# Task 14 report: integrated TechLog parity and release verification ## Status `DONE_WITH_CONCERNS`. The production serving correction, 130-case source-to-target comparison, full recursive product-tree evidence, direct HTTP contract, target visuals, focused browser suites, and static gates pass. The automated Chromium accessibility suite passes 29/29, but the 27 signed human keyboard/focus/screen-reader records remain `PENDING`; `FE-GATE-009` is not claimed as passing. The other concern is the repository's pre-existing restricted-runner `test:all` baseline: 19 provider-environment cases remain red. The isolation and exact counts below prove that no TechLog test is among those failures. The work remains on `feature/techlog-ui-migration`. It was not merged, pushed, finished with GitFlow, or deleted. The immutable code candidate is `3a7c5deca06679fb9b8710da2cce87bbca07ce8a` (`fix: complete TechLog migration evidence`). This report and the durable parity JSON are deliberately recorded afterward in `docs: record TechLog migration evidence`, so the evidence can name the exact candidate it verifies. ## Evidence files Added or replaced product evidence: - `tests/visual/tech-log.visual.spec.ts` and 129 target-only PNG snapshots. The suite has 130 cases because canonical and state coverage for the 1440-pixel `/studio/publications` screen deliberately share the same reviewed image. - `scripts/lib/tech-log-production-server.ts`, the generated self-contained `dist/server.mjs` build artifact, its serving contract/generator, and 39-case direct HTTP regression coverage. - `tests/e2e/tech-log-public-discovery.spec.ts`, `tests/e2e/tech-log-accessibility.spec.ts`, and `tests/e2e/tech-log-responsive.spec.ts`. - `tests/support/browser/tech-log-fixtures.ts`, the checked Node 24 parity runner, and durable `docs/operations/evidence/tech-log-source-parity.json` evidence. - Focused regressions in `tests/unit/vite-route-chunks.test.ts`, `tests/unit/design-system-source.test.ts`, the bounded-body reader tests, the router component suite, and TechLog feature suites. - Governed registry, dependency, release, CI, and operations evidence in `config/contracts`, `config/security`, `config/ci`, the generated Gitea workflow, `README.md`, and `docs/operations/techlog-ui-migration-baseline.md`. Removed starter-only evidence: - `tests/e2e/compact-smoke.spec.ts`, `tests/e2e/design-system-interactions.spec.ts`, `tests/e2e/i18n.spec.ts`, and `tests/e2e/theme.spec.ts`. - `tests/visual/platform.visual.spec.ts` and all five platform visual PNGs. The retained `app-shell`, registry-wide accessibility, and responsive suites were rewritten around TechLog. No stale starter browser or visual snapshot is left referenced. ## Source-to-target visual method and result The supplied source at `/home/donghyeon/workspace/techlog-studio-frontend` was never written. It was copied to `/tmp/techlog-source-parity.I0CBK7`; build and Vinext runtime caches were created only in that temporary copy. The source production server on `4375` and target `dist/server.mjs` production artifact on `4174` were opened by one Playwright Chromium instance with two fresh contexts and the following identical controls: - device scale factor 1, light color scheme, `ko-KR`, `Asia/Seoul`, reduced motion, service workers blocked, 1000-pixel viewport height, and full-page screenshots; - fixed clock `2026-08-14T01:00:00.000Z`, deterministic in-memory data, `document.fonts.ready`, matching Pretendard/IBM Plex Mono font-face state, and zero-duration animation, transition, and caret styles; - no masks and no tolerance: exact RGBA pixel comparison, normalized recursive product-subtree tags, ordered child nodes, complete classes, attributes, text and ARIA relationships, layout diagnostics, response metadata, boot lifecycle, and console/page/request failure collection. The only attributes normalized by name are diagnostics-confirmed framework outputs: React Router `data-discover`; Next Image `data-nimg`, `decoding`, and `srcset`; and Next SSR `selected` for a controlled select. Generated React IDs and CSS-module hashes are normalized by value; there is no broad attribute omission. The final external