Conflicts: ouroboros/tools/control_routing.py (both kept: the presence note inside
its branch, the consciousness origin stamp after it), docs/architecture/03, 06, 12
(their new sentences kept, the consciousness wording re-applied), and the generated
v7next inventories (regenerated).
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
The books still described a private background loop with its own prompt, its
own context, its own card and an observation inbox. They now describe what the
code does.
Architecture: 01 gives `consciousness.py` its alarm-clock description and adds
the missing `consciousness_wake.py` row beside the two P3 modules, drops the
retired observation inbox from the data layout and the deferred-frames clause
from owner_delivery, and names CONSCIOUSNESS.md as the wake template rather
than a second system prompt. 03 says the alarm does not start a wake while an
owner direct turn is live (a running wake is not interrupted by one), drops the
always-shown kind from the block predicate, and describes what Activity and
Evolution actually render. 05 puts the alarm tick in the supervisor pass and
stops claiming a separate consciousness event producer. 06 replaces the
"Background consciousness and Evolution" opening with the new design — an
ordinary Main turn, its origin, its Observe/Act/Full authority with
dispatch-only `disabled_tools` and the per-task mode cap, and one rolling-24h
allowance through the single admission door — and keeps the evolution
paragraphs untouched. 07 loses the retired max_tokens row; 10 loses the inbox
invariant; 11 records the accepted late quiz answer, `max_wait_minutes`, and
that no third activity `kind` was introduced.
Development: 02 stops saying consciousness carries its own prompt; 03 drops the
retired observation growth row; 04 says its context IS the Main context; 06
drops the wake-scoped `ModelTurnState` and states the cache consequence of the
shared prefix. DESIGN.md loses the always-shown kind and the reusable
background card, and states the quiz card's new "you can still answer" family
and the bounded-wait notice. PERSISTENCE.md marks the inbox retired with its
one-time archive move.
The three new modules were missing from `ouroboros/domains.toml`, which left
the domain manifest red; they are D15 and the generated sections and
DOMAIN_MAP.md are regenerated (D15 shed two strict edges, D07 gained the
admission door's edge). The hot-store count is eight everywhere, and the
generated v7next inventories follow their sources.
CHECKLISTS.md (a protected file, owner-sanctioned В30=A) gets three minimal
wording fixes: item 13(b) drops "(or the background whitelist)" because no
whitelist exists, 13(d) points at the wake template and at wakes rather than
"background loop behavior", and the Tool schema critical-surface row names the
wake template.
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
Background Consciousness redesign, P3 (authority). A wake-up carries the level
it started under (`metadata.consciousness_autonomy`: observe | act | full,
owner decision В10', default act) beside its origin label
`metadata.initiator = "consciousness"`. One helper derives the level's two
consequences at task build (`consciousness_authority.apply_consciousness_authority`,
applied at the direct lane's contract attach and at the agent's):
- `disabled_tools` — Act withholds the runtime's own posture (toggle_evolution,
request_restart, set_tool_timeout, toggle_consciousness, configure_presence);
Observe adds every verb that starts work or changes the world, an EXCEPTION
list (`tool_capabilities.OBSERVE_WORLD_MUTATION_TOOLS`, beside ROUTING_VERBS,
plus FOREGROUND_MUTATIVE_TOOLS), so a new read tool is available to Observe
by default; `steer_task` is never withheld (В12 A); Full withholds nothing.
- `runtime_mode_cap = "light"` for Act/Observe (В21=A, "may write, but not into
its own repository"): the tool dispatcher's one local `_runtime_mode` becomes
the stricter of the install mode and the cap (light < advanced < pro <
cyber_pro), so the repo-mutation gate, the protected-write gate, the
start_service gate and the shell write block all read it; `get_runtime_mode()`
itself is unchanged and Cyber Pro does not force Full.
For a consciousness-origin task the disabled list binds at DISPATCH ONLY
(В31=B): the schema filters in `registry_core` (available_tools, schemas,
get_schema_by_name, policy_hidden_reason) skip it and record no
`disabled_by_contract` omission, so the wake's tool schemas, capability
manifest and cached prompt prefix are byte-identical to an owner turn's; the
typed `RESOURCE_CONSTRAINT_BLOCKED` refusal in `registry_guards` is the
mechanism (`disabled_tools_dispatch_only`, documented on `_disabled_tools`).
The shell write block's light gate is now root-independent: a cyber_pro
install resolves user_files to the whole host, which admitted a repository
target under that name for a light-capped task.
Owner-sanctioned protected-file edits (В30=A) are limited to those seams:
registry_core.py (four schema-filter sites, the local mode resolution) and
registry_guards.py (the predicate, the `_disabled_tools` docstring, the light
branch of `_direct_shell_write_block`).
Also folds P1's three-line `ChatOutbound.initiator` addition in
gateway/contracts.py back under the 1600-line gate (comment-only).
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
A supervisor refusal of a chat-issued promote used to reach the owner as a
standalone Ouroboros bubble (WORKSPACE_UNUSABLE ...), reach the model without
its cause, and label the owner's message "Choose a target" with no options.
- Every workspace refusal returns `detail` (cause + repair) composed by
`workspace_admission.workspace_repair_hint` from the typed source of the
refused folder; `_persist_promote_rejection` is the single durable writer.
`_fail_promoted_task_loudly` and `_explicit_workspace_remedy` are gone.
- Placement follows who can narrate: a tool-issued act gets its receipt, the
failed-call error row and `detail`; a host-issued act (skill card, Swarm,
picker click, stamped `host_initiated`) gets ONE typed System row
(`task_not_started` / `task_start_unconfirmed`) in the chat the owner wrote
in, from the one publication boundary `_handle_promote_chat_to_task` wraps
around every promote outcome. The skill-repair untyped bubble is removed;
steer cancel-pending notices obey the same owner-labelled rule.
- The host owns the owner-facing sentence: `project_dialogue.routing_refusal_cause`
(action + status + reason, e.g. "Not started: the working folder can't be
used") rides the annotation, the live `message_annotation` frame, history
replay, `MessageAnnotationOutbound`/`DecisionResponse` and the picker's 409
body; the browser renders `cause` verbatim and keeps no client table.
- Admission-notice rows stay in the chat they were sent to on replay
(`room_membership` ignores the never-started task's project binding); the
"Project · Started" row is announced only after the task is really queued.
- `workspace_root` naming the Ouroboros repository itself maps to the existing
`workspace="none"` sentinel at the promote tool with a disclosure; subfolders,
the data drive and every other caller keep the typed refusal.
- Docs (DESIGN, architecture 01/03/04/05/06/12, DEVELOPMENT naming rule),
generated inventories, python and web tests.
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
Preserve the reviewed feature while moving its documentation into the new reference-book chapters and regenerating their inventory source hash.
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
Doc truth left behind by the chaptering and the activity block: the
configuration row that named the deleted background namer, the data-layout
tree without the two chapter directories, chapter 10 pointing the version
carrier and the map claim at "this document" (they live in the entrypoint),
DESIGN's subscription-wait section naming only the task card, the inventory
header telling the reader to edit a section that is now a chapter, and the LF
pin the inventories' line ranges depend on, unnamed. The reflection router's
docstring now states the owner-accepted Pattern Register input.
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
The reference book already names four routing verbs on the receipt rail
(promote_chat_to_task, route_to_project, steer_task, ensure_project_scope),
but the one owner of that family, ROUTING_VERBS, listed three, so a turn that
only moved itself into a Project drew a block in Main standing on its
ensure_project_scope row beside the Started annotation and the project
pointer that already record the act (observed live on the stand). The table
now carries the fourth verb; the typed action on task_done, the frame stamp
and the metrics count follow from the same row.
The table also moves from tools/control_events.py (D08) to
tool_capabilities.py (D04), which already names the routing tools in the
core envelope: the tool executor and the metrics projector (D01) reading it
from D08 was a new strict cross-domain direction the domain manifest
refused, while D01 -> D04 and D08 -> D04 are existing directions. Same
membership, one owner, no manifest regeneration.
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
Owner decision 11.09 (2A): a turn that only addressed work (promote_chat_to_task,
route_to_project, steer_task) draws no block; the typed annotation on the owner's
message is its receipt. WP-G made every successful tool call a content row and
deleted the client tool-name list (correct, P5), but replaced the deleted rule
with nothing, so "turn this into a project" showed a direct-turn block with one
promote row beside the annotation and the managed root's own card: exactly the
redundancy 11.09 removed (tests/test_chat_addressing_browser.py, promote_only).
The host states the fact once. tools/control_events.py owns the routing-verb
table (ROUTING_VERBS): the typed action on task_done reads its event side, the
live tool-call frames read its tool side (`routing_action` on tool_call_started
and every tool_call_finished producer), and task_tool_metrics counts the calls
through it (`routing_tool_calls`, carried by the task_metrics event, the
authored summary row and the history replay). The client marks such a row
`receipt` (chatView, the timeline item, patched back to content by a failure
frame) and blockVisible's content term skips receipt rows; the replay summary of
a turn whose recorded calls were all addressing calls, without error, is a
receipt row too. A recorded tool error is content on its own
(`record.toolErrors`), which makes the V1 replayToolErrors term explicit. No
client list of tool names decides presence; the row still renders inside a block
that exists for other reasons. DESIGN.md, the web-UI chapter and the
anti-pattern chapter ("an open default behind a closed exception list") state
the rule in present tense and name the host stamps.
Size: loop_tool_execution.py stays at 1500 lines by reusing `_tc_args` for the
started-frame arguments instead of a second best-effort parse; chat.js
192,234 -> 192,349 bytes, paid back in the Stop commit.
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
Ordinary target drift: eleven upstream commits (PR #935 bubble-header facts,
PR #936 update-history scans plus executor progress, PR #938 Windows fixtures,
the durable direct-card completion recovery, the Project-history task-card
facts) landed after this candidate's base c306b40d8. A merge commit is the
right shape — no published ref is rewritten and the candidate is not rebased.
Seven files conflicted; both sides' intent survives in each:
- docs/ARCHITECTURE.md, docs/DEVELOPMENT.md: upstream edited the monoliths,
which are entrypoints here since the reference-book split. The entrypoints
stay byte-identical and each of the ten upstream hunks was applied once, at
the chapter that owns the section its surrounding text belongs to. None of
the ten landed on a sentence the semantic subtraction had merged, so no hunk
had to choose between two copies; docs/reference-books-migration.md records
chapter and heading per hunk. The two generated inventories carry the moved
source lines and SHAs of the chapters that were edited.
- docs/CHECKLISTS.md: upstream's items 7, 8 and 24 (plus the item-24 "Not
applicable" note) beside this candidate's items 2(f), 6, 23 and the
plan-review resource rubric. Nothing else in the protected file moved.
- web/modules/chat.js: upstream's cost projection for a review reference now
renders on the carrier card this candidate resolves through
getLiveCardRecord/ensureLiveCardVisible instead of the deleted forceTaskCard,
and its change signal joins the mount/anchor signals. 192,234 bytes, below
the 200,000 byte gate, so the shrink-only chat.js byte-debt row stays gone.
- ouroboros/gateway/state.py: upstream's post-loop pass that applies bindings
to every copied activity (direct rows included, so a converted direct card
is re-homed while active_direct_turns keeps its source chat) now carries
this candidate's origin_bound gate — an origin-bound row is a convert-gate
fact only (#902) and re-homes nothing, because such a task was never bound
and its chat rows are still where it was started. _activity keeps reading
chat_id/project_id off the row and keeps the _is_direct_chat kind.
- docs/DOMAIN_MAP.md, ouroboros/domains.toml,
ouroboros/size_ratchet_manifest.py: union of both sides' new modules;
DOMAIN_MAP regenerated to 546 modules, the manifest to a checked tree.
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
Five Development introductions promised facts the subtraction moved to
their Architecture owners (the release carrier list, the fresh-rescue
WHY, the process ledger and daemon-stop protocol, the stdio MCP contract,
the dependency-lock authority); the overview is built from these
paragraphs, so each now describes what its chapter owns after the
subtraction. The only line-number reference into the books
(DEVELOPMENT.md §651 in tests/test_v652_scratch_and_masking.py) becomes
a heading reference — line numbers rot, headings resolve through
read_book_section.
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
A release stamp inside the external-fact inventory, plan-wave and
plan-item codenames (W3, A4, 6.1), "is gone" / "former" / "old …
removed" narration beside rules that state the current behaviour, a
retired key named beside the rule that replaced it while section 11.4 is
the retirement ledger, and one commit-relative aside ("out of this
change's scope") are removed. Each removal keeps the current rule in the
same book, keeps every owner citation (R2, R3, R7 dates and ids stay)
and keeps the disclosed residuals (#588, #906). Load-bearing history —
why a rejected design was rejected, the live residues of the Claude SDK
retirement, the ABI 7.0 retirement window — stays (BIBLE P12; CHECKLISTS
item 7 P6/P7).
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
The Development book restated mechanism the Architecture book already
owns: the acceptance pacing rails and their deadline-cut residual were
written three times (Task lifecycle, Review & Commit Protocol, Loop /
State-Machine Changes), the $0 exit shape twice, the credential fence,
the onboarding transaction, the daemon stop protocol, the transport-death
repeat rail, the budget-tracking lifecycle and a dozen smaller mechanisms
once in each book. Two statements of one fact drift apart; a rule that
carries its own copy of the mechanism stops being checked against the
mechanism's owner (BIBLE P7 SSOT; CHECKLISTS item 7).
Every merged paragraph keeps the imperative, the enforcing test names and
the owner citations, and replaces the restated mechanism with a pointer to
the chapter and heading that owns it. Facts stated only in Development
stay where they were: this commit subtracts duplicates, it does not
relocate single-owner rules. The Architecture owners that were missing a
fact the merged text carried (the shared read/search byte masker, the
attachment-ingest leaf checks, the size-ratchet own-tree bootstrap, the
reasoning_effort_clamped disclosure, the transcript cache measurement
date, the base-fallback debt-laundering WHY, the history-row and
download-link carriers) receive those facts in the Architecture commit
that follows.
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
Four descriptions now described the shape the split replaced.
The ARCHITECTURE §1 row for `reference_books.py` still claimed legacy monolith
composition "during migration" and a validator that "serves docs-only CI" with
no production caller. It now names what is true: the membership both books
carry, the pure path question (`book_path_role` / `book_entrypoint_for`) that
every consumer asks instead of keeping its own chapter list, and the tracked-
tree validator run that makes a missing chapter, an unlisted one or a lost
authored introduction red in the suite. The `context_layout.py` row states view
intent and why a compact view addresses the physical chapter. The context-
delivery registry rows in "Core Governance Artifacts", the Low-mode sentence in
"Context fitting, retry, and compaction", and the truncation invariant that
defined "navigation map" all follow.
The "Documentation contract" section gains the canonical-book maintenance rule
it did not need before: one membership list and no second manifest, an authored
introduction on every source (it IS the compact view, so there is no second
editable summary corpus), WHY stays in the chapter that owns it, and readers ask
for a view rather than for a file — with the reason spelled out, because reading
an entrypoint with `read_text()` and treating the result as the book is a pin
that passes while testing nothing.
The byte proof moves onto history, where it belongs. It compared the working
tree against the recorded digests, which made every later ordinary edit to a
chapter a false red — a booby trap under a documentation contract whose own
rule is that a change REPLACES the description of the node it touched. It now
resolves both sides from Git: the base commit's monolith against the chapters of
the commit that ADDED the transfer table, found by content so a rebase cannot
strand it on a rewritten SHA (`quick-test` and `full-test` check out with
`fetch-depth: 0` for exactly this class of proof). Beside it sits a structural
half with no time bound: the base's `##` titles are the chapters' H1 titles, in
order, one each — so a lost, merged or re-titled chapter stays red forever while
an edit to a chapter body does not.
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
The books were one physical file each: ARCHITECTURE 2,386 lines and
DEVELOPMENT 3,886, with 13 and 14 `##` sections. `reference_books.py` had
shipped the chaptered reader — membership, authored introductions, exact
physical source views — with the migration still at zero, so every reader
took the legacy monolith branch and the validator had no production caller.
Each `##` section is now one chapter file under `docs/architecture/` or
`docs/development/`. The only new bytes per chapter are its prologue: the old
section title at H1 (numbering text kept, so every `ARCHITECTURE "8. Git
Branching, CI, and Build"` cross-reference still reads) and one authored
introductory paragraph saying what the chapter owns and why it exists.
Everything after that prologue is the old section body byte for byte, with
`###`/`####` levels untouched — so the residue rules keep reading the exact
subsection headings they exempt, and no section title was renamed.
The move is therefore INVERTIBLE, and `tests/test_reference_book_migration.py`
inverts it: drop each chapter's H1 line and its one introduction, re-prefix
`## `, concatenate in membership order, and require the recorded SHA-256 of
the old body — plus, whenever the base commit is reachable, byte equality with
`git show <base>:<path>`. `docs/reference-books-migration.md` is the operator
transfer table: every row a verbatim move, with its line range at the base, its
destination and an empty rename column. It lives directly under `docs/`, so it
is reviewable without becoming a book member.
`_preamble` now takes the FIRST paragraph under the H1 instead of demanding the
only one before the first H2. Most sections open with prose at the level they
already had, so the old rule could only be satisfied by promoting `###` to `##`
or inventing a sub-heading — either of which would rewrite what this migration
relocates verbatim. A source whose H1 is followed straight by a subsection
still has no introduction and is still refused, which is the property that
keeps an overview from quoting body prose as authored orientation.
`.gitattributes` pins `docs/**/*.md` to LF: chapter line ranges, byte spans and
SHA-256s are physical facts that a Windows checkout must not rewrite, and
`full-test` runs on windows-latest for every PR. The two ARCHITECTURE-derived
generated inventories are regenerated, because a chaptered section now carries
its physical provenance note.
Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>