Program position
Child owner of #445 for R-15 Gate 5 — the largest migration-readiness surface before packaged shadow qualification.
TARGET_RELEASE = v1.30.0
PREDECESSOR = Gate 4 terminal
NO_GAP_INVARIANT = REQUIRED
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO
Objective
Make the packaged desktop's full protected-data universe controllable and migratable with no unfenced writer gap.
Before a class's final migration inventory is captured, every current writer of that class must be routed through an admitted fence-participating adapter, deterministically quiesced/disabled for the migration window, or explicitly refused with truthful recovery behavior. Anything else blocks Gate 5 for that class.
Required protected-class coverage
Re-derive from live §3 inventory. At minimum disposition projects/manuscripts, snapshots, settings, images, binder bytes+metadata+asset-pair, Codex, RAG/vector indexes, quarantine/recovery, active-project marker, authority/catalog/epoch/commit metadata, migration journals, packaged WebView/IndexedDB legacy desktop sources, backups per contract boundary, credentials under their approved separate protected authority, and every new protected class added since the contract inventory.
No packaged-desktop PROTECTED class may be silently skipped, treated as harmless plaintext, or left unknown/unmigrated.
Migration proof
capture final fenced inventory
→ convert each admitted source
→ durably write target generation
→ verify envelope/AAD/digest/identity
→ update authenticated catalog/markers
→ retain prior recoverable source until target commit proof
→ only then permit cleanup
Acceptance
Prefer multiple small PRs grouped by coherent data families. Do not force this gate into one oversized PR.
Program position
Child owner of #445 for R-15 Gate 5 — the largest migration-readiness surface before packaged shadow qualification.
Objective
Make the packaged desktop's full protected-data universe controllable and migratable with no unfenced writer gap.
Before a class's final migration inventory is captured, every current writer of that class must be routed through an admitted fence-participating adapter, deterministically quiesced/disabled for the migration window, or explicitly refused with truthful recovery behavior. Anything else blocks Gate 5 for that class.
Required protected-class coverage
Re-derive from live §3 inventory. At minimum disposition projects/manuscripts, snapshots, settings, images, binder bytes+metadata+asset-pair, Codex, RAG/vector indexes, quarantine/recovery, active-project marker, authority/catalog/epoch/commit metadata, migration journals, packaged WebView/IndexedDB legacy desktop sources, backups per contract boundary, credentials under their approved separate protected authority, and every new protected class added since the contract inventory.
No packaged-desktop PROTECTED class may be silently skipped, treated as harmless plaintext, or left unknown/unmigrated.
Migration proof
Acceptance
Prefer multiple small PRs grouped by coherent data families. Do not force this gate into one oversized PR.