Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
40 commits
Select commit Hold shift + click to select a range
5503721
docs(pace): a run works in parallel up to its ceiling (ruling DR6)
REPPL Sep 30, 2026
d4ad5aa
docs(pace): clear the DR6 spec review's amend items; mark DR6b and DR…
REPPL Sep 30, 2026
7f6eb55
merge: bring main into dr6Spec
REPPL Sep 30, 2026
fa4073d
docs: rule DR6b and DR6c into the DR6 spec amendment
REPPL Sep 30, 2026
b68b3d4
feat(intent): a failed or undecided after-merge audit leaves the inte…
REPPL Sep 30, 2026
8f684ee
chore: resolve iss-2608290820473197 — an undecided audit is flagged a…
REPPL Sep 30, 2026
4780fd7
docs: the DR6 amendment names schema 8, the built landing and three s…
REPPL Sep 30, 2026
e3df1e9
feat(spec): a step's needs line, and its rewrite across a remainder
REPPL Sep 30, 2026
7148862
feat(intent): the owed-review listing names a flagged receipt apart
REPPL Sep 30, 2026
8f49c2e
feat(cli): a provider-run audit names the check it leaves owed
REPPL Sep 30, 2026
b83f51a
chore(capture): the loop armed auto-merge where no approval is required
REPPL Sep 30, 2026
22eeb1f
fix(implement): arm auto-merge only where a person's approval is requ…
REPPL Sep 30, 2026
492e170
chore: resolve iss-2609301858349258 — arm only where approval is requ…
REPPL Sep 30, 2026
72c1f22
docs(brief): the arm step's left-open state names no command shape
REPPL Sep 30, 2026
a1a1baf
fix(capture): file one owed-check issue under concurrent audit ingests
REPPL Sep 30, 2026
a69389e
chore: resolve iss-2609301913458174 — one owed-check issue per receipt
REPPL Sep 30, 2026
4694609
docs(intent): the owed-check issue is one per receipt, concurrent ing…
REPPL Sep 30, 2026
3c19408
feat(loop): a run works in parallel up to its ceiling
REPPL Sep 30, 2026
9edbe18
test(loop): the needs default and one landing hold while a merge waits
REPPL Sep 30, 2026
508b79f
docs: close the pacing spec at criterion 6, with a remainder for 7 and 8
REPPL Sep 30, 2026
770ad92
merge: bring main into dr6Build
REPPL Sep 30, 2026
54a36f1
fix(loop): a refused stage stops the step, and a ready lane opens at …
REPPL Sep 30, 2026
fd4fc88
fix(loop): a merged armed lane lands, and a discard leaves nothing ha…
REPPL Sep 30, 2026
29a7826
docs: the step's help, pages and brief state the refused stage, eager…
REPPL Sep 30, 2026
600d267
merge: land fix/arm-only-under-review (amApproval, 72c1f221b)
REPPL Sep 30, 2026
a802800
merge: land feat/loop-parallel-lanes (dr6Build, 29a7826b6)
REPPL Sep 30, 2026
b515a4d
test(loop): a held lane is never armed, and a released one lands thro…
REPPL Sep 30, 2026
8e06650
docs(decisions): the parallel run's state is schema version 9
REPPL Sep 30, 2026
f6705a9
merge: land feat/audit-owed-flag (dq1cFlag, 4694609d3)
REPPL Sep 30, 2026
d15926f
chore(capture): the arm decision reads CODEOWNERS more loosely than t…
REPPL Sep 30, 2026
2b593e0
fix(loop): read CODEOWNERS as the forge does before arming a code-own…
REPPL Sep 30, 2026
bbc106a
chore: resolve iss-2609302205483845 — the arm decision reads CODEOWNE…
REPPL Sep 30, 2026
34b1dce
chore(capture): a passing audit leaves an unflagged receipt's orphan …
REPPL Sep 30, 2026
f52ca65
fix(intent): a passing audit sweeps its receipt's open owed-check car…
REPPL Sep 30, 2026
8be4fc8
chore: resolve iss-2609302207449478 — a passing audit sweeps its rece…
REPPL Sep 30, 2026
fb38fe2
chore(capture): a failed site build never names the labels it added
REPPL Sep 30, 2026
117b8b0
fix(site): a failed build still names the labels it added to ui.json
REPPL Sep 30, 2026
c23ec03
chore: resolve iss-2609302210137965 — a failed site build names the l…
REPPL Sep 30, 2026
4553f94
chore: recalibrate the reading windows at the integration tip
REPPL Sep 30, 2026
7cec03f
Merge branch 'main' into integ/land-24d
REPPL Oct 1, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 12 additions & 12 deletions .abcd/config/reading-presets.json
Original file line number Diff line number Diff line change
Expand Up @@ -60,10 +60,10 @@
"test"
],
"window": {
"tokens_est": 1490000,
"measured_tokens_est": 1473012,
"measured_bytes": 5671097,
"measured_at": "accf61856ef2b893208e298137a690a33749004e"
"tokens_est": 1510000,
"measured_tokens_est": 1489409,
"measured_bytes": 5734225,
"measured_at": "c23ec03b994c352a1d8e5a37efbf30124bae5703"
}
},
"entailment": {
Expand Down Expand Up @@ -132,10 +132,10 @@
"intent-projection"
],
"window": {
"tokens_est": 430000,
"measured_tokens_est": 424468,
"measured_bytes": 1634205,
"measured_at": "accf61856ef2b893208e298137a690a33749004e"
"tokens_est": 440000,
"measured_tokens_est": 427804,
"measured_bytes": 1647049,
"measured_at": "c23ec03b994c352a1d8e5a37efbf30124bae5703"
}
},
"comparative": {
Expand Down Expand Up @@ -216,10 +216,10 @@
"test"
],
"window": {
"tokens_est": 1500000,
"measured_tokens_est": 1482048,
"measured_bytes": 5705885,
"measured_at": "accf61856ef2b893208e298137a690a33749004e"
"tokens_est": 1520000,
"measured_tokens_est": 1498444,
"measured_bytes": 5769013,
"measured_at": "c23ec03b994c352a1d8e5a37efbf30124bae5703"
}
}
}
Expand Down
6 changes: 3 additions & 3 deletions .abcd/development/brief/04-surfaces/05-intent.md

Large diffs are not rendered by default.

3 changes: 2 additions & 1 deletion .abcd/development/brief/04-surfaces/22-site.md
Original file line number Diff line number Diff line change
Expand Up @@ -143,7 +143,8 @@ A label the struct declares and the file leaves blank fails the build by name. A
label the file does not carry at all, which is how a file written before that
label existed reads, is added to the file by the build and by setting up, with
the words abcd's own interface-string file gives it: each added label is named
on standard error, every byte already in the file stays, and a file carrying a
on standard error, before the error when the build then fails, every byte
already in the file stays, and a file carrying a
key no field reads is left untouched and refused as before. The render the
site gate makes of an empty output directory writes only inside that directory,
so it never completes the file and refuses an incomplete one by name
Expand Down
32 changes: 26 additions & 6 deletions .abcd/development/brief/04-surfaces/27-implement.md
Original file line number Diff line number Diff line change
Expand Up @@ -259,12 +259,30 @@ signals anything.
Three sub-verbs drive the loop a build starts, each over the run's state file in
the checkout's local tier ([`34-build.md`](34-build.md) states the file, the
checks and the step interface). The status render reads every run, or the one
named, and writes nothing. The step verb performs the current lane's next stage and
exits (a lane's stages are worktree, brief, implement, validate and land; the
lane as a whole lands one of the spec's steps); at a stage that hands work to an
agent it names the agent, the brief and the receipt path, and asking again moves
nothing. The receipt hands that file back, and the stage completes only when the
path is the one named and its verifier accepts it. Without a named run, the step
named, and writes nothing: it names the slots in use out of the run's ceiling,
every lane alive with its stage and each agent it awaits, and each held lane with
its cause, the head judged, the landing step it stopped before and the two flags
that decide it. The step verb performs the run's next move and exits (a lane's
stages are worktree, brief, implement, validate and land; the lane as a whole
lands one of the spec's steps). A run works in parallel up to its ceiling (ruling
DR6): a stage the binary owns moves on any lane first, then, while a slot is
free, the first waiting work takes it, an open lane's before a new lane's and
the lower spec step first; a lane opens for a ready spec step whatever the
ceiling, and only its implementer waits for a slot; at a stage that hands work
to an agent it names the agent, the brief and the receipt path, and a step that
finds the ceiling reached hands out nothing and names every agent out. A landing
waiting on the forge's merge holds only its own lane; any other refused stage
the binary performs is the step's answer. The receipt verb looks the path up
among every outstanding await of the run, and the stage completes only when a
lane awaits that path and its verifier accepts it; a verified receipt frees its
slot. After a hand-back the siblings finish and a lane whose round passes is
held before it pushes or arms (ruling DR6c), an armed one disarmed, or, where
the forge refuses the withdrawal, the step refused naming the pull request; the
person's word on a held lane is given through the step verb, one lane per
invocation: release lands it as it is, and discard removes its worktree and
branch, then closes its pull request, and leaves its step unlanded, each refused, changing nothing, unless the lane is
held and no lane has work left.
Without a named run, the step
and receipt verbs act on the one run in progress in the checkout and refuse naming
the runs when there are several. Their refusals name the stage, the reason and
the remedy, and a pause
Expand Down Expand Up @@ -421,6 +439,8 @@ Sub-verbs: none.

| Flag | Type |
|---|---|
| `--discard` | string |
| `--release` | string |
| `--run` | string |

<!-- surface-appendix:end -->
90 changes: 73 additions & 17 deletions .abcd/development/brief/04-surfaces/34-build.md
Original file line number Diff line number Diff line change
Expand Up @@ -187,9 +187,10 @@ minutes so the window arithmetic stays far inside the clock's range and a typed
extra digit is refused rather than run. A pause of 0 minutes is a run that does
not pause.

The ceiling is recorded with the run; this build does not count lanes against
it (criterion 6), and the budget check and the rate-limit checkpoint (criteria
7 and 8) wait on a runner that reports its quota.
The ceiling binds (criterion 6, ruling DR6): the loop counts the agents out
from the state, implementers and validators together, and starts nothing above
the ceiling. The budget check and the rate-limit checkpoint (criteria 7 and 8)
wait on a runner that reports its quota.

## The state file

Expand All @@ -206,7 +207,16 @@ repository abcd manages has one, so a run is managed-only by construction. Each
run directory is created one level at a time and proved real, the state file is
replaced atomically inside an `os.Root`, and the reader decodes strictly,
refusing an unknown field, a schema version it does not know, or a file stored
under a run id it does not name. The state is schema version 8. Version 8
under a run id it does not name. The state is schema version 9. Version 9
made a run work in parallel up to its ceiling (ruling DR6): a lane's `awaits`,
a list replacing the one `awaiting`, the run's `waiting` (the work the ceiling
holds back, each item with the time first held), a lane's `syncs` (each merge of
the default branch after a sibling landed) and `hold` (a lane held after a
sibling's hand-back, ruling DR6c), a pending step's `needs`, and the lane
stages `held` and `discarded`. A file of version 8 or lower reads as a run
whose lanes await zero or one agent, its `awaiting` carried over to a one-entry
`awaits`; one carrying what only version 9 writes is refused, and so is a
version-9 file carrying `awaiting`. Version 8
added the runner's record (itd-2609201916056194): the run's `fallbacks`, one
receipt per role a routed runner did not run, and the `route` a verified receipt
or a validator's recorded return names when a runner ran its agent. Version 7
Expand All @@ -218,7 +228,7 @@ added the fix-round cap (ruling DR1): the pace's `fix_rounds` and a lane's
`validation`). Each earlier version is the next one's strict subset, read as a
run that predates the addition (a version-5 run runs on the bundled cap, a
version-7 run is one the host ran every agent of) and
written back at version 8 by its next mutation; an earlier version carrying what
written back at version 9 by its next mutation; an earlier version carrying what
only a later one writes is refused. Version 4
renamed the lane's stage (BU1, iss-2609291313276243): a lane's and a record
line's `step` became `stage`, so "step" names only the spec's steps (`spec_step`,
Expand Down Expand Up @@ -258,24 +268,57 @@ the run as its own peer. Only the key's shape is checked before the lookup.

A spec's steps and a lane's stages are two words for two things (BU1,
iss-2609291313276243): each spec step lands as one lane, and the loop takes the
lane through its stages. The step verb performs one stage.
lane through its stages. The step verb performs one move of the run.

A host session drives the loop one stage at a time (decision 5's default). The
A host session drives the loop one move per call (decision 5's default). A
lane's stages run in a fixed sequence: the worktree, the brief, the implementer,
the validators, the landing. Each invocation takes the lock, reads the state,
performs the current lane's next stage and writes the state once, after the
stage succeeds. A stage that fails, or a process killed inside one, leaves the
performs one move and writes the state once, after the move succeeds. A stage that fails, or a process killed inside one, leaves the
state as it was, so the next invocation performs that stage again; a stage the
state records as done is never performed twice (criterion 7). A stage's body is
therefore written to find what it made last time. The result names the stage
the call completed as `performed_stage` and the lane's next as `stage`.

A stage that hands work to an agent does not complete by itself: the lane then
awaits, naming the agent's role, the brief it is handed and the path its receipt
goes to (criterion 8). Asking again re-tells the same thing and moves nothing,
and the lane advances only when that receipt is handed back at that path and its
verifier accepts it. When a lane is done, the next pending spec step opens the
next lane, so the spec's steps land one lane at a time.
goes to (criterion 8), and the lane advances only when that receipt is handed
back at that path and its verifier accepts it.

A run works in parallel up to its ceiling (ruling DR6, spc-2609202134341288). A
slot is one outstanding await on any lane; the count is the awaits in the state
file. Each move first performs a stage the binary owns on any lane (the
worktree, the brief, a round's close, a landing step, a sync, a hold), which
takes no slot and is never held by the ceiling; when the move needs an agent it
takes the first waiting item: an
open lane's validators or fix and sync implementers before a new lane, the lower
spec step first, a round's validators in the order the round lists them, then
the implementer of a new lane. A move that finds the ceiling reached hands out
nothing, names every lane alive with what it awaits, and records the held work
under `waiting`; the move that later serves it records the whole minutes it
waited. A lane opens for a spec step once every step it needs has landed (its
`- needs:` line, or by default every step before it, ruling DR6b), so a spec
that declares no needs lands its steps one lane at a time; it opens whatever the
ceiling, its worktree and brief made, and only its implementer waits for a slot.
A landing waiting on the forge's merge holds only that lane: the move goes to
another and names the wait under `blocked` and in its next move. Any other
refusal of a stage the binary performs, a missing preflight receipt included, is
the move's answer, and no other lane moves.

Landing is one lane at a time, the lower spec step first. A lane whose sibling
landed since its base is synced before its landing begins: the default branch is
merged into its branch with a merge commit, never a rebase, and a fresh round
judges the merge head. A conflicting merge is aborted with the branch unchanged
and goes to a fresh implementer with a sync brief; its receipt must carry the
merged sha as an ancestor of its head. A sync counts no fix round. The closing
lane reaches its landing with no step pending, no other lane open and none handed
back; its audit reads each of the run's lanes' own diff. After a hand-back the
siblings finish, no new lane opens, no lane closes the spec, and a lane whose
round passes is held before its push or its arming (an armed one is disarmed;
where the forge refuses the withdrawal the move refuses naming the pull request,
and one the forge reports merged is recorded as landed), until the person
releases or discards it (ruling DR6c). A discard removes the lane's worktree and
branch before it closes the pull request, so a refused removal leaves nothing
half done.

The loop keeps the run's window clock (criteria 4 and 5). A new run's first
window opens at its start. Once the window's working minutes have elapsed, the
Expand Down Expand Up @@ -510,10 +553,23 @@ until the last step.
branch, never opened twice.
5. It reads the merge rule from the ruleset mirror (`.abcd/work/rulesets/`) at
the lane's base, so the lane's own commits cannot change it (decision 3):
where an active ruleset gates the default branch through a merge queue, it
arms auto-merge with the queue's method; where none does, it leaves the pull
request open for a person to merge. Nothing is pushed to the lane after this
step.
where an active ruleset gates the default branch through a merge queue and
an active ruleset on it requires a person's approval, it arms auto-merge
with the queue's method; otherwise it leaves the pull request open for a
person to merge (ruling AM1). A pull_request rule requires approval when its
`required_approving_review_count` is one or more, or when
`require_code_owner_review` is set and the CODEOWNERS file the forge reads
at the lane's base names at least one owner. That file is the first found
in `.github/`, the root and `docs/`, so one there shadows the later ones
even when it names nobody, and a line names an owner only when its pattern
is followed by `@name`, `@org/team` or an e-mail address: a code-owner
review with nobody to own the change asks no person for anything. A missing
mirror requires nothing, so the pull request stays open; a mirror file that
cannot be read or parsed is refused, which also arms nothing. Where a queue
exists but nothing requires approval, the step's note, the run record and
the run's status say "left open for a person to merge: the ruleset requires
no approval", and no later step arms it. Nothing is pushed to the
lane after this step.
6. It fetches the default branch and waits, exiting 3, until the pushed head
is an ancestor of it; only then does it remove the lane's worktree (never
forced) and delete the lane's branch at a tip the same check proves landed,
Expand Down
9 changes: 9 additions & 0 deletions .abcd/development/brief/04-surfaces/35-drain.md
Original file line number Diff line number Diff line change
Expand Up @@ -73,6 +73,15 @@ that is live; ineligible without a remedy or with the automatic filers' value un
a person writes one; and unreadable when the ledger reader refuses the record. A
record written before the field existed reads its `suggested_fix:` as its remedy.

One automatic filer writes a real remedy. An after-merge fidelity audit that
judges a criterion `NOT_MET` or `INCONCLUSIVE` captures one issue carrying the
check it leaves owed (ruling DQ1c; [`05-intent.md`](05-intent.md)), and its
remedy is the work that clears it: "fix, then re-run the audit" for a failed
criterion, "re-run the audit" for an undecided one. The rule judges such a
record by its fields as it judges any other: a failed audit's record is a
`major` `bug`, which the baseline hands back on severity, and an undecided
one's is a `minor` `inconsistency`, which the baseline takes.

Two hand-backs hold whatever the repository's record says, because each marks a
decision a person still owes. A remedy that opens "Waits on" as words, followed
by a blank, a colon or nothing (the shape a remedy takes when its fix waits on an
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -54,6 +54,8 @@ Settled on 2026-09-20 with one defensible answer each, on the product thinker's
4. **Layering is flag, then repository, then machine, then bundled**, the order the model-tier intent already uses.
5. **The bundled default is 120 minutes of work, 300 of pause, two lanes**, the product thinker's numbers for this repository's runs on 2026-09-20; a repository that measured otherwise writes its own.
6. **The budget check and the rate-limit checkpoint come here from `itd-29`**, superseded on 2026-09-20 by the implement verb: A run refuses to start when the estimated cost exceeds the remaining quota where the runner reports one, and a rate-limit response checkpoints the lane and ends the window early.
7. **A run works in parallel up to its ceiling** (ruling DR6, the product thinker, 2026-09-29, verbatim: "per-run agent limit: WORK IN PARALLEL — a run may build several pieces and run reviewers concurrently up to its limit (new build-loop work; then AC6 is testable)."). The validators of a round run side by side, the lanes of steps that do not need each other run side by side, and implementers and reviewers share the ceiling; criterion 6 is tested through the concurrent loop the spec's piece 6 designs.
8. **Steps run one after another unless their plan says otherwise, and a hand-back holds the siblings' landings** (rulings DR6b and DR6c, the product thinker, 2026-09-30). DR6b, verbatim: "(a) ONE AFTER ANOTHER BY DEFAULT: a step runs alongside earlier ones only if its plan says so; nothing already planned changes; reviews run side by side; the 2026-09-21 wording stands." DR6c, verbatim: "(c) FINISH, BUT HOLD THEM: when one piece is handed back, pieces in flight finish but nothing merges until the person re-plans; the person then decides whether the held pieces land as they are." A step's default `needs` is every earlier step, opted out of per step; after a hand-back the sibling lanes run to completion and each passing one is `held`, never armed, until the person releases or discards it with `implement step --release <lane>` or `--discard <lane>` (the spec's piece 6, criteria C6, C11 and C13).

## Open Questions

Expand Down
14 changes: 14 additions & 0 deletions .abcd/development/release/surface.json
Original file line number Diff line number Diff line change
Expand Up @@ -1822,6 +1822,20 @@
"hidden": false,
"sentence": "Perform the next stage of an implement loop run's lane and exit: Writes the run's state and the lane's stages; refuses a push with no preflight receipt.",
"flags": [
{
"name": "discard",
"shorthand": "",
"type": "string",
"required": false,
"hidden": false
},
{
"name": "release",
"shorthand": "",
"type": "string",
"required": false,
"hidden": false
},
{
"name": "run",
"shorthand": "",
Expand Down
Loading
Loading