Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
69 commits
Select commit Hold shift + click to select a range
da90929
chore: capture iss-2609261647358395 — a JSON escape hides tokens and …
REPPL Sep 26, 2026
c55ae5e
fix(scanner): read a line's JSON-escape layers as decoded views
REPPL Sep 26, 2026
4013610
fix(scanner): read the Windows home spelling in the one home matcher
REPPL Sep 26, 2026
7babc8d
fix(scanner): keep a short real name standing in person metadata on b…
REPPL Sep 26, 2026
7909f8b
chore: re-defer iss-96 past v0.11.0 — the entropy residue owes a ruling
REPPL Sep 26, 2026
b605146
chore: capture three siblings the scanner-identity lane leaves open
REPPL Sep 26, 2026
69b3725
chore: resolve iss-2609261647358395 — JSON escapes no longer hide values
REPPL Sep 26, 2026
adc37e4
chore: resolve iss-2609251639263391 — the solidus escape reads as a s…
REPPL Sep 26, 2026
5e8cf3d
chore: resolve iss-2609251639261103 — the Windows home spelling is a …
REPPL Sep 26, 2026
aaf4dd3
chore: resolve iss-2609090934372160 — a short name in author metadata…
REPPL Sep 26, 2026
ef3a963
fix: never take the home directory as a session's repo root
REPPL Sep 26, 2026
b01bcd5
chore: resolve iss-2609020219198779 — the home is never a session's r…
REPPL Sep 26, 2026
ec5ca74
fix: say what a refused root still reads at the working directory
REPPL Sep 26, 2026
33ceaa1
chore: resolve iss-2609251522588539 — the refusal says what it still …
REPPL Sep 26, 2026
aea2ae7
fix: name the bundled guardrail entries an override withholds
REPPL Sep 26, 2026
1418956
chore: resolve iss-174 — a withheld bundled guardrail is named on eve…
REPPL Sep 26, 2026
719803c
chore: defer iss-2609020219265817 past v0.11.0 on the ruling it owes
REPPL Sep 26, 2026
5cc6d1f
docs(record): record the rules-loader lane's rulings and the one stil…
REPPL Sep 26, 2026
b97efc0
chore: capture the review-drainS2 home-identity and refusal-note find…
REPPL Sep 26, 2026
c742b4f
fix(rules): recognise the home by file identity, not by spelling
REPPL Sep 26, 2026
7b22cd1
fix(rules): the refusal note asks about .abcd the way the loader does
REPPL Sep 26, 2026
2cfc3eb
chore: resolve iss-2609261753285273 — the home is recognised by file …
REPPL Sep 26, 2026
13357ec
chore: resolve iss-2609261753290536 — the refusal note Lstats .abcd l…
REPPL Sep 26, 2026
33715d8
fix(scanner): read escaped spellings of the home in the literal backstop
REPPL Sep 26, 2026
930f57e
chore: resolve iss-2609261659041553 — the home backstop reads escaped…
REPPL Sep 26, 2026
01295f8
chore: capture iss-2609261811321435 — a meter fixture lost its unicod…
REPPL Sep 26, 2026
d8f5252
test(scanner): give the unicode-escaped meter fixture its escapes back
REPPL Sep 26, 2026
ce3eb8b
chore: resolve iss-2609261811321435 — the meter fixture spells its es…
REPPL Sep 26, 2026
a8f0af6
fix(reading): drop a CRLF pair whole when the redaction runs to the end
REPPL Sep 26, 2026
ae0b1fb
chore: resolve iss-2609251600019863 — a CRLF pair is dropped whole at…
REPPL Sep 26, 2026
9088559
fix(reading): refuse a nested mapping behind every block indicator
REPPL Sep 26, 2026
b837544
chore: resolve iss-2608301237450573 — nested mappings refused behind …
REPPL Sep 26, 2026
85f1cff
fix(reading): state only what is known when refusing a frontmatter key
REPPL Sep 26, 2026
1284c2d
chore: resolve iss-2608301421381157 — the escaped-key refusal states …
REPPL Sep 26, 2026
ef5f1ab
fix(reading): list only the parked runs no ingest has given an outcome
REPPL Sep 26, 2026
051fd04
chore: resolve iss-2608311621412224 — staged runs lists only runs awa…
REPPL Sep 26, 2026
facc64d
fix(lint): read committed lines in the scanner's decoded spellings
REPPL Sep 26, 2026
6d3ccf1
test(scanner): pin the footer after a decoded line break in a transcript
REPPL Sep 26, 2026
3983396
docs(brief): the privacy rule reads the scanner's decoded spellings
REPPL Sep 26, 2026
c6514ce
chore: resolve iss-2609261658553101 — the lint rules read decoded spe…
REPPL Sep 26, 2026
dd4f0e9
chore: capture iss-2609261827066511 — UTF-16 text on bytes is never read
REPPL Sep 26, 2026
75ce1ac
fix(scanner): read byte-order-marked UTF-16 text in the byte scan
REPPL Sep 26, 2026
4f2f460
chore: resolve iss-2609261827066511 — the byte scan reads marked UTF-…
REPPL Sep 26, 2026
b114e4c
chore: defer the EXIF and PDF-string residues of the UTF-16 byte scan
REPPL Sep 26, 2026
359c07e
chore: capture iss-2609261900095459 — an alias used as a frontmatter …
REPPL Sep 26, 2026
17e795d
fix(reading): refuse a YAML alias wherever a frontmatter key can stand
REPPL Sep 26, 2026
70ae3ad
chore: capture iss-2609261905354450 — the status render's two run pro…
REPPL Sep 26, 2026
97fa2de
fix(reading): probe every staged run through the one repository root
REPPL Sep 26, 2026
398b0ba
chore: resolve iss-2609261900095459 — an alias in a key position is r…
REPPL Sep 26, 2026
0879fbb
chore: resolve iss-2609261905354450 — the status render probes every …
REPPL Sep 26, 2026
3eaeb8b
chore: capture the review-drainS3 follow-ups — hook escapes, astral r…
REPPL Sep 26, 2026
1b4d15c
fix(scanner): let a surrogate pair continue a UTF-16 run
REPPL Sep 26, 2026
453ce8d
chore: resolve iss-2609261909101409 — a UTF-16 run reads past an emoji
REPPL Sep 26, 2026
76d3598
docs(scanner): say the escape-run cap leans on the JSON view's union
REPPL Sep 26, 2026
d010efe
fix(scanner): read a PDF hex text string through the UTF-16 view
REPPL Sep 26, 2026
5e1020e
chore: resolve iss-2609261909108726 — the byte scan reads PDF hex str…
REPPL Sep 26, 2026
e86097c
fix(hooks): the name guard reads the decoded spellings of staged text
REPPL Sep 27, 2026
d7964cf
chore: resolve iss-2609261909106167 — the name guard reads escaped sp…
REPPL Sep 27, 2026
153a124
merge: land lanes drainS1 + drainS3 (fix/drain-scanner-siblings d7964…
REPPL Sep 27, 2026
7a3e022
docs(record): name the Default/All allowlist limit in iss-26092516392…
REPPL Sep 28, 2026
19d8f96
merge: land lane drainS2 (fix/drain-rules-loader 13357ecb7)
REPPL Sep 28, 2026
ecbaf85
