OUROBOROS_SOFT_TIMEOUT_SEC and OUROBOROS_HARD_TIMEOUT_SEC stopped terminating
anything when the activity model (idle window + subtree liveness + absolute
ceiling) replaced them. What survived was five surfaces discussing a value none
of them obeyed: SETTINGS_DEFAULTS offered it, the Settings UI accepted a number,
the save response apologised for it, queue.init compared the caller's value
against the constant it then wrote anyway and logged a deprecation row, and
/status printed "legacy_timeouts_ignored: soft=600s, hard=1800s" on every
request. A knob discussed everywhere and obeyed nowhere reads as a live tunable.
Retired through the existing idiom - RETIRED_SETTING_KEYS, stripped on load. No
successor knob (the activity model already governs), so nothing to seed. Gone
with them: both globals and init parameters in queue/workers, the
_emit_timeout_deprecation_once emitter and its latch, the gateway's
_RETIRED_NO_EFFECT_KEYS bucket (a retired key cannot reach an effect bucket at
all, so _effect_buckets no longer needs the warnings parameter), the status_text
parameters and legacy line, the server reads and ctx fields, the bench settings
carriers and the TB forwarded-env allowlist, and the two ARCHITECTURE rows.
rc_audit's `since` stopped being a one-key special case: RETIRED_IN_THIS_ABI
names the distinction, so an upgrading install still learns the difference
between "stopped working in THIS upgrade" and "was already inert".
Pins: tests/test_legacy_timeout_retirement.py (10 cases, incl. a grep-class
sweep and the auditor's since/behavior). The N-1 fixture carries the pair at its
DEFAULT values - a default-valued ghost is the one nobody looks for - so the
rc_audit fixture suite now pins that both produce a retired-setting finding.
Two tests that asserted the old no-op semantics are reshaped, not deleted.
Disclosed: saving the key through POST /api/settings no longer returns an
explicit "Retired setting(s) saved" warning; it is merged away silently like
every other retired key. Restoring it would mean reading the raw body for keys
the merge deliberately never looks at.
All 15 D15 runtime modules are unsplit by design - upstream bytes stand as-is:
7 byte-identical to the reference, 6 pure upstream drift (nothing to do), and
2 (consciousness, reflection) carry v7 deltas of the D02 family that must NOT
be replayed verbatim - reflection's status-set delta would invert over
upstream's own handling (the re-prove trap is documented in
docs/v7next/LEDGER_CORRECTIONS.md together with a MIGRATION row already
superseded by upstream).
The test side transplants the oracle's D15 split: the 2386-line evolution
integrity giant becomes six themed suites (lossless: 65==65 test functions,
zero upstream drift of the giant since merge-base) plus three siblings carried
verbatim; adaptations are exclusively reverse-mappings of OTHER domains' v7
spellings back to upstream signatures, each keyed to the original monolith.
98 passed in isolation (re-verified independently); every file <=617 lines;
HEAD held through six pytest runs.