Repository navigation
Conversation
… declares The witness asserted 1 from before the test merge, while #11617 landed serving_group_b_route_turn_ceiling at 4 (matching group A's allocation reasoning, never the arm's --max-num-seqs 16). Pre-existing red on the merge head, measured at 62c7a0e; the row's literal is its point, so the repair is the new literal, stated in the row's comment.
…pleted GLM tool round carries no reasoning and is not a truncated chain harness_thinking_format_cause refused ANY closer-less completion under a requested thinking mode, on the claim that GLM-5.3-Flash reasons unconditionally. Production falsified it (dispatch probe, attempt-state shell-typed-invocation-a19c151825c6f6eff): finish_reason tool_calls, reasoning null, zero reasoning tokens, and the refusal killed a healthy four-round turn. The invariant the check protects -- a truncated chain of thought must not be transcribed as speech -- is a property of the stop reason, so the cause now fires only on a ceiling stop with no thinking block, and the more specific truncated-mid-tool-call arm is judged first.
…sing witness The first live harness experiment's result, harvested from attempt ci-executed-coverage-receipt-closing-contract-ad0bb338a840f2be3: the closing witness (4 clauses over gunbc.merge_admission's check-coverage classifier, each on a planted input) and the authority row re-bound through with_execution + gunbc_claim_execution_contract. Witness green by execution: claim-run over dag/test/claim/closing/ci_executed_coverage_receipt_closing_contract_witness_test.dag, 4/4 PASS.
…node plans, a launch gate Operator ruling 2026-09-19: the first live harness worker spent 23 of 40 tool rounds orienting (how to test, where witnesses live, what a planted input is, what the row edit looks like). Centering is now supplied, never derived per attempt. - gunbc.roadmap.roadmap_centering (new, single authority): dispatch_centering_preamble authored once — it REFERENCES the doctrine (the system-prompt contract, gunbc.compute.test_run's command spellings, DESIGN.md Operational essentials) rather than restating command prose — plus declared_node_centerings, one NodeCentering row per dispatch-ready node carrying the near-complete plan (exact witness path + module name, clause-to-test-fn mapping, exemplar to imitate, the with_execution row edit shape, the acceptance pattern). Rosters the seven experiment nodes and the launch canary's two synthetic nodes (so the admission's admit-path witnesses traverse the gate). - gunbc.roadmap_launch_admission: new pre-session centering gate between the contract and dependencies gates; a node with no roster row refuses with the typed LaunchCenteringAbsent cause (wire: centering_absent). Gate and brief read ONE projection (node_centering), so the plan that admits is the plan the worker receives — the gate is not a presence flag. - roadmap_dispatch_actuator: dispatch_brief_with_centering joins preamble (exactly once, by construction at the two assembly sites) + the node's plan + the filled template, on both the fresh and continuation paths. - roadmap_serve: LaunchCenteringAbsent maps to 409 beside contract-missing. - roadmap_belt_actuate: LaunchCenteringAbsent bands BandFail. - roadmap_launch_deployment_cli: rlm1_contract_digest_frozen re-pinned to 7bcb9aaf9a17d274 (the gate and refusal arm change the frozen contract text by design; recomputed via launch_admission_contract_digest_hex). Witnesses (claim-run, systemd-run MemoryMax=6G, all green): - test.claim.roadmap.roadmap_centering_witness_test (new, 7/7): absence refuses centering_absent; the gate is load-bearing (mutation control); a centered node admits; the admitted plan is the briefed plan; the preamble occurs exactly once; the seven rows resolve and render. - roadmap_launch_admission_witness_test 52/52 (pins moved: 24 refusals, 10 gates, gate order + pre-session strings; capacity fixtures re-keyed to centered ids). - roadmap_serve_witness_test 27/27, component_dispatch_button 6/6 (wire total pin 25 to 26 with the new exemplar), belt_actuate + canary + presentation + dispatch_actuator witnesses green (166 PASS batch).
… centering plans Ten verified shell-in-decision-code sites, one roadmap node each under the shared shell-dag- id prefix (the roadmap model carries no project/component grouping mechanism yet; dependency edges to the completed shell-typed-invocation exemplar are the only parent relationship used). Each node closes on a new witness dag/test/claim/shell/<id>_witness_test.dag asserting no shell control word beside a typed-form positive control, accepted via the named test process pattern //dag/test/claim/shell:all. Staggering constraints (same-file pairs in ci_spec.dag and live_deploy/emit.dag) recorded in the centering plans. Verified in a shadow worktree at HEAD plus these three files (the live tree does not typecheck while agent-15's submission/belt files are mid-flight): roadmap_centering_witness_test (8/8, incl. the new ten-node claim), roadmap_launch_admission_witness_test (15/15), roadmap_serve_witness_test (11/11).
…r just reads it closing_contract_authored was textual: it read the witness source, pinned a digest and checked the named function was declared, and attempt ci-gate-contention-independent-verdict-closing-contract-a54b739dd2acf738f passed it with a witness that could not resolve a single one of the 21 names it imported. The textual checks stay as necessary-but-insufficient conditions; every GunbcClaimValidation the contract names now also executes as a child claim-run adjudicated by exit status: a resolve refusal (the runner's 'error: resolve failed for' stderr prefix) is ClosingContractWitnessResolveRefused, any other nonzero exit is ClosingContractWitnessRefused, and only exit 0 greens. The belt's validation argv now passes --arg runner=<the dispatch host's GunbcClaimRunnerCapability executable>; by hand the runner defaults to the checkout's target/release/gunbc, then PATH, else a typed refusal. Discrimination is behavioral on planted fixtures written into a mktemp source root under target/ at run time (a committed unresolvable witness would fail every whole-root resolve): pass / unresolvable-imports / resolved-but-false, enrolled as a bin_wet row beside the other exit-status witnesses.
…erion 3db98ec moved the attempt-identity mint to the spawner for the worker and auditor but missed harness_reviewer_cli, which kept building it from the absolute verdict path. The fleet ssh context's safe-segment law (gunbc.fleet_known_hosts_anchor fleet_ssh_attempt_identity) refuses any identity that is not a safe path segment, so every reviewer's seat bind refused before any ssh leg: measured 2026-09-20 on srv2, all fourteen reviewer lanes of one belt review pass exited 1 with no verdict written. The mint follows the worker's and auditor's, with the criterion key appended because the lanes of one attempt share the node id and attempt key and each lane's identity must stay distinct. The actor stays seeded on the verdict path (an affinity key, not a path segment), as the auditor fix kept it. Witnesses: the minted identity is path_segment_is_safe-admitted, the review argv and the unit spawn site carry the new argument, and the pre-fix path-bearing identity is refused -- the row that would have caught the bug.
…und verify gate, fanin seam Slice 2 of docs/plans/harness-work-lifecycle.md under the 2026-09-20 substrate ruling (gunbc SCM inside, git at the edge). - gunbc.roadmap.roadmap_submission (new, single authority): the .gunbc-submission.json artifact (ready | blocked | needs-context + explanation + limitations), the capture record (schema v2: git edge head + the AUTHORITATIVE SCM binding — project envelope path + commit ordinal), the capture-freshness judgment (a byte-identical declaration re-swept is a checkpoint, never a re-binding), and the evidence-state fold: Yielded / Submitted / Verified->PublicationOwed / BlockedOnPublication(cause) / Published, derived fresh from receipts only, so restart loses nothing and a disabled helper reads as owed, never discharged. - gunbc.scm.worktree_inventory (new): the worktree bridge the SCM layer declares while workers edit git worktrees — git ls-files -z argv + NUL-row parse; every later capture step is an SCM verb. - roadmap_belt_commit: the decision splits candidate (fresh decodable submission) from checkpoint (absent/undecodable/already-captured) — submission ≠ checkpoint. - roadmap_belt_actuate: candidate capture mints the tree into the project's SCM envelope (stage whole tree -> store_corpus_manifest -> commit_staged -> save_repository; nothing-to-freeze is the typed resume), then the git edge commit, then the v2 capture record; the verify gate admits only a head with a decodable capture (a checkpoint head defers — yielded, not ready; blocked / needs-context declarations bind but do not advance). - gunbc.roadmap.roadmap_fanin (new seam): verified candidates squash-merge into the project's one integration head via gunbc.scm.squash_merge; conflicts are a typed FaninConflicted carrying the complete conflict population, never a git merge failure. Standalone task = project of one (project key = node id). - dashboard: new Submission workflow segment renders the lifecycle states on the attempt row (workflow_stage/progress/presentation). - harness_guidance: grounded premise — writing the submission artifact is how the worker ends the task; ending without it is a yield, preserved as a checkpoint. Witnesses (claim-run under systemd-run MemoryMax=6G, all green): - test.claim.roadmap.roadmap_submission_witness_test (new, 18/18): terminal- without-submission is yielded not ready; pass discharges into PublicationOwed with no discretionary ask; blocked-on-publication names its cause; an observed PR receipt discharges; a bound PR is answered as observed and never re-actuated (uncertain remote success reconciles without a duplicate); a later head inherits no prior evidence; two candidates fan into one integration head carrying both sides; a conflicting pair yields the typed conflict and mints no head; codecs round-trip the SCM binding. - roadmap_belt_commit_witness_test rewritten for the candidate/checkpoint split (7/7); workflow_progress, belt_actuate, presentation, serve, validation_oracle, workflow_command, verification_evidence_addressing, harness_guidance suites green (obligation-roster pins moved 7 -> 8 for the new segment). - belt_actuate witness retains two PRE-EXISTING failures (witness_band_fold_pins_operator_vocabulary, witness_exemplar_roster_reconciles_variant_set): launch-label rosters moved 22 -> 26 by in-flight launch-admission work owned by another lane; pins are theirs to move.
…nded payloads, lane aggregation, stale-revision dimming Owner ruling 2026-09-20: the attempt/activity rendering was overwhelming — a Verification lane rendered a ~98-file "unparseable .dag source(s)" dump inline, a Review lane rendered fourteen "key: reviewer exited 1 without a verdict" clauses, and refusals rendered as raw multi-line error strings. - Refusals render as labels: "Kind · refused — <short reason>" on the summary line; the full (bounded) reason sits behind the existing ›details disclosure, closed by default in both realizations (the client's auto-open-on-refused and its data-auto-opened guard are deleted). - Bounded payloads: workflow_segment_detail_bounded is the one bound consumed by the server ledger, the /workflow.json wire, and the presentation seam's located reason — an enumerated payload renders as count + first 3 entries + a pointer to the attempt receipt artifact; the receipt content is unchanged. - Repeated identical lane failures aggregate: "Review · refused — 14/14 lanes — reviewer exited 1 without a verdict"; mixed messages never aggregate (non-uniformity is information). - Staleness dims: WorkRowView.attempt_stale, decided by stale_attempt_nodes as a pure revision comparison (attempt launch-identity revision vs the deployed-tree head the launch host standing observed at the tick, read in roadmap_served_observation), renders node-attempt-stale + data-attempt-revision="stale" and dims the activity region; an unobservable current revision or an unreadable launch record dims nothing. - Lane states render generically through workflow_segment_state_key, so new states (Yielded, BlockedOnPublication) need no presentation change. NOTE: the workflow_stage bounded-detail authority and the bounded wire detail in roadmap_workflow_progress ride in e9f0683 (swept into that lane's commit from the shared working tree); this commit carries the rest of the pass. Witnesses (claim-run under systemd-run MemoryMax=6G): - test.claim.roadmap_presentation_witness 27/27 (6 new: bounded dump count+excerpt+pointer, passthrough control, uniform-lane aggregation, mixed-lane refusal to aggregate, refused Review lane label+bound, stale-revision comparison both honest arms) - test.claim.long.roadmap_page_witness: all parity, script-census, selection and rendering claims green incl. new refused-arm-behind-disclosure and stale-attempt-dimmed pins; six failures (ready_node_doc_emits_button, upcoming_dispatch_refused, ticket_rows_render_structured, ticket_brief_budget, item_detail_disclosure, authority_leads_within_budget) reproduce identically without this diff (in-flight launch-admission/authority lane owns those pins) - roadmap_serve 27/27, component_dispatch_button 6/6, belt 10/10, dispatch_presentation 6/6, served_observation 14/14, launch_canary 13/13
…r onto the stable shell_typed_invocation witness
…ered fixture ids, fixture-grounded disclosure negatives, lead-budget trims The long page-witness suite carried six reds predating the status-surface presentation pass (baseline-proven identical with and without that work): - witness_ready_node_doc_emits_button_and_external_script and witness_upcoming_node_dispatch_refused_dependencies_blocked read back centering_absent since the centering gate landed (9948b04): their fixture-minted node ids are not in gunbc.roadmap.roadmap_centering declared_node_centerings, and the gate runs before the dependency and capacity gates their subjects are about. The fixtures now carry the launch canary's rostered parent/followup ids, the same pattern as rlm_ready_node in the launch admission witnesses. - witness_ticket_rows_render_structured and witness_item_detail_disclosure_present each pinned a negative over the LIVE authority population (no ticket-updates block; no brief-labelled disclosure) — change detectors that redded the day an authored row legitimately produced the forbidden markup. The decided laws (disclosure_updates_block renders the thread exactly when non-empty; view_detail_block labels a legacy-body row 'brief') are now pinned on constructed fixtures beside the kept live-page positives. - witness_authority_leads_within_budget measured 17 overlong leads: 15 identical superseded-row boilerplate sentences from the CI cost re-cut plus the two judgment supersession rows. A punctuation split at the natural clause boundary brings every lead under 300 chars without dropping a word. Remaining red, routed: witness_ticket_brief_budget_holds_and_reds measures six active rows whose boundary fields exceed the 100-word reading budget (2-scm-native-authority-program 134, floor-ceiling-roster-cut-completeness 123, frontend-eval-training-program 177, fleet-mtcollins1-first-host 153, fleet-slot-retirement-wet-proof 116, cardinality-vertical-slice 119). Those are live program contracts owned by six different lanes; the trim is their call. Also: the workflow strip is eight obligations since Submission landed (seven-obligation wording in roadmap_component notes corrected).
…try-line-builder Plants dag/test/claim/shell/shell_dag_cron_entry_line_builder_witness_test.dag as the pattern-prover for the shell-dag migration batch: four adversarial-field arms (schedule, command, log_path, tag each planting a shell control word) red on today's string concat in gunbc.tools.cron_tag build_cron_entry_line, two green positive controls, and the acceptance conjunction cron_entry_line_builder_acceptance_holds bound in the node's execution contract. The five red identities are enrolled in v2.workflow.floor_expected_red (new meaning-named chunk) so the required floor holds them as known red. Restores the node's real execution contract binding, retiring the temporary machinery-smoke binding onto the shell_typed_invocation witness on exactly the condition it declared, and rewrites the M0 step in roadmap_authority.dag and its centering plan to point the dispatched worker at M1-M3 with the pinned-witness no-edit rule.
…eak-calibration-rows Plants dag/test/claim/shell/shell_dag_floor_peak_calibration_rows_witness_test.dag: two red arms over the pre-calibration surface (the echo reset row's 2>/dev/null swallow), two green positive controls (cgroup memory.peak read, [calibration] labels), and the acceptance conjunction floor_peak_calibration_rows_acceptance_holds bound in the node's execution contract. The three red identities are enrolled in v2.workflow.floor_expected_red; the M0 step and centering plan point the dispatched worker at M1-M3 with the pinned-witness no-edit rule.
…gate-line Plants dag/test/claim/shell/shell_dag_ci_fmt_gate_line_witness_test.dag: one red arm (the hand-spelled "$CARGO_BIN" indirection the typed cargo.Build.Fmt operation has no spelling for), two green positive controls (the workspace fmt check shape, no shell control word), and the acceptance conjunction ci_fmt_gate_line_acceptance_holds bound in the node's execution contract. The two red identities are enrolled in v2.workflow.floor_expected_red; the M0 step and centering plan point the dispatched worker at M1-M3 with the pinned-witness no-edit rule.
…oy-invoke-prelude Plants dag/test/claim/shell/shell_dag_ci_deploy_invoke_prelude_witness_test.dag: two red arms over the rendered invoke (the ROOT prelude's || pwd absorbing fallback and 2>/dev/null swallow), two green positive controls (the toplevel read, the declared stage's entry/function), and the acceptance conjunction ci_deploy_invoke_prelude_acceptance_holds bound in the node's execution contract. The three red identities are enrolled in v2.workflow.floor_expected_red; the M0 step and centering plan point the dispatched worker at M1-M3 with the pinned-witness no-edit rule.
…-regen-invoke Plants dag/test/claim/shell/shell_dag_ci_heal_regen_invoke_witness_test.dag: two red arms over the rendered invoke (the ROOT prelude's || pwd absorbing fallback and 2>/dev/null swallow), two green positive controls (the shared toplevel read, the declared regen+verify two-call composition), and the acceptance conjunction ci_heal_regen_invoke_acceptance_holds bound in the node's execution contract. The three red identities are enrolled in v2.workflow.floor_expected_red; the M0 step and centering plan point the dispatched worker at M1-M3 with the pinned-witness no-edit rule.
…-pool-slice-install Plants dag/test/claim/shell/shell_dag_compile_pool_slice_install_witness_test.dag: two red arms over the rendered install body (the benign body's set -euo pipefail opener, an adversarial slice unit name carrying a command separator), two green positive controls (installs the declared unit, starts never restarts), and the acceptance conjunction compile_pool_slice_install_acceptance_holds bound in the node's execution contract. The three red identities are enrolled in v2.workflow.floor_expected_red; the M0 step and centering plan point the dispatched worker at M1-M3 with the pinned-witness no-edit rule.
…pulation-census-read Plants dag/test/claim/shell/shell_dag_slot_population_census_read_witness_test.dag: one red arm (over a planted unexecutable transport, the census cause must carry the transport's typed refusal — not the bare exit code that is the text-carrier signature of the re-joined shell read), three green positive controls (refusal-shape pairing, planted command failure keeps its exit code, planted success classifies), and the acceptance conjunction slot_population_census_read_acceptance_holds bound in the node's execution contract. The two red identities are enrolled in v2.workflow.floor_expected_red; the M0 step and centering plan point the dispatched worker at M1-M3 with the pinned-witness no-edit rule.
…pp-server-trip-script Plants dag/test/claim/shell/shell_dag_codex_app_server_trip_script_witness_test.dag: three red arms over the rendered trip surface (shell control words, the literal stdio sentinels, an adversarial codex_home), one green positive control (the declared payload and subject), and the acceptance conjunction codex_app_server_trip_script_acceptance_holds bound in the node's execution contract. The four red identities are enrolled in v2.workflow.floor_expected_red; the M0 step and centering plan point the dispatched worker at M1-M3 with the pinned-witness no-edit rule, plus the one sanctioned exception inherited from the exemplar: M2 deletes the surface the witness reads, so its import is re-pointed at the typed realization's rendering of the same trip with fn names and claims unchanged.
…ploy-install-owned Plants dag/test/claim/shell/shell_dag_live_deploy_install_owned_witness_test.dag: one red arm (an install path carrying a command separator, rendered into the privileged install line), two green positive controls (benign surface clean, declared path and principal realized), and the acceptance conjunction live_deploy_install_owned_acceptance_holds bound in the node's execution contract. The two red identities are enrolled in v2.workflow.floor_expected_red; the M0 step and centering plan point the dispatched worker at M1-M3 with the pinned-witness no-edit rule.
…ploy-restart-tailscale Plants dag/test/claim/shell/shell_dag_live_deploy_restart_tailscale_witness_test.dag: one red arm (the tree-sync restart step's diagnosis appended as shell text — a || fallback arm with ; separators), three green positive controls (tailscale step clean, declared unit named, both steps elevate through sudo), and the acceptance conjunction live_deploy_restart_tailscale_acceptance_holds bound in the node's execution contract. The two red identities are enrolled in v2.workflow.floor_expected_red; the M0 step and centering plan point the dispatched worker at M1-M3 with the pinned-witness no-edit rule.
…d progress bars on the daily workspace A project is a rendered row with at least one rendered task, and a row's tasks are its PREREQUISITES — the edge law's direction, never its inverse: edge(child: X, parent: Y) says X depends on Y, so display_children(P) = roadmap_parent_ids(edges, P) restricted to rows the page renders. The arc shell-typed-invocation thereby renders as a project whose ten shell-dag-* nodes are its tasks, and nesting recurses (a task with its own prerequisites is an intermediate project — the shell-residue-zero → shell-gate-migration → shell-effectplan-to-bash chain), with rendered depth capped at 3 behind a collapsed '+N deeper' disclosure that still renders every deeper row inside it. Placement rules, each a pure function of the decided rows and the declared edges, decided in gunbc.roadmap_presentation (the seam) and only painted by gunbc.roadmap_page: - RENDERED-ONLY: a task joins a tree (and a progress denominator) only if its row renders somewhere today; an unplanned prerequisite reports no invisible work. - FAMILY-FIRST: a closing-contract family member never nests and never counts — the family is the presentation authority for generated task rows, and edge-nesting would double-render it. - ACTIVE-SURFACES: a row with live work keeps the attention law and renders flat in the Active band rather than inside a tree; it still counts in its project's denominator and still pulses auto-open. - PRIMARY-PARENT: a task that gates several rendered projects nests under the first in edge declaration order (never duplicated) while counting toward each. roadmap_primary_parent was consulted and does not fit — it selects a node's own first prerequisite, the opposite direction of the display parent needed here. - NOTHING-VANISHES: a row whose display-parent chain reaches no top-level entry (only possible on a cycle, refused upstream) renders as an ordinary top-level row. Progress counts closure, never implementation evidence: closed = accepted or superseded (node_closes_dependency) read off the decided lifecycle, so a merged PR without an accepting signoff (ReviewLifecycle) never counts. The project row is the same row shape as every task (the decided head, activity region, disclosure — no forked renderer), plus 'k of n tasks closed' and a CSS-only bar flex-weighted by the counts (the round strip's proportional-by-construction idiom). The task disclosure's open attribute is derived: a project opens when a descendant has a live attempt or a non-routine event-log standing, and collapses when quiet. Witnesses: eight derivation receipts in test.claim.roadmap_presentation_witness (direction, counting, no-loss/no-duplication, primary-parent, active-surfaces, auto-open, recursion, family-first) and four rendering receipts in test.claim.long.roadmap_page_witness (row shape and bar, derived open attribute, depth-cap affordance, the live shell-arc exemplar at identity grain). The .project-progress / .project-tasks style family is tokened and role-routed; the roadmap_css lift-parity digest is re-derived by execution, never chosen.
…needs-context or yield continuation_decision read only workflow segments, so a worker that ended truthfully blocked (attempt cd172fe81b806160: budget spent with its acceptance run still in flight) routed to Fresh-from-base on re-dispatch, discarding the committed implementation. PriorAttemptFacts now carries the same head-grain SubmissionCaptureObservation the verify gate binds, read by the belt through the same reader, and the decision gains a capture arm ordered before the segment arms: blocked / needs-context / yield continue from the prior branch at the next turn with the worker's explanation (or the yield reason, bounded) leading the brief; a ready capture falls through to the segment arms unchanged; an unestablishable capture refuses. The turn-cap and unreadable-turn refusals are shared by every continuation route through continuation_continue_next_turn. Witnesses: capture arms, red control that a ready candidate never continues, cap/unreadable refusals, and the worktree-add argv carrying the prior branch end-to-end.
… integration-head advancement Owner ruling 2026-09-20: the 10-task batch integrates via native gunbc SCM fanin, not a git-side fold. - gunbc.roadmap.roadmap_project (new): project membership DERIVED from the roadmap authority's dependency edges — a node's project is the arc that depends on it (edge child: arc, parent: task); no dependent arc = project of one keyed by the node id; two arcs over one node is a typed ambiguity, not a default. No parallel roster. - Base seeding: project envelopes key by the ARC id. An envelope with no commits is seeded once from the attempt's RECORDED spawn-origin base sha via the declared git bridge (gunbc.scm.worktree_inventory worktree_base_file_args: git show <base>:<path> per tracked path), committed as the envelope's root. Candidates are minted descending from that shared base (selection moves to the base for the mint and is restored); between belt operations checked_out IS the integration head, so restart recovery is a pure envelope derivation. A candidate identical to the intake base refuses (nothing to deliver). - Integration-head advancement: the publish pass first runs the integration step — capture binds this head, verification passed — then fanin_integrate_candidate (squash_merge: target = integration head, source = candidate). FaninAlreadyIntegrated is its own arm (the consumed-source record makes re-integration a typed no-op; that IS the restart path). FaninConflicted writes a per-candidate integration receipt naming the complete conflict population; the candidate stays verified-but-unintegrated and the others are unaffected. Members of a multi-member project never publish alone: they defer with the k-of-n standing (census derived from the per-attempt receipts); a fully integrated project defers naming the publish-edge change that lands the materialize-to-branch edge next. - Handoff states: IntegrationOutstanding/Complete/BlockedStanding sit between Verified and PublicationOwed (HandoffAwaitingIntegration / HandoffBlockedOnIntegration), rendered on the dashboard's Submission segment from the per-attempt integration receipt. - roadmap_fanin: IntegrationReceipt codec (roadmap-integration-receipt/v1) + IntegrationReceiptObservation for the read path. Witnesses (whole-file claim-run, systemd-run MemoryMax=6G): - roadmap_submission_witness_test 27/27: membership derivation (member / standalone / ambiguous), awaiting-integration and blocked-on-integration states, receipt codec round trip, re-integrating a consumed candidate is a typed no-op minting nothing (the restart-safety control), plus the prior 18. - belt_actuate / belt_commit / workflow_progress / presentation / serve / validation_oracle / workflow_command / verification_evidence_addressing all green (belt_actuate's two launch-label pin FAILs remain another lane's). Publish edge (materialize the integration head to a git branch + one PR per project) follows as a second commit.
…ad to its git branch Slice 2's final mechanism. When every member of a multi-node project is integrated, the belt materializes the project's SCM integration head into a belt-owned integration worktree (<worktree-root>/<project>-integration, created detached at the intake base and reset per publication with checkout -B + clean -fdx, so the tree afterwards holds exactly the integration head's corpus), commits it on the dispatch-<project>-integration branch, and enqueues a project-shaped publication subject (node_id: the arc, attempt_key: integration) into the existing helper spool — one PR per project, answered by the same observe-first helper that discovers an existing PR rather than duplicating it. The project receipt lands beside the envelope at projects/<project>.publication-receipt.json. SCM inside, git only at the edge: the materialization reads the corpus out of the object store through the SCM checkout verbs (commit_at_reference + find_corpus_manifest_record + recover_corpus) and writes plain files; git's whole role is worktree-add / checkout / clean / add / commit. The parent-directory computation for the materialized paths is the one pure decision in the edge and is pinned by the_publish_edge_parent_dir_drops_exactly_the_basename; the rest of the edge is effectful by construction and is exercised by the production fanin, not by hermetic witnesses (route-gap honesty, not a mocked boundary). Members of an incomplete project keep deferring with the k-of-n standing; the project-of-one path is unchanged. Witnesses (whole-file claim-run, systemd-run MemoryMax=6G): belt_actuate suite green including the new dirname control (the two launch-label pin FAILs remain another lane's); submission 27/27; serve green.
…ith red-flagged stages and semantic activity coloring INCREMENT 1 — collapse single-child project chains (operator ruling 2026-09-21). A project with EXACTLY ONE display child that is itself a project collapses: the chain renders as one project row carrying the topmost project's identity and headline, with the chain END's display children as its tasks and its k-of-n counts — so the shell chain shell-residue-zero → shell-gate-migration → shell-effectplan-to-bash → shell-typed-invocation renders as one residue-zero row whose bar counts the arc's ten shell-dag-* tasks, one disclosure down. A project collapses through a child only it OWNS (the child's primary display parent is the collapsing project): fleet-closed-loop-converge's single display child shell-gate-migration is owned by shell-residue-zero (first declared edge), so the fleet row does not collapse and its "k of 1" stays honest. Multi-child projects never collapse. Swallowed intermediates render as the chain line inside the task disclosure (identity + lifecycle chip each), so nothing vanishes and nothing duplicates; the depth cap counts a collapsed chain as one level and applies after collapsing. INCREMENT 2 — hero progress rows (operator request 2026-09-21: the bar prominent, everything else a drop down, errors flagged red). Attempt rows render the stage strip on the face — one segment per workflow obligation, classed by the wire's own decided state key (complete lit in the figure role, active on the in-progress band and pulsing while the worker is live, pending dimmed, failed and refused red at that segment) — plus the one-line state and the throughput line; the round strip, obligation ledger texts, bounded refusal payloads and evidence move behind the activity disclosure, which never arrives open (superseding the 2026-09-05 open-while-live rule; the 2026-09-20 label-first refusal ruling stands). The refused and completed ActivityView arms now carry the obligation roster so their strips paint the red segment. Project bars flag red (project-error) when the decided subtree_error holds — derived from refused/anomalous attempt arms over the display-children relation, never text-sniffed. Activity coloring classifies from typed sources through gunbc.roadmap_presentation's ActivityLineClass (read/write/provider-call/error-refusal/done/neutral): round segments re-home their paint onto it (values unchanged), the summary line wears its decided class, and the wire carries summary_class plus a throughput cell so the client paints both verbatim; the strip is painted by the client from the wire segments' decided state keys. The exec class is declared vocabulary with no on-page producer today — the provider fold flattens CodexItemActivity into the current-activity string, and the named trigger is ProviderRunning carrying the typed item; no regex over free text was introduced anywhere. Witnesses: presentation +4 (classification per class with an unclassifiable-neutral control, refused/completed roster carriage, red-flag derivation both directions, wire summary_class), page +6 (bar-first face and strip state mapping, live-pulse gating, round strip disclosed and classified, red-flagged refused/failed rows, project bar red flag from the decided field, client verbatim hero paint), plus the collapse law receipts (single-child collapses, multi-child never, chain-end counting, no-duplication, shared-child ownership). The roadmap_css lift-parity digest is re-derived by execution (9d5d1d23dce5e2f8), never chosen.
…e whole ticket, and every edge argues its contribution The membership walk no longer accepts a standalone end at an arbitrary node: only a declared root (gunbc.roadmap_nesting declared_roadmap_roots = gunbc-project-root) may be parentless, and any other halt resolves AlignmentWalkUnrooted naming where the walk stopped -- a chain that never reaches the top of its functional decomposition has no alignment answer (review 5354823380). AlignmentChainLink keeps the full ticket carrier (approach, red control, handback, displaced cost) plus contribution_to_parent, the edge's own argument for why the child's work advances its parent; RoadmapMembership gains that field and the fingerprint preimage covers it (alignment-chain/v2). Levels and renders are root-to-leaf with cadence still counted from the leaf. The hierarchy is authored: gunbc-project-root <- harness-work-lifecycle <- harness-recursive-alignment <- harness-alignment-checkpoint-resume and harness-conversation-log-forking, plus the shell batch attached at the root. KNOWN GATE: dispatch of any node whose walk does not reach the root now refuses at the alignment step; attaching the wider population is follow-on authoring, not assumed here. Witnesses updated to the rooted fixtures; two pre-existing reds (page ticket-brief budget, belt two-lineage escalation) reproduce on the clean baseline and are untouched.
…oject level gets a suite page The issue detail page now shows the node's alignment chain as a breadcrumb, root to leaf, derived from the same alignment_resolve the dispatch gate consumes -- never a second path answer. Project crumbs link to the new GET /project/<node_id> suite page, which lists the project's direct members in stable topological order (declared dependency edges restricted to the member set, Kahn-layered, authored order within a layer) with links to their issues; the task crumb is plain text, and an unresolved chain renders the typed refusal instead of a partial path. Four presentation witnesses pin root-to-leaf rendering, refusal honesty, exact direct-membership, and prerequisite-first ordering.
…ots, plans, render receipts A prompt is a projection of an admitted context snapshot, never an authored string (scoped review against 81e7c77; owner direction 2026-09-29). PromptInput types the five input kinds with their authority revisions; PromptContextSnapshot binds them to an attempt lineage, epoch, and source revision; PromptPlan assembly refuses a required segment whose source stands Withdrawn rather than rendering a retracted claim as established; PromptRenderReceipt digests exactly what rendered, so identical snapshots render identical digests and a moved authority revision invalidates the old render. Segment content is rendered prose, digested -- the types guard provenance and revision, not the prose, and semantic contradiction between free-text inputs is NOT inferred (conflicts must be typed to refuse). Roadmap: harness-prompt-context-model authored under harness-work-lifecycle, with its edge contribution. Next cuts: harness_guidance emits modeled segments; the belt probe DAG consumes snapshots from day one; harness_turn migrates to PromptPlan last.
…ender projection harness_guidance_segments turns the grounded-premise/derived-conclusion population into PromptSegments on gunbc.harness.harness_prompt_context: each premise segment's source is an AuthorityInput naming its grounding DeclarationRef at the caller's source revision, and each conclusion segment is a DerivedConclusionInput naming its grounds, so a retracted premise moves the conclusion's input digest. The prose stays the render projection of the same population, pinned by a parity witness so the two cannot fork; a second witness pins that a moved source revision moves the segment inputs while content digests stay stable. This is the first consumer of the prompt context model and the shape the worker, reviewer, and alignment-probe prompts converge on.
…t prompt assembly, standing-sensitive identities, honest checkpoint handoff Prompt model: assembly is now an EXACT JOIN between the snapshot's eligible inputs and their renderings -- every non-withdrawn input renders exactly once, withdrawn inputs render zero segments, foreign or duplicate segments refuse with typed causes (RequiredSourceUnrendered / MissingRendering / DuplicateRendering / UnexpectedRendering / WithdrawnSourceRendered), and the plan's segment order derives from the snapshot, never the caller's render order. Canonical preimages are length-prefixed and carry standing/resolved/required, so a hypothesis becoming an observation is a different input, and no field containing a separator can manufacture another sequence's preimage. SemanticPromptArtifact carries per-segment extents with an honestly declared char-count-fallback basis until a UTF-8 byte primitive exists; ProviderPromptArtifact separates the shared semantic digest from the per-envelope wire digest. harness_guidance conclusions now record their EXACT premise grounds (a moved test-process premise no longer invalidates the write-form conclusion), conclusions are keyed once and rendered, and required is derived from the source input, never asserted beside it. Alignment: the fingerprint preimage covers handback and displaced_cost and the render shows them; the contribution read is a typed fail-closed lookup (missing/vacuous/conflicting edges refuse with the edge named) rather than defaulting to the empty string that used to read as root membership; rootness in the render comes only from declared_roadmap_roots; duplicated same-project membership rows are no longer misread as an ownership fork (they reach the contribution read, which judges agreement). AlignmentCheckpointIdentity (lineage, epoch, ordinal, chain fingerprint, conversation tip, candidate subject) is the belt adjudication lane's idempotency key. Handoff honesty: the worker notice now states the epoch boundary returns control for an INDEPENDENT checkpoint -- the harness makes no provider call and the worker is not asked to grade itself -- and checkpoint-due exits with the distinct admitted standing 3, never the generic failure code 1. Witnesses: per-field fingerprint mutation controls (purpose, boundary, approach, red control, handback, displaced cost, contribution), vacuous and conflicting contribution refusals, exact-join assembly controls, standing-sensitive identity, extents, and the semantic/wire digest split. Full affected suite sweep green; the two known pre-existing reds are untouched.
…rsive-alignment The pure planner node (review 5358022153 lane C): freeze the checkpoint subject and derive the homogeneous probe obligations idempotently, so the parallel probe fan-out is a schedule over derived facts rather than an in-loop improvisation.
…ver the alignment ladder Lane C of review 5358022153: checkpoint_probe_obligations walks the resolved chain's levels root-to-leaf and derives one probe obligation per level (principles, project, task), each keyed by a content digest over the checkpoint identity digest plus the level identity, so a crash re-derives byte-identical keys. A checkpoint whose chain fingerprint moved refuses rather than minting obligations a stale checkpoint would execute; outstanding guidance carries the cadence state's recorded verdict payload at the level's leaf distance, and nothing for ALIGNED. No model calls, no effects, no verdicts -- the population a durable scheduler executes later.
…bric KV residency as observation (review 5358022153, lane D)
- harness_turn: every round persists its exact request and response bytes
under <events_path>.wire/<round>.{request,response}.json (same round
numbering as round.usage); a refused wire-log write emits the non-terminal
turn.wire_log_unwritable event and the turn continues -- the event stream
is the terminal record, the wire log is recoverable evidence, and trading
the work for the receipt is the wrong trade. Filesystem.Write does not
create parents; the writes rely on the wire directory being provisioned
with the attempt state directory, the same reliance the scratch pair
carries.
- harness_conversation_fork: ConversationForkPoint/ConversationForkAdmittance
-- a fork is admitted only while model identity, wire shape and alignment
chain fingerprint all still hold, each refusal naming its cause (a fork
across a model change replays context the engine never computed). The
receipt states the law: the durable log is the correctness authority, KV
residency is a performance derivation, never a correctness dependency.
KvPrefixResidency/Observation model the fabric cache standing as pure
observation: Resident prefers a warm location, every other standing --
Unobserved honestly included -- executes cold from durable state; a fork
receipt binds model/checkpoint/tokenizer/template/tool-schema/projection/
prefix digests, and a shared chain fingerprint alone never establishes the
same KV prefix.
- roadmap_provider_events: admits turn.wire_log_unwritable as a classified,
non-terminal event with provider state unchanged (round.usage arm pattern);
the jq projection passes unknown types through as {type} so the bounded
envelope classifier is the single admission point.
- witnesses: fork admitted on exact identity match; each invalidation refuses
with its named cause; five residency standings are distinct variants with
Unobserved defaulting to cold; pure parts only, no harness IO wet-tested.
Lane B of review 5358022153. The census derived from declared_roadmap_nodes() and declared_roadmap_memberships() found 195 nodes, 18 rooted, 177 unrooted -- 18 carrying an ExecutionContract (thirteen active rows plus five completed belt-era rows still bound), the population dispatch refuses at the alignment step today. Author the attachments: seven program-level nodes (dag-scm-program, namespace-unique-on-chain, v1-deletion-program, v2-emitter-production, ci-end-to-end-execution, progress-observation, roadmap-acceptance-integrity) carry the thirteen rows that had no honest existing parent, and the five completed belt-era rows ride the existing harness-work-lifecycle. Twenty-five new membership rows, each edge's contribution arguing why that child's work advances that parent, each program's root edge arguing why the program serves the factory. extended-admission-cardinality stays unrooted on purpose -- it is the named refusal subject of the unrooted controls, and it carries ExecutionContractUnspecified, so it sits outside the dispatchable population. roadmap_alignment_witness_test gains every_dispatchable_node_reaches_the_admitted_root: every node whose execution is an ExecutionContract must derive AlignmentChained, derived from the authority, with no named exclusions.
…re separate triggers; session standing reads the profile projection; wire-log directory provisioned Fixes the reported regression where clicking an issue title link intercepted the anchor, selected the row, and opened the project's topological strip instead of navigating: the link click now returns untouched (middle-click and modifiers were already untouched), and focus/topological strip are the topological-sort chip, the row body, or Enter/Space. Cut B repairs: the session standing endpoint prefers the durable profile projection's members (session stays the identity authority, projection the display authority), reports the roster's degradation as data (profile store unread / N records unreadable), and the profile read's skipped entries are carried with reasons instead of silently dropped. The attempt-state prepare now provisions the wire-log directory (<events>.wire/) so the harness's per-round request/response persistence lands (harness-conversation-log-forking).
…, conversation log — PR #12684 Lane B roots the dispatchable population; lanes C and D add the pure probe planner and the conversation/fork mechanism; the UI fixes the issue-link navigation regression and Cut B's session-standing erasures. The alignment gate is now live: dispatch refuses unrooted chains.
… canonical witness gates
…e rows -- the serve build's source-annotation phase rejects comments inside the declaration body, and the tickets carry the content
…clip the Fabric avatar - The instance owns its auth store roots (gunbc.roadmap_dashboard_instance dashboard_instance_auth_store_root over DashboardAuthStore); the four auth modules derive their directories from it and the provision plan ensures them. auth-profiles was never created on srv2-deploy, so every login's profile publication was refused and every roster read came back unread -- the assignee surfaces rendered the raw principal and a "1" avatar. - A recorded comment (first write or idempotent retry) answers 303 to its own numbered anchor instead of a stranded text/plain 200; a readback that does not carry the committed comment refuses (502) instead of linking #comment-0. - The 24px avatar circle holds only the initial; the workflow kind rides the chip class and hover title instead of clipped text inside the circle. The orphaned .issue-avatar-badge rule is deleted and the CSS pin re-derived by execution. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…-push hook) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…aracters profile_store_read_all handed Filesystem.List's newline-joined `entries` String to a decoder that walks a List<String>, so its first "entry" was a code point and ends_with refused with "expects a string, got Int". It never ran before today because the store directory did not exist; the first login after provisioning wrote a profile and every issue page then failed. The read now goes through filesystem_listing_observation and main's filesystem_listing_entry_names (added here verbatim, the single decoder of the List wire format), with a refused listing or subject carried as ProfileStoreUnread. Verified by execution against the live store: 1 profile, "Brian Searls", 0 skipped. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…he rail, the robot mark for Fabric - Work tab: the issue route observes its own node through the SAME attempt observation the daily page runs (belt_workflow_attempts_observe_scoped over WorkflowAttemptScope), replacing the hard-coded attempts: [] and "not connected" refusal; a census refusal stays a refusal. Stale-revision marks derive the same way the daily page's do. - Rail: "reporter" no longer promotes the owner lane (@shell) to a person -- the ledger has no creation event, so it reads "not recorded (authored roadmap row)". "blocked by"/"blocking" carry a count that opens the Dependencies tab instead of every headline comma-joined into a 34ch column. - Fabric's avatar is the gunb robot mark (gunbc.site.robot_mark, copied from gunb-ai/frontend legacy/moodboard.html #stoic-robot); both chip builders collapse onto issue_avatar_chip_node. - test.claim.auth.profile_store_real_path_witness_test: the profile store's real path in a temp dir (red on the pre-fix read with the ends_with TypeError), enrolled on the local-repo wet lane (exclusion row, schedule, route-gap chunk 17). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… parent, Fabric badge stone
- The ledger's standing sentence takes the caller's principal naming
(roadmap_node_standing_text_naming); the issue page names principals the
way its chips do, so the rail reads "claimed by Fabric", not an unbreakable
principal:gunbc/workflows/fabric token running past the rail.
- Rail labels no longer shrink under a long value ("observation" collided
with its value); values take the remaining width and wrap unbroken tokens.
- The parent field follows the declared membership, titled from the plan rows
then every declared node, spelled by id when untitled -- never "top-level"
for a member whose project the plan rows omit (shell-typed-invocation under
gunbc-project-root, which the breadcrumb already showed).
- The Fabric chip paints the owner's badge stone #f4f1ec (2026-09-30) under
the frontend's ink robot mark, through --fabric-badge-bg/--fabric-badge-ink
theme properties in both schemes (unthemed-colour census unchanged at 15).
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…lection defers; a failed publish pass names its attempts A blocked (or needs-context) submission capture was deferred by the verify pass but read as a candidate by the integrate step, which then found no verification selection (the verify pass never writes one for a non-candidate), mapped that absence to VerificationUnreadable, and failed the publish pass on every tick since 2026-09-29 with a sentence naming no attempt. - gunbc.roadmap.roadmap_submission submission_candidacy: the one classifier of "is this capture a verification candidate"; consumed by belt_verify_capture_gate, belt_integration_capture_gate and the handoff projection, so the passes cannot disagree. - belt_candidate_subject_reading: SelectionAbsent is an absence (VerificationNotPassed -> integrate defers); unaddressable, unreadable, malformed and head-mismatched selections stay unreadable. - belt_publish_pass_outcome_from names each failing outcome's node, arm and detail instead of "one or more publication outcomes could not be recorded". - Four witnesses in roadmap_belt_actuate_witness_test, each red against the pre-change logic ported into the same seams. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
2026-09-28: Google OIDC login + tracker identity surface + GLM 262K×8 qualification
This is the deployment line (
test/main-plus-roadmap-daily) as it stands after the 2026-09-27/28 work. Per-area, in reviewable order:Human identity (auth)
/auth/sessionwire), three-valued decode, never gating. The login claims receipt records which optional profile members the verified token carried, post-verdict, with typed publication.OidcLoginPromptcoproduct =prompt=select_account; Sign out). One client-side session read serves the header swap and inline assignment.docs/plans/google-workspace-identity-convergence.md(Cut 4: Workspace settings as modeled manual-admin obligations with readback; Directory-backed profile source next).Tracker surface
GLM-5.3-Flash group B — the 262K×8 qualification
cached_tokenscounter is blind to the hybrid-cache hits (located instrumentation fact).RuntimeMaxSecreused the 3600s ready timeout as the whole-run lifetime — a deliberate SIGTERM mid-churn. The admitted runtime now derives the whole sequence (10180s at the largest subject). Earlier layers disproved along the way: harness cross-run staleness (fd7cde5), concurrent >500KB request bodies silently closed (flock serializer, repro obligation open), the sampler tail backstop vs the flock queue (window-bounded skip).docs/plans/glm-group-b-workload-qualification.md(frozen objective: qualified 262K×8; unified single-execution closing qualification; deployment gate vs follow-on table; W1b follow-up not a blocker).Honest notes
witness_ticket_brief_budget_holds_and_redsfails identically on clean main (pre-existing).