Skip to content

Composition session: interaction totality, the RoadmapRow archetype, page altitude, anomaly evidence - #7234

Merged
briansrls merged 7 commits into
mainfrom
session/roadmap-composition
Jul 25, 2026
Merged

briansrls merged 7 commits into
mainfrom
session/roadmap-composition

Conversation

@briansrls

@briansrls briansrls commented Jul 25, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The composition session (single PR, brief routed from the management lane; seeded from main at #7177's merge). All four slices landed, each green by execution with REDs live.

Slice 1 — the interaction-totality machinery

gunbc.design.state_response — the detent-table pattern generalized past transforms. Construction: dispatch_state_family is the single authority for the state-class→band mapping (previously spelled at 3 sites); realize folds multiply every stateful channel across the roster — a missing member is unwritable by fold totality. Declaration: ChannelScope = PerStateFamily | ConstantByLaw{ruling: DeclarationRef} — no third arm, the undeclared middle stops being representable. First ConstantByLaw rows: the approach ring (band-neutral-emphasis ruling) and the engage sound (declared ratchet, dissolution on sound_growth_trigger). Census: over the emitted CSS — 20 cells + 2 signed constants, faults typed and located, shaped for StandingIntent enrollment (registry not built). Specimen: the press fix re-derived through the fold, byte-identical (digest unchanged, zero re-pin — proven before slice 2 moved bytes).

Slice 2 — the RoadmapRow archetype

Five regions declared as data with typed placements; grid template derived from the placements (auto 1fr auto by fold); density on two scale tokens (h-row, row gutter), no bare pixels. Actuator chip-scale in rows per the signed ruling — extent from the row's token, width ceiling from the caption reservation (min=max, no reflow), derived-not-set witnessed with a planted RED. Full-size specimen keeps h-control by selector scope in the sandbox gallery; press physics identical at both scales (slice 1's census green over the new emission).

Slice 3 — page altitude from the attention law

gunbc.roadmap_altitude: attention derived-never-chosen (done/superseded→routine, open/review→working, fail/loud→anomaly, fail-closed on unmodeled inputs), density one projection. Node-bearing sections and frontier buckets render as bands with counts (zeros omitted, unknown counted loudly), open exactly when non-routine work is inside. Client: the row's disclosure auto-expands on anomaly bands via a derived predicate chain. Declared convergence row: dissolve-on #7216 merges (supersedes #7162 — verified, successor read) → re-ground on std.observation. Fixture lesson kept as a witness: done-but-unsigned renders review, and review is working — the attention law agreeing with the sign-off gate.

Slice 4 — anomaly evidence is a surface

The loud reason (step: detail) upserts as .disclosure-reason, the disclosure's first line — persistent, inspectable; title stays a convenience. Fail-closed placeholder when the wire carries no located reason. RED live: the title-only fixture (the real title assignment's own shape) fails the surface predicate.

Riders

Stale web_audio resume claim corrected in the cited layer; fourth-round rulings recorded (Sustained amendment signed WIDE, W2-exemplars re-sequenced after the row archetype, depth/motion reference set with concept anchors + demo ladder).

Receipts

Every slice: full keystone battery by execution (register / tactile / palette / page / dispatch-presentation / component-button / sandbox / lift-parity / roadmap-emit / doc-graph) + the slice's own witnesses with planted REDs. Digest re-pins each derived by execution, one per byte-moving slice, separately attested: 50410951147178f6 (unchanged through slice 1) → 8d2372be4c9d6d61 (slice 2) → 5cfdb3c06e603e38 (slice 3) → 3a0411e16e69f2ab (slice 4).

PROVISIONAL rows (operator flips are located one-liners)

  1. h-row = 24px (gunbc.design.scale.height_row_note) — the chip-scale row height.
  2. Overflow guard clips without an ellipsis glyph (roadmap_style.row_actuator_scale_note) — real text-overflow needs a caption span inside the button, which moves the client textContent target; named for the pass, not smuggled.
  3. Row gutter stays the landed space-4 (same note).

Person-observable checkpoints for the operator's pass (live page)

  1. Rows read as one quiet grid line: chip | title+meta | chip-scale actuator at the right edge.
  2. The full-size dispatch instrument still lives in /sandbox's gallery, press physics intact.
  3. Section headers are bands with counts; finished lanes arrive folded; any open/review member holds its band open.
  4. A dispatched row that comes back fail/loud expands its own disclosure.
  5. A loud answer's located reason is the first line inside the disclosure (and still in the hover title).
  6. Pressing any band's pill deepens that band's own material — no green flash over faults.

🤖 Generated with Claude Code

Brian and others added 7 commits July 25, 2026 13:57
…Scope, family census

The composition session's first slice (roadmap-workspace-remodel-plan, round 5;
operator question: how do we prevent the flash class?). No new framework — the
detent-table pattern generalized past transforms, as one new design module plus
the dispatch instrument's rows.

CONSTRUCTION — gunbc.design.state_response: a component declares its state
family once (dispatch_state_family: the state-class-to-band mapping, previously
spelled at THREE sites — the style's four per-state paint StaticRules, the
receipt rules' four hand call sites, the base rule's inline invite vars) and
each stateful channel once as a function of state. The realize folds multiply
every channel across the roster: a missing family member is unwritable by
totality of the fold, and joining the family is a one-row edit.

DECLARATION — ChannelScope = PerStateFamily | ConstantByLaw{ruling:
DeclarationRef}: the table's element type has no third arm, so the undeclared
middle where the flash bug lived stops being representable. First ConstantByLaw
rows: the approach ring (ruling = dispatch_brighten_neutral_note, the recorded
band-neutral-emphasis ruling) and the engage sound (ruling =
dispatch_sound_constant_ratchet_note, a declared ratchet with its dissolution
trigger on sound_growth_trigger — never silent).

CENSUS — executed over the EMITTED CSS, never only the rows: every
(member x channel) cell resolves in-family or sits under a signed constant.
20 cells + 2 signed constants, counted; faults typed and located
(FamilyVarUndefined | ChannelValueMissing | CrossFamilyValue{foreign_key}) per
the detent-edge lesson that conflated fault kinds fail open. Shaped for later
StandingIntent enrollment; the registry deliberately not built.

SPECIMEN — the round-5 press fix re-derived through the fold, proven by
byte-oracle: roadmap_css() emission is byte-identical (digest 50410951147178f6
unchanged, zero re-pin). Also dissolved onto the roster: the four per-state
paint rules, the base rule's rest paint (state_rest_decl splices at authored
positions), and the band var-name grammar (prefix from the family row, suffixes
from the role enum).

Receipts, all by execution on the merged tree: 8 keystones green
(register/tactile/palette/page/dispatch-presentation/component-button/sandbox/
lift-parity), 5 new census witnesses green including two planted REDs — the
cross-wired family locates CrossFamilyValue{fail} on the ok cells, the
dropped-member family locates ChannelValueMissing on every loud cell — and the
fold-totality witness (one response rule per roster member).

Rider: dag/extdeps/web_audio note corrected — the 'no resume dance needed'
inference was refuted by measurement (operator's ears, W1d A.2) and had been
fixed in the consumer but never in the cited layer; the extdeps row now states
the API fact (gesture makes resume() permitted, never unnecessary) and points
at sound_preamble_note for the consumer contract.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Session decisions 2026-07-25, recorded in the remodel plan (carrier rows
deliberately deferred to their first consumers, per the register's own
no-consumerless-rows discipline):

- The "active operation may breathe" amendment SIGNED at the WIDE scope:
  MotionTrigger gains a general Sustained variant in the motion/depth PR;
  the decorative-vs-operational distinction demotes from type to counted
  census, stated at signing.
- W2-exemplars re-sequenced: after the RoadmapRow archetype, own dispatch
  ahead of W2-bulk; the stale Sequencing line corrected (#7177 closed
  without them by the composition carve-out, not by omission).
- The operator-supplied depth/motion references recorded with their concept
  anchors and port constraints (proxemic glow with the enveloped-breath
  mechanism; SUPERHOT cue decomposition with barrel excluded; Discord
  elevation as ElevationPlane shape; train-window parallax grounded on the
  layer DAG's real churn gradient) plus the sandbox demo ladder. The
  DesignProvenance carrier lands with the depth-studies PR.

Doc-graph witnesses green (the plan doc is already a bound root).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…r derived from row scale

The row is the component (composition slice 2; refines the round-5 flex head
line, does not rebuild it).

ARCHETYPE — gunbc.roadmap_component.roadmap_row_archetype: the five regions
declared as data (status chip | title | meta | disclosure | actuator), each
with a typed placement — chip and actuator own auto head tracks (identity
left, action right), title owns the flex track, meta flows IN the title's
cell (badge count varies, so meta is a flow, never a ragged column),
disclosure sits under the head on its landed indent. The grid template is
DERIVED from the placements (roadmap_row_grid_template = "auto 1fr auto" by
fold, no magic string); density rides two tokens on the scale grammar
(h-row, the row gutter) — no bare pixels.

ACTUATOR — chip-scale in rows per the SIGNED ruling (2026-07-24): the
row-scope override derives its extent from the ROW's token (min-height
var(--h-row)) and its width ceiling from the same caption-derived
reservation the base declares — min-width and max-width one authority, so a
caption morph can never reflow the row. The full-size specimen keeps
h-control BY SELECTOR SCOPE: the override applies only under .node-head, so
the sandbox gallery renders the design-surface grain with the SAME press
physics (detent + receipt folds target .dispatch-btn at both scales,
per-family-honest — slice 1's census green over the new emission).

DOM — node-mid wrapper (the title track's cell) in node_head_row; the
margin-left:auto pusher rule deletes (the grid's third track places the
actuator). CSS grain grows three cited property rows (grid-template-columns,
text-overflow, white-space).

DIGEST — re-pinned 8d2372be4c9d6d61, derived by execution; slice 1 was
proven byte-identical against the previous pin first, so the two changes are
separately attested.

WITNESSES (new file, all by execution): the archetype-derived head block +
node-mid block verbatim in the emitted CSS; the served page carries the
cells; actuator derived-not-set (positive + planted RED on the hand-retune
shape); density cells tokened. Full battery green: 8 keystones + slice-1
census + css grain.

PROVISIONAL rows (iteration protocol, one-liner flips at the pass):
h-row = 24px; overflow guard clips without an ellipsis glyph (real ellipsis
needs a caption span, which moves the client textContent target — named,
not smuggled); row gutter stays the landed space-4.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…rived fold/expand

The workspace becomes the THIRD renderer of the observation model's "routine
collapses, anomaly expands" (composition slice 3).

LAW — gunbc.roadmap_altitude, a local derivation in std.observation's exact
shape (attention derived-never-chosen, density derived from attention, one
projection): done/superseded -> routine (folds), open/review -> working
(holds), fail/loud -> anomaly (expands), with FAIL-CLOSED arms — an
unmodeled status or band key is an anomaly, never quietly routine. No
signature accepts per-section or per-node curation input, so hand-curation
is unwritable, not discouraged.

DECLARED CONVERGENCE ROW: std.observation lives on #7216's unmerged branch
(supersedes #7162, the brief's original number — verified, and the successor
read before shaping this). Dissolve-on: #7216 merges — RowAttention
re-grounds on AttentionLevel, RowDensity on PresentationDensity, this module
shrinks to the workspace's subject mapping.

RENDER — node-bearing sections and frontier buckets become BANDS: a
details.section-fold whose summary carries the title plus derived counts
("2 open · 1 review · 12 done", zeros omitted, unknown counted loudly), open
exactly when non-routine work is inside. Prose-only sections have no
altitude axis and stay flat.

CLIENT — the terminal apply flips the row's disclosure open when the band's
density says expands; the emitted predicate (false || band === 'fail' ||
band === 'loud') is DERIVED by folding the wire-band rows through the law.

Receipts by execution: 8 altitude witnesses green — derivation totality
with fail-closed REDs, counts wire pinned, fold/open proven over RENDERED
fixtures (the two fixtures differ by exactly one working member), the
derived chain pinned in the served asset with a negative arm. Fixture
lesson kept as its own witness: a done-but-UNSIGNED node renders review and
review is WORKING — the attention law agreeing with the sign-off gate (the
operator's pending gesture holds a section open). Full battery green
including roadmap_emit (the committed ROADMAP.md untouched). Digest
re-pinned 5cfdb3c06e603e38, derived by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…osure's first line

The loud band's located reason (step: detail, or the wire reason) renders as
the first line of the row's disclosure — persistent, inspectable in the DOM —
and the title attribute stays a convenience channel, never the only carrier
(composition slice 4).

CLIENT — in the terminal apply, gated on the loud band with the disclosure
in hand: upsert .disclosure-reason (query, create-if-absent, insert after
the summary so it IS the first line), textContent from the same computed
`why` the title channel projects. Fail-closed: an empty wire reason writes
"belt fault — no located reason on the wire" — a true statement, never an
empty line that reads as fine.

STYLE — one rule: text-12, theme ink, loud's own hue as a border-left edge
mark, tokened lengths. Digest re-pinned 3a0411e16e69f2ab, derived by
execution.

WITNESSES — the surface predicate (upsert + insertion + why + fail-closed
placeholder, loud-gated); the planted RED: a title-only fixture — the real
title assignment's own shape with no disclosure machinery around it — must
fail the same predicate; the title convenience channel asserted still
present; the styled block pinned verbatim. Full battery green: 8 keystones +
slice 1/2/3 witnesses + roadmap_emit + doc graph.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
All four slices LANDED on #7234, marked on the carrier per the done-line;
PROVISIONAL rows listed in the PR body; the person-observable checkpoints
await the operator's pass on the live page.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The last open review-round item. The resume() fix was the real candidate;
the modeled parameters stand un-retuned per the by-ear-first discipline.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@briansrls
briansrls marked this pull request as ready for review July 25, 2026 18:50
@briansrls
briansrls merged commit 12be3cf into main Jul 25, 2026
5 of 10 checks passed
@briansrls
briansrls deleted the session/roadmap-composition branch July 25, 2026 19:29
briansrls added a commit that referenced this pull request Jul 25, 2026
…IONALs signed kept (#7239)

The three PROVISIONAL rows from #7234's iteration protocol, discharged at
the operator's pass on the live page (2026-07-25):

- h-row 24px SIGNED KEPT (chosen against 22 and 28) — the mark in
  height_row_note discharges, no code change.
- Ellipsis DEFERRED with its trigger: the clip guard stands until the first
  caption able to exceed the reservation lands (likely W2's ticket
  vocabulary), at which point the caption span moves the client textContent
  target and text-overflow becomes honest.
- Gutter SPLIT (the one change): roadmap_row_column_gutter = space_8 on the
  node-head grid gap; node-mid's badge flow keeps space_4 via
  roadmap_row_gutter. Two density decisions that shared a number for one
  commit now retune independently.

The row witness's expected head block moved with the change — it reds on
this edit by design, which is the re-attestation working as built. Digest
re-pinned 93b584dfe4efeb0f, derived by execution on the fresh post-merge
binary. Battery green: row witnesses, lift parity, register/tactile/page/
presentation/sandbox keystones, slice-1 census, altitude chain, anomaly
surface.

Co-authored-by: Brian <briansrls@MacBook-Pro.local>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Jul 25, 2026
…igratable frontier CLOSES

The 6,223-char verdict specimen decomposed: the five phases + D1-D5 as the
brief (budget census fired at 123 words pre-commit — the split chain
working — trimmed under the bar), the candidate AcceptedWithResidue verdict
as current_state with MERGE IS NOT DONE preserved, the full receipt battery
as red_control, the named residues and arcs as out_of_scope, the verdict
itself as handback (the operator's three questions set the status).

One honest time-axis correction, dated rather than silently rewritten: the
P3 flex-container residue ("deferred, unverifiable without a browser") has
since been DISCHARGED — the remodel round-5 head line and #7234's
RoadmapRow archetype are its discharge, with the operator as the browser.

With this row every AuthoredLine on the sheet is dispositioned: MIGRATED
(the ticket corpus), TYPED-HELD (13, the re-sweep worklist, witnessed),
DECLARED BY SHAPE (closed receipts + one-sentence rules), or
OPERATOR-SIGNED (5, never edited under a signature).

ROADMAP.md regenerated; full battery green BEFORE commit.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 25, 2026
…(tranche 1: dispatch-lifecycle cluster) (#7240)

* W2-bulk tranche 1: the dispatch-lifecycle cluster migrates onto the ticket contract (6 rows, 161 -> 155 legacy)

First tranche of the bulk migration (task queued behind the composition
session; the five exemplars are the contract, operator-signed on the
rendered archetype). Rows: ts-dispatch-lifecycle, ts-dispatch-verdict,
ts-dispatch-rework (ticket_row — unsized discipline rows), ts-wf-shape
(ticket_row), ts-wf-belt-refusals, ts-wf-progress (ticket_wi — sized,
sizing preserved).

Honesty rules applied, and they are the tranche's real content:
- fields carry ONLY what the prose stated; a field the prose never filled
  is an honest empty (the renderer omits it), never a fabrication;
- dates come from the prose itself (authored_on only where the row named
  one; last_verified_on stays empty — migration is not verification);
- history moves to the updates axis WITH its dates (ts-wf-shape's #7113
  reconciliation-seam note preserved as a dated update, marked since-landed,
  rather than deleted or left masquerading as current);
- Accept lines map to their honest fields (belt-refusals' became
  red_control; progress's became first_slice), each marked in the
  migration update;
- ambiguous rows stay on the counted legacy frontier rather than guessed —
  none in this cluster needed it.

ROADMAP.md regenerated through the generated-artifact gate (main_wet); the
md projects headline — brief per the signed W2 contract (full fields render
on the served page; the authority carries everything). Receipts by
execution: roadmap_page_keystone (including the 100-word brief-budget
census over the six new briefs), roadmap_emit, roadmap_authority all green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* W2-bulk tranche 2: the loop cluster (4 rows, 155 -> 151 legacy); receipt shape declared

Migrated: ts-loop-pattern (the named loop + the ask), ts-loop-selfheal (the
structural exit — both operator rulings preserved VERBATIM as dated updates,
mechanism notes preserved with the #7121 guard), ts-loop-buildretry (the
widening-arm masking row), ts-loop-falsifier (the 29-red narrative with its
exit condition as first_slice).

Shape ruling applied (operator-signed this session for ts-pr-*; extended
here by the same rule): one-fact receipt rows do NOT migrate — a ticket
around a narrative one-liner is nine empty fields of costume. Stays prose
by declared shape: ts-loop-fmt/docsonly/prepush/stale-roster (closed
incident receipts), ts-loop-deploy (pointer receipt). The parent ticket's
update row declares this so the frontier count reads honestly.

ROADMAP.md regenerated (main_wet); page keystone (brief budget over the new
briefs), emit, authority green by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* W2-bulk tranche 3: the observation family (6 rows, 151 -> 145 legacy)

ts-obs-anchor (the five laws; reference implementation studied by
execution), ts-obs-model (P0 carriers), ts-obs-ci-renderer (P1, the pain
point), ts-obs-tty (P2), ts-obs-census-wall (P3), ts-observation-contract
(the equivalence bar). Accept lines and REDs mapped to red_control /
first_slice, marked per row.

The family's branch state recorded honestly: each row carries a dated
update — verified this session — that the lane's implementation lives on
 #7216's unmerged branch (supersedes #7162) and lands at its merge;
last_verified_on set only on those rows, because that verification actually
happened. The composition PR's altitude convergence row already watches the
same merge.

