# I1 Lane D — Web UI Progress

## Baseline and ownership

- Branch: `impl/i1-d-ui`
- Worktree: `/home/user/Projects/awp-i1-d-ui`
- Current base after FIRE-evidence convergence rebase: `89d5300` (`docs(evidence): land Overdeck FIRE learning corpus`)
- Landed C1 implementation commit beneath that base: `08276e7`
- C0 implementation baseline: `114b57a4ad37f9178b9c6309497c39663d4580e9`
- Stable C1 domain/read-model signal supplied to the lane: `fa6c7d95fbef9194fb9b3b90767b347f87dc11b6`
- Owned paths: `apps/web/**`, `packages/ui-awp/**` if required, `tests/ui/**`, `tests/e2e/ui/**`, this progress file.
- No canonical domain/application/persistence contract was modified.

## Completed Lane D work

- Read the complete required finalization, parallel implementation, C0/C1 progress, UI authority and owner-approved U1-U6 visual sources.
- Reproduced the approved dark AWP visual system rather than redesigning it.
- Implemented U1 Project Overview from an exact serialized snapshot of Lane A's deterministic C1 `projectOverviewReadModel`; `UI-C1-001` fails if that snapshot drifts.
- Implemented the C1 Task fixture projection used by Queue/dependency presentation; `UI-C1-002` fails on fixture drift.
- Implemented Queue and dependency graph views with URL-restorable `view`/Task selection and an accessible text relationship representation. Client movement controls are explicitly preview-only; authoritative application legality is never duplicated in the browser.
- Implemented U2 active FactoryRun with concurrent Task/AgentRun presentation, timeline, WIP/checkpoint safety and pending ChangeSet location.
- Implemented U3 waiting and failure/retry states without changing FactoryRun page identity. Waiting, running and failure/recovery are distinct. Retry is represented as a new immutable Attempt and preserved WIP is explicit.
- Implemented U4 changes-requested ChangeSet/Review with exact blocking finding, candidate identity, evidence and provenance.
- Implemented U5 ready-to-merge MergeGate with exact candidate, expected head, Review/evidence status, trusted publication authority and TOCTOU revalidation copy.
- Implemented U6 merged/completed as a read-only terminal result with resulting commit, provenance, dependent-work re-evaluation, cleanup eligibility and explicit separation from later Release/Deployment lifecycle.
- Implemented loading, error, stale/disconnected, permission and applicable empty states.
- Implemented URL-restorable Project tab, FactoryRun tab, Queue view/Task, Review tab/file/finding state.
- Kept Search/Advisor and later-increment controls in approved positions but inert/non-operational.
- Implemented a small compiled HTTP surface for deterministic I1 rendering and future transport integration without weakening the `apps/web -> @awp/contracts only` architecture boundary.
- Implemented responsive behavior down through 390px with non-fixed mobile navigation and no root horizontal overflow in Chromium render proof.
- Implemented keyboard/focus semantics, skip links, named navigation, tables/captions, accessible dependency relationship text and live-region command acknowledgement.

## FIRE convergence

The FIRE corpus landed at `89d5300` and is mandatory input for this lane. Lane D does not copy Overdeck implementation; the UI invariants below are implemented using AWP's read-model/projection architecture.

### Eight urgent cross-lane findings

| Finding | Lane D disposition |
| --- | --- |
| U1 — result collection can lose nested Git/WIP | **not owned by this lane — Lane C + Lane A** (`INV-FIRE-002`, `RT-001`). Lane D only consumes resulting durable WIP facts. |
| U2 — destructive cleanup needs generation fencing + collection proof | **not owned by this lane — Lane C + Lane A** (`INV-FIRE-001/006`, `RT-002/003/030`). |
| U3 — ambiguous publication success reconciles before retry | **not owned by this lane — Lane B + Lane A** (`INV-FIRE-004`, `RT-006/007`). U5 does not claim merge success from request acknowledgement. |
| U4 — mutable credential authority single-writer | **not owned by this lane — Lane B** (`INV-FIRE-005`, `RT-008/009/016`). |
| U5 — process locks/heartbeats are not durable ownership | **not owned by this lane — Lane C + Lane A** (`INV-FIRE-006/007`, `RT-010/011/012`). |
| U6 — UI never implies completion beyond authoritative lifecycle | **implemented — `FIRE-D-RT021`, `FIRE-D-RT023`, `FIRE-D-RT025`, `FIRE-D-RT026`, `FIRE-D-STATE`, `FIRE-D-STALE`, `FIRE-D-U3`**. Lifecycle comes from the data source, not URL/client command state; stale is explicit; history survives missing executor projection; U3 exposes structured failure and preserved-work truth. |
| U7 — exact execution eligibility/runtime identity | **not owned by this lane — Lane C** (`INV-FIRE-008`, `RT-013/014/015/016`). |
| U8 — Task completion is semantic, not process/diff | **not owned by this lane — Lane A + Lane B/C** (`INV-FIRE-019`, `RT-034/035`). Lane D never infers Task completion from process/UI activity. |

### Thirteen proposed I1-blocking FIRE tests

| Blocking test | Required accounting |
| --- | --- |
| RT-001 | **not owned by this lane — Lane C**. |
| RT-002 | **not owned by this lane — Lane C + Lane A**. |
| RT-006 | **not owned by this lane — Lane B + Lane A**. |
| RT-008 | **not owned by this lane — Lane B + Lane A**. |
| RT-010 | **not owned by this lane — Lane A + Lane C**. |
| RT-013 | **not owned by this lane — Lane C**. |
| RT-016 | **not owned by this lane — Lane C + Lane B**. |
| RT-020 | **not owned by this lane — Lane A + Lane C**. Lane D's historical rendering is covered separately by `FIRE-D-RT021`; authoritative restart durability must come from A/C. |
| RT-023 | **implemented + `FIRE-D-RT023`**. Sequence gap/reconnect returns `stale-refetch`; the UI must re-query authority rather than applying the gap as lifecycle truth. |
| RT-025 | **implemented + `FIRE-D-RT025` and `UI-E2E-003`**. URL/client command acknowledgement cannot promote lifecycle; blocked Review has no Merge command. Full provider refusal integration remains an A/B/C convergence test. |
| RT-026 | **requires shared C1 contract change**. Precise request: add an authoritative I1 FactoryRun/Attempt detail read model/transport projection carrying failure class, cause, retry disposition, exact source/candidate identity, Attempt history, WIP/checkpoint safety and explicit unknown/partial semantics. Lane D rendering is implemented and tested by `FIRE-D-RT026`; persistence→application→transport proof cannot be fabricated in this lane. |
| RT-034 | **not owned by this lane — Lane A + Lane B/C**. |
| RT-040 | **not owned by this lane — Lane B + Lane A**. Display truncation is not used for any UI authorization decision. |

### Other FIRE tests applicable to Lane D

| Test | Lane D disposition |
| --- | --- |
| RT-004 browser/client disconnect | **requires shared C1/control-surface integration**: expose durable FactoryRun/AgentRun identity and reattach/continuation result so a browser reconnect can prove it attaches to the same logical work without cancellation/duplication. |
| RT-021 quarantine/history | **implemented + `FIRE-D-RT021`** for UI projection: historical run/failure/WIP evidence remains rendered when `liveExecutorPresent=false`. A/C own durable storage/provider quarantine integration. |
| RT-027 stage deadline | **requires shared C1 contract change**: FactoryRun/AgentRun detail must expose current stage, last-progress timestamp and deadline/typed wait rationale. |
| RT-028 stalled progress | **requires shared C1 contract change**: expose alive-vs-progressing distinction, last meaningful progress and next automatic action. |
| RT-037 resume from another client | **requires shared control-plane API/read model** for continuation/reattach identity and idempotent client retry. |
| RT-038 work discoverability | **requires shared C1 read-model expansion**: non-terminal Work/Task projection must expose owner/agent, state, last activity, blocker, next action and Project/Plan relation. |
| RT-039 human attention classification | **requires shared C1 read-model expansion**: typed attention reason must distinguish transient provider recovery, authorization/permission attention and actual owner Decision/Approval requirements. |

## Lane C final convergence status

- Lane C reports final owned-boundary convergence complete at remote head `920f59e` (`origin/impl/i0-c-execution`).
- As of this check, that head is not yet part of `origin/main`; main remains `89d5300`. Lane D therefore does not rebase onto the unlanded sibling branch.
- Lane C changed provider/infra/preflight paths plus the shared root `pnpm-lock.yaml`; there is no overlap with Lane D-owned `apps/web/**`, `tests/ui/**`, `tests/e2e/ui/**`, or this ledger.
- Lane C's handoff explicitly records that no shared provider contract change was required. Consequently it does not supply the FactoryRun/Attempt, ChangeSet/Review/MergeGate, realtime-envelope, or typed attention/work read-model seams requested below.
- Lane C's implementation/frozen-install/repository gates are green at its owned boundary. Its handoff intentionally keeps three live readiness rows pending/red: gVisor compatibility on the intended cluster, recoverable node interruption/AWP control-plane restart, and a successful repository workflow while the existing collector workflow remains independently red. Lane D does not reinterpret those rows as green.

## Contract gaps / convergence requests

The stable C1 currently exposes `I1ProjectOverviewReadModel` plus a shallow FactoryRun summary (`id`, lifecycle `status`, optional `reason`). It does **not** yet expose authoritative I1 detail projections required to replace the U2-U6 deterministic UI fixtures. Lane D will not invent competing canonical shapes.

Required shared C1 additions for final end-to-end convergence:

1. **FactoryRun detail read model** keyed by durable FactoryRun identity, with Task topology/state, logical AgentRuns, immutable Attempts, exact provider/account/model provenance where authorized, current stage, last meaningful progress, typed waiting/failure cause, retry disposition, WIP/checkpoint safety, and historical availability independent of live executor/resource presence.
2. **ChangeSet/Review/MergeGate detail read model** keyed by immutable ChangeSet/candidate identity, with base/candidate digest, Review disposition/findings, exact evidence freshness/source, target/expected head, protected-action availability/reason, and merged result identity when terminal.
3. **Realtime projection envelope** with durable identity + revision/sequence marker and an authoritative refetch seam. Lane D's gap/reconnect behavior is already implemented by `decideRealtimeUpdate`.
4. **Typed attention/work projection fields** required by FIRE RT-027/028/038/039: owner/current actor, current stage/state, last progress, blocker/wait reason, deadline or human-wait rationale, next automatic/user action, and typed authorization-vs-transient-vs-decision attention reason.

These are shared Lane A/control-plane contract changes; Lane D does not modify them under its ownership rules.

## Screenshots / render evidence

- Chromium 150 render-state evidence: `tests/e2e/ui/evidence/chromium-render-evidence.json`.
- Desktop proofs at 1440x1000: U1 Project, U3 recovery, U5 ready-to-merge.
- Mobile proofs at 390x844: U1 Project and stale U3 recovery.
- Assertions passed: required lifecycle marker visible, no root horizontal overflow, mobile sidebar becomes relative/full-width, `main` and `navigation` accessibility roles exist, and stale U3 protected actions are disabled.
- Chromium's one-shot raster screenshot command hangs on this Debian Chromium build; DevTools Protocol DOM/layout/accessibility rendering is used as deterministic render evidence instead.

## Tests and gates

Focused Lane D gate on Node 22 / pnpm 9.7 (`debian1`):

- `@awp/web` typecheck: PASS.
- `@awp/web` build: PASS.
- `tests/ui/**` + `tests/e2e/ui/**`: 16/16 PASS before final repository pass.
- HTTP compiled-server smoke: U1, U3 recovery, U6 merged: PASS.
- Browser asset smoke covers compiled ES-module `/client.js` plus its compiled `/interaction.js` dependency; the document loads the client with `type="module"`.
- Chromium desktop/mobile render evidence: PASS.

Repository-wide `pnpm check` after FIRE implementation reached and passed:

- workspace typecheck: PASS;
- lint: PASS;
- all tests: 41/41 PASS;
- build: PASS;
- architecture tests: 6/6 PASS;
- dependency-cruiser: 0 violations;
- format check: PASS.

## Blockers

- No remaining Lane D implementation blocker is known.
- Final **cross-lane convergence** is gated on the C1 detail/read-model additions above. Until those land, U2-U6 use deterministic approved fixtures behind the explicit `AwpWebDataSource` seam and must not be described as end-to-end authoritative API integration.

## Exact next task

1. Lane A/integration supplies the shared FactoryRun/Attempt, ChangeSet/Review/MergeGate, realtime-envelope and typed attention/work read-model seams recorded above.
2. Rebase this lane on that convergence commit and replace deterministic U2-U6 fixture transport with the authoritative application/control-plane read models without changing approved UI semantics.
3. Re-run the FIRE/UI/repository gates and push the integration head.

## Latest pushed commit

- Verified Lane D implementation commit pushed to `origin/impl/i1-d-ui`: `ae9e8f52395732ab194972208033ce834583b632`.
- This progress-only metadata closeout is a subsequent commit, so its own hash cannot be embedded in itself; the exact branch HEAD is reported in the lane response and is verifiable with `git rev-parse origin/impl/i1-d-ui`.


## Final authoritative-read-model convergence — 2026-08-21

This section supersedes the earlier contract-gap/blocker sections above. The requested shared I1 read-model convergence landed on `main` in PR #17 as `69c89b6`, and Lane D was rebased onto the then-current `origin/main` before integration.

### Authoritative wiring completed

- `apps/web` now consumes the transport-safe authoritative `I1FactoryRunDetailReadModel` and `I1ChangeSetReviewReadModel` contracts from `@awp/contracts`.
- U2/U3 FactoryRun state is derived from authoritative FactoryRun status, typed wait/failure/retry fields, Task work projections, logical AgentRuns, immutable Attempts, WIP/checkpoint safety, durable continuation identity, and historical availability.
- U4/U5/U6 Review state is derived from authoritative ChangeSet status, immutable candidate manifest/digest, Review disposition/findings, candidate-bound evidence, expected target identity, protected MergeGate conditions/action availability, and terminal merged result identity.
- URL/query state remains navigation/selection only and cannot promote lifecycle state.
- Client command acknowledgement remains non-authoritative. Protected Merge/Retry actions are rendered from server-projected state and are disabled in stale/permission/error surfaces.
- Missing live executor state no longer removes persisted FactoryRun/Attempt/failure/WIP history from the UI.
- The deterministic source remains only a contract-shaped development/render-test source. It implements the exact authoritative transport shapes; it is not a second lifecycle model. Production GOLIVE control-plane transport wiring is now a program-level runtime concern, not a Lane D contract gap.

### FIRE reconciliation after authoritative wiring

- RT-004/RT-037 UI dependency is now expressible through durable `continuation.factoryRunId`, `continuationKey`, and `reattachable`; browser reconnect still requires the program-level live transport/realtime runtime to exercise it end to end.
- RT-021/RT-026 are represented directly by the authoritative FactoryRun detail model: failure class/cause/retry source, immutable Attempt history, WIP safety, historical availability and live-executor presence are distinct fields.
- RT-027/028/038/039 are represented through typed `stage`, `lastProgressAt`, `deadlineAt`, `wait`, `attention`, `nextAction`, current actor/AgentRun and Task state projections.
- RT-023 remains enforced by the realtime sequence-gap/reconnect stale-refetch policy.
- RT-025 remains enforced: URL/client acknowledgement cannot promote Merge/terminal state.

### Final buildbox validation

All build/test work ran on authorized buildbox `debian1` using Node `v22.23.2` / pnpm `9.7.0`; no tests were run on the workstation.

- `CI=true pnpm install --frozen-lockfile`: **PASS**, 17 workspace projects.
- focused web typecheck + UI/E2E Vitest: **PASS**, 4 files / 16 tests.
- aggregate `pnpm check`: **PASS**.
- repository tests: **29 files / 115 tests PASS**.
- architecture tests: **6/6 PASS**.
- dependency-cruiser: **84 modules / 120 dependencies, 0 violations**.
- typecheck, lint, build and Prettier: **PASS**.

### Chromium render evidence after authoritative wiring

A fresh real Chromium/CDP render pass on `debian1` passed for:

- U1 Project desktop 1440x1000;
- U3 recovery desktop 1440x1000;
- U5 ready-to-merge desktop 1440x1000;
- U1 Project mobile 390x844;
- U3 stale/recovery mobile 390x844.

Assertions remained green: required markers present, no root horizontal overflow, mobile sidebar is non-fixed/full-width, `main` + `navigation` accessibility roles exist, and stale protected actions are disabled.

### Lane D terminal boundary

Lane D implementation is now complete at the I1 UI integration boundary. Remaining work belongs to root/program convergence: land this branch through green PR CI, then implement/run the real `GOLIVE.md` acceptance harness against PostgreSQL + control plane + K3s and prove the complete Project → Merge journey.
