The no-regression contract for transferring every current CodeVetter surface to the native Evidence Workbench.
Native macOS migration matrix
The native macOS client is the sole desktop product, not a reduced viewer. The retired Tauri application remains relevant only as the upgrade and rollback fixture. Production publication still fails closed unless output, interaction, performance, accessibility, signing, notarization, updater, data-continuity, and owner-acceptance gates pass.
This matrix tracks product capability rather than React component count. Native views may combine repeated setup or evidence patterns when that makes the workflow clearer, but they must preserve every input, state, action, receipt, limitation, historical record, and machine-readable boundary that remains reachable in the current product.
Primary surfaces
| Current surface | Current retained capability | Native destination | Current migration state | Replacement gate |
|---|---|---|---|---|
| Usage | Local Claude, Codex, Grok, and bundled ccusage history; separate Devin and provider quota telemetry; agent/model filters, trends, and adapter health |
Usage workspace | The canonical Rust LocalUsageReport powers codevetter usage and the native local-usage desk. Day/week/month granularity; 1w/30d/90d/all-time windows shared by the chart, totals, models, and sessions; Claude/Codex/Grok filters; generated/cache/cost/session totals; model mix; adapter health; refresh; stale/unavailable validation; dark/light evidence; XCUITest; and a 365-period/100-session render gate are implemented. Indexed Devin evidence remains visibly separate and is never folded into local provider totals or described as live quota. Native Usage settings and codevetter history-roots share codevetter.history-roots/v1 for bounded additional Codex homes. Credential-safe live provider telemetry remains separate and fail-closed when unavailable. |
Same providers, time ranges, filters, totals, quota boundaries, empty/error states, and refresh behavior; bounded chart rendering and no implied verification claim |
| Repo Unpack | Repository selection and snapshots; Overview, Handoff, Rules, Analysis, Activity, Inventory, Graph, and Delta; exports and comparisons | Repo Unpack workspace with an AppKit source outline and native inspectors | Native and CLI create the same persisted, model-free snapshot through the shared Rust scanner and codevetter.unpack-scan/v1, with supervised cancellation in the native client. The client receipt strips the raw file list and exposes separate full-scan and SQLite-persistence profiles. Native inspectors preserve repository and commit identity, history limits, outline bounds, and explicit topology/health non-proof labels. Native and CLI export the same Rust-rendered Markdown, offline HTML, graph JSON, agent-context Markdown, and repository-memory Markdown through codevetter.unpack-export/v1. The Graph desk and codevetter unpack --operation query consume one codevetter.repo-query/v2 read-only receipt over the same structural-graph and history services used by MCP; Swift performs no ranking or traversal. Model synthesis remains available through the Rust and agent surfaces without creating a second UI authority. |
Same persisted identities and exports; stable graph/history queries; large-repository bounds; no topology-as-runtime-proof regression |
| Review | Exact PR/range and task intent; source-qualified findings, coverage gaps, blast radius, memory graph, deterministic manifests, executable evidence links, fix handoff, X-Ray/export, synthetic QA and intent diagnostics | Review verification workspace | Exact-change plan/execute/cancel/receipt runs through the Tauri-independent codevetter.verification-command/v1 Rust application service and supervised CLI worker. One bounded request id now correlates ordered codevetter.progress/v2 events, process-level cancellation, and the distinct preflight/final canonical receipt; native ignores foreign progress and rejects mismatched terminal receipts. Optional repository-contained Markdown specs are hashed and parsed by the Rust core; native preflight exposes their explicit requirements and requires a fresh exact selection binding before execution. Final receipts render requirement-level review/executable/verified coverage and exact evidence references. Native Review and codevetter check --agent cross can request independent sequential Claude and Codex passes over the same immutable target and original context. Rust never sends first-review output to the second reviewer, reconciles only exact source-qualified identities, preserves unique and conflicting findings, and fails closed without a composite claim on missing executors, target drift, incomplete coverage, or interruption. Reviewer manifests, qualified candidates, readiness, duration, and availability limits persist in codevetter.cross-review/v1; read-only MCP projects the same receipt without execution authority. Cross-review remains optional until provider-backed caught-bug recall, false-positive, latency, and usage benchmarking passes. The native receipt promotes Rust-qualified findings above raw JSON, preserves severity/confidence/source line/suggestion, opens only repository-contained recorded paths, and exports the unmodified canonical JSON. A separate proof map projects the canonical readiness, deterministic manifest and qualification counts, bounded memory/blast-radius context, revision-qualified structural graph, recorded QA, evidence candidates, and procedure gates while explicitly separating execution proof from navigation leads. The same Rust result now carries codevetter.review-intent-diagnostic/v1: native renders the captured goal, deterministic changed-surface classes, source-review and QA signals, gaps, evidence chronology, and a fail-closed closure state that always requires human disposition. Recorded QA artifacts can be explicitly revealed through validated repository-relative or existing absolute paths; a legacy QA pass is never promoted to revision-exact proof. Review now hands the exact repository, range or pull request, and discovery scope to Testing while clearing stale proof and prior execution consent. This enforces the canonical boundary that Testing owns browser execution and Review consumes its evidence instead of recreating two runner authorities. Persisted reviews can build and atomically save the same fail-closed JSON, Markdown, or offline HTML Agent PR X-Ray through native UI and codevetter xray; public-source confirmation, current-preview identity, the Rust sanitizer, and optional per-finding suggestion approval remain explicit gates. Selected persisted findings can also become a bounded codevetter.agent-fix-packet/v1 through native UI and codevetter fix-packet, carrying exact task/acceptance context, qualified source locations, recorded evidence to preserve, route advice, limitations, and copyable Markdown without claiming the fix is correct. Native UI, CLI, and local agent invocation now share an explicit-consent codevetter.fix-attempt/v1: Rust materializes the recorded head as a detached app-data worktree, supervises one selected agent, bounds the diff, runs git diff --check, reruns the recorded correctness target, source-qualifies a WORKTREE review, and classifies each selected finding as fixed, reproduced, or unchecked. The worktree remains uncommitted and retained until separately confirmed discard; there is no merge or push action. Typed decoding, exact CLI arguments, focused rendering, and true-black visual evidence are recorded. Native Plan, Execute, and Cancel expose keyboard and accessibility contracts; a Rust no_confidence preflight now fails closed, disables execution, names the missing binding, and cannot render an empty finding list as a green pass. A real-agent isolated-fix plus saved-flow post-fix rerun smoke remains pending; saved QA targets, repository spec discovery, and rerun preparation now live in Testing through the shared Rust QA-workspace receipt. |
Equivalent Rust receipt semantics, every review state and export, source navigation, keyboard operation, cancellation, and no-confidence behavior |
| Testing | Direct preview verification, saved QA workflows and targets, Playwright spec discovery, post-fix rerun setup, changed-capability checks, scenarios, portfolio planning, PR watchers, confirmation, execution progress, failures, receipts, and limitations | Testing verification workspace | Direct PR/range preview verification runs through codevetter trex with explicit network confirmation, supervised cancellation, schema and verdict/exit validation, preview identity, derived routes, an optional selected saved route and goal, journey/artifact/console evidence, raw JSON, limitations, and a Runs handoff. codevetter.qa-workspace/v1 is shared by native Testing and codevetter qa; the scoped qa_workspace_inspect MCP tool exposes the same read-only setup. Rust projects safe legacy fields into a separate native preference, never projects credential-bearing storage-state paths, refuses arbitrary external-command execution, discovers bounded repository Playwright specs without executing them, and prepares the same-flow post-fix rerun without restoring network consent or starting the browser. The shared Rust evidence-scope planner is projected through codevetter scope --consumer testing and native Testing for deterministic flow, exact-change, and bounded codebase target portfolios. Warm changed proof runs through codevetter warm; differential verification runs through codevetter differential with a separate preparation gate and the rule that comparison evidence never creates pass evidence. Scenario authoring runs through codevetter scenario and the native Scenario Foundry over the incumbent Rust bridge: free/local generation creates expiring candidates, validation and dry-run remain non-persistent, acceptance rechecks the candidate hash, selected destinations, and replacement approval, and rejection writes no project files. Incoming PR watcher configuration, bounded run history, foreground polling, and exact-head recovery now share codevetter watcher: native scheduling lasts only for the open app session; consent is not persisted; each automatic poll looks across open PRs, executes only a newly arrived PR or an existing PR with a new head SHA, may contact GitHub, execute isolated project code and the configured agent, post commit statuses, and stays supervised until receipts persist. The Rust boundary validates and fetches the exact immutable refs/pull/<number>/head object without changing the user’s branch, index, worktree, FETCH_HEAD, or durable refs; Node projects install with their declared pnpm/npm/Yarn/Bun lockfile contract; and status authentication can reuse existing gh authority in memory without persisting or logging the token. Automatic polls skip unchanged PR heads, while a separately confirmed CLI/native Retry action reruns one exact currently open PR and persists a replacement attempt. MCP discovery never starts these runtimes. Exact Rust/CLI/native arguments and schemas, a local bare-remote materialization test, safe non-network configuration smokes, real-repository warm/differential failure-boundary smokes, XCUITest reachability for every Testing workspace, Swift watcher rendering and supervised consent/execution contracts, dark warm/differential/scenario/watcher visual evidence, and bounded direct-preview render gates are recorded. The shared surface-parity receipt proves that one repository-owned fixture preserves the same Rust, CLI, native, and read-only MCP evidence-scope semantics. The live watcher qualification proves one explicitly approved PR head through exact fetch, pnpm install, repository lint, conservative verdict, persistence, GitHub status posting, and a second same-head explicit recovery attempt. Final owner acceptance remains pending |
Same evidence-scope/v1 resolution and canonical receipts, bounded coverage, confirmation gate, cancellation, watcher lifecycle, and browser evidence |
| Performance | Intent/scope resolution, workload admission, zero-egress evidence, samples/warmups/timeouts, diagnosis, paired optimization, campaign handoff, cleanup, and receipts | Performance verification workspace | Exact-workload admission, capture, and paired verification run through codevetter performance. The same Rust evidence-scope planner now powers native flow/change/codebase discovery, codevetter scope --consumer performance, the read-only MCP resolve_evidence_scope tool, and prepare_review target suggestions; MCP never executes the workload. Selecting a closed native candidate fills the exact adapter, target, and optional workload name before admission. The diagnosis-to-campaign handoff preserves baseline/candidate/promotion states, requires an exact baseline checkout, and keeps promotion blocked until the paired Rust receipt confirms it. Native controls preserve all six Rust/Tauri adapters, bounded samples/warmups/timeouts, contained target identity, stale-plan invalidation, cancellation, exit/state validation, observed/inferred/unverified separation, cleanup, limitations, and canonical JSON. Recorded-run inspection invokes the existing digest-validating Rust operation and renders stored identity, lifecycle, policy, child outcome, bounded capture sizes, diagnosis, and limitations. Every supervised plan/capture/paired/inspection receipt also records 75 ms owned-process-tree samples with peak RSS, peak process count, sampler identity, count, and the explicit between-sample limitation. Exact CLI/native argument and schema tests, Rust sampler tests, MCP schema/validation/protocol coverage, a real-repository blocked-plan/resource smoke, dark rendered evidence, XCUITest coverage, and 100-row receipt rendering are recorded. The shared surface-parity receipt closes the same-fixture Rust/CLI/native/MCP discovery gate while preserving MCP’s non-executing authority. The runtime qualification passes explicit release launch, steady RSS, bridge latency, progress throughput, cancellation, crash recovery, and large-receipt gates. The matched Tauri comparison confirms startup parity, 30.5% lower native settled Performance-workspace RSS, and a 51.5% smaller qualified native bundle across five alternating, surface-confirmed Release launches per app. Workload-execution, energy, and long-session comparisons remain unclaimed. |
Same accepted adapters and workload identity; equivalent statistics, inferred/observed labels, cleanup, limitations, and paired-proof rules |
| Runs | Local-check, preview, T-Rex PR, synthetic QA, warm, differential, and audience histories | Native Runs evidence ledger | One bounded codevetter.run-history/v1 projection and native inspector cover every listable verification history, including audience responses and synthetic-QA artifacts. Repository filtering, canonical JSON export, bounded arrow-key traversal, a 700-run Rust benchmark, and a 100-run/100-response Swift host-render gate are implemented. Foreground interaction remains a release qualification concern. |
Every retained receipt family, canonical JSON, verdict and limitation fidelity, repository filtering, keyboard access, bounded rendering, and export |
| Settings | General, Appearance, Integrations, Agents, Agent Island, Agent MCP, Notifications, Usage, Rubrics, Ops, Memories, and About | Native Settings window with the same sections | All 12 sections use one native information architecture. codevetter.native-settings/v1 and codevetter settings provide 28 validated non-secret values; unknown keys and options fail closed, and credentials are excluded. Onboarding, MCP scope, history roots, retention, memories, rubrics, and local operations each use a bounded Rust receipt shared with the corresponding CLI command. Rust-owned SQLite is the canonical rubric store, and installed-upgrade qualification preserves custom packs and active selection through native replacement and rollback. Agent Island is configuration-only; the retired helper is not shipped. Sparkle remains fail-closed until production identity, signature, appcast, notarization, Gatekeeper, upgrade, and rollback checks pass. |
No preference loss, secret leakage, authority expansion, or silent default change; destructive archive maintenance stays outside agent authority |
The Repo Unpack query desk now uses a supervised read-only Rust worker with one search snapshot that upgrades in place with compact traversal edges. It rechecks live Git freshness and the latest stored snapshot identity on every request, drops the process on cancellation, and keeps the exact one-shot CLI query as compatibility fallback. On the qualified 115,884-node graph, warm Release medians measured 36.07 ms search, 35.15 ms explain, 116.55 ms impact, 68.38 ms path, 32.46 ms history search, and 32.21 ms causal trace. Search-only RSS was 242.6 MiB and rich traversal RSS 307.6 MiB after a 511.9 MiB prototype was rejected. This closes the richer-query performance gate while keeping the memory and cold-upgrade tradeoffs explicit. The latest background-native gate passes 80 Swift package tests and the macOS Debug build; this supersedes earlier per-row test counts in the matrix. The current 33-state packet preserves a true-black canvas with 1–4% near-black working-plane separation, explicit search-only and rich query states, and light-appearance counterparts for Review, Testing, Performance, Runs, bounded history recovery, the memory inspector, Agent Island configuration, and read-only Ops status. Appearance-aware evidence foregrounds meet a checked 4.5:1 contrast floor against dark canvas, warm light canvas, and white evidence planes. The repository-query worker also closes stdin, grants a bounded 200 ms termination grace, and uses a final kill only for its exclusively owned read-only child; the cancellation gate requires settlement within one second.
The shared surface-parity receipt
now binds the same canonical no-confidence local-check fixture to Rust, CLI,
native, and the repository-scoped read-only MCP verification_get_receipt
projection. MCP retains no verification start or cancellation authority.
Shared application behavior
| Current behavior | Native requirement |
|---|---|
| Persistent routes preserve in-progress page state | AppKit window controllers and shared feature models preserve in-progress runs and forms across navigation and window changes. |
| Command palette and ordinary accessible navigation | Native menus, commands, toolbar items, search, keyboard shortcuts, VoiceOver labels, and focus restoration cover the same reachable actions. |
| Onboarding and update state | The shared Rust onboarding receipt, existing completion-state compatibility, default-adapter persistence, four native states, CLI projection, secret boundary, and deterministic rendering are qualified. A read-only codevetter.native-release-readiness/v1 receipt machine-checks the package, signing, updater, notarization, Gatekeeper, and installed-upgrade boundaries without exercising release authority. Production release fails closed until every protected gate passes. |
| Local SQLite records | Rust remains the only persistence authority. Swift receives versioned projections and never opens or reinterprets SQLite directly. |
| Error boundaries and explicit loading/empty states | Every migrated surface has native loading, empty, limited, failed, cancelled, stale, and unavailable states with written meaning. |
Machine surfaces
The visual migration cannot fork product semantics. The Rust capability registry, command contracts, and receipt schemas are projected through:
- native UI commands and inspectors;
codevetter check,fix-packet,fix,xray,scope,trex,warm,differential,scenario,performance,usage,history-roots,memories,ops,unpack --operation scan|list|inspect|compare|export|query,settings,mcp,collect, andcapabilities, plus the structural graph driver;- repository-scoped MCP graph, history, review-preparation, archaeology, and capability-catalog tools;
- versioned JSON receipts and exports.
A native row may be marked complete only when its fixtures prove the same identity, authority, verdict, limitations, and qualification state as the CLI or MCP projection that shares the capability.
The measured Rust/Swift ownership split is defined in Native Rust boundary. Read-only projections may earn an in-process path; verification execution remains supervised.
Retirement rule
The owner approved Tauri retirement. The source tree therefore contains only the native macOS application, while the shared Rust core remains authoritative for UI, CLI, and MCP contracts. The old signed archive is retained solely for the isolated installed-upgrade, stable-record continuity, and rollback proof.
Source migration is not release proof. Publishing and closing the migration issue still require the exact production archive to pass protected signing, notarization, Sparkle, Gatekeeper, upgrade, rollback, and installed-app checks.