Skip to content

[EPIC] Finish the flow suite and prove production-ready orchestration #11

Description

@szmyty

2026-10-01 UTC — aniflow #50 merged; #51 next

This handoff supersedes the earlier execution-status notes below. Aniflow PR #62 merged into main at e0b63d2e3650efed1f4239a286db7970d8e354a5 with the user's explicit direct-merge authorization. #50 is closed. #42–#49 were already merged; all prerequisites for aniflow #51 are now complete.

The bounded optional Basic Pitch 0.4.0 ONNX CPU profile ships probabilistic note candidates and explicit type-0 MIDI export with source/stem/tool/model/configuration evidence, declared timing losses, independent read-back and immutable output companions. Activation is not calibrated confidence or authored-score authority.

Fresh local checks passed: 364 stable Rust tests; 36 focused Rust 1.85.1 tests; strict Clippy/formatting/naming/docs and compiled source package; 12 adapter tests, 16 schema tests, 82 published documents and four actual Task checks; complete repository synthetic smoke with 17 MIDI cases; 31 independently validated captured reports/companions and three external Mido read-backs. The receipt retains exact implementation/tree, hashes, scope and earlier corrections.

Next: #51's bounded integrated synthetic workflow, honest capability support matrix, failure/interruption/resume evidence and renderflow/flow consumer documentation. No #51 implementation has started. Parent aniflow #13 remains open for that reconciliation.

Actual model inference/accuracy, native-platform qualification, full MSRV/dependency closure, hosted CI and releases remain unverified. Synthetic fixtures only; no real-media mutation, model downloads, paid APIs, hosted-CI polling, tags or release creation. Downstream order stays #13 → #32 → #33 → #34 → bounded #24 → #10 → flow #51. Other suite gates below are historical until refreshed.

2026-09-29 UTC — aniflow #49 paused at completed checkpoint

Maintainer requested a pause; PR #61 has been returned to draft. All four checkpoints and final validation evidence are already pushed. Implementation and local checks are complete; resume with review and any requested fixes. No next-issue work has started.

This handoff supersedes earlier execution-status notes below. The maintainer merged aniflow PR #60 at 01130266cd2d6f52fca72e357e01a5a854ad540b; #48 is closed. Fresh main and #42/#43/#47 prerequisites were rechecked before branching.

Aniflow #49 is implemented in draft PR #61. Final head 71ef2170cda940c3b696f963c4736d62e75c1463, tree effc05c8aed511aa064838e03549aea0d168395f; local and remote trees match. Four recoverable checkpoints are pushed. The last commit adds evidence/roadmap documentation only; production code, schemas, tests and scripts remain at validated implementation 39c6da114a78071aa526a3e76bcc475f36f117fd, tree 9838f1c392657b19289fc8f4e58272301729907b.

The optional pinned PocketSphinx 5.1.1 English CPU profile proposes word/cue timing while retaining exact reviewed lyric JSON/text, supplied review provenance and revision identity. Missing/ambiguous mappings remain untimed and partial. Pipeline v3 lifecycle, bounded private staging and dependency rechecks, CLI/tasks, strict schemas and source-bound loss-aware exports are implemented. Forced alignment cannot prove words occur in audio; review assertions are not independently authenticated and timing remains unreviewed.

Exact local receipt: 328 Rust tests, 29 focused Rust 1.85.1 tests, strict Clippy/formatting/naming, twelve schema tests, 70 published contract documents, docs/package verification, complete repository smoke and five actual Task argument checks passed. All twelve final alignment smoke documents validate independently; eleven alignment scenarios passed. The unchanged optional musical analyzer was skipped (ANIFLOW_MUSICAL_PYTHON unset). The receipt records the initial inventory-order failure, native default-LM discovery correction and strict-Clippy correction; final checks cover them without weakened assertions or retries.

Actual PocketSphinx/model inference and alignment quality, especially singing, native macOS/other platforms, full MSRV, broader languages/profiles, native dependency closure/OS isolation, hosted CI, broader audits and release qualification remain unverified. Version is a caller declaration bound to an executable digest, not a native version probe. Independent review found no remaining material blocker within this bounded scope. Synthetic fixtures only; no real-media access/mutation, model downloads, paid APIs, hosted-CI polling, merge, tag or release.

Remain paused until the maintainer resumes review/merge of #61. #49 stays open until merge; parent aniflow #13 stays open through #51 reconciliation. #50 remains the next independently ready checkpoint; #51 requires #49 and #50. Downstream product order remains #13 → #32 → #33 → #34 → bounded #24 → #10 → flow #51. Provider audits and final release closeout remain later. Re-query live GitHub, repository instructions and fresh main before the next branch; older suite gate snapshots and the linked holistic graph remain historical context.


Important

2026-09-29 UTC aniflow #48 review handoff

This supersedes the #48 scope checkpoint and earlier handoffs. Preserve the linked holistic graph below and re-query live GitHub, repository instructions and fresh main before each branch. The maintainer owns review and merge.


Important

2026-09-29 UTC aniflow #47 merged; #48 next

This supersedes the #47 review handoff below. Preserve the linked holistic graph and historical evidence. Re-query live GitHub, repository instructions and fresh main before branching.


Important

2026-09-29 UTC aniflow #47 review handoff

This supersedes the #47 implementation checkpoint. Preserve the linked holistic graph below and re-query live GitHub, repository instructions and fresh main before each branch. The maintainer owns review and merge.


Important

2026-09-28 aniflow #8 review handoff

This is the current suite implementation checkpoint. Preserve the linked holistic graph below as planning context; re-query live main, issues, releases and PRs before branching. Maintainer owns merges.


Important

2026-09-27 Flow #50 review handoff

This is the current Flow implementation checkpoint. The holistic issue graph below remains the planning baseline; older active-checkpoint prose is historical. Re-query live main, issue, release, and PR state before the next branch.

  • Flow #50 is implemented for review in PR #76, head 28a1fc0c0382e6b4a370857d9567d49a091abeaa, validated tree 4107f4495097e7b2113670ba89fa9eff738582dd. The direct-push fallback published a GitHub tree identical to the locally validated commit. The maintainer owns merge.
  • It pins independently verified Optiflow v0.1.1 and exposes only scan, report, and exact-duplicate review planning through a public Flow library adapter. The native CLI result and committed member bytes are checked independently; a versioned local receipt persists attempt transitions. Dry-run, quarantine, restore, and finalization refuse as unsupported. The existing Flow JSONL and durable graph contracts are unchanged.
  • Linux/Rust 1.85 validation: 189 tests passed, two existing subprocess entrypoints ignored; the 49 lifecycle recipes and 81 acceptance scenarios ran within the suite. The released-binary fixture passed on synthetic text and Unicode paths, and strict Clippy, formatting, repository validators, and a real receipt JSON Schema check passed. macOS native execution and hosted CI were not checked; no personal media was scanned.
  • After [FLO-3.5] Integrate an immutable Optiflow release #50 merges, continue the parallel released-provider lanes #51 and #52 as their immutable releases qualify, then #53 suite CLI composition. #73 is the separate v0.2 mutation adapter after Optiflow #93/#111; it is not part of this read-only PR.

Important

2026-09-27 holistic suite roadmap — current handoff

The complete live issue graph and dependency notes supersede older issue counts and active-checkpoint prose below. Re-query live GitHub state before implementation. Older snapshots remain historical.


Important

2026-09-27 Optiflow #96 review handoff

This is the current Optiflow execution checkpoint. Older handoffs below are
historical; re-query live dependencies and main before the next branch.

  • Optiflow PR #108 merged as e50c3b206a243ce607d6863cca8b2423711cde2a; #92 is closed.
  • Optiflow #96 is implemented for review in PR #109, head 6d9f41703de1c2b920de91eba96326175079b3ab, validated tree 422facfe8db0cdf33d13cab4bc0aa14933b6462b. It adds explicit, separately authorized Linux-only finalization of proven retained cross-filesystem quarantine copies, with immutable v4 pending/removed evidence and no physical-savings claim. The original source is never a finalization target; v0.1.1 remains immutable and read-only.
  • Local validation: 251 Rust 1.85.1 tests passed, one existing stress test ignored, 32 PR-tier and 170 scheduled-tier corpus executions, strict Clippy/formatting, and 34 HTML documents. Synthetic fixtures only; no user media. Package tarball verification hit a local copied build-script permission error. Native macOS and hosted CI were not checked or polled.
  • Maintainer owns PR #109 merge. After it merges and a fresh dependency check, the remaining Optiflow lane is #93, with #94 after the relevant [FLO-13.4b] Add deterministic durable lifecycle traces and recovery scenarios #65 fixtures and #95 after #93/#94. Do not start #93 automatically.

Important

2026-09-26 Optiflow #92 review handoff

This is the current Optiflow execution checkpoint. Older handoffs below
remain historical; re-query live issues and main before the next branch.

  • Optiflow PR #105 merged as 559a54676ad9223c0e7858d1dea1b5510c912049; #91 is closed. The bounded CI repair #106 merged through PR #107 as 85e8208c1105f591166ba7b4c5e40fd9dac09b05.
  • Optiflow #92 is implemented for review in PR #108, head c2bb9478d9fb322c7e242e16852e3cc654b14e47, validated tree 097f639304e9a16ac9edca47898a65e018f866c3. It adds Linux-only operator status, bounded resume, collision-safe restore, and empty owned-namespace cleanup with append-only v3 evidence. Historical v2 mutations remain inspection-only; v0.1.1 remains immutable and read-only.
  • Local validation: 245 Rust 1.85 tests passed, one scheduled stress test ignored, 32 PR-tier corpus executions, strict Clippy/formatting, package verification, and 35 HTML documents. Synthetic failure/recovery fixtures only; no user media. Native macOS and hosted CI were not checked or polled.
  • Maintainer owns PR #108 merge. After it merges and a fresh dependency check, the remaining Optiflow lane is #96 → #93, with #94 after the relevant [FLO-13.4b] Add deterministic durable lifecycle traces and recovery scenarios #65 fixtures and #95 after #93/#94. Do not start #96 automatically.

Important

2026-09-26 Optiflow #91 review handoff

This is the current Optiflow execution checkpoint and supersedes the #90
active markers in the older handoff below. Keep the older text as historical
evidence and re-query live state before the next issue.

  • Optiflow PR #104 merged as 437fc326c37fd91b4c9f84a67efd097a17c6f0c6; #90 is closed.
  • Optiflow #91 is implemented for review in PR #105, head 89916aad203c79e9315494f4a5f6d4afadaaf9e2, tree b1705388d3a9bd900a6a8eca5251cefa852d3f0f. It adds Linux-only bounded quarantine with v2 mutation evidence, keeping v1 dry-run and immutable v0.1.1 release guarantees intact.
  • Local validation: 234 Rust tests passed, one scheduled stress test ignored, 32 PR-tier filesystem corpus executions passed, strict Clippy/formatting passed, and 34 HTML documents built. Synthetic same/cross-filesystem mutation and interruption were exercised. Native macOS and hosted CI were not checked; no user media was touched.
  • Maintainer owns PR #105 merge. After that merge and a fresh dependency check, the remaining Optiflow lane is #92 → #96 → #93, with #94 after the relevant [FLO-13.4b] Add deterministic durable lifecycle traces and recovery scenarios #65 fixtures and #95 after #93/#94. Do not start #92 automatically.

