Skip to content

v0.12.0 integration 24c: provider dispatch under DR5, the release retrospective, the doc-fidelity gate - #762

Merged
REPPL merged 39 commits into
mainfrom
integ/land-24c
Sep 30, 2026
Merged

REPPL merged 39 commits into
mainfrom
integ/land-24c

Conversation

@REPPL

@REPPL REPPL commented Sep 30, 2026

Copy link
Copy Markdown
Collaborator

Integration 24c is the last landing of the v0.12.0 cycle. For a user: abcd can send a delegated step to a model provider the person has set up, instead of handing it to the host, and says how much of a reading travels unscanned before a paid send; a cut release can be looked back on with abcd reflect, and the retrospective travels in the lifeboat; and a spec can no longer close, nor a release be cut, while the brief lags a surface that shipped.

From this change on, a spec close that ships an intent (any close without --remainder) and a release cut need a saved docs review for the commit they run at. The review is recorded with abcd docs fidelity record --verdict-json <file>; without one, spec close and launch ship refuse with "run the docs review first". A cut on main needs one for the merge commit, so the reviewer runs after the merge.

Provider dispatch (providerDispatch2). When the person points an agent at a provider in their own ~/.abcd/config.json, the verb that emits the agent's request sends it there itself, runs the answer through its own ingest, and records the provider, the model asked for and the model that answered on the receipt. A paid provider (one whose block names a key) takes only agents whose request carries all their input, which today means the four cold-reading positions; every other agent is refused before anything is written or sent, as the product thinker ruled (DR5, 2026-09-29). oracle.bundled_context_providers is the person's machine-only override. An ingest handed a payload the host produced while its agent is routed to a provider is refused, since its receipt would name work the provider never did. Before reading ingest --dispatch sends a parked run, one stderr line now names how many items it sends and how many of them the manifest marks unscanned, the items the exclusion floor never examined. The adapter's intent ships here: its spec is closed with the impact it declares (additive), and its criterion 8 is met by the security review of this branch (SHIP, AC8 MET).

Release retrospectives (reflect2). abcd reflect v0.11.0 shows what the release shipped, which shipped intents have no audit yet, and which targeted intents missed it; a short interview on the host asks four questions one at a time, asks again when an answer is thin, and abcd reflect write files the result as .abcd/development/retrospectives/v0.11.0/README.md. Every answer passes the secret scanner before it is written, and the write fails closed when the scanner is degraded. launch ship ends a written cut with one line saying a retrospective is owed (retrospective_owed in its JSON), after the provider receipt when the cut was composed on a provider. Lifeboats carry every retrospective, embark writes them back under the intent store's lock with exclusive creates, and abcd embark lessons ranks the predecessor's lessons against the new voyage's brief, the top three first.

The doc-fidelity gate and its chapters (docFidelity, chapterBackfill). abcd docs fidelity checks that every verb, sub-verb and agent the binary ships is named by a brief chapter under 04-surfaces/, and that a docs review is saved for the exact commit being closed or cut; a review that confirmed a false sentence refuses and names it. --report states every finding and refuses nothing, --apply writes a reviewer's drafted corrections and flags each for the product thinker, and --autonomous does the same for an unattended run. The brief now names all 164 shipped surfaces. The record verb refuses a PROMOTE naming a false brief sentence, a sentence or replacement that spans lines or exceeds 2048 bytes, and now also a judge model the receipt reader would refuse as floating (a bare family name, or one naming latest). The brief's docs chapter now says that the autonomous form still refuses unless every drafted edit was applied.

The docs review saved for this head is the integration author's own reading, recorded as an author self-review (the changed sentences of the sixteen brief chapters this change touches, read against the code). An independent docs review of this head is owed before the release cut.

The cold-reading windows are recalibrated at this tip (widening 1,490,000, entailment 430,000, detection 1,500,000 tokens).

Delivers: itd-2609081951381895
Delivers: itd-24
Delivers: itd-60
Resolves: iss-2609300839021188
Resolves: iss-2609301245517138
Resolves: iss-2609301251469172
Refs: iss-2609251455354719
Refs: iss-2609300012273350

Assisted-by: Claude:claude-opus-5-5

…, lessons

internal/core/reflect is the core of `/abcd:reflect <release-tag>` (phase 1
of 2: no front door yet). BuildSeed reads what a release tag shipped: each
intent with its impact and its audit notes read as counts (rollup, gap
audit, receipt), the intents without audit notes with the
`abcd intent audit <itd-N>` offer, the unshipped intents whose
target_release names the tag, the changelog section the cut composed, and
the computed metrics (intents, verdict distribution, this tag's date and
the previous tag's). It refuses a release that shipped no intent in the
criterion's words, a malformed or unknown tag, and a tag that already has
a retrospective. Write rebuilds the seed, asks for confirmation past
unshipped targets, refuses an answer under the declared floor until its
one follow-up is answered, and creates
.abcd/development/retrospectives/<tag>/README.md exclusively inside a
real-directory tree: frontmatter naming the release, the date, the
intents and which audits fed it, links to the changelog section and each
intent's audit notes (never copies), the four answered sections and the
computed metrics. ReadLessons and RankLessons are embark's half (the top
three lessons by term overlap with the brief's framing, through
record/match, the rest as a list); Nudge is the cut's one line.

Decision taken (technical facilitator's how, not in the record): which
intents a tag shipped is read the way the cut reads it: the intents that
reached shipped/ between the previous release tag and this one, less any
stamped `shipped_in:` another release, plus any stamped with this one.
The spec's scope 1 names only the stamp, but `shipped_in` is a migration
field the cut never writes (changelog.Record.ShippedIn), so no intent
names v0.7.0 or any later tag, and a stamp-only seed would refuse every
current release as "no intent shipped", which is false. Checked on a
clone of this repository: v0.10.0, v0.11.0 and v0.11.1 seed 9, 11 and 18
intents.

The floor (spec scope 3) is declared as MinClauses 2 of MinClauseWords 3,
or an answer made only of its heading's terms, or a blank one.

Using record/match makes match.Terms, NewWeights and Overlap reached, so
their stale lines leave the reach baseline; the writer joins the
frontmatter delimiter allowlist. The six reflect names the reach audit
reports (BuildSeed, Write, ParseAnswers, ReadLessons, RankLessons, Nudge)
are wired in phase 2 and are deliberately not baselined.

Refs: itd-24

Assisted-by: Claude:claude-opus-5-5
The core of the doc-fidelity gate over the brief (itd-60,
spc-2609020903498198). Judge is pure: the command tree, the agent set,
the brief's 04-surfaces chapters and a baseline in, a verdict out.
Layer 1 derives the shipped surfaces (every verb, sub-verb and agent;
hidden and moved spellings excluded) and refuses any no chapter names,
before the reviewer is constructed. Layer 2 is the saved review, as
ruled DR3: the delegated docs review records a verdict receipt labelled
with the commit it read, and the gate finds it; a missing, stale,
unreadable or inconclusive one refuses with "run the docs review first",
and a HOLD refuses naming each false brief sentence. A public-doc
sentence is reported and never refuses.

The receipt is the release gate's VSA receipt, judged by the release
gate's own reader: lint.CheckGateReceipt runs checkReceiptGate for one
gate, with the failing entries it parsed handed back, so no second
receipt reader exists.

Assisted-by: Claude:claude-opus-5-5
The doc-fidelity gate's two enforcement points (itd-60), one entry
point with two populations. `abcd spec close` runs it over the intents
the close would ship, before anything moves, and refuses naming the
undocumented surface, the false sentence, or "run the docs review
first"; a --remainder close ships nothing and is not gated. The release
cut (release.Emit, which `launch ship` runs at both its steps) runs it
over every intent in the cut and refuses with a doc-fidelity refusal
naming them; an empty population judges nothing.

The gate is armed only in the repository that ships the binary its
brief describes: one carrying the command-tree snapshot and the brief's
04-surfaces chapters. Elsewhere it judges nothing.

Assisted-by: Claude:claude-opus-5-5
On a confirmed false sentence the reviewer may draft its correction.
The judge proposes the drafted edit and still refuses; Apply, a writer
the judge never reaches, replaces the sentence in its chapter (exactly
once, or the whole apply is refused and nothing is written) and records
a review flag in .abcd/work/brief-review-flags.json naming the reviewed
commit. The gate then lets the change proceed and lists the applied
edit for review: only when the chapter no longer carries the sentence,
carries the drafted replacement, and a flag names the edit, so neither a
silent hand edit nor a flag over an unedited chapter completes a change
with the brief lagging and unflagged.

