# ADR 0019 — The live-`veloxd` conformance runner is a required check, as-is **Status:** accepted · **Date:** 2026-09-12 · **Lane:** PKG/QA ## Context `tests/conformance/run.sh` step 3b (ADR 0014's `conformance` ctest, already required per `.github/BRANCH_PROTECTION.md`) replays every fixture against a real, isolated `veloxd` it builds and starts — not just mockd, which only proves the TS client and the fixtures agree with each other. This is the runner that can catch `veloxd` disagreeing with its own contract, and it is unconditional in `run.sh` (`set -euo pipefail`, no skip flag): it already runs, and already blocks, inside the `conformance` job. What was open was whether to treat that as a settled, defended gate or as something still provisional while `daemon/docs/deferrals.md`'s D1-D4b stub handlers were excused via `veloxd-xfail.json`. PROTO's update: 57/57 fixtures pass on `main`, and the xfail allowlist is down to 18 entries from 34 as DAEMON lands the deferred handlers behind them. ## Decision The live-`veloxd` conformance runner stays required — no change to CI is needed, since it already runs inside the already-required `conformance` job (ADR 0014). What this ADR records is the standing: PKG/QA is not carving out an exception, a `continue-on-error`, or a separate advisory job for it while the xfail list shrinks. A regression here fails the same required check a schema mismatch would. Verified, not assumed: `tests/conformance/veloxd-xfail.json` has 18 entries as of this ADR (`python3 -c "import json; print(len(json.load(open('tests/conformance/veloxd-xfail.json'))))"`). Each remaining entry excuses one still-stubbed handler on `deferrals.md`'s D-list, not a real disagreement between `veloxd` and its contract — `tests/conformance/README.md` already draws that line (an entry for anything else is a `run.sh`-detected "xfail entry unexpectedly passed" or a straight failure, not a quiet pass). ## Consequences - No `ci.yml` or `BRANCH_PROTECTION.md` change: `conformance` was already listed required, and this runner was already inside it. - The xfail list is a visible, shrinking number, not a static allowance — as DAEMON clears more of `deferrals.md`'s D-list, entries come out of `tests/conformance/veloxd-xfail.json`, and `replay.ts` fails loudly (per `applyXfail`'s "unexpectedly passed" check) if one is left in after its handler ships. - Nothing here changes who owns what: `veloxd-xfail.json` and `run.sh` stay PROTO's; PKG/QA's role is the branch-protection policy this ADR confirms, not the runner itself.