Commit graph

3 commits

Author SHA1 Message Date
Ouroboros
90b757712b feat: make owner ingress and startup status honest
Close tool-rights affordances and bounded edit diagnostics, retain per-message batch transport with live-process tail handback, preserve accepted web input evidence through quiz responses, and show Starting/Input saved without implying a running supervisor. This version-neutral contributor slice deliberately defers artifact custody, directory ZIP, and V10 to a separate structural PR.

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-26 02:31:33 +03:00
Ouroboros
7b0f649061 Let a read-only child read Deliverables and its lineage's task files
A root task put files into its own task_drive and sent four read-only
children to check them; all four were refused with "outside selected
root". The only recorded reason for hiding the orchestrator roots from
children was sibling-project independence, which covers subagent_projects
alone. Owner decision T4=A (#1105): the local_readonly_subagent matrix
gains the Deliverables row, and one lineage rule (lineage_task_ids /
lineage_read_base) lets an actor READ the task_drive/artifact_store of its
own id, its parent_task_id and its root_task_id, anchored on the canonical
data root while the child runs on a child or headless drive. The two
cross-prefix carve-outs fold into it: the own-prefix delegated-capture
anchor is the lineage rule's own-id case, and the orphan capture rule
keeps its custody authority. Lineage roots are not content roots, so
secret-named files in a parent's drive stay denied by name.

The read-only child's schema enums now come from the same matrix the
dispatcher enforces instead of a second hard-coded list, refusals and the
roots hint share one vocabulary (operation_roots), and the parent at
schedule time and the child on its first context line see what the child
can read and what stays invisible. The prompt sentence is replaced under
owner 6A (165 of 168 bytes) and the ARCH 06 node byte-negative.
2026-09-21 12:41:08 +03:00
Ouroboros
22c1473117 v7next F1: domain D04 - registry and tool_access split, proof-green; core/typed-result organs hot-deferred
Module side: 4 of 8 D04 owners are byte-identical to the reference and merge
base (protected_artifacts, tool_policy, tools/__init__, tool_discovery), one
is pure upstream drift (tool_capabilities - upstream bytes stand), one keeps
upstream bytes because its reference delta is the typed-dispatch cutover
(extension_dispatch, rows 187/188 deferred). The two splits land from TIP
bytes with the transplant tool's triple proof green on every symbol
(ast=tokens=bytes, leaf_invariants=[], exit 0):

- tools/registry.py 3960 -> 2686 (PROTECTED file: pure byte-preserving span
  relocation + one re-export block + noqa on historical imports - proven by
  line-accounting audit): tool_context (2 symbols), tool_catalog (1),
  tool_resolution (28), registry_guards (16), registry_guard_process (27).
  13 spans were byte-falsified as oracle copy sources by pure upstream drift
  and re-emitted from tip bytes; 5 rows whose reference destination carries
  typed-result semantics moved their TIP bodies verbatim (typed deltas ride
  with F2). HOT-DEFERRED with evidence: registry_core.py (ToolRegistry is a
  2252-line class; the reference slimmed it via 17 method->function
  extractions, which are not byte-preserving), tool_result.py (32/33 symbols
  are the D02 typed organ, absent at tip).
- tool_access.py 1591 -> 782: tool_access_types (14), tool_access_paths (10),
  tool_access_roots (9), tool_access_user_files (8); 39/41 spans byte-equal
  to the reference, _skill_payload_base and ResolvedResourceBinding
  re-emitted from tip (upstream refactor/field would have been reverted by an
  oracle copy). The D1 mirror-path defect travels UNFIXED per lane orders.

Protection closure (protective-only, mirrors the reference and the tree's own
LC2 parity rule): the five landed registry leaves join SAFETY_CRITICAL_PATHS
and HOT_CODE_PATHS - code that moved out of the protected, hot registry keeps
both labels; pinned by the new parity test.

Test side: tests/test_tool_capabilities.py 1991 -> 681 splits into 4 siblings
per ledger rows 784-825 from tip bytes (34/42 spans oracle-equal, 8 re-emitted
from tip); lossless 61==61 test functions, tree-wide AST dup scan clean.
Pins carried with disclosed adaptations: test_tool_owner_facades.py (+alias_for
row), test_tool_access_extraction.py (4 adaptations in docstring),
tool_resolution identity test appended to test_workspace_authority_binding.py
(typed companion deliberately not carried).

size-ratchet manifest regenerated with the official tool (test_tool_capabilities
leaves GIANT_PATHS; no new band entries); ratchet lane 5 passed; ruff F clean;
90+518+586+257 tests green in isolation at the lane base; HEAD held through
every pytest run. Ledger corrections: docs/v7next/LEDGER_CORRECTIONS.md D04
section, entries 1-11.

(cherry picked from commit 2321514369b6f003e92bcd84e6a9a7efda6857df)
2026-08-30 18:38:35 +00:00