Assisted-by: Claude:claude-opus-5-5
Wires the doc-fidelity gate (itd-60) to both front doors. `abcd docs
fidelity` runs the judgement `spec close` and `launch ship` enforce and
exits 1 on a refusal. --report is the per-task pass: every finding and
no refusal. --apply writes the reviewer's drafted corrections and flags
each edit. --autonomous applies the drafts and hands an unattended
routine the reviewer's request, and it still refuses. `abcd docs
fidelity record --verdict-json` saves the delegated review as the
receipt for HEAD; the binary labels it, never the reviewer. The plugin
page commands/docs.md carries the review procedure. Brief chapters
10-docs, 04-launch (the doc-fidelity refusal kind) and 05-intent move
with the surface, and the generated references are regenerated.

The gate's first run over this repository names twelve surfaces no
chapter names: `abcd rules`, `abcd spec`, `abcd spec close` and nine
agents. They are recorded in
.abcd/development/release/doc-fidelity-baseline.json so a close on main
stays possible. The spec's close hook gates the surface an intent
delivered, and these predate every intent the gate will judge. They are
reported on every run, and an entry that stops lagging refuses until it
is removed, so the list only shrinks.

Assisted-by: Claude:claude-opus-5-5
The gate's first run over this repository names `abcd rules`, `abcd
spec`, `abcd spec close` and nine agents that no 04-surfaces chapter
names. They sit in the gate's baseline, which is the recorded deferral,
and the backfill is its own change.

Refs: iss-2609300839021188

Assisted-by: Claude:claude-opus-5-5
The doc-fidelity gate over the brief is built and wired: layer 1
coverage, the saved docs review found automatically by spec close and
launch ship (ruling DR3), draft and apply with a review flag, the
per-task report, and the autonomous flag. This close passed through the
gate itself: layer 1 held with the recorded baseline, and a saved
review for the closing commit matched.

Delivers: itd-60

Assisted-by: Claude:claude-opus-5-5
Assisted-by: Claude:claude-opus-5-5
The configuration walk that guards against an operator-set reading
regime skips files ending "-baseline.json" as machine-written, and
refuses when more than three do. The gate's backlog is hand-edited
configuration, so it is renamed out of that suffix and walked like
the rest of the configuration tree. The chapter, the reader and the
captured issue's location follow it.

Refs: iss-2609300839021188

Assisted-by: Claude:claude-opus-5-5
The doc-fidelity gate's layer 1 found twelve shipped surfaces that no
04-surfaces chapter named. Each is now described from its code or its
agent prompt, in the chapter it belongs with:

- 23-reading.md: the four position definitions, cold-reading-detection,
  -entailment, -widening and -comparative (question, regime, item
  fields, the shared blindness core, how ingest reads a definition).
- 02-disembark.md: press-release-composer and graveyard-interpreter
  beside the synthesis sub-verbs they feed.
- README.md (the register): `abcd rules`, and `abcd spec` with
  `abcd spec close` (status board, close and ship, its flags, the
  doc-fidelity gate and the owed fidelity review), as subsections of the
  operator-internal verbs; and ruthless-reviewer, security-reviewer and
  sota-researcher as the agents no verb dispatches.

With no entry left, the recorded backlog is removed: the gate reads an
absent file as an empty backlog, so it does not need one, and 10-docs.md
says so. Layer 1 reports 156 of 156 surfaces named.

Decision: `abcd rules` and `abcd spec` are documented in the register
rather than in a new NN-rules.md / NN-spec.md or in 05-intent.md. Both
are operator_internal in surface_coverage, and a new chapter needs a
register row that the registry check refuses without a commands/ page,
plus a pin in the release-gate manifest. An NN- chapter's prose may not
spell another verb's sub-verb path or flags (TestSurfaceChapterProse-
StatesNoShape, itd-147), and the fidelity gate names a sub-verb only by
that spelling, so `abcd spec close` can be named only in the register,
which lists both verbs already.

Refs: iss-2609300839021188
Assisted-by: Claude:claude-opus-5-5
…pter

The doc-fidelity layer-1 report names 156 of 156 shipped surfaces with an
empty backlog after d9c67b6.

Resolves: iss-2609300839021188
Assisted-by: Claude:claude-opus-5-5
Assisted-by: Claude:claude-opus-5-5
…eboat half

Phase 2 of itd-24 on the core from f0ef93c: `abcd reflect <tag>` renders
the seed (text and --json, with the four questions); `abcd reflect write
<tag> --answers <file> [--proceed]` files the retrospective, with the core's
refusals mapped to exit 1 and, under --json, to a structured refusal the host
answers (thin_answers with each follow-up question, unshipped_targets,
exists, nothing_shipped). Bare reflect prints help; an intent id is refused
naming the intent audit. commands/reflect.md runs the interview under the
GRILL rules through the new reflection-composer agent (injection canary,
agents changelog, oracle row, catalog and release-gate roster).

Every answer now passes the canonical scanner before it is written, failing
closed on a degraded scanner, as the decision store does.

launch ship ends a written cut with the one nudge line (retrospective_owed in
JSON). disembark packs .abcd/development/retrospectives/<tag>/README.md as a
record-derived family; embark writes it back, admitting only a strict
vMAJOR.MINOR.PATCH directory holding README.md; embark lessons verifies the
manifest and ranks the lessons against the target's framing chapter or a
--brief file, top three plus the rest, each cleaned to one capped line.

Help: reflect is listed under Release and the person's cap goes 14 -> 15
(ruling H13). Surfaces regenerated; brief 09-reflect rewritten at the
release grain; the bare-render exception, dogfooding recall and naming rows
updated.

Decision (not in the record): the embark ranking reads the target's framing
chapter, or a --brief file the interview names, and lists the lessons
unranked when neither exists, because a freshly embarked target has no
framing chapter yet.

Refs: itd-24
Assisted-by: Claude:claude-opus-5-5
spec close --impact additive moves the spec to closed/ and the intent to
shipped/, repointing three links in research/legacy-harvest.md.

The spec's scope 1 is amended in the same change under ruling AD ("seed from
A RELEASE (the intents a tag shipped)"): membership is the intents that
reached shipped/ between the previous release tag and this one, less any
whose shipped_in names another release, plus any whose shipped_in names this
one, because no cut writes shipped_in and the stamp-only reading found
nothing for any release cut the ordinary way. Flagged for the reviewer.

itd-24 still builds_on the superseded itd-27 (superseded_by itd-94); neither
record-lint nor spec close refused on it, so it is left as it is and
reported.

Delivers: itd-24
Assisted-by: Claude:claude-opus-5-5
record-lint's index_drift holds the marked commands region to commands/.

Refs: itd-24
Assisted-by: Claude:claude-opus-5-5
The manifest's pinned roster gained reflect and reflection-composer, so its
hash moved; the example receipt names the committed manifest's hash.

Refs: itd-24
Assisted-by: Claude:claude-opus-5-5
…fault

Ruling DR5 of 2026-09-29: a provider call carries no tools, so an agent
that reads files cannot read them there. Dispatch now admits to a
provider that holds a key only an agent on a self-contained list
compiled into the binary (default deny): the four cold-reading
positions, each handed one assembled bundle. Every other agent is
refused before any call, naming the rule and the override.

The override is oracle.bundled_context_providers, read from the
machine's ~/.abcd/config.json alone; a repository declaring it is
refused as a repository's provider block is. A provider it names takes
a file-reading agent only once that agent's bundle is built, and none
is: which files travel, a size cap and a scan before sending are not
ruled. A provider whose block names no key is outside DR5.

The dispatch tests move from scribe to cold-reading-detection, since
scribe is now refused on a keyed provider.

Refs: itd-2609081951381895, spc-2609221011153746, spc-2609251028149555
Assisted-by: Claude:claude-opus-5-5
…and create every embark write exclusively

A retrospective `reflect write` created between embark's rejudge and its
write was replaced by the lifeboat's copy with no conflict: reflect took no
lock, and writeEmbark wrote each planned create through a rename-over.

reflect.Write now creates the file under intent.WithMintLock, the intent
store's lock embark holds through WithLedgerThenMintLock, so the two are
serialised. And writeEmbark writes every planned create through an
exclusive create (createIntoLifeboat, fsutil.CreateExclusiveIn), so a file
that lands after the rejudge from a writer holding no lock fails the embark
loudly instead of being replaced. Every planned write is a create (the only
other action, unchanged, writes nothing), so no embark path loses its
overwrite. The embark and reflect surface chapters say so.