comparison command was: ```bash TZ=Asia/Seoul corepack pnpm verify:tech-log-source-parity ``` Result: **130/130 passed**, 0 failed, `totalDifferentPixels=0`, every recursive DOM/class/attribute/text/ARIA tree equal, all HTTP metadata equal, and 0 unexplained source/target errors. Source screenshots were temporary comparison inputs; none was copied into target snapshots. The no-update target visual run also passed 130/130 with `maxDiffPixels=0` and `maxDiffPixelRatio=0`. The durable evidence identifies source-tree digest `6724c2f898eefc62d2fc0ee695bccc3ae61a69c5153ed43c69f2cf99ee45bca5`, candidate `3a7c5deca06679fb9b8710da2cce87bbca07ce8a`, build-manifest digest `3579650faa482f566553c00d8b4a05a05b4f7a1ab93b83e48676289bbcf02984`, Vite-manifest digest `cfd583ed7b6c27dce7f47389447608636b6b9df3e28df00c6416674da2c7c46d`, case-inventory digest `5689bcdb5d5637205cdeb92b7c57f72d99f0b039818b8f90afdde526bbafe0ac`, and evidence-payload digest `f046047beded19ce468be607dcf99c6b74d4e07323457ec7145c56d2f67d2c79`. The comparison found and corrected actual integration defects rather than accepting drift: the TechLog Tailwind bootstrap is loaded exactly once in the same cascade order as source; the starter theme import is removed; CSS-module class mapping, shell navigation/focus, publication labels and states, router 404 handling, and generated Vite route-chunk lookup now follow source. All five source/target CSS pairs pass `cmp -s`; their hashes are recorded in the operations baseline. Source production returns missing dynamic slugs and an unmatched Public path as HTTP 404, `text/plain;charset=UTF-8`, with the exact nine-byte body `Not Found`. The target production boundary now returns that exact shell-free response; known Public paths and all known Studio paths remain SPA-served, while an unknown Studio path preserves the source's HTML Studio shell with HTTP 404. This is an observed source-production contract and satisfies the planned prohibition on a generic runtime error; it is not a redesign. ## Route, viewport, and state inventory The 27 canonical contract routes were each compared at 360 and 1440 pixels: - Public: `/`, `/explore`, `/explore/:kind`, `/cases/:slug`, `/references/:slug`, `/questions/:slug`, `/topics/:slug`, `/projects`, `/projects/:slug`, the `records`, `decisions`, and `activity` project views, `/releases`, `/releases/:version`, `/profile`, `/search`, and `*`. - Studio: `/studio`, `/studio/documents`, `/studio/documents/new`, the `edit`, `validation`, `preview`, and `publish` document views, `/studio/publications`, publication-event preview, and `/studio/*`. All known Public fixtures were exercised: two cases, two references, two open questions, three topics, both projects and all three nested views, and release `0.1.0`. Ten unknown Public dynamic shapes were also compared at both widths. The 130-case matrix is 54 canonical-route captures, 18 additional known Public fixture captures, 12 home breakpoints (1180, 1179, 1050, 1024, 980, 900, 820, 768, 767, 420, 390, and 375), 19 Studio states, 20 unknown-Public captures, and 7 interactions. Studio states cover the dashboard, list/new, Case/Reference/Question/conflict editors, valid/invalid validation, current/missing/expired previews, ready/blocked publish, publications/snapshot, missing document/publication, and unknown Studio route. Interactions cover Public search, Studio mobile menu, immediate preview, dirty-leave dialog, newly created current preview, unpublish confirmation, and warning acknowledgement through publish-ready state. ## Browser, responsive, and accessibility outcomes - Required four-spec Chromium command: **48/48 passed**. It covers Public discovery, the full Studio workflow, responsive behavior, and accessibility. - Responsive plus accessibility focused command: **26/26 passed**. - Direct production HTTP contract: **39/39 passed**, including exact raw Public 404s, the in-shell Studio 404, known SPA routes, and boot documents. - Exact target visual command: **130/130 passed** in 2.5 minutes with no masks and zero pixel tolerance. - Automated Chromium `@a11y`: **29/29 passed**. The 27 human review records are intentionally pending, so `corepack pnpm review:a11y-manual` exits 1 and lists missing status, candidate release ID, reviewer/signature/attestation, reviewed time, M1-M7, and screen-reader evidence for every route. - Keyboard/focus checks cover Public search dismissal/restoration, Studio mobile navigation, dirty-leave and unpublish dialogs, labels, heading/landmark order, and focus-visible behavior. Axe reports no violations in the required route and state inventory. Overflow assertions pass at the compact and transition widths, and no unexpected console, page, or request error remains. Commands: ```bash corepack pnpm exec playwright test tests/e2e/tech-log-public-discovery.spec.ts tests/e2e/tech-log-studio-workflow.spec.ts tests/e2e/tech-log-responsive.spec.ts tests/e2e/tech-log-accessibility.spec.ts --project=chromium corepack pnpm exec playwright test tests/e2e/tech-log-responsive.spec.ts tests/e2e/tech-log-accessibility.spec.ts --project=chromium corepack pnpm exec playwright test tests/e2e/tech-log-http-contract.spec.ts --project=chromium corepack pnpm exec playwright test tests/e2e/accessibility.spec.ts --project=chromium --grep @a11y corepack pnpm exec playwright test tests/visual/tech-log.visual.spec.ts --config=playwright.visual.config.ts --project=chromium corepack pnpm test:visual ``` ## Registry and supply-chain governance The initial no-baseline registry artifact reported 23 migration-owned breaking IDs. Each now has owner `tech-log-frontend`, a TechLog contract-version reason, atomic route/runtime/manifest installation, same-release compatibility, and rollback to `05e3d50ba01f01c27f257d2e9040c2bc413ea053`: - Contract: `$contract:{allowedValues,breakingFields,fieldTypes,requiredFields}`. - Removed route rows: `APP_HOME`, `EXAMPLES_AUTH`, `EXAMPLES_PLATFORM`, `EXAMPLES_STATES`, `EXAMPLES_UI`, `REFERENCE_RESOURCE_DETAIL`, `REFERENCE_RESOURCE_FORM`, `REFERENCE_RESOURCE_LIST`, and `REFERENCE_RESOURCE_STATUS`. - Runtime removals: the same nine route IDs. - Runtime change: `NOT_FOUND:moduleId:field-changed`. The governed update used exactly: ```bash REGISTRY_BASELINE_OWNER=tech-log-frontend REGISTRY_BASELINE_REASON="Install approved TechLog Public and Studio route contract" node scripts/update-registry-baseline.ts artifacts/quality/registries.json corepack pnpm check:registries ``` Final result: 11 registries pass, compatibility `none`, no unacknowledged change. Approved snapshot digest: `428479ac5845374a82dd7d02a0c59a713106405f031cdc153789174f14c1405b`. Six direct dependency additions have evidence owner `tech-log-frontend`, reviewer `frontend-platform-security`, product-specific reason, and atomic rollback: `@fontsource/ibm-plex-mono@5.3.0`, `pretendard@1.3.9`, `remark-directive@4.0.0`, `remark-gfm@4.0.1`, `remark-parse@11.0.0`, and `unified@11.0.5`. The dependency policy recognizes the font packages' OFL-1.1 license. Supply-chain generation covered 641 packages. The pre-existing dependency baseline was not promoted; the denied promotion was unnecessary for the regular verification path, which passes with the committed evidence. ## Sample removal and fresh verification The final staged-candidate command passed: ```bash corepack pnpm test:sample-removal ``` Result: **PASS (13 checks, no fixture IDs)**. Its internal evidence included types; reduced architecture (382 modules/1,170 dependencies, 12 graph checks, 9 forbidden fixtures); 11 registry checks; runtime schema 3 files/40 tests; unit 118/1,250; component 18/124; integration 8/74; recipes 2/17; coverage at 77.40% statements, 73.26% branches, 83.88% functions, and 80.02% lines; risk coverage 381/381 with 76 thresholds; source evidence 202 files/129 baselines; artifact/CI checks; router smoke 9/9; and production build. Fresh completion commands and results: | Command | Result | | --- | --- | | `corepack pnpm exec vitest run tests/features/tech-log` | 21 files, 170 tests passed | | required four-spec Chromium command above | 48 tests passed | | `corepack pnpm exec playwright test tests/e2e/tech-log-http-contract.spec.ts --project=chromium` | 39 tests passed | | Chromium `@a11y` command above | 29 tests passed | | `corepack pnpm test:visual` | 130 tests passed | | `corepack pnpm check:types` | app/node/test/recipes/web-worker/service-worker passed | | `corepack pnpm lint` | passed with 0 warnings | | `corepack pnpm check:architecture` | 391 modules, 1,212 dependencies, 12 graph checks, 9 forbidden fixtures passed | | `corepack pnpm check:design-system` | 48 tokens and vendor boundaries passed | | `corepack pnpm check:i18n` | 194 keys across 4 locales passed | | `corepack pnpm check:registries` | 11 registries passed; compatibility `none` | | `corepack pnpm check:browser-security` | injection rejected; Public source maps absent | | `corepack pnpm build` | 2,351 modules transformed; build and manifest completed | | `git diff --check` | passed | The fresh staged-candidate `corepack pnpm test:all` passed runtime schema 3/40, then its unit phase passed 122 files/1,773 tests and failed 19 tests in only `ci-artifact-contract`. The failures are the documented provider/cgroup, RLIMIT/EMFILE, restrictive-umask, `/tmp`, timing, and identity environment cases; no TechLog test failed. A pre-staging run had also exposed 39 release-inventory `APP_HOME` failures because the new serving files were not yet visible to `git ls-files`; staging the complete candidate corrected that test precondition, and all 39 disappeared. Its one aggregate guardian timeout passed 1/1 in isolation and 21/21 in the fresh staged aggregate. The earlier exact baseline-isolation command: ```bash corepack pnpm exec vitest run tests/unit/ci-artifact-contract.test.ts tests/unit/ci-workflow-generation.test.ts tests/unit/http-scenario-evidence.test.ts ``` ran 3 files/529 tests: 510 passed; all 407 CI-workflow and all 14 HTTP-scenario tests passed, leaving the same 19 environment-only CI-artifact cases. Direct runs of the aggregate's remaining phases passed: component 18/124, integration 11/82 under the required child-process scope, reference feature 4/13, and recipes 2/17. This environment-only baseline is also recorded in the operations baseline. ## Fixes, branch audit, and handoff Root-cause-driven fixes added regressions for generated Vite manifest chunk resolution, source-compatible raw 404 responses, palette-source detection, and abort rejection. Presentation integration corrections preserve source DOM, ARIA, copy, assets, CSS, workflow state, and focus behavior; no design was introduced. The branch-wide audit of `05e3d50ba01f01c27f257d2e9040c2bc413ea053..HEAD` found no migrated presentation import of adapters, Next.js, Vinext, or Cloudflare. The 27 route chunks are present in the release manifest and derive from actual Vite output, not hard-coded generated filenames. The immutable code candidate `3a7c5deca06679fb9b8710da2cce87bbca07ce8a` contains the production 404 boundary, parity runner, tests, snapshots, and 27 pending human-review records. Only after that commit existed was the target rebuilt cleanly and the final 130-case parity, visual, HTTP, accessibility, and static verification rerun. This report and its JSON are committed separately as `docs: record TechLog migration evidence`; later human accessibility evidence must cite the candidate SHA, not the evidence-only commit. The independent `final-review.md` remains the immutable review input with its historical `CHANGES_REQUESTED` verdict. This candidate addresses its production 404 issue with a real build artifact and 39 direct HTTP tests; expands the source matrix from 112 to 130 and makes recursive tree equality part of pass; and replaces the missing `tsx` invocation with a checked Node runner and durable provenance. Its accessibility inventory issue is structurally fixed and automated Chromium coverage is green, but the reviewer-dependent 27 human records deliberately remain pending. No review verdict was rewritten or self-approved. Manual completion requires a human to check out candidate `3a7c5deca06679fb9b8710da2cce87bbca07ce8a`, review every route according to `docs/accessibility/manual-checklist.md`, fill each record's exact candidate Release ID, reviewer, signature, attestation, reviewed time, M1-M7, and screen reader result, commit that evidence separately, then rerun `corepack pnpm review:a11y-manual`. Until then `FE-GATE-009` remains pending.