Commit graph

544 commits

Author SHA1 Message Date
Ouroboros
4b34cd4621 docs: use the permitted tracker reference for Windows artifacts 2026-09-27 00:24:21 +03:00
Ouroboros
c2e45111fb fix: restore portable release checks and symlink diagnostics
Preserve declared-entry hash failures and typed evidence omissions under Python 3.13. Keep the approved Windows artifact refusal explicit, isolate custody and nested pytest state, and synchronize the permission, lock, CSP, TLS and dispatcher fixtures without changing runtime policy.
2026-09-26 23:45:06 +03:00
Ouroboros
5a8d254a90 plan-review: a retry of a refused addressed attempt is a distinct, collectable wave
On the barrier route a first addressed re-ask whose named seat is refused at $0 (daemon
unreachable) settles as an unpaid wave that advances nothing, so the retry of the identical
envelope and item shares its cycle index and fingerprint. The resume's "distinct wave" check
and the lineage self-naming guard identified predecessors by that pair and refused the
retry's collection as PLAN_REVIEW_CUSTODY_INVALID — paid money uncollectable, and at the
default cap the task wedged. Predecessor identity is now the ARTIFACT whenever both the
pointer and the wave's own reference are known (_same_wave); the (cycle_index, fingerprint)
pair remains the identity only when a reference is missing. The unreadable-authority refusal
now carries the inner reason; the architecture clause names the empty-item-list envelope as
the third case decided before the addressed rule, and the chapter budget is raised with its
reason. Found by the final Fable seat; pinned on the barrier route with two refused attempts,
a collectable retry and a later same-spec review that still finds the paid cycle-1 wave.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-26 22:10:15 +03:00
Ouroboros
d7d125ee5c plan-review: no addressed note on the in-flight collection; the doc names the note-less cases
Delta-round findings (Fable seat), pinned two-sided: an identical envelope with items sent
while a seat was still in flight rendered "answers_not_addressed (envelope_changed)" — the
resume path never reset the initial reason — so the dispatch-exit note is now suppressed
on the resume path; the architecture clause names the two cases decided before the addressed
rule (a changed roster re-dispatches every slot, a wave still in flight is collected) as
carrying no note; a store failure inside the validate-first prepare is pinned as the typed
PLAN_REVIEW_STATE_INVALID refusal that records nothing.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-26 21:48:14 +03:00
Ouroboros
fc76e64116 docs: state the per-slot continuation rule with its fail-closed custody pin
The continuation paragraphs of the architecture and the handbook now say what the code
does after the per-slot change: each packet slot continues its recorded transcript, the
panel goes out fresh only when no exact artifact reference exists or the roster changed
(each packet slot disclosing its cause), and an unreadable referenced artifact still fails
closed with plan_review_exact_artifact_unavailable. tests/test_doc_context.py pins that
custody sentence in both books; the previous wording had dropped it from the architecture
chapter and split it across a line in the handbook.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-26 21:08:26 +03:00
Ouroboros
ad034ce0a0 plan-review: facts-only next step and schema; escalation stays an answer
The mind-facing texts promised mechanics that did not exist or advised a route of the
host's choosing: "an answer reaches reviewers on the next paid cycle" (true only if the
mind bought one, and the automatic delta that backed the REVISE_PLAN clause is gone), "a
revised envelope ... its open requests can no longer be dispositioned", the deadline rail's
"Proceed with your own best plan directly", and the cap rail's Swarm/hurry escape recipe.

_next_step now states facts in every open branch: the open questions by id (questions to
the author and document requests, from the ONE closure table, bounded to 8 ids), and the
route an answer takes — recorded at $0 and merged by finding_id; beside the unchanged
envelope only the named slots are asked again (one paid cycle, the rest kept at $0) and a
slot that no longer raises its finding retires it; beside a changed envelope every slot
reviews with the answers in view; whether to buy that cycle is the mind's; an envelope
without items supersedes the wave with its answers kept, the identical one replays free. The
below-quorum blocking sentence follows the configured enforcement (advisory: a reasoned
reject closes; blocking: open until the raising slot retires it or a changed spec is
reviewed). The Cyber branch carries the same facts for an open wave. At the cap the answer
stays recorded evidence; the blocking tail names the released finalization, the held
implementation and the owner's authority (raising the cap, an unstick) as owner authority,
never reviewer approval. The deadline rail reports remaining time and the absent review; the
cap head reports the open review, the released finalization and the owner's authority. The
review_disposition schema, its items/rationale descriptions, the plan_task description and
the reviewer_effort note state the same mechanism; the escalated question is documented as
an answer the mind records (defer while the quiz is open, accept with the owner's decision)
with no new decision value and no host shortcut. The blocking reminder states the route.