The brief-budget census fired mid-tranche (ts-obs-anchor=101, located node
+ count exactly as designed) and the brief was trimmed one word — the wall
working, recorded because a census that never fires is the one to distrust.

ROADMAP.md regenerated; page keystone, emit, authority green by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* W2-bulk: the re-sweep hold becomes a typed, counted state (management sharpening 1)

The 13 ts-pr-* children move from a prose flag to w2_bulk_resweep_held —
typed rows, counted, with ts-pr-audit's sweep as the declared dissolve-on —
so the legacy frontier decomposes honestly into not-yet-migrated vs
held-for-disposition, and the operator's re-sweep has a mechanical worklist.
ts-pr-audit itself migrates to a ticket (its sweep instruction is the
first_slice; the sweep is the handback — each child's disposition is the
operator's call).

The lighter one-fact row species is deliberately NOT minted (management
sharpening 2, second-consumer discipline): the sweep will disposition most
of these away, and the hold makes deferring that call cheap.

Witnesses by execution: every held id resolves to a live AuthoredLine (a
held id whose row was migrated, superseded, or deleted reds carrying the
id — the hold outlived its state); planted REDs on a nonexistent id AND on
an already-migrated ticket id. ROADMAP.md regenerated; page/emit/authority
green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* W2-bulk tranche 4: the lens family (6 rows, 145 -> 139 legacy)

ts-lens-endgame (the v2-door dependency named precisely, milestones
preserved), ts-lens-door (M-L1; the Accept T2->T5 block became red_control,
the three-compile-sites scope review became current_state), ts-lens-treewide
(M-L2; the W3 typed-module-store convergence preserved), ts-lens-
contract-truth (M-L3; the twice-verified counted state — 55 ids / 46
contracts / 9 missing including live Determinism — lands as current_state
with its verification date as last_verified_on, the one tranche row where
that field is honestly non-empty from the prose itself), ts-lens-
complexity-scope (M-L4; the red-by-design blockers and the space-complexity
re-home rider preserved), ts-lens-terminal (the 2c fan-in node).

ROADMAP.md regenerated; page keystone (brief budget over six new briefs),
emit, authority, and the re-sweep hold witness green by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* W2-bulk tranche 5: the group-taxonomy family (5 rows, 139 -> 134 legacy)

ts-group-u (the membership taxonomy — positional/derived/frontier/nickname
with the mint->frontier->query pipeline), ts-group-family (the #7069
re-key; the 744-rows-Derived sequencing fact preserved as an update),
ts-group-census (the swept roster ledger; landed items in the brief,
storage-grain residue as current_state), ts-group-dissolve-typed (the
OnRoadmapNode coupling; its lens became red_control), ts-group-
partition-drift (the incident receipt; both drift incidents in the brief,
the regen two-generation side receipt preserved dated).

ROADMAP.md regenerated; page/emit/authority green by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* W2-bulk tranche 6: the host-state family (5 rows, 134 -> 129 legacy)

ts-host-state (the parent gap — both 2026-07-22 tail incidents as
displaced_cost, the srv4 live-fire receipts as current_state, the 0-to-3
dispatch brief as first_slice with the operator's claims-intersection
ruling, TakeoverRuling as red_control), ts-host-frontier (the
Derived|OwnedMember|ForeignWithContract classification), ts-host-antientropy
(the host falsifier), ts-host-cdtransport (deploy from content, not the
runner workspace), ts-host-genlease (StaleDesiredState + subtree lease; the
21:49 overlap receipt as displaced_cost).

ROADMAP.md regenerated; page/emit/authority green by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* W2-bulk tranche 7: the native family (5 rows, 129 -> 124 legacy)

ts-native-bulk (the arc; operator re-pricing + sizing preserved dated),
ts-native-census (derived-denominator discipline made structural:
stale-on-arrival counts kept ONLY as dated snapshots in current_state, the
deleted-drifting-copies history preserved), ts-native-seams (the
measurement-settled crate grain), ts-native-flip (the three-section PR),
ts-native-flip-revert (the working-as-designed receipt; the twice-corrected
re-flip gate as current_state; the one-authority rule — the carrier's
dissolve_on strings, never a roadmap paraphrase — lands as handback, which
is exactly what that clause is).

ROADMAP.md regenerated; page/emit/authority green by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* W2-bulk tranche 8: the ci + access clusters (7 rows, 124 -> 117 legacy)

ts-ci-definition (the three-clause functionality bar; today's failures as
current_state), ts-ci-claimed (the do-not-re-plan ledger; sequencing rule
preserved — a fast CI that lies is worse than a slow one), ts-ci-ergonomics
(the priced touchpoints; the inventory as first_slice), ts-ci-options (the
three merge-gate options; the pick is the operator's — handback),
ts-access-model (the transport-accident gap; grants shape), ts-access-
orgtailnet (operator-owned creation — handback), ts-access-dispatch-auth
(go-live precondition; do-NOT-drop-the-front as handback).

ROADMAP.md regenerated; page/emit/authority green by execution.

Rider: #7239 (the flips PR) merged on its green floor this tranche — the
gutter split and signed PROVISIONAL marks are on main.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* W2-bulk tranche 9: misc batch A (5 rows, 117 -> 112 legacy)

ts-authority-converge (the sprint entry point; the parity-window carrier
contradiction as current_state, the option-b gating ruling dated),
ts-concat-class (the 2,798-site census with its atom-never-composition
ruling), ts-deploy-tail (the DONE incident — its four dated receipt waves,
including the credential-leak find and #7086's construction fix, become the
updates thread the blob never had), ts-doc-anchor (carrier-anchored
sessions), ts-effects-providers (the conflated-counts honesty catch as
current_state; the boundary-enforcement clause as red_control).

ts-branches stays: a closed all-dispositioned receipt, not a blob.

ROADMAP.md regenerated; page/emit/authority green by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* W2-bulk tranche 10: misc batch B — the interpreter-endgame cluster (6 rows, 112 -> 106 legacy)

ts-evaluator-complete (the two-typed-exits bar; refusal-never-fallback),
ts-executor-seams (critical slice, hollowing fenced to out_of_scope with
its stale-on-arrival count rule), ts-falsifier-nfr (DONE — root-cause and
landed rows as the updates thread; the NEW-find clause as red_control),
ts-floor-memory (the ceiling pin; confirm-caps as first_slice),
ts-interp-delete (the delete bar; the missing interpreter-file-only
milestone note as current_state), ts-interp-endgame (the three finish
lines named apart; the counted-fourth-role enrollment as first_slice).

ts-intake-discipline stays: a one-sentence standing rule, not a blob.

ROADMAP.md regenerated; page/emit/authority green by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* W2-bulk tranche 11: misc batch C (5 rows, 106 -> 101 legacy)

ts-lying-stamp (the recurrence class; the 5th occurrence dated; the
decide-once as first_slice AND handback — it is a ruling), ts-material-ci
(the kernel row; the corrected sequencing as current_state; the
different-denominators watch-flag as red_control — land the fresh receipt
BEFORE repricing), ts-merge-gate (the re-evidence), ts-quarantine (the
link-grain dress rehearsal; the deletion-receipt clause as red_control),
ts-queue (ops hygiene; the zombie cancel as first_slice).

Stay by shape: ts-modeling-pass (a per-PR checklist rule), ts-overnight
(done accounting receipt).

ROADMAP.md regenerated; page/emit/authority green by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* W2-bulk tranche 12: the final ts batch (11 rows, 101 -> 90 legacy) — the ts-* sheet is done

ts-review-sweep (the operator checklist; falsifier-dark prioritization as
first_slice), ts-seed-interim (the 8-percent-in-33h receipt as
displaced_cost, counts dated by the wave snapshot), ts-seed-ratchet
(SeedGrowthJustification as the frontier pattern on the seed itself),
ts-seed-data-out (the landed roster move; the live dual-representation
mirror as current_state), ts-seed-intake (the thin-transport policy),
ts-standing-intent (the ask-once row — with the state-response census
recorded as its third idling consumer), ts-store-econ (the ForciblySerial
narrow point: three lanes converge, said out loud in displaced_cost; the
review-hardened RED battery preserved whole), ts-unconsumed (the sweep),
ts-wave-reds (DONE — the three-collision heal chain as dated updates,
including the opposite-way drift lesson), ts-wf-lens-walls (the roadmap
lens trio), ts-zero-hand (the terminal ruling; the third carrier
contradiction as current_state, the never-delay sequencing as out_of_scope).

Stay by shape: ts-roadmap-drift (done receipt), ts-sustainable-close
(one-sentence rule). With this tranche every ts-* row is dispositioned:
migrated, typed-held, or declared by shape.

ROADMAP.md regenerated; page/emit/authority + the hold witness green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* W2-bulk tranche 13: lane 1 — the CI-floor lane (16 rows) + carrier-preserving constructors

New constructors first, because the wall fired before the work: ticket_doc /
ticket_pp — the exact siblings authored_doc/authored_pp are to authored().
Without them, migrating a pointer-carrying row through ticket_row would
silently DROP its carriers (the doc-graph's inbound links) — content loss
the migration's own rules forbid. The doc-graph orphan witness runs green
over the migrated lane as the executing proof the pointers survived.

Migrated: 1-nightly (done, audit-dated) · 1-double-resolve ·
1-sccache-falsegreens (the cache-lies live-repro residue as current_state) ·
1-wallclock-measured (void profile numbers said so, dated) ·
1-placement-authority · 1-sched-resource-aware (the re-base ruling; tracker
link preserved inline) · 1-affected-set-defork(doc) · 1-budget-tree(pp,
both pointers kept) · 1-builtin-registry(pp) · 1-floor-right-things(doc) ·
1-g1-placement(doc) · 1-g2-runner (the modeled-envelope Accept as
red_control) · 1-g3-caps · 1-g4-dispatch(pp) · 1-g5-rust-selection(doc) ·
1-resolver-pathology-b(wi, sizing preserved).

NEW SHAPE RULE, applied and declared: an operator-SIGNED row does not get
edited under its signature — 1-bics-design and 1-resolver-pathology-a stay
as attested receipts (the signoff attests the node as signed; migrating the
line under it would change what was signed).

ROADMAP.md regenerated; page/emit/authority + doc-graph green by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* W2-bulk tranche 14: lane 3 — the audit lane (5 rows)

3-audit-affected-set (done; the three-clause discharge with its live
discrimination receipt), 3-audit-artifact-freshness (green-on-branch is not
green-on-main; the operator ask preserved verbatim in the migration
update), 3-audit-cache-honesty, 3-enforcement-intent (the landed inventory
re-based; the state-response census recorded as its third idling consumer,
closing the loop management asked to watch), 3-cost-risk-benefit (the
2026-07-12 working-session capture — the argmax framing, the
deferred-and-detected invariant, the wet-is-sacred inversion, the
missing-pieces list highlighted not papered over; carriers preserved via
ticket_pp).

3-audit-gate-inventory stays: operator-signed attested receipt.

ROADMAP.md regenerated; page/emit/authority + doc-graph green by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Fix the authority witness's stale headline pin (the tranche-14 red, caught and owned)

roadmap_authority_witnesses redded on tranche 14 — witness_audit_lane_present
pinned the affected-set headline WITH its inline audit date, which the
migration moved to a dated update per the convention every tranche has
applied. The pin moves with the authority (the slice-2 shape: the witness
reds on the change by design, then re-attests). The red was committed before
it was seen — the battery ran in the same chained command as the commit;
this fix commit is the stopped-line analysis, and the chain is split from
here on so a red blocks the commit it belongs to.

Forward note for lane 2: witness_fabric_design_rule pins lane-2 row
strings ("stateless frontend MVP on fabric" et al) — those pins update
alongside their rows' migration, deliberately, not as surprises.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* W2-bulk tranche 15: lanes 5 and 6 (12 rows)

Lane 5: 5-cargo-green-continuous (done — resolved-by-construction, the
unwritable failure mode stated), 5-regen-cutover (done — same discharge
class, migrated for consistency with 1-nightly/3-audit-affected-set),
5-defork (the shadowed-shell.Which incident as displaced_cost), 5-dissolve-
patches (the 7→25 regrowth re-measure dated), 5-emitted-crate-partition,
5-root-b, 5-seed-honesty (the fail-open-by-construction confession
preserved whole; FLAGs A–D as handback), 5-test-migration (wi; the
operator's scrutinize-first ruling as handback; the typed-retirement-path
as first_slice), 5-v1coupled (one-liner, migrated for its deferral field).

Lane 6: 6-shell-emission(doc), 6-shell-intent-phase1(doc — sign-off
PENDING as current_state, the flip instruction as handback),
6-shell-slice2(doc — same pattern, the FLAG discharge dates kept).

Stay signed: 6-shell-slice0, 6-shell-slice1 (operator-signed attested).

ROADMAP.md regenerated; page/emit/authority + doc-graph green by execution
BEFORE this commit (chain split per the tranche-14 lesson).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Record the write-interface assessment (operator question, mid-bulk)

The migration is not the interface's right first consumer (editorial half
irreducible; mechanical half already execution-verified per tranche). The
recurring consumer is typed TicketUpdate APPEND — belt verdicts, session
write-backs, dissolution firings — with the updates axis as the first API.
Assessment as a data row beside the constructors so it is not re-derived.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* W2-bulk tranche 16: lane 2 batch 1 — floor-throughput + fabric-allocation (9 rows)

2-compile-clean-serial (lever a landed, the 37.6x receipt kept; lever c
residue as current_state), 2-compile-clean-shard-a (done, the OWNED wrapper
preserved — owner string survives migration), 2-compile-clean-shard-b (the
full Accept checklist as red_control with its planted RED), 2-admission-
model (the operator's 1-core-3GiB directive dated; derive-never-hand-set as
red_control), 2-cap-deconflation (three facts in three mechanisms; the
no-conflated-survivor receipt as first_slice), 2-burstlease (non-death
before utilization), 2-strictlease (four nouns no scheduler; the
read-back-never-asserted Accept), 2-provider-offer (the dormant design-break
probe with its four witnesses), 2-shape-labels (runs-on as projection; the
later-architecture fence as out_of_scope).

ROADMAP.md regenerated; battery green BEFORE commit.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* W2-bulk tranche 17: lane 2 batch 2 — merge-admission + converge spine (9 rows)

2-merge-admission(pp — HELD as current_state, the green-on-branch evidence
as displaced_cost), 2-cd-transport (done, owned wrapper preserved — the
placement-is-not-proof premise), 2-converge-reland (the landed inventory
in the brief, the full T4 accept as red_control, the ReadAbsent bind note
as current_state), 2-fleet-hardening (the ungated-return debt),
2-host-admission (two modes; the post-patch-values RED and the
counters-did-NOT-increase receipt), 2-live-read-seam (the no-mutation
fence; first-slice-does-not-close preserved), 2-live-read-runner-memory
(done, owned; stop-and-return as handback), 2-periodic-actuation (a timer
existing is not acceptance), 2-privilege-model (done, owned; typed refusal
BEFORE mutation).

ROADMAP.md regenerated; battery green BEFORE commit.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* W2-bulk tranche 18: lane 2 batch 3 — the SCM cluster + fabric services (10 rows)

The scm family (infra-econ with its cited GitLab 10-K carriers ·
node-merge's keyed-diff-over-identity core · publication-ladder with the
pick-two churn-blinding fence as out_of_scope · remote-realization's
protection-IS-billing · visibility-stage0, your 2026-07-25 plan, its T3
Accept as red_control), 2-stateless-frontend (milestone A landed, B + the
unmergedPages cutover as current_state), 2-emit-partition (owned; the four
leftovers a-d; the atom-never-composition wall as red_control), 2-p3,
2-session-slice (the humming apply-rule), 2-service-receipt (the T4
read-back Accept with its three NotConverged REDs).

with_plan and owned wrappers preserved throughout.

ROADMAP.md regenerated; battery green BEFORE commit.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* W2-bulk tranche 19: lane 2 complete — placement, host-effect, srv3/os-install (15 rows)

2-ci-two-tier-placement(doc — the 5-second rule; fail-closed admission),
2-test-decomposition-wcf (with_plan; the W/C/F cut with attribute-before-
decompose), 2-host-effect-phases(doc), 2-keyed-delta-fold (accepts a+b met;
the (c) proof-by-consumption fork as first_slice — re-point or wire,
deliberately), 2-oom-consumer(doc — never EAGAIN-shaped), 2-runner-
allocation-v0 (the operational milestone; its full T4 Accept and RED
battery; not-complete-while-any-hand-edit preserved), 2-temporal-effect-
spine-a (done, owned), 2-resource-namespace-upsert-a (done),
2-os-install-deduction-a (done, owned), 2-srv3-install-reconcile-a (done),
2-srv3-osinstalled(doc), 2-install-media-generic-layer, 2-nbd-serve-held-
session-lease (done; the do-not-mint-a-parallel-lease-vocabulary rule),
2-srv3-boot-action-diagnostic, 2-os-install-generic-naming.

Near-miss, owned: the deduction-a owner string was fabricated from the
sibling's pattern where my read had truncated it — caught before commit by
diffing the removed lines, restored to the true value (zesty-bat-588, the
same dispatch batch). The rule stands: a field the source states is copied,
never patterned.

ROADMAP.md regenerated; battery green BEFORE commit (incl. hold witness).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* W2-bulk tranche 20: ts-ui-model — the sheet's largest blob, and the migratable frontier CLOSES

The 6,223-char verdict specimen decomposed: the five phases + D1-D5 as the
brief (budget census fired at 123 words pre-commit — the split chain
working — trimmed under the bar), the candidate AcceptedWithResidue verdict
as current_state with MERGE IS NOT DONE preserved, the full receipt battery
as red_control, the named residues and arcs as out_of_scope, the verdict
itself as handback (the operator's three questions set the status).

One honest time-axis correction, dated rather than silently rewritten: the
P3 flex-container residue ("deferred, unverifiable without a browser") has
since been DISCHARGED — the remodel round-5 head line and #7234's
RoadmapRow archetype are its discharge, with the operator as the browser.

With this row every AuthoredLine on the sheet is dispositioned: MIGRATED
(the ticket corpus), TYPED-HELD (13, the re-sweep worklist, witnessed),
DECLARED BY SHAPE (closed receipts + one-sentence rules), or
OPERATOR-SIGNED (5, never edited under a signature).

ROADMAP.md regenerated; full battery green BEFORE commit.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian <briansrls@MacBook-Pro.local>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Jul 26, 2026
…roof

The refresh-amnesia the operator hit (spawn a session, reload, the page
forgets) closes without the render losing purity: the healthz digest law
takes the digest over the pure page body, so live state arrives by FETCH,
exactly as dispatch answers do.

WIRE — GET /sessions.json: the belt observation projected as JSON
(belt_sessions_json_value, a pure fn over BeltObserve with every arm
witnessed on synthetic values; the effectful wrapper only threads
belt_observe in). ONE observation feeds both status and body — observing
twice could disagree. Observed → 200; ObserveRefused → 503 carrying the
typed reason: an unknowable session set is loud on the wire, never an
empty panel. Route count pin moved 10 → 11 with the authority.

CLIENT — on load the emitted program fetches the observation and marks
each live node's actuator: ok band + the session-chip morph with the
OBSERVATION word (live — type-distinct from the wire answers spawned/
already_live: those answer MY click, this reports the world) + the tmux
session name in the title channel. The refusal arm (or a failed fetch)
prepends an .observe-refused banner naming the reason — the altitude law's
anomaly-expands applied to the panel. Banner styled in the loud family
(venom edge mark, mono); digest re-pinned c4eabee5bdfb8021 by execution on
the merged tree.

Riders:
- origin/main merged in (the flips squash + ~7 other lanes; local main had
  not been pulled since #7234 — the branch now carries the true tree).
- Two TS-serializer potholes found by execution and fixed at the consumer:
  the optional-else spelling (Present{ts_block}) and a bare-Call arrow body
  the emitter's match does not cover (wrapped block+return).
- The page witness's bare LiveTreeDisposition reference lost its
  pool-coincidence under main's 439-file delta — the documented Class B
  shape, proven pre-existing by running the stashed tree, fixed with the
  explicit import (closure-independent binding).

Witnesses: 4 new sessions-panel fns (wire projection both arms, loud
refusal end-to-end incl. 503 + banner machinery + catch arm, live-mark
pinned in the served asset, banner styled). Full battery green: 15 suites.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 26, 2026
…sults, stop (U1–U4) (#7266)

* U1: dispatch becomes attempt-grain — the redispatch fix

The one-shot-per-node defect had two roots, both dissolved by one move
(operator-approved close-the-loop arc; the operator's accidental spawn of
ts-authority-converge was the live receipt):

- DEBRIS: Stop left dispatch/<node> + its worktree behind, so the next
  POST failed at the git step forever.
- SESSION-ID REUSE: the node-deterministic claude --session-id collided
  with the archived transcript, so a stopped node could never dispatch
  again at the claude layer either.

Dispatch attempts now carry an ATTEMPT KEY — content_hash(node_id x the
spawn's clock observation), std.content_hash the single hashing authority —
threaded into the branch (dispatch/<node>-a<key>), the worktree path, and
the claude session UUID. The TMUX SESSION NAME deliberately stays
node-grain: it is what observe/reconcile key on, so already-live detection,
kill, and tick idempotency are untouched — one live session per node
remains the invariant. Nothing is deleted to make way: prior attempts'
branches/worktrees stay as inspectable receipts (a stopped attempt's
worktree may hold uncommitted work; the rework discipline carries prior
diffs forward; cleanup is separate explicit work, never an absorbing arm
on spawn).

Fail-closed arms: a clock refusal refuses the spawn (step attempt-clock —
an unknown-stamped attempt would collide later); a same-instant double
spawn collides on the key and refuses at the git step, typed.

Also dissolved: the gate preview now names the REAL attempt (the POST
handler's one clock probe feeds gate + spawn), and the hostile-node-id
witness re-derives argv through the real naming fns instead of its own
hand copy (a latent §3 fork, closed).

Witnesses: belt_attempt_grain_holds (new — fresh where debris collides,
stable where identity reconciles: distinct key/branch/worktree/uuid across
stamps, deterministic within one, node-grain tmux invariant); the uuid
determinism suite re-scoped per attempt; the gate pin moved with the
authority (now asserts the attempt-scoped branch). Ten suites green by
execution: belt-actuate, actuator, belt, serve, http-route, page, sandbox,
spawner, register, tactile.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* U2: sessions panel v0 — the page knows what the belt knows, refresh-proof

The refresh-amnesia the operator hit (spawn a session, reload, the page
forgets) closes without the render losing purity: the healthz digest law
takes the digest over the pure page body, so live state arrives by FETCH,
exactly as dispatch answers do.

WIRE — GET /sessions.json: the belt observation projected as JSON
(belt_sessions_json_value, a pure fn over BeltObserve with every arm
witnessed on synthetic values; the effectful wrapper only threads
belt_observe in). ONE observation feeds both status and body — observing
twice could disagree. Observed → 200; ObserveRefused → 503 carrying the
typed reason: an unknowable session set is loud on the wire, never an
empty panel. Route count pin moved 10 → 11 with the authority.

CLIENT — on load the emitted program fetches the observation and marks
each live node's actuator: ok band + the session-chip morph with the
OBSERVATION word (live — type-distinct from the wire answers spawned/
already_live: those answer MY click, this reports the world) + the tmux
session name in the title channel. The refusal arm (or a failed fetch)
prepends an .observe-refused banner naming the reason — the altitude law's
anomaly-expands applied to the panel. Banner styled in the loud family
(venom edge mark, mono); digest re-pinned c4eabee5bdfb8021 by execution on
the merged tree.

Riders:
- origin/main merged in (the flips squash + ~7 other lanes; local main had
  not been pulled since #7234 — the branch now carries the true tree).
- Two TS-serializer potholes found by execution and fixed at the consumer:
  the optional-else spelling (Present{ts_block}) and a bare-Call arrow body
  the emitter's match does not cover (wrapped block+return).
- The page witness's bare LiveTreeDisposition reference lost its
  pool-coincidence under main's 439-file delta — the documented Class B
  shape, proven pre-existing by running the stashed tree, fixed with the
  explicit import (closure-independent binding).

Witnesses: 4 new sessions-panel fns (wire projection both arms, loud
refusal end-to-end incl. 503 + banner machinery + catch arm, live-mark
pinned in the served asset, banner styled). Full battery green: 15 suites.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* U3: result surfacing v0 — attempt branches on the row; the loop closes

The attempt branches ARE the results ledger: every U1 spawn mints
dispatch/<node>-a<key>, so listing refs/heads/dispatch/ observes every
attempt ever made — including pre-attempt-grain LEGACY branches (empty
key; the operator's accidental spawn is one), which are real attempts and
render as such, never filtered as noise.

ACTUATOR — parse_dispatch_attempt_refs: the branch-name parse authority,
discriminating by the last -a segment being exactly the 16-char key width;
the misparse edge (a node id itself ending -a<16 chars>) accepted and
named, not papered over. The round-trip witness closes the U1 loop: a
branch MINTED by dispatch_branch_name must parse back to its own node and
key — the two authorities cannot drift.

BELT — belt_attempts_observe mirrors belt_observe's fail-closed grammar:
git absent or non-zero for-each-ref is an UNKNOWABLE attempts set
(typed, carries stderr), never widened to zero; exit 0 + empty IS a
genuine zero (for-each-ref's documented no-match behavior). Runs in
belt_actuate_workdir — the branches live exactly where spawns mint them.

WIRE — GET /attempts.json (route pin 11 → 12): 200 observed / 503 refused
with the typed reason.