Important

2026-09-26 live execution handoff

This delta supersedes older live counts, active-checkpoint markers, and
execution ordering below where they conflict. Repository-local ROADMAP.md
files remain the detailed product owners; re-query live GitHub state before
starting work.

Verified Flow checkpoint

Later documentation

Provider lanes feeding Flow

The hermetic Flow #31 lane is complete. Optiflow's signed v0.1.1 is published and independently verified. PR #103 is merged and #89 is closed. #90 awaits maintainer review/merge in PR #104; #91 follows that merge. #88 / PR #101 is complete. Renderflow #415 and Aniflow #8 remain recorded ready fronts; re-query their live dependencies before starting provider work.

The 2026-09-26 sweep found no open provider PRs and no Renderflow or Aniflow releases; Optiflow had only v0.1.0 at that historical sweep. Its verified v0.1.1 release now supersedes that release snapshot. Renderflow main a2baa082850a323bb8c0c3cbe14a712eb861be9c has green CI. Optiflow main cc9b4aff492e340220dabcba1fc5242a74e035c6 has failing CI, and Aniflow main 8a88b0e96c2ac89da9b26b579300e84aa80aa762 has failing CI. These are historical hosted-CI observations. The maintainer's focused-local-check preference above supersedes waiting on those runs.

Suite closeout

After the active provider/product lanes and Flow integration/release work,
perform provider post-roadmap audits (Optiflow #61, Renderflow #409, Aniflow
#17) before the final suite-level Flow audit #12. Audit findings should become
bounded remediation issues rather than silently expanding an in-progress
feature issue.

Important

2026-09-22 live-sweep delta

This delta supersedes older live counts, active-checkpoint markers, and execution ordering below. The existing body remains preserved as historical roadmap and decision evidence.

Verified live Flow state

Current Flow execution order

  1. Review and merge PR [FLO-13.2a] Establish the immutable hermetic provider package and success path #47 / close [FLO-13.2a] Establish the immutable hermetic provider package and success path #44.
  2. Retarget, review, and merge PR [FLO-13.2b] Exercise bounded provider lifecycle and protocol outcomes #48 / close [FLO-13.2b] Exercise bounded provider lifecycle and protocol outcomes #45.
  3. Complete [FLO-13.2c] Complete artifact adversaries, graph fixtures, and kit documentation #46, then reconcile and close parent #29.
  4. Complete #30.
  5. Complete #49, the durable plan/run/checkpoint-state foundation.
  6. Complete #31.
  7. Integrate released providers as immutable artifacts permit: #50 Optiflow, #52 Renderflow, then #51 Aniflow. Exact readiness may allow independent adapter work without changing their ownership boundaries.
  8. Complete #53 and reconcile/close #3.
  9. Complete #32, then #33, #34, and #10.
  10. Complete #54, Flow's first immutable integration-candidate release.
  11. The observability sequence #15 through #22 remains a parallel or later lane where dependencies permit; reconcile parent #14 before final release disposition.

Provider priority lanes

Flow Suite Completion Roadmap

Important

Durable continuation point

In a new chat, say: “Continue the Flow Suite roadmap from flow#11, one issue and PR at a time.”

The next agent should read this issue, re-query the four repositories, and resume the item named under Active checkpoint below. Do not rely on the snapshot as live truth, do not combine roadmap items into a mega-PR, and do not merge review PRs without the maintainer.

Active checkpoint

Execution protocol

  1. Re-query default-branch SHA, CI, open PRs, issue state, releases, repository instructions, and external gates before each branch.
  2. Work on exactly one bounded issue at a time, on a clean issue-specific branch.
  3. Record diagnosis, before/after evidence, validation, residual risk, and rollback in the PR.
  4. Open the PR for review and stop; the maintainer decides when to merge.
  5. After merge or disposition, update this body: check the inventory item, update the active checkpoint, and advance the strict next-up queue.
  6. If live evidence invalidates an ordering assumption, update this epic explicitly before implementing the changed order.

Live open-issue inventory

Live re-query: 2026-09-21 after Step 6 merged and parent #25 closed. Flow has 21 open issues and no open pull requests. Across Flow, Aniflow, Optiflow, and Renderflow there are 41 open issues and no open pull requests. Re-query live state again before starting #29 because repository state can change.

Flow — 21 open

  • flow#3 — Implement a versioned cross-holon orchestration vertical slice
  • flow#9 — Backfill repository ADR history and enable continuous decision capture
  • flow#10 — [Publication] Orchestrate exhaustive comic finalization and multilingual release workflows
  • flow#11 — [EPIC] Finish the flow suite and prove production-ready orchestration
  • flow#12 — [Audit] Post-roadmap repository, backlog, and Identity audit
  • flow#13 — Build cross-tool orchestration and failure fixture suites
  • flow#14 — [EPIC] Establish suite-wide observability and CLI experience
  • flow#15 — [FLO-OBS-01] Define the suite observability, privacy, and stream contract
  • flow#16 — [FLO-OBS-02] Prove the observability profile in two holon CLIs
  • flow#17 — [FLO-OBS-03] Prove opt-in OpenTelemetry logs, metrics, and traces
  • flow#18 — [FLO-OBS-04] Decide shared observability crate and repository ownership
  • flow#19 — [FLO-OBS-05] Build the selected reusable observability package
  • flow#20 — [FLO-OBS-06] Migrate the suite and enforce observability conformance
  • flow#21 — [FLO-OBS-07] Add privacy-safe diagnostics and operator runbooks
  • flow#22 — [FLO-OBS-08] Add accessible branded root-help presentation
  • flow#29 — [FLO-13.2] Build the hermetic orchestration provider kit
  • flow#30 — [FLO-13.3] Prove compatibility, artifact, and provider-failure scenarios
  • flow#31 — [FLO-13.4] Prove interruption, retry, resume, and authority state transitions
  • flow#32 — [FLO-13.5] Prove the static publication workflow with released providers
  • flow#33 — [FLO-13.6] Prove the temporal release workflow with released providers
  • flow#34 — [FLO-13.7] Add clean-room compatibility, CI tiers, and regression promotion

Renderflow — 11 open

  • renderflow#349 — Evaluate repository briefings and podcast derivatives from canonical content
  • renderflow#350 — Add a Slidev-backed product presentation publication profile
  • renderflow#367 — Roadmap: universal artifact forest, maximal Renderflow profile, and Flow orchestration readiness
  • renderflow#378 — 🤖 Add Medium-style article Copilot agent for generation and polishing
  • renderflow#379 — 📝 Add long-form editorial article template/profile paired with the Medium-style Copilot agent
  • renderflow#397 — Add Sonic DNA normalization and semantic audio descriptions
  • renderflow#405 — Backfill repository ADR history and enable continuous decision capture
  • renderflow#406 — [Publication] Add localization-ready layered page composition and locale render targets
  • renderflow#409 — [Audit] Post-roadmap repository, backlog, and Identity audit
  • renderflow#412 — Build a comprehensive adversarial rendering fixture corpus
  • renderflow#413 — Add a synthetic comic fixture and reusable document-type fixture packs

Optiflow — 3 open

  • optiflow#60 — Backfill repository ADR history and enable continuous decision capture
  • optiflow#61 — [Audit] Post-roadmap repository, backlog, and Identity audit
  • optiflow#65 — Build a deterministic adversarial file and media corpus

Aniflow — 6 open

  • aniflow#8 — Add an offline-first Demucs vocal-stem separation workflow
  • aniflow#10 — ci(releases): pilot the Rust CLI and binary release convention
  • aniflow#13 — Add typed audio feature, lyrics, and MIDI extraction
  • aniflow#14 — Backfill repository ADR history and enable continuous decision capture
  • aniflow#17 — [Audit] Post-roadmap repository, backlog, and Identity audit
  • aniflow#24 — Build a deterministic adversarial temporal-media corpus

Repositories: flow, renderflow, optiflow, and aniflow
Snapshot: 2026-09-20
Suite coordinator: flow#11
Execution model: one bounded issue, branch, and reviewable pull request at a time; re-query live state before every branch.

Executive conclusion

The suite is much closer than the raw backlog suggests.

  • The provider architecture is substantially implemented. Aniflow's provider/runtime/Pipeline v3 sequence has landed, Optiflow's safe extension boundary and read-only product are mature, and Renderflow's universal artifact foundation is broad.
  • The true critical path is now Flow's production process boundary, durable run state, released-provider adapters, and two clean-room end-to-end proofs.
  • The largest polish gap is release truth: Optiflow is the only repository with a GitHub release. Flow, Renderflow, and Aniflow advertise package versions in source but have no GitHub releases.
  • The immediate default-branch truth blocker is resolved: Optiflow PR #86 preserved every budget, added inspectable three-trial sampling, and all six workflows are green on merged main 7de8483b64387542a05214004c19a9cd05628908.
  • Several issue bodies and repository roadmaps are stale relative to merged work. They must be reconciled as work proceeds so the roadmap, README, release, and CI surfaces report the same reality.

The recommended finish line is a polished suite v1, not “every future idea implemented forever”:

  1. Each holon is independently installable, documented, tested, and releasable from immutable artifacts.
  2. Public CLI/provider/artifact contracts are versioned and compatibility-tested without sibling source coupling.
  3. Flow can inspect, plan, execute, validate, explain, interrupt, retry, and resume real multi-holon work.
  4. One static-publication workflow and one temporal-media workflow pass positive and negative clean-room suites.
  5. Corpora, observability, diagnostics, security, provenance, sites, and release metadata tell the same truth.
  6. Every current issue is shipped, evidence-closed, superseded, or assigned explicitly to a named post-v1 milestone.
  7. Provider audits run first, Flow's suite audit runs last, remediation lands, and final stable releases are smoke-tested from clean hosts.

Optiflow may truthfully reach this suite finish line as a polished, stable, read-only intelligence and planning product. Its future transactional mutation and replacement milestones remain visible post-v1 work and do not block Flow's first production-ready orchestration release.

Live baseline

The suite-wide re-query after Step 6 records 41 open issues: Flow 21, Renderflow 11, Optiflow 3, and Aniflow 6. All four repositories currently have no open pull requests. Re-query again before the next branch.

Repository Current main Main evidence Release truth Open issues Immediate interpretation
Flow 3d854c7 Main CI green; merged PR #43 CI green No GitHub release; Cargo 0.1.0, publish = false 21 External-process boundary #25 is complete; #29 is next. No public product CLI, durable state, or real released-provider slice yet.
Renderflow 170c3d5 CI green, docs green No GitHub release; workspace version 0.2.1; README currently advertises release/package installation paths 11 Broadest product surface; remaining capability/profile work, corpus work, and release-truth repair are the major gaps.
Optiflow 7de8483 CI, docs, site, adversarial, security, and identity green Signed v0.1.0, but current source includes later unreleased capabilities 3 Default-branch truth is restored; release-scope drift and the remaining corpus/audit/governance work stay open.
Aniflow 47c9798 Merged PR #31 CI green No GitHub release; Cargo/README version 0.3.0 6 Provider SDK/runtime/Pipeline v3/conformance work and roadmap reconciliation have landed; release and temporal/audio work remain.

Additional repository-level polish gap: none of the four repositories currently exposes branch protection or a repository ruleset for main. Required-check enforcement belongs in the release/governance closeout, not in feature PRs.

Dependency shape

flowchart TD
    A["Restore live truth"] --> B["Finish Flow process boundary"]
    B --> C["Prove hermetic state and failures"]
    C --> D["Finish provider capabilities and corpora"]
    D --> E["Publish integration-candidate releases"]
    E --> F["Prove real static and temporal workflows"]
    F --> G["Observability, governance, and audits"]
    G --> H["Final stable suite releases"]
Loading

Ordered execution roadmap

Wave 0 — Restore and reconcile repository truth

This wave is mandatory. No later phase should call the suite stable while a default branch is red or roadmaps describe already-merged work as pending.

  1. Completed optiflow#85 through merged PR #86.

    • Diagnosis: the failed run showed whole-host contention across discovery, cold hashing, and warm hashing rather than a discovery-only code regression.
    • Repair: three independent trials, correctness checks in every trial, raw samples, median wall time, and worst-case artifact/RSS enforcement without raising a budget.
    • Exit evidence: #85 is closed; merged main is 7de8483b64387542a05214004c19a9cd05628908; all six default-branch workflows are green.
  2. Completed aniflow#11 through merged PR #31.

  3. Refresh the authoritative status ledgers without creating a documentation mega-PR.

  4. Create the missing bounded child issues listed under “Issue creation needed.” This preserves the one-issue/one-PR protocol and prevents Flow [FLO-3.2] Specify external process transport and provider trust boundaries #25 or Implement a versioned cross-holon orchestration vertical slice #3 from becoming mega-PRs.

Wave 1 — Complete Flow's external-process trust boundary

flow#25 is closed as completed. Its framing and trust boundaries were delivered as separate children in this order:

  1. Complete — FLO-3.2b through merged PR #37: validate artifact bindings and host observations.

    • Immutable input/output bindings, root-relative locators, deterministic file/directory identity, and exact host/provider correlation are merged.
    • Exit evidence: merge commit 55341605968d3343e74d8bdd2b188c99a855aca0; PR CI run 35545386170 and main CI run 35546410096 are green.
  2. Complete — FLO-3.2c through merged PR #39: verify locked packages and executable subjects.

    • Closed v1 contracts and an opaque match token keep digest observation, lock equality, cryptographic verification, publisher declaration, operator trust, and transparency status distinct.
    • Fresh package and executable observations must exactly match the lock before request encoding or transcript validation.
    • Merge commit 9cbe58eff5174faa9511a64211e8119e5c7bda6d; PR CI run 35557639881 and main CI run 35558851556 are green.
  3. Complete — FLO-3.2d via merged PR #41: enforce authority and isolation profiles.

    • Separate requested effects, granted permissions, and host-enforced guarantees.
    • Explicit allowlists for argv, environment handles, filesystem, network, subprocess, GPU, publication, signing, and telemetry propagation.
    • A requested sandbox profile must fail closed when the host cannot prove it.
  4. Complete — FLO-3.2e through merged PR #43: launch and supervise bounded provider processes.

    • Direct executable-plus-argv invocation; no shell strings.
    • Timeout, cancellation, grace, direct-child termination/reaping, output/frame limits, cleanup, redacted evidence, and Unix conformance.
    • Exit zero and file existence remain insufficient for acceptance.
    • Exit evidence: merge commit 3d854c79756b1dee5d3ca267a08ae27b76673a4b; PR CI run 35632038827 and main CI run 35633394688 are green.
  5. Complete — reconcile and close flow#25.

    • All 12 parent acceptance criteria are checked.
    • Rust 1.85, stable Rust, contract, hermetic, package, architecture, skill, and agent validation are recorded green.
    • Residual non-goals remain explicit: no sandbox, authenticated enforcement, descriptor-bound launch, process-tree containment, durable state, real adapters, or public product CLI.

Wave 2 — Build the hermetic orchestration kernel and durable lifecycle

  1. Complete flow#29: hermetic orchestration provider kit.
  2. Complete flow#30: compatibility, artifact, diagnostics, and provider-failure matrix.
  3. Create and complete FLO-3.3 — Persist durable plan, run, checkpoint, and provenance state under flow#3.
    • Atomic state transitions, immutable references, exact configuration/provider locks, accepted artifacts, partial results, and content-aware invalidation.
    • State is authoritative; telemetry is not.
  4. Complete flow#31: interruption, retry, resume, and authority state-transition proof.
  5. Keep flow#3 open until the released-provider adapters and real vertical slice in Wave 6 land.

Wave 3 — Finish provider capabilities required by the product proofs

These issues are provider-owned and may be implemented independently after their own live baselines are green. The following is the preferred sequential order.

