Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .githooks/pre-push
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
#!/bin/sh
# FinWiki pre-push gate. Blocks a push unless the same required verification
# pipeline used by pull requests, GitHub Pages, and Vercel passes locally.
# pipeline used by pull requests and GitHub Pages passes locally.
#
# bun run verify
#
Expand Down
2 changes: 0 additions & 2 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -6,9 +6,7 @@ __pycache__/
# 人類版サイトのビルド成果物は git に入れない(GitHub Actions が CI で生成・配信)
/app/
/_site/
/_vercel_public/
/audit-artifacts/
.vercel/
site/dist/

# loopcoder のローカル成果物(conductor 設定と実行状態。公開ビルドへ含めない)
Expand Down
2 changes: 1 addition & 1 deletion docs/03-requirements/nfr.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

| ID | Category | Requirement | Validation |
|---|---|---|---|
| NFR-001 | Build reliability | 同一 release gate 必须以固定 Bun 与 frozen lockfile 在 local pre-push、pull request、GitHub Pages、Vercel 可重复运行,失败要指出具体 gate。 | `bun run verify` locally and as required `Required verification` PR check |
| NFR-001 | Build reliability | 同一 release gate 必须以固定 Bun 与 frozen lockfile 在 local pre-push、pull request、GitHub Pages 可重复运行,失败要指出具体 gate。 | `bun run verify` locally and as required `Required verification` PR check |
| NFR-002 | Link integrity | Dead wikilink、missing peer、canonical drift 不得进入发布。 | `bun tools/wiki_link_audit.ts --fail-on-issues` |
| NFR-003 | Public information safety | 不得包含密钥、隐私、客户信息、非公开对话。 | 人工 QA + targeted grep |
| NFR-004 | Corpus/discovery separation | `docs/` 不得作为 corpus page、site route、sitemap URL、llms item、ai-index entry/source、API entry 出现;README/CHANGELOG/release note 可公开描述 docs 变更,但生成器不得把 `docs/` markdown links 暴露给 AI surface。 | release gate + surface 抽查 |
Expand Down
4 changes: 2 additions & 2 deletions docs/03-requirements/rtm.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@
| PRD-007 | [PRD](../02-product/prd.md) | `README.md`, `CHANGELOG.md`, `releases/` | `bun run release:docs`, `release.ts --check --strict` | release note |
| PRD-008 | [PRD](../02-product/prd.md) | [Model-Agent Workflow](../06-implementation/model-agent-workflow.md), [User Journeys](../02-product/user-journeys.md) | role contract review | release note |
| PRD-009 | [PRD](../02-product/prd.md), [UI/UX Principles](../02-product/ui-ux-principles.md) current approved baseline | [UI/UX Functional Spec](../05-functional-specs/ui-ux.md), [Theme System](../04-architecture/theme-system.md), `site/src/` UI surfaces | visual QA + site build when UI changes | release note |
| NFR-001 | [NFR](nfr.md) | `.bun-version`, `tools/verify.ts`, executable pre-push, required/deploy/Vercel workflows, main protection | `bun run verify` + `Required verification` + repository-rule evidence | release note |
| NFR-001 | [NFR](nfr.md) | `.bun-version`, `tools/verify.ts`, executable pre-push, required/deploy workflows, main protection | `bun run verify` + `Required verification` + repository-rule evidence | release note |
| NFR-002 | [NFR](nfr.md) | `tools/wiki_link_audit.ts` | `--fail-on-issues` | release note |
| NFR-003 | [NFR](nfr.md) | `AGENTS.md`, QA docs | manual review | release note |
| NFR-004 | [NFR](nfr.md) | `lib/markdown_helpers.ts`, `tools/wiki_link_audit.ts`, `site/` allowlist | surface grep | release note |
Expand All @@ -30,7 +30,7 @@
| NFR-011 | [NFR](nfr.md) | [Code/Docs Alignment Audit](../07-quality/code-doc-alignment-audit.md), [Next Development Plan](../01-strategy/next-development-plan.md) | stale-code-doc scan + docs link check | release note |
| NFR-012 | [NFR](nfr.md) | [Visual QA Checklist](../07-quality/visual-qa-checklist.md), [Theme System](../04-architecture/theme-system.md) | visual QA + responsive spot checks | release note |
| NFR-013 | [NFR](nfr.md) | [Documentation Drift Audit](../07-quality/documentation-drift-audit.md), [Documentation System](../00-governance/documentation-system.md), `tools/generate_ai_discovery.ts` | docs drift scan + surface grep + strict release check | release note |
| NFR-014 | [NFR](nfr.md) | `tools/assemble_static_publish.ts`, generated public manifests, deploy/Vercel pipelines | `bun run publish:test` + assembled-output inspection | release note |
| NFR-014 | [NFR](nfr.md) | `tools/assemble_static_publish.ts`, generated public manifests, the GitHub Pages deploy pipeline | `bun run publish:test` + assembled-output inspection | release note |
| NFR-015 | [NFR](nfr.md) | `tools/audit_runner.ts`, shared walk exclusions, truthfulness workflow, static publisher | `bun test tools/audit_artifact_isolation.test.ts` + strict release/surface checks | release note |
| NFR-016 | [NFR](nfr.md) | `lib/markdown_helpers.ts`, discovery generator/audits, `tools/verify.ts`, canonical verification/deploy workflows | `bun run surface:drift` + `bun test tools/discovery_routes.test.ts` + `bun run verify --out _site` | release note |
| NFR-017 | [NFR](nfr.md) | `tools/audit_runner.ts`, `.github/workflows/truthfulness-audit.yml`, historical summary fixtures | `bun test tools/audit_runner.test.ts` + historical `bun run audit:all` + workflow YAML parse | release note |
Expand Down
2 changes: 1 addition & 1 deletion docs/04-architecture/ai-discovery-architecture.md
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ After Astro and Pagefind output is assembled, `tools/txt_route_audit.ts`
reads those assembled surfaces, collects route-bearing internal URLs from
llms, sitemap, index and all API records, and
requires each one to resolve to a non-empty, non-symlink regular file in the
final `_site` or `_vercel_public` tree. Source-repository existence alone is not
final `_site` tree. Source-repository existence alone is not
route evidence. Same-host values are collected by hostname, then required to
match the exact `SITE_URL` origin; a wrong scheme or port is a blocking finding.

Expand Down
4 changes: 2 additions & 2 deletions docs/04-architecture/ard.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,15 +28,15 @@
2. Release tooling builds entries, counts, sitemap, llms files, ai-index and API outputs.
3. Astro site reads source content and i18n mirrors through explicit allowlists.
4. Validation runs link audit, count sync, JSON/LF/duplicate checks and static-publish boundary tests.
5. Static assembly overlays generated-manifest-approved raw wiki / AI files onto `site/dist` in `_site` or `_vercel_public`.
5. Static assembly overlays generated-manifest-approved raw wiki / AI files onto `site/dist` in `_site`.
6. Push to `origin/main` triggers GitHub Actions deployment.

## Constraints

- `docs/` must remain excluded.
- AI discovery output must not expose `docs/` as crawlable markdown links.
- Static assembly must not copy `docs/`, `lib/`, tooling, development config, hidden/ignored files or unknown root files.
- Recursive output cleanup is restricted to the direct-child build directories `_site` and `_vercel_public`; symlink output targets are rejected.
- Recursive output cleanup is restricted to the direct-child build directory `_site`; symlink output targets are rejected.
- New domain directories require explicit site and audit allowlist updates.
- Release note additions change corpus `md` count.
- `source_hash` must not be casually rewritten to hide stale translations.
Expand Down
6 changes: 3 additions & 3 deletions docs/04-architecture/astro-5-to-7-upgrade-plan.md
Original file line number Diff line number Diff line change
Expand Up @@ -27,8 +27,8 @@ Historical target: upgrade the FinWiki Astro site from the then-locked Astro 5.1
| Content collections | `site/src/content.config.ts` uses `glob()` from `astro/loaders` over the root corpus and i18n mirrors. | Already on the Content Layer API, but the Zod import must move from `astro:content` to `astro/zod` for v6. |
| Entry rendering | `site/src/pages/[lang]/[...slug].astro` imports `render` from `astro:content` and calls `render(tr ?? entry)`. | Already uses the new rendering form required after legacy collection removal. |
| Entry IDs | `site/src/lib/routes.ts` derives routes from `entry.id`. | Already avoids `entry.slug`. |
| Build path | GitHub Pages workflow runs `bun run wiki:audit:ci`, then `cd site && bun install`, `bun run build`, `bun run index:search`, and publish assembly. Vercel runs root `bun run vercel:build`. | The implementation issue must validate both site-local and root release/audit wrappers. |
| Node/Bun | Local `node -v` is `v24.15.0`; local `bun -e "process.versions.node"` reports `24.3.0`; the issue states Vercel uses Node 24.x; GitHub Actions uses `oven-sh/setup-bun@v2` with latest Bun. | Satisfies Astro v6's Node >=22.12 floor, but CI logs should still be checked because the workflows do not pin Node explicitly. |
| Build path | GitHub Pages workflow runs `bun run wiki:audit:ci`, then `cd site && bun install`, `bun run build`, `bun run index:search`, and publish assembly. GitHub Pages is the only deploy target since the Vercel decommission. | The implementation issue must validate both site-local and root release/audit wrappers. |
| Node/Bun | Local `node -v` is `v24.15.0`; local `bun -e "process.versions.node"` reports `24.3.0`; GitHub Actions uses `oven-sh/setup-bun@v2` with latest Bun. | Satisfies Astro v6's Node >=22.12 floor, but CI logs should still be checked because the workflows do not pin Node explicitly. |

## Recommended Staging

Expand Down Expand Up @@ -100,7 +100,7 @@ Do not port these plugins to Satteri in the first v7 upgrade. A Satteri port can

| v6 change | Applies to FinWiki? | Required later implementation action |
|---|---|---|
| Node 22.12 minimum | Yes, environment requirement. | Confirm CI/Vercel logs show Node/Bun compatibility at or above Node 22.12. Current local Node 24.15.0, Bun Node compatibility 24.3.0, issue-stated Vercel 24.x, and current Actions setup satisfy the floor. |
| Node 22.12 minimum | Yes, environment requirement. | Confirm CI logs show Node/Bun compatibility at or above Node 22.12. Current local Node 24.15.0, Bun Node compatibility 24.3.0, and the current Actions setup satisfy the floor. |
| Vite 7 | Low risk. No Vite config or Vite plugins found. | Let Astro dependency resolution move Vite. Run build and inspect any Vite deprecation output. |
| Vite Environment API | Low risk. Local integrations use `astro:build:done` but do not use Vite internals or HMR. | Confirm `localizeWikilinks()` and `responsiveTableHtmlRepair()` still receive `dir` and run after build. |
| Zod 4 | Yes. `site/src/content.config.ts` imports `z` from `astro:content`. | Change to `import { z } from 'astro/zod'` and keep `defineCollection` from `astro:content`. Re-run `astro check` or build to confirm schema inference. |
Expand Down
5 changes: 2 additions & 3 deletions docs/04-architecture/astro-site-architecture.md
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,7 @@ The final deployment directory is not a copy of the repository root. Assembly ha

The raw allowlist includes the selected reader-facing root documents, domain Markdown, release notes, root AI discovery files and indexed API JSON. It excludes `AGENTS.md`, `docs/`, `lib/`, `tools/`, package/deployment configuration, dotfiles and unknown root files even if a generated manifest names them. The assembler creates `.nojekyll` itself as the one required hidden deployment marker.

Only the direct-child outputs `_site` and `_vercel_public` are accepted. Repo-root, parent, arbitrary, nested and symlink targets fail before the assembler performs recursive cleanup. Astro output wins if a raw path collides with an already built site file.
Only the direct-child output `_site` is accepted. Repo-root, parent, arbitrary, nested and symlink targets fail before the assembler performs recursive cleanup. Astro output wins if a raw path collides with an already built site file.

## i18n Rendering

Expand Down Expand Up @@ -89,11 +89,10 @@ bun tools/check_duplicate_html_ids.ts site/dist

For UI/CSS/theme/layout changes, also use [Visual QA Checklist](../07-quality/visual-qa-checklist.md).

The root Vercel/GitHub Pages canonical verification wrapper is:
The root GitHub Pages canonical verification wrapper is:

```bash
bun run verify
bun run verify --out _site
```

## Current Gaps For Next Development
Expand Down
2 changes: 1 addition & 1 deletion docs/05-functional-specs/ai-discovery-surface.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@

- `lib/markdown_helpers.ts` owns route construction, raw/GitHub fallback selection, wikilink route resolution and Git-first `last_modified`. Git subprocesses clear inherited repository-addressing variables such as `GIT_DIR`, `GIT_WORK_TREE` and `GIT_INDEX_FILE` so an explicit source path remains authoritative inside hooks.
- `tools/generate_ai_discovery.ts` reads the shared corpus walk plus `INDEX.md`, then writes the outputs above. `--generated-at` and `--api-index-generated-at` are deterministic comparison inputs, not author-facing content fields.
- `tools/generated_surface_drift_scan.ts` owns read-only corpus/API alignment, excluded-path checks and fixed-timestamp exact regeneration. `tools/txt_route_audit.ts` owns final-route validation against the assembled copies in `_site` or `_vercel_public`, ignores source-preserving `markdown_links`, audits same-host API `external_links`, and rejects same-host URLs whose scheme or port changes the expected origin.
- `tools/generated_surface_drift_scan.ts` owns read-only corpus/API alignment, excluded-path checks and fixed-timestamp exact regeneration. `tools/txt_route_audit.ts` owns final-route validation against the assembled copies in `_site`, ignores source-preserving `markdown_links`, audits same-host API `external_links`, and rejects same-host URLs whose scheme or port changes the expected origin.

## Generation

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,7 @@ Keep `llms.txt` compact. Improvements should be structural, not verbose:

| Option | Benefit | Cost / risk | Decision |
|---|---|---|---|
| Static JSON enrichment | Works on GitHub Pages / Vercel static hosting, no auth, easy diff review. | Full generated diff when schema changes. | Do first. |
| Static JSON enrichment | Works on GitHub Pages and any other static host, no auth, easy diff review. | Full generated diff when schema changes. | Do first. |
| Client-side query library over static JSON | No server; could power future human/agent filters. | Adds bundle/runtime complexity. | Consider after static schema stabilizes. |
| Hosted API endpoint | Flexible filtering and smaller client downloads. | Requires deployment/runtime contract and monitoring. | Defer. |
| MCP server | Agent-native querying and tool semantics. | New operational surface; not needed until graph data is richer. | Defer; write a separate issue only if static files are insufficient. |
Expand Down
15 changes: 9 additions & 6 deletions docs/05-functional-specs/release-gate.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,10 +4,13 @@

```bash
bun tools/release.ts --write # when the public snapshot needs regeneration
bun run verify # canonical local / PR / Vercel gate
bun run verify --out _site # canonical GitHub Pages artifact
bun run verify # canonical local / PR / GitHub Pages gate
```

`_site` is the default and only approved output, so the canonical command
already produces the GitHub Pages artifact. `--out _site` remains accepted and
is what `deploy.yml` passes explicitly.

The runtime must exactly match `.bun-version`. `bun run verify` installs `site/` with `--frozen-lockfile`, fails fast, and is the only command that establishes release readiness. Individual commands remain available for diagnosis but cannot substitute for the canonical gate.

## Release-document contract
Expand All @@ -32,7 +35,7 @@ After Astro, Pagefind and static assembly, the runner executes `bun run ai:audit

The canonical command runs all Bun tests, including the destructive/public-file boundary tests and required-route negative fixtures, before assembling the real artifact:

- only `_site` and `_vercel_public` are valid output directories;
- `_site` is the only valid output directory;
- output validation and symlink rejection happen before recursive cleanup;
- the result contains `site/dist` plus raw source paths selected by `ai-index.json` and `api/entries/index.json`, then filtered by explicit root/domain/release/API allowlists;
- `docs/`, `lib/`, tooling, development configuration, hidden/ignored source files, unmanifested domain/API files and unknown root files remain absent; the assembler-created `.nojekyll` marker is the only hidden output exception.
Expand All @@ -44,9 +47,9 @@ The required-route check remains a release smoke gate. The separate final-HTML r

- `.githooks/pre-push` is tracked executable and runs `bun run verify`.
- `.github/workflows/required-verification.yml` exposes the stable `Required verification` pull-request context.
- GitHub Pages runs `bun run verify --out _site`.
- GitHub Pages runs `bun run verify --out _site`, which is the same target the bare command uses.
- Both canonical GitHub workflows checkout with `fetch-depth: 0`, so Git-first `last_modified` uses full history rather than a shallow HEAD.
- Vercel invokes the same `tools/verify.ts` runner for `_vercel_public` through the official exact-build pin pattern `bunx bun@<version>`; startup rejects drift from `.bun-version` and `packageManager`.
- Runner startup rejects drift from `.bun-version` and `packageManager`.
- Every Actions workflow reads the same `.bun-version`; every dependency installation uses the committed frozen site lockfile.

## Failure Handling
Expand All @@ -59,7 +62,7 @@ The required-route check remains a release smoke gate. The separate final-HTML r
- Generated-route failure: fix URL construction or assembly, regenerate, rebuild and rerun `bun run ai:audit --out <approved-output>`; do not replace localized HTML canonicals with extensionless raw paths.
- Final-HTML href failure: inspect the reported source HTML, element, original `href`, resolved URL and filesystem reason; repair the route or source link, rebuild and rerun `bun run html:routes --out <approved-output>`.
- Docs/development-file leakage: verify corpus exclusions, site allowlists, generated manifests and the static-publish allowlist.
- Unsafe publish output: use `_site` or `_vercel_public`; never relax output validation to make a local command pass.
- Unsafe publish output: use `_site`; never relax output validation to make a local command pass.
- Missing required final route: inspect assembly and Pagefind output; do not remove a required route to make the check pass.
- Bun mismatch: install the exact `.bun-version`; do not update the pin without a separate dependency/runtime review.
- Stale API residue: verify discovery generation clears `api/entries/` before writing current entries.
Expand Down
6 changes: 3 additions & 3 deletions docs/06-implementation/toolchain.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,10 +4,10 @@

## tools/verify.ts(统一必需门禁)

`tools/verify.ts` 是 local pre-push、pull request、GitHub Pages 与 Vercel 共同使用的 canonical runner;local command 是 `bun run verify`。它先拒绝 `.bun-version`、`packageManager`、Vercel pin 或 runtime mismatch,以 frozen lockfile 安装 `site/` dependencies,再依次执行 release / docs / generated-surface exact regeneration / strict i18n / index / wiki / dependency / typecheck / tests / Astro / duplicate-ID / Pagefind / assembly / required-route / final-HTML-href / generated-route / diff gates。任何一步 non-zero 都立即阻断。
`tools/verify.ts` 是 local pre-push、pull request 与 GitHub Pages 共同使用的 canonical runner;local command 是 `bun run verify`。它先拒绝 `.bun-version`、`packageManager` 或 runtime mismatch,以 frozen lockfile 安装 `site/` dependencies,再依次执行 release / docs / generated-surface exact regeneration / strict i18n / index / wiki / dependency / typecheck / tests / Astro / duplicate-ID / Pagefind / assembly / required-route / final-HTML-href / generated-route / diff gates。任何一步 non-zero 都立即阻断。

- default output:`_vercel_public`
- Pages parity:`bun run verify --out _site`
- default output:`_site`(唯一 approved output)
- Pages parity:`bun run verify --out _site` 与 bare command 等价
- focused route check:`bun tools/required_publish_routes.ts --out _site`
- final HTML href check:`bun run html:routes --out _site`(必须在 build、Pagefind、assembly 后运行)
- generated route check:`bun run ai:audit --out _site`(必须在 assembly 后运行)
Expand Down
Loading