NOT_REVIEWED integration checkpoint for READY 02-COGNITION. Contains linked knowledge, book composition, source retention, Nano view primitives and native multiwindow review. Full phase review, shared model/loop wiring, book migration and live acceptance remain pending. No version bump, tag or public delivery.
`duplicate_bodies` extracted a source segment for EVERY function in the module
population, including one-liners that can never reach the ten-line literal-copy
floor. `ast.get_source_segment` re-splits the whole file per call, so the scan
paid O(source) for each short function.
The span a node already carries (`end_lineno - lineno + 1`) decides whether the
slice is worth taking. This is output-identical by construction, not merely by
test: `_normalize_body` dedents, rstrips and DROPS blank lines, so a normalized
body can never have more lines than its raw span, and a node whose span is below
the floor could never have satisfied the existing normalized-line check. The
recursion into nested functions stays unconditional, so a long inner function
inside a short outer one is still scanned.
Oracle, over the full module population with every module given its own domain
so every digest group surfaces as a row: byte-identical output (3 rows, same
sha256) before and after, 31.1s -> 21.4s. `scripts/check_domains.py` exits 0
with "OK: domain manifest complete", and the `[duplicates] allowed = []`
baseline is untouched in both directions.
The new boundary test pins the floor exactly: a cross-domain copy of exactly
DUPLICATE_MIN_LINES lines is still detected, one line shorter is not. Verified
load-bearing - changing the filter to `span > min_lines` reddens it.
Keep runtime terminal custody and UI model history alongside the source-complete tool review path. Generated inventories derive from this combined tree.
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
Keep capture, replay, comparison and drift artifacts byte-paired through the existing reversible codec. Cover LF and CRLF blobs, autocrlf settings, Windows text pipes and unchanged custody handling.
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
- devtools/measure_review_pack.py: the quorum limit and headroom are sized over
the rows that RECEIVE the api pack — api_chat rows without a configured-
subagent binding, decided by review_execution.delivery_retrieves exactly as
review._prepare_unified_review decides before fit_triad_prompt; an all-
retrieving panel reports 'no API pack is assembled for this panel' instead
of a number (codex MAJOR). The 'index IS the working tree' comment became a
checked invariant: an unstaged edit or an untracked file is the typed
MeasuredCheckoutDirty refusal (exit 2), and the advisory arms are re-checked
to resolve the same path set (fable MINOR).
- ouroboros/tools/claude_advisory_review.py: the native advisory slot is built
by the dispatch builder (reviewer_slot_config.reviewer_slots), so use_local
comes off the resolved route and a LOCAL advisory model previews its
MANDATORY READ bound on its own window with the typed shortfall disclosure,
instead of the remote/unknown route's (codex MAJOR); file stays at 1492 lines.
- ADOPTION_v7next.md / scripts/v7next_adoption.py: the Notes no longer call
W4-F4 operator-disclosed; a 'Deferral authorities:' declaration mirrors
DEFERRED_OUT_OF_V70 and the validator refuses a declaration that disagrees
with the register (codex MINOR).
- docs/archive/v7next/LEDGER_CORRECTIONS.md: one-row note that the immutable
band rationale for claude_advisory_review.py cites 1434 lines while the file
stands at 1492 (fable minor).
Tests: tests/test_measure_review_pack.py (3 new, red-first), tests/test_advisory_route_pack.py (1 new, red-first), tests/test_v7next_adoption.py (2 new).
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
(cherry picked from commit eca294f4520802f2f3b64eaaa7e236d19899b4a5)
Owner answer of 2026-09-04 («5. A»): the restart marker is fixed now (W4-F3),
the rescue-local ref accumulation stays deferred with the quote on the row
and a backlog item for deleting the refs of refused/unwound updates. The
deferral register marks the row OWNER so the authority lint enforces the
quote.
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
request_evolution_restart wrote state/pending_restart_verify.json only when
OUROBOROS_EVOLUTION_AUTO_RESTART was on, so an install that restarts by hand
never reached the exact-claim verify path and absorb attribution fell back to
the markerless boot reconcile. The knob now skips only the restart itself.
- one writer helper (write_pending_restart_marker) and one schema for the
supervisor path and the agent's restart tool; the claim key only for an
exact claim; PERSISTENCE names the single writer
- S22 keeps its markerless-reconcile contract: generation A pins that the
marker IS written with auto-restart off and the tree does not restart, then
shapes the crash-window durable state (two atomic files) after the kill
- ADOPTION row W4-F3 re-prove/done/F6 with the owner quote; DEFERRED_OUT_OF_V70
drops it; ARCHITECTURE names the always-written claim; ledger section
(cherry picked from commit 90ed3720740c1e02e49ae16a52dff8f648784fd2)
The manifest's Notes called W4-F3/W4-F4 rowless for two days after d348ea46
made them rows, past a green --release bar: the validator read table rows and
never the prose. Class fix in scripts/v7next_adoption.py: manifest_prose() +
_prose_id_errors() resolve every id-shaped token outside the table against the
table by the table's own id grammar (a rowless id is declared on a
'No-row ids:' line; a declared id with a row is red), and the post-release
authority record is linted against the row text (an OWNER deferral carries the
'owner verbatim «…»' quote, an operator disclosure carries none) — the comment
over DEFERRED_OUT_OF_V70 had drifted from its values (E2/E3, spec §6.4).
Disclosed: a rowless claim in free English is not read; a word marker was
tried and misfired on 'No row carries pending-decision any more'.
Row corrections read from the rc.9 tree: ABI-8 carries its owner quote («6. ок»,
batch №7); DEFER-C6-RESIDUALS — C6-TESTCAP closed by batch №13 item 11 = A, the
split landed (900 + 660 lines), platform_layer pay-down stays post-release;
DEFER-E2E-PAID-LANE — the 'never executed' opening that stood glued to the
executed receipts is gone, «2. A» named as the run order and the E2/E3
remainder as a structural block (OWNER value unchanged). Ledger: the w4 findings
anchors re-read after the F2 relocation, the 'no row' note superseded, and an
F3-C section with the facts the owner batch must carry. W4-F3, W4-F4 and
DEFER-SPEC64-PATHS rows are untouched — they wait for the owner's word.
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
(cherry picked from commit 2a6bdb223d2c0bd82699680990b6b8eaa1d90e0a)
Second parent is the frozen upstream `ouroboros` head (23ab428f, 407 commits
since the merge base a76961de); first parent is v7.0.0-rc.8 (18b9832e).
Every upstream change lands in v7's owning leaf: S1 transplants keep upstream's
bodies (comments verbatim) under the call-time handle idiom, S2 hand-merges keep
both intents, S3 keeps v7 only with proof (retired 7.0 ABI surfaces, superseded
mechanisms). Per-symbol relocation ledger: docs/archive/v7next/LEDGER_CORRECTIONS.md
(F2 absorption section). Provisional decisions awaiting owner ratification:
D-18 (two-destination symbols), D-19 (acceptance rows follow upstream R2),
D-20 (acceptance_dialogue stays deleted), D-21 (tools/registry.py: facade
import block only).
Docs: upstream ARCHITECTURE/DEVELOPMENT as the base with compact v7 deltas;
bookkeeping moved to docs/archive/v7next. Size-ratchet manifest, domain
manifest and generated inventories regenerated; new leaves: tools/write_shape
walker, gateway/cost_breakdown, tools/core_secret_paths; provider_catalogs.py
and acceptance_dialogue.py removed (v7 owners).
Target drift since the sprint base (PR #557-#591: the agentic-review synthesis
moved the acceptance machinery whole into acceptance_dialogue.py, three-delivery
rows, Claudexor 3.9.7, ibl fixes). Resolutions: the acceptance-packet changes
(children debt, dialogue history and the packet budget passed INTO the bounded
builder; per-slot input caps on the panel request; packet sizing from the same
triad delivery rows the panel dispatches) are carried into the relocated module;
a partial tool-result projection withholds packet rows only for a genuinely
unavailable source (the legacy truthy sentinel still refuses) and never
retrieving rows; a report-shaped native episode keeps its draft on a budget
refusal after the failed send is observed; ARCHITECTURE/DEVELOPMENT merge both
sides' rows and paragraphs; the upstream acceptance-delivery test now asserts
the documented `not_dispatched` refusal shape (a refusal is a transport state,
never a verdict).
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
Sixth authoritative review: the trajectory source ref pointed at
get_task_result(...).llm_trace.tool_calls, which no reader serves — the complete
redacted tool-call corpus is now persisted in the task artifact store as a
content-addressed JSON artifact and the ref is a canonical
`artifact_store:<path>#chars=…` that read_file resolves (persistence failure →
source_unavailable); a failed root-task projection append no longer reports
success — append_history_once returns False, writes a durable gap row
(state/skill_review_root_tasks.gaps.jsonl) that the reader folds into coverage
(complete=False with the reason) and the runner receipt names it; the
contributor-lane substrate inventory and its coverage test gain
review_dispatch.py, review_actor_aggregation.py and delegate_custody_usage.py;
review_evidence.py sheds four lines (1596). Manifest untouched.
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
Fifth authoritative review: leading omissions and recaps with a durable
get_task_result reference are not_materialized_for_reviewer again (dispatchable,
non-resolving) — only source-less rows withhold the panel; contributor receipts
take agent-session settlement exclusively from the final custody replay, and a
missing or unreadable custody row is a typed mismatch instead of trusting the
response's self-report; the skill-history projection discloses rows scanned,
truncation, gap reasons and a canonical source, and an incomplete projection is
non-resolving; settlement publication and last-sibling retirement sit under a
stable project-digest file lock that holds across worker processes; the host's
late acceptance fields enter the packet builder before the single budget
enforcement; ARCHITECTURE names all four window-aware surfaces and documents
SETTLED before registration retirement. loop.py 282 903 bytes (−765). Manifest
untouched.
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
Integrates the moved target (193 commits over the sprint base b9bcc2da,
release 6.114.0 — the DeepSeek landing PR #563 and the docs-consolidation
PR #556 included) into the synthesis branch without rewriting history.
Four files conflicted; each was resolved by substance so BOTH sides' facts
and behaviours survive:
- ouroboros/size_ratchet_manifest.py (generated): UNION of both sides'
BAND_PATHS rationales (the target's ouroboros/gateway/extensions.py,
tests/test_provider_contract_ci.py, tests/test_ui_smoke_project_continuity.py
and web/modules/settings_ui.js beside our acceptance_dialogue.py,
deep_self_review.py and test-suite rows), then regenerated for the merged
tree: ouroboros/gateway/history.py left the band on the target line,
BYTE_DEBT is the live merged size everywhere (loop.py 272905,
tests/test_devtools_benchmarks.py 328068 — below both parents — and
web/modules/chat.js 206949). `scripts/regenerate_size_ratchet.py --check`
is green; no new module, function or byte debt.
- docs/ARCHITECTURE.md and docs/DEVELOPMENT.md: the target's consolidated
structure is the frame; every agentic-review fact of this branch is placed
in the target's section or row — the three deliveries of task acceptance
and deep self-review, the reviewer-row schema (`deep_review` singleton,
roster references, `profile_id`), pacing simplified to the one admission
floor (R52/R55; the EWMA sentences are gone), poll purity, the native
read receipts and BIBLE.md coverage, the retrieving work order and the
CI methodology job. The module-tree rows keep the target's condensed form
extended with our contracts; the full contracts live once in §6 (Task
lifecycle, Review delivery, Deep self-review). Stale target sentences
that our side retired (the `api_chat` acceptance pin, the round cap, the
legacy/default API panel residual) are replaced, never duplicated.
- ouroboros/review_native_episode.py: our side already measures the send
bound as the wire size of the serialized message list, which carries the
WHOLE assistant dict — `reasoning_content` included — so the target's
fix (count replayed reasoning in the fail-closed bound, 295c9062) is
subsumed; the target's regression test passes unchanged. The comment
above the append records the invariant.
Auto-merged both-changed files were checked for silent overlap:
tests/conftest.py gained the same autouse os.environ snapshot/restore
fixture on both sides — the target's tested `_os_environ_isolation` is
kept and our redundant `_restore_process_environment_between_tests` is
dropped (its rationale folded into the surviving docstring); our
gateway-settings binding restore fixture stays. .github/workflows/ci.yml,
ouroboros/config.py, ouroboros/tools/control.py, web/modules/settings_ui.js
and web/modules/reviewer_slots.js carry both sides' changes exactly once
(our deep self-review block sits in the target's new `.reviewer-slots-group`
container like its advisory sibling).
Observed live: agent_session slots settle while sibling runs of the same Claudexor
project are still live, so `retire_project` defers removal and every receipt but
the last one carried `project_retired=False` forever, blocking the lane with
`session_settlement_unproven` even when the whole panel responded. Receipts now
bind the settlement projected from the custody replay after every panel slot
finished (AP8). When receipts mismatch, the outcome keeps `original_block_reason`
and `original_message`, so a preflight failure is no longer erased by the
receipt-mismatch override (AP9).
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
DEFER-E2E-DELEG-MUT is done at phase F4; the O3 copy-back race and the
/proc-environ marker race are rooted and fixed (626b48b7). ADOPTION/validator
conflicts resolved by row; ledger union-merged.
Owner batch №13 item 15 = B. Every F4 wave delegated only READ-ONLY runs and
disclosed the same gap: the ONE delegation branch that changes the owner's tree
on behalf of an external harness had no system-level cover. What was missing was
not scenario prose but an ACTOR — the fake daemon had no mutating half, so no run
could produce the applied facts an integration reads.
FakeClaudexorDaemon gains exactly that half and nothing else: on [FAKE:MUTATE] a
run edits the workspace its OWN start body named — read from
execution.workspaceRoot, the private snapshot, never from scope.root, so the fake
cannot break the isolation the scenarios exist to prove — and writes
<runDir>/attempts/a01/attempt.yaml in Claudexor's applied-facts shape, which is
the only evidence attempt_containment has that the harness HOME was scoped and an
OS boundary applied (the mechanism is written WITH its proven denied path,
because a mechanism without one is read as no boundary at all).
S24 (clean pull-in): an external-workspace task delegates access=workspace_write;
the host provisions the private Git snapshot; the harness edits it; delegate_wait
captures; integrate_delegated_patch(apply) stages into the live workspace.
Pinned: the durable custody chain (STARTED with access/mode/snapshot_id/
execution_root/baseline_sha → PATCH_CAPTURED → APPLY_STARTED → DISPOSED(applied)
→ the patch_verdict row whose patch_sha256 equals the capture manifest's), the
capture artifacts, the containment facts reaching the model (os_boundary named
from the run's own attempt record, no delegate_run_unconfined row), the
staged-not-committed contract, and the released snapshot. The ISOLATION proof is
causal, not timed: the script step that runs after the wait returned executes in
the test process, so it reads the live workspace at a point the server's own
ordering places between the capture and the decision — the run's file is absent
and tracked.txt is still the owner's.
S25 (conflicting pull-in): the same step writes the drift before answering with
apply. The apply is refused typed (INTEGRATE_CONFLICT / baseline_drift), nothing
is disposed, the live file keeps the OWNER's content, and snapshot + registry row
+ patch all survive as resolution material. Recorded rather than fixed (no
defect): a task that ENDS holding an undisposed captured patch is not a success —
its terminal is failed / delegated_custody_unreconciled with the model's answer
kept verbatim — and S25 pins that vocabulary.
Red-first for a coverage lane is the absence of the capability, so it is recorded
as a CONTROL run: with the fake's mutating half disabled, S24 fails at
assert 'ready_no_changes' == 'ready_with_changes'.
Full lane: 61 passed (16:47), rc 0. ADOPTION row DEFER-E2E-DELEG-MUT reads done at
phase F4 with a hook naming the three tests and leaves DEFERRED_OUT_OF_V70;
--release green. The WINWAVE registry paragraphs that carried the /proc-environ
flakiness and the open O3 copy-back question now name 626b48b7 as the root fix.
E13 is green on a priced route (openrouter::anthropic/claude-haiku-4.5); E1 is
green once its assertion reads open containment faults rather than the faults
LOG (which carries resolution rows). E2/E3 reach the real Claudexor lane and are
refused there — «Claude subscription route is not ready»: delegate_start asks
for the subscription substrate on purpose and an isolated install's owned
daemon has no login, which only the owner may create. Row DEFER-E2E-PAID-LANE
keeps its deferral under OWNER authority with that residual. Product finding
recorded: a data root deep enough to push the owned daemon's unix socket past
AF_UNIX's limit refuses every delegated start (`listen EINVAL`).
Publisher-scoped typed-fact channel; extension children, skill_exec,
skill_preflight (no more synthetic -9/-1), verify_and_record, run_command
timeouts and Windows host kills all publish what the platform gives and nothing
it does not. ADOPTION/validator conflicts resolved by row (TYPED done from the
lane; SPEC64 owner authority and F23 done from the base); ledger union-merged.
Owner batch #13 item 10 = B: the five surfaces that still lacked typed
process exit/signal facts land in 7.0 (ADOPTION row DEFER-TYPED-PROC-5 is
done). The regex harvest stays retired (batch #7 item 1 = A); nothing here
reads prose, and where the platform gives no fact none is synthesized.
The thread-local channel becomes PUBLISHER-scoped instead of tool-name-scoped:
_PROCESS_META_TOOLS (two names, unable to list a dynamic ext_* surface) is
retired and the loop clears the slot before EVERY dispatch, which is a stronger
no-contamination contract than the name gate it replaces. The fact family gains
three members that exist exactly where an exit code does not: timed_out,
killed_by_host and pre_exec_failure (the platform's exception class).
Producers stamp at the point the truth is known:
- extension child (_run_child): clean/abnormal exit with its POSIX signal,
deadline kill, output-cap kill;
- skill_exec (_run_skill_subprocess): the real negative code its
"returncode or 0" return flattens, the deadline and output-cap kills, and
the spawn OSError;
- skill_preflight (_run_check): the synthesized -9/-1 are RETIRED for
returncode=None plus the typed reason (they read downstream as real POSIX
signal deaths, on Windows too, where a host kill produces none);
- verify_and_record: the check's exit/signal or its timeout kill, with the
receipt now copying that one publication instead of deriving duration and
signal a second time;
- run_command: timeout and pre-exec failures.
Windows kills are carried honestly rather than faked: killed_by_host beside
whatever TerminateProcess left in exit_code, never a fabricated signal name.
Windows-executed proof pending the matrix.
One projection carries the family into the UI live-log card, the tools.jsonl
row and the durable trace. ouroboros/contracts/ is untouched; the typed meta
shape grew additively in tools/process_facts.py only.
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
W4-F1: a crash between the reviewed git commit and its receipt is attributed on
the next boot from the durable commit intent (tree + parents), fail-closed.
W4-F2: a missing cycle_outcome row is re-derived on boot. Ledger union-merged.
Owner batch #13 item 9 = B pulled the two crash windows the F4 wave-4 lane
disclosed (W4-F1, W4-F2) into 7.0. Both are fixed where the durable fact is
written, not by a new guard.
W4-F1: the reviewed evolution commit is now two-phase. The pre_commit_authority
boundary - the last gate before `git commit`, which already rechecks the exact
claim - records a commit_intent (the reviewed tree and parents of the
post-review binding) on the active transaction. Boot reconciliation adopts the
commit sitting on HEAD only when its tree AND full parent list match that
intent, and writes the commit_receipt the crash never wrote, so restart
authority validates a receipt as exact as the tool path's. The task-done
classifier consumes the same intent, so a crashed commit-bearing cycle is no
longer closed as no_op before boot runs. Containment, the one writer that
disowns a commit, clears the intent in the same act.
W4-F2: the cycle_outcome row is re-derived rather than made atomic. The append
stays outside the campaign lock (a ledger failure must not break the restart
path); instead boot replays every commit-bearing resolved transaction that has
no row (source: boot_backfill, idempotent). The shared swallow-wrapper moved to
the ledger module that owns the write.
Red-first pins in tests/test_evolution_restart_claims.py; docs, ADOPTION rows
and the deferral registry updated.
The gate reviews found four code pointers still naming documentation that
moved or never existed — the residency docstring that contradicted its own
selector by treating project membership as the signal, a bench script naming a
C1 section, a UI smoke test naming a retired handbook heading, and the second
copy of the stale ARCHITECTURE line-count comment. Two module-map rows also
carried the size-gate extraction history they were split at; the rows now state
only what the module does and where it is re-imported.
Batch №13 answers (2026-09-02): item 7 = A — DEFER-F23-ACCEPTANCE is done with
the release bar as its hook and the uncovered parts (quorum, spend, scenario
consumption) in its residual clause; item 8 = A — DEFER-SPEC64-PATHS keeps
post-release under OWNER authority with the quote; item 17 = B — the spec's
«test split/delete disposition» and 20-question navigation artifacts are
withdrawn from the 7.0 acceptance by record. Release bar green.
The smalls2 lens found the first-boot notice fixed on one surface only: scripts/rc_audit.py
still told the owner the retired wall-clock pair has "no replacement knob" while
config.normalize_settings_raw names OUROBOROS_TASK_IDLE_TIMEOUT_SEC / _ABS_CEILING_SEC
from RETIRED_SETTING_SUCCESSORS. Both auditor sites now branch on the same table
(pin: tests/test_rc_audit_fixture_suite.py, red on the previous text). Prose: the
notice's "surface that replaced them" no longer presupposes a replacement; the
broadcast_ws docstring names the real writers of the module loop; the ledger's
ws.py:184 citation is marked as the instrumented copy's line and the "hanging run"
is explained (pytest assertion introspection over the 810 KB document,
--assert=plain fails in 0.13 s); the d21806d8 registry row and R-WINWAVE stop
calling rerun-greens first-attempt greens; the train-inventory comment says
"second-parent side"; the vision.py row lists the active task model first.
d348ea46 added eleven post-release rows whose ids the manifest's ID_RE refused
(DEFER-[A-Z0-9]+ allowed no hyphen), so the validator was red in both modes and
the wrapper suite failed — committed and pushed without gating on the rc (operator
error, fixed forward here). The id class now allows hyphenated DEFER tokens; the
one id with a dot is renamed. Validator both modes rc 0, wrapper suite green.
Only ABI-8 carried status=deferred; nine owner-sanctioned deferrals lived as prose
inside done rows or in ledger sections, and several disclosed-not-done items lived
nowhere the release bar reads. Each now has an explicit post-release row (owner
quote or the disclosing ledger section in the text) and an authority entry in
DEFERRED_OUT_OF_V70: owner — headless cancel receipts (batch #7 5=A), the two
frozen-package modules (batch #9 #12=A), the C6 disclosed residuals (batch #12 A),
task_results eternal (batch #8 5=A); operator-disclosed, each an open item of the
STOP batch — W4-F3/W4-F4, the mutating delegation scenarios, the never-executed
paid E2E lane, the five typed process-fact surfaces, spec 6.4 paths/roots, the
F23 acceptance capsule. The validator both modes and the wrapper suite stay green.
Hook resolution runs for every `done` row in BOTH modes — it is a property of
a shipped row, not of the --release invocation — but its five messages were
prefixed `release:` and the docstring still claimed «Outside --release hooks
stay free prose». A reader of a default-mode run was pointed at a switch that
had nothing to do with the failure.
Prefix is now `hook:`; the two genuine release-bar messages (pending-decision,
status != done) keep `release:`. The docstring says what actually gates the
resolution (`done`, not the mode), and the manifest's Notes now state the same
rule, so the code comment that cites them is true.
Red-first: the new parametrized pin drives four hook shapes (prose-only,
missing file, `tests/../` escape, bogus `::nodeid`) through the DEFAULT mode
and asserts no message claims the release bar. On the pre-fix shape 4 failed,
19 passed; after the rename 23 passed. The fifth message (unparseable hook
file) is not driven — it needs a planted syntax-error file — and is renamed
with the others.
No behaviour change: the same rows are red in the same modes.
The rationale for freezing REQUIRED_TRAINS instead of deriving it named the
wrong reason in two places (the comment and the ledger section). Re-derived
read-only with git:
20850191 parents 5187fcdc8d13373b absorb merge, sync #1b9ceed6e parents 3e4a6181f3fbfdbb absorb merge, sync #2f4abe0a5 parents 43dcc1d2a76961de absorb merge, sync #3
All three absorb merges DO take the upstream tip as their literal second
parent, so «only f4abe0a5 has an upstream commit as its literal second parent»
was false. What holds is the first-parent shape: only f4abe0a5 sits on this
branch's first-parent line; 20850191 and b9ceed6e were made on lane lines and
reached mainline as the second-parent side of a lane-integration merge over a
campaign commit (0aa74e9f over 816e7b82; 0f9a8daf over 4c32691e). The re-tie
merge f61ea3c2 is not the cause and cannot be: it is an ancestor of all three
syncs, so it predates them.
The widened alternative is quantified rather than asserted: «second parent
descends from a recorded upstream tip» matches 35 / 15 / 6 merges on this tree
for the three tips, so it would demand a train row for every lane merge made
after a sync. The example given was 8fb08d44, which is not a merge at all; the
C6 lane merge is 9faccf31, whose second parent it is.
The design is unchanged — still a frozen inventory, still no subprocess — and
the TRAIN-F6 row now names both the absorb merge 20850191 and the integration
merge 0aa74e9f, so the one row recorded by its carrier says so.
Nine documentation and generated-report defects verified on the tree, each pinned
red-first in tests/test_docs_sync.py: the component map gets a row for every
live runtime module (24 were missing) and a reverse-completeness pin; the
deep-review atlas row loses its removed compact-manifest retry; the settings
table gains its two missing keys and names the real owners instead of the
config.py facade (README, DEVELOPMENT, ARCHITECTURE invariant); startup's one
compat-pair write is stated instead of "persists nothing"; the CPL-5 design note
describes the landed observability-only contract; section 11.4 carries the ABI
7.0 window; the domain manifest is reachable from the handbook; the domain
report generator writes one trailing newline and the report is regenerated as
the current witness (git diff --check over the campaign range is clean).
Disclosed, not fixed: DESIGN_USAGE_COMPACTION.md §10 "CPL-5 not yet landed"
(stale on this tip; fixed in the integration follow-up) and the two stale
CHECKLISTS.md sentences (protected; owner question). Conflict:
LEDGER_CORRECTIONS.md (union). Gates: docs suites green, cheap gates rc 0.
witness is current again
Every section of the report appends a trailing "" separator, so
`"\n".join(L) + "\n"` turned the last separator into a blank final line and
`git diff --check` was red at DOMAIN_QUOTIENT_REPORT.md:1966 — on the one file
that is generated and never hand-edited. The generator now drops the trailing
separators before writing.
The report is also regenerated, because docs/DOMAIN_MAP.md links it as the
witness behind the pinned baseline and the committed copy was bound to HEAD
5187fcdc with 488 modules, 80 of them still `classification=proposed`, and a
domains.toml sha that no longer exists. It now reads 509 modules, zero
proposed, manifest drift none.
Pinned: the artifact ends with exactly one newline and the generator keeps the
strip. Deliberately NOT pinned: byte-identity to a regeneration — the header
carries a HEAD sha and a tree fingerprint, so that gate belongs to
docs/DOMAIN_MAP.md, whose only input is the manifest.
Three holes, each demonstrated by the manifest itself:
- A whole-file overwrite deleted the sync #2 train row and both validator
modes stayed rc 0. REQUIRED_TRAINS is now a frozen inventory of the
absorbed upstream trains (id -> upstream tip, campaign merge); a missing
or re-pointed row is red in BOTH modes. Frozen rather than derived from
git on purpose, and the comment says why: only one of the three recorded
sync merges has an upstream commit as its literal second parent, so a
second-parent rule would police one train of three, and the widened
"descends from an upstream tip" form would demand a row for every lane
merge.
- Hook `::nodeid` tokens were free text beside a resolved path. They are now
read by AST against the named file's functions, classes and module-level
bindings, so a hook cannot name a pin nobody wrote.
- A `done` row could say "NOT DONE" / "OPEN RESIDUAL" / "still owed" in its
own text. It now must either fix the status or declare what stays open in
an explicit `residual:` clause. A text-vs-cell lint on an operator
manifest, not a gate on any runtime decision.
Hook resolution moves from the --release invocation to the property it
actually is — something true of a shipped row — which is what the manifest's
Notes already claimed.
tests/test_v7next_adoption.py executes the bar: validate() in both modes on
the live manifest, plus a mutant per rule. ci.yml is untouched (protected);
the default pytest lane carries this file.
Three things were true of 7.0 and absent from the manifest:
- DEFER-BROWSER — the gateway/UI-truth E2E actor, deferred out of 7.0 by
owner batch №9 №14=A («браузерная волна пост-релиз, смоук зелёным до
тега»). The refusing PlaywrightUIClient stub and its pin are the hook.
- W4-F1 / W4-F2 — the commit-vs-receipt attribution crash window and the
absorb/cycle_outcome atomicity gap the F4 wave-4 lane found and, by that
lane's rule, disclosed instead of fixing.
W4-F3 and W4-F4 stay disclosed observations in the wave-4 findings table:
both are named asymmetries of decisions that already exist, not work owed.
The validator's single post-release allowlist becomes a record with an
authority per id: every post-release row must be listed, and a row of the
owner-approved required inventory may only be parked there by the owner, so
the anti-bypass property the old frozenset carried is unchanged while an
operator disclosure can also be stated as what it is.
The operator review script's substrate path set decides when a change touches
the review machinery itself (contributor lanes then review the reviewer). The
native tool-round episode, the retrieving-route verdict canonicalizer and the
execution projection were missing from it, so a change to how a native review
reads, bounds or parses its verdict did not count as a substrate change.
Add the three modules and pin them in the contract test; the test file
crosses into the 1001-1500 band with its rationale recorded.
CI run 33576588986 (Windows): the new attestation sentence carried a
Cyrillic letter, and printing the report through a cp1252 console raised
UnicodeEncodeError — five fixture-suite tests red. The sentence is ASCII
now and stdout/stderr are reconfigured with errors=backslashreplace, so a
future character outside the console's codec is escaped, never fatal.
Scope lane 1 findings 3-5: the scenario file still numbered itself S11-S14
and called the skills lifecycle deferred; the registry run table stopped at
the pending 196438c9 run while the ledger already knew later runs; the
ADOPTION notes named D04/D05/D06/D35 as owing work after their lanes landed.
R-WINWAVE flips to done on the green matrices 33569841899..33572515529.
The ABI-3/ABI-6д removal of the compatibility re-export was invisible to the
auditor's five classes and to its attestation list (scope lane 1, finding 2);
an install with an out-of-tree import of the old name now has the fact in the
attestation the owner signs.
Eleven landed rows flip to done with file hooks that resolve on this tree
(D07, D08, D09, D11, D31, D33, D34, D36, D37, D38, ABI-6 — four of them had
hook cells that could not resolve at all: a reference checker absent here,
a Ф4 scenario never built, prose plus grep verbs). Partial rows stay honest:
D03 pending (tests/test_settings_read_seam.py does not exist; the hook names
the two landed halves, phase F1 -> F6 together with the validator's
REQUIRED_PHASE, disclosed as an operator scheduling correction), D18 pending
on MIGRATION row 1030 (verified on the tree), R-WINWAVE pending until a
green Windows leg exists — its registry is docs/v7next/WINWAVE_CLASS_REGISTRY.md
(16 reference-wave classes plus the CRLF-vs-regex class the matrix found,
fixed by a0b35fcd; run 33555971481 @ 9a28e58f red for that class, run
33563498919 @ 196438c9 logged pending). Owner-decided rows carry the batch
№9 texts. Prose: 17 -> 18 delta families, CPL-1 488 -> 504 modules, and the
TRAIN-F6 provenance states the real order (operator inference 10:10Z,
owner sanction post hoc 19:12Z). CPL-4/CPL-5 untouched.
OUROBOROS_SOFT_TIMEOUT_SEC and OUROBOROS_HARD_TIMEOUT_SEC stopped terminating
anything when the activity model (idle window + subtree liveness + absolute
ceiling) replaced them. What survived was five surfaces discussing a value none
of them obeyed: SETTINGS_DEFAULTS offered it, the Settings UI accepted a number,
the save response apologised for it, queue.init compared the caller's value
against the constant it then wrote anyway and logged a deprecation row, and
/status printed "legacy_timeouts_ignored: soft=600s, hard=1800s" on every
request. A knob discussed everywhere and obeyed nowhere reads as a live tunable.
Retired through the existing idiom - RETIRED_SETTING_KEYS, stripped on load. No
successor knob (the activity model already governs), so nothing to seed. Gone
with them: both globals and init parameters in queue/workers, the
_emit_timeout_deprecation_once emitter and its latch, the gateway's
_RETIRED_NO_EFFECT_KEYS bucket (a retired key cannot reach an effect bucket at
all, so _effect_buckets no longer needs the warnings parameter), the status_text
parameters and legacy line, the server reads and ctx fields, the bench settings
carriers and the TB forwarded-env allowlist, and the two ARCHITECTURE rows.
rc_audit's `since` stopped being a one-key special case: RETIRED_IN_THIS_ABI
names the distinction, so an upgrading install still learns the difference
between "stopped working in THIS upgrade" and "was already inert".
Pins: tests/test_legacy_timeout_retirement.py (10 cases, incl. a grep-class
sweep and the auditor's since/behavior). The N-1 fixture carries the pair at its
DEFAULT values - a default-valued ghost is the one nobody looks for - so the
rc_audit fixture suite now pins that both produce a retired-setting finding.
Two tests that asserted the old no-op semantics are reshaped, not deleted.
Disclosed: saving the key through POST /api/settings no longer returns an
explicit "Retired setting(s) saved" warning; it is merged away silently like
every other retired key. Restoring it would mean reading the raw body for keys
the merge deliberately never looks at.
The first 3-OS CI runs on the campaign branch (33555971481, 33563498919)
turned the Windows full-test lane red on sixteen tests; this commit takes
the test-side and script-side share (the code-side share is in the
neighbouring commits):
- chmod(0)-based unreadable probes are POSIX-only (update-tx marker,
rc_audit skills/task_results trees): skip on Windows, and the audit tests
no longer touch os.geteuid before the platform guard;
- a journal held open by its reader cannot be unlinked on Windows (no
FILE_SHARE_DELETE): the replaced-source compaction pin skips there;
- signal.alarm is POSIX-only: the telegram chunker pins keep the suite-wide
pytest-timeout as their Windows guard;
- remnant scans and the credential-listing pin compare POSIX-relative paths
(Windows walks with backslashes);
- the glued `git -C<path>` predicate pin spells its paths POSIX-style: the
predicate parses the command with shlex, which eats Windows backslashes
(pre-existing, upstream-owned residual, disclosed in the test);
- chat.jsonl reads in the message-bus pins are explicit utf-8 (the
unicode-host row is not cp1252);
- the byte-exact atomic-write pin keeps the REAL O_BINARY bit where the
platform has one (stripping it re-enabled the text-mode translation the
pin exists to forbid) and simulates a bit only on POSIX;
- scripts/rc_audit.py --scope-only prints ASCII-escaped JSON: the scope text
carries U+2261, and a cp1252 pipe raised UnicodeEncodeError (exit 1 reads
as "incompatibilities found").
A present-but-unparseable state/ui_preferences.json silently audited
clean (bare except-JSONDecodeError-return), violating the fix-round-1
contract that a malformed mandatory source is never a clean exit 0. It
now yields a blocking unauditable-source finding (exit 1), same class as
an unparseable skill manifest; a read OSError still propagates to exit 2.
Class sweep of every _audit_* source: settings raises InstallUnreadable
(exit 2), skills raise unauditable-source, task_results map parse damage
to the blocking schema-stamp quarantine finding — ui_preferences was the
one surviving instance. Pinned both ways (unparseable blocks; a parsed
non-object still audits clean).
- LEDGER_CORRECTIONS: the F6 rolling-sync decision map (conflict classes,
double extractions, rename classes, protected deltas, disclosed
dispositions, open forks Q-F6-1..3)
- v7next_domains.toml: process_interpreters replaces python_interpreter (D05);
rows for the ten new upstream leaves by campaign family
- size_ratchet_manifest regenerated after the size-gate reshuffle
(extension_plugin_api band row dropped at 1000)