  1. Complete renderflow#406: localization-ready layered page composition and deterministic locale targets.
  2. Complete aniflow#8: offline-first Demucs vocals/accompaniment separation.
  3. Complete aniflow#13: typed technical, musical, lyrics/timed-text, and MIDI analysis artifacts.
  4. Complete renderflow#397: Sonic DNA normalization and semantic audio description, consuming Aniflow evidence without source coupling.
  5. Create and complete Aniflow's already-documented stream-aware temporal correctness issue.
    • Rational time, CFR/VFR, timestamps, stream identity/selection, synchronization, and explicit multi-stream support/refusal.
  6. Create and complete Aniflow's already-documented layered validation and evidence-rich delivery issue.
    • Component, intermediate, candidate-master, and delivery validation; success only after structural, timing, synchronization, decodability, and checksum gates.
  7. Create and complete Aniflow's already-documented content-addressed reuse and operational controls issue.
    • Cross-run reuse, targeted reruns, invalidation, cache inspection/pruning, storage preflight, retention, and concurrent-writer safety.

Wave 4 — Complete deterministic provider corpora and Renderflow's current product queue

  1. Complete aniflow#24, preferably through bounded children:
  2. Complete optiflow#65: deterministic adversarial file/media corpus.
  3. Complete renderflow#412 through bounded corpus families rather than one enormous PR.
  4. Complete renderflow#413: original synthetic comic plus the reusable document-type fixture-pack convention. Use #406 for layered/localized coverage where applicable.
  5. Complete renderflow#378, then renderflow#379: agent/content contract first, canonical long-form profile second.
  6. Complete renderflow#350: Slidev-backed presentation profile.
  7. Complete renderflow#349: evidence-backed repository briefing/podcast derivative, after Aniflow audio evidence is available.
  8. Keep renderflow#367 open until Flow's real integration proof and release closeout are complete.

Wave 5 — Publish integration-candidate provider releases

Flow's real-provider tests should consume immutable release artifacts, not mutable main branches or sibling worktrees.

  1. Complete aniflow#10 after its remaining external dependency, egolint#29, is complete and reverified.
  2. Create and complete “Publish the first verified Renderflow release.”
    • Resolve README/package promises against actual supported channels.
    • Produce checksums, provenance, SBOM/notices, clean-install tests, rollback guidance, and artifact smoke tests.
  3. Create and complete “Publish the current Optiflow read-only contract release and freeze the v1 scope.”
    • Restore green main first.
    • Decide and document whether the next tag is a compatible 0.1.x, a pre-v1 minor, or the read-only v1 candidate.
    • Keep candidate production and source mutation outside this release unless separately approved and fully recoverable.
  4. Record exact provider versions, schemas, capabilities, required tools, effects, and compatibility results in Flow's capability matrix.

Wave 6 — Implement real Flow adapters and close the orchestration proof

Create these bounded children under flow#3:

  1. FLO-3.4 — Integrate an immutable Aniflow release.
  2. FLO-3.5 — Integrate an immutable Optiflow release.
  3. FLO-3.6 — Integrate an immutable Renderflow release.
  4. FLO-3.7 — Ship the first supported flow doctor, inspect, plan, run, status, and resume experience.
  5. Close flow#3 only when a real inspect → plan → transform → validate slice proves persisted state, immutable artifacts, explanation, interruption, and deterministic resume while every provider remains independently usable.
  6. Complete flow#32: static publication proof with immutable Renderflow and Optiflow artifacts.
  7. Complete flow#33: temporal release proof with immutable Aniflow and Renderflow artifacts, with Optiflow only where semantically appropriate.
  8. Complete flow#34: clean-room compatibility matrix, CI tiers, coverage claims, and regression promotion.
  9. Reconcile and close flow#13.
  10. Complete flow#10: generic exhaustive comic finalization/localization/publication orchestration. Ordinary fixtures remain synthetic and redistribution-safe; the private Orientation profile is opt-in and consumer-owned.
  11. Reconcile and close renderflow#367 after its remaining profiles, maximal artifact proof, and Flow evidence are linked.

Wave 7 — Establish suite-wide observability and CLI polish

Execute the children of flow#14 in dependency order:

  1. flow#15: normative observability, privacy, correlation, and stream contract.
  2. flow#16: prove the profile in Renderflow and Aniflow through repository-owned PRs.
  3. flow#17: opt-in OpenTelemetry logs, metrics, traces, and bounded cross-process propagation.
  4. flow#18: evidence-backed ownership/packaging ADR.
  5. flow#19: conditional shared package only if [FLO-OBS-04] Decide shared observability crate and repository ownership #18 selects it; otherwise close or reshape with decision evidence.
  6. flow#20: migrate all four holons and enforce conformance.
  7. flow#21: privacy-safe diagnostic bundles and operator runbooks.
  8. flow#22: accessible branded root-help presentation, without contaminating machine output.
  9. Reconcile and close flow#14.

Wave 8 — Release-candidate and governance convergence

  1. Create one release-hardening issue in each repository that does not already have an adequate owner. Each must prove:
    • clean installation from immutable artifacts on every supported platform;
    • version/help/completion/manual consistency;
    • checksums, provenance, SBOM, notices, and rollback;
    • schema/CLI compatibility policy and migration fixtures;
    • docs, site, repository metadata, and binary version agreement.
  2. Create one suite-governance issue, preferably in egohygiene/.github and linked from Flow [EPIC] Finish the flow suite and prove production-ready orchestration #11, to enable repository rulesets/branch protection and required checks for all four main branches.
  3. Execute the gated ADR backfills only after all live external prerequisites are satisfied:

As of this snapshot, Hygiene #15, Holon #6, and Relay #30 are complete; Relay #5, Relay #27, Relay #33, and Pace #5 remain open. Those external gates must not deadlock independent product work.

