Repoint every remaining literal `.specify/...` / `docs/input` reference to the real package/domain location and delete all compat symlinks. The harness now runs purely via packages/casan-harness/... with no .specify facade; .specify holds ONLY runtime state (logs/, agentops/alerts.log, level5/central-governance). Refs fixed (Phase 0.5 only caught `$VAR/.specify/` — these were bare/`__file__`/literal): - secrets-scan.sh: scan-target excludes -> packages/casan-harness/... (+ apps/okr/domain/corpus) - loop_common.py: loop-policy.yaml -> harness config (package-relative) - evidence-pack-build.py: judge-gate test + traceability-matrix.py -> harness/sibling - phase10-traceability: REQ -> $CASAN_DOMAIN_ROOT/input - run-casan-pipeline.mjs: model-fallback/drift-detect/rollback-manager -> HARNESS_BASH, golden -> GOLDEN_PLAN (apps/okr/domain), with .specify/logs state kept - casan-step.mjs: requirement fallback restored to docs/input for hermetic sandboxes - descriptive config (tool-registry/harness-package/drift-policy/hallucination/risk-registry/ loop-policy.schema + docstrings) repointed for accuracy - policy-bundle.yaml: 8 policy paths -> packages/casan-harness/...; manifest regenerated + re-signed (POLICY_HASHES_VALID files=8, POLICY_SIGNATURE_VALID) Removed 22 .specify code/config symlinks + docs/input symlink. Full gate via packages path, NO facade: PASS=64 FAIL=0 SKIP=3. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
casan-harness (package skeleton)
Core CASAN harness (gate H1→H7) as a reusable package, independent of domain data.
Populated incrementally by Plan-01 (Phase 0→6). During migration, files move here from
.specify/ wave-by-wave; the full harness gate must stay green (PASS=64 FAIL=0) after each phase.
Layout:
scripts/— bash + powershell gate logic (H1→H7), path resolvercasan-paths.shsecurity/— filter/policy rules (prompt-filter, pii-rules, output-policy, ...)governance/,agentops/— H5/H6 codelevel5/— L5 config (drift/kpi/model-fallback/tool-registry YAMLs)templates/,config/— spec/plan templates, loop-policytests/— reproducible harness test suites + integrity manifest
Runtime state (logs, audit chain, tenant state) is NOT part of this package — it stays with
the app under CASAN_STATE_ROOT. Domain data (golden-runs, corpus, input) lives in
apps/okr/domain/ under CASAN_DOMAIN_ROOT.