Phase 4c — hard cutoff, remove .specify compat facade

Repoint every remaining literal `.specify/...` / `docs/input` reference to the real
package/domain location and delete all compat symlinks. The harness now runs purely via
packages/casan-harness/... with no .specify facade; .specify holds ONLY runtime state
(logs/, agentops/alerts.log, level5/central-governance).

Refs fixed (Phase 0.5 only caught `$VAR/.specify/` — these were bare/`__file__`/literal):
- secrets-scan.sh: scan-target excludes -> packages/casan-harness/... (+ apps/okr/domain/corpus)
- loop_common.py: loop-policy.yaml -> harness config (package-relative)
- evidence-pack-build.py: judge-gate test + traceability-matrix.py -> harness/sibling
- phase10-traceability: REQ -> $CASAN_DOMAIN_ROOT/input
- run-casan-pipeline.mjs: model-fallback/drift-detect/rollback-manager -> HARNESS_BASH,
  golden -> GOLDEN_PLAN (apps/okr/domain), with .specify/logs state kept
- casan-step.mjs: requirement fallback restored to docs/input for hermetic sandboxes
- descriptive config (tool-registry/harness-package/drift-policy/hallucination/risk-registry/
  loop-policy.schema + docstrings) repointed for accuracy
- policy-bundle.yaml: 8 policy paths -> packages/casan-harness/...; manifest regenerated +
  re-signed (POLICY_HASHES_VALID files=8, POLICY_SIGNATURE_VALID)

Removed 22 .specify code/config symlinks + docs/input symlink.
Full gate via packages path, NO facade: PASS=64 FAIL=0 SKIP=3.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
thanhnv
2026-07-08 12:28:37 +09:00
co-authored by Claude Opus 4.8
parent e891981b59
commit 7101af9fd4
38 changed files with 48 additions and 60 deletions
@@ -21,6 +21,9 @@ import os
import subprocess
import sys
# Plan-01: this script lives at <harness>/scripts/bash/; the harness root is two levels up.
_HARNESS = os.path.abspath(os.path.join(os.path.dirname(os.path.abspath(__file__)), "..", ".."))
def read_jsonl(path):
rows = []
@@ -73,11 +76,11 @@ def main():
# H3 eval scorecard (best effort — reference known evidence)
reports["h3-eval-scorecard.json"] = {
"harness": "H3-eval", "run_id": run_id,
"judge_gate_tests": os.path.exists(os.path.join(root, ".specify/tests/phase3-judge-gate-tests.sh")),
"judge_gate_tests": os.path.exists(os.path.join(_HARNESS, "tests/phase3-judge-gate-tests.sh")),
"note": "judge-gate fail-before/fix cycle proven by phase3-judge-gate-tests.sh",
}
traceability_out = os.path.join(pack_dir, "traceability-matrix.json")
traceability_script = os.path.join(root, ".specify/scripts/bash/traceability-matrix.py")
traceability_script = os.path.join(os.path.dirname(os.path.abspath(__file__)), "traceability-matrix.py")
traceability_rc = 1
if os.path.isfile(traceability_script):
traceability_rc = subprocess.run(
@@ -136,7 +136,9 @@ def policy_path() -> str:
explicit = os.environ.get("CASAN_LOOP_POLICY_FILE")
if explicit:
return explicit
return os.path.join(project_root(), ".specify/config/loop-policy.yaml")
# Plan-01: loop-policy.yaml is harness config, not app state — resolve it inside the
# package (this file lives at <harness>/scripts/bash/), independent of any .specify facade.
return os.path.abspath(os.path.join(os.path.dirname(__file__), "..", "..", "config", "loop-policy.yaml"))
def load_policy():
@@ -1,5 +1,5 @@
#!/usr/bin/env python3
"""CASAN H4 PII masker driven by .specify/security/pii-rules.yaml.
"""CASAN H4 PII masker driven by packages/casan-harness/security/pii-rules.yaml.
Reads content on stdin, applies every `action: mask` rule from the rules
file, and writes the masked content to stdout. Type-specific replacement
@@ -39,14 +39,15 @@ fi
# Exclude known test-fixture files and evidence directories that intentionally
# contain the pattern as test data.
FIXTURE_EXCLUDES=(
".specify/tests/"
"packages/casan-harness/tests/"
"docs/output/casan/evidence/"
".specify/security/"
".specify/scripts/bash/security-check.sh"
".specify/scripts/bash/verify-audit-chain.sh"
".specify/scripts/bash/verify-tool-audit.sh"
".specify/scripts/bash/tool-audit-lib.sh"
".specify/scripts/bash/governance-check.sh"
"packages/casan-harness/security/"
"apps/okr/domain/corpus/"
"packages/casan-harness/scripts/bash/security-check.sh"
"packages/casan-harness/scripts/bash/verify-audit-chain.sh"
"packages/casan-harness/scripts/bash/verify-tool-audit.sh"
"packages/casan-harness/scripts/bash/tool-audit-lib.sh"
"packages/casan-harness/scripts/bash/governance-check.sh"
)
build_exclude_args() {
for ex in "${FIXTURE_EXCLUDES[@]}"; do printf -- "--exclude-dir=%s " "$ex"; done
@@ -1,7 +1,7 @@
#!/usr/bin/env python3
"""CASAN Plan-10 traceability matrix generator/gate.
Parses FR-* requirements from docs/input/okr-requirement.md and checks each
Parses FR-* requirements from apps/okr/domain/input/okr-requirement.md and checks each
requirement has at least one existing code file and one existing test file.
"""
import argparse