CLIENT — each attempt renders into its node's disclosure as a mono line:
the branch NAME, copyable and TRUE — a tree link would be dead until a
push, and a dead link is a fabricated result; the PR half lands when
push/PR state is observed, not guessed. Upsert by class (no reload
stacking); refusal reuses the loud banner, which became text-agnostic
(the baked session prefix moved to its call sites) rather than forking.

Recovery owned: the first cut of these client edits went in by python
string surgery that aborted mid-script, leaving a call to an undefined fn
committed to nothing but the worktree — reverted to the committed U2
state and re-cut with tool edits in verified steps. A scratch probe entry
also began hanging post-merge (closure-dependent, product entries
unaffected, ~14s compiles throughout) — noted, not chased.

Witnesses: 8 new (parse round-trip · three-shape parse incl. legacy ·
multi-line output · wire both arms · loud 503 · client pins for BOTH
panels · styled row · typed argv with no destructive tokens). Digest
re-pinned c020930b7552052e by execution. Battery: 14 suites green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* U4: stop from the UI — the R5 owned-only teardown as a button

The operator asked for it mid-test, and it is the loop's missing verb:
press → watch → STOP → press again. The blocker was never the teardown
(that existed) — it was ownership PROOF: name-only tmux-ls observation
yields UnknownRefused, and R5 correctly refuses to reap without proof.

FINGERPRINT OBSERVATION (the scaffold's declared dissolution, now
DISCHARGED — its Disposition row flips Scaffold → Terminal and its witness
flips with it): tmux list-panes -a with the cited format variables yields
(session_name, pane_current_command); tmux_session_observation_with_panes
upgrades a name-only observation to SessionObserved with the fingerprint in
hand — Converged for claude, Conflict for anything else wearing the name.
A pane-read failure leaves the observation name-only → the gate refuses
fingerprint-unobserved; it NEVER widens into a kill.

STOP GATE — the R5 table as a typed decision: Converged/Drifted stop;
Absent 404; Conflict/UnknownRefused/Inaccessible 409; observe-refused 503;
kill-failed 502. One observation feeds the whole chain.

WIRE — POST /stop/{node_id} (route pin 12 → 13). CLIENT — a stop chip
appears beside each live session pill (toggle-chip family): stopping… →
reload on stopped; stop refused with the reason in the title channel
otherwise. Digest re-pinned 28c06723684117e4 by execution.

LIVE DRIVE, four arms exercised against real tmux:
- the operator's hand-made sleep session wearing a dispatch name → 409
  "foreign process… refusing to kill what we cannot prove ours" — three
  spoof shapes tried (plain, exec -a, symlink), all refused, session
  intact: p_comm resolves the real image, exactly the anti-spoof R5 wants;
- a SIP-killed copy vanished pre-observation → 404 discriminated from 409;
- the green path proven through the real gate synthetically (witnessed).

NAMED FINDING, landed as a row (dispatch_claude_fingerprint_finding_note):
a REAL claude on this macOS reports its VERSION (2.1.220) as p_comm — the
Converged arm may not fire on real workers until srv1's live fingerprint
is READ, not guessed. Decide-by-receipt: one tmux list-panes on srv1
beside a live worker; the row becomes the observed value if it differs —
a data edit. The safety half (refusals) is unaffected and proven.

Witnesses: 6 new (pane parse · the four-arm gate table with the sleep
Conflict as the star RED · wire-status discrimination incl. 404-vs-409 ·
client chip pins · styled · scaffold discharged). Battery: 13 suites green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Catch up to main; re-home the attempt-grain witness where it executes

CI on #7266 went red two ways, and only one of them was mine.

NOT mine — dag/gunbc/hostname_read.dag: main's #7250 renamed the seed
builtin (shell_materialize_argv_for_operation ->
shell_materialize_operation_argv) and re-homed the call on the new
v2.std.operation_argv types. The branch was seven commits behind, so it
carried the old spelling. Merging main is the whole fix; nothing here
touches that file.

MINE — the Phase 0(b) admission invariant refused belt_attempt_grain_holds
as an enrolled row with zero executing consumers. The row is PURE (content
hashes and string derivations, no host reach) but I had parked it in
roadmap_belt_actuate_witness_test.dag, which is BinWitnessWet-excluded from
discovery because its OTHER witnesses execute real host commands. So the
claim was deferred to a cadence it never needed and never ran on.

The fix is to move the row, not to enroll it: it now lives in
dispatch_attempts_witness_test.dag beside U3's parse witnesses, which
discovery scans on every affected PR. That pairing is the real one — this
row proves the MINT varies per attempt, attempts_parse_roundtrips_the_minted_branch
proves the READ recovers exactly what was minted; one authority, both
directions. Enrolling it on the wet roster would have greened CI by
mislabelling a pure claim as host-executing, which is the kind of quiet
lie the invariant exists to catch. A note stays behind at the old site
saying deferral is a property of the EXECUTION a row needs, never of the
module it happens to name. Three imports went dead with the move and are
deleted rather than left as unused vocabulary.

Two roadmap rows recorded from the operator's questions at the U4 receipt:

  ts-dispatch-ownership-mint — "make it impossible for a foreign process
  to exist here?" The honest answer is that the tmux session namespace is
  host-global and not ours to close, so claiming that wall would be the
  DESIGN section-5 "never" trap. What CAN move is the proof: record
  ownership at MINT (attempt identity + the pane's pid/start-time, which
  no unprivileged process can forge) instead of inferring it at
  observation from a process name. Foreign then means absent-from-the-
  ledger, and the 2.1.220 fingerprint edge dissolves with it.

  ts-wf-messaging — "we'll also need cross session comms/messaging?"
  Recorded rather than built, because its carrier is the SAME durable
  state ts-wf-stage-artifacts and ts-dispatch-ownership-mint need;
  building a messaging channel on its own storage would fork that state
  three ways before it exists once.

ts-dispatch-redispatch updated: U1 is its fix, and the resume-vs-fresh
handback is resolved fresh-per-attempt with the reason recorded — a
resumed session inherits the prior attempt's context, which is exactly
what ts-wf-belt-refusals rules out for NeedsRework. The two rows would
otherwise disagree about the same question. Status stays NOT done: merge
is not done, only a verdict moves it.

Receipts, all green by execution against the merged tree:
  - witness_admission_deferred_rows_have_consumers (the exact CI check) ok
  - 15-witness battery incl. the byte-oracle digest parity, unmoved by
    main's seven commits, and the route-count pin at 13
  - roadmap_page_keystone_holds — the brief-budget census admits both new
    rows under the 100-word wall
  - roadmap_authority_witnesses; ROADMAP.md regenerated, both rows
    rendering under their parents

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian <briansrls@MacBook-Pro.local>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant