docs(opf): describe the background scan, the span cache and the new caps

Commit

peyton-alt6d ago

The security doc now says OPF never runs inside git push: pre-push holds unscanned checkpoints, the scan worker scans and delivers them, the span cache stores only hashes and offsets, and failures keep checkpoints held rather than aborting pushes. Cap values, timeout_seconds, the prompt text and the CI note match the new behavior.

The OPF command-trust integration tests wait for the background worker to log that it finished before checking whether the payload ran, since that is now where the opf binary executes; otherwise the negative tests would pass vacuously. The worker logs that line on every exit.

Co-Authored-By: Claude Opus 5.5 (1M context) noreply@anthropic.com Entire-Checkpoint: 01M3SRQS5BCD884ER2E6ZX76KD

Checkpoints

Fix OPF Byte Cap Scope Per Checkpoint Ref

Claude CodeOpus 5.5
View session
Checkpoint 1