Tests watched RED first: TestWriteWaitsForTheIntentStoresLock (the write
landed while the lock was held) and
TestWriteEmbarkRefusesToReplaceAFileThatLandedAtACreateTarget (writeEmbark
replaced a pre-existing differing README).

Refs: iss-2609301245517138
Assisted-by: Claude:claude-opus-5-5
redactAnswers already refused an unavailable or degraded scanner, but no
test asserted it, so a later edit dropping the guard would have gone green
and let a credential reach the committed retrospective under a silently
weakened pattern set. The test degrades the per-repo scanner config two
ways (invalid JSON, a directory in the file's place) and asserts the write
refuses naming the degraded scanner and leaves no retrospective behind.

Watched RED on a scratch copy with the Unavailable() check removed: both
subtests failed with a nil error; GREEN on the live tree.

Assisted-by: Claude:claude-opus-5-5
Answers come from a host-run composer and landed in the committed record
verbatim after the scanner's redaction, so an ESC or a U+202E in one
reached the retrospective raw and made it read differently from its bytes.
Each answer and follow-up now passes termsafe.SanitizeBlock after the
redaction: control, C1, bidi and zero-width runes become `?`, and the
answer's own line breaks survive. The reflect surface chapter says so.

Test watched RED first: TestWriteMasksControlAndBidiBytesInAnswers (ESC,
BEL, U+202E and U+202C reached the file raw).

Assisted-by: Claude:claude-opus-5-5
…y exit 2

TestReflectRefusesAnUnknownOrMalformedTag and
TestReflectWriteRefusesAMistypedAnswersKey asserted exit 2 alone, which an
unknown verb also returns. They now assert what each refusal says: an
unknown tag that the repository holds no such release tag, a malformed one
that it is not a release tag, and a mistyped answers key that the answers
were refused naming the key and that nothing was written (the standard
library's wording around the key is not pinned).

Watched RED on a scratch copy with the three refusal messages mutated: both
strengthened tests failed while the old ones stayed green.

Assisted-by: Claude:claude-opus-5-5
The press release, scope item 1 and criterion 1's Given still said the
seed was the intents whose `shipped_in` names the tag, the wording spec
scope 1 dropped when it was amended under ruling AD on 2026-09-30. They now
read membership the way the release cut reads it, with a dated Audit Notes
line recording the change.

Assisted-by: Claude:claude-opus-5-5
…an embark is replaced silently

Resolves: iss-2609301245517138
Assisted-by: Claude:claude-opus-5-5
The chapter prose above the generated appendix states no command shape
(TestSurfaceChapterProseStatesNoShape), and the embark chapter's new
sentence on the retrospective lock named `abcd reflect write`. It names the
verb in words instead.

Assisted-by: Claude:claude-opus-5-5
…n three ways

The review of the doc-fidelity lane found three ways the gate passes what
it exists to refuse: a PROMOTE that lists a false brief sentence, a new
undocumented surface listed in the backlog file, and a multi-line or
unbounded sentence that the apply form writes across a chapter.

Refs: iss-2609301251469172

Assisted-by: Claude:claude-opus-5-5
- Record refuses a PROMOTE whose failing list names a brief sentence (the
  mirror of the HOLD-with-no-sentence refusal), and Judge refuses a saved
  PROMOTE carrying one as unusable, so a receipt edited after it was saved
  is still not a pass.
- The backlog file is dropped rather than tied to the anchor tag. The spec
  (spc-2609020903498198) has no backlog: layer 1 requires every verb,
  sub-verb and agent to be named by a chapter, and its legitimate lead
  judges the brief against the binary, never the tag. Admitting a key only
  when the anchor tag's surface.json carries it would put a tag read into
  layer 1, and the file is absent with every shipped surface named. So no
  file exempts a surface, and the "only shrinks" claim goes with it.
- Record and Apply refuse a sentence or replacement that spans lines or
  exceeds 2048 bytes; Apply keeps its exactly-once rule.

The close and cut recipes (AGENTS.md, CONTRIBUTING.md, commands/intent.md,
commands/launch.md) now say that a shipping spec close and launch ship need
a docs review recorded for HEAD, and that a cut on main needs one for the
merge commit. Brief 10-docs.md is reworded to match.

Refs: iss-2609301251469172

Assisted-by: Claude:claude-opus-5-5
Resolves: iss-2609301251469172

Assisted-by: Claude:claude-opus-5-5
…routed to

The delegating verbs now read the machine's provider configuration
(oracle.LoadAPI) when they resolve a route, print its diagnostics, and
refuse a fault in it at exit 2. A step whose route is on a provider is
sent there by the verb itself, the answer is run through the verb's own
ingest, and the receipt names the provider as the connection used with
the model asked and the model reported:

- intent audit <itd-N>, intent consistency, intent audit --owed (its
  head), launch ship and spec close's audit re-emit send the request
  they emitted, with the agent's own prompt;
- reading ingest --dispatch <rdg-N> sends a parked run's bundle with
  the position's definition, the one path a paid provider takes by
  default under ruling DR5.

Ruling DR5 is checked before anything is written (Admitted), so a
file-reading agent pointed at a provider that holds a key exits 2 with
nothing written and nothing sent. A provider that could not be reached
leaves the step to the host with one stderr line. An ingest handed a
payload the host produced while its agent is routed to a provider is
refused, since its receipt would name work the provider never did;
--route <agent>=host-decides keeps one run on the harness. The four
disembark agents read the packed lifeboat and no verb builds a request
carrying it, so none is sent to a provider.

Refs: itd-2609081951381895, spc-2609221011153746, spc-2609251028149555, itd-2609170822093401
Assisted-by: Claude:claude-opus-5-5
…sions

The providers board and the setup's dispatch line say what a verb does
with a pointed role and which agents a paid provider takes under ruling
DR5, where they said dispatch was still to come. The command pages for
intent, launch, disembark, reading and ahoy tell the host that a receipt
whose connection_used is not harness means the step already ran, name
the DR5 refusal and oracle.bundled_context_providers, and document
reading ingest --dispatch. The brief's adapters and configuration
chapters and the ahoy, disembark, launch, intent and reading surface
chapters state the wiring, the self-contained list and the machine-only
override, which inherits the machine layer's trust in $HOME pending
iss-2609300012273350.

itd-2609081951381895 records DR5 and the decisions this lane took
(10 to 14); spc-2609251028149555 records AC 3 met and stays open for
AC 10.

Refs: itd-2609081951381895, spc-2609221011153746, spc-2609251028149555
Refs: iss-2609300012273350
Assisted-by: Claude:claude-opus-5-5
reading ingest --dispatch reads the position's definition through
reading.LoadDefinition, so production code outside its package now
reaches it and its baseline line goes.

Refs: spc-2609251028149555
Assisted-by: Claude:claude-opus-5-5
The delegating verbs send a step to the provider it is routed to.
internal/core/oracle/config.go merged cleanly: it keeps the bundled field
and readBundled from this branch and the malformed/keyed route skip
predicates from routeNameSkip. One conflict, the core reach baseline
(internal/reachaudit/testdata/core-unreached.txt): main's list with this
branch's ratchet applied, reading.LoadDefinition dropped because parked.go
now reaches it; TestEveryExportedCoreFunctionIsReachedOrBaselined passes.

Assisted-by: Claude:claude-opus-5-5
`reading ingest --dispatch` read the parked manifest but dropped its
`unscanned` marks, so a paid send carried items the exclusion floor never
examined without saying so. reading.Parked now carries the manifest's item
count and its unscanned count, and the front door prints one stderr line
naming both, and the provider, before the send. The brief chapter
(23-reading) and commands/reading.md say so. Follow-up pd1 from
review-providerDispatch2 point 3.

TestADispatchSaysHowManyItemsTravelUnscanned was watched fail (the stderr
named nothing) before the change and pass after.

Assisted-by: Claude:claude-opus-5-5
The OpenAI-compatible API oracle adapter is delivered: the adapter, the
machine-only credential, the provider configuration and, with
feat/provider-dispatch-verbs, the delegating verbs sending a step to the
provider it is routed to. Closed with --impact additive, the impact the
intent declares. Acceptance criterion 8 (the network path and credential
handling reviewed) is met by the review of providerDispatch2
(scratch/reports/review-providerDispatch2.md, SHIP, AC8 MET), whose one
follow-up, the unscanned count before a paid send, lands in the commit
before this one. The close precedes the doc-fidelity gate's merge.

Delivers: itd-2609081951381895
Assisted-by: Claude:claude-opus-5-5
`abcd reflect` writes a release retrospective, seeded by what the tag
shipped; itd-24 ships (its spec closed on the branch). The itd-24 intent
merged without a textual conflict: it takes the shipped/ location and
keeps recDefects' dropped builds_on edge with its Audit Note (rf1).
Conflicts, by hunk: internal/surface/cli/ship.go keeps main's provider
dispatch receipt and dispatch line and this branch's retrospective nudge,
which now prints after either receipt line;
internal/core/frontmatter/delimiter_canonical_test.go keeps main's writer
sites (issuebrief.go) and adds this branch's reflect/write.go. Semantic
conflict: main unexported lifeboat.VerifyManifest (83e558c), so
retrospectives.go calls verifyManifest.

Assisted-by: Claude:claude-opus-5-5
dbfdb1d)

The doc-fidelity gate (`abcd docs fidelity`, `abcd docs fidelity record`)
with the brief chapters it judges; itd-60 ships (shipped on the branch).
One conflict, the generated .abcd/development/release/surface.json, taken
from main and regenerated with `go generate ./internal/surface/cli` over
the merged tree. Semantic conflict: the core reach audit on main refuses
docfidelity.Judge, Names and Shipped, which no production code outside the
package reaches; they are unexported, and the one cross-package test use
calls the declared seam ShippedForTest.

Assisted-by: Claude:claude-opus-5-5
10-docs.md said the autonomous form "still refuses" whenever the saved
review is not a match for HEAD, while the same paragraph, and the code,
let the change proceed once every drafted edit is applied (a HOLD whose
one draft applied reports refuse=false, exit 0). The sentence now says
"and, unless every drafted edit was applied, it still refuses", the
wording the doc-fidelity re-verification named (df1).

Assisted-by: Claude:claude-opus-5-5
`abcd docs fidelity record` accepted any non-empty judgeModel, so a bare
alias ("m", "claude-opus") or a rolling one (".. -latest") was saved,
and the gate then read the receipt as invalid through the release gate's
receipt reader, which refuses it. The record now applies that reader's
own shape check, lint.FloatingJudgeModel (exported for the purpose), and
refuses before anything is written. The brief chapter (10-docs) and
commands/docs.md say so. Follow-up df2 from the doc-fidelity
re-verification.

TestRecordRefusesAnUnusablePayload's three new cases (bare family alias,
family with no version, rolling alias) were watched fail ("recorded")
before the change and pass after.

Assisted-by: Claude:claude-opus-5-5
Measured on a clean clone of accf618 with `reading assemble --target
HEAD --dry-run --json`; window = ceil(tokens * 1.01 / 10000) * 10000.
widening 1473012 tokens (was 0.47% under its window) -> 1490000;
entailment 424468 -> 430000 (unchanged); detection 1482048 (was 0.54%
under) -> 1500000.

Refs: iss-2609251455354719
Assisted-by: Claude:claude-opus-5-5
The doc-fidelity store tests spawned git with the ambient environment, so
TestTestGitCallsAreHermetic, the hermetic-git gate, failed at the
integration tip: a developer's global git configuration could reach the
fixture repositories. The helper now sets cmd.Env = gittest.Env(t), as
every other test that spawns git does. The gate was watched fail on the
full run and pass after.

Assisted-by: Claude:claude-opus-5-5
@REPPL
REPPL enabled auto-merge September 30, 2026 15:48
@REPPL
REPPL added this pull request to the merge queue Sep 30, 2026
Merged via the queue into main with commit 4b9b29c Sep 30, 2026
14 checks passed
@REPPL
REPPL deleted the integ/land-24c branch September 30, 2026 16:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant