diff --git a/docs/architecture/06-agent-core.md b/docs/architecture/06-agent-core.md index e2e527d6d..8cbc46c07 100644 --- a/docs/architecture/06-agent-core.md +++ b/docs/architecture/06-agent-core.md @@ -413,7 +413,7 @@ Sizing is density-calibrated, not keyed to model names. `usage_accounting.execut Only the triad packet has a cold-start probe rung: `review_admission.density_probe_before_size_refusal` invokes `capability_evidence.cold_start_density_probe` when an irreducible packet exceeds a cold route's cap. One bounded slice of the actual prompt is sent on that exact model under `physical_attempt_limit(1)`; its witness buys one resize and fit pass. It never probes a warm route, retries the probe or runs when the packet fits. Progress and `review_density_probe` retain the attempt; a paid-ledger refusal is `budget_refused` and leaves the size refusal unchanged. This breaks the loop in which a request rejected before dispatch can never teach its tokenizer density. -`reviewer_window.resolve_reviewer_window` is the route-specific sizing source, with metadata probes serialized per route and limited by evidence TTL. There is no model-window table or window-authority floor. Unknown routes retain a disclosed sizing assumption; `scope_window` adds its designated-default or conservative fallback and distinguishes confirmed, asserted, stale-unverifiable, designated-default and unknown provenance. `POST /api/owner/capability-ack` records an asserted window bound to one route fingerprint, invalidated by a route change; it sizes sends and grants no reviewer authority. A failed send supplies no verdict, while a small window alone does not remove a responding reviewer. +`reviewer_window.resolve_reviewer_window` is the route-specific sizing source, with metadata probes serialized per route and limited by evidence TTL. There is no model-window table or window-authority floor. `ReviewerWindow.sizing_window` has a full-window sizing default for an unknown API window; raw subscription routes keep no numeric unknown-window assumption. `scope_window` adds its designated-default or conservative fallback and distinguishes confirmed, asserted, stale-unverifiable, designated-default and unknown provenance. `POST /api/owner/capability-ack` records an asserted window bound to one route fingerprint, invalidated by a route change; it sizes sends and grants no reviewer authority. A failed send supplies no verdict, while a small window alone does not remove a responding reviewer. #### Scope review by retrieval diff --git a/docs/development/02-naming-and-boundaries.md b/docs/development/02-naming-and-boundaries.md index 6fa5c7236..375853122 100644 --- a/docs/development/02-naming-and-boundaries.md +++ b/docs/development/02-naming-and-boundaries.md @@ -389,7 +389,7 @@ Adding or changing a provider updates one coherent route contract: 3. canonical tool/reasoning/image/cache intent at `llm.py`, wire projection and exact-route recovery in the small transport leaves; 4. nullable pricing/settlement and truthful capability omissions; -5. review and scope routing with sourced context-window evidence; +5. review and scope routing with sourced context-window evidence for send sizing; 6. direct-provider and single-provider regression tests; 7. the route's real streamed wire recorded (redacted) into `tests/fixtures/llm_wire/` and replayed — a hand-written fixture is not @@ -397,9 +397,10 @@ Adding or changing a provider updates one coherent route contract: `physical_stream` blob the runtime retains. Local-only installs keep their local route; unreachable shipped remote defaults -may be cleared, explicit owner values may not. Scope authority follows BIBLE P3: -owner-selected Max requires the applicable sourced window evidence, owner-selected -Low records the declared skip rather than pretending a partial review occurred. +may be cleared, explicit owner values may not. Scope runs in every context-size +mode; window evidence governs send sizing, not review authority. Reading coverage +is diagnostic under BIBLE P3: missing observations do not discard a received +verdict or remove a responding reviewer from quorum. Current model ids and defaults belong in code/config, not here. Use `provider_models.ACTIVE_MODEL_SETTING_KEYS` for any new active consumer; `LEGACY_MODEL_SETTING_KEYS` is migration/history only, and `OUROBOROS_MODEL_HEAVY` diff --git a/docs/development/03-module-size-and-complexity.md b/docs/development/03-module-size-and-complexity.md index 9d164eeb7..6dcc6fc00 100644 --- a/docs/development/03-module-size-and-complexity.md +++ b/docs/development/03-module-size-and-complexity.md @@ -180,9 +180,11 @@ Every new or changed continuity surface is reviewed as one narrow chain: an explicit gap, never silently treated as complete. **Control-plane distrust is metadata, not a data-plane operation.** Paid model -output is evidence until a typed validity predicate fails. Distrust of profile, -route, parser or window may lower authority to DEGRADED/SKIPPED/NOT_RUN, but it -must not blank, rewrite or relabel the artifact or its original cause. +output is evidence until a typed validity predicate fails. Actual profile, +route or subject mismatches, invalid output contracts and delivery failures may +affect review authority; window sizing and reading diagnostics alone may not +(BIBLE P3). Neither case blanks, rewrites or relabels the artifact or its +original cause. Enforcement: CHECKLISTS item 25 `source_completeness` (critical when applicable) scores the chain in commit review; the presentation-adapter @@ -312,4 +314,3 @@ geometry/refresh contracts are pinned in `tests/test_widgets_ui_static.py` and `tests/test_extension_surfaces.py`. --- - diff --git a/tests/test_docs_sync.py b/tests/test_docs_sync.py index 30062e63e..4cc6f1a74 100644 --- a/tests/test_docs_sync.py +++ b/tests/test_docs_sync.py @@ -419,8 +419,10 @@ def test_continuity_projection_contract_is_mirrored_across_governance_docs(): def test_architecture_names_all_window_surfaces_and_settlement_order(): architecture = _read("docs/ARCHITECTURE.md") - assert "keeps the full-window assumption on every surface" in architecture - assert "there is no window floor for a blocking verdict on any surface" in architecture + assert "full-window sizing default for an unknown API window" in architecture + assert "raw subscription routes keep no numeric unknown-window assumption" in architecture + assert "designated-default or conservative fallback" in architecture + assert "no model-window table or window-authority floor" in architecture assert "SETTLED is published before registration retirement" in architecture