Docs: CHECKLISTS "Cycles and closure" (REVISE_PLAN bullet and the replay paragraph) under
the Communication decision; 06-agent-core (continuation per slot, answers merge by id, the
addressed answer replaces the automatic delta, the escalated-question rule, the author call's
items); handbook 06 gains the answer-channel bullet; the two chapter budgets are raised in
this diff with their reasons.

Owner authority: DECISIONS "Communication" item 2; D4 with Q-v = A; "Blocking installs: no
skip"; Q-iv (facts) and the round-2 amendments (facts-only producers in every branch).

Tests: tests/test_plan_review_answer_texts.py (open questions by id, present and absent; the
route in every open branch and forbidden stale sentences; the cap texts; the schema and tool
descriptions; the blocking reminder; the deadline and cap producers; a quiz answer never
closes a finding while a later accept does); the render pins re-pinned; two w3 pins moved to
the facts wording.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-26 21:01:01 +03:00
Ouroboros
e37c0c975c Merge managed/ouroboros (eb7db8cc6) into plan-organ-pr1-verdict
Target movement only (PRs #1340, #1341). Conflicts resolved in
tests/test_reference_book_budgets.py (both sides' reasons kept, merged
chapters re-measured) and the generated inventory regenerated. No
plan-review code changed in this merge.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-26 16:40:37 +03:00
Ouroboros
bad5e7d0de Plan review: predecessor bound to the dispatch, standing findings across pending waves
Delta review round on the standing-findings fix (three reviewers, one batch):

- The exact predecessor reference is bound to the wave the dispatch actually
  judged against (the wave records previous_wave_artifact from the same
  `previous` that produced previous_fingerprint; resume keeps the recorded one),
  not inferred by the writer from whichever older hot entry shared the new
  fingerprint. Returning to an earlier prose with a changed order therefore
  carries the LAST predecessor's open objection, never a retired one from the
  entry it replaced. The key is a plan-review identity key, so state-size
  fitting never truncates the artifact path; the fingerprint fallback refuses
  to hand a wave back as its own predecessor.
- A seat still pending when its wave was superseded gave no terminal answer
  there: plan_review_artifacts.standing_findings_lineage walks the same-spec
  lineage (exact predecessor by pointer, else the hot index) until a real
  answer, a closed predecessor or a changed spec ends the obligation, so a
  later terminal absence of that seat still carries its earlier objection.
- The closed-predecessor pin now revises the prose (a closed review replays an
  effort-only change for free, so the earlier pin never reached the seam).
- Docs: the unanswered-slot floor names the terminal-absence rule and the
  lineage walk; the card variant for a never-sent seat.

Tests: tests/test_plan_standing_lineage.py (a returning fingerprint keeps the
predecessor it was judged against; a seat pending through a superseded wave
still owes its earlier objection, and a clean answer retires it).

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-26 16:38:44 +03:00
Ouroboros
086241ed51 Plan review: standing findings after parse, terminal absence only, predecessor kept
Review round 1 (three independent reviewers, one batch) on the open-set verdict:

- A seat's standing findings are judged once its parse result is final and only
  when its absence is terminal. An unparseable reply (prose, no findings array)
  is a non-answer that keeps the seat's earlier finding listed; a seat still
  awaiting the dispatch barrier, in flight or late-pending is a gap and carries
  nothing (06 §Plan construction and review: an answer that has not arrived is
  never a verdict). Before this, two clean seats plus one unparseable objector
  closed GREEN, and a barrier wave stamped "did not answer" on seats that were
  merely awaited.
- A same-fingerprint re-dispatch (a changed reviewer_effort on an open review)
  replaces its predecessor in the hot index; the replacing wave now keeps that
  predecessor's exact artifact reference (previous_wave_artifact, also kept by
  compact_wave), and free collection resolves the predecessor through it, so the
  standing seam and the prior-cycle packet see the real predecessor instead of
  the in-flight wave itself.
- A closed predecessor carries nothing (plan_standing_findings now reads closed,
  as its contract promised): a finding closed by a reasoned advisory reject is
  earned authority and is not resurrected on a later same-spec wave.
- Notes are neutral for the only-awaited stamp: a quorum whose only findings are
  notes, held open by an awaited seat, is still a mere wait (D4).
- Verdict text: the advisory NOTE states the cap fact like the blocking one; a $0
  not-sent seat with a carried finding says "not sent; its earlier finding is
  still listed"; the Reviews card prints the weaker-order line on compact waves
  too and the carried explanation on every terminal branch; skipped rows carry
  the seat's effort facts; the trace meta labels the historical critic pair.
- Docs: the closure sentence names the CONFIGURED enforcement against the
  hurry-projected advisory (06, 07); CHECKLISTS keys the changed-spec clause on
  the spec hash (D4 hunk, protected path: authority D4 / Q-v as before).

Tests: two-sided pins for the unparseable objector, the awaiting-then-refused
seat through the barrier and collection, the reject-closed predecessor, the
changed-spec subcase from an open objection, the note-neutral wait, and the two
card branches. Size: plan_review_runtime.py leaves the 1001-1500 band (1507,
manifest regenerated); task_results.py 1597; review_presentation.js 1599.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-26 16:11:33 +03:00
Ouroboros
98d80793cf fix: count rescued deliverables through shared unmeasured listing
Verify queued forwarding retains exact unread mail on cancellation before start. Keep unavailable stores unknown, exclude inputs and bookkeeping, preserve split actor stores and delivery identity. Document host factual speech.
2026-09-26 16:06:23 +03:00
Ouroboros
0caac10e9e Merge managed/ouroboros (f9958f341) into plan-organ-pr1-verdict
Target movement only: PR #1338 and its neighbours land beside the plan-review
commits. Conflicts resolved in tests/test_reference_book_budgets.py by keeping
both sides' reasons and re-measuring the merged chapters; the generated
inventories were regenerated. No plan-review code changed in this merge.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-26 15:33:10 +03:00
Ouroboros
7009dd5fd1 Merge remote-tracking branch 'managed/ouroboros' into claude/steer-20260926
# Conflicts:
#	docs/inventories/DATA_LAYOUT_INVENTORY.md
#	ouroboros/task_status.py
#	tests/test_reference_book_budgets.py
2026-09-26 15:29:27 +03:00
Ouroboros
cbf33022bc fix: settle child file and mailbox custody before cleanup
Centralize post-admission drive settlement, preserve captured identities and complete input closures, make metadata reads pure, serve confined nested files and directory archives, and keep maintenance off the supervisor loop. Preserve generation fences at actual mutation boundaries and truthful queued forwarding receipts.
2026-09-26 15:04:49 +03:00
Ouroboros
a265e0eda6 Plan review: conversation-only dialogue view, session fit, read facts
The inline OWN ROOM DIALOGUE a reviewer reads is now the conversation
as numbered readable lines (owner and Ouroboros rows, quiz cards with
the chosen answer, attachment names, addressed mailbox rows), each line
carrying its snapshot line number so a chat:<id>@<sha256>::lines=A-B
locator addresses exactly what a reviewer cites, under one header line
(room, locator, counts, gaps) and a footer pointer to the complete
redacted snapshot in task custody. Progress rows, host system rows and
the archive-file list are never inline; they stay behind the pointer.
The snapshot itself is unchanged (identity, custody, redaction).

Fit per delivery: api and native rows keep the whole conversation when
it fits their measured capacity, else the newest rows with the cut
named as an exact line range; a delegated session receives the same
inline conversation plus the pointer, fitted only to an owner-asserted
reviewer:<slot> context window and otherwise whole (the host invents no
window). The mandatory full-read instruction is gone. The snapshot is
declared to a session as an observed source (never a required
manifest), review_session_reads folds the harness journal over it so
the actor row records room_read_coverage with harness_observed
attestation, and native_incomplete stays reserved for required sources
so an observed source never files a capability delta; the verdict text
shows what each session read. Per-slot delivery facts (rows, first
inline line, window) ride dialogue_delivery as before.

Owner decision implemented: D1=A (conversation-only inline view with a
pointer carrying exact ranges; the coverage metadata leaves the inline
view; the snapshot declared as a read source so per-reviewer coverage
is a fact, never a gate) with the round-2 amendment on sessions (no
invented window; asserted window fits). Amendments applied: A7
(observed_sources admitted by session_read_facts), A8 (asserted window
fit; whole inline otherwise — the amendment's fallback to the API row's
fit was NOT applied because DECISIONS forbids importing the API
unknown-window default into sessions and no session-task budget exists
to bound against). docs/CHECKLISTS.md (protected): the intro paragraph
now states the conversation-only inline view with the pointer (D1).

Disclosed residuals: a single conversation row larger than a route's
capacity fits no window and stays entirely behind the pointer (rows are
the unit; the footer names the exact omitted range); a native plan row
keeps its host-observed receipts and folds no snapshot; a session with
no asserted window on a Main-bound room receives the whole
conversation inline and may fail typed on its own slot.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-26 11:05:03 +03:00
Ouroboros
903156cceb Plan review: envelope effort outranks pins, effort facts, standing seats
A plan envelope's reviewer_effort is an ORDER for that plan: it now
outranks each reviewer row's own pinned effort (reviewer_slot_config.
row_effort, argument of plan_review_slots only), while a compound
Cursor/Agy route slug keeps its encoded effort because that effort is
the route's identity; commit, scope, skill, acceptance and deep review
call without an order and are byte-identical (pinned by the slot-route
contract test). Every wave records the resolved requested effort of
each seat on its actor row (effort, declared_effort), the per-seat owner
baseline captured at dispatch and reused on collection (owner_efforts)
and one typed ordered_weaker fact that the verdict text, the Reviews
card line and the compact index carry; a compound seat that kept its
own effort discloses reviewer_effort_not_applied. The tool text says a
different strength re-dispatches an OPEN review and a CLOSED one stands.

Standing findings by same spec hash and same seat: on a same-spec cycle
(equal spec_hash, whatever the roster, order or effort) a seat that does
not answer keeps its still-open findings from the predecessor listed on
the wave, stamped carried_absent_answer and reported as "did not answer;
its earlier finding is still listed"; the silent seat counts as neither
parseable nor a blocking-slot vote, so a changed order can never retire
a silent objector's finding into GREEN. plan_spec.plan_standing_findings
and plan_spec.plan_ordered_weaker are pure closure-table consumers and
live beside the aggregate, keeping plan_review_runtime.py in its band.

Owner decisions implemented: D3=A with Q-vi=B (the order wins for that
plan in both enforcement modes; the verdict shows a panel ordered
weaker than the owner setting; the effective per-slot effort is
recorded), the round-2 amendment on standing findings keyed by spec
hash and seat (PR1_AMENDMENTS E1), A4 (keyword default= kept, semantics
changed), A5 (per-actor facts, one typed ordered_weaker, owner baseline
at dispatch, compact_wave carries it). docs/CHECKLISTS.md (protected):
the DEGRADED-replay roster identity names the effective per-seat
efforts, and the cycle-2 sentence gains the did-not-answer wording
(A10). Chapter budgets raised with reasons; the data-layout inventory
regenerated for chapter 01.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-26 10:50:46 +03:00
Ouroboros
4197a1c916 Plan review: height rule, cycle-2 adjudication duty, seat line
The reviewer's blocking rule no longer turns a claim that cannot be
checked as written into a blocker by construction: such a claim is a
question to the author (need_evidence naming the claim id) or a note.
The clause leaves plan_packet._BLOCKING_RULE and the Plan Review
Checklist in the same commit, so the injected checklist and the code
that assembles the packet keep agreeing. The rubric gains a subtraction
voice (item 6: what could the spec drop without losing the goal, as a
note); governance becomes item 7.

On cycle 2 and later the convergence rule in the user packet makes a
reviewer adjudicate its OWN earlier findings first: RESOLVED and
SUPERSEDED are not repeated, STILL OPEN is re-emitted with the residual,
and still-open holds only while the goal is unchanged, which the host
states as one fact under the spec delta (Goal changed since cycle n:
yes|no|unknown, unknown when the previous frozen spec body was
truncated). Every slot's send ends with its own panel seat id after the
cache-stable prefix (api rows, native rows and delegated sessions
alike), so a shared packet can say which rows are the reviewer's own.
The E2E marker sentence in the prompt head is byte-identical.

docs/CHECKLISTS.md is a protected path; the edits here are the height
clause deletion (Q-ii=A), the open-set wording of the Cycles and
closure bullets (D4, Q-v=A), the rubric subtraction row and the cycle-2
duty sentence (the owner's convergence item: adjudicate own findings,
subtraction voice). Amendments applied: A2 (no start-anchor sentence,
no distinct-model tokens), A3 (packet fact only, no cycles-left card),
B3 (seat, goal fact and duty after ROOT EXPLORATION LOG).

tests/test_plan_spec.py entered the 1001-1500 band with the open-set
and packet pins; its manifest rationale rides this commit.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-26 10:42:00 +03:00
Ouroboros
575e2b0278 Plan review: open-set verdict, per-finding closure, real author pair
GREEN now means a quorum parsed and the wave's open set is empty: no
blocking finding left open and no need_evidence (a document request or
a question to the author) without a valid disposition. Notes never
change the verdict, so a note-only wave is GREEN instead of a closed
REVIEW_REQUIRED. plan_spec.closure_after_disposition stays the ONE
closure table and now also says what to record: under advisory a
reject with its rationale closes a below-quorum blocking finding, per
finding (accept or defer keep it open); under blocking that finding
stays open until a changed spec is reviewed or the reviewer retires it;
a REVIEW_REQUIRED whose open set empties is written GREEN on every
write path (initial synthesis, disposition, the task_results writer)
with the closure note closed_by_disposition, while the four control
validators keep accepting older closed REVIEW_REQUIRED rows. The
degraded stamp keys on the gate projection as before: a verdict-bearing
wave is open only while its open set is non-empty.

Author selection after a closed critic wave publishes that wave's real
(aggregate, closed) pair instead of an invented (GREEN, open) pair the
validator refused after the plan was persisted and narrated; the tool
result carries plan_review_historical_critic when the selected plan is
not the reviewed one, the text states the earlier plan's verdict and
that this plan has none of its own, and the Reviews card labels such a
group as the earlier plan's review with the selected plan unreviewed.

Positive paths staged through the tightened rule: a note-only wave
reaches GREEN and the blocking gate allows; an advisory reasoned reject
closes a below-quorum blocking finding and the gate allows; a below-
quorum blocking finding under blocking stays open and the gate holds.

Owner decisions implemented: D4 (open set, notes never count, advisory
reasoned reject closes per finding), Q-v=A (blocking closure unchanged,
majority never overrides a single still-open objector), the round-2
amendment on the author path (critic's real pair, historical_critic,
no host-invented verdict; PR1_AMENDMENTS A6/E3). Chapter byte budgets
raised in the same diff with their reasons; the data-layout inventory
regenerated for chapter 01.

Pre-existing base failure, unrelated: tests/test_plan_spec.py::
test_resolve_evidence_and_constitutional_never_raise_on_hostile_locators
fails on the pristine base (macOS symlink-loop reason), deselected in
the focused runs.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-26 10:35:07 +03:00
Ouroboros
08967027c8 Merge remote-tracking branch 'managed/ouroboros' into claude/steer-20260926
# Conflicts:
#	docs/inventories/FACADE_INVENTORY.md
#	tests/test_reference_book_budgets.py
2026-09-26 10:19:11 +03:00
Ouroboros
acba372ca4 delegate_message: discovery inside the deadline, failed-read note, gateway closed on handshake failure
Both capability reads are bounded by the call's remaining budget and the
deadline is checked between them (a spent budget is delivery_unknown /
deadline_exhausted with nothing sent, never a thread-kill mid-wire); a
FAILED capability read gets its own note (channel unknown, not absent: keep
the run, re-check later) instead of the cancel-and-restart guidance meant
for a missing channel; a handshake failure closes the gateway; the notes
and docs name reconciliation as the timeline rows carrying this messageId
(message.* receipts and the harness status row) rather than message.* only.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-26 09:31:03 +03:00
Ouroboros
7fa7df5ba5 merge follow-up: one wait-scope sentence, cache-horizon basis named, budgets re-measured
Keep the "every wait_task caller" sentence once (Waiting on children), name the
cache-horizon note's basis (time since the last model response) in its text and
docstring now that delegate_wait feeds that basis, resolve the reachability pin
to the shared _wait_window ladder, and re-measure the two chapter budgets on
the merged sprint tree.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-26 08:45:37 +03:00
Ouroboros
15555393e2 Merge branch 'ou3-waiting-de' into claude/steer-20260926
# Conflicts:
#	tests/test_cache_optimization.py
#	tests/test_reference_book_budgets.py
2026-09-26 08:40:35 +03:00
Ouroboros
5be5231629 Merge branch 'ou2-waiting-abc' into claude/steer-20260926
# Conflicts:
#	tests/test_reference_book_budgets.py
2026-09-26 08:39:58 +03:00
Ouroboros
a2d4eb4eef Merge branch 'ou4-reclaim-low-water' into claude/steer-20260926
# Conflicts:
#	tests/test_reference_book_budgets.py
2026-09-26 08:39:46 +03:00
Anton Razzhigaev
f0e2fc25f4
Merge pull request #1150 from LeoTechPro/fix/windows-managed-npm-toolchain
Some checks are pending
CI / docker-ui-smoke (push) Waiting to run
CI / docker-portable-test (push) Waiting to run
CI / system-e2e-mock (push) Waiting to run
CI / e2e-live (SM1 x1 — largest subset feasible under the $30 cap) (push) Waiting to run
CI / android-test (push) Waiting to run
CI / Android emulator smoke (API 26) (push) Blocked by required conditions
CI / Android emulator smoke (API 29) (push) Blocked by required conditions
CI / Android emulator smoke (API 30) (push) Blocked by required conditions
CI / Android emulator smoke (API 33) (push) Blocked by required conditions
CI / Android emulator smoke (API 36) (push) Blocked by required conditions
CI / android-build (push) Blocked by required conditions
CI / release-preflight (push) Blocked by required conditions
CI / build (dmg, macos-latest, macos-arm64, syft_1.50.0_darwin_arm64.tar.gz, syft, e32fdb9d47823fa633748a1efca2528fd77c37469ea93c9e40ab835da44e4cce) (push) Blocked by required conditions
CI / build (tar.gz, ubuntu-latest, linux-x86_64, syft_1.50.0_linux_amd64.tar.gz, syft, bf7b29ff57f06da30918266a0e1c2885a8f99784798d1bdb1628886aa015d788) (push) Blocked by required conditions
CI / build (zip, windows-latest, windows-x64, syft_1.50.0_windows_amd64.zip, syft.exe, 815ee6973ec5dff6a671d7f41b0e78835a8c45b91d5a39f4743ea1cee833d3be) (push) Blocked by required conditions
CI / vendor-package-smoke (push) Blocked by required conditions
CI / release (push) Blocked by required conditions
Claudexor platform gate (API keys — subscription auth NOT covered) / toolchain · ubuntu-latest · real managed Node/npm, no ambient Node, no harness install (push) Waiting to run
Claudexor platform gate (API keys — subscription auth NOT covered) / fixture · macos-latest · exact managed runtime, fake harness, no model (push) Waiting to run
Claudexor platform gate (API keys — subscription auth NOT covered) / fixture · ubuntu-latest · exact managed runtime, fake harness, no model (push) Waiting to run
Claudexor platform gate (API keys — subscription auth NOT covered) / fixture · windows-latest · exact managed runtime, fake harness, no model (push) Waiting to run
Claudexor platform gate (API keys — subscription auth NOT covered) / toolchain · macos-latest · real managed Node/npm, no ambient Node, no harness install (push) Waiting to run
Claudexor platform gate (API keys — subscription auth NOT covered) / toolchain · windows-latest · real managed Node/npm, no ambient Node, no harness install (push) Waiting to run
Claudexor platform gate (API keys — subscription auth NOT covered) / consumer · windows-latest · real pinned Codex local install + doctor, no login, no model task (push) Waiting to run
Claudexor platform gate (API keys — subscription auth NOT covered) / live · windows-latest · claude · API key only, subscription NOT covered (push) Waiting to run
Submit Claudexor dependency / Submit managed runtime snapshot (push) Waiting to run
Claudexor platform gate (API keys — subscription auth NOT covered) / live · macos-latest · claude · API key only, subscription NOT covered (push) Waiting to run
Claudexor platform gate (API keys — subscription auth NOT covered) / live · ubuntu-latest · claude · API key only, subscription NOT covered (push) Waiting to run
Claudexor platform gate (API keys — subscription auth NOT covered) / live · macos-latest · codex · API key only, subscription NOT covered (push) Waiting to run
UI browser (ouroboros push) / ui-smoke (push) Waiting to run
fix: enable managed Windows npm toolchain
2026-09-26 08:29:52 +03:00
Ouroboros
04ac2a666a Document the deficit-triggered, low-water-sized reclaim contract
ARCHITECTURE §6 "Context fitting, retry, and compaction" (06-agent-core) and
DEVELOPMENT 04 "Compaction must earn its rewrite" now state the unchanged
trigger (a positive deficit against the binding boundary), the low-water
sizing with its structural divisor, the checkpoint's requested-margin versus
achieved-headroom facts (reaching the boundary is not getting below it), the
overflow minimum, and that the materializer only honours the requested goal
and may under-land it under full-budget summaries. Chapter byte budgets are
raised with reasons (06: 314900 -> 315900, 04: 16431 -> 17000).

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-26 08:17:14 +03:00
Ouroboros
4512b1b10a docs: describe the fifth nanny verb and raise the touched chapter budgets
06-agent-core: "Four nanny verbs" becomes five and states delegate_message's
capability gate, engine-mirrored outcomes with the host's not_found, the
message_id idempotency custody and the attempt-local lifetime; the
harness-named "codex lane has no mid-run channel" clause is replaced by the
capability-based wording. 01-high-level: the delegate_interactions.py and
tools/delegate.py rows name the verb. DEVELOPMENT 06: one delegated-lane
bullet for the live-message rule. Byte budgets raised with measured sizes
and reasons: 06-agent-core 314900 -> 316800, 01-high-level 165900 -> 166200,
development/06 96700 -> 97200.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-26 08:10:21 +03:00
Ouroboros
f28894174a docs: supervision wake facts, wait scope and cost-evidence reminder
ARCHITECTURE 06 Supervision states the task-scoped child cursor, the
whole-call sleep facts, leaf_live_input, dated observation facts, that
the shared wait window and compact projection apply to every wait_task
caller (budget_pause is a dispatch fence, never a sleep), and the
cost-evidence reminder. DEVELOPMENT 06 gains one Timeout & Wait Control
bullet. Both chapter budgets are raised with measured reasons.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-26 08:10:00 +03:00
Ouroboros
a2970c4528 docs: waiting on children states the unsettled body and the shared window
ARCHITECTURE 06 "Waiting on children" now says that only get_task_result and
a settled wait_task give the full handoff, describes the compact unsettled
body with its dated delegated-run facts (no liveness verdict), the one
_wait_window ladder inside the executor's emit window, and that this holds
for every wait_task caller without describing a budget pause or owner wait
as sleeping. DEVELOPMENT 06 names the settled wait_task. The 06-agent-core
byte budget is raised with its reason.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-26 08:07:38 +03:00
Ouroboros
2295099bc9 merge: preserve post-work rails with anchored memory edits 2026-09-26 07:14:58 +03:00
Ouroboros
d49273bee4 merge: preserve TZ2 dialogue semantics over TZ1 ingress 2026-09-26 07:12:29 +03:00
Ouroboros
2f02539fc0 fix: close nested post-work interruption and stop paths 2026-09-26 06:56:59 +03:00
Ouroboros
b567ca51b0 Merge current ouroboros into anchored memory candidate 2026-09-26 06:50:46 +03:00
Ouroboros
c2c4155918 fix: reconcile anchored automatic memory edits with provenance and debt
Adapt the structural intent of PR #1291 (aafad5c5a6) onto #1295/#1299/#1311. Share exact body-span compilation; allow an explicit summary update in the same source-locked transaction while preserving other YAML fields. Keep one outcome per nomination, host provenance, manual edits and supported deletion/reorganization.

Version-neutral contributor candidate. Independent exact-range review and publication are still pending; Stage0 writer-choice experiment remains separate.
2026-09-26 06:23:46 +03:00
Ouroboros
80fdcee156 fix: receive emergency controls while ordered chat acceptance settles 2026-09-26 06:12:30 +03:00
Ouroboros
192a5780a1 fix: settle late quiz forwarding off the ASGI loop 2026-09-26 05:42:05 +03:00
Ouroboros
0672b6891e fix: preserve post-work interruption and explicit stop truth 2026-09-26 05:36:10 +03:00
Ouroboros
9878b66ec9 Merge current ouroboros into focused TZ1 ingress and access candidate 2026-09-26 05:14:48 +03:00
Ouroboros
ebc89607d5 Merge current ouroboros target 90ce019b into Windows contribution 2026-09-26 04:59:47 +03:00
Ouroboros
0a065d2048 fix: keep web ingress off ASGI loop and align rights closure tests
Await durable web acceptance in the existing off-loop completion seam; test responsiveness with a held ingress lock. Diagnose long edit needles honestly, and update old access-matrix assertions while preserving child secret/write refusals. Version-neutral contributor fixup.

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-26 03:30:38 +03:00
Ouroboros
5db5639fc9 Merge origin/ouroboros (f0af68e82: v7.5.0, Presence TZ3 #1310, memory TZ3 #1311) into tz2-bc-open-question
Semantic resolution of 15 conflicts: escalate 0-6/open-question wording folded into ESCALATE_TOOL_SCHEMA; quiz validation keeps zero-option cards; task_decision uses the shared owner_quiz frame builder; telegram skill 1.2.6 = whole/multi-part card (upstream) + lifecycle follow with per-card lock (TZ-2 B2) + open question without keyboard; Presence terminal stamp kept beside the filtered root post-task predicate. Known reds to fix next: consolidator.py over 1600 lines, chat_decision.js band rationale, chapter 11 budget.
2026-09-26 03:20:31 +03:00
ouroboros-agent
8c67716c94 Merge remote-tracking branch 'origin/ouroboros' into ouroboros-agent/tz3-history-visibility
# Conflicts:
#	tests/test_persistence_inventory.py
#	tests/test_reference_book_budgets.py
2026-09-26 02:48:17 +03:00
Ouroboros
1f537e1f80 Merge current ouroboros target (4f8dce1f6) into fix/windows-managed-npm-toolchain
Upstream advanced 86d4e6298 -> 4f8dce1f62
(v7.5.0: PR #1300 single Dockerfile + extra CA bundle, #1207 Z.ai provider,
#1309 OpenAI-family cache layout, TZ2 Presence work), which left PR #1150
CONFLICTING on GitHub.

One textual conflict, tests/test_reference_book_budgets.py: upstream's
chapter-08 budget (22000, measured 21921 on its own tree) does not cover the
merged chapter, measured 22454 = upstream's Docker subsection + this PR's
533-byte platform-gate sentence. Upstream's rationale block is kept and the
budget is raised minimally to 22500 with the PR's rationale re-stated on top.
docs/architecture/08-git-branching-ci-and-build.md itself auto-merged
(different paragraphs, no text touched).

No upstream change since 86d4e6298 touched claudexor-platform-gate.yml,
scripts/claudexor_toolchain_smoke.py, ouroboros/claudexor_runtime.py, the
runtime pin, size_ratchet_manifest.py or the claudexor tests; those files are
byte-identical to a5fa2c998 here. DOMAIN_MAP.md and the generated inventories
already match the merged tree, so nothing was regenerated.
2026-09-26 02:35:32 +03:00
Ouroboros
001904a6bc tz2: B3 follow-up objective_author, C2 stat-only files_rescued fact, B1 comment-only browser test
Timer follow-ups carry the same objective_author stamp a promote carries (B3). The host_task_facts row and the cancel receipt state files_rescued as a stat-only positive/zero/unknown count with hash_computed:false, walking the canonical and child-drive artifact stores (C2 fallback per owner correction; B5 receipt stays NOT_DONE pending the TZ-1 landed API). New real-server Chromium test for a zero-option question card (B1). Chapter budgets bumped with rationale.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-26 02:33:34 +03:00
Ouroboros
90b757712b feat: make owner ingress and startup status honest
Close tool-rights affordances and bounded edit diagnostics, retain per-message batch transport with live-process tail handback, preserve accepted web input evidence through quiz responses, and show Starting/Input saved without implying a running supervisor. This version-neutral contributor slice deliberately defers artifact custody, directory ZIP, and V10 to a separate structural PR.

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-26 02:31:33 +03:00
Ouroboros
00a434d01a Merge origin/ouroboros (4f8dce1f6, v7.5.0) into presence-resilience
tests/test_persistence_inventory.py: EXPECTED_SCAN_PATHS measured at 297 on the merged tree (base 294; upstream +2 for state/extra-ca-bundle and its *.pem glob; ours +1 for task_results/quarantine/*), both comment histories kept.
ouroboros/llm_claudexor.py: upstream's declared-prefix projection and wire_layout stamp (#1309) and our quota re-ask / all-operations-not-started proof are disjoint hunks; the re-ask reuses the projected payload and changes only its account field, so mutable context stays out of the cache unit.
supervisor/message_bus.py: quiz-card host_facts (#1302) and our fail-closed ensure_record_boundary plumbing are separate functions.
docs/architecture/06-agent-core.md: 314156 -> 313972 bytes under the unchanged 314000 budget by tightening the quota-wait paragraph only; no fact removed.
docs/PERSISTENCE.md, tests/test_reference_book_budgets.py: auto-merge kept, rows and budget entries disjoint.
ouroboros/size_ratchet_manifest.py: band rationale for llm_claudexor.py, which enters the 1001-line band only on the merged tree.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-26 02:26:58 +03:00
ouroboros-agent
4a3e47d18a memory: key era_retry to the executed Light binding; input_ref on skip events
Round-3 repairs of the exact-range review of 193a948e:
- era_retry dispatch key is read AFTER the paid era call, so an owner switch
  inside the wait rebinding the Light role keys the record to the binding that
  answered (regression switches the override inside the fake LLM call).
- reflection skip events carry input_ref (the retained task-input prompt /
  bound entry copy), not a misnamed reflection_ref; docs say what is retained.
- _compact_chronicle docstring: a meta-less pass reads/writes no durable retry
  metadata; every run is still paid for.

Repairs authored by a Claude Fable-5.1 subscription session (run-f7ef06af47ab).

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-26 02:23:18 +03:00
Ouroboros
7a387f7178 fix(tz2 C4): an explicit author stop stays a stop
Freshness checks bind a finish only; a stop is recorded as author_stop without buying a panel. The task row reason slot carries the author rationale (project_dialogue + log_events twin + parity fixture). Authored by a delegated Claude Fable run.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-26 02:03:33 +03:00
Ouroboros
6a2ee44ac2 docs/tests: narrow the transport-death repeat wording to Host-executed effects; state the 409 condition exactly
Reviewer P2: a lost response proves no Host-executed tool or correspondent action from the failed attempt, not that nothing ran anywhere — priced read-only provider-owned retrieval (server-side web search) may rerun on the repeat. The 409 and owner notice apply when the round ends unresolved without a further permitted repeat (deadline or a finalize control can refuse the first repeat). Test comment on the owner-notice writer corrected; chapter budgets untouched.
2026-09-26 02:00:57 +03:00
Ouroboros
193a948e07 memory(tz3-pr1): host-only nomination route, effective-route era_retry key, validator skip events, honest route fallback, doc/code sync (review round 2)
Closes the six findings of the exact-diff review of a1f651878..844107a0: model-supplied _nomination_route (and every _-prefixed host key) is stripped in bind_entries and stamped only at the host nomination seam; era_retry is keyed on the effective Light dispatch binding (lane, account pin, model-wait override) shared with dispatch; validator rejections (unsupported_type/empty_content/missing_topic) emit reflection_memory_action_skipped on the real generate_reflection path and cannot abort the batch; observed_route_stamp reads physical facts only (partial -> per-field unknown) and a usage merge forwards only the last call stamp; chapter 06 and PERSISTENCE distinguish ordinary vs pressure era pass and mark calendar recompression deferred; the per-nomination route test covers three rooms with an unknown correction route outranking the block stamp.

Repairs authored by Claude Code (claude-fable-5-1) under Ouroboros supervision.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-09-26 01:40:46 +03:00
Ouroboros
eb4e42b972 test/docs: pin the same-round transport-death repeat as a no-effect attempt for Presence; unknown-outcome notice test on the 409 contract
Regression drives the real round dispatcher with a ledger-backed fake provider: one dispatched ReadError, one repeat, two attempts, no tool run or send between them, no forced final, no presence_unknown_outcome. test_provider_terminal_notice converted from the pre-TZ3 200-deferred expectation to the 409 presence_attempt_outcome_unknown contract with admitted child custody preserved. Ch.06/ch.12 state the contract.
2026-09-26 01:26:42 +03:00