v0.12.0 integration 24c: provider dispatch under DR5, the release retrospective, the doc-fidelity gate - #762
Merged
Merged
Conversation
…, lessons internal/core/reflect is the core of `/abcd:reflect <release-tag>` (phase 1 of 2: no front door yet). BuildSeed reads what a release tag shipped: each intent with its impact and its audit notes read as counts (rollup, gap audit, receipt), the intents without audit notes with the `abcd intent audit <itd-N>` offer, the unshipped intents whose target_release names the tag, the changelog section the cut composed, and the computed metrics (intents, verdict distribution, this tag's date and the previous tag's). It refuses a release that shipped no intent in the criterion's words, a malformed or unknown tag, and a tag that already has a retrospective. Write rebuilds the seed, asks for confirmation past unshipped targets, refuses an answer under the declared floor until its one follow-up is answered, and creates .abcd/development/retrospectives/<tag>/README.md exclusively inside a real-directory tree: frontmatter naming the release, the date, the intents and which audits fed it, links to the changelog section and each intent's audit notes (never copies), the four answered sections and the computed metrics. ReadLessons and RankLessons are embark's half (the top three lessons by term overlap with the brief's framing, through record/match, the rest as a list); Nudge is the cut's one line. Decision taken (technical facilitator's how, not in the record): which intents a tag shipped is read the way the cut reads it: the intents that reached shipped/ between the previous release tag and this one, less any stamped `shipped_in:` another release, plus any stamped with this one. The spec's scope 1 names only the stamp, but `shipped_in` is a migration field the cut never writes (changelog.Record.ShippedIn), so no intent names v0.7.0 or any later tag, and a stamp-only seed would refuse every current release as "no intent shipped", which is false. Checked on a clone of this repository: v0.10.0, v0.11.0 and v0.11.1 seed 9, 11 and 18 intents. The floor (spec scope 3) is declared as MinClauses 2 of MinClauseWords 3, or an answer made only of its heading's terms, or a blank one. Using record/match makes match.Terms, NewWeights and Overlap reached, so their stale lines leave the reach baseline; the writer joins the frontmatter delimiter allowlist. The six reflect names the reach audit reports (BuildSeed, Write, ParseAnswers, ReadLessons, RankLessons, Nudge) are wired in phase 2 and are deliberately not baselined. Refs: itd-24 Assisted-by: Claude:claude-opus-5-5
The core of the doc-fidelity gate over the brief (itd-60, spc-2609020903498198). Judge is pure: the command tree, the agent set, the brief's 04-surfaces chapters and a baseline in, a verdict out. Layer 1 derives the shipped surfaces (every verb, sub-verb and agent; hidden and moved spellings excluded) and refuses any no chapter names, before the reviewer is constructed. Layer 2 is the saved review, as ruled DR3: the delegated docs review records a verdict receipt labelled with the commit it read, and the gate finds it; a missing, stale, unreadable or inconclusive one refuses with "run the docs review first", and a HOLD refuses naming each false brief sentence. A public-doc sentence is reported and never refuses. The receipt is the release gate's VSA receipt, judged by the release gate's own reader: lint.CheckGateReceipt runs checkReceiptGate for one gate, with the failing entries it parsed handed back, so no second receipt reader exists. Assisted-by: Claude:claude-opus-5-5
The doc-fidelity gate's two enforcement points (itd-60), one entry point with two populations. `abcd spec close` runs it over the intents the close would ship, before anything moves, and refuses naming the undocumented surface, the false sentence, or "run the docs review first"; a --remainder close ships nothing and is not gated. The release cut (release.Emit, which `launch ship` runs at both its steps) runs it over every intent in the cut and refuses with a doc-fidelity refusal naming them; an empty population judges nothing. The gate is armed only in the repository that ships the binary its brief describes: one carrying the command-tree snapshot and the brief's 04-surfaces chapters. Elsewhere it judges nothing. Assisted-by: Claude:claude-opus-5-5
On a confirmed false sentence the reviewer may draft its correction. The judge proposes the drafted edit and still refuses; Apply, a writer the judge never reaches, replaces the sentence in its chapter (exactly once, or the whole apply is refused and nothing is written) and records a review flag in .abcd/work/brief-review-flags.json naming the reviewed commit. The gate then lets the change proceed and lists the applied edit for review: only when the chapter no longer carries the sentence, carries the drafted replacement, and a flag names the edit, so neither a silent hand edit nor a flag over an unedited chapter completes a change with the brief lagging and unflagged. Assisted-by: Claude:claude-opus-5-5
Wires the doc-fidelity gate (itd-60) to both front doors. `abcd docs fidelity` runs the judgement `spec close` and `launch ship` enforce and exits 1 on a refusal. --report is the per-task pass: every finding and no refusal. --apply writes the reviewer's drafted corrections and flags each edit. --autonomous applies the drafts and hands an unattended routine the reviewer's request, and it still refuses. `abcd docs fidelity record --verdict-json` saves the delegated review as the receipt for HEAD; the binary labels it, never the reviewer. The plugin page commands/docs.md carries the review procedure. Brief chapters 10-docs, 04-launch (the doc-fidelity refusal kind) and 05-intent move with the surface, and the generated references are regenerated. The gate's first run over this repository names twelve surfaces no chapter names: `abcd rules`, `abcd spec`, `abcd spec close` and nine agents. They are recorded in .abcd/development/release/doc-fidelity-baseline.json so a close on main stays possible. The spec's close hook gates the surface an intent delivered, and these predate every intent the gate will judge. They are reported on every run, and an entry that stops lagging refuses until it is removed, so the list only shrinks. Assisted-by: Claude:claude-opus-5-5
The gate's first run over this repository names `abcd rules`, `abcd spec`, `abcd spec close` and nine agents that no 04-surfaces chapter names. They sit in the gate's baseline, which is the recorded deferral, and the backfill is its own change. Refs: iss-2609300839021188 Assisted-by: Claude:claude-opus-5-5
The doc-fidelity gate over the brief is built and wired: layer 1 coverage, the saved docs review found automatically by spec close and launch ship (ruling DR3), draft and apply with a review flag, the per-task report, and the autonomous flag. This close passed through the gate itself: layer 1 held with the recorded baseline, and a saved review for the closing commit matched. Delivers: itd-60 Assisted-by: Claude:claude-opus-5-5
Assisted-by: Claude:claude-opus-5-5
The configuration walk that guards against an operator-set reading regime skips files ending "-baseline.json" as machine-written, and refuses when more than three do. The gate's backlog is hand-edited configuration, so it is renamed out of that suffix and walked like the rest of the configuration tree. The chapter, the reader and the captured issue's location follow it. Refs: iss-2609300839021188 Assisted-by: Claude:claude-opus-5-5
The doc-fidelity gate's layer 1 found twelve shipped surfaces that no 04-surfaces chapter named. Each is now described from its code or its agent prompt, in the chapter it belongs with: - 23-reading.md: the four position definitions, cold-reading-detection, -entailment, -widening and -comparative (question, regime, item fields, the shared blindness core, how ingest reads a definition). - 02-disembark.md: press-release-composer and graveyard-interpreter beside the synthesis sub-verbs they feed. - README.md (the register): `abcd rules`, and `abcd spec` with `abcd spec close` (status board, close and ship, its flags, the doc-fidelity gate and the owed fidelity review), as subsections of the operator-internal verbs; and ruthless-reviewer, security-reviewer and sota-researcher as the agents no verb dispatches. With no entry left, the recorded backlog is removed: the gate reads an absent file as an empty backlog, so it does not need one, and 10-docs.md says so. Layer 1 reports 156 of 156 surfaces named. Decision: `abcd rules` and `abcd spec` are documented in the register rather than in a new NN-rules.md / NN-spec.md or in 05-intent.md. Both are operator_internal in surface_coverage, and a new chapter needs a register row that the registry check refuses without a commands/ page, plus a pin in the release-gate manifest. An NN- chapter's prose may not spell another verb's sub-verb path or flags (TestSurfaceChapterProse- StatesNoShape, itd-147), and the fidelity gate names a sub-verb only by that spelling, so `abcd spec close` can be named only in the register, which lists both verbs already. Refs: iss-2609300839021188 Assisted-by: Claude:claude-opus-5-5
…pter The doc-fidelity layer-1 report names 156 of 156 shipped surfaces with an empty backlog after d9c67b6. Resolves: iss-2609300839021188 Assisted-by: Claude:claude-opus-5-5
Assisted-by: Claude:claude-opus-5-5
…eboat half Phase 2 of itd-24 on the core from f0ef93c: `abcd reflect <tag>` renders the seed (text and --json, with the four questions); `abcd reflect write <tag> --answers <file> [--proceed]` files the retrospective, with the core's refusals mapped to exit 1 and, under --json, to a structured refusal the host answers (thin_answers with each follow-up question, unshipped_targets, exists, nothing_shipped). Bare reflect prints help; an intent id is refused naming the intent audit. commands/reflect.md runs the interview under the GRILL rules through the new reflection-composer agent (injection canary, agents changelog, oracle row, catalog and release-gate roster). Every answer now passes the canonical scanner before it is written, failing closed on a degraded scanner, as the decision store does. launch ship ends a written cut with the one nudge line (retrospective_owed in JSON). disembark packs .abcd/development/retrospectives/<tag>/README.md as a record-derived family; embark writes it back, admitting only a strict vMAJOR.MINOR.PATCH directory holding README.md; embark lessons verifies the manifest and ranks the lessons against the target's framing chapter or a --brief file, top three plus the rest, each cleaned to one capped line. Help: reflect is listed under Release and the person's cap goes 14 -> 15 (ruling H13). Surfaces regenerated; brief 09-reflect rewritten at the release grain; the bare-render exception, dogfooding recall and naming rows updated. Decision (not in the record): the embark ranking reads the target's framing chapter, or a --brief file the interview names, and lists the lessons unranked when neither exists, because a freshly embarked target has no framing chapter yet. Refs: itd-24 Assisted-by: Claude:claude-opus-5-5
spec close --impact additive moves the spec to closed/ and the intent to
shipped/, repointing three links in research/legacy-harvest.md.
The spec's scope 1 is amended in the same change under ruling AD ("seed from
A RELEASE (the intents a tag shipped)"): membership is the intents that
reached shipped/ between the previous release tag and this one, less any
whose shipped_in names another release, plus any whose shipped_in names this
one, because no cut writes shipped_in and the stamp-only reading found
nothing for any release cut the ordinary way. Flagged for the reviewer.
itd-24 still builds_on the superseded itd-27 (superseded_by itd-94); neither
record-lint nor spec close refused on it, so it is left as it is and
reported.
Delivers: itd-24
Assisted-by: Claude:claude-opus-5-5
record-lint's index_drift holds the marked commands region to commands/. Refs: itd-24 Assisted-by: Claude:claude-opus-5-5
The manifest's pinned roster gained reflect and reflection-composer, so its hash moved; the example receipt names the committed manifest's hash. Refs: itd-24 Assisted-by: Claude:claude-opus-5-5
…fault Ruling DR5 of 2026-09-29: a provider call carries no tools, so an agent that reads files cannot read them there. Dispatch now admits to a provider that holds a key only an agent on a self-contained list compiled into the binary (default deny): the four cold-reading positions, each handed one assembled bundle. Every other agent is refused before any call, naming the rule and the override. The override is oracle.bundled_context_providers, read from the machine's ~/.abcd/config.json alone; a repository declaring it is refused as a repository's provider block is. A provider it names takes a file-reading agent only once that agent's bundle is built, and none is: which files travel, a size cap and a scan before sending are not ruled. A provider whose block names no key is outside DR5. The dispatch tests move from scribe to cold-reading-detection, since scribe is now refused on a keyed provider. Refs: itd-2609081951381895, spc-2609221011153746, spc-2609251028149555 Assisted-by: Claude:claude-opus-5-5
…and create every embark write exclusively A retrospective `reflect write` created between embark's rejudge and its write was replaced by the lifeboat's copy with no conflict: reflect took no lock, and writeEmbark wrote each planned create through a rename-over. reflect.Write now creates the file under intent.WithMintLock, the intent store's lock embark holds through WithLedgerThenMintLock, so the two are serialised. And writeEmbark writes every planned create through an exclusive create (createIntoLifeboat, fsutil.CreateExclusiveIn), so a file that lands after the rejudge from a writer holding no lock fails the embark loudly instead of being replaced. Every planned write is a create (the only other action, unchanged, writes nothing), so no embark path loses its overwrite. The embark and reflect surface chapters say so. Tests watched RED first: TestWriteWaitsForTheIntentStoresLock (the write landed while the lock was held) and TestWriteEmbarkRefusesToReplaceAFileThatLandedAtACreateTarget (writeEmbark replaced a pre-existing differing README). Refs: iss-2609301245517138 Assisted-by: Claude:claude-opus-5-5
redactAnswers already refused an unavailable or degraded scanner, but no test asserted it, so a later edit dropping the guard would have gone green and let a credential reach the committed retrospective under a silently weakened pattern set. The test degrades the per-repo scanner config two ways (invalid JSON, a directory in the file's place) and asserts the write refuses naming the degraded scanner and leaves no retrospective behind. Watched RED on a scratch copy with the Unavailable() check removed: both subtests failed with a nil error; GREEN on the live tree. Assisted-by: Claude:claude-opus-5-5
Answers come from a host-run composer and landed in the committed record verbatim after the scanner's redaction, so an ESC or a U+202E in one reached the retrospective raw and made it read differently from its bytes. Each answer and follow-up now passes termsafe.SanitizeBlock after the redaction: control, C1, bidi and zero-width runes become `?`, and the answer's own line breaks survive. The reflect surface chapter says so. Test watched RED first: TestWriteMasksControlAndBidiBytesInAnswers (ESC, BEL, U+202E and U+202C reached the file raw). Assisted-by: Claude:claude-opus-5-5
…y exit 2 TestReflectRefusesAnUnknownOrMalformedTag and TestReflectWriteRefusesAMistypedAnswersKey asserted exit 2 alone, which an unknown verb also returns. They now assert what each refusal says: an unknown tag that the repository holds no such release tag, a malformed one that it is not a release tag, and a mistyped answers key that the answers were refused naming the key and that nothing was written (the standard library's wording around the key is not pinned). Watched RED on a scratch copy with the three refusal messages mutated: both strengthened tests failed while the old ones stayed green. Assisted-by: Claude:claude-opus-5-5
The press release, scope item 1 and criterion 1's Given still said the seed was the intents whose `shipped_in` names the tag, the wording spec scope 1 dropped when it was amended under ruling AD on 2026-09-30. They now read membership the way the release cut reads it, with a dated Audit Notes line recording the change. Assisted-by: Claude:claude-opus-5-5
…an embark is replaced silently Resolves: iss-2609301245517138 Assisted-by: Claude:claude-opus-5-5
The chapter prose above the generated appendix states no command shape (TestSurfaceChapterProseStatesNoShape), and the embark chapter's new sentence on the retrospective lock named `abcd reflect write`. It names the verb in words instead. Assisted-by: Claude:claude-opus-5-5
…n three ways The review of the doc-fidelity lane found three ways the gate passes what it exists to refuse: a PROMOTE that lists a false brief sentence, a new undocumented surface listed in the backlog file, and a multi-line or unbounded sentence that the apply form writes across a chapter. Refs: iss-2609301251469172 Assisted-by: Claude:claude-opus-5-5
- Record refuses a PROMOTE whose failing list names a brief sentence (the mirror of the HOLD-with-no-sentence refusal), and Judge refuses a saved PROMOTE carrying one as unusable, so a receipt edited after it was saved is still not a pass. - The backlog file is dropped rather than tied to the anchor tag. The spec (spc-2609020903498198) has no backlog: layer 1 requires every verb, sub-verb and agent to be named by a chapter, and its legitimate lead judges the brief against the binary, never the tag. Admitting a key only when the anchor tag's surface.json carries it would put a tag read into layer 1, and the file is absent with every shipped surface named. So no file exempts a surface, and the "only shrinks" claim goes with it. - Record and Apply refuse a sentence or replacement that spans lines or exceeds 2048 bytes; Apply keeps its exactly-once rule. The close and cut recipes (AGENTS.md, CONTRIBUTING.md, commands/intent.md, commands/launch.md) now say that a shipping spec close and launch ship need a docs review recorded for HEAD, and that a cut on main needs one for the merge commit. Brief 10-docs.md is reworded to match. Refs: iss-2609301251469172 Assisted-by: Claude:claude-opus-5-5
Resolves: iss-2609301251469172 Assisted-by: Claude:claude-opus-5-5
…routed to The delegating verbs now read the machine's provider configuration (oracle.LoadAPI) when they resolve a route, print its diagnostics, and refuse a fault in it at exit 2. A step whose route is on a provider is sent there by the verb itself, the answer is run through the verb's own ingest, and the receipt names the provider as the connection used with the model asked and the model reported: - intent audit <itd-N>, intent consistency, intent audit --owed (its head), launch ship and spec close's audit re-emit send the request they emitted, with the agent's own prompt; - reading ingest --dispatch <rdg-N> sends a parked run's bundle with the position's definition, the one path a paid provider takes by default under ruling DR5. Ruling DR5 is checked before anything is written (Admitted), so a file-reading agent pointed at a provider that holds a key exits 2 with nothing written and nothing sent. A provider that could not be reached leaves the step to the host with one stderr line. An ingest handed a payload the host produced while its agent is routed to a provider is refused, since its receipt would name work the provider never did; --route <agent>=host-decides keeps one run on the harness. The four disembark agents read the packed lifeboat and no verb builds a request carrying it, so none is sent to a provider. Refs: itd-2609081951381895, spc-2609221011153746, spc-2609251028149555, itd-2609170822093401 Assisted-by: Claude:claude-opus-5-5
…sions The providers board and the setup's dispatch line say what a verb does with a pointed role and which agents a paid provider takes under ruling DR5, where they said dispatch was still to come. The command pages for intent, launch, disembark, reading and ahoy tell the host that a receipt whose connection_used is not harness means the step already ran, name the DR5 refusal and oracle.bundled_context_providers, and document reading ingest --dispatch. The brief's adapters and configuration chapters and the ahoy, disembark, launch, intent and reading surface chapters state the wiring, the self-contained list and the machine-only override, which inherits the machine layer's trust in $HOME pending iss-2609300012273350. itd-2609081951381895 records DR5 and the decisions this lane took (10 to 14); spc-2609251028149555 records AC 3 met and stays open for AC 10. Refs: itd-2609081951381895, spc-2609221011153746, spc-2609251028149555 Refs: iss-2609300012273350 Assisted-by: Claude:claude-opus-5-5
reading ingest --dispatch reads the position's definition through reading.LoadDefinition, so production code outside its package now reaches it and its baseline line goes. Refs: spc-2609251028149555 Assisted-by: Claude:claude-opus-5-5
The delegating verbs send a step to the provider it is routed to. internal/core/oracle/config.go merged cleanly: it keeps the bundled field and readBundled from this branch and the malformed/keyed route skip predicates from routeNameSkip. One conflict, the core reach baseline (internal/reachaudit/testdata/core-unreached.txt): main's list with this branch's ratchet applied, reading.LoadDefinition dropped because parked.go now reaches it; TestEveryExportedCoreFunctionIsReachedOrBaselined passes. Assisted-by: Claude:claude-opus-5-5
`reading ingest --dispatch` read the parked manifest but dropped its `unscanned` marks, so a paid send carried items the exclusion floor never examined without saying so. reading.Parked now carries the manifest's item count and its unscanned count, and the front door prints one stderr line naming both, and the provider, before the send. The brief chapter (23-reading) and commands/reading.md say so. Follow-up pd1 from review-providerDispatch2 point 3. TestADispatchSaysHowManyItemsTravelUnscanned was watched fail (the stderr named nothing) before the change and pass after. Assisted-by: Claude:claude-opus-5-5
The OpenAI-compatible API oracle adapter is delivered: the adapter, the machine-only credential, the provider configuration and, with feat/provider-dispatch-verbs, the delegating verbs sending a step to the provider it is routed to. Closed with --impact additive, the impact the intent declares. Acceptance criterion 8 (the network path and credential handling reviewed) is met by the review of providerDispatch2 (scratch/reports/review-providerDispatch2.md, SHIP, AC8 MET), whose one follow-up, the unscanned count before a paid send, lands in the commit before this one. The close precedes the doc-fidelity gate's merge. Delivers: itd-2609081951381895 Assisted-by: Claude:claude-opus-5-5
`abcd reflect` writes a release retrospective, seeded by what the tag shipped; itd-24 ships (its spec closed on the branch). The itd-24 intent merged without a textual conflict: it takes the shipped/ location and keeps recDefects' dropped builds_on edge with its Audit Note (rf1). Conflicts, by hunk: internal/surface/cli/ship.go keeps main's provider dispatch receipt and dispatch line and this branch's retrospective nudge, which now prints after either receipt line; internal/core/frontmatter/delimiter_canonical_test.go keeps main's writer sites (issuebrief.go) and adds this branch's reflect/write.go. Semantic conflict: main unexported lifeboat.VerifyManifest (83e558c), so retrospectives.go calls verifyManifest. Assisted-by: Claude:claude-opus-5-5
dbfdb1d) The doc-fidelity gate (`abcd docs fidelity`, `abcd docs fidelity record`) with the brief chapters it judges; itd-60 ships (shipped on the branch). One conflict, the generated .abcd/development/release/surface.json, taken from main and regenerated with `go generate ./internal/surface/cli` over the merged tree. Semantic conflict: the core reach audit on main refuses docfidelity.Judge, Names and Shipped, which no production code outside the package reaches; they are unexported, and the one cross-package test use calls the declared seam ShippedForTest. Assisted-by: Claude:claude-opus-5-5
10-docs.md said the autonomous form "still refuses" whenever the saved review is not a match for HEAD, while the same paragraph, and the code, let the change proceed once every drafted edit is applied (a HOLD whose one draft applied reports refuse=false, exit 0). The sentence now says "and, unless every drafted edit was applied, it still refuses", the wording the doc-fidelity re-verification named (df1). Assisted-by: Claude:claude-opus-5-5
`abcd docs fidelity record` accepted any non-empty judgeModel, so a bare
alias ("m", "claude-opus") or a rolling one (".. -latest") was saved,
and the gate then read the receipt as invalid through the release gate's
receipt reader, which refuses it. The record now applies that reader's
own shape check, lint.FloatingJudgeModel (exported for the purpose), and
refuses before anything is written. The brief chapter (10-docs) and
commands/docs.md say so. Follow-up df2 from the doc-fidelity
re-verification.
TestRecordRefusesAnUnusablePayload's three new cases (bare family alias,
family with no version, rolling alias) were watched fail ("recorded")
before the change and pass after.
Assisted-by: Claude:claude-opus-5-5
Measured on a clean clone of accf618 with `reading assemble --target HEAD --dry-run --json`; window = ceil(tokens * 1.01 / 10000) * 10000. widening 1473012 tokens (was 0.47% under its window) -> 1490000; entailment 424468 -> 430000 (unchanged); detection 1482048 (was 0.54% under) -> 1500000. Refs: iss-2609251455354719 Assisted-by: Claude:claude-opus-5-5
The doc-fidelity store tests spawned git with the ambient environment, so TestTestGitCallsAreHermetic, the hermetic-git gate, failed at the integration tip: a developer's global git configuration could reach the fixture repositories. The helper now sets cmd.Env = gittest.Env(t), as every other test that spawns git does. The gate was watched fail on the full run and pass after. Assisted-by: Claude:claude-opus-5-5
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Integration 24c is the last landing of the v0.12.0 cycle. For a user: abcd can send a delegated step to a model provider the person has set up, instead of handing it to the host, and says how much of a reading travels unscanned before a paid send; a cut release can be looked back on with
abcd reflect, and the retrospective travels in the lifeboat; and a spec can no longer close, nor a release be cut, while the brief lags a surface that shipped.From this change on, a spec close that ships an intent (any close without
--remainder) and a release cut need a saved docs review for the commit they run at. The review is recorded withabcd docs fidelity record --verdict-json <file>; without one,spec closeandlaunch shiprefuse with "run the docs review first". A cut onmainneeds one for the merge commit, so the reviewer runs after the merge.Provider dispatch (providerDispatch2). When the person points an agent at a provider in their own
~/.abcd/config.json, the verb that emits the agent's request sends it there itself, runs the answer through its own ingest, and records the provider, the model asked for and the model that answered on the receipt. A paid provider (one whose block names a key) takes only agents whose request carries all their input, which today means the four cold-reading positions; every other agent is refused before anything is written or sent, as the product thinker ruled (DR5, 2026-09-29).oracle.bundled_context_providersis the person's machine-only override. An ingest handed a payload the host produced while its agent is routed to a provider is refused, since its receipt would name work the provider never did. Beforereading ingest --dispatchsends a parked run, one stderr line now names how many items it sends and how many of them the manifest marksunscanned, the items the exclusion floor never examined. The adapter's intent ships here: its spec is closed with the impact it declares (additive), and its criterion 8 is met by the security review of this branch (SHIP, AC8 MET).Release retrospectives (reflect2).
abcd reflect v0.11.0shows what the release shipped, which shipped intents have no audit yet, and which targeted intents missed it; a short interview on the host asks four questions one at a time, asks again when an answer is thin, andabcd reflect writefiles the result as.abcd/development/retrospectives/v0.11.0/README.md. Every answer passes the secret scanner before it is written, and the write fails closed when the scanner is degraded.launch shipends a written cut with one line saying a retrospective is owed (retrospective_owedin its JSON), after the provider receipt when the cut was composed on a provider. Lifeboats carry every retrospective, embark writes them back under the intent store's lock with exclusive creates, andabcd embark lessonsranks the predecessor's lessons against the new voyage's brief, the top three first.The doc-fidelity gate and its chapters (docFidelity, chapterBackfill).
abcd docs fidelitychecks that every verb, sub-verb and agent the binary ships is named by a brief chapter under04-surfaces/, and that a docs review is saved for the exact commit being closed or cut; a review that confirmed a false sentence refuses and names it.--reportstates every finding and refuses nothing,--applywrites a reviewer's drafted corrections and flags each for the product thinker, and--autonomousdoes the same for an unattended run. The brief now names all 164 shipped surfaces. The record verb refuses a PROMOTE naming a false brief sentence, a sentence or replacement that spans lines or exceeds 2048 bytes, and now also a judge model the receipt reader would refuse as floating (a bare family name, or one naminglatest). The brief's docs chapter now says that the autonomous form still refuses unless every drafted edit was applied.The docs review saved for this head is the integration author's own reading, recorded as an author self-review (the changed sentences of the sixteen brief chapters this change touches, read against the code). An independent docs review of this head is owed before the release cut.
The cold-reading windows are recalibrated at this tip (widening 1,490,000, entailment 430,000, detection 1,500,000 tokens).
Delivers: itd-2609081951381895
Delivers: itd-24
Delivers: itd-60
Resolves: iss-2609300839021188
Resolves: iss-2609301245517138
Resolves: iss-2609301251469172
Refs: iss-2609251455354719
Refs: iss-2609300012273350
Assisted-by: Claude:claude-opus-5-5