Files
chanora/docs/governance/traceability-matrix.md
T
EdisonJwa 02ffadfa52 docs(ptt): land Baseline Candidate v0.9.3 — capability-based desktop PTT
Applies the gen2 desktop-PTT review summary
(`gen2/chanora-desktop-ptt-review-summary-v0.9.2.md`) to our doc set
with the owner rulings PTT-OPEN-001 through PTT-OPEN-006 resolved as
accepted decisions DEC-023 through DEC-028:

  * DEC-023 Windows Global PTT P0 / MVP
  * DEC-024 macOS Global PTT P0 / MVP with permission UX
  * DEC-025 Linux officially-tested env: GNOME on Wayland only
  * DEC-026 Mouse side buttons supported (Win + macOS; Linux portal)
  * DEC-027 PTT diagnostics: capability + availability only, no
            raw key codes ever
  * DEC-028 Missed-key-up watchdog: P0

Requirements (SysRS / SRS) and architecture (SysDes / SAD / SDD)
gain the desktop-PTT ID set the gen2 summary describes:

  SysRS-296..302  -> SysDes-142..148
                  -> SRS-195..203
                  -> SAD-071..079
                  -> SDD-081..092

ID totals advance from 295 / 141 / 194 / 70 / 80 to 302 / 148 / 203
/ 79 / 92. The strict layered sourcing rule (`SRS -> SysDes` only,
`SAD -> SRS` only, `SDD -> SAD` only) is preserved; the
`tools/validate_docs.py` validator reports zero undefined refs and
zero direct-layer-rule violations.

New document:

  * `docs/architecture/desktop-ptt-architecture.md` — capability
    ladder (L0Focused, L1GlobalShortcut, L2GlobalHoldToTalk,
    L3GlobalWithMouseButtons, L4DeviceAware reserved), Windows /
    macOS / Linux strategies, privacy rule, audio-gate rule,
    missed-key-up watchdog, release-readiness evidence requirement,
    traceability summary.

Doc addenda (Baseline Candidate 0.9.3):

  * `privacy/privacy-policy.md` — no raw key history, capability-
    dependent Global PTT, UI reflects actual runtime capability
  * `security/threat-model.md` — THREAT-PTT-001..006
  * `security/diagnostic-redaction-audit-report.md` —
    REDACT-PTT-001..006 banned field list enforced by `PttSanitizer`
  * `release/platform-release-policy.md` — per-platform evidence
    fields, no over-claim on untested Linux compositors
  * `release/release-readiness-go-nogo-record.md` — RR-PTT-001..008
    release-readiness items
  * `verification/swe4-unit-verification-plan.md` —
    SWE4-UV-035..039
  * `verification/swe5-software-integration-verification-plan.md` —
    SWE5-IV-015
  * `verification/swe6-software-verification-plan.md` — SWE6-SV-017
  * `verification/sys4-system-integration-verification-plan.md` —
    SYS4-SIV-016
  * `governance/traceability-matrix.md` — full PTT trace rows +
    verification map
  * `governance/decision-impact-assessment.md` — DEC-023..028
    impact matrix
  * `governance/product-decision-register.md` v0.9.9 entry
    recording DEC-023..028 in the decision table and the status
    table at §7
  * `governance/document-index.md` — adds
    `desktop-ptt-architecture.md` to the controlled set
  * `architecture/proof-of-concept-plan.md` —
    PoC-PTT-001..005 platform items
  * `references/external-references.md` — Windows Raw Input,
    macOS event-tap, Linux GlobalShortcuts portal references
  * Both validation reports
    (`baseline-candidate-validation-report.md`,
    `repo-format-validation-report.md`) bumped to v0.9.3 with the
    new ID totals (302 / 148 / 203 / 79 / 92).

README §"Desktop Push-to-Talk" added between Architecture Overview
and Repository Layout: capability levels, per-platform strategy,
privacy posture, missed-key-up watchdog.

Tooling:

  * `tools/validate_docs.py` copied from the gen2 zip into the
    repo tree (was previously available only inside the zip).
    Reports zero undefined refs, zero direct-layer-rule violations,
    English-only CJK check passes. The 35 "old package-style
    filename" hits are pre-existing and identical to the gen2
    baseline (they live in `path-migration-map.md` and config-ID
    headers of governance docs and are intentional per the path
    migration policy).
  * `.gitignore` adds `/gen2/` so the externally-provided review
    package does not enter the repo.

No code changes in this commit; B (the implementation split into
`transmit_active` / `capture_active`, `PttCapabilityLevel`
reporting, `PttSanitizer` diagnostics rule, and the UI capability
badge) follows in a separate commit.
2026-05-15 14:51:22 +08:00

8.7 KiB

Chanora Requirements and Design Traceability Matrix

Version: 0.9.2 Status: Baseline Candidate
Language: English
Product: Chanora
Lifecycle hierarchy: SysRS -> SysDes -> SRS -> SAD -> SDD

Repo path: docs/governance/traceability-matrix.md ---

1. Strict Hierarchy

The Chanora documentation hierarchy shall follow this structure strictly:

SysRS -> SysDes -> SRS -> SAD -> SDD

Direct-source rules:

Document Direct upstream source allowed
SysDes SysRS
SRS SysDes only
SAD SRS only
SDD SAD only

Prohibited direct links:

Document Prohibited direct source
SRS SysRS
SAD SysRS, SysDes
SDD SysRS, SysDes, SRS

2. Current Baseline Documents

Layer Current baseline ID range
SysRS chanora_SysRS_v0.7.md SysRS-001 through SysRS-285
SysDes chanora_SysDes_ASPICE_SYS3_v0.6.md SysDes-001 through SysDes-132
SRS chanora_SRS_ASPICE_SWE1_v0.5.md SRS-001 through SRS-184
SAD chanora_SAD_ASPICE_SWE2_v0.3.md SAD-001 through SAD-060
SDD chanora_SDD_ASPICE_SWE3_v0.3.md SDD-001 through SDD-070

3. Coverage Rules

Upstream layer Downstream layer Coverage rule
SysRS SysDes SysRS shall be fully covered by SysDes.
SysDes SRS Software-team-related SysDes items shall be fully covered by SRS.
SRS SAD SAD shall cover all SRS items.
SAD SDD SDD shall cover all SAD items.

4. Baseline Coverage Summary

Source Target
SysRS-001 through SysRS-257 SysDes-001 through SysDes-110
SysRS-258 through SysRS-285 SysDes-111 through SysDes-132
SysDes-001 through SysDes-110 SRS-001 through SRS-143
SysDes-111 through SysDes-132 SRS-144 through SRS-184
SRS-001 through SRS-030 SAD-032, SAD-039, SAD-040, SAD-041
SRS-031 through SRS-060 SAD-033, SAD-039, SAD-041
SRS-061 through SRS-090 SAD-034, SAD-039, SAD-041
SRS-091 through SRS-110 SAD-035
SRS-111 through SRS-124 SAD-036, SAD-050
SRS-125 through SRS-134 SAD-037, SAD-049
SRS-135 through SRS-143 SAD-038
SRS-144 through SRS-184 SAD-001 through SAD-031, SAD-039 through SAD-060
SAD-001 through SAD-007 SDD-001 through SDD-010
SAD-008 through SAD-011 SDD-011 through SDD-015
SAD-012 through SAD-016 SDD-016 through SDD-026
SAD-017 through SAD-019 SDD-027 through SDD-030
SAD-020 through SAD-027 SDD-031 through SDD-041
SAD-028 through SAD-031 SDD-042 through SDD-045
SAD-032 through SAD-038 SDD-046 through SDD-050
SAD-039 through SAD-045 SDD-046 through SDD-050, SDD-055, SDD-056
SAD-046 through SAD-050 SDD-051 through SDD-058, SDD-061
SAD-051 through SAD-060 SDD-057 through SDD-070

5. Change Impact Rules

Changed layer Required impact analysis
SysRS Review SysDes coverage; update SRS only through updated SysDes.
SysDes Review affected SRS requirements; SRS shall not bypass SysDes.
SRS Review affected SAD items; SAD shall link only to SRS.
SAD Review affected SDD items; SDD shall link only to SAD.
SDD Review implementation, unit construction, and verification evidence.

6. Traceability Verification Checklist

Check Expected result
SysDes references SysRS Allowed
SRS references SysRS Not allowed
SRS references SysDes Required
SAD references SRS Required
SAD references SysRS or SysDes Not allowed
SDD references SAD Required
SDD references SysRS, SysDes, or SRS Not allowed
Latest SAD ID range SAD-001 through SAD-060
Latest SDD ID range SDD-001 through SDD-070

8. Verification Work Product Traceability

Verification work products are downstream evidence-producing artifacts. They do not change the strict engineering hierarchy.

Verification document Direct verification source Coverage
chanora_SWE4_Unit_Verification_Plan_v0.1.md SDD SDD-001 through SDD-070
chanora_SWE5_Software_Integration_Verification_Plan_v0.1.md SAD and SDD SAD-001 through SAD-060 and SDD-001 through SDD-070
chanora_SWE6_Software_Verification_Plan_v0.1.md SRS SRS-001 through SRS-184
chanora_SYS4_System_Integration_Verification_Plan_v0.1.md SysDes SysDes-001 through SysDes-132
chanora_Verification_Master_Plan_v0.1.md Verification planning baseline SWE.4, SWE.5, SWE.6, SYS.4

9. Verification Change Impact

Changed artifact Verification impact
SDD Re-select SWE.4 unit verification measures and affected SWE.5 integration measures.
SAD Update SDD if needed and re-select affected SWE.5 integration measures.
SRS Update SAD/SDD if needed and re-select affected SWE.6 verification measures.
SysDes Update downstream engineering artifacts if needed and re-select affected SYS.4 measures.
SysRS Update SysDes and downstream artifacts if requirements intent changes.

10. Change History

Version Date Description
0.1.0 2026-05-14 Initial strict traceability matrix.
0.2.0 2026-05-14 Updated current baseline to SAD v0.3 and SDD v0.3, with SAD-001 through SAD-060 and SDD-001 through SDD-070 coverage.
0.3.0 2026-05-14 Added downstream verification work product traceability for SWE.4, SWE.5, SWE.6, and SYS.4.

11. Product Decision Traceability Addendum

Source Target
SysRS-286 through SysRS-295 SysDes-133 through SysDes-141
SysDes-133 through SysDes-141 SRS-185 through SRS-194
SRS-185 through SRS-194 SAD-061 through SAD-070
SAD-061 through SAD-070 SDD-071 through SDD-080
SDD-071 through SDD-080 SWE.4 addendum SWE4-UV-031 through SWE4-UV-034
SAD-061 through SAD-070 and SDD-071 through SDD-080 SWE.5 addendum SWE5-IV-014
SRS-185 through SRS-194 SWE.6 addendum SWE6-SV-016
SysDes-133 through SysDes-141 SYS.4 addendum SYS4-SIV-015

Baseline Candidate 0.9.1 Update

Version Date Description
0.9.1 2026-05-14 Updated baseline after product decision closure: Apple App Store SDK gate uses Xcode 26+ and iOS 26 / iPadOS 26 SDK+ since 2026-04-28, platform baselines and decision traceability propagated across the document set.

12. Platform Release Policy Traceability

Policy document Covered decisions
docs/release/platform-release-policy.md iOS runtime target, Apple App Store Connect upload SDK gate, Android runtime target, Google Play target API gate

The Apple App Store Connect upload gate remains linked through:

SysRS-287 -> SysDes-134 -> SRS-186 -> SAD-062 -> SDD-072

The corrected effective date is:

Since 2026-04-28:
App Store Connect upload builds require Xcode 26 or later
using iOS 26 / iPadOS 26 SDK or later.

This build-SDK gate is separate from the iOS runtime deployment target.

Baseline Candidate 0.9.2 Update

Version Date Description
0.9.2 2026-05-14 Corrected Apple App Store Connect upload gate to 2026-04-28 and checked full-package naming, references, and coverage.

Desktop Push-to-Talk Traceability Addendum (Baseline Candidate 0.9.3)

Strict layered sourcing for the desktop PTT chain:

SysRS-296..302
  -> SysDes-142..148
  -> SRS-195..203
  -> SAD-071..079
  -> SDD-081..092
SysRS SysDes SRS SAD SDD
SysRS-296 (Focused PTT mandatory) SysDes-142, SysDes-144 SRS-201 SAD-075 SDD-089
SysRS-297 (Global PTT capability-dependent) SysDes-142 SRS-195 SAD-071 SDD-081
SysRS-298 (Capability exposed) SysDes-143, SysDes-147, SysDes-148 SRS-196 SAD-076, SAD-078 SDD-082, SDD-088, SDD-091
SysRS-299 (Windows ladder) SysDes-145 SRS-197 SAD-072 SDD-083, SDD-084
SysRS-300 (macOS permission-aware) SysDes-145 SRS-198 SAD-073 SDD-085
SysRS-301 (Linux GNOME-Wayland) SysDes-145 SRS-199 SAD-074 SDD-086
SysRS-302 (No raw key history) SysDes-146 SRS-202 SAD-077 SDD-090
(DEC-026 mouse buttons) SysDes-142, SysDes-145 SRS-200 SAD-072..074 SDD-082..086
(DEC-028 missed-key-up watchdog) SysDes-142, SysDes-144 SRS-203 SAD-079 SDD-092

Verification coverage:

SDD-081..092 -> SWE4-UV-035..039
SAD-071..079 + SDD-081..092 -> SWE5-IV-015
SRS-195..203 -> SWE6-SV-017
SysDes-142..148 -> SYS4-SIV-016

No forbidden direct links introduced: SRS continues to source from SysDes only, SAD from SRS only, SDD from SAD only.

Version Date Description
0.9.3 2026-05-15 Added desktop PTT traceability rows covering SysRS-296..302 -> SysDes-142..148 -> SRS-195..203 -> SAD-071..079 -> SDD-081..092 and the verification coverage onto SWE.4 / SWE.5 / SWE.6 / SYS.4.