mirror of
https://github.com/razzant/ouroboros.git
synced 2026-10-03 12:18:39 +00:00
adoption: every sanctioned deferral and every disclosed-not-done item is a post-release row
Only ABI-8 carried status=deferred; nine owner-sanctioned deferrals lived as prose inside done rows or in ledger sections, and several disclosed-not-done items lived nowhere the release bar reads. Each now has an explicit post-release row (owner quote or the disclosing ledger section in the text) and an authority entry in DEFERRED_OUT_OF_V70: owner — headless cancel receipts (batch #7 5=A), the two frozen-package modules (batch #9 #12=A), the C6 disclosed residuals (batch #12 A), task_results eternal (batch #8 5=A); operator-disclosed, each an open item of the STOP batch — W4-F3/W4-F4, the mutating delegation scenarios, the never-executed paid E2E lane, the five typed process-fact surfaces, spec 6.4 paths/roots, the F23 acceptance capsule. The validator both modes and the wrapper suite stay green.
This commit is contained in:
parent
abea91ec85
commit
d348ea463e
2 changed files with 30 additions and 0 deletions
|
|
@ -95,6 +95,17 @@ Schema (fixed; one row per artifact-level delta family, never per commit):
|
|||
| DEFER-BROWSER | plan-item | Gateway/UI-truth E2E actor — the real-browser client over an isolated server's own web UI. DEFERRED OUT OF 7.0 BY THE OWNER: batch №9 №14 (2026-09-01, requirements archive [A-BATCH-9-ANSWERS]), owner verbatim «14. A» on the option recorded as «браузерная волна пост-релиз, смоук зелёным до тега» — the browser wave is post-release and the condition on the tag is a green smoke, not a green browser lane. tests/system_e2e/interfaces.py therefore keeps `PlaywrightUIClient` as an interface stub that REFUSES instantiation (NotImplementedError naming the gateway/UI-truth lane) instead of a fake that would read as coverage, and the refusal is itself pinned so the stub cannot rot into a silent no-op. residual: no system-level E2E scenario drives the real web UI in 7.0 — every UI claim of the campaign rests on the marker-gated Playwright smoke and on the owner's own manual pass, not on this actor | post-release | deferred | POST | tests/system_e2e/test_system_scenarios.py::test_interface_stubs_refuse_instantiation_until_their_lanes_land + tests/system_e2e/interfaces.py |
|
||||
| W4-F1 | plan-item | Crash window between the reviewed `git commit` and its receipt: a crash between `git commit` and `record_evolution_commit` leaves a landed reviewed commit that NO boot path will ever attribute — the markerless reconcile short-circuits on an empty `commit_sha` (it only stamps the generation) and `_preserve_evolution_orphan` runs on the authority-refusal path only. The commit is not lost as code; the cycle never resolves and is never counted. Found by the F4 wave-4 system-E2E lane, which by its own rule fixes nothing it finds (W2-F2 was the single sanctioned exception), so it enters the manifest as a POST-RELEASE disposition rather than being carried silently. residual: the attribution gap stands in 7.0; call sites and evidence in the wave-4 findings table | post-release | deferred | POST | docs/v7next/LEDGER_CORRECTIONS.md («From the F4 wave 4» section, W4-F1 row of the findings table: ouroboros/tools/git.py:1411-1436 commit→receipt order, ouroboros/tools/git_evolution.py:272-330, ouroboros/agent_startup_checks.py:1130-1142) |
|
||||
| W4-F2 | plan-item | Absorb outcome ledger atomicity: the campaign absorb write and the `cycle_outcome` checkpoint append are not one transaction — the reconcile writes the campaign under `update_json_locked` and appends the checkpoint row AFTER the lock (same shape on the claim path), so a crash in between yields a campaign that says `absorbed` with no `cycle_outcome` row, `build_solve_capability_digest` under-reports that cycle forever and nothing re-derives the row. Same wave-4 lane rule as W4-F1: disclosed, not fixed there; POST-RELEASE by disposition. residual: the digest can under-count absorbed cycles in 7.0; S22 pins only that the row IS written on the clean path | post-release | deferred | POST | docs/v7next/LEDGER_CORRECTIONS.md («From the F4 wave 4» section, W4-F2 row of the findings table: ouroboros/agent_startup_checks.py:1227-1243, locked `update_json_locked` then post-lock `_append_cycle_outcome_tag`) |
|
||||
| DEFER-HEADLESS-CANCEL | plan-item | Panel stop receipts for headless (API/CLI-origin) tasks: a task not born in a chat gets no `cancel_receipt` block in the details panel after cancellation (W2-F1 of the F4 wave-2 system-E2E lane). DEFERRED OUT OF 7.0 BY THE OWNER: batch №7 item 5 (2026-09-01, requirements archive [A-BATCH-7-ANSWERS]), owner verbatim «5. A» on the option recorded as «панельные стоп-квитанции headless-задач — пост-релиз». residual: a `ouroboros run`/HTTP-API caller sees no stop receipt (who cancelled, what finished, what was spent) in 7.0; chat-origin tasks keep theirs | post-release | deferred | POST | docs/v7next/LEDGER_CORRECTIONS.md (F4 wave-2 table, row W2-F1; «Owner closures for the F6-sync forks») |
|
||||
| DEFER-FROZEN-2 | plan-item | Two modules of the frozen-contracts package (`ouroboros/contracts/task_constraint.py`, `ouroboros/contracts/skill_payload_policy.py`) are not listed in the §11.1 frozen table and carry no anchor test. DEFERRED OUT OF 7.0 BY THE OWNER: batch №9 re-ask (2026-09-01), owner verbatim «согласен со всеми рекомендациями твоими» on recommendation №12=A «not now; disclose the gap until post-release». residual: both contracts can change without breaking the frozen table or a mandatory anchor test in 7.0; the package set is pinned by tests/test_generated_inventories.py (a third module is red CI) | post-release | deferred | POST | docs/v7next/FROZEN_CONTRACTS_INVENTORY.md («Package coverage») + docs/v7next/LEDGER_CORRECTIONS.md (CPL-2 item 6) |
|
||||
| DEFER-C6-RESIDUALS | plan-item | Disclosed residuals of the CPL4-C6 monetary-ledger compaction (docs/v7next/C6_REVIEW_PACKET.md §5, §10): on a filesystem the kernel says cannot lock (name tier) the pass never compacts and the ledger grows to the 20 MB tripwire; on a lockd-less NFS `state/` every monetary write refuses typed (ENOLCK, money only — other locks keep the name protocol); on Windows a charge landed inside the swap's one rename syscall is lost silently (POSIX quarantines it); subscription/external/legacy/review rows never fold; orphan archive segments are never GC'd; the two usage suites sit exactly at their line caps. DEFERRED OUT OF 7.0 BY THE OWNER: batch №12 (2026-09-02 ~12:50Z, [A-BATCH-12-C6-SYNC]), owner verbatim «A» on «микро-раунд 5.4 … LOW-остаток интегрируется с раскрытием, HIGH-остаток → назад к владельцу» (no HIGH remained). residual: as listed; the test-suite cap is an owner question (C6-TESTCAP) | post-release | deferred | POST | docs/v7next/C6_REVIEW_PACKET.md §5 + §10; docs/v7next/DESIGN_USAGE_COMPACTION.md §8/§10/§12 |
|
||||
| DEFER-C19-RETENTION | plan-item | `task_results/<id>.json` are kept forever — no retention is introduced in 7.0 (CPL-4 item C19). DEFERRED BY THE OWNER: batch №8 item 5 (2026-09-01, [A-BATCH-8-ANSWERS]), owner verbatim «5. A» on «task_results eternal for 7.0». residual: `data/task_results/` grows monotonically for the life of an install; only a full data reset clears it | post-release | deferred | POST | docs/PERSISTENCE.md (task_results row) + ADOPTION row CPL-4 (C19 record) |
|
||||
| W4-F3 | plan-item | Evolution restart marker vs manual restarts: `request_evolution_restart` returns BEFORE writing `pending_restart_verify.json` when `OUROBOROS_EVOLUTION_AUTO_RESTART` is off, so the exact-claim verify path (`require_claim=True`) is structurally unreachable for installs that restart by hand; absorb attribution then rests on the weaker markerless path. Found by the F4 wave-4 system-E2E lane (docs/v7next/LEDGER_CORRECTIONS.md «E2E-находки w4»), judged «looks intentional», not fixed by that lane's rule; no owner decision recorded. residual: manual-restart installs never exercise the strict verify path in 7.0 | post-release | deferred | POST | docs/v7next/LEDGER_CORRECTIONS.md (w4 findings table, row W4-F3) |
|
||||
| W4-F4 | plan-item | Rescue-local ref accumulation: `create_rescue_local_ref` pins every update stash to a durable `rescue-local-<stash12>` branch and nothing ever deletes them — a refused/unwound attempt leaves its ref exactly like a successful one. Deliberate durability («git-gc can never lose the owner's work»); the unbounded per-distinct-stash growth is the disclosed cost. Same wave-4 lane; no owner decision recorded. residual: the branch list grows with every distinct update stash in 7.0 | post-release | deferred | POST | docs/v7next/LEDGER_CORRECTIONS.md (w4 findings table, row W4-F4) |
|
||||
| DEFER-E2E-DELEG-MUT | plan-item | System-E2E scenarios for MUTATING delegated runs (snapshot + patch pull-in + isolation proof) were carried across the F4 waves and never landed: S1-S23 contain only non-mutating delegation runs. Declared «deferred (disclosed)» by the operator in the wave-3b and wave-4 ledger sections; no owner decision recorded (owner question in the STOP batch). residual: the one delegation branch that changes the working tree on behalf of an external harness has no system-E2E cover in 7.0 | post-release | deferred | POST | docs/v7next/LEDGER_CORRECTIONS.md («Deferred (disclosed)» in the F4 wave-3b and wave-4 sections) |
|
||||
| DEFER-E2E-PAID-LANE | plan-item | The paid («live») system-E2E lane — E1 (delegated launch → wait → answer → cancel), E2/E3 (clean and conflicting delegated patch pull-in) and E13 (a task with an exhausted budget PAUSES before dispatch, replacing the withdrawn E8) — is written (tests/test_e2e_cancellation_scenarios.py, fixtures_e2e_cancellation.py LANE_PAID) and has never been executed: it needs a model with a known price, which the mock lane has not. Plan §8/§10 made an owner-live quittance on the exact SHA an acceptance criterion; no owner decision to waive it is recorded (owner question in the STOP batch). residual: the four scenarios are unverified on any SHA until the owner either runs them (units of $) or waives the criterion | post-release | deferred | POST | tests/test_e2e_cancellation_scenarios.py (module docstring) + tests/fixtures_e2e_cancellation.py (LANE_PAID) |
|
||||
| DEFER-TYPED-PROC-5 | plan-item | Owner batch №7 item 1=A retired the regex fallback that guessed process exit codes from prose; five surfaces were left WITHOUT typed exit/signal facts: extension child-process death, `skill_exec`/`skill_preflight`, `verify_and_record` (prints `exit=` but stamps nothing), `run_command` timeouts and pre-exec failures, Windows kills. The ledger promised to batch this to the owner («candidate post-release train … to be batched») and the batch never happened; recorded here so it cannot pass as shipped (owner question in the STOP batch). residual: those five surfaces show «no fact» instead of an exit code or signal in the UI and tools.jsonl in 7.0 | post-release | deferred | POST | docs/v7next/LEDGER_CORRECTIONS.md («Q-F6-1 provenance investigation», items 4-5) |
|
||||
| DEFER-PATHS-6.4 | plan-item | Spec §6.4 «Paths/roots» (OUROBOROS_V7_SPEC_v72.md ~:815-820) — one `HostPaths`/`TaskPaths` authority, removal of the two `SimpleNamespace` Env clones in agent_task_pipeline.py (:241, :681) and of the silent `Path.home()/Ouroboros/data` fallbacks in seven domain modules — was never delivered on the oracle or here and never entered any inventory or decision; the bytes are inherited from upstream (no regression). Recorded so the undone scope is visible (owner question in the STOP batch: post-release or 7.0). residual: with an incomplete OUROBOROS_* env set a process can still resolve two different data roots without an error | post-release | deferred | POST | OUROBOROS_V7_SPEC_v72.md §6.4 (the requirement); this row (the only tracking) |
|
||||
| DEFER-F23-ACCEPTANCE | plan-item | Roast recommendation F23 — a machine-readable `acceptance.json` with schema and checker (exact SHA, run/artifact ids, scenario consumption, D02-D38 dispositions with decision ids, review quorum, cost cap) — was accepted into the plan (V7NEXT_PLAN.md :261) and never built; the release bar (`scripts/v7next_adoption.py --release`), `scripts/rc_audit.py` and the exact-SHA evidence manifests cover part of it (rows/hooks/gates), not quorum, cost or scenario consumption. Recorded so the gap is visible (owner question in the STOP batch: build before the tag / post-release / close as covered-by-gates). residual: campaign acceptance is proven by the evidence manifests and the validator, not by one generated capsule | post-release | deferred | POST | docs/v7next/LEDGER_CORRECTIONS.md (final evidence sections) + scratchpad evidence manifests (operator-held) |
|
||||
|
||||
Notes:
|
||||
|
||||
|
|
|
|||
|
|
@ -99,6 +99,25 @@ DEFERRED_OUT_OF_V70 = {
|
|||
# shipped, and so the owner can pull either into 7.0.
|
||||
"W4-F1": OPERATOR,
|
||||
"W4-F2": OPERATOR,
|
||||
# Owner-sanctioned deferrals that lived as prose inside done rows or in the
|
||||
# ledger until the stage-2 bookkeeping made them rows (quotes in each row):
|
||||
# batch №7 5=A (headless cancel receipts), batch №9 №12=A (two frozen modules),
|
||||
# batch №12 A (C6 residuals), batch №8 5=A (task_results eternal).
|
||||
# Operator disclosures without an owner decision yet (each an open item of
|
||||
# the STOP batch): the wave-4 observations W4-F3/W4-F4, the mutating
|
||||
# delegation scenarios, the never-executed paid E2E lane, the five typed
|
||||
# process-fact surfaces, spec §6.4 paths/roots, the F23 acceptance capsule.
|
||||
"DEFER-HEADLESS-CANCEL": OWNER,
|
||||
"DEFER-FROZEN-2": OWNER,
|
||||
"DEFER-C6-RESIDUALS": OWNER,
|
||||
"DEFER-C19-RETENTION": OWNER,
|
||||
"W4-F3": OPERATOR,
|
||||
"W4-F4": OPERATOR,
|
||||
"DEFER-E2E-DELEG-MUT": OPERATOR,
|
||||
"DEFER-E2E-PAID-LANE": OPERATOR,
|
||||
"DEFER-TYPED-PROC-5": OPERATOR,
|
||||
"DEFER-PATHS-6.4": OPERATOR,
|
||||
"DEFER-F23-ACCEPTANCE": OPERATOR,
|
||||
}
|
||||
# Post-cutoff upstream adoption trains: id -> (upstream tip, campaign merge).
|
||||
# A frozen inventory rather than a git derivation, and the history is the
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue