Align consolidated review documentation with reading diagnostics

This commit is contained in:
Ouroboros 2026-09-18 04:04:55 +03:00
parent ab5e1989f5
commit 700d525265
4 changed files with 15 additions and 11 deletions

View file

@ -413,7 +413,7 @@ Sizing is density-calibrated, not keyed to model names. `usage_accounting.execut
Only the triad packet has a cold-start probe rung: `review_admission.density_probe_before_size_refusal` invokes `capability_evidence.cold_start_density_probe` when an irreducible packet exceeds a cold route's cap. One bounded slice of the actual prompt is sent on that exact model under `physical_attempt_limit(1)`; its witness buys one resize and fit pass. It never probes a warm route, retries the probe or runs when the packet fits. Progress and `review_density_probe` retain the attempt; a paid-ledger refusal is `budget_refused` and leaves the size refusal unchanged. This breaks the loop in which a request rejected before dispatch can never teach its tokenizer density.
`reviewer_window.resolve_reviewer_window` is the route-specific sizing source, with metadata probes serialized per route and limited by evidence TTL. There is no model-window table or window-authority floor. Unknown routes retain a disclosed sizing assumption; `scope_window` adds its designated-default or conservative fallback and distinguishes confirmed, asserted, stale-unverifiable, designated-default and unknown provenance. `POST /api/owner/capability-ack` records an asserted window bound to one route fingerprint, invalidated by a route change; it sizes sends and grants no reviewer authority. A failed send supplies no verdict, while a small window alone does not remove a responding reviewer.
`reviewer_window.resolve_reviewer_window` is the route-specific sizing source, with metadata probes serialized per route and limited by evidence TTL. There is no model-window table or window-authority floor. `ReviewerWindow.sizing_window` has a full-window sizing default for an unknown API window; raw subscription routes keep no numeric unknown-window assumption. `scope_window` adds its designated-default or conservative fallback and distinguishes confirmed, asserted, stale-unverifiable, designated-default and unknown provenance. `POST /api/owner/capability-ack` records an asserted window bound to one route fingerprint, invalidated by a route change; it sizes sends and grants no reviewer authority. A failed send supplies no verdict, while a small window alone does not remove a responding reviewer.
#### Scope review by retrieval

View file

@ -389,7 +389,7 @@ Adding or changing a provider updates one coherent route contract:
3. canonical tool/reasoning/image/cache intent at `llm.py`, wire projection and
exact-route recovery in the small transport leaves;
4. nullable pricing/settlement and truthful capability omissions;
5. review and scope routing with sourced context-window evidence;
5. review and scope routing with sourced context-window evidence for send sizing;
6. direct-provider and single-provider regression tests;
7. the route's real streamed wire recorded (redacted) into
`tests/fixtures/llm_wire/` and replayed — a hand-written fixture is not
@ -397,9 +397,10 @@ Adding or changing a provider updates one coherent route contract:
`physical_stream` blob the runtime retains.
Local-only installs keep their local route; unreachable shipped remote defaults
may be cleared, explicit owner values may not. Scope authority follows BIBLE P3:
owner-selected Max requires the applicable sourced window evidence, owner-selected
Low records the declared skip rather than pretending a partial review occurred.
may be cleared, explicit owner values may not. Scope runs in every context-size
mode; window evidence governs send sizing, not review authority. Reading coverage
is diagnostic under BIBLE P3: missing observations do not discard a received
verdict or remove a responding reviewer from quorum.
Current model ids and defaults belong in code/config, not here. Use
`provider_models.ACTIVE_MODEL_SETTING_KEYS` for any new active consumer;
`LEGACY_MODEL_SETTING_KEYS` is migration/history only, and `OUROBOROS_MODEL_HEAVY`

View file

@ -180,9 +180,11 @@ Every new or changed continuity surface is reviewed as one narrow chain:
an explicit gap, never silently treated as complete.
**Control-plane distrust is metadata, not a data-plane operation.** Paid model
output is evidence until a typed validity predicate fails. Distrust of profile,
route, parser or window may lower authority to DEGRADED/SKIPPED/NOT_RUN, but it
must not blank, rewrite or relabel the artifact or its original cause.
output is evidence until a typed validity predicate fails. Actual profile,
route or subject mismatches, invalid output contracts and delivery failures may
affect review authority; window sizing and reading diagnostics alone may not
(BIBLE P3). Neither case blanks, rewrites or relabels the artifact or its
original cause.
Enforcement: CHECKLISTS item 25 `source_completeness` (critical when
applicable) scores the chain in commit review; the presentation-adapter
@ -312,4 +314,3 @@ geometry/refresh contracts are pinned in `tests/test_widgets_ui_static.py` and
`tests/test_extension_surfaces.py`.
---

View file

@ -419,8 +419,10 @@ def test_continuity_projection_contract_is_mirrored_across_governance_docs():
def test_architecture_names_all_window_surfaces_and_settlement_order():
architecture = _read("docs/ARCHITECTURE.md")
assert "keeps the full-window assumption on every surface" in architecture
assert "there is no window floor for a blocking verdict on any surface" in architecture
assert "full-window sizing default for an unknown API window" in architecture
assert "raw subscription routes keep no numeric unknown-window assumption" in architecture
assert "designated-default or conservative fallback" in architecture
assert "no model-window table or window-authority floor" in architecture
assert "SETTLED is published before registration retirement" in architecture