- devtools/measure_review_pack.py: the quorum limit and headroom are sized over the rows that RECEIVE the api pack — api_chat rows without a configured- subagent binding, decided by review_execution.delivery_retrieves exactly as review._prepare_unified_review decides before fit_triad_prompt; an all- retrieving panel reports 'no API pack is assembled for this panel' instead of a number (codex MAJOR). The 'index IS the working tree' comment became a checked invariant: an unstaged edit or an untracked file is the typed MeasuredCheckoutDirty refusal (exit 2), and the advisory arms are re-checked to resolve the same path set (fable MINOR). - ouroboros/tools/claude_advisory_review.py: the native advisory slot is built by the dispatch builder (reviewer_slot_config.reviewer_slots), so use_local comes off the resolved route and a LOCAL advisory model previews its MANDATORY READ bound on its own window with the typed shortfall disclosure, instead of the remote/unknown route's (codex MAJOR); file stays at 1492 lines. - ADOPTION_v7next.md / scripts/v7next_adoption.py: the Notes no longer call W4-F4 operator-disclosed; a 'Deferral authorities:' declaration mirrors DEFERRED_OUT_OF_V70 and the validator refuses a declaration that disagrees with the register (codex MINOR). - docs/archive/v7next/LEDGER_CORRECTIONS.md: one-row note that the immutable band rationale for claude_advisory_review.py cites 1434 lines while the file stands at 1492 (fable minor). Tests: tests/test_measure_review_pack.py (3 new, red-first), tests/test_advisory_route_pack.py (1 new, red-first), tests/test_v7next_adoption.py (2 new). Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com> (cherry picked from commit eca294f4520802f2f3b64eaaa7e236d19899b4a5)
90 KiB
ADOPTION manifest — v7-side deltas over the v7next upstream base
Ф0 skeleton (plan §5.1 as revised by roast F2: artifact/train-based, not
one-row-per-commit). Direction: this manifest covers the v7 → upstream
lane — every owner-approved v7 delta and campaign decision that must be
re-applied ON TOP of the integration base ouroboros_v7next @ b9f7597f
(upstream tip at branch creation). The opposite lane — upstream trains landing
after the cutoff — is adopted by owner signal («иди забирай») and is NOT
enumerated here; it gets its own train rows when the owner signals.
Sources (frozen reference, read-only):
ouroboros_v7_wip @ 9f691656—MIGRATION_v7.md(3901 rows by the oracle's own parser; the "3902" this bullet read until 2026-09-02 counted the header) and itsAPPROVED_SEMANTIC_DELTASregistry (scripts/v7_migration.py:130): 18 delta familiesD02–D09, D11, D13, D18, D31, D33–D38(the count read "17" from the F0 skeleton to 2026-09-01; the list and the validator'sREQUIRED_DELTASalways held 18 — the word was wrong, not the inventory).~/.claude/plans/v7next/V7NEXT_PLAN.md— §2 mandatory returns, §6 ABI package 7.0, §7 completeness, §5.4 three-column rule, v1.0 decision digest.
Projection of the oracle's 3901 rows onto the families below — every row family
accounted for, with the residuals the family form does not prove — is the one-off
report docs/archive/v7next/MIGRATION_PROJECTION.md (owner batch №13 item 12 = A).
Validator: scripts/v7next_adoption.py (unique ids; all 18 delta families
present; enum-valid disposition/status/phase; --release refuses any
pending-decision disposition or non-done status — "no unresolved rows at
release", plan §10).
Schema (fixed; one row per artifact-level delta family, never per commit):
id— unique;Dnn= approved semantic delta family;ABI-n= plan §6 item;CPL-n= plan §7 item;R-*= plan §2 class return;TRAIN-*= one post-cutoff upstream adoption train;DEFER-*= a capability the owner deferred out of 7.0;Wn-Fn= a defect a system-E2E wave found and disclosed instead of fixing.kind—semantic-delta|plan-item|class-return.disposition—retain(owner decision stands, apply as decided) |re-prove(re-apply and re-prove against the NEW bytes; plan §11: verbatim ledger rows must be re-proved, precedent «сдвиг базы фальсифицировал 9 строк») |superseded-by-upstream(upstream already carries the semantics; residual named inwhat) |pending-decision(three-column resolution per plan §5.4 still owed to the owner batch — forbidden at release).status—pending|in-progress|done|deferred. All rows startpending;deferredis reserved for the owner-deferred post-release row.phase— target campaign phase (F1 calm domains, F2 hot organs, F3 ABI package, F5 completeness, F6 synthesis and the rolling upstream sync). For the required inventory the phase is pinned in the validator'sREQUIRED_PHASE, so a row cannot be rescheduled silently.verification hook— the suite/checker that proves the row when it lands (suites named from the frozen reference arrive with their domain transplant, plan §5.3 step 4; hooks marked "(new)" are named now, built in their phase). Once the row isdonethe validator resolves EVERY token of its hook — path and::nodeidhalf alike — in both modes, because a resolvable hook is a property of a shipped row and not of the--releaseinvocation. Until then the hook may stay free prose naming the suite the work will land in.- Prose outside the table (this header, the Notes) names row ids only as the
table has them: the validator resolves every id-shaped token it finds there
against the table, and an id the prose names WITHOUT a row must be declared
on one line of the form
No-row ids: A, B— a declared id that has a row is red too (the Notes called W4-F3/W4-F4 rowless for two days afterd348ea46made them rows, past a green bar; a rowless claim in other words is not read, so it belongs on that line).
| id | kind | what | disposition | status | phase | verification hook |
|---|---|---|---|---|---|---|
| D02 | semantic-delta | Typed ToolResult/ToolCodeSpec seam with closed code table replacing re-read result prose (§4.3.3), incl. the loop-side retirement of result-text classification — the «D02-петля» mandatory return (plan §2). PHASE F1→F3 by the ratified F3 layout (2026-08-31): the typed organ is re-derived whole by the F3.1 lane A (design note docs/archive/v7next/DESIGN_TYPED_ORGAN.md); the deferral is documented across the D04/D05/D15 HOT-DEFERRED ledger rows, not silent. LANDED by the F3.1 lane A train (registry_core/tool_result re-split, producer cutovers, typed extension/MCP dispatch, loop cutover, T1 partition, D09 refusal subfamily incl. goldens 15→17); the ABI-9 digest-read and ABI-4 consumer sweep are the F3.2 seam's, not this organ's | re-prove | done | F3 | tests/test_tool_classification_differential.py + tests/test_tool_result.py |
| D03 | semantic-delta | Settings vocabulary seam: config.py -> settings_defaults / settings_scales / model_slots / review_model_routes / runtime_limits (§4.3.5); = plan §2 "S1 settings seam" return. LANDED in three trains: the vocabulary split (oracle rows 840-912) and the launcher half (rows 918-920) at a4481521; the semantic delta proper — rows 913-917 (config.normalize_settings_raw / serialize_settings, owner_settings.settings_document_digest + _owner_update_settings, the packaged_cli writer) and rows 1080-1081 (the server.py lifespan boot write) — by the D03 settings-read-seam lane (owner batch №11 2=A, base 1072a317), re-derived on tip bytes rather than replayed: the normalizer wraps the tip's settings_integrity read path instead of reverting it, the tip has four single-decision endpoints (the scope-review floor is retired, ABI 7.0 Q10=A) so the closed reader inventory is five names not six, the oracle's singular scope-pin ordering clause is dead here (both comma spellings are RETIRED_SETTING_KEYS) and the load-bearing order is re-stated as pass-count-before-purge and purge-before-rename, and the onboarding _settings_fingerprint wrapper was not kept (the digest is called directly; no passthrough). Red-first, stated for the file as DELIVERED rather than for the round-1 draft: 11 of that draft's 18 pins were observed failing on 1072a317, and the delivered 22-pin file has 15 failing on a 1072a317 export (the 11, the three round-2 pins, and the packaged-path pin, which round 2 turned behavioural and which the round-1 table still lists as a green golden); after round 4 deleted the six-file inventory pin (the tripwire closes the inventory over the whole tree) the file is 21 pins with 14 failing on that export. The 7 that stay green are goldens characterizing behaviour the seam must keep producing. The §4.3.5 defect no longer reproduces (one auto-grant POST changes exactly one key). Fix round 2 (same base): the Colab re-run is the third reader (normalize_settings_raw before its defaults merge, serializer bytes back on Drive), the owner reader shares the loader's verified read primitive (a changed pinned snapshot refuses both), and the context-fit route resolver reads the provider-normalized effective document — the read seam carries the vocabulary normalization only; the provider normalization is re-derived by every route consumer, which is what the retired boot write's "no reader needs it" rests on. Fix round 3 (same base): the prologue tripwire derives routing from the CALLS a function makes instead of from its source text (a docstring naming the prologue vouched for an unrouted writer) and sees a writer that neither names SETTINGS_PATH nor carries "settings" in its name; every writer now commits serialize_settings output through the byte-exact utils.write_text_atomic, so "one spelling on disk" is true on Windows too and is pinned on the mechanism as well as on the bytes; the packaged bootstrap saver takes the settings write guards on the path it writes; the context-fit pin takes its expectation from the task-start projection (the loop side) instead of restating the resolver's own expression; and the retired-key seam gains the classification pin for all fifteen keys. Fix round 4 (same base): the context-pair migration writes the one serializer's bytes (it re-derived the JSON text inside atomic_write_json, so "all five put the same spelling on disk" held only until the serializer changed, and was unpinned); the two writer scans are one predicate (tests/_shared.py::settings_writers) that sees a plain-handle write and any serializer call, parses every file (no prefilter), and closes the inventory over the tree against tests/_shared.py::SETTINGS_WRITERS, routed or not; the byte pin drives all five writers, requires each to call the serializer and to commit only through byte-exact shapes, and pins the spelling itself; the "every writer commits through write_text_atomic" wording names the config saver's write_bytes fallback. PHASE F1->F6 stays as the truth wave set it (operator scheduling correction, disclosed) |
re-prove | done | F6 | tests/test_settings_read_seam.py (rows 913-917 and 1080-1081: normalizer golden + idempotence, read-writes-nothing, closed reader inventory, digest-bound locked update, one serializer, retired-key seam; round 2: the Colab fixture, the provider-normalized context-fit route, the pinned-snapshot refusal on every reader; round 3: the byte+mechanism writer pin, the packaged saver's pinned-snapshot refusal, the loop-side context-fit expectation, test_a_retired_key_is_absent_from_every_surface_that_would_react_to_it; round 4: test_every_settings_writer_puts_the_one_serializers_bytes_on_disk — all five writers driven, each calls the serializer, byte-exact commit shapes only, the spelling golden) + tests/test_config_extraction.py + tests/test_onboarding_host.py (the two earlier halves; the boot pin is test_server_boot_never_writes_the_settings_file plus the behavioural test_server_boot_leaves_the_settings_bytes_alone, red on the base) + tests/test_runtime_mode_elevation.py::test_every_settings_writer_routes_through_the_shared_prologue (one predicate, tests/_shared.py::settings_writers, no file prefilter; closed over ouroboros/, supervisor/, server.py and launcher.py against tests/_shared.py::SETTINGS_WRITERS, routed or not) |
