Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
39 commits
Select commit Hold shift + click to select a range
f0ef93c
feat(reflect): the release retrospective's core — seed, floor, writer…
REPPL Sep 30, 2026
5992b38
feat(docfidelity): the doc-fidelity judgement and its saved review
REPPL Sep 30, 2026
02ec15a
feat(docfidelity): spec close and launch ship enforce the gate
REPPL Sep 30, 2026
662f9c8
feat(docfidelity): draft and apply, flagged for review after
REPPL Sep 30, 2026
b051074
feat(docs): abcd docs fidelity, its record verb, and the brief baseline
REPPL Sep 30, 2026
1fae403
chore: capture the twelve surfaces the doc-fidelity gate found uncovered
REPPL Sep 30, 2026
7d50be1
chore(records): close spc-2609020903498198, ship itd-60
REPPL Sep 30, 2026
66781bd
style(lint): gofmt the gate-receipt reader
REPPL Sep 30, 2026
9ddfe9d
fix(docfidelity): name the recorded backlog doc-fidelity-backlog.json
REPPL Sep 30, 2026
d9c67b6
docs(brief): name the twelve backlogged surfaces in their chapters
REPPL Sep 30, 2026
ce5c070
chore: resolve iss-2609300839021188 — every shipped surface has a cha…
REPPL Sep 30, 2026
f6485ae
merge: bring main into reflect2
REPPL Sep 30, 2026
0207356
feat(reflect): the release retrospective's command, interview and lif…
REPPL Sep 30, 2026
84cc3ba
chore(reflect): ship itd-24, closing spc-2609211751376504
REPPL Sep 30, 2026
768f2f7
docs(reflect): list reflect in the surfaces chapter's commands index
REPPL Sep 30, 2026
1e95b21
chore(reflect): re-pin the example receipt to the release-gate manifest
REPPL Sep 30, 2026
657861a
feat(oracle): a paid provider takes only a self-contained agent by de…
REPPL Sep 30, 2026
552c542
fix(embark,reflect): serialise a retrospective write with an embark, …
REPPL Sep 30, 2026
59ec5ce
test(reflect): arm the write's refusal of a degraded scanner
REPPL Sep 30, 2026
7f6c9e3
fix(reflect): mask control and bidi bytes in answers before the write
REPPL Sep 30, 2026
aeb28ee
test(cli): the reflect refusal tests assert the refusal text, not onl…
REPPL Sep 30, 2026
018dad0
docs(itd-24): read release membership as the cut does, under ruling AD
REPPL Sep 30, 2026
61c5745
chore: resolve iss-2609301245517138 — a retrospective written during …
REPPL Sep 30, 2026
62cb45d
docs(embark): name the reflect verb in prose, not by its command shape
REPPL Sep 30, 2026
67adf55
chore: capture iss-2609301251469172 — the doc-fidelity gate fails ope…
REPPL Sep 30, 2026
d155841
fix(docfidelity): close the three ways the gate failed open
REPPL Sep 30, 2026
dbfdb1d
chore: resolve iss-2609301251469172 — the doc-fidelity gate fails closed
REPPL Sep 30, 2026
51c7a97
feat(oracle): the delegating verbs send a step to the provider it is …
REPPL Sep 30, 2026
77c8b79
docs(oracle): say what provider dispatch sends, and record DR5's deci…
REPPL Sep 30, 2026
bb39155
test(reachaudit): ratchet the core baseline down by one
REPPL Sep 30, 2026
ad9282d
merge: land feat/provider-dispatch-verbs (providerDispatch2, bb3915527)
REPPL Sep 30, 2026
70c8a23
feat(reading): a dispatch names its unscanned items before the send
REPPL Sep 30, 2026
5951460
chore: close spc-2609221011153746 and ship itd-2609081951381895
REPPL Sep 30, 2026
0ebf2fe
merge: land feat/reflect-command (reflect2, 62cb45d84)
REPPL Sep 30, 2026
cc6d72e
merge: land docs/brief-chapter-backfill (docFidelity + chapterBackfil…
REPPL Sep 30, 2026
cdd78b0
docs(brief): the autonomous docs gate refuses unless every draft applied
REPPL Sep 30, 2026
accf618
fix(docs): the fidelity record refuses a floating judge model
REPPL Sep 30, 2026
194443c
chore: recalibrate the reading windows at the integration tip
REPPL Sep 30, 2026
cf3d3c9
test(docfidelity): run the store tests' git through gittest.Env
REPPL Sep 30, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 11 additions & 11 deletions .abcd/config/reading-presets.json
Original file line number Diff line number Diff line change
Expand Up @@ -60,10 +60,10 @@
"test"
],
"window": {
"tokens_est": 1480000,
"measured_tokens_est": 1463871,
"measured_bytes": 5635907,
"measured_at": "cb46dbea2c0eb37f4aa976f59046f785a32a86eb"
"tokens_est": 1490000,
"measured_tokens_est": 1473012,
"measured_bytes": 5671097,
"measured_at": "accf61856ef2b893208e298137a690a33749004e"
}
},
"entailment": {
Expand Down Expand Up @@ -133,9 +133,9 @@
],
"window": {
"tokens_est": 430000,
"measured_tokens_est": 418715,
"measured_bytes": 1612056,
"measured_at": "cb46dbea2c0eb37f4aa976f59046f785a32a86eb"
"measured_tokens_est": 424468,
"measured_bytes": 1634205,
"measured_at": "accf61856ef2b893208e298137a690a33749004e"
}
},
"comparative": {
Expand Down Expand Up @@ -216,10 +216,10 @@
"test"
],
"window": {
"tokens_est": 1490000,
"measured_tokens_est": 1472907,
"measured_bytes": 5670695,
"measured_at": "cb46dbea2c0eb37f4aa976f59046f785a32a86eb"
"tokens_est": 1500000,
"measured_tokens_est": 1482048,
"measured_bytes": 5705885,
"measured_at": "accf61856ef2b893208e298137a690a33749004e"
}
}
}
Expand Down
11 changes: 11 additions & 0 deletions .abcd/development/agents/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,17 @@ over the brief's earlier `1.0.0`-at-close expectation). The four M6 synthesis
agents below entered at `0.1.0`, wired to their `abcd disembark` verbs and
unmeasured; `lifeboat-oracle` has since become `lifeboat-reviewer` at `0.1.1`.

## 2026-09-30 (itd-24 — the release retrospective)

### reflection-composer 0.1.0

NEW: the retrospective interview's composer. It reads the seed `abcd reflect
<release-tag> --json` renders, asks the four asked sections one question at a
time, meets a thin answer with the section's one follow-up, and emits the
four-key answers object `abcd reflect write` files. It reads intent records and
the changelog as untrusted data (injection canary under its fixtures).
Unmeasured, in the `0.x` band.

## 2026-09-29 (itd-2609212103572513 — the cut lists targeted intents)

### release-changelog-composer 0.4.1
Expand Down
2 changes: 1 addition & 1 deletion .abcd/development/brief/01-product/01-press-release.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ The lifeboat widens from whole repositories to narrower sources — a single fea
- **Unpack the lifeboat:** `/abcd:embark from <path>` reads the lifeboat, runs a press-release interview to confirm the framing with the user, scaffolds the new repo at canonical locations, and writes provenance so the rebuild knows where it came from. `<path>` is wherever a prior disembark landed its lifeboat; there is no in-tree lifeboat home and no `home` shorthand.
- **Install / promote:** `/abcd:ahoy install` bootstraps abcd in any repo (transparent prompts, visibility-driven gitignore, marker block in CLAUDE.md/AGENTS.md, prompt-router hook). `/abcd:launch ship` cuts a curated release from the single repo — `.abcd/**` excluded from the artifact by packaging — with secret/PII scans and a version stamp.
- **Forward-looking discipline:** `/abcd:intent` captures product intents in three structural kinds per itd-34 — `standalone` (one user moment, one spec), `bundle-member` (coupled intents share a spec), and `discipline` (cross-cutting rules with no user moment, e.g., the itd-1 acceptance-gates rule that enforces Given-When-Then on every other spec). Standalone and bundle-member intents are press-release-shaped; disciplines use a `## Rule` template instead. `/abcd:capture` runs a structured issue ledger at `.abcd/work/issues/` rather than free-form notes. `/abcd:intent ready` answers the question that gates the build: is this intent ready to implement, and if not, what is missing. After shipping, `/abcd:intent audit` (Role 1 of `intent-auditor`) reviews delivered reality against the press release, and `/abcd:intent consistency` (Role 2, per itd-48, which superseded itd-31) catches drift between documents, filing each contradiction it finds as an issue. Two companions are designed and not yet built: `/abcd:intent grill` (per itd-27), a Socratic interview that stress-tests an intent, or a brief section, before it is planned; and `/abcd:intent shape` (Role 3), which keeps each intent's `kind` honest as the corpus grows.
- **Plumbing that makes it possible:** fifteen agents (a sixteenth, the reflection composer, is designed and not yet written), a vendor-agnostic adapter seam, a host-delegated LLM with opt-in oracle adapters (native, CLI, API, MCP), a prompt-quality stack with golden-test fixtures, structural lint, periodic SOTA audit, prompt-version frontmatter, self-improvement pre-flight, and injection-canary fixtures — plus operator-internal command wiring (e.g. `/abcd:run`, the itd-29 autonomous-run operator surface — read-mostly `status`/`pause`/`resume`/`preflight` over the pluggable autonomous-run seam; not part of the user-facing command set).
- **Plumbing that makes it possible:** sixteen agents, a vendor-agnostic adapter seam, a host-delegated LLM with opt-in oracle adapters (native, CLI, API, MCP), a prompt-quality stack with golden-test fixtures, structural lint, periodic SOTA audit, prompt-version frontmatter, self-improvement pre-flight, and injection-canary fixtures — plus operator-internal command wiring (e.g. `/abcd:run`, the itd-29 autonomous-run operator surface — read-mostly `status`/`pause`/`resume`/`preflight` over the pluggable autonomous-run seam; not part of the user-facing command set).

See [`04-scope.md`](04-scope.md) for the full scope boundary and [`04-surfaces/`](../04-surfaces) for per-command detail.

Expand Down
2 changes: 1 addition & 1 deletion .abcd/development/brief/01-product/04-scope.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ spec per the three-kinds taxonomy in

See [`intents/README.md`](../../intents/README.md) for the intent index. The phase documents under [`roadmap/phases/`](../../roadmap/phases/README.md) are history: [adr-2609212115255771](../../decisions/adrs/2609212115255771-phases-and-milestones-are-retired-sequencing-is-dependencies.md) retired the phase and the milestone as units of the record. Capture history lives in `git log` and each intent file's own provenance, never in this page (per [adr-5](../../decisions/adrs/0005-brief-is-current-state.md)).

**Plumbing infrastructure** (fifteen agents — the canonical roster is the catalog in [`05-internals/01-agents.md`](../05-internals/01-agents.md) — 11 adapters, harness shim, prompt-quality stack, hooks): see [`05-internals/`](../05-internals).
**Plumbing infrastructure** (sixteen agents — the canonical roster is the catalog in [`05-internals/01-agents.md`](../05-internals/01-agents.md) — 11 adapters, harness shim, prompt-quality stack, hooks): see [`05-internals/`](../05-internals).

## What comes later

Expand Down
6 changes: 3 additions & 3 deletions .abcd/development/brief/02-constraints/04-naming.md
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,7 @@ The exemptions carrying a rationale of their own:
**staged** (itd-27), and no `intent grill` sub-verb is registered.
- `/abcd:audit`: formal verification surface, **staged** (itd-16). Reserved, not
metaphor-mapped, dignified register.
- `/abcd:reflect`: phase-retrospective surface, **staged** (itd-24). Not
- `/abcd:reflect`: release-retrospective surface (itd-24). Not
metaphor-mapped, soft register.
- `/abcd` (bare, top-level): where-am-i status board (itd-20). The namespace root
refuses any positional that is not a record id, so `status` is not a registered
Expand Down Expand Up @@ -157,8 +157,8 @@ Two things to read the table with:

| Term | Type | Source |
|---|---|---|
| `phase retrospective` | **(staged)** The five-section README (`went well` / `could improve` / `lessons learned` / `decisions made` / `metrics`) written by `/abcd:reflect <phase-id>` to `.abcd/retrospectives/<phase-id>/README.md`. Phase-grained only (the intent form was dropped per the itd-24 grill). Composed by the `reflection-composer` agent from the spc-66 (predecessor store) phase-audit receipt; rendered/written by the deterministic reflect writer. Links to the phase doc + audit report + member specs only (SSOT — no body duplication). | spc-83 (predecessor store) + `spc-83-operator-surfaces-manifest-lockstep.3` (itd-24) |
| `reflection-composer` | **(staged)** The 16th catalog agent: composes phase-retrospective prose from a seeded single-pass interview grounded in the spc-66 (predecessor store) phase-audit receipt's per-bullet acceptance verdicts. Dispatched by `/abcd:reflect`. `capability_scope.task_classes: [surface_render]`. | spc-83 (predecessor store) + `spc-83-operator-surfaces-manifest-lockstep.3` (itd-24) |
| `release retrospective` | The five-section README (`what went well` / `what could improve` / `lessons learned` / `decisions made` / `metrics`) written by `abcd reflect write <release-tag>` to `.abcd/development/retrospectives/<release-tag>/README.md`, seeded from the intents the tag shipped and their audit notes. Release-grained only: an intent id is refused. Its answers come from the `reflection-composer` interview; the deterministic writer computes the metrics and links, never copies, the changelog section and each intent's audit notes. Replaces the `phase retrospective` of the phase grain adr-2609212115255771 retired. | itd-24, spc-2609211751376504 |
| `reflection-composer` | The agent that runs a release retrospective's interview from the seed `abcd reflect` renders, one question at a time, meeting a thin answer with one follow-up, and drafts the answers `abcd reflect write` files. `capability_scope.task_classes: [surface_render]`. | itd-24, spc-2609211751376504 |
| `setup-wizard` | **(staged)** The display-only surface (in the Go binary, `internal/core/...`) that explains a missing external dependency when the spc-76 (predecessor store) validation gate fails closed: four fixed-order elements (tool name + version floor / requiring capability / what fails without it / exact install step), sourced from the gate's typed `MissingToolPayload` (single source) with a curated blurb registry for prose only. NEVER weakens the gate — declining stays fail-closed and the decline is recorded to the local ephemeral run-output tier, never to the retired `logbook` name. NOT a top-level command in v1 (rendered through the gate CLI + a standalone `explain` entrypoint). | spc-83 (predecessor store) + `spc-83-operator-surfaces-manifest-lockstep.4` (itd-63) |
| `JSON sidecar` | **(predecessor vocabulary; superseded by the review charter at [`../../../work/reviews/README.md`](../../../work/reviews/README.md))** The canonical `review.json` file written into each per-review directory in the review store. Consumers MUST read the JSON sidecar; the rendered `.md` is derived. | spc-2 (predecessor store) + `spc-2-move-repoprompt-review-artifacts-into.1` (the cited `docs/reference/review-schema.md` schema page does not exist in this repository) |
| `MD render` | **(predecessor vocabulary; superseded by the review charter at [`../../../work/reviews/README.md`](../../../work/reviews/README.md))** The derived `review.md` file rendered mechanically from the JSON sidecar (front-matter from metadata, prose from `body_markdown`, "## Findings" from `findings[]`). Not canonical; consumers read the JSON sidecar. | spc-2 (predecessor store) + `spc-2-move-repoprompt-review-artifacts-into.1` |
Expand Down
8 changes: 6 additions & 2 deletions .abcd/development/brief/04-surfaces/01-ahoy.md
Original file line number Diff line number Diff line change
Expand Up @@ -154,8 +154,12 @@ running it, and changes nothing.

The key lives in one of the credential store's three homes (below), and a
fourth answer, no key, sets up a local server that takes none.
No delegating verb sends a step to a configured provider until provider dispatch
lands (spc-2609251028149555), and both the board and the setup say so.
A delegating verb whose agent's `oracle.roles` entry points at a configured
provider sends the step there itself (spc-2609251028149555), and a provider
whose block names a key takes only the self-contained agents under ruling DR5
of 2026-09-29, with `oracle.bundled_context_providers` as the person's
machine-only override; both the board and the setup say so in their `dispatch`
line.

### The credential store and its walkthrough

Expand Down
37 changes: 36 additions & 1 deletion .abcd/development/brief/04-surfaces/02-disembark.md
Original file line number Diff line number Diff line change
Expand Up @@ -147,6 +147,7 @@ a section of its own.
│ ├── spine.md # commit-history spine, written where no record store exists
│ ├── intents/{drafts,planned,shipped,superseded,disciplines}/ # intent corpus, verbatim
│ └── specs/{open,closed}/ # spec store, verbatim
├── retrospectives/<release-tag>/README.md # every release retrospective, verbatim (itd-24)
├── docs/
│ └── adrs/ # ADRs copied verbatim
└── activity/
Expand All @@ -156,7 +157,7 @@ a section of its own.
`_provenance.json` is what makes the pack checkable by a third party. It carries
the schema version and generator, the source name and root SHA, the tiers
present, a `manifest_sha256` over every other file, a `record_manifest_sha256`
over the record-derived families alone, the omissions, and a `pass_b_exemption`
over the record-derived families alone (the retrospectives among them), the omissions, and a `pass_b_exemption`
present only when no transcript tier grounded the package, so an unmarked
lifeboat marshals as it always has and embark can say which it is.

Expand All @@ -168,6 +169,32 @@ beside its evidence, a declined claim as `null`, per
writes the verdict artefact, and the graveyard validates and writes the lesson
JSON. None of these exist at pack time.

### The agents the synthesis sub-verbs delegate to

Each delegated payload is composed by a plugin agent and validated by the
binary, which treats it as untrusted input: it decodes the payload with
unknown fields refused, sanitises its prose, and writes only what survives the
citation gate. The press release is delegated to `press-release-composer`, the
graveyard to `graveyard-interpreter`, the principles to `principle-distiller`
and the review to `lifeboat-reviewer`. Each prompt declares
`reads_untrusted_input: true` and tells the agent that everything it reads is
data, never instruction.

- **`press-release-composer`** writes the press release from the packed brief,
the spine and the principles, as the payload the press-release sub-verb
validates in its delegated mode. The document stands or falls whole: its
`evidence` must carry at least one packed path under `brief/`,
`rescue/spine.md` or `principles.json`. A payload that
cites none of them is refused with exit 2 and leaves the previously derived
press release untouched.
- **`graveyard-interpreter`** reads the two evidence layers,
`graveyard/archaeology.json` and `graveyard/abandoned.json`, and returns the
lessons payload the graveyard sub-verb validates, each lesson citing the
finding ids it rests on. A lesson with no live finding id among its evidence
is dropped and reported, a `low`-confidence lesson is written to
`graveyard/low-confidence/<id>.json` instead of `graveyard/lessons.json`, and
no drop is fatal.

The lifeboat is written out-of-tree, so the source repo has nothing to
gitignore.

Expand Down Expand Up @@ -276,6 +303,14 @@ invocation does not dispatch, a tier outside `local`, `economy`, `frontier` and
anything is written. With no table accepted and no override, the step asks for
`host-decides` on the harness and nothing is printed.

**No lifeboat agent is sent to a provider.** The four lifeboat agents read the
packed lifeboat's files, and no verb builds a request carrying them, so none is
dispatched to a provider (the adapters chapter). An ingest handed a payload the
host produced while its agent's `oracle.roles` entry points at a provider is
refused at exit 2 before anything is read, naming the setting to remove, since
its receipt would name work the provider never did; an override to
`host-decides` keeps one run on the harness.

<!-- surface-appendix:begin — generated from the command tree by `go generate ./internal/surface/cli`; never edit by hand -->

## Appendix: the shipped surface
Expand Down
38 changes: 32 additions & 6 deletions .abcd/development/brief/04-surfaces/03-embark.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,8 @@

Start a repository from someone else's record rather than from nothing. Point
embark at a packed lifeboat and it writes that project's decisions, issues,
intents and specs into their canonical places in your repo, verbatim, and opens
intents, specs and release retrospectives into their canonical places in your
repo, verbatim, and opens
with the coverage blanks a human still owes the record. What you get is a
working store on the first day; what you are told, before any of it, is exactly
what the pack could not ground.
Expand Down Expand Up @@ -37,6 +38,7 @@ whose bytes already match is an idempotent skip, so a re-run is a clean no-op.
| Verb | Bucket | Status |
|---|---|---|
| `from` | — | shipped |
| `lessons` | — | shipped |
| `probe` | — | shipped |


Expand All @@ -52,6 +54,15 @@ Bare `/abcd:embark` prints dispatcher help and mutates nothing.
read-only: what would land where, does the lifeboat verify against its
manifest, is its schema version one this build understands. It writes nothing
and runs no product audit.
- **The lessons** take the same two paths and answer what the previous voyage
learned (itd-24): every lesson the lifeboat's release retrospectives carry,
ranked by term overlap against the new voyage's brief (the target's framing
chapter, or the text of a brief file the caller names), the three most like it first and the
rest as a list, for the press-release interview to ask which apply. The
manifest is verified first, a lesson is attributed to its directory's
validated release tag rather than to anything the file says of itself, and
each lesson is cleaned to one inert line of at most 600 bytes. It writes
nothing.

## 1. Source lookup

Expand All @@ -76,16 +87,20 @@ and then its intent store's lock, the order every writer holding both takes,
and every planned write is judged again under them. A record created at a
planned target between the plan and the write — a capture, an intent minted in
the target meanwhile — is a conflict like any other, so it refuses the whole
write rather than being replaced.
write rather than being replaced. A retrospective the reflect verb writes
takes the intent store's lock too, so it cannot land inside that window, and
every planned write is an exclusive create: a file that lands at its target
after the rejudge from a writer holding none of the locks fails the embark
loudly, never replaced.

## 3. Scaffold steps

Embark is a deterministic Go run: it reads the lifeboat, plans, refuses on any
conflict, then writes the record families plus the marker block. No interactive
scaffolder and no model sit in the write path.

0. **Read the lifeboat.** The four record families — ADRs, issues, intents,
specs — plus the report-only files that inform the run. The lifeboat is
0. **Read the lifeboat.** The five record families — ADRs, issues, intents,
specs, release retrospectives — plus the report-only files that inform the run. The lifeboat is
untrusted input: embark verifies its `manifest_sha256` against the on-disk
tree, over every hashed file, and refuses a symlink or an oversize file
anywhere inside. Both operands, the lifeboat and the target, are refused
Expand All @@ -102,7 +117,10 @@ scaffolder and no model sit in the write path.
2. **Write the record families verbatim** to their canonical locations, through
two-layer containment (an `os.Root` boundary plus independent lexical path
validation), skipping the unchanged. Bucketed families keep their source
bucket: issues by state, intents by lifecycle stage, specs by open or closed.
bucket: issues by state, intents by lifecycle stage, specs by open or closed,
and a retrospective by its release tag, where only a strict
`vMAJOR.MINOR.PATCH` directory holding `README.md` maps and anything else in
the family is reported unmapped and never written.
Terminology, docs and the memory store are **not** embark families; they do
not travel.
3. **Re-inject the current abcd marker block** into the target `CLAUDE.md`
Expand Down Expand Up @@ -287,7 +305,7 @@ _Generated from the command tree; a drift test fails `go test` when this appendi

### `abcd embark`

Sub-verbs: `abcd embark from`, `abcd embark probe`.
Sub-verbs: `abcd embark from`, `abcd embark lessons`, `abcd embark probe`.

Flags: none.

Expand All @@ -297,6 +315,14 @@ Sub-verbs: none.

Flags: none.

### `abcd embark lessons`

Sub-verbs: none.

| Flag | Type |
|---|---|
| `--brief` | string |

### `abcd embark probe`

Sub-verbs: none.
Expand Down
Loading
Loading