merge: land lane drainRd (fix/drain-reading-bugs 0879fbb4d)
REPPL Sep 28, 2026
1dedc02
chore: capture the name guard's escaped-backslash layer and its long-…
REPPL Sep 28, 2026
5e7929f
chore: recalibrate the reading windows at the integration tip
REPPL Sep 28, 2026
5c5a859
fix(hooks): the name guard reads escape-spelled backslashes, in linea…
REPPL Sep 28, 2026
975dc10
chore: resolve the name guard's escaped-backslash layer and its long-…
REPPL Sep 28, 2026
33823ea
merge: bring main (#730, #731, #732) into the integration branch
REPPL Sep 28, 2026
35483ff
merge: land drainS3's fix round (fix/drain-scanner-siblings 975dc1026)
REPPL Sep 28, 2026
0671dcc
chore: recalibrate the reading windows at the re-merged integration tip
REPPL Sep 28, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 9 additions & 9 deletions .abcd/config/reading-presets.json
Original file line number Diff line number Diff line change
Expand Up @@ -61,9 +61,9 @@
],
"window": {
"tokens_est": 1300000,
"measured_tokens_est": 1279461,
"measured_bytes": 4925925,
"measured_at": "e1344b4c3a3d7a27382964d4644a3e7cfff0de81"
"measured_tokens_est": 1280867,
"measured_bytes": 4931339,
"measured_at": "35483ff77ca726d81633625eaa816cae14b38d73"
}
},
"entailment": {
Expand Down Expand Up @@ -133,9 +133,9 @@
],
"window": {
"tokens_est": 390000,
"measured_tokens_est": 381285,
"measured_bytes": 1467950,
"measured_at": "e1344b4c3a3d7a27382964d4644a3e7cfff0de81"
"measured_tokens_est": 382072,
"measured_bytes": 1470980,
"measured_at": "35483ff77ca726d81633625eaa816cae14b38d73"
}
},
"comparative": {
Expand Down Expand Up @@ -217,9 +217,9 @@
],
"window": {
"tokens_est": 1310000,
"measured_tokens_est": 1288496,
"measured_bytes": 4960713,
"measured_at": "e1344b4c3a3d7a27382964d4644a3e7cfff0de81"
"measured_tokens_est": 1289903,
"measured_bytes": 4966127,
"measured_at": "35483ff77ca726d81633625eaa816cae14b38d73"
}
}
}
Expand Down
2 changes: 1 addition & 1 deletion .abcd/development/brief/04-surfaces/16-lint.md
Original file line number Diff line number Diff line change
Expand Up @@ -142,7 +142,7 @@ iss-2608231000561060.
| `conventions-router` | error | `AGENTS.md` present at the repo root |
| `decision-durability` | warn | a committed `.abcd/work/DECISIONS.md`; decisions not living only in the gitignored layer |
| `docs-currency` | warn | reuses the docs-lint engine where `docs/` exists, and says so where it cannot: a repo with a `docs/` tree but no docs-lint configuration, and a configuration that will not load, each raise a finding against `.abcd/docs-lint.json` rather than passing quietly |
| `privacy-hygiene` | error (network-identifier findings mapped from a scanner `warn`/`info` land as `warn`) | three leak classes on any tracked text line: absolute local paths in committed files, real network identifiers, and the harness-leak pair the outbound policy bans everywhere (a live agent-session URL, and a tool's own "generated with" footer). The fix names reserved documentation values (RFC 5737/3849/2606/7042, or a persona-derived device name), and an `abcd-lint:allow` line waiver is honoured (the `abcd-audit:allow` spelling too). The network severities come from the merged scanner configuration, so a repo that raises one in `.abcd/config/pii.json` is honoured, and an override that cannot be read is itself an `error` finding saying the scan fell back to the built-in severities. Two findings report what was *not* read rather than a leak: a tracked text file over the 4 MiB scan cap, and one that could not be opened. Binary files are skipped silently |
| `privacy-hygiene` | error (network-identifier findings mapped from a scanner `warn`/`info` land as `warn`) | three leak classes on any tracked text line: absolute local paths in committed files, real network identifiers, and the harness-leak pair the outbound policy bans everywhere (a live agent-session URL, and a tool's own "generated with" footer). The fix names reserved documentation values (RFC 5737/3849/2606/7042, or a persona-derived device name), and an `abcd-lint:allow` line waiver is honoured (the `abcd-audit:allow` spelling too). Each line is read as written and in the scanner's decoded spellings of it (`scanner.DecodedViews`: its percent and JSON-escape views), so a home path, an address or a harness-leak shape written behind an escape in a JSON fixture, export or transcript is the finding its plain spelling is; the waiver is read on the line as written, and the record/docs `harness_leak` rule reads the same spellings. The network severities come from the merged scanner configuration, so a repo that raises one in `.abcd/config/pii.json` is honoured, and an override that cannot be read is itself an `error` finding saying the scan fell back to the built-in severities. Two findings report what was *not* read rather than a leak: a tracked text file over the 4 MiB scan cap, and one that could not be opened. Binary files are skipped silently |
| `site-gates` | warn | where `.abcd/site.json` declares a site: renders it into a fresh temporary directory outside the repository, runs the website's gates over it (the site target's, [`22-site.md`](22-site.md)), and removes it, so the lint still writes nothing in the repository. Each gate failure is one finding, filed against the source span it names; a composition that cannot be rendered is a finding against `.abcd/site.json` rather than an aborted lint. Warn, as `docs-currency` is, because the authoritative gate is the site target's exit 1 and re-raising it as an error would double-gate one check |
| `identity-positioning` | warn | every registered surface still carries the canonical identity block's tagline (and pitch, where required), and every registered surface can still be found: a surface whose locator matches nothing is its own finding, because drift there would go unseen. A registry or identity block that cannot be read is reported rather than passed. Gated on `.abcd/positioning.json` being present on disk, and per-repo upgradeable to `error` (see [`19-identity.md`](19-identity.md)) |

Expand Down
19 changes: 19 additions & 0 deletions .abcd/development/brief/04-surfaces/20-banlist.md
Original file line number Diff line number Diff line change
Expand Up @@ -147,6 +147,25 @@ around: a content line beginning `++`, a blob containing a NUL, a committed
reading. Binary blobs are scanned like anything else, because a name in a binary
file is in history just the same.

Every staged line that holds a JSON string escape (`\u00eb`, `\/`) or a
percent-encoded byte (`%C3%AB`) is also read **decoded**, and a pattern matching
either spelling refuses the commit. An escape changes the bytes a name is written
in without changing the name, plain ASCII letters included, and a JSON
transcript, export or fixture is where such spellings live. The decoded readings
are the two the scanner's redactors read beside the text as written: the JSON
escape layers and the percent view. The guard's reading is deliberately the wider
one: a run of backslashes of any length before an escape decodes as one escape,
so a JSON string nested inside another decodes all its layers at once, and a
chain of `%25` layers before two hex digits decodes to the byte they name. A
decoded reading is itself read again for the escapes it still holds, since a
backslash or a percent sign that an escape spells (`%5C`) opens an escape of its
own, for as many layers as the scanner reads a JSON line through; the hook
declares that bound once and a test holds it equal to the scanner's. The
decode runs in the hook itself, in `awk` and the shell's `printf`, not in the
abcd binary, because the guard holds before abcd is built and in every clone the
dispatcher runs it in. It adds readings and replaces none: the text as written
is still read in full.

On a match the guard refuses the commit and names **the key alone**. The matched
string and the pattern never reach stdout, stderr, or a log — a refusal that
echoed the string would defeat the layer at the moment it worked — and the pattern
Expand Down
8 changes: 4 additions & 4 deletions .abcd/development/brief/04-surfaces/23-reading.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,10 +30,10 @@ a reading whose account of itself can be checked rather than believed.

Bare `abcd reading` is a third form and a **read-only status render**: the
assembler's version and schema number, the include and exclusion row counts, the
charter path, the position definitions the binary resolves, the staged runs, and
any orphaned ingest waiting to be swept. It writes nothing, and it is where an
operator reads what the instrument currently is before commissioning anything
through it.
charter path, the position definitions the binary resolves, the staged runs no
ingest has yet committed or refused, and any orphaned ingest waiting to be
swept. It writes nothing, and it is where an operator reads what the instrument
currently is before commissioning anything through it.

## The invocation carries no free text

Expand Down
39 changes: 28 additions & 11 deletions .abcd/development/brief/05-internals/03-configuration.md
Original file line number Diff line number Diff line change
Expand Up @@ -465,6 +465,16 @@ makes that grain more visible; finer-grained merging, detecting a repo file that
duplicates the user layer, and moving conventions out of per-project harness
memory are all recorded in itd-117 as follow-up questions.

**A withheld guardrail is named.** Because a list replaces the bundled list, an
override written before a release added an entry keeps withholding that entry.
For the three guardrail domains — `PII`, `COMMITTING` and `LOAD` — the load
compares every recall, alias and rule list an override set against the list the
running binary bundles. It names each bundled entry left out, and the file whose
list is in force, on stderr from `abcd rules` and from the hook on every prompt.
The effective set is unchanged. Restating the entry keeps it; leaving the field
out inherits the bundled list. The other bundled domains are conventions a
repository restates in its own words, so a replacement there is not reported.

## The rules root — which `.abcd/` governs a session

The rules, the hazard registry and the per-repo config are read from ONE resolved
Expand Down Expand Up @@ -492,11 +502,16 @@ second falls back to the `.git` marker, under two bounds:
| **ownership** | a marker root whose owner is not the caller. Shape alone is not a trust boundary: `git init` in a shared world-writable directory produces a genuine repository, and git's refusal on ownership is the same signal in that attack as in the legitimate foreign-uid case (iss-2609020259564193) | a declaration, once, per foreign-uid checkout |

A refused root is refused **loudly and fail-closed**: the session resolves to its
own working directory with no walk, the bundled rule defaults (under the user
layer, which is the caller's own) and bundled hazard registry stand in for the
repository's, and every front door prints one line naming
the refused directory, the two uids, and the exact command that re-admits it
own working directory with no walk, and every front door prints one line naming
the refused directory, the two uids, what the session reads instead, and the
exact command that re-admits it
([`../../principles/loud-staging.md`](../../principles/loud-staging.md)). The
refusal bounds the walk, not the working directory. From a directory with no
`.abcd/` of its own, the bundled rule defaults (under the user layer, which is
the caller's own) and the bundled hazard registry stand in for the repository's.
A `.abcd/` at the working directory is still read, so a session started at the
refused root reads that root's configuration, and the line says so rather than
promising the defaults. The
ownership bound applies only to the git-refused fallback: where git answers, the
toplevel it named stands whoever owns it, because that is a repository git itself
vouched for.
Expand All @@ -521,13 +536,15 @@ directory, and
[adr-46](../../decisions/adrs/0046-persistence-never-weakens-the-verification-posture.md)
treats home write as the ownership root.

One residual stays open and recorded rather than assumed shut:
**iss-2609020219198779**, the user scope when the home directory is itself a git
working tree. The toplevel for a session in a non-repo directory beneath such a
home is the home, so the user-scope `.abcd` governs it as the repo root too — its
`rules.json` as the repo layer as well as the user layer, and its `guard.json` and
`config.json` with it; closing it needs a decision on whether a home-directory
toplevel is a legitimate repo-scope root.
**The home directory is never a repo root.** Its `.abcd/` is the user layer, and
a home that is itself a git working tree (dotfiles in the home) is not thereby a
project. The walk passes over the home, and a toplevel that is the home resolves
like a directory outside any repository — the working directory, no walk — when
nothing below the home carries a `.abcd/`. So a session beneath such a home reads
`~/.abcd/rules.json` once, as the user layer, and never the home's `guard.json`
or `config.json` as a repository's own. A toplevel that contains the home — a
test harness that points `HOME` inside its checkout — stays the root, because it
is a repository git vouched for, and its own `.abcd/` stays its own.

## 1. Visibility-driven gitignore policy

Expand Down
2 changes: 1 addition & 1 deletion .abcd/development/plans/2026-08-15-plugin-user-safety.md
Original file line number Diff line number Diff line change
Expand Up @@ -90,7 +90,7 @@ once. Human-paired (the §4 gate is manual by design).
8. **[iss-148](../../work/issues/resolved/iss-148-guard-registry-coverage-gaps-found-while-wiring-itd-103-regi.md)**
(minor) — registry coverage gaps; every entry lands fixture-first per the
v0.5.0 plan's rule.
9. **[iss-174](../../work/issues/open/iss-174-rules-override-withholds-bundled-default-upgrades.md)**
9. **[iss-174](../../work/issues/resolved/iss-174-rules-override-withholds-bundled-default-upgrades.md)**
(minor) — a repo's rules override silently withholds bundled security
upgrades.