| D04 | semantic-delta | Retired settings knobs (§4.3.6). Owner 1B (2026-09-01) after re-checking the knob set against the tip vocabulary: the flat wall-clock pair OUROBOROS_SOFT_TIMEOUT_SEC/OUROBOROS_HARD_TIMEOUT_SEC is RETIRED via RETIRED_SETTING_KEYS — stripped on load, every reader, default, init parameter, save-response bucket, /status line and doc row removed, and the RC auditor classes them as this ABI window's own removals (since: 7.0) |
re-prove | done | F1 | tests/test_legacy_timeout_retirement.py |
| D05 | semantic-delta | Safety host facts (§4.3.8). Three-column outcome: schedule_followup = POLICY_SKIP is ALREADY carried by the tip (ouroboros/safety.py:111, byte-identical to the reference) — no port owed. The other two are ported by owner 2B (01.09) into the protected ouroboros/safety.py, retargeted onto tip bytes rather than copied from the reference: _safety_drive_root(ctx) replaces the cwd-relative getattr(ctx, "drive_root", "../data") at the safety model call with ctx-then-config.DATA_DIR, read late; _record_safety_usage(ctx, payload) takes the ledger writer off the module top level onto a CALL-TIME import of supervisor.state, the idiom the six sibling call sites in ouroboros/ already use, so the module every worker imports carries no import-time edge into the supervisor package. Residual disclosed in the ledger: the reference's injectable ctx.update_budget_from_usage sink is ported with the function but has no ToolContext provider at this tip |
re-prove | done | F1 | tests/test_safety_policy.py |
| D06 | semantic-delta | Events taxonomy: declared disposition of every event kind in four tiers, producer/answer pairing enforced (§4.3.12). Owner 3A (2026-09-01): the table is supervisor/event_taxonomy.py — PURE DATA (imports __future__/dataclasses/typing and nothing from the runtime, pinned by test, so it cannot become a second dispatcher) covering all 45 kinds the tree actually has, derived from the dispatch registry rather than restated: worker_handler (34 acting dispatch entries) + telemetry_only (7, and the tier IS telemetry_events.TELEMETRY_EVENT_HANDLERS — a handler that grows an action must change tier) together equal EVENT_HANDLERS exactly in BOTH directions, server_intercept (restart_request) and nested_log_event (task_checkpoint, task_start_settings_reload_failed, review_reference) are asserted ABSENT from it. Pairing is enforced both ways: the producer→answer direction REUSES the existing test_worker_event_registry AST scan (no second scanner) and every type it sees must be declared here; the answer→producer direction — which no scan can cover — declares each event's producing files and fails when one no longer names the event. The audit's producer-less schedule_task (events.py:272) is RETIRED rather than allowlisted: the handler function keeps its name and serves schedule_subagent, its only real producer, and a row with no producer is a hard failure with NO allowlist, so the next dead key must be retired too |
re-prove | done | F1 | tests/test_event_taxonomy.py |
| D07 | semantic-delta | Emergency Stop 2A (§4.3.11): execute_panic_stop takes the actually bound main port as keyword-only bound_port=None and server.py hands down _actual_bound_port(); the lazy import server back-edge is gone, 8765 stays the last-resort fallback, and the cleanup / fail-soft / host-sweep / os._exit order is unchanged. THREE-COLUMN PASS TAKEN by owner batch №5 (5.5-5.8=A, 2026-08-31), so the disposition is no longer pending-decision: it reads re-prove and the row ships. LANDED at F1 by the D09-lane quiet edge (88479fa7) onto tip bytes with a two-way byte proof, and the F2 cancel/D07 matrices found no interaction with the upstream cancel machinery left to re-derive. Upstream (8d13373b, managed/ouroboros) still carries the lazy import, so this is a retained v7 delta, not superseded. The phase cell stays F2 — that is where the matrix retiring the pending-decision ran — even though the code landed in F1. The F0 hook (the cancellation E2E suite) is REPLACED, not extended: it pins nothing about the panic sweep |
re-prove | done | F2 | tests/test_panic_stop_port_sweep.py::test_the_server_passes_its_bound_port_instead_of_the_leaf_reaching_back + tests/test_panic_stop_port_sweep.py::test_no_server_host_leaf_imports_the_composition_root + tests/test_server_control_panic_daemon.py + tests/test_post_task_evolution.py::test_execute_panic_stop_wires_owner_stop |
| D08 | semantic-delta | Cancellation/delegation fail-closed registries (§4.3.13; frozen rows 834-839 cancel_intents.py and 1083-1091 subagent_worktrees.py). THREE-COLUMN PASS TAKEN by owner batch №5 (2026-08-31), verbatim in the requirements archive: 5.6=A — the four fail-open cancel-intent mutators (mark_finalize_control_drained, mark_intent_scope, release_claim, settle_intent) re-derived on the upstream custody floor with a per-caller audit, request_cancel/claim_intent being the only already-strict, superseded sub-row; 5.10=A — the subagent_worktrees strict registry (absent = empty, malformed = typed SubagentWorktreeRegistryCorrupt plus a durable event, bytes kept, registration inside the cleanup scope) applied byte-identical to the reference. The disposition therefore moves off pending-decision to re-prove and the row ships. LANDED by 1b4a8da9 (registry) and 4fffefb1 (mutators); upstream 8d13373b is still fail-open at all thirteen sites, so this stays a live v7 return. The F0 cross-reference "same three-column pass as D07" is dropped: both rows now carry their own resolution |
re-prove | done | F2 | tests/test_cancel_intent_corruption_s6.py + tests/test_subagent_worktree_registry_s6.py + tests/test_cancel_protocol_inventory_s6.py |
| D09 | semantic-delta | LLM one-physical-attempt-per-candidate ownership (§4.3.2) — mandatory return (plan §2). LANDED, both halves re-derived on tip bytes: the _chat_local for attempt in range(3) loop is deleted (86244943), so one physical attempt per call surfaces a transient failure to the single retry policy that owns the decision, and the typed-policy-refusal subfamily (PROVIDER_POLICY_REFUSAL / ProviderPolicyRefusal, the structural classify_llm_exception branch, goldens 15->17) landed with the F3.1 typed organ (b94a6d1d). ADDRESS CORRECTED: the F0 row's "llm.py:2487" is the pre-split base address — the lane lives in ouroboros/llm_local.py on this tree. Upstream still carries for attempt in range(3) (8d13373b ouroboros/llm.py:2476), so the pins re-verify the return on every rolling sync. DISCLOSED RESIDUAL: the Ф4 "D09-invariant" E2E scenario the F0 hook promised was never built — PARTIAL BY OWNER DECISION (batch №11, 5=A, 2026-09-02): the S24 LLM-routing scenario is POST-RELEASE backlog; the row reads done for the two landed halves and their unit pins only — the system_e2e S1-S23 set has no LLM-routing row — and the invariant is carried by the unit, golden and CPL-6 conformance pins instead. Building an S24 belongs to the scenario lane, not to this bookkeeping wave; recorded here so the promise is not silently dropped |
re-prove | done | F1 | tests/test_context_overflow_hint.py::test_local_transport_makes_exactly_one_physical_attempt + tests/test_llm_typed_policy_refusal.py + tests/test_llm_provider_golden.py + tests/test_multiprovider_conformance.py::test_typed_policy_refusal_is_permanent_one_send_only + tests/test_llm_extraction.py |
| D11 | semantic-delta | FUNCTION_DEBT same-qualname relocation rule (§1.9/№8) — a ledger rule carried into the v7next ledger discipline unchanged. LANDED by the F1 D11 lane (d1c8fca4): the relocated_functions block replayed byte-identical from the oracle into the tip-shaped validate_manifest_transition in ouroboros/review.py, with the MODULE_DEBT_1500 layer deliberately NOT replayed (owner Q11=B) and the pin renamed per row 1033 with oracle bytes. Exercised on real history by the F2 addendum 14567df5 (the _handle_schedule_task debt key moving supervisor/events.py -> supervisor/events_schedule_task.py) and load-bearing for this branch's pairwise base-vs-tip ratchet gate. HOOK REPLACED: the F0 cell named a checker from the frozen reference (scripts/v7_migration.py) that does not exist in this tree, so it could never resolve |
retain | done | F1 | tests/test_repo_health_smoke.py::test_transition_allows_a_same_qualname_relocation_but_not_a_swap + tests/test_smoke.py::test_size_ratchet_transition_against_explicit_base |
| D13 | semantic-delta | supervisor/git_ops pre-init roots follow OUROBOROS_* env (owner-ratified batch №11) | retain | done | F1 | tests/test_git_ops_default_roots.py |
| D18 | semantic-delta | Module-handle reads of rebound supervisor globals in queue/pool leaves (the _queue() / _pool() call-time handle idiom; plan §5.3 keeps it). LANDED in two trains — F1 D08 7d2dca49 (queue_schedules on _queue; worker_promotion, worker_chat_lane, worker_pool_lifecycle on _pool) and F2.2 4fffefb1 (queue_snapshot, queue_timeouts on _queue; worker_health, worker_assignment on _pool); rows 2041-2044 (queue_evolution) were resolved without the reference leaf per owner batch №5 5.8=A (upstream evolution_lifecycle.py). The four F2.2 leaves were proof-green but were NEVER PINNED: the f22 ledger entry claimed their declared sets were in LEAVES and the tree did not bear it out, so none of the three parametrized invariants was running on them. This truth wave adds the four rows with tool-derived exact read sets (147 passed, up from 135). RESIDUAL CLOSED by 091ee3b3, and closed in the direction OPPOSITE to the oracle — stated because the row's own hook would otherwise read as the oracle's. MIGRATION row 1030 asked for «supervisor.state owns the queue snapshot path; the queue reads it through the module at use time»; what landed here is supervisor.queue as the sole authority with no copy left in supervisor/state.py. The defect is the same one either way (two module globals answered one question and agreed only because both inits were handed the same drive root); the harness consequence is mirrored: the oracle noted that an isolation harness must then call state.init because queue.init alone would no longer redirect the snapshot, and on this tree it is queue.init that redirects and state.init alone that does not — production is invariant in both directions (server startup and the worker boot bind both). The oracle's hook name never came across either (test_the_queue_snapshot_path_has_one_owner in the heartbeat suite); the pin is the one this row names. Choosing the direction was the operator's call, not an owner decision, so it is disclosed here and in the ledger for the owner to overturn |
re-prove | done | F1 | tests/test_module_handle_extraction.py (the eight queue/pool LEAVES rows through the three parametrized invariants) + tests/test_worker_process_extraction.py + tests/test_events_extraction.py::test_f22_queue_and_worker_leaves_keep_the_hot_label + tests/test_module_handle_extraction.py::test_queue_snapshot_path_has_a_single_authority (MIGRATION row 1030: supervisor.queue is the only QUEUE_SNAPSHOT_PATH authority) |
| D31 | semantic-delta | Contributor-review trust boundary: the lane always executes the review machinery of the target base via a detached trusted-base worktree (owner 2026-08-19 «всегда на старой версии», re-confirmed by batch №5 5.1=A) — mandatory return (plan §2). LANDED by the F2.3b lane 3b62c1d6 with the marker teeth of db944347, preserved through the F6 sync: _run_on_trusted_base in scripts/run_external_review.py re-executes the contributor review from a detached worktree of the target base with pinned base/head SHAs, wired ahead of any preflight in main(); the substrate path list is demoted to review_substrate_changed evidence, the contributor result is decided by the exit code alone, and a base without the wrapper fails closed rather than silently reviewing in place. Upstream still carries the classifier gate instead, so this is a genuine delta, not superseded |
re-prove | done | F2 | tests/test_external_review_script.py (D31 pins: always-runs-on-the-trusted-base incl. the no-list-membership case, the e2e real-wrapper handoff, the wrapperless fail-closed refusal, exit-code-only result, receipt-drift fail-closed) |
| D33 | semantic-delta | L-B loop module-handle delta (_loop() call-time handle for the nine loop leaves; plan §5.3 keeps it). LANDED by the F1 D01 lane pick f0d8b147: nine _loop() leaves cut from tip bytes with 150 spans proof-green (ast = tokens = bytes), zero live v7 deltas, the full loop.py re-export surface kept (the reference's L3 trimming is a F5 consumer-rebind concern and was not carried) and HOT_CODE_PATHS closed over the nine leaves; declared sets re-derived after the F6 sync, where the owner acked that the FINALIZE_NOW drain calls owner_stop directly and the loop re-export stays |
re-prove | done | F1 | tests/test_module_handle_extraction.py (the nine _loop LEAVES rows through the three parametrized invariants) + tests/test_loop_owner_facades.py (facade identity and HOT_CODE_PATHS parity over the nine leaves) |
| D34 | semantic-delta | Carrier-aware update engine: shared span-substitution resolver plus a span-descriptor SSOT in release_sync.py, applied at the three managed-update insertion points — mandatory return over the #276-based upstream engine (plan §2, §5.4). LANDED by the F2.4 update-engine train 7f0a1124 under owner answers 5.12-5.14=A: the span SSOT re-cut atop the tip release_sync.py to 25 descriptors over nine carrier paths (the eight reference spans incl. uv.lock and the README download refs, plus the install-page anchors derived from the release-asset templates); supervisor/update_carriers.py returned whole with bounded git; the three insertion points re-derived against the rewritten tip bodies in the re-split supervisor/update_merge_plan.py with zero resolver calls left in the parent; update_merge_policy reads CARRIER_SPAN_PATHS at call time; release-invariant, domain-manifest and popen-allowlist parity closed. DISCLOSED RESIDUALS: the engine governs steady state only, so the first pre-v7 upgrade still runs the OLD updater, and the boot-recovery M0 backfill does not re-run span resolution and degrades to assisted |
re-prove | done | F2 | tests/test_update_carriers.py + tests/test_carrier_rebase_helper.py + tests/test_update_merge_owner_facade.py + tests/test_update_merge_assisted.py::test_materialize_projects_version_to_target_and_pins_m0 |
| D35 | semantic-delta | G1 git_ops module-handle delta (_go(); init rebinds REPO_DIR/DRIVE_ROOT/BRANCH_*) |
re-prove | done | F1 | tests/test_module_handle_extraction.py + tests/test_git_ops_owner_facades.py |
| D36 | semantic-delta | DEL1 delegate-family module-handle delta (delegate_custody / tools/delegate / delegate_integration / subagent_integration leaves). LANDED by 782b5fe3 (F2.1: delegate_custody_reconcile on _custody, delegate_payload_patch on _di, subagent_integration_delegated on _si) and 1b4a8da9 (F2 finisher: tools/delegate_terminal_evidence on _delegate, renamed from the ledger's delegate_terminal per owner 5.9=A); all nineteen D36 rows read onto the tree with tip-derived declared sets rather than reference-verbatim ones, row 3467 is superseded-by-upstream, the facades keep every historical name, and both 1600-cap giants left the cap. Re-proven green on post-F6-sync bytes |
re-prove | done | F2 | tests/test_module_handle_extraction.py (the four delegate-family LEAVES rows through the three parametrized invariants) + tests/test_delegate_owner_facades.py (facade identity and hot-code parity) |
| D37 | semantic-delta | L-C review-stack module-handle delta (_rev() / _car() over tools/review.py and tools/claude_advisory_review.py). LANDED by the F2.3a lane 04b1de9c (_rev() in tools/review_multi_model.py) and the F2.3b lane 3b62c1d6 (_car() in tools/preflight_review_prompt.py and tools/preflight_review_run.py), re-proved on tip bytes: the reference leaf names review_advisory_prompt/run were byte-falsified by the drift probe (the SDK transport had been retired) and were re-minted under the organ's public rename; declared sets are tool-exact read sets, supersets of the reference's, and the facades keep their EOF re-exports so the parent-namespace patch points survive. RESIDUAL BY DISPOSITION: _parse_model_response superseded by tools/review_response.py, the three deterministic preflights live with the upstream commit_admission.py (owner Q3=A), the review-model timeout constants and four SDK-era advisory names retired, and SLOT_ID_PREFIX plus seven prompt-vocabulary names stay import-bound behind a default-arg / f-string gate |
re-prove | done | F2 | tests/test_module_handle_extraction.py (the review_multi_model, preflight_review_prompt and preflight_review_run LEAVES rows through the three parametrized invariants) + tests/test_review_owner_facades.py (REVIEW_LEAF_OWNERS identity plus the superseded-row pins for _parse_model_response and the deterministic preflights) |
| D38 | semantic-delta | L-C2 module-handle delta: agent-dispatch and usage legacy-import leaves. LANDED from tip bytes — usage_legacy_import.py on _usage() by the D16 pilot 1a17218d (the _cached name is upstream cache drift re-seated at the F6 sync), agent_dispatch.py on _agent() by the D01 lane f0d8b147 with a maximal declared set over the tip patch surfaces, plus the same-family post_task_synthesis.py on _atp() beyond the reference's handle-less leaf. Parents keep full facade re-exports. Upstream still carries the unsplit monoliths, so nothing here is superseded. DISCLOSED RESIDUAL: the usage declared set and the post_task_synthesis handle diverge from the frozen reference table — tip truth, recorded in the ledger — and a future F5 consumer-rebind wave may trim the facade re-exports without touching this mechanism |
re-prove | done | F1 | tests/test_module_handle_extraction.py (the usage_legacy_import, agent_dispatch and post_task_synthesis LEAVES rows through the three parametrized invariants) + tests/test_lc2_owner_facades.py + tests/test_generated_inventories.py::test_facade_inventory_is_byte_identical |
| R-WINWAVE | class-return | Windows/cross-OS fix wave: re-apply by CLASS with a one-decision-per-class registry (both sides fixed the same territory independently — dedup, plan §2, risk §11). The registry now EXISTS as docs/archive/v7next/WINWAVE_CLASS_REGISTRY.md: sixteen reference-wave classes plus the one the matrix itself found, each with one recorded decision — 7 re-applied by the F1/F2/F3 lanes in reference form (fchmod guard plus the paid-lane non-POSIX refusal, the 0600 skipif, canonical-path compares, os.sep and !r-mirror expectations, the per-scenario registry route pin, the planted-stamp clock tick, the utf-8 ARCHITECTURE fixture), 3 superseded-by-upstream with one decision each (O_BINARY answered by write_bytes_atomic, reaper normpath/getuid, child-env SystemRoot forwarding), 6 not-applicable because the carriers the reference patched are absent here. DONE by the re-prove itself, after five red matrices — the history is kept because it is what the classes were decided against. The first 3-OS matrix ever dispatched on this branch (run 33555971481 on 9a28e58f) was green on ubuntu and macos and RED on windows — two source-text regex pins in the upstream-born web/tests/chat_plain_system_rows.test.js cannot match a CRLF checkout. That is a SEVENTEENTH cross-OS class neither the reference wave nor upstream had decided, not a regression of anything re-applied here; the registry now carries it as a decided row (normalize CRLF at the two source reads, landed by a0b35fcd on the campaign integration line — not on this worktree). The second matrix run 33563498919 on 196438c9 does carry that fix; it has since been read — it cleared class 17 and surfaced nine further Windows platform classes, fixed in 20afdbb7..e0aee1ac — so it is no longer the row's blocker. The re-prove is run 33569841899 on 8b27b507 (full 3-OS green on the first attempt) and it held on 33570328266, 33571681398 and 33572515529, each green on its first attempt. On the later branch tips two of the greens were RERUNS and the registry now says so: 33579445704 (1072a317) and 33624546416 (ac17fa03) each had full-test (windows-latest) fail on attempt 1 and go green on the rerun — ac17fa03's cause was rooted by the code fix 43dcc1d2 (the coarse-clock horizon pin), while 1072a317's two Windows failures (the observability GC copy-back and a preflight xdist worker timeout) have no landed fix and stay an intermittent, unrooted class: that is the O3 question put to the owner, disclosed rather than decided here. First-attempt greens on the later tips are 33626834806 (43dcc1d2, all three full-test legs green on attempt 1; only its separate system-e2e-mock job was rerun) and 33644668074 on the sync #3 merge f4abe0a5, green on every job on attempt 1 — verdict read 2026-09-02 15:00Z, so the newest tip is no longer a freshness gap. Read since as well: run 33574822693 (d21806d8) was not pending but RED — full-test (windows-latest) failed and the run was never rerun, so it is not a re-prove; the two tips after it (1072a317, ac17fa03) went green on the Windows leg only on rerun, and the first later first-attempt-green Windows leg is 43dcc1d2 (33626834806). Second item, still open on this tree: the accepted 2026-08-30 audit item to re-pin the registry route test on the actual alias condition instead of os.name — tests/test_registry_core.py:813 still reads os.name here, and the repin is being landed by the stage-2 smalls lane of this same fix wave, not by this row. PHASE F1->F6: plan §10 places the full 3-OS matrix in the F6 gate, and this row is not in the validator's REQUIRED_PHASE, so no pinning changes with it |
re-prove | done | F6 | docs/archive/v7next/WINWAVE_CLASS_REGISTRY.md (the per-class decisions and the 3-OS run log) + the per-class Linux pins tests/test_atomic_write_v639.py + tests/test_launcher_server_reaper.py + tests/test_registry_core.py + tests/fixtures_e2e_cancellation.py + tests/test_e2e_cancellation_scenarios.py + tests/test_core_native_results.py + tests/test_owner_stop_fences_s6.py + tests/test_update_carriers.py + tests/test_evolution_state_integrity_v3.py + first-attempt-green 3-OS runs 33569841899 (8b27b507), 33570328266, 33571681398, 33572515529, 33626834806 (43dcc1d2, the three full-test legs) and 33644668074 (f4abe0a5, every job), all logged with their attempt counts in the registry run table |
| ABI-1 | plan-item | PluginAPI 2.0 via the convergent design (§6-1 + §6.1-Δ, owner «A» 30.08) — LANDED by the F3.1-B lane: PLUGIN_API_VERSION="2.0" with full manifest negotiation (major strict/minor minimum, closed-set capabilities, typed educational refusals, checked BEFORE plugin import/OOP catalog), absent field ≡ LEGACY "1.3" by construction, admission predicate at NEW-PASS issuance common to review/attest/native-seed (native_seed closed; $0 refusal before panel dispatch), hash-bound-PASS grandfather + clobber-guard, preflight fail-open fixed (fail-closed, no persist on infra failure), frozen RuntimeInfo TypedDict, per-version surface fingerprints fail-closed both directions, FORBIDDEN_EXTENSION_SETTINGS alias collapsed, legacy PluginAPIImpl kwargs removed, iframe_raw desync healed (VALID_EXTENSION_PERMISSIONS re-derived from skill_manifest — single carrier), negotiated generation in registration bundle + dispatch-surface stamps, bundled skills (telegram, unix_computer_use) declare the field with version bumps, grants resync on native re-seed with unchanged requested sets per owner «A», and the 6.2=A declarative dependency fingerprint (.ouroboros_env outside the hash, declared names inside; deps_declaration_desync typed refusal) | retain | done | F3 | tests/test_extension_plugin_api_matrix.py + tests/test_plugin_api_admission.py (packaged-artifact admission) |
| ABI-2 | plan-item | task-result _schema_version=1 per Q8=B safe-B: no legacy converter, quarantine on unstamped/future/malformed/retired-until_deadline rows with log-only visibility (owner 6.3=B: one batched durable event, no UI counter, no chat notice); state.json/queue_snapshot get a stamp on write, shape unchanged. Ф3.1 fix-round closed the reader gaps: POST /api/tasks probes identity with the STRICT loader (an inadmissible stored row keeps its id occupied — 409 — and is never quarantined by the probe) and the unfiltered GET /api/tasks slice is admission-aware with one batched quarantine event per scan; fix-round-2 closed the last silent drop — a candidate whose bytes fail to parse reaches the SAME admission reader (quarantine + the one batched event) even beyond the slice window, with the parseable-inadmissible-beyond-window residual disclosed in the payload docstring. ONE CARVE-OUT (owner 4A, E9 lane): the quarantine stranded the very rows the cancellation redesign exists to rescue — a pre-redesign result still LATCHED at cancel_requested is unstamped by definition, so the first ordinary read quarantined it, migrate_legacy_cancel_latches no longer found it, and custody's own fail-soft read then settled not_found — the wedged task disappeared without ever reaching a terminal. The boot latch migration now opens with a pre-pass that re-writes exactly those rows through the ordinary writer (same status, same fields, the stamp-on-write require_writable_task_result_schema already admits as lawful for a live pre-upgrade task — a wedged one has no worker left to perform it); the row is then an ordinary latch that the existing intent→custody path drives to the cancelled terminal. Not a converter and deliberately not a general one: no other refusal reason, no other status, and every other unstamped row still quarantines on the next read; applying the carve-out is ONE typed durable task_result_cancel_latch_admitted event per boot (6.3=B log-only, never one per file) |
retain | done | F3 | tests/test_task_result_schema_quarantine.py — F12 semantics: future-refusal, malformed, idempotency, N−1, rollback + tests/test_cancel_intents_phase_a.py::test_boot_migration_admits_the_unstamped_latch_and_quarantines_the_rest + ::test_the_admitted_latch_reaches_the_cancelled_terminal + tests/test_e2e_cancellation_scenarios.py::test_e9_boot_migration_adopts_a_legacy_cancel_requested_latch (mock lane) + tests/test_headless_task_api.py::test_task_api_identity_collision_check_is_strict_not_fail_soft + tests/test_tasks_list_slice.py::test_unfiltered_list_slice_is_admission_aware_with_one_batched_event + ::test_malformed_result_file_is_quarantined_not_silently_dropped + ::test_malformed_candidate_beyond_the_slice_window_is_still_quarantined |
| ABI-3 | plan-item | Gateway ABI — LANDED by the F3.1 lane D3 train: the five compat aliases removed (cost_usd/cost_usd_with_children stripped at the cost SSOT seams with stored read-tolerance kept; telegram_chat_id gone from the four outbound frames and the history mapper; project_last_viewed/hidden gone from UiPreferencesResponse + endpoint, unknown-key 400) + the contracts/api_v1 shim removed (ABI-6д routed here); executable ABI = gateway/schema.py JSON Schema DERIVED from the contracts TypedDicts, validated on INGRESS only (WS chat/command + typed HTTP request bodies; replay never validated); GATEWAY_ABI_VERSION="7.0" is the carrier decoupled from the product version (the stale alias JSDoc lines were cleaned in the F3.3 comma-sweep tact: the browser mirror is exact again and the parity test's field loop runs with NO excuse set — DocumentOutbound and UiPreferencesResponse joined the exact loop in the F3 adversarial fix-round with negative pins on the removed telegram_chat_id/project_last_viewed/project_hidden fields). Ф3.1 fix-round cut the remaining supervisor/task-result producers over to the honest cost names (task_admission, events_schedule_task, workers, events_task_done, queue/cancel_publication/task_lifecycle fallbacks, reconstruct_task_cost, post_task_checkpoint, post_task_synthesis evidence rows); fix-round-2 landed the projection-boundary semantics: the ABI carries NO alias — public_task_result/task detail/list row/history frames/cancel path emit honest names only, stored legacy resolves deprecated-wins and NORMALIZES at projection and at re-write (write_task_result strips aliases from the merged existing row; TASK_COST_META_FIELDS is honest-only with carry_cost_meta at every possibly-legacy copy seam), and the public-projection planes (subagent envelope, loop-outcome usage snapshot) are cut over and banned from the sweep allowlist; fix-round-3 landed the DEPTH: one shared normalizer (normalize_task_result_cost_planes) serves projection AND rewrite so the nested public planes (subagent envelope + envelope.usage — the actually supported producer path — and loop_outcome.usage) leave honest-only, build_subagent_envelope normalizes the stored usage snapshot before embedding, the evolution campaign history producer stamps the honest name with a /api/state projection-boundary conversion for stored legacy rows, the sweep allowlist is count-anchored per site (a new emission inside an allowlisted function fails), and the Logs UI reads the honest backfill name via the shared JS pair resolver. RESIDUAL BY DESIGN: internal evidence planes (review receipts, ledger rows, checkpoint/observability records) keep their own cost_usd spelling per the anchored per-site allowlist — their durable-log replays convert at the /api/logs projection boundary | retain | done | F3 | tests/test_gateway_abi3_removals.py incl. TestAliasProducerFanOutSweep (whole-runtime-tree emission sweep: write_task_result kwargs unallowlisted, dict-key/subscript/ANY-call-kwarg allowlist = PER-SITE (file, alias, scope) internal non-gateway planes only, staleness fails, public-projection planes banned) + TestProjectionBoundaryNormalization (stored legacy row → outbound honest-only, deep-scanned; rewrite normalization) + tests/test_gateway_ingress_schema.py + tests/test_contracts.py + F11 inventory docs/v7next/ABI3_GATEWAY_ALIAS_INVENTORY.md |
| ABI-4 | plan-item | ResolvedModelTarget frozen dataclass (D02-owner). LANDED by the F3.2 lane A sweep (base 3ba9f452), truth-scoped by the F3 adversarial fix-round: dataclass in model_slots.py, constructor provider_models.resolve_model_target at the existing seams; consumers typed — the cross-model fallback ladder (fallback_candidate_targets → tuple of targets, loop chain iterates .model_id; provider_route stays the "" sentinel because the chain's local-vs-remote dispatch lane is the loop's single global USE_LOCAL_FALLBACK flag, the pre-existing contract kept byte-identical), the reviewer SLOT builders (resolved_review_model_target read per slot in reviewer_slot_config; get_review_targets/get_scope_review_targets are typed views WITHOUT production consumers yet, disclosed in their docstrings) — PARTIAL BY OWNER DECISION (batch №11, 4=A, 2026-09-02): the views stay, the reviewer-surface migration onto them is POST-RELEASE backlog; the row reads done for the landed dataclass and constructor only, and the delegated lane (DelegationRoute.resolved_target() in ouroboros/subagents.py:183, read once by ouroboros/tools/delegate.py:245 into the run-request assembly; the relocation to a provider_models.delegated_route_target(route) free function that an earlier draft of this row named was NOT what landed — no such symbol exists on this tree). NAMED RESIDUAL (migration NOT performed, review surfaces untouched): plan_review_runtime, review_multi_model and the reviewer parallel vectors (models/routes/efforts in reviewer_slot_config/commit review) keep their string ABI. Strings also survive at transport wire boundaries (chat-API model param, Claudexor JSON body) — residual disclosed in the F3.2 lane A ledger section |
retain | done | F3 | tests/test_resolved_model_target.py |
| ABI-5 | plan-item | Q10 removals (all owner «A») — LANDED by the F3.0 opening train: SCOPE_REVIEW_FLOOR removed on all surfaces (key retired via RETIRED_SETTING_KEYS, endpoint/contract/web client/shell+browser guards/SAFETY clause/tests; family read-carve survives), dead fail_tasks removed (pause = the only semantics; E8 superseded by E13 already in F2.2), until_deadline/stall_rounds aliases removed incl. bench adapters | retain | done | F3 | tests/test_abi5_q10_removals.py (per-surface removal pins) + tests/fixtures_e2e_cancellation.py (E13 supersession row) |
| ABI-6 | plan-item | P1 hygiene, per-item disposition, all seven items now closed on tip. LANDED by the F3.0 F9 train (03a835b9, e94f063d, cf320c78): the _call_llm_with_retry alias removed, the compute_cost_with_children plus format_handoff_message dead rollup removed, and the latent CHECKLISTS doc-vs-code fix applied (the env_allowlist row falsely listed TELEGRAM_BOT_TOKEN in FORBIDDEN_SKILL_SETTINGS; the quoted line number had drifted). CLOSED SINCE: the _typed_or_adapted branch executed inside the F3.1 lane A re-derivation (ccbb933a — the branch was not reproduced and has zero tip hits) and the contracts/api_v1 shim executed in lane D3 with negative pins (33ba6e83). SUPERSEDED-BY-UPSTREAM: the «failure-detector compat wrapper» and the «3 underscore renames» are not re-locatable on tip — the primary P1 inventory carries no addresses and a tip re-location sweep found no match, evidence in LEDGER_CORRECTIONS (F3.0 lane section); no replacements are to be invented. The _updater_imports change stays REJECTED — the baseline pin is intentional. DISCLOSED RESIDUAL: the three F3.0 removals are proven by surviving positive suites plus grep-level absence, not by dedicated negative-pin tests. HOOK REPLACED: the F0 cell was prose plus grep verbs and could never resolve |
retain | done | F3 | tests/test_contracts.py::test_api_v1_shim_removed_and_gateway_declares_core_ws_message_types + tests/test_gateway_abi3_removals.py (TestApiV1ShimRemoval negative pins) + tests/test_tool_classification_differential.py + tests/test_tool_result.py (the loop holds no classifier of its own) + tests/test_run_llm_loop.py + tests/test_budget_limits.py (only the public call_llm_with_retry is a patch point) + tests/test_cost_projection.py + tests/test_task_status_flow.py (the surviving rollup readers) + tests/test_skill_exec.py + tests/test_extension_plugin_api.py (the FORBIDDEN_SKILL_SETTINGS consumers behind the CHECKLISTS fix) + docs/archive/v7next/LEDGER_CORRECTIONS.md (the F3.0 lane section carrying the re-location sweep for the two superseded items) |
| ABI-7 | plan-item | RC auditor/migrator — both halves LANDED: 7b RC auditor (F13, F3.3 serial tail) — scripts/rc_audit.py, a READ-ONLY pre-upgrade scan of a third-party install emitting the machine-readable scope document (abi 7.0, sources tree/inventories_frozen_at, checks[] of the five frozen classes: gateway-alias × ABI-3 F11 inventory, retired-setting × RETIRED_SETTING_KEYS, comma-list × RETIRED_COMMA_LIST_SETTING_KEYS snapped from settings_defaults at execution time, plugin-api × ABI-1 admission facts, schema-stamp × ABI-2 with the Q8=B quarantine consequence named) + typed JSON report + human render, exit 0/1/2 (F3 adversarial fix-round hardening: unreadable/unparseable mandatory sources are BLOCKING unauditable-source findings on exit 1, traversal/report-write OSError and an unsafe PYTHONPYCACHEPREFIX are exit 2, the grandfather note is hash-VERIFIED against the current payload bytes under the directory-basename state key, discovery reuses the runtime skill walk, sources.tree carries -dirty), everything non-machine-checkable printed as the OWNER ATTESTATION list (no pretend-coverage), N−1 fixtures = REAL previous-minor bytes in tests/fixtures/nminus1/ (settings + task result written by the v6.113.4 code itself, telegram manifest @ f0313064); 7a N−1 updater transition entry point/shim with crash-point tests (F14, Q10=A — landed: tx stamp, unstamped-N−1 accepted, future fail-closed) |
retain | done | F3 | tests/test_update_tx_nminus1_shim.py (F14, landed) + tests/test_rc_audit_fixture_suite.py (the RC audit fixture suite — F13/F14, landed) |
| ABI-8 | plan-item | Handler-ABI finale: tool handlers return ToolResult, not str (the true D02 finale). POST-RELEASE BACKLOG, not the v7.0 campaign: Q5=A kept it OUT of the ABI bundle; Q16=A retires the «7.1» label into post-release backlog, not into v7.0. DEFERRED OUT OF 7.0 BY THE OWNER: batch №7 item 6 (2026-09-01, requirements archive [A-BATCH-7-ANSWERS]), owner verbatim «6. ок» on «ABI-8 подтверждён в пост-релизный бэклог»; the no-«7.1» frame is Q16=A with the owner's поправка «никакого «7.1» как части кампании» ([A-V7NEXT-BATCH-2], 2026-08-30) | post-release | deferred | POST | tests/test_core_native_results.py + tests/test_control_native_results.py extended to handler signatures |
| ABI-9 | plan-item | Atomic publication of extension registrations — LANDED by the F3.1-B lane: stage→validate→swap of the registration snapshot for BOTH the in-process register() window and the child-catalog install (not _lock around inserts); deferred side effects (supervised runners, companion spawns) start only at publication, which structurally fixes the supervised-future leak (direct regression test proven red on 29e2b045 pre-fix); internal disposers list stays out of the ABI; per-publication extension-generation digest stamped into tool/route/ws surfaces + extension_generation_digest reader for physical-call provenance (dispatch-side read = Ф3.2 seam — LANDED by the F3.2 lane B: _dispatch_extension_tool_result stamps extension_generation — the descriptor's per-publication surface stamp, registry reader fallback — into the typed result meta of every physical dispatch attempt, so the tools.jsonl tool_result_meta record names the exact published generation the call ran against; a provenance READ only — no validation/gating, and the pre-dispatch typed refusals EXTENSION_UNAVAILABLE/SAFETY_VIOLATION keep their exact pre-seam shape). Ф3.1 fix-round hardened publication under ONE registry-lock hold with STAGED event subscriptions; fix-round-2 fixed the ordering to validate→SWAP→attach (the definitive validation runs first, the snapshot swap publishes the bundle, and only then do the deferred side effects attach — a handler is visible to the bus only for an already-published extension, closing the mid-publication EventBus race; a post-swap attach failure is disclosed and disposed through the standard unload path); fix-round-3 closed the OOP/unload tails as the disclosed STAGED PROTOCOL (not a false "one atomic publication" absolute): the OOP load stages catalog surfaces AND companion spawns on one snapshot and publishes them in a single transaction, the one structurally later publication (server-side companion recovery onto a live bundle) re-stamps every already-published descriptor with the freshly minted digest and routes ANY failure through dispose+unload (never a silent abort leaving a half-alive extension), and unload closes visibility outside-in (bus unsubscribe + runtime-API close BEFORE surfaces leave), with the EventBus copy-semantics residual disclosed in its docstring — the supported pin is "a publish started after unsubscribe never delivers"; fix-round-4 closed the recovery lifecycle TOCTOU: the companion-recovery publication is GENERATION-BOUND — ensure_companions_running snapshots the observed bundle generation with the companion names, publishes under the lifecycle lock, and _publish_registrations(require_live_generation=…) re-validates under the registry lock that the observed publication is still live (a vanished or reloaded bundle is a typed ExtensionStaleRecoveryError refusal with zero effects; the recovery form of the OOP publication helper structurally REQUIRES a pre-existing live bundle and can no longer resurrect a companion-only bundle after disable/unload — the test that pinned bundle-creation-on-recovery is replaced with the opposite pin, disclosed), and the recovery failure-disposal is generation-bound too (unload_extension(expected_generation=…) no-ops with disclosure on a newer publication); fix-round-5 made the stale refusal's zero effects true on the FILESYSTEM as well: the companion auth token (auth_token.json) is no longer minted/rotated during descriptor build — it materializes into the staged companion descriptors only in the post-swap attach, after the generation fence admitted the publication — so a recovery that lost the race to an unload/reload can no longer overwrite the live publication's token and permanently de-authorize its running companions (their spawn env holds the token while the Host Service rereads the file on every request); fix-round-6 extended the post-fence materialization to the WHOLE companion env: descriptor build no longer reads settings (_scrub_env→load_settings takes the settings lock and may persist a settings migration) and the recovery entry resolves the state dir without a creating mkdir — the settings-derived values, the manifest env overlay, the host bridge URL, the state dir and the token all materialize only in the post-swap attach, so a stale refusal has zero effects on the authorization/token/registry/bundle/companion-env planes; RESIDUAL BY DESIGN: an accepted post-fence mint can rotate the shared token while an older companion keeps its stale spawn-env copy — every rotation precondition (missing/corrupt/hash-stale token file) means that companion's token already failed the Host Service's per-request file+content-hash check, so rotation restores authorization for the publication's spawns and never revokes a valid one; the un-restarted old companion stays de-authorized until reload; fix-round-7 (final, converged) scoped the pre-fence contract honestly instead of rewriting the runtime-wide settings/grant read layer: on the way to the fence the liveness/grant projection may take infrastructure reads (the settings lock inside load_settings via requested_core_setting_keys, a state-dir mkdir via the health/grant projection) exactly as anywhere else in the runtime — the zero-effects guarantee covers authorization/token/registries/bundles/companion-env, never "every filesystem plane"; and made the token mint transient-safe: a hash/read failure with a parseable stored token reuses it byte-for-byte unrotated (the running companion stays authorized), and with no reusable token it fails closed with the typed SkillTokenHashUnavailableError instead of minting against an empty hash — which is what makes the round-6 "never revokes a valid one" claim true; RESIDUAL DISCLOSED (pre-existing, not introduced by this cycle): concurrent mints (publication attach / get_skill_token / process-runner child env) are read-decide-write over auth_token.json without a shared lock, so the last writer can supersede a token just returned to another caller |
retain | done | F3 | tests/test_extension_registration_atomicity.py (incl. test_conflict_refused_publication_has_zero_external_effects + test_event_published_before_publication_never_invokes_the_handler + test_concurrent_publish_in_the_validate_to_attach_window_never_invokes_the_handler (real barrier-sequenced race) + test_supervised_effect_starts_only_after_the_swap + test_post_swap_attach_failure_disposes_through_the_standard_unload_path + test_out_of_process_surfaces_and_companions_publish_as_one_transaction + test_companion_recovery_failure_unloads_instead_of_silent_abort + test_late_publication_restamps_already_published_descriptors + test_unload_closes_bus_and_runtime_visibility_before_surfaces_leave + test_publish_started_after_unload_never_delivers) + tests/test_extension_companion.py fix-round-4 pins (test_unload_completing_between_snapshot_and_publication_refuses_recovery + test_recovery_publication_refuses_on_generation_mismatch_without_effects + test_generation_bound_disposal_skips_a_newer_publication + test_recovery_publication_requires_a_pre_existing_live_bundle) + fix-round-5 pin (test_stale_recovery_does_not_break_live_publication_authorization, red pre-fix) + fix-round-6 pin (test_stale_recovery_with_env_from_settings_has_zero_filesystem_effects; hardened in round-7: both load_settings seams tripwired in the post-snapshot window, size+mtime tree snapshot, settings-lock absence, settings-derived/manifest-overlay/PYTHONPATH delivery asserts) + fix-round-7 pins (test_transient_hash_error_never_rotates_a_valid_token, red pre-fix + test_transient_hash_error_without_reusable_token_fails_closed) + tests/test_extension_loader_extraction.py + F3.2 dispatch-read pins (test_dispatch_provenance_carries_the_published_generation_digest, red pre-fix + test_dispatch_provenance_falls_back_to_the_registry_reader, red pre-fix + test_unavailable_refusal_keeps_the_pre_seam_typed_shape) |
| ABI-10 | plan-item | Reviewer comma-lists → actor rows: the model is already upstream (#384); residual migration read REMOVED by the F3.1 lane D4 train (owner 5.4=A) — legacy block deleted, shipped default panel over the derived env plane (identical models on every config class), comma keys + phase-5 route envs retired via RETIRED_SETTING_KEYS, derived projection kept, bench templates migrated to structured slots with the same models | superseded-by-upstream | done | F3 | tests/test_comma_list_remnant_sweep.py (F3.3 count-anchored remnant sweep — the phase CI gate) + tests/test_comma_list_sweep.py (F3.1 migration-read sweep) + tests/test_reviewer_slot_config.py |
| CPL-1 | plan-item | Production manifest ouroboros/domains.toml (module→domain 1:1 over all 508 tracked runtime modules; completeness = red on drift) + domain gate: strict direction matrix pinned as FACTUAL baseline data (164 pairs; new direction = red), cycle gate against the pinned SCC ceiling (owner №8=A, 2026-09-01: the current all-20-domain strict-quotient SCC ceiling is ACCEPTED for v7.0 — the gate binds shrink-only, target cycle_groups = []; a true cycles=0 untangling is a post-release campaign), lazy/dynamic import classification pinned (92 lazy-only pairs); the 80 [classification].proposed new-upstream module placements are no longer open — owner batch №9 №10=A (2026-09-01) accepted them as the 7.0 base, the review marker retired and DOMAIN_MAP.md regenerated with zero starred rows, cross-domain literal-copy ban (baseline EMPTY — every new copied body is red); DOMAIN_MAP.md generated from the manifest (gen/verify pair). Report-only Ф0 stage superseded: the manifest moved from scripts/v7next_domains.toml, the report stays the witness-level companion on the shared scripts/domain_graph.py core |
retain | done | F5 | scripts/check_domains.py (gate + --write regenerator) + tests/test_domain_manifest.py (verify half incl. synthetic red-branch pins) + docs/DOMAIN_MAP.md |
| CPL-2 | plan-item | gen/verify pairs shipped for all three inventories: frozen-contracts table (ARCHITECTURE §11.1 machine extraction, owner/anchor path resolution, contracts-package coverage gap pinned), data-layout tree (ARCHITECTURE §1 Data-layout tree — the factual carrier here; the reference PERSISTENCE_OWNERS.md doc does not exist in this tree — probed entry-by-entry against tracked paths and runtime-source literals), facade inventory (AST noqa:F401 re-export scan over the manifest population); staleness = red CI | retain | done | F5 | scripts/regenerate_inventories.py (--check) + tests/test_generated_inventories.py + docs/v7next/FROZEN_CONTRACTS_INVENTORY.md + docs/v7next/DATA_LAYOUT_INVENTORY.md + docs/v7next/FACADE_INVENTORY.md |
| CPL-3 | plan-item | code_intelligence architecture facts: owner_of(path|symbol), domain_dependencies(d), facade_consumers(sym), persistence_entities_written_by(sym), protected_contracts_affected(diff); consumer №1 = Ouroboros self-evolution (Q12=B: completeness ships whole in v7.0). LANDED by the F5 lane C: five pure queries over the pinned carriers (domain manifest, facade/persistence/frozen-contract inventories, runtime_mode_policy protected sets) in ouroboros/code_intelligence_architecture.py — a D05 leaf beside code_intelligence; model seam = the EXISTING query_code tool, new op=architecture (no new registry tool — lane decision, ledger F5 lane C section) |
retain | done | F5 | tests/test_architecture_facts.py (real-example pins + carrier completeness both ways + the query_code op seam) |
| CPL-4 | plan-item | Persistence: schema_version/migration/retention/reset decision per durable entity, local (no generic framework); close §16 findings (undocumented planes, unbounded ledgers, mismatched temp — the §16 source is unrecoverable; inventory rebuilt by factual writer scan, disclosed in the F5 lane B ledger section with the candidate-fix table). Inventory + verify hook DONE; the mechanical train (owner plan №9=A) landed CPL4-C1..C5, C7, C8, C10, C12..C15, C17, C18, C20, C23, and owner batch №8 (2026-09-01, all A) ratified + landed C9 (2A retire reader), C11 (3A tombstone), C16 (4A digest-only), C21 (6A agent media GC), C22 (7A retire knob), recorded C19 (5A task_results eternal for 7.0). CPL4-C6 (1A) — monetary usage-ledger compaction — LANDED by its own reviewed lane (rounds 2–5.4 plus the operator close-out of the 5.4 lens findings, owner batch №12 A) and INTEGRATED here by the lane merge (tip 8fb08d44): seq-preserving compaction under a two-tier kernel/name lock with per-caller ENOLCK refusal for money only, dir-fd anchored archive reader, quarantined-not-receipted swap-window loss; disclosed residuals in docs/archive/v7next/C6_REVIEW_PACKET.md §5/§10. The mechanical train landed; the corrective lane over audits #14/#15 landed the defects it left (append short-write, unreadable-chain typing, byte-exact atomic text, journal-compaction digest/lock/streaming guards, agent-media symlink containment, the durable reconcile failure fact, the bounded cross-skill history read, identity-based rotation detection, the missing ARCHITECTURE leaf rows). This row is done only when C6 is integrated and its verification hook is green — status must not run ahead of the work |
retain | done | F5 | docs/PERSISTENCE.md + tests/test_persistence_inventory.py (AST writer scan, count-anchored both ways) + the persistence-train and corrective-lane ledger sections + tests/test_usage_compaction.py (C6 pass side: exact-money/projection equality, crash injection, in-flight survival, idempotency, trigger policy, swap-window and lock-tier pins) + tests/test_usage_compaction_archive.py (C6 reader side: the CPL-5 join across chained compactions and the baseline-block structural validation) + tests/fixtures_usage_compaction.py (the fixtures both hold) + tests/test_lockfile_helpers.py (lock tiers, ownership, ENOLCK per-caller policy) |
| CPL-5 | plan-item | Runtime invariant model-visible⟺logged, narrowed per F15: sealed model_send records at the last host-controlled pre-transport seam, typed exclusions (provider-native queries/transforms/secrets), reverse-⟺ for model_send only; canonicalization design note BEFORE code (batch-1 Q8=A confirmed). LANDED by the F5 lane D: model_send_seal block in the existing physical-candidate manifest (reuses canonical_json_v1 digests + persist_physical_candidate — no parallel serializer), at-call reconstruction of the durable record with a byte compare at llm_attempt._candidate_before_dispatch (mismatch = typed durable model_send_invariant_violation fact beside the seal + events.jsonl — an observability invariant, never a second dispatch gate), the CLOSED four-class exclusion enum with per-instance disclosure, per-rung seals on the retry ladder, delegated lanes disclosed model_send_seal: unobserved, and the bounded fail-soft reverse reconciliation sweep riding the startup-sweep family (orphan_seal / unlogged_attempt facts, never repairs) |
retain | done | F5 | tests/test_model_send_seal.py (seal round-trip, damaged-record typed facts, closed-enum coverage, cost-shape pin, reverse sweep both ways) + docs/v7next/DESIGN_MODEL_VISIBLE_LOGGED.md |
| CPL-6 | plan-item | Conformance contracts for multi-provider seams: LLM providers and the executor axis native|harness — one normative shared suite every new provider must pass. LANDED by the F5 lane C: the provider half parametrizes over the FACTUAL registry (provider_models.PROVIDER_PREFIXES + the local lane; a registered provider without a conformance driver = red) and pins route form, (message, usage) shape, honest-only cost planes, typed 400-refusal permanence (one physical send), 429-body typed marker, finish_reason:null surfacing, timeout propagation and the one-settled-ledger-row-per-send accounting on every lane over the golden recording fakes (reuse, no network); the executor half parametrizes over subagents.SUBAGENT_EXECUTORS (a new axis point without an outcome row = red) and pins the closed rule-table matrix across route states, typed refusals at both seams, launch/artifact semantics per point (native never contacts the daemon; harness leaves run identity + the durable last-delegation projection) |
retain | done | F5 | tests/test_multiprovider_conformance.py (registry-derived shared suite) |
| CPL-7 | plan-item | Skill manifest "Model Experience" section (prose: what the model sees / token effect) + teaching errors on registration refusal | retain | done | F5 | tests/test_skill_model_experience.py (schema + model-visible surfaces + teaching fix_hint refusals; bundled manifests carry the section) |
| TRAIN-F6-8d13373b | plan-item | Post-cutoff upstream adoption train: the F6 rolling-upstream sync — 121 upstream commits b9f7597f..8d13373b merged whole as absorb merge 20850191 (literal second parent 8d13373b), which reached the mainline first-parent line as the second-parent side of lane-integration merge 0aa74e9f (over campaign commit 816e7b82) — both SHAs are named because the absorb merge is the one that took upstream and the integration merge is the one on the line — under «upstream = semantic truth, campaign = structural truth»; every upstream semantic delta re-seated in its campaign owner leaf, the upstream twin extractions (acceptance_dialogue.py, delivery_protocol.py, supervisor/chat_delivery_events.py) folded into their campaign owners (loop_acceptance/loop_acceptance_review, loop_delivery, events_chat_delivery). PROVENANCE, corrected 2026-09-01: the F0 cell read «(owner signal, 2026-09-01)», which claimed the «иди забирай» signal the Q1 adoption contract names. That signal was NOT given for this train. It was adopted on the operator's inference from the owner's «И надо как-то ускоряться … а то уроборос двигается вперёд быстрее чем ты работаешь» (10:10Z), and the owner sanctioned taking upstream POST HOC, after the merge, with «уроборос далеко уехал в ветке ouroboros … можешь ребейзнуться, забрать оттуда вещи новые» (19:12Z). The sanction is real and the train stands; the order is what the row now states honestly |
retain | done | F6 | docs/archive/v7next/LEDGER_CORRECTIONS.md («From the F6 rolling-upstream sync» section) + absorb merge 20850191 + integration merge 0aa74e9f + the full non-serial + serial batteries on the merged tree |
| TRAIN-F6b-f3fbfdbb | plan-item | Post-cutoff upstream adoption train, sync #2 (owner signal, 2026-09-01): 101 upstream commits 8d13373b..f3fbfdbb (180 files, 20 new) merged whole as merge b9ceed6e under the same «upstream = semantic truth, campaign = structural truth» rule — every upstream semantic delta re-seated in its campaign owner leaf (registry post-exec organ, #447 H1 note ordering, В23=A owner-home read carve, #468 shape-first reasoning pin, delivery-control provenance, D4 export policy, A5 literal-argv disclosure), and the upstream twins of campaign organs folded into their owners (tools/read_inspection.py -> registry_guard_process, tools/result_envelope.py -> tools/tool_result, tools/output_export_policy.py -> shell_outputs; delivery_protocol.py stays folded in loop_delivery) |
retain | done | F6 | docs/archive/v7next/LEDGER_CORRECTIONS.md («From the F6 rolling-upstream sync #2» section) + merge b9ceed6e + the full non-serial, serial, size_ratchet and E2E mock batteries on the merged tree |
| TRAIN-F6c-a76961de | plan-item | Post-cutoff upstream adoption train, sync #3 (owner signal 2026-09-02 ~12:50Z, requirements archive [A-BATCH-12-C6-SYNC], verbatim «+не забудь подтянуть все свежие изменения, там многое изменилось вреоятно уже в ветке ouroboros. Или это и так в плане в конце?» — the owner named the gap and the plan gained the step): 40 upstream commits f3fbfdbb..a76961de (upstream release 6.114.0, the live chat card, the Agents panel, the SYSTEM.md rewrite, governance schemas) merged whole as merge f4abe0a5 (parents 43dcc1d2, a76961de) under the same «upstream = semantic truth, campaign = structural truth» rule. Automerge took 18 of the 25 files both sides touched; the seven textual conflicts and the six semantic ones the automerge hid were resolved BY CLASS, and the classes are written out in the merge commit message (git show --stat f4abe0a5) rather than restated here: generated carriers taken from upstream and regenerated on the merged tree (size_ratchet_manifest — the upstream band rationale for tests/test_ui_smoke_project_continuity.py carried verbatim — domains, FROZEN_CONTRACTS_INVENTORY); protected prose taking upstream's compressed shape with the v7next deltas re-seated (prompts/SAFETY.md drops the retired OUROBOROS_SCOPE_REVIEW_FLOOR control per ABI-5 / owner Q10=A and regenerates the protected-path mirror from the merged runtime_mode_policy; the upstream-rewritten prompts/SYSTEM.md gains the v7next safety-critical set); upstream's Windows/CRLF/argv test fixes winning over the campaign's interim shims; and upstream's new governance and terminal-receipt tests adapted to the v7 contracts they actually meet on this tree (module-level registry_guard_process._run_shell_safety_check, the typed ToolResult code SKILL_STATE_WRITE_BLOCKED, the shell_outputs home of _sensitive_output_component_reason, the ABI-2 task-result stamp with its Q8=B quarantine), with the git catalog schema pin moved onto the bytes of upstream's advisory_review→preflight_review rename (332a02f1; the catalog itself unchanged) |
retain | done | F6 | tests/test_packaging_sync.py (the SAFETY/SYSTEM mirrors) + tests/test_golden_capabilities.py + tests/test_capability_effect_predicates.py + tests/test_terminal_delegation_receipt.py + tests/test_git_extraction.py + docs/archive/v7next/LEDGER_CORRECTIONS.md («From the stage-2 fix wave, lane ledger-validator» section) + merge f4abe0a5 |
| DEFER-BROWSER | plan-item | Gateway/UI-truth E2E actor — the real-browser client over an isolated server's own web UI. DEFERRED OUT OF 7.0 BY THE OWNER: batch №9 №14 (2026-09-01, requirements archive [A-BATCH-9-ANSWERS]), owner verbatim «14. A» on the option recorded as «браузерная волна пост-релиз, смоук зелёным до тега» — the browser wave is post-release and the condition on the tag is a green smoke, not a green browser lane. tests/system_e2e/interfaces.py therefore keeps PlaywrightUIClient as an interface stub that REFUSES instantiation (NotImplementedError naming the gateway/UI-truth lane) instead of a fake that would read as coverage, and the refusal is itself pinned so the stub cannot rot into a silent no-op. residual: no system-level E2E scenario drives the real web UI in 7.0 — every UI claim of the campaign rests on the marker-gated Playwright smoke and on the owner's own manual pass, not on this actor |
post-release | deferred | POST | tests/system_e2e/test_system_scenarios.py::test_interface_stubs_refuse_instantiation_until_their_lanes_land + tests/system_e2e/interfaces.py |
| W4-F1 | plan-item | Crash window between the reviewed git commit and its receipt: a crash between git commit and record_evolution_commit left a landed reviewed commit that NO boot path attributed — the markerless reconcile short-circuits on an empty commit_sha and _preserve_evolution_orphan runs on the authority-refusal path only. FIXED in 7.0 by owner batch №13 item 9 = B: the reviewed commit is now two-phase — the pre_commit_authority boundary records a commit_intent (the reviewed tree and parents of the post-review binding) BEFORE git commit runs, and boot reconciliation adopts the commit at HEAD only when its tree AND full parent list match that intent, writing the commit_receipt the crash never wrote; the task-done path adopts the same intent so a crashed cycle is classed commit-bearing instead of no_op. Attribution is structural, so a failed commit, a contained orphan or any later HEAD movement stays unattributed |
re-prove | done | F6 | tests/test_evolution_restart_claims.py::test_boot_attributes_the_commit_a_crash_left_without_a_receipt, tests/test_evolution_restart_claims.py::test_boot_refuses_to_attribute_a_head_that_is_not_the_reviewed_material; docs/archive/v7next/LEDGER_CORRECTIONS.md («From the W4 crash-window lane (owner 9 = B)») |
| W4-F2 | plan-item | Absorb outcome ledger atomicity: the campaign absorb write and the cycle_outcome checkpoint append are not one transaction — the reconcile writes the campaign under update_json_locked and appends the row AFTER the lock (same shape on the claim path), so a crash in between left a campaign that says absorbed with no row and build_solve_capability_digest under-reported that cycle forever. FIXED in 7.0 by owner batch №13 item 9 = B: the row is DERIVABLE from the resolved transaction, so boot re-derives every missing commit-bearing outcome row (source: boot_backfill, idempotent — a task that already has a cycle_outcome row is skipped), and the swallow-wrapper both append sites share now lives with the ledger it writes |
re-prove | done | F6 | tests/test_evolution_restart_claims.py::test_boot_backfills_the_cycle_outcome_row_a_crash_lost; ouroboros/evolution_checkpoints.py backfill_missing_cycle_outcomes; docs/archive/v7next/LEDGER_CORRECTIONS.md («From the W4 crash-window lane (owner 9 = B)») |
| DEFER-HEADLESS-CANCEL | plan-item | Panel stop receipts for headless (API/CLI-origin) tasks: a task not born in a chat gets no cancel_receipt block in the details panel after cancellation (W2-F1 of the F4 wave-2 system-E2E lane). DEFERRED OUT OF 7.0 BY THE OWNER: batch №7 item 5 (2026-09-01, requirements archive [A-BATCH-7-ANSWERS]), owner verbatim «5. A» on the option recorded as «панельные стоп-квитанции headless-задач — пост-релиз». residual: a ouroboros run/HTTP-API caller sees no stop receipt (who cancelled, what finished, what was spent) in 7.0; chat-origin tasks keep theirs |
post-release | deferred | POST | docs/archive/v7next/LEDGER_CORRECTIONS.md (F4 wave-2 table, row W2-F1; «Owner closures for the F6-sync forks») |
| DEFER-FROZEN-2 | plan-item | Two modules of the frozen-contracts package (ouroboros/contracts/task_constraint.py, ouroboros/contracts/skill_payload_policy.py) are not listed in the §11.1 frozen table and carry no anchor test. DEFERRED OUT OF 7.0 BY THE OWNER: batch №9 re-ask (2026-09-01), owner verbatim «согласен со всеми рекомендациями твоими» on recommendation №12=A «not now; disclose the gap until post-release». residual: both contracts can change without breaking the frozen table or a mandatory anchor test in 7.0; the package set is pinned by tests/test_generated_inventories.py (a third module is red CI) |
post-release | deferred | POST | docs/v7next/FROZEN_CONTRACTS_INVENTORY.md («Package coverage») + docs/archive/v7next/LEDGER_CORRECTIONS.md (CPL-2 item 6) |
| DEFER-C6-RESIDUALS | plan-item | Disclosed residuals of the CPL4-C6 monetary-ledger compaction (docs/archive/v7next/C6_REVIEW_PACKET.md §5, §10): on a filesystem the kernel says cannot lock (name tier) the pass never compacts and the ledger grows to the 20 MB tripwire; on a lockd-less NFS state/ every monetary write refuses typed (ENOLCK, money only — other locks keep the name protocol); on Windows a charge landed inside the swap's one rename syscall is lost silently (POSIX quarantines it) and the directory chain is fsync'd only as a path-based best effort; the Windows LOCK TIER is no longer a residual — owner batch №13 item 1 = B (2026-09-02) made it a release condition and it is re-enabled IN 7.0 (platform_layer._WIN32_LOCK_OFFSET: one byte beyond any owner stamp, the capability probe running there like POSIX, the compaction pass landing there), with its Windows-EXECUTED proof pending the next CI matrix and its weaker-than-POSIX eviction guarantee disclosed in DESIGN §8; subscription/external/legacy/review rows never fold; orphan archive segments are never GC'd; the two usage suites sat at the 1600-line cap until owner batch №13 item 11 = A split them. DEFERRED OUT OF 7.0 BY THE OWNER: batch №12 (2026-09-02 ~12:50Z, [A-BATCH-12-C6-SYNC]), owner verbatim «A» on «микро-раунд 5.4 … LOW-остаток интегрируется с раскрытием, HIGH-остаток → назад к владельцу» (no HIGH remained). residual: as listed, minus the test-suite cap — C6-TESTCAP is CLOSED by owner batch №13 item 11 (2026-09-02, [A-BATCH-13-ANSWERS]), owner verbatim «11. A» on «тест компакции разрезать по естественной границе; platform_layer pay-down ≤1500 post-release + issue»: the split landed as tests/test_usage_compaction.py (900 lines) + tests/test_usage_compaction_archive.py (660 lines); what stays open post-release is the ouroboros/platform_layer.py pay-down (1587 → ≤1500 lines, a BAND_BASELINE_PATHS entry of ouroboros/size_ratchet_manifest.py) and its issue |
post-release | deferred | POST | docs/archive/v7next/C6_REVIEW_PACKET.md §5 + §10; docs/v7next/DESIGN_USAGE_COMPACTION.md §8/§10/§12 |
| DEFER-C19-RETENTION | plan-item | task_results/<id>.json are kept forever — no retention is introduced in 7.0 (CPL-4 item C19). DEFERRED BY THE OWNER: batch №8 item 5 (2026-09-01, [A-BATCH-8-ANSWERS]), owner verbatim «5. A» on «task_results eternal for 7.0». residual: data/task_results/ grows monotonically for the life of an install; only a full data reset clears it |
post-release | deferred | POST | docs/PERSISTENCE.md (task_results row) + ADOPTION row CPL-4 (C19 record) |
| W4-F3 | plan-item | Evolution restart marker vs manual restarts: request_evolution_restart returned BEFORE writing pending_restart_verify.json when OUROBOROS_EVOLUTION_AUTO_RESTART was off, so the exact-claim verify path (require_claim=True) was structurally unreachable for installs that restart by hand and absorb attribution rested on the weaker markerless reconcile. Found by the F4 wave-4 system-E2E lane (docs/archive/v7next/LEDGER_CORRECTIONS.md «E2E-находки w4»). FIXED in 7.0 BY OWNER DECISION — the v7 follow-up F3 owner batch (2026-09-04), item 5 «W4-F3 fix now (always write the marker)», owner verbatim «5. A»: the knob now skips ONLY the restart itself; the exact claim marker is written whenever the reviewed commit's authority still holds, so the owner's manual restart verifies the cycle by exact claim; the two marker writers (the supervisor path and the agent's restart tool) share one helper and one schema (write_pending_restart_marker). S22 keeps its contract — markerless boot reconcile absorbs exactly once after a crash between the campaign's waiting_for_restart write and the marker write — by shaping that durable state (open transaction, commit on HEAD, no marker) after the kill: the two writes are separate atomic files, so removing the marker is byte-identical to a crash between them; the scenario now also pins that the marker IS written with auto-restart off and that the tree does not restart |
re-prove | done | F6 | tests/test_evolution_terminal_events.py::test_auto_restart_off_still_writes_the_exact_restart_marker, tests/test_evolution_terminal_events.py::test_both_restart_marker_writers_share_one_schema, tests/system_e2e/test_system_scenarios_w4.py::test_s22_absorb_kill_recovery_absorbs_once_and_never_twice; docs/archive/v7next/LEDGER_CORRECTIONS.md («From the W4-F3 lane (owner 5 = A)») |
| W4-F4 | plan-item | Rescue-local ref accumulation: create_rescue_local_ref pins every update stash to a durable rescue-local-<stash12> branch and nothing ever deletes them — a refused/unwound attempt leaves its ref exactly like a successful one. Deliberate durability («git-gc can never lose the owner's work»); the unbounded per-distinct-stash growth is the disclosed cost. Same wave-4 lane. OWNER-deferred on 2026-09-04 — owner verbatim «5. A» (the operator's question: fix the restart marker now and keep this row deferred with a quote plus a backlog item for deleting the rescue-local refs of cancelled updates); backlog: delete the rescue-local-<stash12> refs of a refused/unwound update once its attempt has no owner work left to lose. residual: the branch list grows with every distinct update stash in 7.0 |
post-release | deferred | POST | docs/archive/v7next/LEDGER_CORRECTIONS.md (w4 findings table, row W4-F4) |
| DEFER-E2E-DELEG-MUT | plan-item | System-E2E scenarios for MUTATING delegated runs (snapshot + patch pull-in + isolation proof) were carried across the F4 waves and never landed: S1-S23 contained only non-mutating delegation runs. LANDED as the wave-5 pair (owner batch №13 item 15=B, 2026-09-02: fix now): S24 drives an EXTERNAL-WORKSPACE task through delegate_start(access=workspace_write) → private Git snapshot → the fake harness editing THAT snapshot → delegate_wait capture → integrate_delegated_patch(apply), pinning the durable custody chain, the capture artifacts, the containment facts read back from the run's own attempt record, the isolation proof (the live workspace still lacks the run's file at the step after the wait returned) and the released snapshot; S25 drives the conflicting variant — the live tree drifts on a patched path, the apply is refused typed (baseline_drift), nothing is disposed, the task's own terminal reads failed / delegated_custody_unreconciled, and snapshot + patch survive as resolution material. The fake daemon gained the mutating half it lacked (workspace edits + attempts/a01/attempt.yaml applied facts) | retain | done | F4 | tests/system_e2e/test_system_scenarios_w5.py::test_s24_mutating_delegated_run_is_isolated_until_an_explicit_clean_apply + tests/system_e2e/test_system_scenarios_w5.py::test_s25_mutating_delegated_patch_conflict_is_refused_and_keeps_its_material + tests/system_e2e/test_system_scenarios_w5.py::test_fake_daemon_mutating_run_edits_only_the_execution_workspace |
| DEFER-E2E-PAID-LANE | plan-item | The paid («live») system-E2E lane — E1 (delegated launch → wait → answer → cancel), E2/E3 (clean and conflicting delegated patch pull-in) and E13 (a task with an exhausted budget PAUSES before dispatch, replacing the withdrawn E8) — is written (tests/test_e2e_cancellation_scenarios.py, fixtures_e2e_cancellation.py LANE_PAID) and needs a model with a known price, which the mock lane has not; plan §8/§10 made an owner-live quittance on the exact SHA an acceptance criterion. EXECUTED BY OWNER DECISION: batch №13 item 2 (2026-09-02, [A-BATCH-13-ANSWERS]), owner verbatim «2. A». Runs 2026-09-02/03 on ad39ec54, 6bd799fb, ca1b38df, 9c04ff47 (operator receipts in LEDGER «From the paid E-lane»): E13 GREEN on openrouter::anthropic/claude-haiku-4.5 (a priced route; anthropic:: has no tariff, so the drain never fires there — by design, cost unknown is never enforced); E1 GREEN once its fault assertion read OPEN faults (the faults log carries resolution rows); E2/E3 reach the real Claudexor lane and are refused by it: claude is unavailable: Claude subscription route is not ready — delegate_start asks for the subscription substrate by design and the owned daemon of an isolated install has no login; an interactive login is the owner's act, which the operator may not perform — the E2/E3 remainder is a STRUCTURAL block, not an owner-decided deferral, and no quote waiving the §8/§10 criterion exists. residual: E2/E3 (clean and conflicting delegated patch pull-in) unexecuted until an install with a logged-in Claude account runs the lane |
post-release | deferred | POST | tests/test_e2e_cancellation_scenarios.py (module docstring) + tests/fixtures_e2e_cancellation.py (LANE_PAID) |
| DEFER-TYPED-PROC-5 | plan-item | Owner batch №7 item 1=A retired the regex fallback that guessed process exit codes from prose; five surfaces were then left WITHOUT typed exit/signal facts: extension child-process death, skill_exec/skill_preflight, verify_and_record (printed exit=, stamped nothing), run_command timeouts and pre-exec failures, Windows kills. LANDED by owner batch №13 item 10 = B (typed process-facts lane): the thread-local channel is now PUBLISHER-scoped instead of tool-name-scoped (the _PROCESS_META_TOOLS table is retired; the loop clears the slot before EVERY dispatch, which is a stronger no-contamination contract than the name gate it replaces), and the family grows three members that exist exactly where an exit code does not — timed_out, killed_by_host, pre_exec_failure (the platform's exception class). Producers stamp at the point the truth is known: the extension child in _run_child (clean exit, abnormal exit with its POSIX signal, deadline kill, output-cap kill), _run_skill_subprocess (including the negative code its returncode or 0 return flattens, and the spawn OSError), the skill_preflight validators — whose synthesized -9/-1 are RETIRED for returncode=None plus the typed reason, since the fakes read downstream as real POSIX signal deaths (on Windows too, where a host kill produces none) — and the verify_and_record check, whose receipt now copies the SAME publication instead of deriving duration/signal a second time. Consumers: one projection feeds the UI live-log card, the tools.jsonl row and the durable trace. Windows kills are carried honestly rather than faked: killed_by_host beside whatever TerminateProcess left in exit_code, and never a fabricated signal name — Windows-executed proof pending the matrix |
retain | done | F6 | tests/test_process_signal_observability.py::test_extension_child_death_publishes_typed_exit_and_signal + tests/test_process_signal_observability.py::test_skill_exec_signal_death_survives_the_or_zero_flattening + tests/test_process_signal_observability.py::test_skill_preflight_timeout_reports_no_returncode_instead_of_fake_minus_nine + tests/test_process_signal_observability.py::test_verify_check_publishes_typed_exit_and_signal + tests/test_process_signal_observability.py::test_run_shell_timeout_publishes_typed_timeout_facts + tests/test_process_signal_observability.py::test_windows_host_kill_carries_no_forged_signal + tests/test_process_signal_observability.py::test_tools_jsonl_row_carries_the_typed_process_facts |
| DEFER-SPEC64-PATHS | plan-item | Spec §6.4 «Paths/roots» (OUROBOROS_V7_SPEC_v72.md ~:815-820) — one HostPaths/TaskPaths authority, removal of the two SimpleNamespace Env clones in agent_task_pipeline.py (:241, :681) and of the silent Path.home()/Ouroboros/data fallbacks in seven domain modules — was never delivered on the oracle or here and never entered any inventory or decision; the bytes are inherited from upstream (no regression). DEFERRED OUT OF 7.0 BY THE OWNER: batch №13 item 8 (2026-09-02, [A-BATCH-13-ANSWERS]), owner verbatim «8. A» on «post-release строка — подтвердить». residual: with an incomplete OUROBOROS_* env set a process can still resolve two different data roots without an error |
post-release | deferred | POST | OUROBOROS_V7_SPEC_v72.md §6.4 (the requirement); this row (the only tracking) |
| DEFER-F23-ACCEPTANCE | plan-item | Roast recommendation F23 — a machine-readable acceptance.json with schema and checker (exact SHA, run/artifact ids, scenario consumption, D02-D38 dispositions with decision ids, review quorum, cost cap) — was accepted into the plan (V7NEXT_PLAN.md :261) and never built; the release bar (scripts/v7next_adoption.py --release), scripts/rc_audit.py and the exact-SHA evidence manifests cover part of it (rows/hooks/gates), not quorum, cost or scenario consumption. Recorded so the gap is visible (owner question in the STOP batch: build before the tag / post-release / close as covered-by-gates). residual: campaign acceptance is proven by the evidence manifests and the validator, not by one generated capsule CLOSED AS COVERED-BY-GATES BY THE OWNER: batch №13 item 7 (2026-09-02, requirements archive [A-BATCH-13-ANSWERS]), owner verbatim «7. A» on «закрыть F23 как «покрыт гейтами» с записью пробелов». What covers it: the exact-SHA evidence manifests (every gate its own rc, HEAD after each gate, live-data inventory), scripts/v7next_adoption.py --release (rows/hooks/authority) with its pytest wrapper, scripts/rc_audit.py. residual: no single generated capsule; review quorum, spend and scenario consumption are proven by the ledger sections and the operator's manifests, not by one machine-readable file |
retain | done | F6 | scripts/v7next_adoption.py + tests/test_v7next_adoption.py (the release bar) |
Notes:
- §7-8 (atomic extension-registration publication) is deliberately absent from the CPL family: roast F8 moved it into Ф3 — it is row ABI-9.
- No row carries
pending-decisionany more. The four that did — D04, D05, D07, D08 — each got their plan §5.4 three-column resolution from an owner batch: D07 and D08 by batch №5 (5.5-5.8=A, 5.10=A, 2026-08-31), D04 by batch №9 №1=B and D05 by batch №9 №2=B (2026-09-01). All four have since landed — D04 at5b1767faand D05 at0bf723cc— and all four rows readdone; the sentence that called the D04/D05 lanes owed and their rowspendingoutlived the lanes. The enum value stays in the schema for the next genuine fork. - W4-F3 and W4-F4 ARE rows (since
d348ea46, 2026-09-02): the two wave-4 observations the F4 lane disclosed instead of fixing — named asymmetries of existing decisions (the restart-marker knob predates the claim machinery; rescue-local refs are deliberately durable). Batch №13 item 13(и) asked to ratify them and the owner answered that he had not read that item; the F3 owner batch (2026-09-04) re-asked, and its item 5 = A pulled W4-F3 into 7.0 — that row readsdone(marker always written, one writer helper, S22 kept) and leftDEFERRED_OUT_OF_V70. The same answer kept W4-F4 deferred: its row carries the owner's quote and a backlog item (delete the rescue-local refs of a refused/unwound update), and the register records it as an owner deferral — the declaration below mirrors that register. The sentence that called them rowless «disclosed observations» outlivedd348ea46by two days past a green bar; the prose-id lint above is its class fix. W4-F1 and W4-F2 are rows because they are crash windows nobody decided to keep — and the owner pulled both into 7.0 (batch №13 item 9 = B), so those two rows readdonewith red-first pins. - Deferral authorities, as
DEFERRED_OUT_OF_V70in scripts/v7next_adoption.py records them (a declaration that disagrees with the register turns the bar red — free prose about authority is not read): ABI-8 owner, DEFER-BROWSER owner, DEFER-HEADLESS-CANCEL owner, DEFER-FROZEN-2 owner, DEFER-C6-RESIDUALS owner, DEFER-C19-RETENTION owner, W4-F4 owner, DEFER-E2E-PAID-LANE owner, DEFER-SPEC64-PATHS owner. - Hook cells are honest about existence. For a
donerow the validator resolves everytests/,scripts/ordocs/token it finds and refuses a missing file, so a shipped row cannot point at a suite nobody wrote. For a row that is not done, an owed suite is described inwhatrather than spelled as a path in the hook cell — naming a non-existent file there would read as a hook and prove nothing. - D04, D05, D06 and D35 landed through their owner-decided lanes (1B/2B/3A/13B)
and read
done; their phase cells still say F1 because re-phasing a required row is an owner decision (the validator'sREQUIRED_PHASEenforces exactly that) and the lanes did not invent one. CPL-4, the last row that still owed work, landed with the C6 usage-ledger compaction lane (merge9faccf31), so no row is open on this base. D03 landed its remainder at F6 (the settings read seam, owner batch №11 2=A); its phase moved F1→F6 with the matchingREQUIRED_PHASEedit in the truth-wave commit, disclosed in the row and in the ledger, and that move is the operator's scheduling correction — not an owner decision — so the owner may still overturn it.