Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
78 commits
Select commit Hold shift + click to select a range
62d1ab5
fix(guard): read a default's word, deep alternatives and a substring'…
REPPL Sep 29, 2026
cfe4d83
chore(issues): capture a trim that can leave only the root
REPPL Sep 29, 2026
6b4516f
chore: resolve iss-2609290426544292 — a default's word reads as the h…
REPPL Sep 29, 2026
e8fa545
chore(issues): capture the trim and replacement siblings of the root …
REPPL Sep 30, 2026
d82049f
fix(guard): read a trim or a replacement by its pattern's shape
REPPL Sep 30, 2026
358e0a8
chore: resolve iss-2609292320015665 and its two siblings
REPPL Sep 30, 2026
3b3507c
feat(release): a cut moves every target it passes to `next`
REPPL Sep 30, 2026
7bcea7e
feat(status): a status block row shows the release its intent targets
REPPL Sep 30, 2026
279f524
chore(record): ship itd-2609212103572513 with criterion 3 worded to r…
REPPL Sep 30, 2026
6afb514
feat(drain): read the drained repository's own eligibility record, na…
REPPL Sep 30, 2026
a101c59
feat(ahoy): offer the drain eligibility record at setup, written only…
REPPL Sep 30, 2026
1c11625
docs(decisions): record the drain's own-rule reading, its loud loosen…
REPPL Sep 30, 2026
e73af97
chore(issues): capture review-guardSet's four root bypasses and two s…
REPPL Sep 30, 2026
598f477
fix(guard): read quoted default words, a named IFS, bash 5 patterns a…
REPPL Sep 30, 2026
5b51dbc
chore: resolve review-guardSet's four root bypasses and the /$HOME si…
REPPL Sep 30, 2026
5e3fec2
fix(guard): read a parameter that can print nothing as the text besid…
REPPL Sep 30, 2026
bb652a3
chore: resolve iss-2609300057467536 — a parameter that can print nothing
REPPL Sep 30, 2026
a99b276
chore(issues): capture reverify-guardSet's four finding classes
REPPL Sep 30, 2026
3c68b00
fix(guard): count an IFS named through an expansion
REPPL Sep 30, 2026
8b6ddeb
fix(guard): read a colon default without the empty value
REPPL Sep 30, 2026
97f1d7a
fix(guard): read an expansion that can print nothing as nothing too
REPPL Sep 30, 2026
9e5fb2e
fix(guard): read a positional slice as the parameters it prints
REPPL Sep 30, 2026
2829087
chore: resolve reverify-guardSet's four finding classes
REPPL Sep 30, 2026
788f0a5
fix(drain): refuse a rule record stating any key twice, cap its read,…
REPPL Sep 30, 2026
6683d62
fix(ahoy): ask the drain-rule offer only at a terminal, so a piped an…
REPPL Sep 30, 2026
1f7b436
docs(decisions): record the terminal-only drain-rule offer, the unkno…
REPPL Sep 30, 2026
b8ae7c4
chore: resolve iss-2609300711394709, iss-2609300711402515 — the drain…
REPPL Sep 30, 2026
b93f4cd
chore: resolve iss-2609300711394491 — the drain-rule offer is asked o…
REPPL Sep 30, 2026
5a0184c
chore(issues): capture reverify3-guardSet's two findings
REPPL Sep 30, 2026
ff4016a
fix(guard): take the colon test of @ and * on the count, not a value
REPPL Sep 30, 2026
84ad332
fix(guard): read a name built from an expansion by its shape, not its…
REPPL Sep 30, 2026
74595ed
chore: resolve reverify3-guardSet's two findings
REPPL Sep 30, 2026
b993017
test(termsafe): allowlist buildsName's backtick scans
REPPL Sep 30, 2026
37bf44e
chore(issues): capture that rulings CF1 and CF2 are not built
REPPL Sep 30, 2026
a910d94
docs(decisions): record the person's eighteen rulings of 2026-09-30
REPPL Sep 30, 2026
7ce8b18
docs(capture): offer a SOTA pass before a person writes a machine-fil…
REPPL Sep 30, 2026
3674db3
fix(history): name the foreign owner when refusing another account's …
REPPL Sep 30, 2026
959e433
chore: resolve iss-2609291731336469 — foreign-owned store refusal nam…
REPPL Sep 30, 2026
ab7382d
feat(rules): teach a repository's own guard entries in SHELL
REPPL Sep 30, 2026
b4fe210
chore: resolve iss-2609300756163382 — SHELL teaches a repository's ow…
REPPL Sep 30, 2026
e9a3936
feat(ahoy): offer to install a missing gh on a yes typed at a terminal
REPPL Sep 30, 2026
3802c49
chore: resolve iss-2609281911024838 — ahoy offers to install gh
REPPL Sep 30, 2026
dd7f6a7
fix(status): the board's next-up head pays build next's peers check
REPPL Sep 30, 2026
1029ff5
feat(capture): run the filing-time match on inbox promote and the con…
REPPL Sep 30, 2026
9a546b4
chore(issues): note two of three filing-match routes landed
REPPL Sep 30, 2026
415f8eb
fix(oracle): skip a repository's route to a keyed provider with a war…
REPPL Sep 30, 2026
0f718f5
chore(issues): capture the round-5 IFS target regression
REPPL Sep 30, 2026
2d7ac0a
fix(guard): read an assignment target holding an expansion as naming IFS
REPPL Sep 30, 2026
5649f53
chore: resolve iss-2609300812525892 — the round-5 IFS target regression
REPPL Sep 30, 2026
b6f27a4
fix(intent): settle a blocker replaced by an accepted ADR or a discip…
REPPL Sep 30, 2026
d5f7b43
chore: resolve iss-2609300751191426 — rulings CF1 and CF2 are built
REPPL Sep 30, 2026
92f0845
fix(ahoy): say a skipped provider route at connect, credential and th…
REPPL Sep 30, 2026
5e6f1ff
chore: resolve iss-2609300805090515 — skipped provider routes are sai…
REPPL Sep 30, 2026
52327c0
docs(decisions): record ruling DQ2b, reversing itd-180's warm-work-on…
REPPL Sep 30, 2026
b796ac7
feat(reading): match every stored finding and the draft its promotion…
REPPL Sep 30, 2026
f2ebd0c
chore: resolve iss-2609281911024185 — the filing-time match runs on e…
REPPL Sep 30, 2026
42f0503
fix(bootstrap): announce an update once, when the swap completes
REPPL Sep 30, 2026
b25ba21
chore: resolve iss-2609291942520919 — the update is announced once, a…
REPPL Sep 30, 2026
205b2ad
feat(lint): resolve a reading item named by a typed link
REPPL Sep 30, 2026
4fb3575
fix(ahoy): claim an unseen update once per release, per-root included
REPPL Sep 30, 2026
a5e772b
chore: resolve iss-2609300939590291 — an unseen update is claimed onc…
REPPL Sep 30, 2026
5d8aad6
merge: land fix/guard-trim-to-root (drainTrim, 5649f5362)
REPPL Sep 30, 2026
34d26f1
merge: land feat/guard-teach-repo-entries (teachRepoGuard, b4fe21075)
REPPL Sep 30, 2026
820e236
merge: land fix/ahoy-connect-config-warnings (connectWarn, 5e6f1ff26)
REPPL Sep 30, 2026
1cee445
merge: land fix/blocker-settled-adr-discipline (cfSettled, d5f7b4369)
REPPL Sep 30, 2026
4e2e04e
merge: land feat/filing-duplicate-every-route (filingMatch2 + filingR…
REPPL Sep 30, 2026
9d001ab
merge: land fix/installer-previous-tag (installerMeta2, a5e772b7d)
REPPL Sep 30, 2026
0f6c018
merge: land feat/target-release-next (targetNext, 279f5241f)
REPPL Sep 30, 2026
0bc9279
merge: land feat/drain-own-rule (drainOwnRule, b93f4cdd3)
REPPL Sep 30, 2026
cf73fde
merge: land feat/ahoy-offer-gh (ghOffer, 3802c4971)
REPPL Sep 30, 2026
1b47001
docs(decisions): correct the unseen-update claim's name in the CJ1 entry
REPPL Sep 30, 2026
20218e0
docs(intent): amend itd-2609211116005482 decision 9 for rulings CF1 a…
REPPL Sep 30, 2026
4f6c76d
test(intent): pin a decision id two files claim, skipped until adrIdU…
REPPL Sep 30, 2026
718fd82
fix(guard): name no real home directory in the IFS-split test's comment
REPPL Sep 30, 2026
a586d62
chore: resolve iss-2609301046113575 — the guard test's comment names …
REPPL Sep 30, 2026
03c2b99
chore: recalibrate the reading windows at the integration tip
REPPL Sep 30, 2026
105617e
test(reachaudit): ratchet the core baseline down by one
REPPL Sep 30, 2026
9804500
fix(decide): build a stated ADR from the skeleton's pieces, not a del…
REPPL Sep 30, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 11 additions & 11 deletions .abcd/config/reading-presets.json
Original file line number Diff line number Diff line change
Expand Up @@ -60,10 +60,10 @@
"test"
],
"window": {
"tokens_est": 1440000,
"measured_tokens_est": 1421126,
"measured_bytes": 5471337,
"measured_at": "d37b3f04964399db5a214460357b7bdad23f74c0"
"tokens_est": 1460000,
"measured_tokens_est": 1441769,
"measured_bytes": 5550812,
"measured_at": "a586d62ff35df482f45a93989466d3a4d1b230e4"
}
},
"entailment": {
Expand Down Expand Up @@ -133,9 +133,9 @@
],
"window": {
"tokens_est": 420000,
"measured_tokens_est": 406587,
"measured_bytes": 1565362,
"measured_at": "d37b3f04964399db5a214460357b7bdad23f74c0"
"measured_tokens_est": 411876,
"measured_bytes": 1585724,
"measured_at": "a586d62ff35df482f45a93989466d3a4d1b230e4"
}
},
"comparative": {
Expand Down Expand Up @@ -216,10 +216,10 @@
"test"
],
"window": {
"tokens_est": 1450000,
"measured_tokens_est": 1430162,
"measured_bytes": 5506125,
"measured_at": "d37b3f04964399db5a214460357b7bdad23f74c0"
"tokens_est": 1470000,
"measured_tokens_est": 1450805,
"measured_bytes": 5585600,
"measured_at": "a586d62ff35df482f45a93989466d3a4d1b230e4"
}
}
}
Expand Down
2 changes: 1 addition & 1 deletion .abcd/development/brief/02-constraints/03-invariants.md
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,6 @@ The following are non-negotiable invariants — any architectural choice that vi

18. **Shape claims in the brief's surface chapters are derived, never hand-authored** — every flag and sub-verb the chapters under `04-surfaces/` state comes from the command tree, through one generated appendix at the end of each chapter under `04-surfaces/`, composed from the walk that builds the compatibility snapshot, with one exception: a chapter's `## Sub-verbs` table (adr-40 §6) and its standard note are hand-written, and `surface_coverage` checks them against the snapshot in both directions. A chapter whose command the tree does not register carries the same block saying there is no shipped surface. The prose above the appendix states no flag the tree registers and no sub-verb written as an invocation, and says why a surface exists, what it refuses and which trade was made. The appendix carries flags and sub-verbs only: exit codes, output fields and behavioural claims stay prose and review-grain until the binary records them where a generator can read. Per [adr-2609231028044006](../../decisions/adrs/2609231028044006-surface-chapter-shape-claims-are-derived-never-hand-authored.md), delivering itd-147. Held by `TestSurfaceAppendicesMatchCommandTree` and `TestSurfaceChapterProseStatesNoShape` (`internal/surface/cli/brief_appendix_test.go`), which run in `go test ./...`. `surface_coverage` stays the row-level presence check over the surfaces index and each chapter's sub-verb table, and says so in every finding. The invariant holds those chapters only: a shape claim elsewhere in the record is not checked by it. How a chapter is added is in [`04-surfaces/README.md` § The generated appendix](../04-surfaces/README.md#the-generated-appendix).

19. **A machine takes an issue alone only when its fields say it needs no decision** — an unattended drain takes an open issue only when no record in its `blocked_by` is still open, its category is in the fixable set (`bug`, `documentation`, `drift`, `inconsistency`, `tech-debt`, `ux`), its severity is `nitpick` or `minor`, and it carries a `remedy:` other than `none (filed automatically)`, the value an automatic filer writes when it has no fix (every new issue carries a remedy; a record filed before that carries none and is listed as ineligible); `security` is always a person's, and every other open issue is handed back, listed as ineligible or skipped by the rule that excluded it, each with exactly one disposition. A host judgement over the remedy may only hand an issue back, never let one through, and the classification is re-derived every run rather than written onto the issue. The drain refuses to start without the record of the rule. Per [adr-2609291342092738](../../decisions/adrs/2609291342092738-a-drain-takes-an-issue-alone-only-when-its-fields-say-it.md), from itd-82 decision 4; the rule is `eligibility` in `internal/core/capture/eligible.go`, reached through `capture.PlanDrain`, and `TestTheEligibilityRuleIsRecordedAndAccepted` holds the record the binary names to an accepted record this invariant cites.
19. **A machine takes an issue alone only when its fields say it needs no decision** — an unattended drain takes an open issue only under the drained repository's own rule, read from an accepted decision record in its own store carrying the four `drain_` fields, and refuses a repository without one, or with a partial, malformed or ambiguous one, never falling back to a looser or a stricter rule. Under that rule it takes an issue only when no record in its `blocked_by` is still open, its category and severity are ones the rule takes, it carries a `remedy:` other than `none (filed automatically)`, the value an automatic filer writes when it has no fix, and its remedy does not open "Waits on" nor is its deferral live at the current anchor tag (every new issue carries a remedy; a record filed before that carries none and is listed as ineligible); every other open issue is handed back, listed as ineligible or skipped by the rule that excluded it, each with exactly one disposition. abcd's strict baseline takes the fixable set (`bug`, `documentation`, `drift`, `inconsistency`, `tech-debt`, `ux`) at `nitpick` or `minor` and hands every `security` issue to a person; a repository's record may narrow it, and may loosen it to `major`, `critical` or `security`, and every floor loosened is named by the dry run and at the start. A host judgement over the remedy may only hand an issue back, never let one through, and the classification is re-derived every run rather than written onto the issue. abcd's own repository states the baseline in [adr-2609291342092738](../../decisions/adrs/2609291342092738-a-drain-takes-an-issue-alone-only-when-its-fields-say-it.md), from itd-82 decision 4 and the product thinker's rulings BX2 and H11; the record is read by `drainrule.Load` in `internal/core/drainrule/drainrule.go`, the rule is `eligibility` in `internal/core/capture/eligible.go`, reached through `capture.PlanDrain`, and `TestAbcdsOwnDrainRuleIsTheStrictBaseline` holds abcd's own record to the baseline and to this citation.

20. **A workflow asserts a person's authorship only inside a declared bound, and a machine never becomes an identity on the commit** — a bot-opened dependency bump is re-authored only when its author and the run's actor are a bot the repository's declaration names, its branch lives in the repository under the row's prefix, it carries one commit by that bot, and that commit only modifies files the row names at the directory the bot's own configuration declares; anything else is left alone with the failed clause named. The re-authored commit carries the owner the declaration names as author AND committer; the GitHub App that pushes it is never either, so the attribution gate stays unchanged and judges it like any other commit. The bound judges which files change, never their content, and that residual is accepted on the record. The App's credentials are Dependabot secrets, and while the owner or either secret is missing an in-bound bump is refused by name — the workflow never pushes with its own token and never keeps the bot as author. Per [adr-2609292116133348](../../decisions/adrs/2609292116133348-a-dependency-bump-inside-the-bound-is-re-authored-as-the.md), on iss-2609221820487644 and itd-2609221842494980; the bound is `scripts/dependency-reauthor.sh`, byte-exact with the template `abcd launch scaffold` lays, held by the tests in `internal/core/launch/scaffold/dependency_reauthor_test.go`.
12 changes: 12 additions & 0 deletions .abcd/development/brief/04-surfaces/01-ahoy.md
Original file line number Diff line number Diff line change
Expand Up @@ -119,6 +119,17 @@ the API host explicitly, so an ambient host variable cannot send the write to an
endpoint the origin never named, and the call goes through the caller's own
authenticated identity: abcd never holds a token.

That identity is the GitHub CLI's, so a missing `gh` is met with the
explain-then-install mode (itd-63): after the first three gates and before the
read, the verb explains `gh` from the tool registry and offers to install it,
running the registry's step only on a yes typed at a terminal. The pre-given
yes answers the settings change and never the install of a program, and a
piped answer is not a person's answer, so both decline the offer; the verb then
refuses, its notes carrying the explanation and the command. A failed or
unverified install refuses the same way, before any request leaves the
machine. The read never offers the install, because looking is never acting;
it names the apply as the verb that does.

### The provider setup

The setup takes the provider's name, its base URL, its first allowlist (every
Expand Down Expand Up @@ -476,6 +487,7 @@ about, one question per category present, never one per item.
| `dependency` | a tool a capability uses and cannot find: gitleaks, optional over the native secret scanner and required where the repository armed it in `.abcd/config/gitleaks.json` | the category approval reaches the step; each tool is then explained from the tool registry (what it is, optional or required here, what works without it, the exact install step, what the install does) and its install step runs only on a per-tool yes — typed at a terminal, or relayed by a host as a flag naming the tool — never under the approve-everything flag, a piped answer or CI; a no is reported as what the capability continues on |
| `status-line` | the offer of abcd's status line in the host harness | an advisory offer asked after its own question, written only on an answered consent; never under the approve-everything flag, and reported as optional work it skipped |
| `oracle-routing` | the offer of abcd's proposed model-tier routing table (itd-2609170822093401): the machine's `~/.abcd/oracle-routing.json`, then, as a separate question, the repository's `.abcd/config/oracle-routing.json` | the proposal rendered as a table (agent, tier, fan-out) and each file written only on its own answered consent, the machine one owner-only; never under the approve-everything flag, and reported as optional work it skipped; a decline records nothing, so the next install offers again; uninstall leaves both files |
| `drain-rule` | the offer of the repository's drain eligibility record (ruling BX2, itd-82): abcd's strict baseline as an accepted decision record carrying the four `drain_` fields, minted through the decision store's seam | the rule stated in one question and the record written only on a consent answered at a terminal; never under the approve-everything flag and never off a terminal, where neither its category nor the offer is asked (so a piped answer stream keeps its order), and reported as optional work it skipped; a decline records nothing, so the next install offers again; raised only while no accepted record states the rule, so a record stating it badly is never offered a second; only ever the baseline, never a loosened rule |
| `user-state` | the registry entry, re-founding, stale or duplicate entries | guided; never auto-edit user-scope state, report extras read-only |

**The artefact kind is a gap until it is declared** (itd-2609150819432059). A
Expand Down
8 changes: 7 additions & 1 deletion .abcd/development/brief/04-surfaces/04-launch.md
Original file line number Diff line number Diff line change
Expand Up @@ -675,7 +675,13 @@ the parity diff and the deep smoke tier where the run made them, and every
planned intent that names a release it must land by, under *Targeted, not
shipped* (itd-2609212103572513): the preview, the cut's emit and its ingest list
the same intents in their human and machine-readable output too, and none of
them refuses on one.
them refuses on one. The ingest moves every target the cut passes (`next`, or a
tag at or below the derived version) to `next`, whatever the following release
is numbered (the product thinker's ruling BS1 of 2026-09-29), rewriting the
record in the write that rolls the changelog and naming the move in one line
under the dated section's notice (`changelog.TargetMoveNote`), which the site's
release stamp passes over because the line names intents the release did not
ship.
A refused cut writes its report too, and the refusal names where it landed. The
preview's JSON carries `report_path`, the cut's `preflight_report`. A detector
fails the build if any non-test Go source under `internal/` so much as names the
Expand Down
Loading
Loading