One Ouroboros across Main and project rooms: each root may publish a short
authored focus (update_focus) that rides the durable task result and the
[INDEPENDENT_ROOTS] tail, so concurrent foci can see one another without a
shared chat, a new wake or any widened authority; explicit cross-room
journal/workpad reads are honoured instead of silently redirected.
Dialogue consolidation summarizes each source room of a logical chunk from
its own bytes (Light draft + source-grounded Light correction), assembles the
typed room sections deterministically into one shared block and carries
them through era compression; a failed room withholds its whole chunk while
earlier complete chunks stay published; legacy mixed blocks keep unknown
provenance. Room labels resolve against the canonical registry root even on
a forked task drive. BIBLE P1 states the principle in three sentences.
Version-neutral contribution: release carriers untouched.
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
The differential derives its expected key set from the corpus, and the
corpus derives every LIST_FILES_NOT_FOUND key from the tree itself:
`harvested_identifiers` sees the literal prefix of the producer's
f-string and yields `ident:LIST_FILES_NOT_FOUND:{plain,named}`, while
`harvested_native_pairs` sees the same `ToolResult(...)` call carrying a
literal `code="LEGACY_WARNING"` and a leading literal text, and yields
`native:LEGACY_WARNING:LIST_FILES_NOT_FOUND`. All three golden rows
therefore stay: removing any one of them fails
`test_single_classifier_matches_the_retired_pair_except_approved_deltas`
on its own `case.key in golden` assertion, the plain row additionally
fails `test_golden_covers_every_harvested_producer`, and the native row
additionally fails `test_native_golden_answers_have_identical_retired_text_inputs`.
The third row is not a hand-picked extra: the producer's native code
path publishes it and the derivation demands it. The identifier rows
were what P5.2 called "a corpus row for the new identifier", and the
harvest produces them without a hand-written entry.
What was genuinely missing is the producer's own shape. The miss
interpolates the exception into its text and publishes it under
`list_files`, and no case exercised that: the identifier rows carry a
synthetic detail under `read_file`, and the native row reuses that exact
input by construction. The shape row adds it, and the golden gains the
one answer its key forces.
That answer is derived, not invented. The retired pair no longer exists
in this repository and its source tree is unreachable here, so a new
shape answer could only be reused from a recorded one. The new test
`test_shape_golden_answers_match_their_own_identifier_line` states the
rule that permits the reuse, the sibling of the native-key rule already
asserted beside it: every shape row whose text opens with a marker holds
exactly its `ident:IDENT:plain` answer, over the rows captured from the
golden's own source tree, with no counterexample. GOLDEN_SOURCE_SHA and
the fixture's recorded `source_sha` are unchanged, and nothing was
regenerated.
Owner item I27. All three _ListingFailure kinds (path escape, directory not
found, not a directory) were caught by one except clause and published as
status=error / LEGACY_TOOL_ERROR / LIST_FILES_ERROR. In the live case the
listed folder name carried a non-breaking space: the miss was recorded as a
tool failure, the very next call found the right spelling, and the task still
finished as tool_failure because the recovery scan only credits a later success
with the SAME target signature, which a differently spelled path can never
match. Naming the miss at the producer removes the failure instead of widening
_call_target_signature or adding a bucket.
_ListingMiss subclasses _ListingFailure and carries the not-found and
not-a-directory raises; the confinement refusal (path escape) keeps the existing
error arm untouched. A new except clause above it publishes
ToolResult(status='ok', code='LEGACY_WARNING', '⚠️ LIST_FILES_NOT_FOUND: ...'),
the same shape the absent-memory-file read already uses (DATA_NOT_YET_CREATED).
This does NOT reopen v6.54.3: the miss is published as its own result with its
⚠️ identifier preserved and warning severity, so there is still no error string
inside an ok-shaped listing. Only the severity separates "nothing is at that
path" from "the listing itself failed". The TERMINAL root-required branches and
the hard-exception arm are unchanged.
Golden fixture: the new literal is harvested by the corpus, so three entries
were added BY HAND to tests/fixtures/legacy_tool_classification_0f715831.json at
an UNCHANGED GOLDEN_SOURCE_SHA - ident:LIST_FILES_NOT_FOUND:{named,plain} and
native:LEGACY_WARNING:LIST_FILES_NOT_FOUND (the phase named the first two; the
third follows from the producer publishing the code natively). This is not a
regeneration: every other answer is byte-identical, and the recorded answer is
the retired text chain's own generic-warning answer for an identifier that
matches no family or suffix rule, exactly as the neighbouring
DATA_NOT_YET_CREATED and NOT_FOUND rows show. No APPROVED_DELTAS row is needed
because golden and live agree.
Tests: the three '⚠️ LIST_FILES_ERROR' not-found pins in
tests/test_core_native_results.py now pin the miss, and a new case in
tests/test_observability_outcomes_v2.py drives the real registry through
miss-then-success-on-another-path and asserts execution stays ok with a "Done"
headline.
Recover complete reviewer results from their original operation CAS, preserve terminal custody separately from model narrative, and consume remote streams within physical-attempt accounting. Apply caller deadlines before every recovery send, publish known tool refusals accurately, and retain raw reviewer PASS separately from completion eligibility.
Managed work waits through unknown provider outcomes and continues with a marked new attempt after route-bound upstream observation, retaining old monetary custody. Metadata HEAD observations reuse the connection bound; ordinary no-deadline clients retain their existing timeout defaults.
Preserves the complete interrupted implementation and source-only version policy. Focused consumer, golden, lifecycle, domain, inventory, lint and size checks pass. The initial full preflight failed on stale consumers and a missing manifest compatibility field; the final full preflight is still required on this committed candidate.
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
Mechanical integration snapshot; retain the System mailbox reader unchanged here. The following explicit compatibility commit restores acknowledged owner-source reads without changing wait-local completeness semantics. This intermediate is not publication-ready.
Integrate the approved lifecycle source tree eb07a1f9853ec07f88fd30e7747256871fa21e55 on target 5c3f47ce6c. Carry the approved lifecycle checklist spans, exact trace-fixture migration, Read-only documentation wording and the two retired-oracle classification rows supplied with the installer stream.
Keep review, grants, dependencies, enablement and execution provenance separate. Reuse the shared lifecycle effect and rollback owners while preserving the selected payload revision and ordinary development capabilities.
Validation: 82 lifecycle/review/rollback neighbor tests and 28 classification/trace tests; whole-tree Ruff F, size manifest, generated inventories and domain checks. Original source trees were not modified. Formal review and publication remain pending.
- ouroboros/domains.toml: ouroboros/update_letter.py joins D12 "Settings &
configuration" beside update_channels.py (a human assignment; the checker
refuses to invent one); docs/DOMAIN_MAP.md regenerated.
- docs/v7next/DATA_LAYOUT_INVENTORY.md and FACADE_INVENTORY.md regenerated
(state/update_letter.json, the relocated getter and the new facade names).
- tests/fixtures/legacy_tool_classification_0f715831.json: the F3-A pack
exclusion note introduced the warning identifier PACK; the golden is
regenerated by the standard recipe (corpus harvested from this tree,
answered by the retired pair at the golden source SHA): +2 entries, both
informational (is_error false, status ok).
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
(cherry picked from commit 591e80f58b4481c67a57bff146463f6973fdc457)
Second parent is the frozen upstream `ouroboros` head (23ab428f, 407 commits
since the merge base a76961de); first parent is v7.0.0-rc.8 (18b9832e).
Every upstream change lands in v7's owning leaf: S1 transplants keep upstream's
bodies (comments verbatim) under the call-time handle idiom, S2 hand-merges keep
both intents, S3 keeps v7 only with proof (retired 7.0 ABI surfaces, superseded
mechanisms). Per-symbol relocation ledger: docs/archive/v7next/LEDGER_CORRECTIONS.md
(F2 absorption section). Provisional decisions awaiting owner ratification:
D-18 (two-destination symbols), D-19 (acceptance rows follow upstream R2),
D-20 (acceptance_dialogue stays deleted), D-21 (tools/registry.py: facade
import block only).
Docs: upstream ARCHITECTURE/DEVELOPMENT as the base with compact v7 deltas;
bookkeeping moved to docs/archive/v7next. Size-ratchet manifest, domain
manifest and generated inventories regenerated; new leaves: tools/write_shape
walker, gateway/cost_breakdown, tools/core_secret_paths; provider_catalogs.py
and acceptance_dialogue.py removed (v7 owners).
The full non-serial run after the merge surfaced 29 reds. None was fixed by
weakening an assertion; each is either a pin retargeted onto the campaign owner
or a real gap the sync opened.
Product gaps closed:
- the skill owner-state read carve never reached its call site: the guard was
taught `writeish` but still called without it, so `rg review.json` stayed
refused with a WRITE-named marker;
- a post-exec tripwire lost its typed fact whenever the producer returned plain
text. With the notes now TRAILING the payload the marker no longer owns line
1, so a text-only reader could not re-derive the classification — the guard
adapts once through the one legacy adapter instead;
- the reasoning-pin ContextVar sat in llm_messages, which imports llm_attempt,
closing an import cycle the leaf-graph test caught. It moves to
reasoning_artifacts, beside the fact it carries, where neither producer nor
reader imports the other.
Pins retargeted with their reason named: the composer's retired
ambiguous_safety_wrapper, the LLMClient member inventory (second documented
move), the declared handle sets of three leaves, the registry facade count,
the gh-auth denial text, and two observation seams the campaign split moved
(events_budget's append, registry_guard_process's guard entry).
Goldens re-recorded by their own documented recipes, every diff explained: the
llm route goldens now carry the reasoning_pin fact and pin openai/* on a sealed
artifact (#468 absorbs the family carve-out); the classification golden gains
five new warning identifiers and loses two retired ones. One golden case was
repaired rather than re-baselined — `or_provider_never_unpins_reasoning` held a
READABLE artifact, which the shape-first classifier never pins, so the case had
silently stopped testing its own contract; it now carries a sealed one. The one
real behavior delta is recorded as A.24: a structured `{"ok": false}` answer
behind an appended host note is a failure again.
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
- module-handle declared sets updated to the folded reality (hold controls,
body parser, quiz drain, cached ledger read)
- node-resolver tests retarget the campaign guard/attestation seams; frozen
ToolEntry replaced via dataclasses.replace
- sweep-refresh test targets ouroboros.server_maintenance (campaign owner)
- process-signal tests drive the typed dispatcher; the upstream regex-fallback
pin replaced by the D02 contract pin (prose forges no process facts) and the
stale regex-fallback comments corrected
- routing-decision/find-child fixtures stamp _schema_version (ABI 7.0 readers
quarantine unstamped rows); emit-and-wait patch retargets control_routing
- terminal-writers manifest gains _rewrite_execution_evidence (cursor/backfill)
- core catalog pins updated for send_links/escalate (owners: core_artifacts);
node argv policy moved beside its PATH-prepend half in extension_child_catalog
to keep extension_plugin_api at the 1000-line bound
- classification golden regenerated per the corpus recipe at 0f715831; three
A.23 approved deltas record the F6-sync classification changes
Re-derived on tip bytes; oracle v7_wip @ 9f691656 is the structural contract.
- loop_tool_execution (rows 157-164, 826-828): the retired result-text
classifiers (_FAILURE_PREFIXES/_FAILURE_MARKERS/_EXIT_CODE_RE/_SIGNAL_RE and
the elif ladder) are gone; status/is_error and the process/plan facts are
READ from the dispatcher's published ToolResult (ABI-6(b): the unreachable
_typed_or_adapted branch is NOT reproduced — the loop holds the typed result,
text-only callers get the ONE adapter through compatibility wrappers).
trace rows carry tool_result_status/code/meta alongside the legacy fields.
- extension_dispatch (D04 entry 5, rows 187/188) ADOPTED WHOLE from the
reference WITH BYTE PROOF (tip == merge-base == v6.64.0 for this file, md5
4e9ad3ba, so reference == tip+delta exactly): _dispatch_extension_tool_result
/ _dispatch_mcp_tool_result / _extension_dispatch_candidate produce native
EXTENSION_*/MCP outcome facts; dispatch_extension_tool stays the text
projection. registry_core retires the ToolRegistry dispatch methods and the
hoisted candidate; the dead-extension unknown-name answer is typed
EXTENSION_UNAVAILABLE (helper extracted per the function-size law).
- extension_process_runner (D14 entry 10): ExtensionProcessError gains
failure_kind ('timeout' at the deadline kill) consumed by the typed
dispatcher's EXTENSION_TIMEOUT arm.
- _outcome_tool_errors T1-partition (D15 entries 3-4, re-derived against the
upstream status handling): every produced status is homed by its nearest
analogue; tool_reported_failure and unavailable are policy-denial-partitioned
(spec 1.15) while argument_error stays a real failure; retired codes'
status names survive for stored traces; _UNPARTITIONED_BUCKETS makes the
deliberate vlm_error hole explicit; untyped joins _OK_TOOL_STATUSES.
- reflection (row 166): the 4 CLAUDE_CODE markers retire (0 emitters, pinned
by a repo scan test); _trace_call_errored reads the ok-status SSOT so
untyped/ok_autocorrected successes stop triggering error reflections.
- plan-review typed control: _parse_plan_review_control moves to plan_render
(its render-side home); publish_plan_review_projection/publish_rendered_wave
emit the typed plan result whose meta the loop trusts (wave_control_state is
the same projection the rendered footer reads); the plan handler pool-hops
through contextvars.copy_context so the sidecar publication reaches the
dispatching thread (reference delta, tip timeout design kept).
- tools/git facade re-exports _publish_git_error/_publish_review_blocked.
- Carried suites adapted to this tree (docstring/comment disclosures at each
non-verbatim spot): test_tool_result{,_meta_boundaries,_t46}, test_registry_core,
test_registry_guard_process, test_process_guard_codes, test_tool_catalog,
test_tool_classification_differential + corpus + legacy fixture; the two
loop_misc structured-failure tests re-home into the classification suite.
Notable adaptations: facade keeps the broad historical surface (AST 'defines
nothing' pin replaces the reference's exact-32 vars equality); guard patch
points follow the _registry() call-time handle; the strict managed-update
resolver is pinned with its corrupt-marker A4 channel; SCOPE_REVIEW_FLOOR
rows dropped (ABI-5, Q10=A).
- ARCHITECTURE.md same-commit delta (extension_dispatch + loop rows); size
ratchet regenerated officially (test_tool_result.py enters the band with
rationale); ruff F clean; -m size_ratchet 5 passed.
(cherry picked from commit c12800b3cf320490f59f1d2532fa45ce62e9486a)