Expand Down
1 change: 1 addition & 0 deletions .abcd/work/DECISIONS.md
Original file line number Diff line number Diff line change
Expand Up @@ -2566,4 +2566,5 @@ together (the script's header says why there is no escape hatch).
- 2026-09-26 — Three departures the scribe lane (itd-2609020625402599, spc-2609020626045177) made from its closed spec, which its review found recorded only in code, the chapter or the lane report, recorded here (implementer of lane fix2-scribe, autonomous run A). First, the surface chapter is `04-surfaces/31-scribe.md`, not the `24-scribe.md` the spec names: row 24 is `decide`'s, taken before the lane landed, so the chapter took the next free row. The spec is closed and keeps its text; four open lanes claim row 31 (build, lab, source ledger and this one), so the integration step renumbers three of them. Second, the transcript store's check is `SessionSeparation(repoRoot, rootSHA)`, not the `SessionSeparation(rootSHA)` the spec names, because it reads through `history.List`, which takes the repository root to find a checkout's opt-in per-repo transcript store; the report is unchanged. Third, the scribe's context is assembled from the ledger as it stands in the working tree, uncommitted records included, while the intent's scope condition (cond-2609020626046719) says committed ledger content. The working-tree read is what the code does today and the chapter says so. Whether the condition or the code should move is not decided here: it is captured as iss-2609261056373310, a ruling owed.
- 2026-09-25 — itd-2609211913453478's acceptance criterion 4 ships under two readings the intent's scope line does not state. A glossary entry's `not_to_be_confused_with` passes when at least one member names a family row on the record-families page or the page itself, where the scope line says the field "may name only a family on the page"; the stricter reading would force nonsense pairs such as warm against intent, and the entries keep their real confusion pairs. The family-key rule (`record_family_key`, warn) reports a record frontmatter key only when the glossary already marks that word superseded or forbidden, so a brand-new grouping word with no row (the intent's own Mechanism case, e.g. an `initiative:` key) is not detected by construction, and the stores the page does not row (adr, rdi, dsp, rdg, adm, srp) are not reported. The six `grandfathered_at_phase` warnings on itd-20, 27, 28, 63, 69 and 72 are history and stay. Recorded for the product thinker to confirm or widen (autonomous run A, glossary lane review, orchestrator abcd-39).
- 2026-09-26 — The lab store is keyed `~/.abcd/lab/<root-sha>/<lab-id>/`, with one `index.jsonl` registry per root-sha lane beside the lab homes (lane implementer, autonomous run A, on review-lab's third finding against spc-2609212141418943 for itd-2609212137128014). This supersedes two recorded texts: the spec's literal `~/.abcd/lab/<lab-id>/` (scope item 1), and the 2026-08-31 lab-convention entry's hand-run keying `~/.abcd/lab/<timestamp>-<source-sha7>/` with a single top-level `~/.abcd/lab/index.jsonl`, whose stated divergence from root-sha keying is withdrawn. Why: the intent's scope condition keys the store "as the other machine-scoped stores are", and the worktree and transcript stores key on the repository's root commit, because a checkout moves, is renamed and is cloned twice on one machine while its root commit does none of that; a lab's identity is still its intention, carried by its id `lab-<yymmddHHMMSS>-<pin7>` (the UTC mint time and the pin), so several labs share one baseline inside one lane. The hand-run labs that predate the verb stay where they are, beside the root-sha lanes, and the verb neither reads nor writes them or the top-level registry, so no real lab is moved or migrated by the change. A later text naming `~/.abcd/lab/<lab-id>/` (the open spc-2609221011151661's `pairs.jsonl` among them) means the lab home inside its root-sha lane.
- 2026-09-26 — Three of the rules loader's security records close, and one stays owed to the product thinker (autonomous run A orchestrator's lane brief, taken by the implementer of lane drainS2). (1) The home directory is never a session's repo root (iss-2609020219198779, answering the owed question "is a home-directory git toplevel a legitimate config scope, or excluded outright?" as the brief rules it): its `.abcd/` is the user layer, so the root walk passes over the home and a toplevel that is the home resolves like a non-repo directory. The lane narrowed the brief's "or an ancestor of HOME": a toplevel that contains the home, the shape of a hermetic harness that points `HOME` inside its checkout, stays the root because git vouched for it and its own `.abcd/` is its own; only the stop at the home is removed. A session whose working directory is the home still reads a `.abcd/` there as the working directory's, the posture question recorded on 2026-09-25. (2) A bundled guardrail that an override withholds is named on every load (iss-174): for COMMITTING, LOAD and PII, each bundled recall keyword, alias or rule missing from a list an override set goes to stderr with the file whose list is in force, and the merge stays per field. The other bundled domains are left out because a repository restates them in its own words, and a note on every restatement would bury the one that matters. Still owed to the product thinker: whether security-bearing lists should union with the bundled entries or take a replace-versus-extend marker instead (itd-117's finer-grained-merging follow-up). (3) The foreign-uid refusal says what it still reads (iss-2609251522588539): the note, the configuration chapter and the install how-to now say that a `.abcd/` at the working directory is read, as AGENTS.md has since 0434d475. (4) iss-2609020219265817 is deferred past v0.11.0, not closed. Every CommonMark heading construct in a rule body (ATX on any line, the first line included, setext, and HTML h1-h6) can be closed only by a code-safe rendering that flattens legitimate structure, or by a fence-aware escaper that is complete only by enumeration and changes the raw text the model reads. So "escaped, fenced, or left to the line-start contract" is the product thinker's ruling.
- 2026-09-26 — The build loop's worktree store is keyed on the FULL root sha: a lane lives at `~/.abcd/worktrees/<root-sha>/<run-id>-<lane-id>` with the 40-hex root commit, the form the history, transcript and voyage stores use and the one the store's draft (itd-2609091014076309) specifies. The lanes of autonomous run A made by hand under the abbreviated key (`~/.abcd/worktrees/488a0aa9/<name>/`) are the pre-verb convention, not a second form of the store: the loop never reads or adopts a lane under that key, and those worktrees are retired with `git worktree remove` like any other (implementer of fix round fix2-loop2, autonomous run A, on item 4 of the loop2 review; spc-2609202134338445 piece 6).
Loading
Loading