Wave 9 — Provider-first audits, remediation, and final stable releases

Run the deferred audit issues only after the active roadmap and release-candidate sequence is complete:

  1. aniflow#17
  2. optiflow#61
  3. renderflow#409
  4. flow#12 last, so it can reconcile the provider audits and the full suite.

Each audit PR records evidence and creates bounded remediation issues; it does not mix fixes into the audit. Execute resulting issues in this order:

  1. data-loss, corruption, authority, privacy, security, or false-evidence risks;
  2. contract, compatibility, recovery, and reproducibility gaps;
  3. release/install/site/version drift;
  4. accessibility, identity, onboarding, and presentation polish;
  5. optional convenience improvements.

Then:

  1. run clean-room installation and positive/negative workflows exclusively from immutable release candidates;
  2. publish the final stable versions of all four tools;
  3. publish the suite compatibility table and rollback guide;
  4. confirm required checks/rulesets on all four default branches;
  5. close the remaining child/parent issues with exact evidence;
  6. close flow#11 with one final completion report linking commits, releases, workflows, corpora, docs/sites, and intentional post-v1 deferrals.

Strict next-up queue

For one-issue-at-a-time execution, the immediate queue is:

  1. COMPLETE — optiflow#85 / merged optiflow#86: performance-budget/main repair
  2. COMPLETE — aniflow#11 / merged aniflow#31: provider SDK roadmap reconciliation
  3. COMPLETE — flow#36 / merged flow#37: FLO-3.2b artifact binding and host acceptance
  4. COMPLETE — flow#38 / merged flow#39: FLO-3.2c package/executable integrity
  5. COMPLETE — flow#40 / merged flow#41: FLO-3.2d authority/isolation profiles
  6. COMPLETE — flow#42 / merged flow#43: FLO-3.2e bounded process runner
  7. COMPLETE — Close Flow [FLO-3.2] Specify external process transport and provider trust boundaries #25
  8. NEXT — Flow [FLO-13.2] Build the hermetic orchestration provider kit #29
  9. Flow [FLO-13.3] Prove compatibility, artifact, and provider-failure scenarios #30
  10. NEW Flow FLO-3.3 durable state
  11. Flow [FLO-13.4] Prove interruption, retry, resume, and authority state transitions #31
  12. Renderflow #406
  13. Aniflow feat: freeze the federated extension contract #8
  14. Aniflow Build cross-tool orchestration and failure fixture suites #13
  15. Renderflow #397
  16. Provider v1-hardening issues and corpora from Waves 3–4
  17. Provider integration-candidate releases
  18. Flow real adapters and Implement a versioned cross-holon orchestration vertical slice #3 closeout
  19. Flow [FLO-13.5] Prove the static publication workflow with released providers #32 → [FLO-13.6] Prove the temporal release workflow with released providers #33 → [FLO-13.7] Add clean-room compatibility, CI tiers, and regression promotion #34 → [Publication] Orchestrate exhaustive comic finalization and multilingual release workflows #10
  20. Renderflow remaining profiles and #367 closeout
  21. Flow observability [FLO-OBS-01] Define the suite observability, privacy, and stream contract #15 → [FLO-OBS-08] Add accessible branded root-help presentation #22 and [EPIC] Establish suite-wide observability and CLI experience #14 closeout
  22. ADR convergence when externally unblocked
  23. Aniflow [FLO-OBS-03] Prove opt-in OpenTelemetry logs, metrics, and traces #17 → Optiflow test(flow): prove compatibility and provider acceptance scenarios #61 → Renderflow #409 → Flow [Audit] Post-roadmap repository, backlog, and Identity audit #12
  24. Audit remediation, final releases, then Flow [EPIC] Finish the flow suite and prove production-ready orchestration #11 closeout

Issue creation needed

The live issue set does not yet represent every bounded step needed to reach the documented finish line. Create these before implementation, duplicate-checking first.

Proposed issue Repository/parent Why it is needed
optiflow#85: Restore deterministic cold-discovery performance evidence Optiflow Completed as Step 1 through merged PR #86; all six workflows are green on current main.
FLO-3.2b artifact binding and host acceptance Flow #25 Completed through merged PR #37; merged-main CI is green.
FLO-3.2c package and executable integrity Flow #25 Completed through merged PR #39; merged-main CI is green.
FLO-3.2d authority and isolation profiles Flow #25 Completed through merged PR #41 with green merged-main CI.
FLO-3.2e bounded process runner Flow #25 Completed through merged PR #43 with green merged-main CI; parent #25 is closed.
FLO-3.3 durable plan/run/checkpoint state Flow #3 Required by Flow #31 and deterministic resume.
FLO-3.4 released Aniflow adapter Flow #3 Real temporal provider boundary.
FLO-3.5 released Optiflow adapter Flow #3 Real inspection/planning provider boundary.
FLO-3.6 released Renderflow adapter Flow #3 Real static derivative provider boundary.
FLO-3.7 product CLI and vertical-slice closeout Flow #3 Turns the library seam into a supported product experience.
Stream-aware temporal correctness Aniflow roadmap Already documented v1 work but lacks an open issue.
Layered validation and evidence-rich delivery Aniflow roadmap Already documented v1 work but lacks an open issue.
Content-addressed reuse and operational controls Aniflow roadmap Already documented v1 work but lacks an open issue.
Publish the first verified Renderflow release Renderflow roadmap README promises packages/releases but no GitHub release exists.
Publish/freeze the current Optiflow read-only v1 scope Optiflow roadmap Current source is ahead of v0.1.0; mutation must not become an implicit blocker.
Flow release hardening and first immutable release Flow #11 Flow has no release and publish = false.
Enforce suite default-branch rulesets and required checks egohygiene/.github, linked by Flow #11 All four main branches currently lack branch protection/rulesets.

Current open-issue disposition

Every open issue is represented below so none disappears between the live backlog and the ordered plan.

Flow — 21 open issues

Issue Disposition
#3 Waves 2 and 6; decompose, implement real adapters/CLI, then close.
#9 Wave 8; externally gated ADR convergence.
#10 Wave 6 after static proof and Renderflow #406.
#11 Suite umbrella; refresh now, close last.
#12 Wave 9; final suite audit after all provider audits.
#13 Parent for #29–#34; close after #34.
#14 Observability parent; close after #15–#22.
#15 Wave 7.1.
#16 Wave 7.2.
#17 Wave 7.3.
#18 Wave 7.4.
#19 Wave 7.5; conditional on #18.
#20 Wave 7.6.
#21 Wave 7.7.
#22 Wave 7.8.
#29 Wave 2.1 after #25.
#30 Wave 2.2 after #29.
#31 Wave 2.4 after durable state and #30.
#32 Wave 6.6 after released providers and #31.
#33 Wave 6.7 after released providers and #31.
#34 Wave 6.8 final fixture/CI gate.

Renderflow — 11 open issues

Issue Disposition
#349 Wave 4 after Aniflow audio evidence.
#350 Wave 4.6.
#367 Product umbrella; refresh now, close after profiles + Flow proof + release.
#378 Wave 4.5 before #379.
#379 Wave 4.5 after #378.
#397 Wave 3 after Aniflow #8/#13.
#405 Wave 8; externally gated ADR convergence.
#406 Wave 3 first provider capability.
#409 Wave 9 provider audit.
#412 Wave 4; split into bounded corpus children.
#413 Wave 4 after the applicable #406/#412 foundations.

Optiflow — 3 open issues

Issue Disposition
#60 Wave 8; externally gated ADR convergence.
#61 Wave 9 provider audit.
#65 Wave 4 deterministic adversarial corpus.

Aniflow — 6 open issues

Issue Disposition
#8 Wave 3 Demucs capability.
#10 Wave 5 release after Egolint #29.
#13 Wave 3 audio/lyrics/MIDI evidence.
#14 Wave 8; externally gated ADR convergence.
#17 Wave 9 provider audit.
#24 Wave 4 deterministic temporal-media corpus.

Explicit post-v1 lanes

The following work remains valid but should not silently expand the completion gate:

  • Optiflow transactional duplicate application, quarantine/restore, permanent deletion, lossless candidate production, and source replacement.
  • Optiflow broad image/audio/video optimization profiles beyond the stable read-only evidence boundary.
  • Distributed/remote Flow execution, hardware-aware scheduling, and hosted orchestration.
  • Aniflow arbitrary temporal DAGs, remote providers, and real-time processing.
  • Renderflow managed services, marketplaces, and enterprise controls.

Move each surviving item to a named post-v1 milestone with an explicit owner and rationale. “Deferred” must remain visible; it must not mean forgotten or implied as shipped.

Final definition of done

  • All four current default branches are protected and required validation is reproducibly green.
  • Each tool installs and runs independently from an immutable stable release artifact.
  • Public schemas, CLI behavior, exit semantics, provider contracts, and compatibility rules are versioned.
  • Flow proves real multi-holon discovery, planning, execution, validation, explanation, interruption, retry, and deterministic resume.
  • Static-publication and temporal-media workflows pass clean-room positive and negative suites.
  • Provider and Flow corpora are deterministic, redistribution-safe, generator-first, and tiered by cost.
  • Manifests retain content digests, exact tool/provider versions, configuration/authority identities, provenance, diagnostics, validation, and partial/unavailable outcomes.
  • Telemetry remains optional, privacy-safe, and non-authoritative.
  • Documentation, sites, release metadata, READMEs, CLI help, and observed binaries agree.
  • ADR ledgers are converged once their shared external platform is actually ready.
  • Identity, accessibility, security, licensing, recovery, and rollback pass provider-first audits and the final Flow audit.
  • Every issue named here is closed with evidence, superseded with evidence, or assigned deliberately to a named post-v1 milestone.
  • The final Flow [EPIC] Finish the flow suite and prove production-ready orchestration #11 completion report links exact commits, releases, workflows, fixtures, compatibility tables, and intentional deferrals.

Music-video workflow extension — 2026-09-27

Aniflow #35 captures the observed selective-repair → resumable-upscale → verified-delivery workflow. Focused gaps are #36 existing frame import/selective repair, #37 bounded Upscayl recovery, #38 optional toolchain profiles, and #39 a prototype-first invisible-watermark evaluation.

These consume the existing Aniflow #32/#33/#34/#13/#24/#10 foundations and preserve the current execution order. They are not new implicit release blockers. #39 requires a separate short-clip experiment and actual quality/effectiveness evidence before optional provider integration; it does not block ordinary delivery. Broader synthetic test-video work is being planned separately and should coordinate through Aniflow #24 rather than duplicate its corpus. Cross-artifact publication hygiene remains Renderflow #361; Flow consumes released providers via #51.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions