Commit graph

160 commits

Author SHA1 Message Date
Ouroboros
ffbd10f09c Checkpoint cognition sources and working views for private integration
NOT_REVIEWED integration checkpoint for READY 02-COGNITION. Contains linked knowledge, book composition, source retention, Nano view primitives and native multiwindow review. Full phase review, shared model/loop wiring, book migration and live acceptance remain pending. No version bump, tag or public delivery.
2026-09-13 02:03:42 +03:00
Ouroboros
4c91444b60 docs: qualify the source-span duplicate scan shortcut 2026-09-12 17:47:28 +03:00
Anton
065467f97d P8-4: skip the per-function source re-slice below the copy floor
`duplicate_bodies` extracted a source segment for EVERY function in the module
population, including one-liners that can never reach the ten-line literal-copy
floor. `ast.get_source_segment` re-splits the whole file per call, so the scan
paid O(source) for each short function.

The span a node already carries (`end_lineno - lineno + 1`) decides whether the
slice is worth taking. This is output-identical by construction, not merely by
test: `_normalize_body` dedents, rstrips and DROPS blank lines, so a normalized
body can never have more lines than its raw span, and a node whose span is below
the floor could never have satisfied the existing normalized-line check. The
recursion into nested functions stays unconditional, so a long inner function
inside a short outer one is still scanned.

Oracle, over the full module population with every module given its own domain
so every digest group surfaces as a row: byte-identical output (3 rows, same
sha256) before and after, 31.1s -> 21.4s. `scripts/check_domains.py` exits 0
with "OK: domain manifest complete", and the `[duplicates] allowed = []`
baseline is untouched in both directions.

The new boundary test pins the floor exactly: a cross-domain copy of exactly
DUPLICATE_MIN_LINES lines is still detected, one line shorter is not. Verified
load-bearing - changing the filter to `span > min_lines` reddens it.
2026-09-12 16:18:32 +03:00
Anton
0ce757d15b Merge recovered tool and review source repairs into private synthesis
Keep runtime terminal custody and UI model history alongside the source-complete tool review path. Generated inventories derive from this combined tree.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-11 03:13:56 +03:00
Ouroboros
5181efd78e Keep managed smoke fixtures within Unix socket path limits
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-10 08:00:11 +03:00
Ouroboros
ea6b9d944e Preserve startup recovery after supervisor failure
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-09 23:25:07 +03:00
Ouroboros
ec3fc6e5b5 fix: preserve review evidence and tool delivery semantics 2026-09-09 15:18:56 +03:00
Ouroboros
a3d53963f1 Keep task completion responsive and preserve shared execution 2026-09-09 14:40:45 +03:00
Anton Razzhigaev
dc79ef4126 fix(review): preserve staged patch bytes across platforms
Keep capture, replay, comparison and drift artifacts byte-paired through the existing reversible codec. Cover LF and CRLF blobs, autocrlf settings, Windows text pipes and unchanged custody handling.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-07 12:24:30 +00:00
Ouroboros
7b564c5cd8 fix(review): reconcile skipped delegated preflight without stranding new work 2026-09-06 18:25:55 +00:00
Ouroboros
24fbd48bc1 fix(review): prepare and recover authoritative review candidates 2026-09-06 12:31:01 +00:00
Ouroboros
8b2d1e6b6d rc.11 delta review: api-pack rows sized as production filters them, the advisory preview slot on its resolved route, a checked one-change invariant in the measurer, W4-F4 notes mirror the register
- devtools/measure_review_pack.py: the quorum limit and headroom are sized over
  the rows that RECEIVE the api pack — api_chat rows without a configured-
  subagent binding, decided by review_execution.delivery_retrieves exactly as
  review._prepare_unified_review decides before fit_triad_prompt; an all-
  retrieving panel reports 'no API pack is assembled for this panel' instead
  of a number (codex MAJOR). The 'index IS the working tree' comment became a
  checked invariant: an unstaged edit or an untracked file is the typed
  MeasuredCheckoutDirty refusal (exit 2), and the advisory arms are re-checked
  to resolve the same path set (fable MINOR).
- ouroboros/tools/claude_advisory_review.py: the native advisory slot is built
  by the dispatch builder (reviewer_slot_config.reviewer_slots), so use_local
  comes off the resolved route and a LOCAL advisory model previews its
  MANDATORY READ bound on its own window with the typed shortfall disclosure,
  instead of the remote/unknown route's (codex MAJOR); file stays at 1492 lines.
- ADOPTION_v7next.md / scripts/v7next_adoption.py: the Notes no longer call
  W4-F4 operator-disclosed; a 'Deferral authorities:' declaration mirrors
  DEFERRED_OUT_OF_V70 and the validator refuses a declaration that disagrees
  with the register (codex MINOR).
- docs/archive/v7next/LEDGER_CORRECTIONS.md: one-row note that the immutable
  band rationale for claude_advisory_review.py cites 1434 lines while the file
  stands at 1492 (fable minor).

Tests: tests/test_measure_review_pack.py (3 new, red-first), tests/test_advisory_route_pack.py (1 new, red-first), tests/test_v7next_adoption.py (2 new).

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
(cherry picked from commit eca294f4520802f2f3b64eaaa7e236d19899b4a5)
2026-09-04 23:55:32 +00:00
Ouroboros
20d9950894 adoption: W4-F4 (rescue-local ref accumulation) is owner-deferred with the owner's quote and a backlog item
Owner answer of 2026-09-04 («5. A»): the restart marker is fixed now (W4-F3),
the rescue-local ref accumulation stays deferred with the quote on the row
and a backlog item for deleting the refs of refused/unwound updates. The
deferral register marks the row OWNER so the authority lint enforces the
quote.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-04 23:27:27 +00:00
Ouroboros
d99b6ff1bd evolution: always write the restart-verify marker — auto-restart off skips only the restart (W4-F3, owner 5 = A)
request_evolution_restart wrote state/pending_restart_verify.json only when
OUROBOROS_EVOLUTION_AUTO_RESTART was on, so an install that restarts by hand
never reached the exact-claim verify path and absorb attribution fell back to
the markerless boot reconcile. The knob now skips only the restart itself.

- one writer helper (write_pending_restart_marker) and one schema for the
  supervisor path and the agent's restart tool; the claim key only for an
  exact claim; PERSISTENCE names the single writer
- S22 keeps its markerless-reconcile contract: generation A pins that the
  marker IS written with auto-restart off and the tree does not restart, then
  shapes the crash-window durable state (two atomic files) after the kill
- ADOPTION row W4-F3 re-prove/done/F6 with the owner quote; DEFERRED_OUT_OF_V70
  drops it; ARCHITECTURE names the always-written claim; ledger section

(cherry picked from commit 90ed3720740c1e02e49ae16a52dff8f648784fd2)
2026-09-04 23:23:45 +00:00
Ouroboros
7590aa70ac adoption: the 7.0 deferral register tells one story — prose ids resolved against the table, authority lint, stale rows corrected (F3-C, owner decision D-14)
The manifest's Notes called W4-F3/W4-F4 rowless for two days after d348ea46
made them rows, past a green --release bar: the validator read table rows and
never the prose. Class fix in scripts/v7next_adoption.py: manifest_prose() +
_prose_id_errors() resolve every id-shaped token outside the table against the
table by the table's own id grammar (a rowless id is declared on a
'No-row ids:' line; a declared id with a row is red), and the post-release
authority record is linted against the row text (an OWNER deferral carries the
'owner verbatim «…»' quote, an operator disclosure carries none) — the comment
over DEFERRED_OUT_OF_V70 had drifted from its values (E2/E3, spec §6.4).
Disclosed: a rowless claim in free English is not read; a word marker was
tried and misfired on 'No row carries pending-decision any more'.

Row corrections read from the rc.9 tree: ABI-8 carries its owner quote («6. ок»,
batch №7); DEFER-C6-RESIDUALS — C6-TESTCAP closed by batch №13 item 11 = A, the
split landed (900 + 660 lines), platform_layer pay-down stays post-release;
DEFER-E2E-PAID-LANE — the 'never executed' opening that stood glued to the
executed receipts is gone, «2. A» named as the run order and the E2/E3
remainder as a structural block (OWNER value unchanged). Ledger: the w4 findings
anchors re-read after the F2 relocation, the 'no row' note superseded, and an
F3-C section with the facts the owner batch must carry. W4-F3, W4-F4 and
DEFER-SPEC64-PATHS rows are untouched — they wait for the owner's word.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
(cherry picked from commit 2a6bdb223d2c0bd82699680990b6b8eaa1d90e0a)
2026-09-04 22:53:15 +00:00
Ouroboros
9698e2e077 Merge upstream ouroboros 23ab428f into the v7 line: absorb 407 commits into the module split
Second parent is the frozen upstream `ouroboros` head (23ab428f, 407 commits
since the merge base a76961de); first parent is v7.0.0-rc.8 (18b9832e).

Every upstream change lands in v7's owning leaf: S1 transplants keep upstream's
bodies (comments verbatim) under the call-time handle idiom, S2 hand-merges keep
both intents, S3 keeps v7 only with proof (retired 7.0 ABI surfaces, superseded
mechanisms). Per-symbol relocation ledger: docs/archive/v7next/LEDGER_CORRECTIONS.md
(F2 absorption section). Provisional decisions awaiting owner ratification:
D-18 (two-destination symbols), D-19 (acceptance rows follow upstream R2),
D-20 (acceptance_dialogue stays deleted), D-21 (tools/registry.py: facade
import block only).

Docs: upstream ARCHITECTURE/DEVELOPMENT as the base with compact v7 deltas;
bookkeeping moved to docs/archive/v7next. Size-ratchet manifest, domain
manifest and generated inventories regenerated; new leaves: tools/write_shape
walker, gateway/cost_breakdown, tools/core_secret_paths; provider_catalogs.py
and acceptance_dialogue.py removed (v7 owners).
2026-09-04 19:32:55 +00:00
Ouroboros
77b9df3ed5 Merge managed/ouroboros (b9d39ac7) into the catlife route fixes
Target drift since the sprint base (PR #557-#591: the agentic-review synthesis
moved the acceptance machinery whole into acceptance_dialogue.py, three-delivery
rows, Claudexor 3.9.7, ibl fixes). Resolutions: the acceptance-packet changes
(children debt, dialogue history and the packet budget passed INTO the bounded
builder; per-slot input caps on the panel request; packet sizing from the same
triad delivery rows the panel dispatches) are carried into the relocated module;
a partial tool-result projection withholds packet rows only for a genuinely
unavailable source (the legacy truthy sentinel still refuses) and never
retrieving rows; a report-shaped native episode keeps its draft on a budget
refusal after the failed send is observed; ARCHITECTURE/DEVELOPMENT merge both
sides' rows and paragraphs; the upstream acceptance-delivery test now asserts
the documented `not_dispatched` refusal shape (a refusal is a transport state,
never a verdict).

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-04 08:58:47 +03:00
Ouroboros
dda698e60c acceptance packet: persisted trajectory corpus behind a resolvable ref, durable projection gaps, complete substrate inventory
Sixth authoritative review: the trajectory source ref pointed at
get_task_result(...).llm_trace.tool_calls, which no reader serves — the complete
redacted tool-call corpus is now persisted in the task artifact store as a
content-addressed JSON artifact and the ref is a canonical
`artifact_store:<path>#chars=…` that read_file resolves (persistence failure →
source_unavailable); a failed root-task projection append no longer reports
success — append_history_once returns False, writes a durable gap row
(state/skill_review_root_tasks.gaps.jsonl) that the reader folds into coverage
(complete=False with the reason) and the runner receipt names it; the
contributor-lane substrate inventory and its coverage test gain
review_dispatch.py, review_actor_aggregation.py and delegate_custody_usage.py;
review_evidence.py sheds four lines (1596). Manifest untouched.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-04 04:09:16 +03:00
Ouroboros
09ac51b2f0 acceptance packet / custody: durable omissions dispatch, custody-only settlement receipts, cross-process retirement lock, one packet budget
Fifth authoritative review: leading omissions and recaps with a durable
get_task_result reference are not_materialized_for_reviewer again (dispatchable,
non-resolving) — only source-less rows withhold the panel; contributor receipts
take agent-session settlement exclusively from the final custody replay, and a
missing or unreadable custody row is a typed mismatch instead of trusting the
response's self-report; the skill-history projection discloses rows scanned,
truncation, gap reasons and a canonical source, and an incomplete projection is
non-resolving; settlement publication and last-sibling retirement sit under a
stable project-digest file lock that holds across worker processes; the host's
late acceptance fields enter the packet builder before the single budget
enforcement; ARCHITECTURE names all four window-aware surfaces and documents
SETTLED before registration retirement. loop.py 282 903 bytes (−765). Manifest
untouched.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-04 03:21:07 +03:00
Ouroboros
c50c2c944c Merge managed/ouroboros (85c1e386) into the agentic-review synthesis branch
Integrates the moved target (193 commits over the sprint base b9bcc2da,
release 6.114.0 — the DeepSeek landing PR #563 and the docs-consolidation
PR #556 included) into the synthesis branch without rewriting history.
Four files conflicted; each was resolved by substance so BOTH sides' facts
and behaviours survive:

- ouroboros/size_ratchet_manifest.py (generated): UNION of both sides'
  BAND_PATHS rationales (the target's ouroboros/gateway/extensions.py,
  tests/test_provider_contract_ci.py, tests/test_ui_smoke_project_continuity.py
  and web/modules/settings_ui.js beside our acceptance_dialogue.py,
  deep_self_review.py and test-suite rows), then regenerated for the merged
  tree: ouroboros/gateway/history.py left the band on the target line,
  BYTE_DEBT is the live merged size everywhere (loop.py 272905,
  tests/test_devtools_benchmarks.py 328068 — below both parents — and
  web/modules/chat.js 206949). `scripts/regenerate_size_ratchet.py --check`
  is green; no new module, function or byte debt.

- docs/ARCHITECTURE.md and docs/DEVELOPMENT.md: the target's consolidated
  structure is the frame; every agentic-review fact of this branch is placed
  in the target's section or row — the three deliveries of task acceptance
  and deep self-review, the reviewer-row schema (`deep_review` singleton,
  roster references, `profile_id`), pacing simplified to the one admission
  floor (R52/R55; the EWMA sentences are gone), poll purity, the native
  read receipts and BIBLE.md coverage, the retrieving work order and the
  CI methodology job. The module-tree rows keep the target's condensed form
  extended with our contracts; the full contracts live once in §6 (Task
  lifecycle, Review delivery, Deep self-review). Stale target sentences
  that our side retired (the `api_chat` acceptance pin, the round cap, the
  legacy/default API panel residual) are replaced, never duplicated.

- ouroboros/review_native_episode.py: our side already measures the send
  bound as the wire size of the serialized message list, which carries the
  WHOLE assistant dict — `reasoning_content` included — so the target's
  fix (count replayed reasoning in the fail-closed bound, 295c9062) is
  subsumed; the target's regression test passes unchanged. The comment
  above the append records the invariant.

Auto-merged both-changed files were checked for silent overlap:
tests/conftest.py gained the same autouse os.environ snapshot/restore
fixture on both sides — the target's tested `_os_environ_isolation` is
kept and our redundant `_restore_process_environment_between_tests` is
dropped (its rationale folded into the surviving docstring); our
gateway-settings binding restore fixture stays. .github/workflows/ci.yml,
ouroboros/config.py, ouroboros/tools/control.py, web/modules/settings_ui.js
and web/modules/reviewer_slots.js carry both sides' changes exactly once
(our deep self-review block sits in the target's new `.reviewer-slots-group`
container like its advisory sibling).
2026-09-03 22:07:20 +00:00
Ouroboros
198c6d0376 contributor review lane: bind final session settlement; keep the original block reason
Observed live: agent_session slots settle while sibling runs of the same Claudexor
project are still live, so `retire_project` defers removal and every receipt but
the last one carried `project_retired=False` forever, blocking the lane with
`session_settlement_unproven` even when the whole panel responded. Receipts now
bind the settlement projected from the custody replay after every panel slot
finished (AP8). When receipts mismatch, the outcome keeps `original_block_reason`
and `original_message`, so a preflight failure is no longer erased by the
receipt-mismatch override (AP9).

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-03 21:13:28 +03:00
Ouroboros
099dab0d78 Merge lane/deleg-mut-and-races: mutating delegation scenarios S24/S25, write-once copy-back source handles, the post-exec environ window (owner batch №13 item 15 = B)
DEFER-E2E-DELEG-MUT is done at phase F4; the O3 copy-back race and the
/proc-environ marker race are rooted and fixed (626b48b7). ADOPTION/validator
conflicts resolved by row; ledger union-merged.
2026-09-03 08:12:22 +00:00
Ouroboros
01cc657c10 tests: system-E2E cover for MUTATING delegated runs (S24/S25) — DEFER-E2E-DELEG-MUT closed
Owner batch №13 item 15 = B. Every F4 wave delegated only READ-ONLY runs and
disclosed the same gap: the ONE delegation branch that changes the owner's tree
on behalf of an external harness had no system-level cover. What was missing was
not scenario prose but an ACTOR — the fake daemon had no mutating half, so no run
could produce the applied facts an integration reads.

FakeClaudexorDaemon gains exactly that half and nothing else: on [FAKE:MUTATE] a
run edits the workspace its OWN start body named — read from
execution.workspaceRoot, the private snapshot, never from scope.root, so the fake
cannot break the isolation the scenarios exist to prove — and writes
<runDir>/attempts/a01/attempt.yaml in Claudexor's applied-facts shape, which is
the only evidence attempt_containment has that the harness HOME was scoped and an
OS boundary applied (the mechanism is written WITH its proven denied path,
because a mechanism without one is read as no boundary at all).

S24 (clean pull-in): an external-workspace task delegates access=workspace_write;
the host provisions the private Git snapshot; the harness edits it; delegate_wait
captures; integrate_delegated_patch(apply) stages into the live workspace.
Pinned: the durable custody chain (STARTED with access/mode/snapshot_id/
execution_root/baseline_sha → PATCH_CAPTURED → APPLY_STARTED → DISPOSED(applied)
→ the patch_verdict row whose patch_sha256 equals the capture manifest's), the
capture artifacts, the containment facts reaching the model (os_boundary named
from the run's own attempt record, no delegate_run_unconfined row), the
staged-not-committed contract, and the released snapshot. The ISOLATION proof is
causal, not timed: the script step that runs after the wait returned executes in
the test process, so it reads the live workspace at a point the server's own
ordering places between the capture and the decision — the run's file is absent
and tracked.txt is still the owner's.

S25 (conflicting pull-in): the same step writes the drift before answering with
apply. The apply is refused typed (INTEGRATE_CONFLICT / baseline_drift), nothing
is disposed, the live file keeps the OWNER's content, and snapshot + registry row
+ patch all survive as resolution material. Recorded rather than fixed (no
defect): a task that ENDS holding an undisposed captured patch is not a success —
its terminal is failed / delegated_custody_unreconciled with the model's answer
kept verbatim — and S25 pins that vocabulary.

Red-first for a coverage lane is the absence of the capability, so it is recorded
as a CONTROL run: with the fake's mutating half disabled, S24 fails at
assert 'ready_no_changes' == 'ready_with_changes'.

Full lane: 61 passed (16:47), rc 0. ADOPTION row DEFER-E2E-DELEG-MUT reads done at
phase F4 with a hook naming the three tests and leaves DEFERRED_OUT_OF_V70;
--release green. The WINWAVE registry paragraphs that carried the /proc-environ
flakiness and the open O3 copy-back question now name 626b48b7 as the root fix.
2026-09-03 08:07:43 +00:00
Ouroboros
cb736346d0 tests: the paid E-lane's first executions — a real delegated leaf in the roster, E1 asserts open faults; receipts in the ledger (owner batch №13 item 2 = A)
E13 is green on a priced route (openrouter::anthropic/claude-haiku-4.5); E1 is
green once its assertion reads open containment faults rather than the faults
LOG (which carries resolution rows). E2/E3 reach the real Claudexor lane and are
refused there — «Claude subscription route is not ready»: delegate_start asks
for the subscription substrate on purpose and an isolated install's owned
daemon has no login, which only the owner may create. Row DEFER-E2E-PAID-LANE
keeps its deferral under OWNER authority with that residual. Product finding
recorded: a data root deep enough to push the owned daemon's unix socket past
AF_UNIX's limit refuses every delegated start (`listen EINVAL`).
2026-09-03 08:00:39 +00:00
Ouroboros
9c04ff4741 Merge lane/typed-proc-facts: typed exit/signal/timeout/pre-exec facts on the five remaining process surfaces (owner batch №13 item 10 = B)
Publisher-scoped typed-fact channel; extension children, skill_exec,
skill_preflight (no more synthetic -9/-1), verify_and_record, run_command
timeouts and Windows host kills all publish what the platform gives and nothing
it does not. ADOPTION/validator conflicts resolved by row (TYPED done from the
lane; SPEC64 owner authority and F23 done from the base); ledger union-merged.
2026-09-03 07:53:05 +00:00
Ouroboros
2365bd2b7c feat(process-facts): typed exit/signal facts for the five remaining surfaces
Owner batch #13 item 10 = B: the five surfaces that still lacked typed
process exit/signal facts land in 7.0 (ADOPTION row DEFER-TYPED-PROC-5 is
done). The regex harvest stays retired (batch #7 item 1 = A); nothing here
reads prose, and where the platform gives no fact none is synthesized.

The thread-local channel becomes PUBLISHER-scoped instead of tool-name-scoped:
_PROCESS_META_TOOLS (two names, unable to list a dynamic ext_* surface) is
retired and the loop clears the slot before EVERY dispatch, which is a stronger
no-contamination contract than the name gate it replaces. The fact family gains
three members that exist exactly where an exit code does not: timed_out,
killed_by_host and pre_exec_failure (the platform's exception class).

Producers stamp at the point the truth is known:
- extension child (_run_child): clean/abnormal exit with its POSIX signal,
  deadline kill, output-cap kill;
- skill_exec (_run_skill_subprocess): the real negative code its
  "returncode or 0" return flattens, the deadline and output-cap kills, and
  the spawn OSError;
- skill_preflight (_run_check): the synthesized -9/-1 are RETIRED for
  returncode=None plus the typed reason (they read downstream as real POSIX
  signal deaths, on Windows too, where a host kill produces none);
- verify_and_record: the check's exit/signal or its timeout kill, with the
  receipt now copying that one publication instead of deriving duration and
  signal a second time;
- run_command: timeout and pre-exec failures.

Windows kills are carried honestly rather than faked: killed_by_host beside
whatever TerminateProcess left in exit_code, never a fabricated signal name.
Windows-executed proof pending the matrix.

One projection carries the family into the UI live-log card, the tools.jsonl
row and the durable trace. ouroboros/contracts/ is untouched; the typed meta
shape grew additively in tools/process_facts.py only.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-03 07:50:24 +00:00
Ouroboros
ca1b38dfc6 Merge lane/w4-crash-windows: commit intent before the reviewed commit, boot adoption and cycle-outcome backfill (owner batch №13 item 9 = B)
W4-F1: a crash between the reviewed git commit and its receipt is attributed on
the next boot from the durable commit intent (tree + parents), fail-closed.
W4-F2: a missing cycle_outcome row is re-derived on boot. Ledger union-merged.
2026-09-03 07:47:25 +00:00
Ouroboros
c6187deec8 evolution: close the commit-vs-receipt and outcome-ledger crash windows
Owner batch #13 item 9 = B pulled the two crash windows the F4 wave-4 lane
disclosed (W4-F1, W4-F2) into 7.0. Both are fixed where the durable fact is
written, not by a new guard.

W4-F1: the reviewed evolution commit is now two-phase. The pre_commit_authority
boundary - the last gate before `git commit`, which already rechecks the exact
claim - records a commit_intent (the reviewed tree and parents of the
post-review binding) on the active transaction. Boot reconciliation adopts the
commit sitting on HEAD only when its tree AND full parent list match that
intent, and writes the commit_receipt the crash never wrote, so restart
authority validates a receipt as exact as the tool path's. The task-done
classifier consumes the same intent, so a crashed commit-bearing cycle is no
longer closed as no_op before boot runs. Containment, the one writer that
disowns a commit, clears the intent in the same act.

W4-F2: the cycle_outcome row is re-derived rather than made atomic. The append
stays outside the campaign lock (a ledger failure must not break the restart
path); instead boot replays every commit-bearing resolved transaction that has
no row (source: boot_backfill, idempotent). The shared swallow-wrapper moved to
the ledger module that owns the write.

Red-first pins in tests/test_evolution_restart_claims.py; docs, ADOPTION rows
and the deferral registry updated.
2026-09-03 07:45:10 +00:00
Anton Razzhigaev
eb36770ca0 docs: close the remaining stale pointers and two extraction-history clauses
The gate reviews found four code pointers still naming documentation that
moved or never existed — the residency docstring that contradicted its own
selector by treating project membership as the signal, a bench script naming a
C1 section, a UI smoke test naming a retired handbook heading, and the second
copy of the stale ARCHITECTURE line-count comment. Two module-map rows also
carried the size-gate extraction history they were split at; the rows now state
only what the module does and where it is re-imported.
2026-09-03 04:52:07 +00:00
Ouroboros
c300fbf33e ledger: owner batch №13 records — F23 closed as covered by the release bar, §6.4 deferral under owner authority, spec's disposition/navigation artifacts withdrawn
Batch №13 answers (2026-09-02): item 7 = A — DEFER-F23-ACCEPTANCE is done with
the release bar as its hook and the uncovered parts (quorum, spend, scenario
consumption) in its residual clause; item 8 = A — DEFER-SPEC64-PATHS keeps
post-release under OWNER authority with the quote; item 17 = B — the spec's
«test split/delete disposition» and 20-question navigation artifacts are
withdrawn from the 7.0 acceptance by record. Release bar green.
2026-09-02 20:23:54 +00:00
Ouroboros
42bc431d69 close-out: the RC auditor names the successor of a retired key, and six prose leftovers of the close-out lenses
The smalls2 lens found the first-boot notice fixed on one surface only: scripts/rc_audit.py
still told the owner the retired wall-clock pair has "no replacement knob" while
config.normalize_settings_raw names OUROBOROS_TASK_IDLE_TIMEOUT_SEC / _ABS_CEILING_SEC
from RETIRED_SETTING_SUCCESSORS. Both auditor sites now branch on the same table
(pin: tests/test_rc_audit_fixture_suite.py, red on the previous text). Prose: the
notice's "surface that replaced them" no longer presupposes a replacement; the
broadcast_ws docstring names the real writers of the module loop; the ledger's
ws.py:184 citation is marked as the instrumented copy's line and the "hanging run"
is explained (pytest assertion introspection over the 810 KB document,
--assert=plain fails in 0.13 s); the d21806d8 registry row and R-WINWAVE stop
calling rerun-greens first-attempt greens; the train-inventory comment says
"second-parent side"; the vision.py row lists the active task model first.
2026-09-02 17:05:02 +00:00
Ouroboros
f2f014bc32 adoption: DEFER ids may carry hyphenated tokens; the spec 6.4 row is DEFER-SPEC64-PATHS
d348ea46 added eleven post-release rows whose ids the manifest's ID_RE refused
(DEFER-[A-Z0-9]+ allowed no hyphen), so the validator was red in both modes and
the wrapper suite failed — committed and pushed without gating on the rc (operator
error, fixed forward here). The id class now allows hyphenated DEFER tokens; the
one id with a dot is renamed. Validator both modes rc 0, wrapper suite green.
2026-09-02 17:00:31 +00:00
Ouroboros
d348ea463e adoption: every sanctioned deferral and every disclosed-not-done item is a post-release row
Only ABI-8 carried status=deferred; nine owner-sanctioned deferrals lived as prose
inside done rows or in ledger sections, and several disclosed-not-done items lived
nowhere the release bar reads. Each now has an explicit post-release row (owner
quote or the disclosing ledger section in the text) and an authority entry in
DEFERRED_OUT_OF_V70: owner — headless cancel receipts (batch #7 5=A), the two
frozen-package modules (batch #9 #12=A), the C6 disclosed residuals (batch #12 A),
task_results eternal (batch #8 5=A); operator-disclosed, each an open item of the
STOP batch — W4-F3/W4-F4, the mutating delegation scenarios, the never-executed
paid E2E lane, the five typed process-fact surfaces, spec 6.4 paths/roots, the
F23 acceptance capsule. The validator both modes and the wrapper suite stay green.
2026-09-02 16:58:47 +00:00
Ouroboros
265755ba53 scripts(v7next): a hook-resolution error says hook:, not release:
Hook resolution runs for every `done` row in BOTH modes — it is a property of
a shipped row, not of the --release invocation — but its five messages were
prefixed `release:` and the docstring still claimed «Outside --release hooks
stay free prose». A reader of a default-mode run was pointed at a switch that
had nothing to do with the failure.

Prefix is now `hook:`; the two genuine release-bar messages (pending-decision,
status != done) keep `release:`. The docstring says what actually gates the
resolution (`done`, not the mode), and the manifest's Notes now state the same
rule, so the code comment that cites them is true.

Red-first: the new parametrized pin drives four hook shapes (prose-only,
missing file, `tests/../` escape, bogus `::nodeid`) through the DEFAULT mode
and asserts no message claims the release bar. On the pre-fix shape 4 failed,
19 passed; after the rename 23 passed. The fifth message (unparseable hook
file) is not driven — it needs a planted syntax-error file — and is renamed
with the others.

No behaviour change: the same rows are red in the same modes.
2026-09-02 16:24:28 +00:00
Ouroboros
8578a2af6d docs(v7next): the frozen train inventory states the git facts it is derived from
The rationale for freezing REQUIRED_TRAINS instead of deriving it named the
wrong reason in two places (the comment and the ledger section). Re-derived
read-only with git:

  20850191 parents 5187fcdc 8d13373b   absorb merge, sync #1
  b9ceed6e parents 3e4a6181 f3fbfdbb   absorb merge, sync #2
  f4abe0a5 parents 43dcc1d2 a76961de   absorb merge, sync #3

All three absorb merges DO take the upstream tip as their literal second
parent, so «only f4abe0a5 has an upstream commit as its literal second parent»
was false. What holds is the first-parent shape: only f4abe0a5 sits on this
branch's first-parent line; 20850191 and b9ceed6e were made on lane lines and
reached mainline as the second-parent side of a lane-integration merge over a
campaign commit (0aa74e9f over 816e7b82; 0f9a8daf over 4c32691e). The re-tie
merge f61ea3c2 is not the cause and cannot be: it is an ancestor of all three
syncs, so it predates them.

The widened alternative is quantified rather than asserted: «second parent
descends from a recorded upstream tip» matches 35 / 15 / 6 merges on this tree
for the three tips, so it would demand a train row for every lane merge made
after a sync. The example given was 8fb08d44, which is not a merge at all; the
C6 lane merge is 9faccf31, whose second parent it is.

The design is unchanged — still a frozen inventory, still no subprocess — and
the TRAIN-F6 row now names both the absorb merge 20850191 and the integration
merge 0aa74e9f, so the one row recorded by its carrier says so.
2026-09-02 16:19:59 +00:00
Ouroboros
c8b6b044a8 merge: stage-2 fix lane docs-truth (fix-docs-20260902 @ 565161fe)
Nine documentation and generated-report defects verified on the tree, each pinned
red-first in tests/test_docs_sync.py: the component map gets a row for every
live runtime module (24 were missing) and a reverse-completeness pin; the
deep-review atlas row loses its removed compact-manifest retry; the settings
table gains its two missing keys and names the real owners instead of the
config.py facade (README, DEVELOPMENT, ARCHITECTURE invariant); startup's one
compat-pair write is stated instead of "persists nothing"; the CPL-5 design note
describes the landed observability-only contract; section 11.4 carries the ABI
7.0 window; the domain manifest is reachable from the handbook; the domain
report generator writes one trailing newline and the report is regenerated as
the current witness (git diff --check over the campaign range is clean).
Disclosed, not fixed: DESIGN_USAGE_COMPACTION.md §10 "CPL-5 not yet landed"
(stale on this tip; fixed in the integration follow-up) and the two stale
CHECKLISTS.md sentences (protected; owner question). Conflict:
LEDGER_CORRECTIONS.md (union). Gates: docs suites green, cheap gates rc 0.
2026-09-02 15:55:06 +00:00
Ouroboros
be7c8b0cbc report: the domain quotient generator writes one final newline, and the
witness is current again

Every section of the report appends a trailing "" separator, so
`"\n".join(L) + "\n"` turned the last separator into a blank final line and
`git diff --check` was red at DOMAIN_QUOTIENT_REPORT.md:1966 — on the one file
that is generated and never hand-edited. The generator now drops the trailing
separators before writing.

The report is also regenerated, because docs/DOMAIN_MAP.md links it as the
witness behind the pinned baseline and the committed copy was bound to HEAD
5187fcdc with 488 modules, 80 of them still `classification=proposed`, and a
domains.toml sha that no longer exists. It now reads 509 modules, zero
proposed, manifest drift none.

Pinned: the artifact ends with exactly one newline and the generator keeps the
strip. Deliberately NOT pinned: byte-identity to a regeneration — the header
carries a HEAD sha and a tree fingerprint, so that gate belongs to
docs/DOMAIN_MAP.md, whose only input is the manifest.
2026-09-02 15:35:51 +00:00
Ouroboros
19a4ff7d9b scripts: the adoption bar refuses a lost train, a bogus nodeid and a lying status
Three holes, each demonstrated by the manifest itself:

- A whole-file overwrite deleted the sync #2 train row and both validator
  modes stayed rc 0. REQUIRED_TRAINS is now a frozen inventory of the
  absorbed upstream trains (id -> upstream tip, campaign merge); a missing
  or re-pointed row is red in BOTH modes. Frozen rather than derived from
  git on purpose, and the comment says why: only one of the three recorded
  sync merges has an upstream commit as its literal second parent, so a
  second-parent rule would police one train of three, and the widened
  "descends from an upstream tip" form would demand a row for every lane
  merge.
- Hook `::nodeid` tokens were free text beside a resolved path. They are now
  read by AST against the named file's functions, classes and module-level
  bindings, so a hook cannot name a pin nobody wrote.
- A `done` row could say "NOT DONE" / "OPEN RESIDUAL" / "still owed" in its
  own text. It now must either fix the status or declare what stays open in
  an explicit `residual:` clause. A text-vs-cell lint on an operator
  manifest, not a gate on any runtime decision.

Hook resolution moves from the --release invocation to the property it
actually is — something true of a shipped row — which is what the manifest's
Notes already claimed.

tests/test_v7next_adoption.py executes the bar: validate() in both modes on
the live manifest, plus a mutant per rule. ci.yml is untouched (protected);
the default pytest lane carries this file.
2026-09-02 15:24:57 +00:00
Ouroboros
b89b9bd295 adoption: the owner-deferred browser wave and the two W4 crash windows get rows
Three things were true of 7.0 and absent from the manifest:

- DEFER-BROWSER — the gateway/UI-truth E2E actor, deferred out of 7.0 by
  owner batch №9 №14=A («браузерная волна пост-релиз, смоук зелёным до
  тега»). The refusing PlaywrightUIClient stub and its pin are the hook.
- W4-F1 / W4-F2 — the commit-vs-receipt attribution crash window and the
  absorb/cycle_outcome atomicity gap the F4 wave-4 lane found and, by that
  lane's rule, disclosed instead of fixing.

W4-F3 and W4-F4 stay disclosed observations in the wave-4 findings table:
both are named asymmetries of decisions that already exist, not work owed.

The validator's single post-release allowlist becomes a record with an
authority per id: every post-release row must be listed, and a row of the
owner-approved required inventory may only be parked there by the owner, so
the anti-bypass property the old frozenset carried is unchanged while an
operator disclosure can also be stated as what it is.
2026-09-02 15:20:30 +00:00
Ouroboros
6ace1a1f5a review: native episode and verdict canonicalizer are review substrate
The operator review script's substrate path set decides when a change touches
the review machinery itself (contributor lanes then review the reviewer). The
native tool-round episode, the retrieving-route verdict canonicalizer and the
execution projection were missing from it, so a change to how a native review
reads, bounds or parses its verdict did not count as a substrate change.

Add the three modules and pin them in the contract test; the test file
crosses into the 1001-1500 band with its rationale recorded.
2026-09-02 03:01:22 +00:00
Ouroboros
a5cec66df4 rc_audit: ASCII attestation text and a console that never dies on its own prose
CI run 33576588986 (Windows): the new attestation sentence carried a
Cyrillic letter, and printing the report through a cp1252 console raised
UnicodeEncodeError — five fixture-suite tests red. The sentence is ASCII
now and stdout/stderr are reconfigured with errors=backslashreplace, so a
future character outside the console's codec is escaped, never fatal.
2026-09-02 01:02:34 +00:00
Ouroboros
9509d49362 docs(v7next): W3A prose follows the manifest (S14-S17), WINWAVE run table complete, R-WINWAVE and D18 done
Scope lane 1 findings 3-5: the scenario file still numbered itself S11-S14
and called the skills lifecycle deferred; the registry run table stopped at
the pending 196438c9 run while the ledger already knew later runs; the
ADOPTION notes named D04/D05/D06/D35 as owing work after their lanes landed.
R-WINWAVE flips to done on the green matrices 33569841899..33572515529.
2026-09-02 00:38:30 +00:00
Ouroboros
b099fc1751 rc_audit: the owner attestation names the removed contracts.api_v1 module
The ABI-3/ABI-6д removal of the compatibility re-export was invisible to the
auditor's five classes and to its attestation list (scope lane 1, finding 2);
an install with an out-of-tree import of the old name now has the fact in the
attestation the owner signs.
2026-09-02 00:38:30 +00:00
Ouroboros
36de0d0aae tools: prove f-string module-handle transplants 2026-09-01 23:38:29 +00:00
Ouroboros
285ab66dcc adoption: the ledger says what the tree proves (truth wave)
Eleven landed rows flip to done with file hooks that resolve on this tree
(D07, D08, D09, D11, D31, D33, D34, D36, D37, D38, ABI-6 — four of them had
hook cells that could not resolve at all: a reference checker absent here,
a Ф4 scenario never built, prose plus grep verbs). Partial rows stay honest:
D03 pending (tests/test_settings_read_seam.py does not exist; the hook names
the two landed halves, phase F1 -> F6 together with the validator's
REQUIRED_PHASE, disclosed as an operator scheduling correction), D18 pending
on MIGRATION row 1030 (verified on the tree), R-WINWAVE pending until a
green Windows leg exists — its registry is docs/v7next/WINWAVE_CLASS_REGISTRY.md
(16 reference-wave classes plus the CRLF-vs-regex class the matrix found,
fixed by a0b35fcd; run 33555971481 @ 9a28e58f red for that class, run
33563498919 @ 196438c9 logged pending). Owner-decided rows carry the batch
№9 texts. Prose: 17 -> 18 delta families, CPL-1 488 -> 504 modules, and the
TRAIN-F6 provenance states the real order (operator inference 10:10Z,
owner sanction post hoc 19:12Z). CPL-4/CPL-5 untouched.
2026-09-01 23:15:15 +00:00
Ouroboros
5b1767fadd D04: retire the flat wall-clock timeout pair (owner 1B)
OUROBOROS_SOFT_TIMEOUT_SEC and OUROBOROS_HARD_TIMEOUT_SEC stopped terminating
anything when the activity model (idle window + subtree liveness + absolute
ceiling) replaced them. What survived was five surfaces discussing a value none
of them obeyed: SETTINGS_DEFAULTS offered it, the Settings UI accepted a number,
the save response apologised for it, queue.init compared the caller's value
against the constant it then wrote anyway and logged a deprecation row, and
/status printed "legacy_timeouts_ignored: soft=600s, hard=1800s" on every
request. A knob discussed everywhere and obeyed nowhere reads as a live tunable.

Retired through the existing idiom - RETIRED_SETTING_KEYS, stripped on load. No
successor knob (the activity model already governs), so nothing to seed. Gone
with them: both globals and init parameters in queue/workers, the
_emit_timeout_deprecation_once emitter and its latch, the gateway's
_RETIRED_NO_EFFECT_KEYS bucket (a retired key cannot reach an effect bucket at
all, so _effect_buckets no longer needs the warnings parameter), the status_text
parameters and legacy line, the server reads and ctx fields, the bench settings
carriers and the TB forwarded-env allowlist, and the two ARCHITECTURE rows.

rc_audit's `since` stopped being a one-key special case: RETIRED_IN_THIS_ABI
names the distinction, so an upgrading install still learns the difference
between "stopped working in THIS upgrade" and "was already inert".

Pins: tests/test_legacy_timeout_retirement.py (10 cases, incl. a grep-class
sweep and the auditor's since/behavior). The N-1 fixture carries the pair at its
DEFAULT values - a default-valued ghost is the one nobody looks for - so the
rc_audit fixture suite now pins that both produce a retired-setting finding.
Two tests that asserted the old no-op semantics are reshaped, not deleted.

Disclosed: saving the key through POST /api/settings no longer returns an
explicit "Retired setting(s) saved" warning; it is merged away silently like
every other retired key. Restoring it would mean reading the raw body for keys
the merge deliberately never looks at.
2026-09-01 23:01:30 +00:00
Ouroboros
6ef400020c tests: Windows lane — POSIX-only probes skip, POSIX-relative paths, utf-8 reads
The first 3-OS CI runs on the campaign branch (33555971481, 33563498919)
turned the Windows full-test lane red on sixteen tests; this commit takes
the test-side and script-side share (the code-side share is in the
neighbouring commits):

- chmod(0)-based unreadable probes are POSIX-only (update-tx marker,
  rc_audit skills/task_results trees): skip on Windows, and the audit tests
  no longer touch os.geteuid before the platform guard;
- a journal held open by its reader cannot be unlinked on Windows (no
  FILE_SHARE_DELETE): the replaced-source compaction pin skips there;
- signal.alarm is POSIX-only: the telegram chunker pins keep the suite-wide
  pytest-timeout as their Windows guard;
- remnant scans and the credential-listing pin compare POSIX-relative paths
  (Windows walks with backslashes);
- the glued `git -C<path>` predicate pin spells its paths POSIX-style: the
  predicate parses the command with shlex, which eats Windows backslashes
  (pre-existing, upstream-owned residual, disclosed in the test);
- chat.jsonl reads in the message-bus pins are explicit utf-8 (the
  unicode-host row is not cp1252);
- the byte-exact atomic-write pin keeps the REAL O_BINARY bit where the
  platform has one (stripping it re-enabled the text-mode translation the
  pin exists to forbid) and simulates a bit only on POSIX;
- scripts/rc_audit.py --scope-only prints ASCII-escaped JSON: the scope text
  carries U+2261, and a cp1252 pipe raised UnicodeEncodeError (exit 1 reads
  as "incompatibilities found").
2026-09-01 22:31:38 +00:00
Ouroboros
b09604074a fix(rc_audit): unparseable ui_preferences.json is a blocking unauditable-source
A present-but-unparseable state/ui_preferences.json silently audited
clean (bare except-JSONDecodeError-return), violating the fix-round-1
contract that a malformed mandatory source is never a clean exit 0. It
now yields a blocking unauditable-source finding (exit 1), same class as
an unparseable skill manifest; a read OSError still propagates to exit 2.
Class sweep of every _audit_* source: settings raises InstallUnreadable
(exit 2), skills raise unauditable-source, task_results map parse damage
to the blocking schema-stamp quarantine finding — ui_preferences was the
one surviving instance. Pinned both ways (unparseable blocks; a parsed
non-object still audits clean).
2026-09-01 15:07:00 +00:00
Anton Razzhigaev
0aa74e9fed Merge commit '816e7b82' into ouroboros_v7next
# Conflicts:
#	docs/v7next/LEDGER_CORRECTIONS.md
2026-09-01 11:48:47 +00:00
Ouroboros
816e7b82d7 docs(f6-sync): ledger section, domain rows, regenerated ratchet manifest
- LEDGER_CORRECTIONS: the F6 rolling-sync decision map (conflict classes,
  double extractions, rename classes, protected deltas, disclosed
  dispositions, open forks Q-F6-1..3)
- v7next_domains.toml: process_interpreters replaces python_interpreter (D05);
  rows for the ten new upstream leaves by campaign family
- size_ratchet_manifest regenerated after the size-gate reshuffle
  (extension_plugin_api band row dropped at 1000)
2026-09-01 11:47:14 +00:00