-
Strict filesystem WAL stores now persist a checksummed writer-epoch ledger containing the active epoch, its exact latest closed predecessor, and final LSN and commit-digest evidence. Bounded retention keeps ledger writes and reopen validation independent of lifetime restart count. An OS-backed writer lease—not the deterministic chain markers stored in the generic fencing, process, host, and lease fields—refuses overlapping processes before append. A recovered trusted host closes only an abandoned epoch under that lease and derives a fresh, monotonically linked successor. Duplicate, stale, skipped, regressed, or unfenced epoch chains fail closed. Independent-process witnesses carry an external-action request, claim, settlement, and effect-free replay across successive host processes.
-
Echo now consumes the exact independently verified Edict
workspace.patch.applyValidated@1request through a capability-rooted single-file patch adapter. The request binds the prior bounded-observation basis, replacement identity, exact writable aperture, immutable no-follow and CI-workflow-exclusion policy, and byte budgets before mutation. The adapter rejects stale bases, escaped or substituted paths, symlinks, special files, and oversized writes without mutation; synchronizes a same-directory atomic replacement; and settles the resulting basis and observed before/after content identities before resumption. Claimed attempts reconcile by observing only the exact postcondition or settlingOutcomeUnknown, never by claiming an unobserved pre-state or reapplying the patch. Identical settlement retry and replay remain effect-free. -
Bounded workspace claims can now settle as
OutcomeUnknownafter directory authority disappears. A rootless reconciliation handle retains only the exact runtime-owned profile, revalidates the durable grant's exact claim commit and compiler-admitted request, and constructs the schema-bound settlement inside Echo. It cannot observe files or construct success, while zero evidence and substituted profiles, grants, or requests fail before another WAL commit. -
Settled external-action candidates can now be reconciled idempotently after acknowledgement loss without a WAL store, transition context, or claim grant. An exact retained candidate returns the original admitted settlement and commit digest without appending history or making adapter execution reachable. A different valid candidate conflicts, malformed candidates fail ordinary settlement validation, and duplicated settlement records remain a recovery obstruction.
-
Echo now independently admits compiler-produced Edict Core and Target IR for one non-callable external request, verifies its exact source, target profile, result, basis, and capability closure, independently corroborates the complete Target IR request against Core, and evaluates argument-rooted runtime fields under both compiler-declared and Echo-owned step, allocation, and output ceilings. Admission also requires enough capacity for every terminal settlement posture. The derived generic request invokes no provider. The first operation-specific adapter observes an explicit relative-path set through a capability-rooted directory after request and claim commits. It refuses traversal, duplicate or unauthorized paths, symlinks, special files, stale bases, malformed settlements, substituted success apertures, and aggregate byte-budget overruns; revalidates registry authority before settlement; retains canonical path/content bytes plus complete basis evidence; admits
OutcomeUnknownexplicitly; and replays settled bytes without reopening the workspace. -
Echo now admits domain-neutral external actions through separate request-before-effect, bounded claim, and settlement-before-resumption WAL transactions (ADR 0026). Canonical requests bind worldline, operation, schemas, authority scope, basis, single-claim and retained-byte budgets, input digest, and reconciliation law. Runtime-owner adapter registration attenuates operation and scope policy into an exact request-, basis-, and registry-policy-bound authorization without granting Edict or the provider seam external authority.
Succeeded,Rejected,Failed, andOutcomeUnknownsettlements bind the exact request, attempt, adapter, basis, schema, canonical result bytes, admission evidence, and nonzero external evidence. Echo derives each lifecycle frontier from a canonical request-id-keyed sparse Merkle index; insertion order cannot move its root, one planned mutation advances its bounded path without replaying prior WAL payloads, and recovery rejects substituted roots. Raw WAL builders and commit flushes cannot mint the coordinator's opaque authority; causal transaction coordinates come from one checked local continuation. Arbitrary recovery reports are observation-only. A coordinator recovered from a fallible local-store snapshot reconstructs interrupted request tokens, claim grants, and resumable settlements; storage corruption cannot masquerade as genesis. Recovery reconstructs requested, claimed, and settled posture from committed WAL records, including strict filesystem reopen; duplicate, conflicting, stale, unauthorized, malformed, and over-budget evidence fails closed. Replay consumes retained settlement bytes and never invokes an adapter. -
The generic Edict-operation runner now exposes complete fresh-host and WAL-recovered application-result records beside the applied result. Report construction fails closed unless all three schema-neutral projection identities, output types, canonical bytes, and result identities are exactly equal.
-
Executable-operation packages can now bind an exact compiler-owned
edict.result-projection.artifact/v1. Projected invocations retain the exact canonical application input, scheduler-owned private evaluation emits the compiler-declared output type and canonical result bytes, and a domain-separated identity binds that evidence. Applied Action outcomes, Receipts, and decided-Tick WAL transactions retain the same projection, bytes, type, and identity; fresh-host recovery revalidates them against the installed package before publication. Rebound projections, mismatched application inputs, and substituted result evidence fail closed. Obstructed Actions carry no application result. The generic external runner reports and recovers this evidence without a native application callback or application-specific reconstruction. Runtime admission caps canonical application input at 65,536 bytes and the compiler-declared result ceiling at 65,536 before private scheduler evaluation. Both independent provider components reject result ceilings above that runtime maximum and ambiguous input bindings. Configuration-derived node-key and replacement field names share the projection path-segment text ceiling. Package admission preserves authored source kinds and paths, and optional result evidence carries an explicit presence tag. Evaluation preflights exact canonical output size before constructing the projected value, while recovery re-evaluates the projection over the retained invocation input and refuses substituted result bytes before publication. -
The generic Edict-operation runner's duplicate witness now exposes canonical before/after application-state roots and typed target-value digests. The graph-only roots commit reachable application state without conflating WAL, Tick history, Receipts, or commit metadata; report emission fails closed if either the root or target value changes during an obstructed duplicate.
-
cargo xtask run-edict-operationnow consumes an exact external compiler-produced executable-operation package, its structurally separate accepted verification report, the manifest-to-adapter-to-target-configuration closure, and typed JSON input. The generic runner durably installs the package, acknowledges one canonical Action only after accepted-submission WAL commit, drops that host, recovers the exact installed package and pending Action into a fresh host, then lets the scheduler privately evaluate the recovered work while constructing one singleton Tick. Publication follows only after the decided-Tick WAL commit. A second fresh filesystem host recovers the package, Action, Tick, state, typed outcome, and Receipt. Repeating creation yields the package-declared, lawpack-qualified typed obstruction with no hidden mutation, while a changed initial state produces the typedecho-operation-execution-mismatch/action-basisrecovery refusal. Admission binds the accepted verification report's Target IR to the package semantic closure, selects target configuration only from the package-supported target intrinsic, and verifies both created node and attachment types. The machine-readable witness reports exact package, verification-report, and lawpack-manifest digests plus basis, node, submission, Tick-commit, typed Receipt, result-projection, output-type, canonical-result, and result identities. The checked external fixture and bounded failure/stress suite contain application vocabulary only underxtask/tests; the production runner is generic and contains no native application callback or handwritten package. -
The former native
hello-echocounter capsule is now explicitly namedruntime-counter-diagnostic, including its command, artifact paths, and internal identities. It remains a low-level callback-based maintenance diagnostic and no longer claims to be the external application proof. -
Echo's checked Edict provider now lowers arbitrary application-owned Core coordinates through one generic executable-operation route. Exact Edict source, Core, lawpack, exports, target adapter, target configuration, and Target IR artifacts produce a canonical
echo.operation-package/v1for the bounded anchored create-if-absent capability without application-specific dispatch or a native callback. A structurally separate verifier reconstructs the source-to-package relation and emits an exact accepted or rejectedecho.operation-package-verifier-report/v1. Target IR validation consumes the adapter-lowered target obstruction coordinate while independently corroborating its source-failure mapping. The provider package exposes seven new closure domains through 31 total schema bindings. The generic route now binds source-local capability aliases to canonical lawpack exports through the exact digest-locked Edict import and corroborates lawpack-owned coordinate-framed exports and adapter references independently from their provider-envelope domains. Its lowerer and verifier components were independently reproduced in copy-only, mount-free designatedlinux/amd64containers and promoted at 258,787 bytes /dfd14015705ff555a7efdb3787ddb0f8b4f304168a9a0ebf324fd25d430bf5cdand 277,836 bytes /279738ffeea40027eb493c15e873b87cf3aa0677a57f9f03fb824698e532322f, respectively. The resulting 25-file package has provider identitysha256:6685b7c629ae6955515d69158feb1d7db06af2193de7e5d13e1095101670b977. This package build proves generic compiler/provider lowering and independent verification. The separaterun-edict-operationwitness now consumes that crossing through Echo-owned runtime execution. -
Executable-operation application writes now enter Echo as canonical, WAL-acknowledged Actions and are evaluated only by the scheduler while constructing a Tick (ADR 0025). Accepted pre-Tick Actions recover as pending work. Runtime-owned admission uses a bounded pending index and cache; unavailable packages are quarantined without poisoning unrelated work. Durable-acceptance lookup and newly committed receipt correlations are indexed directly, so scheduler Ticks do not replay or diff retained history. A WAL-enabled app surface rejects executable Actions submitted outside the durable acknowledgement boundary before witnessed intake can mutate. Mixed executable and provider/native backlogs alternate by durable parent global-Tick parity. The scheduler-round coordinate advances once per pass, so every head switches categories even when several heads share one worldline, preventing caller-controlled ingress hashes from starving either category. Homogeneous unbounded admission moves the complete inbox map instead of rebuilding and removing its entries one by one. Positional receipt attribution is exclusive to executable Actions; ordinary correlations without an exact scope match fail closed. Scheduler selection admits at most 64 executable Actions per Tick, leaving excess work pending, and meters footprint comparisons, blocker evidence, and aggregate operations during composition. Two independent Actions can share one exact parent coordinate and contribute to one composite Tick while retaining candidate-specific application-basis propositions and per-Action typed outcomes. Footprint conflicts name earlier applied members; evaluator and composition-budget obstructions contribute no operations. Every noncommitted typed outcome carries its deciding writer head, worldline and global Tick coordinates, commit and Tick-receipt identities, and canonical member index. Tick construction pins that index to the corresponding receipt entry with an executable alignment invariant. One scheduler WAL transaction retains exactly one batched Tick decision record, then each Action's receipt correlation and typed outcome in canonical order, followed by exactly one replayable state delta. Recovery rejects every second transaction claiming the same state-transition coordinate, including a byte-identical delta, so a Tick cannot be reconstructed from split WAL fragments. The decided Tick is durable before state, frontier, receipt, or outcome publication. Recovery and same-host retry both preserve an accepted Action when Tick-WAL persistence fails; runtime rollback also rolls back the corresponding admission cache so the Action re-enters scheduler admission. Fresh-host recovery validates every outcome against its exact envelope, admission, invocation, installed operation, causal coordinate, evaluation basis, reconstructed preparation and actual footprint, Tick entry, composite consequence, exact reconstructed aggregate patch membership, and state root. Typed obstruction records retain their invocation-admission policy and budget ceiling; recovery reproduces bounded evaluation and the complete scheduler composition before accepting an obstruction kind. For a cross-worldline basis obstruction, recovery reconstructs the submitted basis on its named worldline but resolves the deciding transition on the target head's worldline. Recovery records one monotonic installation ordinal per package and one installation-count boundary per Action, avoiding per-outcome package-set snapshots while preserving exact installation-before-Tick validation. Activation caches each reconstructed causal state by worldline coordinate, so Actions sharing one scheduler basis do not replay that history repeatedly. Recovered Action outcomes resolve installed packages through one package-ID index instead of scanning the complete installation set per Action. Test instrumentation now counts the actual package-index and installation-order lookups rather than asserting constant zero-value proxies. Tick WAL staging borrows its read-only outcome index instead of deep-cloning every outcome. The v1 scheduler Action-candidate ceiling is exported as
ACTION_BATCH_CANDIDATE_LIMIT_V1; its acceptance witness now proves the complete limit with independent, non-conflicting node targets. Admission applies that ceiling independently to each runnable head, so Actions retained for dormant or faulted heads cannot consume another head's Tick capacity.run_until_idlecontinues after a no-Step pass that advances bounded Action admission, so an obstructed prefix cannot hide later admissible work. When more than that ceiling is pending, runtime admission selects the bounded set by canonical ingress identity rather than submission identity.TrustedRuntimeHost::into_partsnow returns an opaqueTrustedRuntimeHostPartsvalue consumed byfrom_parts, preserving WAL, authority, policy, pending admission, and every typed Action outcome across host decomposition and reconstruction. A composite receipt cannot validate outside its complete Action-batch context. Legacy operation recovery-index roots remain byte-compatible when no Action outcome exists. Direct operation prepare/commit remains a documentation-hidden publicTrustedRuntimeHostcompatibility/test seam, absent fromTrustedRuntimeApp; removal is tracked by issue #689. -
TrustedRuntimeHostnow has the first hook-free executable-operation runtime slice. A runtime owner can admit exact canonicalExecutableOperationPackageV1bytes under a separate package policy, install their data-onlyEchoOperationProgramV1, independently admit an exact-basis invocation under caller authority and delegated budget, evaluate privately, and either commit one parent-visible patch or return typed noncommit evidence. On that transitional direct seam, only committed operation consequences enter the operation-tick WAL. The initial generic program performs an anchored typed-node alpha-attachment compare-and-set; it contains no application matcher, executor, footprint callback, or prebuilt mutation plan. Package, installation, invocation, evaluation, actual-footprint, budget, patch, result, basis, and terminal identities are bound into a typed receipt. The parent patch and singleton tick evidence name the admitted installation rather than promoting the subordinate program digest into rule authority. Application-basis corroboration is bounded by the delegated read budget. A runtime-control installation record and distinct execution-kernel commit records retain the full admitted installation and committed state delta under exact frame and frontier shapes so a fresh host can re-admit and reconstruct them without callbacks. A program digest alone cannot install, invoke, or authorize an operation. This slice does not yet include Edict compiler emission, a structurally separate target verifier, Jedit's rope lawpack,ReplaceRange, or an independently implemented semantic oracle. -
The executable-operation corridor now has a separate
AnchoredNodeAttachmentCreateIfAbsentprogram (ADR 0024). The original compare-and-set program remains update-only with its canonical program, invocation, application-basis, target-profile, and result identities unchanged. Creation has distinct schema, footprint, basis, result, and target-profile identities; observes node and attachment occupancy independently; succeeds only when both are absent; emits one atomicUpsertNodeplusSetAttachmentconsequence; charges the node type, attachment type, and payload; and refuses every occupied target withPreconditionMismatch. Filesystem-WAL recovery validates the exact installed-program consequence, including operation and slot shape, program-owned node and attachment types, the atom-only attachment algebra, replacement bounds, and operations scoped to descended WARP instances. Descended evaluation now validates the complete parent chain, retains every portal attachment as both a footprint read and replay input, and charges each portal-pointer read incrementally before dereferencing that portal, so out-of-budget ancestry cannot affect evaluation; activation recovery reconstructs each operation's exact parent state and rejects missing, duplicate, substituted, or otherwise non-chain portal inputs, and independently corroborates the creation receipt's total-absence proposition against both target locations before replay. This closes only the single anchored-node-plus-alpha-attachment creation gap. It does not establish Graft-style multi-record mutation or a real Edict application crossing. -
TrustedRuntimeHostcan now admit a previously witnessed mutation for an installed Edict provider package withadmit_provider_contract_submission_v1(...). The shared installed-contract admission boundary requires the exact canonical EINT v1 outer kind and an installed provider operation before staging. Provider invocation evidence binds the installed package id, exact package reference, semantic operation, Target IR, and scheduler rule; Echo reports an applied provider outcome only when that exact rule appears in the tick receipt, so the same-scope system acknowledgement cannot masquerade as application execution. A distinct validated tag-2 WAL encoding retains the evidence without fabricating a legacy contract coordinate, while the tag-1 legacy bytes remain stable. A fresh filesystem-WAL host recovers the exact outcome after independently reinstalling the provider package, without callback execution or duplicate work. Unknown operations, malformed or relabeled EINT, structurally invalid retained evidence, and provider inverse requests fail closed through stable typed errors. This closure does not authenticate callers, authorize targets, validate codec-owned input against an operation schema, or implement provider-native reads. -
echo-wesley-gennow owns the proof-consuming provider installation adapter: it consumesDigestCorroboratedProviderContractPackageV1throughwarp-core's sealed runtime-owner installer port and delegates to aTrustedRuntimeHostlower primitive that explicitly does not authenticate package bytes itself. Installation creates a distinct owned provider record retaining the exact occurrence, provider reference, complete provider registry, and mutation-rule identity, then atomically installs provider-package, package-root, operation, and shared scheduler-rule indexes. It fabricates no legacy Wesley/GraphQL metadata or evidence, exposes no app installation surface, and invokes no callbacks. Installation alone remains distinct from the provider mutation admission, invocation, receipt, and WAL crossings described above; generated bounded-read observations remain subsequent work. -
echo-wesley-gencan now consume aDigestAdmittedProviderPackageV1and an independently Echo-admittedAdmittedProviderContractPackageV1, require the exactecho.edict-provider@1coordinate and strict lowercasesha256:package-root agreement with the proposal occurrence, and return an opaqueDigestCorroboratedProviderContractPackageV1. Stable structured failures distinguish coordinate, digest-rendering, and artifact-root disagreement. This pure crossing corroborates package occurrence only: it does not derive registry semantics from package bytes, install or mutate registry state, invoke callbacks, schedule or execute work, emit receipts, or grant runtime authority. The real-host witness extends the exact generator dependency closure, so generation evidence and the checked provider occurrence refresh tosha256:ee870c75ec08c8818b3f80ab6562ae62a5cf741cd709edcee0085d951c5d5a7b; the primary semantic and Target IR artifacts remain byte-identical. -
TrustedRuntimeHostcan now admit an opaque Edict provider proposal against an independently constructedProviderContractAdmissionPolicyV1. The pure crossing compares the complete host-owned package occurrence claim and provider registry—including schema, target-bundle profile, semantic and release identities, ABI/helper versions, operations, codecs, Target IR, obstruction, profiles, and footprint claims—and returns stable typed mismatches. The resultingAdmittedProviderContractPackageV1retains private proposal material for the proof-owned provider installation crossing but does not rehash package bytes, mutate the engine registry, install handlers, invoke callbacks, schedule work, or grant application authority. -
The checked Echo Edict provider conformance corpus now declares twelve reviewed executable obligations: exactly six owned by the isolated host executor and six by the package executor, with one accepted, nine rejected, and two refused dispositions. Each declaration names its crossing, stimulus, required disposition, and outcome contract, but embeds no pass flag, result, evidence pointer, implementation command, or runtime authority. The two exact-set executors separately produce provider-conformance evidence for baseline package parity, admission and binding failures, typed semantic refusals, and verifier disagreements. Corpus declarations and their executed provider evidence remain distinct from Echo installation, execution, observation, and runtime receipts.
-
TrustedRuntimeHostcan now admit a witnessed installed-contract submission without accepting caller-manufactured ticket authority. Echo derives a domain-separated admission digest from its witnessed submission record and verified installed-package identity, stages the operation through the same package-evidence boundary, and binds the resulting receipt to that evidence. The explicit ticketed staging API remains available for actual Optic admissions; application-facing handles still cannot admit, stage, or tick. -
echo-wesley-gennow purely assembles and digest-admits the first complete Echo Edict provider distribution from the verified 22-file generated corpus and explicit lowerer/verifier bytes. The derived provider manifest carries ten exact routes and 31 schema bindings—nine compatibility invocation domains, the generated artifact profile, 14 generated-resource domains, and seven generic executable-operation closure domains—but never inventories itself. A versioned canonical-CBOR package root binds those semantics plus raw hashes of all 24 non-manifest members, while the exact 25-file inventory, deterministic JSON rendering, mixed raw/domain-framed digest laws, packaged Wesley provenance/review, component bounds, and an external expected provider pin all fail closed through structured errors. This is package-occurrence authentication only; Edict schema/component preflight and Echo runtime installation remain separate authority crossings. A dedicated publisher now checks that all 22 generated members exactly reproduce the current checked provider corpus introduced by #652 before writing the two components and derived manifest as a self-contained 25-file distribution. Its capability-oriented filesystem boundary refuses invalid expected inventories before resolving the root, bounds actual-tree enumeration and expected-byte reads, never opens an unexpected regular file, and makes--checkreport sorted drift without creating, deleting, or rewriting package material. -
The checked provider package now passes an isolated Edict-native readiness boundary pinned to Edict merge
c75c3f55. The exact manifest constructs its immutable 24-domain schema registry, all five canonical primaries and 14 generated resources satisfy their owning CDDL roots, resource references are bound field-by-field to independently recomputed domain-framed digests, both components pass frozen-WIT preflight, and both request kinds produce opaque validation proofs. Schema-valid byte replacement, digest mutation, semantic field swaps, authority-source disagreement, malformed schemas/components, and invalid requests all fail before guest execution. This proves package readiness only, never Echo installation, execution, or runtime authority. -
echo-wesley-gennow carries a fixed 38-file package-local source and provider asset boundary, preserving original logical source labels while making its.cratearchive independent of workspace-parent files. An explicit sync tool distinguishes authoritative generated/component owners from their checked package corroboration, supports staged regeneration without circularity, and checks exact Cargo archive selection. Fixed owner leaves are opened without following final symbolic links and read twice through one retained descriptor; file-type, length, or byte disagreement refuses a moving owner. The generator source identity now enumerates 20 files and includes the exact manifest and implementation bytes of its canonicalization, operation-id-law, and provider-registry dependencies. The extracted archive compiles when its still-unpublished Echo dependencies are supplied through local patches. -
Echo now owns the versioned semantic operation-id law
echo.semantic-operation-id.fnv1-32/v1. It derives a persistedu32from the exact semantic coordinate and generic query/mutation kind, remains domain-separated from Wesley's GraphQL-field-name law, and reserves the top two ids for Echo protocol envelopes:u32::MAXfor scheduler control andu32::MAX - 1for witnessed suffix import. The canonical generated-artifact profile carries both the law coordinate and each derived id; generation refuses either reserved value and package-local collisions without salting, probing, or renaming. Its CDDL boundsoperationIdto the remaining numeric application range, but schema admission alone does not prove derivation or collision freedom: semantic generation recomputes the law and checks the complete operation set. This packages an exact operation-identity proposition but does not register, install, authorize, or execute the operation. Generated source now carries public expected constants for the profile-owned law and id, requires both as untrusted bundle claims, refuses disagreement, and exposes the matched claim through the resulting private-state registration descriptor. -
Echo now provides the exact
edict:target-provider/lowerer@1.0.0Component Model implementation for the first checked provider closure. The pure lowerer accepts only explicit digest-bound Core, target-profile, authority, lawpack, lowerability, and output-role inputs; produces canonicalecho.span-ir/v1Target IR with byte-for-byte parity to Edict's built-in Echo wrapper; and returns typed refusals for unsupported ABI, profiles, semantics, reads, rebound operations, unresolved authored optics, changed type bindings, Core type definitions, evaluation budgets, out-of-scope locals, intrinsics, and undeclared or malformed output-role claims. Local admission distinguishes pre-effect, obstruction-arm, and post-effect scope from the exact input, effect-result, and obstruction declarations before cloning any expression into Target IR. The first closure also requires an empty input-constraint set and the exact zero-argumentdomain.WriteRejectedobstruction constructor. Effect inputs and intent results admit no call-expression callee, refusing unreviewed calls until their own lowering laws exist. A deterministic build boundary pins the frozen WIT bytes, rejects ambient or callable imports, checks the exact decoded world type graph and contract attestation, and reproduces the checked component byte-for-byte across independently provisionedlinux/amd64containers from the immutable Rust image used by CI. The builder resolves and authenticates the exact Rust and Cargo executables, binds Cargo to that compiler, owns the inner Cargo home, removes ambient Cargo profile/build/target overrides, remaps its dependency source paths to/cargo, and atomically promotes only distinct candidates matching a reviewed repository digest. The promoted 225,428-byte component has SHA-2563a0a1ce454f3083df814f60554997d26d0b539f7977a7aae6b00e7e09159e392. Other-host builds are structural and semantic witnesses rather than cross-host compiler-identity claims. The publication-enabled, archive-self-containedecho-edict-provider-lowerersource crate carries package-local copies of its four exact admitted resources, with a workspace witness binding them to the checked generated corpus. Its full package gate follows publication ofecho-edict-canonical 0.1.0. These artifacts describe and translate provider semantics; they confer no Echo runtime authority. -
The native Echo Edict lowerer model now accepts any exact, lexicographically sorted subset of the declared
generated.echo-dpogenerated artifact,review.echo-dporeview payload, andtarget-ir.echo-dpoTarget IR roles. It emits canonical-CBOR generated and review envelopes atgenerated/echo_dpo.rsandreview/echo_dpo.json, and refuses unknown, mismatched, duplicate, or out-of-order role claims with typedUnsupportedOutputRole. The generated Rust binds the semantic operation, Target IR, Echo ABI and helper API, provider and operation schemas, target and generated profiles, and abstract footprint obligation/algebra. It then performs only an explicit post-assembly equality and consistency comparison between an independent expected pin and untrusted Edict semantic/release bundle claims, with typed refusal for every identity class. Every domain-framed resource is compared as a complete coordinate/domain/digest proposition. The generated-artifact profile now ownsle-binary-v1, and generated Rust implements distinct boundedId,Input, andOutputtypes with fail-closed decoding for malformed, over-bound, truncated, or trailing bytes. Descriptor methods round-trip the exact input/output types and pack typed input into canonical EINT v1; EINTvarsremain codec-owned opaque bytes rather than a universal canonical-CBOR value. The matched descriptor exposes a borrowed, provider-generic registry and can bind its generated matcher to one explicitly identified host mutation implementation. It returns only an opaque, non-installing package proposal after checking the complete Target IR, semantic/release bundle, target/generated/operation profile, provider/value schema, codec, obstruction, operation-id, ABI, helper-API, rule-name, and footprint identities. Echo adds the mandatory ingress matcher reads to the host's effect footprint. Identity equality detects cross-binding but does not prove arbitrary callback semantics. The mutation proposal fails closed for aQuery; authored reads remain a separate bounded observer/optic path. The isolated actual-host fixture is green for binding, typed codec refusal and round trips, EINT packing, the borrowed registry, and proposal preflight. The permanently non-authoritative review is bound to the exact generated artifact. Neither projection authenticates a pin, admits or installs a package, or grants Echo runtime authority; checked-component promotion and host-side CDDL admission remain separate crossings. -
Echo now provides the exact
edict:target-provider/verifier@1.0.0Component Model implementation for the checked provider closure. The pure verifier independently compares explicit digest-bound Core and Target IR artifacts under the exact target profile and ordered semantic inputs. It emits a canonical accepted report for the reviewed relation, admits a well-formed intrinsic disagreement as a rejected report with an error diagnostic and host-authored output manifest, and preserves an unsupported output-role overclaim as a typed provider refusal with neither response nor manifest. Its bounded native preflight validates complete known expression, predicate, input-constraint, require-failure, and Core-value shapes before separating malformed artifacts from well-formed unsupported semantics, and one admitted diagnostic-ABI identity now binds both the target profile and every emitted report. The 242,350-byte checked component has SHA-256660ad5ad875b844e30c027e2a861e7941b5905098311fe578ae7fed732cf322cand reproduces byte-for-byte across independently provisioned designatedlinux/amd64builders. The isolated pinned Edict host preflights the exact request artifacts and declared output schema, invokes that checked component, then schema-admits each returned accepted or rejected report and authors its output manifest. It replays accepted, rejected, and refused completed outcomes identically in independent fresh stores and separate host processes. These witnesses prove provider verification and host replay only; they do not install, authorize, execute, or observe an operation in Echo. -
echo-edict-canonicalnow owns the shared pure implementation of Edict's canonical CBOR and domain-framed digest contracts as a publishable0.1.0leaf.echo-wesley-genretains its existing compatibility surface through a re-export, while executable provider components use the same codec without depending on generator or Wesley APIs. Its decoder now applies a 65,536-node host materialization ceiling, charging map keys and values separately. A matching cumulative reservation budget rejects both oversized direct containers and nested declarations that attempt to reuse the same capacity allowance before reserving their storage. -
echo-wesley-gennow checks in the first exact 22-file Edict provider artifact corpus: five canonical-CBOR primaries, fourteen canonical-CBOR resources, the self-contained CDDL, Wesley provenance JSON, and non-authoritative review JSON. A dedicated generator binds an explicit, compile-time-enumerated source/dependency-lock bundle rather than executable, Git, path, or environment discovery. Its--checkmode reports sorted missing, changed, and unexpected paths without creating, deleting, or rewriting files, while generation refuses observed unexpected entries before writing and retains no-follow directory capabilities through temporary-file replacement. The crate test suite checks the committed snapshot. -
echo-wesley-gennow derives Wesley's canonicalGenerationReviewV1from verified provider provenance. The deterministic JSON copies the exact input, provenance, generator, projection-role, source, and emitted-output identities, is structurally unable to claim authority, and preserves typed Wesley failures when its input and provenance disagree. The semantic source now identifies both provenance and review contracts as Wesley #728 artifacts. -
echo-wesley-gennow constructs canonical Wesley provider-generation provenance from explicit material only. The manifest binds the exact three authored source artifacts, checked settings digest, caller-supplied generator component bytes, and exactly six non-derived primary outputs, then immediately re-verifies all referenced bytes. Generated resources remain transitively bound through the primary artifacts, while provenance and review stay outside the emitted set to prevent circular digests. Typed Wesley failures are preserved without exposing Rust debug spelling as a stable diagnostic. The primary closure retains its producing input digest so outputs cannot be attributed to another invocation, and generator coordinates must remain disjoint from every exact source, declared artifact, resource, and package coordinate. -
echo-wesley-gennow deterministically projects the validated Echo Edict source into a canonical lawpack, target profile, two source-partitioned authority-facts documents, generated operation profile, fourteen declarative resources, and a self-contained provider CDDL artifact. Every output passes its owning generated root, Edict-owned values also pass the independently admitted upstream roots, manifest edges use domain-framed digests, and Wesley references bind exact output bytes. The projection preserves direct adapters, operation-local obstructions, and optic contracts, and keeps read-class operations as bounded observers rather than mutation DPOs. These artifacts describe provider semantics and confer no Echo runtime authority. -
echo-wesley-gennow admits the exact Apache-2.0 Edict provider contract pack introduced in Edict PR #162 and extended with the result-projection contract in Edict PR #174 as an explicit generator input. The pure boundary pins the CDDL and manifest publication, verifies strict contract and domain inventories plus every embedded resource byte, digest, and provenance record, rejects tampering with stable structured error kinds, and performs no filesystem, registry, environment, or network discovery. -
echo-wesley-gennow implements the exactedict.canonical-cbor/v1value, encoding, nesting, map-ordering, and domain-framed SHA-256 contracts. Named provider artifacts must both use those canonical bytes and satisfy their owning root in the admitted Edict CDDL; typed failures distinguish unknown contracts, invalid canonical encoding, and schema mismatch, and oversized declared lengths produce platform-stable truncation failures before host-width conversion. This validates a generation artifact and does not grant Echo runtime authority or admission. -
echo-wesley-gennow constructs a canonical Wesley extension-generation input from exact Echo semantic-source bytes, the admitted Edict CDDL and manifest, and checked versioned settings. The first provider closure uses an explicitly empty GraphQL Shape/operation catalog, derives six primary output roles without circular provenance/review digests, preserves the normalized semantic model across set reordering, and moves the generation-input digest when exact authored source or settings bytes change. -
warp-corenow separates application-requested causal-anchor claims from Echo admission.CausalAnchorAdmissionRequestcontains no admission receipt,CausalAnchorClaimis an opaque canonical value over only the caller's claim, and admitted fact construction is reserved for Echo's trusted admission path under ADR 0022. -
The causal WAL now has stable causal-anchor admission transaction, fact, and receipt record kinds. Transaction validation requires exactly one fact frame followed by exactly one receipt frame before append, while recovery rejects uncommitted, malformed, coordinate-mismatched, basis-mismatched, frontier-root-mismatched, or cross-admission evidence. Public WAL builders and stores cannot originate causal-anchor admission transactions without Echo's crate-private admission capability. Writer-cursor and read-only recovery consume one shared causal-anchor traversal so basis and frontier validation cannot diverge between recovery modes. Self-contained and CAS-addressed WSC imports consume that same traversal before accepting anchor sidecars, so matching projection material cannot legitimize forged recovered basis or frontier evidence.
-
TrustedRuntimeAppnow admits causal anchors only through an enabled runtime WAL at the current logical durable frontier. A host-owned exact root-support policy is validated and bound into receipt identity; successful admissions recover by anchor id after restart, while stale bases, unsupported roots, and failed storage commits publish no authority. Exact-retry lookup uses a disposable claim projection rebuilt from validated WAL history, replaced on writer recovery, and advanced only after a successful admission commit. -
Causal-anchor request, fact, receipt, observation-only WAL evidence, and recovered admission evidence are now available from the
warp-corecrate root. Arbitrary recovery reports produceObservedCausalAnchorAdmission; sealingRecoveredCausalAnchorAdmissionis reserved for trusted local WAL recovery. A Jim-shaped external-consumer witness and standalone golden vector pin Echo-produced subject, basis, root, purpose, anchor, receipt, transaction, and commit identity so applications do not create a second anchor hash domain. Both evidence types expose coordinates through read-only accessors rather than caller-reconstructible public fields. External consumers can reconstruct an opaque anchor lookup key from persisted Echo-produced identifier bytes without gaining fact, receipt, or admission construction authority. -
echo-wesley-gennow exposes a strict, versioned Echo Edict provider semantic-source model and pure validator. The checked first-operation source fixestarget.replaceauthority, typed failure and obstruction schemas, exhaustive source mapping, full optic profile, budget, native capability, explicit semantic discharge, source-partitioned authority facts, complete lawpack/target-profile resources, generated artifact roles, package ABI and provider identity, and full invocation schema bindings. It deterministically rejects recursive types, Edict Core ownership violations, byte-counted string aliases, invalid failure identifiers, duplicate or dangling facts, missing or ambiguous effect implementations, duplicate target-profile adapter selectors, authority/profile/capability disagreement, self-referential manifests, and incorrect generated contracts, invocation domains, or schema roots while treating generated files and relocated SDL as non-authoritative. Authority-facts outputs are bound to Edict's canonical ABI work inflyingrobots/edict#157rather than defining an Echo-owned wire contract. -
warp-coreinstalled contract packages can now provide read-only inverse laws for mutation operations. The trusted app surface resolves an exact retained causal receipt after restart, verifies the recovered witnessed submission and currently installed artifact, checks the caller's current frontier, resolves the receipt set for the current frontier commit, and WAL-acknowledges the contract-produced mutation with both the target receipt and current-basis receipts as causal parents. The retained ingress preserves a typed inverse-target role, and the app surface can recover the inverse target and admission basis directly from receipt history after restart. Missing receipts, non-applied target receipts, stale bases, unavailable inverse fragments, unmappable spans, absent handlers, and contract-version mismatches remain typed obstructions; inverse admission never deletes or rewrites the original transition. Ordinary app and runtime submission reject the reserved inverse-target parent role, preventing caller-authored intents from being projected as contract-defined inverses. Runtime recovery rejects a receipt correlation when its non-empty retained tick receipt contains only other submission ingresses. -
warp-corenow distinguishes repeatableTickReceiptcontent commitments from admitted receipt-event identity.CausalTickReceiptRefbinds receipt content to worldline, worldline tick, global tick, commit, submission, and admission ticket coordinates; ingress, trusted-runtime WAL, recovery indexes, app-facing outcomes, and WSC causal history now retain and follow that exact coordinate.echo-cli wal submission-posturereports the canonical receipt reference bytes alongside the repeatable receipt-content digest. Versioned codecs reject malformed magic and empty-but-present, duplicated, or reordered parent sets as corruption and report structurally valid legacy digest-only parent evidence as an explicit ambiguity rather than aliasing it to an arbitrary event. Read-only runtime-WAL recovery also rejects any correlation parent set that disagrees with the independently retained ingress envelope. Retained tick-receipt reconstruction also rejects non-canonical blocker ordering, forward or non-applied blocker references, and blocker attribution incompatible with the candidate disposition before the receipt re-enters provenance history. -
Trusted runtime scheduler commits now retain canonical local-commit provenance, the exact typed tick receipt, and installed-contract evidence in the same WAL transaction as receipt correlation. Filesystem reopen replays that evidence into a fresh runtime without invoking scheduler or contract callbacks and restores global tick, worldline frontier, materialized state, receipt indexes, causal parents, and app-facing outcome. Legacy digest-only runtime deltas remain explicit recovery obstructions. WAL activation also rejects live process-only authority that recovered durable history cannot reproduce. Recovery rejects duplicate singular acceptance, retained-envelope, tick-receipt, receipt-correlation, or state-delta frames instead of selecting one claim. WAL transaction construction rejects retained submission, correlation, or replayable state-delta material that does not bind the other evidence in the same atomic claim.
-
Trusted runtime submission intake now atomically retains a versioned canonical ingress envelope with each WAL-backed acceptance. Filesystem WAL reopen restores the witnessed submission ledger without ticking or dispatching, preserves duplicate posture, and reports legacy acceptances without envelope material as explicit recovery obstructions.
-
warp-coreingress can now cite typed causal parent tick receipts. Trusted runtime outcomes, WAL receipt correlations, read-only recovery indexes, and WSC causal-history envelopes retain both parent and reverse child lookup so contract-defined inverse intents remain attributable after host restart. -
warp-corenow exposesRetainedEvidenceBoundaryPosturewith boundary layer, origin, proof strength, access, completeness, and obstruction axes so retained evidence refs can be projected without conflating citation, reveal permission, redaction, unsupported evidence kinds, or missing retention. -
warp-corenow exposes a recovered WAL evidence segment catalog derived fromRecoveryScanReport, with a non-authoritative live cache inTrustedRuntimeWalthat marks cache-update failures as rebuild posture without turning committed WAL transactions into failures. -
warp-corenow exposes a narrow Edictecho.span-ir/v1Target IR fixture bridge that accepts strict lowercase digest-locked pre-stepcontinueObstructedrequirements, evaluates deterministic basis freshness facts, and emits versioned attempt receipt objects bound to the supplied Target IR digest. The bridge distinguishes accepted artifacts from executed receipts, obstructed attempts from invalid proposals, and obstruction from legal unselected counterfactuals without claiming bundle admission, Jim semantics, scheduler counterfactual exploration, canonical Echo receipt bytes, or receipt digests. -
warp-corenow exposes WAL projection fact records forWalRoot,WalWriterEpoch,WalSegmentRef,WalCommitAnchor, andRecoveryCertificateRef;WalSegmentRef::identity_digest()binds writer epoch, LSN range, commit chain, segment digest, commit anchors, and seal posture while excluding storage locators from causal projection identity. -
warp-corecan now project recovered WAL history into graph-readyWalRecoveryProjectionrecords from explicit manifest, segment seal, segment locator, writer epoch, and recovery certificate evidence; missing manifests or unavailable locators produce typed projection obstructions instead of empty success. -
warp-corenow exposesWalRecoveryPlanrecords that bootstrap from a projected WAL root or storage manifest, record checkpoint posture, committed replay suffix, tail posture, recovered index roots, retained-material posture, and projected evidence posture without requiring graph WAL nodes as input. -
warp-corenow exposesRecoveredDurabilityIndexesandrebuild_durability_indexes_after_recovery(...), composing committed WAL recovery into submission, receipt, retained-material, materialization outbox, topology, and graph/WSC projection indexes without invoking scheduler, observer, wall-clock, network, or app code. -
warp-corematerialization outbox recovery now exposes typedMaterializationRecoveryPostureevidence for missing artifacts, artifact or metadata digest mismatches, committed observation mismatches, and retained material unavailability while preserving the coarse replay posture for existing callers. -
echo-dind-testsnow includes a process-kill WAL crashpoint witness that kills child processes after committed WAL material and before transaction commit, proving recovery preserves committed history and excludes uncommitted tails. -
warp-corecan now materialize WAL projection records into deterministic WARP graph facts with root, writer epoch, segment, commit-anchor, and recovery certificate nodes plus typed graph edges suitable for WSC serialization. The materialized graph omits raw WAL storage locator authority and rebuilds to identical WSC bytes from the same recovery evidence. -
warp-corenow exposes observation-only WAL projection graph WSC import evidence, keeping materialized projection bytes readable as schema/count facts while rejecting them as causal-history import material or WAL recovery authority without manifests and segment evidence. -
warp-corenow exposes a versioned WSC causal-history export profile model forref-only,self-contained, andCAS-addressedprofiles, including the evidence each profile must carry and an explicit CAS byte-retention posture that does not promote CAS hashes into causal authority. -
warp-corenow exports and validates a ref-only WAL WSC fixture that joins WAL projection graph material, accepted-submission evidence, and receipt correlation evidence while reporting external segment bytes as explicit dependencies and normalizing absolute locator paths out of causal identity. -
warp-corenow exports and validates a self-contained WAL WSC fixture that embeds WAL segment bytes as WSC material, replays those bytes through WAL recovery to validate segment digest and commit-chain evidence, rebuilds accepted-submission and receipt indexes without access to the original filesystem WAL root, and reports tampered embedded bytes as typed recovery obstruction evidence. -
warp-corenow exports and validates a CAS-addressed WAL WSC fixture that joins WAL projection graph facts with content-addressed segment and retained material references, verifies referenced blobs through CAS content hashes without making CAS semantic authority, reports missing blobs as typed import obstructions, and keeps equal bytes under different semantic coordinates as distinct retained material references. -
warp-coreWAL WSC exports now carry retained material and reading-reference envelopes through ref-only, self-contained, and CAS-addressed profiles. Self-contained exports can embed retained payload bytes and validate them against the WAL-retained material digest, while CAS-addressed imports require the referenced retained blobs to be present before reporting success. -
WSC causal-history profile version 2 now carries explicit Echo causal-anchor fact, receipt, WAL transaction, LSN, and commit evidence through all three export profiles. Ref-only imports expose sidecar records as unverified until external WAL dependencies are resolved, but require every supplied sidecar to match a transaction and commit anchor in the projected WAL root; self-contained and CAS-addressed validation recovers retained WAL segments and requires the envelope to match the complete recovered anchor history before exposing observation evidence. CAS-addressed exports and imports also require retained CAS references to exactly match every retention record whose material posture is present; mismatch errors report missing and extra references independently.
echo-clibundle schema version 2 writes, inspects, and reports the dedicated causal-anchor envelope without treating Continuum transport as admission. -
warp-corenow includes a filesystem-backed WSC store adapter that persists envelope material separately from commit markers, hides staged material until marker publication, reopens committed envelopes in deterministic order, and reports torn envelope or marker files as typed WSC store obstructions. -
echo-clinow exposes read-onlywsc causal-historycommands that export ref-only and self-contained WAL WSC bundles from filesystem WAL roots, inspect bundle envelope metadata including retained evidence envelopes, verify self-contained bundles without the original WAL root, and report unavailable ref-only segment bytes as typed material obstructions in JSON output. -
echo-casnow exposes a fallible filesystem-backedDiskTierfor durable retained blobs, preserving content-only BLAKE3 hash semantics across process reconstruction while keeping missing blobs as explicit absence. -
cargo xtask test-slice durable-runtime-walnow runs the release-grade filesystem runtime WAL durability gate, joining filesystem ACK recovery, filesystem failure atomicity, CLI submission posture JSON, stale-claim, and generated man-page checks while leavingruntime-wal-ackas the fast semantic gate. -
cargo xtask test-slice durability-releasenow includes the exactwsc_retained_evidence_export_modeswitness, keeping retained-evidence WSC export coverage in the release gate without using Cargo's slow package-level name filter. -
cargo xtask test-slice durability-releasenow includes the exactretained_reading_missing_payload_is_not_empty_successwitness, locking the app-safe missing-retention posture for reading payloads, reading envelopes, and retained receipt support. -
cargo xtask test-slice durability-releasenow includes the exactrecovery_plan_bootstraps_from_wal_rootwitness, locking recovery plan bootstrap posture without using Cargo's slow package-level name filter. -
cargo xtask test-slice durability-releasenow includes the exactwal_recovery_rebuilds_all_durability_indexeswitness, locking committed-only rebuild coverage for durability indexes without using Cargo's slow package-level name filter. -
cargo xtask test-slice durability-releasenow includes the exactmaterialization_outbox_recovery_returns_typed_posturewitness, locking typed materialization outbox recovery posture into the release gate. -
cargo xtask test-slice durability-releasenow includes the exactwal_process_crashpointswitness, promoting the process-kill WAL crashpoint runner from future descriptor to release-gate evidence. -
cargo xtask dindnow defaults to run mode and includes the exactdind_durability_convergence_gatewitness, proving live WAL execution, read-only WAL recovery, WSC import, and retained-material reveal agree on the same app-facing receipt and bounded reading while missing or corrupt support material returns typed obstruction. -
cargo xtask test-slice durability-releasenow includes the exactdind_durability_convergence_gatewitness so the release slice also carries the DIND durability convergence proof. -
warp-coretrusted runtime hosts now configure runtime WAL throughTrustedRuntimeWalConfig, including in-memory and filesystem-backed adapters.TrustedRuntimeWalStoreKindexposes the configured adapter kind as host-owned read-only evidence, filesystem roots recover pending and decided submissions after host reconstruction, reopened filesystem adapters continue the committed LSN/digest chain, filesystem commits are markedStrictFilesystem, read-only filesystem recovery preserves torn/corrupt tail posture, host-test-only filesystem fault plans inject append, flush, and manifest failures to prove submission/tick rollback, andTrustedRuntimeAppremains limited to submit and observe surfaces. -
Added an Echo 1.0 release contract that records the four binary release gates, compatibility policy, evidence requirements, and GitHub Project boundary without carrying live roadmap state in the repository.
-
Recast the WAL/WSC packet as stable durability doctrine and added guards that reject live roadmap issue inventories while preserving WAL authority, graph projection, WSC export modes, storage locators, and bootstrap recovery language linked to issue
#521. -
warp-corenow hardens the first braids/strands roadmap goalpost:Strand<P>fields are no longer publicly constructible,Strand::new(...)validates typestate/runtime-posture coherence before construction, public strand tests use fixture builders and accessors,ProofEnvelope::validate_shape(...)returns structuredProofError, and invalid braid lifecycle transitions report typedBraidTransitionKindinstead of action strings. -
warp-corenow locks the second braids/strands roadmap goalpost with golden vectors for replay-trace proof-envelope identity, proofless and proof-bearing braid shell identity, revealed and sealed member identity, and sealed-member salt effects. The vector metadata marks these identities as E1 scaffolding identity, and API docs now state that deterministic member blinding defaults are reproducibility tools, not unlinkability boundaries. -
warp-corenow begins the third braids/strands roadmap goalpost with append-only braid membership history.BraidMembershipEntryandBraid::membership_history()expose acceptedMemberWovenfacts as a read-only projection over the braid event log, whilefrontier()remains the current membership projection. -
warp-corenow exposes historical braid membership views throughBraidMembershipCursor,Braid::current_membership_cursor(), andBraid::membership_at(...). The cursor is a half-open event-log interval, so later woven members do not appear in earlier membership views. -
warp-corenow exposesBraidMembershipDiffthroughBraid::diff_membership(...), reporting deterministic added and ended membership projection facts between historical cursors while reserving revealed/concealed fact slots for future lawful disclosure evidence. -
warp-corenow exposes retained braid shell replay/audit facts throughaudit_braid_shell(...)andBraidShellAudit, including member verdicts, support/frontier digests, posture floor, proof binding, and explicit self-witness integrity-only posture. -
The braids/strands hardening docs now define the Braid Flight Recorder and Causal X-Ray lower-mode output target over historical membership, diff, shell audit, proof-binding, and witness-posture facts.
-
warp-corenow completes the fourth braids/strands roadmap goalpost with typed witness receipts, witness kinds, a verifier-shaped witness backend boundary, deterministic simulator fixtures, explicit witness compatibility rules, generic sealed membership presentations, disclosure budget labels, and braid shell audit receipts that keep E1 self-witnessing marked as integrity-only local evidence. The self-witness simulator rejects non-E1 compatibility requests with a typedUnsupportedCompatibilityerror instead of minting stable public identity for scaffolding evidence. Sealed membership presentations validate that their witness receipt subject and evidence digests bind the braid coordinate, purpose, authority domain, member commitment, and disclosure budget. -
warp-corenow completes the fifth braids/strands roadmap goalpost with a named plurality law registry, machine-readable Law Cards, typed law references and versions in braid shell replay/audit readings, adapter-provided law-family routing through authority domains, and typed law obstruction evidence for unsupported or unauthorized law execution. Law references and braid shell policy ids reject all-zero names before replay, collapse-derived shells report collapse policy ids as collapse laws, and law versions reject zero before registration. Law readings derive integrity-only posture from witness attestation strength, so non-self integrity-only receipts are not promoted to external witness evidence, and they reject witness receipts whose subject digest does not match the retained support digest. Collapse-derived shells also reject records whose shell policy id diverges from the nested collapse policy id. -
The braids/strands hardening docs now define Goalpost 6 for topology intents and WAL recovery, making strand forks, braid event logs, retained braid shells, and replica suffix import explicit WAL/WSC hardening work rather than process-local topology state.
-
warp-corenow enforces the v1 single-writer-head strand invariant through bothStrand::new(...)andStrandRegistry::insert(...), and runtime strand forking constructs the registered relation through the same constructor boundary used by external callers. -
warp-corecasting a dynamically postured strand to statically shared now returns a semantically precisePostureObstruction::PostureMismatchinstead ofPostureObstruction::NarrowingRefused. -
warp-corerenamedProofEnvelope::verifytovalidate_shapeand updated error variants toProofShapeValidationFailedto accurately reflect shape/input checks rather than full cryptographic proof verification. -
warp-corestrand creation now carries explicitRetentionPosturethroughForkStrandRequest,ForkStrandReceipt, andStrand. Session-default and debugger fork constructors choose posture policy explicitly, session-default work always recordsPostureDerivation::SessionDefault, debugger forks never silently becomeShared, andStrandRegistryrejects incoherent retained posture such asSharedwithout an admission scope. -
warp-coreimport admission receipts now bind local source-shared import admission to an explicit imported artifact identity. A receipt minted for one imported artifact cannot admit another import into a local shared admission scope. -
warp-coreretained plural settlement artifacts now persist their causal posture inProvenanceEventKind::PluralArtifactand include the posture tag in canonical provenance-event hashing. -
warp-corenow exposes a generic contract obstruction taxonomy for product-facing contract-host surfaces.ContractObstructionKind,ContractObstructionSubject, andContractObstructionclassify unsupported operations, unsupported queries, admission obstructions, runtime faults, missing retention, stale basis, residual readings, and budget limits without importing application-domain failure names into core or treating runtime faults as lawful domain rejections. -
warp-corenow exposes retained evidence references and missing-retention posture for contract-hosted evidence.RetainedEvidenceRefbinds installed contract identity, retained role, semantic digest, content hash, and byte length;RetainedEvidencePosturereturns either available evidence or typedMissingRetentionobstruction. CAS hashes remain byte identities only and cannot stand in for semantic reading or evidence coordinates. -
warp-corenow exposes a local witnessed-submission persistence shell.WitnessedSubmissionPersistenceSnapshotpairs accepted submission records with canonical ingress envelopes so hosts can persist accepted-but-not-yet- ticked work and restore duplicate detection plus envelope material without staging scheduler-visible inbox work, ticking, dispatching handlers, or executing contracts. -
warp-corenow exposes a local product-facing intent outcome surface.submit_app_intent(...)returns anIntentSubmissionHandlewithout ticking or staging runtime ingress, andobserve_app_intent_outcome(...)maps internal scheduler correlation intoIntentOutcome::{Unknown, Pending, Applied, Rejected, Obstructed}with receipt evidence and typed contract obstruction posture. -
echo-registry-api,echo-wesley-gen, andwarp-corenow enforce local contract/API compatibility at the installed package boundary. Generated registries carry Echo contract ABI, Wesley generator, and contract-host helper API versions; host verification policy rejects version drift before package install; and installed contract receipt/reading evidence cites the verified compatibility metadata without granting execution or query authority. -
warp-corenow exposes a reference trusted runtime host loop for the local contract-host path.TrustedRuntimeHostowns generated package installation, ticketed ingress staging, scheduler passes, until-idle policy, and read-only observation service access, whileTrustedRuntimeAppexposes app-facing submit/observe/query methods without tick, package-install, ingress-staging, or fault-recovery authority. -
warp-corenow has an external contract proof fixture for the v0.1.0 local contract-host path. The fixture installs a generated-style package with a mutation, conflict-capable mutation, and QueryView query; submits non-trivial canonical vars; executes only through scheduler-owned ticks; observes a bounded contract reading; retains reading payload and receipt evidence throughecho-cassemantic coordinates; and replays witnessed submission history to the same observed intent outcome. The fixture keeps application nouns inside the test package and generated payload shape, not in Echo core. -
warp-corenow has a serious external-consumer-shaped contract fixture for the local contract-host path. The fixture uses hot-text-style document edit names only in test code, installs through the generic package boundary, submits through the app-facing host handle, produces a footprint-conflict rejection for overlapping edits, observes a bounded QueryView reading, and retains both reading payload and receipt evidence through semantic coordinates. -
xtask test-slicenow includescontract-path-release, a narrow local v0.1 contract-host release witness. The slice runs the installed contract pipeline replay tests, reference trusted host loop test, and serious external consumer fixture without requiring developers to run the full DIND suite for normal local iteration. -
xtask test-slicenow includesruntime-wal-ack, a narrow runtime WAL ACK witness. The slice runs WAL-backed app-facing submission acceptance, scheduler tick receipt commit-before-publish, recovered runtime indexes, CLI submission-posture JSON for filesystem runtime WAL roots, stale-claim guard, and generated man-page checks. -
The docs now include an executable local contract-host quickstart and a v0.1.0 authority-boundary audit. The quickstart points developers at
cargo xtask test-slice contract-path-release, names the app-facing and trusted-host APIs, and documents compatibility and retention boundaries. The audit records current evidence that application code cannot tick, stage ingress, install packages, or recover scheduler faults through the app surface. -
echo-cassemantic retention now supports bounded byte-range lookup throughRetainedBlobIndex::load_range(...). Range lookup requires the exact semantic coordinate, enforces the caller's byte budget, and returns typedRetentionErrorvariants for missing coordinates, missing content, over-budget requests, or out-of-bounds ranges. Content-hash lookup remains a byte lookup only; semantic success still requires coordinate match. -
echo-cassemantic retention now fails closed when the sameSemanticBlobCoordinateis retained with different bytes. Retaining the same coordinate with the same content is idempotent, while conflicting content returnsRetentionError::SemanticCoordinateConflict. Bounded range lookup now proves the semantic coordinate exists before reporting range-budget errors. -
echo-casnow provides a local semantic retention index above the content-only blob store.RetainedBlobIndexmapsSemanticBlobCoordinatevalues to retained descriptors for contract artifacts, receipts, witnesses, reading payloads, reading envelopes, and observer artifacts while preserving the rule thatBlobHashnames bytes only. Retained blobs can be loaded by content hash or exact semantic coordinate, equal bytes under different semantic coordinates do not alias, and missing coordinates or missing bytes return typedRetentionErrorvariants instead of fake successful reads. -
warp-coreQueryView readings now carry aQueryReadingIdentityinReadingEnvelope. The identity binds query id, domain-separated vars digest, resolved basis digest, requested aperture digest, observer plan, and installed contract evidence when present, while keeping payload bytes inObservationPayload::QueryBytes. Tests prove reading identity changes when query vars, query id, causal basis, schema/observer plan, or budget changes. Over-budget reads still obstruct withBudgetExceeded; residual readings remain explicit posture rather than fake complete payloads. -
warp-corequery reading identity now excludes observation freshness metadata from the basis digest. The same QueryView against the same resolved commit keeps a stableQueryReadingIdentityeven if unrelated runtime-owned tick progress changes the observation freshness watermark. -
warp-corenow publishes observation artifacts under observation contract version 4 andecho:observation-artifact:v4because contract evidence, query reading identity, and retained-evidence posture are now part of the canonical reading envelope hashed into observation artifacts. -
echo-wasm-abinow reportsABI_VERSION12 for the expandedReadingEnveloperesponse shape. Legacy retained reading envelopes that omit the new optional contract, query identity, and retained-evidence fields decode those fields asNoneor empty vectors. -
warp-corenow attaches contract package evidence to installed contract readings and receipt correlations. Installed QueryView readings carry package id, package name/version, artifact hash, schema hash, codec identity, registry version, query op id, and operation kind in theReadingEnvelope. Installed mutation receipt correlations copy the same package evidence from ticketed runtime ingress after scheduler-owned execution. Built-in reads and non-package observers can still leave this evidence empty. The evidence is metadata only: it does not grant tick authority, mutate state, replace semantic reading identity, or act as a CAS lookup key. -
warp-corenow connects the installed contract package boundary to the witnessed intent pipeline. Package-supported canonical EINT mutation ids can be staged through ticketed runtime ingress only after Echo has witnessed the submission and verified an installed package owns the op id; unsupported installed-contract mutation ids are rejected before they become runtime-visible scheduler work. The new installed-contract intent pipeline tests prove application submission does not tick or execute, ticketed ingress stages without executing, scheduler-owned ticks dispatch the installed mutation handler, conflict rejection is a final tick outcome with blocker attribution, duplicate submits do not create hidden retries, witnessed submissions can be replayed back into pending ingress history without staging inbox work, and the replayed pipeline converges to the same receipt correlation and observed outcome. Replayed witnessed submission records preserve generation continuity so the next live submission receives the next contiguous generation instead of skipping ahead. -
warp-corenow exposes an installed contract package registry boundary for runtime-owner host adapters. An installed package binds generated registry metadata, schema hash, codec identity, package artifact identity, supported mutation op ids, mutation handler rules, supported query op ids, and read-only query observers before the handlers or observers are installed intoEngine. The boundary verifies the generatedRegistryProviderwithecho-registry-api, rejects unknown operation ids, rejects mutation/query kind mismatches, rejects mutation rules whose generated rule name does not bind the declared mutation op id, rejects duplicate package operation ids, and preflights package-internal rule name/id conflicts plus engine-level rule and observer conflicts before mutating engine state. This does not add dynamic plugin loading, application-controlled ticks, streaming subscriptions, or domain nouns towarp-core. -
echo-wesley-gen --contract-hostnow emits std-only query observer host helpers againstwarp-core'sContractQueryObserverboundary. Generated query helpers include deterministic authored observer plan identity, typed context-vars decoders that returnResulton malformed canonical vars, and typed observer constructors that install read-only host closures throughEngine::register_contract_query_observer. The core observer function boundary now returns a typedResult, so decode failures and host observer failures are explicit observation errors. The generated smoke crate proves mutation host helpers and query observer helpers install together without giving query observers write authority, tick authority, or application nouns in core. -
warp-corenow routesQueryView/Queryobservations to installed contract query observers. Installed observers are keyed by generated query op id, receive canonical vars bytes plus the resolved causal basis, returnObservationPayload::QueryBytes, and stamp the emittedReadingEnvelopewith the authored observer plan identity. Unsupported query ids remain typedUnsupportedQueryerrors, artifact identity changes when query vars, op id, schema/plan identity, or basis changes, and observer-reported residual posture participates in bounded reading evidence. This does not add streaming subscriptions, generated query observer helpers, dynamic plugin loading, or application-controlled execution. -
echo-wesley-gennow supports--contract-host, an opt-in generated helper surface for installedwarp-coremutation handlers. Generated mutation helpers now include stable contract command-rule names, op-id matchers, typed vars decoding from scheduler-materialized EINT runtime ingress events, base runtime-ingress read footprints, and rule constructors that accept host-supplied executor and footprint functions. A generated toy-counter smoke crate proves the emitted helpers install intowarp-coreand run only during scheduler-owned ticks. This flag is std-only and does not implement QueryView, dynamic plugin loading, or a generated application mutation body. -
warp-corenow exposes a scheduler-owned installed contract host seam for EINT-backed mutation handlers. Host/generatedcmd/*rules can read a scheduler-materialized runtime ingress event, match its EINT operation id, borrow canonical vars bytes for generated decoding, and extend a standard runtime-ingress read footprint with handler-specific writes. Tests prove an installed toy contract handler does not run during application dispatch, runs only duringSchedulerCoordinator::super_tick(...), and ignores nonmatching EINT operation ids. This does not generate Wesley handler rules, implement QueryView, add dynamic plugin loading, or allow application code to tick the runtime. -
warp-corenow records runtime-local scheduler fault quarantine posture after internal scheduler faults. Lawful receipt-level rejections remain normal tick outcomes and do not fault heads. Scoped internal head faults roll back the failedSuperTickattempt, record scheduler fault evidence, quarantine only the failing writer head, and allow unrelated heads to proceed on later ticks. Unscoped panic faults mark the runtime globally faulted until trusted runtime recovery resolves the fault. Generic head eligibility changes do not clear fault quarantine. Durable control-plane/provenance publication for scheduler fault evidence remains follow-up work. Trusted host adapters can enablewarp-core/trusted_runtimeto construct the recovery authority; the authority remains unavailable to ordinary application builds. -
warp-corenow exposes a zero-writeobserve_intent_outcome(...)polling surface over witnessed submission ids. The observation reportsUnknownSubmission,Pendingwith optional ticketed-ingress identity, orDecidedwith the scheduler-owned receipt correlation and typed receipt decision once a ticketed submission reaches a tick receipt. The decision reports applied entries or rejected entries with deterministic rejection reason and blocker attribution. This does not stream updates, dispatch installed handlers, execute contracts outside scheduler-owned ticks, or introduce automatic retry. -
warp-corenow records scheduler-owned receipt correlations for ticketed runtime ingress. AfterSchedulerCoordinator::super_tick(...)commits a ticketed ingress batch, Echo indexes the witnessed submission id, admission ticket digest, ticketed ingress id, ingress id, writer head, logical tick coordinates, receipt digest, and commit hash. Correlations are created only after scheduler-owned ticks and only for ticketed runtime ingress; legacy direct inbox ingress remains uncorrelated. This does not expose intent outcome observation, dispatch installed handlers, execute contracts outside scheduler-owned ticks, or introduce automatic retry. -
warp-corenow exposes a ticketed runtime ingress boundary.WorldlineRuntime::submit_intent(...)records witnessed submission history without entering a head inbox, ticking, dispatching handlers, or mutating application state.WorldlineRuntime::ingest_ticketed_invocation(...)stages a witnessed submission into runtime ingress only when the caller holds the explicitTicketedRuntimeIngressAuthorityruntime-owner token and supplies anOpticAdmissionTicket, records deterministic ticketed-ingress correlation material, rejects unknown or mismatched submissions, and treats duplicate staging of the same ticket/submission pair idempotently. This does not correlate tick receipts, expose intent outcome observation, dispatch installed handlers, execute contracts outside scheduler-owned ticks, or introduce automatic retry. -
warp-coreoptic invocation admission now issues anOpticAdmissionTicketafter BasisResolution, ApertureResolution, BudgetResolution, RuntimeSupport, capability identity coverage, InvocationAdmission, SchedulerAdmission, SchedulerWorkCandidate, and LawWitness all resolve. The ticket binds the registered artifact handle, artifact hash, operation id, requirements digest, canonical variables digest, request digests, law witness digest, and a deterministic ticket digest, and publishes anAdmissionTicketIssuedgraph fact with the same invocation-binding material. Echo-owned admission evidence fixture recorders now require an explicitOpticAdmissionEvidenceAuthoritytoken, making the host/runtime-owner boundary explicit before test fixture evidence can be recorded; the runtime-owner constructor is only available behindwarp-core's internalhost_testfeature. This does not enqueue scheduler work, enter runtime ingress, tick, dispatch handlers, execute contracts, correlate tick receipts, or observe intent outcomes. -
warp-corenow records a narrow WitnessedIntentSubmission ledger whenWorldlineRuntime::ingest(...)accepts canonical application ingress. The runtime derives a deterministicsubmission_idfrom the resolved writer head and content-addressedingress_id, assigns an Echo-ownedsubmission_generationfor intake/audit correlation, and returns the same submission identity for duplicate pending or committed ingress without appending duplicate semantic submission history. This ledger does not tick, mutate application state, dispatch handlers, enqueue scheduler work, issue law witnesses, issue admission tickets, or make submission order decide scheduler order.DispatchResponsenow carries optionalsubmission_idandsubmission_generationfields for application ingress, and the WASM ABI version is now 10. -
warp-coreoptic invocation admission now has a narrow SchedulerWorkCandidate boundary. After BasisResolution, ApertureResolution, BudgetResolution, RuntimeSupport, capability identity coverage, InvocationAdmission, and SchedulerAdmission all resolve, Echo checks runtime-owned scheduler work candidate facts for the registered artifact handle. Without that Echo-owned scheduler work candidate fact, the ladder obstructs atSchedulerWorkUnavailable; with the exactscheduler-work-candidate:resolved-fixturefixture, the ladder advances toLawWitnessUnavailable. Scheduler work candidate fixture recording is scoped through Echo-issued artifact handles, publishes idempotent graph facts, and rejects unknown handles without publishing scheduler work candidate evidence. This does not add law witnesses, admission tickets, scheduler enqueueing, handler dispatch, execution, or caller-supplied scheduler work testimony. -
warp-coreoptic invocation admission now has a narrow LawWitness boundary. After BasisResolution, ApertureResolution, BudgetResolution, RuntimeSupport, capability identity coverage, InvocationAdmission, SchedulerAdmission, and SchedulerWorkCandidate all resolve, Echo checks runtime-owned law witness facts for the registered artifact handle. Without that Echo-owned law witness fact, the ladder obstructs atLawWitnessUnavailable; with the exactlaw-witness:resolved-fixturefixture, the ladder can issue an admission ticket. Law witness fixture recording is scoped through Echo-issued artifact handles, publishes idempotent graph facts, and rejects unknown handles without publishing law witness evidence. This does not enqueue scheduler work, dispatch handlers, execute contracts, or accept caller-supplied law witness testimony. -
warp-coreoptic invocation admission now has a narrow SchedulerAdmission boundary. After BasisResolution, ApertureResolution, BudgetResolution, RuntimeSupport, capability identity coverage, and InvocationAdmission all resolve, Echo checks runtime-owned scheduler admission facts for the registered artifact handle. Without that Echo-owned scheduler admission fact, the ladder obstructs atSchedulerAdmissionUnavailable; with the exactscheduler-admission:resolved-fixturescheduler admission fixture, the ladder advances toSchedulerWorkUnavailable. Scheduler admission fixture recording is scoped through Echo-issued artifact handles, publishes idempotent graph facts, and rejects unknown handles without publishing scheduler admission evidence. This does not add admission tickets, law witnesses, scheduler work, scheduler enqueueing, handler dispatch, execution, or caller-supplied scheduler admission testimony. -
warp-coreoptic invocation admission now has a narrow InvocationAdmission boundary. After BasisResolution, ApertureResolution, BudgetResolution, RuntimeSupport, and capability identity coverage all resolve, Echo checks runtime-owned admission facts for the registered artifact handle. Without that Echo-owned admission fact, the ladder obstructs atInvocationAdmissionUnavailable; with the exactinvocation-admission:resolved-fixtureadmission fixture, the ladder advances toSchedulerAdmissionUnavailable. Invocation admission fixture recording is scoped through Echo-issued artifact handles, so caller-supplied invocation bytes and capability presentations cannot supply admission testimony. This does not add admission tickets, law witnesses, scheduler admission, scheduler work, handler dispatch, execution, or successful grant validation. -
warp-coreoptic invocation admission now has a narrow RuntimeSupport boundary. After BasisResolution, ApertureResolution, and BudgetResolution all resolve, Echo checks runtime-owned support facts for the registered requirements digest. Without that Echo-owned support fact, admission still obstructs atRuntimeSupportUnavailable; with the exactruntime-support:resolved-fixturesupport fixture and no Echo-owned invocation admission fact, the ladder advances toInvocationAdmissionUnavailable. Runtime support fixture recording is scoped through Echo-issued artifact handles, so unknown handles cannot publish support facts, repeated recordings for the same requirements digest do not duplicate support facts, and registration rejects artifacts whose stored requirements digest does not match the artifact requirements digest. This does not add caller-supplied runtime support testimony, admission tickets, law witnesses, scheduler work, execution, budget reservation, or successful grant validation. -
dispatch_optic_intent(...)and the defaultKernelPortoptic dispatch path now reject EINT payloads that use Echo's reserved scheduler/control op id, closing the remaining application-facing control-intent ingress path. -
warp-coreoptic invocation admission now has a narrow ApertureResolution boundary. Identity-covered invocations with exact fixture basis bytesbasis-request:resolved-fixtureand exact fixture aperture bytesaperture-request:resolved-fixtureprogress past aperture resolution and still obstruct atUnsupportedBudgetResolution; unsupported aperture shapes continue to obstruct atUnsupportedApertureResolution, and aperture resolution remains unreachable when basis resolution fails. This does not issue admission tickets, law witnesses, scheduler work, execution, budget evaluation, runtime support checks, or successful grant validation. -
warp-coreoptic invocation admission now has a narrow BasisResolution boundary. Identity-covered invocations with exact fixture basis bytesbasis-request:resolved-fixtureprogress past basis resolution and still obstruct atUnsupportedApertureResolution; all unsupported non-empty basis shapes continue to obstruct atUnsupportedBasisResolution. This does not issue admission tickets, law witnesses, scheduler work, execution, aperture resolution, budget evaluation, runtime support checks, or successful grant validation. -
warp-coreoptic invocation admission now has a budget/runtime-support obstruction shell. Empty budget request bytes obstruct asMissingBudgetRequest;UnsupportedBudgetResolutionandRuntimeSupportUnavailableare defined as future vocabulary but remain unreachable until basis and aperture resolution exist. -
docs/design/budget-and-runtime-support-optic-admission.mddefines budget as caller-supplied bounded-resource context and runtime support as Echo-owned capability checking against registered artifact requirements, not caller testimony. -
warp-coreoptic invocation admission now has an aperture-bound obstruction shell. Empty aperture request bytes obstruct asMissingApertureRequest;UnsupportedApertureResolutionis defined as future vocabulary but remains unreachable until basis resolution exists because aperture semantics are scoped inside a resolved causal basis. -
docs/design/aperture-bound-optic-admission.mddefines aperture as the visibility/effect window over a resolved basis and pins the rule that basis resolution gates aperture resolution. -
warp-coreoptic invocation admission now has a basis-bound obstruction shell. Empty basis request bytes obstruct asMissingBasisRequest; identity covered capability presentations still obstruct asUnsupportedBasisResolutionbecause Echo has not wired basis resolution, admission tickets, law witnesses, scheduler work, or execution into invocation admission. -
docs/design/basis-bound-optic-admission.mddefines the current basis boundary: basis selection is explicit admission context, and covered authority material still cannot authorize execution without basis resolution. -
warp-coreoptic invocation admission can now route bound capability presentations through a narrowCapabilityPresentationValidatorto publish sharper grant-validation obstruction facts while preserving conservativeCapabilityValidationUnavailableinvocation refusal. Identity coverage still does not issue an admission ticket, law witness, scheduler work, or execution. -
docs/design/invocation-grant-validation-obstruction-routing.mddefines the validator routing boundary: validation evidence refines refusal, but it does not create authority. -
warp-corenow publishesGraphFact::CapabilityGrantValidationObstructedwhen recorded capability grant material fails narrow identity coverage against a registered optic artifact. The validation checks artifact hash, operation id, requirements digest, and explicit expiry posture, and remains refusal-first: it does not issue successful admission tickets, law witnesses, scheduler work, execution, delegation policy, quorum governance, or Continuum protocol. -
docs/design/capability-grant-validation-obstruction-facts.mddefines grant validation obstruction as graph evidence rather than authority. A recorded grant can fail causally before any invocation can succeed. -
warp-corenow publishesGraphFact::OpticInvocationObstructedwhenever the optic invocation admission skeleton refuses an invocation. The fact records the artifact handle id, operation id, canonical variables digest, basis and aperture request digests, and structured obstruction kind without creating a success admission ticket, law witness, execution, scheduler output, or counterfactual candidate. -
docs/design/invocation-obstruction-graph-facts.mddefines the invocation refusal publication boundary: registered handles are not authority, and invocation obstruction facts are causal refusal evidence rather than counterfactual worlds. -
Local verification now maps
warp-coreoptic artifact and causal fact source changes to the exact integration test targets they exercise, avoiding broad Cargo name-filter runs while preserving targeted smoke coverage. -
warp-corenow publishes in-memory causal graph facts from optic artifact registration. Successful registration emitsGraphFact::ArtifactRegistered, computes a deterministicFactDigest, and links that digest from anArtifactRegistrationReceipt; obstructed registration emitsGraphFact::ArtifactRegistrationObstructedwithout issuing a handle or success receipt. Fact digests use explicit domain tags, field tags, present/absent markers, and length-prefixed bytes, not JSON. -
docs/design/graph-fact-publication-skeleton.mddefines the first substrate publication boundary: facts are world statements, receipts explain publication/refusal boundaries, and registration facts are the first in-memory proof that Echo can describe its own runtime decisions. -
echo-wesley-gennow imports realwesley-core0.0.4 runtime optic artifacts intowarp-coreregistration structs, preserving Wesley artifact hashes, schema ids, operation ids, requirements digests, and registration descriptors while keepingwarp-corefree of a Wesley dependency. Echo still owns opaque runtime-localOpticArtifactHandleissuance. Imported admission requirements now preserve Wesley-owned canonical requirement bytes, codec id, and digest directly fromOpticAdmissionRequirementsArtifact; downstream runtimes must not serialize Wesley structs to create admission truth. -
docs/procedures/DIRECT-MAIN-EXCEPTION-LOG.mdrecords the 2026-05-14 docs-only direct-main exception for the Echo graph model checkpoint, including authorization context, exact commits, validation, changed files, and the future rule to prefer PRs unless an emergency or docs-only fast path is explicitly authorized. Future exception records must also cite explicit authorizer identity and authorization evidence. -
docs/design/built-in-echo-graph-data-model.mddefines Echo's native graph ontology for future optic admission, authority, transaction atomicity, receipts, witnessed readings, footprint addressing, transaction-local object identity, worldlines, strands, attachments, provenance, materialization, import/export, and settlement. -
docs/design/obstruction-receipt-boundary.mddistinguishes causal obstruction receipts from counterfactual retention: refusal is a causal event but not admission, and counterfactuals begin only after a rewrite is legally admitted and then left unselected at the scheduler boundary. -
warp-corenow attaches anObstructionReceiptto capability grant intent refusals. The receipt records causal refusal context and remains explicitlyRewriteDisposition::Obstructed, not an admission ticket, law witness, or counterfactual candidate. It also carries the authority policy id/posture used to classify the refusal when that policy context is present. Receipt input bytes are rebuilt on demand for digest verification instead of being stored on every refusal receipt. -
docs/design/transaction-optic-atomicity-model.mddefines Echo's doctrine for atomic composite optics: one basis, one admission surface, transaction-local execution, one committed delta, and receipt-emitting refusal or admission. It also pins the rule that policy evaluation reading graph state is an atomic causal phase, not a detached preflight query. -
warp-corenow has an Echo-ownedOpticArtifactRegistryregistration proof for Wesley-compiled optic artifacts. The registry verifies artifact id, artifact hash, schema id, operation id, and requirements digest before storing admission requirements internally and returning an opaqueOpticArtifactHandle. -
warp-corenow has an optic invocation admission skeleton that resolves registered artifact handles internally and obstructs unknown handles, operation mismatches, and registered-handle invocations without capability presentation. Admission outcomes are must-use, and placeholder capability presentations still obstruct until grant validation is wired into invocation admission. The registration and invocation regression fixtures avoidexpect(...)so all-target Clippy remains clean. -
Optic invocation obstruction now returns a ticket-shaped pre-admission posture carrying the invocation handle, operation id, canonical variables digest, basis request, aperture request, and structured obstruction reason. This is not a success ticket and does not authorize execution.
-
Optic invocation admission now classifies capability presentation obstruction without validating grants: missing, malformed, unbound, and placeholder presentations all remain obstructed until real bounded grant validation exists.
-
warp-corenow has an Echo-owned capability grant intent obstruction skeleton.CapabilityGrantIntentGaterecords well-formed submitted authority intents deterministically, obstructs malformed, missing-issuer, invalid-delegation, scope-escalation, replay/duplicate, and unsupported-policy grant intents, and keeps all submissions from becoming authority until future witnessed grant admission exists. -
Echo-owned WASM package boundary tooling:
scripts/build-warp-wasm-package.shnow buildscrates/warp-wasm/pkgwith the bundler target and the package export smoke test importscrates/warp-wasm/pkg/rmg_wasm.jsto verify the JavaScript byte ABI surface expected by consumers. -
The WASM package export smoke test now runs through
scripts/tests/warp_wasm_package_exports_test.sh, which rebuilds the package before importing it so the export witness cannot pass against a stale package. -
Stack Witness 0001 drift lock —
warp-wasmnow mirrors Wesley's fixture vectors for the jedit-through-Echo walking skeleton and verifies Echo's fixture op ids, buffer-inclusive fixture vars bytes, thewesley-binary/v0target codec marker, helper entrypoints, and expectedQueryBytes("hello")payload bytes against that vector. -
echo-registry-api::verify_contract_artifact(...)— generic load-time verification for Wesley-generated registries, including schema/codec/layout checks, expected footprint certificate hashes, optional generated artifact hashes, and a policy switch requiring all mutation operations to be backed by an expected certificate before the artifact is treated as compile-time-certified. -
Cycle 0003 (dt policy) — ratify fixed timestep as default, variable-dt as opt-in admitted stream, braidability constraint for settlement.
-
KERNEL_strand-contractbacklog item — strand as a first-class relation with exact fields, invariants, lifecycle, and TTD mapping. -
KERNEL_strand-settlementbacklog item — deterministic settlement semantics (compare → plan → import → conflict artifact). -
crates/method/— standalone METHOD library crate (cycle 0002).cargo xtask method statusandcargo xtask method status --jsonfor backlog lane counts, active cycles, and legend load. -
Adopt METHOD: backlog lanes, legends, cycle loop, BEARING signpost.
-
docs/DOCS_AUDIT.md— full audit of every file in the docs corpus. -
docs/BEARING.md— current direction and tensions signpost. -
Four legends: KERNEL, MATH, PLATFORM, DOCS.
-
Seven asap backlog items (five xtask METHOD commands, docs cleanup, roadmap migration).
-
Three graveyard entries (BOAW naming, 5x Duty Model, unimplemented future specs).
- Removed the provisional caller-authoritative causal-anchor API:
CausalAnchorRequest,CausalAnchorFact::from_request, public admitted-fact fields, and raw admitted-identity constructors. Applications now submit aCausalAnchorAdmissionRequestand treat the returned Echo fact, receipt, and identities as opaque. This is an intentional breaking Rust API correction; preserving the old surface would let callers manufacture Echo authority. - Removed the abandoned Method system: its workspace crate and
xtaskcommands, checked-in backlog, cycles, retrospectives, status ledgers, process manuals, and generated task graphs. Current architecture now lives in canonical topics/specs/invariants, durable decisions live in ADRs, and live work/status lives in GitHub. - Removed the superseded
docs/design/packet corpus and the retired TTD counterfactual-creation invariant after promoting current doctrine into canonical topics, ADRs, architecture documents, specifications, and tests. - Removed the remaining architecture drift/future packets and dated benchmark reports after preserving the retained-reading storage and proof boundary in ADR 0020. Benchmark instructions now keep methodology in source docs and measurements in generated artifacts and pull requests.
- Deleted zombie crates with no consumers (recoverable from git history):
echo-wasm-bindings(browser demo kernel),echo-ttd,ttd-protocol-rs, andecho-session-proto(the TTD stack now lives withwarp-ttd), plusecho-config-fs(desktop app-shell fossil) and thepackages/ttd-protocol-tsgenerated consumer. - Deleted
echo-app-core(desktop app-shell fossil: toasts, prefs, config ports) and theecho-dry-testsin-memory config fake that existed only to test its trait; no other crate consumed either. - Removed the unused
echo-wasm-abi::ttdmodule and its publicPrivacyMask,SessionToken, andTtdErrorexports after the owning TTD/session stack was retired. This is a breaking Rust API removal for unknown external consumers. - Deleted
cargo xtask wesley(existed only to sync the removed TTD protocol consumer artifacts). - Deleted stale point-in-time audit reports under
docs/audit/anddocs/audits/. - Removed the deleted crates from workspace members, CI clippy lanes,
det-policy.yaml,scripts/verify-local.sh, and the unordered-ABI allowlist. - Removed the VitePress docs-site toolchain from active repo tooling: npm scripts, Make targets, tracked docs-site config, the dead browser-open helper, and VitePress/Mermaid dependencies are gone.
- Removed the broken
warp-core/serdefeature and the gatedSerializable*wrapper exports.warp-coreno longer declares directserde,serde-value, orciboriumdependencies; authoritative core serialization must stay in explicit canonical boundary encoders rather than general serde derives. - Removed the legacy
ttd-browsercrate from Echo's active workspace. The release browser/runtime boundary now stays centered onwarp-wasmandecho-wasm-abi; debugger session semantics and browser delivery adapters belong inwarp-ttd. docs/METHODOLOGY.md— 5x Duty Model (never practiced; see graveyard).- 17 unimplemented future spec files (see graveyard).
docs/march-16.plan.md— stale planning scratchpad.docs/plans/parallel-merge-and-footprint-optimizations.md— superseded by design review.- Old plans, book (LaTeX), and research artifacts. All remain recoverable from Git history.
warp-fficrate deleted: The C ABI integration path (crates/warp-ffi) has been removed. The C ABI approach was abandoned in favor of Rust plugin extension viaRewriteRuletrait registration and Rhai scripting. See TASKS-DAG.md #26 (Graveyard). This is a BREAKING CHANGE for any downstream code that depended on the C FFI surface.
- Public installed-contract evidence fields on runtime ingress, receipt
correlation, outcome, and WAL state-delta carriers now use
Option<InstalledInvocationEvidence>instead ofOption<ContractEvidenceIdentity>. This is an intentional pre-1.0 source compatibility change: legacy callers wrap withLegacyContractor.into()and inspect withlegacy_contract(), while provider callers inspectprovider_v1(). The enum is non-exhaustive to match the extensible wire-tag family, so direct downstream matches require a wildcard arm. The legacy tag-1 WAL encoding remains byte-identical. - The public
RuntimeErrorenum now includesInstalledContractIntentKindMismatchandUnsupportedInstalledProviderContractMutation, and the publicContractInverseObstructionenum now includesProviderTargetUnsupported. These are intentional pre-1.0 source-compatibility additions: downstream exhaustive matches must handle the new variants (or use an appropriate wildcard arm). echo-wesley-gennow follows Wesley's operation-neutral adapter names:import_runtime_optic_artifact(...)acceptsOperationArtifact, andimport_registration_descriptor(...)acceptsOperationRegistrationDescriptor. Source consumers using Wesley's formerOpticArtifactorOpticRegistrationDescriptornames must update when they adopt the corresponding Wesley 0.3 prerelease; Echo's runtime-local optic artifact types and handles are unchanged.- Provider semantic-source, generation-input, and contract-pack
Displaydiagnostics now render explicit kebab-case failure labels instead of RustDebugvariant spellings. Typed error enums remain the programmatic contract, while human/CLI diagnostics no longer move when Rust variants are refactored. - Restored the durable ADR 0001–0011 namespace and moved the post-Method decisions to ADR 0012–0019, preserving the meaning of existing source citations. CI now rejects missing, duplicate, non-contiguous, unindexed, or collided ADR identifiers.
- Recorded the WSC, CAS, semantic reading identity, and optional proof boundary as ADR 0020 without carrying forward the source packet's implementation roadmap or application-specific checkpoint design.
- Replaced the opaque numeric determinism claim-pack generator with an honest gate over upstream job results and exact artifact payload presence. The executable suites remain the authority for what passed.
- Replaced the frozen root architecture and advanced guides with explicit supersession signposts to the living no-graph architecture, topics, specifications, invariants, and ADRs.
- Echo 1.0 release eligibility now depends only on Continuum participant
conformance, networked causal suffix exchange, and release integrity. Edict,
jedit, and any particular generated package remain downstream compatibility work and no longer gate the Echo release. - Echo 1.0 planning references now point at the cross-repository Continuum Stack Convergence Project instead of the retired Echo-only Project.
- Local
scripts/verify-local.sh fullnow treats broad Cargo test lanes as GitHub Actions-owned by default, while keeping a maintainer opt-in throughVERIFY_LOCAL_FULL_TESTS=1for intentional local full-suite runs. warp-corerenamed the generated contract package host API frominstall_contract_package(...)toregister_contract_package(...)so the trusted-runtime boundary reads as explicit runtime-owned registration instead of process-global installation.warp-coresealed braid member lookup now requires authority-bound sealed query material, redacts non-public blinding material from debug output, and keeps hidden-member commitments stable across parent frontier movement.warp-coresettlement planning now rejects non-Sharedstrands before producing import candidates. Author-only/debugger strand suffixes can remain real causal work, but they cannot enter base shared history without an explicit shared admission posture. Settlement compare remains local revelation/inspection only: it can inspect a locally held strand suffix without promoting, planning, admitting, or settling it.warp-coresettlement plural artifacts and retained braid shells now carry the source strand posture instead of hard-coding author-only posture for shared settlement records.- Local determinism tooling now fails closed around
scripts/check-warp-core-serialization-boundaries.sh. The serialization boundary guard is mandatory, runs throughbashrather than executable mode, works withoutrg, rejects table-form serde/ciborium dependencies, and blocks direct, grouped, multiline, or aliased canonical ABI serialization imports outside explicitwarp-coreboundary modules. - The nondeterminism guard now shares the same
rg/Perl fallback scanner, supportsDETERMINISM_FORCE_NO_RG=1regression coverage, catches namespace imports and alias calls forstd::env,std::fs, andstd::process, bansstd::thread::available_parallelism, and replaces file-wide allowlists with rule-scoped waivers for build/native filesystem boundaries and test fixtures. warp-coreengine and scheduler state now use orderedBTreeMap/BTreeSetstorage instead ofHashMap,HashSet, orFxHashMapin deterministic core paths. WAL filesystem tests also recreate stale deterministic fixture roots before use so previous local residue cannot change the test outcome.warp-coreengine construction now defaults to deterministic serial execution instead of readingECHO_WORKERSor host CPU availability. Callers can still opt into parallel execution explicitly withEngineBuilder::workers(...)or worker-count constructors.echo-cli wal submission-posturenow exposes generic read-only recovery JSON for one submission id and canonical envelope digest. The output reports retry posture, recovered submission posture, receipt digest, and ticket digest without importing any application nouns into Echo.- Runtime WAL-backed scheduler ticks now roll back all tick WAL evidence from a failed multi-head scheduler pass, treat missing or mismatched receipt correlation evidence as an invariant error instead of a normal obstruction, and bind runtime recovery certificates to rebuilt submission and receipt indexes.
warp-wasmno longer contains the legacy Stack Witness 0001createBuffer/replaceRange/textWindowshortcut. QueryView requests now route through the generic installed contract observer boundary only; without an installed observer, WASMobserve(...)returnsUNSUPPORTED_QUERYinstead of materializing hardcoded text bytes.warp-corestructured binding tests no longer use rope/text-shaped fixture names. The executable examples now exercise generic authored scopes, heads, segments, and markers so core test fixtures do not imply built-in editor semantics.- The canonical pre-push hook now runs the narrowest changed-file Rust witness
instead of reusing the broader local PR gate. Rust module edits map to exact
cargo test -p <crate> --lib <module>::testsslices, integration-test edits map to exact--test <target>invocations, and tooling edits stay on local shell smoke checks. Broader clippy, rustdoc, package, and workspace coverage remains available throughmake verify-pr,make verify-full, and CI. The selector now avoids fake zero-test module filters for source files without inline tests, mapssrc/bin/*.rsedits to exact binary targets, and preserves required features for gated integration tests. - Deterministic math now lives in a slim
warp-mathworkspace crate.warp-corekeeps the existingwarp_core::math::*compatibility surface as a re-export, whilewarp-geomdepends directly onwarp-mathinstead of pulling in all ofwarp-core. Math-only integration tests, deterministic trig golden vectors, PRNG golden regression, and the LUT generator moved with the math crate. - CI and local verification now split broad clippy coverage into explicit
library, binary, and selected integration-test lanes instead of invoking one
monolithic cargo pass. The
warp-coreruntime inbox test target is now an explicit lint lane with the samenative_rule_bootstrap,host_testfeatures used by the ticketed-ingress regression suite. - Local verification now treats rustdoc warnings as CI-owned by default.
scripts/verify-local.shskips local rustdoc lanes unlessVERIFY_LOCAL_RUSTDOC=1is set, keeping pre-push and full local gates focused on faster edit-loop witnesses while preserving CI rustdoc coverage. - Tooling-only full verification now selects focused hook regression scripts by
changed file family, so a
scripts/verify-local.shedit runs the verify-local hook regression without also running unrelated runtime-schema, PR-status, or timing hook tests. - Local hook regression tests are now CI-owned by default. The local full gate
skips hook tests unless
VERIFY_LOCAL_HOOK_TESTS=1is set, and the opt-in hook-test lane clears verifier override variables before launching nested hook regressions.
- Generic executable-operation lowering and independent verification now resolve source-local obstruction constructor aliases through the exact digest-locked lawpack import before encoding or comparing the package. Runtime duplicate outcomes therefore retain the capability-owned obstruction coordinate instead of exposing an application-local alias or collapsing it into the generic precondition-mismatch class.
- Provider-native installation now applies the same pure structural validation
used to reconstruct retained invocation evidence before mutating any Echo
engine index. Empty operation or Target IR coordinates, empty Target IR
digest domains, and Target IR digests that are not exact lowercase
sha256:<64-hex>values fail with stable typed installation errors, so Echo cannot originate receipt or WAL evidence that fresh-host recovery would reject. Existing valid tag-2 provider evidence and byte-stable tag-1 legacy evidence retain their encoding and recovery behavior. - Full local verification now enables the declared
native_rule_bootstrap,trusted_runtimefeature set when testing or lintingprovider_contract_admission_tests, matching the canonical pre-push route. - Direct GraphQL SDL lowering in
echo-wesley-gennow binds the exact pinnedwesley-coreversion into generated Rust artifact-hash provenance, with a regression test that refuses dependency/provenance version drift. - Generated-rule architecture now distinguishes Wesley's current raw
RewriteRulefixture path, Edict's fixture-only Target IR bridge, and the still-target package-registration corridor. It also recordsnative_rule_bootstrapas an opt-in Cargo policy boundary rather than an access-control seal. - Generated-rule documentation no longer implies that release footprint
enforcement is already wired. Wesley and Edict packs remain unqualified until
package emitters and positive and negative
footprint_enforce_releasewitnesses exist. warp-corerecovered filesystem WAL ACK paths now rebuild the live evidence catalog before returning recovered success, live catalog-update failures record the last commit where the catalog was actually fresh, and committed evidence segments now populatecoverings_by_rangefor their exact LSN range. Rebuilt evidence catalogs now reject malformed commit/frame evidence before admittingExactCommittedWalsegments.Cargo.locknow pinscrossbeam-epochto0.9.20, clearingRUSTSEC-2026-0204for the benchmark-onlyrayondependency path.warp-coreevolving braid logs now reject unchecked incremental mutations:Braid::applyreturns typed lifecycle errors, rejects duplicate member weaving and mixed revealed/sealed membership, refuses empty-frontier settlement finalization, detects member sequence overflow with checked arithmetic, rejects empty collapse witnesses, and exposes folded state through read-only accessors instead of public mutable fields. Duplicate checks now use a deterministic member index instead of scanning the append-ordered frontier.warp-corebraid-shell digests now bind optional proof-shaped envelopes: proof-bearing shells have distinct content identity from proof-less shells, mutating proof bytes after assembly is caught by shell validation, andBRAID_SHELL_VERSIONis now2for the proof-digest marker shape. Shape-only proof envelope admission is limited to replay-trace evidence; cryptographic proof kinds require a verifier backend before admission.warp-coresealed braid members now require caller-supplied blinding material, preserve hidden shared source disclosure in settlement shells, mix a settlement-localMemberBlindingSaltinto hidden settlement member commitments, reject mixed revealed/sealed shell member sets, and treat sealed member authority as part of duplicate-member identity.warp-coreretained braid shell queries now distinguish revealed member lookup from sealed member lookup:has_revealed_member_strandandBraidShellQuery::revealed_member_strandonly match revealed references, whileBraidShellMemberQuerycarries blinding material for sealed matches.warp-corecrate-root braid exports now includeBraidError,BraidStatus, andBraidMemberRefso external consumers can handle public braid results.warp-coreshared-strand settlement handles now re-enter the live registry path before planning or settling, and crate-internal settlement helpers reject stale handles that no longer match registered strand state.CausalPostureStateis sealed to Echo's marker types so external crates cannot add typestate implementations outside the runtime posture gate.warp-wasmsettlement publication now maps non-Sharedstrand admission rejection to the stableINVALID_STRANDABI error code instead of collapsing the lawful posture denial intoENGINE_ERROR.echo-file-aperturenow normalizesHostFileSnapshotmaterial at the aperture boundary so caller-forged snapshot metadata or fingerprints cannot bind a basis, observation receipt, or materialization verification to bytes different from the observed host bytes.scripts/verify-local.shstamp storage now resolves the real gitdir viagit rev-parse --git-dir, so pre-commit and pre-push hooks work in linked worktrees where.gitis a file rather than a directory. Stamps are per-worktree as a result.docs/spec/SPEC-0009-wasm-abi-v3.mdis now a historical supersession signpost to the canonical current WASM ABI specification. The former v3 export table, wire contract, migration notes, and test checklist remain in Git history rather than presenting a second active ABI authority.warp-coreWSC retained-evidence recovery now rejects conflicting duplicate retained material digests and reading ids instead of letting recovery or the recovered retention index silently overwrite evidence identity collisions.warp-coreWSC causal-history and retained-evidence recovery now rejects envelopes whose recorded basis digest does not match the canonical digest of recovered records, returning typedBasisDigestMismatchobstruction evidence instead of admitting stale or forged envelope bindings.echo-cli wal doctornow inspects a real filesystem WAL root through Echo's read-only filesystem WAL doctor instead of reporting a fresh empty in-memory store. The command accepts an optional WAL root path, defaults to the current directory, and the generated man pages cover the newwalsubcommand.warp-corewitnessed-submission persistence snapshots now fail closed when a submission lacks retained canonical envelope material instead of silently dropping replayed submissions from the host-persistable image.- Local pre-push verification now includes the changed-file fingerprint in its
cache key, skips nested integration-test helper modules instead of inventing
fake
--test modtargets, and only emits<module>::testsfilters for source files that declare a realmod tests. The hook also preserves thedelta_validateandtrusted_runtimefeature gates required by the correspondingwarp-coreintegration tests. warp-mathis now explicitly covered by determinism classification plus the default global-state and nondeterminism guard scans, whilewarp-core/serdeforwards the re-exported math serde feature.SchedulerCoordinator::super_tick(...)now journals ticket-local receipt correlation writes instead of checkpointing whole historical correlation indexes, preserving failure-atomic rollback while keeping rollback bookkeeping proportional to the attempted tick's writes.warp-coresubmit-only intake now enforces the same canonicalIngressEnvelopecontent-address invariant as runtime inbox ingestion, sowould_accept(...)cannot approve malformed ingress ids.warp-coreticketed runtime ingress now rejects duplicate pending or already committed runtime ingress before recording ticketed correlation material, so an admission ticket cannot retroactively claim legacy direct inbox work.Determinism Guardsno longer runsapt-get install ripgrep; static guard scripts now fall back to Perl regex scanning whenrgis unavailable, so mirror stalls cannot hang the determinism gate.- Stack Witness 0001 fixture observations now require the fixture
createBufferandreplaceRange("hello")history to be admitted and materialized beforetextWindowcan returnQueryBytes("hello"). - Stack Witness 0001
textWindowobservations now fail closed when the bounded read budget is smaller than the returned payload and carry a deterministic BLAKE3 artifact hash instead of a dummy reading identity. - Strengthened Echo's Wesley fixture-vector drift lock to cover artifact family, schema, version, declared footprints, and generated helper field shapes.
- Corrected Stack Witness 0001 terminology so the current semicolon-kv byte strings are fixture vars only, not Wesley's future runtime codec bytes.
- Hardened Stack Witness 0001 fixture integrity by validating fixture vars
before admission, requiring fixture intents to commit before
textWindowmaterializes, and rejecting fixtureQueryViewreads for non-default worldlines.
- Added regression coverage that rejects trailing whitespace in the committed
echo-cli --helpgolden fixture, and cleaned the existing padded blank line. - Split generated contract artifact verification into
MetadataVerifiedandCompileTimeCertifiedpostures so weak or metadata-only host policies cannot accidentally enable the trusted footprint fast path. - Strengthened Wesley footprint certificate artifact hashes so they incorporate a generated Rust artifact manifest hash and operation argument shape instead of only the declared read/write footprint.
- Changed GraphQL SDL operation id generation to fail closed on derived id collisions instead of silently incrementing persisted ABI ids.
- Replaced generated query optic variable digests with Echo ABI's
domain-separated BLAKE3
query_vars_digest_v1(...)helper. - Made built-in observation request helpers fail closed on invalid
frame/projection pairs instead of silently falling back to
QueryBytes. - Restored the CodeRabbit archive path filter and added a hook regression guard
so frozen
docs/archive/**files stay out of automated review. - Split the large
warp-coreoptic module test body intooptic/tests.rsand added a hook guard so production optic code is no longer buried under the test suite. - Verified imported witnessed causal suffix bundle digests before admission and reject forged retained-shell identities.
- Validated exported witnessed suffix boundary witnesses against the source worldline and resolved base/target frontier range.
- Fixed Wesley-generated helper output so helper-only vars and intent error types live in a generated namespace instead of colliding with user contract types, while preserving top-level helper function re-exports, and added no-std smoke coverage for op-bearing generated helpers.
- Fixed contract-hosting docs to describe synchronous
KernelPortdispatch accurately, treatObservationRequestas the read boundary, keep artifact identity separate from trust posture, hash canonical submitted intent bytes, and require codec/hash metadata for future Continuum artifact interchange.
- The adaptive parallel-policy experiment follow-ups so benchmark/report rows
now describe the plan that actually executed, adaptive planning reuses the
runtime shard-partitioning path instead of duplicating profiling logic, stale
adaptive Criterion directories are selected deterministically, malformed
adaptive benchmark directory names now fail loudly instead of disappearing
from baked reports, conflicting truthful adaptive rows are rejected before
export, and the experimental selector seam stays out of the public
warp-corekernel surface while the benchmark-facing adaptive routing entrypoints remain concrete and deterministic.
- The docs-surface reduction follow-ups so the collision tour no longer points
at a deleted guide route, the architecture outline uses implementation-backed
deterministic wording for the scene boundary, task-DAG tooling/docs use the
new
tasks-dag-source.mdname consistently, and the backlog now tracks broader docs-validation cleanup beyond Markdown-only checks, including recursivedocs/public/**/*.htmlcoverage.
- The PR workflow hardening follow-ups so
pr-preflightskips deleted file-targeted inputs,pr-threads replycan target an explicit PR context instead of assuming the checkout repo, review-thread batch resolution reports partial progress before failure, GitHub auth-error detection avoids genericauthor-style false positives, and the workflow docs point at the trackeddocs/archive/AGENTS.mdpath.
- The Phase 8 runtime-schema/tooling follow-ups so workspace Prettier usage is
declared and lockfile-pinned, runtime schema validation now fails clearly
when
nodeis unavailable, dependency DAG generation usesdocs/archive/tasks/TASKS-DAG.mdas the default task source with UTC-stable fallback labels, and the tracked Rust Analyzer workspace target dir is repo-local and cross-platform. - Shared Phase 8 type extraction so
WorldlineIdis actually opaque likeHeadId,echo-wasm-abiforwardsstd/serdeintoecho-runtime-schemaexplicitly,echo-wasm-abi --no-default-featuresavoids a straystddependency, and positive-only scheduler/inbox schema inputs are represented explicitly asPositiveInt. - Late Phase 8 review follow-ups so contributor docs use portable workspace
links, the runtime-schema README matches the default
serdecontract, the schema audit/inventory docs reflect the typed-id migration, and dependency-DAG docs use the correct GitHub workflow wording. - Final Phase 8 review follow-ups so shared logical counters enforce their
checked-arithmetic boundary, runtime-schema validation runs through the
pinned
pnpm schema:runtime:checkentrypoint, worldline-id/schema nullability docs match the frozen 32-byte and scheduler-state contracts, and backlog follow-up tasks now requirecargo xtaskas the maintenance surface.
- Fixed the session WebSocket gateway TLS stack to use the Rustls ring
provider instead of AWS-LC, clearing the current
cargo auditandcargo-denyblockers without weakening TLS coverage. - Fixed hook timing instrumentation to cache its clock source, serialize CSV header creation, and runtime-test the sequential and parallel pre-push hooks instead of only checking them statically.
- Fixed ABI/runtime metadata surfaces so dormant heads are representable, playback cursor tick/state invariants stay encapsulated, and typed logical counter helpers have direct boundary coverage.
- Fixed the browser adapter to reuse the canonical committed-tick helper and preserve large logical tick values end-to-end instead of clamping them.
- Fixed final PR review follow-ups so browser-only large-tick DTOs no
longer hand-edit generated protocol artifacts, forked provenance retains
checkpoint state at the copied tip,
verify-localrecords failing lane timings even when helpersexit, and the session gateway tolerates an already-installed Rustls crypto provider. - Fixed final replay/tooling follow-ups so checkpoints are validated before
storage, suffix replay rebuilds metadata without a second provenance scan,
hook timing reaps stale CSV locks,
pr-statuspropagates paginated parse failures, and mixed timing logs prefer current run records over legacy rows. - Fixed final Rabbit review follow-ups so checkpoint fixtures carry honest replay metadata, playback rejects non-canonical tick-zero materializations, observation/spec docs spell out deterministic U0 hashes, and verifier timing appends stay serialized without hiding helper failures.
- Changed playback, replay, snapshot, and fork materialization now rebuild
full
WorldlineStateinstead of a warp-local store-only approximation. - Added checkpoint-backed playback and provenance replay so historical materialization can restore from validated full-state checkpoints as an acceleration path before replaying the remaining suffix from authoritative provenance.
- Changed replay, observation, and ABI metadata now carry typed
WorldlineTick/GlobalTickcoordinates consistently across the public Phase 7 boundary.
- Changed local verification success stamps now key off the actual checked
tree instead of
HEAD, so commit-only churn can reuse the same clean proof across manual and hook-triggered runs without ignoring unstaged or untracked changes. - Added per-lane and per-run timing records under
.git/verify-local/timing.jsonl, keeping local timing artifacts off the tracked repo while making verifier cost visible. - Added
scripts/pr-status.shplusmake pr-statusas a one-shot GitHub summary for PR number, head SHA, unresolved thread count, review decision, merge state, and grouped checks. - Fixed
cargo nextesttargeted verification now respects crate target shape instead of hardcoding--lib --tests, which keeps bin-only crates from tripping the local fast path. - Changed the full local tooling lane now runs all hook regression scripts
under
tests/hooks/test_*.shinstead of one hardcoded verifier test.
- Changed the local full verifier now runs as curated parallel lanes with
isolated
CARGO_TARGET_DIRs for clippy, tests, rustdoc, and guard checks, which cuts local wall-clock time by avoiding one giant serialized cargo invocation. - Changed staged and reduced local Rust checks now use a narrower fast-path target surface, keeping the heaviest all-target clippy drag in CI instead of every local iteration loop.
- Changed full local verification is now scope-aware: tooling-only full changes stay tooling-local, while critical Rust changes run local smoke lanes and defer exhaustive proof to CI.
- Changed local
warp-coresmoke selection is now file-family aware: default source edits stay on--lib, runtime/inbox files pullinbox, playback files pull playback-smoke tests, and PRNG edits pull the golden regression. - Changed local
warp-wasmandecho-wasm-abismoke selection is now file-family aware too:warp-wasm/src/lib.rsstays on plain lib smoke,warp_kernel.rspulls the engine-enabled lane, canonical ABI work pulls only canonical/floating-point vectors, and non-Rust crate docs no longer wake Rust lanes at all. - Added
make verify-ultra-fastas the shortest local edit-loop lane: changed Rust crates getcargo check, critical runtime surfaces still pull targeted smoke tests, tooling-only changes stay on a syntax/smoke path, and clippy/rustdoc/guard scans stay on heavier local paths and CI. - Added
make verify-full-sequentialas an explicit fallback when the lane runner itself needs debugging. - Fixed ultra-fast tooling smoke now detects actual shell tooling files by
extension or shebang, so extensionless hook entrypoints stay covered while
non-shell files like hook docs or timing logs do not false-fail under
bash -n.
- Added ADR-0011 documenting the explicit observation contract with worldline, coordinate, frame, and projection semantics.
- Changed Phase 4 provenance/BTR work is now the documented substrate
baseline: provenance is entry-based, parent refs are stored explicitly, and
the standalone
ProvenanceServiceowns authoritative worldline history. - Added
ObservationService::observe(...)as the canonical internal read path with explicit worldline, coordinate, frame, and projection semantics. - Added deterministic observation artifacts and error mapping:
INVALID_WORLDLINE,INVALID_TICK,UNSUPPORTED_FRAME_PROJECTION,UNSUPPORTED_QUERY, andOBSERVATION_UNAVAILABLE. - Changed
WarpKerneland the WASM ABI now exposeobserve(...), whileget_head,snapshot_at, anddrain_view_opsare thin one-phase adapters over the observation contract.execute_query(...)currently lowers through observation semantics and returns deterministicUNSUPPORTED_QUERYuntil full query support is implemented. - Changed
drain_view_ops()is now legacy adapter/debug behavior only: it reads recorded truth throughobserve(...)and tracks only adapter-local drain state instead of mutating runtime-owned materialization state. - Changed
ttd-browsermigrated to the entry-based provenance API after the Phase 4 hard cut removed the old provenance convenience methods.
- Changed during the post-Phase-5 closeout, the ADR-0008 / ADR-0009 implementation plan was updated to mark Phases 0-5 implemented and record Phase 5 as shipped.
- Changed ADR-0010 is now accepted, aligning the observational/admin split with the implemented observation contract rather than leaving it in a hypothetical state.
- Added
docs/march-16.plan.mdas the post-merge execution bridge for dev-loop hardening, Phase 6 adapter deletion, explicit tick types, and the later replay / transport horizons.
- Fixed
Engine::commit_with_state()now restores both the engine-owned runtime metadata and the borrowedWorldlineStateeven if rule execution unwinds, and duplicate admitted ingress is deduplicated byingress_idbefore command enqueue. - Fixed the canonical pre-commit hook now routes staged crate verification
through
scripts/verify-local.sh pre-commit, which uses index-scoped changed files plus an index-tree stamp instead of branch-HEADreuse. - Clarified cumulative
unpause(PlaybackMode::Paused)notes now describe the shipped deterministic all-build failure instead of mixing final behavior with the earlier debug-only guard.
- Changed
scripts/hooks/pre-commitandscripts/hooks/pre-pushnow delegate to the canonical.githooks/implementations instead of enforcing a stale parallel local policy. - Added
scripts/verify-local.shplusmake verify-fast,make verify-pr, andmake verify-fullso local verification can scale with the change set and reuse a same-HEADsuccess stamp. - Changed the canonical pre-push hook now classifies docs-only, reduced, and critical verification paths, escalating to a determinism/tooling-focused local gate only for determinism-critical, CI, hook, and build-system changes.
- Fixed manual
make verify-fullruns and the canonical pre-push full gate now share the same success stamp, so an explicit clean full pass suppresses the identical hook rerun for the sameHEAD. - Changed the curated local full test lane now runs library and integration targets only for the small non-core confidence crates, cutting doc-test-only churn while the script reports total elapsed time on completion or failure.
- Changed the main CI workflow no longer runs on
pushforfeat/**branches, leavingpull_requestas the authoritative branch-validation lane whilemainretains push-time protection. - Changed the CI
Testsgate now fans in from parallelworkspace sans warp-coreandwarp-coreshards, preserving the requiredTestsstatus while cutting PR wall-clock time spent waiting on one serialized workspace job. - Changed the
warp-coreCI shard now usescargo nextestfor the main test inventory and keepscargo test --docas a separate step so the heavy crate runs faster without dropping its doctest coverage.
- Fixed
Enginenow caches canonicalcmd/*rule order at registration time instead of rebuilding and sorting that list for every admitted ingress envelope. - Fixed
WorldlineRegistry::register(...)now preserves the restored frontier tick implied byWorldlineState.tick_historyinstead of rewinding restored worldlines to tick 0. - Fixed
WorldlineStateroot validation is now fallible and explicit: callers must supply or derive the unique root instance with a backing store, and the old fabricated fallback root is gone. - Fixed
WarpKernel::with_engine(...)now returns a typedKernelInitErrorfor non-fresh or invalid caller-supplied engine state instead of panicking through the WASM host boundary. - Clarified ADR-0008 and the Phase 3 implementation plan now describe
duplicate suppression as per-resolved-head, use full
head_keyvalues for per-head APIs, and keepWorldlineRuntimepseudocode encapsulated.
- Fixed
WorldlineRuntimeno longer exposes raw public registries that can desynchronize the default-writer / named-inbox route tables; named inbox lookup is now allocation-free on the live ingress path. - Fixed
SchedulerCoordinator::super_tick()now preflightsglobal_tick/frontier_tickoverflow before draining inboxes or mutating worldline state. - Fixed runtime ingress event materialization is now folded back into the
recorded tick patch boundary, so replaying
initial_state + tick_historymatches the committed post-state. - Fixed
WarpKernel::with_engine(...)now rejects non-fresh engines instead of silently dropping runtime history that it cannot preserve.
- Fixed duplicate worldline registration now surfaces as a typed
RuntimeError::DuplicateWorldlineat the runtime boundary instead of being silently ignored at the call site. - Fixed golden-vector and proptest determinism harnesses now pin
EngineBuilderto a single worker so hashes do not inherit ambientECHO_WORKERSor host core-count entropy. - Fixed GV-004 now pins both engines to the expected
state_root,patch_digest, andcommit_hashartifacts rather than checking only one run against constants and the second run for self-consistency. - Clarified hook/docs governance:
.githooks/installed viamake hooksis canonical,scripts/hooks/are legacy shims, ADR-0008 now states seek is observational-only, and the ADR exceptions ledger no longer uses a sentinel pseudo-entry.
- Fixed
HeadIdis now opaque with internal range bounds, so public callers cannot fabricate arbitrary head identities whileheads_for_worldline()still keeps itsBTreeMaprange-query fast path. - Fixed
WriterHeadnow derives pause state frommode, andunpause(PlaybackMode::Paused)now fails deterministically in all builds instead of only underdebug_assert!. - Fixed
PlaybackHeadRegistryandWorldlineRegistryno longer expose raw public mutable access to stored heads/frontiers; runtime code uses targeted internal inbox/frontier mutation instead. - Fixed
IngressEnvelopefields are now private andHeadInbox::ingest()enforces the canonical content hash in release builds too, closing the debug-only invariant hole. - Fixed
SchedulerCoordinator::peek_order()now derives runnable order from the head registry instead of trusting cached state, and tick counters now fail deterministically on overflow. - Fixed INV-002 now asserts exact head-key equality against the canonical expected order, not just length plus pairwise zip checks.
- Fixed the ADR implementation plan now shows private-field pseudocode for
worldline frontiers and the stronger verification matrix, including the
rustdoc warnings gate (
RUSTDOCFLAGS="-D warnings" cargo doc ... --no-deps).
- Fixed
WriterHead.keyis now private with akey()getter, preventing mutation viaPlaybackHeadRegistry::get_mut()which would break the BTreeMap key invariant. - Fixed INV-002 proptest now verifies exact key identity (sorted+deduped input vs output), catching bugs where rebuild substitutes one key for another.
- Fixed plan doc pseudocode updated to reflect private fields with getters
(
WriterHead,WorldlineFrontier) and correct constructor name (IngressEnvelope::local_intent).
- Fixed
WriterHead.modeis now private with amode()getter, preventing themode/pausedpair from diverging via direct field assignment. - Fixed
SchedulerCoordinator::super_tick()now uses canonical runnable order derived from the head registry viapeek_order()instead of trusting stale runnable-cache state. - Fixed
HeadInbox::set_policy()now revalidates pending envelopes against the new policy, evicting any that no longer pass. - Fixed
HeadInbox::admit()now usesmem::take+into_values()instead ofclone()+clear()for zero-copy admission inAcceptAll/KindFilter. - Fixed
HeadInbox::ingest()added envelope hash invariant checks; later hardening enforces the canonicalingress_id/payload-hash match in release builds as well. - Fixed
WorldlineState.warp_stateis nowpub(crate)with awarp_state()getter, andWorldlineFrontierfields arepub(crate)with public getters. - Fixed INV-002 proptest now verifies set preservation (length check) in addition to canonical ordering.
- Fixed removed
redundant_cloneclippy suppression fromhead.rsandcoordinator.rstest modules. - Fixed ADR exceptions ledger sentinel row no longer mimics an active entry.
- Fixed verification matrix in implementation plan now matches the hook-enforced gate used in that phase.
- Fixed
HeadInbox::ingest()now rejects non-matching envelopes at ingest time underKindFilterpolicy, preventing unbounded memory growth. - Fixed GV-003 golden vector now covers all 6 fork entries (ticks 0..=5), closing a gap where the fork-tick itself was never verified.
- Added INV-002 proptest for canonical head ordering (shuffled insertion
always produces canonical
(worldline_id, head_id)order). - Added duplicate-tick detection to INV-001 (append at existing tick fails).
- Fixed
heads_for_worldline()now uses BTreeMap range queries (O(log n + k) instead of O(n) full scan). - Fixed
unpause()initially added a debug-only guard forPaused; later hardening made the failure deterministic in all build configurations. - Fixed pre-commit hook now passes
--workspaceto clippy. - Improved documentation: multi-writer frontier semantics,
global_tickbehavior on empty SuperTicks,compute_ingress_idlength-prefix safety,InboxAddressas human-readable alias.
- Added
IntentKind— stable, content-addressed intent kind identifier using domain-separated BLAKE3 ("intent-kind:" || label). - Added
IngressEnvelope— unified, content-addressed ingress model with deterministic routing and idempotent deduplication. - Added
IngressTarget— routing discriminant:DefaultWriter,InboxAddress, orExactHead(control/debug only). - Added
IngressPayload— payload enum starting withLocalIntent, extensible for cross-worldline messages (Phase 10) and imports (Phase 11). - Added
HeadInbox— per-head inbox withBTreeMap-keyed pending envelopes for deterministic admission order. - Added
InboxPolicy— admission control:AcceptAll,KindFilter, orBudgeted { max_per_tick }.
- Added
SchedulerCoordinator— serial canonical scheduling loop that iterates runnable writer heads in(worldline_id, head_id)order and advances each worldline's frontier tick. - Added
WorldlineRuntime— top-level runtime struct bundling worldline registry, head registry, runnable set, and global tick. - Added
StepRecord— output record documenting which heads were stepped and in what order during a SuperTick.
- Added
HeadId,WriterHeadKey,WriterHead— first-class head types for worldline-aware scheduling. Heads are control objects (identity, mode, paused state), not private mutable stores. - Added
PlaybackHeadRegistry—BTreeMap-backed registry providing canonical(worldline_id, head_id)iteration order. - Added
RunnableWriterSet— ordered live index of non-paused writer heads. - Added
WorldlineState— broad wrapper aroundWarpStatepreventing API calcification aroundGraphStore. - Added
WorldlineFrontier— the single mutable frontier state per worldline, owningWorldlineStateandfrontier_tick. - Added
WorldlineRegistry—BTreeMap-backed registry of worldline frontiers with deterministic iteration. - Added
make_head_id()— domain-separated BLAKE3 identifier factory ("head:" || label).
- Added golden vector suite (
golden_vectors_phase0.rs) pinning commit determinism, provenance replay integrity, fork reproducibility, and idempotent ingress hashes before the worldline runtime refactor. - Added invariant test suite (
invariant_property_tests.rs) enforcing monotonic worldline ticks, idempotent ingress, cross-worldline isolation, commit determinism, and provenance immutability; INV-001/002/003/005 useproptest, while INV-004/006 are fixed regression tests. - Added ADR exceptions ledger (
docs/adr/adr-exceptions.md) — operational from Phase 0 onward, every intentional model violation must be logged with owner and expiry. - Added ADR-0010: Observational Seek, Explicit Snapshots, and Administrative Rewind — companion ADR clarifying the seek/rewind split under the one-frontier-state-per-worldline design.
- Added implementation plan for ADR-0008 and ADR-0009
(
docs/plans/adr-0008-and-0009.md) — 14-phase roadmap with verification matrix and exit criteria. - Added git hooks (
scripts/hooks/pre-commit,scripts/hooks/pre-push) for lint and test gating.
- Added ADR-0009: Inter-Worldline Communication, Frontier Transport, and Conflict Policy — formalizes message-passing-only communication between worldlines, frontier-relative patches, suffix transport as the replication primitive, four-dimensional footprint interference, explicit conflict surfacing over silent LWW, and the state-vs-history convergence separation.
- Added ADR-0008: Worldline Runtime Model — formalizes writer/reader heads, SuperTick scheduling contract, three-domain boundaries (Echo Core, App, Janus), per-head seek/jump semantics, and the 8-step normative refactor plan.
- Exported
compute_tick_commit_hash_v2,compute_op_emission_index_digest, andOpEmissionEntryfromwarp-corepublic API (previouslydead_code). - Wired
LocalProvenanceStore::append_with_writes()to actually store atom writes instead of discarding them. - Added
LocalProvenanceStore::atom_writes(w, tick)— query atom writes for a specific tick (TTD "Show Me Why" provenance). - Added
LocalProvenanceStore::atom_history(w, atom)— causal cone walk usingout_slots(Paper IIIOut(μ)) to filter ticks that wrote to the atom, with early termination at creation. O(history) scan, no reverse index. - Fixed
LocalProvenanceStore::fork()to copyatom_writesalongside patches, expected hashes, and outputs. - Added 12 tests covering atom write storage, queries, filtering, fork,
causal-cone walk, skip behavior, early termination, within-tick ordering,
and
SlotId::Node(atom)provenance path.
- Added
digest_golden_vectors.rs— DIND-level golden-hash tests that exercisecompute_emissions_digest,compute_op_emission_index_digest, andcompute_tick_commit_hash_v2through warp-core's crate-root re-exports. - Pinned 3 golden vectors: individual emission/op-emission-index digests plus a full hash chain (emissions → op-index → tick-commit). Any wire format drift in the public digest surface is now caught outside module-local tests.
- Fixed
atom_history()within-tick write ordering: the backward tick walk collected per-tick writes in forward order, so the finalreverse()flipped within-tick execution sequence. Iteratetick_writes.iter().rev()so the global reverse restores original order. - Fixed creation truncation: if a single tick had
[create, mutate]for the same atom, forward iteration hitis_create()first and returned early, losing the subsequent mutation. - Updated
fork()rustdoc to mentionatom_writesin the copied fields. - Documented
append_with_writes()invariant: atom writes must reference atoms declared inpatch.out_slotsforatom_history()visibility.
- Fixed
scripts/ban-globals.sh: the\bthread_local!\band\blazy_static!\bpatterns never matched because!is not a word character in ripgrep regex, making the trailing\bimpossible. Use escaped\!without trailing\b. - Added
.ban-globals-allowlistto exemptwarp-wasm/src/lib.rs(WASM boundary legitimately needs module-scopedthread_local+install_kernel).
- Fixed
init()now returns real 32-bytestate_rootandcommit_idhashes from the freshly constructed kernel instead of empty vecs. - Fixed
WarpKernel::with_engine()auto-registerssys/ack_pendingif absent, silently ignoring duplicates. PreventsENGINE_ERRORon first dispatched intent when callers forget to register it. - Removed unnecessary
#[allow(dead_code)]on publicWarpKernel::with_engine()method. - Removed redundant explicit type annotation on
get_registry_info(). - Fixed broken
RegistryInforustdoc link after import removal.
- Fixed
warp-core: cfg-gate footprint enforcement internals (FootprintGuard,OpTargets,op_write_targets, etc.) so they compile out cleanly underunsafe_graphwithout dead-code warnings. - Fixed
warp-core: add#[allow(unused_mut)]on cfg-conditional mutation inengine_impl.rs. - Fixed
echo-wasm-bindings: restructureTtdControllerWASM bindings to use per-methodwasm_bindgenwithJsValue/JsErrorwrappers instead of blanketwasm_bindgenon the impl block (fixes trait bound errors under--all-features). - Fixed
echo-scene-codec: add clippy allow attributes to test module forexpect_used,unwrap_used, andfloat_cmp. - Fixed
warp-coretests: move enforcement-only imports into cfg-gatedmod enforcementinparallel_footprints.rs.
- Fixed
dispatch_intentnow validates the EINT envelope before passing bytes to the engine, returningINVALID_INTENT(code 2) for malformed envelopes instead of forwarding garbage. - Added
Displayimpl forEnvelopeError(no_std compatible). - Changed
OkEnvelopeandErrEnvelopefields to private with::new()constructors, enforcing correctokfield values at compile time. - Added default implementations for
KernelPort::execute_queryandKernelPort::render_snapshotreturningNOT_SUPPORTED, making future trait evolution non-breaking. - Updated SPEC-0009 error code 2 description and versioning notes.
- Added
KernelPorttrait toecho-wasm-abi— app-agnostic byte-level boundary contract for WASM host adapters. Includes ABI response DTOs (DispatchResponse,StepResponse,HeadInfo,DrainResponse,RegistryInfo), error codes, and CBOR wire envelope types. - Added
WarpKerneltowarp-wasm(behindenginefeature) — wrapswarp-core::EngineimplementingKernelPort. Registerssys/ack_pendingsystem rule, provides deterministic tick execution. - Replaced all placeholder WASM exports with real implementations:
dispatch_intent,step,drain_view_ops,get_head,snapshot_at,get_registry_info, and handshake metadata getters now return live data. - Added
init()export for kernel initialization; calling exports before init returns structured error (no panics). - Added CBOR success/error envelope protocol (
{ ok: true/false, ... }) for allUint8Arrayreturns. - Added
install_kernel()public API for app-agnostic kernel injection. - Added SPEC-0009 documenting ABI v1 contract, wire encoding, error codes, versioning strategy, and migration notes.
- Added 14 conformance tests covering dispatch, step, drain, snapshot, determinism, error paths, and handshake metadata.
execute_queryandrender_snapshothonestly reportNOT_SUPPORTED(error code 5) until the engine query dispatcher lands.
- Renamed
warp_core::boawmodule towarp_core::parallel— all import paths, re-exports, and doc comments updated. - Renamed 14
boaw_*integration test files toparallel_*, updated test harness types (BoawScenario→ParallelScenario,BoawTestHarness→ParallelTestHarness, etc.) and string literals. - Renamed
boaw_baselinebenchmark toparallel_baseline, updatedwarp-benches/Cargo.tomltarget. - Annotated 5 ADR files with deprecation notice (filenames preserved as historical records).
- Updated book/LaTeX sections, specs, guides, and source comments to
replace BOAW references with
parallel. - Replaced "Echo/JITOS" → "Echo" in
echo-wasm-bindings,echo-wasm-abi, andspec-000-rewritecrate metadata and READMEs. - Replaced "JITOS Engineering Standard" → "Echo Engineering Standard" in
METHODOLOGY.md. - Replaced "Echo / Continuum" → "Echo" in ADR-0007.
- Archived 6 entire directories to
docs/archive/:notes/,plans/,tasks/,rfc/,memorials/,jitos/(session artifacts, completed work). - Archived
docs/study/(51 files: LaTeX papers, build artifacts, tour materials) todocs/archive/study/. - Archived 4 completed DIND mission docs from
docs/determinism/and the supersededECHO_ROADMAP.mdfromdocs/ROADMAP/. - Archived 18 stale loose docs from
docs/root:AGENTS.md,ISSUES_MATRIX.md,code-map.md,phase1-plan.md,roadmap-mwmr-mini-epic.md,branch-merge-playbook.md,testing-and-replay-plan.md,runtime-diagnostics-plan.md,telemetry-graph-replay.md,warp-demo-roadmap.md,warp-runtime-architecture.md,capability-ownership-matrix.md,ROLLBACK_TTD.md,aion-papers-bridge.md,rust-rhai-ts-division.md,hash-graph.md,two-lane-abi.md,diagrams.md. - Archived dead redirect
guide/collision-tour.md(both targets missing). - Rewrote
docs/meta/docs-index.md: curated golden-path index with clear separation of implemented specs, vision specs (unimplemented), ADRs, and archive. Removed broken links and stale entries.
- Fixed
CONTRIBUTING.md: Rust version 1.71.1 → 1.90.0,AGENTS.mdpath todocs/AGENTS.md,reference/typescript/→packages/andapps/, commit message guidance aligned with conventional commits. - Fixed
.devcontainer/post-create.sh: reads toolchain version fromrust-toolchain.tomlinstead of hardcoding 1.71.1, removed stalermg-corecrate reference. - Fixed
warp-wasm/README.md: corrected dependency claim fromwarp-coretoecho-wasm-abi+echo-registry-api. - Fixed
echo-session-proto/README.md: removed brokendocs/tex/paths, pointed todocs/js-cbor-mapping.mdand book sections instead. - Fixed
ttd-browser/README.md: removed brokendocs/plans/ttd-app.mdreference and nonexistentttd-controllercrate mention. - Fixed
NOTICE: copyright year 2025 → 2025–2026, SPDX identifier aligned toLicenseRef-MIND-UCAL-1.0. - Fixed ROADMAP priority mismatch: 5 milestone READMEs aligned from P2 → P3 to match the parent index. Proof Core status downgraded from "Verified" to "In Progress" (Docs Polish feature still incomplete).
- Fixed
guide/cargo-features.md: removed nonexistentspec-000-rewritecrate section. - Fixed
guide/course/glossary.md: correctedViolationKindvariantAdjacencyViolation→OpWarpUnknownwith full variant names. - Fixed
BENCHMARK_GUIDE.md: updated "CI Integration (Future)" section to reflect existing G3 perf gate. - Fixed
echo-session-clientandecho-session-serviceCargo.toml descriptions: removed stale "(skeleton)" qualifier.
- Fixed
scripts/check_task_lists.sh: accept file arguments for testability; fall back to built-inFILESarray when none are given. - Fixed
scripts/tests/check_task_lists_test.sh: updated tests to pass file arguments to the checker and match current output messages. Tests were broken after theFILESarray was emptied when task lists were archived.
- Removed stale root-level ADR duplicates (
ADR-0003throughADR-0006); canonical copies already exist indocs/adr/. - Removed completed one-shot plan
MERGE_TTD_BRANCH_PLAN.md. - Moved determinism docs (
DETERMINISM-AUDIT.md,DIND-MISSION*.md) todocs/determinism/. - Moved task trackers (
TASKS.md,TASKS-DAG.md,WASM-TASKS.md) todocs/tasks/. - Moved
ECHO_ROADMAP.mdtodocs/ROADMAP/,COMING_SOON.mdtodocs/plans/,AGENTS.mdtodocs/. - Deleted untracked junk files (
paper-7eee.log,dind-report.json,.DS_Store). - Archived 14 superseded/completed docs: redirect stubs removed,
canonical content already in
docs/archive/. Updated cross-references indocs-index.md,code-map.md,DETERMINISTIC_MATH.md, andwarp-geom/README.md. - Added
docs/archive/README.mddefining archive policy.
- CI: G3 perf regression gate now compares criterion benchmark output
against a git-tracked
perf-baseline.jsonand fails if any benchmark regresses beyond 15% (configurable via--threshold). Structuredperf-report.jsonartifact uploaded alongside rawperf.log. - CI: New
perf-baseline-update.ymlworkflow auto-generates baseline update PRs on main pushes that touch Rust sources. - Scripts: Added
check_perf_regression.cjs(gate comparison) andgenerate_perf_baseline.cjs(baseline generation from bencher output).
- Policy: Added "Determinism Allowlist Governance" section to
docs/RELEASE_POLICY.mddocumenting acceptable exemption criteria, approval requirements, and audit cadence for.ban-nondeterminism-allowlist. - Scripts: Added cross-reference from
ban-nondeterminism.shheader to the governance policy.
-
License: Renamed SPDX identifier
MIND-UCAL-1.0→LicenseRef-MIND-UCAL-1.0across 328 files to comply with SPDX Appendix IV (custom identifiers must useLicenseRef-prefix). Updatedensure_spdx.shtooling and pre-commit hook accordingly. -
Fix: Fixed radix sort scope pair index inversion in
scheduler.rsbucket16(). LSD passes were processing scope bytes MSB-first instead of LSB-first, causing the radix-sort path (n > 1024) to produce a different ordering than the comparison-sort path (n ≤ 1024). Added 3 property tests:proptest_drain_matches_btreemap_reference(fuzzes both sort paths),proptest_insertion_order_independence, andthreshold_boundary_determinism. -
Spec: Replaced "Theorem A" in
spec-mwmr-concurrency.mdwith the formal name from Paper II: "Skeleton-plane Tick Confluence theorem (§6, Thm. 6.1)". -
Spec: Changed
<i>Alea iacta est</i>to semantic HTML inmemorials/2026-01-18-phase4-rubicon.md(foreign phrase italics). -
Spec: Resolved 4 CRITICAL CodeRabbit items: normative frame ordering rule in
spec-editor-and-inspector.md(stable sort by(tick, frameType), UTF-8 lexicographic, insertion-order tie-break); addedgetNode()toBridgeContextinspec-temporal-bridge.mdwithNodeIddisambiguation note (timeline hash vs WARP graphu64); definedworld:configcapability inspec-capabilities-and-security.mdand removed "not yet defined" warning fromspec-runtime-config.md; verifiedSweepProxyrename inspec-knots-in-time.md. Also changedproducerreturn type fromobjecttounknowninspec-editor-and-inspector.md. -
Spec: Rewrote
spec-branch-tree.mdto resolve all 10 CodeRabbit review items. Key changes: formalReadKey/WriteKey/QualifiedKeytype definitions with ECS-layer layering rationale;MergeStrategyIdas extensible namespaced string registry; extractedTimelineNodeCorehashable subset and replaced broken hash formula; unifiedparents[]replacingparentId + mergeParents?; renamed entropy heuristic to "branch strain" (distinguished from Aion Boltzmann entropy); definedWorldView,GCPolicy, three explicit GC modes with transitive pin semantics, domain-separated seed derivation, layered causal-edge semantics,CapabilityAssertionwith forward reference to capabilities spec, andStabilityObserverlifecycle. -
Polish: Resolved remaining 13 Tier 2 CodeRabbit items (all 66 complete): session token format (HMAC-SHA256) and filter semantics in
spec-editor-and-inspector.md; signing canonicalization subsection with 8-field byte layout inspec-warp-confluence.md; breaking-change criteria and deprecation timeline inspec-world-api.md;BlockManifestsection encoding inspec-serialization-protocol.md; radix sort internals documentation inscheduler-optimization-followups.md; enum style unification in SPEC-0002;cargo metadataprovenance command incargo-features.md; expanded serde acceptance criteria inissue-canonical-f32.md. -
Polish: Resolved 12 Tier 1 CodeRabbit items:
remain disjoint→are non-conflictingin SPEC-0003, tightened subnormal definition inDETERMINISTIC_MATH.md, added Aion inline definition inbranch-merge-playbook.md, converted numbered narrative to bullets inspec-time-streams-and-wormholes.md, verified 3 already-correct items (serialization link, admission MUST language, musings blank line), dismissed 3 prettier-enforced formatting items. -
Spec: Resolved all 3 TODO comments in
spec-scheduler.md: bidirectional dependency resolution rules, cleanerregisterSystempseudo-code, and a formal resource conflict detection model aligned with warp-core'sFootprint. ReplacedComponentSignaturewithSystemFootprint(reads/writes/exclusiveTags). -
Review: Addressed 69 CodeRabbit review comments across 37 files:
- xtask: Cross-platform
command_exists, annotated UTF-8 errors, warned on non-UTF-8 path drops, simplifiedhas_extension, fixed doc comment. - Specs: Hardened 15 spec docs — added error handling for branch-tree
commit conflicts, defined equality predicates, bounded parent counts in
merkle-commit, specified canonical field ordering, fixed broken cross-refs
and link styles, added validation rules and error codes to runtime-config,
unified
BranchId/KairosBranchId, clarified signing payloads. - Notes/Archive: Corrected O(n log n) cost attribution in scheduler notes, fixed stale code references and branch names, expanded commit hashes, added provenance blocks.
- Docs: Fixed ADR-0004 placeholder, normalized titles, corrected dependency direction in ISSUES_MATRIX, fixed emphasis style, consolidated repetitive bullets, added cargo-features provenance note, fixed heading levels in warp-math-claims, fixed workflow artifacts in mat-bus-finish RFC.
- xtask: Cross-platform
-
Archive: Moved 6 superseded docs to
docs/archive/with redirect stubs (spec-deterministic-math.md,spec-geom-collision.md,notes/scheduler-radix-optimization.md,notes/xtask-wizard.md,plans/cross-warp-parallelism.md,plans/BOAW-tech-debt.md). -
Consolidate: Added "Docs Map" callouts to
SPEC_DETERMINISTIC_MATH.mdandDETERMINISTIC_MATH.mdlinking all 5 docs in the deterministic math cluster. Updatedscheduler.mdQuick Map with status labels. -
Fix: Repaired 13 broken cross-references (
docs/specs/->docs/spec/,memorial.md->memorials/...,streams-inspector-frame.md->streams-inspector.md,docs/spec/SPEC-0004...prefix, archived file image paths, nonexistent README link). -
New:
cargo xtask lint-dead-refs— scansdocs/for broken markdown cross-references. Handles relative paths, root-relative docs links, anddocs/public/asset resolution. Use--allto also check non-markdown file references (images, HTML). -
New:
cargo xtask markdown-fix— auto-fixes common markdown lint violations: SPDX header repair, prettier formatting, and markdownlint--fix. Supports--no-prettierand--no-lintflags. -
New:
cargo xtask docs-lint— combined pipeline that runsmarkdown-fixfollowed bylint-dead-refs. Single command for full docs hygiene. -
New: Configuration reference (
docs/guide/configuration-reference.md) covering engine parameters, protocol constants, and environment variables. -
New: Cargo feature flags reference (
docs/guide/cargo-features.md) covering all 19 features across 11 crates. -
Fix:
cargo xtask lint-dead-refsnow usespulldown-cmarkfor link extraction (handles title text, balanced parens, angle-bracket URLs) and separates scan scope from the docs root. Includes 10 unit tests. -
Fix:
det_fixedcorrectly documented as a behavioral switch incargo-features.md;worker_countdefault now showsNUM_SHARDScap. -
Fix: All file collection in xtask now uses
git ls-filesinstead of filesystem walks so ignored build artifacts stay out of docs scans. -
Update: Archival stubs enriched with date, reason, and PR metadata. Draft spec (
spec-scheduler.md) marked with[!CAUTION]disclaimer and TODO markers for unspecified sections. -
Update: Math code fences converted from
texttomathwith proper LaTeX markup acrossTHEORY.md,SPEC-0001, and scheduler notes. -
Fix: Archived
cross-warp-parallelism.mdannotated with implementation traceability andWorkUnitstruct deviation (noshard_idin actual code). -
Fix: Archived
BOAW-tech-debt.mdchecklists annotated as frozen with tracking-moved callout pointing toTECH-DEBT-BOAW.md. -
Fix: Archived
scheduler-radix-optimization.mdcanonical order clarified and code-reference staleness disclaimer made visible. -
New:
.coderabbit.yaml— excludesdocs/archive/**from CodeRabbit reviews (frozen historical records generate low-value feedback). -
Update: README determinism claims link, reference docs section, docs-index entries, docs-audit log.
- Determinism Claims v0.1: New
docs/determinism/DETERMINISM_CLAIMS_v0.1.mddocumenting five determinism claims (DET-001 through DET-005) covering static inspection, float parity, parallel execution, trig oracle golden vectors, and torture-rerun reproducibility. - Trig Golden Vectors (DET-004): New test
crates/warp-core/tests/trig_golden_vectors.rswith a 2048-sample golden binary (testdata/trig_golden_2048.bin) that locks downdfix64sin/cos/tan outputs across platforms. Runs on Linux and macOS in CI. - Torture Rerun Script (DET-005):
scripts/torture-100-reruns.sh— turnkey repro script that runs 100 sequential simulations and asserts identical hashes. - CI Trig Oracle Gate: Added trig golden vector tests to
.github/workflows/det-gates.ymlfor both Linux and macOS runners, with log artifacts uploaded alongside existing determinism artifacts. - CLAIM_MAP.yaml: Added DET-004 and DET-005 entries with required evidence pointers and owner roles.
- Evidence Generator: Wired DET-004 and DET-005 into
scripts/generate_evidence.cjsso the evidence policy cross-check passes. - Ban-Nondeterminism Allowlist: Added
trig_golden_vectors.rsto.ban-nondeterminism-allowlist(test-onlystd::fsfor reading golden vector binaries).
- Updated
docs/ROADMAP/proof-core/README.md: checked off P1 exit criteria, marked milestone as "In Progress". - Resequenced roadmap phases: P0 verified, P1→P2→P3 ordering clarified.
- Bench Recursive Scanning:
collect_criterion_resultsnow walks directories recursively, correctly finding grouped (benchmark_group) and parameterised (BenchmarkId) benchmarks that Criterion stores in nested directories (e.g.group/bench/new/estimates.json). - Bench Regex Filter: Post-filter now uses
regex::Regexto match Criterion's own regex semantics instead of substringcontains. Filters with anchors or metacharacters (e.g.^hotpath$) now work correctly.
- Stale
warp-ffiReferences: Removed deleted crate from git hooks (pre-push-parallel,pre-push-sequential),warp-core/README.md, andAGENTS.md. Only historical references in CHANGELOG and TASKS-DAG remain. - Broken Spec Paths: Fixed
docs/specs/→docs/spec/in two acceptance criteria indocs/ROADMAP/backlog/security.md. emit()Error Propagation: Changedoutput::emit()to returnResult<()>instead of silently printing to stderr on serialization failure. All call sites (bench.rs,verify.rs,inspect.rs) now propagate with?.- SPEC-0005 Clarity: Bound loop index variable in BTR verification algorithm
(H-3); documented missing-producer behavior in
derive()(H-4); clarified multi-producer vs. most-recent-producer semantics betweenbuild_provenance_graph()andderive()(M-4); addedcanonical_state_hash()cross-reference (M-5); specified composition error semantics (M-6); added set semantics forOut(μ)/In(μ)(M-8); expandedProvenanceNodeconstructor in pseudocode (L-10); documented empty derivation graph semantics (L-11); formalized identity composition (L-12); definedH(P)notation in example (L-13); added Paper III citation (L-14). format_duration()Infinity: Addedis_infinite()check alongsideis_nan()sof64::INFINITYreturns "N/A" instead of formatting as seconds.- Safe
edge_ixCast: Replacedas usizewithusize::try_from()ininspect.rstree builder to guard against truncation on 32-bit targets. - Bench Test Ordering: Added positional assertion ensuring
--precedes the filter pattern inbuild_bench_command. - Bench Empty Warning: Added stderr warning when no benchmark results found.
- WSC Loader Warnings: Warning messages now include entity IDs (first 4 bytes hex) for easier debugging.
- Inspect Docstring: Changed "Prints" to "Displays" in module docstring.
TREE_MAX_DEPTHDoc: Added doc comment explaining the depth limit's purpose.- Fragile
len() - 1: Changedi == node.children.len() - 1toi + 1 == node.children.len()to avoid underflow on empty children (though the loop guards against this, the pattern is safer).
- Bench Filter:
echo-cli bench --filter <pattern>now passes the filter as a Criterion regex (-- <pattern>) instead of a--benchcargo target selector. Previous behavior would look for a bench target named after the pattern rather than filtering benchmarks by regex. - Verify Expected Hash:
--expectednow correctly reports "unchecked" for warps 1+ instead of silently claiming "pass". Emits a stderr warning when--expectedis used with multi-warp snapshots. Text and JSON output now use consistent lowercase status values. - Unused Dependency: Removed
colored = "2"fromwarp-cli(declared but never imported). - Output Hardening:
emit()no longer panics on JSON serialization failure; falls back to stderr. Bench exit status now reports Unix signal numbers instead of a misleading-1. - Error Handling:
collect_criterion_resultsnow logs a warning on unparseableestimates.jsoninstead of silently skipping.format_durationreturns "N/A" for NaN/negative values.att_row_to_valuewarns on missing blob data instead of silent fallback. - Dead Code: Replaced blanket
#![allow(dead_code)]onlib.rswith targeted#[allow(dead_code)]on theoutputmodule only. - Man Page Headers: Subcommand man pages now use prefixed names
(
echo-cli-bench,echo-cli-verify,echo-cli-inspect) in.THheaders instead of bare subcommand names. - Visibility: Narrowed all non-API structs and functions from
pubtopub(crate)in bench, verify, inspect, and wsc_loader modules. Onlycli.rstypes remainpub(required by xtask man page generation). - cargo-deny: Fixed wildcard dependency error for
warp-cliinxtask/Cargo.tomlby adding explicitversion = "0.1.0"alongside the path override. - Man Page Cleanup:
cargo xtask man-pagesnow removes staleecho-cli*.1files before regeneration so the output directory is an exact snapshot.
- Inspect Tree Warp Identity: Multi-warp snapshots now label each tree
section with its warp index (
Tree (warp 0):,Tree (warp 1):) instead of flattening all trees into a single unlabeledTree:section. - WSC Loader Attachment Checks: Replaced
debug_assert!with runtime warnings for attachment multiplicity violations. Previously, release builds silently dropped extra attachments; now emits a warning to stderr. - Test Naming: Renamed
tampered_wsc_failstotampered_wsc_does_not_panicto accurately reflect the test's behavior (no assertion, just no-panic guard). - Test Coverage: Added
roundtrip_with_edge_attachmentsandroundtrip_with_descend_attachmenttests towsc_loader.rs, covering previously untested code paths. - SPEC-0005
global_tickInvariant: Reworded frompatches[i].global_tick == ito correctly state contiguity relative to the payload's start tick, since payloads can begin at any absolute tick viafrom_store(store, wl, 5..10). - SPEC-0005 BTR Verification: Fixed step 5 of the verification algorithm
to reference the actual hash formula from §5.4 instead of a nonexistent
parentsfield. - SPEC-0005 Derivation Algorithm: Fixed backward-cone traversal that dropped
transitive dependencies. The original filter checked the root query slot at
every hop; now accepts all frontier nodes unconditionally (they are already
known-causal) and traces all
in_slotsbackward. - Stale
warp-ffiReferences: Removed deadwarp-ffientry fromdet-policy.yaml, C ABI text fromphase1-plan.md, and stale CLI names fromrust-rhai-ts-division.md.
- TASKS-DAG Spec Path:
SPEC-PROVENANCE-PAYLOAD.md→SPEC-0005-provenance-payload.mdin sub-task title and AC1 (two occurrences). Same stale path fixed in ROADMAP backlogsecurity.md. - SPEC-0005 Byte Counts: Domain separation tag sizes corrected:
echo:provenance_payload:v1\0= 27 bytes (was 28),echo:provenance_edge:v1\0= 24 bytes (was 25). - Project Tour: Updated
warp-clidescription from "Placeholder CLI home" to list actual subcommands (verify, bench, inspect). - CI Formatting: Removed stray blank line between warp-geom and warp-wasm
rustdoc steps in
ci.yml.
- CLI Scaffold (
warp-cli): Replaced placeholder with fullclap4 derive subcommand dispatch. Three subcommands:verify,bench,inspect. Global--format text|jsonflag for machine-readable output. - Verify Subcommand:
echo-cli verify <snapshot.wsc>loads a WSC snapshot, validates structural integrity viavalidate_wsc, reconstructs the in-memoryGraphStorefrom columnar data, and computes the state root hash. Optional--expected <hex>flag compares against a known hash. - WSC Loader: New
wsc_loadermodule bridges WSC columnar format toGraphStore— the inverse ofwarp_core::wsc::build_one_warp_input. Reconstructs nodes, edges, and attachments fromWarpView. - Bench Subcommand:
echo-cli bench [--filter <pattern>]shells out tocargo bench -p warp-benches, parses Criterion JSON fromtarget/criterion/*/new/estimates.json, and renders an ASCII table viacomfy-table. Supports--format jsonfor CI integration. - Inspect Subcommand:
echo-cli inspect <snapshot.wsc> [--tree]displays WSC metadata (tick, schema hash, warp count), graph statistics (node/edge counts, type breakdown, connected components via BFS), and optional ASCII tree rendering depth-limited to 5 levels. - Man Pages: Added
clap_mangen-based man page generation toxtask.cargo xtask man-pagesgeneratesdocs/man/echo-cli.1,echo-cli-verify.1,echo-cli-bench.1,echo-cli-inspect.1.
- SPEC-0005: Published
docs/spec/SPEC-0005-provenance-payload.mdmapping Paper III (AION Foundations) formalism to concrete Echo types. Defines four new types (ProvenancePayload,BoundaryTransitionRecord,ProvenanceNode,DerivationGraph), wire format with CBOR encoding and domain separation tags, two worked examples (3-tick accumulator, branching fork), bridge to existingProvenanceStore/PlaybackCursorAPIs, and attestation envelope with SLSA alignment.
- Evidence Derivation: Replaced artifact-directory-presence check for
DET-001with structured parsing and validation ofstatic-inspection.json;FAILEDstatic inspections now correctly yieldUNVERIFIEDevidence instead of relying solely on artifact existence. Addssource_file,source_status, and optionalerrorfields to DET-001 evidence. - Evidence Script Hardening: Added TypeError guard on
generateEvidenceinput, try/catch withprocess.exit(1)in CLI mode, truncated log interpolations to 200 chars incheckStaticInspection, harmonized parameter naming, and tightened JSDoc return types to'VERIFIED'|'UNVERIFIED'union.
- Docs Build: Rewrote
ADR-0007-impl.mdfrom a 3185-line raw conversation transcript into a proper 13-section ADR document. The Vue template compiler was crashing on bare Rust generics (BTreeMap<NodeId, NodeRecord>, etc.) outside fenced code blocks. The new document preserves all architectural knowledge as a structured implementation companion to ADR-0007. - Stale Hash Domain: Updated three stale
DIND_STATE_HASH_V2references ingraph.rsdoc comment andADR-0007-impl.md§2.1/§7 to match the actual domain prefixecho:state_root:v1defined indomain.rs. Renamed the adjacentV2 Changessubsection toLayout Notesto remove versioning ambiguity. - Module Count: Fixed off-by-one module count in
ADR-0007-impl.mdmetadata and §1 prose (36 → 37) and added qualifier noting tables cover key modules only. - Stale Design Doc: Deleted
docs/WARP-GRAPH.md(1,219-line chat transcript fully superseded byADR-0007-impl.mdandcrates/warp-core/src/wsc/). Extracted all-zero-key caveat into ADR §9.6 andsave_wsc()convenience wrapper gap intoTASKS-DAG.mdbacklog before removal.
- CI Security: Hardened
det-gatesworkflow against script injection by using environment variables for allgithub.*interpolations (branch refs, SHA, run ID, event name). - WASM Reproducibility: Implemented bit-exact reproducibility checks (G4)
for
ttd-browserWASM using hash comparison of clean isolated rebuilds. - Static Inspection: Added automated CI guard for
DET-001covering all 14 DET_CRITICAL crate paths (expanded fromecho-wasm-abionly). Report now conditional on check outcome (PASSED/FAILED). - Evidence Validation: Made artifact presence checks in
validate-evidenceconditional on classification tier; addeddet-macos-artifactscheck;run_reducedandDET_NONCRITICALpaths no longer hard-fail. - Policy Classification: Promoted
warp-benchesfrom DET_NONCRITICAL to DET_IMPORTANT so benchmark crate changes trigger reduced gates. - Benchmark Correctness: Replaced
let _ =with.unwrap()on allbus.emit()calls; migratediter_with_setuptoiter_batched. - CBOR Robustness: Expanded negative security tests for
ProjectionKindandLabelAnchorenum tags and optimizedMAX_OPSboundary check. - Evidence Integrity: Enhanced
generate_evidence.cjsandvalidate_claims.cjswith stricter semantic validation (SHAs, run IDs) and artifact existence checks. - Script Quality: Replaced
process.exit(1)withthrowinclassify_changes.cjs; removed dead import; exported functions for testing. - Governance: Moved
sec-claim-map.jsontodocs/determinism/, formalized gate states inRELEASE_POLICY.md, tightened claim statements inCLAIM_MAP.yaml. - CI Permissions: Added
permissions: contents: readtodet-gates.ymlfor least-privilege workflow execution. - CI Robustness: Made ripgrep install idempotent; gated
validate-evidenceonclassify-changessuccess; invoked CJS scripts vianodefor cross-platform portability. - Evidence Validation: Relaxed
commit_shacheck to acceptlocalsentinel for local development; exportedgenerateEvidenceandvalidateClaimsfunctions for unit testing (#286). - Claims Precision: Sharpened
PRF-001statement to reference specific Criterion benchmark rather than generic threshold language. - Backlog: Added five
TASKS-DAG.mditems: BLD-001 claim gap, macOS parity claim, CI concurrency controls, expanded script test coverage, anddet-policy.yamlpath simplification. - Evidence Completeness: Added
REPRO-001claim for G4 build reproducibility toCLAIM_MAP.yamland wired intogenerate_evidence.cjs. - Script Hardening: Added
Array.isArrayguard forrequired_gatesinvalidate_det_policy.cjs; used explicit null/undefined check invalidate_claims.cjsinstead of falsy coercion. - Test Robustness: Encoded all 5 CBOR fields in
reject_invalid_versionto prevent false passes from decoder field-read reordering. - Docs: Added G3 staging-optional rationale in
RELEASE_POLICY.md; merge-commit revert guidance and evidence packet filing inROLLBACK_TTD.md; documentedtests/**/e2e/**classification rationale indet-policy.yaml. - Gate Coverage: Made G3 (perf-regression) run for all non-
run_nonepaths, not justrun_full. Ensures PRF-001 claim fires for DET_IMPORTANT changes (e.g.,warp-benches). Movedperf-artifactspresence check to always-required. - Classification Precision: Carved
tests/dind*andtestdata/dind/**out of the DET_NONCRITICALdocscatch-all into a dedicateddind-tests-rootentry at DET_IMPORTANT, preventing gate evasion for DIND test modifications. - Policy Simplification: Replaced 20+ explicit docs paths with
**catch-all indet-policy.yaml; max-class semantics ensure higher-priority patterns win. - CI Concurrency: Added
concurrencyblock todet-gates.ymlto cancel superseded runs on the same branch. - CI Robustness: Added push-event empty changelist guard (defaults to full run).
- Dynamic DETERMINISM_PATHS: Replaced hardcoded crate list in
static-inspectionwithyq/jqextraction fromdet-policy.yamlDET_CRITICAL entries, eliminating manual sync. - Evidence Sync Guardrails: Added CI cross-check step validating claim IDs
in
evidence.jsonmatchCLAIM_MAP.yamlexactly; addedsec-claim-map.jsontest ID existence verification against source. - macOS Parity Claim: Added
DET-003toCLAIM_MAP.yamlandgenerate_evidence.cjsfor macOS-specific determinism verification. - Claims Precision: Fixed REPRO-001 evidence type from
static_inspectiontohash_comparison; flattened verboserequired_evidencesyntax. - Test Assertions: Strengthened
reject_invalid_enum_tagstest to assert specific error messages instead of bareis_err()checks. - CI Timeouts: Added
timeout-minutesto alldet-gates.ymljobs to prevent hung jobs from burning the 6-hour GitHub default. - Classification Optimization: Added early-exit in
classify_changes.cjswhenmaxClassreachesDET_CRITICAL(guarded byrequire_full_classification). - Build Repro Fix: Restored
rustup target add wasm32-unknown-unknowninbuild-repro— required becauserust-toolchain.tomlpins a specific Rust version that overrides thedtolnay/rust-toolchainaction's target.
- Path-Aware CI Gates: Implemented
det-policy.yamlandclassify_changes.cjsto classify workspace crates (DET_CRITICAL/IMPORTANT/NONCRITICAL) and drive selective CI gate triggering (G1-G4). - Hardening Gates (G1-G4):
- G1 (Determinism): Integrated float parity tests and the DIND (Deterministic Ironclad Nightmare Drills) suite on both Linux and macOS.
- G2 (Security): Added negative security tests for the CBOR decoder (MAX_OPS, invalid versions/enums, truncated payloads).
- G3 (Performance): Created
materialization_hotpathCriterion benchmark inwarp-benchesto track materialization overhead. - G4 (Build): Added WASM build reproducibility checks verifying bit-exact artifacts across clean rebuilds.
- Evidence Integrity: Added
generate_evidence.cjsandvalidate_claims.cjsto ensure allVERIFIEDclaims are backed by immutable CI artifacts (run IDs, commit SHAs). - Static Inspection: Integrated
DET-001automated static inspection into CI to verify zero-HashMap usage in deterministic guest paths. - Governance: Published
RELEASE_POLICY.md(staging/prod blockers) andROLLBACK_TTD.md(commit-ordered rollback sequences). - Security Claim Mapping: Exported
sec-claim-map.jsonmapping decoder controls to explicit negative test cases.
- Scene Rendering Port (
echo-scene-port): Defined the core data model for deterministic scene updates, including nodes, edges, labels, and camera state. - Scene Codec (
echo-scene-codec): Implemented a high-performanceminicborcodec forSceneDeltaserialization with strict validation. - Float Parity Proof: Integrated a cross-language verification suite
ensuring
canonicalize_f32produces bit-identical results between Rust and JavaScript. - Scene Integrity Drills: Added stress tests for atomic state mutations and robustness against truncated CBOR payloads.
- TTD Wire Protocols (v2): Implemented high-integrity codecs for intents and
receipts.
- Added
EINT v2(Intent Envelope) with Little-Endian fixed headers and BLAKE3 payload checksums. - Added
TTDR v2(Tick Receipt Record) supporting full provenance commitments including state roots and emission digests. - Integrated "Header Integrity Drills" and a decoder fuzzer to ensure protocol robustness.
- Added
- Provenance & Merkle Hardening: Expanded core state model to support
deterministic "Show Me Why" features.
- Added
AtomWriterecords to track causal arrows from rules to state changes. - Implemented
compute_tick_commit_hash_v2, binding schema identity, worldline history, and materialized emissions into a single Merkle root. - Added
TruthSink::clear_sessionto ensure isolated and leak-free memory management for TTD sessions.
- Added
- DIND Phase 5 (The Shuffle): Added robustness against insertion order and
HashMap iteration leaks.
- Implemented
echo-dind convergecommand to verify that shuffles of commutative operations (e.g. disjointput_kv) yield identical final state hashes. - Added randomized scenario generator (
scripts/bootstrap_randomized_order.mjs) producing semantically equivalent transcripts via different orderings. - Added regression tests for Invariant A (Self-Consistency) and Invariant B (Convergence) in CI; see issue #22.
- Implemented
- Domain-Separated Hash Contexts: Added unique domain-separation prefixes
to all core commitment hashes to prevent cross-context structural collisions.
state_root(graph hash),patch_digest(tick patch), andcommit_id(Merkle root) now use distinct BLAKE3 domain tags (e.g.echo:state_root:v1\0).RenderGraph::compute_hash(echo-graph) now uses its own domain tag, ensuring renderable snapshots cannot collide with engine state roots.- Added
warp_core::domainmodule containing public prefix constants. - Integrated cross-domain collision tests into CI.
- Benchmarks CI Integration: The
warp-benchespackage is now integrated into the CI compilation gate (cargo check --benches).
- Roadmap Refactor ("Sharpened" structure): Migrated the flat roadmap into
a 2-level hierarchy based on features and milestones.
- Established a WIP Cap policy: maximum 2 active milestones and 3 active feature files per milestone to prevent context thrashing.
- Added binary Exit Criteria to all milestone READMEs to ensure clear, objective completion signals.
- Renamed milestones for clarity (e.g.
lock-the-hashes,first-light,proof-core). - Audited and updated license headers (SPDX) and formatting (Prettier/MD028) across roadmap documents.
-
Typed
HubConnectErrorenum replaces the opaqueHubConnectError(String). Four variants (Timeout,Connect,Handshake,Subscribe) carry structured context, and ashould_retry()predicate is wired into the ninelives retry policy so future non-transient variants can short-circuit retries. -
Hub observer task exits are surfaced — the fire-and-forget
tokio::spawnis wrapped in a watcher task that logs unexpected exits and panics atwarn!/error!level, preventing silent observer disappearance. -
connect_failuresrestored to per-attempt semantics — the metric now increments on every failed connection attempt (1:1 withconnect_attempts), not once per exhausted retry burst. This preserves dashboard/alerting accuracy during prolonged hub outages. -
Hub observer reconnect now uses
ninelivesretry policy with exponential backoff (250 ms → 3 s) and full jitter, replacing hand-rolled backoff state. Retries are grouped into bursts of 10 attempts; on exhaustion a 10 s cooldown separates bursts. This prevents synchronized retry storms across gateway instances and improves recovery behavior during prolonged hub outages. -
Connection setup (connect + handshake + subscribe) extracted into
hub_observer_try_connect, separating connection logic from retry orchestration. -
Entire connection attempt (connect + handshake + subscribe) is now wrapped in a single 5 s timeout, preventing a stalled peer from hanging the retry loop.
-
Retry policy construction uses graceful error handling instead of
.expect(), so a misconfiguration disables the observer with a log rather than panicking inside a fire-and-forgettokio::spawn. -
Added 1 s cooldown after the read loop exits to prevent tight reconnect loops when the hub accepts connections but immediately closes them.
- Security: upgraded
bytes1.11.0 → 1.11.1 to fix RUSTSEC-2026-0007 (integer overflow inBytesMut::reserve).