Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
40 commits
Select commit Hold shift + click to select a range
868b9c3
fix(lint): the name gate reaches the plugin surfaces the artefact ships
REPPL Sep 28, 2026
fbbd0d7
fix(implement): every backoff the log holds names its reason and minutes
REPPL Sep 28, 2026
efe9aa6
fix(report): an unreadable report in the inbox still names its sender
REPPL Sep 28, 2026
39c3c04
chore: defer five fidelity-drift records as rulings owed to the produ…
REPPL Sep 28, 2026
aa64797
chore: resolve iss-2609231206207995 — the brief's last epic was rewor…
REPPL Sep 28, 2026
c364ea7
chore: resolve iss-2609261457358637 — the name gate reaches the shipp…
REPPL Sep 28, 2026
cdce323
chore: resolve iss-2609231206196407 — every backoff names its reason …
REPPL Sep 28, 2026
d3dddfb
chore: resolve iss-2609240133234244 — an unreadable report names its …
REPPL Sep 28, 2026
9a33bdc
feat(launch): the manifest lockstep check gets its own front door
REPPL Sep 28, 2026
a2101b7
chore: resolve iss-2609261423222935 — the lockstep check has a front …
REPPL Sep 28, 2026
19b98f3
test(scanner): pin every answer ProbeIdentity gives before its git re…
REPPL Sep 28, 2026
1683ed2
perf(scanner): read the caller's identity in one git exec, not four
REPPL Sep 28, 2026
278b19b
chore: resolve iss-2609281546130900 — the identity probe spends one g…
REPPL Sep 28, 2026
4998c97
fix(lint): hold the name gate to the payload's own include list
REPPL Sep 28, 2026
0fb19ec
fix(implement): log a joining session's backoff and say when one goes…
REPPL Sep 28, 2026
0ea3984
chore: capture the macOS check flushing every test write and starting…
REPPL Sep 28, 2026
7bbf752
perf(fsutil): let an opted-in test binary skip the flush to stable st…
REPPL Sep 28, 2026
0b621ad
test(banlist): build the name-root fixtures from the config
REPPL Sep 28, 2026
94d311f
ci: start the slowest race packages first
REPPL Sep 28, 2026
dc1d841
chore: resolve iss-2609281715083637 — tests skip the flush and the sl…
REPPL Sep 28, 2026
352b21e
fix(ahoy,release): take a file lock on the repo-local rewrites
REPPL Sep 28, 2026
391d5ee
chore: resolve iss-127 — repo-local rewrites take a file lock
REPPL Sep 28, 2026
9d00f6d
docs(intent): record the fidelity audit of itd-63, itd-26092121371166…
REPPL Sep 28, 2026
10b9a31
fix(ahoy): keep a rules.json written after detection
REPPL Sep 28, 2026
6562907
chore: resolve iss-2609281931185016 — rules skeleton keeps a file wri…
REPPL Sep 28, 2026
d6143aa
merge: land ci/speed-flush-order (ciSpeed) into the integration branch
REPPL Sep 28, 2026
f442138
merge: land fix/lmw-repo-local-locks (lmw127) into the integration br…
REPPL Sep 28, 2026
82c3f74
merge: land fix/drain-fidelity-drift (drainDrift) into the integratio…
REPPL Sep 28, 2026
64534aa
merge: land chore/audit-v012-intents (audits10) into the integration …
REPPL Sep 28, 2026
5a7d45d
test(fsutil): the flush gate names a datasync, a raw fsync and an ali…
REPPL Sep 28, 2026
592cfa2
chore: recalibrate the reading windows at the integration tip
REPPL Sep 28, 2026
b6fab81
merge: bring main (#741) into the integration branch
REPPL Sep 29, 2026
3a282f5
merge: land perf/scanner-identity-one-exec (scanFold, 278b19bba)
REPPL Sep 29, 2026
15dc634
chore: recalibrate the reading windows at the integration tip
REPPL Sep 29, 2026
92c2a41
chore: capture iss-2609290518278152 — a concurrent rewrite makes a de…
REPPL Sep 29, 2026
b342b2b
fix(fsutil): re-vet a guarded file replaced between its vetting and i…
REPPL Sep 29, 2026
ea6fed3
chore: resolve iss-2609290518278152 — a guarded read re-vets a benign…
REPPL Sep 29, 2026
7dda770
merge: bring main (#746) into the integration branch
REPPL Sep 29, 2026
24e7850
merge: land fix/concurrent-config-read (flakeOracle, ea6fed33d)
REPPL Sep 29, 2026
352d087
chore: recalibrate the reading windows at the integration tip
REPPL Sep 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 7 additions & 7 deletions .abcd/config/reading-presets.json
Original file line number Diff line number Diff line change
Expand Up @@ -133,9 +133,9 @@
],
"window": {
"tokens_est": 400000,
"measured_tokens_est": 387939,
"measured_bytes": 1493566,
"measured_at": "db30f1a10992df69d1253260a88065884a21937d"
"measured_tokens_est": 388426,
"measured_bytes": 1495442,
"measured_at": "3a282f5fee1dfb46da002e41b9193ab8a1ca2ce0"
}
},
"comparative": {
Expand Down Expand Up @@ -216,10 +216,10 @@
"test"
],
"window": {
"tokens_est": 1370000,
"measured_tokens_est": 1353945,
"measured_bytes": 5212690,
"measured_at": "db30f1a10992df69d1253260a88065884a21937d"
"tokens_est": 1380000,
"measured_tokens_est": 1358267,
"measured_bytes": 5229331,
"measured_at": "24e78506b9e7d4471d9c9110d6217e6e5f2c4b88"
}
}
}
Expand Down
20 changes: 17 additions & 3 deletions .abcd/development/brief/04-surfaces/04-launch.md
Original file line number Diff line number Diff line change
Expand Up @@ -66,6 +66,7 @@ refuses to stage one and the archive render refuses outright.
| Verb | Bucket | Status |
|---|---|---|
| `archive` | gate | shipped |
| `manifests` | gate | shipped |
| `receipts` | gate | shipped |
| `scaffold` | — | shipped |
| `ship` | gate | shipped |
Expand Down Expand Up @@ -592,8 +593,12 @@ read-only lockstep checker proves this over the path list adr-20 records, and a
half-state is drift. The cut's bump step runs it against the staged artefact at
the **public** polarity and refuses to publish on drift; the **dev** polarity
runs in `dry-run` over the working tree, asserting the committed manifests carry
no version key. The checker has no bypass flag, and adr-20 records that
a dirty-tree override must not bypass manifest consistency.
no version key. The checker also has a front door of its own, read-only, over
any tree a person holds at the polarity they choose (a marketplace install or a
release source archive at public, a checkout at dev), exiting 0 consistent, 1
drift with a line per field, and 2 when an input cannot be read. The checker
has no bypass flag, and adr-20 records that a dirty-tree override must not
bypass manifest consistency.

The release commit message format — carrying the bump tier and its reason — is
a **full-cut design target** (itd-72). The shipped cut never
Expand Down Expand Up @@ -777,7 +782,7 @@ _Generated from the command tree; a drift test fails `go test` when this appendi

### `abcd launch`

Sub-verbs: `abcd launch archive`, `abcd launch receipts`, `abcd launch scaffold`, `abcd launch ship`, `abcd launch smoke-pages`.
Sub-verbs: `abcd launch archive`, `abcd launch manifests`, `abcd launch receipts`, `abcd launch scaffold`, `abcd launch ship`, `abcd launch smoke-pages`.

| Flag | Type |
|---|---|
Expand All @@ -797,6 +802,15 @@ Sub-verbs: none.
| `--tag` | string |
| `--verify` | bool |

### `abcd launch manifests`

Sub-verbs: none.

| Flag | Type |
|---|---|
| `--root` | string |
| `--tree` | string |

### `abcd launch receipts`

Sub-verbs: none.
Expand Down
5 changes: 4 additions & 1 deletion .abcd/development/brief/04-surfaces/20-banlist.md
Original file line number Diff line number Diff line change
Expand Up @@ -77,7 +77,10 @@ markdown, with `exempt_paths` excusing a historical tree as it does under
blocks, which the rest of the family skips by default: a fenced example is not
prose, but a fence is published as readily as prose, so an entry that means to
skip fences declares `skip_code_fences: true`. This repository's `name_roots` are `.abcd`, `AGENTS.md`,
`.github/CONTRIBUTING.md` and `scripts`, and its `exempt_paths` excuse the
`.github/CONTRIBUTING.md`, `scripts` and every other surface the shipped artefact
carries (`commands`, `agents`, `hooks`, `.claude-plugin`, `LICENSE` and
`.gitignore`; `docs` and `README.md` are `roots`), a coverage a test holds to
the launch payload's own include list, and its `exempt_paths` excuse the
configuration itself (whose entries spell every ban), the research data and the
review archive.

Expand Down
15 changes: 13 additions & 2 deletions .abcd/development/brief/04-surfaces/27-implement.md
Original file line number Diff line number Diff line change
Expand Up @@ -124,7 +124,14 @@ check verdict reports the count (`agents_alive`) beside the ceiling
outside the log — is invisible to the count, which is why the run's no-fork
rule stays the discipline for that half (iss-2609240646542516); a run that went
over anyway says so with a `ceiling_overrun` line. On a refused claim the
second session also logs a `backoff` with its reason and minutes.
second session also logs a `backoff` with its reason and minutes, the minutes
being what the attempt spent, measured from its start; a run state locked past
the lock's timeout by another session's change is contention too, and the second
session's `backoff` from it carries `on: run_state` and the minutes it waited. A
second session whose join meets the lock has no record yet, so the role it is
joining with places the line; a session that never joined has no role to place
it by, and the refusal says the backoff went unlogged. The append takes no lock,
so that line reaches the log while the lock is held.

Every bound keys on the role in the session's record, which is the session's
own statement: the release refusal, like the others, rests on a cooperative,
Expand Down Expand Up @@ -157,7 +164,11 @@ twin does, so two writers each land whole lines and a log leaf planted as a link
onto a claim file appends nothing. The session, window,
claim and load events are refused here: they are written by their own sub-verbs,
so the log cannot record a claim the run state does not hold, or a load warning
the check did not give.
the check did not give. A hand-logged `backoff` names its `reason` and the
`minutes` it spent (a number no smaller than zero), or it is refused with nothing
written: contention the verb cannot see, such as the merge queue, reaches the
comparison only this way, and a backoff with neither would count as one that
cost nothing for no reason.

An event missing a field the report reads is refused when it is written, naming
the field, rather than found missing afterwards (iss-2609240646555891): a
Expand Down
6 changes: 5 additions & 1 deletion .abcd/development/brief/04-surfaces/30-inbox.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,11 @@ A waiting file this abcd cannot read is listed as unreadable with its reason,
never dropped: a report written to a later template version names the version;
a file that is not a report, is over the size bound, is not a regular file, or
whose sender key disagrees with its file name says so. Its id and sender key come
from the file name.
from the file name. Its sender's name comes from the envelope alone, which is
abcd's own writing and is read apart from the reporter's block: when the block
names `sender_key` once, equal to the file name's key, and `sender_name` once,
in the shape a filing writes, the listing names the sender beside the key;
otherwise it names the key alone.

Every value a report carries is another repository's words, and every front
door sanitises it before it reaches the terminal. The list and show both reach
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -196,5 +196,63 @@ None stated.

## Audit Notes

<!-- abcd-review: OWED receipt=rcp-8a6673e9bc8a -->
Fidelity review OWED (receipt rcp-8a6673e9bc8a).
<!-- abcd-review: INGESTED receipt=rcp-8a6673e9bc8a -->
Fidelity review — receipt rcp-8a6673e9bc8a (verifier intent-auditor claude-fable-5-1).

Provenance: intent-auditor@claude-fable-5-1 · rubric_hash sha256:effa65b3e9e88ff29433b443ec2be159522a8b0b71cf1434526514aa61edb13e · prompt_hash sha256:8c00566b452e24b3cfccc53a3665ee1d434077813fff058646e8b147a7313dc8
Input attestations: tree:ceb4b6dbb97622bddf2401c91f9f808ed05060a0 (origin/main; internal/core/identity/{identity,establish,toolidentity}.go, internal/core/ahoy/{detect,identity_establish}.go, internal/surface/cli/cli.go)@-;

Acceptance rollup: MET 4 · MET_WITH_CONCERNS 1 · NOT_MET 0 · INCONCLUSIVE 0

Per-criterion verdicts:
- ac-1 — MET: an author mismatch against the pin is the required git_identity.mismatch gap; the apply step proposes the pin (else the global identity, disk only), asks Confirm at a terminal and writes repo-local user.name/user.email only on a yes; TestStepGitIdentity_ProposesPinAndWritesOnlyOnConfirm and TestStepGitIdentity_DeclineWritesNothing pass at BASE
evidence: internal/core/ahoy/detect.go:336 — "ID: MismatchGapID, Category: ConfigChange, Scope: "repo","
evidence: internal/core/ahoy/identity_establish.go:76 — "if !a.prompter.Confirm("Commit to this repository as " + who + ", " + prop.From + "? (sets user.name and user.email in this repository's .git/config only)") {"
evidence: internal/core/identity/establish.go:25 — "func Propose(root string) (Proposal, bool, error)"
evidence: internal/core/ahoy/identity_establish_test.go:142 — "func TestStepGitIdentity_ProposesPinAndWritesOnlyOnConfirm"
- ac-2 — MET: Check resolves the committer through EffectiveCommitter (GIT_COMMITTER_* first, then committer.*/user.*), compares it with the author and the pin, and ahoy raises git_identity.committer; TestCheck_CommitterEnvOverrideDiverges, TestCheck_CommitterConfigDiverges and TestDetectGitIdentity_CommitterDiverges pass at BASE
evidence: internal/core/identity/identity.go:371 — "committer, err := EffectiveCommitter(root)"
evidence: internal/core/identity/identity.go:403 — "func committerDivergence(pin Pin, pinned bool, author, committer Effective) (bool, string)"
evidence: internal/core/ahoy/detect.go:364 — "ID: CommitterGapID, Category: ConfigChange, Scope: "repo","
evidence: internal/core/identity/committer_test.go:60 — "func TestCheck_CommitterEnvOverrideDiverges"
- ac-3 — MET: with no TerminalPrompter reporting a tty the step refuses before asking, writes nothing and records the reason, and --yes is refused the same way; the CLI's stdinPrompter reports its tty; TestStepGitIdentity_NoTerminalFailsClosed asserts no question, no config change and the refusal text, and TestAhoyInstallPipedAnswersNeverRewriteTheIdentity covers the front door
evidence: internal/core/ahoy/identity_establish.go:53 — "if !atTerminal(a.prompter) {"
evidence: internal/core/ahoy/identity_establish.go:49 — "if a.autoYes {"
evidence: internal/surface/cli/cli.go:3782 — "func (p *stdinPrompter) AtTerminal() bool { return p.tty }"
evidence: internal/core/ahoy/identity_establish_test.go:189 — "func TestStepGitIdentity_NoTerminalFailsClosed"
evidence: internal/surface/cli/ahoy_identity_gate_test.go:54 — "func TestAhoyInstallPipedAnswersNeverRewriteTheIdentity"
- ac-4 — MET_WITH_CONCERNS: detection is delivered: IsToolIdentity reads the gate's own tool-identities list plus the structural bot and noreply signals, Check sets AuthorIsTool/CommitterIsTool, and ahoy raises the required git_identity.tool gap whose hint names the runner record; concern: the criterion defers establishment to iss-2608210932052003, which is still in issues/open/, so a routine's identity is established by nothing abcd ships today and the deferral has no delivered counterpart to verify against
evidence: internal/core/identity/toolidentity.go:42 — "func IsToolIdentity(role Role, name, email string) bool {"
evidence: internal/core/identity/identity.go:378 — "res.AuthorIsTool = eff != (Effective{}) && IsToolIdentity(RoleAuthor, eff.Name, eff.Email)"
evidence: internal/core/ahoy/detect.go:374 — "ID: ToolIdentityGapID, Category: ConfigChange, Scope: "repo","
evidence: internal/core/ahoy/identity_establish_test.go:106 — "func TestDetectGitIdentity_ToolIdentity"
evidence: .abcd/work/issues/open/iss-2608210932052003-abcd-launches-autonomous-routines.md:1 — "open/"
- ac-5 — MET: the only write is git config --local on the repository's own .git/config under a scrubbed environment, reached solely after Confirm; an outranking GIT_*_ override or author.*/committer.* key makes the step name what to unset instead of writing; TestStepGitIdentity_EnvOverrideIsNotRewritten and TestStepGitIdentity_DeclineWritesNothing pass at BASE
evidence: internal/core/identity/establish.go:83 — "cmd := exec.Command("git", "-C", root, "config", "--local", kv[0], kv[1])"
evidence: internal/core/ahoy/identity_establish.go:71 — "if len(over) > 0 {"
evidence: internal/core/ahoy/identity_establish_test.go:248 — "func TestStepGitIdentity_EnvOverrideIsNotRewritten"
evidence: internal/core/ahoy/identity_establish_test.go:169 — "func TestStepGitIdentity_DeclineWritesNothing"

Gap audit:
- honoured:
- detect here, establish at launch: the gate detects and proposes, and names the runner record for a routine (decision 1)
evidence: internal/core/ahoy/identity_establish.go:54 — "An autonomous routine's runner sets the human identity before its first commit (" + routineRunnerRecord + ")"
- the proposal chain is disk-only, pinned then global, no gh fallback (decision 2, adr-38)
evidence: internal/core/identity/establish.go:20 — "Propose returns the identity to offer: the committed pin, else the global git // identity"
- the committer is resolved env-first then config, not through git var, so StatusUnset survives (open question 1)
evidence: internal/core/identity/identity.go:278 — "func EffectiveCommitter(root string) (Effective, error)"
evidence: internal/core/identity/committer_test.go:143 — "func TestCheck_UnsetSurvivesTheCommitterPath"
- doctor shares the detector: detectGitIdentity runs inside Detect, which every read-only mode renders
evidence: internal/core/ahoy/detect.go:96 — "gaps = append(gaps, detectGitIdentity(abs)...)"
- a forge committer (GitHub < noreply@github.com>) is not read as a tool, matching the attribution gate's role asymmetry
evidence: internal/core/ahoy/identity_establish_test.go:126 — "func TestDetectGitIdentity_ForgeCommitterIsNotATool"
- the plugin page relays the four identity gaps and the person-only answer
evidence: commands/ahoy.md:169 — "(`git_identity.mismatch`, `git_identity.unset`, `git_identity.committer`, `git_identity.tool`)"
- the un-pinned repo's pin adoption stays a prompt-only step and refuses a machine identity
evidence: internal/core/ahoy/apply.go:433 — "if identity.IsToolIdentity(identity.RoleAuthor, eff.Name, eff.Email) {"
- diverged: (none)
- missing:
- establishing a routine's human identity before its first commit is verified against the runner: the runner record iss-2608210932052003 is still open, so the establish half the press release promises for autonomous routines has no shipped counterpart
evidence: .abcd/work/issues/open/iss-2608210932052003-abcd-launches-autonomous-routines.md:1 — "open/"
evidence: internal/core/ahoy/detect.go:377 — "An autonomous routine has no one to ask: whatever launches it sets the human identity before the first commit"
<!-- abcd-review-end receipt=rcp-8a6673e9bc8a -->
Loading
Loading