3.7 KiB
3.7 KiB
P1.1 manual acceptance
This walkthrough is the separate human gate for the P1.1 workspace-directory registry.
It is independent from both .artifacts/p1-integration/** and .artifacts/p11-integration/**.
The helper prepares and serves the lab, but the reviewer performs the registry, Git, UI, export,
render, tht, refusal, secret-scan, and cleanup checks and records the verdict.
Prerequisites
- clean repository checkout with the P1.1 implementation present;
node,npm,git,curl, andpython3available;- built production assets:
npm --prefix backend run build
npm --prefix frontend run build
- executable harness CLI at
harness/.venv/bin/tht; - free loopback ports
127.0.0.1:8791and127.0.0.1:8792.
Lifecycle commands
Run from the repository root:
./scripts/p11-manual-acceptance.sh prepare
./scripts/p11-manual-acceptance.sh serve
./scripts/p11-manual-acceptance.sh stop
./scripts/p11-manual-acceptance.sh cleanup
The fixed lab root is:
.artifacts/manual-acceptance/p11/
Expected lifecycle behavior:
preparecreates the fixed root, ownership record, bare remote, curator clone, root catalog, nested filesystem evidence, fixture secrets, request fixtures, generated command scripts, andGUIDE.md; it leaves statusPENDING, performs no reviewer publish operation, and never writesVERDICT.md.servestarts the production backend on127.0.0.1:8791and a production-built frontend preview on127.0.0.1:8792, recording exact ownership for both.stoprefuses foreign or partial ownership and stops only the two owned loopback processes.cleanuprefuses live state and removes only.artifacts/manual-acceptance/p11/.
Reviewer workflow
After prepare, open the generated .artifacts/manual-acceptance/p11/GUIDE.md and personally:
- inspect the catalog, nested descriptor/evidence layout, ownership, and secret-path bindings;
- serve both surfaces and verify the owned listeners;
- list
configuration_requiredslots; - validate and bootstrap-create descriptors exactly once;
- inspect catalog/descriptor/evidence/docs Git object IDs;
- retry create/update/delete and verify refusal plus unchanged object IDs;
- make a curator descriptor+catalog edit, push, pull, and verify the API did not rewrite curator bytes;
- make an evidence-only commit and inspect the new revision identity;
- verify the live UI shows read-only existing workspaces and bootstrap-only editing for missing slots;
- exercise export/import under bootstrap-only rules;
- render twice, diff the results, and run
tht config check; - run negative catalog/path/secret cases and a bounded secret scan;
- stop the lab, verify both listeners are gone, write
VERDICT.md, and only then cleanup if desired.
Expected outcomes
prepareproduces a fresh P1.1-only lab and leaves noVERDICT.md.serveexposes only the owned loopback backend and frontend preview.- positive API operations succeed once; curator-owned follow-up mutations are refused safely;
- curator Git changes become active only after pull;
- renders are deterministic;
tht config check -c <file>succeeds; - secret scans find no canaries outside the fixture-secret boundary;
- after
stop, nothing remains listening on127.0.0.1:8791or127.0.0.1:8792.
Verdict format
The reviewer creates VERDICT.md manually. Include:
- reviewer identity;
- UTC timestamp;
- result for each checklist step;
- observations and failure evidence;
- exactly one final line:
manual acceptance: PASSormanual acceptance: FAIL.
Passing bash scripts/test-p11-manual-acceptance.sh proves only the tooling/lifecycle guards. It
does not perform or approve manual acceptance.