Skip to content

Enforce the MVP acceptance, performance, accessibility, and security gate #16

Description

@codeacme17

Tracks #1.

Summary

Build and enforce the complete MVP acceptance, performance, accessibility, compatibility, and security release gate across standalone and Codex-hosted surfaces.

Scope

  • Encode AC-01 through AC-24 as traceable automated tests where feasible, with explicit manual checks only where host/macOS behavior requires them.
  • Build the supported-scale fixture: 25 active Worktrees, unavailable diagnostics, 2,000 Changed Files, and 5,000 refs.
  • Gate shell ≤1 second, selected ordinary Worktree ≤2 seconds, full supported snapshot ≤5 seconds, visible external change ≤2 seconds, and loaded UI interactions ≤100 ms on the documented reference machine.
  • Verify 2 MiB/20,000-line diff degradation without UI freeze.
  • Complete keyboard, visible-focus, target-specific accessible-name, live status, non-color, and focus-retention coverage.
  • Add Codex Host Adapter compatibility matrix/smoke automation and standalone parity checks.
  • Perform threat tests for loopback binding, token/origin validation, iframe capabilities, message generation, path/ref injection, process spawning, and diagnostic redaction.
  • Run multi-process race, external lock, disappearing Worktree, and UnknownOutcome recovery tests.
  • Publish a release checklist mapping every acceptance scenario to evidence.

Acceptance criteria

  • Every AC-01 through AC-24 row has passing evidence or the MVP cannot release.
  • Timing measurements are reproducible and record hardware, macOS, Git, Node, and Codex versions.
  • No accessibility requirement relies on color alone or mouse-only interaction.
  • No security fixture secret appears in logs, UI errors, or test artifacts.
  • Standalone and supported Codex-hosted paths expose the same Git product behavior.
  • A Codex compatibility failure degrades to the standalone surface without corrupting native UI state.

Out of scope

  • New product capabilities or performance work beyond the documented MVP envelope.

Dependencies

PRD coverage

  • AC-01–24 and all non-functional requirements.

Verification

  • The release gate itself is the verification; archive the matrix and benchmark results as CI artifacts.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P1Core reachable product behavior required for the MVPaccessibilityBarrier affecting people with disabilitiesenhancementNew feature or request

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions